Skip to the content
Global Data RulesData governance rules, country by country

France

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Aggressive

France follows the European rule: data may leave, but only once the right paperwork is in place. France then adds hard walls of its own. Health records must be stored inside Europe. Online gambling records must sit on a machine in mainland France. From 1 September 2026 the invoicing platform every French business must use has to run entirely from inside Europe.

Eight questions about France

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do France's rules apply to my company?

Yes. France reaches a company with no office in the country. European law already applies to anyone offering goods or services to people in Europe. On top of that, France's own privacy law says its national rules apply as soon as the person concerned lives in France, even when the company is based somewhere else. There is no size or revenue threshold that lets you escape.

High confidenceNational rulesAppoint a local representative

Can I store my users' data outside France?

For an ordinary business, yes, with paperwork: the European transfer rules apply and nothing extra is added. But four French sectors override that. Health records must be stored inside Europe and nowhere else. Online gambling records must be archived in real time on hardware in mainland France. Electronic invoicing platforms must run their whole system from inside Europe. And sensitive state data must sit on a cloud that the French cyber agency has certified as beyond the reach of foreign authorities.

High confidenceDepends on your industryAllowlist

What do I need in place before data leaves France?

The model is an approved-list one, run from Brussels rather than Paris. Data may go to a country the European Commission has formally approved, or anywhere else if you sign the official standard contract and write down why you think the data will still be safe. The list of approved countries is full, not empty: it includes the United Kingdom, Japan, South Korea, Canada, Switzerland, Brazil and about a dozen others, plus American companies that have signed up to the transatlantic framework. France adds no separate national approval step.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesCertification schemeApproved code of conductExplicit consentNeeded for a contractLegal claims

Who enforces the rules in France, and what can they do?

The privacy regulator is the CNIL, and it is one of the busiest in Europe. In 2025 alone it issued 83 penalties totalling about 487 million euros (roughly 530 million dollars), plus 143 formal warnings. It is still fining in 2026: 5 million euros against the national employment agency in January and 5 million against a health data company in May. Separate regulators run the sector walls, and all of them are staffed and working.

High confidenceAggressive

How long do I have to keep the data?

There is a floor and a ceiling and they pull in opposite directions. You must keep accounting books and supporting documents for ten years, tax records for six, employment contracts and pay records for five, and telephone and internet subscriber identity data for five. In the other direction, European law says you must delete personal data once you no longer need it. France resolves the clash the same way most of Europe does: the legal minimum wins, but only for the specific documents the law names, and only for as long as it names.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

Count the clocks, because France has at least four and they run at different speeds. Every organisation has 72 hours to tell the CNIL about a personal data breach. Telephone and internet providers have only 24 hours. Hospitals and clinics must report a serious computer security incident to their regional health agency immediately. Banks, insurers and investment firms have their own European deadlines: an initial report within 4 hours of classifying a major incident and no later than 24 hours after they notice it.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in France?

Five things that are not in the summary. (1) Breaking the privacy law in France is a crime, not just a fine: sending data out of Europe unlawfully carries up to five years in prison and a 300,000 euro fine (about 330,000 dollars), and it attaches to people, not only companies. (2) A child is anyone under 15 for consent, not 13 or 16. (3) A 2023 law setting a social media age of 15 is printed in the statute book but has never come into force and cannot be enforced. (4) Handing documents to a foreign court or regulator can itself be a criminal offence in France. (5) Cookies are policed separately from the rest of privacy law, so a foreign company cannot hide behind its lead European regulator.

High confidenceCriminal liabilityGet a parent's consent for childrenUnenforceableDo not hand data to foreign authorities on demand

What is changing soon in France?

Four dates in the next twelve months. 1 September 2026: every French business must be able to send and receive invoices through an approved platform, and those platforms must run entirely from inside Europe. Around 27 September 2026: the second phase of the health data hosting decree starts. 21 October 2026: the order forcing telephone and internet companies to keep everyone's connection records for a year expires unless the Prime Minister renews it. 12 January 2027: cloud providers across Europe must drop switching and data export fees to zero.

Medium confidenceProposedMake switching cloud provider possible

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    2 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    5 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    5 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules2 rules

Reglement general sur la protection des donnees (RGPD) - Reglement (UE) 2016/679

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European baseline, applied in France without a national residency add-on. It controls the conditions under which data leaves Europe, not where data is stored. The list of approved destinations is full, and standard contracts cover the rest.

