GDPR and LLM citation tracking: what does the CNIL say in 2026?
The CNIL hasn't published specific doctrine on LLM citation tracking in 2026, but its general GDPR guidelines apply: no tracking of identifiable persons without legal basis, no sending of prompts containing personal data to LLMs without a contract. Discuss with a lawyer.
When GDPR actually kicks in
LLM citation tracking (who cites what, how, in which prompts) generally involves querying models with prompts built by the agency. As long as those prompts don't contain personal data of real users, GDPR isn't directly engaged, it's monitoring of published content. GDPR risk appears in three specific cases: (a) you send a prompt with client emails, user names or purchase behaviour to an LLM; (b) you store LLM conversations containing personal data; (c) you train a model on personal data without a legal basis identified among the six options of Article 6 GDPR (consent, contract, legal obligation, vital interest, public-interest task, legitimate interest).
Applicable CNIL and EDPB corpus
The CNIL published in June 2024 its AI recommendations (seven sheets on dataset construction, legal basis, anonymisation, data-subject rights, source: cnil.fr/fr/developpement-des-systemes-dia). In 2025-2026 those sheets remain the operational reference for France; no doctrine specific to "LLM citation tracking" has been issued. At European level, EDPB Opinion 28/2024 of 17 December 2024 clarified the lawfulness conditions for personal-data processing inside AI models. "The CNIL and the EDPB have taken an important position on this: if you send personal data of your clients or employees to ChatGPT, Copilot or any third-party LLM, you are the controller, not the LLM provider," stresses Lorenzo Eeman, founder of PROEMA.
PROEMA position and practice
PROEMA position: LLM citation tracking via third-party tools (proprietary monitoring or Audit Express / In-Depth panels) is legal as long as we work with generic prompts without personal data. For per-client B2B tracking, foresee a clause in the service contract and a DPA if the monitoring tool is hosted outside the EU (Schrems II international transfers). The tested content is public, not confidential. PROEMA + Sabrina (consulting lawyer) audits client workflows to guarantee Article 6 + Article 28 GDPR compliance (sub-processing). Sources: CNIL AI recommendations June 2024, EDPB Opinion 28/2024, CJEU Schrems II ruling (C-311/18), Dalloz IT articles 2025-2026.
Same checklist.