Law / France

France

European Union law applies in France France is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of France, described on this page below, applies here too.

25 of 32 named instruments researched to a stage, across all six areas of law we track: 21 in force, 1 enacted but not yet in force, 2 proposed and 1 repealed, withdrawn or blocked. As of 13 September 2026.

When they take effect17 of 25 carry a date, 8 do not. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 8 instruments (8 in force) 2019: 2 instruments (2 in force) 2020: 0 instruments ’20 2021: 1 instrument (1 in force) 2022: 0 instruments 2023: 1 instrument (1 in force) 2024: 1 instrument (1 in force) 2025: 2 instruments (2 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 8
  3. Scraping law 2
  4. Cybersecurity law 5
  5. Age gating law 5
  6. News aggregation law 3

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (126 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in France and is not restated here.

France's own layer over it is currently criminal, not administrative: loi n. 2024-449 du 21 mai 2024 visant a securiser et a reguler l'espace numerique (SREN) inserted a new Code penal Article 226-8-1 punishing a non-consensual sexual montage or a non-consensual, algorithmically generated sexual image, video, or audio reproducing a real person's likeness or voice, and separately amended the pre-existing Article 226-8 offense to assimilate a non-consensual, algorithmically generated visual or audio likeness to that same offense and to add its own aggravated tier for online publication.

No French statute or decree has designated the national authorities responsible for market surveillance of the EU AI Act under its Article 70.

AI prohibited practices

Code Pénal Article 226-8 as Amended, Existing Offense Extended to Algorithmically Generated Content

Code penal art. 226-8, tel que modifie par la loi n. 2024-449 du 21 mai 2024 visant a securiser et a reguler l'espace numerique (SREN), art. 15official Journal officiel text of loi n. 2024-449 du 21 mai 2024 (SREN), Legifrance (read through an archived capture of the official page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000049563368

In force. Binds public and private bodies.

What this law does

SREN Article 15 amended the pre-existing Article 226-8 offense, whose first alinea had used the verb 'publier' (to publish) for its prohibited conduct; the amending text itself does not restate that offense's full original description beyond the verb it replaces.

Article 15 replaced 'publier' with 'porter a la connaissance du public ou d'un tiers' (bringing to the knowledge of the public or a third party) and added a sentence assimilating to that same, pre-existing offense, punished identically, a non-consensual, algorithmically generated visual or audio content representing a person's image or words, unless it is obvious that the content is algorithmically generated or this is expressly stated.

It also inserted a new alinea raising the penalty to two years' imprisonment and a 45,000 euro fine where the offense, including the algorithmically generated content this same amendment assimilates to it, is committed through an online public communication service.

What it requires

Code Pénal Article 226-8-1, Non-Consensual Sexual Montage and Algorithmically Generated Sexual Content

Code penal, art. 226-8-1, insere par la loi n. 2024-449 du 21 mai 2024 visant a securiser et a reguler l'espace numerique (SREN), art. 21official Journal officiel text of loi n. 2024-449 du 21 mai 2024 (SREN), Legifrance (read through an archived capture of the official page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000049563368

In force. Binds public and private bodies.

What this law does

Article 226-8-1, inserted after Article 226-8 by SREN Article 21, punishes with two years' imprisonment and a 60,000 euro fine bringing to the knowledge of the public or a third party, by any means, a non-consensual sexual montage made with a person's words or image. The same alinea assimilates to that offense, and punishes identically, a non-consensual, algorithmically generated visual or audio content of a sexual character reproducing a person's image or words.

The penalty rises to three years' imprisonment and a 75,000 euro fine where the montage or the algorithmically generated content is published through an online public communication service. Article 64 of the enacting law, which lists every article whose commencement is delayed, does not name Article 21, and the article carries no commencement clause of its own.

What it requires

Privacy law8 instruments, 8 in force

Research summary (101 words)

France's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by the Loi Informatique et Libertes (Law on Information Technology, Data Files and Civil Liberties, Loi n. 78-17 du 6 janvier 1978).

France adds its own Code penal criminal-offense regime for unlawful processing, the CNIL's own administrative sanctioning procedure, and the most developed biometric-authorization framework surveyed: a binding standard regulation for workplace biometric access control and a facial-recognition policy position.

Every finding here rests on Legifrance and CNIL pages, and a specific named CNIL biometric enforcement decision, for example its Clearview AI matter, is not verified against a primary source.

Biometric privacy

CNIL Standard Regulation on Workplace Biometric Access Control (Deliberation No. 2019-001)

CNIL Deliberation n. 2019-001 du 10 janvier 2019 portant reglement type relatif a la mise en oeuvre de dispositifs de controle d'acces… biometriqueCNIL, Deliberation n. 2019-001 du 10 janvier 2019 (PDF)

In force since 10 January 2019. Binds public and private bodies.

