RGPD

I. Introduction

On 20 June 2018, France adopted Act No. 2018-493 on the protection of personal data in order to implement the General Data Protection Regulation (GDPR). This Act revises and consolidates the 1978 Data Protection Act.

The National Commission for Information Technology and Civil Liberties (CNIL), as the national supervisory authority, is responsible for supervising, guiding and enforcing the GDPR and its implementing texts in France. Thus, France has set up a personal data protection system that complies with the requirements of the European Union.

II. Scope of Application

The GDPR implementing regulations in France apply to:

any controller or processor established in France;

any organisation located outside France that offers goods or services to individuals located in France, or that monitors their behaviour in France.

Regardless of where the processing is carried out, as long as it concerns personal data of individuals located in France, the law applies. It covers automated processing as well as non-automated processing contained in a file. Activities of an exclusively personal or domestic nature do not fall within its scope.

III. Principles of Data Processing

Lawfulness, fairness and transparency: all processing must be based on a clear legal basis and be carried out in a transparent manner.

Purpose limitation: data can only be used for specified and legitimate purposes.

Data minimisation: only strictly necessary data should be collected.

Accuracy: data must be accurate and regularly updated.

Storage limitation: data should only be kept for the strictly necessary period, then deleted or anonymised.

Security and confidentiality: appropriate technical and organisational measures must be put in place to prevent any breach, alteration or loss of data.

IV. Rights of Data Subjects

In accordance with the GDPR and French law, individuals have the following rights:

right to information and access;

right to rectification;

right to erasure (right to be forgotten);

right to restriction of processing;

right to data portability;

right to object.

For minors under 15 years of age, the processing of their data requires the consent of a parent or legal guardian, and information must be provided to them in clear and understandable language.

V. Obligations of the Processor

Processors must:

strictly follow the written instructions of the controller;

implement adequate security measures;

assist the controller in fulfilling its obligations, particularly in responding to requests from data subjects;

notify the controller without undue delay of any data breach, which must then inform the CNIL within 72 hours.

Controllers must maintain a record of processing activities and carry out a Data Protection Impact Assessment (DPIA) in case of high risk. Some organisations must also appoint a Data Protection Officer (DPO) and register with the CNIL.

VI. International Data Transfers

Votre panier est vide

Vous possédez un compte ? Connectez-vous pour payer plus vite.

Continuer vos achats

Rechercher