Following my previous article on the "Phrygians," many readers asked me about the practical workings of the services, the "files," the administrative investigations, the surveillance, and the databases. This report revisits the texts, public reports, and oversight institutions to answer a simple question: what does the citizen finance, how does this system function, and what safeguards govern it?
This report reveals no classified information, agent identities, sources, non-public operational methods, or vulnerabilities. It adheres to what has been made public by regulations, services, and oversight bodies. When the law protects a detail, the article stops at that boundary instead of speculating.
Politics and intelligence: informing the citizen without revealing the secret
Intelligence is fascinating because it immediately evokes clandestine operations, wiretapping, undercover agents, and classified information. Yet, before being a world of secrecy, French intelligence is a public policy governed by law. The Internal Security Code stipulates that the services operate under the authority of the Government, in accordance with the law and the guidelines established at the highest levels of the State. Their general function is preventive: they seek to understand a threat, anticipate its evolution, inform political decision-making, and, when the law allows, contribute to hindering hostile action before it has its full effect. This logic explains why intelligence is distinct from both the criminal investigation department, which establishes offenses for the purpose of criminal proceedings, and the justice system, which judges, as well as administrative discipline, which sanctions professional misconduct.
This distinction is fundamental to understanding everything else. Information can be relevant to an intelligence service without constituting criminal evidence. An individual can be the subject of a security check without being guilty of a crime. An administration can verify the compatibility of behavior with a sensitive position without initiating disciplinary proceedings. Conversely, the fact that information has been collected or that a name appears in a database does not mean that a person is considered dangerous, guilty, or under constant surveillance. The terms "listed," "monitored," "flagged," "radicalized," "cleared," or "under investigation" cover different legal realities. A large part of public misunderstandings stems precisely from this conflation.
The other key is the concept of prevention. Intelligence is not intended to systematically wait for an attack, a spying operation, sabotage, technological interception, or organized crime to be completed. It seeks out signals, cross-references them, prioritizes them, and places them within a context. This does not give the services carte blanche: action must have a purpose defined by law, be necessary and proportionate, and the most intrusive surveillance techniques are subject to a specific authorization and oversight regime. Modern French intelligence law has largely been structured around this balance between anticipation and civil liberties, particularly since the law of July 24, 2015.
Sources for context: Internal Security Code, Book VIII; DGSI, "Our missions"; DGSE, "Our missions".
The "Phrygians": what is established, what is stated, what we do not know
The starting point for this report is political, but it must never become partisan. Several press articles in 2026 reported the existence of an informal network of senior civil servants close to La France Insoumise (LFI), nicknamed "the Phrygians," who were allegedly working on analyses and preparing for a possible change of government. In June, Le Monde mentioned around thirty members, according to LFI's presentation; in August, other publications, relying in particular on the anonymous testimony of a group leader, cited a number closer to eighty. These figures describe statements and press reports: they do not constitute a certified official census.
The first precaution, therefore, is to separate what we know from what we assume. The public existence of such a network is documented. However, there is no exhaustive public list that would allow us to verify the identity of all its members, their original administration, their hierarchical level, or the reality of each claimed location. Nor do we have, on this basis alone, any publicly available evidence establishing that members are using confidential information, work time, state resources, or their administrative prerogatives for the benefit of a political organization.
The second precaution is equally important: no public source consulted confirms that the DGSI, the DNRT, or any other intelligence service is monitoring Phrygians as a group, that they are collectively "listed," or that their existence is considered a threat to national security. Proximity to a legal party, political affiliation, or the private development of ideas do not, in themselves, constitute an intelligence objective. The potential shift toward ethics, discipline, security investigations, or intelligence gathering depends on concrete facts, the individual's role, and the applicable legal framework.
It is precisely this lack of automaticity that makes the subject interesting. A democracy must simultaneously protect two things: the political freedom of public officials as citizens and the neutrality of the administrative apparatus in the exercise of its duties. This case therefore seeks neither to exonerate in the abstract a network whose internal practices we do not know, nor to attribute to it behaviors for which we have no proof. It seeks to determine what rules would allow us to classify the facts if, tomorrow, verifiable evidence were to emerge.
Methodological note: "reported existence" does not mean "proven illegality" or "proven surveillance." This distinction applies to the Phrygians as well as to any political, trade union, associative, or ideological network.
| Level | What one can seriously write |
|---|---|
| ESTABLISHED / PUBLIC | A network called "the Phrygians" has been publicly reported since 2026 and is presented as bringing together senior officials close to LFI working on preparing for a possible change of government. |
| REPORTED / NOT EXHAUSTIVELY VERIFIED | The reported numbers have varied from approximately 30 to approximately 80 depending on the period and the source; no exhaustive public list allows verification of all members. |
| NOT PUBLICLY ESTABLISHED | There is no public evidence, on this basis alone, of the use of confidential information or administrative means for partisan purposes. |
| NOT PUBLICLY ESTABLISHED | There is no public basis for claiming that there is collective profiling or surveillance by the DGSI, the DNRT or any other service. |
Verification sources: Le Monde, June 5, 2026; press publications of August 22-23, 2026; General Code of the Civil Service; Internal Security Code.
Can a civil servant be politically engaged? The legal boundary
The first principle is often forgotten: a civil servant does not cease to be a citizen upon entering the civil service. Article L. 111-1 of the General Code of the Civil Service stipulates that freedom of opinion is guaranteed to public employees. This protection is not merely symbolic. It means that an employee can hold convictions, vote, join a political party or a trade union, participate in public life, and, subject to the specific rules attached to certain positions, exercise political responsibilities. The civil service statute, therefore, does not impose internal neutrality of conscience; it establishes the neutrality of public action.
The second principle mirrors the first. Articles L. 121-1 and L. 121-2 require public servants to perform their duties with dignity, impartiality, integrity, and probity, and, in the performance of their duties, to respect the obligation of neutrality. This clarification—"in the performance of their duties"—is essential. It specifically prohibits transforming the public service into an instrument of propaganda, favoring or disfavoring a user because of their opinions, influencing an administrative decision to satisfy a partisan interest, or using the authority attached to their position to promote a political organization.
In addition to this neutrality, there is the duty of discretion. This is frequently confused with a general prohibition on discussing politics, whereas it primarily concerns the methods of expression. Service-Public clarifies that it does not prohibit freedom of opinion or freedom of expression, but requires restraint and moderation; its intensity varies according to hierarchical rank, circumstances, the publicity given to the remarks, and their form. A senior civil servant directly involved in the implementation of government policies will therefore generally be bound by greater discretion than an employee without specific responsibilities, while a union representative enjoys greater freedom in the exercise of their mandate.
Another, much clearer distinction lies in professional secrecy and discretion. Articles L. 121-6 and L. 121-7 protect information to which an employee has access by virtue of their duties. A political analysis written at home based on public statistics, reports from the Court of Auditors, and press articles is therefore not legally equivalent to the transmission of an internal ministry memo, a personnel file, an unpublished arbitration decision, confidential economic information, or a classified document. In the first case, the employee is using their civic rights; in the second, they would potentially be exploiting an informational privilege attached to their position.
The prevention of conflicts of interest must also be addressed. Article L. 121-5 requires public officials to prevent or immediately cease any situations in which a public interest may be influenced by a private interest in a way that could compromise the independent, impartial, and objective performance of their duties. Party affiliation does not automatically constitute a conflict of interest. However, an official tasked with investigating a case could encounter a serious problem if they used their position to favor an organization to which they belong, to circumvent oversight, to access information unrelated to their duties, or to discreetly influence a decision to benefit their own side.
This is where the issue of networks among senior civil servants becomes institutionally interesting. Preparing reform scenarios or public policy briefs, outside of official duties and using one's own resources, based on publicly available documents, can be considered civic engagement. However, using administrative channels, soliciting subordinates during working hours, exploiting a restricted database, disseminating a non-public document, or influencing a decision in the name of partisan interests would radically alter the classification. Between these two extremes lie gray areas that hierarchical authorities, the ethics officer, and, where applicable, the administrative judge must assess in light of the facts.
Disciplinary action is taken when a professional obligation is violated. Depending on the facts, the administration may request explanations, open an internal administrative inquiry, or initiate disciplinary proceedings. This process should not be confused with intelligence gathering. The fact that an agent is politically motivated does not automatically give the DGSI (General Directorate for Internal Security) jurisdiction. However, if distinct elements reveal foreign interference, espionage, preparation of serious violence, an attack on the republican form of government, or another purpose as defined in Article L. 811-3 of the Internal Security Code, the matter takes on a different character.
For sensitive positions, a third logic exists: that of security clearance. An individual may not have committed any offense or be subject to disciplinary action, yet still be the subject of a security assessment due to vulnerabilities, relationships, behaviors, or circumstances incompatible with classified access. The withdrawal or refusal of security clearance is therefore not necessarily a sanction; it is based on a preventative approach. Here again, legal political commitment alone is insufficient: what matters are the objective risks associated with the position and the protection of classified information.
The most accurate formulation is therefore the following: a civil servant can be an activist, contribute to public debate, and even politically prepare for a change of government within the bounds of the law; however, they cannot transform public power, non-public information, or the resources of their department into partisan instruments. This is neither political immunity nor a presumption of guilt. It is a legal boundary, and this boundary must be assessed based on verifiable behavior rather than ideological labels.
Sources: General Code of the Civil Service, art. L. 111-1, L. 121-1 to L. 121-7; Service-Public.fr, duties of reserve, discretion, neutrality and professional secrecy.
Who does what? The first circle, the second circle, and the coordination
The general public often speaks of "the secret services" as if there were a single organization. In reality, France has an intelligence community organized into several circles. Article R. 811-1 of the Internal Security Code designates six specialized services, often referred to as the "first circle": the General Directorate for External Security (DGSE), the Directorate of Intelligence and Security of Defense (DRSD), the Directorate of Military Intelligence (DRM), the General Directorate for Internal Security (DGSI), the National Directorate of Customs Intelligence and Investigations (DNRED), and TRACFIN. Alongside these, the community includes, in particular, the National Coordination for Intelligence and Counterterrorism, the National Counterterrorism Center, the Intelligence Academy, and the Inspectorate of Intelligence Services.
The "second circle" comprises services that are not specialized services as defined in Article R. 811-1, but which may, for certain purposes and according to the techniques stipulated by law, contribute to intelligence policy. The list was updated in 2026. It notably includes the National Directorate of Territorial Intelligence within the National Police, certain specialized police and gendarmerie units, the Intelligence Directorate of the Paris Police Prefecture, and the National Prison Intelligence Service. Their authority is not general: the regulations specify, service by service, the purposes and techniques for which authorization exists. It is therefore misleading to present each police unit as an intelligence service endowed with all the powers of the "first circle."
Above this complex structure, coordination serves precisely to prevent six specialized services and several partner services from working in silos. Modern intelligence is cross-cutting: an interference operation may include a diplomatic component monitored abroad, a human approach on the ground, financial transactions, an attempt at industrial takeover, and a cyber intrusion. No single service possesses all the sensors or all the skills. The quality of the system therefore depends as much on the legal sharing and cross-referencing of information as on the performance of each service individually.
Reference: Internal Security Code, articles R. 811-1 and R. 811-2, versions in force in 2026.
The six specialized services: six different professions behind a single term
DGSE — Directorate General for External Security
The DGSE is the French foreign intelligence service. Attached to the Ministry of the Armed Forces, it gathers protected or difficult-to-access information abroad, cross-references it, analyzes it, and produces strategic intelligence for the highest authorities. Its public missions notably cover terrorism, proliferation, geopolitical crises, foreign interference, and cybersecurity. The DGSE publicly states that it sends several thousand reports to the government each year and employs approximately 7,200 agents. This figure highlights an often-overlooked reality: an intelligence service is not solely composed of field agents. It also employs analysts, linguists, engineers, cybersecurity specialists, technicians, lawyers, security personnel, and support staff.
DGSI — Directorate General for Internal Security
The DGSI is the specialized service under the Ministry of the Interior responsible for internal security. Its public remit includes the prevention of terrorism and violent extremism, counter-espionage, the protection of economic and scientific assets, cyber threats, counter-proliferation, and specialized judicial police work in certain types of litigation. Its counter-intelligence mission is particularly important: it seeks to detect operations by foreign states or organizations targeting institutions, businesses, laboratories, expertise, or individuals. The DGSI itself states that it issues alerts to the authorities when economic or scientific threats are detected, while also conducting extensive awareness campaigns for businesses and the research community.
DRM — Directorate of Military Intelligence
The DRM is the French military intelligence service. Under the authority of the Chief of the Defence Staff, it produces military intelligence: assessing military capabilities, understanding the intentions and operational possibilities of foreign armies, armed groups, private military companies, or organizations likely to threaten French interests. It informs civilian and military authorities and directly supports deployed forces. Military intelligence is therefore not simply about "counting tanks": it involves integrating data of different kinds to build a situational awareness useful for decision-making and action.
