The consent rule, and where it comes from
In France, sending commercial email to a private individual requires their prior consent — free, specific and informed. The rule is set by Article L34-5 of the Code des postes et des communications électroniques, introduced by the LCEN of 2004 to transpose the European ePrivacy Directive. Pre-ticked boxes do not produce valid consent.
Note the wording carefully: L34-5 protects a natural person. That single word is what makes the French regime different from most of its neighbours, and it is the basis of everything in the next section.
B2B prospecting is not opt-in
This is the point most guides miss, and it is the one that matters most to business senders. The CNIL accepts that prospecting a professional can rest on the sender's legitimate interest rather than on prior consent, provided the subject of the message relates to the profession of the person contacted — a software pitch to an IT director being the standard illustration.
Three conditions come with it. The message must relate to the recipient's professional activity. The person must be informed of where their data came from and what it will be used for. And they must be able to object simply, at any time.
Two cautions. First, generic company addresses such as info@ or contact@ concern the company rather than an individual and fall outside these rules altogether — that is a separate case, not a B2B sub-case. Second, this professional carve-out is the CNIL's stated position rather than an exemption written into the statute, since a named work address is still the contact detail of a natural person. Treat it as regulator doctrine and document your reasoning.
The existing-customer exception
You may email an existing customer without fresh consent where you collected the address directly from them, on the occasion of a sale or the provision of a service, the message concerns similar products or services supplied by you, and you offered a free and simple way to object both when the address was collected and in every message since.
The limits are real. Creating an account is not, on its own, a purchase. And partner offers are not "similar products or services from the same company" — passing prospect data to partners has drawn substantial CNIL sanctions.
What every message must carry
Every commercial message must give valid contact details through which the recipient can ask to stop receiving them, at no cost beyond transmission. It must not conceal the identity of the person on whose behalf it is sent, and it must not carry a subject line unrelated to what is being offered. Alongside this, the GDPR gives every recipient an absolute right to object to direct marketing — there is no balancing test, and once they object you must stop.
Two myths worth retiring. French law does not require double opt-in, though it remains the cleanest way to prove consent. And it does not require a postal address in the message — that is a US requirement, not a French one.
Keeping data no longer than you need
The CNIL's reference framework recommends keeping prospect data for up to three years from the last contact coming from the prospect — a click or an enquiry restarts the clock, simply opening an email does not. That is a recommendation carrying a presumption of compliance rather than a hard statutory maximum; you may depart from it if you can justify and document the choice. Records kept to honour someone's objection are the opposite case: keep those long enough to keep honouring the opt-out, minimised to what that purpose requires.
Sanctions in this area are being restructured following a 2026 constitutional ruling on overlapping enforcement powers, so any figure you read should be checked against its date. What has not changed is the CNIL's appetite: recent penalties for prospecting without valid consent have run well into six and even eight figures.
See also: emailing monitored by the CNIL, and our guide to emailing law by country.