Skip to content

GDPR and AI in France: The CNIL method step by step

A project-lifecycle walkthrough of GDPR compliance for AI built on the CNIL method: framing, legal basis, DPIA, contracts, production, enforcement.

There are two ways to write about the GDPR and AI. The first is by friction point, which I did in the companion piece organized around six blockers. The second is the way a project actually unfolds: framing, legal basis, impact assessment, contracts, production, and eventually an audit. This article takes the second route, and it takes it through the French door, because the CNIL is the only European regulator that has published a full operational method for GDPR-compliant AI development: a numbered set of practical fiches, refined through three public consultations between 2024 and 2025, plus a regulatory sandbox that has now processed real AI projects end to end.