DRSD — Directorate of Intelligence and Security of Defence
The DRSD is the counterintelligence service for the defense sector. Its mission is to "gather intelligence to protect": to detect threats to military and civilian personnel, classified information, equipment, facilities, deployed forces, and the defense industry. It examines, in particular, risks related to terrorism, espionage, sabotage, subversion, organized crime, and cyberattacks. It also protects the nation's scientific and technical capabilities within the defense domain. This function explains why intelligence gathering can have very concrete consequences for security clearances, access, or protection measures without necessarily constituting criminal proceedings.
DNRED — National Directorate of Customs Intelligence and Investigations
The DNRED is the customs intelligence service's first-tier intelligence unit. Its public structure has been refocused on organized crime and economic and financial crime. It intervenes in major trafficking operations, money laundering, certain tax and customs frauds, counterfeiting, cultural property, sanctions evasion, and counter-proliferation. Customs officials indicated that the DNRED would have nearly 800 agents by 2024. Its contribution illustrates a key characteristic of modern intelligence: the boundaries between national security, trade flows, organized crime, international sanctions, and the financing of hostile activities are increasingly blurred.
TRACFIN — financial intelligence
TRACFIN is the French financial intelligence unit and one of six specialized services. It receives suspicious activity reports from professionals subject to anti-money laundering and counter-terrorist financing obligations, as well as information from partner agencies and foreign counterparts. It analyzes, enhances, and uses this data in three main public areas: economic and financial crime, fraud against public finances, and the defense of fundamental national interests, particularly the financing of terrorism and criminal interference. Its existence serves as a reminder that a hostile operation often leaves a financial trace, even when its initial objective is political, criminal, or clandestine.
Sources: DGSE; DGSI; Ministry of the Armed Forces (DRM, DRSD); French Customs; TRACFIN; Internal Security Code, art. R. 811-1.
What we know about the cost and staffing levels
Intelligence gathering is expensive, but it is wrong to say that citizens have no idea what they are funding. The 2025 public report from the Parliamentary Delegation for Intelligence indicates that fourteen budget programs contributed to this public policy in 2024, and that the overall allocation of payment appropriations in regular funds reached €3.4 billion, an increase of 10.26% year-on-year. The staff of the six specialized services reached 16,150 agents in 2024, compared to 15,816 in 2023 and 14,912 in 2020. The services falling under Article L. 811-4, often associated with the "second circle," totaled 4,177 agents in 2024, compared to 4,170 in 2023. These figures do not describe all national security spending, but they provide a public sense of the scale of the core of intelligence policy.
Transparency deliberately stops short of certain details. The same report from the DPR (Directorate of Public Security) contains passages marked with five asterisks. The Delegation explains to the reader that it seeks precisely to reconcile "a legitimate expectation of transparency from citizens" with national defense secrecy. Special funds are subject to specific oversight by the Special Funds Audit Commission, but their details are not made public like an ordinary administrative budget. This method is instructive: in a democracy, secrecy does not mean that no one is in charge; it means that certain controls are entrusted to parliamentarians, judges, or authorities empowered to know what the public cannot know.
Source: Parliamentary Delegation for Intelligence, Public Report 2025, Volume I, in particular the developments on resources 2024.
How does information become intelligence?
Raw information is not yet useful intelligence. The work begins with a question: what threat do we need to understand, what decision do we need to inform, what vulnerability do we need to verify? Information can then come from open sources, reports, institutional partners, human sources, authorized technical devices, or data held by other government agencies when a law authorizes its transmission. Intelligence arises from cross-referencing: a single piece of information can be false, incomplete, misinterpreted, or deliberately manipulated. Analysts compare sources, look for inconsistencies, assess reliability, place the facts in a chronological order, and distinguish what is certain, probable, possible, or unconfirmed.
Once consolidated, the information can be integrated into a file, analyzed, used to inform a report, lead to a request for additional surveillance within the legal framework, or, conversely, be classified as irrelevant. The DGSE (General Directorate for External Security) publicly states that it collects, cross-checks, and analyzes information before sending several thousand reports annually to the authorities. The DGSI (General Directorate for Internal Security), for its part, indicates that it produces alert reports, for example, regarding economic interference. This documentary output is one of the most important results of intelligence work: the objective is not to accumulate data, but to transform a mass of information into an assessment usable by a decision-maker.
It is also necessary to understand the concept of obstruction. In the public vocabulary of intelligence services, obstruction refers to actions intended to prevent or reduce a threat. Their nature depends on the context and the legal framework: administrative measures, enhanced protection, inter-agency cooperation, raising awareness among a target, diplomatic decisions, legal action when offenses are established, or other responses decided upon by the competent authorities. The details of certain operational methods are precisely what this article does not seek to describe.
The seven legal purposes that govern the use of intelligence techniques
Article L. 811-3 of the Internal Security Code is one of the most important texts for understanding the legal limits of intelligence. It does not allow for the surveillance of someone simply because a service finds them "interesting." The techniques provided for in Book VIII must, in the exercise of the missions of the service concerned, be linked to the defense and promotion of the fundamental interests of the Nation as defined by law. These objectives are intentionally broad, but they are not unlimited.
1. National independence, territorial integrity and national defense.
2. The major interests of foreign policy, the execution of France’s European and international commitments and the prevention of any form of foreign interference.
3. France's major economic, industrial and scientific interests.
4. The prevention of terrorism.
5. The prevention of attacks on the republican form of institutions, the maintenance or reconstitution of dissolved groups and collective violence likely to seriously harm public peace.
6. The prevention of organized crime and delinquency.
7. Preventing the proliferation of weapons of mass destruction.
This framework explains why the same technique can be legal in one case and illegal in another. Legality depends not only on the tool used, but also on the competence of the service, the intended purpose, necessity, proportionality, duration, and applicable safeguards. The CNCTR's role is precisely to examine these requests before their implementation and then monitor their execution. The specialized administrative judge can also intervene.
Source: Internal Security Code, article L. 811-3.
Technical surveillance: what the CNCTR oversees
The law provides for several categories of intelligence techniques. At a deliberately general level, these include access to certain connection data, security interceptions, certain location or interception devices, and the collection of computer data under the conditions set forth in the Code. These techniques are not interchangeable: their regulations, durations, and conditions vary, and not all services can use them all for all purposes. This document does not describe their operational implementation, as legal education does not require transforming a citizen's article into a surveillance manual.
The National Commission for the Control of Intelligence Techniques (CNCTR) is the independent administrative authority established by the 2015 law to oversee the legality of these techniques. It intervenes both beforehand, by issuing an opinion on requests before they are submitted to the Prime Minister, and afterward, by verifying within the intelligence services that implementation complies with the authorizations granted. Its 2025 activity report, published in June 2026, provides particularly revealing figures: 25,332 individuals were subject to surveillance using domestic techniques in 2025, and 100,813 requests for implementation were submitted for its opinion, compared to 24,308 individuals and 98,883 requests in 2024. Since a single individual can be the subject of multiple requests or techniques, these two numbers are obviously not equivalent.
The breakdown of objectives also shows that intelligence is no longer limited to terrorism. In 2025, the prevention of organized crime and delinquency involved 7,599 individuals, or 30% of the total, while the prevention of foreign interference involved 6,290 individuals, compared to 5,458 in 2024. The CNCTR conducted 120 ex-post audits of intelligence services in 2025. It also notes an increase in the use of certain more intrusive techniques, particularly the collection of computer data, in the context of the development of encrypted messaging. Importantly for democratic debate, the CNCTR also highlights its own limitations in resources and indicates that it reached a capacity alert threshold in 2025.
|
KEY POINT — SURVEILLANCE ≠ BEING LISTED IN A FILE A file can contain information about a person even if no surveillance technique is currently being used against them. Conversely, the authorization of a technique is subject to a specific regime that goes beyond the mere existence of an entry in a database. The CNCTR oversees these techniques; the CNIL intervenes primarily in matters of data processing and the exercise of certain rights. Confusing these two mechanisms leads to erroneous conclusions. |
|---|
Source: CNCTR, 2025 Activity Report, published June 25, 2026.
Information, intelligence note, file, S file, administrative investigation: stop conflating them
The term "file" has become a media shortcut that masks several realities. Raw information can be a report or a fact gathered. An intelligence note is an analytical document intended to circulate a useful assessment. Automated data processing is a database organized according to specific purposes and rules. An "S file" is a particular category in the Wanted Persons File. The FSPRT (File of Persons Suspected of Terrorism and Radicalization) is a system focused on radicalization leading to terrorism. PASP (Public Safety and Protection) and GIPASP (Integrated System for the Prevention of Threats to Public Safety and State Security) are used to prevent threats to public safety and national security. EASP (Administrative Security Investigations File) retains data useful for administrative security investigations. ACCReD facilitates the screening of multiple systems within the context of certain investigations. These mechanisms may be encountered in the same situation, but they are not synonymous.
The "white note" constitutes yet another category. In administrative litigation, intelligence notes can be produced without disclosing the sources or the methods of collection. The courts do not automatically grant them legal weight: they examine their accuracy, their detailed nature, and the possibility of adversarial debate, to the extent compatible with confidentiality. A note, therefore, does not become irrefutable proof simply because it originates from a service. This case law is essential for understanding the balance between protecting sources and judicial oversight.
The "S" file deserves special clarification. It belongs to the Wanted Persons File (FPR), but "wanted" does not necessarily mean "wanted for arrest." Depending on the categories and instructions attached to the report, the FPR can be used to inform the authorities when a person is stopped and checked. The CNIL (French Data Protection Authority) reiterates that being listed in the FPR is not in itself proof of dangerousness or an indication of active surveillance. The DGSI (General Directorate for Internal Security) has also explained that the "S" file does not constitute a secret radicalization scale and does not replace monitoring files. Therefore, an "S" file, a listing in the FSPRT (File of Persons Suspected of Terrorism and Related Threats), and technical surveillance are three distinct things.
"White notes": when intelligence enters into administrative decision-making
The term "white note" regularly appears in the news, particularly in cases related to terrorism, administrative policing measures, denials of access to sensitive sites, decisions concerning nationality, and security investigations. It does not refer to a file, much less a category of people. It is a method of providing intelligence. A white note presents information useful to an administrative authority or a judge without revealing, in its communicated form, the identity of the service or official who issued the note and, above all, without disclosing human sources, technical resources, or investigations whose disclosure could compromise an operation or endanger someone. A recent parliamentary report clearly summarizes this rationale: the white note allows the necessary information to be brought to the attention of the administration and the judge while protecting sources, ongoing investigations, and, where applicable, national defense secrets.
This peculiarity explains why intelligence reports have sometimes been presented in public debate as mysterious documents, or even as "secret evidence." This formulation, however, is misleading. When an intelligence report is used before an administrative judge, it can be submitted as evidence in the adversarial proceedings. The litigant can then contest the facts reported therein. The judge must not consider the document as inherently true simply because it originates from intelligence. The judge assesses its content as part of the case file. Case law emphasizes precision, specificity, coherence, and the possibility of comparison with the applicant's explanations. A highly detailed report, some elements of which can be corroborated by other documents or by the statements of the individual concerned, can carry significant weight. Conversely, a vague report, undated in its grievances, formulated in general terms, and lacking supporting evidence may prove insufficient.
The decisions of the Council of State perfectly illustrate this logic. In 2016, in several cases of house arrest, the judge agreed to consider unsubstantiated reports because they contained specific and detailed information, and the proceedings had not invalidated their content. Conversely, other decisions show that the judge can overturn a measure when the report is too old, too vague, or insufficiently corroborated. In April 2016, for example, the Paris Administrative Court of Appeal dismissed an administrative ban from the country when the minister had essentially only produced a report stating that the individual's presence would constitute a serious threat, without presenting sufficiently precise facts. This logic is essential in a state governed by the rule of law: protecting the source does not authorize the elimination of the requirement for proof.
Finally, it is important to distinguish a "white note" from another use of the expression "blank file," sometimes found in memoirs or accounts of the former General Intelligence Directorate (RG). A "white note" is an intelligence document whose origin has been anonymized. It should not be confused with a supposed "blank file" that the administration might have shown to a citizen requesting their file. The history of the right of access to RG files is more nuanced and, in some respects, more perplexing: for a long time, citizens did not necessarily receive the contents of their own files. They could only be informed that the CNIL (French Data Protection Authority) had carried out the necessary checks. It is this procedural opacity that has sometimes fostered the impression that a file could be completed without the individual concerned seeing anything.
