CNIL (France)

From GDPRhub
Revision as of 16:05, 31 December 2020 by Roka (talk | contribs) (→‎Annual Reports)
Commission nationale de l'informatique et des libertés
Name: Commission nationale de l'informatique et des libertés
Abbreviation : CNIL
Jurisdiction: France
Head: Marie-Laure Denis
Secretary general: Jean Lessi
Adress: 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07
Fax: +33 1 53 73 22 00
Phone: +33 1 53 73 22 22
Twitter: @CNIL and @CNIL_en
Procedural Law: n/a
Decision Database: Legifrance
Translated Decisions: Category:CNIL (France)
Head Count: 225[1]
Budget: 20,143,890 € in 2020[2]

The CNIL is the federal Data Protection Authority for France. The authority is established in Paris and is in charge of enforcing GDPR for France.


The CNIL was established in 1978 with the law "Informatique et Libertés". It is an independent administrative authority led by a college of 18 members and a contract staff team. Twelve out of eighteen members are elected or designated by the national authorities and courts to which they belong (i.e. Senate, National Parliament, Economic and Social Committee, Supreme Civil and Administrative Courts, Court of Auditors and the Commission of Access to Administrative Documents). The CNIL's president can freely recruit its other staff.

The CNIL issues orders and imposes fines within a restricted formation, meaning one president and five others elected members, pursuant to Article 9 of the Law "Informatique et Libertés". The CNIL's internal rules indicate that, unless otherwise justified, the pronunciation of fines is public.

Anyone can ask for the agenda of the hearing and attend. You can find the CNIL's public agenda here.

The composition, nomination and the organisational structure is laid down by Articles 9 to 18 of the Law "Informatique et Libertés". You can find the organizational chart here.

Procedural Information

Applicable Procedural Law

The CNIL operates under the law "Informatique et Libertés" under the conditions laid down by Articles 19 to 29. See the law here, in French. The law "informatique et Libertés" has to be read jointly with the Decree n° 2019-536 of May 29.

Complaints Procedure under Art 77 GDPR

According to Article 8(I)(2)(d) of the loi "Informatique et Liberté", a data subject or their representative(s) can lodge a complaint with the CNIL regarding an alleged infringement of the GDPR.

According to Article 10 of the Decree n°2019-536, the complaint will be deemed rejected if the CNIL did not reach the author of the complaint within a three months period, regarding its complaint - whatever the means-.

Ex Officio Procedures under Art 57 GDPR

The CNIL can run ex officio procedures out of its own motion. Its powers are described under Article 8 of the law "Informatique et Libertés".


You can help us filling this section!

Practical Information

Filing with the DPA

The CNIL provides an online service to submit a complaint (in French) here.

You can help us filling this section further!

Known Problems

  • The CNIL takes the view that the data subject is not a party to a complaints procedure.

You can help us filling this section!

Filing an Appeal

Under Article R311-1(4) of the French code of administrative justice, any act taken by the CNIL can be appealed directly before the highest administrative court (Conseil d'État). This applies to sanctions, guidelines or any decision of the authority.

Decision Database

You can help us filling this section!


The CNIL publishes open source data related to its activity, including statistics on complaints, controls and sanctions. The CNIL also publishes the list of all French organizations which have designated a DPO.

You can find open source data published by the CNIL here.


The budget of the CNIL is decided by the Parliament as part of the annual finance act. datas on the budget since 2000 can be found here.


You can help us filling this section!


You can help us filling this section!


You can help us filling this section!

Annual Reports

As required by article 8 of the law "Informatique et Liberté", the CNIL publishes an annual activities report. You can find all the reports published since 2007 here.

EU/EEA/UK Data Protection Authorities
Austria · Belgium · Bulgaria · Croatia · Cyprus · Czech Republic · Denmark · Estonia · Finland · France · Germany (Baden-Württemberg · Bavaria, private sector · Bavaria, public sector · Berlin · Brandenburg · Bremen · Hamburg · Hesse · Lower Saxony · Mecklenburg-Vorpommern · North Rhine-Westphalia · Rhineland-Palatinate · Saarland · Saxony · Saxony-Anhalt · Schleswig-Holstein · Thuringia ) · Greece · Hungary · Ireland · Italy · Latvia · Lithuania · Luxembourg · Malta · Netherlands · Poland · Portugal · Romania · Slovakia · Slovenia · Spain (Basque Country · Catalonia · AndalusiaSweden
Iceland · Liechtenstein · Norway · United Kingdom EDPS · EDPB