Data Protection and Privacy 2025

FRANCE Law and Practice Contributed by: Frédéric Sardain and Claire Allavena, Jeantet

to be forgotten. These rights protect individu - als from potential harms associated with AI systems, such as biased decision-making. • Algorithmic accountability: The proposed regulations emphasise accountability mecha - nisms for AI systems, requiring organisa - tions to ensure that their algorithms are fair and transparent and do not perpetuate bias. This includes regular audits of AI systems to evaluate data handling practices and algo - rithm performance. • Security: The security of AI systems remains an obligation in order to guarantee data pro - tection both during system development and in anticipation of its deployment (eg, security measures concerning both the training data and the development and operation of the AI system). • Impact assessments: For high-risk AI sys - tems, conducting Data Protection Impact Assessments (DPIAs) is required to evaluate the risks to personal data and the measures needed to mitigate those risks. Regulations The evolving regulation of AI in France reflects a balance between fostering innovation and ensuring robust data protection. As AI sys - tems increasingly permeate various sectors, the emphasis on ethical considerations, transpar - ency, and individual rights translates into strong safeguards designed to protect personal data. Thus, organisations must navigate these regu - latory landscapes carefully to leverage AI tech - nologies while complying with data protection and privacy laws. 1.6 Interplay Between AI and Data Protection Regulations The AI Act significantly impacts data protection in France by integrating principles of privacy and

ethical governance into the development and deployment of AI technologies. Alignment with Data Protection Principles The AI Act emphasise key principles of data pro - tection, including transparency, accountability, and data minimisation. These principles ensure that AI systems processing personal data are designed and deployed in ways that respect individuals’ rights. Stricter Requirements for High-Risk Applications Under the AI Act, high-risk AI applications (eg, in sectors like healthcare and finance) face rig - orous requirements, including the necessity for risk assessments. Enhanced Transparency Obligations AI systems must provide clear and understand - able information to users regarding how per - sonal data is being processed. This aligns with the transparency obligations of data protection and privacy laws, reinforcing users’ rights to be informed about data usage. Protection Against Bias and Discrimination AI regulations compel developers to consider fairness and non-discrimination. This is particu - larly important in the context of data protection and privacy laws, which require adherence to principles of equality and non-discrimination, minimising the risk of biased algorithms adverse -

ly affecting individuals. National Governance

The CNIL is fully committed to securing com - panies that are innovating in AI in their appli - cation of data protection and privacy laws and promoting AI that respects people’s rights over their data.

127 CHAMBERS.COM

Powered by