What this law does

CNIL's binding standard regulation for workplace biometric access control (English: Standard Regulation on the Implementation of Biometric Access-Control Devices) replaces the prior authorization regime with an accountability model: the controller must justify necessity and proportionality, run a data protection impact assessment before deployment, and document why a less intrusive alternative was rejected.

A companion CNIL page states the standard regulation's definition of biometrics names fingerprints, iris, facial recognition, gait, and voice as covered modalities, though CNIL's own worked operational guidance emphasizes the physical modalities and carries no voice-specific worked example.

CNIL guidance states that employee consent alone is not a valid legal basis for a workplace biometric system, since workplace hierarchy undermines the General Data Protection Regulation (GDPR)'s freely-given requirement; the employer must rely on a legal obligation or legitimate-interest basis instead, or offer a genuinely equivalent non-biometric alternative where consent is used.

What it requires

Breach notification

GDPR Articles 33-34, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34GDPR Arts. 33-34

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the CNIL within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No France-specific derogation from the General Data Protection Regulation (GDPR) timeline or threshold is identified; treat this as the GDPR-uniform baseline rather than an independently confirmed French addition.

What it requires

Comprehensive regime

Loi Informatique et Libertés, GDPR-Aligned Comprehensive Regime (Data Processing, Data Files and Individual Liberties Act)

Loi n. 78-17 du 6 janvier 1978 relative a l'informatique, aux fichiers et aux libertes, as amended (JORFTEXT000000886460)Legifrance, consolidated text

In force since 25 May 2018. Binds public and private bodies.

What this law does

France gives the General Data Protection Regulation (GDPR) domestic effect through the Loi Informatique et Libertes (Law on Information Technology, Data Files and Civil Liberties), enacted 6 January 1978 and amended for GDPR alignment. Article 6 cross-references Regulation (EU) 2016/679 for the special-category exceptions, Article 8 gives the CNIL authority to prescribe measures for biometric-data processing, and Article 19 sets the CNIL's on-site inspection powers, all confirmed against the consolidated text. Lawful bases follow the GDPR Article 6 list, with no French derogation identified.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

Regulation (EU) 2016/679, Arts. 44-49, 83(5)GDPR Arts. 44-49, 83(5)

In force since 25 May 2018. Binds public and private bodies.

What this law does

A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. A CNIL guidance page lists exactly this toolkit, plus administrative arrangements for public-authority exchanges requiring CNIL authorization, and names no France-specific localization mandate beyond it.

What it requires

Data subject rights

GDPR Article 22, Right Against Automated Individual Decision-Making

Regulation (EU) 2016/679, Art. 22Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Individuals in France have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, unless a contract, explicit consent, or an EU or French law exception applies.

This sits alongside the general General Data Protection Regulation (GDPR) Articles 12-23 rights of access, rectification, erasure, restriction, portability, and objection, all enforceable through the Member State's supervisory authority; France's designated supervisory authority is the CNIL, a designation made by French domestic law rather than by the Regulation text itself.

What it requires

Loi 78-17 Article 47, Automated Administrative Decisions

Loi n. 78-17 du 6 janvier 1978, Art. 47Legifrance, consolidated text (promulgation date only

In force since 6 January 1978. Binds government bodies.

What this law does

Loi 78-17 Article 47 extends an automated-decision explicability duty specifically to French government decisions, beyond General Data Protection Regulation (GDPR) Article 22's own scope. Article 47's own text is not cited at article level. No date specific to Article 47's own insertion or last amendment is established.

The date recorded here is Loi n. 78-17's own promulgation date, 6 January 1978, confirmed against the consolidated text; it is the parent Act's promulgation date, not a confirmed commencement date for Article 47 itself, which almost certainly postdates it given the article's subject matter.

What it requires

Enforcement supervision

CNIL Enforcement, GDPR Article 83 and Code Pénal Articles 226-16 to 226-22-2

Regulation (EU) 2016/679, Art. 83; Code penal, Arts. 226-16 to 226-22-2CNIL, "La loi Informatique et Libertes" and "Les sanctions penales" (regulator commentary)

In force since 25 May 2018. Binds public and private bodies.

What this law does

The CNIL is France's supervisory authority, sanctioning through a formation restreinte or, under a simplified procedure, its president, up to the General Data Protection Regulation (GDPR) Article 83 ceiling.

France separately criminalizes unlawful processing in Code penal Articles 226-16 through 226-22-2 (five years' imprisonment and up to EUR 300,000 for the primary offenses), per CNIL's own regulator commentary; no working Legifrance URL for the codified text of these articles resolves, so the criminal-offense detail rests on CNIL's commentary rather than a direct statute read.

