France

Nine Eyes member and Europol, Schengen and Prüm participant bound by the Budapest and 1959 assistance conventions, running algorithmic “black box” surveillance and DGSE bulk access at Europe’s largest submarine-cable hub

← Back to Privacy Law Directory

Overview

EU Member State: France is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page. This page covers national laws, intelligence and surveillance, and France’s role in international data sharing.

France was the first European country to enact comprehensive data protection legislation (Loi Informatique et Libertés, 1978) and the first EU country to authorise algorithmic “black box” scanning of communications metadata for intelligence purposes. Following the 2015 Paris attacks, France enacted broad surveillance legislation granting intelligence agencies some of the widest powers in Western Europe. The CNIL imposed EUR 486.8 million in fines in 2025 alone (including EUR 325M against Google and EUR 150M against Shein), while intelligence agencies surveilled 24,308 persons across 98,883 technique authorisations in 2024.[1][2]

France is a Nine Eyes member with a bilateral SIGINT agreement with the NSA codenamed Lustre, and a Maximator alliance member (joined 1985). Marseille is Europe’s largest submarine cable hub (17+ systems), where DGSE conducts bulk cable interception under Article L.854-1 with no CNCTR prior opinion required.[3][4]

France’s outward data-sharing runs through its alliances and treaties, each detailed below. Beyond the Nine Eyes and Maximator signals-intelligence alliances, France is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks (it was an original 2005 Prüm signatory) and to Europol, and holds a bilateral mutual legal assistance treaty with the United States (1998) alongside numerous bilateral judicial-cooperation conventions with Francophone and Maghreb states; even absent a convention, French authorities may assist on a reciprocity basis. These are the channels through which the domestic protections described below are, in practice, bypassed.[45]

International Data Sharing Agreements

Mutual Legal Assistance: Layered Framework

EU instruments: As an EU member state, France cooperates with the other 26 EU states through the EU Mutual Legal Assistance Convention (2000) and the European Investigation Order. It belongs to the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland), with real-time SIS alerts.[42] France was an original Prüm Convention signatory (2005); the Prüm framework now binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland) in automated DNA, fingerprint, and vehicle-data exchange, and Prüm II (2024) adds facial images and police records.[43]

European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): With its Additional Protocols, this Council of Europe instrument has 51 parties as of July 2026: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[40]

Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): France is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[41]

Bilateral MLAT with the United States: A France-US mutual legal assistance treaty (signed December 10, 1998) supplements the conventions; the Ministry of Justice is France’s central authority, with roughly 10-month average processing times.[20][45]

Bilateral judicial-cooperation conventions: France maintains numerous bilateral MLA and judicial-cooperation conventions with Francophone and Maghreb states and other former colonial territories across Africa, the Middle East, and Southeast Asia, supplementing the multilateral conventions above. France does not publish a single consolidated list; the complete country-by-country set is searchable in the Ministry for Europe and Foreign Affairs treaty database (Base des traités et accords). Even where no convention applies, French authorities may grant assistance on a reciprocity basis.[45]

French Blocking Statutes

Modernised 2022, designed to protect against unilateral US law enforcement requests. However, they apply only to unilateral requests and do not prevent data sharing through MLATs, the EU-US Umbrella Agreement, Nine Eyes channels, or EU frameworks like SIS II and Prüm. The result: blocking statutes provide limited practical protection against the web of multilateral data sharing frameworks.[21]

Nine Eyes Intelligence Sharing

Under the Lustre agreement, DGSE exchanges raw SIGINT with the NSA. The Nine Eyes framework creates reciprocal bypass: French intelligence can collect on Five Eyes persons and share back; partner agencies can collect on French persons and share with French intelligence, bypassing CNIL oversight and French judicial warrants.[22]

EU and Multilateral Frameworks

SIS II: Real-time query and alerts across Schengen. EU-US Umbrella Agreement: French citizens get judicial redress before US courts. SWIFT/TFTP: International wire transfers subject to US Treasury subpoena. PNR: Passenger data for France-US flights. Interpol I-24/7 (195 countries). Egmont Group: Tracfin shares financial intelligence across 164+ FIUs.

