FRANCE Law and Practice Contributed by: Frédéric Sardain and Claire Allavena, Jeantet
1. Legal and Regulatory Framework 1.1 Overview of Data and Privacy- Related Laws In France, data protection and privacy laws are primarily governed by the General Data Protec - tion Regulation (the “GDPR”) and the French Data Protection Act No. 78-17 of 6 January 1978 as amended by Act No 2018-493 of 20 June 2018 and Ordinance No 2018-1125 of 12 December 2018 (the “FDPA”), hereinafter together “data protection and privacy laws”. GDPR as the baseline: The GDPR serves as the primary legal framework for data protec - tion across the EU, including France. It aims to harmonise data protection standards, ensuring a consistent approach to individual rights and data protection across member states. The FDPA as a Complement: While the GDPR establishes a baseline for data protection, each EU member state has the option to introduce additional provisions through their national laws. In France, the FDPA provides extra protections in specific contexts, addressing particular national concerns or local customs. For example, the FDPA includes specific pro - visions that focus on certain areas not fully addressed by the GDPR, such as genetic and biometric data usage, health data, and data relating to criminal convictions or offences. In conclusion, France’s data protection and pri - vacy landscape is characterised by the interplay between the GDPR and the FDPA. The GDPR provides a harmonised framework that sets min - imum standards for the protection of personal data across the EU, while the FDPA introduces
specific adaptations to address national needs and contexts. 1.2 Regulators In France, the National Commission for Infor - mation Technology and Civil Liberties (“CNIL”) is the primary regulator for data protection and privacy. However, other relevant regulators in the broader context of information technology and digital services include the French Informa - tion Systems Security Agency (“ANSSI”) and the French Regulatory Authority for Electronic Communications, Postal Services and Press Distribution (“ARCEP”). Furthermore, the French Prudential Supervision and Resolution Authority (“ACPR”), which regulates financial institutions, will take into account whether a regulated entity is meeting data privacy standards. The CNIL The CNIL is responsible for overseeing data pro - tection and privacy laws, particularly the enforce - ment of data protection and privacy laws. The CNIL’s main functions are the following: • Supervision: Monitors compliance with data protection and privacy laws by organisations operating in France. • Guidance: Provides advice and guidelines to businesses, public authorities, and individuals on data protection issues. • Complaints: Handles complaints from indi - viduals regarding data protection violations. • Sanctions: Has the authority to conduct audits and investigations and impose sanc - tions such as fines for non-compliance with data protection regulations. • Public awareness: Promotes understanding of data protection rights and responsibilities among the public.
123 CHAMBERS.COM
Powered by FlippingBook