France - Electronic Identification Service (2022-676)
Decree No. 2022-676 of 26 April 2022 - Authorising creation of the 'Service de garantie de l'identité numérique' (SGIN) electronic identification service
Décret n° 2022-676 du 26 avril 2022 - Autorisant création du 'Service de garantie de l'identité numérique' (SGIN) service d'identification électronique
France
RAI-FR-NA-DN22AXX-2022Decree No. 2022-676 (26 April 2022) authorises the French Ministry of the Interior and the Agence nationale des titres sécurisés (ANTS) to implement an automated personal-data processing system named the Service de garantie de l'identité numérique (SGIN), enabling holders of the French electronic national identity card (CNIe) to create an electronic identification/authentication means via a mobile application and to generate attestations containing only the identity attributes chosen by the user. (justice.pappers.fr)
Summary
Decree No. 2022-676 (enacted 26 April 2022; published JORF 27 April 2022; entry into force 28 April 2022) authorises the Minister of the Interior (secretariat general) and the ANTS to create and operate the Service de garantie de l'identité numérique (SGIN). The SGIN system is intended to allow holders of a French national identity card with an electronic component (CNIe) to install a mobile application on an NFC-capable terminal to read the electronic component of their identity card and to perform electronic identification and authentication with public or private service providers. The application allows users to generate electronic attestations containing only the identity attributes they choose to transmit to third parties. The decree specifies categories of personal data that may be processed (name, given names, date and place of birth, nationality, sex, postal address from the card, user-supplied postal address, photo from the card, contact email, mobile device number if provided; plus card identifiers, issuance and expiry dates and validity status), records transaction metadata (recipient, category and status of transaction, timestamp, optional purpose and duration) and records operational events (creation, consultation, use, revocation, deletion) with a three-year retention for those logs. Access to the processing is limited to designated agents of the Ministry of the Interior and the ANTS and certain recipients such as FranceConnect and convention-linked teleservice providers, within the limits stated by the decree. The decree abrogates Decree No. 2019-452 (13 May 2019: 'Authentification en ligne certifiée sur mobile') and applies across metropolitan France and overseas territories (with specified local adaptations). The processing is subject to the data-subject rights provided by the EU GDPR. The decree provides the legal basis for SGIN operations and sets operational, access and data-retention constraints while linking the service to France's broader digital identity strategy (including FranceConnect and related projects). ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))
Full article
Read full text ↗Overview
The Decree No. 2022-676 of 26 April 2022 authorises the creation and operation of the Service de garantie de l'identité numérique (SGIN), a processing system implemented jointly by the Minister of the Interior (secretariat general) and the Agence nationale des titres sécurisés (ANTS). The SGIN enables holders of a French national identity card containing an electronic component (CNIe) to use a mobile application on an NFC-capable terminal to read that component, to create a secure electronic identification/authentication means, and to generate attestations with a selectable subset of identity attributes to present to public or private third parties. The decree entered into force on 28 April 2022 and replaces the prior mobile-authentication measure created by Decree No. 2019-452. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))
Definitions
Key defined concepts in the decree include: 'SGIN' (Service de garantie de l'identité numérique) — the authorised automated personal-data processing; 'CNIe' — the national identity card with an electronic component as referenced in the decree of 22 October 1955; 'application' or 'means of identification electronic' — the user-installed mobile application on an NFC-capable terminal; 'user' — the holder of a CNIe who voluntarily creates and uses the electronic means; 'FranceConnect' — the national federated login/identity hub which may receive certain data from SGIN under the conditions described by the decree. The decree also specifies categories of personal data, transaction metadata, and recipient categories for lawful processing. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))
Governance and Institutional Framework
The decree establishes joint responsibility for implementation and operation between the Ministry of the Interior (secretariat general) and the ANTS. Responsibilities include development, deployment, operation, security, and maintenance of servers and the application ecosystem. Access to stored data is restricted to individually designated and specially authorised agents within the Ministry and the ANTS charged with project management and operation. The decree also requires publication of the up-to-date list of teleservice providers conventionally linked to FranceConnect and those linked by convention to the Ministry/ANTS to which specific identity attributes may be transmitted. Execution and enforcement are assigned to the Minister of the Interior. This governance framework positions SGIN as a public-regulated digital identity infrastructure designed to integrate with existing national services such as FranceConnect and complement broader governmental digital-identification projects. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))
Key Focus Areas
The decree concentrates on several operational and legal axes: (1) lawful basis and scope of personal-data processing — listing permitted identity attributes and card metadata; (2) user autonomy and minimisation — the user may choose which attributes to disclose in generated attestations; (3) security and access control — access limited to designated staff and secured servers; (4) interoperability with national teleservice infrastructures — notably FranceConnect and convention-linked providers, subject to attribute-limited transmission; (5) data retention and logging — operational actions and transaction metadata are recorded and retained (three-year retention for operation logs); (6) rights of data subjects — the decree expressly references exercise of information, access, rectification and limitation rights under the EU GDPR; and (7) territorial application — the decree applies across metropolitan France and overseas territories with particular local adaptations (e.g., NC Connect in New Caledonia). These focus areas reflect a balance between enabling high-assurance digital identification and ensuring data-protection safeguards. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))
