
CNIL lawyer in Paris: inspections, formal notices and sanctions
Have you received a questionnaire, an inspection decision, a formal notice or a rapporteur’s report? The content of your first reply can weigh on the entire rest of the procedure.
Our lawyers help you define the scope of the checks, reconstruct the facts, gather the relevant evidence, correct any breaches and challenge the allegations where the facts or the law justify it.
Based in Paris, Cabinet Bouchara & Avocats advises companies, legal departments, DPOs, platforms, software publishers, agencies and e-retailers facing a complaint or a CNIL procedure.
Would you like a CNIL letter or decision reviewed? Contact our team.
You have just received a letter from the CNIL: what should you do?
As soon as the letter arrives, the firm helps you understand the scope of the procedure, assess the risks and organise the first steps. This support centralises communications, avoids contradictory replies and preserves the time needed to prepare the company’s defence.
Our lawyers assist you in order to:
- characterise the request, its scope, the deadlines and the entities concerned;
- coordinate the legal department, the DPO, the CISO and the operational teams;
- preserve the relevant documents, communications and technical evidence;
- identify urgent measures and prepare the points to be explained or challenged.
Where a fix is deployed during the procedure, we make sure its date, scope and effectiveness are documented, while keeping the material needed to trace the previous situation.
How we support you through CNIL procedures
On-site, documentary, online and summons inspections
La CNIL may combine several inspection methods in a single case. An online check may, for example, be followed by a questionnaire or an on-site inspection (French Data Protection Act, art. 19 ; RGPD, art. 58).
The firm acts to:
- analyse the inspection decision and the powers exercised by the officers;
- determine which processing operations, tools, entities and providers fall within the scope;
- prepare the company’s representatives and the individuals likely to be questioned;
- coordinate the collection of contracts, records, policies, data extracts and technical evidence;
- assist the company during an on-site inspection or a hearing;
- review the report drawn up after an on-site, online or hearing inspection and, where necessary, submit observations;
- prepare the replies and additional documents requested after the inspection.
During an online inspection, we compare the CNIL’s findings with how the website, application or platform actually works: trackers, forms, consent journeys, interfaces, user accounts and processing visible remotely.
Responding to information requests following a complaint
A complaint from a customer, an employee, a prospect or a user may lead the CNIL to question the company about how it handled the request and, more broadly, about its practices (French Data Protection Act, art. 8, I, 2°, d).
We reconstruct the timeline of the exchanges, the searches actually carried out and the systems involved. The reply is built around three elements: the verified facts, their legal analysis and the available supporting evidence.
This method makes it possible to spot a reply left sitting in a tool, a search limited to a single database, a misidentified controller or a gap between the internal procedure and actual practice.
Responding to a CNIL formal notice
A formal notice lists the breaches identified and the measures expected within a set deadline. It is not in itself a sanction, but it calls for a substantiated reply.
For each allegation, we establish:
- the facts on which the CNIL bases its analysis;
- the rule invoked and how it applies to the processing concerned;
- the arguments open to debate;
- the corrective measures required;
- the operational owner and deadline for each action;
- the documents, tests or screenshots proving they were carried out.
The reply therefore cannot rest on new policies alone. It must show that the announced measures genuinely work in the company’s tools and processes.
Defence before the restricted committee
In sanction proceedings, we analyse the rapporteur’s report, the case file and the legal characterisation of each breach.
We prepare the written observations, organise input from the legal and technical teams, and assist or represent the organisation before the restricted committee.
The defence may address whether the facts are established, the role of the entity prosecuted, the legal characterisation, the scope of the processing, the measures already taken and the proportionality of the proposed sanction.
The strategy must also take into account the seriousness and duration of the facts, the number of data subjects, the nature of the data, the level of cooperation and the steps taken to limit the consequences of the breach (RGPD, art. 83, § 2).
Appealing a CNIL decision
CNIL sanctions and formal notices issued by its chair can be challenged before the Conseil d’État (French Code of Administrative Justice, art. R. 311-1, 4°).
The firm reviews the procedural regularity, whether the facts are established, their characterisation, the reasoning of the decision and the proportionality of the measures imposed.
The time limit for appeal is in principle two months from notification for an organisation located in France and four months for an organisation located abroad (French Code of Administrative Justice, art. R. 421-1 et R. 421-7).
