France’s national cybersecurity strategy aims to position the country as a leading cyber power in response to the evolving cyber‑threat landscape. In particular, the recently published national cybersecurity strategy for 2026–2030 develops a structured approach based on five pillars:
France’s cybersecurity framework is built upon a combination of European Union (EU) regulations, national legislation and non-binding technical standards – notably as follows.
EU Regulations and Directives
French Legislation
Non-Binding Standards
To guide organisations in GDPR and data security compliance, the National Commission for Information Technology and Civil Liberties (CNIL), along with the European Data Protection Board (EDPB) regularly publish practical guides and recommendations that set the standard for personal data security. The following are a few examples:
The French cybersecurity agency (ANSSI) has also issued many technical recommendations that set out best practices for securing IT environments, including:
ANSSI
France’s public cybersecurity landscape is orchestrated by ANSSI, which operates under the authority of the Secretary General for Defence and National Security (SGDSN). As the national cyber authority, ANSSI is responsible for proposing and implementing state cybersecurity policy, supervising regulated operators, and co-ordinating the operational response to cyber-threats. To deliver on these missions, its capabilities are structured in a tiered model.
National-level operations
Operating as an integral part of ANSSI, the national government Computer Emergency Response Team (CERT-FR) is the nation’s primary technical and operational division for cyber defence. It is primarily responsible for handling incidents affecting the most critical entities, such as State ministries and operators of vital importance (OIVs).
Regional support network
Complementing this central capability is a network of regional CSIRTs (CSIRT-Régions) and Cyber Resource Centres (CRCs), whose development is co-ordinated and supported by ANSSI as part of its national strategy. These regional bodies are not direct branches of ANSSI but are typically independent local structures designed to provide crucial “first-level” cybersecurity support. Their mission is to assist small and medium-sized enterprises (SMEs), local authorities and associations by offering free initial support in diagnosing incidents and by connecting them with nearby, trusted private-sector incident response providers.
CNIL
The CNIL is France’s national data protection authority. The CNIL’s mission consists of safeguarding individual rights while steering public and private organisations towards compliance, advising the government, and supporting innovation by anticipating the ethical implications of emerging technologies. To fulfil this role, it holds broad supervisory and enforcement powers, including conducting on‑site or online inspections, issuing injunctions and imposing substantial fines. The CNIL is one of the regulators empowered with the enforcement of the AI Act in France.
Section J3 of the Paris Criminal Prosecutor Office
Section J3 has a national competence, alongside local criminal prosecutors, for the investigation and prosecution of all sorts of cyber infringements. It works with specialised investigators, mainly from the Central Office for Combating Crime Linked to Information and Communication Technologies (OCLCTIC), the Paris Cybercrime Unit (BL2C), the Gendarmerie Command in Cyberspace (COMCyberGend) and the General Directorate for Internal Security (DGSI).
Arcep
The Electronic Communications, Postal and Print Media Distribution Regulatory Authority (Arcep) is France’s national regulator for electronic communications, postal services and print media distribution. It notably monitors the security obligations imposed on electronic communications operators. Such operators are legally required to ensure the continuity, availability and security of their networks under the European Electronic Communications Code (EECC) and the Postal and Electronic Communications Code. Arcep may initiate proceedings and, if necessary, impose sanctions on the operators concerned.
Arcom
The Regulatory Authority for Audiovisual and Digital Communication (Arcom) is the national authority responsible for regulating audiovisual media, digital platforms and online content in France. It notably works to protect freedom of speech in the public interest, while monitoring the security obligations imposed on online public communication service publishers and video-sharing platform service providers with regards to online protection of minors. Arcom also holds extensive sanctioning powers, allowing it to impose measures such as suspending programmes or services, reducing or withdrawing broadcasting authorisations, and ordering the publication of corrective statements. Arcom is one of the regulators empowered with the enforcement of the AI Act in France.
DGCCRF
The General Directorate for Competition, Consumer Affairs and Fraud Control (DGCCRF), which is a department within the French Ministry of the Economy, is inter alia in charge of consumer protection. As such, it may be involved in privacy investigations, platforms regulation, payment security and generally all frauds affecting consumers. The DGCCRF is one of the regulators empowered with the enforcement of the AI Act in France, and is the co-ordinator of all the regulators involved in that field in France.
Across critical sectors such as banking and health, cybersecurity oversight is ensured by dedicated national authorities such as the following.
ACPR
The French Prudential Supervision and Resolution Authority (ACPR), attached to the Banque de France, is the administrative authority responsible for supervising the banking and insurance sectors. It aims at ensuring financial stability, protecting customers, and combating money laundering and terrorist financing. As part of its oversight of banks and insurers, the ACPR monitors emerging risks, including cyber-risk. The ACPR conducts on‑site and off‑site inspections, applies a wide range of supervisory and sanctioning measures, and exercises resolution powers to safeguard financial stability. The ACPR is one of the regulators empowered with the enforcement of the AI Act in France.
AMF
The French Financial Markets Authority (AMF) is the independent public body responsible for regulating France’s financial markets. It supervises market participants, including asset management companies, investment firms and listed companies. Its primary missions are to ensure investor protection, promote orderly markets and provide information to the public.
With the implementation of DORA, the AMF’s remit has been explicitly extended to oversee the digital and cyber-resilience of the financial entities under its supervision.
ANS
The French Digital Health Agency (ANS), under the authority of the Ministry of Health, is responsible for strengthening the security of health information systems in France. It operates the CERT Santé, the dedicated Computer Emergency Response Team for the healthcare sector. Specifically, the CERT Santé supports healthcare and medico‑social organisations in responding to information‑system security incidents by providing prevention, alerts and essential cyber‑risk guidance. In addition, the ANS oversees compliance with key data-security requirements for healthcare providers, including monitoring adherence to the Health Data Hosting (HDS) certification scheme.
Essential and Important Entities
Legislative framework
The primary legislative framework governing cybersecurity for essential or critical entities in France is currently established by the 2018 Security Law, which transposes the original NIS Directive, alongside the specific LPM provisions codified in the French Defence Code.
The 2018 framework is now undergoing a comprehensive overhaul to transpose the NIS2 Directive. Indeed, the French government introduced the Draft Resilience Bill in late 2024, which will serve as the vehicle for implementing the NIS2 Directive into national law.
The legislative process at the French Parliament is still ongoing. Once enacted, this bill will repeal the 2018 framework and significantly broaden its scope.
Material scope: a two-tier system
The NIS Directive, as transposed by the 2018 Security Law, provides for a separate classification of “Operators of Essential Services” (OESs) and “Digital Service Providers” (DSPs).
OESs are entities designated by the State in traditional sectors (eg, energy, transport, banking) and subject to proactive, ex ante supervision. This stricter regime also applies to a few key digital infrastructure providers, namely Internet Exchange Points (IXPs), Domain Name System (DNS) providers, and Top-Level Domain (TLD) registries – a detail specified not in the 2018 Security Law itself but in its key implementing decree. In contrast, DSPs are an exhaustively defined category comprising only online marketplaces, online search engines and cloud computing services. These entities benefit from a much lighter, reactive ex post supervisory regime. Notably, this framework leaves significant gaps, as some providers in the digital supply chain – such as those qualified as managed service providers (MSPs) and managed security service providers (MSSPs) under the NIS2 Directive, as well as data centre service providers – are not explicitly covered at all.
