The CNIL explains the challenges of electronic invoicing for the protection of personal data
The National Commission on Informatics and Liberty (CNIL) has published guidelines on the challenges of the electronic invoicing reform for the protection of personal data, which came into effect on September 1, 2026.
This reform requires all companies to be able to receive electronic invoices from September 1, 2026, with a universal issuance obligation starting September 1, 2027. The GDPR applies when invoices contain data of natural persons, such as sole proprietors or named contacts, but not to invoices mentioning only information about legal entities. The authority emphasizes the principle of minimization, recommending avoiding the inclusion of unnecessary personal information, especially sensitive data targeted by Article 9 of the GDPR. The issuing or receiving company is generally considered the controller, while the state-approved platform acts as a processor, unless it reuses the data for its own purposes. The retention period for invoices is set at ten years, in accordance with the commercial code.
Approved platforms are subject to high security requirements, including ISO 27001 certification and, where applicable, SecNumCloud qualification. The CNIL specifies that these certifications do not exempt controllers from conducting their own risk assessment to comply with Article 32 of the GDPR. Regarding user authentication, platforms must implement robust mechanisms, ultimately aiming for a substantial level of assurance under the eIDAS regulation. During the transitional period, two-factor authentication is required. The authority recommends that companies adopt best practices such as using individual accounts and being vigilant against phishing.
This reform requires all companies to be able to receive electronic invoices from September 1, 2026, with a universal issuance obligation starting September 1, 2027. The GDPR applies when invoices contain data of natural persons, such as sole proprietors or named contacts, but not to invoices mentioning only information about legal entities. The authority emphasizes the principle of minimization, recommending avoiding the inclusion of unnecessary personal information, especially sensitive data targeted by Article 9 of the GDPR. The issuing or receiving company is generally considered the controller, while the state-approved platform acts as a processor, unless it reuses the data for its own purposes. The retention period for invoices is set at ten years, in accordance with the commercial code.
Approved platforms are subject to high security requirements, including ISO 27001 certification and, where applicable, SecNumCloud qualification. The CNIL specifies that these certifications do not exempt controllers from conducting their own risk assessment to comply with Article 32 of the GDPR. Regarding user authentication, platforms must implement robust mechanisms, ultimately aiming for a substantial level of assurance under the eIDAS regulation. During the transitional period, two-factor authentication is required. The authority recommends that companies adopt best practices such as using individual accounts and being vigilant against phishing.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire