By Pascale Gelly

Happy Birthday the CNIL: 30 years!

Thirty years ago, the Law of January 6, 1978 on data processing, data files and individual liberties entered into force, giving birth to one of the first data protection authorities in Europe, the Commission Nationale de L'Informatique et des Libertés (CNIL). In celebration, Mr. Alex Türk, current president of the CNIL, took the opportunity to assess the law. He considers it as a robust and creative law, still efficient in protecting the rights of individuals, even if technologies have greatly evolved since its enactment.

The president emphasized that the law dated August 6, 2004 that reinforces the power of control and sanction of the CNIL re-energized the protection of personal data while confirming the legitimacy of the authority. In 2007, the CNIL carried out 164 controls, which is an increase of 20 percent over the previous year. Forty percent of these controls were carried out as a result of complaints by individuals against the concerned data controllers.

The president wished again for an increase of budget, which is lower than the budget of most of its European counterparts, and for closer cooperation among data protection authorities to give rise to "a universal right to privacy." The new French government has already agreed to the appointment of 15 new employees and to an increase of budget in 2008.

The CNIL will play a prominent role on the international scene this year. Mr. Türk was appointed chairman of the G29 (Article 29 Working Party). The CNIL will also co-organize with its German counterpart the International Conference of Data Protection Commissioners next fall (Oct 15-17).

Biometrics: CNIL sets the conditions for devices storing fingerprint data in a database and grants authorization for new types of technology

The Commission Nationale de L'Informatique et des Libertés (CNIL) has repeatedly expressed concerns about the use of biometrics, which is subject to its prior authorization. Devices where fingerprint data (algorithm) are stored on an individual media held by the concerned individual were more easily authorized than devices involving the storage of such data in a central database.

The CNIL has recently stated the conditions that systems with a central repository must meet to be authorized:

  • the system must control the access of a limited number of people to a specifically limited zone representing a major stake, going beyond the mere interest of the data controller, such as the protection of the physical integrity of people, of goods, or premises, or of sensitive information;
  • the measure must be proportionate; the CNIL challenges the process to check if there is no more adequate process to reach the purpose of the data controller, such as devices storing fingerprint data on an individual medium;
  • trustworthy security measures must be implemented; data controllers must provide the French Authority with detailed documentation explaining the technical characteristics of the biometric process and how authentication/ identification is ensured, and;
  • individuals must receive appropriate notice, which must include information about the purposes of the data processing, the recipients or categories of recipients of the data, and the rights of access and rectification to the data including how to exercise them. Notice can be provided in a short memo describing the functioning of the device.

Besides, after a careful review of the technical aspects of two types of unusual biometrics technologies, the CNIL has granted specific authorizations to a system implemented by Michelin based on voice recognition, and to systems based on the recognition of the veins in fingers, which the CNIL recognized as being a technology without tracks.

A code of conduct for employment Web sites

The Employment Agency has issued a code of conduct to improve the practices of employment Web sites. The code, called "charte net-emploi," addresses the obligation of notification to the CNIL, of security and confidentiality, and of non-discrimination. Major actors of the employment sector have adhered to this code, such as Monster, Vediorbis and Adecco.

French companies concerned about the transfer of personal data to the USA for litigation purposes

Increasingly, French companies receive requests from U.S.-based companies to transfer the content of hard drives or email of France-based employees in order to handle litigations. In investigating the requests on behalf of French companies, the CNIL identified four different transfer scenarios:

  • the so called "litigation hold" or "litigation freeze," where data is transferred just in case a litigation may occur;
  • pre-trial discovery (and the development of a software industry to organize fishing expeditions);
  • injunctions by U.S. authorities (e.g. Department of Justice requests under the foreign Corrupt Practices Act);
  • retention of information for fear of being sanctioned for having deleted information to prevent ongoing investigations.

The CNIL indicated that these transfers are contrary to the provisions of the French Data Protection Act relating to notice and consent of individuals, to the proportionality rule and to data transfers outside of the EU. Moreover, some French companies expressed concerns about the protection of trade and industrial secrets.

