The law of digital technology is no longer limited to a theoretical corpus on the protection of personal data. We have observed a clear shift towards enforcement over the past two years, with sanctions targeting specific operational failures: management of deletion requests, cookie consent interfaces, security of health databases. This tightening alters the risk landscape for any organization that processes data online.
CNIL Sanctions and the Right to Deletion: What Has Changed Since 2025
On July 21, 2026, the CNIL sanctioned the company EXTIA for failures related to the management of data deletion requests and violations of individuals’ rights. This type of decision marks a turning point: the right to deletion becomes an autonomous ground for sanction, no longer an ancillary grievance in a broader case.
For data controllers, the direct consequence impacts the architecture of internal workflows. A deletion process that relies on manual handling, without traceability or formalized timelines, is now exposed to swift formal notice. We recommend documenting each exercise of rights request in a timestamped register, with a validation circuit that does not exceed the regulatory deadline of one month.
The legal resources compiled on the BackUpYourBrain website allow for tracking this jurisprudential evolution, particularly regarding the concrete obligations of subcontractors in response to access and deletion requests.
Cookies and Consent: The End of Deceptive Interfaces
In November 2025, the CNIL imposed a fine of 500,000 euros for failures related to cookies. The main grievance targeted degraded refusal mechanisms, those interfaces where the “Accept All” button is highlighted while refusal requires several additional clicks.
Consent dark patterns pose a direct financial risk. This trend is not limited to France: at the European level, the issue of jurisdiction over dark patterns is the subject of discussions between Brussels and national authorities.

GDPR: The European Procedural Reform of 2027
The GDPR Procedural Regulation, adopted in 2025, will come into effect starting in 2027. This text does not change the principles of the GDPR, but transforms the way cross-border complaints are handled by supervisory authorities.
Three structural changes deserve attention:
- Binding investigation deadlines are imposed on lead authorities, which should reduce procedures that sometimes drag on for several years between the CNIL, the Irish authority (DPC), or the German BfDI.
- The defense rights of companies involved are strengthened, with formalized access to the file and harmonized procedural guarantees across the Union.
- The cooperation mechanism between authorities is revised to avoid political blockages that have paralyzed some major cases involving technology platforms.
For corporate lawyers, this reform requires anticipating the structuring of responses to cross-border complaints now. A poorly prepared case in front of a foreign supervisory authority will no longer benefit from procedural slowness as a safety net.
Health Data and Information System Security
A private hospital in Saint-Étienne was sanctioned by the CNIL after the theft of data concerning several hundred thousand patients. The identified failure concerned a specific technical point: one user account allowed access to all patient files, without compartmentalization or granular access control.
This case illustrates a recurring problem in the healthcare sector. Institutions often have outdated information systems where access management has not evolved with the volume of data processed. The CNIL does not sanction the cyberattack itself, but the inadequacy of prior technical and organizational measures.

Concrete Obligations for Health Data Controllers
The minimum expected by the CNIL is based on known but insufficiently applied principles: compartmentalization of access by service, logging of connections, periodic review of active accounts. The absence of a least privilege policy constitutes a sanctionable failure, regardless of whether an incident occurs.
Healthcare institutions that outsource all or part of their infrastructure must also verify that their subcontractors comply with these requirements. The subcontracting contract as defined in Article 28 of the GDPR is not sufficient: the CNIL expects effective and documented audits.
Artificial Intelligence and Data Protection: The Framework Being Built
The European AI Act imposes new constraints on AI systems that process personal data, particularly for systems classified as high risk. The intersection between the GDPR and the AI Act creates a complex compliance zone where legal bases for processing, impact assessments, and transparency obligations overlap.
We observe that organizations deploying generative AI tools often underestimate the issue of the legal basis for processing training data. Consent is rarely actionable at this scale. Legitimate interest requires a documented balancing of interests, which most providers do not make available to their clients.
For legal departments, the priority is mapping data flows between AI and existing databases. A processing register that ignores AI-related processing is incomplete, and this gap will likely be targeted by upcoming audits.
Digital law is intensifying on all fronts: strengthened enforcement from the CNIL, European procedural reform, GDPR-AI Act convergence. Organizations that wait for sanctions to adapt their processes are accumulating legal and financial risks that the regulatory timeline can no longer absorb.



