On July 7, 2026, the European Data Protection Board (EDPB) adopted a draft of new guidelines on anonymization (“Guidelines”) [1]. These Guidelines aim to update Opinion 05/2014 of the Article 29 Working Party on anonymization techniques, in order to take into account developments “in the legal, privacy, engineering and technological landscapes”....
ReadArchives
- 2026-07-17
- Jeanne BOSSI MALAFOSSE, Guillaume BUHAGIAR
- Personal data
By way of four deliberations dated 19 March 2026, the French data protection authority (CNIL) has updated two of its reference methodologies governing the processing of personal data carried out in the context of health research : MR-001, relating to processing operations carried out in the context of health research requiring the collection...
Read- 2026-03-20
- Jeanne BOSSI MALAFOSSE, Guillaume BUHAGIAR
- Life sciences
On March 4, 2026, Decree No. 2026-153 [6] (“Decree”) was published, defining the procedures under which the Minister of Health may impose financial penalties on publishers of digital health services (services numériques en santé - "DHS") in the absence of a certificate of compliance with the interoperability, ethics, and security standards...
Read- 2026-01-23
- Jeanne BOSSI MALAFOSSE, Guillaume BUHAGIAR
- Personal data
On 8 January 2026, the French data protection authority (CNIL) issued two rulings against Free Mobile [7] and Free [8] (the “Companies”), imposing fines of €27 million and €15 million respectively for various breaches of the General Data Protection Regulation (GDPR). In this case, the Companies were alerted in October 2024 that an attacker had...
ReadOn 27 December 2025, Decree No. 2025-1335 [12] (the “Decree”) was published in the French Official Journal. In particular, this Decree : sets out the arrangements for monitoring and supervising compliance with the periodic certification obligation applicable to healthcare professionals ; specifies the procedures applicable in the event of a...
ReadIn a judgment dated September 4th, 2025 [16] , the Court of Justice of the European Union (CJEU) provided major clarifications regarding the concept of personal data. In this case, the Court was asked to rule, in particular, on the qualification, in terms of the definition of personal data, of comments made by individuals to a controller (the...
ReadOn 9 September, in accordance with the Regulation on artificial intelligence (“AI Act”) [17], the French Ministry of Economy and Finance unveiled the list of national authorities responsible for artificial intelligence and the division of their respective powers [18]. The diagram presented by Bercy distinguishes between the authorities...
ReadIn a ruling dated September 3, 2025 [19] , the General Court of the European Union (“GCEU”) dismissed the appeal brought by the French member of parliament Philippe Latombe, seeking annulment of the “Data Privacy Framework” established by the European Commission’s adequacy decision of July 10, 2023, allowing the transfer of personal data from the...
Read- 2025-07-18
- Jeanne BOSSI MALAFOSSE, Guillaume BUHAGIAR
- Personal data
On 10 July 2025, the code of practice (“Code”) [21] for general purpose artificial intelligence models (“GPAI models”) was published. Provided for in Article 56 of Regulation 2024/1689 on Artificial Intelligence (“AI Act”), the Code forms part of the regulation’s phased implementation and is intended to help GPAI model providers comply with their...
Read- 2025-07-16
- Jeanne BOSSI MALAFOSSE, Guillaume BUHAGIAR
- Personal data
On June 26th, 2025, the French Data Protection Authority (CNIL) announced the launch of the Privacy Auditing of AI Models (PANAME) project — which it will lead and legally frame — with the goal of developing a tool that can test the confidentiality of artificial intelligence models (“AI Model(s)”). This initiative comes against the backdrop of EU...
ReadOn July 1st 2025, the Minister for Health and Access to Care, Yannick Neuder, presented the national strategy for artificial intelligence (AI) and healthcare data [24] ("Strategy") at an exceptional Strategic Committee meeting. Set up to take advantage of the development of AI in the healthcare field (e.g., improving the quality of care,...
Read- 2025-06-24
- Jeanne BOSSI MALAFOSSE, Guillaume BUHAGIAR
- Personal data
In a ruling dated June 18, 2025 [27], the Social Chamber of the Court of Cassation held that an employee’s right of access to his professional emails covered not only metadata but also the content of the emails. Called upon to rule on the scope of the right of access in a dispute between an employee and his employer in the context of his...
Read- 2025-06-23
- Jeanne BOSSI MALAFOSSE, Guillaume BUHAGIAR
- Personal data
On June 19, 2025, the French data protection authority (CNIL) published two new practical guidelines [30] [31] detailing its recommendations regarding the use of legitimate interest as a legal basis for developing artificial intelligence systems (“AIS”), particularly in cases involving the harvesting of data available online (web scraping)....
ReadOn June 6, 2025, the European Commission launched a public consultation to gather feedback from stakeholders (e.g. providers and deployers of high-risk AI systems, industry organisations, independent experts, public authorities) on the implementation of the provisions applicable to high-risk AI systems (“Consultation”), as set out in Regulation...
Read- 2025-05-26
- Jeanne BOSSI MALAFOSSE, Guillaume BUHAGIAR
- Personal data
In a decision dated May 15, 2025 [34], the CNIL imposed a fine on the company SOLOCAL MARKETING SERVICES (“Solocal company”) for failing to comply with regulations related to commercial prospecting and for breaching the obligation to demonstrate data subjects’ consent to the processing of their data. Solocal company, which operates in the field...
Read- 2025-01-31
- Jeanne BOSSI MALAFOSSE, Guillaume BUHAGIAR
- Personal data
On December 23, 2024, the CNIL announced the opening of a public consultation on a draft « Framework for the GDPR certification of processors » [35] (« Certification framework »). In accordance with Article 28 of the GDPR [36], a controller wishing to entrust a processor with carrying out processing on its behalf must only use « processors...
Read
