France - Mobile Authentication System (2019-452)
Decree No. 2019-452 of 13 May 2019 - Authorising creation of the Alicem mobile certified online authentication system
Décret No. 2019-452 du 13 mai 2019 - Autorisant création d'un moyen d'identification électronique ALICEM
France
RAI-FR-NA-DN21MXX-2019Decree No. 2019-452 (13 May 2019) authorised the French Ministry of the Interior and the Agence nationale des titres sécurisés (ANTS) to create ALICEM, a high-assurance mobile electronic identification means using contactless reading of biometric passports/residence permits and facial recognition for enrolment. The Decree set permitted purposes, data elements readable from travel documents (except fingerprint images), retention rules and safeguards; it was judicially upheld (Conseil d'État, 4 Nov 2020) and subsequently abrogated and replaced by a broader identity service decree in April 2022.
Summary
Decree No. 2019-452 of 13 May 2019 (published in the Journal Officiel on 16 May 2019) authorised the French Minister of the Interior to implement an automated personal-data processing operation named "Authentification en ligne certifiée sur mobile" (commonly known by the acronym ALICEM). The processing aimed to allow adult holders of biometric passports or electronic biometric residence permits to create a secure digital identity on a mobile device equipped with a contactless reader and to authenticate themselves to public or private online service providers. The Decree expressly referenced and sought to respect EU Regulation (EU) No 910/2014 (eIDAS) and the GDPR (Regulation (EU) 2016/679) and established a legal framework for using biometric data (facial recognition) for the specific purpose of identity creation and authentication.
Key elements authorised by the Decree included: reading data stored in the electronic component of passports and electronic residence permits (excluding the scanned image of fingerprints); the use of a combination of static and dynamic facial recognition to compare the live user and the document photo at enrolment; creation of an account tied to a telephone number and to the cryptographic keys/profiles generated by the mobile application; secure storage and limited retention of authentication and transaction history; logging of operations and conditions under which administration staff could access data for operational purposes; and the possibility to make the ALICEM identity available to services interoperating with FranceConnect.
Before adoption the draft was the subject of an opinion process with the CNIL (the French data-protection authority) (see CNIL deliberations and agenda items in October 2018). The CNIL expressed reservations, particularly that the proposed system did not, in its view, sufficiently establish effective alternatives to biometrics at enrolment and that the freedom of consent could be undermined if users lacked feasible alternatives. Following publication, the associative claimant La Quadrature du Net challenged the Decree for excess of power; the Conseil d'État rejected the claim on 4 November 2020 (Decision No. 432656), finding that at the time of the Decree there was no fully dematerialised alternative providing the equivalent level of guarantee for remote, high-assurance identity creation and that users retained access to services via FranceConnect without consenting to facial-recognition processing.
ALICEM was implemented under the joint responsibility of the Ministry of the Interior (program oversight) and ANTS (technical implementation). The Decree spelled out data categories, permitted recipients, access rules, retention periods, logging requirements, information and rights for data subjects (access/rectification/deletion), and requirements for security measures. It also referred to the eIDAS technical assurance levels and to the GDPR's special categories rules (notably Article 9). The Decree did not itself create criminal sanctions; however, non‑compliance with data-protection obligations exposed implementing actors to administrative enforcement and sanctions under French data-protection law and the GDPR, and to judicial review.
On 26 April 2022 the Government issued Decree No. 2022-676 authorising the creation of a new "Service de garantie de l'identité numérique" (SGIN) and expressly abrogating Decree No. 2019-452; the abrogation came into effect at the date the SGIN decree entered into force (publication/entry into force end of April 2022). Since then the legal basis for the national sovereign digital identity service in France is the newer SGIN regime. The ALICEM decree therefore has ended its legal effect, though its history remains important for understanding French policymaking on biometrics, eIDAS alignment, and the jurisprudence on biometric consent and necessity.
Full article
Read full text ↗Overview
Decree No. 2019-452 of 13 May 2019 authorised the French State, via the Ministry of the Interior in partnership with the Agence nationale des titres sécurisés (ANTS), to create and operate a mobile electronic identification scheme known as ALICEM ("Authentification en ligne certifiée sur mobile"). The system allowed adult holders of biometric passports or electronic biometric residence permits to create a high-assurance digital identity on a smartphone using contactless reading of the travel-document chip and facial-recognition checks at enrolment. The Decree referenced EU and national data-protection and e‑ID rules (in particular eIDAS Regulation (EU) No 910/2014 and the GDPR), defined permitted data flows, and set safeguards, retention and transparency obligations. The text was published in the Journal Officiel on 16 May 2019 and later abrogated and replaced by a subsequent identity-service decree in April 2022 (Decree No. 2022-676).
