# Website privacy policy in France: mandatory even for a brochure site? GDPR contents and template 2026

> As soon as a website collects personal data (a contact form, a newsletter, customer accounts, audience measurement, even plain server logs), articles 13 and 14 of the GDPR require you to inform the people concerned: that is the job of the privacy policy. It says who processes the data, why, on what legal basis, with which providers, for how long and how to exercise their rights, including with the CNIL (the French data protection authority). Leaving it out exposes you to a CNIL fine: up to €20 million or 4% of worldwide turnover, and up to €20,000 (€100,000 above €50 million in turnover) under the simplified procedure, reserved for cases with no particular difficulty.

Source: https://legalnest.io/en/guides/privacy-policy-france/
Updated on 8 October 2026. Checked against the law in force on 07/10/2026.
General information, not personalised legal advice.

On 19 September 2024, a gun shop selling online and in store was fined [€20,000](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil) by the CNIL (the French data protection authority) under its simplified procedure. Alongside data security and the right to erasure, the CNIL found two breaches you can read straight off a privacy policy: “information of individuals and transparency” and “retention period”. Not a tech giant: a shop with an e-commerce site.

The GDPR is EU-wide, so the core rules below are the same across the EU. What is French is the enforcer (the CNIL), its simplified sanction procedure, a criminal penalty on top, and a separate cookie provision in French law. A contact form is enough to make a « politique de confidentialité » (privacy policy) mandatory, and a brochure site with no form rarely escapes it. Here is what the text says, and an annotated template, section by section.

## Is a privacy policy mandatory on a website in France?

Yes, as soon as the site collects any personal data: articles 13 and 14 of the GDPR require you to inform people at the time of collection. The regulation never uses the words “privacy policy”, but that is the form this information takes on a website.

**What the law says**

> Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information: (a) the identity and the contact details of the controller and, where applicable, of the controller’s representative; (b) the contact details of the data protection officer, where applicable; (c) the purposes of the processing for which the personal data are intended as well as the legal basis for the processing; […]
>
> Source: [Regulation (EU) 2016/679 (GDPR), Article 13(1)(a) to (c)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679)

[Article 12](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679) adds the how: information “in a concise, transparent, intelligible and easily accessible form, using clear and plain language”. For data obtained from a third party (a bought list, contacts gathered from LinkedIn), article 14 requires you to inform people within a reasonable period of no more than one month, or at the latest when you first contact them.

What triggers the obligation on a small business website:

| On your site | Data collected | Privacy policy |
|---|---|---|
| Contact or quote form | Name, email, phone, message | Mandatory |
| Newsletter sign-up | Email, first name, opens and clicks | Mandatory |
| Customer accounts, online shop | Identity, addresses, orders, payment | Mandatory |
| Online booking | Name, contact details, time slot, subject | Mandatory |
| Audience measurement tool | Tracker ID, pages viewed, IP address | Mandatory, with the cookie information |
| Embedded video, map or social network | IP address sent to the provider, sometimes trackers | Mandatory |
| Plain page with no form or third-party tool | IP address in server logs | See the next question |

The [official French government page on mandatory website information](https://entreprendre.service-public.gouv.fr/vosdroits/F31228) (in French) gives the contact form as an example and states that this policy must be separate from your « CGV » (terms of sale).

## Does a brochure website with no contact form need a privacy policy?

In almost every case, yes. Even without a form, a site records IP addresses in its server logs, and the Court of Justice of the European Union has ruled that an IP address can be personal data for the website publisher.

In the [Breyer judgment of 19 October 2016](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0582), the Court held that a dynamic IP address recorded by a website publisher is personal data for that publisher when it has legal means to have the person identified through their internet access provider.

Other processing almost always comes on top, often invisible:

- an audience measurement tool installed by your agency or your theme;
- a YouTube video, a map or a font loaded from a third-party server, which passes the visitor’s IP address to that third party;
- a displayed email address: the messages you receive are data collected from the people who send them.

Only a site that collects strictly nothing escapes article 13, and that means checking every script and every embedded item. A ten-line policy costs less than that check.

```mermaid
flowchart TD
  A["Your website"] --> B{"Form, account or newsletter?"}
  B -->|Yes| P["Full policy mandatory"]
  B -->|No| C{"Analytics or embedded content?"}
  C -->|Yes| P2["Policy mandatory, with a cookie section"]
  C -->|No| D{"Server logs or contact email?"}
  D -->|Yes| P3["A short policy is enough"]
  D -->|No| E["No collection: check every script"]
```

To see what your home page actually loads, the [free cookie scanner](https://app.legalnest.io/tools/cookies?lang=en) detects known trackers and the cookies set on first load.

