Leading decision: cc • No. 90-87.555 • 1991-05-23 • View the decision →
Imagine: you are an owner in Saint-Paul-lès-Dax and you manage the letting of your flat yourself. For years, you have been using a small Excel file to keep track of the names, addresses and bank details of your tenants. Nothing too serious, you think. Yet this file is an automated processing of nominative information within the meaning of the Data Protection Act. And if you have never declared it to the CNIL (Commission nationale de l'informatique et des libertés), you are committing an offence. But for how long?
The question that arises for every owner or real estate professional is: am I safe from prosecution if I installed my file more than three years ago? The answer is no, if you are still using it today. That is what the Court of Cassation decided in a judgment of 23 May 1991, a landmark decision for understanding limitation periods in data protection matters.
This judgment, although dating from 1991, remains highly relevant in the digital age. It established a clear principle: the offence of failure to declare is a continuing offence, which means that it continues as long as the file is in use. In other words, the limitation clock does not start on the day of installation, but on the day the infringement ends, i.e. when the processing ceases or is regularised. A safety net for the authorities, but a trap for the negligent.
The facts: a story like many others
Mr X, an owner in Saint-Paul-lès-Dax, installed a computer system in 1986 to manage his seasonal lettings on the Landes coast, particularly in Capbreton. This tool allowed him to store the names, addresses, dates of stay and bank details of his clients. He had never made the prior declaration to the CNIL, which had been mandatory since the Act of 6 January 1978. In 1989, a complaint was filed by a dissatisfied former tenant, who discovered that his personal data was being kept without his explicit consent.
The case came before the criminal court. Mr X was prosecuted for the offence under Article 41 of the 1978 Act, which punishes by one year's imprisonment and a fine of €15,000 (updated amount) the carrying out of automated processing of nominative data without prior declaration. But Mr X invoked the limitation period: according to him, the three-year limitation period (applicable to offences) would have started to run on the day of installation of his software in 1986, i.e. more than three years before the complaint.
The criminal court nevertheless convicted him. Mr X appealed. The Court of Appeal upheld the conviction, but did not clearly address the starting point of the limitation period. Mr X appealed to the Court of Cassation. The Court of Cassation, in its judgment of 23 May 1991, dismissed his appeal and clarified the rule: the offence of failure to declare is a continuing offence; the limitation period only runs from the cessation of the processing. Since Mr X was still using his file at the time of the complaint, the infringement was still ongoing. The limitation period had therefore not started to run.
The reasoning of the court — dissected
The Court of Cassation relies on Article 41 of the Act of 6 January 1978, which makes it an offence to "carry out or have carried out automated processing of nominative information without having previously made the declaration provided for in Article 16". The text therefore targets not only the initial act of implementation, but also the fact of "carrying out" the processing, i.e. executing it on a continuous basis.
The judges recall a classic principle in criminal law: the continuing offence is distinguished from the instantaneous offence. An instantaneous offence (such as theft) is completed in an instant, and the limitation period begins at that instant. A continuing offence (such as false imprisonment) extends over time; the limitation period only begins at the end of that situation. Here, the failure to declare is a state: as long as the file exists and is used without declaration, the offence is committed every day.
The Court specifies that the starting point of the limitation period cannot be fixed on the day of installation of the system, because the offence is not only the installation, but also the continuation of the processing. In short, if you install an undeclared file and use it for ten years, you are committing an offence for ten years. The three-year limitation period only begins to run when the processing ceases (or is regularised).
This decision was subsequently confirmed by the Court of Cassation and is part of a logic of personal data protection: it prevents an offender from being able to shelter himself by letting three years pass after installation, while continuing to process data illegally.
What this means for you — practically
This case law has immediate implications for real estate professionals, who often handle personal data files.
Landlord owner: If you manage your lettings with property management software, a spreadsheet or even a simple computerised paper file, you must check that you have declared this processing to the CNIL. Example: an owner in Capbreton has been using a file for his seasonal lettings since 2015. In 2023, a dissatisfied tenant files a complaint. The owner cannot invoke the limitation period on the grounds that the file was created more than three years ago. He is still committing an offence. He risks a fine of up to €15,000 (for an individual) and a term of imprisonment.
Estate agency or property manager: These professionals process thousands of data (clients, prospects, co-owners). If they have not declared their files, they are liable to criminal sanctions. Moreover, since the GDPR (General Data Protection Regulation), administrative fines can reach €20 million or 4% of annual worldwide turnover. The 1991 case law remains relevant for determining the limitation period for criminal prosecutions.
Co-owner: If your property manager uses a file of co-owners without declaration, you can report it to the CNIL. But be careful: the offence is constituted as long as the file is used. Even if the property manager installed the file ten years ago, he can be prosecuted today.
What few people know: declaring to the CNIL is free and easy to do online (via the website www.cnil.fr). Not doing so exposes you to risks far greater than the cost of compliance.
Four tips to avoid this type of dispute
- Systematically declare any file containing nominative data to the CNIL. Whether you are an owner, estate agent or property manager, as soon as you collect names, addresses, telephone numbers, etc., in a computerised file, you must make a prior declaration. The procedure is free and takes 15 minutes online. Do not wait until you are inspected.
- Keep a register of your processing activities. Since the GDPR, anyone processing data must keep a register. Note the date of creation, the purpose, the recipients, and especially the date of CNIL declaration. This will allow you to prove your compliance in the event of an inspection.
- Update your declarations. If you change the use of your file (for example, you start collecting bank details in addition to names), you must make an additional declaration. The continuing offence case law also applies to undeclared modifications.
- Delete unused files. If you no longer use a file, destroy it or archive it offline. As long as it exists on your computer, even if you no longer use it, you could be considered to be committing a continuing offence if you have not declared it. Clean up regularly.
Further reading: related case law and developments
The Court of Cassation has confirmed this position in several subsequent judgments. For example, in a judgment of 20 March 2001 (No. 00-84.519), it reaffirmed that the failure to declare is a continuing offence for the purposes of limitation. Similarly, the Criminal Division has extended this reasoning to other related offences, such as the lack of consent of the persons filed.
This case law has been incorporated into the amended Data Protection Act, and later into the GDPR. Although the GDPR replaced the declaration obligation with an obligation to keep a register and carry out impact assessments, the principle of the continuing offence remains for breaches of these new obligations. The courts continue to refer to it.
undefined that CNIL inspections can relate to files installed a long time ago, without the limitation period having expired. Real estate professionals must therefore be vigilant: a file created ten years ago and never declared can still be sanctioned today. The trend is towards increased data protection, with heavier sanctions.
Checklist before taking action
- Check whether you have declared all your files containing personal data. Log on to the CNIL website (www.cnil.fr) and consult your declarant space. If you have never declared anything, you are probably committing an offence.
- Identify all the files you use. Take an inventory: property management software, client file, prospect file, list of co-owners, etc.
- Regularise immediately. Make an online declaration for each file. For existing files, there is no need to go back in time; declare them now. This stops the offence and starts the limitation period running from that date.
- Delete obsolete files. If you no longer use a file, delete it permanently. Keep proof of deletion (date, procedure).
- In the event of a complaint or inspection, do not attempt to conceal. Good faith may be taken into account, but prompt regularisation is the best asset. Consult a lawyer to prepare your defence.
Are you in a similar situation? A first 30-minute consultation with Maître Zakine (€45) can save you months of proceedings — and often much more. Book an appointment →

