SRBS Training · Digital Regulation
Data protection and digital platform regulation in France: a compliance guide for investors
GDPR, the SREN law, DSA, DMA, AI Act, foreign investment screening, digital services tax: France is a structured compliance market.

A compliance market, not only a market to win
This December 2025 session, delivered at the Silk Road Business School for a delegation of investors, deals with a question asked without detour: what has to be mastered to enter the French digital market without being stopped by compliance.
The starting point is an openly stated French double imperative. Maintain economic attractiveness and assert digital sovereignty. The two do not contradict each other, but they produce a dense regulatory architecture that has to be read as part of the business plan, not as residual legal risk.
Fifty years of law: from SAFARI to the GDPR
Data protection in France does not begin in 2018. It begins in 1974, with the scandal of the SAFARI project to interconnect administrative files, then the 1978 act that created the CNIL. In 2004 the data protection correspondent appeared, forerunner of the data protection officer, marking the start of internal compliance. Sanctioning power, first capped at €150,000 then raised to €3 million in 2016, remained a weak incentive for global players.
The 2018 GDPR changes the scale. The 1978 act was rewritten to articulate with the European regulation, and sanctions can reach €20 million or 4% of worldwide turnover.
Accountability: the burden of proof reversed
The paradigm shift is not the amount, it is the reversal of the burden of proof. Before 2018, the company declared. After 2018, it must be able to prove its compliance at any moment. Data protection then leaves the IT department for the executive committee.
France also retains national specificities, notably a prior authorisation regime maintained for health data used for research purposes.
SREN law, DSA, DMA: platform regulation
The act of 21 May 2024, known as SREN, adapts French law to the European Digital Services Act and adds national measures: effective age verification on pornographic sites, an experimental anti-scam filter, a hybrid framework for games with monetisable digital objects, and anti-lock-in measures on cloud services that anticipate the European Data Act.
Governance is shared. A tripartite agreement signed on 27 June 2024 organises inter-regulation between the competent authorities. Sanction ceilings differ by text: up to 6% of turnover under the DSA and the SREN law, up to 4% under the GDPR.
AI Act and CNIL doctrine: training a model without consent
The AI Act calendar structures deployment decisions: prohibitions applicable in February 2025, general-purpose model obligations in August 2025, then a ramp-up across 2026 and 2027. The risk pyramid places recruitment, health, justice and critical infrastructure in the high-risk category, and requires foundation model providers to maintain up-to-date technical documentation.
The 2025 CNIL doctrine addresses the most sensitive point, web scraping of data to train models. It proposes a three-step test around the interest pursued, necessity and the balancing of rights. Two risks must be documented: regurgitation, meaning the model returning raw personal data learned during training, and the effective exercise of individual rights.
Foreign investment screening: thresholds, procedure, sanctions
This is the first sovereignty barrier, and it no longer concerns defence alone. Artificial intelligence, data hosting and digital infrastructure are among the sensitive activities that trigger a mandatory internal audit.
Thresholds depend on the investor profile, with a trigger from 10% of voting rights in some situations and 25% in others, without forgetting concert action, which aggregates shareholdings. The procedure is digital, through the TREFLE platform. The sanction is dissuasive: completing the investment without authorisation renders the transaction civilly void and exposes the investor to a fine of up to 10% of turnover.
Tax architecture: digital services tax and one-stop shop
In the absence of a complete agreement on OECD pillar 1, France maintains a 3% digital services tax, whose liability criteria are cumulative and assessed at group level. On VAT, the principle remains taxation at the place of consumption, with a one-stop shop allowing a non-EU investor to register in a single member state to declare and pay VAT for all twenty-seven, instead of twenty-seven separate registrations.
The four most frequent blind spots
The legal representative required by article 13 of the DSA, often forgotten by foreign investors. GDPR territoriality, which applies to the targeting of the European market even without an establishment in France, with the article 27 representative obligation. The one-stop-shop myth, since an Irish subsidiary is not enough to keep the CNIL out. And transfers outside the European Union, where the fragility of the transatlantic framework requires a transfer impact assessment, including the question of surveillance permitted by local law.
A fifth point comes from French doctrine on cookies: on a consent banner, refusing must be as easy as accepting.
Operational conclusion
The French market is not only a commercial market to win, it is a structured compliance market. An investor who treats that compliance as an asset, documented and dated in the deployment plan, turns a constraint into a barrier to entry against less prepared competitors.