## What must a GDPR privacy policy contain?

The information listed in article 13 of the GDPR: who processes the data, why and on what basis, who it is shared with, where it goes, how long it is kept, and which rights people can exercise. Some items apply only “where applicable” (DPO, transfers, automated decision-making).

| Required information | Article | What to write in practice |
|---|---|---|
| Identity and contact details of the controller | 13(1)(a) | Company name, address, contact email |
| Contact details of the data protection officer | 13(1)(b) | Only if you have appointed one |
| Purposes and legal basis | 13(1)(c) | One line per use: answering enquiries, sending the newsletter, invoicing |
| Legitimate interests pursued | 13(1)(d) | If a purpose relies on legitimate interest, which one |
| Recipients or categories of recipients | 13(1)(e) | Team, host, email marketing tool, payment provider, accountant |
| Transfers outside the European Union | 13(1)(f) | Country and safeguard: adequacy decision or standard contractual clauses |
| Retention period or criteria | 13(2)(a) | One period per category of data |
| Rights of access, rectification, erasure, restriction, objection, portability | 13(2)(b) | The list, and the address where to exercise them |
| Right to withdraw consent | 13(2)(c) | For the newsletter and trackers that require consent |
| Right to lodge a complaint | 13(2)(d) | With a supervisory authority: the CNIL in France, with its address or website |
| Whether providing the data is mandatory or optional | 13(2)(e) | Which fields are required and what happens if they are missing |
| Automated decision-making, profiling | 13(2)(f) | Only for fully automated decisions with legal or similarly significant effects (art. 22) |

A data protection officer (DPO) is only mandatory in the cases set out in [article 37 of the GDPR](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679) (public body, large-scale monitoring or large-scale sensitive data): a solo consultant does not have one, and the line disappears. And for any new use of the data, article 13(3) requires you to inform people before, not after.

For a US provider certified under the EU-US framework, cite the [adequacy decision of 10 July 2023](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023D1795); otherwise, the safeguard you rely on, most often standard contractual clauses, and where to see it.

## Which legal basis should I state for each processing purpose?

Each purpose rests on one of the six bases in [article 6 of the GDPR](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679): consent, contract, legal obligation, vital interests, public interest task, legitimate interest.

| Common processing | Usual legal basis |
|---|---|
| Answering a quote request | Pre-contractual steps (art. 6(1)(b)) |
| Answering a simple question | Legitimate interest in replying to enquiries (art. 6(1)(f)) |
| Managing orders and delivery | Performance of the contract (art. 6(1)(b)) |
| Invoicing and keeping accounting records | Legal obligation (art. 6(1)(c)) |
| Newsletter to consumer prospects | Consent (art. 6(1)(a)) |
| Offers to a customer for products similar to those bought | Legitimate interest, according to the [CNIL standard](https://www.cnil.fr/sites/default/files/atoms/files/referentiel_traitements-donnees-caractere-personnel_gestion-activites-commerciales.pdf) (in French) |
| Non-exempt audience measurement | Consent, collected through the cookie banner |

The CNIL explains each basis on its [legal bases page](https://www.cnil.fr/fr/les-bases-legales) (in French). The choice shapes the rights: no objection to a legal obligation, while consent can always be withdrawn.

## What is the difference between a privacy policy, a cookie policy and a legal notice?

The legal notice says who publishes the site, the privacy policy what you do with personal data, the cookie policy which trackers are placed on the visitor’s device. Three texts, three legal foundations, often three pages.

| | Legal notice (« mentions légales ») | Privacy policy | Cookie policy |
|---|---|---|---|
| Law | [LCEN, art. 1-1](https://www.legifrance.gouv.fr/loda/article_lc/LEGIARTI000049568614) (French) | [GDPR, art. 12 to 14](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679) (EU-wide) | [French Data Protection Act, art. 82](https://www.legifrance.gouv.fr/loda/article_lc/LEGIARTI000037813978) (French) |
| Answers | Who publishes and hosts the site? | What do you do with my data? | Which trackers, what for, for how long? |
| Applies to | Every business website | Every site that collects data | Every site that places trackers |
| Penalty | Criminal | CNIL | CNIL |

No text requires three separate pages: the cookie policy can be a section of the privacy policy. What matters is that the banner and both policies describe the same trackers, purposes and lifetimes. The detail is in our guides to the [legal notice for a website in France](/en/guides/legal-notice-website-france/) and the [CNIL-compliant cookie banner](/en/guides/cookie-banner-france-cnil/).

