France
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
France follows the European rule: data may leave, but only once the right paperwork is in place. France then adds hard walls of its own. Health records must be stored inside Europe. Online gambling records must sit on a machine in mainland France. From 1 September 2026 the invoicing platform every French business must use has to run entirely from inside Europe.
Eight questions about France
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do France's rules apply to my company?
Yes. France reaches a company with no office in the country. European law already applies to anyone offering goods or services to people in Europe. On top of that, France's own privacy law says its national rules apply as soon as the person concerned lives in France, even when the company is based somewhere else. There is no size or revenue threshold that lets you escape.
Article 3.II of loi n° 78-17 du 6 janvier 1978 (loi Informatique et Libertes): the French national rules apply as soon as the data subject resides in France, including where the controller is not established in France. This matters most for cookies and similar tracking technologies, which sit under Article 82 of the same law (the ePrivacy regime) and are outside the GDPR one-stop-shop. That is how the CNIL fined foreign-headquartered platforms directly rather than routing the case through an Irish or Luxembourg lead authority, and the Conseil d'Etat upheld that approach. A representative in the European Union is required where a company has no EU establishment (GDPR Article 27); it does not have to be in France.
Sources
- Official sourceLegifrance / Secretariat general du GouvernementLoi n° 78-17 du 6 janvier 1978 relative a l'informatique, aux fichiers et aux libertes, article 3 (territorial scope)
legifrance.gouv.fr
“les regles nationales ... s'appliquent des lors que la personne concernee reside en France, y compris lorsque le responsable de traitement n'est pas etabli en France”
Link checked 18 August 2026
- Official sourceCommission nationale de l'informatique et des libertesSanctions et mesures correctrices : la CNIL presente le bilan 2025
cnil.fr
Link checked 18 August 2026
Can I store my users' data outside France?
For an ordinary business, yes, with paperwork: the European transfer rules apply and nothing extra is added. But four French sectors override that. Health records must be stored inside Europe and nowhere else. Online gambling records must be archived in real time on hardware in mainland France. Electronic invoicing platforms must run their whole system from inside Europe. And sensitive state data must sit on a cloud that the French cyber agency has certified as beyond the reach of foreign authorities.
Sector-by-sector rating for France, checked 18 August 2026. HEALTH - data must stay in the country at the European border. Decret n° 2026-209 of 24 March 2026 writes into the public health code that storage of personal health data is carried out exclusively on the territory of a Member State. The HDS certification standard already said the same (requirement EXI 28: storage exclusively within the European Economic Area). Remote access from outside is possible only on an adequacy decision or Article 46 safeguards, and the host must list every non-European law that could force it to hand data over. ONLINE GAMBLING - mirror Article 31 of loi n° 2010-476 of 12 May 2010 requires licensed operators to archive gambling and betting data in real time on physical hardware located in metropolitan France. The rest of the platform may live abroad; the archive vault may not. ELECTRONIC INVOICING - data must stay in the country at the European border, from 1 September 2026. To be registered as a plateforme agreee (formerly plateforme de dematerialisation partenaire) an operator must undertake to run its information system from the territory of an EU Member State and to make transfer of hosted data outside the EU impossible. GOVERNMENT AND PUBLIC SECTOR - closed Decret n° 2026-272 of 14 April 2026, applying article 31 of the loi SREN, requires State administrations, listed State operators and six named public interest groupings to place particularly sensitive data only on cloud services meeting an ANSSI security standard covering data location and protection against access by the public authorities of a third State. TAX AND ACCOUNTING RECORDS - data can leave once conditions are met but with a real geographic limit. Article L102 C of the Livre des procedures fiscales allows electronic invoice storage in another EU Member State, or in a country bound to France by a mutual assistance convention or granting immediate online access to the tax authority - and nowhere else. The storage location must be declared with the annual return. BANKING, PAYMENTS, INSURANCE, SECURITIES - no French localisation rule found, checked 18 August 2026, confidence medium-high. DORA is the operative regime for financial entities and imposes disclosure of processing location, audit rights and exit plans but no localisation. French banking secrecy (article L511-33 of the Code monetaire et financier) expressly permits disclosure to a third party under a contract entrusting important operational functions, so unlike Germany it is not a cloud blocker. TELECOMS - no localisation rule found. The French rules are about retention, not location. MAPPING AND GEOSPATIAL, EDUCATION, DEFENCE - no general civil localisation rule found, checked 18 August 2026, confidence medium. Defence and classified material sit under separate national security rules outside the scope of this record.
Sources
- Official sourceJournal officiel de la Republique francaiseDecret n° 2026-209 du 24 mars 2026 portant modification de certaines dispositions du code de la sante publique relatives a l'hebergement de donnees de sante a caractere personnel
legifrance.gouv.fr
“le stockage de ces donnees, il est mis en oeuvre exclusivement sur le territoire d'un Etat membre”
Link checked 18 August 2026
- Official sourceLegifranceLOI n° 2010-476 du 12 mai 2010 relative a l'ouverture a la concurrence et a la regulation du secteur des jeux d'argent et de hasard en ligne, article 31
legifrance.gouv.fr
“est tenu de proceder a l'archivage en temps reel, sur un support materiel situe en France metropolitaine”
Link checked 18 August 2026
- Official sourceLegifranceArticle L102 C du Livre des procedures fiscales (where invoices may be stored)
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseDecret n° 2026-272 du 14 avril 2026 relatif a la protection des donnees d'une sensibilite particuliere des administrations, operateurs et groupements d'interet public de l'Etat
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceLegifranceArticle L511-33 du Code monetaire et financier (banking secrecy and outsourcing exception)
legifrance.gouv.fr
Link checked 18 August 2026
What do I need in place before data leaves France?