Europol

As an EU member state, France is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so French person data flowing through Europol is reachable onward.[44]

The Privacy Backdoor Effect

Despite GDPR enforcement by CNIL and French blocking statutes, international agreements create alternative access:

SIGINT Seniors of the Pacific (SSPAC)

France joined SIGINT Seniors of the Pacific (SSPAC) in 2013, giving it a seat in the NSA-led Asia-Pacific counterterrorism SIGINT coalition despite standing outside the Five Eyes. The ten members are the Five Eyes (the United States, the United Kingdom, Canada, Australia, and New Zealand) plus France, India, Singapore, South Korea, and Thailand, sharing counter-terrorism intelligence over the CRUSHED ICE secure network, so French SIGINT cooperation with the NSA runs through SSPAC and the Fourteen Eyes (SIGINT Seniors Europe) simultaneously.[47]

Club de Berne and the Counter Terrorism Group

France’s DGSI takes part in the Club de Berne (founded 1969), the forum of the heads of the domestic intelligence and security services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland. The Club is a broad, all-source intelligence-sharing body, not a counterterrorism-specific one; its separate offshoot, the Counter Terrorism Group (CTG), created in September 2001, shares terrorism intelligence among the same services plus the United Kingdom and has run a joint operational platform in The Hague with a common database and real-time information system since 2016.[48]

Surveillance and Intelligence

Intelligence Act 2015

Passed after the Charlie Hebdo attack. Authorises targeted interception, real-time geolocation, IMSI catchers, microphones and cameras in private spaces, computer intrusion, and bulk metadata analysis. Algorithmic “black boxes” allow automated devices at data centres and telecom networks to detect communications patterns matching terrorist selectors. France was the first EU country to authorise this. The CNCTR’s 2024 report noted computer data collection more than doubled over five years.[1][7]

CNCTR Oversight

The CNCTR (Commission nationale de contrôle des techniques de renseignement) provides prior opinions before surveillance authorisation, but these are not binding; the Prime Minister may override with written justification. 2024: 24,308 persons surveilled, 98,883 technique authorisations (+3%). Counterterrorism: 30% of monitored persons, 39.3% of technique requests.[7]

International Electronic Communications Law (November 2015)

Governs surveillance of communications “emitted from or received abroad” with significantly reduced oversight: CNCTR prior opinion not required; international communications may be intercepted in bulk. Retention: content 1 year after first exploitation (max 4 years; 8 years for encrypted content); metadata up to 6 years. Internet routing means many nominally domestic French communications transit foreign servers and qualify as “international.”[8]

SILT Law 2017: Permanent Emergency Powers

Formally ended the state of emergency while permanently incorporating key emergency powers: administrative security perimeters, closure of places of worship, house visits with judicial authorisation, and MICAS (individual surveillance measures including municipality restriction, daily police check-ins, passport confiscation, electronic bracelet monitoring for up to one year, with no requirement to disclose evidence). These powers have been repeatedly renewed.[9]

Intelligence Agencies

DGSI: Domestic intelligence (counterterrorism, counterintelligence, economic protection), under Ministry of Interior.

DGSE: Foreign intelligence and SIGINT, under Ministry of Defence. Contains the Direction Technique (DT) handling signals intelligence (ROEM), operating overseas CRE stations spanning the Mediterranean, Africa, and the Middle East.[10]

Nine Eyes and Maximator

The Nine Eyes comprises the Five Eyes (Australia, Canada, New Zealand, the United Kingdom, and the United States) plus Denmark, France, the Netherlands, and Norway. France maintains a bilateral SIGINT agreement with the NSA codenamed Lustre, exchanging raw SIGINT data. As a third-party partner, France is not exempt from NSA collection. Operation Dunhammer confirmed NSA surveillance of senior French officials via Danish cables.[22][3][11]

Maximator, a separate European signals-intelligence alliance kept secret from 1976 until 2020, has five members: Denmark, France, Germany, the Netherlands, and Sweden. France joined in 1985 (the fifth member). DGSE’s Direction Technique contributes cryptanalytic capabilities to the encryption-defeat cooperative. Germany’s Maximator membership connected the alliance to Operation Rubicon (CIA-BND co-ownership of Crypto AG).[12]

Commercial Surveillance Procurement

Palantir/DGSI: France renewed its DGSI intelligence contract with Palantir through 2025. As a US company subject to the CLOUD Act, the contract raises concerns about US access to French intelligence data bypassing bilateral frameworks.[13]

Pegasus: In July 2021, the Pegasus Project revealed that phone numbers associated with French President Macron, members of his government, and journalists appeared on an NSO Group target list. France launched an investigation, and the DGSE reportedly explored but did not procure Pegasus.[14]