The new NIS2 Directive framework fundamentally alters this landscape. All regulated organisations are now integrated into a two-tier system of “Essential Entities” (EEs) and “Important Entities” (IEs), which applies to a much larger number of critical and highly critical sectors.
EEs, operating in the “highly critical sectors” listed in Annex I of the NIS2 Directive, include “Digital Infrastructure”, which encompasses cloud computing and data centre providers alongside TLD registries and DNS providers. Furthermore, a new highly critical activity, information and communication technology (ICT) service management (business-to-business), has been created to directly bring MSPs and MSSPs into scope. EEs are subject to a robust, proactive supervisory regime.
IEs are entities operating in “other critical sectors” listed in Annex II of the NIS2 Directive. This second tier includes a diverse range of activities such as postal and courier services, waste management, food production and distribution, and the manufacturing of certain critical goods. It also covers other digital providers, namely online marketplaces, online search engines, and social networking service platforms. IE entities are subject to a lighter, ex post supervisory regime.
Size thresholds and exemptions
The outgoing NIS1 framework operates on a dual system for determining its scope.
The upcoming NIS2 framework’s reliance on a size-cap rule marks a significant departure from the logic of the 2018 Security Law. In most cases, entities employing fewer than 50 people and whose annual turnover and/or annual balance sheet total does not exceed EUR10 million are exempt from the NIS2 Directive. However, some entities in various sectors fall under the NIS2 Directive regardless of their size – for instance:
National specificities of the Draft Resilience Bill compared with the NIS2 Directive
While the Draft Resilience Bill faithfully transposes the NIS2 Directive’s overall scope, its most significant departure lies in its treatment of public administration entities. Indeed, the NIS2 Directive leaves the inclusion of regional and local bodies to a member state’s discretionary, risk-based assessment. Therefore, under the Draft Resilience Bill, the EE category includes regions, departments and municipalities with a population over 30,000, as well as major metropolitan and urban communities. Conversely, the IE category covers other local bodies, notably communities of municipalities (communautés de communes).
To ensure a clear separation of powers, the latest version of the Draft Resilience Bill establishes a new and independent sanctions committee. Instituted under the Prime Minister, this committee will have the sole authority to impose penalties, upon referral from ANSSI after an investigation has revealed a persistent infringement.
Operators of Vital Importance (OIVs)
The notion of OIVs was introduced by Law No 2013‑1168 of 18 December 2013 on military programming for the years 2014–2019, which notably required operators of vital infrastructures to implement specific measures to strengthen their protection against cyber-risks.
OIVs are defined in the French Defence Code as public or private operators running establishments or using facilities and structures whose unavailability could significantly reduce the nation’s war or economic potential, security or survivability.
While the specific list of entities designated as OIVs is classified for national security reasons, the overarching “sectors of activities of vital importance” are publicly defined and include (for instance) energy, transport, banking, financial market infrastructures, health and digital infrastructure.
The Draft Resilience Bill plans to replace and rewrite the entire chapter of the French Defence Code relative to OIVs, redefining its core concepts to align with the new NIS2 Directive framework. It provides that an OIV is automatically classified as an EE if its activities also qualify as an “essential service” under the framework of the CER Directive.
For completeness, it should be noted that the Draft Resilience Bill also transposes the CER Directive. This directive strengthens the physical resilience of critical entities against a wide range of threats. These obligations are not detailed further here, as they concern physical – rather than cybersecurity – requirements.
Essential and Important Entities
The requirements under the Draft Resilience Bill are substantially more demanding than those established by the 2018 Security Law and its implementing texts.
Governance
While OESs are required to adopt a security policy approved by their management, the 2018 Security Law does not impose specific obligations on management training. The NIS2 Directive takes a different approach. Management bodies of EEs and IEs must now approve their organisation’s cybersecurity risk-management measures and oversee their implementation. They are also required to receive dedicated cybersecurity training to ensure informed decision-making. In addition, NIS2 encourages them to promote regular cybersecurity training across their workforce.
The 2018 Security Law provides for personal liability for the managers of OESs. However, this liability is limited to financial penalties – up to EUR125,000 – for failing to comply with security rules or obstructing supervisory controls. By contrast, the NIS2 Directive allows member states to go further by temporarily prohibiting individuals with managerial responsibilities from exercising those functions. It also introduces sanctions targeting the entity itself (fines of up to EUR10 million or 2% of total worldwide annual turnover for EEs, and up to EUR7 million or 1.4% of total worldwide annual turnover for IEs).
Cyber-risk management
The 2018 Security Law requires designated OESs to comply with a detailed list of 23 security rules set out in a specific governmental order, such as conducting security accreditation, implementing network partitioning and establishing crisis management procedures. These stringent rules do not apply to DSPs, which are subject to a much more general and less prescriptive set of obligations defined directly in the law.
The new framework under the NIS2 Directive and the Draft Resilience Bill eliminates this distinction and mandates a single, non-exhaustive baseline of at least ten security measure categories that all in-scope entities – both EEs and IEs – must implement, including:
This new baseline is complemented by the NIS2 Implementing Regulation of 17 October 2024. This regulation is important as, for a specific list of entities, it moves beyond the high-level principles of the NIS2 Directive to define precise, legally binding requirements. It applies specifically to DNS service providers, TLD registries, cloud computing providers, data centre service providers, content delivery network providers, MSPs, MSSPs, online marketplaces, online search engines, social networking platforms and trust service providers. For these entities, it details technical and methodological requirements, as well as significant incident thresholds (see 2.3 Incident Response and Notification Obligations).
The implementation of the NIS2 Directive can be supported by aligning with the ISO/IEC 27001 standard, which provides a robust framework for an Information Security Management System (ISMS). However, it should be noted that certification to ISO/IEC 27001 alone is not sufficient, as it does not automatically cover all the specific prescriptive measures required under NIS2. It should therefore be used as a valuable, complementary tool, while full compliance in France will ultimately need to be measured against ANSSI’s forthcoming national framework.
Supply Chain Security
Under the 2018 Security Law transposing the NIS Directive, supply chain security is not an explicit, standalone requirement. It is only implicitly covered under the general risk management obligations for OESs.
Under the NIS2 Directive, this will become a core, explicit obligation. Entities must manage risks arising from their direct suppliers and service providers, including assessing the overall quality and cybersecurity practices of third-party products and services.
Operators of Vital Importance
Once designated, OIVs are subject to a stringent regulatory framework codified in the French Defence Code. Their obligations include the following.
Organisational measures
OIVs must appoint a Delegate for Defence and Security (Délégué pour la défense et la sécurité), who acts as the primary point of contact for the State and oversees the protection of the entity’s vital interests.
Physical and strategic planning
OIVs must identify their Points of Vital Importance (PIVs). They are required to draft an Operator Security Plan (PSO) and individual External Protection Plans to restrict access to sensitive facilities and systems to authorised personnel only. The Draft Resilience Bill updates this, now requiring an “Operator Resilience Plan” and, for each PIV, a “Specific Resilience Plan”.