Sources: National Assembly, information report on administrative surveillance measures; Council of State, orders of December 23, 2015, February 1, 2016 and subsequent decisions on the value of white notes; CAA Paris, April 2, 2026, No. 25PA00635.
The profiling of citizens: the very particular legacy of the General Intelligence Directorate
To understand current concerns about surveillance, one must look back to the former General Intelligence Directorate (RG). The RG was not simply a service responsible for political violence, public order, or certain extremist phenomena. For much of the 20th century, it also handled what was known as political, social, and territorial intelligence. Its role was to inform the government and prefects about political life, social movements, unions, organizations, influential figures, and evolving public opinion. This work generated a considerable number of files and index cards. The 2009 parliamentary report on police files also points out that the RG's activities long included collecting information about political parties and sometimes the private lives of prominent figures, and that these "political missions" were gradually abandoned after several public controversies.
The legal framework adopted in 1991 is particularly revealing. The decree of October 14, 1991, began by reiterating that the prohibition on retaining data revealing political, philosophical, or religious opinions and trade union affiliations applied to the General Intelligence Directorate (RG). However, it then provided for specific exceptions. The RG could, in particular, retain information revealing political, philosophical, religious, or trade union activities when they concerned individuals likely to threaten national security or public safety, when they were necessary for certain sensitive security clearances, and also when they concerned individuals holding or having sought a political, trade union, or economic office, or playing a significant political, economic, social, or religious role, provided that this information was necessary to allow the Government to assess the situation and anticipate its evolution.
This framework illustrates why the debate surrounding "political profiling" is more complex than a simple choice between two simplistic statements: "the state keeps files on its opponents" or "the state never retains political information." Historically, the law did indeed allow the General Intelligence Directorate (RG) to record data revealing political activities for specific purposes. At the same time, the same decree prohibited the selection of a category of individuals based solely on this information and imposed access restrictions, periodic reviews, and oversight by the CNIL (French Data Protection Authority). Legally, this was not a blanket license to create a file of the opinions of the entire population. However, there was undeniably a capacity for documenting political life by name, a capacity broad enough to make the democratic safeguards surrounding its use a major issue.
This distinction between “opinion” and “activity” is fundamental. A service may claim that it does not “track political opinions” while simultaneously recording that a person is responsible for a local branch, organizes meetings, regularly participates in demonstrations, belongs to a movement’s security detail, meets with certain figures, or plays an active role in an organization. Taken individually, each of these facts describes an activity. Taken together, they can obviously reveal a political orientation very clearly. This is one of the reasons why contemporary law considers political data particularly sensitive and why controlling the purpose, proportionality, retention period, and access to the file is at least as important as the vocabulary used to describe the data.
Sources: Decree No. 91-1051 of October 14, 1991, in particular Articles 1 to 7; CNIL, deliberation No. 91-083 of September 24, 1991; National Assembly, information report No. 1548 on police files, 2009.
Could you request to see your "RG file"? Yes, but not like a regular administrative file.
The French Data Protection Act of January 6, 1978, introduced a fundamental principle: citizens must be able to exercise rights over the personal information that the government holds about them. For ordinary files, access can be direct. However, for files concerning national security, defense, or public safety, the law provides for indirect access. Citizens did not simply go to the police station and ask for a file with their name on it. Instead, they contacted the CNIL (French Data Protection Authority). A member of the Commission, belonging or having belonged to the Council of State, the Court of Cassation, or the Court of Auditors, would conduct the necessary checks, examine the information, and request its correction or deletion if needed.
In the early 1980s, this system was extremely frustrating for the applicant. The CNIL (French Data Protection Authority) itself explained this in its annual reports: when a file fell under the security regime, the applicant was only notified that "the necessary checks have been carried out." This wording did not tell them what had been found and, above all, it did not always allow them to know if a file even existed. This system responded to an understandable security logic: confirming to a person under surveillance that they are in a file can reveal to that person that they have attracted the attention of the service, that their contacts are known, or that an investigation is underway. But, from the citizen's point of view, it created a considerable asymmetry since the administration could know information about them without them necessarily being able to know the information held by the administration.
The 1991 decree introduced a significant shift. For certain categories of cases, the CNIL (French Data Protection Authority) could, with the agreement of the Minister of the Interior, determine that the information did not compromise national security, defense, or public safety and disclose it to the individual concerned. When the General Intelligence Directorate (RG) held no information, the CNIL could also indicate this. Conversely, if the disclosure of all or part of the data risked harming national security, defense, or public safety, the Minister could object to such disclosure. The CNIL would then review the case, correct or delete inaccurate or outdated data if necessary, but the individual would only receive confirmation that the checks had been carried out.
This is where we need to correct a frequently misleading image. The General Intelligence Directorate (RG) didn't necessarily give citizens a "blank file" with a secret file full of information hidden behind it. The legal mechanism was more sophisticated: in some cases, no content was disclosed at all. The citizen received a neutral, procedural response. They could therefore have the impression of hitting a brick wall, even though a file did exist and had been reviewed by the CNIL (French Data Protection Authority). Before the 1991 reform, this lack of information was even more widespread. This is probably one of the reasons for the memory of being able to request a file and find nothing there, despite the existence of information.
The oversight was not merely symbolic. The CNIL's 1990 annual report is particularly revealing. For the Ministry of the Interior, the Commission recorded 401 interventions that year under the right of indirect access. It noted 160 cases without records, 145 records not requiring deletion, 19 files resulting in partial deletion, and 7 in total deletion, while other cases were still under investigation. The CNIL noted that approximately 15% of individuals for whom a record or file had been created had obtained partial or total deletion of information. This demonstrates two things: the oversight system could indeed correct files, but the very existence of deletions also shows that questionable, outdated, or unjustified information could still end up in the files.
Sources: CNIL, activity reports 1983-1984, 1990, 1991 and 2000; decree no. 91-1051 of 14 October 1991, article 7; Council of State, 28 April 2004, no. 251397.
Why might this lack of transparency pose a democratic problem?
Intelligence secrecy is not inherently anti-democratic. A service that systematically revealed to everyone the names of their sources, the elements that attracted their attention, the dates of reports, or the connections made would render some intelligence gathering impossible. The difficulty arises when a surveillance or personal data collection system deals with politically sensitive information and the person concerned has few means of knowing exactly what is being recorded. They can then hardly demonstrate that information is false, taken out of context, attributed to the wrong person, or outdated. It is precisely to compensate for this asymmetry that the CNIL (French Data Protection Authority) and then the courts play the role of trusted third parties: they can see what citizens cannot always see for themselves.
The specific risk of political profiling also lies in the chilling effect it can have. In a democracy, joining a legal party, attending a meeting, demonstrating peacefully, signing a petition, or publicly defending a belief should not in itself become an indicator of dangerousness. If citizens believed that all political activity automatically leaves a lasting personal record in a police file that could subsequently influence security clearance, recruitment, or interactions with the administration, some might refrain from exercising perfectly legal freedoms. This is why the purpose of the processing must be precise: documenting a threat to public order or national security is not the same as mapping public opinion for the convenience of those in power.
The problem is all the more delicate because the boundaries can be semantic. An administration can deny engaging in "opinion profiling" while retaining information about political activities that reveal those opinions. It can also rightly claim that a file is not a file of activists, even though specific activists are included for reasons related to their role, their connections, or particular events. Democratic oversight must therefore go beyond slogans and examine the categories of data, the criteria for inclusion, the purposes, the individuals authorized to access the data, the retention periods, the possibilities for linking databases, and the avenues for appeal. This is where the difference lies between a legitimate intelligence tool and a drift toward political surveillance.
Were all National Front activists "on file"? What the sources actually allow us to say
The memory of extensive surveillance of the National Front by the General Intelligence Directorate (RG) is not without historical basis, but it would be excessive to claim that "all FN activists were automatically registered" without evidence of such a general directive. The public sources consulted do not allow us to establish a rule according to which simply possessing a National Front membership card would have automatically triggered an individual file at the RG. Furthermore, the 1991 decree specifically prohibited selecting a category of people based solely on information relating to their political activities. We must therefore resist the temptation to transform the reality of widespread political surveillance into an absolute assertion that is impossible to prove.
However, several facts are firmly established. First, monitoring the activities and internal workings of political parties has long been a traditional mission of the General Intelligence Directorate (RG). A National Assembly inquiry commission explicitly stated this in 1999. Second, this mission was officially discontinued by a circular from the Minister of the Interior dated January 3, 1995. The parliamentary report specifies that the National Front, as a party, was therefore no longer to be subject to internal monitoring. Third, this cessation of party monitoring did not eliminate the surveillance of individuals, groups, or movements likely to resort to violence, seriously disrupt public order, or be associated with violent extremism. It is within this framework that certain members of the National Front's Department of Protection and Security (DPS), as well as activists linked to neo-Nazi, ultra-nationalist, or violent groups, continued to be of interest to the intelligence services.
The 1999 hearing of Jean-Pierre Pochon, then head of the General Intelligence Directorate (RG) at the Paris police headquarters, is particularly revealing. He explained to the parliamentary inquiry that after 1995, the RG was no longer to be directly or indirectly involved in the internal organization of political parties, but that it remained responsible for monitoring individuals and groups, on both the far right and the far left, who resorted to violence or failed to respect democratic principles. He indicated that the directorate was notably monitoring neo-Nazi, ultra-nationalist, and skinhead groups, as well as certain security companies influenced by far-right activists and mercenary networks, and that some of these profiles were found within the DPS (Department of Protection and Security). The parliamentary report also mentions an RG census estimating the number of more or less stable members of the DPS at around a thousand at the end of 1998. This establishes real and documented monitoring, but not the automatic profiling of all National Front (FN) members.
This nuance is important because it precisely protects the article's credibility. It is historically possible to demonstrate that the General Intelligence Directorate (RG) engaged in political intelligence gathering, that it monitored political parties before 1995, that it possessed data revealing political activities, and that it monitored certain radical elements of the National Front, as well as other movements. There is no need to go beyond the evidence. The subject is already sensitive and democratically important enough without adding a sweeping assertion that the available public archives do not support.
Sources: National Assembly, commission of inquiry into the DPS of the National Front, report no. 1622 and hearings of 1999, notably Jean-Pierre Pochon; decree no. 91-1051 of 14 October 1991.
From the RG to PASP and GIPASP: the debate hasn't disappeared, it has changed its framework.
The General Intelligence Directorate (RG) ceased to exist as a central directorate in 2008. Part of its security missions were transferred to the DCRI (Directorate General for Internal Security) along with the DST (Directorate of Territorial Surveillance), with the DCRI subsequently becoming the DGSI (General Directorate for Internal Security) in 2014. Local territorial intelligence followed a different path, passing through the Sub-Directorate of General Information and then the Central Service of Territorial Intelligence. Since 2023, the National Directorate of Territorial Intelligence (DNRT) has been responsible for the collection, centralization, and analysis of intelligence intended to inform the Government and state representatives in institutional, economic, and social matters, as well as in areas concerning public order, outside the specific jurisdiction of the Paris Police Prefecture. The long-standing need to understand what is happening in society has therefore not disappeared. It has been reorganized, specialized, and given greater legal oversight.
The PASP and GIPASP files illustrate this transformed continuity. They can contain data related to political, philosophical, religious, or trade union activities when these activities fall within the intended purposes of preventing threats to public safety or national security. A 2020 regulatory attempt replaced the notion of "activities" with that of political "opinions," philosophical or religious beliefs, and trade union membership. The Council of State overturned this amendment in December 2021 because the CNIL (French Data Protection Authority) had not been consulted on this substantial change and ordered the deletion of data that revealed mere opinions without corresponding activities, unless a new text is adopted through the proper procedure. This case is a concrete example of the role of law in limiting sensitive data collection.
It also shows why it is too simplistic to respond to concerns with "political profiling doesn't exist." The real question isn't whether a computer system officially bears that name. The real question is what political data can be recorded, for what purpose, based on what criteria, for how long, with what search and cross-referencing capabilities, and under what oversight. Conversely, it would be equally wrong to present PASP, GIPASP, or the DNRT as instruments designed to register all opponents of the government. The legal texts link them to the purposes of public safety and national security, and the courts can intervene when the limits are exceeded.
This is probably the most important lesson for citizens. Intelligence is necessary for a modern state, but its legitimacy rests precisely on the existence of boundaries that it must not cross. Secrecy protects sources and operations. It must not become an argument for exempting the entire system from oversight. The right of indirect access, the CNIL (French Data Protection Authority), the CNCTR (National Commission for the Control of Intelligence Techniques), the administrative courts, the specialized division of the Council of State, and Parliament do not eliminate all risk of error or abuse, but they constitute the mechanisms by which a democracy attempts to reconcile two demands that will always remain in tension: knowing enough about threats to protect the community and preventing the knowledge accumulated by the state from transforming into general political surveillance of its own citizens.
