Data Protection and Privacy 2025

FRANCE Trends and Developments Contributed by: Prudence Cadio and Lobna Boudiaf, LPA Law

Understanding permissions vs consent Permissions allow apps to access certain device resources (eg, location, contacts, or microphone) but do not necessarily equate to user consent under GDPR and French data protection laws. While permissions control technical access, they do not regulate data use. In some cases, collect - ing explicit user consent is still required. Key recommendations for OS providers CNIL advises operating system (OS) providers to refine permission systems to enhance user control by: • allowing users to grant permissions with vary - ing levels of precision (eg, granting approxi - mate rather than exact location); • limiting permissions to specific files instead of entire media libraries; and • providing time-limited permissions instead of indefinite access. Best practices for app developers App developers must: • choose permissions that align with their appli - cation’s functionality while minimising data access; • clearly differentiate when permission alone is sufficient and when additional user consent is needed; • implement a Consent Management Platform (CMP) when handling data processing that requires explicit consent; and • ensure users understand the connection between permission requests and the actual data processing involved. Balancing permissions and consent Developers should seamlessly integrate permis - sions and consent collection, ensuring users are not confused. CNIL suggests:

even intimate matters. The whistle-blower was particularly alarmed by recordings of disturbing content and raised concerns with supervisors, though it remains unclear how these reports were handled. The complaint also highlights that millions of recordings were collected unintentionally, often without users actively triggering the voice assis - tant. Analysts were reportedly encouraged not to flag recordings as accidental unless absolutely necessary, leading to an exponential increase in the volume of processed voice data. This prac - tice is alleged to be in direct conflict with GDPR, which requires clear and informed consent before personal data is collected and processed. The whistle-blower previously alerted privacy regulators, including the CNIL, criticising what they perceive as a lack of enforcement against major tech firms. Meanwhile, the company in question has defended its practices in the US case, insisting that voice data has never been used for marketing profiles or sold to third par - ties. However, the French complaint argues that the company’s public messaging on privacy protections is misleading, as its products do not necessarily offer the level of data protection claimed. This case underscores the growing tension between AI-powered voice assistants and data privacy regulations, raising critical questions about transparency, user control, and corporate accountability. Summary of CNIL’s recommendations on mobile app permissions The French data protection authority, CNIL, has issued guidelines to help developers create mobile applications that respect user privacy, particularly regarding app permissions.

144 CHAMBERS.COM

Powered by