Internet Infrastructure and Cable Surveillance

Marseille: Europe’s Largest Submarine Cable Hub

Marseille hosts at least 17 submarine cable systems including SEA-ME-WE 3/4/5/6, AAE-1, ACE, IMEWE, and 2Africa (Meta’s 45,000 km system). The majority of Europe-Asia and Europe-Africa internet traffic passes through Marseille, making it Europe’s primary cable chokepoint.[15]

DGSE Cable Access (Article L.854-1)

The International Electronic Communications Law provides the legal basis for DGSE bulk interception of all communications “emitted from or received abroad” at cable landing stations and IXPs, with no CNCTR prior opinion required. Combined with algorithmic black box capabilities, this gives DGSE extensive collection access at one of Europe’s most concentrated cable chokepoints.[8]

France-IX and Orange Marine

France-IX: ~500 members, largest French IXP, with exchanges in Paris and Marseille. Orange Marine (former state-owned France Télécom subsidiary) operates 7 cable ships averaging ~50 maintenance operations/year, giving France operational knowledge of cable routing and infrastructure directly relevant to SIGINT collection.[16][17]

Recent Developments

Narcotrafficking Law Surveillance Provisions Struck Down (June 2025): The Conseil constitutionnel struck down Article 15 (extending algorithmic black boxes from counterterrorism to drug trafficking) as disproportionate, along with provisions for direct intelligence access to tax databases. An encryption backdoor provision was separately rejected by the National Assembly. AVS (algorithmic video surveillance) extension to 2027 was also censured. France has no operative statutory basis for AI video surveillance as of early 2026.[23]

Ghost Participant Encryption Backdoor Rejected (March 2025): The National Assembly rejected requiring messaging platforms to allow hidden law enforcement access to encrypted chats. France’s existing authorities (including device-based spyware) already provide lawful access to encrypted content.[18]

Algorithmic Video Surveillance: Olympics Experiment Expired (March 2025): The 2023 Olympic AVS authorisation expired March 31, 2025. Police pushed for permanence; CNIL warned of a “ratchet effect.” The push to extend via transport security law was censured by the Conseil constitutionnel in April 2025.[24]

Chat Control: France generally supports the EU CSA Regulation. The November 2025 Council general approach dropped mandatory encrypted scanning but preserved “high-risk” service mitigation measures. However, the EU Parliament rejected the voluntary scanning extension on March 26, 2026 (311–228), and the ePrivacy derogation expired April 3, 2026.[25]

CNIL Enforcement (January 2026): The CNIL fined FREE MOBILE €27M and FREE €15M (January 13) for data security failures affecting 24 million subscriber contracts including IBANs. Separately, France Travail received a €5M fine (January 22) for failing to secure job seekers’ data, where identified security measures were documented in impact assessments but never implemented. The CNIL’s 2025 sanctions totalled a record €486.8 million.[29]

NIS2: Loi Résilience (still not voted, July 2026): France’s NIS2 transposition law (Loi relative à la résilience des infrastructures critiques) missed the projected Q1 2026 adoption and then missed July as well. The National Assembly Special Committee adopted its text in September 2025, leaving only the final vote in séance publique, which has still not been scheduled. Parliament was convened in extraordinary session by decree from July 1, 2026, sitting through the week of July 20, with roughly thirty texts on the agenda; the resilience bill is not among them, and the word “cyber” does not appear in the convening decree at all. The Digital Minister, Anne Le Hénanff, now says she hopes the text will be examined in September 2026. The law packages NIS2 with the Critical Entities Resilience (CER) and DORA transpositions and will bring approximately 15,000 entities into scope.[30][37]

The transposition deadline was October 17, 2024. France is now more than twenty months past it, and on July 9, 2026 the European Commission referred France to the Court of Justice of the European Union over the failure, together with Ireland, Spain, and the Netherlands, asking the Court to impose a lump sum and ongoing daily financial penalties until each state notifies full transposition.[38] The cause of the delay is not parliamentary congestion but a single contested clause. The Commission supérieure du numérique et des postes attributes the blockage to article 16 bis, introduced in the Senate to write protection of encryption into law and to prohibit the imposition of backdoors on messaging services, which the government opposes. In February 2026 the two presidents of the Assembly’s special committee publicly accused the DGSI of holding up the entire bill to kill that article; committee president Philippe Latombe, who authored the amendment sanctuarising end-to-end encryption, said plainly that “the DGSI and the services want the end of article 16 bis.” ANSSI director-general Vincent Strubel framed the impasse without resolving it, saying France faces “two imperatives of equal value,” privacy and national security, and that in the end the legislature will have to make “a choice among several bad solutions.” The practical result is that France’s cybersecurity transposition is hostage to its encryption policy, and neither has moved.[37][34]