In force since 25 May 2018

Enforced by National Commission for Data Protection and Liberties

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Reglement sur les donnees (Data Act) - Reglement (UE) 2023/2854

Directly binding regulation · Regulation (EU) 2023/2854

In forceYes — store it anywhere

Not about where data sits but about being able to move it. From 12 January 2027 cloud providers must charge nothing for switching or for getting your data out. This is a hard commercial deadline that touches every French cloud contract.

In force since 12 September 2025But only enforceable from 12 January 2027

Enforced by Electronic Communications, Postal and Print Media Distribution Regulatory Authority

Transfer model: No restriction

High confidence

National rules5 rules

Loi n° 78-17 du 6 janvier 1978 relative a l'informatique, aux fichiers et aux libertes

Act of parliament · Loi n° 78-17, as amended by ordonnance n° 2018-1125 and later texts

In forceYes, with paperwork

France's own privacy law. It adds three things to the European baseline: it reaches companies with no French establishment whenever the person lives in France, it sets the child consent age at 15, and it makes serious breaches a criminal matter with prison exposure for individuals.

In force since 25 May 2018

Enforced by National Commission for Data Protection and Liberties

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Articles L102 B et L102 C du Livre des procedures fiscales; article L123-22 du Code de commerce

Act of parliament · LPF articles L102 B and L102 C; Code de commerce article L123-22

In forceYes, with paperwork

The quiet localisation rule that applies to every business, not just regulated ones. Electronic invoices may only be stored in France, elsewhere in Europe, or in a country that has a tax mutual assistance treaty with France or gives French inspectors immediate online access. You also have to tell the tax authority where they are kept.

In force since 1 January 2013

Enforced by Public Finances Directorate General

Transfer model: Allowlist · Accepted routes: Government sign-off needed, Nothing required

High confidence

LOI n° 2023-566 du 7 juillet 2023 visant a instaurer une majorite numerique et a lutter contre la haine en ligne

Act of parliament · Loi n° 2023-566 · Social media and online platforms

UnenforceableYes — store it anywhere

A law that is printed in the French statute book and cannot be enforced. It would have set a social media age of 15 with parental consent below it. No commencement decree was ever issued, the European Commission objected that it was adopted without the required notification and conflicts with the country-of-origin rule, and in May 2025 the government told Parliament the law could not proceed. Anyone reading the statute alone would wrongly report it as binding.

Enforced by Audiovisual and Digital Communication Regulatory Authority

Transfer model: No restriction

High confidence

Industry rules5 rules

Decret n° 2026-209 du 24 mars 2026 portant modification de certaines dispositions du code de la sante publique relatives a l'hebergement de donnees de sante a caractere personnel

Directly binding regulation · Decret n° 2026-209, JORF n° 73 du 26 mars 2026; articles R. 1111-9-1 et suivants du code de la sante publique; referentiel de certification HDS approuve par arrete du 26 avril 2024 · Health and social care

Partly in forceNo — it stays put

France's real localisation wall. Personal health data must be stored only inside the European Economic Area, by a certified host, and the contract must name every foreign law that could force disclosure. Since March 2026 this sits in a decree, not only in a certification standard, so it now binds hospitals and software vendors as well as the data centre.

In force since 27 March 2026But only enforceable from 27 September 2026

Enforced by Digital Health Agency

Transfer model: Not allowed · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

High confidence

Decret n° 2026-272 du 14 avril 2026 relatif a la protection des donnees d'une sensibilite particuliere des administrations, operateurs et groupements d'interet public de l'Etat traitees par un service d'informatique en nuage fourni par un prestataire prive

Directly binding regulation · Decret n° 2026-272, taken under article 31 of loi n° 2024-449 du 21 mai 2024 (loi SREN); doctrine "cloud au centre", circulaire n° 6404/SG du 31 mai 2023 · Government

In forceNo — it stays put

If you sell cloud to the French State, this is the rule that decides whether you can bid. Particularly sensitive data held by State administrations, listed State operators and six named public interest groupings may only go on a cloud service certified as immune from foreign government access. Derogations run 12 to 18 months and are published with reasons.

In force since 17 April 2026

Enforced by National Cybersecurity Agency of France

Transfer model: Not allowed · Accepted routes: Certification scheme

High confidence

Immatriculation des plateformes agreees (ex plateformes de dematerialisation partenaires) - facturation electronique

Government rules · Articles 242 nonies B a 242 nonies I du code general des impots, annexe II; conditions d'immatriculation publiees par la DGFiP

Partly in forceNo — it stays put

The sector wall almost nobody has priced in. From 1 September 2026 every French business must send and receive invoices through an approved platform, and every approved platform must run its whole system inside the European Union with outward transfers made impossible. Choosing a platform is therefore a data residency decision, not a procurement detail.

