Skip to content
Case Law · Supreme Administrative Court ·CE - N. 433539 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Several digital rights organisations asked the Prime Minister to repeal Decree No

2010-236 of 5 March 2010. The decree regulated an automated personal data processing system used by the French authority for freedom of communications (ARCOM, hereinafter the French authority) for France’s online copyright enforcement mechanism, known as the graduated response procedure. Under this system, the French authority could receive IP addresses linked to alleged copyright infringements and request the corresponding subscriber identity data from electronic communications operators. This data could then be used to send warnings to subscribers and, in repeated cases, refer the matter to the public prosecutor. The applicants argued that the decree allowed the French authority to access personal data linked to IP addresses without sufficient safeguards under EU law. The court had previously referred questions to the CJEU, which ruled in Case C-470/21 that such access may be allowed, but only under strict conditions. Following the CJEU judgment, the court reviewed whether the French decree complied with EU law. Holding — The court partly upheld the action. First, the court held that EU law allows the general and indiscriminate retention of IP addresses for combating criminal offences in general only where serious interference with private life is effectively excluded. This requires strict separation between different categories of retained data, secure technical safeguards and regular monitoring by an independent public authority. The court found that French law did not require electronic communications operators to retain subscriber identity data and IP-related data under these conditions. Therefore, the decree was unlawful insofar as it allowed the French authority to process data that had not necessarily been retained in compliance with EU-law safeguards. Second, the court held that the French authority may access subscriber identity data linked to IP addresses in order to identify persons suspected of online copyright infringements and send the first two warnings under the graduated response procedure. However, the court distinguished the third access to such data. At that stage, the authority is no longer dealing with an isolated identification request: it has already linked the same person’s identity twice with alleged unlawful online activity and with the protected works concerned. A third access therefore allows the authority to build a more detailed picture of the person’s conduct and may reveal sensitive aspects of their private life. It also marks a more serious procedural stage, since it may lead to a registered letter and ultimately to referral to the public prosecutor. For that reason, EU law requires prior authorisation by a court or an independent administrative body before this third access takes place. The decree did not provide for such prior review, so the court held that it was unlawful to that extent. For this third access, EU law requires prior authorisation by a court or an independent administrative body. The decree did not provide for such prior review. The court therefore held that the decree was unlawful to that extent. The court annulled the Prime Minister’s refusal to repeal the unlawful parts of the decree and ordered their repeal. It also held that the French authority must stop applying the unlawful provisions. However, the French authority may still access identity data for the first and second warnings, and may request access in serious copyright offence cases under the conditions set out in the judgment.

Supreme Administrative Court

How it connects

23 of 25 paragraphs apply legislation or carry a topic — see them in the full text ↓

Full text 25 paragraphs

Paragraphs carrying a topic or an applied provision show those connections inline Original at the source →
§

Council of State - 10th - 9th Chambers sitting together No. 20260430 Not published in the Lebon Digest Read on Thursday, April 30, 2026 Rapporteur Mr. Stéphane Eustache Public Rapporteur Ms. net, and Fédération des fournisseurs d'accès à internet associatifs (Federation of Community Internet Service Providers) recorded, and secondly, dismissed the grounds based on a lack of The Court of Justice of the European Union, on the grounds of a lack of legal basis, a violation of Regulation (EU) 2016/679 of 27 April 2016, and the right to an effective remedy, challenged the implicit decision by which the Prime Minister rejected the application of these associations to repeal Decree No. 2010-236 of 5 March 2010. Finally, the Court deferred its ruling on the claims seeking the annulment of this implicit decision for abuse of power until the Court of Justice of the European Union has ruled on the following preliminary questions: 1) Are civil identity data corresponding to an IP address among the traffic or location data subject, in principle, to the requirement of prior review by a court or an independent administrative body with binding powers?

§

2) If the answer to the first question is yes, and given the low sensitivity of civil identity data... Users, including their contact details, should the Directive of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector, read in light of the Charter of Fundamental Rights of the European Union, be interpreted as precluding national legislation providing for the collection of this data, corresponding to users' IP addresses, by an administrative authority, without prior review by a court or an independent administrative body with binding powers? 3) If the answer to the second question is yes, and given the low sensitivity of data relating to civil identity, the fact that only this data may be collected, solely for the purposes of preventing breaches of obligations defined precisely, exhaustively, and restrictively by national law, and the fact that systematic review of access to each user's data by a court or a third-party administrative body with binding powers would be likely to compromise the performance of the public service mission entrusted to Given that the administrative authority itself is independent and carries out this data collection, does the directive preclude this control from being conducted using appropriate methods, such as automated control, possibly under the supervision of an internal service within the body that offers guarantees of independence and impartiality towards the staff responsible for collecting the data?

