CNIL
CNIL (Commission Nationale de l'Informatique et des Libertés) is France's independent data protection authority, enforcing GDPR and French privacy law since 1978. It serves French citizens, organizations, and DPOs through compliance guidance, complaint handling, sanctions, and emerging-technology enforcement.
- Company typePublic
- Founded1978
- HeadquartersParis, France
- Headcount51–100
- GTM typeB2B and B2C
- OfferingServices
What CNIL does
CNIL (Commission Nationale de l'Informatique et des Libertés) is France's independent administrative authority for data protection, established by Law No. 78-17 of January 6, 1978, and headquartered at 3 Place de Fontenoy, Paris. Operating under the supervision of the French Parliament and funded through the state budget, CNIL fulfills four statutory missions: informing and protecting citizens, accompanying organizational compliance, anticipating innovation challenges, and controlling and sanctioning non-compliance with GDPR and French data protection law. It serves individual citizens exercising data rights, organizations (companies, associations, public administrations, local authorities) seeking compliance guidance, designated Data Protection Officers, and specific populations such as children and minors requiring enhanced protection.
CNIL's operational outputs consist of regulatory services, compliance guidance, and online tools rather than commercial products. Core platforms include the official cnil.fr website (information resources, complaint filing, rights guidance) and the services.cnil.fr teleservices portal (secure request submission and tracking with FranceConnect identity integration). Its product portfolio spans browser cookie control guidance, mobile application security recommendations, session replay tools guidelines, AI system development GDPR recommendations (an 11-step framework), DPO activity report templates, online DPO designation services, data breach notification services, and the annual Privacy Research Day conference. The LINC (Laboratoire d'Innovation Numérique) conducts research on emerging privacy challenges, and a dedicated economic analysis team supports regulatory impact assessment.
CNIL generates no commercial revenue; all services are provided free of charge and the organization is funded through the French state budget. Its operational scale is evidenced by 87 sanctions totaling €55 million imposed in 2024 and 5,629 data breaches processed (a 20% year-over-year increase from 2023). It is a member of the European Data Protection Board and maintains bilateral partnerships with authorities including PIPC (Korea), Autorité de la concurrence, ANJ, AFPA, and academic institutions including EHESS and INRIA.
CNIL firmographics
Firmographics- Name
- CNIL
- Legal name
- Commission Nationale de l'Informatique et des Libertés
- Website
- https://cnil.fr
- Company type
- Public
- Founded year
- 1978
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- CNIL (Commission Nationale de l'Informatique et des Libertés) is France's independent data protection authority, enforcing GDPR and French privacy law since 1978. It serves French citizens, organizations, and DPOs through compliance guidance, complaint handling, sanctions, and emerging-technology enforcement.
- Ownership category
- akta.pro rank
Where CNIL is headquartered
LocationHeadquarters
- HQ city
- Paris
- HQ country
- France
- HQ region
- Europe
Offices1 record
Markets served
CNIL business model
Business model- GTM type
- B2B and B2C
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Others
Distribution channels4 records
Marketing channels8 records
CNIL product offering
Product offeringCore offering
CNIL is France's independent administrative authority for data protection, established in 1978 under the "Loi Informatique et Libertés." It informs and protects citizens' data rights, accompanies organizations in GDPR compliance, anticipates innovation challenges, and controls and sanctions non-compliance through investigations, audits, and fines. It provides online services for DPO designation, data breach notification, complaint filing, and publishes regulatory guidance on emerging technologies including AI, connected devices, and session replay tools.
Product overview
CNIL (Commission Nationale de l'Informatique et des Libertés) is France's national data protection authority, not a commercial product company. Its offerings consist of regulatory services, compliance guidance, and online tools. The core offerings include the official website portal (cnil.fr) providing rights information and complaint filing, a dedicated user account services portal (services.cnil.fr) for tracking requests, browser cookie control guidance, mobile application security recommendations, session replay tools guidelines, AI system development GDPR recommendations, DPO activity report templates, DPO designation services, data breach notification services, and annual Privacy Research Day events. These are regulatory guidance and administrative services rather than commercial technology products.
Differentiator
Problem solved
Functional benefit
Products and services
- CNIL Website Portal (cnil.fr) Official website providing information resources for individuals and professionals on data protection rights, GDPR compliance guidance, regulatory decisions, and the ability to file complaints or exercise rights.
- CNIL Teleservices Portal (services.cnil.fr)
Quantifiable outcome
- 87 sanctions issued in 2024 totaling €55 million, establishing compliance precedents
- +2 more outcomes
Companies that use CNIL
Customer profileSegments5 records
Ideal customer profiles5 records
CNIL technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
CNIL partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered notable, flagship and minor.
- INRIA (Institut national de recherche en informatique et en automatique)notableJoint prize 'Protection de la vie privée' awarded annually to recognize outstanding research in privacy protection.
- Autorité de la concurrence (French Competition Authority)flagshipJoint declaration on 'Protection des données et concurrence : une ambition commune' establishing cooperation framework between data protection and competition regulation. Ongoing joint work on AI, data markets, and competitive implications of data processing practices.
- PIPC (Personal Information Protection Commission, Korea)notableCooperation agreement signed in October 2022 for joint work on data protection, particularly focusing on children's digital rights. Partnership has produced co-branded educational materials including 'Tes données, tes droits' poster and 'IA générative et vie privée' awareness campaign.
- AFPA (Association pour la formation professionnelle des adultes)notableCollaboration on periodic DPO (Data Protection Officer) survey, conducted every two years since 2018. AFPA conducts statistical survey on behalf of Ministry of Labour, with CNIL utilizing results for economic analysis of DPO function.
