On April 23, the French data protection authority, the CNIL (Commission Nationale de l’Informatique et des Libertés), published its annual report for 2012, emphasizing a significant increase in complaints, audits, and sanctions. In this blog post, we review each of these topics addressed by the CNIL’s report.
Tag Archives: CNIL
German Privacy Publication Features Hogan Lovells Piece on Proposed Data Protection Regulation
The German publication, Zeitschrift fur Datenschutz, has just published a piece authored by Christopher Wolf, director of the global Privacy and Information Management practice, entitled “A Critical Time for the EU Data Protection Regulation.” The article highlights issues that have been raised about the proposed Regulation, described as ”real and substantial.” The point of the piece is… Continue Reading
French CNIL Publishes English Language Compliance Guides
France’s data protection authority, the Commission Nationale de l’Informatique et des Libertés (CNIL), released on November 14, 2012 English-language versions of its compliance guides for businesses. The first guide, “Methodology for Privacy Risk Management”, provides a step-by-step guide for identifying risks and prioritising remedial actions. The second guide, “Measures for the Privacy Risk Treatment“, provides practical guidance on… Continue Reading
CNIL’s Annual Report Highlights Right To Be Forgotten and Shortcomings of proposed regulation
CNIL’s recently-released annual report gives insight from France’s authority into sanctions, the right to be forgotten, whistleblowing, and what it believes are several shortcomings in the proposed EU regulation.
CNIL Cloud Guidelines Address Controller vs. Processor Issues
The French CNIL’s new guidelines on cloud computing revisit the tricky question of whether a cloud provider is a data processor or a data controller under French data protection law. The CNIL’s guidelines contain seven recommendations for cloud customers, and a list of recommended contractual clauses. The CNIL points out that when the cloud provider is located in a non-European country “local government authorities can send requests to the provider to have access to the data.”
Blogging from IAPP London: BCRs Key to Accountability and Interoperability
Are BCRs the key to global interoperability? Some think so at the IAPP London conference. This post discusses opinions from conference presenters — will BCRs will become more and more popular as corporations implement new accountability measures, or will they fade under the weight of continued bureaucracy?
CNIL Chief Offers Frank Comments on EU Regulation at Hogan Lovells-Sponsored Gathering in Paris
CNIL, Falque-Pierrotin, ‘data protection’, privacy, Europe, EU, regulation, BCR, accountability, sanctions, interoperability
French Data Protection Authority launches public consultation on cloud computing
The French Data Protection Authority (the Commission Nationale de l’Informatique et des Libertés or CNIL) opened a public consultation on cloud computing, citing the growing significance of the cloud computing market: “already €6 billion at the European level, with a yearly growth of approximately 20%”. The CNIL is focusing on five areas: definition of cloud computing, role of the parties, applicable law, international transfers of data outside the European Union and data security. Public input into the issue is sought by the CNIL, as explained in this blog entry.
French Court of Appeals reject company’s whistleblower system despite CNIL approval
A French Court of Appeals in Caen recently confirmed a lower court’s order for the suspension of a whistleblowing system implemented by French company Benoist Girard, a subsidiary of American group Stryker. The decision comes as a surprise as it rejects the approval of the whistleblower system by French data protection authority (the “CNIL”).
CNIL Cites French Yellow Pages Operator for Illegal Use of Social Media Data
The French CNIL found the French provider of universal telephone directory services “Pages Jaunes” guilty of violating several provisions of the French data protection law due to Pages Jaunes’ collection of personal data in social media sites.
Upcoming EU Cloud Strategy Announced: Application of Local Privacy Laws Remain an Issue, To Be Explored at IAPP Navigate on September 14
An announcement came this week from EC Digital Agenda VP Neelie Kroes of an EU Cloud Strategy (described in this blog entry), for which the former US CIO Vivek Kundra will be an advisor, and it once again raises questions about the application of the EU Directive in the cloud. This is an issue that will be explored through a Moot Court problem at IAPP’s Navigate in Dallas on September 14, also described and shared in this entry.
Privacy v. Anti-Piracy: Content Owners Warned to Supervise Anti-Piracy Monitor to Ensure Privacy
The anti-piracy efforts of the content industry in France recently resulted in a warning from French authorities that, when policing online piracy through use of a third-party contractor, privacy must be respected and enforced.
CNIL Simplifies Formalities for Non-EU Companies Using Data processors in France
The French data protection authority (CNIL) recently simplified the formalities imposed on non-EU companies using data processors in France. While limited in scope as it only relates to processes in the fields of human resources and client and prospects management, the simplification can only be welcomed.
Privacy in France: 2010 review, 2011 perspectives
Lionel de Souza, a Hogan Lovells privacy lawyer in our Paris Office provides a thorough review of 2010 developments in French privacy law and a look ahead to 2011.
French Supreme Court invalidates whistle-blowing code
French Supreme Court invalidates whistle blowing code of conduct because it exceeds scope of CNIL blanket license
French CNIL comments on nanotechnologies
France’s data protection authority contributes to national debate on nanotechnologies. The CNIL recommends “Privacy by Design,” and warns of potential abuses.
French CNIL Issues Data Security Tips
CNIL issues data security recommendations, which are rudimentary compared to ENISA work on the subject