Definitions
Key terms used or implied by the Decree included: "ALICEM" (the named treatment / mobile application and service), "electronic identification means" (a means enabling electronic identification and authentication), "biometric passport" and "electronic residence permit" (documents with an electronic component and biometric data), "contactless reading" (NFC or equivalent reading of the document chip), "static and dynamic facial recognition" (image comparison methods used at enrolment and liveness checks), "FranceConnect" (national authentication gateway), "data controller(s)" (Ministry/ANTS jointly), and "teleservice providers" (public or private services receiving authentication assertions under convention).
Governance and Institutional Framework
The Decree placed governance responsibility with the Minister of the Interior and designated ANTS as the implementation/operational agency. Operational rules and supervisory links connected ALICEM to FranceConnect (authorising transmission of a limited set of attributes to convention-linked teleservice providers). The Commission Nationale de l'Informatique et des Libertés (CNIL) was the supervisory authority responsible for assessing compliance with data-protection obligations; CNIL examined the draft and issued a formal opinion process (see the CNIL plenary agenda and deliberation references of October 2018). Judicial oversight occurred through administrative courts and ultimately the Conseil d'État, which reviewed challenges (notably Decision No. 432656, 4 Nov 2020) and interpreted necessity and proportionality in light of the GDPR. Implementation also required coordination with other ministries and conformity to eIDAS technical assurance specifications (Commission Implementing Regulation (EU) 2015/1502).
Key Focus Areas
The Decree focused on several core technical and policy areas: (1) the lawful basis and narrow purposes for processing personal and biometric data to permit high-assurance, remote digital identity creation and authentication; (2) the exact categories of data readable from the electronic component of travel documents (identity attributes, document identifiers, cryptographic keys and authenticity data; expressly excluding the stored scanned image of fingerprints); (3) the use of static and dynamic facial-recognition systems limited to enrolment / verification with explicit consent and subject to erasure once recognition tasks finish; (4) integration with FranceConnect so that ALICEM identities could be used by teleservice providers under convention; (5) limitations on recipients and strict access rules for administrative staff and service providers in the "need-to-know" scope; (6) required information and rights of data subjects (right to information, access, rectification, deletion, limitation) consistent with the GDPR and French law; (7) logging, recordkeeping and retention periods for transactional and operational logs; and (8) security and confidentiality obligations placed on implementers (technical protections, access controls, audit capabilities). The policy balanced the State’s interest in enabling remote high-assurance authentication for public services with data-protection safeguards and oversight mechanisms.
Implementation Framework
Operationalising the Decree required technical, organisational and legal steps: ANTS built the mobile application and backend services; NFC/contactless readers in compatible mobile devices were required to read passport/residence-permit chips; facial-recognition modules performed static photo comparison and dynamic liveness checks during enrolment; cryptographic key generation tied identities to mobile devices and phone numbers; privacy notices, consent collection flows and user interfaces were developed to meet GDPR requirements; data retention and erasure routines were established; secure servers and logging systems were provisioned; agreements (conventions) with FranceConnect and teleservice providers were drafted to govern attribute exchanges; staff authorisations and training were implemented; and data-protection impact assessments (DPIAs) and CNIL consultations were completed as part of the pre-deployment compliance process.
Monitoring and Evaluation
The Decree required logging of key operations (creation, consultation, use, revocation, deletion) including actor identity, timestamps and operation purpose, with retention of those logs for specified durations (the Decree and implementing notices set defined retention windows). CNIL oversight, periodic audits, DPIAs and reporting obligations were the primary evaluation mechanisms. Judicial review (administrative litigation) served as an additional monitoring channel; for example, after the Decree’s adoption La Quadrature du Net filed a challenge that led to the Conseil d'État review and ruling in 2020. Metrics for technical evaluation included false-acceptance/false-rejection rates for facial recognition, failure/retry rates for contactless reading, user retention and incidence of security incidents. The Ministry and ANTS were expected to publish lists of authorised teleservice providers and to make transparency information available to users.
