Loi Informatique et Libertés, GDPR-Aligned Comprehensive Regime (Data Processing, Data Files and Individual Liberties Act)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
A comprehensive regime rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in France, and follow Loi 78-17 Article 6's cross-reference to GDPR Article 9 for any special-category data.
- Expect the CNIL to hold on-site inspection powers under Loi 78-17 Article 19, and to have authority to prescribe measures for biometric-data processing under Article 8.
Who checks it
Audit expectation
on_request
Who audits it
Regulator
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
France gives the General Data Protection Regulation (GDPR) domestic effect through the Loi Informatique et Libertes (Law on Information Technology, Data Files and Civil Liberties), enacted 6 January 1978 and amended for GDPR alignment. Article 6 cross-references Regulation (EU) 2016/679 for the special-category exceptions, Article 8 gives the CNIL authority to prescribe measures for biometric-data processing, and Article 19 sets the CNIL's on-site inspection powers, all confirmed against the consolidated text. Lawful bases follow the GDPR Article 6 list, with no French derogation identified.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.