The Commission nationale de l'informatique et des libertés is France's independent data protection authority. Created in 1978 by the Loi Informatique et Libertés — well before the GDPR existed — it supervises how personal data is processed in France, advises on legislation, investigates complaints, and issues sanctions. It is one of the most active enforcement authorities in the EEA and a significant voice within the EDPB.
What the CNIL publishes
- Deliberations, the formal instrument for its decisions, opinions and standards
- Sanctions decisions, frequently published in full and often naming the organisation
- Référentiels and standards for specific processing contexts
- Recommendations and practical guides, including its widely used cookie and tracker guidance and its PIA methodology
- Positions on emerging technology, notably artificial intelligence and mobile applications
- Formal opinions on draft French legislation
Why it matters for compliance teams
The CNIL has repeatedly set the European direction on digital tracking, and its cookie enforcement has produced some of the largest fines issued under French law. Its guidance is unusually operational — it tends to say what a compliant banner or a compliant retention schedule actually looks like, rather than restating the principle.
Seqlense DOC indexes CNIL deliberations, sanctions and recommendations in full text next to EDPB guidelines and the other national authorities applying the same regulation, so a privacy team can compare the French reading against the European baseline directly.