GDPR Article 82 arms an individual with a direct private right of action; France's own collective "action de groupe" mechanism for data-protection claims is not independently confirmed and is not asserted here beyond the Article 82 baseline.

What it requires

Sensitive categories

GDPR Article 9 Special Categories, as Implemented by Loi 78-17 Article 6

Regulation (EU) 2016/679, Art. 9; Loi n. 78-17, Art. 6Legifrance, consolidated text, Loi 78-17 Art. 6

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) lists biometric data processed for unique identification as a special category of personal data. Loi 78-17 Article 6 restates this special-category list with a cross-reference to the Regulation rather than a separate French list, confirmed against the consolidated Legifrance text. No general publicly-available carve-out narrows this coverage in France; only Article 9(2)(e)'s narrow self-disclosure exception applies.

What it requires

Scraping law2 instruments, 2 in force

Research summary (237 words)

France criminalizes unauthorized access to and interference with automated data processing systems through the Code penal's STAD offenses (atteintes aux systemes de traitement automatise de donnees), Articles 323-1 to 323-8, which reach a scraper that defeats an access control or that impairs or corrupts the data or functioning of a system it reaches.

The Code de la propriete intellectuelle grants a sui generis database right at Articles L341-1 to L343-7, transposing the EU Database Directive, letting a producer who shows substantial investment prohibit extraction or re-utilization of a qualitatively or quantitatively substantial part of a database's content, independent of any copyright in its contents.

France's general text-and-data-mining exception, Code de la propriete intellectuelle Article L122-5-3, is researched under this jurisdiction's aggregation topic; its machine-readable opt-out reaches an AI-training scraper the same way it reaches a news aggregator.

No French statute or reported case located this session assigns robots.txt a distinct legal weight, establishes an AI-training-specific scraping rule, or states a scraping-specific browsewrap or clickwrap enforceability rule; ordinary Code civil contract-formation and evidentiary rules govern terms-of-service enforceability generally, and no scraping-specific unfair-competition or misappropriation doctrine distinct from ordinary tort law (Code civil Article 1240, responsabilite civile) was located.

Personal data scraped from a public French website remains subject to the General Data Protection Regulation (GDPR) and Loi n. 78-17 du 6 janvier 1978, researched under this jurisdiction's privacy topic, which carries no general exemption for information the data subject has made public.

Computer misuse

Code pénal STAD Offenses, Unauthorized Access to and Interference with Automated Data Processing Systems

Code penal, art. 323-1 a 323-8 (Chapitre III, Des atteintes aux systemes de traitement automatise de donnees)official consolidated Code penal text, Legifrance (read through an archived capture of the official page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://www.legifrance.gouv.fr/codes/id/LEGISCTA000006149839

In force. Binds public and private bodies.

What this law does

Article 323-1 punishes fraudulently accessing or remaining within all or part of an automated data processing system with three years' imprisonment and a fine of EUR 100,000.

Article 323-2 punishes impairing or falsifying the functioning of such a system, and Article 323-3 punishes fraudulently introducing, extracting, holding, reproducing, transmitting, deleting or altering data within one, each with five years' imprisonment and a fine of EUR 150,000, rising to seven years and EUR 300,000 where the targeted system is a State-operated system processing personal data.

Article 323-1's own penalty rises in the same pattern where the access results in the deletion or alteration of data held in the system. Because the base Article 323-1 offense requires infringing a security measure to gain access, a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision.

Article 323-3-1 separately punishes possessing or supplying a tool or program designed to commit these offenses, Article 323-4 punishes conspiring to commit them, and Article 323-7 punishes an attempt with the same penalties as the completed offense. Article 323-8 exempts measures carried out by authorized state intelligence services for protecting national security interests abroad.

What it requires

Database right

CPI Sui Generis Database Right, Producer's Right to Prohibit Extraction and Reutilization

Code de la propriete intellectuelle art. L341-1 a L343-7 (Titre IV, Droits des producteurs de bases de donnees), created by loi n. 98-536 du 1er juillet 1998, transposing Directive 96/9/CEofficial consolidated Code de la propriete intellectuelle text, Legifrance (read through an archived capture of the official page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://www.legifrance.gouv.fr/codes/section_lc/LEGITEXT000006069414/LEGISCTA000006133329/

In force since 1 January 1998. Binds public and private bodies.

What this law does

A database producer, understood as the person who takes the initiative and the risk of the corresponding investment, holds protection over the database's content where the constitution, verification, or presentation of that content shows a substantial financial, material, or human investment, under Article L341-1.

