Cybersecurity 2026

FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields

to moderate attacks, updated in 2025 to mandate stricter hardware and communication security against logical and relay attacks. • Qualifications: these go beyond technical robust - ness. A qualification acts as a formal government recommendation, attesting that a product or ser - vice complies with the specific regulatory, organi - sational and strategic requirements necessary for deployment by the French State or OIVs. Sovereign Cloud Certification: SecNumCloud 3.2 Under the French government’s “Cloud au Centre” doctrine, French State administrations, their opera - tors and certain public interest groups that use cloud services to host or process particularly sensitive data (ie, data covered by secrets protected by law and data necessary for essential State functions) must choose cloud services implementing security and protection measures that effectively prevent unauthorised access by non-EU authorities, a condition that in practice requires using SecNumCloud-qualified solutions. Ver - sion 3.2 imposes rigorous sovereignty requirements to prevent extraterritorial interference (eg, under the US CLOUD Act, the FISA or the PATRIOT Act). Sector-Specific Certifications: Healthcare France heavily relies on sector-specific certification schemes for critical industries such as healthcare. In this regard, any entity hosting personal health data collected in certain conditions must obtain the man - datory HDS certification (see 6.3 Cybersecurity in the Healthcare Sector for detailed obligations). Platform Transparency: the Cyberscore Law The Cyberscore Law introduced a French legal framework for cybersecurity certification – com - monly referred to as the “Cyberscore” – applicable to consumer-facing digital platforms, by amending the French Consumer Code. This certification aims to require certain online platforms to carry out a cyber - security audit of their services (including data security and localisation) and to inform users in a clear, visible way about the level of security of their data. Although the law entered into force on 1 October 2023, its practical application has been stalled, as the necessary decree and implementing order detailing which platforms are covered, the thresholds and the

precise audit criteria have never been published. As a result, three years after adoption, the Cyberscore scheme is still not operational. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection Cybersecurity overlaps heavily with data protection under the GDPR and the FDPA, stringently enforced by the CNIL. The principle of integrity and confiden - tiality, requiring personal data to be processed in a manner that ensures appropriate security against unauthorised processing, loss or destruction, forms part of the core principles of the GDPR. This is opera - tionalised through obligations mandating controllers and processors to implement technical and organi - sational measures appropriate to the risk. In the event of a personal data breach, controllers are required to notify the relevant supervisory authority (in France, the CNIL) within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. This notification, submitted via the dedicated CNIL portal , must describe: • the data controller and its legal representative (eg, address, workforce, business sector); • the nature of the breach (eg, date, origin of the inci - dent, cause of the breach, nature of data affected, type and number of data subjects affected, secu - rity measures prior to the breach); • possible consequences for affected personal data; • possible harm for affected data subjects and level of severity of the breach (ie, negligible, limited, high or maximal); • information to the affected data subjects (if any); and • cross-border and other notifications. If the breach poses a high risk to individuals’ rights and freedoms, affected data subjects must also be notified without undue delay. It should be noted that the European Commission’s proposed “Digital Omnibus”, published in late 2025, includes provisions modifying the GDPR seeking to

136 CHAMBERS.COM

Powered by