France
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in France — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Most data can leave France. You just need the right paperwork first, the same as anywhere in Europe. France then adds strict rules of its own. Health records must be stored inside Europe. Online gambling records must sit on a machine in mainland France. From 1 September 2026, the invoicing platform every French business must use has to run entirely from inside Europe.
Data governance in France
The eight things that decide how you handle data about people in France. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. French rules apply even if you have no office in France. European law already covers anyone offering goods or services to people in Europe. France's own privacy law goes further. Its national rules apply as soon as the person concerned lives in France. That holds even if your company is based somewhere else. There is no size or revenue limit that lets you escape.
- What you have to do here:
- Appoint a representative
France's privacy law of 6 January 1978, the loi Informatique et Libertes, says French national rules apply whenever the person whose data it is lives in France. That holds even if your company has no office in France. This matters most for cookies and other tracking technology. Cookies sit in a separate part of that law. It is the French version of Europe's ePrivacy rules. Those rules sit outside Europe's one-stop-shop system. That system normally lets a company deal with a single lead regulator in one country. Because cookies are outside it, France's privacy regulator, the CNIL, has fined foreign-based platforms directly. It did not route the cases through the Irish or Luxembourg regulator. France's top administrative court, the Conseil d'Etat, agreed this was allowed. If you have no office anywhere in the European Union, you must appoint a representative there. That representative does not have to be in France.
Sources
- Official sourceLegifrance / Secretariat general du GouvernementLoi n° 78-17 du 6 janvier 1978 relative a l'informatique, aux fichiers et aux libertes, article 3 (territorial scope)
legifrance.gouv.fr
“les regles nationales ... s'appliquent des lors que la personne concernee reside en France, y compris lorsque le responsable de traitement n'est pas etabli en France”
Link checked 18 August 2026
- Official sourceCommission nationale de l'informatique et des libertesSanctions et mesures correctrices : la CNIL presente le bilan 2025
cnil.fr
Link checked 18 August 2026
Where the data is allowed to live
Yes for an ordinary business, as long as you do the paperwork. The European transfer rules apply and France adds nothing extra. But four French industries override that. Health records must be stored inside Europe and nowhere else. Online gambling records must be copied in real time onto hardware in mainland France. Electronic invoicing platforms must run their whole system from inside Europe. Sensitive state data must sit on a cloud that France's cyber agency has certified as beyond the reach of foreign authorities.
How France treats each industry, checked 18 August 2026. HEALTH - data must stay in the country at the European border. Decret n° 2026-209 of 24 March 2026 writes into the public health code that personal health data is stored only on the territory of a Member State. The health hosting certification standard already said the same: storage only within the European Economic Area (requirement EXI 28). Someone outside Europe can look at the data remotely, but only in two cases. Either the country has an official European decision saying it is safe enough. Or you use one of Europe's approved safeguards, such as the standard contract. The host must also list every non-European law that could force it to hand data over. ONLINE GAMBLING - a copy must stay in the country Article 31 of loi n° 2010-476 of 12 May 2010 makes licensed operators copy gambling and betting data in real time onto physical hardware in mainland France. The rest of your platform can live abroad. The archive copy cannot. ELECTRONIC INVOICING - data must stay in the country at the European border, from 1 September 2026. To be registered as an approved platform, formerly called a plateforme de dematerialisation partenaire, an operator must promise two things. It must run its computer systems from an EU Member State. And it must make it impossible to move hosted data outside the European Union. GOVERNMENT AND PUBLIC SECTOR - data must stay in the country Decret n° 2026-272 of 14 April 2026 applies article 31 of the loi SREN. It covers State administrations, listed State bodies and six named public interest groupings. They may put particularly sensitive data only on cloud services that meet a security standard set by ANSSI, France's cyber agency. That standard covers where data is kept and protection against access by another country's public authorities. TAX AND ACCOUNTING RECORDS - data can leave only if conditions are met, but with a real geographic limit. Article L102 C of the Livre des procedures fiscales allows electronic invoices to be stored in another EU Member State. It also allows a country bound to France by a mutual assistance convention, or one that gives the tax authority immediate online access. Nowhere else is allowed. You must declare where you store them with your annual return. BANKING, PAYMENTS, INSURANCE, SECURITIES - we found no French rule forcing this data to stay in France, checked 18 August 2026, confidence medium-high. The main rules for financial firms come from DORA, Europe's digital resilience law. It makes you disclose where data is kept, allow audits and have exit plans. It does not make data stay in France. French banking secrecy sits in article L511-33 of the Code monetaire et financier. It expressly allows you to share data with an outside supplier. The contract must cover important operational work. So, unlike Germany, banking secrecy does not block cloud use. TELECOMS - we found no rule forcing this data to stay in France. The French rules are about how long you keep data, not where you keep it. MAPPING AND GEOSPATIAL, EDUCATION, DEFENCE - we found no general civil rule forcing data to stay in France, checked 18 August 2026, confidence medium. Defence and classified material fall under separate national security rules. Those are outside what this record covers.
