Image featuring an article that answers the question "what is cnil".

What is CNIL? Functions, rules and best practices

Contents

Ready to use in minutes, Matomo gives you:
✔ Accurate privacy-first analytics
✔ Full data ownership
✔ GDPR compliance

Data breaches expose personal data at a massive scale. In the second quarter of 2025 alone, nearly 94 million data records were leaked, impacting millions of individuals worldwide.

As these risks grow, governments have introduced stricter data protection laws to hold organisations accountable. In France, the Commission nationale de l’informatique et des libertés (CNIL) plays this role.

In this post, we explain what CNIL is, its mission and the best practices organisations can follow to stay compliant.

Key takeaways

  • CNIL is France’s data protection authority, but its rules affect any organisation collecting or processing personal data from people in France.
  • Beyond fines and enforcement, CNIL actually wants to help. They provide guidance, cybersecurity resources and practical tools to build stronger privacy programmes.
  • Compliance starts with good data governance. Keep clear records of what data you collect and why, assess risks before launching new projects and set automatic retention policies so you don’t hoard data forever.
  • If you’re using web analytics, take a hard look at your data collection practices. Are you transferring data to the US? Using third-party cookies? Tracking across sites? If so, consider privacy-focused alternatives like Matomo.

What is CNIL?

CNIL is France’s independent data protection authority. While based in France, CNIL’s authority is not limited to organisations established there; its requirements can also apply to any organisation that offers goods or services to individuals in France or processes their personal data.

History of CNIL

In 1970, the French government proposed a project called SAFARI that linked government records with unique identification numbers for each citizen. There was a widespread public concern about the use of technology to collect personal information.

In response, an independent commission studied the issue and created CNIL in 1978 to help protect personal data and individual rights.

CNIL’s missions

CNIL France has four core missions.

These include making people aware about data protection rights, foreseeing risks, offering support to businesses and enforcing regulations.

Protect individual rights and raise awareness

Many people don’t know how their personal information is stored or shared online. CNIL provides resources that make data protection easier to understand. It also gives individuals a way to report privacy concerns and can step in when organisations fail to respect their obligations.

Support compliance and provide guidance

For businesses, privacy rules can sometimes be difficult to interpret. CNIL helps organisations simplify this by offering practical guidance and toolkit on topics like data collection, consent and security. This way, organisations are able to include privacy considerations into their operations while also being innovative and developing products and services to meet business needs.

Anticipate risks and drive innovation

Technology changes quickly, and privacy challenges often emerge before clear rules are set. CNIL monitors and studies the new technologies and trends around personal data collection.

It also encourages organisations to treat privacy as a priority in their design process, and not as an afterthought.

CNIL also regularly engages with researchers, startups and other stakeholders. It does this to examine questions and debate around data innovation, privacy and public trust. For example, CNIL has created Phantom, a mobile application to help teenagers better understand and protect the personal information they share on social media platforms.

Investigate and enforce regulations

CNIL has the power to investigate organisations that don’t comply with data protection laws. Investigations can happen because of complaints or for sectors identified as high risk. When violations come to surface, CNIL can issue warnings, order corrective measures, impose relevant restrictions and apply financial penalties where appropriate.

CNIL and the French Data Protection Act

France’s data protection framework is a combination of national and European laws. Though CNIL oversees compliance in France, it’s also closely tied to both the French Data Protection Act and the GDPR.

The French Data Protection Act

CNIL was established under France’s Data Protection Act of 6 January 1978. The law was introduced to protect individuals from the misuse of personal information and remains a key part of France’s privacy framework today.

How the Act works with GDPR

GDPR came into effect in 2018. It created a common set of data protection rules across the European Union. In France, GDPR works alongside the French Data Protection Act and CNIL supervises and enforces these requirements.

The French framework also aligns with other European privacy laws, including:

  • ePrivacy rules covering electronic communications and cookies.
  • The Law Enforcement Directive governing certain data processing activities carried out by competent authorities.

What is personal data?

To understand better about how these principles work, we must understand what they were designed to protect: personal data.

Personal data refers to any information that helps identify a person, either directly or indirectly.

Examples include:

  • Names
  • Email addresses
  • Phone numbers
  • Location data
  • Online identifiers
  • Customer or account numbers linked to an individual

What is GDPR?

The GDPR is the European Union’s data protection law. It was created to give individuals greater control over their personal information and also to build a consistent compliance framework across EU member states.

Since GDPR is an important part of European privacy law, understanding it will help get more insight into CNIL’s responsibilities.

Rights provided under GDPR

GDPR gives individuals several important rights over their personal data, including the right to:

  • Access the information an organisation holds about them
  • Correct inaccurate or incomplete data
  • Object to certain types of data processing
  • Request the removal of search engine results in some circumstances
  • Receive their data in a portable format
  • Request the deletion of personal data where applicable

Organisations are expected to follow several key principles alongside above rights when handling personal data:

Purpose limitation

Personal data should be collected for a specific and legitimate purpose and not used in ways that are incompatible with that purpose.

