France
Nine Eyes member and Europol, Schengen and Prüm participant bound by the Budapest and 1959 assistance conventions, running algorithmic “black box” surveillance and DGSE bulk access at Europe’s largest submarine-cable hub
Overview
EU Member State: France is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page. This page covers national laws, intelligence and surveillance, and France’s role in international data sharing.
France was the first European country to enact comprehensive data protection legislation (Loi Informatique et Libertés, 1978) and the first EU country to authorise algorithmic “black box” scanning of communications metadata for intelligence purposes. Following the 2015 Paris attacks, France enacted broad surveillance legislation granting intelligence agencies some of the widest powers in Western Europe. The CNIL imposed EUR 486.8 million in fines in 2025 alone (including EUR 325M against Google and EUR 150M against Shein), while intelligence agencies surveilled 24,308 persons across 98,883 technique authorisations in 2024.[1][2]
France is a Nine Eyes member with a bilateral SIGINT agreement with the NSA codenamed Lustre, and a Maximator alliance member (joined 1985). Marseille is Europe’s largest submarine cable hub (17+ systems), where DGSE conducts bulk cable interception under Article L.854-1 with no CNCTR prior opinion required.[3][4]
France’s outward data-sharing runs through its alliances and treaties, each detailed below. Beyond the Nine Eyes and Maximator signals-intelligence alliances, France is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks (it was an original 2005 Prüm signatory) and to Europol, and holds a bilateral mutual legal assistance treaty with the United States (1998) alongside numerous bilateral judicial-cooperation conventions with Francophone and Maghreb states; even absent a convention, French authorities may assist on a reciprocity basis. These are the channels through which the domestic protections described below are, in practice, bypassed.[45]
International Data Sharing Agreements
Mutual Legal Assistance: Layered Framework
EU instruments: As an EU member state, France cooperates with the other 26 EU states through the EU Mutual Legal Assistance Convention (2000) and the European Investigation Order. It belongs to the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland), with real-time SIS alerts.[42] France was an original Prüm Convention signatory (2005); the Prüm framework now binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland) in automated DNA, fingerprint, and vehicle-data exchange, and Prüm II (2024) adds facial images and police records.[43]
European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): With its Additional Protocols, this Council of Europe instrument has 51 parties as of July 2026: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[40]
Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): France is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[41]
Bilateral MLAT with the United States: A France-US mutual legal assistance treaty (signed December 10, 1998) supplements the conventions; the Ministry of Justice is France’s central authority, with roughly 10-month average processing times.[20][45]
Bilateral judicial-cooperation conventions: France maintains numerous bilateral MLA and judicial-cooperation conventions with Francophone and Maghreb states and other former colonial territories across Africa, the Middle East, and Southeast Asia, supplementing the multilateral conventions above. France does not publish a single consolidated list; the complete country-by-country set is searchable in the Ministry for Europe and Foreign Affairs treaty database (Base des traités et accords). Even where no convention applies, French authorities may grant assistance on a reciprocity basis.[45]
French Blocking Statutes
Modernised 2022, designed to protect against unilateral US law enforcement requests. However, they apply only to unilateral requests and do not prevent data sharing through MLATs, the EU-US Umbrella Agreement, Nine Eyes channels, or EU frameworks like SIS II and Prüm. The result: blocking statutes provide limited practical protection against the web of multilateral data sharing frameworks.[21]
Nine Eyes Intelligence Sharing
Under the Lustre agreement, DGSE exchanges raw SIGINT with the NSA. The Nine Eyes framework creates reciprocal bypass: French intelligence can collect on Five Eyes persons and share back; partner agencies can collect on French persons and share with French intelligence, bypassing CNIL oversight and French judicial warrants.[22]
EU and Multilateral Frameworks
SIS II: Real-time query and alerts across Schengen. EU-US Umbrella Agreement: French citizens get judicial redress before US courts. SWIFT/TFTP: International wire transfers subject to US Treasury subpoena. PNR: Passenger data for France-US flights. Interpol I-24/7 (195 countries). Egmont Group: Tracfin shares financial intelligence across 164+ FIUs.