Sources
- Official sourceJournal officiel de la Republique francaiseDecret n° 2026-209 du 24 mars 2026 portant modification de certaines dispositions du code de la sante publique relatives a l'hebergement de donnees de sante a caractere personnel
legifrance.gouv.fr
“le stockage de ces donnees, il est mis en oeuvre exclusivement sur le territoire d'un Etat membre”
Link checked 18 August 2026
- Official sourceLegifranceLOI n° 2010-476 du 12 mai 2010 relative a l'ouverture a la concurrence et a la regulation du secteur des jeux d'argent et de hasard en ligne, article 31
legifrance.gouv.fr
“est tenu de proceder a l'archivage en temps reel, sur un support materiel situe en France metropolitaine”
Link checked 18 August 2026
- Official sourceLegifranceArticle L102 C du Livre des procedures fiscales (where invoices may be stored)
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseDecret n° 2026-272 du 14 avril 2026 relatif a la protection des donnees d'une sensibilite particuliere des administrations, operateurs et groupements d'interet public de l'Etat
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceLegifranceArticle L511-33 du Code monetaire et financier (banking secrecy and outsourcing exception)
legifrance.gouv.fr
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
You can only send data to countries Europe has approved, or use approved paperwork. Brussels decides this, not Paris. Data may go to a country the European Commission has formally approved. Or it may go anywhere else if you sign Europe's official standard contract. With that contract you must also write down why you think the data will still be safe. The approved list is long. It includes the United Kingdom, Japan, South Korea, Canada, Switzerland, Brazil and about a dozen others. It also covers American companies signed up to the transatlantic Data Privacy Framework. France adds no separate national approval step.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims
France uses the European transfer routes unchanged. Those routes are official European decisions that a country is safe enough, the 2021 standard contract clauses, and company-wide binding rules. Certification and codes of conduct also count. So do a few narrow exceptions in European law. Since the Schrems II judgment you are also expected to write a transfer risk assessment. Two French points sit on top. First, sending data outside the European Union unlawfully is a crime in France. Article 226-22-1 of the Code penal carries up to five years in prison and a fine of 300,000 euros (about 330,000 US dollars). That is not merely an administrative fine. Second, the health, gambling, electronic invoicing and sensitive state data rules are geographic bans. No transfer paperwork fixes them. The objection is to the location itself, not to the level of protection. The EU-US Data Privacy Framework was still valid on 18 August 2026. But it is under appeal at the Court of Justice. On 31 July 2026 the European Data Protection Board formally asked the Commission to re-examine it. Do not build your whole setup on that one route.
Sources
- Official sourceEuropean CommissionAdequacy decisions - the populated list of approved destinations
commission.europa.eu
Link checked 18 August 2026
- Official sourceLegifranceArticle 226-22-1 du Code penal - criminal offence of unlawful transfer outside the European Union
legifrance.gouv.fr
“Le fait de proceder ou de faire proceder a un transfert de donnees a caractere personnel ... vers un Etat n'appartenant pas a l'Union europeenne ... en violation du chapitre V du reglement (UE) 2016/679”
Link checked 18 August 2026
- Official sourceCommission nationale de l'informatique et des libertesTransferer des donnees hors de l'Union europeenne - the CNIL's own guidance page
cnil.fr
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
France's privacy regulator is the CNIL. It is one of the busiest in Europe. In 2025 alone it issued 83 penalties totalling about 487 million euros (roughly 530 million US dollars). It also issued 143 formal warnings. It is still fining in 2026. In January it fined the national employment agency 5 million euros. In May it fined a health data company 5 million euros. Separate regulators run the industry rules. All of them are staffed and working.
These are the CNIL's own published figures for 2025. It made 259 corrective decisions. Of those, 83 were penalties: 16 through the ordinary route and 67 through the simplified one. It also issued 143 formal notices to comply, 31 reminders and 2 warnings. Total fines came to 486,839,500 euros (about 530 million US dollars). Twenty-one penalties concerned cookies and trackers. One was 325 million euros and one was 150 million euros. Sixteen concerned video surveillance of employees. Fourteen concerned poor security. Twenty-seven fines came with orders backed by daily payments until you fix the problem. That pattern is the best guide to where a French inspection will go: cookies, watching staff, and weak passwords. Rating: aggressive. The regulator does not wait for complaints. It sets yearly inspection themes and uses the simplified route to get through volume. Other regulators you may meet. ANSSI is the cyber agency, and it owns the SecNumCloud certification. The Agence du numerique en sante certifies health data hosts. The ANJ handles online gambling. The DGFiP is the tax authority and registers electronic invoicing platforms. The ACPR and the AMF cover finance. ARCEP covers telecoms. The SISSE at the finance ministry is the single desk for foreign document requests.
Sources
- Official sourceCommission nationale de l'informatique et des libertesSanctions et mesures correctrices : la CNIL presente le bilan 2025 (published 9 February 2026)
cnil.fr
“83 sanctions ... 486 839 500 euros”
Link checked 18 August 2026
- Official sourceCommission nationale de l'informatique et des libertesCNIL sanctions index - showing EUR 5m against France Travail (22 January 2026) and EUR 5m against IQVIA Operations France (26 May 2026)
cnil.fr
Link checked 18 August 2026
How long you must keep it — and when to delete it
You face minimum keeping times and a maximum, and they pull in opposite directions. You must keep accounting books and supporting documents for ten years. Tax records must be kept for six years. Employment contracts and pay records must be kept for five years. Phone and internet subscriber identity data must be kept for five years. In the other direction, European law says you must delete personal data once you no longer need it. France solves the clash the way most of Europe does. The legal minimum wins. But it only wins for the exact documents the law names, and only for as long as it says.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
MINIMUM KEEPING TIMES. Accounting books, ledgers and supporting documents: 10 years from the close of the financial year (Code de commerce, article L123-22). Tax books, registers and documents: 6 years from the last entry (Livre des procedures fiscales, article L102 B), or 10 years in fraud cases. Commercial contracts and business correspondence: 5 years. Employment contracts and payroll: 5 years. Social contribution records: 3 years. Time-recording records: 1 year. Property transaction deeds: 30 years. Telecoms, under article L34-1 of the Code des postes et des communications electroniques: civil identity data 5 years from the end of the contract. Subscription and payment information: 1 year. Technical connection data: 1 year. On top of that, a Prime Minister's decree of 15 October 2025 ordered everyone's traffic and location data kept for one year. The ground was national security. It expires on 21 October 2026 unless renewed. It has been renewed every year since 2021. MAXIMUM. European law says you must not keep personal data longer than you need it. The CNIL enforces this. Several 2025 penalties were about keeping customer or sales prospect records forever. If you store invoices electronically outside France, article L102 C of the Livre des procedures fiscales also limits where they may sit. It is not just about how long you keep them. WHICH WINS. A minimum keeping time set by law is a legal duty. It beats a request to delete. The practical answer is to move the record into a locked-down archive instead of leaving it in your live system.
