Data Protection and Privacy 2025

FRANCE Trends and Developments Contributed by: Prudence Cadio and Lobna Boudiaf, LPA Law

France’s data protection authority, the CNIL, has released new guidelines on AI models, offering a structured approach to compliance with the GDPR. These recommendations provide much- needed clarity amid the increasing complexity of AI governance at both the national and European levels. A risk-based approach to AI and personal data The CNIL recognises the growing interconnec - tion between AI and personal data processing, particularly in machine learning models trained on vast datasets. In its new guidelines, the authority emphasises a risk-based approach, urging AI developers and deployers to assess data protection risks at every stage of the AI life - cycle. This aligns with the principles of privacy by design and by default, ensuring that GDPR compliance is not an afterthought but an integral part of AI system development. A key takeaway from the CNIL’s recommenda - tions is the need to distinguish between personal and non-personal data in AI training datasets. While fully anonymised data falls outside the scope of GDPR, pseudonymised data remains subject to its provisions. The CNIL stresses that AI stakeholders must ensure robust anonymisa - tion techniques or justify the necessity of pro - cessing personal data under an appropriate legal basis. Clarifying the role of AI stakeholders One of the central challenges in AI regulation is identifying responsible parties within the data processing chain. The CNIL provides practical insights into classifying AI developers, deploy - ers, and users as data controllers or processors, depending on their role in determining the pur - poses and means of data processing.

• AI model providers who design and train models on personal data will often be consid - ered data controllers with direct obligations under GDPR. • Companies integrating AI solutions into their services may also qualify as controllers if they influence how the model processes personal data. • Cloud-based AI service providers could act as processors, processing data on behalf of client organisations. These distinctions are crucial, as they define the extent of regulatory responsibility and the nec - essary contractual safeguards between parties involved in AI operations. Managing AI model transparency and data subjects’ rights The CNIL highlights the challenge of ensuring transparency in AI decision-making, particularly for complex models based on machine learning and deep learning. AI systems must be designed to provide meaningful explanations to individu - als affected by automated processing, in line with GDPR’s right to information and right to explanation. The guidelines also stress that AI developers must facilitate data subjects’ rights, including: • the right to access and rectify data used by AI models; • the right to object to automated decision- making; and • the right to deletion, especially in cases where personal data is no longer necessary. To achieve this, the CNIL encourages data gov - ernance mechanisms that ensure traceability of AI decisions and enable users to challenge or correct model outputs when necessary.

141 CHAMBERS.COM

Powered by