Examples of situations we handle
Trackers are detected before consent is collected
An online inspection reveals that advertising cookies are dropped before consent is collected. The cookie banner and the privacy policy do not match the trackers actually present on the site.
We analyse the CMP settings, the tag manager, the trackers fired, earlier versions of the site and any work carried out by providers. The fixes are dated, tested and backed by evidence of deployment.
A complaint concerns a right of access request
The reply sent to the user does not cover the data held in the CRM, the support tool, the archives or the environments operated by providers.
We reconstruct how the request was handled, the checks performed and the sources searched, in order to determine whether the disagreement concerns the deadline, the scope of the search or the legal limits on disclosure.
The CNIL questions the company after a data breach
The questions concern the incident timeline, the security measures, the risk assessment, the notification and the containment actions.
With the DPO, the CISO and the providers involved, we reconstruct the incident timeline and justify the decisions taken on the basis of the information available at each stage.
An employee monitoring system is challenged
The CNIL examines a CCTV, geolocation or activity-monitoring system.
We analyse its purpose, its proportionality, the information given to employees, access rights, retention periods and any consultations required. We separate the settings that must be changed from the arguments that justify the system.
Personal data and digital law team
Cabinet Bouchara & Avocats advises and represents its clients in both advisory and litigation matters in personal data and digital law.
The firm also acts as an external DPO for controllers and processors.
Awards
Cabinet Bouchara & Avocats is regularly recognised for its expertise in data law, cybersecurity and digital platforms.
Décideurs | Leaders League 2026 — Data law and cybersecurity
Cabinet Bouchara & Avocats — “Strong reputation”.
Décideurs | Leaders League 2026 — Digital platforms and applications law
Cabinet Bouchara & Avocats — “Strong reputation”.
Décideurs | Leaders League 2025 — Advertising & Marketing law
Bouchara & Avocats — “Highly regarded practice”.
CNIL inspections and sanctions: the essentials
La CNIL monitors compliance with the GDPR and the French Data Protection Act by controllers and processors. Its inspections may follow a complaint, form part of its annual programme or be decided because a sector or a practice is in the news (GDPR, art. 57 and 58 ; French Data Protection Act, art. 8 and 19).
At the end of its investigations, the CNIL may close the file, issue a formal notice or open sanction proceedings. The restricted committee may in particular issue a reprimand, an injunction with a periodic penalty payment, a restriction or ban on processing, a suspension of data flows or an administrative fine (GDPR, art. 58, § 2 ; French Data Protection Act, art. 20, IV).
The decision may be made public. A procedure must therefore be assessed in the light of the legal risk, but also of its consequences for the business, its reputation and its relationships with clients and partners (French Data Protection Act, art. 22).
For questions about audits, contracts, records, impact assessments or the overall organisation of compliance, see our expertise in GDPR and personal data protection.
FAQ
Can the CNIL open sanction proceedings without a prior formal notice?
Yes. The CNIL can open sanction proceedings without a prior formal notice (French Data Protection Act, art. 20, IV).
Does calling in a lawyer suspend an on-site inspection?
The company may ask to be assisted by its counsel, but the inspection does not stop while waiting for them to arrive (French Data Protection Act, art. 19, II; CNIL inspection charter, p. 10). An internal protocol for immediately alerting management, the DPO and the lawyer is therefore useful.
What is the difference between the ordinary and the simplified procedure?
The simplified procedure covers cases that raise no particular difficulty. The chair of the restricted committee or an appointed member rules alone; the fine is capped at EUR 20,000 and the decision cannot be published (French Data Protection Act, art. 22-1). The ordinary procedure is collegiate, is not subject to the EUR 20,000 cap and can lead to a published decision.
What is the maximum amount of a CNIL fine?
Depending on the category of breach, the fine can reach EUR 10 million or 2% of worldwide annual turnover, or even EUR 20 million or 4%, whichever is higher (GDPR, art. 83, §§ 4 to 6; French Data Protection Act, art. 20, IV, 7°). The amount depends on the specific circumstances of the case and does not capture the full range of risks: an injunction, a ban on processing, a periodic penalty payment or publication of the decision can have major operational consequences.
Is your company facing a CNIL procedure?
Have you received a letter or a decision from the CNIL? Send us the document, its notification date and the deadline stated, so that our team can identify the first steps to take.
Meet our team in Paris
Cabinet Bouchara & Avocats welcomes companies at its offices in the 8th arrondissement of Paris.