Sources
- Official sourceDirection de l'information legale et administrativeCombien de temps une entreprise doit-elle conserver ses documents ? - official retention table
entreprendre.service-public.gouv.fr
Link checked 18 August 2026
- Official sourceLegifranceArticle L34-1 du Code des postes et des communications electroniques - telecoms retention periods
legifrance.gouv.fr
“les informations relatives a l'identite civile de l'utilisateur, jusqu'a l'expiration d'un delai de cinq ans”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseDecret n° 2025-980 du 15 octobre 2025 portant injonction de conservation pour une duree d'un an de certaines categories de donnees de connexion
legifrance.gouv.fr
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
France has at least four breach deadlines and they run at different speeds. Every organisation has 72 hours to tell the CNIL about a personal data breach. Phone and internet providers have only 24 hours. Hospitals and clinics must report a serious computer security incident to their regional health agency immediately. Banks, insurers and investment firms follow their own European deadlines. They must send a first report within 4 hours of classifying an incident as major. That must happen no later than 24 hours after they notice it.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Clock 1. European privacy law: 72 hours to the CNIL. You must also tell the affected people without undue delay where the risk to them is high. Clock 2. The telecoms rules. If you provide electronic communications services to the public and are declared with ARCEP, you must tell the CNIL within 24 hours of establishing the breach. If your investigation is incomplete, you send a follow-up within a further 72 hours. This is a separate register and a separate form. It applies on top of the 72-hour rule, not instead of it. Clock 3. Health. Articles D1111-16-2 to D1111-16-4 of the Code de la sante publique, made by decret n° 2016-1214 of 12 September 2016, cover hospitals, medico-social establishments and laboratories. They must report serious computer security incidents without delay to their regional health agency. The agency passes them to CERT Sante. Clock 4. DORA, Europe's digital resilience law for financial firms. A first report within 4 hours of classifying an incident as major, and within 24 hours of becoming aware of it. Then an intermediate report and a final report. A fifth clock will appear when France passes its NIS2 law. NIS2 is Europe's cybersecurity directive. It will require a 24-hour early warning to ANSSI, the cyber agency. The most common mistake is a telecoms or health organisation running only the 72-hour European process and missing the shorter industry deadline.
Sources
- Official sourceCommission nationale de l'informatique et des libertesNotification "Paquet telecom" - the 24-hour clock for electronic communications providers
cnil.fr
“La notification doit etre transmise a la CNIL dans les 24 h de la constatation de la violation”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseDecret n° 2016-1214 du 12 septembre 2016 relatif aux conditions selon lesquelles sont signales les incidents graves de securite des systemes d'information
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceLegifranceArticles D1111-16-2 a D1111-16-4 du Code de la sante publique - categories of reportable incidents
legifrance.gouv.fr
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things the summary does not tell you. (1) Breaking the privacy law in France is a crime, not just a fine. Sending data out of Europe unlawfully carries up to five years in prison and a 300,000 euro fine (about 330,000 US dollars). It attaches to people, not only companies. (2) A child is anyone under 15 for consent. Not 13, not 16. (3) A 2023 law setting a social media age of 15 is printed in the statute book. It never came into force and cannot be enforced. (4) Handing documents to a foreign court or regulator can itself be a crime in France. (5) Cookies are policed separately from the rest of privacy law. A foreign company cannot hide behind its lead European regulator.
- What you have to do here:
- Get a parent's consent for children · Do not hand data to foreign authorities on demand
- What it costs if you get it wrong:
- Criminal liability
TRAP 1. You can go to prison. Articles 226-16 to 226-24 of the Code penal cover most serious data protection failures. They carry 5 years in prison and a 300,000 euro fine (about 330,000 US dollars). That includes sending data outside the European Union unlawfully, under article 226-22-1. Obstructing the CNIL is a separate offence carrying 1 year and a 15,000 euro fine (about 16,000 US dollars). This is a real difference from most of Europe, where the risk is a fine only. TRAP 2. Age 15. The French privacy law of 1978 sets the digital consent age at 15. Below that age, a parent must consent together with the child. Products built for age 13 (United States) or age 16 (Germany) are wrong in France. TRAP 3. A law that looks binding and is not. Loi n° 2023-566 of 7 July 2023 set a social media age of 15 and duties on platforms. It never came into force. No application decree was ever published. In May 2025 the government told Parliament the law could not proceed because it rubbed against European Union law. The European Commission wrote on 14 August 2023 that France adopted the text without the notification procedure required by Directive 2015/1535. That makes it unenforceable. The Commission also said it conflicted with the Digital Services Act and the country-of-origin principle. A simple text search will report this as French law in force. It is not. A replacement bill was finally adopted on 21 July 2026. See what's coming. TRAP 4. The blocking statute. Loi n° 68-678 of 26 July 1968 makes it an offence to give economic, commercial, industrial, financial or technical documents to a foreign authority. You must use the official mutual assistance channels instead. Decret n° 2022-207 of 18 February 2022 created a single desk at the finance ministry, the SISSE. You must consult it. American discovery requests and foreign regulator demands are the usual trigger. TRAP 5. Cookies sit outside the one-stop-shop. They fall under article 82 of loi n° 78-17, the French version of Europe's ePrivacy rules. So the CNIL acts directly against foreign companies without going through a lead regulator. Cookies were the biggest single category of French fines in 2025, including one of 325 million euros. BONUS. Unlike Germany, French banking secrecy does not block cloud use. Article L511-33 of the Code monetaire et financier expressly allows you to share data with a supplier under a contract for important operational work.