Data minimisation

Only the information needed to achieve a particular purpose should be collected and processed.

Storage limitation

Personal data should not be kept for longer than necessary and retention periods should be clearly defined.

Security and confidentiality

Organisations should protect personal data through appropriate security measures and limit access to authorised individuals.

How does the CNIL work?

18 members representing different public institutions and areas of expertise lead CNIL. They meet every week to discuss and review laws that could affect the use of personal data in France. They also verify guidance documents, recommendations and other non-binding rules that let organisations understand their privacy-related responsibilities.  

Alongside this body, CNIL has a separate restricted committee responsible for sanctions. When serious violations are identified, this committee decides whether warnings, corrective measures or financial penalties should be issued.

CNIL law enforcement process

Here’s a step-by-step explanation of how CNIL enforcement process works.

Step 1: Detecting an infringement

First, CNIL needs to identify a privacy issue which can come from several sources, including:

  • Complaints submitted by individuals
  • Investigations carried out by CNIL
  • Reports published in the media or online
  • Areas that CNIL has identified as enforcement priorities
  • Referrals from other European data protection entities

With this approach, CNIL can identify individual complaints as well as broader compliance problems.

Step 2: Investigating the issue

After the verification of the concern, the next step for CNIL is to examine facts and validate whether an organisation has breached GDPR and other relevant laws. To do that, CNIL can:

  • Do an on-site inspection
  • Check websites, apps or online services remotely
  • Request documents and written explanations
  • Interview relevant individuals

The goal is to understand what happened and assess whether any corrective action is required.

Step 3: Deciding the next steps

After reviewing the findings, the Chair of CNIL can:

  • Close the case where issues are limited or already resolved
  • Issue a formal notice requiring the organisation to address the problem
  • Refer the matter to the restricted committee for sanctions

If organisations receive corrective actions from CNIL, they also receive a deadline to comply with them.

Step 4: Sanctions procedure

For more serious cases, CNIL may refer the matter to its restricted committee.

Before the session

At this stage:

  • CNIL appoints a rapporteur to review the case
  • The organisation receives notice of the hearing date
  • The rapporteur prepares a report proposing corrective measures

Written submissions

Before the hearing:

  • The organisation can submit written observations
  • The rapporteur can respond
  • Both sides may provide additional comments if needed

This stage gives organisations an opportunity to explain their position before any decision is made.

Restricted committee hearing

The committee goes through the evidence and hears out both parties before reaching a conclusion.

Depending on the circumstances, it may:

  • Issue a warning
  • Order specific compliance measures
  • Impose periodic penalty payments
  • Levy a financial penalty

Step 5: Notification and publication

Whatever the decision is, CNIL notifies it to the organisation.

Depending on the case, CNIL may also:

  • Publish the decision
  • Share a statement publicly
  • Publish details of corrective measures or sanctions

Public decisions help promote transparency and encourage organisations to take data protection obligations seriously.

CNIL and cybersecurity

Cybersecurity forms an important part of CNIL’s work in the following ways.

Educating general public

CNIL regularly publishes practical advice for everyday internet users on common issues like:

  • Phishing emails or SMS
  • Stolen accounts
  • How to respond to social media account hacks
  • Password security
  • Online scams and fraud

The aim is to help people spot risks early and know what to do when something goes wrong.

Guiding professionals and organisations

CNIL also provides practical guidance on security practices for organisations, including:

  • Password management recommendations
  • Data security checklists
  • Website and system security guidance
  • Resources specially designed for SMEs, associations and public bodies

These help organisations strengthen security without having to interpret complex regulations on their own.

Regular sanctions

Security measures are one of the first things it reviews during investigations.

Common issues include:

  • Weak password policies
  • Personal data exposed through poorly designed websites
  • Information sent without encryption
  • Devices or systems left accessible to unauthorised users
  • New applications released without adequate security testing

Many of these problems are preventable, which is why basic security controls remain so important.

Collaboration in broader cyber ecosystem

CNIL collaborates with cybersecurity agencies, industry groups and other organisations to share knowledge and improve awareness of emerging threats.

This helps organisations stay informed about new risks while encouraging stronger security practices across the wider digital ecosystem.

Web analytics and CNIL compliance: How Matomo helps  

Web analytics measures visitor behaviour on your website, but traditional tools often transfer personal data outside the EU, combine datasets across clients or reuse data for advertising.

Matomo is different because it keeps data in the EU, never combines or reuses your data, and can be configured to qualify for CNIL’s consent exemption under French guidance.

Here’s how:

CNIL compliance mode

When you enable CNIL mode, you can assess your current setup against CNIL consent exemption conditions and apply supported settings in one click:

  • Cookies are disabled
  • IP anonymisation activates
  • Cross-site tracking is blocked
  • PII filtering runs
  • And data retention is set to 180 days

You also see clearly what still needs your attention. Just go to Administration > Privacy > Compliance, select your site, and click « Enforce compliance where possible. »

You only add the opt-out link to your privacy policy.

Data stays in the EU

Matomo never transfers data to the US. Cloud data lives on EU servers in France or you host on your own infrastructure. No GDPR violations from cross-border transfers.