Europol
As an EU member state, France is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so French person data flowing through Europol is reachable onward.[44]
The Privacy Backdoor Effect
Despite GDPR enforcement by CNIL and French blocking statutes, international agreements create alternative access:
- Nine Eyes/Lustre: NSA can collect on French persons and share with French intelligence, bypassing judicial oversight; DGSE can collect on partner nations’ persons and share back
- MLAT Bypass: US requests via MLAT circumvent blocking statutes, with potentially lower evidentiary standards than French judicial warrants
- Marseille Cable Access: DGSE intercepts Europe-Asia/Africa traffic in bulk under Article L.854-1 with no CNCTR prior opinion
- EU Framework Sharing: French person data in SIS II, Prüm, or EIO channels accessible to 27 EU states and through Europol to US FBI
- SWIFT/PNR: Financial transactions and air travel data subject to US access
SIGINT Seniors of the Pacific (SSPAC)
France joined SIGINT Seniors of the Pacific (SSPAC) in 2013, giving it a seat in the NSA-led Asia-Pacific counterterrorism SIGINT coalition despite standing outside the Five Eyes. The ten members are the Five Eyes (the United States, the United Kingdom, Canada, Australia, and New Zealand) plus France, India, Singapore, South Korea, and Thailand, sharing counter-terrorism intelligence over the CRUSHED ICE secure network, so French SIGINT cooperation with the NSA runs through SSPAC and the Fourteen Eyes (SIGINT Seniors Europe) simultaneously.[47]
Club de Berne and the Counter Terrorism Group
France’s DGSI takes part in the Club de Berne (founded 1969), the forum of the heads of the domestic intelligence and security services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland. The Club is a broad, all-source intelligence-sharing body, not a counterterrorism-specific one; its separate offshoot, the Counter Terrorism Group (CTG), created in September 2001, shares terrorism intelligence among the same services plus the United Kingdom and has run a joint operational platform in The Hague with a common database and real-time information system since 2016.[48]
Surveillance and Intelligence
Intelligence Act 2015
Passed after the Charlie Hebdo attack. Authorises targeted interception, real-time geolocation, IMSI catchers, microphones and cameras in private spaces, computer intrusion, and bulk metadata analysis. Algorithmic “black boxes” allow automated devices at data centres and telecom networks to detect communications patterns matching terrorist selectors. France was the first EU country to authorise this. The CNCTR’s 2024 report noted computer data collection more than doubled over five years.[1][7]
CNCTR Oversight
The CNCTR (Commission nationale de contrôle des techniques de renseignement) provides prior opinions before surveillance authorisation, but these are not binding; the Prime Minister may override with written justification. 2024: 24,308 persons surveilled, 98,883 technique authorisations (+3%). Counterterrorism: 30% of monitored persons, 39.3% of technique requests.[7]
International Electronic Communications Law (November 2015)
Governs surveillance of communications “emitted from or received abroad” with significantly reduced oversight: CNCTR prior opinion not required; international communications may be intercepted in bulk. Retention: content 1 year after first exploitation (max 4 years; 8 years for encrypted content); metadata up to 6 years. Internet routing means many nominally domestic French communications transit foreign servers and qualify as “international.”[8]
SILT Law 2017: Permanent Emergency Powers
Formally ended the state of emergency while permanently incorporating key emergency powers: administrative security perimeters, closure of places of worship, house visits with judicial authorisation, and MICAS (individual surveillance measures including municipality restriction, daily police check-ins, passport confiscation, electronic bracelet monitoring for up to one year, with no requirement to disclose evidence). These powers have been repeatedly renewed.[9]
Intelligence Agencies
DGSI: Domestic intelligence (counterterrorism, counterintelligence, economic protection), under Ministry of Interior.