## What should a privacy policy template say, section by section?

A good template follows the order of article 13 and describes your real processing. Example for Claire, an HR consultant running a SASU (a single-shareholder simplified joint-stock company): contact form, newsletter, online booking and audience measurement.

**1. Controller.** “The controller is Claire Martin Conseil, SASU, [registered office address]. For any question about your data: [dedicated email].”
Comment: use an address someone reads regularly, because that is where access requests will land.

**2. Data collected and whether it is mandatory.** “Contact form: name, email and message are required, phone number is optional. Without an email address, we cannot reply to you.”
Comment: this is article 13(2)(e), often forgotten. Mark the required fields in the form too.

**3. Purposes and legal bases.** “Answering your quote requests (pre-contractual steps); sending you our newsletter (consent); issuing and keeping invoices (legal obligation).”
Comment: never “we use your data to improve our services” with nothing more specific.

**4. Recipients.** “Your data is intended for Claire Martin Conseil. It is processed on our behalf by our host, our newsletter tool, our booking tool and, for invoices, our accountant.”
Comment: the category of provider is enough, but each one must be covered by a contract that complies with [article 28 of the GDPR](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679).

**5. Transfers outside the European Union.** “Our booking tool hosts data in the United States; this transfer is covered by [safeguard and link].”
Comment: if everything is hosted in Europe, say so in one sentence.

**6. Retention periods.** “Contact requests with no follow-up: 3 years after your last message. Newsletter: until you unsubscribe. Invoices: 10 years. Audience measurement: trackers 13 months, data collected 25 months.”
Comment: every period has a source. The 3 years for a prospect come from the [CNIL standard on managing commercial activities](https://www.cnil.fr/sites/default/files/atoms/files/referentiel_traitements-donnees-caractere-personnel_gestion-activites-commerciales.pdf) (in French), the 10 years from [article L123-22 of the « Code de commerce » (Commercial Code)](https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000006219327/), the 13 and 25 months from the [CNIL’s recommendations on audience measurement](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies-solutions-pour-les-outils-de-mesure-daudience) (in French).

**7. Your rights.** “You can access your data, rectify it, erase it, restrict its processing, object to its processing, request its portability and withdraw your consent at any time, by writing to [email].”
Comment: [article 12(3)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679) gives you one month to respond, extendable by two months if you tell the person.

**8. Complaints.** “If you believe your rights are not being respected, you can lodge a complaint with the CNIL (cnil.fr).”
Comment: article 13(2)(d), a right based on [article 77](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679). Its absence gives away an imported template.

**9. Last updated.** “Last updated: 7 October 2026.”
Comment: not required as such, but it lets you prove what was displayed.

Your [record of processing activities](/en/guides/gdpr-record-of-processing/) already contains sections 3, 4, 5 and 6: purposes, recipients, transfers and retention periods. Fill it in first, then write the policy from it: the two documents must say the same thing.

**With Legalnest**: Legalnest offers a **privacy policy template** customised through a questionnaire, which follows this order. Once ready, it is published on a **hosted page** (`app.legalnest.io/d/…`) that shows its last update date. In the **compliance score**, it counts towards the “Website” framework, while your record of processing, your data processing agreements (DPA) and your retention policy count towards the “GDPR” framework; a document goes back to “to review” 12 months after its last review. [See the plans](/en/pricing/).

## Where should the privacy policy go on my website?

On a dedicated page, reachable from every page of the site (usually in the footer), and summarised in a few lines under each form. The CNIL recommends layered information: the essentials at the point of collection, the detail one click away.

The [official page on entreprendre.service-public.fr](https://entreprendre.service-public.gouv.fr/vosdroits/F31228) (in French) asks for a link that is “clearly visible on every page of the site”. In its [guidance on informing individuals](https://www.cnil.fr/fr/conformite-rgpd-information-des-personnes-et-transparence) (in French), the CNIL puts the controller’s identity, the purposes and the rights in the first layer. It also publishes [sample information notices](https://www.cnil.fr/fr/passer-laction/rgpd-exemples-de-mentions-dinformation) (in French), including one for a data collection form. Under Claire’s contact form, that gives:

> The information you enter is used by Claire Martin Conseil to answer your request and kept for 3 years after your last message. You can access, rectify or erase it by writing to [email]. Learn more: [privacy policy].