CNIL Designated as AI Act Authority: As of February 2026, the CNIL is the national supervisory authority for the EU AI Act in France, with power to sanction prohibited practices and audit transparency of high-risk AI systems.[30]

Paris Court Compels VPN Providers to Block Sites: In seven simultaneous rulings, the Paris Judicial Court ordered ISPs, VPN providers, and DNS resolvers (including ProtonVPN, CyberGhost, and ExpressVPN) to block access to 35 sports-piracy domains on petition from the Ligue de Football Professionnel. The orders are dynamic (Arcom may add new domains during the order’s life) and run until June 21, 2026. This is the first time French courts have directly conscripted VPN providers into a national content-blocking regime, marking a structural shift from pure ISP-level filtering. ProtonVPN and others have publicly opposed compliance as inconsistent with their no-log architecture and EU fundamental-rights protections.[31]

Arcom Automated Real-Time Piracy Blocking System: Arcom has announced plans to deploy an automated, real-time IPTV blocking system within six months, modelled on the UK and Italian regimes. The plan explicitly identifies VPNs and alternative DNS providers as priority targets, citing data that 66% of users accessing pirated content rely on these tools. Arcom is seeking voluntary cooperation first; if providers refuse, Arcom is asking the legislature for coercive powers to compel compliance.[32]

Operation Saffron, France co-leads First VPN takedown (May 2026): France, with the Netherlands and support from Europol, Eurojust, and Bitdefender, led Operation Saffron (May 19–20, 2026), dismantling the criminal anonymisation service “First VPN” used by 25+ ransomware groups since 2014. Authorities seized 33 servers across 27 countries and obtained the service’s complete user database of 5,000+ accounts, with intelligence on hundreds of users shared across partner states. The case underscores France’s central role in EU cooperative takedowns and the cross-border circulation of seized VPN subscriber data.[35]

Privacy Framework

The CNIL (Commission nationale de l’informatique et des libertés), one of the world’s oldest DPAs, issued the first major GDPR fine (Google EUR 50M, January 2019). In 2025, 83 sanctions totalling EUR 486.8M, a nine-fold increase over 2024. Google alone has been fined EUR 625 million across four CNIL actions. 2025 budget: EUR 30.6M; 301 FTE staff; 17,772 complaints (2024). The Loi Informatique et Libertés (1978, as amended) supplements the GDPR with specific provisions on national security processing, public sector data, and health research.[5][6]

Cryptography

Domestic encryption use is unrestricted. Compelled decryption: up to 3 years imprisonment and EUR 270,000 for refusing judicial decryption orders (higher for terrorism/organised crime). In March 2025, the National Assembly rejected a “ghost participant” proposal that would have forced messaging platforms to allow hidden law enforcement access to encrypted chats. An encryption backdoor provision in the Narcotrafficking Law (requiring platforms to provide decrypted messages within 72 hours) was also rejected, with Signal threatening to withdraw from France.[18]

Data Retention

The Council of State validated generalized retention of connection data, ruling that the national security threat justifies it while requiring periodic government reassessment. Intelligence can retain metadata up to 6 years. The national security justification has been continuously reaffirmed since 2015 with no reduction in retention obligations.[19]

Age Verification: Identity Infrastructure as Surveillance

France has implemented mandatory age verification for online pornography (effective January 11, 2025, Law 2024-449). Platforms must implement digital ID verification, biometric analysis, or document checks; simple “I am 18” declarations are explicitly insufficient. Enforcement authority Arcom can impose fines up to EUR 150,000 or 2% of worldwide turnover. In February 2025, the scope was extended to 17 services in other EU member states, asserting French jurisdiction over non-French platforms.[26]

