Skip to main content
Start free
Premium

French CNIL Declaration — Sensitive Data Processing (GDPR)

French CNIL declaration for processing sensitive personal data (health, biometric, opinions), required under GDPR Article 9 for affected businesses.

What data categories fall under GDPR Article 9?

GDPR Article 9 identifies eight special categories: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership; genetic data; biometric data processed for unique identification; health data; and data concerning a person's sex life or sexual orientation. Data on criminal offences and convictions is governed separately under GDPR Article 10 and specific provisions of the amended Loi Informatique et Libertés. Any organisation processing Article 9 categories must document the applicable legal basis from the ten exceptions listed in Article 9.2 GDPR — explicit consent, legal obligation, and public interest being the most common.

Source: CNIL — Practical DPIA (PIA) Guide v3.0 and prior consultation online service (Art. 36 GDPR) · updated 2026

About this form

Under EU Regulation 2016/679 of 27 April 2016 (GDPR), Article 9 prohibits as a default rule the processing of "special categories" of personal data — including health data, biometrics, political opinions, trade union membership, genetic data, and sexual orientation. Since the GDPR took effect on 25 May 2018, reinforced by French Law n° 2018-493 of 20 June 2018 amending the foundational Loi Informatique et Libertés (Law n° 78-17 of 6 January 1978, France's data protection act), the old prior-declaration regime has been replaced by an accountability principle (responsabilité). In practice, any processing falling under GDPR Article 9 requires three things: maintaining a Record of Processing Activities (Article 30 GDPR); conducting a Data Protection Impact Assessment (DPIA — the French term is AIPD, Analyse d'Impact relative à la Protection des Données) under Article 35 GDPR; and, where residual risk remains high, seeking prior consultation from the CNIL (Commission Nationale de l'Informatique et des Libertés, France's data protection authority) under Article 36 GDPR. Non-compliance risks administrative fines up to €20 million and criminal prosecution under Article 226-19 of the French Penal Code (Code pénal).

Worked example

SantéKin SARL, a physiotherapy practice with 12 employed physiotherapists, annual revenue €1.2 million, based in Lyon, processes health data daily — diagnoses, session notes, prescriptions — for 3,200 active patients. In 2025 the practice deploys a connected case-management platform hosted on a cloud server in Ireland. Its externally mandated DPO conducts a DPIA (service cost: €2,400 ex-VAT): residual risk is judged manageable through AES-256 encryption, pseudonymisation, and a sub-processing agreement compliant with GDPR Article 28 with an HDS-certified cloud provider (Hébergeur de Données de Santé — a French health-data hosting certification under Article L. 1111-8 of the Public Health Code). The DPIA is archived and no CNIL prior consultation is needed. The practice avoids the €6,000–€12,000 administrative penalty it would have risked by starting processing without a documented DPIA.

How to fill out the form

  1. Identify and classify the data: verify that the categories you process fall under GDPR Article 9 (health, biometrics, political opinions, etc.) and record the purposes, volumes, and retention periods in your Record of Processing Activities (Article 30 GDPR). Document the applicable legal basis from the ten exceptions in Article 9.2 GDPR — such as explicit consent, performance of legal obligations, or public interest.
  2. Appoint or consult your DPO (Délégué à la Protection des Données — the French statutory term for Data Protection Officer): if large-scale sensitive data processing makes DPO appointment mandatory under GDPR Article 37.1(c), appoint a DPO and notify the CNIL via its online service. The DPO leads the DPIA and validates the methodology, referencing the CNIL's official PIA Guide v3.0.
  3. Conduct the Data Protection Impact Assessment (DPIA / AIPD) under GDPR Article 35: describe the processing and its purposes; assess necessity and proportionality; evaluate risks to individuals (likelihood and severity); and define the technical and organisational safeguards — encryption, pseudonymisation, access controls — to reduce those risks. Use the CNIL's open-source PIA tool.
  4. Document and archive the DPIA: produce a formal written report including the DPO's opinion, the safeguards adopted, and the estimated residual risk. If residual risk is acceptable, archive the report for the duration of the processing plus 5 years (CNIL recommendation). Update the DPIA whenever the processing changes materially, as required by GDPR Article 35.11.
  5. If residual risk remains high, submit a prior consultation request to the CNIL (GDPR Article 36) via the dedicated online service, attaching the complete DPIA, the DPO's contact details, and the planned measures. Do not start any sensitive data processing until the CNIL issues its written opinion — within 8 weeks of receiving a complete file, extendable to 14 weeks for complex cases.

