France's data protection regulator, and what it expects
The Commission nationale de l'informatique et des libertés — the CNIL — is the authority that supervises how personal data is collected and used in France, email prospecting very much included. It publishes detailed practical guidance on commercial prospecting by electronic means, and it enforces it.
One thing has changed fundamentally since the GDPR took effect in 2018, and older articles still get it wrong: there is no longer any obligation to declare your contact database to the CNIL. The old declaration regime was abolished. What replaced it is accountability — you must be able to demonstrate compliance, which in practice means keeping a record of your processing activities and being able to produce evidence of consent.
Collecting addresses: what is and is not allowed
Addresses harvested from websites, forums and directories cannot be used for prospecting. Where someone gives you their address themselves — through a form, a newsletter signup, a survey — they must be told at that moment that it may be used to send them commercial messages, and by whom.
Consent does not travel down a chain. If addresses are collected so they can be passed to partners, the person has to be told who those partners are when they give consent; a generic reference to "our partners" does not work. The CNIL has fined data brokers substantially on exactly this point.
The two levels of prospecting
The CNIL distinguishes between prospecting a consumer and prospecting a professional.
For consumers, prior consent is required, with the narrow exception of writing to an existing customer about products or services similar to what they already bought from you.
For professionals, the rules are lighter. A message may be sent without prior consent where its subject relates to the profession of the person contacted, provided they are informed and can object simply at any time. The sender must still identify themselves clearly. This is the CNIL's stated position rather than a statutory exemption, so document why you consider a given campaign to fall within it.
How long you may keep prospect data
The CNIL's reference framework recommends keeping data about a prospect who has not become a customer for up to three years from the last contact coming from that person. A click on a link or a request for documentation counts as contact; merely opening an email does not. For customers, the equivalent period runs from the end of the commercial relationship.
These are recommendations that create a presumption of compliance rather than fixed legal deadlines — you may keep data longer if you can justify and document why. The binding obligation is the GDPR's storage limitation principle: do not keep personal data longer than the purpose requires.
Enforcement is real
Prospecting is a standing CNIL priority and produces sanctions every year. Recent decisions have penalised sending without valid consent, forms designed so that consent was neither free nor unambiguous, unsubscribe mechanisms that required emailing a data protection officer rather than one click, and passing prospect data to third parties without a proper basis. Penalties have ranged from tens of thousands of euros to eight figures for the largest cases.
The practical lesson is consistent across all of them: collect consent cleanly, keep the evidence, make leaving easy, and do not treat a prospect file as an asset you can pass around.
See also: law and emailing in France.