Skip to the content
Global Data RulesData governance rules, country by country

France

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in France — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Aggressive

Most data can leave France. You just need the right paperwork first, the same as anywhere in Europe. France then adds strict rules of its own. Health records must be stored inside Europe. Online gambling records must sit on a machine in mainland France. From 1 September 2026, the invoicing platform every French business must use has to run entirely from inside Europe.

Data governance in France

The eight things that decide how you handle data about people in France. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. French rules apply even if you have no office in France. European law already covers anyone offering goods or services to people in Europe. France's own privacy law goes further. Its national rules apply as soon as the person concerned lives in France. That holds even if your company is based somewhere else. There is no size or revenue limit that lets you escape.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes for an ordinary business, as long as you do the paperwork. The European transfer rules apply and France adds nothing extra. But four French industries override that. Health records must be stored inside Europe and nowhere else. Online gambling records must be copied in real time onto hardware in mainland France. Electronic invoicing platforms must run their whole system from inside Europe. Sensitive state data must sit on a cloud that France's cyber agency has certified as beyond the reach of foreign authorities.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

You can only send data to countries Europe has approved, or use approved paperwork. Brussels decides this, not Paris. Data may go to a country the European Commission has formally approved. Or it may go anywhere else if you sign Europe's official standard contract. With that contract you must also write down why you think the data will still be safe. The approved list is long. It includes the United Kingdom, Japan, South Korea, Canada, Switzerland, Brazil and about a dozen others. It also covers American companies signed up to the transatlantic Data Privacy Framework. France adds no separate national approval step.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

France's privacy regulator is the CNIL. It is one of the busiest in Europe. In 2025 alone it issued 83 penalties totalling about 487 million euros (roughly 530 million US dollars). It also issued 143 formal warnings. It is still fining in 2026. In January it fined the national employment agency 5 million euros. In May it fined a health data company 5 million euros. Separate regulators run the industry rules. All of them are staffed and working.

How long you must keep it — and when to delete it

You face minimum keeping times and a maximum, and they pull in opposite directions. You must keep accounting books and supporting documents for ten years. Tax records must be kept for six years. Employment contracts and pay records must be kept for five years. Phone and internet subscriber identity data must be kept for five years. In the other direction, European law says you must delete personal data once you no longer need it. France solves the clash the way most of Europe does. The legal minimum wins. But it only wins for the exact documents the law names, and only for as long as it says.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

France has at least four breach deadlines and they run at different speeds. Every organisation has 72 hours to tell the CNIL about a personal data breach. Phone and internet providers have only 24 hours. Hospitals and clinics must report a serious computer security incident to their regional health agency immediately. Banks, insurers and investment firms follow their own European deadlines. They must send a first report within 4 hours of classifying an incident as major. That must happen no later than 24 hours after they notice it.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things the summary does not tell you. (1) Breaking the privacy law in France is a crime, not just a fine. Sending data out of Europe unlawfully carries up to five years in prison and a 300,000 euro fine (about 330,000 US dollars). It attaches to people, not only companies. (2) A child is anyone under 15 for consent. Not 13, not 16. (3) A 2023 law setting a social media age of 15 is printed in the statute book. It never came into force and cannot be enforced. (4) Handing documents to a foreign court or regulator can itself be a crime in France. (5) Cookies are policed separately from the rest of privacy law. A foreign company cannot hide behind its lead European regulator.

What you have to do here:
Get a parent's consent for children · Do not hand data to foreign authorities on demand
What it costs if you get it wrong:
Criminal liability

What's changing next

Four dates in the next twelve months. 1 September 2026: every French business must be able to send and receive invoices through an approved platform. Those platforms must run entirely from inside Europe. Around 27 September 2026: the second phase of the health data hosting decree starts. 21 October 2026: the order forcing phone and internet companies to keep everyone's connection records for a year expires. It ends unless the Prime Minister renews it. 12 January 2027: cloud providers across Europe must drop switching and data export fees to zero.

What you have to do here:
Make switching cloud provider possible

What to do: Diarise 21 October 2026 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Health and social care

Health and social care data must stay in the country

Official name: Decret n° 2026-209 du 24 mars 2026 portant modification de certaines dispositions du code de la sante publique relatives a l'hebergement de donnees de sante a caractere personnel · Decret n° 2026-209, JORF n° 73 du 26 mars 2026; articles R. 1111-9-1 et suivants du code de la sante publique; referentiel de certification HDS approuve par arrete du 26 avril 2024 · Directly binding regulation

Partly in forceNo — it stays put

This is France's real hard rule on where data sits. Personal health data must be stored only inside the European Economic Area, by a certified host. The contract must name every foreign law that could force disclosure. Since March 2026 this sits in a decree, not only in a certification standard. So it now binds hospitals and software vendors as well as the data centre.

