Menu

GDPR and Data Protection Compliance in France: A Guide for Foreign Companies

Articles 29 July 2026
Digital and Technology Law New Technologies, Digital and Telecoms CSR Privacy +

To be GDPR-compliant in France, map your data processing, set a lawful basis for each use, keep a record of processing (Article 30), publish clear privacy notices, secure the data, manage subject rights, and follow CNIL guidance — the French regulator that enforces the GDPR and the Data Protection Act.

France applies the GDPR alongside national rules in the French Data Protection Act, policed by an active regulator, the CNIL. Foreign companies handling French residents’ data face real enforcement risk. This guide highlights the practical compliance steps and the CNIL-specific points that catch international teams.

GDPR Compliance Steps in France

Step What to Do Why It Matters
1. Map data Inventory what you collect and why Foundation of every other step
2. Set lawful basis Consent, contract, legitimate interest, etc. No processing without a basis
3. Record processing Maintain the Article 30 register Required in most operating cases and routinely requested in CNIL investigation
4. Inform people Clear privacy notices Transparency is a core duty
5. Secure and govern Technical + organisational measures Reduces breach and fines
6. Handle rights & breaches Respond in time; notify within 72h Non-response triggers complaints

Does the GDPR Apply to a Company Based Outside France?

Yes, if you offer goods or services to people in France or monitor their behaviour, the GDPR applies regardless of where your company sits. Where Article 3(2) GDPR applies and you have no establishment in the EU, you have to appoint an EU representative under Article 27 GDPR, subject to limited exceptions (for example, occasional, low-risk processing that does not involve large-scale use of special-category data). The CNIL can investigate foreign companies in these situations.

What Are the CNIL-Specific Points to Watch?

  • Data subject rights: the CNIL expects clear, timely handling of access, deletion, objection (especially to marketing) and other GDPR rights, with no systematic obstruction of unjustified refusals.
  • Retention periods: you must define, document and actually apply retention periods, deleting or anonymizing data when they are no longer needed and justifying any longer retention under French law (for example, limitation periods or archiving obligations).
  • Data security and breaches: the CNIL looks at concrete technical and organizational measures and at how you detect, investigate and report incidents. Weak security and poor breach handling regularly lead to sanctions.
  • Cookies and trackers: the CNIL enforces strict consent rules for cookies and has fined major companies over cookie banners, and has recently published practical guidance dedicated to trackers.
  • .Data transfers: transfers outside the EU/EEA need a valid mechanism (adequacy decision, standard contractual clauses, BCR), and where needed a documented transfer impact assessment, and supplementary measures The CNIL pays particular attention to transfer involving US-based providers and to health or other sensitive data.
  • Sensitive data and HR: the CNIL scrutinises health data, employee monitoring and biometric access.
  • French language: privacy notices to French consumers should be available in French.

When Do You Need a DPO or a DPIA?

A Data Protection Officer (DPO) is mandatory for public bodies and for organisations whose core activity involves large-scale, regular and systematic monitoring of individuals, or large scale processing of sensitive data or data relating to criminal convictions. A Data Protection Impact Assessment (DPIA) is required when processing is likely to result in a high risk to individuals rights and freedoms, such as large-scale profiling or systematic surveillance.

What Are the Penalties for Non-Compliance?

The GDPR allows fines up to €20 million or 4% of global annual turnover, whichever is higher. The CNIL can also issue formal notices, injunctions and public sanctions. Reputational damage and business disruption often exceed the fine itself.

Controller vs Processor: Who Is Responsible?

Feature Controller Processor
Role Decides why and how Acts on controller instructions
Main duty Overall compliance Security + follow instructions
Contract needed With processors (article 28 GDPR)

With joint controllers (article 26 GDPR)

With controller (article 28 GDPR)

With subprocessor (article 28 (GDPR)

Direct fines Yes Yes, for its own GDPR breaches

Final Verdict

Our data protection team builds and audits GDPR programmes for foreign companies operating in France, from cookie and pixel compliance to international transfers and CNIL investigations. De Gaulle Fleurance turns data rules into a workable operating model and defends clients when the regulator comes knocking.

FAQs

General registration was abolished under the GDPR. You no longer have to file a blanket registration of all your processing activities. Instead, you must keep an internal record of processing and, where required, carry out Data Protection Impact Assessments (DPIAs). Some specific activities – in particular certain health-data projects (research, studies, evaluations, use of the French national health data system) – may still require prior CNIL authorisation. Finally, when you appoint a Data Protection Officer (DPO), you must notify this appointment to the CNIL via its online form.

No. Consent is only one of six lawful bases. Contract performance or legitimate interest often applies, but each use needs a documented basis.

Notify the CNIL within 72 hours of becoming aware of a breach that risks individuals’ rights, and inform affected people when the risk is high.

You must appoint an EU representative where Article 3(2) GDPR applies (you target or monitor people in the EU) and you have no EU establishment, unless an exception applies (for example, occasional, low-risk processing that does not include large-scale use of special-category data).

Would you like to be kept up to date with the latest news on this topic?
Sign up to receive e-mails of new articles, events, analysis... on the subjects most relevant to you.
Create your customized watch

Receive news on the topics
that matter to you


Further information

Discover our professionals

Matthieu
Dary
Partner
Cécile
Théard-Jallu
Partner
Serge
Lederman
Partner
Adam
Stolcz
Lawyer - Senior Manager

Latest news

Space law France 2026
Articles 29 July 2026
Space law in France (2026)
Deals 16 July 2026
De Gaulle Fleurance is advising the Caisse des Dépôts on the restoration of the Vauban Citadel in Belle-Île-en-Mer
Van Lys Bank
Deals 8 July 2026
De Gaulle Fleurance advises Van Lys Bank, the investment bank of Caisse d’Epargne Hauts-de-France, on the financing of Spacinov’s first LBO
CIC-BNP-LCL
Deals 7 July 2026
De Gaulle Fleurance has advised the lenders on the financing of Ailancy’s acquisition of the Valmen Group