REGULATORY WATCH BRIEF Moderate 48 🧭 Regulatory Guidance in effect

CNIL guidance on data‑protection obligations under the electronic invoicing reform effective 1 Sept 2026

Practitioners must align invoicing processes with GDPR, ISO‑27001, and eIDAS‑level authentication to avoid breaches and ensure lawful handling of personal data.

ImpactModerate 48
Type🧭 Regulatory Guidance
Statusin effect in force
JurisdictionEU-FR
Effective1 September 2026

What happened

The CNIL explains the data‑protection implications of the French electronic invoicing reform that entered into force on 1 Sept 2026. It details which personal data may be processed, the roles of issuers, receivers and certified platforms, and the security and retention requirements that apply. The guidance also outlines the upcoming compliance deadline of 1 Sept 2027 for all companies to both emit and receive e‑invoices.

Why it matters for trust and compliance

  • Its status is in effect. It is in force now.
  • Practitioners must align invoicing processes with GDPR, ISO‑27001, and eIDAS‑level authentication to avoid breaches and ensure lawful handling of personal data.
  • Takes effect September 1, 2026.

Who is affected

controller processor

Recommended actions

  1. Review consent, cookie and tracking practices against the requirement.
  2. Check that privacy notices describe the practices this addresses.
  3. Confirm access, correction, deletion and opt-out requests are handled within the required time.
  4. Revisit retention schedules and data minimisation for the data involved.
  5. Map the security requirements to existing controls and close gaps.