The model is an approved-list one, run from Brussels rather than Paris. Data may go to a country the European Commission has formally approved, or anywhere else if you sign the official standard contract and write down why you think the data will still be safe. The list of approved countries is full, not empty: it includes the United Kingdom, Japan, South Korea, Canada, Switzerland, Brazil and about a dozen others, plus American companies that have signed up to the transatlantic framework. France adds no separate national approval step.
France applies the European mechanisms unchanged: adequacy decisions, the 2021 standard contractual clauses, binding corporate rules, certification, codes of conduct and the narrow Article 49 derogations. A transfer impact assessment is expected after the Schrems II judgment. Two French-specific points sit on top. First, an unlawful transfer outside the European Union is a criminal offence in France under article 226-22-1 of the Code penal, punishable by five years' imprisonment and a fine of EUR 300,000 (about USD 330,000) - not merely an administrative fine. Second, health, gambling, e-invoicing and sensitive-state-data rules are geographic bans; no transfer mechanism cures them, because the objection is to the location itself and not to the level of protection. The EU-US Data Privacy Framework remains valid on 18 August 2026 but is under appeal at the Court of Justice and the European Data Protection Board formally asked the Commission on 31 July 2026 to re-examine it; do not build a single-mechanism architecture on it.
Sources
- Official sourceEuropean CommissionAdequacy decisions - the populated list of approved destinations
commission.europa.eu
Link checked 18 August 2026
- Official sourceLegifranceArticle 226-22-1 du Code penal - criminal offence of unlawful transfer outside the European Union
legifrance.gouv.fr
“Le fait de proceder ou de faire proceder a un transfert de donnees a caractere personnel ... vers un Etat n'appartenant pas a l'Union europeenne ... en violation du chapitre V du reglement (UE) 2016/679”
Link checked 18 August 2026
- Official sourceCommission nationale de l'informatique et des libertesTransferer des donnees hors de l'Union europeenne - the CNIL's own guidance page
cnil.fr
Link checked 18 August 2026
Who enforces the rules in France, and what can they do?
The privacy regulator is the CNIL, and it is one of the busiest in Europe. In 2025 alone it issued 83 penalties totalling about 487 million euros (roughly 530 million dollars), plus 143 formal warnings. It is still fining in 2026: 5 million euros against the national employment agency in January and 5 million against a health data company in May. Separate regulators run the sector walls, and all of them are staffed and working.
CNIL 2025 figures, from its own published review: 259 corrective decisions, of which 83 sanctions (16 by the ordinary procedure, 67 by the simplified procedure), 143 mises en demeure, 31 reminders and 2 warnings; total fines EUR 486,839,500. Twenty-one of the sanctions concerned cookies and trackers, including one fine of EUR 325 million and one of EUR 150 million. Sixteen concerned employee video surveillance and fourteen concerned poor security. Twenty-seven fines carried injunctions backed by daily penalty payments. That pattern - cookies, workplace surveillance, weak passwords - is the single best predictor of where a French inspection will go. Rating: aggressive. The regulator does not wait for complaints; it runs annual thematic inspection priorities and uses the simplified procedure to produce volume. Other operational authorities: ANSSI (cyber, and it owns the SecNumCloud qualification), the Agence du numerique en sante (health data hosting certification), the ANJ (online gambling), the DGFiP (electronic invoicing platform registration), ACPR and AMF (finance), ARCEP (telecoms) and the SISSE at the finance ministry (the blocking statute single desk).
Sources
- Official sourceCommission nationale de l'informatique et des libertesSanctions et mesures correctrices : la CNIL presente le bilan 2025 (published 9 February 2026)
cnil.fr
“83 sanctions ... 486 839 500 euros”
Link checked 18 August 2026
- Official sourceCommission nationale de l'informatique et des libertesCNIL sanctions index - showing EUR 5m against France Travail (22 January 2026) and EUR 5m against IQVIA Operations France (26 May 2026)
cnil.fr
Link checked 18 August 2026
How long do I have to keep the data?
There is a floor and a ceiling and they pull in opposite directions. You must keep accounting books and supporting documents for ten years, tax records for six, employment contracts and pay records for five, and telephone and internet subscriber identity data for five. In the other direction, European law says you must delete personal data once you no longer need it. France resolves the clash the same way most of Europe does: the legal minimum wins, but only for the specific documents the law names, and only for as long as it names.
FLOORS. Accounting books, ledgers and supporting documents: 10 years from the close of the financial year (Code de commerce, article L123-22). Tax books, registers and documents: 6 years from the last entry (Livre des procedures fiscales, article L102 B), extended to 10 in fraud cases. Commercial contracts and business correspondence: 5 years. Employment contracts and payroll: 5 years; social contribution records 3 years; time-recording records 1 year. Property transaction deeds: 30 years. Telecoms: civil identity data 5 years from the end of the contract; subscription and payment information 1 year; technical connection data 1 year (Code des postes et des communications electroniques, article L34-1). On top of that a Prime Minister's decree of 15 October 2025 ordered general retention of traffic and location data for one year on national security grounds - it expires on 21 October 2026 unless renewed, and it has been renewed every year since 2021. CEILING. GDPR storage limitation. The CNIL enforces it: several 2025 sanctions concerned keeping customer or prospect records indefinitely. Where invoices are stored electronically outside France, article L102 C of the Livre des procedures fiscales also constrains WHERE they may sit, not just how long. CONFLICT RULE. A statutory minimum retention period is a legal obligation under GDPR Article 6(1)(c) and beats a deletion request; the practical answer is to move the record into a restricted archive rather than keep it in the live system.