Sources: DGSI, historical timeline; National Police, National Directorate of Territorial Intelligence; Council of State, decisions of December 24, 2021 on PASP and GIPASP; CNIL, publication of decrees relating to PASP, GIPASP and EASP.
T4, T5 and internal designations: caution is advised
Designations such as "T4" and "T5" circulate in journalistic works, testimonies, and older descriptions of internal organizational charts. They are sometimes presented as if they officially and permanently describe DGSI units today. This is a methodological error. The DGSI does not publish a comprehensive operational organizational chart of its subdivisions, and the organization of an intelligence service evolves with threats, reforms, and priorities. Designations used at a given time may be accurate in their context but no longer correspond to the current organization.
It is particularly important to avoid asserting, without a contemporary official source, that "T4 and T5 are the units responsible for monitoring officials likely to influence institutions." The DGSI's public missions in the areas of counter-espionage, foreign interference, violent extremism, economic protection, and national security are well established; the existence of specialized internal structures is logical; but assigning a specific role to an unconfirmed internal code today would be tantamount to presenting a hypothesis as fact. This article therefore adopts a simple rule: when a file name, purpose, or controlling authority is public, we describe it; when the internal organization or the detailed decree is not published, we state this clearly and we do not invent the rest.
|
METHOD RULE A secret service can be seriously examined without claiming to know what is secret. The quality of a report is also measured by its ability to state "we do not know publicly" when the law has chosen not to publish information. |
|---|
Timeline: from the RG to the current system
The French intelligence architecture of 2026 should not be interpreted as if the General Intelligence Directorate of the 1980s still existed under a different name. In thirty-five years, its missions, databases, controls, and institutions have been profoundly restructured. This chronology helps to understand the continuities—the need to anticipate threats—and the breaks—the abandonment of institutional monitoring of political parties, the development of oversight bodies, the reform of territorial intelligence, and the regulation of intelligence techniques.
| Year | Milestone |
|---|---|
| 1991 | Decree governing several files of the General Intelligence Directorate and organization of the right of indirect access via the CNIL. |
| 1995 | According to subsequent parliamentary proceedings, the RG (General Intelligence Directorate) officially abandoned the monitoring of the internal workings of political parties. |
| 2008 | Disappearance of the Central Directorate of the General Intelligence Directorate; reorganization between specialized domestic intelligence and general/territorial information. |
| 2014 | Creation of the DGSI as an autonomous directorate general of the Ministry of the Interior. |
| 2015 | Law relating to intelligence, creation of the CNCTR and modern structuring of the control of techniques; establishment of the FSPRT. |
| 2020 | Reform of PASP, GIPASP and EASP processing; debate on the nature of political data that can be retained. |
| 2021 | The Council of State intervenes on the wording relating to "opinions" and recalls the procedural and purpose requirements. |
| 2023 | Creation of the National Directorate of Territorial Intelligence (DNRT), a new stage in territorial intelligence. |
| 2026 | Evolution of the second circle and creation of ACCReD MINDEF; the number of processing systems covered by Article R. 841-2 reaches twenty-five. |
This timeline does not claim to summarize the entire history of French intelligence; it situates the transformations directly useful for understanding the present case.
The galaxy of 25 files or parts of files relating to state security
To avoid turning a pedagogical deduction into a false revelation, each description must be read according to three levels of documentation. ESTABLISHED means that a public text, authority, or decree explicitly describes the existence or purpose. PUBLIC CONTEXT means that the responsible department and its general mission are known, but the details of the processing are not published. NON-PUBLIC means that the exact categories of data, registration criteria, authorizations, durations, or operational procedures are not publicly accessible. In a sovereign data file, ignorance does not authorize fabrication.
| Level | Meaning |
|---|---|
| ESTABLISHED | The public text or official authority explicitly states it. |
| PUBLIC CONTEXT | The existence or responsible department is known; the details of the processing remain partial. |
| NOT PUBLIC | The exact criteria, categories, durations or procedures are not published. |
Article R. 841-2 of the Internal Security Code provides an excellent starting point for understanding the diversity of the ecosystem. In its version in force in August 2026, it lists twenty-five automated processing operations or parts thereof of personal data subject to the specific legal regime applicable to files concerning national security. This list is impressive, but it should not be interpreted as "twenty-five secret files all used to monitor the population." Some are files of national sovereignty whose detailed decrees are not published; others are much larger administrative systems of which only a fraction of the data concerning national security falls under this regime.
| Processing system | Responsible authority / environment | General public-service framework | Publication level |
|---|---|---|---|
| CRISTINA | DGSI | State security | Detailed decree not published |
| SECU | DGSE | Security / sovereignty | Detailed decree not published |
| SIRCID | DRSD | Defence counter-intelligence | Detailed decree not published |
| DOREMI | DRM | Military intelligence | Detailed decree not published |
| FSPRT | Interior Ministry / CT community | Terrorist radicalization | Public existence and purpose |
| FPR (state-security section) | Interior Ministry | Wanted/reported persons | Public framework, special state-security section |
| SIS / N-SIS (state-security section) | Schengen Information System | European alerts | Public framework, special state-security section |
| STARTRAC (state-security section) | TRACFIN | Financial intelligence | Detailed decree not published |
| BCR-DNRED | DNRED | Customs intelligence | Detailed decree not published |
| GESTEREXT | Paris Police Prefecture | Paris territorial intelligence | Detailed decree not published |
| BIOPEX | DRM | Specialized DRM processing system | Detailed decree not published |
| LEGATO | Foreign Legion | Specialized processing system | Detailed decree not published |
| ACCReD (state-security section) | Interior Ministry | Administrative-investigation screening | Public decree |
| EASP (state-security section) | Police / Paris Police Prefecture | Administrative investigations | Public framework |
| PASP (state-security section) | National Police | Public-safety prevention | Public framework |
| GIPASP (state-security section) | National Gendarmerie | Public-safety prevention | Public framework |
| TREX | DGSE | External intelligence | Detailed decree not published |
| HOPSYWEB (security section) | Regional health agencies / prefects | Involuntary care + regulated cross-checking | Public framework |
| RINC | Armed Forces General Staff | Cyber defence | Detailed decree not published |
| NATALI (state-security section) | DGEF | Nationality / naturalization | Public decree |
| Prison intelligence file | Prison administration | Prison intelligence | Decree not published |
| Nuclear-interest data processing (state-security section) | National Gendarmerie / CoSSeN | Nuclear security | Public decree |
| FiMPA | Interior Ministry | Administrative policing measures | Detailed decree not published |
| PERS-CM | DGSE | DGSE personnel management | Detailed decree not published |
| ACCReD MINDEF | DRSD / Defence | Defence-security administrative investigations | Public 2026 decree |
List: Internal Security Code, article R. 841-2, version in force since February 26, 2026.
1. CRISTINA — DGSI
CRISTINA is the official name of an automated system implemented for the benefit of the DGSI (General Directorate for Internal Security) and relevant to national security. It is probably the most shrouded in mystery, precisely because the decree that sets out its details is not published. The public is therefore aware that the system exists, that it falls under the DGSI's purview, and that it is subject to specialized judicial oversight, but it lacks comprehensive information on the categories of data, the criteria for data input, retention periods, and all access authorizations. This non-publication is mandated by law for certain files deemed to be of national sovereignty. It would therefore be misleading to claim that CRISTINA "is only accessed in the event of a clear threat" or, conversely, that it automatically contains the information of anyone expressing a radical opinion. The appropriate level of certainty is more restrained: CRISTINA is a domestic intelligence tool related to national security; its detailed procedures are deliberately protected; The CNIL and the specialized division of the Council of State can intervene within the framework of the rights and remedies provided.
2. SECU — DGSE
SECU is a security processing system belonging to the Directorate General for External Security (DGSE). Article R. 841-2 lists it among the files relevant to national security, and public texts confirm that its detailed authorization is exempt from publication. Its mere existence should not lead one to imagine a database intended for the general public: the word "security" and its affiliation with the DGSE indicate a processing system falling within the service's protection and sovereignty framework, but the details of its data and uses are not public. This category is useful for understanding that intelligence services also need files to protect their own personnel, sites, access, procedures, and information, in addition to databases related to their investigative missions.
3. SIRCID — DRSD
SIRCID is a data processing system implemented by the Directorate of Intelligence and Security of Defense (DRSD). Its detailed decree has not been published. However, the institutional context allows us to understand its environment: the DRSD is responsible for counter-intelligence within the defense sphere, the protection of personnel, equipment, facilities, sensitive information, and defense-related industries. SIRCID is therefore part of the data processing system necessary for these security and counter-intelligence missions. To go further by claiming to precisely describe the categories of people, the fields recorded, or the access rules would be to speculate on an act that is, by its very nature, not public.
4. DOREMI — DRM
DOREMI is a system operated by the Directorate of Military Intelligence and falls under the regulations governing files relevant to national security. It is part of the activity of producing and exploiting military intelligence, which involves assessing the capabilities and operational possibilities of armed forces or armed groups that could affect French interests. As with several sovereignty files, the regulatory details are not made public. Citizens can therefore learn of its existence, the person responsible for it, and its general functional affiliation, but cannot reconstruct its data schema or the data collection methods used to populate it.
5. FSPRT — reports for the prevention of radicalization leading to terrorism
The FSPRT (File for the Processing of Reports for the Prevention of Radicalization of a Terrorist Nature) is much more publicly documented. Created in 2015, this file centralizes objective information on individuals flagged in a context of radicalization potentially linked to a terrorist threat. It is used for sharing and monitoring between relevant services and organizations, particularly within departmental assessment groups. Registration is neither a criminal conviction nor proof that a person is under 24/7 surveillance. Situations can evolve, be reassessed, and lead to different levels of monitoring. Furthermore, the DGSI (General Directorate for Internal Security) emphasizes that the FSPRT, political Islam, religious practice, and the S file should not be confused: their purposes and criteria are not the same.
6. FPR — the section concerning national security and the infamous S files
The Wanted Persons File is a vast operational police tool that includes several categories of alerts. Only certain data relevant to national security falls under the specific regime outlined in Article R. 841-2. Category S, for "national security," is the best known. Being listed in the S file does not automatically mean being a terrorist, convicted, under surveillance, or wanted for arrest. The alert can, in particular, allow information to be brought to the attention of a service when a person is being checked and for the application of the prescribed procedures. The S file alone does not contain an entire intelligence file and does not constitute a universal scale of dangerousness.
7. SIS / N-SIS — the Schengen Information System, for its security component
The Schengen Information System is a European alert infrastructure used by participating states. It is not a secret French file: its primary purpose is to disseminate alerts concerning wanted or missing persons, those subject to inadmissibility measures, or those wanted in connection with legal proceedings, as well as certain objects. The national component is integrated into this shared system. Article R. 841-2 only subjects certain national security data to specialized legal proceedings. This distinction is important: the inclusion of the Schengen Information System on the list does not transform every Schengen alert into classified French intelligence.
8. STARTRAC — TRACFIN, for its State security division
STARTRAC is a TRACFIN system, only the part relevant to national security falling under the specialized regime. TRACFIN receives and processes financial information, particularly in the fight against money laundering and terrorist financing, but also for defending the fundamental interests of the nation and detecting criminal interference. The detailed decree governing STARTRAC has not been published. Therefore, its place within the financial intelligence architecture can be explained without claiming to know its internal structure. It primarily illustrates a key idea: money is a sensor. Atypical flows, shell companies, financing circuits, or economic relationships can reveal connections that purely physical or political observation would not uncover.
9. BCR-DNRED — customs intelligence
BCR-DNRED is a system operated by the National Directorate of Customs Intelligence and Investigations (DNRED). Its detailed operating procedures are not publicly available. However, its mission context is clear: the DNRED combats large-scale customs fraud, trafficking, money laundering, sanctions evasion, counter-proliferation, and certain forms of economic and financial crime. Intelligence processing within this framework necessarily allows for the structuring of information useful for analyzing networks and flows, but the exact categories, retention rules, and access rights of the BCR-DNRED file should not be inferred beyond what is publicly available in the official documents.
10. GESTEREXT — intelligence from the police headquarters
GESTEREXT is a data processing system cited in Article R. 841-2 and implemented within the intelligence services of the Paris Police Prefecture. It may appear in certain verification or appeal mechanisms related to state security files. As its detailed decree is not publicly available, providing a technical description would be risky. What can be said with certainty is that its existence is recognized by law, that it falls within the scope of Parisian territorial intelligence, and that it is subject to the specific control regime applicable to data concerning state security.
