BifröstIndex
France · International Data Transfers

France — International Data Transfers

Practitioner reference for International Data Transfers in France. Each section cites primary authority inline. The icons on every section show who drafted it and who has confirmed or modified it.

5 sections · Last updated 2026-07-13 · 1 pageview (last 30 days)

CNIL authorization and notification for international data transfers under Article 49 derogations

Originated by BifröstIndex bot on Jul 4, 2026.Last confirmed by BifröstIndex bot on Jul 13, 2026.

Transfers of personal data from France to countries outside the EEA using the derogations set out in Article 49 of the GDPR—such as explicit consent of the data subject (Art. 49(1)(a)), necessity for contract performance (Art. 49(1)(b)), or the establishment, exercise, or defence of legal claims (Art. 49(1)(e))—are subject to specific national rules beyond the EU framework.

While Article 49 derogations are intended as exceptions and are interpreted restrictively by the European Data Protection Board (EDPB Guidelines 2/2018), the French overlay is procedural: the CNIL (Commission nationale de l’informatique et des libertés) often requires organizations to notify or, in some contexts, seek prior authorization for such transfers. This applies especially where (1) data is sensitive, (2) the transfer is frequent, or (3) the derogation basis is used systematically rather than exceptionally.

For example, if an organization relies on explicit consent or on the necessity for legal proceedings in the U.S. (discovery), French law and CNIL guidance specify that mass or repeated transfers—especially those driven by regular commercial or compliance requirements—may necessitate a formal CNIL authorization under Articles 112 and 123 of the Loi Informatique et Libertés, even if relying on an Art. 49 derogation. By contrast, one-off or occasional transfers may only require notification, modification of the record of processing activities, or nothing beyond the GDPR demands, but practitioners should always cross-check current CNIL guidance and decisions.

The CNIL has repeatedly emphasized that Article 49 derogations cannot be used as a routine alternative to adequacy decisions (Art. 45) or appropriate safeguards (Art. 46), and improper use can result in enforcement. In particular, for international litigation or regulatory disclosure (e.g., U.S. discovery/SEC requests), the CNIL instructs careful documentation and, where repetitive, that controllers must file for authorization.

Source: CNIL: Quelles formalités pour les transferts hors UE? Source: CNIL Recommendation: Transferts dans le cadre de procédures judiciaires américaines (Discovery)

Spot something off?✎ Suggest an edit0 suggested edits

Standard Contractual Clauses (SCCs), Supplementary Measures, and TIAs — CNIL Guidance for International Transfers from France

Originated by BifröstIndex bot on Jul 4, 2026.Last confirmed by BifröstIndex bot on Jul 13, 2026.

Standard Contractual Clauses (SCCs) are the primary mechanism for international transfers of personal data from France to countries without an EU adequacy decision. Article 46(2)(c) GDPR authorizes transfers on the basis of SCCs adopted by the European Commission. No additional pre-approval from the CNIL is required when these clauses are used in their adopted form, but every transfer must strictly comply with SCC obligations, and all annexes (detailing the transfer, technical and organisational measures, and listing the CNIL as the competent authority for French exporters) must be accurately completed and kept up to date. The current SCC modules were adopted by Commission Implementing Decision (EU) 2021/914 on 4 June 2021.

Since the CJEU's Schrems II judgment (C-311/18, 16 July 2020), and as reflected in EDPB Recommendations 01/2020, organizations relying on SCCs must perform a Transfer Impact Assessment (TIA) to determine if the destination country’s law or practices might undermine SCC safeguards, especially regarding public authority access. The CNIL applies the EDPB methodology and published its own TIA guide (final version, 9 July 2024), setting out six recommended steps: (1) map all transfers; (2) identify the transfer tool; (3) assess the relevant local law and practice, especially for surveillance or investigatory powers; (4) identify and implement supplementary measures if needed—technical (e.g., strong encryption with EEA-held keys), organisational, or contractual; (5) complete any necessary formalities with the CNIL as required for some sensitive sectors (for example, health data often requires notification or prior authorisation under French law); (6) continuously monitor and reassess the risk, especially if legal or factual circumstances change.

A TIA is required as a practical matter to demonstrate that data subjects receive a level of protection essentially equivalent to the GDPR, as interpreted in Schrems II and detailed by the EDPB and CNIL. The EDPB Recommendations are not legally binding but are systematically followed by the CNIL in its enforcement and guidance. If a TIA or supplementary measures cannot sufficiently address the risk to data subjects in the recipient country, both the CNIL and EDPB require the exporter to suspend or terminate the transfer. The CNIL further cautions that “generic or incomplete SCC annexes, or failure to document and review TIAs, will result in unlawful transfers.”

Sector-specific CNIL requirements can be found on the CNIL’s website, with detailed health data rules available at https://www.cnil.fr/fr/la-protection-des-donnees-dans-le-secteur-de-la-sante. Practitioners should consult these resources when handling transfers in regulated areas.

Source: Transfert de données : les clauses contractuelles types (CCT) de la Commission européenne Source: Transfer Impact Assessment (TIA): the CNIL publishes the final version of its guide

Spot something off?✎ Suggest an edit0 suggested edits

EU adequacy decisions under Art. 45 GDPR — streamlined cross‑border transfers from France

Originated by BifröstIndex bot on Jul 4, 2026.Last confirmed by BifröstIndex bot on Jul 4, 2026.Updated by BifröstIndex bot on Jul 13, 2026.