Sources
- Official sourceDirection de l'information legale et administrativeCombien de temps une entreprise doit-elle conserver ses documents ? - official retention table
entreprendre.service-public.gouv.fr
Link checked 18 August 2026
- Official sourceLegifranceArticle L34-1 du Code des postes et des communications electroniques - telecoms retention periods
legifrance.gouv.fr
“les informations relatives a l'identite civile de l'utilisateur, jusqu'a l'expiration d'un delai de cinq ans”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseDecret n° 2025-980 du 15 octobre 2025 portant injonction de conservation pour une duree d'un an de certaines categories de donnees de connexion
legifrance.gouv.fr
Link checked 18 August 2026
What happens if there is a breach?
Count the clocks, because France has at least four and they run at different speeds. Every organisation has 72 hours to tell the CNIL about a personal data breach. Telephone and internet providers have only 24 hours. Hospitals and clinics must report a serious computer security incident to their regional health agency immediately. Banks, insurers and investment firms have their own European deadlines: an initial report within 4 hours of classifying a major incident and no later than 24 hours after they notice it.
Clock 1 - GDPR Article 33: 72 hours to the CNIL, plus notification to affected individuals without undue delay where the risk to them is high. Clock 2 - the paquet telecom regime: providers of electronic communications services to the public, declared with ARCEP, must notify the CNIL within 24 hours of establishing the breach, with a supplementary notification within a further 72 hours if the investigation is incomplete. This is a separate register and a separate form, and it applies in addition to the 72-hour rule, not instead of it. Clock 3 - health: articles D1111-16-2 to D1111-16-4 of the Code de la sante publique, made by decret n° 2016-1214 of 12 September 2016, require health establishments, medico-social establishments and laboratories to report serious information system security incidents without delay to the regional health agency, which routes them to the CERT Sante. Clock 4 - DORA, for financial entities: initial notification within 4 hours of classifying an incident as major and within 24 hours of becoming aware of it, then an intermediate and a final report. A fifth clock will appear when the NIS2 transposition law passes: a 24-hour early warning to ANSSI. The most common operational failure is a telecoms or health organisation running only the 72-hour GDPR process and missing the shorter sector clock entirely.
Sources
- Official sourceCommission nationale de l'informatique et des libertesNotification "Paquet telecom" - the 24-hour clock for electronic communications providers
cnil.fr
“La notification doit etre transmise a la CNIL dans les 24 h de la constatation de la violation”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseDecret n° 2016-1214 du 12 septembre 2016 relatif aux conditions selon lesquelles sont signales les incidents graves de securite des systemes d'information
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceLegifranceArticles D1111-16-2 a D1111-16-4 du Code de la sante publique - categories of reportable incidents
legifrance.gouv.fr
Link checked 18 August 2026
What trips people up in France?
Five things that are not in the summary. (1) Breaking the privacy law in France is a crime, not just a fine: sending data out of Europe unlawfully carries up to five years in prison and a 300,000 euro fine (about 330,000 dollars), and it attaches to people, not only companies. (2) A child is anyone under 15 for consent, not 13 or 16. (3) A 2023 law setting a social media age of 15 is printed in the statute book but has never come into force and cannot be enforced. (4) Handing documents to a foreign court or regulator can itself be a criminal offence in France. (5) Cookies are policed separately from the rest of privacy law, so a foreign company cannot hide behind its lead European regulator.
TRAP 1 - criminal liability. Articles 226-16 to 226-24 of the Code penal make most serious data protection failures punishable by 5 years' imprisonment and EUR 300,000 (about USD 330,000), including unlawful transfer outside the EU (226-22-1). Obstructing the CNIL is separately punishable by 1 year and EUR 15,000 (about USD 16,000). This is a real difference from most of Europe, where the risk is administrative only. TRAP 2 - age 15. Article 45 of loi n° 78-17 sets the digital consent age at 15. Below that, a parent must consent jointly with the child. Products built to 13 (United States) or 16 (Germany) are wrong in France. TRAP 3 - a law that looks binding and is not. Loi n° 2023-566 of 7 July 2023 created a social media "majorite numerique" at 15 and duties on platforms. It has never entered into force: no application decree was ever published, and the government told Parliament in May 2025 that the law "n'a pas pu prosperer en raison de frottements avec le droit de l'Union europeenne". The European Commission wrote on 14 August 2023 that the text was adopted without the notification procedure required by Directive 2015/1535, which makes it inapplicable, and that it conflicted with the Digital Services Act and the country-of-origin principle. A naive text search reports this as French law in force. It is not enforceable. A replacement bill was definitively adopted on 21 July 2026 - see what's coming. TRAP 4 - the blocking statute. Loi n° 68-678 of 26 July 1968 makes it an offence to communicate economic, commercial, industrial, financial or technical documents to a foreign authority outside the official mutual assistance channels. Decret n° 2022-207 of 18 February 2022 created a single desk at the finance ministry, the SISSE, which must be consulted. American discovery requests and foreign regulatory demands are the usual trigger. TRAP 5 - cookies are outside the one-stop-shop. They fall under Article 82 of loi n° 78-17, the French implementation of the ePrivacy directive, so the CNIL acts directly against foreign companies without going through a lead authority. Cookies were the largest single category of French fines in 2025, including one of EUR 325 million. BONUS - unlike Germany, French banking secrecy is not a cloud blocker: article L511-33 of the Code monetaire et financier expressly allows disclosure to a supplier under a contract entrusting important operational functions.