11. BIOPEX — DRM
BIOPEX is a second processing system of the Directorate of Military Intelligence (DRM) mentioned in Article R. 841-2. Public texts establish its existence and its affiliation with the DRM, while the detailed regulatory act is exempt from publication. Older administrative documents suggest that it is a specialized processing system distinct from DOREMI, but an article intended for the general public should not reconstruct what the State has chosen not to publish. The relevant conclusion is that military intelligence does not rely on a single system: several specialized processing systems can coexist depending on the nature of the data and the missions.
12. LEGATO — Foreign Legion Command
LEGATO is a data processing system implemented by the French Foreign Legion Command and classified as a system relevant to national security. It is a highly instructive case because it highlights that the ecosystem extends beyond the six major services. The Foreign Legion faces specific challenges related to recruitment, security, identity, and institutional protection. Since the detailed decree governing LEGATO has not been published, we must adhere to its legal existence and the identity of its administrator without extrapolating data categories or decision-making criteria.
13. ACCReD — Automation of centralized consultation of information and data
ACCReD is one of the most revealing tools for understanding administrative screening. Created by a 2017 public decree, it facilitates administrative security investigations by allowing authorized agents to query several police or intelligence databases, depending on the legal basis of the investigation. It can record the identity of the person being checked, the reason for the investigation, whether they are already in certain databases, any additional checks carried out, and the nature of the opinion or decision. The decree specifies that data relating to political, philosophical, or religious opinions can only be processed when essential to the investigation and prohibits selecting a category of people solely on this basis. A computer "hit" is not supposed to automatically constitute an unfavorable decision: it must be considered within the context of the investigation, verified, and assessed in light of the function or access involved.
14. EASP — administrative investigations related to public safety
EASP is a public database implemented by the National Police and the Paris Police Prefecture to facilitate certain administrative investigations. Its purpose is, in particular, to retain data from previous investigations relating to the same individual, including those concerning national security. The text defines these as data revealing activities likely to harm the fundamental interests of the Nation or to constitute a terrorist threat to those interests. EASP is therefore neither a secondary criminal record nor a general list of opinions: it is a security assessment tool used when the administration needs to evaluate the compatibility of behavior with a sensitive function, mission, access, or authorization.
15. PASP — prevention of threats to public safety
PASP is the French National Police's system for collecting, storing, and analyzing information concerning individuals, legal entities, or groups whose individual or collective activity indicates that they may pose a threat to public safety or national security. The text specifically mentions terrorism, attacks on the integrity of the territory or the institutions of the Republic, and certain forms of collective violence. Because its purpose is preventative, PASP can investigate a situation before a conviction is obtained. This does not mean that every political protest or demonstration results in registration: the security objective and legal requirements must be respected, and security data is specifically identified within the system.
16. GIPASP — Information Management and Prevention of Threats to Public Safety
GIPASP is the gendarmerie's counterpart to this public safety intelligence approach. Implemented by the Directorate General of the National Gendarmerie, it collects, stores, and analyzes information on individuals, legal entities, or groups whose activities may threaten public safety or national security. Like PASP, it specifically targets terrorist activities, attacks on institutions or territorial integrity, and certain forms of collective violence. The coexistence of PASP and GIPASP reflects the French territorial organization: the police and the gendarmerie have their own channels and tools, with rules designed to ensure effective information sharing while maintaining traceability and clearly defined responsibilities.
17. TREX — DGSE external intelligence
TREX is a DGSE (General Directorate for External Security) processing system dedicated to foreign intelligence. Its detailed authorization document is not published, but its existence is explicitly recognized by the Internal Security Code and by the CNIL (French Data Protection Authority) in the procedure for the indirect exercise of certain rights. TREX illustrates the core business of the DGSE: structuring and using information gathered in the context of foreign intelligence to produce knowledge useful to the authorities. Here again, the public can know the name of the processing system, the responsible department, and the control mechanism without accessing the data mapping, sources, or methods that would make it a tool exploitable by an adversary.
18. HOPSYWEB — be careful not to stigmatize psychiatry
HOPSYWEB primarily concerns the administrative monitoring of individuals receiving involuntary psychiatric care. It is not, in itself, a terrorist database. However, the law provides for the linking of identity data with the FSPRT (File of Individuals Subject to Terrorism Prevention) for a precisely defined security purpose. When a match appears in the database, a "verification" procedure must confirm that it is indeed the same person before any further communication. The decree prohibits the recording of this information in another database based on a simple, unverified match. This system is sensitive and must be presented with rigor: suffering from psychiatric disorders or having been hospitalized without consent does not in any way mean being radicalized or dangerous; the system simply aims to prevent serious security information already known in the FSPRT from being ignored when a specific administrative situation arises.
19. RINC — digital information collection for cyber defence
RINC is the French Armed Forces General Staff's processing system entitled "Digital Information Collection for Cyber Defense Purposes." Its detailed decree is not published. However, its public name clearly situates its function within the field of military cyber defense. In an environment where cyberattacks can involve espionage, sabotage, conflict preparation, or hybrid operations, the armed forces need to process technical information to understand the threat and protect systems. The details of sources, indicators, infrastructure, and exploitation methods fall precisely within the type of information that a responsible citizen should not attempt to reconstruct.
20. NATALI — nationality and naturalization, for its sole purpose of state security
NATALI is an excellent example of a general administrative system, only a portion of which is relevant to national security. Created in 2023, it notably allows for the digitization and processing of procedures for acquiring, reinstating, losing, or forfeiting French nationality, as well as certain appeals. The system is therefore not an "intelligence file" in the ordinary sense. However, some data used in these procedures may have a security dimension and thus fall under the specialized regime of Article R. 841-2. This distinction illustrates why the list of twenty-five should never be interpreted as a uniform list of secret databases.
21. Prison intelligence file
The Prison Intelligence File is implemented within the framework of the prison administration's intelligence gathering. Its detailed authorization decree is not published. The National Prison Intelligence Service belongs to the second tier of intelligence services and works specifically on terrorist threats, radicalization, violence, organized crime, and risks that develop or persist in detention. The file is therefore used within the specific context of prison intelligence, but the data categories, retention periods, and detailed access rules are protected. Again, the existence of the file is public; its operating procedures are not.
22. Processing system for optimizing data and information of nuclear interest
This data processing, authorized by a 2024 public decree, concerns the security of nuclear facilities, structures, installations, and activities. It allows, in particular, the collection and analysis of information relating to events revealing a risk to nuclear safety, the management of certain access authorization procedures, and the monitoring of security clearances related to national defense secrecy in this area. The decree publicly describes several categories of data, including identity, contact information, professional status, certain risk factors, and the indication of potential presence in multiple data processing systems. Only data relevant to national security falls under the specialized regime. The highly regulated nature of the nuclear sector explains the depth of the screening: a nuclear power plant, a sensitive site, or a nuclear activity cannot operate with the same access rules as an ordinary administrative building.
23. FiMPA — Administrative policing measures and fundamental interests of the Nation
FiMPA is the "File of Administrative Police Measures Contributing to the Prevention of Threats to the Fundamental Interests of the Nation." Its official title is public, but the decree detailing its operation has not been published. The name, however, allows us to understand its general logic: to organize information related to certain administrative police measures designed to prevent threats to fundamental interests. We must resist the temptation to deduce a precise list of measures or data from this; the distinction between what the title reveals and what the decree protects is an integral part of the legal framework.
24. PERS-CM — DGSE personnel management
PERS-CM is a personnel management system used by the DGSE (General Directorate for External Security). Its inclusion on the list is particularly instructive: not all security files target "suspects." A secret service must also recruit, manage, authorize, assign, and protect its own agents. The personnel of a service that handles classified information and conducts sensitive missions are themselves a security risk. Since the detailed document is not published, it would be inappropriate to speculate on the nature of all the checks or data; however, the existence of PERS-CM serves as a reminder that the security of a service also begins with the security of its human resources.
25. ACCReD MINDEF — the Department of Defense security screening
Document level: ESTABLISHED. Decree No. 2026-124 of February 24, 2026 creates the processing; Decree No. 2026-125 of the same day adds it to Article R. 841-2 of the Internal Security Code.
ACCReD MINDEF is the most recent system added to the list, created by a decree of February 24, 2026, and implemented by the DRSD (Directorate of Military Intelligence and Security). It aims to facilitate certain administrative security investigations under the purview of the Ministry of the Armed Forces and to utilize the information gathered in this context. The decree provides for access to several systems based on authorizations and the need to know. It authorizes, when essential, the processing of certain sensitive data, including political, philosophical, or religious opinions, while prohibiting the selection of a category of individuals solely on this basis. It also mandates individual authorizations and data retention rules. ACCReD MINDEF demonstrates how the screening process has become more specialized: the defense sector now possesses its own tool, aligned with the imperatives of counter-intelligence and security clearance.
|
WHAT THE LIST OF 25 DOESN'T SAY This list does not mean that a citizen can be registered indiscriminately in twenty-five databases. Each processing operation has a data controller, a purpose, a scope, and a legal framework. Some decrees are public and very detailed; others are not published because they concern national sovereignty. In several cases, only a subset of data "related to national security" falls under specialized legal jurisdiction. The right question is therefore never "am I in the galaxy of files?", but "what processing operation, for what purpose, by which authority, and with what rights?" |
|---|
Administrative investigations, security clearances and career consequences
The issue becomes particularly relevant when a citizen works for the State, a sensitive company, critical infrastructure, or applies for security clearance. The Internal Security Code allows for administrative investigations to be conducted before certain recruitment, assignment, authorization, approval, or clearance decisions. These investigations can also take place when, after recruitment, an individual's behavior appears to be incompatible with the position or access in question. The objective is not to punish a crime, but rather to assess a security risk. This explains the existence of ACCReD, EASP, and, since 2026, ACCReD MINDEF.
Let's take a hypothetical example. An agent has access to classified information and maintains repeated, unexplained, and covert contact with an individual identified elsewhere as a potential liaison for a foreign intelligence service. No criminal offense is necessarily established. However, the administration may legitimately question whether the security clearance remains compatible with the risk. A security investigation may lead to checks, an unfavorable assessment, a refusal, or a withdrawal of access, depending on applicable law. This decision is not automatically a disciplinary sanction: it aims to protect a secret, a site, or a mission.
Discipline follows a different path. A civil servant who fails to fulfill their professional obligations may be subject to disciplinary proceedings with the corresponding safeguards and graduated sanctions. Intelligence may provide information that triggers or informs proceedings, but it does not replace disciplinary rules. Thus, the statement that "absent a clear threat, ethical oversight always takes precedence and no personal data file can exist without proven misconduct" is too absolute. Intelligence gathering is precisely preventative and can process information relevant to security purposes before any conviction or professional misconduct, subject to legal conditions and controls.
Political opinions, activism, “entryism”: where is the line?
This is probably the most sensitive point. A democracy cannot transform criticism of the government, voting, legal activism, union involvement, religious opinions, or personal philosophies into independent criteria for suspicion. Several public texts governing ACCReD, PASP, GIPASP, or ACCReD MINDEF authorize, under certain circumstances, the processing of sensitive data such as political, philosophical, or religious opinions when strictly necessary for the intended purpose; but they prohibit selecting a particular category of people solely on the basis of this data. In other words, an opinion is not supposed to become, in itself, a shortcut to being considered dangerous.
The difficulty arises when public opinion is embedded within a set of facts related to a security objective: preparation of serious violence, reconstitution of a dissolved group, foreign interference, terrorism, sabotage, espionage, or organized crime. In this case, intelligence services may focus on networks and individuals not because they are "left-wing," "right-wing," religious, environmentalist, nationalist, or revolutionary, but because objective behaviors may constitute a threat defined by law. This distinction is easier said than done; this is precisely why oversight authorities and the courts are essential.
The CNCTR's 2025 report provides a very topical example: the commission indicates that the question has arisen of monitoring individuals on the grounds that they are pursuing a strategy of "infiltration." This concept is politically and legally sensitive because an influence strategy can fall within the scope of ordinary democratic debate or, in other circumstances, be linked to foreign interference, a violent organization, or an attack on institutions. The proportionality test must therefore focus on the facts and the legal purpose, not on a mere ideological label.
The term "entryism" thus calls for a specific discipline. In political discourse, it can refer to the strategy of a faction seeking to exert influence from within an organization, administration, or professional environment. This political definition does not automatically translate into a legal qualification. A network of civil servants legally sharing convictions and preparing proposals can be described politically as a form of organized influence, but this alone is not sufficient to establish a threat to national security. For an intelligence service to be able to employ such techniques, it is necessary to consider the service's competencies, a legal purpose, and the requirements of necessity and proportionality.
The CNCTR, however, demonstrates that the boundary is not purely theoretical. Its 2025 report indicates that it encountered requests in which the notion of "infiltration" was invoked. The controller's question is then not whether the term is politically alarming, but whether the described actions truly correspond to one of the purposes stipulated by law. Ordinary democratic influence, legal activism, or the pursuit of political change cannot be conveniently equated with an attack on institutions; conversely, an organization that clandestinely uses administrative positions to serve a foreign power, prepare acts of violence, or divert the State from its duties could fall under a completely different legal framework.
