Most data protection authorities were built for the GDPR. The CNIL is older than the problem it regulates — created by a French law in 1978, decades before the GDPR, before the web, before “big tech”. It exists because of a 1974 newspaper scandal over SAFARI — a government plan to link all the state’s files on citizens through one shared number, a single key to everything the state knows about you. Today it hands out some of the largest privacy fines in Europe — a record €325 million on Google in 2025. This is a profile of what the CNIL is, where it came from, how it is structured, what it does, who runs it, and the fines that made it famous. Every fact is sourced.
Quick facts
- Full name: Commission nationale de l’informatique et des libertés (CNIL) — France’s data protection authority
- Role: France’s GDPR supervisory authority — the independent national body that enforces data-protection law in France and sits on the EDPB
- Founding law: created by the Loi Informatique et Libertés of 6 January 1978, after the 1974 SAFARI scandal — decades before the GDPR (CNIL, Rapport annuel 2024)
- Legal status: an autorité administrative indépendante (independent administrative authority) (CNIL, Rapport annuel 2024)
- Structure: a college (collège) of 18 members, with a separate formation restreinte (a sanctions-only chamber) that imposes the fines (CNIL — Le collège)
- President: Marie-Laure Denis (Conseiller d’État), Chair of the CNIL since 2 February 2019; reappointed by decree of the President of the Republic of 30 January 2024 for a five-year term (CNIL)
- Staff and budget: 298 staff and a budget of €28.2 million in 2024 (CNIL, Rapport annuel 2024)
- Enforcement (2024): 321 inspections, 180 formal notices, 87 sanctions and €55.2 million in fines (CNIL, Rapport annuel 2024)
- Largest fine: €325 million on Google on 1 September 2025 (Gmail ads and cookies) (CNIL)
- Seat: 3 place de Fontenoy, 75334 Paris Cedex 07 (CNIL, Rapport annuel 2024)
- Website: cnil.fr
What the CNIL is — and what it is not
The CNIL is France’s data protection authority (DPA — the independent national regulator that supervises and enforces data-protection law) and, since the GDPR became applicable, France’s GDPR supervisory authority. It is one of the national authorities that make up the EDPB. Crucially, it is not a creature of the GDPR: it was created by the Loi Informatique et Libertés of 6 January 1978, well before the GDPR generalised these rules across the EU (CNIL, Rapport annuel 2024). Many GDPR concepts have French regulatory ancestors here.
What it is not: it is not France’s AI Act authority, and it is not a court. The CNIL polices how personal data is processed — including inside AI systems. But the AI Act itself regulates an AI system as a product (risk class, conformity assessment, market surveillance — much as the EU regulates machinery or medical devices), and that belongs to a separate national competent authority, not the CNIL. Like Italy’s Garante, the CNIL’s AI work is GDPR enforcement that happens to touch AI, which is why it sits on the GDPR pillar.
SAFARI and the 1978 law: how France invented the DPA
The CNIL was born from a scandal. On 21 March 1974 the newspaper Le Monde ran a front-page story by journalist Philippe Boucher headlined “SAFARI ou la chasse aux Français” (“SAFARI, or the hunt for the French”) (franceinfo). It revealed a government project called SAFARI (Système Automatisé pour les Fichiers Administratifs et le Répertoire des Individus) to interconnect all of the state’s separate files on citizens, using the social-security number (NIR) as a single shared identifier — in effect, a master key linking every administrative record about a person.
The outcry was immediate. The government withdrew the project and set up a commission on “Informatique et Libertés” to propose safeguards. Its work produced the Loi Informatique et Libertés of 6 January 1978, which created the CNIL as an independent authority to police the use of personal data (Sénat — l’histoire du Sénat).
Two things follow from this origin, and both still shape the CNIL today:
- It predates the GDPR by 40 years. France worked out the core ideas — consent, purpose limitation, a right of access, an independent regulator — in 1978. When the GDPR arrived in 2018 it generalised across the EU a model France had run for four decades, which is why the CNIL functions as a reference regulator far beyond its borders.
- It was built to watch the state, not just companies. SAFARI was a government project. The CNIL’s original job was to stop the state from over-linking its own files — and public-sector supervision remains central to what it does.
How the CNIL is built: a college, and a separate chamber that fines
The CNIL is not run by a single director but by a college of 18 members (commissaires) — elected or designated by the parliamentary assemblies, the courts (Conseil d’État, Cour de cassation, Cour des comptes), the economic council, and the presidents of the National Assembly and Senate (CNIL — Le collège). The college sets the CNIL’s doctrine, adopts its guidance, and decides its priorities.
