France - Digital Space Regulation (2024-449)
Law No. 2024-449 of May 21, 2024, Aiming to Secure and Regulate the Digital Space ("SREN")
Loi n° 2024-449 du 21 mai 2024 visant à sécuriser et à réguler l'espace numérique ("SREN")
France
RAI-FR-NA-LN2D2XX-2024The SREN law (Loi n°2024-449, 21 May 2024) strengthens regulation of online services and the digital ecosystem in France, including protections for minors, platform obligations (age verification, content takedown), measures on cloud market fairness and expanded powers for regulators such as ARCOM and CNIL. It interacts with EU instruments including the EU AI Act.
Summary
Read full text ↗Plain English
Overview
The law entitled "visant à sécuriser et à réguler l'espace numérique" (SREN) was adopted by Parliament in spring 2024 and promulgated in May 2024 to strengthen protections in the French digital ecosystem. The text brings together measures across protection of minors, platform responsibility for illegal content, market fairness in cloud services, new powers and cooperation rules for regulators and procedural tools for faster takedown and sanctions for online harms. The law is available in consolidated and JORF versions on Légifrance and its legislative dossier is hosted by the Assemblée nationale. Consolidated text.
Definitions
The SREN law uses defined terms for categories of online actors (e.g. "services permettant l'accès à des contenus pornographiques", "fournisseurs de services d'informatique en nuage", "services de très grandes plateformes en ligne" by reference to the DSA/DMA) and refers to regulatory definitions in EU instruments where relevant. Legislative definitions and cross-references are provided in the text of the law; readers should consult the text for the statutory wording and precise article cross‑references. See law text (articles and definitions).
Governance and Institutional Framework
SREN strengthens a multi‑agency governance model: it allocates specific powers to ARCOM (Autorité de régulation de la communication audiovisuelle et numérique) for age verification and audiovisual compliance, to CNIL for data protection and new investigative competences, to ARCEP for cloud‑market related oversight and to other sectoral regulators where indicated. The law prescribes cooperation mechanisms between these authorities and provides for delegated powers to adopt implementation decrees. The law and subsequent implementing decrees set out the respective remits. Law (governance provisions) and Decree n°2025-387 (cooperation ARCEP/CNIL).
Key Focus Areas
Principal focus areas include: (1) protection of minors online through mandatory age‑verification systems for sites providing pornographic content and ARCOM referential standards; (2) stronger takedown powers and penalties for platforms hosting illegal content (including expedited procedures for child sexual abuse material); (3) regulation of cloud services (interoperability and market fairness obligations, transparency requirements for cloud offers); (4) extension of investigative powers of CNIL for compliance with data protection obligations when connected to digital platform regulation; and (5) alignment and operationalization of EU-level rules such as the Digital Services Act, Digital Markets Act and the EU Artificial Intelligence Act. Each focus area includes statutory obligations and delegated rule‑making powers for ministers and authorities to adopt technical referentials. See core provisions.
Implementation Framework
The law sets deadlines and mandates for issuance of implementing decrees and regulator referentials. For cloud‑market interoperability rules, implementing measures and technical reference offers were to be specified by decree (see article 29 and implementing decrees of 2025). For ARCOM's age‑verification referential the Authority must publish the technical referential within two months of promulgation of the law and platforms were given transitional windows to comply; exact timelines and technical modalities are defined in the law and associated ARCOM referentials. Law text (article references) and Decree n°2025-484 (cloud implementing rules).
Monitoring and Evaluation
The law requires periodic reporting and gives regulators powers to audit and obtain documents. The Government transmitted a report on application to Parliament on 18 April 2025 in accordance with the statutory reporting duties. Authorities are required to publish activity reports and assessment material; cross‑authority cooperation provisions (e.g. ARCEP/CNIL cooperation) are regulated by decree to enable joint procedures. Legislative dossier and government report.
Penalties, Liability, and Appeals
SREN provides for administrative sanctions by designated regulators. Monetary sanctions for certain platform failures are calibrated in the statute (for example ARCOM sanctions linked to age‑verification non‑compliance and other infractions reference caps such as up to €250,000 or percentages of turnover for recidivism in specified cases; other sanction maxima are set in the statutory text). Detailed sanctioning regimes and appeal procedures are specified in the law and national administrative procedure codes, with rights to contest before administrative courts. See sanction provisions in the law.
Relationship to Other Instruments
SREN was designed to operate alongside and implement obligations under EU instruments (DSA/DMA) and to dovetail with the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). The EU AI Regulation is directly applicable in Member States and SREN focuses on sectoral national powers (e.g., cloud market fairness and platform rules) that intersect with EU AI requirements; national regulators will therefore coordinate enforcement with the EU AI Office and use the law's powers where sectoral national measures are required. EU AI Act (Regulation (EU) 2024/1689) and SREN.
International Alignment
By design SREN references and implements obligations aligned with EU-level law and seeks compatibility with internal market rules; where the law delegates technical standards, those standards must respect EU obligations and international commitments. The law's cloud fairness measures also reference EU data and cloud governance regulations to avoid fragmentation. EU AI Act and implementing opinions issued by regulators.