Full data ownership

Matomo is open-source and fully auditable. Data stays isolated per customer with no pooling. Matomo never reuses your data for its own commercial purposes.

Best practices for CNIL compliance

CNIL expects organisations to take real responsibility for the data they handle.

Here are some best practices to adopt.

Appoint a data protection officer (DPO)

Assign someone to manage data protection and act as your go-to person when questions arise about data handling. This can be an internal person or an external expert. Your DPO reviews projects before launch and ensures they meet privacy requirements.

Maintain a record of processing activities (ROPA)

Document exactly how and why you collect personal data. Track your legal basis for each data type, like legal obligation for tax records. If you can’t identify a valid legal reason for collecting a data type, don’t store it. ROPA shows CNIL you understand what data you hold and why. This record becomes your privacy blueprint.

Conduct data protection impact assessments (DPIA)

Some projects may have greater privacy risks than others. This is especially true for cases where organisations adopt new technologies or track individuals at scale. A DPIA is a structured review that helps identify privacy risks before a project goes live.

For example, if a company plans to deploy an AI-powered recruitment tool that analyses candidate profiles, a DPIA can help uncover issues such as excessive data collection or inadequate security controls before they affect real users.

Anonymise or pseudonymise data

Organisations can use two approaches to use data safely for analysis or innovation.

  • Anonymisation permanently removes identifying elements so that an individual can no longer be identified.
  • Pseudonymisation replaces identifiers with codes or references while allowing authorised users to reconnect the data when necessary.

Audit AI data for bias and quality

Inaccurate data used to train AI systems produce unfair outcomes. Regular reviews help organisations identify gaps, inconsistencies and hidden biases before they affect customers or employees.

Establish a data breach response plan

Even organisations with a strong security protocol can experience a breach. What differentiates it from others is having a clear response plan. A response plan should clearly define:

  • How to detect and report incidents
  • Who investigates the issue
  • How to contain affected systems
  • When to notify affected individuals and regulators

Automate data retention and deletion

Set automatic timelines to delete data once you no longer need it. Don’t store data without a clear purpose. CNIL’s consent exemption requires retention limits, and automated deletion ensures you never keep data longer than necessary.

Make privacy part of your strategy

CNIL plays a central role in guiding businesses towards better data practices and long-term accountability.

For organisations looking to align with CNIL practices, Matomo offers a privacy-focused analytics solution that avoids reliance on invasive tracking while still delivering useful insights. It helps teams stay compliant without overcomplicating their data strategy.

Start your 21-day free trial with Matomo. No credit card required.

FAQs

Who is subject to CNIL?

Any organisation that processes personal data of people in France is subject to CNIL, regardless of where the company is located. This includes businesses, public authorities, non-profits and websites targeting French users.

What are the penalties for violating CNIL rules?

CNIL has the power to impose significant fines. In 2025, CNIL issued €486.8 million in cumulative fines across 83 sanctions.

The most notable recent case: FREE MOBILE received a €27 million fine and FREE received €15 million for a data breach affecting 24 million subscribers in 2024. The exact fine amount depends on the severity, duration and whether the organisation acted intentionally or negligently.

Does a data controller have to notify a data breach to CNIL?

Yes. Data controllers must notify CNIL within 72 hours when a breach presents a risk to individuals’ rights and freedoms. You must also document all breaches internally and inform affected individuals if the risk is high.

When should I appoint a DPO?

You only need a DPO if your organisation processes large volumes of sensitive data (like health records), conducts regular large-scale monitoring of people, or is a public authority. Most regular businesses don’t legally require one. However, appointing a DPO (even internally or externally) is highly recommended.

Can CNIL fine organisations for GDPR violations?

Yes. If an organisation fails to comply with GDPR or French data protection rules, CNIL can investigate the matter and take action. Depending on the severity of the issue, this may include warnings, formal notices, orders to correct non-compliant practices or financial penalties.

Démarrez avec Matomo

En choisissant Matomo, l’alternative éthique pour l’analyse web, vous ne faîtes aucun compromis concernant la confidentialité et la sécurité de vos données privées.

Enjoyed this post?
Join the 160,000+ subscribers who receive the Matomo Newsletter straight to their inbox every month

https://matomo.org/newsletter (last update: 2026/07/22)

Ce champ n’est utilisé qu’à des fins de validation et devrait rester inchangé.

Certifié ISO 27001:2022

Vos données analytics sont protégées par des standards de sécurité reconnus à l’international. La certification ISO 27001 garantit que nous appliquons les plus hauts standards de gestion de la sécurité de l’information.

Sites web en ligne à travers le monde
0 K
de sites web ont utilisé Matomo
0 M
de satisfaction client
0 %

Gardez le contrôle de vos données. Respectez la vie privée de vos utilisateurs. Accédez à des analyses plus performantes.

Les organisations devraient pouvoir comprendre leurs performances numériques tout en conservant la pleine propriété et le contrôle de leurs données.

Aucune carte bancaire requise.