Fines are a separate process. The decision to penalise is taken not by the full college, nor by the president alone, but by the formation restreinte — a dedicated sanctions-only chamber. It is drawn from the same college, but specifically from members who did not investigate the case. The point of the design is to split those who investigate from those who punish: one set of people builds the case, a different set decides the fine. That keeps the procedure impartial and helps the fines survive appeal.
- President: Marie-Laure Denis, a Conseiller d’État (a senior member of France’s highest administrative court). She has chaired the CNIL since 2 February 2019, and was reappointed by decree of the President of the Republic of 30 January 2024 (published 31 January in the Official Journal) for a further five-year term (CNIL).
Because it is collegiate, with a ring-fenced sanctions chamber, a CNIL decision is the institution’s — and the investigation/sanction split is structural, not optional.
What the CNIL actually does
As a GDPR supervisory authority its core job is to apply one EU regulation consistently — inform, advise, authorise, investigate, and sanction. Three things make it stand out:
- It is a reference regulator. Because it pre-dates the GDPR by 40 years, its guidance, formal notices and doctrine are widely read across the EU, not just in France.
- It enforces hard, through a dedicated chamber. Sanctions run through the formation restreinte, and since a 2022 reform added a simplified sanction procedure (for clear-cut cases, with fines capped at €20,000), the number of sanctions jumped from 21 in 2022 to 87 in 2024 (CNIL, Rapport annuel 2024).
- It moves early on new technology. It has been an active voice on AI, cookies and tracking, biometrics and connected devices — typically issuing guidance and recommendations before formal enforcement.
Resources and 2024 in numbers
By EU standards the CNIL is mid-to-large — bigger than most national DPAs, reflecting both France’s size and the breadth of its remit (CNIL, Rapport annuel 2024):
- 298 staff and a €28.2 million budget in 2024.
- 15,350 complaints received and 15,639 handled (net figures); 5,629 personal-data-breach notifications; 24,947 indirect-access requests (a French speciality — people asking the CNIL to check police, intelligence and certain other files on their behalf).
- 321 inspections carried out, 180 formal notices (mises en demeure) issued, and 87 sanctions imposed.
- €55.2 million in fines in 2024 — and that is before the €325 million Google penalty, which landed in September 2025.
The trend is sharply upward: across 2022–2024 the CNIL adopted 495 formal notices and 150 sanctions for a cumulative €245 million in fines, with cookies and tracking a recurring target (CNIL, Rapport annuel 2024).
Landmark fines: from Google’s first €50M to €325M
The CNIL is one of the heaviest-hitting DPAs in the EU, and its biggest cases have repeatedly set records — usually against US tech giants, usually over consent and cookies.
Google LLC — €50 million, 21 January 2019. The CNIL’s formation restreinte fined Google €50 million for a lack of transparency, inadequate information and no valid consent for ad personalisation — acting on collective complaints by the privacy groups NOYB and La Quadrature du Net (EDPB). It was the first major fine under the GDPR anywhere in the EU, and France’s highest administrative court, the Conseil d’État, upheld it in 2020.
Cookies — Google €150M and Facebook €60M, 31 December 2021. The CNIL fined Google a total of €150 million (€90M to Google LLC, €60M to Google Ireland) and Facebook Ireland €60 million for making it harder to refuse cookies than to accept them on google.fr, youtube.com and facebook.com — there was an “accept all” button but no equally easy “refuse all” (DLA Piper Privacy Matters). These were ePrivacy/cookie-law fines, which is why the CNIL could act directly rather than through the GDPR’s lead-authority system.
Clearview AI — €20 million, 17 October 2022. The CNIL imposed its maximum penalty of €20 million on the US facial-recognition company Clearview AI for unlawfully scraping photos of French residents from the web to build a biometric search engine, and ordered it to stop and delete the data (EDPB). Clearview’s refusal to comply later drew an additional penalty payment.
Google — €325 million (a record), 1 September 2025. Acting on a 2022 complaint by NOYB, the CNIL fined Google a record €325 million — €200 million to Google LLC and €125 million to Google Ireland — for inserting advertisements between users’ emails in Gmail’s “Promotions” and “Social” tabs without consent (ads that mimicked real messages), and for placing cookies on French users’ devices without valid consent when they created a Google account (CNIL). The CNIL found more than 74 million accounts affected by the cookie issue and 53 million French users exposed to the Gmail ads. It is the largest fine the CNIL has ever imposed.