Sources
- Official sourceLegifranceCode penal, articles 226-16 a 226-24 - criminal offences relating to personal data files
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceCommission nationale de l'informatique et des libertesCNIL recommendation 4 - parental consent for minors under 15 (article 45 of loi 78-17)
cnil.fr
Link checked 18 August 2026
- Official sourceAssemblee nationaleQuestion ecrite n° 5149 and government answer of 6 May 2025 - the majorite numerique law never entered into force
assemblee-nationale.fr
“La loi n° 2023-566 du 7 juillet 2023 ... n'a, pour sa part, pas pu prosperer en raison de frottements avec le droit de l'Union europeenne.”
Link checked 18 August 2026
- Official sourceMinistere de l'Economie, Direction generale des EntreprisesLa loi de blocage - Direction generale des Entreprises
entreprises.gouv.fr
Link checked 18 August 2026
What's changing next
Four dates in the next twelve months. 1 September 2026: every French business must be able to send and receive invoices through an approved platform. Those platforms must run entirely from inside Europe. Around 27 September 2026: the second phase of the health data hosting decree starts. 21 October 2026: the order forcing phone and internet companies to keep everyone's connection records for a year expires. It ends unless the Prime Minister renews it. 12 January 2027: cloud providers across Europe must drop switching and data export fees to zero.
- What you have to do here:
- Make switching cloud provider possible
CONFIRMED DATES. 1 September 2026 - electronic invoicing becomes compulsory. You must use an approved platform to send and receive invoices. To be approved, a platform operator must run its computer systems from an EU Member State. It must also prevent any transfer of hosted data outside the European Union. Around 27 September 2026 - paragraphs 2 and 3 of article 1 of decret n° 2026-209 take effect, six months after the rest. 21 October 2026 - decret n° 2025-980 expires. It has been renewed every year since 2021 and renewal is likely. But it is a decision someone has to take, not an automatic rollover. 12 January 2027 - the Data Act: all cloud switching charges and data export fees must be zero. STILL A BILL. DO NOT PLAN AS BINDING. France has a bill on the resilience of critical infrastructure and stronger cybersecurity. It would bring in NIS2, DORA and the critical entities directive. The Senate adopted it on 12 March 2025. A National Assembly special committee reported on it on 10 September 2025. ANSSI's own guidance says NIS2 starts in France only once the law, the decrees and the orders have all been promulgated. As of 18 August 2026 we found no evidence of promulgation. A new law protecting minors on social media was finally adopted by the National Assembly on 21 July 2026, after a joint committee. We could not verify its content or its start dates on an official source at the date of this record. THINGS THE GOVERNMENT CAN CHANGE WITH NO CONSULTATION. (1) The yearly order to keep connection data: one Prime Minister's decree turns it on or off. (2) The ANSSI SecNumCloud standard is approved by Prime Minister's order. So the rules for sensitive state cloud can be tightened without a new law. (3) The list of State bodies and public interest groupings covered by the SecNumCloud rule is set by decree and can be extended. (4) The health hosting decree sets transfer conditions inside contracts. So if Europe changes which countries it officially treats as safe, what a French hospital's supplier may do changes at once. The EU-US Data Privacy Framework is under appeal at the Court of Justice.
Sources
- Official sourceDirection generale des Finances publiquesFacturation electronique et plateformes agreees - 1 September 2026 start date
impots.gouv.fr
“Les entreprises assujetties devront en effet recourir aux services d'une plateforme agreee pour transmettre et recevoir leurs factures electroniques ... a compter du 1er septembre 2026”
Link checked 18 August 2026
- Official sourceAgence nationale de la securite des systemes d'informationAvancement de la transposition de la directive NIS 2 - ANSSI's own status page
aide.monespacenis2.cyber.gouv.fr
“NIS 2 rentrera donc en vigueur en France des lors que l'ensemble des textes de transposition (loi, decrets, arretes) auront ete promulgues.”
Link checked 18 August 2026
- Official sourceAssemblee nationaleProteger les mineurs des risques auxquels les expose l'utilisation des reseaux sociaux - definitive adoption 21 July 2026
assemblee-nationale.fr
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseDecret n° 2025-980 du 15 octobre 2025 - one-year retention injunction, expires 21 October 2026
legifrance.gouv.fr
Link checked 18 August 2026
What to do: Diarise 21 October 2026 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Health and social care data must stay in the country
Official name: Decret n° 2026-209 du 24 mars 2026 portant modification de certaines dispositions du code de la sante publique relatives a l'hebergement de donnees de sante a caractere personnel · Decret n° 2026-209, JORF n° 73 du 26 mars 2026; articles R. 1111-9-1 et suivants du code de la sante publique; referentiel de certification HDS approuve par arrete du 26 avril 2024 · Directly binding regulation
This is France's real hard rule on where data sits. Personal health data must be stored only inside the European Economic Area, by a certified host. The contract must name every foreign law that could force disclosure. Since March 2026 this sits in a decree, not only in a certification standard. So it now binds hospitals and software vendors as well as the data centre.
