The legal framework for personal data protection is not limited to the text of the GDPR. The regulatory developments of 2025 and 2026 profoundly change the operational obligations of data controllers, particularly regarding the security of information systems and the control of data flows in mobile applications.
Control of SDKs in Mobile Applications: The New Frontier of the GDPR
The CNIL has opened a technical front that most articles on data protection ignore. Since spring 2025, a specific campaign targets SDKs integrated into mobile applications to verify whether these components actually stop transmitting data when the user declines tracking.
This approach is based on deliberation no. 2025-024 of March 27, 2025, published in the Official Journal on April 11, 2025. The recommendation requires application publishers to ensure that each third-party SDK respects the consent choice expressed by the data subject.
A refusal of cookies on a web banner remains visible and verifiable. An SDK buried in the code of a mobile application can continue to collect geolocation data or advertising identifiers without the user noticing.
It is precisely this gap between the consent interface and the actual behavior of processing that the CNIL is now tracking. To better understand the obligations surrounding these processes, we recommend consulting the legal page of BackUpYourBrain which details the applicable regulatory foundations.

CNIL Sanctions in 2026: Data Security at the Center of Enforcement Activity
The amount of fines imposed by the CNIL has been multiplied by nearly nine between 2024 and 2025. This acceleration is not merely a tightening of tone: it reflects a strategic refocusing of the regulatory authority.
The fine of 42 million euros imposed on Free and Free Mobile for data security failures illustrates the priority given to cybersecurity. The CNIL announced that about half of its inspections and enforcement actions in 2026 would be dedicated to data security and intrusions.
We observe that this direction changes the hierarchy of risks for data controllers. Until recently, sanctions mainly focused on failures related to consent or information provided to data subjects. Today, a lack of encryption, absence of network segmentation, or poor management of access rights exposes one to sanctions of a similar magnitude.
What This Means for Data Controllers
Documentary compliance (processing register, impact assessments, privacy policy) is no longer sufficient to demonstrate the good faith of an organization. The CNIL now verifies the technical reality of the declared security measures.
- Penetration tests and vulnerability audits must be conducted regularly, not just during the production deployment of a system
- Segmentation of personal data databases must prevent a single compromise from granting access to all information
- Notification procedures for breaches (Article 33 of the GDPR, 72-hour deadline) must be tested through simulation exercises, not just documented
- Logging of access to personal data must allow for traceability that can be utilized in case of inspection
ePrivacy Regulation and the Scheduled End of Cookie Banners
The draft ePrivacy regulation, long stalled at the European level, is experiencing significant revival. The European Union is exploring the possibility of removing cookie consent banners in favor of a centralized management mechanism at the browser or operating system level.
This paradigm shift would have direct consequences on the compliance architecture of websites. CMPs (Consent Management Platforms) that currently manage banners would become partly obsolete if consent were expressed only once at the terminal level.
We recommend not waiting for the final adoption of the text to anticipate this transition. Organizations that rely solely on a cookie banner to establish the legality of their marketing data processing expose themselves to a risk of sudden non-compliance on the day of enforcement.

Artificial Intelligence and the GDPR: Specific Obligations for Automated Systems
The interplay between the GDPR and the European regulation on artificial intelligence (AI Act) creates a dual compliance framework for automated processing of personal data. AI systems that process personal data remain subject to the principles of minimization, purpose limitation, and transparency of the GDPR.
The right to object to a fully automated decision (Article 22 of the GDPR) takes on a new dimension with the proliferation of scoring, profiling, and recommendation models. The data subject retains the right to obtain human intervention, express their point of view, and contest the decision.
Training Models and Legal Basis for Processing
The use of personal data to train an AI model raises the question of the applicable legal basis. Consent, legitimate interest of the data controller, or performance of a contract: each basis imposes different obligations regarding information and the right to withdraw.
- Consent must be obtained before integrating the data into the training set, not retroactively
- Legitimate interest requires a documented balancing act between the needs of the data controller and the rights of the data subject
- The right to erasure also applies to data already incorporated into a model, which raises major technical difficulties
The legal framework for personal data protection is becoming denser each year. The CNIL’s inspections now focus on the technical reality of security measures, not just on documentation. Anticipating regulatory developments rather than suffering them remains the best lever for compliance for any data controller.