The test must remain central to the analysis: what facts? what purpose? what jurisdiction? what proportionality? This method protects both the state against genuinely hostile strategies and citizens against the transformation of political disagreement into a security concern. It is particularly important during election periods, when the temptation to too hastily label a network as "infiltration," or conversely, to trivialize any use of the administrative apparatus, can become very strong.
Can someone be entered in a file without having committed an offense?
Yes, in certain cases and under certain conditions. It's even a logical consequence of the preventive nature of intelligence gathering and administrative investigations. The PASP and GIPASP, for example, focus on activities indicating that a person or group may pose a threat to public safety or national security. An administrative investigation can be opened to assess the compatibility of behavior with a sensitive position even if no crime has been committed. The FPR itself contains categories that don't all correspond to convicted individuals. Therefore, saying "he hasn't done anything, so legally there can't be any personally identifiable information" is incorrect.
But the opposite statement would be equally false: “the State can register anyone for any reason.” Each data processing operation has a purpose, categories of data, rules for access and retention, and files concerning national sovereignty remain subject to controls even when their creation is not public. The general principle of data protection requires that the information processed be adequate, relevant, and proportionate to the purposes. The Council of State, in its specialized formation, can order the rectification or erasure of irregular data. The democratic question, therefore, concerns less the abstract existence of files than the quality of the criteria, the updating of the data, and the proportionality and effectiveness of the controls.
Finally, it is important to distinguish between "being mentioned" and "being the target." In an intelligence file, a name may appear as a contact, witness, interlocutor, leader of an organization, potential victim, person approached by a foreign intelligence service, or simply as a piece of background information. Modern intelligence processing involves relationships between entities and events. Therefore, the presence of a name alone does not allow one to deduce the person's status within the intelligence service's analysis without knowing the context.
How can you find out if you are in an intelligence file?
For several police files, citizens can exercise their rights with the responsible ministry and then, depending on the case, contact the CNIL (French Data Protection Authority). For intelligence service files such as CRISTINA, FSPRT, TREX, SIRCID, DOREMI, or GESTEREXT, the CNIL outlines a specific procedure: the request is submitted to the CNIL so that it can carry out the checks required by law. The result is not comparable to simply opening one's personal administrative file. The reason is simple: systematically confirming to an individual whether or not they are known to a service could reveal surveillance, a source, an operational interest, or the absence of such an interest—information that could be exploited by a hostile party.
The dispute may then fall under the jurisdiction of the specialized division of the Council of State. Its members are authorized to access national defense secrets and can consult documents that the applicant cannot see. The procedure is therefore asymmetrical compared to a standard administrative trial, but it allows the judge to effectively control what secrecy prevents from being publicly disclosed. If no illegality is found, the decision does not inform the applicant whether or not they are included in the file. If an illegality is discovered, the judge can order the rectification or erasure of data, the destruction of illegally collected information, or, depending on the circumstances, award compensation for damages.
This mechanism may seem frustrating because it deprives citizens of the binary answer they often seek: "Am I on file, yes or no?" But this is the compromise chosen by the legislature: citizens do not necessarily receive confidential information, but an independent authority and an authorized judge can verify that the administration is complying with the law. Decisions rendered as recently as 2026 show that this specialized body is indeed handling disputes concerning the FPR, PASP, EASP, or GESTEREXT.
Sources: CNIL, “Requesting a check on a police or intelligence file”; Council of State, presentation of the specialized training and decisions 2026.
Who oversees the intelligence services?
French intelligence oversight is fragmented because no single institution could reasonably control interceptions, files, secret budgets, the legality of decisions, service management, and public policy simultaneously. The CNCTR (National Commission for the Control of Intelligence Techniques) oversees intelligence techniques before their implementation and after authorization. The CNIL (National Commission for Information Technology and Civil Liberties) intervenes regarding data protection and the exercise of certain rights concerning files. The specialized division of the Council of State legally oversees techniques and processing related to national security. The Parliamentary Delegation for Intelligence monitors government actions and evaluates public policy. The Special Funds Oversight Commission examines the use of special appropriations. The Inspectorate of Intelligence Services conducts inspection, audit, and evaluation missions. The Court of Auditors can also audit certain management aspects.
This system has a unique democratic characteristic: part of the oversight is public, while another part is secret but institutionalized. Members of the Directorate of Public Security (DPR) operate under national defense secrecy; judges in the specialized division can consult classified documents; the National Commission for the Control of Security Interceptions (CNCTR) visits government departments and audits their systems; and the National Commission for Information Technology and Civil Liberties (CNIL) can conduct checks that citizens could not perform themselves. Secrecy, therefore, is not intended to be a legal vacuum. It shifts oversight to institutions to which the law grants access that the public does not have.
This does not mean the system is perfect. The CNCTR itself raised concerns in 2026 about insufficient staffing and several unresolved legal issues, notably data exchanges between French and foreign intelligence services and so-called sovereignty files. The DPR regularly issues recommendations on resources, coordination, threat transformation, and budgetary accuracy. Democratic transparency, therefore, does not consist of asserting that "everything is controlled" once and for all; it consists of examining what the controllers themselves say about their limitations and strengthening their capabilities as the system becomes more complex.
What secrecy protects — and what it must not prevent
Why not publish everything? Because an intelligence service whose sources, technical criteria, vulnerabilities, access methods to databases, operational thresholds, or the identities of its agents are known to the adversary would lose some of its effectiveness. Secrecy protects individuals, sources, foreign cooperation, methods, ongoing operations, and the ability to anticipate threats. The DPR itself cannot publish information on ongoing operations, operational methods, or certain exchanges with foreign intelligence services. The law therefore deliberately creates areas where even legitimate public curiosity cannot be fully satisfied.
But the argument of secrecy cannot be used to render the very existence of a public policy invisible. Citizens can be informed about the general missions, legal objectives, main services, some budgets and staffing levels, oversight authorities, the existence of numerous data processing operations, the public texts that govern them, and the available appeal procedures. They can also read the reports of the CNCTR and the DPR, which contain genuine criticisms. It is precisely this public layer that this article brings together. Providing information about it does not weaken intelligence services; on the contrary, it allows us to understand why certain information must remain secret and to demand that those who access it be properly vetted.
The democratic risk works both ways. Too much transparency can expose operations, agents, and capabilities. Too much secrecy can fuel speculation, stifle budgetary debate, and make it difficult to detect abuses. The French system is therefore based on a compromise: public disclosure of objectives, the legal framework, and numerous controls; protection of operational details and certain data processing activities; and the possibility for authorized authorities and judges to access what the public does not see. It is this compromise that must be constantly evaluated, rather than choosing between absolute naiveté and widespread suspicion.
Quick glossary: fifteen concepts not to confuse
After dozens of pages of acronyms and mechanisms, a glossary is helpful for quickly finding the correct definition. It doesn't replace the preceding explanations but helps avoid the most common oversimplifications in public discourse.
| Term | Concise definition |
|---|---|
| S file | Category of report in the Wanted Persons File (FPR) linked to state security; it does not signify conviction or arrest warrant. |
| FPR | File of wanted or reported persons, comprising several categories with different purposes. |
| FSPRT | Processing of reports for the prevention of radicalization of a terrorist nature; registration does not imply conviction. |
| CRISTINA | The DGSI's sovereign processing of data, the regulatory details of which are not public; its existence and legal framework are established. |
| PASP | Police handling of the prevention of threats to public safety, for the purposes defined by the texts. |
| GIPASP | The gendarmerie's approach follows a similar logic of prevention and information. |
| EASP | Processing system relating to administrative investigations connected with public safety. |
| ACCReD | A tool that automates, in certain administrative investigations, the consultation of several authorized processing systems. |
| “White note” | The return of information protects, in particular, the origin of the information; it can be discussed before a judge and does not have the value of automatic truth. |
| Administrative investigation | A preliminary or in-career check designed to assess a person’s compatibility with a sensitive function, access, or clearance. |
| Security clearance | A decision authorizing access to certain classified information; its withdrawal is not necessarily a disciplinary sanction. |
| CNIL | Data protection authority, which intervenes in particular in the exercise of rights over certain police and intelligence files. |
| CNCTR | Independent authority responsible for overseeing intelligence techniques as provided for in the Internal Security Code. |
| DPR | Parliamentary Delegation for Intelligence, parliamentary oversight body for public intelligence policy. |
| Specialized division of the Council of State | Judge authorized to hear disputes involving certain files and techniques covered by national defense secrecy. |
And abroad? Six architectures for the same question
Comparing foreign intelligence systems helps us understand what aspects of intelligence are almost universal necessities and what depends on political choice. All states seek to understand the intentions of adversaries, detect espionage, prevent terrorism, protect their secrets, monitor certain domestic threats, and exploit technical data. However, the separation between domestic and foreign intelligence, the role of the police, the protection of political activity, the authorization of interceptions, citizen access to files, and the strength of parliamentary or judicial oversight vary considerably.
The following comparison deliberately remains at the public level. It describes neither clandestine procedures, nor sources, nor vulnerabilities, nor operational details. It relies on laws, official service websites, oversight institutions, and a few historical episodes whose importance the states themselves have acknowledged. The aim is not to draw up a simplistic ranking of "good" and "bad" services, but to show how each regime organizes the relationship between efficiency, secrecy, politics, and freedoms.
United States: a vast community, a domestic intelligence service deeply marked by its history
The United States does not possess a single service comparable to the DGSI or the DGSE. Its Intelligence Community is a coalition of eighteen entities, including the Office of the Director of National Intelligence (ODNI), the CIA, the NSA, the DIA, the FBI, the National Geospatial-Intelligence Agency, the National Reconnaissance Office, components of several government departments, and the intelligence services of the armed forces. This size reflects both the country's global power and the extreme specialization of its functions: foreign human intelligence, interceptions and cryptography, imagery, military intelligence, domestic counterintelligence, and economic and energy intelligence.
The CIA is primarily focused on foreign operations; the FBI, on the other hand, combines a federal police function with a central role in counterintelligence and national security within the United States. This is a significant difference from France: the institutional boundary between intelligence and criminal investigation is less clear when the same organization possesses both criminal and national security powers. The FBI now presents itself as the leading federal agency for domestic counterintelligence and coordinates numerous federal, state, and sectoral partners.
American history explains the particular sensitivity of political profiling. Between 1956 and 1971, the FBI's COINTELPRO program initially targeted the American Communist Party and later various groups, including the Socialist Workers Party, the Ku Klux Klan, the Black Panthers, and New Left movements. The FBI itself now acknowledges that the program was sharply and legitimately criticized for violating First Amendment rights. This history has profoundly influenced contemporary oversight of so-called sensitive investigations and the debate surrounding the surveillance of political or religious activities.
The modern framework does not mean that an activity protected by the First Amendment precludes all investigation. Rather, it requires that an intelligence or investigative activity have a legitimate national security or law enforcement purpose and not be based solely on the lawful exercise of constitutional rights. FBI operational guides emphasize the particular care to be taken when investigations risk affecting freedom of speech, association, religion, or the press. This is the American equivalent of a question France faces with "entryism": how to investigate a real risk without transforming a legitimate political activity into an independent cause for suspicion?
For foreign intelligence techniques conducted in the United States or targeting individuals protected by U.S. law, the Foreign Intelligence Surveillance Court, established by the Foreign Intelligence Surveillance Act of 1978, plays a central role. This specialized court, composed of eleven federal judges, reviews applications for authorization of electronic surveillance, searches, and other foreign intelligence measures. For the Section 702 program, it does not individually approve each foreign target but reviews the certifications and procedures for targeting, minimizing, and interrogation in accordance with the law and the Fourth Amendment.
Political control is also powerful on paper. The Senate Select Committee on Intelligence, created in 1976 after major revelations of intelligence abuses, exercises continuous oversight of the Intelligence Community, its programs, and its operations. The House of Representatives has its own specialized committee. This structure stems from a historical observation: in a democratic state, the effectiveness of secrecy depends on a small number of institutions having access to what the public cannot see.
The American model, however, remains marked by a persistent tension between national security and mass data collection. The Snowden revelations about the NSA, the debates surrounding Section 702, the National Security Letters, and searches of incidentally collected data have shown that the issue is never definitively resolved. The American system thus offers an instructive contrast: it possesses some of the most powerful technical tools in the world, but also a culture of litigation, parliamentary reports, declassification, and access to archives that sometimes allows, decades later, for the very precise documentation of past abuses.