Enforced by Digital Health Agency
How this country controls where data goes: Not allowed · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Keep the data in the countryPersonal health data must be stored only on the territory of a Member State. The certification standard says the same: storage only within the European Economic Area (requirement EXI 28).
- Hold a security certificateYour host must hold French health data hosting certification, known as HDS or hebergeur de donnees de sante. The standard was approved by the arrete of 26 April 2024.
- Put a transfer safeguard in placeAny transfer needs an official European decision that the country is safe enough, or approved European safeguards such as the standard contract. Remote access from outside the European Economic Area counts as a transfer. The people whose data it is must have rights they can enforce and real ways to complain.
- Do not hand data to foreign authorities on demandYour hosting contract must list every non-European rule that could force the host to transfer or disclose the data. It must also list what you do to reduce that risk, and what risk is left.
- Written vendor contract
What it costs if you get it wrong
- Criminal liability: Hosting personal health data without certification is an offence under the code de la sante publiqueUncertified hosting
- Order to stopThe CNIL can order processing to stop; a health authority can terminate the hosting arrangement
Sources
- Official sourceJournal officiel de la Republique francaiseDecret n° 2026-209 du 24 mars 2026 relatif a l'hebergement de donnees de sante a caractere personnel
legifrance.gouv.fr
“le stockage de ces donnees, il est mis en oeuvre exclusivement sur le territoire d'un Etat membre”
Link checked 18 August 2026
- Official sourceAgence du numerique en santeReferentiel de certification Hebergeur de donnees de sante - exigences EXI 28, EXI 29 and EXI 30
esante.gouv.fr
“l'Hebergeur ou ses sous-traitants doivent stocker ces DSCP exclusivement au sein de l'Espace Economique Europeen (EEE)”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseArrete du 26 avril 2024 approuvant le referentiel de certification pour l'hebergement de donnees de sante a caractere personnel
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceCNIL / Journal officielDeliberation CNIL n° 2025-098 du 16 octobre 2025 portant avis sur le projet de decret
legifrance.gouv.fr
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Decret n° 2026-272 du 14 avril 2026 relatif a la protection des donnees d'une sensibilite particuliere des administrations, operateurs et groupements d'interet public de l'Etat traitees par un service d'informatique en nuage fourni par un prestataire prive · Decret n° 2026-272, taken under article 31 of loi n° 2024-449 du 21 mai 2024 (loi SREN); doctrine "cloud au centre", circulaire n° 6404/SG du 31 mai 2023 · Directly binding regulation
If you sell cloud services to the French State, this rule decides whether you can bid. State administrations, listed State bodies and six named public interest groupings hold particularly sensitive data. That data may only go on a cloud service certified as safe from foreign government access. Exemptions run 12 to 18 months and are published with reasons.
Enforced by National Cybersecurity Agency of France
How this country controls where data goes: Not allowed · Accepted routes: Certification scheme
What you have to do
- Prove the data stays under local controlThe cloud service must meet a security standard set by ANSSI, France's cyber agency. That standard covers where data is kept. It also covers protection against any access by another country's public authorities.
- Hold a security certificateYou need SecNumCloud certification from ANSSI, or an equal certification issued in the European Union or European Economic Area.
- Keep the data in the countryWhere you keep the data is one of the areas the ANSSI standard covers.
- Register or notifyIf no compliant service exists, you ask for an exemption through the supervising minister. The Prime Minister decides within two months. The decision and its reasons are published.
What it costs if you get it wrong
- Order to stopA non-compliant cloud arrangement cannot lawfully be used for the data concerned; the practical sanction is loss of the public contract
Sources
- Official sourceJournal officiel de la Republique francaiseDecret n° 2026-272 du 14 avril 2026
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceMinistere de l'Economie, Direction des affaires juridiquesPublication du decret d'application de l'article 31 de la loi SREN
economie.gouv.fr
“protection contre tout acces par des autorites publiques d'un Etat tiers”
Link checked 18 August 2026
- Official sourceDirection interministerielle du numeriqueLa doctrine de l'Etat - "cloud au centre"
numerique.gouv.fr
Link checked 18 August 2026
- Official sourcePremier ministre / LegifranceCirculaire n° 6404/SG du 31 mai 2023 - actualisation de la doctrine "cloud au centre"
legifrance.gouv.fr
Link checked 18 August 2026
Personal data must stay in the country
Official name: Immatriculation des plateformes agreees (ex plateformes de dematerialisation partenaires) - facturation electronique · Articles 242 nonies B a 242 nonies I du code general des impots, annexe II; conditions d'immatriculation publiees par la DGFiP · Government rules
Almost nobody has planned for this one. From 1 September 2026 every French business must send and receive invoices through an approved platform. Every approved platform must run its whole system inside the European Union, with outward transfers made impossible. So choosing a platform decides where your data lives. It is not just a purchasing detail.
Enforced by Public Finances Directorate General
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the country — from 1 September 2026The platform operator must promise to run its computer systems from an EU Member State. It must also make sure no hosted data can move outside the European Union.
- Register or notifyYou must register with the DGFiP, the French tax authority. The list of approved platforms is published as open data.
- Hold a security certificateIf you use a SecNumCloud-certified host, you do not have to list every server location. That certification already proves you meet the EU requirement.
