CNIL (France)

From GDPRhub
Commission nationale de l'informatique et des libertés
Name: Commission nationale de l'informatique et des libertés
Abbreviation : CNIL
Jurisdiction: France
Head: Marie-Laure Denis
Secretary general: Louis Dutheillet de Lamothe
Adress: 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07
Fax: +33 1 53 73 22 00
Phone: +33 1 53 73 22 22
Twitter: @CNIL and @CNIL_en
Procedural Law: n/a
Decision Database: Legifrance
Translated Decisions: Category:CNIL (France)
Head Count: 245[1]
Budget: 21,507,033 € in 2021[2]

The CNIL is the Data Protection Authority for France. The authority is established in Paris and is in charge of enforcing GDPR for France, as well as the national law for data protection "Loi Informatique et Libertés".

Structure[edit | edit source]

The CNIL was established in 1978 with the law "Informatique et Libertés". It is an independent administrative authority led by a college of 18 members and a contract staff team. Twelve out of eighteen members are elected or designated by the national authorities and courts to which they belong (i.e. Senate, National Parliament, Economic and Social Committee, Supreme Civil and Administrative Courts, Court of Auditors and the Commission of Access to Administrative Documents). The CNIL's president can freely recruit its other staff.

The CNIL issues orders and imposes fines within a restricted formation, meaning one president and five others elected members, pursuant to Article 9 of the Law "Informatique et Libertés". The CNIL's internal rules indicate that, unless otherwise justified, the pronunciation of fines is public.

Anyone can ask for the agenda of the hearing and attend. You can find the CNIL's public agenda here.

The composition, nomination and the organisational structure is laid down by Articles 9 to 18 of the Law "Informatique et Libertés". You can find the organizational chart here.

Procedural Information[edit | edit source]

In April 2022, the CNIL announced a simplified procedure for less complex cases, to better face the growing number of complaints and focus more on significant cases. The simplified sanction procedure follows the same stages as the ordinary procedure (for deadlines, adversarial procedure, etc.), but its implementation methods are reduced.

Applicable Procedural Law[edit | edit source]

The CNIL operates under the law "Informatique et Libertés" under the conditions laid down by Articles 19 to 29. See the law here, in French. The law "informatique et Libertés" has to be read jointly with the Decree n° 2019-536 of May 29.

Complaints Procedure under Art 77 GDPR[edit | edit source]

According to Article 8(I)(2)(d) of the loi "Informatique et Liberté", a data subject or their representative(s) can lodge a complaint with the CNIL regarding an alleged infringement of the GDPR.

According to Article 10 of the Decree n°2019-536, the complaint will be deemed rejected if the CNIL did not reach the author of the complaint within a three months period, regarding its complaint - whatever the means-.

Ex Officio Procedures under Art 57 GDPR[edit | edit source]

The CNIL can run ex officio procedures out of its own motion. Its powers are described under Article 8 of the law "Informatique et Libertés".

Appeals[edit | edit source]

Under Article R311-1(4) of the French code of administrative justice, acts taken by the CNIL can be appealed directly before the highest administrative court (Conseil d'État). This applies to sanctions, guidelines or any decision of the authority.

Decisions by the Conseil d'État are final and cannot be appealed.

Practical Information[edit | edit source]

Filing with the DPA[edit | edit source]

The CNIL provides an online service to submit a complaint (in French) here.

You can help us filling this section further!

Known Problems[edit | edit source]

  • The CNIL takes the view that the data subject is not a party to a complaints procedure.

You can help us filling this section!

Filing an Appeal[edit | edit source]

The Conseil d'État have an online procedure:

- for citizen and private organization: ;

- for Lawyers and public organizations:

You can help us filling this section!

Decision Database[edit | edit source]

Every publicly available decision of the CNIL is published on Legifrance, the French database regarding Law. Decisions can be either anonymised from publication or nominative, with anonymisation being applied two years after the decision was published.

Decisions of the CNIL are available here.

Statistics[edit | edit source]

The CNIL publishes open source data related to its activity, including statistics on complaints, controls and sanctions. The CNIL also publishes the list of all French organizations which have designated a DPO.

You can find open source data published by the CNIL here.

Funding[edit | edit source]

The budget of the CNIL is decided by the Parliament as part of the annual finance act. data on the budget since 2000 can be found here.

Personal[edit | edit source]

You can help us filling this section!

Caseload[edit | edit source]

You can help us filling this section!

Fines[edit | edit source]

You can help us filling this section!

Annual Reports[edit | edit source]

As required by article 8 of the law "Informatique et Liberté", the CNIL publishes an annual activities report. You can find all the reports published since 2007 here.

EU/EEA/UK Data Protection Authorities
Austria · Belgium · Bulgaria · Croatia · Cyprus · Czech Republic · Denmark · Estonia · Finland (Åland) · France · Germany (Baden-Württemberg · Bavaria, private sector · Bavaria, public sector · Berlin · Brandenburg · Bremen · Hamburg · Hesse · Lower Saxony · Mecklenburg-Vorpommern · North Rhine-Westphalia · Rhineland-Palatinate · Saarland · Saxony · Saxony-Anhalt · Schleswig-Holstein · Thuringia ) · Greece · Hungary · Ireland · Italy · Latvia · Lithuania · Luxembourg · Malta · Netherlands · Poland · Portugal · Romania · Slovakia · Slovenia · Spain (Basque Country · Catalonia · AndalusiaSweden
Iceland · Liechtenstein · Norway · United Kingdom EDPS · EDPB