There is no need for an “I accept the privacy policy” checkbox: informing people is not collecting consent, and the box suggests the processing depends on it. Keep checkboxes for genuine consent, such as signing up to the newsletter.

## What is the fine for not having a privacy policy in France?

A breach of articles 12 to 14 of the GDPR carries a fine of up to €20 million or 4% of worldwide annual turnover, whichever is higher. In a case with no particular difficulty, the CNIL can use its simplified procedure, capped at €20,000 for a business with turnover below €50 million.

The general cap is set by [article 83(5)(b) of the GDPR](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679), and applies across the EU. The [simplified procedure](https://www.cnil.fr/fr/la-procedure-de-sanction-simplifiee) (in French) is French: its cap is set by [article 22-1 of the « loi Informatique et Libertés » (French Data Protection Act)](https://www.legifrance.gouv.fr/loda/article_lc/LEGIARTI000054142442), in the version in force since 28 May 2026: a €20,000 fine and a €100 penalty per day of delay, raised to €100,000 and €500 per day when worldwide turnover exceeds €50 million. The decision is not made public.

There is also a French criminal side: [article R625-10 of the « Code pénal » (Criminal Code)](https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000038607906) punishes failure to provide the information required by articles 13 and 14 of the GDPR with a fine for a 5th-class petty offence: up to €1,500 for an individual ([art. 131-13](https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000006417259)) and €7,500 for a company ([art. 131-41](https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000006417342)), excluding repeat offences.

What has actually been imposed, according to the [CNIL’s list of sanctions](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil) (in French):

| Date | Organisation | Breaches found (extract) | Sanction |
|---|---|---|---|
| 12 March 2026 | Catalogue distance selling (simplified procedure) | Information of individuals (exercising rights), right of access | €5,000 |
| 3 July 2025 | Distance selling of furniture and home decor | Retention period, information of individuals, cookies, marketing | €600,000 |
| 3 April 2025 | Building works brokerage and project management (simplified procedure) | Information of individuals (exercising rights), failure to cooperate | €10,000 and an injunction |
| 12 December 2024 | Communications and video production agency (simplified procedure) | Transparency and information (exercising rights), right of access | €6,000 |
| 19 September 2024 | Gun shop, online and in store (simplified procedure) | Retention period, information and transparency, erasure, security | €20,000 |

The landmark case is still Google: €50 million on 21 January 2019 ([SAN-2019-001](https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000038032552/), in French), notably because the information required by article 13 was “excessively scattered” across several documents. The [Conseil d’État (France’s highest administrative court) upheld](https://www.conseil-etat.fr/actualites/rgpd-le-conseil-d-etat-rejette-le-recours-dirige-contre-la-sanction-de-50-millions-d-euros-infligee-a-google-par-la-cnil) (in French) the fine on 19 June 2020, noting that the information available was “sometimes incomplete, in particular as regards the data retention period”. Our guide to [CNIL fines](/en/guides/cnil-fines/) details the procedures and amounts.

## What are the most common privacy policy mistakes?

A copied template that does not describe your business, forgotten providers, and retention periods that are missing or “unlimited”.

**The US template trap**

A “privacy policy” borrowed from a US website talks about the “sale of data”, California law or arbitration clauses, and leaves out what the GDPR requires: the legal bases, the retention periods and the right to complain to the CNIL. It looks complete and fails on substance.

- **Forgetting your processors.** The email marketing tool, the CRM, the booking tool, the payment provider, the host: each one receives data and must be listed among the recipients, with any transfer outside the EU flagged.
- **Writing “for as long as necessary”.** Article 13(2)(a) accepts criteria when a fixed period is impossible, but a vague phrase is not a criterion. The CNIL says so on its page on [retention periods](https://www.cnil.fr/fr/les-durees-de-conservation-des-donnees) (in French): “personal data cannot be kept indefinitely”.
- **Basing everything on consent.** Invoicing is a legal obligation, delivery is a contract: relying on consent would suggest it can be withdrawn.
- **Never updating it.** New tool, new provider: the policy must follow.

## Will the EU Digital Omnibus change the GDPR information duty?

Not so far. On 19 November 2025 the European Commission proposed a “Digital Omnibus” regulation that amends the GDPR among other texts, but as of 7 October 2026 the procedure is still ongoing and article 13 applies as currently worded.