- Written vendor contract
What it costs if you get it wrong
- Loss of your licenceLoss or refusal of registration means the platform cannot lawfully transmit invoices in France
Sources
- Official sourceDirection generale des Finances publiquesGuide utilisateur - demande d'immatriculation des plateformes agreees (lettre d'engagement)
impots.gouv.fr
“vous vous engagez a exploiter votre systeme d'information depuis le territoire d'un Etat membre de l'Union europeenne”
Link checked 18 August 2026
- Official sourceDirection generale des Finances publiquesFacturation electronique et plateformes agreees
impots.gouv.fr
Link checked 18 August 2026
- Official sourceDGFiP via data.gouv.frListe des plateformes agreees pour la facturation electronique (official register)
data.gouv.fr
Link checked 18 August 2026
Online gaming data needs a copy kept in the country
Official name: Article 31 de la loi n° 2010-476 du 12 mai 2010 relative a l'ouverture a la concurrence et a la regulation du secteur des jeux d'argent et de hasard en ligne · Loi n° 2010-476, article 31; ANJ exigences techniques ET1 v1.0 du 23 novembre 2023 · Act of parliament
This is a true mirror rule and one of the oldest of its kind in Europe. A licensed online gambling operator can run its business anywhere. But a copy of every bet and every game event must be written in real time to a machine physically in mainland France. The regulator can seize that machine.
Enforced by National Gambling Authority
How this country controls where data goes: No restriction
What you have to do
- Keep the data in the countryYou must archive gambling and betting events in real time on physical hardware in mainland France. The gambling regulator ANJ calls this the coffre-fort, or safe. Its technical rules confirm it must be hosted in mainland France.
- Keep logsArchived game records are held encrypted. You must be able to produce them for the regulator.
- Independent auditThe frontal component must be certified after six months, then once a year after that.
- Register or notifyOnly licensed operators may take bets from France.
What it costs if you get it wrong
- Loss of your licenceFailure to comply with the technical requirements attached to the licence
Sources
- Official sourceLegifranceLOI n° 2010-476 du 12 mai 2010, article 31
legifrance.gouv.fr
“est tenu de proceder a l'archivage en temps reel, sur un support materiel situe en France metropolitaine”
Link checked 18 August 2026
- Official sourceAutorite nationale des jeuxExigences techniques relatives au systeme d'information des operateurs de jeu (ET1 v1.0, 23 November 2023)
ressources.anj.fr
“la localisation physique du coffre-fort (celui-ci devant etre heberge en France metropolitaine conformement a l'article 31 de la loi n°2010-476 du 12 mai 2010)”
Link checked 18 August 2026
Telecoms rules
Official name: Article L34-1 du Code des postes et des communications electroniques, complete par le decret n° 2025-980 du 15 octobre 2025 · CPCE article L34-1 and article R. 10-13; decret n° 2025-980 du 15 octobre 2025 · Act of parliament
France does not require telecoms data to be stored in France. But it does require you to keep it. Identity data for five years, connection data for one year. Keeping everyone's traffic and location records rests on a Prime Minister's order that is renewed every year. So this can switch off, or back on, without a debate.
Enforced by Electronic Communications, Postal and Print Media Distribution Regulatory Authority
How this country controls where data goes: No restriction
What you have to do
- Keep data for a minimum period — 5 yearsThe user's civil identity data: 5 years from the end of the contract.
- Keep data for a minimum period — 1 yearOther subscription information and payment data: 1 year. Technical connection data (source of connection, terminal equipment): 1 year.
- Keep logs — 1 yearTraffic and location data: keep for one year. This was ordered by decret n° 2025-980 on national security grounds. That order expires on 21 October 2026 unless it is renewed.
- Report breaches to the regulator — within 24 hoursIf you provide electronic communications services to the public, you tell the CNIL within 24 hours, not 72.
What it costs if you get it wrong
- Criminal liabilityFailure to retain or produce data as required by the code
- Fixed maximum fineARCEP sanctions for breach of licence and code obligations
Sources
- Official sourceLegifranceArticle L34-1 du Code des postes et des communications electroniques
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseDecret n° 2025-980 du 15 octobre 2025 portant injonction de conservation d'un an
legifrance.gouv.fr
“Il est enjoint aux operateurs de communications electroniques ... de conserver, pour une duree d'un an, les donnees de trafic et de localisation”
Link checked 18 August 2026
- Official sourceCNILNotification "Paquet telecom" - 24-hour breach notification
cnil.fr
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Loi n° 78-17 du 6 janvier 1978 relative a l'informatique, aux fichiers et aux libertes · Loi n° 78-17, as amended by ordonnance n° 2018-1125 and later texts · Act of parliament
This is France's own privacy law. It adds three things to the European baseline. It reaches companies with no French office whenever the person lives in France. It sets the child consent age at 15. And it makes serious breaches a crime, with prison possible for individuals.
Enforced by National Commission for Data Protection and Liberties
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Get a parent's consent for children — applies at: under 15Article 45. A parent must consent together with the child. The age is 15, not 13 and not 16.
- Get consentArticle 82 covers cookies and similar trackers. It sits outside Europe's one-stop-shop system. So the CNIL acts directly against foreign companies.