The CNIL has informed the French government of these practices and will work on the matter in the framework of the Article 29 Working Party to issue guidance.


The working group on offshoring, created by the CNIL, has already visited several countries in Africa to make a first assessment of the situation. They will soon interview representatives from the IT sector, business, government, and trade unions, to pursue their assessment before issuing recommendations at the end of June.

Data retention

The French government is working on a regulation related to the retention of traffic data on the Web. The CNIL has been consulted on the project. Its opinion will be released at the same time as the regulation.

Phone call monitoring
The Employment Chamber of the Supreme Court held that an employee of Canon who had used a company phone line to make personal calls to prohibited numbers during working hours has been rightfully terminated, even though the employee had not been informed of potential controls. The court considered that a mere verification of the detailed phone reports (duration, cost, numbers called from a given station) does not amount to unlawful monitoring for not having been brought to the attention of employees. This approach differs greatly from the approach taken by courts in cases of controls of the use of the Internet or of email systems.

Pascale Gelly is Avocat à la Cour within SCM Lambot Gelly Soyer. She may be reached at pg@pascalegelly.com.


If you want to comment on this post, you need to login.


Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

Latin America Dashboard Digest

A roundup of the top privacy news from Latin America

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Get more News »

IAPP Communities

Meet locally with privacy pros, dive deep into specialized topics or connect over common interests. Find your Community in KnowledgeNet Chapters, Sections and Affinity Groups.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find a KnowledgeNet Chapter Near You

Talk privacy and network with local members at IAPP KnowledgeNet Chapter meetings, taking place worldwide.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

The Privacy Core™ Library Has Evolved

Privacy Core™ e-learning essentials just expanded to include seven new units for marketers. Keep your data safe and your staff in the know!

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

Upcoming Web Conferences

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Team

Get your team up to speed on privacy by bringing IAPP training to your organization.

Let’s Get You DPO Ready

There’s no better time to train than right now! We have all the resources you need to meet the challenges of the GDPR.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

FIP Designation

Recognizing the advanced knowledge and issue-spotting skills a privacy pro must attain in today’s complex world of data privacy.

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.


The IAPP’S CIPP/E and CIPM are the ANSI/ISO-accredited, industry-recognized combination for DPO readiness. Learn more today.

Learn more about IAPP certification »

Are You Ready for the GDPR?

Check out the IAPP's EU Data Protection Reform page for all the tools and resources you need.

IAPP-OneTrust PIA Platform

New U.S. Government Agency privacy impact assessments - free to IAPP members!

IAPP Communities

Meet locally with privacy pros, dive deep into specialized topics or connect over common interests. Find your Community in KnowledgeNet Chapters, Sections and Affinity Groups.

Privacy Vendor List

Find a privacy vendor to meet your needs with our filterable list of global service providers.

More Resources »

Europe Data Protection Intensive 2017

The Intensive is sold out! But cancellations do happen—so hurry and get on the wait list in case more seats become available.

Global Privacy Summit 2017

The world’s premier privacy conference returns with the sharpest minds, unparalleled programs and preeminent networking opportunities.

Canada Privacy Symposium 2017

The Symposium returns to Toronto this spring and registration has opened! Take advantage of Early Bird rates and join your fellow privacy pros for another stellar program.

The Privacy Bar Section Forum 2017

The Privacy Bar Section Forum returns to Washington, DC April 21, delivering renowned keynote speakers and a distinguished panel of legal and privacy experts.

Asia Privacy Forum 2017

The Forum returns to Singapore for exclusive networking and intensive education on data protection trends and challenges in the Asia Pacific region. Call for Speakers open!

Privacy. Security. Risk. 2017

This year, we're bringing P.S.R. to San Diego. The Call for Speakers is now open. Submit today and be a part of something big! Submission deadline: February 26.

Europe Data Protection Congress 2017

European policy debate, multi-level strategic thinking and thought-provoking discussion. The Call for Speakers is open until March 19.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»