The Commission nationale de l'informatique et des libertés (CNIL) is France's independent data protection authority, responsible for enforcing the French data protection regime and, increasingly, for AI-specific guidance and enforcement where AI systems process personal data. Established in 1978, it is one of the longest-tenured European data protection authorities and has been among the most active on AI in the period following the public release of ChatGPT.
| Field | Value |
|---|---|
| Type | French independent administrative authority (autorité administrative indépendante) |
| Founded | 1978 (established by the Loi Informatique et Libertés, one of the world's first data protection laws) |
| Headquarters | Paris |
| President (current) | Marie-Laure Denis |
| Entity type | Regulator (data protection authority) |
Overview and mandate
CNIL enforces the French data protection regime, originally the 1978 Loi Informatique et Libertés and now harmonized with the GDPR. Its remit extends to AI-specific guidance and enforcement wherever AI systems process personal data. CNIL is structured as an independent administrative authority (autorité administrative indépendante) and is headquartered in Paris; as of the last update its president was Marie-Laure Denis.
AI activities
CNIL was among the first data protection authorities to scrutinize generative AI under GDPR. In March 2023, following Italy's Garante, it became one of the first DPAs to publicly examine ChatGPT under GDPR, opening inquiries on lawful basis, data subject rights, and training data. In 2023 it announced a dedicated Artificial Intelligence Department within the authority, among the first such units established by a European DPA.
Across 2023 and 2024, CNIL published an AI Action Plan and guidance on GDPR-compatible AI model training, addressing lawful basis, data minimization, and data subject rights in the context of large language model training. From 2024 through 2026 it continued issuing guidance on generative AI, biometric systems, and public-sector AI, including the administrative use of AI and questions tied to French sovereign AI ambitions.
On EU AI Act implementation, CNIL is positioned as a key French authority for EU AI Act enforcement, alongside a to-be-designated market-surveillance authority. Where the AI Act regulates a system that also processes personal data, CNIL's GDPR jurisdiction continues to apply.
Positions
CNIL has taken the position that GDPR can and should cover AI training, rejecting industry arguments that training-data processing falls categorically outside GDPR's scope. It maintains that publicly available personal data remains personal data, and that the "legitimate interest" lawful basis requires careful balancing rather than treating public availability as unrestricted use.
CNIL has engaged with how data subject rights, including erasure and rectification, apply to model weights, though it has not issued definitive guidance on the question. On the innovation side, it has operated AI regulatory sandboxes for health and public-interest AI projects.
Enforcement profile
CNIL has historically been more willing to issue large GDPR fines than most DPAs, with Google, Meta, and Amazon among its high-profile targets. Its AI-era actions to date have been more guidance-focused than fine-focused.
Relationship to other data protection authorities
CNIL operates alongside several peer authorities. The UK's ICO held a parallel role before diverging after Brexit; UK DUAA reforms narrow the ICO's automated-decision scope, while CNIL retains full GDPR reach. Ireland's DPC serves as GDPR lead supervisor for most US technology companies, and CNIL has frequently disagreed with DPC positions under the "one-stop-shop" framework. The Italian Garante was the first mover on ChatGPT regulation under GDPR. CNIL also plays a leading role in European Data Protection Board (EDPB) coordination on AI.
French AI policy context
CNIL operates alongside France's broader AI policy push, including the Paris AI Action Summit of February 2025, Mistral AI as a national champion, and significant state AI investment. CNIL's GDPR rigor has at times been in tension with the French government's AI industrial-policy ambitions.
Relationships
- related: General Data Protection Regulation (GDPR) — primary enforcement instrument
- related: EU AI Act (Regulation 2024/1689) — enforcement layer
- related: UK Information Commissioner's Office (ICO), Irish Data Protection Commission (DPC) — parallel data protection authorities
- related: Mistral AI — French national AI champion CNIL regulates
- related: Paris AI Action Summit Declaration (2025)
Notes
No primary CNIL source is currently in the wiki. The institutional role is well established; specific enforcement outcomes move quickly and should be verified against recent CNIL publications.