DPI16_Banner_300x250 WITH COPY
IAPP-GDPR Web Banners-300x250-FINAL

By Pascale Gelly

Happy Birthday the CNIL: 30 years!

Thirty years ago, the Law of January 6, 1978 on data processing, data files and individual liberties entered into force, giving birth to one of the first data protection authorities in Europe, the Commission Nationale de L'Informatique et des Libertés (CNIL). In celebration, Mr. Alex Türk, current president of the CNIL, took the opportunity to assess the law. He considers it as a robust and creative law, still efficient in protecting the rights of individuals, even if technologies have greatly evolved since its enactment.

The president emphasized that the law dated August 6, 2004 that reinforces the power of control and sanction of the CNIL re-energized the protection of personal data while confirming the legitimacy of the authority. In 2007, the CNIL carried out 164 controls, which is an increase of 20 percent over the previous year. Forty percent of these controls were carried out as a result of complaints by individuals against the concerned data controllers.

The president wished again for an increase of budget, which is lower than the budget of most of its European counterparts, and for closer cooperation among data protection authorities to give rise to "a universal right to privacy." The new French government has already agreed to the appointment of 15 new employees and to an increase of budget in 2008.

The CNIL will play a prominent role on the international scene this year. Mr. Türk was appointed chairman of the G29 (Article 29 Working Party). The CNIL will also co-organize with its German counterpart the International Conference of Data Protection Commissioners next fall (Oct 15-17).

Biometrics: CNIL sets the conditions for devices storing fingerprint data in a database and grants authorization for new types of technology

The Commission Nationale de L'Informatique et des Libertés (CNIL) has repeatedly expressed concerns about the use of biometrics, which is subject to its prior authorization. Devices where fingerprint data (algorithm) are stored on an individual media held by the concerned individual were more easily authorized than devices involving the storage of such data in a central database.

The CNIL has recently stated the conditions that systems with a central repository must meet to be authorized:

  • the system must control the access of a limited number of people to a specifically limited zone representing a major stake, going beyond the mere interest of the data controller, such as the protection of the physical integrity of people, of goods, or premises, or of sensitive information;
  • the measure must be proportionate; the CNIL challenges the process to check if there is no more adequate process to reach the purpose of the data controller, such as devices storing fingerprint data on an individual medium;
  • trustworthy security measures must be implemented; data controllers must provide the French Authority with detailed documentation explaining the technical characteristics of the biometric process and how authentication/ identification is ensured, and;
  • individuals must receive appropriate notice, which must include information about the purposes of the data processing, the recipients or categories of recipients of the data, and the rights of access and rectification to the data including how to exercise them. Notice can be provided in a short memo describing the functioning of the device.

Besides, after a careful review of the technical aspects of two types of unusual biometrics technologies, the CNIL has granted specific authorizations to a system implemented by Michelin based on voice recognition, and to systems based on the recognition of the veins in fingers, which the CNIL recognized as being a technology without tracks.

A code of conduct for employment Web sites

The Employment Agency has issued a code of conduct to improve the practices of employment Web sites. The code, called "charte net-emploi," addresses the obligation of notification to the CNIL, of security and confidentiality, and of non-discrimination. Major actors of the employment sector have adhered to this code, such as Monster, Vediorbis and Adecco.

French companies concerned about the transfer of personal data to the USA for litigation purposes

Increasingly, French companies receive requests from U.S.-based companies to transfer the content of hard drives or email of France-based employees in order to handle litigations. In investigating the requests on behalf of French companies, the CNIL identified four different transfer scenarios:

  • the so called "litigation hold" or "litigation freeze," where data is transferred just in case a litigation may occur;
  • pre-trial discovery (and the development of a software industry to organize fishing expeditions);
  • injunctions by U.S. authorities (e.g. Department of Justice requests under the foreign Corrupt Practices Act);
  • retention of information for fear of being sanctioned for having deleted information to prevent ongoing investigations.

The CNIL indicated that these transfers are contrary to the provisions of the French Data Protection Act relating to notice and consent of individuals, to the proportionality rule and to data transfers outside of the EU. Moreover, some French companies expressed concerns about the protection of trade and industrial secrets.

The CNIL has informed the French government of these practices and will work on the matter in the framework of the Article 29 Working Party to issue guidance.


The working group on offshoring, created by the CNIL, has already visited several countries in Africa to make a first assessment of the situation. They will soon interview representatives from the IT sector, business, government, and trade unions, to pursue their assessment before issuing recommendations at the end of June.

Data retention

The French government is working on a regulation related to the retention of traffic data on the Web. The CNIL has been consulted on the project. Its opinion will be released at the same time as the regulation.

Phone call monitoring
The Employment Chamber of the Supreme Court held that an employee of Canon who had used a company phone line to make personal calls to prohibited numbers during working hours has been rightfully terminated, even though the employee had not been informed of potential controls. The court considered that a mere verification of the detailed phone reports (duration, cost, numbers called from a given station) does not amount to unlawful monitoring for not having been brought to the attention of employees. This approach differs greatly from the approach taken by courts in cases of controls of the use of the Internet or of email systems.

Pascale Gelly is Avocat à la Cour within SCM Lambot Gelly Soyer. She may be reached at pg@pascalegelly.com.


If you want to comment on this post, you need to login.


Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

Latin America Dashboard Digest

A roundup of the top privacy news from Latin America

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Get more News »

Find a KnowledgeNet Chapter Near You

Network and talk privacy at IAPP KnowledgeNet meetings, taking place worldwide.

Women Leading Privacy

Events, volunteer opportunities and more designed to help you give and get career support and expand your network.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

The Training Post—Can’t-Miss Training Updates

Subscribe now to get the latest alerts on training opportunities around the world.

New Web Conferences Added!

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Staff

Get your team up to speed on privacy by bringing IAPP training to your organization.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.

Learn more about IAPP certification »

Get Close-up

Looking for tools and info on a hot topic? Our close-up pages organize it for you in one easy-to-find place.

Where's Your DPA?

Our interactive DPA locator helps you find data protection authorities and summary of law by country.

IAPP Westin Research Center

See the latest original research from the IAPP Westin fellows.

Looking for Certification Study Resources?

Find out what you need to prepare for your exams

More Resources »

GDPR Comprehensive: Spots Going Fast

With the top minds in the field leading this exceptional program, it's no wonder it's filling quickly. Register now to secure your spot.

Be Part of Something Big: Join the Summit

Registration is open for the Global Privacy Summit 2016. Discounted early bird rates available for a short time, register today!

Data Protection Intensive Returns to London

Registration is now open for the IAPP Europe Data Protection Intensive in London. Check out the program!

P.S.R. Call for Speakers Open!

P.S.R. is THE privacy + cloud security event of the year, and you can take a leading role. Propose a session for this year's program.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

Exhibit at an Event

Put your brand in front of the largest gatherings of privacy pros in the world. Learn more.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»