People counting in France: measuring within the CNIL framework
France is the rare market where the regulator has written the playbook: CNIL publishes explicit rules for footfall measurement in publicly accessible spaces. That is good news for buyers, because it turns a vague compliance worry into a concrete checklist. Orientation, not legal advice.
Most European markets leave footfall measurement to be reasoned out from GDPR’s general principles. France does not. CNIL, the French data protection authority, publishes explicit rules for dispositifs de mesure d’audience et de fréquentation in publicly accessible spaces: measurement devices in shopping centres, stations, high streets and advertising environments. For a retailer, a property owner or a city, that framework is an advantage. It means the compliance conversation in France is not “is this allowed?” but “does this method meet the published expectations?”, a question with a checkable answer.
What the framework expects
CNIL’s framework comes down to three demands. The data must be genuinely anonymised, or processed under strong guarantees if anything identifiable is touched along the way. Visitors must be informed that measurement is taking place. And the processing must rest on a sound legal basis rather than an assumption. As with everything in our compliance library, this is orientation, not legal advice, but the direction is clear: the further a method’s output is from personal data, the shorter every one of those conversations becomes.
That is the architectural bet Bumbee Labs made from the start. Measurement is passive, nothing is asked of the visitor, and all personal data is irrevocably deleted, never hashed and kept, never stored, leaving only anonymous, aggregated statistics: counts, dwell, flows and trends per zone and period. There is no profile, no journey of an identified individual, nothing that could put a person back into the numbers.
Reviewed where it matters most
Compliance claims are cheap, which is why France’s clearest-playbook market deserves the strongest evidence. Bumbee Labs runs the only footfall method in Europe approved by a data protection authority. The approval was issued by IMY, the Swedish Authority for Privacy Protection, which examined our Wi-Fi footfall method: what is collected, what is deleted, and what remains. GDPR is one regulation across the EU, so the question IMY answered is the same one CNIL’s framework puts to any device operating in France, and the same one your DPO will put to any supplier. The difference between a self-declared “conforme au RGPD” and a regulator-reviewed method is the subject of its own page, and it is nowhere more relevant than here.
For deployments that combine methods, the same privacy-by-design engineering carries 3D sensor, LiDAR and cellular measurement into one platform, with the anonymous, aggregated output the framework favours.
What French operators measure
The French market runs on the same questions as every other, with the regulator’s checklist on top. Retailers and centres commerciaux measure store performance: footfall, conversion, dwell and flows between zones. Cities and collectivités measure high streets and public space to steer investment and report on it. Transport operators measure stations and hubs. In every case the deliverable is the same: anonymous statistics a French compliance review can approve without drama, through dashboards or an API into your own tools.
Start the conversation with your DPO in the room
A demo walks through the method, the data journey and the dashboards in plain language, and we answer compliance questions in writing. Bring the CNIL framework; we are glad to go through it point by point. The GDPR footfall analytics page collects the full compliance position, and the DPIA guide lists the questions to put to us and to any other supplier.
We are excited about the collaboration with Bumbee Labs through our Unicorn Academy program. A fantastic solution that fits in most of our industry segments such as retail, transportation, public sector etc. We are happy to support Bumbee Labs with our expertise and global presence, and we are delighted to add such an innovative solution to our portfolio, to be offered standalone or integrated in our own solutions.
Frequently asked questions
What does CNIL expect from footfall measurement?
CNIL's published framework for measurement devices in publicly accessible spaces sets expectations in three areas: the data must be properly anonymised or processed with strong guarantees, visitors must be informed, and the processing needs a sound legal basis. The cleanest way to meet the framework is a method whose output contains no personal data at all.
Is Wi-Fi people counting legal in France?
CNIL's framework explicitly addresses signal-based footfall measurement rather than banning it: it describes the conditions under which such devices operate lawfully. A method built on anonymisation by design, where personal data is irrevocably deleted and only aggregated statistics remain, is built for exactly those conditions. The assessment of a specific deployment belongs to its own review; this page is orientation, not legal advice.
Which authority approved Bumbee Labs' method?
IMY, the Swedish Authority for Privacy Protection, which examined the Wi-Fi footfall method: what is collected, what is deleted and what remains. GDPR is the same regulation in Stockholm as in Paris, so the question IMY answered is the same one a French review asks: does this produce personal data?
Do visitors have to consent to being counted?
Consent is one of the routes CNIL's framework describes, but not the only one: the framework also covers processing built on anonymisation with strong guarantees, paired with clear visitor information. Measurement that produces only anonymous, aggregated statistics avoids resting the whole deployment on collecting consent from every passer-by, which no footfall project can realistically do.