France - Electronic Identification Service (2022-676)

Decree No. 2022-676 of 26 April 2022 - Authorising creation of the 'Service de garantie de l'identité numérique' (SGIN) electronic identification service

Décret n° 2022-676 du 26 avril 2022 - Autorisant création du 'Service de garantie de l'identité numérique' (SGIN) service d'identification électronique

France

RAI-FR-NA-DN22AXX-2022
Effective: April 28, 2022
In Force(In Force)
DecreeGovernance and OversightData Protection and PrivacyAccountability and Documentation
Export PDF

Decree No. 2022-676 (26 April 2022) authorises the French Ministry of the Interior and the Agence nationale des titres sécurisés (ANTS) to implement an automated personal-data processing system named the Service de garantie de l'identité numérique (SGIN), enabling holders of the French electronic national identity card (CNIe) to create an electronic identification/authentication means via a mobile application and to generate attestations containing only the identity attributes chosen by the user. (justice.pappers.fr)

Summary

Decree No. 2022-676 (enacted 26 April 2022; published JORF 27 April 2022; entry into force 28 April 2022) authorises the Minister of the Interior (secretariat general) and the ANTS to create and operate the Service de garantie de l'identité numérique (SGIN). The SGIN system is intended to allow holders of a French national identity card with an electronic component (CNIe) to install a mobile application on an NFC-capable terminal to read the electronic component of their identity card and to perform electronic identification and authentication with public or private service providers. The application allows users to generate electronic attestations containing only the identity attributes they choose to transmit to third parties. The decree specifies categories of personal data that may be processed (name, given names, date and place of birth, nationality, sex, postal address from the card, user-supplied postal address, photo from the card, contact email, mobile device number if provided; plus card identifiers, issuance and expiry dates and validity status), records transaction metadata (recipient, category and status of transaction, timestamp, optional purpose and duration) and records operational events (creation, consultation, use, revocation, deletion) with a three-year retention for those logs. Access to the processing is limited to designated agents of the Ministry of the Interior and the ANTS and certain recipients such as FranceConnect and convention-linked teleservice providers, within the limits stated by the decree. The decree abrogates Decree No. 2019-452 (13 May 2019: 'Authentification en ligne certifiée sur mobile') and applies across metropolitan France and overseas territories (with specified local adaptations). The processing is subject to the data-subject rights provided by the EU GDPR. The decree provides the legal basis for SGIN operations and sets operational, access and data-retention constraints while linking the service to France's broader digital identity strategy (including FranceConnect and related projects). ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))

Full article

Read full text ↗

Overview

The Decree No. 2022-676 of 26 April 2022 authorises the creation and operation of the Service de garantie de l'identité numérique (SGIN), a processing system implemented jointly by the Minister of the Interior (secretariat general) and the Agence nationale des titres sécurisés (ANTS). The SGIN enables holders of a French national identity card containing an electronic component (CNIe) to use a mobile application on an NFC-capable terminal to read that component, to create a secure electronic identification/authentication means, and to generate attestations with a selectable subset of identity attributes to present to public or private third parties. The decree entered into force on 28 April 2022 and replaces the prior mobile-authentication measure created by Decree No. 2019-452. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))

Definitions

Key defined concepts in the decree include: 'SGIN' (Service de garantie de l'identité numérique) — the authorised automated personal-data processing; 'CNIe' — the national identity card with an electronic component as referenced in the decree of 22 October 1955; 'application' or 'means of identification electronic' — the user-installed mobile application on an NFC-capable terminal; 'user' — the holder of a CNIe who voluntarily creates and uses the electronic means; 'FranceConnect' — the national federated login/identity hub which may receive certain data from SGIN under the conditions described by the decree. The decree also specifies categories of personal data, transaction metadata, and recipient categories for lawful processing. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))

Governance and Institutional Framework

The decree establishes joint responsibility for implementation and operation between the Ministry of the Interior (secretariat general) and the ANTS. Responsibilities include development, deployment, operation, security, and maintenance of servers and the application ecosystem. Access to stored data is restricted to individually designated and specially authorised agents within the Ministry and the ANTS charged with project management and operation. The decree also requires publication of the up-to-date list of teleservice providers conventionally linked to FranceConnect and those linked by convention to the Ministry/ANTS to which specific identity attributes may be transmitted. Execution and enforcement are assigned to the Minister of the Interior. This governance framework positions SGIN as a public-regulated digital identity infrastructure designed to integrate with existing national services such as FranceConnect and complement broader governmental digital-identification projects. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))

