Cybersecurity 2026

FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields

Direct Provisions Impacting International Data Transfers GDPR The GDPR serves as the legal foundation for personal data transfers and is strictly enforced by the CNIL. Transfers outside the European Economic Area (EEA) are permitted only through lawful mechanisms such as EU adequacy decisions, Standard Contractual Claus - es (SCCs) – supplemented by a mandatory Transfer Impact Assessment (TIA) – or Binding Corporate Rules (BCRs). When a financial entity’s ICT provider pro - cesses personal data in a third country, the transfer must comply with these strict GDPR requirements, as well as any DORA obligations. DORA DORA does not impose a blanket data localisation requirement. However, it makes outsourcing to third countries conditional on maintaining full regulatory compliance and oversight. • Risk-based approach: DORA requires financial entities to conduct a thorough risk assessment before outsourcing critical or important functions to a third-country provider. This assessment must consider potential risks relating to data security, business disruption, and the ability of French supervisors to conduct effective oversight. • Guaranteed supervisory access: contracts must explicitly guarantee the access, inspection and audit rights of the financial entity and its regulators. • Extraterritorial anchor: for CTPPs, the mandatory establishment of an EU-based subsidiary ensures that DORA’s rules are enforceable regardless of the parent company’s location. The NIS2 Directive The NIS2 Directive reinforces supply chain security for all EEs and IEs. It requires entities to assess the cybersecurity practices of their direct suppliers. This includes vetting providers in third countries and con - sidering the geopolitical risks associated with their jurisdiction. In France, ANSSI is responsible for over - seeing the implementation of the NIS2 Directive. There is a strong national focus on “digital sovereignty”, meaning that outsourcing critical functions to certain third countries may be subject to greater supervisory scrutiny.

take to implement them. Failure to comply can trigger financial penalties. Financial penalties for non-compliance If a CTPP fails to comply with its obligations (eg, by refusing an inspection or ignoring a recommendation), the LO can impose significant financial penalties. This takes the form of a periodic penalty payment, calculat - ed daily until compliance is achieved. The penalty can be up to 1% of the CTPP’s average daily worldwide turnover from the preceding business year. Recommendations for contract termination Where a CTPP’s conduct poses a significant risk to financial stability and the CTPP fails to remedy the situation, the LO can recommend that financial entities suspend or terminate their service contracts with the non-compliant provider. Cross-border enforcement and co-ordination Owing to the global nature of CTPPs, enforcement is inherently cross-border. • Joint examination teams: the LO establishes a team for each CTPP, including staff from the rel - evant ESAs and national competent authorities, to ensure co-ordinated, pan-European supervision. • EU cyber crisis response: for large-scale incidents affecting multiple financial firms, enforcement actions are co-ordinated through EU-wide crisis management frameworks to ensure a unified and effective response. • Information sharing: the framework requires close collaboration between the LO and national authori - ties to ensure consistent supervision across the Union. 3.5 International Data Transfers A multi-layered framework combining the GDPR, DORA and the NIS2 Directive governs the regulation of data protection, cybersecurity and operational resil - ience.

132 CHAMBERS.COM

Powered by