France - Digital Space Regulation (2024-449)

Law No. 2024-449 of May 21, 2024, Aiming to Secure and Regulate the Digital Space ("SREN")

Loi n° 2024-449 du 21 mai 2024 visant à sécuriser et à réguler l'espace numérique ("SREN")

France

RAI-FR-NA-LN2D2XX-2024
In Force(In Force)
ActGovernance and OversightEnforcement and Penalties
Export PDF

The SREN law (Loi n°2024-449, 21 May 2024) strengthens regulation of online services and the digital ecosystem in France, including protections for minors, platform obligations (age verification, content takedown), measures on cloud market fairness and expanded powers for regulators such as ARCOM and CNIL. It interacts with EU instruments including the EU AI Act.

Overview

The law entitled "visant à sécuriser et à réguler l'espace numérique" (SREN) was adopted by Parliament in spring 2024 and promulgated in May 2024 to strengthen protections in the French digital ecosystem. The text brings together measures across protection of minors, platform responsibility for illegal content, market fairness in cloud services, new powers and cooperation rules for regulators and procedural tools for faster takedown and sanctions for online harms. The law is available in consolidated and JORF versions on Légifrance and its legislative dossier is hosted by the Assemblée nationale. Consolidated text.

Definitions

The SREN law uses defined terms for categories of online actors (e.g. "services permettant l'accès à des contenus pornographiques", "fournisseurs de services d'informatique en nuage", "services de très grandes plateformes en ligne" by reference to the DSA/DMA) and refers to regulatory definitions in EU instruments where relevant. Legislative definitions and cross-references are provided in the text of the law; readers should consult the text for the statutory wording and precise article cross‑references. See law text (articles and definitions).

Governance and Institutional Framework

SREN strengthens a multi‑agency governance model: it allocates specific powers to ARCOM (Autorité de régulation de la communication audiovisuelle et numérique) for age verification and audiovisual compliance, to CNIL for data protection and new investigative competences, to ARCEP for cloud‑market related oversight and to other sectoral regulators where indicated. The law prescribes cooperation mechanisms between these authorities and provides for delegated powers to adopt implementation decrees. The law and subsequent implementing decrees set out the respective remits. Law (governance provisions) and Decree n°2025-387 (cooperation ARCEP/CNIL).

Key Focus Areas

Principal focus areas include: (1) protection of minors online through mandatory age‑verification systems for sites providing pornographic content and ARCOM referential standards; (2) stronger takedown powers and penalties for platforms hosting illegal content (including expedited procedures for child sexual abuse material); (3) regulation of cloud services (interoperability and market fairness obligations, transparency requirements for cloud offers); (4) extension of investigative powers of CNIL for compliance with data protection obligations when connected to digital platform regulation; and (5) alignment and operationalization of EU-level rules such as the Digital Services Act, Digital Markets Act and the EU Artificial Intelligence Act. Each focus area includes statutory obligations and delegated rule‑making powers for ministers and authorities to adopt technical referentials. See core provisions.

Implementation Framework

The law sets deadlines and mandates for issuance of implementing decrees and regulator referentials. For cloud‑market interoperability rules, implementing measures and technical reference offers were to be specified by decree (see article 29 and implementing decrees of 2025). For ARCOM's age‑verification referential the Authority must publish the technical referential within two months of promulgation of the law and platforms were given transitional windows to comply; exact timelines and technical modalities are defined in the law and associated ARCOM referentials. Law text (article references) and Decree n°2025-484 (cloud implementing rules).

Monitoring and Evaluation

The law requires periodic reporting and gives regulators powers to audit and obtain documents. The Government transmitted a report on application to Parliament on 18 April 2025 in accordance with the statutory reporting duties. Authorities are required to publish activity reports and assessment material; cross‑authority cooperation provisions (e.g. ARCEP/CNIL cooperation) are regulated by decree to enable joint procedures. Legislative dossier and government report.

Penalties, Liability, and Appeals

SREN provides for administrative sanctions by designated regulators. Monetary sanctions for certain platform failures are calibrated in the statute (for example ARCOM sanctions linked to age‑verification non‑compliance and other infractions reference caps such as up to €250,000 or percentages of turnover for recidivism in specified cases; other sanction maxima are set in the statutory text). Detailed sanctioning regimes and appeal procedures are specified in the law and national administrative procedure codes, with rights to contest before administrative courts. See sanction provisions in the law.

Relationship to Other Instruments

SREN was designed to operate alongside and implement obligations under EU instruments (DSA/DMA) and to dovetail with the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). The EU AI Regulation is directly applicable in Member States and SREN focuses on sectoral national powers (e.g., cloud market fairness and platform rules) that intersect with EU AI requirements; national regulators will therefore coordinate enforcement with the EU AI Office and use the law's powers where sectoral national measures are required. EU AI Act (Regulation (EU) 2024/1689) and SREN.

International Alignment

By design SREN references and implements obligations aligned with EU-level law and seeks compatibility with internal market rules; where the law delegates technical standards, those standards must respect EU obligations and international commitments. The law's cloud fairness measures also reference EU data and cloud governance regulations to avoid fragmentation. EU AI Act and implementing opinions issued by regulators.

