Data Protection and Privacy 2025

FRANCE Trends and Developments Contributed by: Prudence Cadio and Lobna Boudiaf, LPA Law

• consent may be requested before or after permission requests, but the process must remain transparent; and • if a user denies consent, there is no need to request permission unnecessarily. These recommendations aim to empower users while ensuring compliance with privacy regula - tions. Developers and OS providers must work together to strike a balance between functional - ity and privacy protection. The CNIL’s Expansive Interpretation of Personal Data The CNIL has reaffirmed its particularly broad interpretation of the concept of personal data, drawing a clear distinction between personal and anonymous data, in a formal notice addressed to the French company, Qwant. This decision fur - ther destabilises an already fragile legal frame - work, where regulatory authorities and courts continue to adopt diverging interpretations. Qwant’s Position: A Privacy-Centric Search Engine Qwant, a search engine designed to prioritise user privacy, maintained that it did not collect personal data from users conducting searches when displaying advertisements related to their queries. As part of its advertising model, Qwant transmit - ted primarily technical data to Microsoft, includ - ing truncated or hashed IP addresses used to generate an identifier. This data enabled Micro - soft to: • display contextual advertisements relevant to users’ search queries; • count ad impressions; and

• provide supplemental search results when Qwant’s own engine could not return suffi - cient results. The CNIL’s findings: pseudonymisation does not equate to anonymisation Following a detailed technical investigation, the CNIL concluded that the data transmitted could not be classified as anonymous but only as pseudonymous. Furthermore, Qwant failed to disclose in its pri - vacy policy the advertising purpose behind its data transfers to Microsoft, nor did it specify the legal basis for such processing – leading the CNIL to issue a formal reminder of its legal obligations. The legal boundaries of anonymisation, a contested issue At the heart of this case lies a fundamental and long-contested legal question: Can data that uniquely distinguishes an individual – without necessarily allowing for their direct identifica - tion – still be classified as personal data? Data that enables the differentiation of an indi - vidual may be deemed to “relate” to that per - son, thus satisfying one of the core criteria of the GDPR’s definition of personal data. Such processing allows for individualised treatment – such as targeted advertising – even if the per - son’s identity is not immediately discernible. However, whether such data meets the equally essential identifiability criterion remains a matter of legal debate, particularly in light of the evolv - ing jurisprudence of the Court of Justice of the European Union (CJEU). The Court has consist - ently assessed whether an individual’s identity can be reasonably re-established using available means (notably in the Breyer and Scania rulings).

145 CHAMBERS.COM

Powered by