Data Protection and Privacy 2025

FRANCE Law and Practice Contributed by: Frédéric Sardain and Claire Allavena, Jeantet

Findings: The company was sanctioned for infractions related to processing personal data for targeted advertising without valid user con - sent. Discord (2022) Background: In November 2022, CNIL sanc - tioned Discord with a EUR800,000 fine. Findings: The company was penalised for sev - eral breaches, including issues with user data retention and password security. TikTok (2022): Background: In December 2022, CNIL fined Tik - Tok EUR5 million for cookie-related violations. Findings: The investigation revealed that TikTok did not allow users to refuse cookies as easily as they could accept them, thus violating French data protection law. These cases demonstrate CNIL’s ongoing vigi - lance in enforcing data protection and privacy laws, particularly paying attention to large tech companies and large-scale data processing practices. 1.5 AI Regulation Recent developments regarding artificial intel - ligence (AI) regulation in France reflect ongoing efforts to ensure that AI technologies are used responsibly and ethically, particularly regarding data protection. EU Artificial Intelligence Act (the “AI Act”) Proposal and Adoption As part of the European Union’s broader approach to AI regulation, France has supported the proposed AI Act. This legislation seeks to classify AI systems based on risk levels (e.g., minimal, limited, high, and unacceptable) and

impose stricter requirements for high-risk appli - cations, particularly those that process personal data. The AI Act has been published on 12 July 2024, and its implementation will take place in stages until 2 August 2027. CNIL’s Implications The CNIL is actively participating in the work currently being carried out by the European Data Protection Board (EDPB) on the relation - ship between the rules applicable to the protec - tion of personal data and the AI Act. The aim of this work is to provide further clarification on the points of articulation while enabling a har - monised interpretation between the CNIL and its European counterparts. Moreover, the CNIL published several guidelines and recommenda - tions on the interplay between data protection and privacy laws and the AI Act. Integration of AI Systems The integration of AI systems in various sectors necessitates firms to ensure compliance with data and privacy laws. Organisations utilising AI must assess how their technologies affect the processing of personal data and implement measures to remain compliant, such as those outlined below. • Data minimisation: AI systems must adhere to the principle of data minimisation, meaning that only data necessary for the specified pur - pose should be collected and processed. • Transparency: Organisations using AI must clearly inform individuals about how their data is being used by AI systems, including the purposes of processing, data retention periods, and the logic behind automated decision-making. • Rights of data subjects: Individuals have the right to access their data, request corrections, object to data processing, and seek the right

126 CHAMBERS.COM

Powered by