Implementation Timeline

Date/PeriodMilestoneStatus
10 Apr 2024Assembly adoption of CMP text; final adoption by Assemblée nationaleCompleted; parliamentary adoption
17 May 2024Conseil constitutionnel decision n°2024-866 DC (partial conformity review)Completed; partial validation
21 May 2024Promulgation of Loi n°2024-449Completed; law promulgated
22 May 2024Publication in Journal officiel (JORF)Completed; JORF publication
18 Apr 2025Government report on application transmitted to Parliament (Article 67 reporting)Completed; report delivered
28 Apr 2025Decree n°2025-387 (cooperation ARCEP/CNIL) publishedCompleted; implementing decree
30 May 2025Decree n°2025-484 (cloud implementation) publishedCompleted; implementing decree

Compliance Checklist

RequirementDescriptionDeadline
Age verificationImplement ARCOM referential for age verification on services giving access to pornographic content as required by the law.As set by ARCOM after publication of the referential (referential publication required within 2 months of promulgation); see law and ARCOM obligations.
Cloud interoperability disclosureCloud providers must publish technical information and an "offer technique de référence" describing portability and interoperability features as required by Article 28-29.Rules specified by Decree (see Decree n°2025-484 with deadlines referenced in the decree).
Regulator cooperationSubmit to joint procedures and information sharing between ARCEP, CNIL and other regulators pursuant to law and implementing decrees.Immediate (procedures set by decree); see Decree n°2025-387.

Sources and References

DocumentTypeLink
LOI n° 2024-449 du 21 mai 2024 visant à sécuriser et à réguler l'espace numériqueNational law (consolidated text)Consolidated law text (Légifrance)
Decision n° 2024-866 DC (Conseil constitutionnel)Constitutional reviewConseil constitutionnel decision
Regulation (EU) 2024/1689 (Artificial Intelligence Act)EU regulationRegulation (EU) 2024/1689 (EU AI Act) - EUR-Lex
CNIL — Plan d'action sur l'IA (May 2023) and subsequent recommendationsRegulatory guidanceCNIL plan of action (CNIL)
Rapport d'information n°216 (Sénat) "L'intelligence artificielle générative et les métiers du droit"Senate reportSenate report n°216
Decree n°2025-387 (ARCEP/CNIL cooperation)Implementing decreeDecree n°2025-387
Decree n°2025-484 (cloud implementation)Implementing decreeDecree n°2025-484
Plain English

France's SREN law, enacted in May 2024, significantly tightens regulations for online services and the digital ecosystem, primarily impacting platforms, content providers, and cloud services operating in the country.

This legislation places new responsibilities on various online actors. Providers of pornographic content, for instance, must implement mandatory age verification systems, with specific technical standards to be set by the French audiovisual and digital regulator, ARCOM. Online platforms face stronger obligations and expedited procedures for removing illegal content, particularly child sexual abuse material. Cloud service providers are also in scope, now required to ensure market fairness through greater transparency, interoperability, and data portability for their offerings. The law also aligns French rules with broader European Union instruments like the Digital Services Act, Digital Markets Act, and the EU Artificial Intelligence Act, ensuring national regulators coordinate with EU-level enforcement.

The SREN law was promulgated on May 21, 2024, and published the following day. While the core law is in force, many specific implementation details, such as technical referentials for age verification and cloud interoperability rules, are being fleshed out through decrees and regulatory guidance published throughout 2025. Non-compliance can lead to substantial administrative sanctions imposed by regulators like ARCOM, the national data protection authority CNIL, and the electronic communications and postal regulator ARCEP. These penalties can include monetary fines reaching up to €250,000 or a percentage of a company's turnover for repeat offenses.

A key practical consideration for businesses is navigating the multi-agency governance model, where different regulators have specific powers and are mandated to cooperate. Companies must stay abreast of not only the law itself but also the numerous implementing decrees and technical standards issued by these authorities, as these will define the precise compliance requirements and timelines.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 8 marked complete

Plain-English obligations under France - Digital Space Regulation (2024-449). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalAs set by ARCOM after referential publication.

    Applies to: Providers of services giving access to pornographic content.

    protection of minors online through mandatory age‑verification systems for sites providing pornographic content and ARCOM referential standards
  2. #2Critical

    Applies to: Platforms hosting illegal content.

    stronger takedown powers and penalties for platforms hosting illegal content (including expedited procedures for child sexual abuse material)
  3. #3Critical

    Applies to: Entities subject to the EU Artificial Intelligence Act in France.

    alignment and operationalization of EU-level rules such as... the EU Artificial Intelligence Act.
  4. #4Critical

    Applies to: Entities subject to the Digital Services Act and Digital Markets Act in France.

    alignment and operationalization of EU-level rules such as the Digital Services Act, Digital Markets Act
  5. #5Critical

    Applies to: Digital platforms and entities processing personal data.

    extension of investigative powers of CNIL for compliance with data protection obligations when connected to digital platform regulation
  6. #6ImportantAs specified by Decree n°2025-484.

    Applies to: Cloud service providers.

    regulation of cloud services (interoperability and market fairness obligations, transparency requirements for cloud offers)
  7. #7ImportantAs specified by Decree n°2025-484.

    Applies to: Cloud service providers.

    transparency requirements for cloud offers
  8. #8ImportantImmediate (procedures set by decree).

    Applies to: Entities regulated by ARCOM, CNIL, or ARCEP.

    The law requires periodic reporting and gives regulators powers to audit and obtain documents.

© Regulations.AI — created on 06-Jan-2026