FRANCE Law and Practice Contributed by: Frédéric Sardain and Claire Allavena, Jeantet
integrity. In this regard, the ANSSI published specific guidelines on the security of the IoT. Summary Data regulation related to IoT in France is enforced by the CNIL, where personal data are processed through IoT services. Furthermore, sector-specific regulators like the ARCEP and the ANSSI also play vital roles in overseeing compliance in their respective domains. To date, there is no official regulator in France specifically dedicated to IoT. In France, the use of cookies is mainly gov - erned by the FDPA, the ePrivacy Directive (often referred to as the Cookie Law and which has been transposed into the FDPA), and specific guidelines on cookies issued by the CNIL. Consent Requirements Websites must obtain explicit consent from web users before placing cookies on their devices, except for cookies that are strictly necessary for the website’s functioning. This means that web users must be presented with a clear and affirmative option to accept cookies (opt-in). Web users must be provided with clear infor - mation about the types of cookies used, their purposes, and how long they are stored. Cookies Essential cookies are necessary for the web - site to function correctly (eg, for session man - agement and shopping carts). Consent is not required for these cookies. 4. Sectoral Issues 4.1 Use of Cookies
Non-essential cookies include cookies that track user behaviour for analytics, advertising, and marketing purposes. Consent is required before using these types of cookies. For third-party cookies (eg, those from advertis - ers), the website must obtain web user consent for its own cookies and any cookies placed by third parties. Websites must also display a cookie banner or pop-up that informs users about cookie usage upon their first visit. This banner should include: • clear options for users to accept or reject cookies; and • a link to a detailed cookie policy that explains what cookies are used, their purposes, and how users can manage their preferences. Users must be able to withdraw their consent easily at any time. This should be straightforward and accessible, similar to the process of provid - ing consent. Organisations must keep records of user con - sent and cookie preferences to demonstrate compliance with cookie regulations. Further - more, organisations are encouraged to regu - larly review their use of cookies, ensuring that consent mechanisms function correctly and that users are informed of any changes in cookie policies. Websites must provide the web user with a cookie policy that clearly outlines: • the types of cookies used (eg, first-party vs. third-party cookies); • the purpose of each cookie (eg, functionality, performance, marketing);
133 CHAMBERS.COM
Powered by FlippingBook