Identity
25/2/2026
12 min

Customer identity: regain control over access rules and customer data

Gestion des règles d’accès et des données pour reprendre la maîtrise de l’identité client
Table of contents
Section Content 1

Managing customer identity is a strategic challenge for companies of all sizes. Between increasing regulatory requirements, the proliferation of channels, and customer expectations for seamless experiences, structuring access and data governance is as much a technical necessity as it is a lever for data sovereignty, business performance, and operational peace of mind.

A context that prompts us to ask the right questions

In 2025, the CNIL issued 83 sanctions totaling nearly 487 million euros—a record. The primary reasons cited included cookie management and insufficient protection of personal data. In December 2025, two organizations were sanctioned for security failures, specifically: weak passwords, faulty authentication, and a lack of abnormal access detection. In its rulings, the CNIL emphasized one point: these rules have been known and communicated for several years. Companies can no longer ignore them, and oversight is intensifying.

These situations are not always the result of negligence; they illustrate the growing complexity of the subject. Between the multiplication of channels (web, mobile, in-store, customer service), the constantly evolving regulatory framework, and the pressure to meet compliance deadlines, even the most diligent teams can find themselves struggling.

The question is not whether you are doing things "right" or "wrong," but rather: do you have the right tools to demonstrate, at any time, who is accessing which data, on which channels, and with what consent? Do you know precisely which customers can be activated, on what basis, and by whom?

It is this level of control and the peace of mind it provides that we will explore in this article.

Why mastering customer identity governance is strategic

When customer identity management is not structured, the company exposes itself to major risks. Identifying these risks makes it easier to prioritize and measure your actions.

Brand image: the first asset affected

Customer trust is capital that takes time to build but can be damaged in a matter of hours. According to a Ponemon Institute study, 65% of consumers say they lose trust in a company after a security incident. Even more concerning: 70% state they would stop buying from a brand that has suffered a data breach.  

And in the event of an incident, communication is not optional. The GDPR requires notification to the CNIL within 72 hours and, when the risk to individuals is high, direct communication to the affected customers "without undue delay." This communication must describe the nature of the breach in clear terms and indicate the measures taken.

In other words: all potentially impacted customers will be informed. The incident becomes public, sometimes amplified by social media and the press. Managing this crisis communication is a delicate exercise, and it is precisely this type of situation that we aim to avoid.

Financial impact: beyond fines

CNIL sanctions can reach significant amounts: up to 4% of global annual turnover or 20 million euros. But the direct cost of a fine is often just the tip of the iceberg.

Added to this are the direct costs of crisis management: mobilizing internal teams for weeks, hiring forensic experts, specialized lawyers, and crisis communication agencies, as well as supporting victims (information, assistance, monitoring), technical analysis, and corrective measures.

Then come the indirect costs, which are often more long-lasting: customers who do not return, prospects who hesitate, and partners who start to have doubts.

The financial impact of a breach is not measured only in fines; it is also an erosion of trust, which translates directly into lost revenue.

The risk of non-compliance: a framework that keeps expanding

The GDPR has provided a foundational framework since 2018, establishing clear rights for customers: access, rectification, erasure, and portability. However, the regulatory landscape continues to expand.

The AI Act is gradually coming into force, imposing transparency obligations for artificial intelligence systems. The Data Act, applicable since September 2025, regulates data sharing between stakeholders. A company deploying a chatbot that collects customer data must now simultaneously comply with the GDPR, the AI Act, and potentially the Data Act—three texts, three sets of logic, and three compliance timelines.

And audits are on the rise. In 2025, 14 organizations were sanctioned by the CNIL for failing to address requests for access, objection, or deletion. It is no longer just security breaches that create exposure; it is also the inability to respond to customer requests within the required timeframes.

For DPO and legal teams, the challenge is no longer just to "check the boxes" once and for all, but to maintain active compliance and ensure true sovereignty over customer data: knowing where it is, who has access to it, and being able to respond to requests in real time.

Cost control: an often underestimated issue

Two configurations deserve attention.

Modules integrated into e-commerce platforms often meet initial needs, but their pricing models can evolve as business grows. Some charge per monthly active user, per profile, or per login. As the customer base expands, the bill can skyrocket, following a trajectory that is difficult to manage.

In-house developed solutions offer apparent control but generate recurring costs: daily maintenance, security updates, regulatory monitoring, and evolving authentication standards.
Added to this is the challenge of scalability: a solution designed for one channel and one market must be able to adapt as the business evolves—new channels, new markets, new brands. However, an in-house architecture designed for a specific context is not always built to handle this increasing complexity. Without a dedicated team, the risk is ending up with a solution that "works" but remains difficult to keep up to date regarding security, compliance, and usage.

In both cases, a lack of visibility into costs complicates budget decisions and planning.

Regaining control: what a CIAM makes possible.

The risks are identified. But how do you address them?

This is where CIAM (Customer Identity and Access Management) comes in: a dedicated component that centralizes account creation, authentication, and customer preferences across all channels.
Let’s take a look at its main benefits together.

More precise: a unified, real-time view

A CIAM can act as a single customer view (SCV), becoming the source of truth for all company systems: CRM, CDP, e-commerce platform, POS system, and customer service. Identity becomes the pivot of the data ecosystem.

This means knowing in real time who is accessing what, from which channel, and with what data. The customer is recognized consistently, whether they are in-store, on the mobile app, on the website, or on the phone with customer service.

This unification is essential in an omnichannel context: customers come from everywhere and expect to be recognized everywhere.