Article L342-1 lets the producer prohibit extraction, by permanent or temporary transfer of all or a qualitatively or quantitatively substantial part of the database's content onto another medium, and reutilization, by making that content available to the public, whatever the means. The right is independent of any copyright or other right in the database's contents or structure.

Article L343-1 lets a rightholder prove an infringement by any means, including a bailiff's seizure (saisie-contrefacon) with a court-appointed expert.

What it requires

Cybersecurity law5 instruments, 3 in force, 2 proposed

Research summary (607 words)

France's transposition of the NIS2 Directive (Directive (EU) 2022/2555) has not been enacted.

Loi n° 2025-391 du 30 avril 2025, sometimes taken for the transposition, is a different, unrelated statute (Journal officiel n° 0101 du 1er mai 2025), portant diverses dispositions d'adaptation au droit de l'Union européenne en matière économique, financière, environnementale, énergétique, de transport, de santé et de circulation des personnes (an omnibus European Union law adaptation act covering economic, financial, environmental, energy, transport, health and immigration matters); its full text names neither resilience nor cybersecurity nor the NIS directives, and that citation is corrected here.

The actual transposition vehicle, the projet de loi relatif à la résilience des infrastructures critiques et au renforcement de la cybersecurité (transposing the Critical Entities Resilience Directive, NIS2 and the Digital Operational Resilience Act in three titles), passed the Sénat in first reading on 12 March 2025 and had its special committee (commission spéciale) review at the Assemblée nationale conclude on 10 September 2025; as of this writing it has not been debated on the Assemblée nationale floor, has not had a second reading, and has not been promulgated.

Pending its enactment, the predecessor NIS1 transposition, loi n° 2018-133 du 26 février 2018 (Titre Ier), remains in full effect and is the operative regime: it binds an opérateur de services essentiels (operator of essential services, OSE) designated by the Premier ministre in a sector whose continuity could be gravely affected by a network or information system incident, and a fournisseur de service numérique (digital service provider, FSN) operating an online marketplace, an online search engine or a cloud computing service above a small-business threshold, to security measures set by the Premier ministre and to an incident-declaration duty to the Agence nationale de la sécurité des systèmes d'information (ANSSI, the national network and information system security authority under Code de la défense Article L. 2321-1), enforced through criminal fines on a non-compliant operator's own directors rather than through an administrative penalty on the entity itself.

No French instrument reviewed here imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.

France does hold one standalone security-baseline statute reaching a class of digital platform beyond General Data Protection Regulation (GDPR), NIS1 or the Cyber Resilience Act (CRA): loi n° 2022-309 du 3 mars 2022 (the cyberscore law), in force since 1 October 2023, requires a large online platform operator (Code de la consommation Article L. 111-7-3, covering the online marketplace, ranking and comparison operators Article L. 111-7 defines) and a large number-independent interpersonal communications service, above a visitor-count threshold set by decree, to undergo a cybersecurity audit by an ANSSI-qualified provider (a PASSI) and display the result to consumers on a coloured scale; press reporting found the decrees fixing the applicability thresholds and audit criteria delayed past the statute's own commencement date, so the practical reach of the duty as of this writing is not confirmed in the sources reviewed here even though the statute itself is in force.

Personal-data breach notification to the CNIL and to the affected person under GDPR Articles 33 and 34 and loi 78-17 is separate law, already documented in the privacy topic, and sits there rather than here even where one incident triggers both regimes. The French statutory texts here were read from public Internet Archive captures of Legifrance rather than from Legifrance itself, which refuses automated requests with an HTTP 403 at every tier.

A capture states the law as it stood when the copy was made, so a reader checking whether a provision has since been amended should consult Legifrance directly.

Sector security regimes

Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements

Loi n° 2018-133 du 26 février 2018, Titre Ier, Chapitres II et III, art. 5, 6, 10, 11 et 12Journal officiel de la République française n°0048 du 27 février 2018, Loi n° 2018-133

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived June 1, 2024. Publisher's page: https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000036644772

In force since 10 May 2018. Binds public and private bodies.

What this law does

Chapitre II of Titre Ier binds an opérateur de services essentiels (operator of essential services, OSE), public or private, designated by the Premier ministre because it offers a service essential to the functioning of society or the economy whose continuity could be gravely affected by an incident touching the network or information systems it needs to provide that service (Article 5).

Article 6 has the Premier ministre set the applicable security rules, covering governance, protection, defence and resilience of the operator's networks and systems, which the operator applies at its own expense.

Chapitre III imposes the equivalent duty on a fournisseur de service numérique (digital service provider, FSN) operating an online marketplace, an online search engine or a cloud computing service (Article 10), excluding a business with fewer than fifty employees and no more than EUR 10 million in annual turnover (Article 11), and requiring it to identify risks and take technical and organisational measures across systems security, incident management, business continuity, monitoring and audit, and compliance with international standards (Article 12), transposing the original NIS Directive (Directive (EU) 2016/1148).