France’s “double anonymity” principle attempts to separate identity from content: the site does not know the user’s identity, and the verification provider does not know which sites the user visits. However, any age verification system necessarily creates metadata linking an individual to age-restricted content access at a specific time. The infrastructure required (centralised verification services, government-approved identity checks, platform integration) creates a surveillance-capable architecture that could be repurposed beyond its original scope. A CJEU referral (March 2024, Advocate General opinion September 2025) may determine whether France’s extraterritorial enforcement is compatible with the e-Commerce Directive’s country-of-origin principle.[27]

France’s parliament gave final approval to a social media ban for under-15s on July 21, 2026, making France the first European Union country to pass a blanket ban on the platforms (following Australia’s under-16 ban, in force since December 2025). The National Assembly first passed the bill on January 27, 2026 (130–21), but the two chambers then deadlocked for months over scope, and the European Commission found that the latest version overlapped with the EU Digital Services Act. A joint committee (commission mixte paritaire) agreed an amended compromise text on July 20, which the Senate adopted 243–2 and the National Assembly 279–81 the next day. The final text drops the Senate’s proposed blacklist-plus-parental-consent model in favour of a blanket ban on social networks (Facebook, Snapchat, TikTok, YouTube) for under-15s, with the digital minister to publish the list of covered services and carve-outs for online encyclopedias, educational and scientific directories, and open-source platforms. Platforms must run age verification approved by the CNIL; new accounts are barred from September 1, 2026, and existing accounts must be age-verified from January 1, 2027, with under-15 accounts suspended from that date. The law also extends the existing school phone ban to high schools. It is not yet in force: a group of 60 lawmakers has referred the law to the Conseil constitutionnel, arguing that it disproportionately restricts minors’ freedom of expression, ignores age, maturity, and parental authority, and violates the right to privacy by making age verification mandatory for everyone accessing social media, and a mandatory EU notification period runs to around August 10, 2026, so Macron’s targeted September start could slip. Combined with the pornography verification mandate, France is building one of the most extensive government-mandated age verification infrastructures in any democracy, creating identity verification touchpoints across the internet that did not previously exist.[28][39][46]

EU Age Verification Blueprint Pilot: France is one of seven Member States piloting the EU-wide Age Verification Solution (alongside Denmark, Greece, Italy, Spain, Cyprus, and Ireland), with plans to integrate the app into the national EUDI Wallet. The Commission released the enhanced second version of the blueprint on October 10, 2025; on April 15, 2026, von der Leyen announced the EU-level system was “technically ready,” and the seven pilot states are integrating it into their national digital identity wallets. The pilot architecture uses a zero-knowledge proof track intended to confirm age brackets without disclosing identity to the relying party.[33] France is also one of five EU countries (with Estonia, Ireland, Spain, and Italy) where Google announced a summer-2026 Google Wallet rollout of passport-based digital IDs and age credentials via its Credential Manager API, raising the prospect that a single US platform becomes the de facto holder of age-verification data even as France defends its own SREN-law mandate before the CJEU. See the European Union page for the broader critique of Google’s positioning as the age-assurance gatekeeper.[36]