According to the [European Parliament’s procedure file 2025/0360(COD)](https://oeil.europarl.europa.eu/oeil/en/procedure-file?reference=2025/0360%28COD%29), proposal COM(2025) 837 is still awaiting its committee vote and has been neither adopted nor published in the Official Journal: the CNIL checks compliance against the current text.

## How do I check my privacy policy before publishing it?

Compare it point by point with article 13 and with your real processing, ideally starting from your record of processing.

**Your privacy policy in 12 points**

- [ ] Identity and contact details of the controller, with an email address someone reads
- [ ] DPO contact details, only if you have appointed one
- [ ] One purpose per line, each with its **legal basis** (art. 6)
- [ ] The legitimate interest spelled out when that is the basis relied on
- [ ] Every recipient, including the email marketing tool, the CRM and the host
- [ ] Transfers outside the EU, with the country and the safeguard
- [ ] A sourced **retention period** for each category of data
- [ ] The six rights, withdrawal of consent and the address to exercise them
- [ ] The right to lodge a complaint with the CNIL
- [ ] Required fields flagged, and what happens if they are left blank
- [ ] A cookie section consistent with the banner, or a link to the cookie policy
- [ ] A link in the footer of every page, a short notice under each form, a last updated date

To check that your home page links to your legal documents, run the [free website audit](https://app.legalnest.io/tools/website-audit?lang=en). To see where your whole site stands, take the [website compliance quiz](/en/guides/website-compliance-quiz/). And if you sell online, read on with our guides to [terms of sale in France](/en/guides/terms-of-sale-france/) and the [mandatory legal documents for a French business](/en/guides/mandatory-legal-documents-france/).

## Frequently asked questions

### Is a privacy policy mandatory on a website in France?

Yes, as soon as the site collects personal data: a contact form, newsletter sign-up, customer account, online booking or audience measurement tool. Articles 13 and 14 of the GDPR then require you to inform people at the time of collection. The GDPR does not dictate what the document is called, but on a website this information takes the form of a privacy policy that can be reached from every page.

### Does a brochure website with no contact form need a privacy policy?

Almost always. Even without a form, a site usually records IP addresses in its server logs, and the Court of Justice of the European Union ruled in 2016 that an IP address can be personal data for the website publisher. On top of that there is often an audience measurement tool, an embedded map or video, or a contact email address. A short policy covering just those processing operations is then enough.

### What must a GDPR privacy policy contain?

Article 13 of the GDPR lists it: the controller’s identity and contact details, the data protection officer’s contact details if there is one, purposes and legal bases, the legitimate interests relied on, recipients, transfers outside the European Union, retention periods, data subjects’ rights, the right to withdraw consent, the right to complain to a supervisory authority (the CNIL in France), whether providing the data is mandatory or optional, and the existence of automated decision-making. Each item must be written in a concise, clear and easily accessible way.

### What is the fine for not having a privacy policy in France?

A breach of articles 12 to 14 of the GDPR falls under the higher cap in article 83: €20 million or 4% of worldwide annual turnover. In a straightforward case, the CNIL can use its simplified procedure, where the fine is capped at €20,000 (€100,000 above €50 million in worldwide turnover). The French Criminal Code also provides for a 5th-class petty offence: up to €1,500 for an individual and €7,500 for a company, excluding repeat offences.

### Can I copy another website’s privacy policy or use a US template?

Copying another site’s text, or a US template, means describing processing, providers and retention periods that are not yours, which amounts to inaccurate information. A template gives you a structure, not the content: every purpose, tool and retention period must match what your business actually does, and your record of processing. US templates add a further problem: they often leave out the legal bases and the right to complain to the CNIL.

### Do I need a separate cookie policy as well as a privacy policy?

Cookies fall under a separate French text, article 82 of the French Data Protection Act, which requires you to explain what trackers are for and to obtain consent when they are not exempt. That information can sit in a section of the privacy policy or on a dedicated page. What matters is that the banner, the cookie policy and the privacy policy describe the same trackers with the same lifetimes.


