
A file sharing link is a URL generated by a hosting service (cloud, dedicated platform) that allows a third party to download or view a document. In France, this seemingly mundane technical mechanism is at the intersection of several texts: the Data Protection Act, GDPR, the Intellectual Property Code, and, recently, directives from the CNIL regarding trackers embedded in these links.
Trackers in shared links: the CNIL’s position in 2026
Most sharing services insert tracking mechanisms into the URL or the download page. Invisible pixels, UTM parameters, session cookies: these devices collect data on the recipient’s terminal even before they have clicked on “Download.”
Article 82 of the Data Protection Act constitutes the applicable legal basis. It generally requires prior consent before any registration or reading of information on the user’s device. Sharing links that include a tracking pixel or an advertising identifier fall within this scope.
In 2026, the CNIL clarified that tracking pixels in emails fall under the regime of trackers. The transitional period granted to publishers to comply ended on July 14, 2026. Any service that generates a sharing link containing a marketing tracker must obtain the recipient’s consent, unless the tracker falls under a strict exception.
To better understand the legal issues surrounding links to 1fichier.com in France, the issue of trackers is a good starting point.

Exceptions allowed by the CNIL
Three scenarios are exempt from the consent requirement:
- Trackers related to the security of the service (detection of fraudulent downloads, protection against brute force attacks on a password-protected link).
- Authentication mechanisms explicitly requested by the user, such as a session token necessary for the link’s operation.
- Some limited measures of technical deliverability, provided they are not used for commercial scoring or profiling.
Marketing tracking, click counting for advertising purposes, and user profile enrichment do not benefit from any of these exceptions.
Sensitive state data and cloud services
File sharing is not just for individuals. French administrations use cloud services to store and transmit documents, sometimes classified as sensitive.
The SREN law regulates the use of private cloud computing providers to process data of particular sensitivity. The text specifically addresses the risk of access by foreign authorities, a point directly related to file sharing via platforms whose servers are located outside the European Union.
For companies sharing files with administrations or state operators, this provision has a direct consequence: the choice of hosting service determines the legality of the sharing. A link generated by a service that does not comply with the national security framework may be rejected, or even expose the sender to contractual sanctions.
Graduated response and identification of file sharers
The sharing of files protected by copyright remains monitored in France by Arcom (formerly Hadopi). The graduated response mechanism relies on the collection of IP addresses and the identification of internet subscribers by access providers.
The 2026 case law has strengthened the requirements surrounding this mechanism. The Council of State reminded that access to identity and traffic data must respect principles of partitioning and proportionality derived from European law. In practice, this means that agents responsible for collecting IP addresses cannot access identification data, and vice versa.

What this changes for users of sharing links
Sharing a link to a file protected by copyright (film, album, software) via a hosting platform still exposes one to the graduated response procedure. The strengthening of partitioning does not protect the end user: it regulates the conditions under which the administration accesses the data, without questioning the principle of sanction.
The nuance is legal, not practical. Sending a download link to pirated content remains an act of infringement, whether the file is hosted in France or abroad.
SREN law and data portability: what link with file sharing
The SREN law (law n° 2024-449 of May 21, 2024) does not directly address file sharing between individuals, but its provisions on cloud and data portability have an indirect effect.
The European Data Act and the DMA (Digital Markets Act) require providers to facilitate the transfer of data from one service to another, which includes files stored on a sharing platform.
For a user wishing to migrate their files from one service to another, the combination of the SREN law and the Data Act creates a more concrete right to portability than before. Outgoing transfer fees are gradually being regulated, and proprietary formats that prevented the recovery of shared files are in the regulator’s sights.
The French legal framework surrounding file sharing links combines rules on trackers (CNIL, article 82), the protection of sensitive state data (SREN law), the fight against infringement (graduated response, strengthened partitioning), and cloud portability (SREN law, Data Act). The date of July 14, 2026, the end of the transitional period for tracking pixels, marks a turning point for all services that generate tracking links.