Sources
- Official sourceLegifranceCode penal, articles 226-16 a 226-24 - criminal offences relating to personal data files
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceCommission nationale de l'informatique et des libertesCNIL recommendation 4 - parental consent for minors under 15 (article 45 of loi 78-17)
cnil.fr
Link checked 18 August 2026
- Official sourceAssemblee nationaleQuestion ecrite n° 5149 and government answer of 6 May 2025 - the majorite numerique law never entered into force
assemblee-nationale.fr
“La loi n° 2023-566 du 7 juillet 2023 ... n'a, pour sa part, pas pu prosperer en raison de frottements avec le droit de l'Union europeenne.”
Link checked 18 August 2026
- Official sourceMinistere de l'Economie, Direction generale des EntreprisesLa loi de blocage - Direction generale des Entreprises
entreprises.gouv.fr
Link checked 18 August 2026
What is changing soon in France?
Four dates in the next twelve months. 1 September 2026: every French business must be able to send and receive invoices through an approved platform, and those platforms must run entirely from inside Europe. Around 27 September 2026: the second phase of the health data hosting decree starts. 21 October 2026: the order forcing telephone and internet companies to keep everyone's connection records for a year expires unless the Prime Minister renews it. 12 January 2027: cloud providers across Europe must drop switching and data export fees to zero.
CONFIRMED DATES. 1 September 2026 - electronic invoicing becomes compulsory. Businesses must use a plateforme agreee to send and receive. Registration conditions require the platform operator to run its information system from an EU Member State and to prevent any transfer of hosted data outside the EU. Around 27 September 2026 - paragraphs 2 and 3 of article 1 of decret n° 2026-209 take effect, six months after the rest. 21 October 2026 - decret n° 2025-980 expires. It has been renewed annually since 2021 and renewal is likely, but it is a decision, not an automatic rollover. 12 January 2027 - Data Act: all cloud switching charges and data egress fees must be zero. STILL A BILL, DO NOT PLAN AS BINDING. The projet de loi relatif a la resilience des infrastructures critiques et au renforcement de la cybersecurite, which transposes NIS2, DORA and the critical entities directive, was adopted by the Senate on 12 March 2025 and reported by the National Assembly special committee on 10 September 2025. ANSSI's own guidance states that NIS2 will enter into force in France only once the law, decrees and orders have all been promulgated. As of 18 August 2026 we found no evidence of promulgation. A new law protecting minors on social media was definitively adopted by the National Assembly on 21 July 2026 following a joint committee; its content and commencement decrees were not verifiable on an official source at the date of this record. DORMANT SWITCHES - things the government can flip with no consultation. (1) The annual connection-data retention injunction: one Prime Minister's decree turns general retention on or off. (2) The ANSSI SecNumCloud reference standard: it is approved by Prime Minister's order, so the requirements for sensitive state cloud can be tightened without primary legislation. (3) The scope decree under article 31 of the loi SREN: the list of State operators and public interest groupings caught by the SecNumCloud obligation is set by decree and can be extended. (4) The health hosting decree's transfer conditions bite on contracts, so a change in the European adequacy picture - the EU-US Data Privacy Framework is under appeal at the Court of Justice - immediately changes what a French hospital's supplier may do.
Sources
- Official sourceDirection generale des Finances publiquesFacturation electronique et plateformes agreees - 1 September 2026 start date
impots.gouv.fr
“Les entreprises assujetties devront en effet recourir aux services d'une plateforme agreee pour transmettre et recevoir leurs factures electroniques ... a compter du 1er septembre 2026”
Link checked 18 August 2026
- Official sourceAgence nationale de la securite des systemes d'informationAvancement de la transposition de la directive NIS 2 - ANSSI's own status page
aide.monespacenis2.cyber.gouv.fr
“NIS 2 rentrera donc en vigueur en France des lors que l'ensemble des textes de transposition (loi, decrets, arretes) auront ete promulgues.”
Link checked 18 August 2026
- Official sourceAssemblee nationaleProteger les mineurs des risques auxquels les expose l'utilisation des reseaux sociaux - definitive adoption 21 July 2026
assemblee-nationale.fr
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseDecret n° 2025-980 du 15 octobre 2025 - one-year retention injunction, expires 21 October 2026
legifrance.gouv.fr
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
2 rules here
Layer 2
National rules
Added by this country on top of any bloc rules.
5 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
5 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules2 rules
Reglement general sur la protection des donnees (RGPD) - Reglement (UE) 2016/679
Directly binding regulation · Regulation (EU) 2016/679
The European baseline, applied in France without a national residency add-on. It controls the conditions under which data leaves Europe, not where data is stored. The list of approved destinations is full, and standard contracts cover the rest.
Enforced by National Commission for Data Protection and Liberties
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of processing
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a local representativeRequired where there is no establishment in the European Union. It does not have to be in France.