It is also a major challenge for multi-brand groups where the same customer may interact with several of the group's brands.
Recognizing your customer regardless of the entry point means being able to:

  • Simplify login and streamline the purchasing journey
  • Personalize journeys based on history and preferences
  • Adapt the relationship and provide reassurance from the very first interaction
  • Optimize conversion

More compliant: peace of mind every day

Delegating customer identity management to an industry expert significantly lightens this burden: consents (opt-in, opt-out) are centralized and automatically synchronized across all channels.

Every access and every change is tracked. When a customer updates their preferences or closes their account, the update propagates throughout all information systems without manual intervention and without the risk of desynchronization.

The result: a GDPR access or deletion request can be processed in a few clicks, with full traceability. In the event of a regulatory audit, the company has the evidence needed to demonstrate its compliance with confidence.
Responsibility is delegated, and data access is easy and reliable.

More flexible: maintain control over your architecture and costs

Outsourcing customer identity management to a CIAM specialist provides flexibility in three key areas:

  • Architecture: the identity component becomes independent of the e-commerce platform or CMS. In the event of a migration or IT system update, it remains stable—serving as a point of continuity rather than an additional project.
  • Authentication methods: passwords, OTPs, social login, biometrics, passkeys... Options can be activated as needed, without major overhauls. The architecture is based on open standards (OAuth 2.0), ensuring interoperability with your existing ecosystem.
  • Costs: The business model becomes predictable, decoupled from the number of connections or active profiles. The company regains medium-term visibility and can make decisions with peace of mind.

Customer identity management: build or buy?

The question often comes up: should you develop your own customer identity solution in-house or rely on a specialist? This is the classic "build vs. buy" dilemma, and there is no one-size-fits-all answer. Here are a few criteria to help guide your thinking:

Long-term maintenance capacity

A customer identity solution is not a one-off project. It requires ongoing maintenance: security patches, regulatory updates (GDPR, AI Act, ePrivacy), and evolving authentication standards. The question to ask: do you have the resources to handle this monitoring and these updates?

Service criticality and availability

For some brands, customer authentication accounts for hundreds of thousands, or even over a million, connections per day during peak periods. At this scale, availability becomes a business issue: downtime, even for a few minutes, can lead to abandoned carts and customer dissatisfaction. The question: are you able to ensure optimal service availability and 24/7 support in the event of an incident?

Budgetary trade-offs

Developing in-house may seem cost-effective at first, but hidden costs add up: time spent, mobilized skills, and technical debt. The question: do you have a clear view of the total cost of ownership over three years compared to an external solution?

Data localization

For companies operating in Europe, the question of hosting, data sovereignty, and native GDPR compliance can influence the choice. A European provider guarantees that data remains in Europe, without transfers outside the EU; a non-European provider may require more complex contractual arrangements.

Transfer of responsibility

Outsourcing to a CIAM specialist also means transferring part of the operational responsibility: security, availability, and regulatory compliance. In the event of an incident, the provider is on the front line, backed by the corresponding contractual commitments. This is a point to include in your assessment.

Every company has its own context, constraints, and priorities. The key is to ask these questions upfront.

Four questions to assess your maturity

To take stock of your customer identity governance, four questions can serve as a guide.

Compliance / Risk

1. Are we able to process a GDPR access or deletion request within the legal thirty-day timeframe, with full traceability?

2. In the event of an incident, can we trace who accessed which data, when, and from which channel?

Business / Customer experience

3. Are we able to recognize a customer regardless of their entry point (web, mobile, store) and adapt their journey accordingly?

4. Have we measured our login conversion rate and identified the friction points during registration or login that are impacting our overall conversion rate?

If any of these answers remain unclear, it might be time to structure your identity governance.

Customer identity management is a strategic priority. Between stricter CNIL controls, a growing stack of regulations, and increasing customer expectations for seamless experiences, it is a challenge that concerns IT and legal teams just as much as e-commerce departments.

Structuring your governance means giving yourself the means to meet these requirements while creating the conditions for a smoother customer experience and regaining sovereignty over your customer data.

The questions raised in this article do not have a single answer. Every company has its own context, existing infrastructure, and priorities. Simply asking them is already a step forward!  

Homme portant des lunettes, tenant une carte bancaire d'une main, un smartphone de l'autre, concentré.

FAQ — Frequently Asked Questions

Find answers to the most common questions.

What are the risks of poor customer identity management?

Unstructured governance exposes a company to four major risks: damage to brand image in the event of an incident, financial impact beyond CNIL fines, regulatory non-compliance (GDPR, AI Act, Data Act), and loss of cost control.

What is a CIAM?

A CIAM (Customer Identity and Access Management) is a system that centralizes customer identity management: account creation, authentication, and personal data management (updates, preferences, and consents). It allows you to recognize the customer across all channels—web, mobile, store, and customer service—and feed other parts of the IT system with unified data.

What is the difference between a CIAM and an authentication module integrated into a CMS or e-commerce platform?

An integrated module offers limited omnichannel capabilities and suffers from a high dependency on the platform being used. A CIAM unifies customer identity across all touchpoints, natively integrates GDPR consent management, and offers an open architecture, allowing you to switch e-commerce platforms without starting from scratch on identity.

Why choose a European CIAM?

Choosing a European provider ensures they are directly subject to the GDPR and the requirements of European supervisory authorities. It also means the convenience of working with teams that are easily accessible for day-to-day operations or in the event of an incident, and having points of contact who operate within the same regulatory environment.

What authentication methods are available?

CIAM solutions offer a wide range of authentication methods: standard username/password, OTP (one-time codes via email or SMS), social login (Google, Apple, Facebook, PayPal, etc.), biometrics, and passkeys. These authentication factors vary in their resilience to attacks: some, like passwords alone, are more vulnerable to phishing or credential stuffing, while others, such as biometrics or passkeys, offer significantly higher security. The platform allows you to enable or disable these methods based on your needs and desired security level, without requiring complex technical intervention.