France Data Protection Authority CNIL: All What You Need to Know

The Commission nationale de l'informatique et des libertés (CNIL) is France's independent data protection authority, established in 1978 and one of the most active GDPR enforcers in Europe with over €1B in cumulative fines. Complete 2026 reference covering role, powers, recent enforcement (Google €325M, Shein €150M), the July 2026 email pixel consent deadline, and how to file complaints.
Alaa
By Alaa
SMTPedia documents email infrastructure end to end: SMTP standards from the RFC archive, delivera...
7 min read Updated Jul 29, 2026 55 views

The Commission nationale de l’informatique et des libertés (CNIL) is France’s independent data protection authority and one of the most active GDPR enforcers in the European Union. Founded in 1978, forty years before GDPR, the CNIL has become the second-largest enforcer by cumulative fines behind Ireland’s DPC, crossing €1 billion in issued penalties. It publishes the most detailed sector-specific guidance in Europe on cookie consent, ad tech, and, since April 2026, email tracking pixels.

Commission nationale de l’informatique et des libertés (CNIL) · Established 6 January 1978 under Loi Informatique et Libertés · Chaired by Marie-Laure Denis since 2019 · Based at 3 Place de Fontenoy, 75007 Paris · Independent administrative authority (autorité administrative indépendante), reporting to Parliament · Enforces GDPR, French Data Protection Act, ePrivacy Directive as transposed by LCEN, and cookie rules under Article 82 of the Data Protection Act · Max fine: €20M or 4% of global annual turnover.

1978
World’s first independent data protection authority (predates GDPR by 40 years)
€1B+
Cumulative GDPR fines: second-largest EU enforcer after Ireland’s DPC
€486M
Total fines issued in 2025 alone across 83 sanctions
€325M
Google decision (Sept 2025): largest CNIL fine to date

Role and powers

The CNIL is one of the earliest and most independent data protection authorities in the world. Under the 2004 amendments to the Loi Informatique et Libertés and the 2016 loi pour une République numérique, it holds four core mandates:

  • Enforcement. Investigations, formal notices (mise en demeure), corrective measures, and administrative fines up to €20M or 4% of global annual turnover under GDPR Article 83. Sanctions are issued by the CNIL’s restricted formation (formation restreinte) after adversarial proceedings.
  • Guidance. The CNIL publishes sector-specific recommendations that carry significant persuasive authority across the EU. Its cookie guidelines (2019, updated 2020, 2022), ad-tech doctrine (Criteo €40M decision, 2023), and April 2026 email pixel recommendation are widely followed.
  • Approvals. Codes of conduct, certification schemes, standard contractual clauses for international transfers, and binding corporate rules for multinational groups.
  • Individual redress. The CNIL handles complaints from data subjects and can order controllers to grant access, correct data, or delete personal information. Approximately 15,000 complaints per year are processed under a simplified procedure introduced in 2022.

Recent enforcement highlights

Sept 2025
Google €325M
Advertisements inserted between Gmail messages without consent, invalid consent flow during account creation. Largest CNIL fine to date.
Sept 2025
Shein €150M
Cookie consent failures, deceptive consent design, tracking pixels without valid opt-in on the French shein.fr domain.
Dec 2025
Optimove (Deezer processor) €1M
UK-registered marketing technology processor fined for retaining 46.9M Deezer users’ data after contract termination.

Other recent notable decisions include Criteo €40M (June 2023, upheld March 2026) for pre-ticked consent boxes in real-time bidding, Carrefour Group €3.05M for unsubscribe failures, IQVIA France €5M (May 2026) for inadequate safeguards on health data warehouses, and a €3.5M penalty against an unnamed loyalty programme operator (December 2025) for combining customer data with social-network data for ad targeting without valid consent.

2026 enforcement priorities

Email pixel consent: hard deadline 14 July 2026. The CNIL published its final recommendation on tracking pixels in marketing email on 14 April 2026. From 14 July, existing subscribers require explicit consent for open-tracking pixels, and any subscriber added after 14 April 2026 must have given consent from day one. The recommendation applies to CNIL’s own jurisdiction — France — but is expected to be adopted by other EU DPAs. Beyond email pixels, the 2026 priority list covers information and transparency (aligned with EDPB’s coordinated enforcement action), mobile app data collection, cybersecurity measures by local authorities, prison administration data processing, and the right to erasure.