§

In a judgment of 30 April 2024 (C-470/21), the Court of Justice of the European Union answered the preliminary questions referred by the French Council of State. Having regard to the other documents in the file; Having regard to: - the Charter of Fundamental Rights of the European Union; - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016; - Directive 2001/29/EC of the European Parliament and of the Council of 22 May 2001; - Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002; - Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016; - the Penal Code; - the Postal and Electronic Communications Code; - the Intellectual Property Code; - the Code of Relations between the Public and the Administration; - Law No. 86-1067 of 30 September 1986; - Decree No. 2010-236 of 5 March 2010; - the Judgment of the Court of Justice of the European Union of 30 April 2024 (C-470/21); - the Code of Administrative Justice; Having heard in open court: - the report of Mr.

§

Stéphane Eustache, Master of Requests, - the submissions of Ms. Charline Nicolas, Public Rapporteur; Considering the following: 1. net, and Fédération des fournisseurs d'accès à internet associatifs (Federation of Community Internet Service Providers) requested the Council of State to annul, on the grounds of abuse of power, the implicit decision by which the Prime Minister rejected their request for the repeal of the decree of March 5, 2010, concerning the automated processing of personal data authorized by Article L. " By an interlocutory decision of 5 July 2021, the French Council of State, sitting in its judicial capacity, stayed proceedings on these submissions until the Court of Justice of the European Union had ruled on the questions it had referred to it for a preliminary ruling. By judgment C-470/21 of 30 April 2024, the Court of Justice of the European Union answered these questions.

§

Regarding the European Union's legal framework: 2. Pursuant to Article 2 of Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications), "traffic data" means "all data processed for the purpose of routing a communication over an electronic communications network or for its billing" and "location data" means "all data processed within an electronic communications network indicating the geographical location of the terminal equipment of a user of a publicly available electronic communications service". According to paragraph 1 of Article 5 of this Directive: "Member States shall, by national legislation, ensure the confidentiality of communications made via a public communications network and publicly available electronic communications services, as well as the confidentiality of related traffic data.

§

In particular, they shall prohibit any person other than the users from listening to, intercepting, storing communications and related traffic data, or subjecting them to any other means of interception or surveillance, without the consent of the users concerned, except where such person is legally authorized to do so in accordance with Article 15(1). " According to Article 6 of this Directive: "1. Traffic data relating to subscribers and users processed and stored by the provider of a public communications network or a publicly accessible electronic communications service must be erased or anonymized when it is no longer required for the transmission of a communication, without prejudice to paragraphs 2, 3 and 5 of this Article and to Article 15(1). / 2. Traffic data which is necessary for the calculation of subscriber invoices and interconnection payments may be processed. Such processing is permitted only until the end of the period during which the invoice may be legally contested or legal proceedings may be initiated to obtain payment.

§

/ 3. ). 3. Pursuant to paragraph 1 of Article 15 of the same Directive: "Member States may adopt legislative measures aimed at limiting the scope of the rights and obligations provided for in Articles 5 and 6, Article 8(1), (2), (3) and (4), and Article 9 of this Directive where such a limitation is a necessary, appropriate and proportionate measure in a democratic society to safeguard national security—that is to say, state security—defense and public safety, or to ensure the prevention, investigation, detection and prosecution of criminal offences or unauthorized use of the electronic communications system, as provided for in Article 13(1) of Directive 95/46/EC. To this end, Member States may, inter alia, adopt legislative measures providing for the retention of data for a limited period where this is justified by one of the grounds set out in this paragraph. All the measures referred to in this paragraph are taken in compliance with the general principles of Community law, including those referred to in Article 6, paragraphs 1 and 2, of the Treaty on European Union.

§

Regarding the retention of personal data by electronic communications service providers: 4. It follows from the provisions cited in points 2 and 3, as interpreted by the Court of Justice of the European Union in its judgment of 30 April 2024, that a Member State may require electronic communications service providers, pursuant to Article 15(1) of the Directive of 12 July 2002, to ensure the general and indiscriminate retention of their users' IP addresses for the purposes of combating criminal offences in general, where it is effectively ruled out that such retention could lead to serious interference with the privacy of the data subjects due to the possibility of drawing precise conclusions about them, in particular by linking those IP addresses with a set of traffic or location data that would also have been retained by the providers. 5. In order to prevent such interference, it is incumbent upon the Member State to provide, in its legislation, for clear and precise rules guaranteeing an effectively watertight separation of data held by providers of electronic communications services.