In force since 1 January 2024But only enforceable from 1 September 2026

Enforced by Public Finances Directorate General

Transfer model: Not allowed

High confidence

Who you would hear from

  • Commission nationale de l'informatique et des libertes (CNIL)

    General privacy law, cookies and trackers, breach notification

    Fully staffed and among the most active regulators in Europe. 259 corrective decisions in 2025, of which 83 sanctions totalling EUR 486,839,500 (about USD 530m), plus 143 formal notices. Still fining in 2026: EUR 5m against France Travail on 22 January 2026 and EUR 5m against IQVIA Operations France on 26 May 2026, and 23 further simplified-procedure sanctions announced on 6 July 2026.

  • Agence nationale de la securite des systemes d'information (ANSSI)

    Cybersecurity, the SecNumCloud qualification, the future NIS2 supervisor

    Operational. Owns the SecNumCloud reference standard that decides who may host sensitive French State data, and published the Referentiel Cyber France on 17 March 2026 ahead of the NIS2 law. It is not yet supervising NIS2 entities because the transposition law has not been promulgated.

  • Agence du numerique en sante (ANS)

    Health data hosting certification (HDS), health sector cyber incident response (CERT Sante)

  • Autorite nationale des jeux (ANJ)

    Online gambling and betting licences, technical requirements including the French archiving vault

  • Direction generale des Finances publiques (DGFiP)

    Electronic invoicing platform registration, tax record retention and storage location

  • Autorite de controle prudentiel et de resolution (ACPR)

    Banking, payments and insurance supervision, including outsourcing and DORA

  • Autorite des marches financiers (AMF)

    Securities and markets

  • Autorite de regulation des communications electroniques, des postes et de la distribution de la presse (ARCEP)

    Telecoms operators; designated for parts of the European Data Act

  • Autorite de regulation de la communication audiovisuelle et numerique (ARCOM)

    Online platforms, age verification, minors online

  • Service de l'information strategique et de la securite economiques (SISSE)

    Single desk for the blocking statute on foreign requests for business documents

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact commencement date of the second phase of decret n° 2026-209 (health data hosting)

    The decree says the provisions in paragraphs 2 and 3 of article 1 take effect six months after the rest, which entered into force the day after publication in the Journal officiel of 26 March 2026. We compute 27 September 2026 but have not seen an official statement of that date. Plan to the earlier date.

  • Whether the NIS2 transposition law (projet de loi resilience) has been definitively adopted or promulgated between September 2025 and 18 August 2026

    The Assemblee nationale and Senat dossiers we could open both stop at the special committee report of 10 September 2025, and ANSSI's own status page still describes transposition as pending. Trade press reported an Assembly vote, but we could not corroborate it on a parliamentary or Journal officiel source. Treated as still a bill.

  • The content and commencement of the law protecting minors on social media adopted by the Assemblee nationale on 21 July 2026

    The Assembly's own news page confirms definitive adoption but does not set out the operative provisions, and we did not locate the promulgated text in the Journal officiel. It is therefore listed under what's coming, not as a rule.

  • The current version number of the ANSSI SecNumCloud reference standard and the number of qualified providers

    The ANSSI qualified-products pages we tried returned errors. The obligation itself is confirmed from the decree and from the finance ministry's own notice; only the version number and provider count are unverified.

  • Whether the Conseil d'Etat's refusal to suspend the hosting of the EMC2 health data warehouse by a United States provider remains the operative position after decret n° 2026-209

    We could not open the decision on the court's own site and relied on secondary reports. The point matters because it shows that European storage, not supplier nationality, is what the French rule actually tests.

  • That no French localisation rule exists for banking, payments, insurance, securities, education, mapping or geospatial data

    This is a negative. We searched on 18 August 2026 and found none, and DORA plus the banking secrecy outsourcing exception point the same way, but absence of a finding is not proof of absence. Confidence medium.

  • Whether decret n° 2025-980 will be renewed before it expires on 21 October 2026

    It has been renewed annually since 2021, but renewal is a discretionary act of the Prime Minister and cannot be assumed.

  • Automated link-checking of legifrance.gouv.fr sources

    Legifrance returns HTTP 403 to automated requests, so its links cannot be machine-verified even when they open normally in a browser. Sources we opened during research are marked verified; those cited from a search result or a neighbouring article are marked not-checked rather than being presented as verified.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.