How to file a complaint

  • File online via cnil.fr/plaintes or by post to Commission nationale de l’informatique et des libertés, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.
  • Include the data controller’s name, a description of the alleged violation, and any evidence in your possession (screenshots, email exchanges, response to a prior data subject request).
  • The CNIL first attempts an amicable resolution. If the controller does not remedy the issue within one month, a formal investigation can be opened.
  • Complaints from non-French residents against controllers based in France are accepted directly; complaints against controllers based in another member state are transferred to the lead supervisory authority under the GDPR one-stop-shop mechanism.
  • The CNIL provides a status update every three months by default. Public decisions are published on cnil.fr and cross-listed on the European Data Protection Board’s public register.

Common misconceptions

“The CNIL only fines multinationals.” No. CNIL’s 2024 simplified sanctions procedure produced 87 sanctions with a median penalty in the low five-figures, primarily against SMEs for cookie consent, data retention, and access-request violations. The pattern continued in 2025 with 83 further sanctions.

“A cookie banner solves consent.” No. CNIL guidance requires the banner to offer “reject all” with equal prominence to “accept all” and prohibits pre-ticked, hidden, or greyed-out reject options. The Google €150M (2022) and Shein €150M (2025) fines both rested on this exact issue.

“Email tracking pixels are exempt from consent.” No, not since 14 April 2026 in France. The CNIL’s final recommendation classifies tracking pixels in marketing email as reading/writing operations that require prior consent under Article 82 of the French Data Protection Act. The transition deadline for existing lists is 14 July 2026.

“Our controller is in Ireland so CNIL cannot fine us.” Partially true, subject to important exceptions. For cross-border processing the GDPR one-stop-shop routes the case to the lead authority. But CNIL can act directly on local infringements (Article 82 cookie violations are handled outside the one-stop-shop, and CNIL has repeatedly used this route to fine Google and Meta directly).

Frequently asked questions

How independent is the CNIL from the French government?

The CNIL is an autorité administrative indépendante with an 18-member college drawn from Parliament, the Council of State, the Court of Cassation, and civil society. Its chair is appointed by the President of France for a five-year non-renewable term. It reports to Parliament, not to the executive, and its budget is fixed by the state budget law with dedicated staff (over 300 in 2026).

Does CNIL enforce the ePrivacy Directive?

Yes, as transposed into French law through LCEN (Loi pour la confiance dans l’économie numérique) and Article 82 of the Data Protection Act. Article 82 handles cookies and equivalent tracking technologies including email pixels. Enforcement powers on Article 82 sit outside the GDPR one-stop-shop mechanism, which is why CNIL can act directly against multinational advertisers headquartered in Ireland.

What is the simplified procedure and what does it change?

Introduced in 2022, the simplified sanctions procedure allows a single member of the restricted formation to issue smaller fines (up to €20,000 in most cases) without a full adversarial hearing. It has accelerated enforcement volume from roughly 20 fines per year pre-2022 to more than 80 fines per year in 2024 and 2025.

Do CNIL decisions apply outside France?

Decisions apply directly only in France, but they carry significant persuasive weight across the EU. CNIL sits on the European Data Protection Board (EDPB) and its ad-tech, cookie, and email pixel doctrines have consistently been adopted by other member state DPAs six to eighteen months after French publication.

Where can I find CNIL’s official guidance?

All CNIL publications are available at cnil.fr, including sector-specific compliance packages (guides pratiques), model documents (privacy policies, cookie banners, DPA templates), and the searchable public sanctions register. English translations are provided for the most consequential decisions and recommendations.

Where to go next

Sending marketing email into France? Pre-validating recipient addresses with SMTPing before you press send catches disposables, catch-alls, and dead mailboxes that generate CNIL complaints. Thirteen validation types, twenty-five free checks daily, no card required. Try SMTPing free.


About the Author

Alaa - SMTPedia author

Alaa · LinkedIn

Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. I’ve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.


About SMTPedia

SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.

We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.