DGSE: Foreign intelligence and SIGINT, under Ministry of Defence. Contains the Direction Technique (DT) handling signals intelligence (ROEM), operating overseas CRE stations spanning the Mediterranean, Africa, and the Middle East.[10]
Nine Eyes and Maximator
The Nine Eyes comprises the Five Eyes (Australia, Canada, New Zealand, the United Kingdom, and the United States) plus Denmark, France, the Netherlands, and Norway. France maintains a bilateral SIGINT agreement with the NSA codenamed Lustre, exchanging raw SIGINT data. As a third-party partner, France is not exempt from NSA collection. Operation Dunhammer confirmed NSA surveillance of senior French officials via Danish cables.[22][3][11]
Maximator, a separate European signals-intelligence alliance kept secret from 1976 until 2020, has five members: Denmark, France, Germany, the Netherlands, and Sweden. France joined in 1985 (the fifth member). DGSE’s Direction Technique contributes cryptanalytic capabilities to the encryption-defeat cooperative. Germany’s Maximator membership connected the alliance to Operation Rubicon (CIA-BND co-ownership of Crypto AG).[12]
Commercial Surveillance Procurement
Palantir/DGSI: France renewed its DGSI intelligence contract with Palantir through 2025. As a US company subject to the CLOUD Act, the contract raises concerns about US access to French intelligence data bypassing bilateral frameworks.[13]
Pegasus: In July 2021, the Pegasus Project revealed that phone numbers associated with French President Macron, members of his government, and journalists appeared on an NSO Group target list. France launched an investigation, and the DGSE reportedly explored but did not procure Pegasus.[14]
Internet Infrastructure and Cable Surveillance
Marseille: Europe’s Largest Submarine Cable Hub
Marseille hosts at least 17 submarine cable systems including SEA-ME-WE 3/4/5/6, AAE-1, ACE, IMEWE, and 2Africa (Meta’s 45,000 km system). The majority of Europe-Asia and Europe-Africa internet traffic passes through Marseille, making it Europe’s primary cable chokepoint.[15]
DGSE Cable Access (Article L.854-1)
The International Electronic Communications Law provides the legal basis for DGSE bulk interception of all communications “emitted from or received abroad” at cable landing stations and IXPs, with no CNCTR prior opinion required. Combined with algorithmic black box capabilities, this gives DGSE extensive collection access at one of Europe’s most concentrated cable chokepoints.[8]
France-IX and Orange Marine
France-IX: ~500 members, largest French IXP, with exchanges in Paris and Marseille. Orange Marine (former state-owned France Télécom subsidiary) operates 7 cable ships averaging ~50 maintenance operations/year, giving France operational knowledge of cable routing and infrastructure directly relevant to SIGINT collection.[16][17]
Recent Developments
Narcotrafficking Law Surveillance Provisions Struck Down (June 2025): The Conseil constitutionnel struck down Article 15 (extending algorithmic black boxes from counterterrorism to drug trafficking) as disproportionate, along with provisions for direct intelligence access to tax databases. An encryption backdoor provision was separately rejected by the National Assembly. AVS (algorithmic video surveillance) extension to 2027 was also censured. France has no operative statutory basis for AI video surveillance as of early 2026.[23]
Ghost Participant Encryption Backdoor Rejected (March 2025): The National Assembly rejected requiring messaging platforms to allow hidden law enforcement access to encrypted chats. France’s existing authorities (including device-based spyware) already provide lawful access to encrypted content.[18]
Algorithmic Video Surveillance: Olympics Experiment Expired (March 2025): The 2023 Olympic AVS authorisation expired March 31, 2025. Police pushed for permanence; CNIL warned of a “ratchet effect.” The push to extend via transport security law was censured by the Conseil constitutionnel in April 2025.[24]
Chat Control: France generally supports the EU CSA Regulation. The November 2025 Council general approach dropped mandatory encrypted scanning but preserved “high-risk” service mitigation measures. However, the EU Parliament rejected the voluntary scanning extension on March 26, 2026 (311–228), and the ePrivacy derogation expired April 3, 2026.[25]
CNIL Enforcement (January 2026): The CNIL fined FREE MOBILE €27M and FREE €15M (January 13) for data security failures affecting 24 million subscriber contracts including IBANs. Separately, France Travail received a €5M fine (January 22) for failing to secure job seekers’ data, where identified security measures were documented in impact assessments but never implemented. The CNIL’s 2025 sanctions totalled a record €486.8 million.[29]
NIS2: Loi Résilience (still not voted, July 2026): France’s NIS2 transposition law (Loi relative à la résilience des infrastructures critiques) missed the projected Q1 2026 adoption and then missed July as well. The National Assembly Special Committee adopted its text in September 2025, leaving only the final vote in séance publique, which has still not been scheduled. Parliament was convened in extraordinary session by decree from July 1, 2026, sitting through the week of July 20, with roughly thirty texts on the agenda; the resilience bill is not among them, and the word “cyber” does not appear in the convening decree at all. The Digital Minister, Anne Le Hénanff, now says she hopes the text will be examined in September 2026. The law packages NIS2 with the Critical Entities Resilience (CER) and DORA transpositions and will bring approximately 15,000 entities into scope.[30][37]