## Sources

- [Regulation (EU) 2016/679 (GDPR), art. 12 to 14: transparency and information to be provided (in French)](https://www.cnil.fr/fr/reglement-europeen-protection-donnees/chapitre3) (CNIL)
- [Regulation (EU) 2016/679 (GDPR), art. 5 and 6: principles and lawfulness of processing (in French)](https://www.cnil.fr/fr/reglement-europeen-protection-donnees/chapitre2) (CNIL)
- [Regulation (EU) 2016/679 (GDPR), art. 28 and 37: processor and data protection officer (in French)](https://www.cnil.fr/fr/reglement-europeen-protection-donnees/chapitre4) (CNIL)
- [Regulation (EU) 2016/679 (GDPR), art. 77 and 83: complaints and administrative fines (in French)](https://www.cnil.fr/fr/reglement-europeen-protection-donnees/chapitre8) (CNIL)
- [Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679) (EUR-Lex)
- [Conformité RGPD : comment informer les personnes et assurer la transparence ? (GDPR compliance: informing individuals and ensuring transparency, in French)](https://www.cnil.fr/fr/conformite-rgpd-information-des-personnes-et-transparence) (CNIL)
- [RGPD : exemples de mentions d’information (GDPR: sample information notices, in French)](https://www.cnil.fr/fr/passer-laction/rgpd-exemples-de-mentions-dinformation) (CNIL)
- [Les bases légales (legal bases, in French)](https://www.cnil.fr/fr/les-bases-legales) (CNIL)
- [Les durées de conservation des données (data retention periods, in French)](https://www.cnil.fr/fr/les-durees-de-conservation-des-donnees) (CNIL)
- [Référentiel relatif aux traitements de données à caractère personnel mis en œuvre aux fins de gestion des activités commerciales (CNIL standard on personal data processing for managing commercial activities, in French)](https://www.cnil.fr/sites/default/files/atoms/files/referentiel_traitements-donnees-caractere-personnel_gestion-activites-commerciales.pdf) (CNIL)
- [Cookies : solutions pour les outils de mesure d’audience (cookies: solutions for audience measurement tools, in French)](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies-solutions-pour-les-outils-de-mesure-daudience) (CNIL)
- [Les sanctions prononcées par la CNIL (sanctions issued by the CNIL, in French)](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil) (CNIL)
- [La procédure de sanction simplifiée (the simplified sanction procedure, in French)](https://www.cnil.fr/fr/la-procedure-de-sanction-simplifiee) (CNIL)
- [Loi n° 78-17 du 6 janvier 1978 (French Data Protection Act, « loi Informatique et Libertés »), art. 22-1 (version in force since 28 May 2026, amended by Loi n° 2026-403 du 26 mai 2026)](https://www.legifrance.gouv.fr/loda/article_lc/LEGIARTI000054142442) (Légifrance)
- [Loi n° 78-17 du 6 janvier 1978 (French Data Protection Act), art. 82](https://www.legifrance.gouv.fr/loda/article_lc/LEGIARTI000037813978) (Légifrance)
- [Code pénal (Criminal Code), art. R625-10](https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000038607906) (Légifrance)
- [Code pénal (Criminal Code), art. 131-13](https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000006417259) (Légifrance)
- [Code pénal (Criminal Code), art. 131-41](https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000006417342) (Légifrance)
- [Loi n° 2004-575 du 21 juin 2004 pour la confiance dans l’économie numérique (LCEN, Law on Confidence in the Digital Economy), art. 1-1](https://www.legifrance.gouv.fr/loda/article_lc/LEGIARTI000049568614) (Légifrance)
- [Code de commerce (Commercial Code), art. L123-22](https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000006219327/) (Légifrance)
- [Mentions obligatoires sur le site internet d’un entrepreneur individuel (mandatory information on a sole trader’s website, in French)](https://entreprendre.service-public.gouv.fr/vosdroits/F31228) (entreprendre.service-public.fr)
- [CJEU, 19 October 2016, Breyer, C-582/14](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0582) (EUR-Lex)
- [Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 (EU-US Data Privacy Framework)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023D1795) (EUR-Lex)
- [Simplification of the digital legislative framework, Digital Omnibus (Omnibus VII), procedure 2025/0360(COD)](https://oeil.europarl.europa.eu/oeil/en/procedure-file?reference=2025/0360%28COD%29) (Parlement européen, Observatoire législatif)
- [Délibération de la formation restreinte n° SAN-2019-001 du 21 janvier 2019 (CNIL restricted committee decision against Google, in French)](https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000038032552/) (Légifrance)
- [RGPD : le Conseil d’État rejette le recours dirigé contre la sanction de 50 millions d’euros infligée à Google par la CNIL (the Conseil d’État upholds the CNIL’s €50 million fine against Google, in French)](https://www.conseil-etat.fr/actualites/rgpd-le-conseil-d-etat-rejette-le-recours-dirige-contre-la-sanction-de-50-millions-d-euros-infligee-a-google-par-la-cnil) (Conseil d’État)
