YOUR
Search

    01.06.2026

    France - Management of Information Reported During an Internal Investigation – Legal Privilege, Collection, and Circulation


    Information collected during an internal investigation is inherently sensitive. Its collection must comply not only with the European General Data Protection Regulation (GDPR), but the information obtained must be circulated with caution.

    One principle must guide the entire process: the strict confidentiality of the internal investigation, including the investigation report itself.

    Circulation of information collected during an internal investigation within the company

    The internal investigation report should be circulated only to a limited number of individuals within the company. Restricting distribution indeed minimizes the risk of rumors spreading within the company and, more importantly, prevents the potential external dissemination of sensitive information that could damage the company’s reputation. 

    As a matter of principle, an internal investigation report should not be disclosed to authorities nor to the external auditors without prior authorization from the relevant internal decision-making body.

    That said, a company may decide to disclose the report to judicial authorities in the context of judicial cooperation, especially with a view to negotiating a Convention Judiciaire d’Intérêt Public – a kind of French DPA - if applicable. 

    Legal uncertainty surrounding French legal privilege in internal investigation

    In the absence of a clear statutory framework, the applicability of French legal professional privilege to internal investigations remains a matter of debate.

    Under French law, communications and documents exchanged between a lawyer and a client involved in criminal proceedings are, in principle, protected by legal privilege. Accordingly, an internal investigation launched after a company has been formally implicated in criminal proceedings would normally fall within the scope of that protection.

    However, significant uncertainty remains when the company is not yet under investigation. Although the preliminary article of the French Code of Criminal Procedure extended legal professional privilege to legal advice provided by lawyers, the French supreme court (in French, “Cour de cassation”) has adopted a restrictive approach. The court has issued decisions that appear inconsistent, creating uncertainty as to the exact scope of privilege.

    Soft law instruments further reflect this divergence. Guidelines issued by the Financial Public Prosecutor’s Office and the French Anticorruption Agency denies the application of legal professional privilege to internal investigations. By contrast, guidance from lawyers’ representative bodies, including the Conseil national des barreaux, supports the application of privilege to such investigations conducted by lawyers.

    For this reason, Bill. No. 2208 submitted to the French National Assembly on 9 December 2025 but not enacted yet seeks to clarify the issue. The reform intends to extend legal professional privilege to internal investigations conducted by lawyers, characterizing them as legal advice relating to the rights of the defense.

    Pending legislative clarification, we regularly accompany our clients on how to navigate the evolving and sometimes contradictory contours of French legal professional privilege in the context of internal investigations.

    Legaltech momentum in Italy
    Lukas Plattner reflects on LEGALTECH IN SCENA: Bringing the legaltech community…
    Read more
    Best Lawyers Germany 2027: 70 Anwältinnen und Anwälte von ADVANT Beiten ausgezeichnet
    ADVANT Beiten ist in den aktuellen Best Lawyers Germany-Rankings erneut…
    Read more
    Space Economy e Data Economy: il Documento Strategico di Politica Spaziale Nazionale (DSPSN)
    Il contesto e la funzione del Documento Strategico di Politica Nazionale…
    Read more
    Governance dei dati personali nei club calcistici: l’uso dei dati come leva strategica tra GDPR, sicurezza e valore generato
    Il club calcistico come ecosistema di dati (e come media company) Dal punto di…
    Read more
    Tracking pixel nelle e-mail: le nuove regole del Garante
    1. Introduzione Con il Provvedimento n. 284 del 17 aprile 2026, pubblicato in…
    Read more
    Le nuove Linee Guida della Commissione sulla classificazione dei sistemi di IA ad alto rischio
    Il contesto e la struttura delle Linee Guida Il Regolamento (UE) 2024/1689 (“AI…
    Read more
    Perché il Tribunale di Roma ha annullato il provvedimento del Garante su OpenAI?
    La sentenza in sintesi Il 18 marzo 2026, il Tribunale di Roma ha annullato…
    Read more
    Cyber Resilience Act: il conto alla rovescia è iniziato
    Con il Regolamento (UE) 2024/2847 (“Cyber Resilience Act” o “CRA”), l’Unione…
    Read more
    AI: il CdM approva in via preliminare i decreti attuativi della Legge n. 132/2025
    Il quadro Il 10 giugno 2026, in attuazione della delega contenuta nella Legge…
    Read more