The transposition deadline was October 17, 2024. France is now more than twenty months past it, and on July 9, 2026 the European Commission referred France to the Court of Justice of the European Union over the failure, together with Ireland, Spain, and the Netherlands, asking the Court to impose a lump sum and ongoing daily financial penalties until each state notifies full transposition.[38] The cause of the delay is not parliamentary congestion but a single contested clause. The Commission supérieure du numérique et des postes attributes the blockage to article 16 bis, introduced in the Senate to write protection of encryption into law and to prohibit the imposition of backdoors on messaging services, which the government opposes. In February 2026 the two presidents of the Assembly’s special committee publicly accused the DGSI of holding up the entire bill to kill that article; committee president Philippe Latombe, who authored the amendment sanctuarising end-to-end encryption, said plainly that “the DGSI and the services want the end of article 16 bis.” ANSSI director-general Vincent Strubel framed the impasse without resolving it, saying France faces “two imperatives of equal value,” privacy and national security, and that in the end the legislature will have to make “a choice among several bad solutions.” The practical result is that France’s cybersecurity transposition is hostage to its encryption policy, and neither has moved.[37][34]
CNIL Designated as AI Act Authority: As of February 2026, the CNIL is the national supervisory authority for the EU AI Act in France, with power to sanction prohibited practices and audit transparency of high-risk AI systems.[30]
Paris Court Compels VPN Providers to Block Sites: In seven simultaneous rulings, the Paris Judicial Court ordered ISPs, VPN providers, and DNS resolvers (including ProtonVPN, CyberGhost, and ExpressVPN) to block access to 35 sports-piracy domains on petition from the Ligue de Football Professionnel. The orders are dynamic (Arcom may add new domains during the order’s life) and run until June 21, 2026. This is the first time French courts have directly conscripted VPN providers into a national content-blocking regime, marking a structural shift from pure ISP-level filtering. ProtonVPN and others have publicly opposed compliance as inconsistent with their no-log architecture and EU fundamental-rights protections.[31]
Arcom Automated Real-Time Piracy Blocking System: Arcom has announced plans to deploy an automated, real-time IPTV blocking system within six months, modelled on the UK and Italian regimes. The plan explicitly identifies VPNs and alternative DNS providers as priority targets, citing data that 66% of users accessing pirated content rely on these tools. Arcom is seeking voluntary cooperation first; if providers refuse, Arcom is asking the legislature for coercive powers to compel compliance.[32]
Operation Saffron, France co-leads First VPN takedown (May 2026): France, with the Netherlands and support from Europol, Eurojust, and Bitdefender, led Operation Saffron (May 19–20, 2026), dismantling the criminal anonymisation service “First VPN” used by 25+ ransomware groups since 2014. Authorities seized 33 servers across 27 countries and obtained the service’s complete user database of 5,000+ accounts, with intelligence on hundreds of users shared across partner states. The case underscores France’s central role in EU cooperative takedowns and the cross-border circulation of seized VPN subscriber data.[35]
Privacy Framework
The CNIL (Commission nationale de l’informatique et des libertés), one of the world’s oldest DPAs, issued the first major GDPR fine (Google EUR 50M, January 2019). In 2025, 83 sanctions totalling EUR 486.8M, a nine-fold increase over 2024. Google alone has been fined EUR 625 million across four CNIL actions. 2025 budget: EUR 30.6M; 301 FTE staff; 17,772 complaints (2024). The Loi Informatique et Libertés (1978, as amended) supplements the GDPR with specific provisions on national security processing, public sector data, and health research.[5][6]
Cryptography
Domestic encryption use is unrestricted. Compelled decryption: up to 3 years imprisonment and EUR 270,000 for refusing judicial decryption orders (higher for terrorism/organised crime). In March 2025, the National Assembly rejected a “ghost participant” proposal that would have forced messaging platforms to allow hidden law enforcement access to encrypted chats. An encryption backdoor provision in the Narcotrafficking Law (requiring platforms to provide decrypted messages within 72 hours) was also rejected, with Signal threatening to withdraw from France.[18]
Data Retention
The Council of State validated generalized retention of connection data, ruling that the national security threat justifies it while requiring periodic government reassessment. Intelligence can retain metadata up to 6 years. The national security justification has been continuously reaffirmed since 2015 with no reduction in retention obligations.[19]
Age Verification: Identity Infrastructure as Surveillance