Primary sources: ODNI and Senate Select Committee on Intelligence; Foreign Intelligence Surveillance Court; FBI, Counterintelligence and COINTELPRO archives; Department of Justice, Attorney General’s Guidelines for Domestic FBI Operations.
Germany: “Militant democracy” and a domestic service designed as an early warning system
Germany probably presents the most interesting European model when considering politics and intelligence. The trauma of the Weimar Republic and the Nazi takeover led the Federal Republic to develop the concept of "militant democracy" or "democracy capable of defending itself." The Federal Office for the Protection of the Constitution (BfV) and its counterparts in the Länder (states) are specifically tasked with identifying efforts directed against the free democratic constitutional order, the security of the Federation or the Länder, as well as certain espionage or interference activities.
The BfV (Federal Office for the Protection of the Constitution) publicly emphasizes a point reminiscent of the philosophy of French intelligence: it works upstream of the police, before a concrete danger or offense necessarily occurs. It describes itself as an early warning system. But it simultaneously asserts that its mission is not "to spy on opinions": the target must be an undertaking or activity directed against protected fundamental principles. This distinction does not eliminate controversy, as labeling a movement as suspicious or extremist can have major political consequences, but it legally situates the debate at the level of objectives and behaviors rather than mere opinion.
Foreign intelligence falls under the purview of the Federal Intelligence Service (BND), while the Military Intelligence Service (MAD) is responsible for protection and counter-espionage in the military sphere. The German structure thus mirrors the French separation of powers between domestic, foreign, and defense matters, while simultaneously giving the Federal Intelligence Service (BfV) a particularly strong constitutional identity: its explicit purpose is the protection of democratic order against those who would seek to exploit freedoms to abolish those same freedoms.
Parliamentary oversight is organized around the Parliamentary Oversight Panel (PKGr), the Bundestag's parliamentary control panel. The federal government must report to the panel on the general activities of government departments and on operations of particular importance; the panel can request additional information. The Bundestag also has a permanent departmental administration specializing in oversight of government departments, thus institutionalizing ongoing parliamentary expertise rather than entrusting the matter to elected officials without their own resources.
Infringements of the confidentiality of correspondence and telecommunications are subject to a specific mechanism: the G10 Commission. This commission decides on the necessity and admissibility of restrictions under Article 10 of the Basic Law. The model is interesting because the authorization and oversight of an intrusive measure are not solely the responsibility of the executive branch. As in France with the CNCTR, the existence of a specialized body reduces the risk that an immediate political imperative will be the sole arbiter of the necessity of surveillance.
Germany thus demonstrates that a state can publicly acknowledge the observation of certain political or ideological movements without claiming to be compiling information on public opinion. However, this structure rests on a demanding constitutional standard, extensive litigation, and ongoing oversight. This is precisely what explains why the phrase "intelligence should never interfere in politics" would be unrealistic: certain political projects may aim for the violent or authoritarian destruction of the constitutional order. The real question is what evidence and criteria allow us to distinguish this case from ordinary democratic opposition.
Main sources: Bundesamt für Verfassungsschutz, public FAQ; Deutscher Bundestag, Parliamentary Oversight Panel and G 10 Commission; Bundesnachrichtendienst.
Italy: a system refocused around the Prime Minister after the 2007 reform
Italy profoundly reformed its intelligence apparatus with Law No. 124 of August 3, 2007. The current system, called Sistema di informazione per la sicurezza della Repubblica, places political responsibility at the top of the executive: the President of the Council of Ministers sets the guidelines, can delegate certain functions to a delegated authority and relies on the Comitato interministeriale per la sicurezza della Repubblica (CISR) for major security guidelines.
The Department of Information Security (DIS) coordinates the system. It receives information and analyses, facilitates exchanges, monitors agency activity, and has inspection functions. Two operational agencies form the core of the system: AISE, Agenzia informazioni e sicurezza esterna, which focuses on threats from abroad and on Italy’s political, military, economic, scientific and industrial interests; and AISI, Agenzia informazioni e sicurezza interna, which is responsible for internal security, protection of democratic institutions, counter-espionage on national territory, and criminal or terrorist threats within its remit.
The Italian division of powers is therefore based less on the ministry to which the threat is attached than on its territorial origin. The law also provides for cooperation mechanisms when a case crosses the border between domestic and foreign affairs. This organization aims to reduce the institutional rivalries that have historically characterized the Italian services and to give the DIS a coordinating role comparable, in some respects, to that of the French national intelligence and counter-terrorism coordination.
Parliamentary oversight is exercised by COPASIR, the Parliamentary Committee for the Security of the Republic. The official website of the Italian system presents it as the body responsible for verifying that intelligence activities are carried out in accordance with the Constitution and the law, and solely in the interest of the Republic and its institutions. Its composition, drawn from both houses of parliament, and the tradition of entrusting its chairmanship to the opposition, aim to create a credible political counterweight in an area where the governing majority naturally holds the lion's share of information.
The comparison with France is illuminating: both systems have a distinction between domestic and foreign intelligence, a level of coordination, protected secrecy, and specialized parliamentary oversight. However, Italy has chosen to place AISE, AISI, and DIS in a chain very directly centered on the Prime Minister's office, whereas the French services remain attached to several ministries and coordinated at the presidential and governmental levels. In both cases, the democratic question is the same: the executive branch sets intelligence priorities, but it must not be able to transform the services into tools of political competition.
Italy’s 20th-century history, marked by political violence, terrorism, clandestine networks, and numerous controversies surrounding the former intelligence services, partly explains the importance the 2007 reform placed on clarifying responsibilities, inspection, and parliamentary oversight. Here again, the lesson is not that a new law will definitively eliminate all risk of abuse; it is that the traceability of political accountability and the existence of an identified oversight body are essential conditions for secrecy to remain compatible with democracy.
Main sources: Sistema di informazione per la security della Repubblica; Italian Law No. 124/2007; official DIS, AISE, AISI and COPASIR pages.
United Kingdom: MI5, MI6, GCHQ and the "double lock" of intrusive powers
The United Kingdom has a clear structure: MI5, officially the Security Service, focuses on threats to national security within the UK; the Secret Intelligence Service, better known as MI6, gathers intelligence abroad; and GCHQ is the main intelligence service for signals intelligence, data, and cybersecurity. This structure is reminiscent of France, although GCHQ plays a particularly important role in the British digital ecosystem and in the Five Eyes cooperation.
MI5 publicly details the main categories of techniques it can employ: clandestine human sources, surveillance and targeted monitoring, communications interception, communications data, massive personal data sets, intrusive surveillance, and clandestine access to equipment. This publicity is interesting: it doesn't reveal how a specific operation is carried out, but it allows citizens to understand the nature of the capabilities the law has granted to the service.
The current framework is based in particular on the Investigatory Powers Act 2016, amended in 2024. For many intrusive warrants, authorization follows the "double lock" mechanism: a minister decides that the measure is necessary and proportionate, and then a Judicial Commissioner must approve it. For certain wiretaps targeting members of legislative assemblies, a strengthened "triple lock" mechanism adds the intervention of the Prime Minister. The principle is institutionally remarkable: the political authority assumes responsibility for the security decision, but a specialized magistrate then verifies its legality and proportionality before it takes effect in the specified cases.
The Investigatory Powers Commissioner and the Judicial Commissioners ensure independent oversight of the use of these powers, employing inspectors, legal and technical expertise, and conducting audits. The United Kingdom also has the Investigatory Powers Tribunal, a specialized court to which individuals who believe they have been victims of the unlawful use of secret techniques can appeal. This is a useful difference to compare with the specialized division of the French Council of State: both countries have established legal avenues adapted to the fact that disputes sometimes concern elements that the claimant cannot fully know.
Parliamentary oversight falls under the purview of the Intelligence and Security Committee of Parliament (ISC). This statutory committee oversees, in particular, the policies, expenditures, administration, and certain operations of MI5, MI6, and GCHQ, as well as other components of the security community. Its members have access to classified information, giving it a function comparable to the French DPR. The committee itself regularly reiterates that the effectiveness of oversight depends on the quality and speed with which the executive branch provides it with information.
The British case also illustrates a significant evolution in modern intelligence: the shift from traditional personal files to "bulk personal datasets." Intelligence services may require large datasets containing numerous individuals who are not themselves targets, in order to search for specific relationships or clues. The democratic question is therefore no longer simply "Am I on file?", but also "In which datasets might my information be found, who can access them, according to what rules, and with what level of traceability?"
Main sources: MI5, “How We Work” and legal framework; SIS/MI6, “What We Do”; GCHQ, legal framework; Investigatory Powers Commissioner; Intelligence and Security Committee of Parliament.
Russia: a highly centralized system, involving the SVR, FSB, military intelligence, and interceptions.
The Russian system cannot be interpreted as a simple institutional variant of the French model. The SVR, the Foreign Intelligence Service, gathers and processes information on the capabilities, actions, plans, and intentions of foreign states, organizations, and individuals, and provides intelligence to the highest authorities. Military intelligence falls under the purview of the Ministry of Defense, generally referred to in public discourse by its historical name, the GRU. Domestically, the FSB possesses very broad powers in the areas of counter-espionage, terrorism, security, border protection, certain forms of crime, and information security.
The Russian Foreign Intelligence Service Law places the system's overall management under the authority of the President of the Russian Federation. The law formally establishes principles of legality, respect for rights and freedoms, and oversight by the President and the Federal Assembly. It also provides for budgetary control and oversight of compliance with the law by the Prosecutor's Office. However, the same framework removes certain information—notably the identity of sources, organizational structure, methods, and resources—from the ordinary scope of Prosecutor's Office oversight. The scope of secrecy is therefore legally very broad.
For operations within the territory, the law on operational search activities governs the covert measures that can be used by various agencies. Certain measures that infringe on the secrecy of communications or privacy must, by law, be based on a judicial order. However, the technical operation of the SORM interception system has long been the subject of strong criticism. In the 2015 case of Roman Zakharov v. Russia, the Grand Chamber of the European Court of Human Rights held that the Russian framework for covert interceptions did not provide sufficient safeguards against arbitrariness and did not allow for an effective remedy under Article 8 of the Convention.
This decision must be placed in its historical context: it concerns the framework examined in 2015, and Russia has since ceased to be a member of the Council of Europe. Nevertheless, it remains a key document for understanding the difference between the formal existence of judicial authorization and the effectiveness of the monitoring. A court can intervene in theory, but if the service has technically direct access, if individuals have virtually no way of knowing they have been monitored, and if the traceability of the monitoring is weak, the safeguard may lose some of its real-world impact.
The relationship between politics and intelligence is also different in a regime where executive power is much more centralized and where the pluralist political space is more limited. It would be methodologically misleading to adopt French categories—legal opposition, administrative neutrality, independent authority, pluralist parliamentary oversight—and assume that they produce the same institutional effects. For a fair comparison, it is therefore necessary to distinguish the controls provided for in Russian legislation from the question of their independence, their public transparency, and the concrete possibilities for challenging them.
Russia is finally demonstrating that modern intelligence is inseparable from telecommunications. Monitoring an individual no longer necessarily involves a "file" in the traditional sense: metadata, communications, technical identifiers, geolocation, and digital relationships can generate far richer knowledge than a paper file. This transformation is universal; what varies from one country to another is the extent of the powers and the strength of the checks and balances.
Main sources: SVR, Federal Law “on Foreign Intelligence”; FSB, Federal Law on Operational Research Activity; ECHR, Roman Zakharov v. Russia, 2015.
China: Intelligence, state security, and a much more integrated mobilization of society
China presents yet another architecture. The 2017 National Intelligence Law describes a “centralized and unified” system under the leadership of the Central National Security Agency, while the Central Military Commission directs military intelligence. The law identifies state security agencies, public security intelligence agencies, and military intelligence agencies as intelligence bodies. The Ministry of State Security (MSS) is the most prominent actor in state security, counterintelligence, and civilian intelligence.
The difference with Western systems is very clear in Article 7 of the national intelligence law: every organization and every citizen must, in accordance with the law, support, assist, and cooperate with national intelligence work and maintain secrecy about what they know about it. The same text provides for the protection of individuals and organizations that provide this assistance. This general obligation to cooperate is much more explicit and broader than the ordinary obligations found in the French, German, or British frameworks.
The 2017 law simultaneously affirms that intelligence work must respect the law, human rights, and the legitimate rights and interests of individuals and organizations. It provides for internal oversight and security mechanisms and authorizes citizens and organizations to report abuses of power or other illegal conduct by intelligence agencies. It would therefore be inaccurate to claim that Chinese law contains no provisions for oversight. The essential difference lies rather in the organization of power: the system is under centralized political leadership, and the public mechanisms for external oversight are not comparable to those of a National Commission for the Control of Intelligence Techniques (NCCIT), a Federal Intelligence Service (FIS) judge, a Public Security Bureau (PSB), or an Independent Security Council (ISC) with similar institutional autonomy.
