CNIL Enforcement, GDPR Article 83 and Code Pénal Articles 226-16 to 226-22-2
Regulation (EU) 2016/679, Art. 83; Code penal, Arts. 226-16 to 226-22-2
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
An enforcement supervision rule binding public and private bodies.
As of 2 September 2026.
What it requires
- Expect the CNIL to have General Data Protection Regulation (GDPR) Article 83 fining power, plus France's own criminal-offense exposure under Code penal Articles 226-16 to 226-22-2 for unlawful processing.
- Expect any person in France who suffered material or non-material damage from an infringement to have a direct GDPR Article 82 right to compensation from you as controller or processor.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Code penal Articles 226-16 to 226-24 (Chapitre VI, Section 5, Des atteintes aux droits de la personne resultant des fichiers ou des traitements informatiques) create a family of criminal offences for personal-data processing, layered on top of, and independent from, the CNIL's GDPR Article 83 administrative fines. The standard maximum, which applies to most offences in this family including Article 226-16 (processing personal data, including by negligence, without complying with the legally required prior formalities), Article 226-19 (unlawfully recording sensitive personal data such as racial or ethnic origin, political, philosophical or religious opinions, trade union membership, health, sexual orientation or gender identity, or offence and conviction data), Article 226-20 (unlawful retention beyond the authorised period), and Article 226-21 (misuse of data outside its declared purpose), is five years' imprisonment and a fine of EUR 300,000. Article 226-22 (unlawfully disclosing personal data whose disclosure would harm the data subject's reputation or privacy) carries the same five-year, EUR 300,000 maximum for an intentional disclosure, reduced to three years and EUR 100,000 where the disclosure was merely reckless or negligent, and is prosecutable only on the victim's own complaint. Article 226-22-2 separately punishes obstructing the CNIL's own investigative action with up to one year's imprisonment and a EUR 15,000 fine. A corporate defendant faces the amende under Code penal Article 131-38 plus the additional penalties listed in Article 131-39(2) to (5) and (7) to (9), per Article 226-24.
Penalty structure
GDPR Article 83(5) sets the higher administrative-fine tier the CNIL applies, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher, for the gravest infringement categories (basic processing principles including Articles 5 to 9, the Article 12 to 22 data-subject rights, and the Chapter V transfer rules). The narrower Article 83(4) tier, up to EUR 10,000,000 or 2 percent, applies instead to the Article 25 to 39 controller and processor obligations. France has not been found to narrow or replace this EU-wide ceiling for private-sector processing; Code penal Articles 226-16 to 226-22-2 layer separate CRIMINAL fines on top of, not instead of, the CNIL's administrative fine, and are recorded under criminal_exposure_note rather than here.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Commission Nationale de l'Informatique et des Libertes (CNIL), France's independent supervisory authority for data protection under the GDPR and Loi n. 78-17 du 6 janvier 1978 (Loi Informatique et Libertes, as amended). The Code penal Articles 226-16 to 226-22-2 criminal offences are prosecuted separately, through the ordinary French criminal courts, rather than by the CNIL directly; several of those offences (Article 226-22-2, and the aggravated form of Article 226-16) are engaged specifically by interference with the CNIL's own supervisory work.
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The CNIL is France's supervisory authority, sanctioning through a formation restreinte or, under a simplified procedure, its president, up to the General Data Protection Regulation (GDPR) Article 83 ceiling.
France separately criminalizes unlawful processing in Code penal Articles 226-16 through 226-22-2 (five years' imprisonment and up to EUR 300,000 for the primary offenses), per CNIL's own regulator commentary; no working Legifrance URL for the codified text of these articles resolves, so the criminal-offense detail rests on CNIL's commentary rather than a direct statute read.
GDPR Article 82 arms an individual with a direct private right of action; France's own collective "action de groupe" mechanism for data-protection claims is not independently confirmed and is not asserted here beyond the Article 82 baseline.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
Read the law
CNIL, "La loi Informatique et Libertes" and "Les sanctions penales" (regulator commentary)
GDPR Art. 83
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.