PoliticalRepoPoliticalRepo

France · Question · Question écrite

12977

Question 12977 — digital

openFrance· National Assembly· FR

Introduced

17 February 2026

Last action

Status

posée

Sponsors

Subjects

Discovery layer

Source updated

17 February 2026

Summary

Mr. Marc Chavent questions the Prime Minister on France's exposure to massive civilian data and the protection measures envisaged. Contemporary conflicts show that the initial phase of an armed confrontation is now largely informational and statistical, based on the collection, correlation and exploitation of data from civilian systems, well beyond just infrastructure classified as vitally important. There France produces daily, via its digital economy and its general public uses, considerable volumes of civil data used or exploited by private and public actors, French or foreign. Mobile sports, navigation or delivery applications make it possible to deduce recurring journeys, schedules, areas of residence and work, as well as the attendance of sensitive infrastructures, including when these journeys concern public officials or personnel of the armed and security forces, in a context where the CNIL recalls that connection and location data make it possible to reconstruct lifestyle habits, daily movements and social environments frequented. Connected health objects and e-health platforms manipulate data whose sensitivity and volume have already led to cyberattacks massive and sanctions, as illustrated by the leak of data of hundreds of thousands of patients or the sanction of 380,000 euros pronounced against a large online health site for breaches of its obligations, which confirms the strategic value of this information for attackers likely to infer state of fatigue, stress or operational availability of individuals and entire professional categories. Networks Civil IoT, whether urban sensors, smart meters or connected devices in transport, contribute to real-time mapping of population and logistics flows; various works on IoT networks show that these infrastructures make it possible to analyze video, audio or environmental data streams in real time in order to deduce collective behaviors and vulnerabilities, which, correlated with other metadata, can make it possible to indirectly identify the location and operation of critical infrastructures. Furthermore, the French legal framework has already recognized the strategic power of metadata: the law relating to intelligence and the provisions of the internal security code organize the collection of connection data, including the location of terminal equipment, lists of numbers called and appellants, the duration and date of the communications, precisely because these elements make it possible to reconstruct relational networks, chains of command and activity patterns without accessing the content of the communications. The cyber threat itself is the subject of a consolidated assessment by the competent authorities: ANSSI describes a continuous increase in incidents and reports, particularly in the context of major events such as the Olympic Games and underlines that the threat affects all territories, with particular attention to information systems of vital importance and information systems of vital importance (SIIV) operated by operators of vital importance within the framework of the SAIV system. This approach nevertheless remains mainly focused on the identified critical infrastructures, while the massive flows of Civilian data, not classified as such, can produce military intelligence by simple correlation. In this context, if France has adopted advanced cybersecurity systems, sectoral digital sovereignty (notably in terms of health data and sovereign cloud) and institutional cooperation between CNIL and ANSSI, these frameworks still favor an approach by categories of data (personal data). personnel, health data, data of vital importance) rather than an approach based on correlation and use effects in conflict or hybrid crisis situations. The MP therefore wishes to know, first of all, what is the current assessment of the French authorities on the strategic role of this massive civilian data (mobile applications, connected objects, IoT networks, metadata) when they are exploited by powers foreign or non-state actors and which operational scenarios (mapping of territorial weak points, anticipation of population movements, targeting of influence campaigns, preparation of sabotage or cyberattacks) are retained in the government analysis. He also wishes to know whether the intelligence services have a formalized and identified capacity to analyze and integrate these risks into the defense planning, beyond the connection data collection devices already regulated by the law relating to intelligence and how this capacity fits with the work of the ANSSI on SIIV, the 2026-2030 national cybersecurity strategy announced by the Government and the missions of the CNCTR in terms of control of intelligence techniques. He also questions him about the way in which the State distinguishes legally "civilian" data from "strategic" data as long as their correlation, sometimes simple and carried out from public or commercial sources, produces information of military interest or national security and if a development of the law (for example by the creation of a category of "data of strategic interest" or by the extension of the perimeter of information systems of vital importance) is envisaged to better take into account these correlation effects. Finally, he would like to know if there is an explicit national doctrine aimed at reducing the exposure of critical flows, including for the mobility and digital habits of decision-makers and exposed personnel, in terms of choice of applications, configuration of terminals, use of services based on extra-European infrastructures or clouds and if the Government intends to strengthen, through regulatory, technical or awareness-raising measures, the security obligations applicable to economic operators who collect and process this massive civilian data likely to be misused for intelligence or destabilization purposes. In this context, he would like to know what actions the Government intends to put in place to recognize, regulate and reduce France's exposure to the strategic risks generated by the exploitation of this massive civilian data, both for national defense planning and for the protection of decision-makers, forces and essential infrastructure.

Machine translation from French. The official text remains authoritative.

Timeline

No timeline events have been ingested for this record yet.

Votes

No vote records are attached yet.

Versions

No version snapshots stored. Document URLs remain at the source.

Documents

No documents linked.

Sponsors

No sponsors or actors listed by the source.

Related records

No cross-record relationships stored yet.

Sources

PoliticalRepo is an index and interpretation layer, not the authoritative legal source.