- UNICEF InnocentinotableCollaboration on children's digital rights and privacy protections, contributing to international policy development alongside European Data Protection Board, Global Privacy Assembly, Council of Europe, UNESCO, and OECD.
- EHESS (École des hautes études en sciences sociales)notableJoint CNIL/EHESS research prize awarded to researchers studying the reception of the AI Regulation by European citizens. Second edition held in June 2026.
- ANJ (Autorité Nationale des Jeux)notableJoint work with France's National Gaming Authority on GDPR application to online gambling platforms, released new guidelines on health data processing for addiction prevention.
- European Data Protection Board (EDPB)flagshipMember authority contributing to EU-wide GDPR enforcement coordination, guidelines development, and cross-border case resolution.
- Direction générale du TrésornotableCo-organization of academic event 'RGPD : quel impact économique?' in May 2025 to evaluate GDPR's economic impact, with joint research on data economy and regulatory economics.
- AFCDP (Association française des correspondants à la protection des données)minorFrench association of data protection correspondents providing qualitative interview subjects for CNIL economic studies on DPO benefits.
Scale indicators8 records
Recent moves6 records
Expansion highlights5 records
CNIL competitors and assessment
Company assessmentDirect peers
- Commission nationale pour la protection des données (CNPD) - Luxembourg: Luxembourg's national data protection authority. Directly comparable peer with identical statutory mandate under GDPR, similar enforcement powers, and parallel functions (information, accompaniment, anticipation, sanctions) operating in a nearby jurisdiction.
- Autoriteit Persoonsgegevens (AP) - Netherlands: Dutch data protection authority, explicitly named as a CNIL cooperation partner on major cross-border enforcement (e.g., the €290M Uber fine). Comparable in mandate, enforcement posture, and bilateral coordination role with CNIL.
- Agencia Española de Protección de Datos (AEPD) - Spain: Spanish data protection authority with the same statutory mandate as CNIL under GDPR. Comparable in scale, sanctioning authority, and EU-level coordination, serving as a directly analogous peer in another major EU member state.
- Garante per la protezione dei dati personali - Italy: Italy's independent data protection authority. Directly comparable peer performing identical regulatory functions (enforcement, guidance, complaint handling) under GDPR in another major EU jurisdiction.
- Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI) - Germany: Germany's federal data protection commissioner. Direct peer operating under the same GDPR mandate with comparable enforcement powers, public-sector status, and role in coordinating cross-border cases within the EDPB framework alongside CNIL.
- Data Protection Commission (DPC) - Ireland: Ireland's data protection regulator and CNIL's counterpart for many US tech firm investigations within the EDPB "one-stop-shop" framework. Directly comparable in mandate and enforcement powers, with significant cross-case coordination given shared jurisdiction over major global platforms.
- Autorité de protection des données (APD) - Belgium: Belgian data protection authority. Direct peer in a neighboring jurisdiction, sharing identical GDPR mandate, enforcement tools, and EDPB coordination role with CNIL.
- Comissão Nacional de Proteção de Dados (CNPD) - Portugal: Portugal's national data protection authority. Direct peer with identical GDPR-mandated functions (enforcement, guidance, awareness) in another EU member state, useful for peer comparison on sanction trends, breach handling, and compliance tooling approaches.
Regional players
- Information Commissioner's Office (ICO) - United Kingdom: UK's data protection authority, a direct functional equivalent of CNIL. Although operating under the UK GDPR post-Brexit (with reduced EDPB coordination), it shares identical mandate, sanctioning powers, and advisory functions. Comparable as a peer for benchmarking, though no longer in direct EDPB coordination with CNIL.
Broad incumbents
- European Data Protection Board (EDPB): EU-level body coordinating national DPAs including CNIL. Not a competitor but the institutional umbrella under which CNIL participates in cross-border enforcement and guideline-setting. Comparable as a broader governance entity that influences CNIL's strategic direction.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights5 records
Customer concentration
CNIL social profiles
Digital presenceCNIL financial estimates
Financial estimateRevenue estimate
Valuation estimate
CNIL leadership team
Management profileNumber of profiles
Profiles3 records
CNIL funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CNIL M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CNIL
What does CNIL do?
CNIL is France's independent administrative authority for data protection, established in 1978 under the "Loi Informatique et Libertés." It informs and protects citizens' data rights, accompanies organizations in GDPR compliance, anticipates innovation challenges, and controls and sanctions non-compliance through investigations, audits, and fines. It provides online services for DPO designation, data breach notification, complaint filing, and publishes regulatory guidance on emerging technologies including AI, connected devices, and session replay tools.
Is CNIL a public or private company?
CNIL is a public company. It is classified as state government owned and is currently operating.
When was CNIL founded?
CNIL was founded in 1978. It employs 51 to 100 people.
Where is CNIL based?
CNIL is headquartered in Paris, France, in the Europe region.
Who are CNIL's main competitors?
Direct peers on record are Commission nationale pour la protection des données (CNPD) - Luxembourg, Autoriteit Persoonsgegevens (AP) - Netherlands, Agencia Española de Protección de Datos (AEPD) - Spain, Garante per la protezione dei dati personali - Italy, Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI) - Germany, Data Protection Commission (DPC) - Ireland, Autorité de protection des données (APD) - Belgium and Comissão Nacional de Proteção de Dados (CNPD) - Portugal. Information Commissioner's Office (ICO) - United Kingdom is listed as a regional player. European Data Protection Board (EDPB) is listed as a broad incumbent.
Does CNIL have an API?
No public API is recorded for CNIL.