By country

GDPR Policy Generator France

GDPR plus the Loi Informatique et Libertés, CNIL cookie doctrine and the mentions légales duty.

Generate your GDPR policy Read the GDPR policy guide

CNIL supervision leans on documented retention and documented consent. Its référentiels give you a benchmark, and departing from one without a reasoned justification is the finding that tends to escalate.

France applies GDPR through the Loi Informatique et Libertés, and the CNIL is one of the most active regulators in Europe on the specific question of cookies. Its recommendation that refusing must be as simple as accepting was backed by fines in the tens and hundreds of millions against the largest advertising platforms, and it has continued down the long tail since.

The CNIL also publishes référentiels - sector reference frameworks for HR data, health research, customer management and more. They are not binding in the way a regulation is, but departing from one is something you are expected to justify.

Alongside data protection, French e-commerce carries its own disclosure regime: mentions légales identifying the publisher and host, CGV setting sale terms, and Code de la consommation rules on the fourteen-day withdrawal right and the two statutory guarantees.

What a GDPR policy in France has to cover

How France actually moves personal data

Audience measurement under the CNIL exemption

France allows a narrow consent exemption for strictly first-party, non-shared audience measurement configured to CNIL parameters. Standard Google Analytics does not qualify; a properly configured Matomo instance can.

Prospection commerciale

B2C email marketing needs prior opt-in; B2B is permitted on a professional address where the message relates to the person’s role and an opt-out is offered. The distinction is French-specific and frequently missed.

Health and wellbeing data

French rules on health data are stricter than the GDPR baseline, and hosting health data on behalf of others requires an HDS-certified host.

HR and recruitment records

The CNIL HR référentiel sets expected retention - typically two years for unsuccessful applicants - and restricts what may be collected during recruitment.

Cookie consent proof

The CNIL asks operators to demonstrate consent. In its enforcement decisions the evidence examined was the live banner behaviour, not the wording of the cookie policy.

Third parties the draft will ask you about

Stripe · Lydia · Chronopost and Colissimo · OVHcloud · Scaleway · Matomo · Sendinblue/Brevo · Salesforce · Google Workspace

The rules that apply

Loi Informatique et Libertés + GDPR

The French implementation, including the age of digital consent set at fifteen and specific rules on health and research data.

CNIL cookie recommendation

Refusal as easy as acceptance, no consent by continued browsing, consent lifetime of about six months before re-asking, and a documented audience-measurement exemption if you rely on it.

Mentions légales

Publisher identity, director of publication, and the host’s name and address must be published - a duty from the LCEN, separate from privacy law.

Code de la consommation

Fourteen-day withdrawal, the garantie légale de conformité and the garantie des vices cachés, plus mandatory pre-contractual information.

CNIL référentiels

Sector frameworks covering customer management, HR, health and more. Divergence is permitted but has to be reasoned.

What the generated GDPR policy contains

The French checklist

  1. Publish mentions légales

    Identity of the publisher, the director of publication, and the host’s name, address and telephone number.

  2. Configure the banner symmetrically

    Accept and refuse at the same level, same visual weight, same number of clicks. Store the choice for roughly six months.

  3. Decide honestly whether the analytics exemption applies

    If it does not, analytics fires only after consent.

  4. Set the age of digital consent to fifteen

    Below that, parental authorisation is required for consent-based services.

  5. Publish CGV before checkout

    The general conditions of sale must be accessible and acceptable before the order is confirmed, with a payment-obligation button.

Where this usually goes wrong

A banner where "Tout accepter" is a button and refusal is a link

This is the exact configuration the CNIL fined. Symmetry is the test.

Claiming the audience-measurement exemption while sharing data

The exemption dies the moment the measurement data is used for anything else or shared with the provider for its own purposes.

Missing mentions légales

Publisher, director of publication and host details are required by law and are trivially checkable by anyone.

English-only notices for a French audience

The Toubon law and Article 12 transparency both point the same way: if you sell in France, the notice should be in French.

Treating B2B prospection as unrestricted

It is permitted without prior consent only where the message relates to the recipient’s professional function and an opt-out is present in every message.

Frequently asked questions

Does my privacy policy have to be in French?

If you target French consumers, yes in substance. Article 12 requires intelligible language for the audience and French consumer law reinforces it. A French version alongside English is the safe configuration.

Can I use Google Analytics in France?

The CNIL has issued formal notices over standard Google Analytics configurations and transfers. It is possible to use analytics lawfully with consent and appropriate transfer safeguards, but the consent-free exemption is designed around tools that do not share data, not around GA.

How long can cookie consent last?

The CNIL recommends re-asking after about six months, and treats an indefinitely stored acceptance as a problem. Refusals should be remembered for a comparable period so the banner does not nag.

What are mentions légales?

A statutory legal notice identifying who publishes the site, who is responsible for its content, and who hosts it. It is separate from the privacy policy and from the CGV, and all three are expected.

Does GDPR apply to a business outside the EU?

Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.

What is the difference between EU GDPR and UK GDPR?

The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.

Do I need a Data Protection Officer?

Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.

Is a GDPR policy the same as a privacy policy?

No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.

GDPR Policy Generator France

Answer a short questionnaire and get a draft written for France. Free to start, no card required.

Generate your GDPR policy

Other documents for France

Each one is written for the same context, not a generic template.

The same document, by country

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.