Regional regulatory context

Vendor risk and data privacy in France

France applies GDPR with enforcement through the CNIL, which has been one of the most active GDPR supervisory authorities in Europe. The CNIL has issued significant fines against Google and Amazon, and has taken strong positions on cookie consent and international data transfers.

Applicable regulations

  • GDPR
  • Loi Informatique et Libertés
  • ePrivacy

Hosting considerations

French government and defense sector vendors may be required to use SecNumCloud-certified cloud services, which currently favors French providers (OVHcloud, Outscale) over US hyperscalers.

Common questions

What is SecNumCloud and does it affect my SaaS procurement?
SecNumCloud is ANSSI's (the French cybersecurity agency) cloud security qualification. It is required for some French government contracts and preferred for critical infrastructure. Commercial SaaS procurement is generally not required to use SecNumCloud providers.

Which of your vendors operate in FR?

TrustVendor tracks vendor hosting regions, subprocessor geographies, and applicable adequacy decisions.

Book a demo