I. Introduction
On June 20, 2018, France adopted Law No. 2018-493 on the protection of personal data, in order to implement the General Data Protection Regulation (GDPR). This law revises and consolidates the 1978 Data Protection Act.
The National Commission for Information Technology and Liberties (CNIL), as the national supervisory authority, is responsible for overseeing, guiding, and enforcing the GDPR and its implementing texts in France. Thus, France has equipped itself with a personal data protection system compliant with the requirements of the European Union.
II. Scope of Application
The GDPR implementing regulations in France apply to:
any data controller or processor established in French territory;
any organization located outside France offering goods or services to individuals located in France, or monitoring their behavior within French territory.
Regardless of where the processing takes place, as long as it concerns personal data of individuals located in France, the law applies. It covers automated processing as well as non-automated processing that is part of a filing system. Activities of an exclusively personal or domestic nature do not fall within its scope.
III. Principles of Data Processing
Lawfulness, fairness, and transparency: all processing must be based on a clear legal basis and be conducted transparently.
Purpose limitation: data can only be used for specified and legitimate purposes.
Data minimization: only strictly necessary data should be collected.
Accuracy: data must be accurate and updated regularly.
Storage limitation: data should only be kept for the strictly necessary period, then deleted or anonymized.
Security and confidentiality: appropriate technical and organizational measures must be put in place to prevent any breach, alteration, or loss of data.
IV. Rights of Data Subjects
In accordance with the GDPR and French law, individuals have the following rights:
Right to information and access;
Right to rectification;
Right to erasure (right to be forgotten);
Right to restriction of processing;
Right to data portability;
Right to object.
For minors under 15 years old, the processing of their data requires the consent of a parent or legal guardian, and information must be provided to them in clear and understandable language.
V. Obligations of the Processor
Processors must:
strictly follow the written instructions of the controller;
implement adequate security measures;
assist the controller in fulfilling its obligations, particularly in responding to data subjects' requests;
notify the controller without undue delay in case of a data breach, which must then inform the CNIL within 72 hours.
Controllers must maintain a record of processing activities and conduct a Data Protection Impact Assessment (DPIA) in cases of high risk. Some organizations must also designate a Data Protection Officer (DPO) and register with the CNIL.
VI. International Data Transfers
When a transfer to a country outside the EU is contemplated, the controller must ensure an adequate level of protection. This can be achieved via:
an adequacy decision by the European Commission;