- Appoint a data protection officer
- Secure the data
- Put a transfer safeguard in place
What it costs if you get it wrong
- Criminal liability: 5 years' imprisonment and €300,000 — about $330 thousandMost serious data protection offences under Code penal articles 226-16 to 226-24, including transferring data outside the European Union in breach of Chapter V of the GDPR (article 226-22-1)
- Criminal liability: 1 year's imprisonment and €15,000 — about $16 thousandObstructing the CNIL's work (Code penal article 226-22-2)
- Percentage of global turnover: Up to 4% of worldwide group turnover or €20,000,000 — about $22 millionAdministrative fines by the CNIL under the GDPR
- Daily fine until fixedInjunctions backed by daily penalty payments - used in 27 of the CNIL's 2025 fines
Sources
- Official sourceLegifranceLoi n° 78-17 du 6 janvier 1978 (consolidated text), articles 3, 45 and 82
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceLegifranceCode penal, articles 226-16 a 226-24
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceCNILCNIL 2025 enforcement review - 83 sanctions, EUR 486,839,500
cnil.fr
Link checked 18 August 2026
Personal data must stay in the country (2013)
Official name: Articles L102 B et L102 C du Livre des procedures fiscales; article L123-22 du Code de commerce · LPF articles L102 B and L102 C; Code de commerce article L123-22 · Act of parliament
This quiet rule applies to every business, not just regulated ones. You may only store electronic invoices in France, elsewhere in Europe, or in a country that has a tax mutual assistance treaty with France. A country that gives French inspectors immediate online access is also allowed. You must also tell the tax authority where you keep them.
Enforced by Public Finances Directorate General
How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed, Nothing required
What you have to do
- Keep data for a minimum period — 10 yearsAccounting books, ledgers and supporting documents: 10 years from the close of the financial year (Code de commerce L123-22).
- Keep data for a minimum period — 6 yearsTax books, registers, documents and records: 6 years from the last entry (Livre des procedures fiscales, L102 B). It is 10 years where fraud is established.
- Keep the data in the countryYou may store electronic invoices in France or in another EU Member State. You may also use a country bound to France by a mutual assistance convention. Or a country that gives the tax authority an immediate online right of access. Nowhere else is allowed.
- Keep records of how you use dataYou must declare where you store them with your annual results return. You must also declare any change of location outside France.
What it costs if you get it wrong
- Fixed maximum fineTax penalties for failure to produce records; rejection of accounts on audit
Sources
- Official sourceLegifranceArticle L102 C du Livre des procedures fiscales
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceLegifranceArticle L102 B du Livre des procedures fiscales - six-year retention
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceDirection de l'information legale et administrativeCombien de temps une entreprise doit-elle conserver ses documents ?
entreprendre.service-public.gouv.fr
Link checked 18 August 2026
Government data rules
Official name: Loi n° 68-678 du 26 juillet 1968 relative a la communication de documents et renseignements d'ordre economique, commercial, industriel, financier ou technique a des personnes physiques ou morales etrangeres ("loi de blocage") · Loi n° 68-678; decret n° 2022-207 du 18 fevrier 2022 · Act of parliament
This is France's answer to foreign court demands and foreign regulators. Handing business documents to a foreign authority is a crime if you skip the official cooperation channels. Since 2022 there is a single government desk you are expected to consult first.
Enforced by Strategic Information and Economic Security Service
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Do not hand data to foreign authorities on demandA request from a foreign court or authority must go through official mutual assistance channels. Since 2022 the SISSE at the finance ministry is the single desk. You must consult it. It answers within one month.
What it costs if you get it wrong
- Criminal liabilityCommunicating covered economic, commercial, industrial, financial or technical documents to a foreign authority outside the official channels
Sources
- Official sourceMinistere de l'Economie, Direction generale des EntreprisesLa loi de blocage - Direction generale des Entreprises
entreprises.gouv.fr
“La loi dite " de blocage " de 1968 permet d'eviter que les autorites etrangeres n'aient connaissance d'informations sensibles attentant aux interets de la Nation.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseDecret n° 2022-207 du 18 fevrier 2022 relatif a la communication de documents et renseignements a des personnes etrangeres
legifrance.gouv.fr
Link checked 18 August 2026
Cyber security rules
Official name: Projet de loi relatif a la resilience des infrastructures critiques et au renforcement de la cybersecurite · PRMD2412608L - transposes NIS2, DORA and the critical entities resilience directive · Draft law
France has not yet turned Europe's cybersecurity directive, NIS2, into French law. The bill passed the Senate on 12 March 2025. A National Assembly special committee reported on it on 10 September 2025. We found no evidence that it was promulgated. The cyber agency says the rules start only once the law and every decree have been published. So nothing binds today.
Enforced by National Cybersecurity Agency of France
How this country controls where data goes: No restriction
What you have to do
- Report cyber incidents — within 24 hoursPROPOSED ONLY. A 24-hour early warning to ANSSI is expected once the law and its decrees are in force. Not binding today.
- Register or notifyPROPOSED ONLY. Covered organisations would register themselves through the MonEspaceNIS2 portal.
Sources
- Official sourceAgence nationale de la securite des systemes d'informationAvancement de la transposition de la directive NIS 2
aide.monespacenis2.cyber.gouv.fr
“NIS 2 rentrera donc en vigueur en France des lors que l'ensemble des textes de transposition (loi, decrets, arretes) auront ete promulgues.”
Link checked 18 August 2026
- Official sourceAssemblee nationaleDossier legislatif - projet de loi resilience des infrastructures critiques et renforcement de la cybersecurite
assemblee-nationale.fr
Link checked 18 August 2026
Applies across the European Union2 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Reglement general sur la protection des donnees (RGPD) - Reglement (UE) 2016/679 · Regulation (EU) 2016/679 · Directly binding regulation
This is the European baseline. France applies it without adding a national storage rule. It controls the conditions for sending data out of Europe. It does not say where you must store data. The list of approved destinations is long, and standard contracts cover the rest.