The CNIL and AI
The CNIL is one of the most active enforcers in the EU and a frequent first-mover on emerging-tech guidance, including a dedicated workstream on artificial intelligence. As with every DPA, that AI work runs through the GDPR — the lawfulness of training data, transparency, the legal basis (Article 6 requires a specific lawful ground before any personal data is processed) — not through the AI Act. The Clearview case is the clearest example: a biometric AI product, fined entirely under data-protection law. For the EU-wide enforcement picture, see the GDPR pillar; for worked AI examples, the Garante AI fines registry.
How to contact the CNIL
- File a complaint: through the online forms on cnil.fr under “Nous contacter” — free of charge. You can complain about any organisation you believe is processing your personal data in breach of the GDPR.
- By phone: 01 53 73 22 22, on working days from 9:30 to 17:00 (CNIL, Rapport annuel 2024).
- By post: CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.
- Cross-border cases: if the organisation is headquartered in another EU country, the CNIL routes the case through the EDPB one-stop-shop — you do not need to file separately in that country.
What this means for you
- If you process personal data and reach French users: the CNIL is your supervisory authority. Its published guidance is unusually detailed — treat it as the practical standard, not just the legal minimum.
- If you use cookies or tracking: this is where the CNIL bites hardest. The Google and Facebook fines turned on a single principle — refusing must be as easy as accepting — and the €325M Google case extends it to ads disguised as content. Make “refuse all” as one click as “accept all”.
- If you build or train AI on personal data: the CNIL has an explicit AI track, but it enforces under the GDPR — the Article 6 legal-basis question is decided before training, not after, and Clearview shows it will reach a foreign company scraping French data.
- If you receive a CNIL proceeding: the investigators and the punishing body are different — the formation restreinte decides sanctions. A formal notice (mise en demeure) is a chance to fix things before a fine, and is itself a real signal.
- If you are a journalist or researcher: “France’s privacy regulator” = the Commission nationale de l’informatique et des libertés, an autorité administrative indépendante created by the Loi Informatique et Libertés of 6 January 1978 (after the SAFARI scandal), an 18-member college chaired by Marie-Laure Denis (reappointed January 2024), seat 3 place de Fontenoy, Paris.
TL;DR
The CNIL is France’s GDPR supervisory authority and one of the oldest data protection regulators in the world — created by the Loi Informatique et Libertés of 6 January 1978, after the 1974 SAFARI scandal over a plan to interconnect the state’s files on citizens. That seniority (40 years before the GDPR) makes it a reference regulator across the EU. It is an autorité administrative indépendante run by an 18-member college, with a separate sanctions chamber (formation restreinte) that imposes fines, seated at 3 place de Fontenoy, Paris. It is also one of the EU’s heaviest enforcers: Google’s first €50M GDPR fine (2019), €150M + Facebook’s €60M over cookies (2021), €20M on Clearview AI (2022), and a record €325 million on Google in 2025. In 2024 it had 298 staff, a €28.2M budget, and issued 87 sanctions worth €55.2M. President: Marie-Laure Denis, chair since 2 February 2019, reappointed by presidential decree of 30 January 2024. Its AI enforcement, like every DPA’s, runs through the GDPR — see the GDPR pillar.
Sources
- CNIL — Rapport annuel 2024 (official PDF) — autorité administrative indépendante, Loi Informatique et Libertés of 6 January 1978, seat 3 place de Fontenoy; 2024 figures: 298 staff, €28.2M budget, 321 inspections, 180 formal notices, 87 sanctions, €55.2M fines, 15,350 complaints, 5,629 breach notifications; 21→87 sanctions (2022→2024); 2022–2024 totals (495 notices, 150 sanctions, €245M)
- CNIL — Le collège — 18-member college, composition and appointment, the formation restreinte sanctions chamber, Présidente Marie-Laure Denis
- CNIL — Marie-Laure Denis reappointed Chair — chair since 2 February 2019, reappointed by presidential decree of 30 January 2024, five-year term
- CNIL — Google fined €325 million, 1 September 2025 (official) — €200M Google LLC + €125M Google Ireland, Gmail ads and cookie consent, 74M accounts / 53M users
- EDPB — CNIL €50 million fine on Google LLC, 21 January 2019 — first major GDPR fine
- DLA Piper — CNIL fines Google €150M and Facebook €60M over cookies, December 2021
- EDPB — CNIL €20 million fine on Clearview AI, 17 October 2022
- franceinfo — “La peur du Big Data dès 1974” (the SAFARI affair) · Sénat — examination of the 1978 Informatique et Libertés bill
- GDPR — Regulation (EU) 2016/679 (EUR-Lex) — Article 6 legal basis
- GDPR pillar · EDPB profile · Garante profile · Garante AI fines · cnil.fr