News: Guillaume BUHAGIAR

Archives

Guidelines on Anonymization : Adoption of the European Data Protection Board’s New Draft

On July 7, 2026, the European Data Protection Board (EDPB) adopted a draft of new guidelines on anonymization (“Guidelines”) [1]. These Guidelines aim to update Opinion 05/2014 of the Article 29 Working Party on anonymization techniques, in order to take into account developments “in the legal, privacy, engineering and technological landscapes”....

Read

Update to the CNIL’s Reference Methodologies MR-001 and MR-003

By way of four deliberations dated 19 March 2026, the French data protection authority (CNIL) has updated two of its reference methodologies governing the processing of personal data carried out in the context of health research : MR-001, relating to processing operations carried out in the context of health research requiring the collection...

Read

Non-compliance to the interoperability, ethics, and security standards may be penalized

On March 4, 2026, Decree No. 2026-153 [6] (“Decree”) was published, defining the procedures under which the Minister of Health may impose financial penalties on publishers of digital health services (services numériques en santé - "DHS") in the absence of a certificate of compliance with the interoperability, ethics, and security standards...

Read

CNIL sanctions Free Mobile and Free for various breaches of the GDPR following data breaches

On 8 January 2026, the French data protection authority (CNIL) issued two rulings against Free Mobile [7] and Free [8] (the “Companies”), imposing fines of €27 million and €15 million respectively for various breaches of the General Data Protection Regulation (GDPR). In this case, the Companies were alerted in October 2024 that an attacker had...

Read

A new online service, ‘Ma Certif’Pro Santé’, to monitor the periodic certification requirement for healthcare professions registered with an Ordre

On 27 December 2025, Decree No. 2025-1335 [12] (the “Decree”) was published in the French Official Journal. In particular, this Decree : sets out the arrangements for monitoring and supervising compliance with the periodic certification obligation applicable to healthcare professionals ; specifies the procedures applicable in the event of a...

Read

Major contributions by the CJEU on the concepts of pseudonymisation and personal data

In a judgment dated September 4th, 2025 [16] , the Court of Justice of the European Union (CJEU) provided major clarifications regarding the concept of personal data. In this case, the Court was asked to rule, in particular, on the qualification, in terms of the definition of personal data, of comments made by individuals to a controller (the...

Read

AI Regulation : distribution of responsibilities between French national authorities

On 9 September, in accordance with the Regulation on artificial intelligence (“AI Act”) [17], the French Ministry of Economy and Finance unveiled the list of national authorities responsible for artificial intelligence and the division of their respective powers [18]. The diagram presented by Bercy distinguishes between the authorities...

Read

Appeal seeking annulment of the Data Privacy Framework dismissed

In a ruling dated September 3, 2025 [19] , the General Court of the European Union (“GCEU”) dismissed the appeal brought by the French member of parliament Philippe Latombe, seeking annulment of the “Data Privacy Framework” established by the European Commission’s adequacy decision of July 10, 2023, allowing the transfer of personal data from the...

Read

Publication of the code of practice for general purpose AI models

On 10 July 2025, the code of practice (“Code”) [21] for general purpose artificial intelligence models (“GPAI models”) was published. Provided for in Article 56 of Regulation 2024/1689 on Artificial Intelligence (“AI Act”), the Code forms part of the regulation’s phased implementation and is intended to help GPAI model providers comply with their...

Read

Launch of the PANAME project to help stakeholders analyse the confidentiality of their AI model(s)

On June 26th, 2025, the French Data Protection Authority (CNIL) announced the launch of the Privacy Auditing of AI Models (PANAME) project — which it will lead and legally frame — with the goal of developing a tool that can test the confidentiality of artificial intelligence models (“AI Model(s)”). This initiative comes against the backdrop of EU...

Read

Publication of the national strategy for artificial intelligence and healthcare data

On July 1st 2025, the Minister for Health and Access to Care, Yannick Neuder, presented the national strategy for artificial intelligence (AI) and healthcare data [24] ("Strategy") at an exceptional Strategic Committee meeting. Set up to take advantage of the development of AI in the healthcare field (e.g., improving the quality of care,...

Read

Court of Cassation ruling : new interpretation of the scope of an employee’s right of access to his professional emails

In a ruling dated June 18, 2025 [27], the Social Chamber of the Court of Cassation held that an employee’s right of access to his professional emails covered not only metadata but also the content of the emails. Called upon to rule on the scope of the right of access in a dispute between an employee and his employer in the context of his...

Read

The CNIL issues new recommendations on the use of legitimate interest for the development of AI systems

On June 19, 2025, the French data protection authority (CNIL) published two new practical guidelines [30] [31] detailing its recommendations regarding the use of legitimate interest as a legal basis for developing artificial intelligence systems (“AIS”), particularly in cases involving the harvesting of data available online (web scraping)....

Read

European Commission launches a public consultation on the implementation of the rules applicable to high-risk AI systems

On June 6, 2025, the European Commission launched a public consultation to gather feedback from stakeholders (e.g. providers and deployers of high-risk AI systems, industry organisations, independent experts, public authorities) on the implementation of the provisions applicable to high-risk AI systems (“Consultation”), as set out in Regulation...

Read

SOLOCAL MARKETING SERVICES sanctioned by the CNIL for non-compliance with the rules relating to commercial prospecting

In a decision dated May 15, 2025 [34], the CNIL imposed a fine on the company SOLOCAL MARKETING SERVICES (“Solocal company”) for failing to comply with regulations related to commercial prospecting and for breaching the obligation to demonstrate data subjects’ consent to the processing of their data. Solocal company, which operates in the field...

Read

The French data protection authority (CNIL) launches a public consultation on a draft certification framework for processors

On December 23, 2024, the CNIL announced the opening of a public consultation on a draft « Framework for the GDPR certification of processors » [35] (« Certification framework »). In accordance with Article 28 of the GDPR [36], a controller wishing to entrust a processor with carrying out processing on its behalf must only use « processors...

Read