§

These rules must require that each category of data, including data relating to civil identity and IP addresses, be kept completely separate from other categories of data held; that this watertight separation be effectively ensured by a secure and reliable IT system; that linking IP addresses to the civil identity of the data subject be carried out by a high-performance technical process that does not compromise the effectiveness of the watertight separation of these categories of data; and finally, that the reliability of this storage be subject to regular monitoring by a public authority other than the one seeking access to the data held by providers of electronic communications services. Regarding access by a national public authority to civil identity data: 6. The provisions cited in points 2 and 3, as interpreted by the judgment of the Court of Justice of the European Union of 30 April 2024, do not preclude a national public authority, responsible for protecting copyright and related rights against infringements of those rights committed on the internet, from accessing, for the purposes of combating criminal offences in general, civil identity data of subscribers to electronic communications services, corresponding to IP addresses, solely for the purpose of identifying persons suspected of having committed such infringements and, where appropriate, taking action against them.

§

However, since the same public authority can repeatedly link this personal data for the same individual with even limited information about the content of works illegally made available online, and thus be informed about aspects, including sensitive ones, of the private lives of the individuals concerned, such access must be regulated by national legislation. 7. In this regard, the Court of Justice of the European Union has ruled that agents with such access must be prohibited from, firstly, disclosing, in any form whatsoever, information about the content of files accessed by the individuals concerned, except solely for the purpose of referring the matter to the public prosecutor, and secondly, from tracking the browsing activity of these individuals and, more generally, from using their IP addresses for purposes other than identifying their owners for the purpose of taking possible action against them.

§

8. Secondly, the Court of Justice of the European Union ruled that, where a public authority has already linked the identity data of the same person twice with information relating to the content of works illegally made available on the internet, it cannot link them a third time without authorization from a court or an independent administrative body. The Court held, as is clear from the grounds and operative part of the judgment, that such a check, which cannot be entirely automated, must be carried out beforehand, except in duly justified emergencies, by a body with full powers and offering all the necessary safeguards to ensure a balance between the various legitimate interests and rights at stake. When carried out by an administrative body, that body must have a status enabling it to act objectively and impartially, and must be a third party in relation to the authority requesting access to the data.

§

9. Furthermore, it follows from the grounds of the judgment of the Court of Justice of the European Union of 30 April 2024 that, where the person concerned is suspected of having committed acts constituting criminal offences in general, the court or independent administrative body responsible for carrying out the check referred to in the preceding point must refuse access to data relating to civil identity when such access would allow the public authority requesting it to draw specific conclusions about that person's private life. Conversely, such access may be authorized when the information brought to the attention of that court or independent administrative body gives rise to suspicion that the person concerned has committed acts constituting serious forms of crime. 10. Third, the Court of Justice of the European Union has ruled that the processing of personal data used by a public authority must be subject, at regular intervals, to audits by an independent body, acting as a third party in relation to that public authority, for the purposes of verifying the integrity of the system, including effective safeguards against the risks of misuse or unlawful access to and use of data, as well as its effectiveness and reliability in detecting any breaches.

§

Regarding the domestic legal framework: 11. Pursuant to Article L. 336-3 of the Intellectual Property Code, the holder of access to online public communication services has an obligation to ensure that this access is not used for the purposes of reproducing, representing, making available, or communicating to the public works or objects protected by copyright or related rights without the authorization of the rights holders, when such authorization is required. To ensure compliance with this obligation, the Audiovisual and Digital Communication Regulatory Authority (ARCOM), acting upon referral from duly constituted professional organizations, collective management organizations, the National Center for Cinema and Animated Images, or based on information transmitted by the public prosecutor or a bailiff's report drawn up at the request of a rights holder, is responsible for implementing the measures for the protection of works and objects to which copyright or related rights are attached, as defined in Articles L.