Key Focus Areas

The decree concentrates on several operational and legal axes: (1) lawful basis and scope of personal-data processing — listing permitted identity attributes and card metadata; (2) user autonomy and minimisation — the user may choose which attributes to disclose in generated attestations; (3) security and access control — access limited to designated staff and secured servers; (4) interoperability with national teleservice infrastructures — notably FranceConnect and convention-linked providers, subject to attribute-limited transmission; (5) data retention and logging — operational actions and transaction metadata are recorded and retained (three-year retention for operation logs); (6) rights of data subjects — the decree expressly references exercise of information, access, rectification and limitation rights under the EU GDPR; and (7) territorial application — the decree applies across metropolitan France and overseas territories with particular local adaptations (e.g., NC Connect in New Caledonia). These focus areas reflect a balance between enabling high-assurance digital identification and ensuring data-protection safeguards. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))

Implementation Framework

Operationally, the decree authorises reading of specified personal data from the electronic component of the CNIe (excluding biometric fingerprint images) via NFC, generation of attestations via the user’s application, and transmission to approved recipients. The application lifecycle (creation, consultation, use, revocation, deletion) must be recorded with the actor identifier, timestamp and purpose; such logs are retained for three years on servers managed by the responsible authorities. Interfacing with third parties is controlled by convention; FranceConnect and convention-bound teleservice providers may receive limited attribute sets as defined by the decree. The ANTS is actively procuring implementation and operational contracts to realise and maintain SGIN, and budgetary planning and public procurement notices indicate multi-year IT and security programmes to support the service. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))

Monitoring and Evaluation

The decree requires that access be limited to named and authorised personnel and that operational logs be kept for three years, available to those personnel on user request or in case of dispute. The listing and publication of authorised teleservice providers and conventions create a transparency mechanism for recipients. Monitoring responsibilities lie with the Ministry of the Interior and the ANTS; data-protection supervision and enforcement remain under the EU GDPR framework and the French Data Protection Authority (CNIL). Procurement and budget documents referenced by the government describe ongoing oversight, maintenance and security activities supporting SGIN. These monitoring arrangements are designed to enable audits, incident investigations and compliance checks. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))

Penalties, Liability, and Appeals

The decree itself sets operational and access limits rather than bespoke criminal penalties; processing is explicitly subject to data-subject rights under Regulation (EU) 2016/679 (GDPR), and enforcement of data-protection obligations (including potential administrative sanctions) falls within the CNIL’s competence under applicable EU and national law. Operational errors, unlawful access, data breaches or violations of the GDPR could therefore engage administrative fines and corrective powers available to the CNIL; contractual liability and internal disciplinary measures are expected to be governed by ANTS and Ministry arrangements and public procurement contracts. The decree provides for user-requested access to operational logs and for their consultation in case of disputes, thereby creating procedural avenues for administrative review and evidentiary obligations for the operators. ([justice.pappers.fr](https://justice.pappers.fr/loi/JORFTEXT000045667825?utm_source=openai))

Relationship to Other Instruments

The decree expressly abrogates Decree No. 2019-452 of 13 May 2019 (which authorised the earlier “Authentification en ligne certifiée sur mobile”) and references the decree of 22 October 1955 regarding the national identity card. It also operates within the normative frameworks of the EU eIDAS Regulation (Regulation (EU) No 910/2014) for electronic identification and trust services and the EU General Data Protection Regulation (Regulation (EU) 2016/679) for personal-data protection. Connections to national initiatives such as FranceConnect and the broader France Identité programme are explicit in government planning and budget documentation. The decree therefore functions as a national implementing measure enabling integration of the CNIe-based identification into federated services and national digital-identity strategies. ([vlex.fr](https://vlex.fr/vid/decret-n-2022-676-902363477?utm_source=openai))

International Alignment

The SGIN is designed to be compatible with the EU-level eIDAS framework by allowing a CNIe-backed means of high-assurance identification and by enabling integration with services that may interoperate across EU member states under eIDAS principles. Budgetary and programme documentation frames SGIN/France Identité as part of a national strategy to meet eIDAS assurance levels and to provide a sovereign, interoperable identity solution for both domestic use and (where applicable) for cross-border interactions aligned with EU rules. The decree also contemplates application to overseas territories with local adjustments, and subsequent procurement and technical specifications have referenced EU interoperability and cybersecurity standards. ([budget.gouv.fr](https://www.budget.gouv.fr/files/uploads/extract/2023/PLR/BG/PGM/354/FR_2023_PLR_BG_PGM_354_JPE.html?utm_source=openai))