Enforced by National Commission for Data Protection and Liberties
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of how you use data
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a representativeYou need this if you have no office in the European Union. It does not have to be in France.
- Put a transfer safeguard in placeYou also need a written transfer risk assessment. This follows the Schrems II judgment.
- Do not hand data to foreign authorities on demandAn order from a non-European authority is not on its own a legal reason to hand data over. This comes from European Data Protection Board Guidelines 02/2024.
- Delete data after a period
- Get a parent's consent for children — applies at: under 15 in France
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $11 millionController and processor obligations
- Order to stopThe CNIL can order processing to stop or suspend flows to a third country - usually worse commercially than the fine
- Claims by individualsIndividuals can claim compensation; French group actions are available
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions - list of approved destinations
commission.europa.eu
Link checked 18 August 2026
Cloud and outsourcing rules (2027)
Official name: Reglement sur les donnees (Data Act) - Reglement (UE) 2023/2854 · Regulation (EU) 2023/2854 · Directly binding regulation
This is not about where data sits. It is about being able to move it. From 12 January 2027 cloud providers must charge nothing for switching or for getting your data out. That is a firm commercial deadline and it touches every French cloud contract.
That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by Electronic Communications, Postal and Print Media Distribution Regulatory Authority
How this country controls where data goes: No restriction
What you have to do
- Make switching cloud provider possible — from 12 January 2027All cloud switching charges and data export fees must be zero from 12 January 2027.
- Do not hand data to foreign authorities on demandCloud providers must take technical, organisational and legal steps against access by a non-European government. This covers non-personal data held in Europe. It applies where such access would conflict with EU law.
Sources
- Official sourceEuropean CommissionData Act explained
digital-strategy.ec.europa.eu
Link checked 18 August 2026
On the books, but not enforceable1 rule
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
Internet and platform rules
Official name: LOI n° 2023-566 du 7 juillet 2023 visant a instaurer une majorite numerique et a lutter contre la haine en ligne · Loi n° 2023-566 · Act of parliament
This law is printed in the French statute book and cannot be enforced. It would have set a social media age of 15, with parental consent below that age. No commencement decree was ever issued. The European Commission objected that France adopted it without the required notification, and that it conflicts with the country-of-origin rule. In May 2025 the government told Parliament the law could not proceed. Reading the statute alone would wrongly suggest it is binding.
Enforced by Audiovisual and Digital Communication Regulatory Authority
How this country controls where data goes: No restriction
What you have to do
- Get a parent's consent for children — applies at: under 15NOT ENFORCEABLE. No commencement decree was ever published. The government has said the law cannot proceed.
Sources
- Official sourceAssemblee nationaleQuestion ecrite n° 5149 - Decrets d'application, majorite numerique a 15 ans, with the government's answer of 6 May 2025
assemblee-nationale.fr
“La loi n° 2023-566 du 7 juillet 2023 ... n'a, pour sa part, pas pu prosperer en raison de frottements avec le droit de l'Union europeenne.”
Link checked 18 August 2026
- Official sourceLegifranceLOI n° 2023-566 du 7 juillet 2023 (text as published)
legifrance.gouv.fr
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact commencement date of the second phase of decret n° 2026-209 (health data hosting)
We could not confirm the exact start date. The decree says paragraphs 2 and 3 of article 1 take effect six months after the rest. The rest started the day after publication in the Journal officiel of 26 March 2026. We work that out as 27 September 2026, but no official source states it. Plan for the earlier date.
Whether the NIS2 transposition law (projet de loi resilience) has been definitively adopted or promulgated between September 2025 and 18 August 2026
We could not confirm that this bill has become law. The Assemblee nationale and Senat records stop at the special committee report of 10 September 2025. ANSSI still describes the French law as pending. Trade press reported a vote in the National Assembly, but no parliamentary or Journal officiel source confirms it. Treat it as still a bill.
The content and commencement of the law protecting minors on social media adopted by the Assemblee nationale on 21 July 2026
We could not confirm what this law actually requires. The National Assembly confirms it was finally adopted, but does not set out the details. We did not find the promulgated text in the Journal officiel. So we list it under what's coming, not as a rule.
The current version number of the ANSSI SecNumCloud reference standard and the number of qualified providers
We could not confirm the standard's version number or how many providers hold it. The requirement itself is confirmed by the decree and by the finance ministry's own notice. If those details matter to you, check with ANSSI.
Whether the Conseil d'Etat's refusal to suspend the hosting of the EMC2 health data warehouse by a United States provider remains the operative position after decret n° 2026-209
We could not confirm this decision against the court's own site, so we relied on secondary reports. It matters because it shows the French rule tests where data is stored, not the supplier's nationality.
That no French localisation rule exists for banking, payments, insurance, securities, education, mapping or geospatial data
We found no such rule on 18 August 2026. Europe's DORA law and the French banking secrecy exception both point the same way. But finding nothing is not proof that nothing exists. Confidence medium. If you work in finance, check before you rely on it.
Whether decret n° 2025-980 will be renewed before it expires on 21 October 2026
We cannot confirm this will be renewed. It has been renewed every year since 2021. But renewal is the Prime Minister's choice, so do not assume it.
Automated link-checking of legifrance.gouv.fr sources
We could not check links to Legifrance automatically, because it blocks automated requests. Those links open normally in a browser. Sources we opened ourselves are marked verified. Sources cited from a search result or a neighbouring article are marked not-checked.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.