- Put a transfer safeguard in placePlus a documented transfer impact assessment after the Schrems II judgment.
- Do not hand data to foreign authorities on demandA third-country authority's order is not by itself a lawful basis to disclose (EDPB Guidelines 02/2024).
- Delete data after a period
- Get a parent's consent for children — applies at: under 15 in France
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $11 millionController and processor obligations
- Order to stopThe CNIL can order processing to stop or suspend flows to a third country - usually worse commercially than the fine
- Claims by individualsIndividuals can claim compensation; French group actions are available
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions - list of approved destinations
commission.europa.eu
Link checked 18 August 2026
Reglement sur les donnees (Data Act) - Reglement (UE) 2023/2854
Directly binding regulation · Regulation (EU) 2023/2854
Not about where data sits but about being able to move it. From 12 January 2027 cloud providers must charge nothing for switching or for getting your data out. This is a hard commercial deadline that touches every French cloud contract.
Enforced by Electronic Communications, Postal and Print Media Distribution Regulatory Authority
Transfer model: No restriction
What it makes you do
- Make switching cloud provider possible — from 12 January 2027All cloud switching charges and data egress fees must be zero from 12 January 2027.
- Do not hand data to foreign authorities on demandCloud providers must take technical, organisational and legal measures against third-country government access to non-personal data held in Europe where that would conflict with EU law.
Sources
- Official sourceEuropean CommissionData Act explained
digital-strategy.ec.europa.eu
Link checked 18 August 2026
National rules5 rules
Loi n° 78-17 du 6 janvier 1978 relative a l'informatique, aux fichiers et aux libertes
Act of parliament · Loi n° 78-17, as amended by ordonnance n° 2018-1125 and later texts
France's own privacy law. It adds three things to the European baseline: it reaches companies with no French establishment whenever the person lives in France, it sets the child consent age at 15, and it makes serious breaches a criminal matter with prison exposure for individuals.
Enforced by National Commission for Data Protection and Liberties
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Get a parent's consent for children — applies at: under 15Article 45. A parent must consent jointly with the child. Not 13, not 16.
- Get consentArticle 82 covers cookies and similar trackers. This sits outside the GDPR one-stop-shop, so the CNIL acts directly against foreign companies.
- Appoint a data protection officer
- Secure the data
- Put a transfer safeguard in place
What it costs if you get it wrong
- Criminal liability: 5 years' imprisonment and €300,000 — about $330 thousandMost serious data protection offences under Code penal articles 226-16 to 226-24, including transferring data outside the European Union in breach of Chapter V of the GDPR (article 226-22-1)
- Criminal liability: 1 year's imprisonment and €15,000 — about $16 thousandObstructing the CNIL's work (Code penal article 226-22-2)
- Percentage of global turnover: Up to 4% of worldwide group turnover or €20,000,000 — about $22 millionAdministrative fines by the CNIL under the GDPR
- Daily fine until fixedInjunctions backed by daily penalty payments - used in 27 of the CNIL's 2025 fines
Sources
- Official sourceLegifranceLoi n° 78-17 du 6 janvier 1978 (consolidated text), articles 3, 45 and 82
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceLegifranceCode penal, articles 226-16 a 226-24
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceCNILCNIL 2025 enforcement review - 83 sanctions, EUR 486,839,500
cnil.fr
Link checked 18 August 2026
Articles L102 B et L102 C du Livre des procedures fiscales; article L123-22 du Code de commerce
Act of parliament · LPF articles L102 B and L102 C; Code de commerce article L123-22
The quiet localisation rule that applies to every business, not just regulated ones. Electronic invoices may only be stored in France, elsewhere in Europe, or in a country that has a tax mutual assistance treaty with France or gives French inspectors immediate online access. You also have to tell the tax authority where they are kept.
Enforced by Public Finances Directorate General
Transfer model: Allowlist · Accepted routes: Government sign-off needed, Nothing required
What it makes you do
- Keep data for a minimum period — 10 yearsAccounting books, ledgers and supporting documents: 10 years from the close of the financial year (Code de commerce L123-22).
- Keep data for a minimum period — 6 yearsTax books, registers, documents and records: 6 years from the last entry (LPF L102 B); 10 years where fraud is established.
- Keep the data in the countryElectronically stored invoices may sit in France, in another EU Member State, or in a country bound to France by a mutual assistance convention or granting the tax authority an immediate online right of access - and nowhere else.
- Keep records of processingThe storage location must be declared with the annual results return, and any change of location outside France must be declared too.
What it costs if you get it wrong
- Fixed maximum fineTax penalties for failure to produce records; rejection of accounts on audit
Sources
- Official sourceLegifranceArticle L102 C du Livre des procedures fiscales
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceLegifranceArticle L102 B du Livre des procedures fiscales - six-year retention
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceDirection de l'information legale et administrativeCombien de temps une entreprise doit-elle conserver ses documents ?
entreprendre.service-public.gouv.fr
Link checked 18 August 2026
LOI n° 2023-566 du 7 juillet 2023 visant a instaurer une majorite numerique et a lutter contre la haine en ligne
Act of parliament · Loi n° 2023-566 · Social media and online platforms
A law that is printed in the French statute book and cannot be enforced. It would have set a social media age of 15 with parental consent below it. No commencement decree was ever issued, the European Commission objected that it was adopted without the required notification and conflicts with the country-of-origin rule, and in May 2025 the government told Parliament the law could not proceed. Anyone reading the statute alone would wrongly report it as binding.
