AI Policy Wiki
Dashboard

CNIL (Commission nationale de l'informatique et des libertés)

medium confidence · updated 2026-06-06

French independent data protection authority; GDPR enforcer; significant AI-relevant enforcement role including early OpenAI/ChatGPT interventions and a dedicated AI department.

The Commission nationale de l'informatique et des libertés (CNIL) is France's independent data protection authority, responsible for enforcing the French data protection regime and, increasingly, for AI-specific guidance and enforcement where AI systems process personal data. Established in 1978, it is one of the longest-tenured European data protection authorities and has been among the most active on AI in the period following the public release of ChatGPT.

FieldValue
TypeFrench independent administrative authority (autorité administrative indépendante)
Founded1978 (established by the Loi Informatique et Libertés, one of the world's first data protection laws)
HeadquartersParis
President (current)Marie-Laure Denis
Entity typeRegulator (data protection authority)

Overview and mandate

CNIL enforces the French data protection regime, originally the 1978 Loi Informatique et Libertés and now harmonized with the GDPR. Its remit extends to AI-specific guidance and enforcement wherever AI systems process personal data. CNIL is structured as an independent administrative authority (autorité administrative indépendante) and is headquartered in Paris; as of the last update its president was Marie-Laure Denis.

AI activities

CNIL was among the first data protection authorities to scrutinize generative AI under GDPR. In March 2023, following Italy's Garante, it became one of the first DPAs to publicly examine ChatGPT under GDPR, opening inquiries on lawful basis, data subject rights, and training data. In 2023 it announced a dedicated Artificial Intelligence Department within the authority, among the first such units established by a European DPA.

Across 2023 and 2024, CNIL published an AI Action Plan and guidance on GDPR-compatible AI model training, addressing lawful basis, data minimization, and data subject rights in the context of large language model training. From 2024 through 2026 it continued issuing guidance on generative AI, biometric systems, and public-sector AI, including the administrative use of AI and questions tied to French sovereign AI ambitions.

On EU AI Act implementation, CNIL is positioned as a key French authority for EU AI Act enforcement, alongside a to-be-designated market-surveillance authority. Where the AI Act regulates a system that also processes personal data, CNIL's GDPR jurisdiction continues to apply.

Positions

CNIL has taken the position that GDPR can and should cover AI training, rejecting industry arguments that training-data processing falls categorically outside GDPR's scope. It maintains that publicly available personal data remains personal data, and that the "legitimate interest" lawful basis requires careful balancing rather than treating public availability as unrestricted use.

CNIL has engaged with how data subject rights, including erasure and rectification, apply to model weights, though it has not issued definitive guidance on the question. On the innovation side, it has operated AI regulatory sandboxes for health and public-interest AI projects.

Enforcement profile

CNIL has historically been more willing to issue large GDPR fines than most DPAs, with Google, Meta, and Amazon among its high-profile targets. Its AI-era actions to date have been more guidance-focused than fine-focused.

Relationship to other data protection authorities

CNIL operates alongside several peer authorities. The UK's ICO held a parallel role before diverging after Brexit; UK DUAA reforms narrow the ICO's automated-decision scope, while CNIL retains full GDPR reach. Ireland's DPC serves as GDPR lead supervisor for most US technology companies, and CNIL has frequently disagreed with DPC positions under the "one-stop-shop" framework. The Italian Garante was the first mover on ChatGPT regulation under GDPR. CNIL also plays a leading role in European Data Protection Board (EDPB) coordination on AI.

French AI policy context

CNIL operates alongside France's broader AI policy push, including the Paris AI Action Summit of February 2025, Mistral AI as a national champion, and significant state AI investment. CNIL's GDPR rigor has at times been in tension with the French government's AI industrial-policy ambitions.

Relationships

Notes

No primary CNIL source is currently in the wiki. The institutional role is well established; specific enforcement outcomes move quickly and should be verified against recent CNIL publications.