Implementation Framework
Operationally, the decree authorises reading of specified personal data from the electronic component of the CNIe (excluding biometric fingerprint images) via NFC, generation of attestations via the user’s application, and transmission to approved recipients. The application lifecycle (creation, consultation, use, revocation, deletion) must be recorded with the actor identifier, timestamp and purpose; such logs are retained for three years on servers managed by the responsible authorities. Interfacing with third parties is controlled by convention; FranceConnect and convention-bound teleservice providers may receive limited attribute sets as defined by the decree. The ANTS is actively procuring implementation and operational contracts to realise and maintain SGIN, and budgetary planning and public procurement notices indicate multi-year IT and security programmes to support the service. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))
Monitoring and Evaluation
The decree requires that access be limited to named and authorised personnel and that operational logs be kept for three years, available to those personnel on user request or in case of dispute. The listing and publication of authorised teleservice providers and conventions create a transparency mechanism for recipients. Monitoring responsibilities lie with the Ministry of the Interior and the ANTS; data-protection supervision and enforcement remain under the EU GDPR framework and the French Data Protection Authority (CNIL). Procurement and budget documents referenced by the government describe ongoing oversight, maintenance and security activities supporting SGIN. These monitoring arrangements are designed to enable audits, incident investigations and compliance checks. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))
Penalties, Liability, and Appeals
The decree itself sets operational and access limits rather than bespoke criminal penalties; processing is explicitly subject to data-subject rights under Regulation (EU) 2016/679 (GDPR), and enforcement of data-protection obligations (including potential administrative sanctions) falls within the CNIL’s competence under applicable EU and national law. Operational errors, unlawful access, data breaches or violations of the GDPR could therefore engage administrative fines and corrective powers available to the CNIL; contractual liability and internal disciplinary measures are expected to be governed by ANTS and Ministry arrangements and public procurement contracts. The decree provides for user-requested access to operational logs and for their consultation in case of disputes, thereby creating procedural avenues for administrative review and evidentiary obligations for the operators. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))
Relationship to Other Instruments
The decree expressly abrogates Decree No. 2019-452 of 13 May 2019 (which authorised the earlier “Authentification en ligne certifiée sur mobile”) and references the decree of 22 October 1955 regarding the national identity card. It also operates within the normative frameworks of the EU eIDAS Regulation (Regulation (EU) No 910/2014) for electronic identification and trust services and the EU General Data Protection Regulation (Regulation (EU) 2016/679) for personal-data protection. Connections to national initiatives such as FranceConnect and the broader France Identité programme are explicit in government planning and budget documentation. The decree therefore functions as a national implementing measure enabling integration of the CNIe-based identification into federated services and national digital-identity strategies. ([vlex.fr](https://vlex.fr/vid/decret-n-2022-676-902363477?utm_source=openai))
International Alignment
The SGIN is designed to be compatible with the EU-level eIDAS framework by allowing a CNIe-backed means of high-assurance identification and by enabling integration with services that may interoperate across EU member states under eIDAS principles. Budgetary and programme documentation frames SGIN/France Identité as part of a national strategy to meet eIDAS assurance levels and to provide a sovereign, interoperable identity solution for both domestic use and (where applicable) for cross-border interactions aligned with EU rules. The decree also contemplates application to overseas territories with local adjustments, and subsequent procurement and technical specifications have referenced EU interoperability and cybersecurity standards. ([budget.gouv.fr](https://www.budget.gouv.fr/files/uploads/extract/2023/PLR/BG/PGM/354/FR_2023_PLR_BG_PGM_354_JPE.html?utm_source=openai))
Implementation Timeline
| Milestone | Date |
|---|---|
| Decree signed | 2022-04-26 |
| Publication in JORF | 2022-04-27 |
| Entry into force | 2022-04-28 |
| ANTS procurement notices (implementation & maintenance) | 2024–2025 (ongoing public procurement activity; example notices published 2025-01-02 and 2025-01-07) |
| Integration with France Identité/FranceConnect planning and rollout (budgeted) | 2023–2025 (programme documents indicate multi-year rollout) |
Sources and References
| Source | Type |
|---|---|
| Legifrance – Decree No. 2022-676 (JORFTEXT000045667825) | Primary Source |
| Justice / Pappers – Text and article summaries for Décret n°2022-676 | Primary Source (republished) |
| ANTS – Agence nationale des titres sécurisés (program and procurement pages) | Primary Source (implementing agency) |
| Ministry of Economy – references to SGIN used for e-carte Vitale integration | Official Government Reference |
| Budget / Programme documents – France Identité / SGIN budgeting and project description | Official Budgetary Document |
Requirements for a company
What an organisation has to do under France - Electronic Identification Service (2022-676), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
10- Jointly implement and operate the Service de garantie de l'identité numérique (SGIN) system.Ministry of the Interior and ANTS.
