Customer identity: regain control over access rules and customer data


Managing customer identity is a strategic challenge for companies of all sizes. Between increasing regulatory requirements, the proliferation of channels, and customer expectations for seamless experiences, structuring access and data governance is as much a technical necessity as it is a lever for data sovereignty, business performance, and operational peace of mind.
In 2025, the CNIL issued 83 sanctions totaling nearly 487 million euros—a record. The primary reasons cited included cookie management and insufficient protection of personal data. In December 2025, two organizations were sanctioned for security failures, specifically: weak passwords, faulty authentication, and a lack of abnormal access detection. In its rulings, the CNIL emphasized one point: these rules have been known and communicated for several years. Companies can no longer ignore them, and oversight is intensifying.
These situations are not always the result of negligence; they illustrate the growing complexity of the subject. Between the multiplication of channels (web, mobile, in-store, customer service), the constantly evolving regulatory framework, and the pressure to meet compliance deadlines, even the most diligent teams can find themselves struggling.
The question is not whether you are doing things "right" or "wrong," but rather: do you have the right tools to demonstrate, at any time, who is accessing which data, on which channels, and with what consent? Do you know precisely which customers can be activated, on what basis, and by whom?
It is this level of control and the peace of mind it provides that we will explore in this article.
When customer identity management is not structured, the company exposes itself to major risks. Identifying these risks makes it easier to prioritize and measure your actions.
Customer trust is capital that takes time to build but can be damaged in a matter of hours. According to a Ponemon Institute study, 65% of consumers say they lose trust in a company after a security incident. Even more concerning: 70% state they would stop buying from a brand that has suffered a data breach.
And in the event of an incident, communication is not optional. The GDPR requires notification to the CNIL within 72 hours and, when the risk to individuals is high, direct communication to the affected customers "without undue delay." This communication must describe the nature of the breach in clear terms and indicate the measures taken.
In other words: all potentially impacted customers will be informed. The incident becomes public, sometimes amplified by social media and the press. Managing this crisis communication is a delicate exercise, and it is precisely this type of situation that we aim to avoid.
CNIL sanctions can reach significant amounts: up to 4% of global annual turnover or 20 million euros. But the direct cost of a fine is often just the tip of the iceberg.
Added to this are the direct costs of crisis management: mobilizing internal teams for weeks, hiring forensic experts, specialized lawyers, and crisis communication agencies, as well as supporting victims (information, assistance, monitoring), technical analysis, and corrective measures.
Then come the indirect costs, which are often more long-lasting: customers who do not return, prospects who hesitate, and partners who start to have doubts.
The financial impact of a breach is not measured only in fines; it is also an erosion of trust, which translates directly into lost revenue.
The GDPR has provided a foundational framework since 2018, establishing clear rights for customers: access, rectification, erasure, and portability. However, the regulatory landscape continues to expand.
The AI Act is gradually coming into force, imposing transparency obligations for artificial intelligence systems. The Data Act, applicable since September 2025, regulates data sharing between stakeholders. A company deploying a chatbot that collects customer data must now simultaneously comply with the GDPR, the AI Act, and potentially the Data Act—three texts, three sets of logic, and three compliance timelines.
And audits are on the rise. In 2025, 14 organizations were sanctioned by the CNIL for failing to address requests for access, objection, or deletion. It is no longer just security breaches that create exposure; it is also the inability to respond to customer requests within the required timeframes.
For DPO and legal teams, the challenge is no longer just to "check the boxes" once and for all, but to maintain active compliance and ensure true sovereignty over customer data: knowing where it is, who has access to it, and being able to respond to requests in real time.
Two configurations deserve attention.
Modules integrated into e-commerce platforms often meet initial needs, but their pricing models can evolve as business grows. Some charge per monthly active user, per profile, or per login. As the customer base expands, the bill can skyrocket, following a trajectory that is difficult to manage.
In-house developed solutions offer apparent control but generate recurring costs: daily maintenance, security updates, regulatory monitoring, and evolving authentication standards.
Added to this is the challenge of scalability: a solution designed for one channel and one market must be able to adapt as the business evolves—new channels, new markets, new brands. However, an in-house architecture designed for a specific context is not always built to handle this increasing complexity. Without a dedicated team, the risk is ending up with a solution that "works" but remains difficult to keep up to date regarding security, compliance, and usage.
In both cases, a lack of visibility into costs complicates budget decisions and planning.
The risks are identified. But how do you address them?
This is where CIAM (Customer Identity and Access Management) comes in: a dedicated component that centralizes account creation, authentication, and customer preferences across all channels.
Let’s take a look at its main benefits together.
A CIAM can act as a single customer view (SCV), becoming the source of truth for all company systems: CRM, CDP, e-commerce platform, POS system, and customer service. Identity becomes the pivot of the data ecosystem.
