FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields
group-wide process roll-outs, and in advising on cybersecurity and data compliance aspects in transactions. She leads Freshfields’ knowledge management efforts for data, cyber and tech in Europe, and has collaborated with the Freshfields Lab on projects leveraging new technologies for data advice, such as the Freshfields Data Breach Notification Platform. She is fluent in French, English and German.
Freshfields 9 avenue de Messine 75008 Paris France Tel: +33 1 4456 4456 Email: jerome.philippe@freshfields.com Web: www.freshfields.com
1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy France’s national cybersecurity strategy aims to posi - tion the country as a leading cyber power in response to the evolving cyber‑threat landscape. In particular, the recently published national cybersecurity strategy for 2026–2030 develops a structured approach based on five pillars: • making France the largest pool of cyber talent in Europe by massively investing in early orientation, training and inclusion; • strengthening the nation’s cyber-resilience by rais - ing the overall level of cybersecurity across the economy and society, enhancing collective cri - sis‑response capabilities and preparing the entire nation to withstand large‑scale cyber-attacks; • hindering the spread of cyber-threats by co- ordinating all available levers – judicial, technical, diplomatic, military and economic;
• maintaining control over the security of digital foundations by maintaining and advancing mastery of critical cybersecurity technologies; and • supporting the security and stability of cyberspace in Europe and internationally by promoting a free, open and rules‑based digital space. 1.2 Cybersecurity Laws France’s cybersecurity framework is built upon a com - bination of European Union (EU) regulations, national legislation and non-binding technical standards – notably as follows. EU Regulations and Directives • Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free move - ment of such data (the General Data Protection Regulation; GDPR). • Regulation (EU) 2019/881 of the European Parlia - ment and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology
121 CHAMBERS.COM
Powered by FlippingBook