Implementation Timeline
| Date/Period | Milestone | Status |
|---|---|---|
| 10 Apr 2024 | Assembly adoption of CMP text; final adoption by Assemblée nationale | Completed; parliamentary adoption |
| 17 May 2024 | Conseil constitutionnel decision n°2024-866 DC (partial conformity review) | Completed; partial validation |
| 21 May 2024 | Promulgation of Loi n°2024-449 | Completed; law promulgated |
| 22 May 2024 | Publication in Journal officiel (JORF) | Completed; JORF publication |
| 18 Apr 2025 | Government report on application transmitted to Parliament (Article 67 reporting) | Completed; report delivered |
| 28 Apr 2025 | Decree n°2025-387 (cooperation ARCEP/CNIL) published | Completed; implementing decree |
| 30 May 2025 | Decree n°2025-484 (cloud implementation) published | Completed; implementing decree |
Compliance Checklist
| Requirement | Description | Deadline |
|---|---|---|
| Age verification | Implement ARCOM referential for age verification on services giving access to pornographic content as required by the law. | As set by ARCOM after publication of the referential (referential publication required within 2 months of promulgation); see law and ARCOM obligations. |
| Cloud interoperability disclosure | Cloud providers must publish technical information and an "offer technique de référence" describing portability and interoperability features as required by Article 28-29. | Rules specified by Decree (see Decree n°2025-484 with deadlines referenced in the decree). |
| Regulator cooperation | Submit to joint procedures and information sharing between ARCEP, CNIL and other regulators pursuant to law and implementing decrees. | Immediate (procedures set by decree); see Decree n°2025-387. |
Sources and References
| Document | Type | Link |
|---|---|---|
| LOI n° 2024-449 du 21 mai 2024 visant à sécuriser et à réguler l'espace numérique | National law (consolidated text) | Consolidated law text (Légifrance) |
| Decision n° 2024-866 DC (Conseil constitutionnel) | Constitutional review | Conseil constitutionnel decision |
| Regulation (EU) 2024/1689 (Artificial Intelligence Act) | EU regulation | Regulation (EU) 2024/1689 (EU AI Act) - EUR-Lex |
| CNIL — Plan d'action sur l'IA (May 2023) and subsequent recommendations | Regulatory guidance | CNIL plan of action (CNIL) |
| Rapport d'information n°216 (Sénat) "L'intelligence artificielle générative et les métiers du droit" | Senate report | Senate report n°216 |
| Decree n°2025-387 (ARCEP/CNIL cooperation) | Implementing decree | Decree n°2025-387 |
| Decree n°2025-484 (cloud implementation) | Implementing decree | Decree n°2025-484 |
France's SREN law, enacted in May 2024, significantly tightens regulations for online services and the digital ecosystem, primarily impacting platforms, content providers, and cloud services operating in the country.
This legislation places new responsibilities on various online actors. Providers of pornographic content, for instance, must implement mandatory age verification systems, with specific technical standards to be set by the French audiovisual and digital regulator, ARCOM. Online platforms face stronger obligations and expedited procedures for removing illegal content, particularly child sexual abuse material. Cloud service providers are also in scope, now required to ensure market fairness through greater transparency, interoperability, and data portability for their offerings. The law also aligns French rules with broader European Union instruments like the Digital Services Act, Digital Markets Act, and the EU Artificial Intelligence Act, ensuring national regulators coordinate with EU-level enforcement.
The SREN law was promulgated on May 21, 2024, and published the following day. While the core law is in force, many specific implementation details, such as technical referentials for age verification and cloud interoperability rules, are being fleshed out through decrees and regulatory guidance published throughout 2025. Non-compliance can lead to substantial administrative sanctions imposed by regulators like ARCOM, the national data protection authority CNIL, and the electronic communications and postal regulator ARCEP. These penalties can include monetary fines reaching up to €250,000 or a percentage of a company's turnover for repeat offenses.
A key practical consideration for businesses is navigating the multi-agency governance model, where different regulators have specific powers and are mandated to cooperate. Companies must stay abreast of not only the law itself but also the numerous implementing decrees and technical standards issued by these authorities, as these will define the precise compliance requirements and timelines.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 8 marked completePlain-English obligations under France - Digital Space Regulation (2024-449). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ As set by ARCOM after referential publication.
Applies to: Providers of services giving access to pornographic content.
“protection of minors online through mandatory age‑verification systems for sites providing pornographic content and ARCOM referential standards”
- #2Critical
Applies to: Platforms hosting illegal content.
“stronger takedown powers and penalties for platforms hosting illegal content (including expedited procedures for child sexual abuse material)”
- #3Critical
Applies to: Entities subject to the EU Artificial Intelligence Act in France.
“alignment and operationalization of EU-level rules such as... the EU Artificial Intelligence Act.”
- #4Critical
Applies to: Entities subject to the Digital Services Act and Digital Markets Act in France.
“alignment and operationalization of EU-level rules such as the Digital Services Act, Digital Markets Act”
- #5Critical
Applies to: Digital platforms and entities processing personal data.
“extension of investigative powers of CNIL for compliance with data protection obligations when connected to digital platform regulation”
- #6Important⏰ As specified by Decree n°2025-484.
Applies to: Cloud service providers.
“regulation of cloud services (interoperability and market fairness obligations, transparency requirements for cloud offers)”
- #7Important⏰ As specified by Decree n°2025-484.
Applies to: Cloud service providers.
“transparency requirements for cloud offers”
- #8Important⏰ Immediate (procedures set by decree).
Applies to: Entities regulated by ARCOM, CNIL, or ARCEP.
“The law requires periodic reporting and gives regulators powers to audit and obtain documents.”
Related Regulations
France AI Regulation Overview
France88% similar
Law No. 2018-493 of 20 June 2018 - Law on the Protection of Personal Data (adaptation of the French Data Protection Act to the GDPR)
France87% similar
Digital X.0 Framework Law
Morocco86% similar
Proposition de loi relative à la reconnaissance biométrique dans l'espace public (Proposal / parliamentary bill on biometric recognition in public space) - report deposited 31 May 2023
France86% similar
Bill for the Establishment of the National Agency for AI Governance
Morocco85% similar
© Regulations.AI — created on 06-Jan-2026