
Since the summer of 2026, several legal decisions and cybersecurity flaws have reshaped the landscape of digital freedoms in France and Europe. Between the constitutional censorship of a law on social networks, delays in the transposition of European directives, and repeated cyberattacks against public services, the topic far exceeds the circle of specialists.
Age Verification on Social Networks: Censorship by the Constitutional Council
The law that was supposed to ban social networks for those under 15 in France has generated a lot of ink. Its principle was based on a system of age verification imposed on each user, directly managed by the platforms.
On August 14, 2026, the Constitutional Council censored the central article of the text (decision n° 2026-911 DC). The identified problem: disproportionate infringement on freedom of expression and privacy. The guarantees surrounding the age verification system were deemed insufficient by the judges.
Why this severity? To ensure that a teenager is indeed 15 years old, it is actually necessary to collect personal data on all users, including adults. It is this massive collection that the Council considered too intrusive.
The Electronic Frontier Foundation has pointed out that protecting minors does not justify widespread surveillance of all internet users. Those who wish to follow these developments can access the Rockette Libre site for regular analyses on these topics.
The consequences extend beyond French borders. Australia has already banned those under 16 from social networks, but the European legal framework, which is more protective of fundamental rights, significantly complicates the implementation of similar measures on the continent.

NIS 2 Directive and Cybersecurity of Public Services in France
The European NIS 2 directive strengthens cybersecurity obligations for administrations and companies. It should have been transposed into French law several months ago. France is significantly behind this schedule.
This delay has very concrete effects. Cyberattacks against French public services are multiplying, and Franceinfo identifies France as the main European target for data theft. Without the transposition of NIS 2, the rules for incident reporting, continuity planning, and infrastructure protection remain vague for many public actors.
What NIS 2 Would Change in Practice
- Administrations would be required to report any intrusion within a short and documented timeframe, instead of handling leaks internally for weeks without informing anyone
- IT subcontractors of local authorities would be subject to the same security requirements as the public bodies they support
- A mechanism for financial sanctions would push organizations to invest in data protection rather than indefinitely postponing updates
As a result: attacks are increasing, the restrictive framework is delayed, and users suffer the consequences without clear recourse.
Personal Data Leaks: Unequal Risks Depending on the Public
When a data leak occurs, the response almost always follows the same pattern. The affected organization publishes a statement urging vigilance: change passwords, monitor accounts, be wary of unusual messages.
Have you noticed that this advice assumes knowledge of phishing, mastery of online navigation, and the ability to spot a fake banking SMS? Understanding the risk and asserting one’s rights requires resources that are unevenly distributed. An elderly person targeted by a fraudulent message does not have the same reference points as a thirty-something accustomed to these attempts.
Thus, the protection of personal data functions as a marker of social inequality. The least connected individuals are also the least equipped to protect themselves after an incident.
Three Reflexes After a Data Leak
- Check if your email address appears in a compromised database using free services like Have I Been Pwned, without waiting for an official notification that may arrive weeks later
- Enable two-factor authentication on the most sensitive accounts (email, banking, administration), which blocks the vast majority of fraudulent access attempts
- File a complaint with the CNIL when the affected data is sensitive (health, family situation, income), because collective reporting accelerates control procedures

European Digital Regulation: the DSA Faces Its First Limits
The Digital Services Act (DSA), now in effect for very large platforms, imposes obligations for moderation, algorithmic transparency, and combating illegal content. In France, Arcom is one of the national regulators responsible for ensuring compliance.
Concrete effects are already visible. Platforms are publishing transparency reports on content moderation. Users have a right to appeal when one of their posts is removed.
The fight against online hate speech remains the main point of friction. Automated moderation, if not precisely regulated, risks removing legitimate content alongside illegal content. The balance between protection and freedom of expression is constantly shifting, and each national decision, such as the French constitutional censorship, redistributes the balances.
The European Union’s “Chat Control” project illustrates this tension well. Designed to combat child exploitation, it proposed the automatic analysis of private messages. Several digital rights advocacy organizations have denounced it as a direct threat to end-to-end encryption and the privacy of all European citizens.
The transposition of NIS 2, the first sanctions imposed under the DSA, and the aftermath of the French Constitutional Council’s decision will set the framework for digital freedoms in Europe for several years to come.