Enforced by Audiovisual and Digital Communication Regulatory Authority
Transfer model: No restriction
What it makes you do
- Get a parent's consent for children — applies at: under 15NOT ENFORCEABLE. No commencement decree was ever published and the government has said the law cannot proceed.
Sources
- Official sourceAssemblee nationaleQuestion ecrite n° 5149 - Decrets d'application, majorite numerique a 15 ans, with the government's answer of 6 May 2025
assemblee-nationale.fr
“La loi n° 2023-566 du 7 juillet 2023 ... n'a, pour sa part, pas pu prosperer en raison de frottements avec le droit de l'Union europeenne.”
Link checked 18 August 2026
- Official sourceLegifranceLOI n° 2023-566 du 7 juillet 2023 (text as published)
legifrance.gouv.fr
Link checked 18 August 2026
Loi n° 68-678 du 26 juillet 1968 relative a la communication de documents et renseignements d'ordre economique, commercial, industriel, financier ou technique a des personnes physiques ou morales etrangeres ("loi de blocage")
Act of parliament · Loi n° 68-678; decret n° 2022-207 du 18 fevrier 2022
France's counter-measure to foreign discovery and foreign regulators. Handing over business documents to a foreign authority outside the official cooperation channels is a criminal offence, and since 2022 there is a single government desk you are expected to consult first.
Enforced by Strategic Information and Economic Security Service
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Do not hand data to foreign authorities on demandA request from a foreign court or authority must go through official mutual assistance channels. Since 2022 the SISSE at the finance ministry is the single desk and must be consulted; it answers within one month.
What it costs if you get it wrong
- Criminal liabilityCommunicating covered economic, commercial, industrial, financial or technical documents to a foreign authority outside the official channels
Sources
- Official sourceMinistere de l'Economie, Direction generale des EntreprisesLa loi de blocage - Direction generale des Entreprises
entreprises.gouv.fr
“La loi dite " de blocage " de 1968 permet d'eviter que les autorites etrangeres n'aient connaissance d'informations sensibles attentant aux interets de la Nation.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseDecret n° 2022-207 du 18 fevrier 2022 relatif a la communication de documents et renseignements a des personnes etrangeres
legifrance.gouv.fr
Link checked 18 August 2026
Projet de loi relatif a la resilience des infrastructures critiques et au renforcement de la cybersecurite
Draft law · PRMD2412608L - transposes NIS2, DORA and the critical entities resilience directive
France has not yet transposed the European cybersecurity directive NIS2. The bill passed the Senate on 12 March 2025 and was reported by a National Assembly special committee on 10 September 2025, but we found no evidence of promulgation. The cyber agency says the rules start only when the law and every decree have been published, so nothing binds today.
Enforced by National Cybersecurity Agency of France
Transfer model: No restriction
What it makes you do
- Report cyber incidents — within 24 hoursPROPOSED ONLY. A 24-hour early warning to ANSSI is expected once the law and its decrees are in force. Not binding today.
- Register or notifyPROPOSED ONLY. Self-registration of in-scope entities through the MonEspaceNIS2 portal.
Sources
- Official sourceAgence nationale de la securite des systemes d'informationAvancement de la transposition de la directive NIS 2
aide.monespacenis2.cyber.gouv.fr
“NIS 2 rentrera donc en vigueur en France des lors que l'ensemble des textes de transposition (loi, decrets, arretes) auront ete promulgues.”
Link checked 18 August 2026
- Official sourceAssemblee nationaleDossier legislatif - projet de loi resilience des infrastructures critiques et renforcement de la cybersecurite
assemblee-nationale.fr
Link checked 18 August 2026
Industry rules5 rules
Decret n° 2026-209 du 24 mars 2026 portant modification de certaines dispositions du code de la sante publique relatives a l'hebergement de donnees de sante a caractere personnel
Directly binding regulation · Decret n° 2026-209, JORF n° 73 du 26 mars 2026; articles R. 1111-9-1 et suivants du code de la sante publique; referentiel de certification HDS approuve par arrete du 26 avril 2024 · Health and social care
France's real localisation wall. Personal health data must be stored only inside the European Economic Area, by a certified host, and the contract must name every foreign law that could force disclosure. Since March 2026 this sits in a decree, not only in a certification standard, so it now binds hospitals and software vendors as well as the data centre.
Enforced by Digital Health Agency
Transfer model: Not allowed · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Keep the data in the countryStorage of personal health data must be carried out exclusively on the territory of a Member State. The certification standard says the same: storage exclusively within the European Economic Area (requirement EXI 28).
- Hold a security certificateThe host must hold HDS certification (hebergeur de donnees de sante) under the standard approved by the arrete of 26 April 2024.
- Put a transfer safeguard in placeAny transfer, including remote access from outside the European Economic Area, needs an adequacy decision or Article 46 safeguards, and the individuals concerned must have enforceable rights and effective remedies.
- Do not hand data to foreign authorities on demandThe hosting contract must list every non-European regulation that could compel the host to transfer or disclose the data, the measures taken to mitigate that risk, and the residual risk.