§

331-19 to L. 331-24 of the same code, under the so-called "graduated response" procedure. 12. In accordance with Article L. 331-13 and paragraph I of Article L. 331-14 of the Intellectual Property Code, this task is carried out by the ARCOM member designated pursuant to paragraph IV of Article 4 of the Law of 30 September 1986 on freedom of communication, as well as by public officials sworn before the judicial authority and authorized by the President of ARCOM under the conditions set forth in Articles R. 331-2 to R. 331-5 of the same Code. Pursuant to Article 8 of this Law, this member and these officials are bound by professional secrecy with regard to the facts, actions, and information they may have learned in the course of their duties, under the conditions and penalties provided for in Articles 413-9 and 413-10 of the Penal Code. 13. As provided in the first paragraph of Article L.

§

331-20 of the Intellectual Property Code, the graduated response procedure consists of sending subscribers who have committed acts likely to constitute a breach of the obligation defined in Article L. 336-3 of the same Code a recommendation reminding them of the content of this obligation, urging them to comply with it, and warning them of the penalties incurred. If such acts are repeated within six months, the second paragraph of the same Article L. " If, within one year of this second recommendation, new breaches are observed, Article R. 331-12 of the same Code provides that the authority informs the party concerned by letter delivered against signature that these acts are liable to prosecution. Where applicable, in accordance with Article R. 331-14 of the same code, the decision of the competent ARCOM member, finding that the facts are likely to constitute the offense of gross negligence as defined in Article R.

§

335-5 or the infringement offenses provided for in Articles L. 335-2, L. 335-3, and L. 335-4 of the same code, is transmitted to the public prosecutor at the competent judicial court. 14. For the purposes of this graduated response, Article L. 331-23 of the Intellectual Property Code authorizes ARCOM to implement automated processing of personal data under the conditions defined by a decree of the Council of State, issued after consultation with the National Commission for Information Technology and Civil Liberties (CNIL). As provided for in Article 4 I and the annex of the contested decree of March 5, 2010 relating to the automated processing of personal data authorized by Article L. 331-23 of the Intellectual Property Code called "System for managing measures for the protection of works on the internet", the member and competent agents of ARCOM have "direct access", on the one hand, to the personal data transmitted by the persons and authorities who have referred the matter to ARCOM and which relate in particular to the "IP address" of the person who committed the reported acts, the "information relating to the protected works or objects concerned by the acts" and the "name of the file as present on the subscriber's computer" and, on the other hand, to the personal data obtained from the electronic communications operators, in particular the "surname, first names" of the subscriber, his "postal address and email addresses", his "telephone contact details" and the "address of the telephone installation".

§

On the legality of the contested refusal to repeal: 15. Pursuant to Article L. " The practical effect of the annulment for abuse of power of the refusal to repeal an illegal regulatory act lies in the obligation, which the judge may order ex officio under the provisions of Article L. 911-1 of the Code of Administrative Justice, for the competent authority to repeal this act in order to cease the unlawful infringements of the legal order caused by its continued force. It follows that, when presented with a request for annulment of the refusal to repeal a regulatory act, the administrative court is required to assess the legality of the regulatory act whose repeal was sought in light of the rules applicable on the date of its decision. 16. First, while the Minister of Culture maintains that the four main Internet service providers operating in France retain data relating to subscribers' civil identity and their "IP traffic" under conditions that comply with the requirements set out in point 5, no legal provision mandates such retention, under these conditions, for electronic communications operators, with regard to the needs of combating criminal offenses in general.

§

Consequently, the applicants are justified in arguing that the decree of 5 March 2010 is unlawful insofar as it does not limit the data recorded in the processing to that which has been retained by electronic communications operators under conditions that meet the requirements of European Union law, as outlined in point 5. They are therefore justified in arguing that the refusal to repeal the decree of 5 March 2010 is, to that extent, unlawful. 17. Secondly, while it is true that the member and the competent agents of ARCOM implement, in accordance with the provisions cited in point 12, the graduated response procedure in compliance with the confidentiality and privacy protection requirements set out in point 7, no provision requires these persons to seek authorization from a court or an independent administrative entity, under the conditions provided for in point 8, to access the identity data of a person who, although having been the subject of two recommendations pursuant to Article L.

§

331-20 of the Intellectual Property Code, has committed for the third time acts likely to constitute a breach of the obligation provided for in Article L. 336-3 of the same Code. However, as the Court of Justice of the European Union has ruled, such access at this stage of the graduated response procedure is likely to reveal information, potentially sensitive, concerning aspects of the data subject's private life and must therefore be authorized beforehand by a court or by an administrative body independent of ARCOM, acting objectively and impartially. 18. It follows that the applicants are correct in arguing that the provisions of Article 4(1) of the Decree of 5 March 2010, insofar as they authorize the ARCOM member and agents mentioned in point 12 to access, a third time for the same person, the identity data stored in the processing system without such access being subject to authorization by a court or an independent administrative body, infringe the requirements stemming from European Union law.