Cybersecurity and monitoring
OIVs are specifically mandated to implement qualified detection systems (such as PDIS) to monitor their Information Systems of Vital Importance (SIIVs). These systems must be operated by certified service providers to ensure real-time detection of cyber-threats.
Audits and compliance
OIVs must regularly undergo security inspections and technical audits, often conducted at their own expense by ANSSI or State-certified auditors, to verify the resilience and compliance of their critical infrastructure.
The Draft Resilience Bill seeks to harmonise the cybersecurity obligations applicable to OIVs. It explicitly provides that the (current) former cyber-specific rules for OIVs under the French Defence Code are replaced by the new NIS2 Directive framework, so that OIVs will have to implement the same cybersecurity risk management and incident-reporting obligations as EEs.
Essential and Important Entities
The framework under the 2018 Security Law, transposing the NIS Directive, is based on a general principle. OESs and DSPs are required to notify ANSSI of incidents having a “significant” impact “without delay”. The implementing orders specify the modalities of the declaration (ie, via a form) but do not prescribe a mandatory multi-stage reporting process with fixed, harmonised deadlines across all sectors.
The NIS2 Directive alters this by mandating a uniform, multi-stage reporting process for any “significant incident” affecting both EEs and IEs. An incident is deemed to be significant if:
For entities such as cloud providers and MSPs, the NIS2 Implementing Regulation of 17 October 2024 provides directly applicable, concrete thresholds, such as a complete service unavailability of more than 30 minutes or a direct financial loss exceeding EUR500,000.
The reporting timeline is now highly structured.
In France, notifications are to be made to ANSSI. The latest version of the Draft Resilience Bill provides that the ANSSI will be required to inform the CNIL of any incident that may constitute a personal data breach.
Operators of Vital Importance (OIVs)
It is important to note that the OIV regime, codified in the French Defence Code, imposes stringent incident-reporting requirements that go beyond the general NIS Directive framework. This strict national regime is a key reason why OIVs’ core SIIVs were explicitly carved out of the 2018 Security Law’s scope.
Key OIV obligations include the following.
To avoid a dual-reporting structure, the Draft Resilience Bill plans to repeal these specific provisions. For cybersecurity incidents, OIVs will have to follow the same multi-stage notification process to ANSSI as EEs and IEs.
The French State, primarily through its national cybersecurity authority, ANSSI, has extensive responsibilities for ensuring national cyber-resilience, managing threat intelligence and fostering co-operation.
Under the current framework of the 2018 Security Law, the French State’s primary responsibility is to formally designate the OESs by order of the Prime Minister. By contrast, under the upcoming NIS2 Directive, an entity will be directly subject to the law as either EE or IE if it meets the new criteria of sector and size, placing the initial onus on the entity to self-assess and register with the national authority, ANSSI.
Compliance is monitored by the national authority, ANSSI, which is empowered to conduct security audits and on-site inspections. In its support role, ANSSI centralises incident reports and disseminating threat intelligence to the ecosystem.
This co-operative approach is anchored in concrete initiatives such as the Campus Cyber – a physical hub co-locating State experts with private companies – and practical tools such as the MonEspaceNIS2 digital platform, designed to guide businesses in their compliance efforts with the upcoming framework.
DORA is the primary legal framework that governs operational resilience. As a directly applicable EU legislation, DORA establishes a comprehensive and harmonised set of rules for managing ICT risks, superseding prior national laws and covering both financial entities and their critical technology providers.
Material Scope of Application
Scope for supervised financial entities
DORA applies to a wide range of financial entities operating in France. These include traditional entities such as:
It also covers newer participants, including crypto-asset service providers, crowdfunding platforms, and managers of alternative investment funds (AIFMs).
A key feature is the principle of proportionality, whereby requirements are tailored to an entity’s size, business profile and complexity.
Scope for critical third-party providers
For technology providers, DORA introduces a direct oversight framework for critical ICT third-party providers (CTPPs), such as cloud computing or data centre service providers, whose failure could cause systemic risk. CTPPs are designated by European Supervisory Authorities (ESAs) based on specific criteria, including the number of financial entities that rely on them and their systemic importance.
Territorial scope of application
The scope of application covers the following:
DORA defines ICT service providers very broadly as any undertaking providing ICT services. This includes everything from cloud platforms and data centres to software vendors and managed service providers.
DORA stipulates that contracts with ICT providers must include robust provisions covering the entire life cycle of the relationship. The key requirements are as follows.
Financial entities are subject to a set of specific obligations designed to create a robust and consistent framework for managing technology-related risks.
Governance and Internal Control
Ultimate responsibility lies with the entity’s management body. Their obligations include:
Financial entities must also establish control functions to ensure the proper implementation and monitoring of the risk framework.
ICT Risk Management Framework
Financial entities must implement a sound, comprehensive and well-documented ICT risk management framework. This is the operational core of DORA and must include the following.
Incident Management and Reporting
DORA harmonises the reporting process.
Internal incident management
Financial entities must have a process in place for managing and classifying ICT-related incidents.
Incident materiality criteria
Reporting to national regulators (such as the ACPR or AMF) is mandatory for any “major ICT-related incident”, where materiality is determined by factors including the number of clients affected, service duration, geographical spread, loss of data confidentiality integrity, or availability, impact on critical services and functions, and direct and indirect costs and economic impact.
Reporting timelines for financial entities
The reporting timeline is multi-staged. It begins with an initial notification to the relevant national regulator. This must be submitted without undue delay, and no later than 24 hours after the incident has been classified as major. This is followed by an intermediate report within 72 hours of the initial notification, providing an update on the situation. Finally, a comprehensive final report detailing the root cause, overall impact and corrective actions must be submitted within one month of the incident being fully resolved.
Obligations for Third-Party Service Providers
Indirect reporting obligation
DORA does not impose a direct reporting timeline on third-party providers to regulators. However, their contracts must stipulate that they report any ICT incident impacting the services provided to a financial entity without undue delay. This contractual obligation is critical, as it enables the financial entity to meet its own strict reporting deadlines.
Direct information requests
For providers designated as CTPPs, the lead supervisor can request all the information needed to assess the impact of an incident independently of the financial entity’s reporting channel.
Responsible Regulatory Authorities
Under DORA, the enforcement framework is multi-layered, combining EU-level direct supervision with the support of national authorities.
The lead overseer (LO)
The LO is either the EBA, EIOPA or ESMA. This is the central enforcement authority. One of the ESAs is appointed as the LO for each designated CTPP and has primary responsibility for direct supervision, investigation and sanctioning, regardless of where the CTPP is headquartered.
National competent authorities (NCAs)
The ACPR and the French Financial Markets Authority (AMF) act in a supporting role. They assist the LO during on-site inspections in France and enforce DORA’s rules against the financial entities they supervise.
The European Central Bank (ECB)
For significant credit institutions within the eurozone, the ECB collaborates closely with the LO to ensure that supervisory activities concerning CTPPs align with prudential oversight.