- Written vendor contract
What it costs if you get it wrong
- Criminal liability: Hosting personal health data without certification is an offence under the code de la sante publiqueUncertified hosting
- Order to stopThe CNIL can order processing to stop; a health authority can terminate the hosting arrangement
Sources
- Official sourceJournal officiel de la Republique francaiseDecret n° 2026-209 du 24 mars 2026 relatif a l'hebergement de donnees de sante a caractere personnel
legifrance.gouv.fr
“le stockage de ces donnees, il est mis en oeuvre exclusivement sur le territoire d'un Etat membre”
Link checked 18 August 2026
- Official sourceAgence du numerique en santeReferentiel de certification Hebergeur de donnees de sante - exigences EXI 28, EXI 29 and EXI 30
esante.gouv.fr
“l'Hebergeur ou ses sous-traitants doivent stocker ces DSCP exclusivement au sein de l'Espace Economique Europeen (EEE)”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseArrete du 26 avril 2024 approuvant le referentiel de certification pour l'hebergement de donnees de sante a caractere personnel
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceCNIL / Journal officielDeliberation CNIL n° 2025-098 du 16 octobre 2025 portant avis sur le projet de decret
legifrance.gouv.fr
Link checked 18 August 2026
Decret n° 2026-272 du 14 avril 2026 relatif a la protection des donnees d'une sensibilite particuliere des administrations, operateurs et groupements d'interet public de l'Etat traitees par un service d'informatique en nuage fourni par un prestataire prive
Directly binding regulation · Decret n° 2026-272, taken under article 31 of loi n° 2024-449 du 21 mai 2024 (loi SREN); doctrine "cloud au centre", circulaire n° 6404/SG du 31 mai 2023 · Government
If you sell cloud to the French State, this is the rule that decides whether you can bid. Particularly sensitive data held by State administrations, listed State operators and six named public interest groupings may only go on a cloud service certified as immune from foreign government access. Derogations run 12 to 18 months and are published with reasons.
Enforced by National Cybersecurity Agency of France
Transfer model: Not allowed · Accepted routes: Certification scheme
What it makes you do
- Prove the data stays under local controlThe cloud service must meet an ANSSI security reference standard covering data location and protection against any access by the public authorities of a third State.
- Hold a security certificateSecNumCloud qualification by ANSSI, or an equivalent certification issued in the European Union or European Economic Area.
- Keep the data in the countryData location is one of the domains the ANSSI standard governs.
- Register or notifyWhere no compliant service exists, a derogation must be requested through the supervising minister; the Prime Minister decides within two months and the reasoned decision is published.
What it costs if you get it wrong
- Order to stopA non-compliant cloud arrangement cannot lawfully be used for the data concerned; the practical sanction is loss of the public contract
Sources
- Official sourceJournal officiel de la Republique francaiseDecret n° 2026-272 du 14 avril 2026
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceMinistere de l'Economie, Direction des affaires juridiquesPublication du decret d'application de l'article 31 de la loi SREN
economie.gouv.fr
“protection contre tout acces par des autorites publiques d'un Etat tiers”
Link checked 18 August 2026
- Official sourceDirection interministerielle du numeriqueLa doctrine de l'Etat - "cloud au centre"
numerique.gouv.fr
Link checked 18 August 2026
- Official sourcePremier ministre / LegifranceCirculaire n° 6404/SG du 31 mai 2023 - actualisation de la doctrine "cloud au centre"
legifrance.gouv.fr
Link checked 18 August 2026
Immatriculation des plateformes agreees (ex plateformes de dematerialisation partenaires) - facturation electronique
Government rules · Articles 242 nonies B a 242 nonies I du code general des impots, annexe II; conditions d'immatriculation publiees par la DGFiP
The sector wall almost nobody has priced in. From 1 September 2026 every French business must send and receive invoices through an approved platform, and every approved platform must run its whole system inside the European Union with outward transfers made impossible. Choosing a platform is therefore a data residency decision, not a procurement detail.
Enforced by Public Finances Directorate General
Transfer model: Not allowed
What it makes you do
- Keep the data in the country — from 1 September 2026The platform operator must undertake to operate its information system from the territory of an EU Member State and to ensure that no transfer of hosted data outside the European Union is possible.
- Register or notifyRegistration with the DGFiP is compulsory; the register of approved platforms is published as open data.
- Hold a security certificateApplicants using a SecNumCloud-qualified host are excused from itemising server locations, because that qualification already establishes EU compliance.
- Written vendor contract
What it costs if you get it wrong
- Loss of your licenceLoss or refusal of registration means the platform cannot lawfully transmit invoices in France
Sources
- Official sourceDirection generale des Finances publiquesGuide utilisateur - demande d'immatriculation des plateformes agreees (lettre d'engagement)
impots.gouv.fr
“vous vous engagez a exploiter votre systeme d'information depuis le territoire d'un Etat membre de l'Union europeenne”
Link checked 18 August 2026
- Official sourceDirection generale des Finances publiquesFacturation electronique et plateformes agreees
impots.gouv.fr
Link checked 18 August 2026
- Official sourceDGFiP via data.gouv.frListe des plateformes agreees pour la facturation electronique (official register)
data.gouv.fr
Link checked 18 August 2026
Article 31 de la loi n° 2010-476 du 12 mai 2010 relative a l'ouverture a la concurrence et a la regulation du secteur des jeux d'argent et de hasard en ligne
Act of parliament · Loi n° 2010-476, article 31; ANJ exigences techniques ET1 v1.0 du 23 novembre 2023 · Online gaming
A true mirror rule and one of the oldest localisation requirements in Europe. A licensed online gambling operator can run its business anywhere, but a copy of every bet and every game event must be written in real time to a machine physically in mainland France, where the regulator can seize it.
