⚖️
Loi SREN and the ARCOM framework
Article 227-24 of the Criminal Code has long made it an offence to allow minors to access pornographic material, and the loi SREN of 21 May 2024 gave the regulator the tools to act on it. ARCOM has published a binding technical framework for age verification built on double anonymity: the verifier must not learn which site the user visited, and the site must not learn who the user is. Since SREN, ARCOM can order ISP blocking and search-engine delisting administratively, without first obtaining a court decision, and it has used that power. A declared date of birth is not a compliant age check in France.
💳
Payments, VAT and subscription law
French acquirers and the mainstream PSPs - Stripe, PayPal, Lydia, SumUp - exclude adult. Verotel and SegPay are the usual choice for EU-facing projects because they settle in euros and act as merchant of record for EU VAT on digital services; CCBill and Epoch also work. Every EEA card payment needs SCA through 3-D Secure 2. Selling subscriptions to French consumers brings French consumer law with it: pre-ticked boxes are void, the cancellation path must be no harder than the sign-up path, and the three-click termination rule applies to online subscriptions.
🌐
French, and real French
French as the default, written by a native - this market punishes machine translation harder than most, and the tone in this segment is specific. English and Russian versions cover the Paris international audience and the Russian-speaking presence on the Côte d'Azur. Mentions légales, CGV and a privacy policy are mandatory in French under the LCEN and must identify the publisher and the host by name. That is a concrete French requirement, not generic boilerplate you can copy from an English site.
🔐
Hosting and identity data
Hosting in the EU keeps the project inside one legal regime and makes the LCEN host-identification requirement trivial to satisfy. Most operators use an EU entity with hosting in the Netherlands or Germany, and keep age verification entirely with a certified third-party provider so no identity data ever reaches their own infrastructure - which is what double anonymity means in practice. The CNIL takes a firm line on sites performing biometric age estimation themselves, so that is the one component we do not build in-house.