Compliance obligations for CTPPs
CTPPs must adhere to a comprehensive set of resilience obligations, compliance with which is monitored by the LO. Key requirements include the following.
Enforcement Measures and Sanctions
The LO has a powerful toolkit to enforce compliance. If a CTPP fails to meet its obligations, the following measures can be applied.
Supervisory audits and on-site inspections
The LO can conduct investigations and inspections at any time. These activities are used to verify compliance with DORA and may involve forensic reviews of systems and procedures, particularly where vulnerabilities have been identified.
Recommendations and corrective measures
If deficiencies are discovered, the LO will issue formal recommendations for corrective action. These recommendations are not mere suggestions; the CTPP is legally required to notify the LO of the measures it will take to implement them. Failure to comply can trigger financial penalties.
Financial penalties for non-compliance
If a CTPP fails to comply with its obligations (eg, by refusing an inspection or ignoring a recommendation), the LO can impose significant financial penalties. This takes the form of a periodic penalty payment, calculated daily until compliance is achieved. The penalty can be up to 1% of the CTPP’s average daily worldwide turnover from the preceding business year.
Recommendations for contract termination
Where a CTPP’s conduct poses a significant risk to financial stability and the CTPP fails to remedy the situation, the LO can recommend that financial entities suspend or terminate their service contracts with the non-compliant provider.
Cross-border enforcement and co-ordination
Owing to the global nature of CTPPs, enforcement is inherently cross-border.
A multi-layered framework combining the GDPR, DORA and the NIS2 Directive governs the regulation of data protection, cybersecurity and operational resilience.
Direct Provisions Impacting International Data Transfers
GDPR
The GDPR serves as the legal foundation for personal data transfers and is strictly enforced by the CNIL. Transfers outside the European Economic Area (EEA) are permitted only through lawful mechanisms such as EU adequacy decisions, Standard Contractual Clauses (SCCs) – supplemented by a mandatory Transfer Impact Assessment (TIA) – or Binding Corporate Rules (BCRs). When a financial entity’s ICT provider processes personal data in a third country, the transfer must comply with these strict GDPR requirements, as well as any DORA obligations.
DORA
DORA does not impose a blanket data localisation requirement. However, it makes outsourcing to third countries conditional on maintaining full regulatory compliance and oversight.
The NIS2 Directive
The NIS2 Directive reinforces supply chain security for all EEs and IEs. It requires entities to assess the cybersecurity practices of their direct suppliers. This includes vetting providers in third countries and considering the geopolitical risks associated with their jurisdiction. In France, ANSSI is responsible for overseeing the implementation of the NIS2 Directive. There is a strong national focus on “digital sovereignty”, meaning that outsourcing critical functions to certain third countries may be subject to greater supervisory scrutiny.
Indirect Provisions Affecting International Data Transfers
Supervisory expectations for cloud and ICT provider oversight
The ACPR and AMF expect French financial institutions to demonstrate robust due diligence when relying on non-EU cloud and ICT providers:
Supply chain due diligence and data flow vetting
Financial entities remain fully accountable for risks introduced by their supply chain:
Incident reporting
Under DORA, when reporting a major ICT incident, a financial entity must specify whether the incident originated with or impacted a third-party provider located outside the EU. This gives French and European supervisors critical insights into the risks posed by third-country dependencies, enabling them to identify concentration risks or jurisdiction-specific threats.
Mandatory TLPT for the financial sector is governed by DORA, which is based on the national TIBER-FR initiative and is aligned with the TIBER-EU framework. The French regulators, the ACPR and AMF, conduct oversight.
TLPT Scope
TLPT is an advanced, intelligence-led testing regime designed to rigorously assess the resilience of significant financial entities against sophisticated, real-world cyber-attacks.
Entities in scope
The obligation applies to financial entities identified as “significant” by the ACPR and AMF based on their size, business profile and systemic importance. This includes major banks, certain insurance undertakings, and key financial market infrastructures.
Systems in scope
The tests must cover the “live critical production systems” that underpin an entity’s critical or important functions.
ICT third-party providers
Although the obligation lies with the financial entity, critical ICT providers (such as major cloud service providers) are inherently part of the scope. DORA allows for “pooled tests”, whereby multiple financial entities can collectively test a shared provider, co-ordinated by the provider itself.
Key TLPT obligations Under DORA
Frequency and risk-based approach
Eligible financial entities must conduct a full TLPT at least every three years. The frequency may be adjusted by national authorities based on the entity’s risk profile or new threats emerging.
Scenario selection and threat intelligence
The entire test must be driven by specific, tailored threat intelligence. Scenarios must realistically mimic the tactics, techniques and procedures (TTPs) of advanced threat actors who are deemed to pose a genuine threat to the entity. In France, threat intelligence may be sourced from internal teams, specialist external providers, and national authorities such as ANSSI.
Red team qualifications
The testers (the “red team”) must have a high level of expertise and be functionally independent from the defence and response teams (the “blue team”). DORA mandates that testers hold relevant certifications and have a proven track record in threat intelligence and penetration testing. For each test, at least one of the testing providers involved must be an independent, external entity.
Cross-border recognition and reliance
DORA establishes the crucial principle of mutual recognition. If a financial group’s subsidiary in another EU member state conducts TLPT in compliance with DORA, the French authorities must recognise it as fulfilling the requirement for the group’s French operations.
Enforcement and non-compliance
Failure to conduct a required TLPT or to adequately address the identified vulnerabilities constitutes a breach of DORA:
The CRA, which is directly applicable in France, establishes a horizontal regulatory framework for the security of digital products across the EU. It applies to all products with digital elements (PDEs), meaning any hardware or software – whether final products or components marketed separately – made available on the EU market.
A central aspect of the CRA is that it imposes cybersecurity obligations on manufacturers, importers and distributors from the design stage and throughout the entire life cycle of the product.
Under the CRA, PDEs are classified into four categories.
The CRA places its main obligations on manufacturers, who must ensure that any product with digital elements they place on the market complies with the regulation’s essential cybersecurity requirements. To do so, manufacturers must conduct a cybersecurity risk assessment that guides security measures across all phases of the product’s life cycle, from planning and design to development, production, delivery and maintenance.
Manufacturers must document their risk assessment and the technical measures or standards used to meet the essential requirements, keeping this technical documentation available for market surveillance authorities upon request. Before placing a product on the market, they must complete the appropriate conformity assessment, and then issue an EU declaration of conformity and apply the CE marking.
Manufacturers must notify actively exploited vulnerabilities and severe security incidents affecting the security of their products with digital elements. They are required to submit the following.
In France, the implementation of the CRA relies on several national authorities with distinct roles.
The Agence Nationale des Fréquences (ANFR) is responsible for market surveillance. It ensures that products made available in France comply with the CRA’s requirements and may impose sanctions, including product withdrawal from the market or financial penalties of up to EUR15 million or 2.5% of the manufacturer’s global annual turnover.
ANSSI plays a key role in the practical implementation of the CRA, acting as the notifying authority responsible for assessing, supervising and notifying conformity assessment bodies. It also provides technical support to the ANFR for market‑surveillance activities and centralises reports of actively exploited vulnerabilities and major incidents, co-ordinating remediation actions with manufacturers when necessary.