The 2023 revision of the Counter-Espionage Act broadened and modernized the scope of targeted activities. It now covers not only state secrets and intelligence in the traditional sense, but also certain documents, data, materials, or objects related to national security and interests, as well as cyberattacks or intrusions targeting state bodies, entities holding secrets, or critical infrastructure. State security agencies have significant investigative powers, while organizations and citizens have obligations to provide support and prevent such attacks.
This architecture often fosters the idea abroad that every Chinese company or citizen is automatically an “intelligence agent.” This conclusion is overly simplistic. A legal obligation to cooperate creates a risk and an institutional difference that foreign partners must take into account, but it does not allow us to label every person or company as an operational conduit for the Ministry of Security. As with political profiling in France, prudence lies in distinguishing between a potentially broad legal framework and proof that a specific individual has actually been mobilized.
Another common misconception must also be avoided: Chinese intelligence is not simply the "social credit" system, and social credit is not a vast, single intelligence database that politically rates every citizen. Intelligence, public security, administrative data management, censorship, policing, and reputation or compliance mechanisms are all interconnected but legally distinct entities. Merging them into a single narrative would prevent us from understanding the true power of the system.
For a French reader, the contrast is instructive. The Chinese model favors a broad conception of national security and centralized coordination in which the boundary between the state, the party, public institutions, and social mobilization is less rigid. The French, German, American, and British models rely more on the fragmentation of powers, pluralism of oversight, and the possibility of legal challenges before bodies separate from the executive branch. These are not merely differences in technique: they are differences in the political philosophy of intelligence.
Main sources: National People’s Congress of China, National Intelligence Law of 2017; Law on Counter-Espionage revised in 2023; Chinese official texts on state security organs.
What international comparison reveals
Despite very different traditions, six constants emerge. First, all states separate foreign intelligence, domestic security, and military intelligence to varying degrees. Second, political information is never entirely separate from intelligence, as espionage, interference, violent extremism, and threats against institutions necessarily have a political dimension. Third, no serious system can function solely after a crime has been committed: intelligence is preventive. Fourth, the digital age shifts the debate from personal files to large datasets and the possibilities for cross-referencing. Fifth, secrecy is universal. Finally, democratic differences lie primarily in the definition of objectives, the plurality of oversight bodies, the independence of the judiciary, and the possibility of effective redress.
Perhaps the most useful parallel with the old intelligence files is this: all states retain a memory. The question, therefore, is not to dream of intelligence without files, databases, or notes; such an intelligence system would be incapable of cross-referencing signals over time. The question is who can enter a name into this memory, on what basis, who can access it, how long the information remains, how an error is corrected, and what authority outside the service can verify the entire system. It is precisely in these areas that the safeguards—or their weaknesses—lie.
| Country | Dominant architecture | Characteristic public oversight |
|---|---|---|
| France | DGSE / DGSI / DRM / DRSD / DNRED / TRACFIN + second circle | CNCTR, CNIL, DPR, Council of State, budgetary and judicial oversight |
| United States | 18-element Intelligence Community; CIA external intelligence; FBI domestic counterintelligence; NSA signals intelligence | FISC/FISCR for certain surveillance activities, congressional committees, inspectors general, courts |
| Germany | BND external intelligence; BfV/LfV domestic constitutional protection; MAD defence | Bundestag PKGr, G 10 Commission, constitutional and administrative courts |
| Italy | DIS coordination; AISE external intelligence; AISI domestic intelligence | COPASIR, responsibility of the President of the Council, inspection of the DIS and jurisdictional control |
| United Kingdom | MI6 external intelligence; MI5 domestic intelligence; GCHQ signals/cyber | Ministerial double lock + Judicial Commissioner, IPCO, IPT, ISC |
| Russia | SVR external intelligence; FSB internal security/counterintelligence; military intelligence | Formal presidential, parliamentary, judicial and public prosecutorial controls; more limited transparency and appeals |
| China | Centralized leadership; MSS/state security, public security and military intelligence | Internal supervision and legally mandated complaint mechanisms; external public oversight less comparable to Western pluralist models |
International comparison ultimately compels us to be wary of words. “Political surveillance” can refer to the abuse of a service against an opponent, but also to the lawful observation of a violent movement or a network manipulated by a foreign power. “Profiling” can refer to an operational base, an archive, a report, a mass dataset, or a simple contextual mention. And “control” can exist in a text without offering the same degree of independence everywhere. Any serious comparison must therefore examine the actual institutions behind the labels.
Conclusion: a democracy must know what it can know
The title of this report deliberately links politics and intelligence. Not because the services are meant to arbitrate political debate, but because their legitimacy hinges precisely on this boundary: protecting institutions without protecting a government against its opponents, detecting interference without criminalizing democratic influence, documenting a threat without transforming an opinion into a crime. It is in this balance that the maturity of a state governed by the rule of law is measured.
After examining this structure, one thing becomes clear: French intelligence is far more extensive than the image of a "secret service" and far more legalistic than popular culture suggests. It comprises six specialized services with very different functions, a second circle, coordinating bodies, thousands of agents, billions of euros in funding, techniques subject to authorization, dozens of data processing systems, administrative investigations, sovereignty files, parliamentary oversight, independent authorities, and a specially empowered judge. The system forms a continuum ranging from the prevention of a terrorist attack to the protection of a laboratory, from the detection of a criminal network to the screening of a nuclear clearance.
The second lesson is that we must avoid shortcuts. “Fiché S” does not mean “terrorist.” FSPRT does not mean “convicted.” An intelligence report is not automatically criminal evidence. An administrative inquiry is not a disciplinary sanction. Being mentioned in a file does not mean being the target of surveillance. CRISTINA is not a database whose criteria are all publicly available, and it is therefore incorrect to invent its thresholds. PASP and GIPASP are preventative tools whose use must remain linked to legal objectives. HOPSYWEB is not a terrorist file. NATALI is not a secret intelligence file, even if some of its data may be of interest to national security. Each term refers to a specific mechanism.
The third lesson is perhaps the most democratic: secrecy does not negate the right to know; it shifts its boundaries. We do not need to know the name of an agent involved in an operation, a human source, a non-public technical method, or the detailed structure of a sovereign database. On the other hand, we can legitimately ask what purposes the law authorizes, how many people are being monitored, which bodies oversee the technologies, what databases exist, how to appeal, and how much the public policy costs. It is this information that allows citizens to understand what they are funding without demanding that the state publish information that would render their protection impossible.
This is ultimately the reason for this article. The questions that arose following my previous report on the "Phrygians" demonstrated a very healthy curiosity: many readers feel that intelligence has become central in a world marked by terrorism, hybrid warfare, economic espionage, drug trafficking, cyberattacks, and foreign interference, but they are unfamiliar with its institutions. The answer should be neither "don't ask questions, it's secret," nor "anything goes in the shadows." It should be: here is what the law makes public, here is what the regulators tell us, here are the avenues of appeal, and here is also the boundary beyond which secrecy is legitimate. A mature democracy does not demand that its intelligence services be transparent about their operations; it demands that they be secret where they must be and accountable wherever they operate.
Main public sources
The references below were prioritized because they are institutional, legal, or issued by oversight authorities. They allow readers to continue verifying the information without relying on journalistic interpretations. This version adds a historical section on the General Intelligence Directorate (RG), the indirect right of access, “white notes,” and the debate over political profiling. When the decree governing a file is not published, that lack of publication is itself a legal fact: this report does not attempt to circumvent it and limits itself to what can be established from public texts.
1. Internal Security Code — Article L. 811-3: Purposes of intelligence — open
2. Internal Security Code — Article R. 811-1: six specialized services — open
3. Internal Security Code — Article R. 841-2: 25 processing operations or parts of processing operations relevant to national security — open
4. Internal Security Code — EASP, article R. 236-1 — open
5. Internal Security Code — PASP, article R. 236-11 — open
6. Internal Security Code — GIPASP, article R. 236-21 — open
7. ACCReD Decree of August 3, 2017 — open
8. HOPSYWEB Decree / involuntary psychiatric care of May 23, 2018 — open
9. NATALI Decree of February 3, 2023 — open
10. Decree of April 8, 2024 — processing and optimization of data and information of nuclear interest — open
11. DGSI — Our missions — open
12. DGSI — Counter-espionage and protection of France's interests — open
13. DGSI — Protection of economic and scientific assets — open
14. DGSE — Our missions — open
15. DGSE — Who are we? — open
16. DRSD — Intelligence to protect: defence counter-intelligence — open
17. DRM — 2025 presentation brochure — open
18. French Customs — 2024 annual report, presentation of the DNRED — open
19. TRACFIN — Presentation and missions — open
20. CNCTR — 2025 Activity Report, published June 25, 2026 — open
21. Parliamentary Delegation for Intelligence — 2025 public report, Volume I — open
22. National Assembly — presentation of the Parliamentary Delegation for Intelligence — open
23. CNIL — Requesting a check on a police or intelligence file — open
24. Council of State — Specialized division: control of files relevant to national security — open
25. Council of State — Oversight of intelligence techniques — open
26. Council of State — Decision No. 502995 of April 10, 2026 (EASP, PASP, GESTEREXT) — open
27. Council of State — Decision No. 511283 of June 5, 2026 (FPR, PASP, EASP) — open
28. Decree No. 91-1051 of October 14, 1991, on the files of the General Intelligence Directorate — open
29. CNIL — Deliberation No. 91-083 of September 24, 1991 on the files of the General Intelligence Directorate — open
30. CNIL — 1990 Activity Report, indirect right of access and RG files — open
31. CNIL — 1991 Activity Report, right of access and disclosure of RG files — open
32. CNIL — 2000 Activity Report, General Intelligence files and indirect access — open
33. National Assembly — Commission of Inquiry into the National Front's DPS, report no. 1622, 1999 — open
34. National Assembly — Hearing of Jean-Pierre Pochon, Director of the General Intelligence Directorate at the Paris Police Prefecture, March 2, 1999 — open
35. National Assembly — Information Report No. 1548 on police files, 2009 — open
36. Council of State — decisions of 24 December 2021 relating to PASP and GIPASP files — and — open / open
37. CNIL — Publication of decrees relating to PASP, GIPASP and EASP files — open
38. National Police — National Directorate of Territorial Intelligence (DNRT) — open
39. National Assembly — Information report describing the use of white notes in administrative surveillance measures — open
40. Council of State — Decision No. 491089 of November 4, 2024, on the insufficient precision of a white note and the role of the judge — open
41. Paris Administrative Court of Appeal — Decision of April 2, 2026, No. 25PA00635, insufficiently precise “white note” — open
42. General Civil Service Code — freedom of opinion, Articles L. 111-1 to L. 111-5 — open
43. General Civil Service Code — general obligations, Articles L. 121-1 to L. 121-11 — open
44. Service-Public.fr — duties of reserve, discretion, neutrality and professional secrecy — open
45. Le Monde — June 5, 2026, first public description of the “Phrygians” and the size then reported — open
46. CNCTR — 2025 Activity Report, Technical Control and the Problem of “Entryism” — open
47. Decree No. 2026-124 of February 24, 2026 creating ACCReD MINDEF — open
48. Decree No. 2026-125 of February 24, 2026, amending Article R. 841-2 of the Internal Security Code — open
49. United States — Senate Select Committee on Intelligence, Intelligence Community Elements — open
50. United States — Foreign Intelligence Surveillance Court, role and procedures — open
51. United States — Senate Select Committee on Intelligence, oversight mission — open
52. United States — FBI Vault, COINTELPRO and historic recognition of First Amendment violations — open
53. United States — FBI, Domestic Investigations and Operations Guide (2024 version published in the Vault) — open
54. Germany — BfV, FAQ on the protection of the Constitution and the early warning role — open
55. Germany — Bundestag, intelligence oversight bodies: PKGr and G10 Commission — open
56. Italy — Sistema di informazione per la sicurezza della Repubblica, official architecture — open
57. Italy — Law No. 124/2007 and the missions of DIS, AISE and AISI — open
58. United Kingdom — MI5, legal framework, powers and oversight — open
59. United Kingdom — SIS/MI6, missions and legal framework — open
60. United Kingdom — GCHQ, legal framework — open
61. United Kingdom — Intelligence and Security Committee of Parliament, oversight and remedies — open
62. Russia — SVR, Federal Law on Foreign Intelligence — open
63. Russia — FSB, Federal Law on Operational-Search Activity — open
64. Russia — European Court of Human Rights, Roman Zakharov v. Russia, 2015 — open
65. China — National People’s Congress, National Intelligence Law (2017) — open
66. China — National People’s Congress, revised Counter-Espionage Law (2023) — open
END OF REPORT

