
GDPR and Data Protection Compliance in France: A Guide for Foreign Companies
To be GDPR-compliant in France, map your data processing, set a lawful basis for each use, keep a record of processing (Article 30), publish clear privacy notices, secure the data, manage subject rights, and follow CNIL guidance — the French regulator that enforces the GDPR and the Data Protection Act.
France applies the GDPR alongside national rules in the French Data Protection Act, policed by an active regulator, the CNIL. Foreign companies handling French residents’ data face real enforcement risk. This guide highlights the practical compliance steps and the CNIL-specific points that catch international teams.
GDPR Compliance Steps in France
| Step | What to Do | Why It Matters |
| 1. Map data | Inventory what you collect and why | Foundation of every other step |
| 2. Set lawful basis | Consent, contract, legitimate interest, etc. | No processing without a basis |
| 3. Record processing | Maintain the Article 30 register | Required in most operating cases and routinely requested in CNIL investigation |
| 4. Inform people | Clear privacy notices | Transparency is a core duty |
| 5. Secure and govern | Technical + organisational measures | Reduces breach and fines |
| 6. Handle rights & breaches | Respond in time; notify within 72h | Non-response triggers complaints |
Does the GDPR Apply to a Company Based Outside France?
Yes, if you offer goods or services to people in France or monitor their behaviour, the GDPR applies regardless of where your company sits. Where Article 3(2) GDPR applies and you have no establishment in the EU, you have to appoint an EU representative under Article 27 GDPR, subject to limited exceptions (for example, occasional, low-risk processing that does not involve large-scale use of special-category data). The CNIL can investigate foreign companies in these situations.
What Are the CNIL-Specific Points to Watch?
- Data subject rights: the CNIL expects clear, timely handling of access, deletion, objection (especially to marketing) and other GDPR rights, with no systematic obstruction of unjustified refusals.
- Retention periods: you must define, document and actually apply retention periods, deleting or anonymizing data when they are no longer needed and justifying any longer retention under French law (for example, limitation periods or archiving obligations).
- Data security and breaches: the CNIL looks at concrete technical and organizational measures and at how you detect, investigate and report incidents. Weak security and poor breach handling regularly lead to sanctions.
- Cookies and trackers: the CNIL enforces strict consent rules for cookies and has fined major companies over cookie banners, and has recently published practical guidance dedicated to trackers.
- .Data transfers: transfers outside the EU/EEA need a valid mechanism (adequacy decision, standard contractual clauses, BCR), and where needed a documented transfer impact assessment, and supplementary measures The CNIL pays particular attention to transfer involving US-based providers and to health or other sensitive data.
- Sensitive data and HR: the CNIL scrutinises health data, employee monitoring and biometric access.
- French language: privacy notices to French consumers should be available in French.
When Do You Need a DPO or a DPIA?
A Data Protection Officer (DPO) is mandatory for public bodies and for organisations whose core activity involves large-scale, regular and systematic monitoring of individuals, or large scale processing of sensitive data or data relating to criminal convictions. A Data Protection Impact Assessment (DPIA) is required when processing is likely to result in a high risk to individuals rights and freedoms, such as large-scale profiling or systematic surveillance.
What Are the Penalties for Non-Compliance?
The GDPR allows fines up to €20 million or 4% of global annual turnover, whichever is higher. The CNIL can also issue formal notices, injunctions and public sanctions. Reputational damage and business disruption often exceed the fine itself.
Controller vs Processor: Who Is Responsible?
| Feature | Controller | Processor |
| Role | Decides why and how | Acts on controller instructions |
| Main duty | Overall compliance | Security + follow instructions |
| Contract needed | With processors (article 28 GDPR)
With joint controllers (article 26 GDPR) |
With controller (article 28 GDPR)
With subprocessor (article 28 (GDPR) |
| Direct fines | Yes | Yes, for its own GDPR breaches |
Final Verdict
Our data protection team builds and audits GDPR programmes for foreign companies operating in France, from cookie and pixel compliance to international transfers and CNIL investigations. De Gaulle Fleurance turns data rules into a workable operating model and defends clients when the regulator comes knocking.