The French cybersecurity certification landscape combines European harmonisation efforts with national sovereignty imperatives. Certifications and qualifications evaluate the security robustness of ICT products, services and processes. While historically utilised as voluntary markers of quality, these certifications are increasingly becoming mandatory prerequisites for market access and public procurement in France.
The European Framework
At EU level, the CSA established the European Cybersecurity Certification Framework (ECCF) in 2019 to harmonise evaluation approaches across the internal market. In 2024, the European Commission adopted the first scheme under this framework: the Common Criteria-based European Cybersecurity Certification Scheme (EUCC).
The EUCC provides a unified assessment process specifically for certifying the security of ICT products, including software, hardware and technological components such as microchips and smartcards. The scheme classifies products under two defined assurance levels based on risk:
While obtaining an EUCC certificate is inherently voluntary, it is increasingly important for demonstrating compliance with other mandatory frameworks, such as the NIS2 Directive and the CRA. Following a transition period, ANSSI issued France’s first EUCC certificates in 2025.
The Proposed Cybersecurity Act 2
In January 2026, the European Commission proposed a comprehensive cybersecurity package including a Cybersecurity Act 2 (CSA2), alongside targeted amendments to the NIS2 Directive. This proposal shifts the regulatory focus towards systemic vulnerabilities by introducing the EU’s first horizontal framework for ICT supply chain security. It empowers the European Commission to identify “key ICT assets” and prohibit entities from utilising components from high-risk suppliers. Furthermore, the CSA2 broadens the scope of the certification framework beyond individual products to include managed security services and the overall “cyber posture” of an organisation.
French National Framework: ANSSI Security Visas
At the national level, ANSSI issues “Security Visas” to validate the trustworthiness of cybersecurity solutions, making a clear distinction between two mechanisms.
Sovereign Cloud Certification: SecNumCloud 3.2
Under the French government’s “Cloud au Centre” doctrine, French State administrations, their operators and certain public interest groups that use cloud services to host or process particularly sensitive data (ie, data covered by secrets protected by law and data necessary for essential State functions) must choose cloud services implementing security and protection measures that effectively prevent unauthorised access by non-EU authorities, a condition that in practice requires using SecNumCloud-qualified solutions. Version 3.2 imposes rigorous sovereignty requirements to prevent extraterritorial interference (eg, under the US CLOUD Act, the FISA or the PATRIOT Act).
Sector-Specific Certifications: Healthcare
France heavily relies on sector-specific certification schemes for critical industries such as healthcare. In this regard, any entity hosting personal health data collected in certain conditions must obtain the mandatory HDS certification (see 6.3 Cybersecurity in the Healthcare Sector for detailed obligations).
Platform Transparency: the Cyberscore Law
The Cyberscore Law introduced a French legal framework for cybersecurity certification – commonly referred to as the “Cyberscore” – applicable to consumer-facing digital platforms, by amending the French Consumer Code. This certification aims to require certain online platforms to carry out a cybersecurity audit of their services (including data security and localisation) and to inform users in a clear, visible way about the level of security of their data.
Although the law entered into force on 1 October 2023, its practical application has been stalled, as the necessary decree and implementing order detailing which platforms are covered, the thresholds and the precise audit criteria have never been published. As a result, three years after adoption, the Cyberscore scheme is still not operational.
Cybersecurity overlaps heavily with data protection under the GDPR and the FDPA, stringently enforced by the CNIL. The principle of integrity and confidentiality, requiring personal data to be processed in a manner that ensures appropriate security against unauthorised processing, loss or destruction, forms part of the core principles of the GDPR. This is operationalised through obligations mandating controllers and processors to implement technical and organisational measures appropriate to the risk.
In the event of a personal data breach, controllers are required to notify the relevant supervisory authority (in France, the CNIL) within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. This notification, submitted via the dedicated CNIL portal, must describe:
If the breach poses a high risk to individuals’ rights and freedoms, affected data subjects must also be notified without undue delay.
It should be noted that the European Commission’s proposed “Digital Omnibus”, published in late 2025, includes provisions modifying the GDPR seeking to streamline incident reporting to extend the supervisory authority notification deadline to 96 hours.
The CNIL actively sanctions organisations for fundamental IT hygiene failures. Enforcement is increasingly driven by a close collaboration with ANSSI. In 2024, the CNIL published an updated “Practice guide for the security of personal data” that heavily integrates ANSSI’s recommendations. In practice, the CNIL treats ANSSI’s guidelines as the legal “state of the art” during investigations and enforcement procedures.
As an illustration, in January 2026, the CNIL levied a record cumulative fine of EUR42 million against telecoms operators FREE MOBILE and FREE following a massive data breach affecting 24 million subscribers in October 2024. The CNIL, notably applying Article 32 of the GDPR, cited severe negligence, including weak VPN authentication (lack of MFA) and ineffective intrusion detection systems, directly benchmarking the companies’ failures against the expected ANSSI standards.
Cybersecurity obligations for AI are rapidly evolving, driven by the AI Act and intersecting heavily with existing data protection frameworks.
Security-by-Design and Component Security
The AI Act mandates that “high-risk” AI systems achieve declared levels of accuracy, robustness and cybersecurity before being placed on the market and throughout their life cycle. This embeds a strict security-by-design expectation, requiring resilience against adversarial attacks, data poisoning and model manipulation.
General purpose AI (GPAI) models presenting systemic risks face additional burdens, including mandatory adversarial testing and robust cybersecurity protections.
Incident-Reporting Requirements
Under the AI Act, the primary duty to track, document and formally report serious incidents rests with the providers of high-risk AI systems and GPAI models with systemic risk. They must report incidents, including severe cybersecurity breaches or malfunctions, to the competent market surveillance authorities or the European AI Office (for GPAI models) without undue delay. Other operators, such as deployers, have a related duty to inform the provider and competent authorities of any serious incidents they identify.
The European Commission’s “Digital Omnibus” proposal aims to streamline this landscape by introducing a single-entry point for incident reporting, effectively unifying notification obligations under the AI Act, the NIS2 Directive and the GDPR.
Interaction With General Cybersecurity and Data Protection
The AI Act clearly states that its application is without prejudice to that of the GDPR. The texts are therefore complementary, and certain resources developed within the framework of the GDPR can be used as a basis for compliance with the AI Act (in particular, data protection impact assessments).
In France, the CNIL published recommendations in 2024 and 2025 concerning the development of AI systems. Aligning with EDPB Opinion 28/2024, the CNIL emphasises that AI models generally fall within the scope of the GDPR due to the memorisation capabilities of models trained on personal data. The CNIL has dedicated practical how-to sheets to guide professionals, including on ensuring the security of AI development, which outlines the precise risks and measures to consider during the design phase to guarantee that AI systems are built in a secure environment.
