CNIL inspections: how to prepare with confidence

An inspection cannot be improvised. The documents to keep up to date and the reflexes that make the difference on the day.
An inspection by the CNIL, the French data protection authority, may follow a complaint, a data breach or one of the authority’s annual priority themes. Preparing for it continuously turns an ordeal into a mere formality.
The key documents
An up-to-date record of processing activities, impact assessments, privacy notices, processor contracts and the security policy: these are the documents most frequently examined.
How an inspection comes about
Four main origins: the CNIL’s annual programme (priority themes are announced every year — healthcare features regularly), complaints from patients or employees, notified data breaches (a notification can trigger a verification), and reports — press, whistleblowers, other authorities. The inspection takes four forms: on site, on documents, online (remote verification of your website or application) or by hearing.
In the healthcare sector, precedents show that the risk is real: in 2022, a laboratory software vendor was fined 1.5 million euros following a massive leak of patient data — with security and contractual failings at the heart of the case.
On the day: how it unfolds and the right reflexes
During an on-site inspection, the officers may enter the premises, request any relevant document, interview staff and make copies. Everything is recorded in an official report, on which your observations can be entered — always do so. You may be assisted by counsel. Two mistakes never to make: improvisation (contradictory answers from different people weigh heavily) and obstruction — hindering the CNIL’s action is a criminal offence (Article 226-22-2 of the French Criminal Code), and the line between that and mere reluctance is quickly crossed.
Prepare an “inspection kit” in advance: who receives the officers, who answers on what, where the documents are, who alerts management and the DPO. When the day comes, that hour of preparation is worth a hundred.
What the CNIL scrutinizes in particular in healthcare
Access rights and the traceability of access to patient records (who can read what, and can you prove it?), the retention periods actually applied, patient information, the framework for processors — HDS hosting included —, security (passwords, encryption, backups) and the handling of past breaches. All points that are prepared continuously, not the day before.
And afterwards?
Three outcomes: simple closure, a formal notice (public or not) with a deadline to come into compliance, or the opening of sanction proceedings — fines of up to 20 million euros or 4% of worldwide turnover, injunctions with periodic penalty payments, publication of the decision. A simplified procedure exists for less complex cases. The most effective line of defence is the same in every case: up-to-date documentation that demonstrates living compliance, not a dusty binder.
The 12 documents you must be able to produce within 48 hours
1. The record of processing activities, dated and up to date. 2. The data breach register, even if empty. 3. The impact assessments (DPIAs) for high-risk processing — frequent in healthcare — or, failing that, the documented screening concluding that none is required. 4. The DPO’s designation and proof of notification to the CNIL. 5. The privacy notices and information provided to patients and employees. 6. The processor contracts (Article 28) of critical providers, software vendors and the HDS hosting provider first. 7. The hosting provider’s HDS certificate and its scope. 8. The security policy and the access management policy. 9. The procedures for exercising rights and evidence of their application. 10. The retention policy and evidence of deletion. 11. Training materials and attendance sheets. 12. The map of transfers outside the European Union, where applicable.
This is not a theoretical list: it is, give or take, the first document request of an inspection team. Every missing or outdated document steers the rest of the inspection deeper.
The five mistakes that make an inspection worse
Answering beside the point or too much: produce only what is requested, exactly what is requested. Letting everyone answer on their own: a single voice coordinates, the DPO. Improvising commitments (“we will encrypt everything within a month”) that the CNIL will record and verify. Backdating or doctoring a document: that is the fault that turns a shortcoming into a sanction case. Finally, neglecting the official report: reread it line by line and have your observations entered — it is your first piece of evidence for the defence.
In short: this quarter’s to-do list
Put together your inspection kit (documents + roles + decision chain), run a half-day dry run on the 12-document list, fix the gaps found, and schedule the review every six months. An organization that has done this exercise once faces a real inspection with 90% less stress — and with documents that plead its case.