France has implemented mandatory age verification for online pornography (effective January 11, 2025, Law 2024-449). Platforms must implement digital ID verification, biometric analysis, or document checks; simple “I am 18” declarations are explicitly insufficient. Enforcement authority Arcom can impose fines up to EUR 150,000 or 2% of worldwide turnover. In February 2025, the scope was extended to 17 services in other EU member states, asserting French jurisdiction over non-French platforms.[26]
France’s “double anonymity” principle attempts to separate identity from content: the site does not know the user’s identity, and the verification provider does not know which sites the user visits. However, any age verification system necessarily creates metadata linking an individual to age-restricted content access at a specific time. The infrastructure required (centralised verification services, government-approved identity checks, platform integration) creates a surveillance-capable architecture that could be repurposed beyond its original scope. A CJEU referral (March 2024, Advocate General opinion September 2025) may determine whether France’s extraterritorial enforcement is compatible with the e-Commerce Directive’s country-of-origin principle.[27]
France’s parliament gave final approval to a social media ban for under-15s on July 21, 2026, making France the first European Union country to pass a blanket ban on the platforms (following Australia’s under-16 ban, in force since December 2025). The National Assembly first passed the bill on January 27, 2026 (130–21), but the two chambers then deadlocked for months over scope, and the European Commission found that the latest version overlapped with the EU Digital Services Act. A joint committee (commission mixte paritaire) agreed an amended compromise text on July 20, which the Senate adopted 243–2 and the National Assembly 279–81 the next day. The final text drops the Senate’s proposed blacklist-plus-parental-consent model in favour of a blanket ban on social networks (Facebook, Snapchat, TikTok, YouTube) for under-15s, with the digital minister to publish the list of covered services and carve-outs for online encyclopedias, educational and scientific directories, and open-source platforms. Platforms must run age verification approved by the CNIL; new accounts are barred from September 1, 2026, and existing accounts must be age-verified from January 1, 2027, with under-15 accounts suspended from that date. The law also extends the existing school phone ban to high schools. It is not yet in force: a group of 60 lawmakers has referred the law to the Conseil constitutionnel, arguing that it disproportionately restricts minors’ freedom of expression, ignores age, maturity, and parental authority, and violates the right to privacy by making age verification mandatory for everyone accessing social media, and a mandatory EU notification period runs to around August 10, 2026, so Macron’s targeted September start could slip. Combined with the pornography verification mandate, France is building one of the most extensive government-mandated age verification infrastructures in any democracy, creating identity verification touchpoints across the internet that did not previously exist.[28][39][46]
EU Age Verification Blueprint Pilot: France is one of seven Member States piloting the EU-wide Age Verification Solution (alongside Denmark, Greece, Italy, Spain, Cyprus, and Ireland), with plans to integrate the app into the national EUDI Wallet. The Commission released the enhanced second version of the blueprint on October 10, 2025; on April 15, 2026, von der Leyen announced the EU-level system was “technically ready,” and the seven pilot states are integrating it into their national digital identity wallets. The pilot architecture uses a zero-knowledge proof track intended to confirm age brackets without disclosing identity to the relying party.[33] France is also one of five EU countries (with Estonia, Ireland, Spain, and Italy) where Google announced a summer-2026 Google Wallet rollout of passport-based digital IDs and age credentials via its Credential Manager API, raising the prospect that a single US platform becomes the de facto holder of age-verification data even as France defends its own SREN-law mandate before the CJEU. See the European Union page for the broader critique of Google’s positioning as the age-assurance gatekeeper.[36]
Pending Legislation
- Loi Résilience (NIS2/CER/DORA): committee text adopted September 2025; the séance publique vote has never been scheduled and was absent from the July 2026 extraordinary session agenda. The minister now targets September 2026, and on July 9, 2026 the Commission referred France to the CJEU over the missed October 2024 deadline, seeking a lump sum and daily penalties. Brings ~15,000 entities into scope. The bill is stalled over article 16 bis, which would “sanctuarise” encryption and bar backdoor mandates; the government and the DGSI oppose it, while intelligence services press for the ability to access protected data without the consent of its authors or recipients. This is the core encryption-policy fight in the text.[30][34][37]
- Arcom coercive anti-piracy / VPN powers: Arcom has asked the legislature for statutory power to compel VPN providers and alternative DNS resolvers to block sites if voluntary cooperation fails, which would be the first French statute directly conscripting VPN providers into content blocking.[32]
- Age verification: France co-leads the EU age-verification blueprint pilot (EUDI Wallet integration) and continues to defend its SREN-law age-verification mandate, which is under challenge before the CJEU (AG opinion September 2025, judgment pending).[33]
