FRANCE Law and Practice Contributed by: Véronique Millischer, Léna Sersiron, Eléonore d’Anthonay, Guillaume Nataf, Olivia Chriqui-Guiot, Pauline Celeyron, Damien Berruyer and Nella Picou, Baker McKenzie Paris
8. Data Protection 8.1 Applicable Regulations
In practice, this means that such companies must comply with the core requirements of the GDPR, including having a valid legal basis for process - ing personal data, providing clear and transparent information to individuals, implementing appropriate security measures, respecting data subject rights and complying with the rules governing international data transfers. In addition, where they are not established in the EU, foreign companies may be required to appoint an EU representative and will need to engage with European supervisory authorities. Overall, this extraterritorial framework ensures that foreign and EU-based companies are subject to equivalent data protection standards when they target individuals in France or elsewhere in the EU. 8.3 Role and Authority of the Data Protection Agency In France, the authority responsible for enforcing data protection rules is the National Commission on Informatics and Liberty ( Commission nationale de l ’ informatique et des libertés , or CNIL). The CNIL is an independent administrative author - ity tasked with ensuring the proper application of the GDPR and the French Data Protection Act. Its role is both regulatory and supervisory. On the one hand, it issues guidance, recommendations and practical tools to help organisations understand and comply with their obligations. On the other, it monitors com - pliance through audits and investigations, which may be carried out on-site, remotely, or on the basis of documentary evidence. The CNIL also has significant corrective and enforce - ment powers. It may issue warnings or formal notices, order organisations to bring processing operations into compliance, restrict or suspend certain data pro - cessing activities, and impose administrative fines. In line with the GDPR, these fines can reach up to EUR20 million or 4% of the undertaking’s global annual turno - ver, whichever is higher, depending on the seriousness of the infringement.
France’s data protection framework is primarily based on the EU General Data Protection Regulation (GDPR), which applies directly across all Member States and has extraterritorial scope. The GDPR sets out the core principles governing the processing of personal data, including lawfulness, transparency, purpose limitation, data minimisation and security, as well as detailed obligations for controllers and processors. This framework is complemented at national level by the French Data Protection Act ( Loi informatique et libertés ), as amended, which supplements the GDPR in areas where Member States retain flexibility (eg, certain processing conditions, enforcement proce - dures, and specific rules for public sector or sensitive data processing). Together, these instruments establish a comprehen - sive regime governing the collection, use, storage and transfer of personal data. They apply not only to enti - ties established in France, but also to foreign organi - sations that target individuals in the EU or monitor their behaviour. In line with the GDPR, non-compliance may result in significant administrative fines, which can reach up to 4% of a company’s global annual turnover, depending on the severity of the infringement. 8.2 Geographical Scope EU and French data protection rules have a broad extraterritorial reach, meaning they can apply to for - eign companies even if they have no physical pres - ence in France or the EU. Under the GDPR, these rules apply to any organisa - tion that offers goods or services to individuals locat - ed in the EU, whether or not payment is required, or that monitors the behaviour of individuals within the EU – eg, through tracking or profiling techniques. As a result, a foreign company targeting customers in France – eg, through a website in French, pricing in euros or marketing campaigns directed at EU resi - dents – will typically be subject to the GDPR and, where relevant, to certain provisions of French law.
375 CHAMBERS.COM
Powered by FlippingBook