§

They are therefore justified in arguing that the refusal to repeal the decree of March 5, 2010, is, to that extent, unlawful. 19. It follows from all the foregoing that the contested decision must be annulled insofar as it refuses to annul the contested decree solely because, firstly, for the purposes of combating criminal offenses in general, it does not limit the data recorded in the processing system it establishes to data stored by electronic communications operators under conditions that meet the requirements of European Union law, as outlined in paragraph 5, and secondly, the provisions of Article 4(I) authorize the ARCOM member and agents mentioned in paragraph 12 to directly access the identity data of a person who, despite having received two recommendations pursuant to Article L. 331-20 of the Intellectual Property Code, has committed, for the third time, acts likely to constitute a breach of the obligation set forth in Article L.

§

336-3 of the same Code. On the effects of the annulment: 20. First, while the Minister of Culture argues that the enactment and implementation of the provisions necessary for full compliance with the European requirements disregarded by the decree of March 5, 2010, necessitate a twelve-month postponement of the effects of the annulment, the documents in the case file do not demonstrate that the immediate annulment of the refusal to repeal the contested provisions is met with an overriding necessity that would justify, on an exceptional basis, a departure from the principle that a national court cannot modulate the effects of a judicial annulment resulting from a breach of European Union law. The Minister of Culture's arguments seeking to modulate the effects of the annulment over time must therefore be rejected. 21. Secondly, the annulment of the Prime Minister's decision refusing to repeal the decree of 5 March 2010 implies only that he be ordered to repeal that decree to the extent that its provisions contravene the requirements arising from European Union law, without the need for a penalty payment to be imposed.

§

22. Thirdly, the annulment pronounced by this decision necessarily implies that ARCOM must refrain from applying the legislative provisions which, for the reasons stated above, contravene the requirements arising from European Union law. In order to ensure the continuity of its mission to combat the offense of gross negligence, which contributes in particular to the objectives set by the European Directive of 22 May 2001 on the harmonisation of certain aspects of copyright and related rights in the information society, ARCOM may, pending the enactment of the provisions necessary to comply with the requirements mentioned in point 5, continue to request access from electronic communications operators to personal data relating to subscribers whose IP addresses have been transmitted to it by the persons responsible for ensuring the protection of copyright and related rights, only if it is established that this data has been stored by these operators under the conditions set out in point 5.

§

However, since these storage conditions are not required for the pursuit of an objective falling within the scope of serious crime, ARCOM may, without being required to verify their application, request such access from electronic communications operators when the facts brought before it are likely to constitute the offences defined in Articles Articles L. 335-2, L. 335-3, or L. 335-4 of the Intellectual Property Code and fall within the scope of serious criminal activity. 23. Finally, the annulment pronounced by this decision does not preclude the member and agents of ARCOM mentioned in point 12 from accessing a person's identity data, pending the enactment of the provisions necessary to comply with the requirements mentioned in point 8, solely for the purpose of sending them the first or second of the two successive recommendations provided for in Article L. 331-20 of the Intellectual Property Code.

§

24. net, and Fédération des fournisseurs d'accès à internet associatifs the sum of €1,000 each, pursuant to Article L. 761-1 of the Code of Administrative Justice. DECIDES: Article 1: The Prime Minister's decision, insofar as it refuses to repeal the provisions of Decree No. 2010-236 of March 5, 2010, which, for the reasons set forth in this decision, fail to comply with the requirements of European Union law, is annulled. Article 2: The Prime Minister is ordered to repeal the provisions of the Decree of March 5, 2010, to the extent set forth in Article 1. Article 3: The annulment pronounced in Article 1 entails for ARCOM the obligations defined by the grounds of this decision. net, and Fédération des fournisseurs d'accès à internet associatifs (Federation of Community Internet Service Providers) the sum of €1,000 each, pursuant to Article L. 761-1 of the Code of Administrative Justice.

§

Article 5: The remainder of the application is dismissed. Article 6: This decision shall be notified to the association La Quadrature du Net, the first-named applicant, the Prime Minister, the Minister of Culture, the Audiovisual and Digital Communication Regulatory Authority, and the National Commission for Information Technology and Civil Liberties. 20260430

applies Art. 5Art. 6