Governance and Threat Landscape in France
With regard to governance, the French government has recently proposed a decentralised regulatory model for AI, with the DGCCRF acting as the central operational co-ordinator. Control responsibilities would be divided among sectoral authorities (mainly the CNIL, Arcom and DGCCRF). The CNIL in particular would play a major role, being responsible for the oversight and enforcement of most prohibited practices and obligations relating to high-risk AI systems falling under Annex III of the AI Act. However, the CNIL would not have any role in relation to high-risk AI systems covered under Annex I of the EU AI Act. ANSSI and the Pôle d’Expertise de la Régulation Numérique would provide pooled technical support. This government proposal is currently subject to parliamentary approval.
Finally, in February 2026, ANSSI published a threat intelligence report (CERTFR-2026-CTI-001) on generative AI facing cyber-attacks. The report notes that, while generative AI cannot yet autonomously execute full attacks from end to end, it is increasingly integrated into attacker toolsets for victim profiling, social engineering and malware development, lowering the barrier to entry for less experienced actors. Furthermore, the report warns that generative AI systems (such as LLMs) themselves are lucrative targets, highly susceptible to model poisoning, software supply chain compromises and data exfiltration.
The healthcare sector faces strict cybersecurity obligations to protect sensitive medical data across health sector entities, medical devices and electronic health record (EHR) systems.
Health Sector Entities and EHR Systems
Entities handling electronic health records must comply with the General Security Policy for Health Information Systems (PGSSI-S) established by the ANS.
Furthermore, any entity hosting health data collected in the course of prevention, diagnosis, care or social and medical-social follow-up activities must hold the HDS certification. Technical operations considered to be part of the hosting activity notably include:
The updated HDS Version 2.0 (mandatory by May 2026) introduces stringent data sovereignty rules, requiring all health data storage to reside exclusively within the EEA and mandating explicit transparency for any remote access from outside the EEA.
The certification requires audits by independent bodies accredited by the French Accreditation Committee (COFRAC). Failure to comply carries severe risks, including criminal penalties.
Sector-Specific Incident Reporting
France imposes stringent sector-specific incident-reporting obligations. As such, healthcare establishments, bodies and professionals must immediately report significant security incidents affecting their health information systems to the competent state authorities. This reporting is typically facilitated through the regional health agencies (ARS) and the dedicated CERT Santé.
Medical Devices
Connected medical devices must satisfy the General Safety and Performance Requirements (GSPR) under the EU Medical Device Regulation (MDR). To obtain CE marking and market access, manufacturers must integrate cybersecurity across the software life cycle, commonly utilising the universally recognised EN IEC 81001-5-1:2022 standard.
Procurement-Related Security
In public procurement, health data security is increasingly tied to national sovereignty. For instance, recent government tenders for major infrastructures such as the national Health Data Hub explicitly mandate that providers hold an ANSSI SecNumCloud qualification, effectively excluding standard foreign cloud offerings to immunise public health data against extraterritorial laws.
9 avenue de Messine
75008 Paris
France
+33 1 4456 4456
jerome.philippe@freshfields.com www.freshfields.com
Introduction
Cybersecurity threats in France have exploded in recent years. According to the French Ministry of Home Affairs’ 2026 Annual Report on Cybercrime, 453,200 cyber-attacks were recorded in France in 2025, representing an 87% increase in five years. This surge is confirmed by French Cybersecurity Agency (ANSSI) CERT-FR’s Cyber Threat Landscape 2025, published in March 2026. The report records 1,366 incidents notified to ANSSI in 2025. It is also reflected in the 2025 cybersecurity reportof the CNIL, or French Data Protection Authority, which shows that it received 5,629 data breach notifications in 2024, averaging almost 15 notifications per day, with 596 notifications of breaches resulting from ransomware attacks. Even a significant number of the government’s confidential and sensitive files (including files for ID documents and requests to carry weapons) have been compromised.
These figures illustrate a worrying reality: that digital transformation of businesses and government agencies is boosting their exposure, while cybercriminals’ tools are becoming increasingly sophisticated and accessible (with, for example, the development of CaaS, or “Cybercrime as a Service”). Artificial intelligence (AI) significantly expands the arsenal available to cybercriminals: automated generation of malicious code, hyper-personalised phishing, as well as voice and face spoofing capable of convincingly replicating a trusted interlocutor. Under these conditions, cybercrime is becoming an extremely lucrative activity.
This escalating threat has triggered a multi-faceted national response. France is countering this wave of attacks through new cybersecurity strategies, stringent regulatory enforcement led, in particular, by the CNIL against operators that fail to adequately secure their information system – and an increasingly close collaboration between its key agencies. This dynamic landscape is further defined by the transformation of technical “best practices” into legal standards, raising the compliance stakes for all organisations operating in the country.
The Evolving Threat Landscape in France: Scale, Cost and Sophistication
A wave of diversified personal data breaches
In recent years, France has been the scene of massive personal data leaks due to cyber-attacks affecting a wide variety of players (eg, Internet service providers, third-party payment operators, mobile phone operators, e-merchants, public services, etc) and tens of millions of citizens. Cyber-attackers sometimes manage to exfiltrate sensitive information – such as medical data – but also, as several recent cases have shown, bank details (eg IBAN, BIC, bank names) and, as already indicated, sensitive government information. These breaches can clearly have harmful consequences: following a data leak, personal information is often resold on the dark web and exploited by malicious third parties to perfect phishing attacks on the victims of the initial breach.
Beyond the harm to individuals, the financial cost on the affected organisations should be considered. A June 2024 survey conducted by ANSSI among cybersecurity professionals reveals the scale of these costs: a single cyber-attack costs an average of EUR466,000 for a small or medium-sized company, rises to EUR13 million for a mid-sized company, and can reach hundreds of millions for the largest companies. This financial impact consistently represents 5% to 10% of an organisation’s annual revenue (consisting of operating losses (50%), the cost of external support services (20%), the cost of restoration and investment in the information system (20%), and reputational costs (10%)).
2025/26 has been marked by a series of high-profile incidents, each exposing vast quantities of personal data. For instance, in August 2025, the telecommunications sector was hit hard with a major breach at a major French carrier, compromising some personal details of its subscribers. The healthcare sector faced another profound crisis later that year with an attack on medical software provider Cegedim Santé, resulting in the exfiltration of highly sensitive patient health data. Toward the end of 2025, an intrusion affecting the Ministry of the Interior led to extremely sensitive personal files being compromised, including criminal records and national security watchlists (fiche S).
AI is a game changer for cyber-attacks
AI is significantly expanding the arsenal of cybercriminals, from software attacks (such as the automated generation of malicious code to avoid detection or vulnerability scanning) to social attacks (such as hyper-personalised phishing, ultra-realistic document forgery, or voice-and-face spoofing capable of convincingly replicating a trusted interlocutor). These techniques create profound risks for individual privacy and data protection. For businesses, cybersecurity and employee awareness must therefore be considered a strategic priority. The most recent events relating to Claude Mythos’ forced temporary restriction and to the compromise of Hugging Face by an OpenAI agent show that AI risk in cybersecurity is even higher than expected.
This reality is acknowledged by the CERT-FR, the French Computer Emergency Response Team (CERT) for governmental agencies operated by ANSSI in its February 2026 report Generative artificial intelligence (GenAI) against computer attacks. It indicates that while, to date, ANSSI has not observed a fully autonomous cyber-attack carried by AI against a French entity, it is more than plausible that these technologies are already empowering cyber-attackers (eg, by the design of social engineering and recognition content, development of malicious code, identification of information of interest). A large number of zero-days vulnerabilities have been detected by AI that are not currently patched.
