CNIL guidance on data‑protection obligations under the electronic invoicing reform effective 1 Sept 2026
Practitioners must align invoicing processes with GDPR, ISO‑27001, and eIDAS‑level authentication to avoid breaches and ensure lawful handling of personal data.
ADTP Regulatory Watch· September 10, 2026· CNIL
ImpactModerate 48
Type🧭 Regulatory Guidance
Statusin effectin force
JurisdictionEU-FR
Effective1 September 2026
What happened
The CNIL explains the data‑protection implications of the French electronic invoicing reform that entered into force on 1 Sept 2026. It details which personal data may be processed, the roles of issuers, receivers and certified platforms, and the security and retention requirements that apply. The guidance also outlines the upcoming compliance deadline of 1 Sept 2027 for all companies to both emit and receive e‑invoices.
Why it matters for trust and compliance
Its status is in effect. It is in force now.
Practitioners must align invoicing processes with GDPR, ISO‑27001, and eIDAS‑level authentication to avoid breaches and ensure lawful handling of personal data.
Takes effect September 1, 2026.
Who is affected
controllerprocessor
Recommended actions
Review consent, cookie and tracking practices against the requirement.
Check that privacy notices describe the practices this addresses.
Confirm access, correction, deletion and opt-out requests are handled within the required time.
Revisit retention schedules and data minimisation for the data involved.
Map the security requirements to existing controls and close gaps.