Data Protection and Privacy 2025

FRANCE Law and Practice Contributed by: Frédéric Sardain and Claire Allavena, Jeantet

Reporting findings: After the investigation, CNIL compiles its findings and notifies the organisa - tion of any violations found, allowing the entity to respond or rectify issues before formal sanctions are imposed. Decision-making: CNIL issues formal decisions based on its findings, determining whether a vio - lation occurred and what sanctions (if any) are appropriate. Calculation of Administrative Fines • Criteria for Fines: When calculating adminis - trative fines under the French Data Protection Act, CNIL considers various factors, such as: (a) the nature, severity and duration of the violation; (b) the number of affected individuals; (c) the intention or negligence behind the violation; (d) the categories of personal data involved; (e) the previous compliance history of the organisation; as well as (f) the degree of cooperation with CNIL dur - ing the investigation. • Proportionality and fairness: The CNIL takes into account the company’s turnover with a view to imposing such a fine. • Fine limits: The CNIL applies the limit set up in the GDPR (up to €20 million or 4% of the total worldwide annual turnover of the pre - ceding financial year, whichever is higher). CNIL also follows these thresholds but typically applies fines based on the specific context of the violation. • Publication of sanctions: Decisions, includ - ing fines, are generally published (in an annual report or online), but the specifics of the organisation involved may sometimes be anonymised to protect confidentiality. • This administrative approach underscores CNIL’s commitment to enforcing data protec -

tion and privacy laws effectively while allow - ing organisations to comply before facing punitive measures (even if nothing prevents the CNIL from sanctioning directly). 1.4 Data Protection Fines in Practice The CNIL has undertaken several notable admin - istrative proceedings in recent years, reflecting its commitment to enforcing data protection and privacy laws and ensuring compliance with them. Here are some of the most significant cases. Orange (2024) Background: In November 2024, Orange was fined EUR50 million. Findings: The company was sanctioned for dis - playing advertisements in its users’ emails with - out their consent. Amazon (2024) Background: In June 2024, Amazon received a EUR15 million fine. Findings: CNIL identified violations concerning excessive worker monitoring. Yahoo! (2023) Background: In December 2023, Yahoo! received a EUR10 million fine. Findings: The company was sanctioned for failing to respect web users’ choice to refuse cookies on its “Yahoo.com” site and for failing to allow users of its “Yahoo! Mail” messaging ser - vice to freely withdraw their consent to cookies. Criteo (2023) Background: In June 2023, Criteo was fined EUR40 million.

125 CHAMBERS.COM

Powered by