Titre Ier entered into force from a date fixed by décret en Conseil d'Etat, at the latest 10 May 2018 (Article 25); Décret n° 2018-384 du 23 mai 2018 sets out the security-rule content, the OSE-designation procedure and ANSSI's role implementing this chapter, and Article 25 separately gave the designation of the first OSEs until 9 November 2018.

What it requires

Loi n° 2022-309 du 3 mars 2022 (loi Cyberscore), Cybersecurity Audit and Disclosure Duty

Loi n° 2022-309 du 3 mars 2022, art. 1 (Code de la consommation, art. L. 111-7-3)Journal officiel de la République française n°0053 du 4 mars 2022, Loi n° 2022-309

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived June 1, 2024. Publisher's page: https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000045294275

In force since 1 October 2023. Binds private bodies.

What this law does

Article 1 inserts Article L. 111-7-3 into the Code de la consommation, requiring an online platform operator (opérateur de plateforme en ligne, Article L. 111-7, covering an online marketplace, a ranking or referencing service and a price-comparison service) and a provider of a number-independent interpersonal communications service, above one or more activity thresholds a decree sets, to undergo a cybersecurity audit by a provider qualified by ANSSI (a prestataire d'audit de la sécurité des systèmes d'information, PASSI), covering the security and location of the data it hosts (directly or through a third party) and its own security, and to present the result to the consumer in a legible, clear and comprehensible form using a colour-coded scale, modelled on the Nutri-Score.

A joint order of the ministers responsible for digital affairs and consumer protection, issued after the CNIL's opinion, fixes the audit criteria and the conditions of validity and presentation.

The law entered into force on 1 October 2023 (Article 2); press reporting at the time and since found the decree fixing the applicability thresholds, expected at 25 million unique monthly French visitors for 2024 and 15 million for 2025, delayed past that commencement date, so the practical reach of the duty as of this writing is not confirmed in the sources reviewed here.

What it requires

Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Cybersecurity Risk-Management Measures (NIS2)

Article 14, texte adopté n° 78 (2024-2025), Sénat, 12 mars 2025 (mesures de gestion des risques)Texte adopté n° 78 (2024-2025), Sénat, 12 mars 2025

Proposed: draft date not recorded. Before the second chamber, dated 10 September 2025, as of 12 September 2026. Binds public and private bodies.

What this law does

Article 14 of the text the Sénat adopted in first reading would require an essential entity, an important entity, and a list of named public bodies to take technical, operational and organisational measures appropriate and proportionate to the risks facing the network and information systems they use for their activities or services, covering management-body approval and cybersecurity training, protection of networks and systems (including where a subcontractor is used), incident-handling tools and procedures, and the resilience of activities, transposing NIS2 Article 21.

Articles 8 to 10 designate the essential and important entities this reaches, naming a provider of an online marketplace, an online search engine or a social-networking-services platform among the digital infrastructure and digital providers it covers expressly, a wider list than the predecessor NIS1 transposition's three digital-service categories.

The instrument the corpus previously carried as France's NIS2 transposition, loi n° 2025-391 du 30 avril 2025, is a different, unrelated European Union law adaptation act that does not mention resilience, cybersecurity or the NIS directives; this bill, not that loi, is the actual transposition vehicle.

It passed the Sénat in first reading on 12 March 2025 and had its special committee (commission spéciale) review at the Assemblée nationale conclude on 10 September 2025, without a floor debate, a second reading, or a promulgation recorded since.

What it requires

Vulnerability and incident reporting

Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Incident Notification

Loi n° 2018-133 du 26 février 2018, Titre Ier, art. 7 et 13Journal officiel de la République française n°0048 du 27 février 2018, Loi n° 2018-133

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived June 1, 2024. Publisher's page: https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000036644772

In force since 10 May 2018. Binds public and private bodies.

What this law does

Article 7 requires an opérateur de services essentiels to declare, without delay after becoming aware of it, to ANSSI (the national network and information system security authority under Code de la défense Article L. 2321-1) an incident affecting the networks and information systems necessary to provide its essential services, where the incident has or is likely to have a significant impact on the continuity of those services; the administrative authority may inform the public of the incident after consulting the operator.

Article 13 imposes the equivalent duty on a digital service provider for an incident with a significant impact on the provision of its services in the European Union, and lets the authority require the provider to inform the public itself. Neither article states a fixed reporting clock in hours; the duty runs «sans délai» (without delay) from the operator's or provider's own knowledge of the incident.

