Skip to main content
Category: Laws and Regulations

Loi Informatique et Libertés

Also known as: Loi n° 78-17 du 6 janvier 1978, French Data Protection Act
Simply put

The Loi Informatique et Libertés is a French law, originally adopted in 1978, that regulates how personal data about individuals is handled and aims to protect privacy and fundamental rights. It is built on the principle that computing must serve every citizen without harming human identity, human rights, or private life. The law has since been updated so that European data protection rules can be applied effectively in France.

Formal definition

The Loi Informatique et Libertés (Loi n° 78-17 of 6 January 1978) is the French statute governing the processing of personal data. Its foundational principle holds that information technology must be at the service of every citizen and must not infringe human identity, human rights, private life, or individual and public liberties. Following reforms adopted to align French law with European instruments, the current version enables the effective application of those European texts within the French legal framework. The specific interaction between this national law and the broader EU regime, as well as its detailed provisions on cookies and tracking technologies, is not addressed by the evidence provided here and should be verified against the current statutory text and CNIL guidance.

Why it matters

The Loi Informatique et Libertés is the foundational statute for personal data protection in France, predating the modern EU data protection framework by decades. Its guiding principle, that information technology must serve every citizen without infringing human identity, human rights, private life, or individual and public liberties, continues to anchor how data processing is understood and regulated in the French legal order. For organizations operating in France, this law is the national reference point through which broader European data protection rules take effect.

Because the law was reformed to enable the effective application of European texts within France, it functions as the bridge between the EU regime and the French statutory and enforcement environment. Compliance teams working across multiple jurisdictions should be aware that the practical rules applicable to processing personal data in France are shaped by this national law alongside the European framework, rather than by the European rules in isolation. The precise interaction between the two, including how it affects cookies and tracking technologies, is not detailed in the evidence provided here and should be confirmed against the current statutory text and guidance from the French data protection authority (CNIL).

Who it's relevant to

Privacy officers and data protection professionals in France
Those responsible for data protection compliance in France need to understand this law as the national statute governing personal data processing and as the vehicle through which European data protection rules are given effect domestically. Its specific provisions should be confirmed against the current text and CNIL guidance.
Legal counsel advising on French data processing
Lawyers advising organizations that process personal data of individuals in France should treat the Loi Informatique et Libertés as the relevant national framework, recognizing that it works alongside the European regime rather than in place of it. The precise interaction is not covered by this entry and requires review of the statutory text.
Multi-jurisdiction compliance teams
Teams managing data protection obligations across several countries should note that France applies European rules through this national law, so obligations should not be assumed to be identical to those in other EU member states, the UK, or US states. Scope-specific verification is advisable.
Web developers and marketing compliance teams operating in France
Those implementing data-driven technologies for French audiences should be aware that this law governs the processing of personal data in France. However, its detailed rules on cookies and tracking technologies are not addressed in the evidence here and must be checked against current CNIL guidance and the statutory text.

Inside Loi Informatique et Libertés

French national data protection framework
The Loi Informatique et Libertés is France's foundational data protection statute. It has been amended over time to align with EU law and now operates alongside and in implementation of the GDPR within the French legal order, rather than replacing it.
The CNIL as supervisory authority
The law establishes and empowers the Commission Nationale de l'Informatique et des Libertés (CNIL), the French data protection authority responsible for supervision, guidance, and enforcement in relation to personal data processing in France.
Interaction with ePrivacy rules on cookies
In France, the rules governing the placing of and access to information on a user's device (the ePrivacy-derived requirements) are implemented through the national framework and applied via CNIL guidance and recommendations. This device-access layer is distinct from the GDPR-governed processing of any personal data that follows, and the two should not be conflated.
Consent and user rights provisions
The framework addresses the lawful basis for processing, including consent, and the rights of individuals. Where consent is required, it is generally expected to meet the GDPR standard of being freely given, specific, informed, and unambiguous through a clear affirmative action.
Enforcement and record-keeping context
The law provides the basis on which the CNIL may investigate and act, which in practice makes it relevant to how organizations document and demonstrate their compliance, including in relation to cookie and tracking technologies.

Common questions

Answers to the questions practitioners most commonly ask about Loi Informatique et Libertés.

