France Introduces Data Security Breach Notification Requirement for Electronic Communication Service Providers
Time 2 Minute Read

On August 24, 2011, France’s new law concerning electronic communications (Ordonnance n° 2011-1012 du 24 août 2011 relative aux communications électroniques, or the “Ordinance”) came into force.  The Ordinance implements the provisions of the revised EU Directive 2002/58/EC (the “e-Privacy Directive”) with respect to the French Data Protection Act of 1978, the French Postal and Electronic Communications Code and the French Consumer Protection Code.  In particular, the Ordinance introduces new provisions under the French Data Protection Act, which impose an obligation on electronic communication service providers to provide notice in the event of a data security breach. 

These new provisions apply only to companies that process personal data as part of electronic communication services they provide through a public network (e.g., ISPs or telecom operators).  A data security breach is defined as any security breach that accidentally or unlawfully results in the destruction, loss, alteration, disclosure or unauthorized access to personal data that is being processed in the context of electronic communication services that are provided to the public.

If such a security breach occurs, the electronic communication service provider must inform without delay the French Data Protection Authority (the “CNIL”).  If the breach is likely to impact subscribers’ (or any other individual’s) right to the protection of personal data or right to privacy, the service provider also must inform the potentially affected individuals without delay.  The service provider is not required to inform affected individuals if the CNIL determines that appropriate protective measures have been implemented to render the data in question inaccessible or indecipherable by unauthorized individuals.  However, in the absence of such protective measures, and after investigating the seriousness of the breach, the CNIL may send a legal notice to the service provider requesting that it inform the affected individuals.

Companies in the telecom industry also are required to maintain (and make available to the CNIL at all times) an inventory of all data security breaches they have experienced, including a description of each breach, its impact, and the measures the company implemented to remediate the situation.  Non-compliance with these provisions is punishable by up to five years of imprisonment and a €300,000 fine.

You May Also Be Interested In

Time 2 Minute Read

On February 18, 2026, Virginia Attorney General Jay Jones announced that his office intends to fully enforce new provisions of the Virginia Consumer Data Protection Act restricting minors’ use of social media.

Time 3 Minute Read

On January 8, 2026, the Kentucky Attorney General announced the first enforcement action against a company for alleged violations of the Kentucky Consumer Data Protection Act, just eight days after the law went into effect. The enforcement action is part of a larger legislative and regulatory focus on AI-powered chatbots used by minors.

Time 2 Minute Read

On July 8, 2025, Connecticut Attorney General William Tong announced a settlement with TicketNetwork for alleged violations of the Connecticut Data Privacy Act.

Time 2 Minute Read

On May 9, 2025, the Texas House of Representatives passed Senate Bill 2420—the App Store Accountability Act—by a vote of 120 to 9. The bill, which previously cleared the state Senate in April by a vote of 30 to 1, now awaits concurrence from the Senate on House amendments before it can be sent to Governor Greg Abbott.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page