In force since 27 March 2026Enforced from 27 September 2026

Enforced by Digital Health Agency

How this country controls where data goes: Not allowed · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Government

Cloud and outsourcing rules

Official name: Decret n° 2026-272 du 14 avril 2026 relatif a la protection des donnees d'une sensibilite particuliere des administrations, operateurs et groupements d'interet public de l'Etat traitees par un service d'informatique en nuage fourni par un prestataire prive · Decret n° 2026-272, taken under article 31 of loi n° 2024-449 du 21 mai 2024 (loi SREN); doctrine "cloud au centre", circulaire n° 6404/SG du 31 mai 2023 · Directly binding regulation

In forceNo — it stays put

If you sell cloud services to the French State, this rule decides whether you can bid. State administrations, listed State bodies and six named public interest groupings hold particularly sensitive data. That data may only go on a cloud service certified as safe from foreign government access. Exemptions run 12 to 18 months and are published with reasons.

In force since 17 April 2026

Enforced by National Cybersecurity Agency of France

How this country controls where data goes: Not allowed · Accepted routes: Certification scheme

Personal data must stay in the country

Official name: Immatriculation des plateformes agreees (ex plateformes de dematerialisation partenaires) - facturation electronique · Articles 242 nonies B a 242 nonies I du code general des impots, annexe II; conditions d'immatriculation publiees par la DGFiP · Government rules

Partly in forceNo — it stays put

Almost nobody has planned for this one. From 1 September 2026 every French business must send and receive invoices through an approved platform. Every approved platform must run its whole system inside the European Union, with outward transfers made impossible. So choosing a platform decides where your data lives. It is not just a purchasing detail.

In force since 1 January 2024Enforced from 1 September 2026

Enforced by Public Finances Directorate General

How this country controls where data goes: Not allowed

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Loi n° 78-17 du 6 janvier 1978 relative a l'informatique, aux fichiers et aux libertes · Loi n° 78-17, as amended by ordonnance n° 2018-1125 and later texts · Act of parliament

In forceYes, with paperwork

This is France's own privacy law. It adds three things to the European baseline. It reaches companies with no French office whenever the person lives in France. It sets the child consent age at 15. And it makes serious breaches a crime, with prison possible for individuals.

In force since 25 May 2018

Enforced by National Commission for Data Protection and Liberties

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Personal data must stay in the country (2013)

Official name: Articles L102 B et L102 C du Livre des procedures fiscales; article L123-22 du Code de commerce · LPF articles L102 B and L102 C; Code de commerce article L123-22 · Act of parliament

In forceYes, with paperwork

This quiet rule applies to every business, not just regulated ones. You may only store electronic invoices in France, elsewhere in Europe, or in a country that has a tax mutual assistance treaty with France. A country that gives French inspectors immediate online access is also allowed. You must also tell the tax authority where you keep them.

In force since 1 January 2013

Enforced by Public Finances Directorate General

How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed, Nothing required

Government data rules

Official name: Loi n° 68-678 du 26 juillet 1968 relative a la communication de documents et renseignements d'ordre economique, commercial, industriel, financier ou technique a des personnes physiques ou morales etrangeres ("loi de blocage") · Loi n° 68-678; decret n° 2022-207 du 18 fevrier 2022 · Act of parliament

In forceYes, with paperwork

This is France's answer to foreign court demands and foreign regulators. Handing business documents to a foreign authority is a crime if you skip the official cooperation channels. Since 2022 there is a single government desk you are expected to consult first.

In force since 27 July 1968Enforced from 1 April 2022

Enforced by Strategic Information and Economic Security Service

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Applies across the European Union2 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Reglement general sur la protection des donnees (RGPD) - Reglement (UE) 2016/679 · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

This is the European baseline. France applies it without adding a national storage rule. It controls the conditions for sending data out of Europe. It does not say where you must store data. The list of approved destinations is long, and standard contracts cover the rest.

In force since 25 May 2018

Enforced by National Commission for Data Protection and Liberties

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Cloud and outsourcing rules (2027)

Official name: Reglement sur les donnees (Data Act) - Reglement (UE) 2023/2854 · Regulation (EU) 2023/2854 · Directly binding regulation

In forceYes — store it anywhere

This is not about where data sits. It is about being able to move it. From 12 January 2027 cloud providers must charge nothing for switching or for getting your data out. That is a firm commercial deadline and it touches every French cloud contract.

In force since 12 September 2025In force now, but not enforced until 12 January 2027

That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by Electronic Communications, Postal and Print Media Distribution Regulatory Authority

How this country controls where data goes: No restriction

On the books, but not enforceable1 rule

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

Social media and online platforms

Internet and platform rules

Official name: LOI n° 2023-566 du 7 juillet 2023 visant a instaurer une majorite numerique et a lutter contre la haine en ligne · Loi n° 2023-566 · Act of parliament

UnenforceableYes — store it anywhere

This law is printed in the French statute book and cannot be enforced. It would have set a social media age of 15, with parental consent below that age. No commencement decree was ever issued. The European Commission objected that France adopted it without the required notification, and that it conflicts with the country-of-origin rule. In May 2025 the government told Parliament the law could not proceed. Reading the statute alone would wrongly suggest it is binding.