Good to know

  • Don't confuse the Record of Processing Activities (Art. 30 GDPR, kept internally) with the CNIL prior consultation (Art. 36 GDPR, triggered only when residual risk is still high after the DPIA). Starting sensitive data processing without a finalised DPIA exposes you to administrative fines up to €20 million (Art. 83 GDPR).
  • Biometric workplace data — fingerprint access badges, facial recognition — requires a systematic DPIA and a strict legal basis: GDPR Art. 9.2(b) for employment-law contexts, or explicit consent under Art. 9.2(a). The CNIL may additionally require prior authorisation based on its published sector-specific reference frameworks before any deployment.
  • Update your DPIA whenever processing changes materially: new sub-processor, change of purpose, geographic expansion. GDPR Art. 35.11 requires periodic review; failing to update when new risks emerge constitutes a breach of the accountability principle under Art. 5.2 GDPR.

Frequently asked questions

What data categories fall under GDPR Article 9?

GDPR Article 9 identifies eight special categories: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership; genetic data; biometric data processed for unique identification; health data; and data concerning a person's sex life or sexual orientation. Data on criminal offences and convictions is governed separately under GDPR Article 10 and specific provisions of the amended Loi Informatique et Libertés. Any organisation processing Article 9 categories must document the applicable legal basis from the ten exceptions listed in Article 9.2 GDPR — explicit consent, legal obligation, and public interest being the most common.

Is a DPIA always mandatory when processing sensitive data?

Yes. GDPR Article 35.3(b) requires a DPIA for any large-scale processing of Article 9 data. The CNIL published a list of operations that always require a DPIA (Deliberation n° 2018-327 of 11 October 2018). Even below the large-scale threshold, a DPIA is required whenever processing presents a high risk to individuals' rights and freedoms. The DPIA must be documented in writing and cover: a description of the processing, an assessment of necessity and proportionality, a risk evaluation, and the planned mitigation measures.

How long does the CNIL take to respond to a prior consultation request?

When the DPIA concludes that residual risk is too high for the data controller to mitigate alone, GDPR Article 36 requires a prior consultation with the CNIL before processing begins. The CNIL has 8 weeks from receipt of a complete file to issue a written opinion. This period may be extended by a further 6 weeks — 14 weeks in total — for complex cases; the CNIL must notify the data controller within the first month. No sensitive data processing may start while the consultation is pending.

Who within the organisation is responsible for carrying out the DPIA?

The data controller — typically the chief executive or a designated DPO (Délégué à la Protection des Données, the French-law term for Data Protection Officer) — is legally accountable under GDPR Article 5.2. Where large-scale sensitive data processing makes DPO appointment mandatory (GDPR Article 37.1(c)), the DPO must be notified to the CNIL and consulted during the DPIA per Article 35.2. Where a DPO is not compulsory, the data controller may conduct the DPIA in-house or engage an external specialist, but retains final legal responsibility.

What penalties apply for processing sensitive data without a valid legal basis?

Penalties operate on two tracks. Administratively, GDPR Article 83.5 allows the CNIL to impose fines up to €20 million or 4% of global annual turnover — whichever is higher. In 2024 the CNIL issued several fines exceeding €3 million for unlawful processing of health data. Criminally, Article 226-19 of the French Penal Code (Code pénal) punishes collection of sensitive data without a legal basis with up to 5 years' imprisonment and a €300,000 fine.

Must a small business maintain a Record of Processing Activities for sensitive data?

Yes, without exception. GDPR Article 30.5 exempts organisations with fewer than 250 persons employed from the records obligation — unless the processing risks harm to individuals' rights and freedoms, is non-occasional, or involves Article 9 special-category data. The moment a small business processes sensitive data — even sporadically — a detailed record covering purposes, legal basis, retention periods, recipients, and security measures is mandatory. Failing to maintain it risks fines up to €10 million under GDPR Article 83.4.

Updated on 2026-06-27

A question about this form?

Ask Solva, ActioFin's AI finance advisor — answers sourced from official texts.

5 free questions per day with a free account

Ask Solva

Related forms

French CNIL Declaration — Sensitive Data Processing (GDPR)