What it requires

Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Incident Notification (NIS2)

Article 17, texte adopté n° 78 (2024-2025), Sénat, 12 mars 2025 (notification des incidents)Texte adopté n° 78 (2024-2025), Sénat, 12 mars 2025

Proposed: draft date not recorded. Before the second chamber, dated 10 September 2025, as of 12 September 2026. Binds public and private bodies.

What this law does

Article 17 of the text the Sénat adopted in first reading would require the same essential and important entities Article 14 covers to notify ANSSI without undue delay of any incident with an important impact on the provision of their services, on a graduated clock: an initial notification within 24 hours of becoming aware of it, an intermediate notification within 72 hours updating the initial one and giving an initial assessment of severity and impact, a report on ANSSI's request, and a final report within one month (or, for an incident still being handled, a progress report at one month followed by a final report within one month of resolution), transposing NIS2 Article 23.

A trust-service provider and certain domain-name and registry services named in Articles 8(4) and 9(3) notify within 24 hours rather than 72 for the intermediate notification. ANSSI in turn responds within 24 hours of the initial notification where possible.

What it requires

Age gating law5 instruments, 3 in force, 1 enacted but not yet in force, 1 repealed, withdrawn or blocked

Research summary (259 words)

France requires pornographic websites and video sharing platforms to verify that users are adults under the SREN law of 21 May 2024, which is in effect and enforced by Arcom through a technical référentiel (technical reference framework, Délibération n° 2024-20 of 9 October 2024) and an administrative blocking power that survived a Conseil d'État challenge brought by Hammy Media Ltd (xHamster) in July 2025; the Court of Justice of the EU's 16 June 2026 judgment in WebGroup Czech Republic and NKL Associates (C-188/24) further confirmed that France may impose targeted, proportionate age verification on pornographic services established in other member states.

A separate 2023 law that would require parental authorization for a minor under 15 to open a social media account has never entered into force because its implementing decree, conditioned on a European Commission compatibility response, was never issued.

A 2026 bill that would have banned social media for under 15s completed its passage, but the Conseil constitutionnel struck its operative article in decision n° 2026-911 DC of 14 August 2026 as a disproportionate infringement of freedom of expression and for setting no conditions or limits on the age proof it would have demanded of every user, adults included; the rest of the law was promulgated as Loi n° 2026-813 du 24 août 2026 without it, so France still has no minimum age for social media accounts.

France has no distinct national app store or device level age verification statute, and no binding statutory design code for children, only the CNIL's non-binding 2021 recommendations on protecting minors online.

Adult content age verification (AV)

Arrêté du 26 février 2025 désignant les services établis dans un autre État membre de l'Union européenne soumis aux articles 10 et 10-1 de la loi n° 2004-575 du 21 juin 2004 (Ministerial order of 26 February 2025 designating services established in another EU member state subject to the age verification regime)

Arrêté du 26 février 2025 (ministère de la culture, ministère chargé du numérique), published in the Journal officiel of 6 March 2025official ministerial order (arrêté), published in the Journal officiel via Légifrance

In force since 6 June 2025. Binds private bodies.

What this law does

Extends the LCEN articles 10 and 10-1 age verification and blocking regime to named pornographic websites and video sharing platforms established in other EU member states, including Pornhub, YouPorn and RedTube (Aylo group) and xHamster (Hammy Media Ltd). Signed 26 February 2025, published in the Journal officiel on 6 March 2025, and applicable three months after publication, from 6 June 2025.

Some designated platforms deployed age verification, while the Aylo sites voluntarily blocked access from France in protest rather than comply.

Note and primary source

Délibération n° 2024-20 du 9 octobre 2024 de l'Arcom relative au référentiel technique de vérification de l'âge pour l'accès aux contenus pornographiques (Arcom Deliberation No. 2024-20 of 9 October 2024 on the technical reference framework for age verification for access to pornographic content)

Délibération n° 2024-20 du 9 octobre 2024, published in the Journal officiel of 22 October 2024official Arcom deliberation, published in the Journal officiel via Légifrance

In force since 22 January 2025. Binds private bodies.

What this law does

Sets the minimum technical requirements an age verification system must meet under the SREN law: protection by default so no pornographic content is shown before verification, at least one double anonymity method letting an independent third party such as a bank, mobile operator, or dedicated identity provider confirm a user is an adult without the pornographic site learning the user's identity and without the third party learning which site is being visited, and independent audits.

Adopted after a favorable opinion from the CNIL of 26 September 2024 (délibération n° 2024-067) and published in the Journal officiel on 22 October 2024; covered services had three months from publication (until 22 January 2025) to deploy a compliant system, followed by a further three month transition (until 22 April 2025) during which a card based check was tolerated pending deployment of a double anonymity method.

