Data Protection and Privacy 2025

FRANCE Law and Practice Contributed by: Frédéric Sardain and Claire Allavena, Jeantet

GDPR’s Broad Applicability The GDPR is the cornerstone. It applies to any processing of personal data by an organisation within the EU, regardless of the organisation’s location. This means IoT services operating in or targeting French users fall under GDPR’s scope, regardless of where the service provider is based. French National Laws While the GDPR sets the baseline, France may likely have specific national laws that further detail or specify certain aspects of data protec - tion within the IoT context. To this end, France has enacted a law to secure and regulate the digital space (the Law No 2024-449 of 21 May 2024 aimed at securing and regulating the digital space) in anticipation of the Data Act’s obliga - tions. For example, the law sets out interopera - bility, portability and functional equivalence obli - gations for cloud computing service providers. 3.3 Rights and Obligations Under Applicable Data Regulation In France, the use of IoT entails specific obli - gations for organisations operating in this field. Thus, some key aspects of data protection rel - evant to IoT can be highlighted. Data minimisation and purpose limitation: IoT devices often collect vast amounts of personal data. Data protection and privacy laws man - date that only necessary data be collected for specified, explicit, and legitimate purposes. This requires careful design and implementation of IoT systems to avoid excessive data collection. Consent: For IoT devices, obtaining meaning - ful consent where appropriate can be challeng - ing due to the complexity of the technology and the variety of data collected. This often requires

particularly for reasons of competition, innova - tion, or public interest. The Data Act also addresses the issue of indus - trial data sharing, which is particularly important for industrial IoT. It aims to encourage the shar - ing of this data to promote innovation and the competitiveness of European businesses. In short, the Data Act represents a significant change in the regulation of data generated by connected objects. It aims to empower users, encourage competition and innovation, and create a fairer and more open data ecosystem. Its impact on the IoT will be substantial in the medium term, requiring significant adaptations from manufacturers and application developers. Moreover, the Cybersecurity Act and the Cyber Resilience Act (which will be applicable, in part, in December 2027), both pieces of EU legisla - tion, have significant implications for the Inter - net of Things (IoT) since the Cybersecurity Act establishes a framework for managing cyberse - curity risks at the infrastructure level, indirectly affecting IoT, while the Cyber Resilience Act directly addresses the security of IoT products themselves. 3.2 Interaction of Data Regulation and Data Protection The interplay between data regulation on IoT services, such as the Data Act, the Cybersecu - rity Act, and the Cyber Resilience Act, and data protection requirements in France is complex. It is primarily shaped by data protection and pri - vacy laws (where IoT systems process personal data) and may be complemented by French national laws in the future.

131 CHAMBERS.COM

Powered by