- Restrict access to stored data to individually designated and specially authorized agents.Ministry of the Interior and ANTS.
- Ensure users can choose which identity attributes to disclose in generated attestations.Ministry of the Interior and ANTS.
- Exclude biometric fingerprint images from data read from the CNIe.Ministry of the Interior and ANTS.
- Record and retain operational actions and transaction metadata logs for three years.Ministry of the Interior and ANTS.
- Facilitate the exercise of GDPR data subject rights, including information, access, rectification, and limitation.Ministry of the Interior and ANTS.
- +4 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under France - Electronic Identification Service (2022-676), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Ministry of the Interior and ANTS. | Jointly implement and operate the Service de garantie de l'identité numérique (SGIN) system. “The decree establishes joint responsibility for implementation and operation between the Ministry of the Interior (secretariat general) and the ANTS.” | null | — | Critical |
| 2 | Ministry of the Interior and ANTS. | Restrict access to stored data to individually designated and specially authorized agents. “Access to stored data is restricted to individually designated and specially authorised agents within the Ministry and the ANTS charged with project management and operation.” | Before placing on market | — | Critical |
| 3 | Ministry of the Interior and ANTS. | Ensure users can choose which identity attributes to disclose in generated attestations. “user autonomy and minimisation — the user may choose which attributes to disclose in generated attestations” | Before placing on market | — | Critical |
| 4 | Ministry of the Interior and ANTS. | Exclude biometric fingerprint images from data read from the CNIe. “excluding biometric fingerprint images” | Before placing on market | — | Critical |
| 5 | Ministry of the Interior and ANTS. | Record and retain operational actions and transaction metadata logs for three years. “operational actions and transaction metadata are recorded and retained (three-year retention for operation logs)” | null | — | Critical |
| 6 | Ministry of the Interior and ANTS. | Facilitate the exercise of GDPR data subject rights, including information, access, rectification, and limitation. “the decree expressly references exercise of information, access, rectification and limitation rights under the EU GDPR” | Before placing on market | — | Critical |
| 7 | Ministry of the Interior and ANTS. | Interface with third parties only via formal conventions, transmitting limited attribute sets. “Interfacing with third parties is controlled by convention; FranceConnect and convention-bound teleservice providers may receive limited attribute sets...” | Before data transmission to third parties | — | Critical |
| 8 | Ministry of the Interior and ANTS. | Record the application lifecycle, including actor identifier, timestamp, and purpose. “The application lifecycle (creation, consultation, use, revocation, deletion) must be recorded with the actor identifier, timestamp and purpose” | null | — | Critical |
| 9 | Ministry of the Interior and ANTS. | Cease operation under Decree No. 2019-452. “The decree expressly abrogates Decree No. 2019-452 of 13 May 2019” | Apr 28, 2022 | — | Critical |
| 10 | Ministry of the Interior and ANTS. | Publish an up-to-date list of conventionally linked teleservice providers. “The decree also requires publication of the up-to-date list of teleservice providers conventionally linked to FranceConnect and those linked by convention...” | null | — | Important |
Related Regulations
Decree No. 2019-452 of 13 May 2019 - Authorising creation of the Alicem mobile certified online authentication system (Décret autorisant la création d'un moyen d'identification électronique ALICEM)
France89% similar
Law No. 2018-493 of 20 June 2018 - Law on the Protection of Personal Data (adaptation of the French Data Protection Act to the GDPR)
France85% similar
Proposition de loi relative à la reconnaissance biométrique dans l'espace public (Proposal / parliamentary bill on biometric recognition in public space) - report deposited 31 May 2023
France84% similar
Loi n° 2024-449 du 21 mai 2024 visant à sécuriser et à réguler l'espace numérique ("SREN")
France84% similar
Decree No. 2017-331 of 14 March 2017 - Service public for provision of reference data (Décret relatif au service public de mise à disposition des données de référence)
France84% similar
© Regulations.AI · updated on 13-Jun-2026