Note and primary source

Loi n° 2024-449 du 21 mai 2024 visant à sécuriser et réguler l'espace numérique (SREN, Law No. 2024-449 of 21 May 2024 on securing and regulating the digital space), articles 1 and 2 (age verification for access to pornographic content)

Loi n° 2004-575 du 21 juin 2004 pour la confiance dans l'économie numérique (LCEN) art. 10, 10-1 et 10-2, modifiés et créés par la loi n° 2024-449 du 21 mai 2024, art. 1 et 2official law text, Journal officiel via Légifrance

In force since 22 May 2024. Binds private bodies.

What this law does

Requires editors of pornographic websites and video sharing platforms accessible from France to verify that users are adults, using a system that meets a technical référentiel adopted by Arcom after an opinion from the CNIL.

Abrogates the prior judicial blocking mechanism (former article 23 of the law of 30 July 2020) and lets Arcom issue a mise en demeure and then order internet access providers and DNS resolvers to block a noncompliant site directly, without a judge, and have it delisted from search engines.

Note and primary source

Social media and minors

Interdiction d'accès des mineurs de quinze ans aux réseaux sociaux, article 1er de la loi visant à protéger les mineurs des risques auxquels les expose l'utilisation des réseaux sociaux (Under-15 social media ban, article 1 of the law to protect minors from the risks posed by social media use), déclaré contraire à la Constitution

Conseil constitutionnel décision n° 2026-911 DC du 14 août 2026, art. 1er (l'article 1er de la loi visant à protéger les mineurs des risques auxquels les expose l'utilisation des réseaux sociaux est contraire à la Constitution); loi promulguée sans cet article sous le n° 2026-813 du 24 août 2026, JO du 25 août 2026 (ex proposition de loi n° 2107, 17e législature)décision du Conseil constitutionnel

Struck down: invalidated by a court. Binds private bodies.

What this law does

This provision does not bind anyone: it was struck before it could enter the statute book. Article 1 of the bill would have banned access to online social media platforms for minors under 15, by inserting a new section 3 bis (Protection des mineurs en ligne, Protection of minors online) and a new article 6-9 into the law of 21 June 2004.

After the Assemblée nationale and the Sénat agreed a joint text in a commission mixte paritaire (joint committee) on 1 April 2026, more than sixty deputies referred the law to the Conseil constitutionnel on 23 July 2026. In decision n° 2026-911 DC of 14 August 2026 the Conseil held article 1 contrary to the Constitution on two independent grounds.

First, because the ban reached every online platform letting end users connect, communicate, share content and discover other users, without regard to the individual minor's situation or to the risks specific to each service, it was not suitable, necessary or proportionate to the objective pursued, and so infringed the freedom of expression and communication under article 11 of the 1789 Declaration.

Second, because banning under-15s from those services meant that every user, adults included, would have to prove their age, and the legislature set no conditions or limits for that proof, it provided none of the legal guarantees that the right to respect for private life requires. The Conseil raised no question of its own motion about the law's other provisions and did not rule on them.

The remainder of the law was promulgated as Loi n° 2026-813 du 24 août 2026 and published in the Journal officiel (official gazette) on 25 August 2026; what those surviving articles require is not described here, because the Journal officiel text on Légifrance could not be read for this entry. France therefore has no minimum age for social media accounts, and the separate 2023 digital majority law remains without its implementing decree.

Note and primary source

Loi n° 2023-566 du 7 juillet 2023 visant à instaurer une majorité numérique et à lutter contre la haine en ligne (Law No. 2023-566 of 7 July 2023 establishing a digital majority and combating online hate)

Loi n° 2023-566 du 7 juillet 2023, art. 4 (créant l'art. 6-7 de la loi n° 2004-575 du 21 juin 2004) et art. 7 (entrée en vigueur)official law text, Journal officiel via Légifrance

Commencement not set. Binds private bodies.

What this law does

Would require online social network service providers operating in France to refuse registration of a minor under 15 unless a holder of parental authority consents, and to deploy a system verifying age and collecting that consent, with a fine of up to 1 percent of worldwide annual turnover for noncompliance.

Article 7 conditions entry into force on a decree in Conseil d'Etat, issued after a CNIL opinion, that cannot come more than three months after the European Commission confirms the scheme is compatible with EU law. As of this survey no such decree has been published, the European Commission never issued a confirming response, and the article has never entered into force.

Note and primary source

News aggregation law3 instruments, 3 in force

Research summary (250 words)

France was the first EU member state to transpose the Digital Single Market Copyright Directive's press-publisher neighbouring right, through loi n. 2019-775 du 24 juillet 2019, which added Articles L218-1 to L218-5 to the Code de la propriete intellectuelle.

