CNIL (France)

From GDPRhub
Commission nationale de l'informatique et des libertés
Name: Commission nationale de l'informatique et des libertés
Abbreviation : CNIL
Jurisdiction: France
Head: Marie-Laure Denis
Secretary general: Jean Lessi
Adress: 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07
Fax: +33 1 53 73 22 00
Phone: +33 1 53 73 22 22
Twitter: @CNIL and @CNIL_en
Procedural Law: n/a
Decision Database: Legifrance
Translated Decisions: Category:CNIL (France)
Head Count: n/a
Budget: n/a

The CNIL is the federal Data Protection Authority for France. The authority is established in Paris and is in charge of enforcing GDPR for France.

Structure[edit | edit source]

The CNIL was established in 1978 with the law "Informatique et Libertés". It is an independent administrative authority led by a college of 18 members and a contract staff team. Twelve out of eighteen members are elected or designated by the national authorites and courts to which they belong (i.e. Senate, National Parliament, Economic and Social Committee, Supreme Civil and Administrative Courts, Court of Auditors and the Commission of Access to Administrative Documents). The CNIL's president can freely recruit its other staff.

The CNIL issues orders and imposes fines within a restricted formation, meaning one president and five others elected members, pursuant to Article 9 of the Law "Informatique et Libertés". The CNIL's internal rules indicate that, unless otherwise justified, the pronunciation of fines is public. Anyone can ask for the agenda of the hearing and attend.

The composition, nomination and the organisational structure is laid down by Articles 9 to 18 of the Law "Informatique et Libertés".

You can find the organizational chart here.

Procedural Information[edit | edit source]

Applicable Procedural Law[edit | edit source]

The CNIL operates under the law "Informatique et Libertés" under the conditions laid down by Articles 19 to 29. See the law here, in French. The law "informatique et Libertés" has to be read jointly with the Decree n° 2019-536 of May 29.

Complaints Procedure under Art 77 GDPR[edit | edit source]

According to Article 8, par.2 d) of the loi "Informatique et Liberté", a data subject or their representative(s) can lodge a complaint with the CNIL regarding an alleged infringement of the GDPR.

According to Article 10 of the Decree n°2019-536, the complaint will be deemed rejected if the CNIL did not reach the author of the complaint within a three months period, regarding its complaint - whatever the means-.

Ex Officio Procedures under Art 57 GDPR[edit | edit source]

The CNIL can run ex officio procedures out of its own motion. Its powers are described under Article 8 of the law "Informatique et Libertés".

Practical Information[edit | edit source]

The CNIL provides an online service to submit a complaint (in French) here.

Statistics[edit | edit source]

You can help us filling this section!

EU/EEA Data Protection Authorities
Austria · Belgium · Bulgaria · Croatia · Cyprus · Czech Republic · Denmark · Estonia · Finland · France · Germany (Baden-Württemberg · Bavaria, private sector · Bavaria, public sector · Berlin · Brandenburg · Bremen · Hamburg · Hesse · Lower Saxony · Mecklenburg-Vorpommern · North Rhine-Westphalia · Rhineland-Palatinate · Saarland · Saxony · Saxony-Anhalt · Schleswig-Holstein · Thuringia ) · Greece · Hungary · Ireland · Italy · Latvia · Lithuania · Luxembourg · Malta · Netherlands · Poland · Portugal · Romania · Slovakia · Slovenia · Spain · Sweden
Iceland · Liechtenstein · Norway EDPS · EDPB
Non-EU/EEA Data Protection Authorities
United Kingdom