This means knowing in real time who is accessing what, from which channel, and with what data. The customer is recognized consistently, whether they are in-store, on the mobile app, on the website, or on the phone with customer service.
This unification is essential in an omnichannel context: customers come from everywhere and expect to be recognized everywhere.
It is also a major challenge for multi-brand groups where the same customer may interact with several of the group's brands.
Recognizing your customer regardless of the entry point means being able to:
Delegating customer identity management to an industry expert significantly lightens this burden: consents (opt-in, opt-out) are centralized and automatically synchronized across all channels.
Every access and every change is tracked. When a customer updates their preferences or closes their account, the update propagates throughout all information systems without manual intervention and without the risk of desynchronization.
The result: a GDPR access or deletion request can be processed in a few clicks, with full traceability. In the event of a regulatory audit, the company has the evidence needed to demonstrate its compliance with confidence.
Responsibility is delegated, and data access is easy and reliable.
Outsourcing customer identity management to a CIAM specialist provides flexibility in three key areas:
The question often comes up: should you develop your own customer identity solution in-house or rely on a specialist? This is the classic "build vs. buy" dilemma, and there is no one-size-fits-all answer. Here are a few criteria to help guide your thinking:
A customer identity solution is not a one-off project. It requires ongoing maintenance: security patches, regulatory updates (GDPR, AI Act, ePrivacy), and evolving authentication standards. The question to ask: do you have the resources to handle this monitoring and these updates?
For some brands, customer authentication accounts for hundreds of thousands, or even over a million, connections per day during peak periods. At this scale, availability becomes a business issue: downtime, even for a few minutes, can lead to abandoned carts and customer dissatisfaction. The question: are you able to ensure optimal service availability and 24/7 support in the event of an incident?
Developing in-house may seem cost-effective at first, but hidden costs add up: time spent, mobilized skills, and technical debt. The question: do you have a clear view of the total cost of ownership over three years compared to an external solution?
For companies operating in Europe, the question of hosting, data sovereignty, and native GDPR compliance can influence the choice. A European provider guarantees that data remains in Europe, without transfers outside the EU; a non-European provider may require more complex contractual arrangements.
Outsourcing to a CIAM specialist also means transferring part of the operational responsibility: security, availability, and regulatory compliance. In the event of an incident, the provider is on the front line, backed by the corresponding contractual commitments. This is a point to include in your assessment.
Every company has its own context, constraints, and priorities. The key is to ask these questions upfront.
To take stock of your customer identity governance, four questions can serve as a guide.
1. Are we able to process a GDPR access or deletion request within the legal thirty-day timeframe, with full traceability?
2. In the event of an incident, can we trace who accessed which data, when, and from which channel?
3. Are we able to recognize a customer regardless of their entry point (web, mobile, store) and adapt their journey accordingly?
4. Have we measured our login conversion rate and identified the friction points during registration or login that are impacting our overall conversion rate?
If any of these answers remain unclear, it might be time to structure your identity governance.
Customer identity management is a strategic priority. Between stricter CNIL controls, a growing stack of regulations, and increasing customer expectations for seamless experiences, it is a challenge that concerns IT and legal teams just as much as e-commerce departments.
Structuring your governance means giving yourself the means to meet these requirements while creating the conditions for a smoother customer experience and regaining sovereignty over your customer data.
The questions raised in this article do not have a single answer. Every company has its own context, existing infrastructure, and priorities. Simply asking them is already a step forward!

Find answers to the most common questions.
Unstructured governance exposes a company to four major risks: damage to brand image in the event of an incident, financial impact beyond CNIL fines, regulatory non-compliance (GDPR, AI Act, Data Act), and loss of cost control.
A CIAM (Customer Identity and Access Management) is a system that centralizes customer identity management: account creation, authentication, and personal data management (updates, preferences, and consents). It allows you to recognize the customer across all channels—web, mobile, store, and customer service—and feed other parts of the IT system with unified data.
An integrated module offers limited omnichannel capabilities and suffers from a high dependency on the platform being used. A CIAM unifies customer identity across all touchpoints, natively integrates GDPR consent management, and offers an open architecture, allowing you to switch e-commerce platforms without starting from scratch on identity.
Choosing a European provider ensures they are directly subject to the GDPR and the requirements of European supervisory authorities. It also means the convenience of working with teams that are easily accessible for day-to-day operations or in the event of an incident, and having points of contact who operate within the same regulatory environment.
CIAM solutions offer a wide range of authentication methods: standard username/password, OTP (one-time codes via email or SMS), social login (Google, Apple, Facebook, PayPal, etc.), biometrics, and passkeys. These authentication factors vary in their resilience to attacks: some, like passwords alone, are more vulnerable to phishing or credential stuffing, while others, such as biometrics or passkeys, offer significantly higher security. The platform allows you to enable or disable these methods based on your needs and desired security level, without requiring complex technical intervention.