Does the Loi Informatique et Libertés replace the GDPR in France?
No. The Loi Informatique et Libertés does not replace or override the GDPR; the two operate together. The GDPR is directly applicable across the EU, while the French law adapts and supplements it within the margins the GDPR leaves to Member States, and it also carries certain national provisions predating the GDPR. For cookies and similar technologies, the rules on placing and accessing information on a user's device derive primarily from the ePrivacy framework as implemented in France, with the GDPR governing any subsequent processing of personal data. Reading the Loi Informatique et Libertés in isolation, without reference to the GDPR and the ePrivacy rules, generally gives an incomplete picture of the applicable obligations.
Is the Loi Informatique et Libertés only relevant to cookies because the CNIL enforces it?
The Loi Informatique et Libertés is a general data protection statute and is not limited to cookies. It establishes the powers and role of the CNIL, France's data protection authority, and provides the national legal basis on which the CNIL acts. Cookie and tracking-technology matters are one area the CNIL supervises, but the law addresses personal data processing more broadly. The specific consent requirements for cookies and similar technologies stem from the ePrivacy framework as transposed into French law, which the CNIL interprets through its guidance; the exact scope and interpretation of that guidance can evolve over time.
Which cookie practices does the CNIL generally consider non-compliant under this framework?
In line with EU-level standards for valid consent, practices such as pre-ticked boxes, inferring consent from continued browsing, and designs that make refusing cookies significantly harder than accepting them are generally regarded as failing to meet the requirement for a freely given, specific, informed, and unambiguous choice. Strictly necessary cookies are typically exempt from consent, while analytics, advertising, and functional cookies usually require prior consent. This reflects the general EU approach as applied in France; the precise assessment depends on the facts of a given implementation and on current regulatory guidance, which can change.
Do the same rules apply to pixels, local storage, SDKs, and fingerprinting, or only to cookies?
The rules on placing or reading information on a user's terminal are generally understood to apply to a range of technologies beyond cookies, including tracking pixels, local storage, mobile SDKs, and fingerprinting techniques, where they involve storing or accessing information on the device. The label matters less than the function. As a result, consent obligations that apply to non-exempt cookies may also apply to these technologies. The specific treatment of any given technique can raise contested interpretation questions and should be assessed case by case.
What consent records should organizations keep to demonstrate compliance?
Because the ability to demonstrate valid consent is a core expectation, organizations typically maintain records showing that consent was obtained through a clear affirmative action, along with information about what the user was told and when the choice was made. Consent management platforms are commonly used to capture and log these choices, but a tool supports compliance rather than guaranteeing it, and it does not replace legal judgment about whether the consent mechanism itself is valid. The precise record-keeping expectations depend on the processing involved and on current regulatory guidance, which this entry does not exhaustively specify.
Does compliance in France cover an organization's obligations elsewhere in the EU, the UK, or the US?
Not necessarily. While the GDPR provides a common baseline across the EU, national implementations of the ePrivacy rules and the interpretive guidance of each data protection authority can differ, so aligning with French requirements does not automatically satisfy every other EU jurisdiction. The UK operates under its own regime following its departure from the EU, and US state privacy laws such as the CCPA and CPRA in California often rely on an opt-out model rather than the opt-in consent expected in the EU. Organizations operating across borders generally need to assess each applicable regime separately.

Common misconceptions

The Loi Informatique et Libertés was replaced by the GDPR and no longer matters.
The French law was amended to operate alongside the GDPR rather than being repealed. It remains part of the applicable national framework in France and, together with CNIL guidance, continues to shape how cookie and data protection obligations apply there.
Because it is a French law, it governs cookies the same way everywhere in the EU.
The Loi Informatique et Libertés and CNIL guidance describe the position in France. While there is broad EU-level alignment, national implementations and supervisory authority positions can differ between the EU, the UK, and individual US states, so its rules should not be treated as universal.
Satisfying the law's device-access (cookie) requirements automatically covers all data protection obligations.
The rules on placing and accessing information on a user's device are distinct from the GDPR rules on processing any personal data that results. Meeting one does not automatically satisfy the other; both may need to be addressed separately.

Best practices

Treat the device-access requirements for cookies and similar technologies separately from the GDPR obligations that apply to any resulting processing of personal data, and document how you meet each.
Consult current CNIL guidance and recommendations when configuring cookie consent for French users, and revisit it periodically because supervisory positions can evolve.
Where consent is relied upon, design consent flows to meet the freely given, specific, informed, and unambiguous standard through a clear affirmative action, avoiding pre-ticked boxes and implied consent.
Apply the same analysis to non-cookie technologies such as pixels, local storage, SDKs, and fingerprinting, which generally fall within the same rules even though they are not literally cookies.
Maintain records that demonstrate compliance and support accountability to the CNIL, rather than relying solely on a tool or platform to establish lawfulness.
Confirm the geographic and legal scope of your obligations before applying French rules to users elsewhere, since requirements differ across the EU, the UK, and US state regimes.