Pending Legislation

Sources

[1] Légifrance: Intelligence Act 2015 – Algorithmic black boxes, authorised techniques, Code of Internal Security
[2] CNIL: Sanctions Statistics – EUR 486.8M in 2025, EUR 55M in 2024, 83 sanctions
[3] The Guardian: France’s NSA – Lustre Agreement – Nine Eyes, bilateral SIGINT partnership
[4] Submarine Cable Map – Marseille 17+ cable systems, Europe’s largest hub
[5] CNIL: At a Glance – Independence, 18-member College, oldest DPA
[6] CNIL: 2024 Annual Report – EUR 30.6M budget, 301 FTE, 17,772 complaints
[7] CNCTR: Annual Reports – 24,308 persons, 98,883 authorisations, computer data collection doubled
[8] International Electronic Communications Law (November 2015) – Article L.854-1, bulk interception, no CNCTR prior opinion, 6-year metadata retention
[9] Amnesty International: France SILT Law (2017) – Permanent emergency powers, MICAS, no evidence disclosure
[10] Wikipedia: DGSE – Direction Technique, ROEM, CRE stations
[11] Wikipedia: Operation Dunhammer – NSA surveillance of French officials via Danish cables
[12] Bart Jacobs: Maximator (2020) – France joined 1985, encryption-defeat cooperative
[14] Amnesty: Pegasus Project – Macron, French officials on target list
[15] Submarine Cable Map – Marseille hub: SEA-ME-WE 3/4/5/6, AAE-1, ACE, IMEWE, 2Africa
[16] France-IX – ~500 members, Paris and Marseille exchanges
[17] Orange Marine – 7 cable ships, ~50 maintenance operations/year
[19] Conseil d’État: Data Retention – Generalized retention validated, periodic reassessment
[20] DOJ Office of International Affairs – France-US MLAT
[21] French Blocking Statutes (2022) – Limited to unilateral requests, bypassed by MLATs and EU frameworks
[22] Privacy International: Five Eyes / Nine Eyes – Reciprocal surveillance bypass, warrant bypass
[23] Conseil constitutionnel: Decision 2025-885 DC (June 12, 2025) – Narcotrafficking Law Art. 15 struck down, tax database access censured
[24] CNIL: Algorithmic Video Surveillance “Ratchet Effect” Warning – Olympics AVS expired, permanence push, CNIL concerns
[26] Arcom: Age Verification for Pornographic Content – Law 2024-449, mandatory verification January 2025, double anonymity, EUR 150K/2% penalties, extraterritorial enforcement to 17 EU services
[27] CJEU: Case C-348/24 (French Age Verification Referral) – Conseil d’État referral March 2024, AG opinion September 2025 on e-Commerce Directive compatibility
[28] France 24: MPs Adopt Social Media Ban for Under-15s (January 27, 2026) – 130–21 vote, age verification mandate, parental consent
[29] CNIL: Data Breach – FREE MOBILE and FREE Fined €42 Million (January 13, 2026) – 24 million subscriber contracts, IBANs exposed; France Travail €5M (January 22); 2025 sanctions totalled €486.8M
[30] Copla: NIS2 France Implementation (2026) – Loi Résilience expected Q1 2026; ANSSI décrets Q2 2026; ~15,000 entities; CNIL designated AI Act authority
[31] TorrentFreak: Paris Court Issued Simultaneous Site-Blocking Orders Against ISPs, DNS Resolvers and VPNs – Seven simultaneous Paris Judicial Court rulings; LFP petition; ProtonVPN, CyberGhost, ExpressVPN ordered to block 35 sports-piracy domains; dynamic orders running until June 21, 2026; first French court conscription of VPN providers into national blocking regime
[32] TorrentFreak: Automated Real-Time Pirate IPTV Blocking in France “Within Six Months” – Arcom automated blocking system modelled on UK and Italian regimes; VPNs and alternative DNS providers identified as priority targets; 66% of pirate-content users rely on these tools; Arcom seeking coercive powers
[33] European Commission: European Age-Verification App to Keep Children Safe Online (April 15, 2026) – Seven pilot Member States (France, Denmark, Greece, Italy, Spain, Cyprus, Ireland) integrating the EU Age Verification Solution into national EUDI Wallets; second-version blueprint published October 10, 2025; zero-knowledge-proof age-bracket attestation; cross-border issuance and acceptance via EU coordination mechanism
[34] Village de la Justice: Loi Résilience (NIS2/CER): Sanctuarisation du chiffrement (article 16 bis) – Analysis of the Loi Résilience encryption-protection clause (article 16 bis) and the tension with intelligence services seeking access to encrypted data without the consent of authors or recipients; bill in National Assembly
[35] Help Net Security: Authorities Dismantle First VPN, Used by Ransomware Actors (May 21, 2026) – Operation Saffron (May 19–20, 2026) led by France and the Netherlands with Europol, Eurojust, and Bitdefender; 33 servers seized across 27 countries; complete user database of 5,000+ accounts obtained; intelligence on 506 users shared with partner countries
[36] Biometric Update: Google Expands Wallet with Digital IDs and Age Credentials in EU (June 2026) – Money 20/20 Europe announcement; summer-2026 Google Wallet rollout across Estonia, Ireland, Spain, France, and Italy; passport scan creates a digital pass; Credential Manager API age credentials integrated into Android and Chrome
