Data Protection and Privacy 2025

FRANCE Law and Practice Contributed by: Frédéric Sardain and Claire Allavena, Jeantet

Special case of data transfers with the USA: Since July 2023, transfers between the USA and the European Union are now governed by the “EU-US Data Privacy Framework.” This frame - work follows the CJEU’s invalidation of the previ - ous adequacy decision (Privacy Shield). If a third country does not have an adequacy decision, organisations may not transfer per - sonal data there unless they provide appropriate safeguards such as: Standard Contractual Clauses (SCCs): Organi - sations can use SCCs, which are pre-approved contract templates provided by the European Commission that outline data protection obliga - tions and rights for parties involved in the data transfer. Binding Corporate Rules (BCRs): Multinational companies can implement BCRs, which are internal policies enforced across their global operations. BCRs must meet specific require - ments and receive approval from relevant data protection authorities. Transfer Risk Assessment (TRA) of Data Importing Jurisdiction In cases where personal data is transferred to jurisdictions without an adequacy decision, organisations must carefully assess the data protection practices of the importing country, as follows. • Evaluating local laws: Organisations must analyse the local data protection laws and practices in the recipient country to determine whether they provide sufficient protection for the transferred data. This includes assessing: (a) the comprehensiveness of privacy laws; (b) the enforcement of privacy rights; and (c) potential government access to data and

surveillance practices. • The impact on data subjects’ rights: Organi - sations should consider how local laws may affect individuals’ rights under data protection and privacy laws. If the imported jurisdiction’s laws pose risks to data subjects’ rights (eg, through excessive government access or lack of recourse), this may prohibit transfers unless additional protections are implement - ed. Furthermore, the CNIL has issued recommenda - tions emphasising the need for a thorough TRA and highlighting the importance of maintaining documentation of the measures taken to ensure compliance during international data transfers. Data subjects should be informed if their data will be transferred to a non-EEA country, par - ticularly if that jurisdiction lacks an adequate decision. This communication should include details about the potential risks and the safe - guards implemented. In summary, international data transfers of per - sonal information from France are regulated rig - orously under data protection and privacy laws, with specific restrictions and requirements for assessing international data importing juris - dictions. Organisations must ensure that any transfers comply with applicable regulations, utilising appropriate safeguards and conduct - ing thorough risk assessments to protect data subjects’ rights. 5.2 Government Notifications and Approvals Government notifications or approvals can be required to apply the “French Blocking Statute” (see section 5.4 Blocking Statutes ).

136 CHAMBERS.COM

Powered by