GDPR Policy Generator France
GDPR plus the Loi Informatique et Libertés, CNIL cookie doctrine and the mentions légales duty.
CNIL supervision leans on documented retention and documented consent. Its référentiels give you a benchmark, and departing from one without a reasoned justification is the finding that tends to escalate.
France applies GDPR through the Loi Informatique et Libertés, and the CNIL is one of the most active regulators in Europe on the specific question of cookies. Its recommendation that refusing must be as simple as accepting was backed by fines in the tens and hundreds of millions against the largest advertising platforms, and it has continued down the long tail since.
The CNIL also publishes référentiels - sector reference frameworks for HR data, health research, customer management and more. They are not binding in the way a regulation is, but departing from one is something you are expected to justify.
Alongside data protection, French e-commerce carries its own disclosure regime: mentions légales identifying the publisher and host, CGV setting sale terms, and Code de la consommation rules on the fourteen-day withdrawal right and the two statutory guarantees.
What a GDPR policy in France has to cover
A registre des traitements in French covering every processing activity
Retention schedules mapped to the applicable référentiel
AIPD (DPIA) for processing on the CNIL’s mandatory list
Consent proof for cookies and prospection, retained and retrievable
Breach notification to the CNIL within 72 hours with the internal escalation path defined
How France actually moves personal data
Audience measurement under the CNIL exemption
France allows a narrow consent exemption for strictly first-party, non-shared audience measurement configured to CNIL parameters. Standard Google Analytics does not qualify; a properly configured Matomo instance can.
Prospection commerciale
B2C email marketing needs prior opt-in; B2B is permitted on a professional address where the message relates to the person’s role and an opt-out is offered. The distinction is French-specific and frequently missed.
Health and wellbeing data
French rules on health data are stricter than the GDPR baseline, and hosting health data on behalf of others requires an HDS-certified host.
HR and recruitment records
The CNIL HR référentiel sets expected retention - typically two years for unsuccessful applicants - and restricts what may be collected during recruitment.
Cookie consent proof
The CNIL asks operators to demonstrate consent. In its enforcement decisions the evidence examined was the live banner behaviour, not the wording of the cookie policy.
Third parties the draft will ask you about
Stripe · Lydia · Chronopost and Colissimo · OVHcloud · Scaleway · Matomo · Sendinblue/Brevo · Salesforce · Google Workspace
The rules that apply
Loi Informatique et Libertés + GDPR
The French implementation, including the age of digital consent set at fifteen and specific rules on health and research data.
CNIL cookie recommendation
Refusal as easy as acceptance, no consent by continued browsing, consent lifetime of about six months before re-asking, and a documented audience-measurement exemption if you rely on it.
Mentions légales
Publisher identity, director of publication, and the host’s name and address must be published - a duty from the LCEN, separate from privacy law.
Code de la consommation
Fourteen-day withdrawal, the garantie légale de conformité and the garantie des vices cachés, plus mandatory pre-contractual information.
CNIL référentiels
Sector frameworks covering customer management, HR, health and more. Divergence is permitted but has to be reasoned.
What the generated GDPR policy contains
Article 13 and 14 transparency notice
The full disclosure set, split by whether the data came from the person or from somewhere else.
Lawful basis register
Every processing activity mapped to one of the six bases, with the legitimate interests assessment written down where you rely on that basis.
Records of processing (Article 30)
The internal register a supervisory authority can ask for at any time, covering purposes, categories, recipients, transfers and retention.
Data subject rights procedure
How a request arrives, how identity is verified, who handles it, and the one-month clock with its two-month extension.
International transfer mechanism
Adequacy, SCCs with a transfer impact assessment, or the UK IDTA/addendum - named per destination, not asserted in general.
Breach detection and 72-hour notification
The internal escalation path, the assessment test, and the template for notifying the regulator and, where required, the individuals.
Processor and sub-processor controls
Article 28 terms, the sub-processor list, and the change-notification commitment your customers will ask for.
The French checklist
Publish mentions légales
Identity of the publisher, the director of publication, and the host’s name, address and telephone number.
Configure the banner symmetrically
Accept and refuse at the same level, same visual weight, same number of clicks. Store the choice for roughly six months.
Decide honestly whether the analytics exemption applies
If it does not, analytics fires only after consent.
Set the age of digital consent to fifteen
Below that, parental authorisation is required for consent-based services.
Publish CGV before checkout
The general conditions of sale must be accessible and acceptable before the order is confirmed, with a payment-obligation button.
Where this usually goes wrong
A banner where "Tout accepter" is a button and refusal is a link
This is the exact configuration the CNIL fined. Symmetry is the test.
Claiming the audience-measurement exemption while sharing data
The exemption dies the moment the measurement data is used for anything else or shared with the provider for its own purposes.
Missing mentions légales
Publisher, director of publication and host details are required by law and are trivially checkable by anyone.
English-only notices for a French audience
The Toubon law and Article 12 transparency both point the same way: if you sell in France, the notice should be in French.
Treating B2B prospection as unrestricted
It is permitted without prior consent only where the message relates to the recipient’s professional function and an opt-out is present in every message.
Frequently asked questions
Does my privacy policy have to be in French?
If you target French consumers, yes in substance. Article 12 requires intelligible language for the audience and French consumer law reinforces it. A French version alongside English is the safe configuration.
Can I use Google Analytics in France?
The CNIL has issued formal notices over standard Google Analytics configurations and transfers. It is possible to use analytics lawfully with consent and appropriate transfer safeguards, but the consent-free exemption is designed around tools that do not share data, not around GA.
How long can cookie consent last?
The CNIL recommends re-asking after about six months, and treats an indefinitely stored acceptance as a problem. Refusals should be remembered for a comparable period so the banner does not nag.
What are mentions légales?
A statutory legal notice identifying who publishes the site, who is responsible for its content, and who hosts it. It is separate from the privacy policy and from the CGV, and all three are expected.
Does GDPR apply to a business outside the EU?
Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.
What is the difference between EU GDPR and UK GDPR?
The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.
Do I need a Data Protection Officer?
Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.
Is a GDPR policy the same as a privacy policy?
No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.
GDPR Policy Generator France
Answer a short questionnaire and get a draft written for France. Free to start, no card required.
Generate your GDPR policyOther documents for France
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.