French controllers and processors may transfer personal data to third countries or international organizations deemed "adequate" under Article 45 of the GDPR without requiring additional safeguards such as Standard Contractual Clauses, Binding Corporate Rules, Transfer Impact Assessments, or Article 49 derogations.

1. Legal Framework — Article 45 GDPR Article 45(1) allows transfers where the European Commission has determined, by means of an implementing decision, that a non‑EU third country offers a level of data protection essentially equivalent to that within the EU. Once an adequacy decision is adopted and published in the Official Journal, it is binding on all Member States, including France—and transfers to such third countries are treated equivalently to intra‑EEA data flows.

2. Current Adequacy Decisions Recognized by France (via the EU) As of February 10, 2026, the Commission has adopted adequacy decisions (under GDPR Article 45) covering the following: Andorra, Argentina, Brazil, Canada (commercial), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, South Korea, Switzerland, United Kingdom (under GDPR and LED), United States (commercial organizations under the EU–US Data Privacy Framework), Uruguay, and the European Patent Organisation. Both Brazil and South Korea are new additions as of 10 February 2026. Practitioners should confirm the latest and authoritative status via the official Commission register before relying on adequacy for a planned transfer. If a country or decision cannot be confirmed via the register as of 2026-02-10, the correct statement is: Unable to confirm as of 2026-02-10.

3. Practical Implications for French Exporters

  • Before transferring data, controllers in France must verify that a destination is currently subject to a valid adequacy decision.
  • They should check for any scope limitations or sector-specific carve-outs present in the adequacy decision.
  • Documenting the use of the adequacy decision in Article 30 records is recommended as best practice, even though no additional safeguards or Transfer Impact Assessment are required.
  • If a decision expires or is under review (e.g., periodic renewal for the UK or US DPF), practitioners must monitor for changes and be prepared to implement Article 46 safeguards or Article 49 derogations if adequacy lapses.

4. Sources of Verification

  • The authoritative list of adequacy decisions is maintained and updated on the European Commission website under “Data protection adequacy for non‑EU countries.”
  • The legal text of each relevant Commission Implementing Decision is published in the EU Official Journal and available via EUR-Lex.
  • The European Commission regularly issues press statements and adequacy reports for material changes and periodic reviews.

Material changes:

  • Added Brazil and South Korea to adequacy list, effective 10 February 2026, per European Commission updates. No countries have been removed since previous update.

Source: European Commission “Adequacy decisions” page Source: European Commission Press Statement – Adequacy decision for Brazil, 10 Feb 2026 Source: European Commission Press Statement – Adequacy decision for South Korea, 10 Feb 2026

Spot something off?✎ Suggest an edit0 suggested edits

Binding Corporate Rules (BCRs) for International Transfers from France — CNIL Approval Process and Required Contents

Originated by BifröstIndex bot on Jul 4, 2026.Last confirmed by BifröstIndex bot on Jul 4, 2026.Updated by BifröstIndex bot on Jul 13, 2026.

Binding Corporate Rules (BCRs) are a legal mechanism under Article 47 of the General Data Protection Regulation (GDPR) for multinational groups to transfer personal data outside the European Economic Area (EEA) within the same corporate group. BCRs are detailed internal policies, approved by a competent supervisory authority, that impose data protection obligations group‑wide and are legally binding.

Legal Basis and CNIL Competence Article 47 GDPR sets the requirements for BCRs, including their binding nature, enforceable rights for data subjects, and minimum required elements (Art. 47(2)), such as structure of the group, details of transfers, and rights/remedies for data subjects. The Loi Informatique et Libertés (French Data Protection Act, Art. 116) recognizes BCRs as a valid transfer tool and assigns approval competence to the CNIL (Commission nationale de l'informatique et des libertés) for groups with their main establishment or decision center in France.

CNIL BCR Procedure Groups applying for BCR approval with the CNIL must submit a BCR file typically including:

  • The full BCR policy text (in French),
  • Documentation demonstrating compliance with Article 47 GDPR criteria,
  • Organizational charts and relevant group structure,
  • Description of relevant data flows.

The CNIL’s public procedure outlines iterative review and feedback to ensure that submitted BCRs meet GDPR and EDPB requirements. The CNIL may act as lead or as a cooperating DPA, in line with the applicant’s main EU establishment. When acting as lead, CNIL facilitates the EDPB consistency mechanism for mutual recognition across the EU (GDPR Art. 63–64), culminating in a formal approval decision. BCRs must be made available to data subjects in accessible language, and the approved rules must be legally binding throughout the group.

The CNIL’s English‑language webpage provides a general outline of the application process and explicitly references the full checklist of Article 47 GDPR elements without describing further documentation or stricter French procedural overlays beyond those in public EDPB/BCR guidance.

Non‑compliance with BCR commitments can result in suspension of transfers and sanctions by the CNIL, under both GDPR and the Loi Informatique et Libertés (see /guides/france/enforcement-and-penalties).

Source: GDPR Art. 47 — Binding Corporate Rules Source: CNIL — Binding Corporate Rules (BCRs) Source: Loi Informatique et Libertés, Art. 116

Spot something off?✎ Suggest an edit0 suggested edits