Cybercrime Law in France
France was an early mover on computer crime with the 1988 “loi Godfrain,” now codified in the Penal Code and extended several times since.
Key laws
- Penal Code, Book III, Title II, Chapter III — “Des atteintes aux systèmes de traitement automatisé de données” (articles 323-1 to 323-8) — offences against automated data-processing systems: fraudulently accessing or remaining in a system (art. 323-1), hindering or distorting its operation (art. 323-2), and fraudulently introducing, extracting, holding, reproducing, transmitting, deleting or altering data (art. 323-3). Article 323-3-1 covers the tools used to commit those offences; articles 323-4, 323-4-1 and 323-4-2 add aggravated forms for organised groups and where a person’s life is put at risk; articles 323-5 to 323-7 deal with additional penalties, corporate liability and attempts.
- LOI n° 2023-22 du 24 janvier 2023 (LOPMI) — the most recent significant recasting of this chapter: it amended articles 323-1 and 323-4-1 and created article 323-4-2 (offences endangering life).
- Loi n° 78-17 du 6 janvier 1978 (“Informatique et Libertés”) together with the GDPR (Regulation (EU) 2016/679) — personal-data protection, enforced domestically by the CNIL (Commission nationale de l’informatique et des libertés).
- France is a party to the Budapest Convention on Cybercrime, published in French law by Décret n° 2006-580 du 23 mai 2006.
Enforcement
Specialised units within the Police nationale and the Gendarmerie nationale investigate cybercrime. The CNIL regulates personal-data protection, and ANSSI is the national information-systems security agency.
Plain-language overview, not legal advice. Laws change — read the current Penal Code text linked above and consult a qualified lawyer for any specific question.
Sources verified 9 August 2026 against Légifrance and EUR-Lex.