Enforced by Audiovisual and Digital Communication Regulatory Authority

How this country controls where data goes: No restriction

Who you would hear from

  • Commission nationale de l'informatique et des libertes (CNIL)

    General privacy law, cookies and trackers, breach notification

    Fully staffed and among the most active regulators in Europe. It made 259 corrective decisions in 2025. Of those, 83 were penalties totalling 486,839,500 euros (about 530 million US dollars). It also issued 143 formal notices. It is still fining in 2026. It fined France Travail 5 million euros on 22 January 2026. It fined IQVIA Operations France 5 million euros on 26 May 2026. It announced 23 more simplified-procedure penalties on 6 July 2026.

  • Agence nationale de la securite des systemes d'information (ANSSI)

    Cybersecurity, the SecNumCloud qualification, the future NIS2 supervisor

    Working. It owns the SecNumCloud standard, which decides who may host sensitive French State data. It published the Referentiel Cyber France on 17 March 2026, ahead of the NIS2 law. It does not yet supervise NIS2 organisations, because the French law bringing NIS2 in has not been promulgated.

  • Agence du numerique en sante (ANS)

    Health data hosting certification (HDS), health sector cyber incident response (CERT Sante)

  • Autorite nationale des jeux (ANJ)

    Online gambling and betting licences, technical requirements including the French archiving vault

  • Direction generale des Finances publiques (DGFiP)

    Electronic invoicing platform registration, tax record retention and storage location

  • Autorite de controle prudentiel et de resolution (ACPR)

    Banking, payments and insurance supervision, including outsourcing and DORA

  • Autorite des marches financiers (AMF)

    Securities and markets

  • Autorite de regulation des communications electroniques, des postes et de la distribution de la presse (ARCEP)

    Telecoms operators; designated for parts of the European Data Act

  • Autorite de regulation de la communication audiovisuelle et numerique (ARCOM)

    Online platforms, age verification, minors online

  • Service de l'information strategique et de la securite economiques (SISSE)

    Single desk for the blocking statute on foreign requests for business documents

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact commencement date of the second phase of decret n° 2026-209 (health data hosting)

    We could not confirm the exact start date. The decree says paragraphs 2 and 3 of article 1 take effect six months after the rest. The rest started the day after publication in the Journal officiel of 26 March 2026. We work that out as 27 September 2026, but no official source states it. Plan for the earlier date.

  • Whether the NIS2 transposition law (projet de loi resilience) has been definitively adopted or promulgated between September 2025 and 18 August 2026

    We could not confirm that this bill has become law. The Assemblee nationale and Senat records stop at the special committee report of 10 September 2025. ANSSI still describes the French law as pending. Trade press reported a vote in the National Assembly, but no parliamentary or Journal officiel source confirms it. Treat it as still a bill.

  • The content and commencement of the law protecting minors on social media adopted by the Assemblee nationale on 21 July 2026

    We could not confirm what this law actually requires. The National Assembly confirms it was finally adopted, but does not set out the details. We did not find the promulgated text in the Journal officiel. So we list it under what's coming, not as a rule.

  • The current version number of the ANSSI SecNumCloud reference standard and the number of qualified providers

    We could not confirm the standard's version number or how many providers hold it. The requirement itself is confirmed by the decree and by the finance ministry's own notice. If those details matter to you, check with ANSSI.

  • Whether the Conseil d'Etat's refusal to suspend the hosting of the EMC2 health data warehouse by a United States provider remains the operative position after decret n° 2026-209

    We could not confirm this decision against the court's own site, so we relied on secondary reports. It matters because it shows the French rule tests where data is stored, not the supplier's nationality.

  • That no French localisation rule exists for banking, payments, insurance, securities, education, mapping or geospatial data

    We found no such rule on 18 August 2026. Europe's DORA law and the French banking secrecy exception both point the same way. But finding nothing is not proof that nothing exists. Confidence medium. If you work in finance, check before you rely on it.

  • Whether decret n° 2025-980 will be renewed before it expires on 21 October 2026

    We cannot confirm this will be renewed. It has been renewed every year since 2021. But renewal is the Prime Minister's choice, so do not assume it.

  • Automated link-checking of legifrance.gouv.fr sources

    We could not check links to Legifrance automatically, because it blocks automated requests. Those links open normally in a browser. Sources we opened ourselves are marked verified. Sources cited from a search result or a neighbouring article are marked not-checked.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.