It points out thatthe AI systems themselves are vulnerable to new potential attack vectors at different stages: during the model’s training (eg, by entering corrupt or false data), its integration into other systems (eg, by implementing backdoors), and during the querying process itself (eg, by injecting false information, prompting to bypass security measures or retrieving confidential information.
In response to these emerging threats, the CERT-FR recommends consulting the specific guide published by ANSSI on securing generative AI systems, which contains recommendations for implementing generative AI solutions based on Large Language Models.
CNIL and ANSSI’s Continuous Collaboration
To foster a more resilient and harmonised security landscape, the French authorities are increasingly emphasising close operational collaboration, particularly between the data protection and cybersecurity agencies. This commitment was stated as a key objective within the CNIL’s strategic plan for 2025-28. The plan explicitly calls for robust collaboration with authorities such as ANSSI to ensure the consistent enforcement of new national and European obligations, including the NIS2 directive, DORA and the broader “cyber package”, preventing conflicting guidance where data protection and cybersecurity rules intersect.
This synergy is clearly demonstrated by the CNIL’s updated 2024 Practice Guide for the Security of Personal Data, which now heavily integrates ANSSI’s technical recommendations. This is also evident in joint publications, such as their shared Recommendations Regarding Multi-Factor Authentication and Passwords of 8 October 2021.
This unified approach also addresses the challenges of emerging technologies, such as AI models. A key example is the PANAME project (Privacy Auditing of AI Models), launched in June 2025 jointly by the CNIL, ANSSI and academic partners such as PEReN and the IPoP project. This initiative aims to develop a practical, open-source tool to audit the confidentiality of AI models, enabling organisations to conduct effective and low-cost technical assessments to verify General Data Protection Regulation (GDPR) compliance. It will take the form of a library enabling extraction and/or re-identification tests to be carried out on AI models.
Data Security Under CNIL’s Scrutiny
The CNIL’s stringent enforcement approach over data security
Faced with a wave of personal data leaks, the CNIL now finds itself on the front line. Under the GDPR, affected companies must react quickly: the data controller – the entity that decides on the purposes and means of processing – has 72 hours after becoming aware of a breach to notify the CNIL of the incident unless the incident is unlikely to pose a risk to individuals. This initial mandatory notification may be supplemented at a later date once initial investigations have been carried out.
The CNIL then examines whether the security measures put in place before the incident, as well as those deployed in response to it, as described in the notification form, are sufficient. Based on this assessment, it may decide to open an investigation to further examine the circumstances of the breach. If the security incident reveals insufficient protective measures, the CNIL may sanction the company.
In 2025, insufficient security of personal data was one of the three main grounds for sanctions under the CNIL’s simplified procedure, in addition to failure to cooperate with the CNIL and failure to respect individuals’ rights. In fact, a breach relating to the security of personal data was found against 14 organisations that had not implemented all the necessary measures to ensure data security and confidentiality, such as the use of insufficiently robust passwords or of accounts shared between users. This proves that cybersecurity remains a weak point for many organisations, and a major focus for the CNIL.
A trio of recent sanctions against FREE MOBILE (a EUR27 million fine),France Travail (a EUR5 million fine), and software editor NEXPUBLICA FRANCE (a EUR1.7 million fine) reveals a common thread: the CNIL is not sanctioning the occurrence of a breach as such, but the underlying and often-documented lack of diligence that made it possible – frequently qualifying these failures as “negligence” or even “gross negligence”.
Common failings condemned across these decisions include:
The targets – a major private telecom operator (FREE MOBILE), a national public institution (France Travail), and a software provider (NEXPUBLICA) – show that neither sector nor status provides a shield. The CNIL explicitly held NEXPUBLICA responsible as a data processor with its own autonomous security obligations under Article 32 GDPR and rejected arguments that France Travail’s public status should exempt it from significant fines. The message is clear: a failure to act on known risks and adhere to the established “state of the art” carries severe consequences for all types of organisations.
The growing legal weight of ANSSI’s standards in CNIL enforcement
A significant development in French enforcement is the increasing application of ANSSI’s technical guidelines as an authoritative benchmark by the CNIL. While not laws themselves, these guidelines are now consistently used by the CNIL as a benchmark for assessing compliance with the GDPR. This practice effectively elevates ANSSI’s guidance from mere “best practice” to a key reference for demonstrating GDPR compliance.
This principle was applied with significant force in the major sanctions of 2025 and 2026.
In its decision against FREE and FREE MOBILE, the CNIL explicitly pointed to the companies’ failure to implement multi-factor authentication (MFA) on their VPN access as an act of negligence, directly benchmarking this failure against the established recommendations published by ANSSI and the CNIL itself. In its ruling, the CNIL recalled that, while recommendations from the CNIL and ANSSI are not mandatory in themselves, they serve to “specify and illustrate” the applicable laws and to define the concrete “state-of-the-art” measures that organisations are expected to implement.The authority concluded that the security measures that would have prevented or limited the breach were “clearly identified by the state of the art”, and emphasised that the companies possessed the necessary human, technical, and financial means to implement them, rendering the failure an act of negligence.
Similarly, in the France Travail decision, the CNIL condemned the company for its inadequate security measures by directly referencing its own, as well as ANSSI’s, recommendations, such as the latter’s regarding multi-factor authentication and passwords of 2021, as well as its security recommendations for the architecture of a logging system of 2 December 2013 (updated in 2022). The CNIL ultimately concluded that these failures resulted from gross negligence, as France Travail had “omitted to take into account the state of the art, the consistent doctrine of the CNIL and ANSSI, as well as the recommendations that had been made to it”.
In the decision against NEXPUBLICA FRANCE, a key finding was the company’s use of the SHA-1 hashing algorithm, a technology the CNIL noted had been deemed obsolete and vulnerable by ANSSI as far back as 2017. This was presented as a clear-cut failure to adhere to the established state of the art.
This enforcement approach is supported by a decision from France’s highest administrative court (Conseil d’État). On 11 March 2015, the court ruled that the CNIL can legitimately “take [its recommendations] into account to assess compliance” with the law. This principle was reaffirmed by France’s highest administrative court in 2024, considering that the CNIL could use its own password recommendation not as a binding rule in itself but as a benchmark to “assess the respect” of Article 32 of the GDPR. In this latter decision, the court applied the same logic to ANSSI’s technical standards, ruling that, even if they “lack normative value”, the CNIL could legally refer to them to “explain the good technical practices” that allow it to ensure a level of security appropriate to the risk as required by Article 32 of the GDPR.
The practical implication for any organisation operating in France is therefore clear: companies must now treat ANSSI’s technical guides and the CNIL’s security recommendations as integral components of their GDPR compliance programme. Ignoring these standards creates a risk as, in the event of a data breach, the CNIL will almost certainly use these national publications to define the expected “state of the art”. A deviation from the standards could be interpreted as a failure to implement appropriate measures under Article 32 of the GDPR.
