CNIL Recommendation
A CNIL Recommendation is guidance issued by France's data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), to help organizations understand and apply personal data protection rules in practice. These recommendations illustrate how the law applies to specific topics, such as mobile applications or artificial intelligence, often using concrete examples. They are intended to support compliance but generally do not replace the underlying legal obligations themselves.
A CNIL Recommendation is a form of soft-law guidance published by the CNIL, the French supervisory authority, to clarify how the GDPR and related national and EU data protection frameworks apply to particular contexts (for example, mobile applications, AI, or informing data subjects). CNIL recommendations frequently complement guidelines endorsed by the European Data Protection Board (EDPB) and may provide practical, example-based interpretation aimed at controllers, processors, developers, and other actors. As guidance reflecting the authority's interpretive and enforcement positions, such recommendations are typically influential but do not, on their own, constitute binding statutory rules; their status, scope, and weight depend on the specific instrument and the underlying legal basis, and interpretations may evolve over time. The precise legal effect of any given recommendation, and its interaction with regimes outside France, is outside the scope of this definition and should be assessed against the specific text and applicable law.
Why it matters
For organizations operating in or targeting users in France, CNIL Recommendations offer some of the most practical, example-based interpretation available on how abstract data protection obligations translate into concrete design and operational choices. Because the GDPR and the ePrivacy rules are often drafted at a high level, the recommendations issued by France's supervisory authority help controllers, processors, and developers understand what a data protection authority may expect in specific contexts, such as mobile applications, artificial intelligence, or informing data subjects. This practical guidance can reduce uncertainty when building consent flows, drafting privacy notices, or configuring tracking technologies.
At the same time, it is important to understand the status of this guidance. CNIL Recommendations are generally a form of soft law: they reflect the authority's interpretive and enforcement positions and are typically influential, but they do not on their own replace the underlying statutory obligations under the GDPR and related national and EU frameworks. Aligning with a recommendation can support a compliance posture, but it is not a substitute for legal analysis of the specific facts, and it does not automatically establish lawfulness under every applicable regime.
Because CNIL Recommendations speak primarily to the French context, their weight outside France is limited, even though they frequently complement guidelines endorsed by the European Data Protection Board. Readers operating across the EU, the UK, or US states should not treat French guidance as universal, and should recognize that interpretations may evolve over time as the authority updates its positions.
Who it's relevant to
Inside CNIL Recommendation
Common questions
Answers to the questions practitioners most commonly ask about CNIL Recommendation.