New Privacy Developments in France


Indeed, a lot of changes are taking place in France in terms of data privacy.

First, the Digital Republic Bill, which passed in October 2016 in France initiated a lot of changes for companies and organizations in terms of Privacy. As an example, pursuant to this new Bill,  data subjects have now the right to know how long their data is stored, decide how their data will be used after their death, or request that personal data be deleted without delay when it was collected at a time when data subjects were minors.

Furthermore, sanctions to be taken by the French Data Protection Agency have increased from €150,000 up to €3 Million euros. Companies should know that this new Bill is only an anticipation of the GDPR that will come into force in 2018 in Europe.

Thus, with the Digital Republic Act, France has sent a clear message that it is taking personal data protection very seriously and is keen to establish strong safeguards to protect personal data. Even though the GDPR is going to establish a harmonized data protection regime across Europe, EU member states can adopt additional data protection rules on specific topics, and therefore, country-specific laws will continue to apply meaning that businesses may still need to comply with different national laws when processing personal data across Europe.

Second, there have also been an increased focus given to issues relating to employee monitoring this year in France.

The French Supreme Court continues to sharpen its case law regarding the possibility to monitor employees at the workplace.

Generally, to lawfully monitor an employee under French law, employers have to comply with 3 different steps:

  1. Informing and consulting the employees’ representatives bodies about the contemplated monitoring.  It generally takes 3 months;

  2. Informing the employees of the monitoring;

  3. Filing the monitoring system with the CNIL. This is quite fast as it can be done online.

However, once it is done, employers still have to remain cautious in the way the monitoring is done if they want to be able to take appropriate sanctions against their employees since the French Supreme Court tends to consider that:

In terms of biometry, the French Data Protection Agency (“CNIL”) announced, on September 27, 2016, that it had updated its biometrics doctrine to take into consideration technological changes (meaning that there is no longer a distinction between biometric data processing with trace (e.g. DNA) and biometric data processing without trace (e.g. voice). Now, the CNIL discerns between biometric data processing which enables data subjects to keep the control of their biometric data and ones which do not offer such a protection.

In particular, the CNIL adopted 2 new single authorisations encompassing biometric access control systems in the workplace.

 


© 2025 Proskauer Rose LLP.
National Law Review, Volume VI, Number 351