The Cyber-Attack Criminal Complaint Process
A tangible manifestation of this priority is the creation in 2023 of a requirement in L12-10-1 of the French Insurance Code for victims of cyber-attacks to file a criminal complaint within 72 hours of the discovery of the breach to be eligible to cyber-insurance coverage. This requirement, aligning in practice with the delay to inform CNIL, was created to provide visibility to law enforcement authorities on cyber-attacks, and in particular on ransomware attacks that may lead to payments.
This means, in practice, that cyber-attack victims must coordinate rapidly with their incident response providers and legal counsel to gather the factual background to notify regulators and inform law enforcement. A criminal complaint in such circumstances typically includes:
Companies and their counsel can leverage the information gathered by their internal and external IT providers, such as incident timelines and initial descriptions of the vectors used.
The criminal complaint should include the relevant documentation (such as appropriate logs) and form part of a comprehensive response plan to ensure its accuracy, consistency with notifications to other authorities (eg, the CNIL). In the criminal complaint process, companies and their counsel should also assess whether the description of protective measures (or lack thereof) could expose them to regulatory enquiry in order to anticipate such risks.
The complaint can be filed at a police station or local gendarmerie (in which case the complaint is prepared by law enforcement, based on the complainant’s statements), or by letter to the local public prosecutor’s office. In Paris, the J3 section of the Criminal Prosecutor office is specialised for cyber matters and is leading a large number of major investigations, often in coordination with its foreign equivalents.
Criminal complaints regarding cyber-attacks cannot currently be filed online. While two online criminal complaint processes exists in France (the general Online Criminal Complaint service and the THESEE platform for online fraud), they are limited to certain offenses and cyber-attacks strictly speaking are outside the scope of this tool.
French Courts Redrawing the Boundaries for Data Collection and AI Use in Investigations
Recent judicial decisions and legislative initiatives are also redrawing the boundaries for data collection and use in investigations by both private and public actors.
Judiciary’s restrictive interpretation of open-source data collection
In a ruling of 30 April 2024, the Criminal Chamber of the French Court of Cassation provided important clarifications on what constitutes the “unfair collection” of personal data, particularly when that data is publicly available online.
The case concerned a private investigator hired by a company to conduct background checks on individuals such as employees and job candidates. The investigations involved cross-referencing data from publicly accessible sources (social media, directories, forums, and regional press sites) covering matters such as criminal records, banking information, health data, and travel history. The court held that the public accessibility of the data did not strip the collection of its unreliable nature on two grounds: (i) the data was exploited for purposes (namely, covert profiling and investigation into the private lives of the individuals concerned) entirely unrelated to the reason for which it had been made available online; and (ii) the collection was carried out without the knowledge of the data subjects, thereby depriving them of the right of object under the French Data Protection Act.
On the substance of the law, the court therefore confirmed that such practices constitute the criminal offence of collecting personal data by unfair means under Article 226-18 of the French Criminal Code sanctioning the collection of personal data by fraudulent, unfair or unlawful methods.
While the ruling provides a reminder that public availability does not confer an unrestricted right to collect and exploit personal data, its reasoning warrants careful reading. It does not call into question the principle that, within certain legitimate investigative contexts – such as pre-litigation intelligence gathering or fraud detection – the collection of data without the prior knowledge of the individuals concerned may be lawful where prior disclosure would fundamentally undermine the purpose of the processing, as expressly covered by the derogations set out in Articles 14(5)(b) and 14(5)(d) of the GDPR. Rather, the decision should be understood as a fact-specific condemnation of a particularly egregious case involving collecting and cross-referencing a wide array of highly personal data for the purposes of investigating private lives. This case sends a clear signal that the absence of a transparent and proportionate framework for such data collection carries significant legal risk, including criminal liability. Nonetheless, a part of the OSINT (Open Source Intelligence) community is now calling for a higher level of legal recognition of that activity (see below).
Authorisation of AI-altered identity techniques for undercover online investigations
Act No 2025-532 of 14 June 2025 (also known as the “Loi Narcotrafic”) introduced a discrete but significant amendment to Article 230-46 of the French Code of Criminal Procedure which governs investigations conducted under pseudonym for offences perpetrated online. The new provision authorises investigators, subject to certain conditions and within the context of such operations, to use technical “devices enabling the alteration or transformation of their voice or physical appearance”. This constitutes a clear legal gateway for the use of AI-generated deepfake techniques (voice synthesis, facial transformation) by law enforcement. This amendment, driven by operational requests from investigators and magistrates confronting the increasing sophistication of criminal networks, is the first implicit authorisation of such AI-driven tools in the French Code of Criminal Procedure. The amendment also extends the use of such tools across several investigative regimes, and may serve as a precedent for the use of similar technologies in other categories of criminal investigations.
Proposed regulation of OSINT activities and the debate over the use of leaked data
A legislative debate has emergedaround the legal framework for open-source intelligence (OSINT) in France, pursued through both a dedicated legislative proposal by MP Philippe Latombe and a potential amendment to the bill on critical infrastructure resilience and cybersecurity currently before the National Assembly, which notably transposes the NIS2 Directive into French law. While the collection of genuinely public information raises few legal difficulties, the core issue is more contentious: the reuse of data made publicly accessible as a result of a cyber-attack. A two-year working group hosted by the IHEDN’s cyber chair and the Alliance pour la Confiance Numérique (ACN) concluded that cybersecurity professionals face significant legal uncertainty when exploiting such leaked data, which could amount to the offense of receiving (ie, handling the product of criminal activity) under French criminal law – a concern echoed by the head of the cyber section of the Paris Prosecutor’s office.
The working group advocates for introducing an explicit exemption for the handling of leaked data modeled on the existing exemption under Article 323-3-1 of the Criminal Code. The latter provision de-criminalises the possession or distribution of hacking tools when carried out for a “legitimate motive”, citing research and IT security as key examples.
The proposal remains contested: critics warn that it could enable private actors to build vast personal data repositories under the guise of cybersecurity, and six OSINT practitioner organisations have stated that they do not support legalising the use of breach-derived data. This initiative remains under active parliamentary discussion and will be an important development to monitor.
Key Takeaways for Businesses
The convergence of accelerated threats, stringent enforcement, and the hardening of technical guidance into legal standards demands an immediate and strategic change in how businesses approach cybersecurity.
In this regard, organisations must reassess their security baseline as a matter of priority, treating the published guidance from both the CNIL and ANSSI not as optional advice but as the default, expected standard for compliance.
This forward-looking stance is also essential preparation for the next wave of European legislation. Forthcoming frameworks, such as the NIS 2 Directive, will impose more prescriptive security obligations and notification timelines across a wide range of organisations.
Close cooperation between the Data Protection Officer (DPO), Chief Information Officer (CIO), and Chief Information Security Officer (CISO) are now more critical than ever, notably to orchestrate the management of the upcoming obligations (eg, incident notifications) and ensure state-of-the-art security measures. More than ever, cybersecurity, cyber-awareness and cyber good practices within companies have become C-suite matters.
9 avenue de Messine
75008 Paris
France
+33 1 44 56 44 56
jerome.philippe@freshfields.com www.freshfields.com/