A press publisher's or news agency's authorization is required before any online reproduction or communication to the public of its press publications, and journalists are entitled to an appropriate and fair share of the resulting remuneration.

France's long-standing quotation and press-review exception, Code de la propriete intellectuelle Article L122-5 3°, exempts short analyses and quotations justified by a critical, polemical, pedagogical, scientific, or informational character, and press reviews, provided the author's name and source are clearly indicated; it predates and sits alongside the 2019 neighbouring right rather than being amended by it.

A separate text-and-data-mining exception, Article L122-5-3, created by ordonnance n. 2021-1518 du 24 novembre 2021, permits reproduction for text and data mining subject to an express, machine-readable rightholder opt-out, alongside a narrower, non-waivable exception for research organizations, public-access libraries, museums, and archives.

France has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act; disputes over the Article L218-2 authorization are resolved through ordinary civil litigation and, since 2019, direct negotiation overseen by the Autorite de la concurrence, which fined Google in 2021 and 2024 for failing to negotiate in good faith with French publishers under this regime. No hot-news or misappropriation doctrine distinct from ordinary unfair-competition law is confirmed for France.

Press publishers' right

CPI Articles L218-1 to L218-5, Press Publisher and News Agency Neighbouring Right

Code de la propriete intellectuelle art. L218-1 a L218-5 (Livre II, Chapitre VIII, Droits des editeurs de presse et des agences de presse), created by loi n. 2019-775 du 24 juillet 2019 tendant a creer un droit voisin au profit des agences de presse et des editeurs de presse, art. 4official consolidated Code de la propriete intellectuelle text, Legifrance (read through an archived capture of the official page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://www.legifrance.gouv.fr/codes/section_lc/LEGITEXT000006069414/LEGISCTA000038826677/

In force since 24 July 2019. Binds private bodies.

What this law does

A press publication, defined at Article L218-1 as a collection composed mainly of literary works of a journalistic nature, which may also include other protected works such as photographs or video, requires the authorization of the press publisher or news agency before any total or partial reproduction or communication to the public of that publication in digital form by an online public communication service, per Article L218-2.

Article L218-3 lets the publisher assign the right or license it, including through a collective-management body. Article L218-4 bases the remuneration owed on revenue from the exploitation of the publication of every kind, direct or indirect, or a flat assessment where that cannot be established. Article L218-5 entitles professional journalists and other authors whose work appears in the covered publications to an appropriate and fair share of that remuneration.

The effective date recorded here is the enacting law's own promulgation date; a commencement provision specific to this chapter is not confirmed in the primary text read.

Note and primary source

Snippet reproduction

CPI Article L122-5 3°, Quotation and Press-Review Exception

Code de la propriete intellectuelle, art. L122-5 3°official consolidated Code de la propriete intellectuelle text, Legifrance (read through an archived capture of the official page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://www.legifrance.gouv.fr/codes/section_lc/LEGITEXT000006069414/LEGISCTA000006161637/

In force. Binds public and private bodies.

What this law does

Once a work has been disclosed, its author cannot prohibit, provided the author's name and source are clearly indicated, analyses and short quotations justified by the critical, polemical, pedagogical, scientific, or informational character of the work into which they are incorporated, or press reviews, per Article L122-5 3°(a) and (b).

This general exception is not scoped to news aggregation specifically and is not conditioned on the 2019 neighbouring right created at Articles L218-1 to L218-5; it predates that right and continues to apply alongside it. No amendment date specific to paragraph 3° itself was confirmed this session; the article as a whole carries a 2021 modification note not attributed here to this paragraph without confirmation.

Note and primary source

Text and data mining (TDM) opt-out

CPI Article L122-5-3, Text and Data Mining Exception

Code de la propriete intellectuelle, art. L122-5-3, created by ordonnance n. 2021-1518 du 24 novembre 2021, art. 1official consolidated Code de la propriete intellectuelle text, Legifrance (read through an archived capture of the official page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000044363192

In force since 26 November 2021. Binds public and private bodies.

What this law does

Article L122-5-3.I defines text and data mining as implementing an automated analysis technique on digital text and data to extract information such as patterns, trends, and correlations, for the purposes of Article L122-5's 10° exception.

Paragraph II lets research organizations, public-access libraries, museums, archives, and film, audiovisual, or sound heritage institutions, or others acting on their behalf and at their request including under a nonprofit partnership with private actors, reproduce a lawfully accessed work for text and data mining carried out solely for scientific research, without the author's authorization.

Paragraph III separately lets any person reproduce a lawfully accessed work for text and data mining regardless of its purpose, unless the author has appropriately objected, including by machine-readable means, for content made available online. An indexing or training use that respects a rightholder's machine-readable opt-out under paragraph III falls outside the exception and requires authorization.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.