Implementation Timeline

MilestoneDate
Decree signed2022-04-26
Publication in JORF2022-04-27
Entry into force2022-04-28
ANTS procurement notices (implementation & maintenance)2024–2025 (ongoing public procurement activity; example notices published 2025-01-02 and 2025-01-07)
Integration with France Identité/FranceConnect planning and rollout (budgeted)2023–2025 (programme documents indicate multi-year rollout)

Sources and References

SourceType
Legifrance – Decree No. 2022-676 (JORFTEXT000045667825)Primary Source
Justice / Pappers – Text and article summaries for Décret n°2022-676Primary Source (republished)
ANTS – Agence nationale des titres sécurisés (program and procurement pages)Primary Source (implementing agency)
Ministry of Economy – references to SGIN used for e-carte Vitale integrationOfficial Government Reference
Budget / Programme documents – France Identité / SGIN budgeting and project descriptionOfficial Budgetary Document

Requirements for a company

What an organisation has to do under France - Electronic Identification Service (2022-676), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

10
  • Jointly implement and operate the Service de garantie de l'identité numérique (SGIN) system.Ministry of the Interior and ANTS.
  • Restrict access to stored data to individually designated and specially authorized agents.Ministry of the Interior and ANTS.
  • Ensure users can choose which identity attributes to disclose in generated attestations.Ministry of the Interior and ANTS.
  • Exclude biometric fingerprint images from data read from the CNIe.Ministry of the Interior and ANTS.
  • Record and retain operational actions and transaction metadata logs for three years.Ministry of the Interior and ANTS.
  • Facilitate the exercise of GDPR data subject rights, including information, access, rectification, and limitation.Ministry of the Interior and ANTS.
  • +4 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under France - Electronic Identification Service (2022-676), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Ministry of the Interior and ANTS.Jointly implement and operate the Service de garantie de l'identité numérique (SGIN) system.
The decree establishes joint responsibility for implementation and operation between the Ministry of the Interior (secretariat general) and the ANTS.
nullCritical
2Ministry of the Interior and ANTS.Restrict access to stored data to individually designated and specially authorized agents.
Access to stored data is restricted to individually designated and specially authorised agents within the Ministry and the ANTS charged with project management and operation.
Before placing on marketCritical
3Ministry of the Interior and ANTS.Ensure users can choose which identity attributes to disclose in generated attestations.
user autonomy and minimisation — the user may choose which attributes to disclose in generated attestations
Before placing on marketCritical
4Ministry of the Interior and ANTS.Exclude biometric fingerprint images from data read from the CNIe.
excluding biometric fingerprint images
Before placing on marketCritical
5Ministry of the Interior and ANTS.Record and retain operational actions and transaction metadata logs for three years.
operational actions and transaction metadata are recorded and retained (three-year retention for operation logs)
nullCritical
6Ministry of the Interior and ANTS.Facilitate the exercise of GDPR data subject rights, including information, access, rectification, and limitation.
the decree expressly references exercise of information, access, rectification and limitation rights under the EU GDPR
Before placing on marketCritical
7Ministry of the Interior and ANTS.Interface with third parties only via formal conventions, transmitting limited attribute sets.
Interfacing with third parties is controlled by convention; FranceConnect and convention-bound teleservice providers may receive limited attribute sets...
Before data transmission to third partiesCritical
8Ministry of the Interior and ANTS.Record the application lifecycle, including actor identifier, timestamp, and purpose.
The application lifecycle (creation, consultation, use, revocation, deletion) must be recorded with the actor identifier, timestamp and purpose
nullCritical
9Ministry of the Interior and ANTS.Cease operation under Decree No. 2019-452.
The decree expressly abrogates Decree No. 2019-452 of 13 May 2019
Apr 28, 2022Critical
10Ministry of the Interior and ANTS.Publish an up-to-date list of conventionally linked teleservice providers.
The decree also requires publication of the up-to-date list of teleservice providers conventionally linked to FranceConnect and those linked by convention...
nullImportant

© Regulations.AI · updated on 13-Jun-2026