[37] Next: Cybersécurité, la transposition de NIS2 continue de traîner des pieds (June 16, 2026) – Transposition deadline was October 17, 2024; special-committee text adopted September 2025, séance publique vote never scheduled; extraordinary session convened by decree from July 1, 2026 through the week of July 20 with ~30 texts, none on cybersecurity (the word “cyber” is absent from the decree); Commission reported to be preparing a CJEU referral against France, with Spain, Ireland and the Netherlands also untransposed; CSNP attributes the blockage to article 16 bis (encryption protection, backdoor prohibition), opposed by the government; February 2026 accusation by the special committee’s presidents that the DGSI is blocking the bill, Philippe Latombe: “the DGSI and the services want the end of article 16 bis”; ANSSI director-general Vincent Strubel on “two imperatives of equal value” and “a choice among several bad solutions”
[38] The Record: EU Takes Member States to Court over Unimplemented Cybersecurity Law (July 9, 2026) – European Commission referred France, Ireland, Spain and the Netherlands to the Court of Justice of the European Union for failing to transpose NIS2 more than 20 months after the October 2024 deadline; Commission asked the Court to impose a lump sum and ongoing daily financial penalties until each state notifies full transposition; only 6 of 27 member states had transposed NIS2 by January 2025
[39] NPR/AP: French Lawmakers Approve a Sweeping Social Media Ban for Children Under 15 (July 22, 2026) – Both chambers of Parliament adopted the ban July 21, 2026, making France the first EU country to pass a blanket social-media ban; final commission mixte paritaire negotiations held on July 20 after the European Commission found the prior version overlapped with the Digital Services Act; exemptions for online encyclopedias and educational or scientific directories; CNIL-approved age verification; new accounts barred from September 1, 2026, with existing under-15 accounts closed after a grace period; high-school phone ban; a French constitutionality review likely before the September start
[40] Council of Europe Treaty Office: European Convention on Mutual Assistance in Criminal Matters (ETS No. 30) – Chart of signatures and ratifications; 51 parties as of July 2026 (all 46 Council of Europe member states plus Chile, Israel, Mongolia, the Republic of Korea and Russia), France among them
[41] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026 (45 Council of Europe member states plus 37 non-member states), France among them
[42] European Commission: Schengen Area – The 29 states of the Schengen Area (all EU members except Ireland and Cyprus, plus the non-EU associates Iceland, Liechtenstein, Norway and Switzerland; Bulgaria and Romania became full members January 1, 2025), France among them
[43] Wikipedia: Prüm Convention – The Prüm framework for automated DNA, fingerprint and vehicle-data exchange; binds all 27 EU member states plus the non-EU Schengen associates Iceland, Liechtenstein, Norway and Switzerland (31 in all); France was an original 2005 signatory; Prüm II (2024) adds facial images and police records
[44] Europol: Operational Agreements – Europol is constituted by the 27 EU member states (France among them) and maintains operational cooperation agreements permitting exchange of personal data with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, the United States) plus Denmark under a separate agreement, and with Eurojust, Frontex and Interpol
[45] Tribunal judiciaire de Paris: International Mutual Legal Assistance – France’s mutual legal assistance in criminal matters, with the Ministry of Justice as central authority; governed by the 1959 Council of Europe Convention, the Schengen Convention, the 2000 EU Mutual Assistance Convention, the UN Convention against Corruption and the Budapest Convention, plus bilateral treaties (including the France-US MLAT signed December 10, 1998) and, absent any convention, assistance on a reciprocity basis; the complete country-by-country list of France’s bilateral conventions is searchable in the Ministry for Europe and Foreign Affairs treaty database (Base des traités et accords)
[46] The Local: How Will France’s Social Media Ban for Under-15s Actually Work? (July 22, 2026) – two-phase rollout (age verification for new accounts from September 1, 2026; verification of existing accounts and suspension of under-15 accounts from January 1, 2027); a group of 60 lawmakers has referred the law to the Conseil constitutionnel, arguing disproportionate restriction of minors’ free expression and that mandatory age verification for all users violates the right to privacy
[47] The Intercept: The Powerful Global Spy Alliance You Never Knew Existed (March 1, 2018) – the NSA-led SIGINT Seniors coalitions; SIGINT Seniors of the Pacific founded 2005, comprising the Five Eyes plus France, India, Singapore, South Korea, and Thailand; counter-terrorism intelligence shared over the CRUSHED ICE secure network
[48] Wikipedia: Club de Berne – informal forum (founded 1969) of the heads of the domestic intelligence and security services of the 27 EU member states plus Norway and Switzerland; its separate post-9/11 offshoot the Counter Terrorism Group (September 2001) additionally includes the United Kingdom and has operated a joint platform in The Hague with a common database and real-time information system since 2016
← Back to Privacy Law Directory