Data Protection and Privacy 2025

FRANCE Trends and Developments Contributed by: Prudence Cadio and Lobna Boudiaf, LPA Law

The CJEU is set to revisit this issue in the highly anticipated CRU case, where the Advocate Gen - eral’s recent opinion offers crucial insights into the Court’s likely reasoning. The Advocate General’s opinion in the CRU case: a potential shift in the legal framework? In Single Resolution Board (CRU) v European Data Protection Supervisor (EDPS), Advocate General Dean Spielmann has taken a nuanced position on classifying pseudonymised data and its implications for data controllers and proces - sors. The case concerns the CRU’s failure to inform affected shareholders and creditors of a bank’s insolvency about the transfer of their question - naire responses to Deloitte, which had been engaged as an independent auditor. These responses were pseudonymised – names were replaced with alphanumeric identifiers – raising the question of whether Deloitte should be con - sidered a recipient of personal data under the GDPR. Key takeaways from the Advocate General’s opinion are as follows. • Pseudonymisation does not automatically equate to personal data. Referring to Recital 26 of the GDPR, the Advocate General emphasises that data should only be consid - ered personal if it allows for the reasonable identification of the individual concerned. In this case, the robustness of the pseudonymi - sation process should have been assessed to determine whether Deloitte could reasonably re-identify individuals.

• A complex approach to the notion of a “data recipient.” While Deloitte may not have been processing personal data from its own perspective, the Advocate General suggests that it should still be considered a recipi - ent of personal data vis-à-vis the CRU since the data remained personal from the CRU’s standpoint. This reasoning, while intricate, could have significant implications for how data controllers and processors are classified under the GDPR. • The data protection authority bears the burden of proof. The Advocate General also addressed the evidentiary standard for deter- mining whether data is personal, concluding that the CRU had already provided sufficient evidence that Deloitte could not identify indi - viduals. Consequently, the burden shifted to the EDPS to prove otherwise. The CJEU’s forthcoming ruling in the CRU case is likely to shape the evolving landscape of per - sonal data classification, particularly regarding pseudonymisation and the obligations of data controllers and processors. Its decision will be closely watched, as it could redefine fundamen - tal aspects of data protection law in the EU. Conclusion In conclusion, as artificial intelligence reshapes digital environments, France maintains a strong commitment to safeguarding individual privacy, including that of clients. The CNIL plays an active role in developing data protection frameworks that balance innovation with ethical considera - tions. With the regulatory landscape evolving, businesses, developers, and organisations must stay updated on new legal requirements and guidance.

146 CHAMBERS.COM

Powered by