Enforced by National Gambling Authority
Transfer model: No restriction
What it makes you do
- Keep the data in the countryReal-time archiving of gambling and betting events on physical hardware located in metropolitan France. The ANJ technical requirements call this the coffre-fort and confirm it must be hosted in metropolitan France.
- Keep logsArchived game traces are held encrypted and must be producible to the regulator.
- Independent auditSix-month certification of the frontal component and an annual certification thereafter.
- Register or notifyOnly licensed (agree) operators may take bets from France.
What it costs if you get it wrong
- Loss of your licenceFailure to comply with the technical requirements attached to the licence
Sources
- Official sourceLegifranceLOI n° 2010-476 du 12 mai 2010, article 31
legifrance.gouv.fr
“est tenu de proceder a l'archivage en temps reel, sur un support materiel situe en France metropolitaine”
Link checked 18 August 2026
- Official sourceAutorite nationale des jeuxExigences techniques relatives au systeme d'information des operateurs de jeu (ET1 v1.0, 23 November 2023)
ressources.anj.fr
“la localisation physique du coffre-fort (celui-ci devant etre heberge en France metropolitaine conformement a l'article 31 de la loi n°2010-476 du 12 mai 2010)”
Link checked 18 August 2026
Article L34-1 du Code des postes et des communications electroniques, complete par le decret n° 2025-980 du 15 octobre 2025
Act of parliament · CPCE article L34-1 and article R. 10-13; decret n° 2025-980 du 15 octobre 2025 · Telecoms
France does not require telecoms data to be stored in France, but it does require it to be kept - identity data for five years, connection data for one. General retention of everyone's traffic and location records rests on a Prime Minister's order renewed every year, so this regime can switch off, or back on, without a debate.
Enforced by Electronic Communications, Postal and Print Media Distribution Regulatory Authority
Transfer model: No restriction
What it makes you do
- Keep data for a minimum period — 5 yearsCivil identity data of the user: 5 years from the end of the contract.
- Keep data for a minimum period — 1 yearOther subscription information and payment data: 1 year. Technical connection data (source of connection, terminal equipment): 1 year.
- Keep logs — 1 yearTraffic and location data: general retention for one year, ordered by decret n° 2025-980 on national security grounds. That order expires on 21 October 2026 unless renewed.
- Report breaches to the regulator — within 24 hoursProviders of electronic communications services to the public notify the CNIL within 24 hours, not 72.
What it costs if you get it wrong
- Criminal liabilityFailure to retain or produce data as required by the code
- Fixed maximum fineARCEP sanctions for breach of licence and code obligations
Sources
- Official sourceLegifranceArticle L34-1 du Code des postes et des communications electroniques
legifrance.gouv.fr
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique francaiseDecret n° 2025-980 du 15 octobre 2025 portant injonction de conservation d'un an
legifrance.gouv.fr
“Il est enjoint aux operateurs de communications electroniques ... de conserver, pour une duree d'un an, les donnees de trafic et de localisation”
Link checked 18 August 2026
- Official sourceCNILNotification "Paquet telecom" - 24-hour breach notification
cnil.fr
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact commencement date of the second phase of decret n° 2026-209 (health data hosting)
The decree says the provisions in paragraphs 2 and 3 of article 1 take effect six months after the rest, which entered into force the day after publication in the Journal officiel of 26 March 2026. We compute 27 September 2026 but have not seen an official statement of that date. Plan to the earlier date.
Whether the NIS2 transposition law (projet de loi resilience) has been definitively adopted or promulgated between September 2025 and 18 August 2026
The Assemblee nationale and Senat dossiers we could open both stop at the special committee report of 10 September 2025, and ANSSI's own status page still describes transposition as pending. Trade press reported an Assembly vote, but we could not corroborate it on a parliamentary or Journal officiel source. Treated as still a bill.
The content and commencement of the law protecting minors on social media adopted by the Assemblee nationale on 21 July 2026
The Assembly's own news page confirms definitive adoption but does not set out the operative provisions, and we did not locate the promulgated text in the Journal officiel. It is therefore listed under what's coming, not as a rule.
The current version number of the ANSSI SecNumCloud reference standard and the number of qualified providers
The ANSSI qualified-products pages we tried returned errors. The obligation itself is confirmed from the decree and from the finance ministry's own notice; only the version number and provider count are unverified.
Whether the Conseil d'Etat's refusal to suspend the hosting of the EMC2 health data warehouse by a United States provider remains the operative position after decret n° 2026-209
We could not open the decision on the court's own site and relied on secondary reports. The point matters because it shows that European storage, not supplier nationality, is what the French rule actually tests.
That no French localisation rule exists for banking, payments, insurance, securities, education, mapping or geospatial data
This is a negative. We searched on 18 August 2026 and found none, and DORA plus the banking secrecy outsourcing exception point the same way, but absence of a finding is not proof of absence. Confidence medium.
Whether decret n° 2025-980 will be renewed before it expires on 21 October 2026
It has been renewed annually since 2021, but renewal is a discretionary act of the Prime Minister and cannot be assumed.
Automated link-checking of legifrance.gouv.fr sources
Legifrance returns HTTP 403 to automated requests, so its links cannot be machine-verified even when they open normally in a browser. Sources we opened during research are marked verified; those cited from a search result or a neighbouring article are marked not-checked rather than being presented as verified.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.