Penalties, Liability, and Appeals
The Decree itself did not create bespoke criminal penalties but it operated within the enforcement landscape of the GDPR and French data-protection law (law no. 78-17 as amended). Non-compliance exposed implementing authorities and suppliers to CNIL administrative sanctions (including fines under the GDPR) and to civil liability for damages. Users could exercise rights before CNIL and pursue judicial remedies; administrative actors and associations could challenge the Decree by bringing cases before the administrative courts (as happened). Liability allocation among the Ministry, ANTS and contracted vendors was managed through conventions and procurement contracts. The Conseil d'État’s decision (4 Nov 2020) provides precedent on proportionality and consent interpretation for biometric processing in government identity projects.
Relationship to Other Instruments
ALICEM was explicitly framed to comply with or complement: (1) Regulation (EU) No 910/2014 (eIDAS) concerning electronic identification and trust services; (2) GDPR (2016/679) concerning processing, special categories (biometrics) and consent; (3) Commission Implementing Regulation (EU) 2015/1502 for assurance-level technical specifications; (4) French Data-Protection Act (Law No. 78-17) and successor national provisions; and (5) the FranceConnect interop framework. The Decree also interacted with immigration and identity statutes (codes governing passports, residence permits and civil-status documents). It was later superseded/abrogated by Decree No. 2022-676 (SGIN), which replaced the ALICEM-specific authorisation with a broader national identity-guarantee service regime.
International Alignment
From a legal and technical perspective the Decree sought alignment with EU frameworks: eIDAS assured interoperability and defined assurance-level requirements; GDPR governed biometric data as a special category with strict conditions for processing; and EU implementing acts defined technical measures and attestation levels. The Conseil d'État’s analysis referenced EU law and indicated that, at the time of the Decree, no equivalent fully dematerialised method assured the same remote enrolment guarantees, so the limited biometric processing was permissible. The Decree and subsequent jurisprudence are frequently cited in EU debates on state-led electronic identity, biometric authentication, and the limits of consent for government digital services. Internationally, the ALICEM experience has been referenced in policy discussions about balancing biometric convenience with fundamental-rights safeguards.
Implementation Timeline
| Event | Date |
|---|---|
| Decree signed (Decree No. 2019-452) | 2019-05-13 |
| Decree published in Journal Officiel | 2019-05-16 |
| CNIL deliberation / opinion process (plenary agenda) | 2018-10-18 |
| Implementation and public roll-out (ANTS / Ministry) | 2019–2020 (implementation period) |
| Administrative challenge — Conseil d'État decision rejecting annulment | 2020-11-04 |
| Abrogation and replacement by SGIN (Decree No. 2022-676) | 2022-04-26 (signed) / 2022-04-28 (entry into force) |
Sources and References
| Source | Type |
|---|---|
| Decree No. 2019-452 (Legifrance – Journal Officiel) | Primary Source |
| Conseil d'État Decision No. 432656, 4 Nov 2020 (La Quadrature du Net v. State) | Primary Source |
| Decree No. 2022-676 (Legifrance) — SGIN; abrogating Decree No. 2019-452 | Primary Source |
| CNIL Plenary Agenda (18 Oct 2018) — ALICEM item and deliberation references | Primary Source (administrative opinion process) |
| Agence nationale des titres sécurisés (ANTS) — official site and technical/operational pages | Primary Source (operator) |
Requirements for a company
What an organisation has to do under France - Mobile Authentication System (2019-452), at a glance. Not legal advice.
Related Regulations
Decree No. 2022-676 of 26 April 2022 - Authorising creation of the 'Service de garantie de l'identité numérique' (SGIN) electronic identification service (Décret autorisant la création d'un moyen d'identification électronique SGIN)
France89% similar
Proposition de loi relative à la reconnaissance biométrique dans l'espace public (Proposal / parliamentary bill on biometric recognition in public space) - report deposited 31 May 2023
France86% similar
Decree No. 2017-330 of 14 March 2017 - Rights of persons subject to individual decisions based on algorithmic processing (Décret relatif aux droits des personnes faisant l'objet de décisions individuelles prises sur le fondement d'un traitement algorithmique)
France81% similar
Loi n° 2024-449 du 21 mai 2024 visant à sécuriser et à réguler l'espace numérique ("SREN")
France81% similar
European Commission Guidelines regarding prohibited AI practices (guidance on Article 5 prohibitions)
European Union80% similar
© Regulations.AI · updated on 13-Jun-2026