Loading…
Loading…
SREN is structurally a sectoral omnibus rather than a single-purpose statute. The instruments most relevant to the IPTM register are:
1. SecNumCloud-anchored public-sector data-localisation. Article 31 amends the code des relations entre le public et l'administration to require that "données d'une sensibilité particulière" generated or held by the State, its public establishments, and other delegated public-service bodies must be hosted on cloud services that meet a qualification level set by reference to the ANSSI SecNumCloud cybersecurity-certification scheme — which is, by design, accessible only to providers immune from extraterritorial third-country law (notably the US CLOUD Act). This is the first French statute to bind public-sector cloud sourcing to a sovereign- cloud certification scheme at primary-legislation level (previously it was a circulaire-level cloud-au-centre policy).
2. ARCOM age-verification regime for adult-content sites. Articles 1–3 give ARCOM (the audiovisual + digital regulator) the authority to issue an obligatory technical reference frame ("référentiel") for age-verification of pornographic websites, to formally notify non-compliant publishers (whether established in France, in the EU, or outside), and to seek site-blocking, delisting, and account closure orders. The maximum fine is €250,000 per natural person or 2% of worldwide consolidated turnover for a legal person (4% in case of repeat offence).
3. Anti-scam cybersecurity filter (filtre anti-arnaque). Articles 6–8 create a statutory mandate for browsers and DNS resolvers operating in France to block, on user-facing endpoints, fraudulent websites and domains designated by ANSSI under a defined notification procedure. This is one of the first EU-Member-State statutory mandates imposing a content-blocking obligation directly on browser vendors at the application layer.
4. JONUM regime for digital-asset / Web3 gaming. Articles 15–18 create an experimental authorisation regime under ANJ (Autorité nationale des jeux) for "jeux à objets numériques monétisables" — i.e., games combining a chance-of-gain mechanic with rewards in the form of digital assets (NFTs / fungible tokens). It is the first national authorisation scheme in the EU specifically targeted at on-chain gaming.
5. DSA / DMA / DGA national-level enforcement plumbing. SREN designates ARCOM as the French Digital Services Coordinator under the EU DSA, allocates DMA enforcement to the Autorité de la concurrence, and makes the CNIL the competent authority for the Data Governance Act's data-intermediation-service notification regime. Articles 24–28 create cooperation channels between CSA, CNIL, ARCOM, and the Autorité de la concurrence.
6. Online-publication portability and the "Pôle d'expertise du numérique de l'État" (DPNA). Article 33 establishes a State digital-expertise hub for advising public administrations on digital and AI procurement.
sensitive-data hosting to SecNumCloud, SREN materially advantages qualified providers (OVHcloud, Outscale/Dassault, Bleu/Orange- Capgemini-Microsoft, S3NS/Thales-Google) over non-qualified hyperscaler offerings for State workloads. The Bleu and S3NS joint-ventures — both architected explicitly to obtain SecNumCloud — derive their commercial logic from this article.
SREN is the most far-reaching national instrument anchoring public- data-hosting rules to a sovereign-cloud certification scheme; it precedes equivalent steps under consideration in Germany (BSI C5+ evolution), Italy (ACN qualifica), and Spain (ENS High evolution).
to formally notify several non-French / non-EU publishers since Q3 2024; legal challenges before the Conseil d'État on extra- territorial reach are still pending.
obligation on browsers raises a Single-Market-rules question (country-of-origin principle under the e-Commerce Directive vs. national imperative-reasons-of-public-interest carve-outs) that will likely be tested by Mozilla / Google / Microsoft.
(cloud-switching, Article 32 international-access safeguards), the AI Act (audit/transparency obligations), and DORA (financial-sector ICT third-party regime). The French national overlay creates additional obligations on top of EU-baseline regimes.
"données d'une sensibilité particulière" qualifier — implementing decree(s) under Article 31 are still being staged.
verification orders against non-EU publishers.
filtering obligation, especially as it interacts with the EU CRA (Regulation 2024/2847) and the EU Cybersecurity Act qualification regime.
binding tie-in for sovereign data hosting, which would accelerate the EU cloud-market fragmentation already in progress.