The algorithm shall remain under the controller’s supervision. Therefore a “selflearning” algorithm cannot be used.
The question came under debate in France because of the use of such algorithms
for first-year university registrations. The previous “Admission Post Bac” system or
APB was replaced by a new “Parcours Sup” system because of a lack of transparency and of recourse to drawing lots for university places.
27
Lastly, the Act of 20 June 2018 introduces into the area of healthcare a general
regime for processing health data and a specific regime for processing data for
research purposes.
28
Although the LIL was initially enacted to protect citizens from the administration,
it applies to both public and private entities. Subsequently, specific or sector-wide
legislation has supplemented the personal data protection arrangements in areas as
diverse as the fight against terrorism,
29 archives,
30 or healthcare.
31
In France, the CNIL,
32 an independent administrative authority, is tasked with
data protection. Although it is not a legal entity, it does have locus standi.
33 It is
composed of 18 members who are elected or designated by assemblies or courts and
tribunals.
34 Since February 2019 the CNIL has been chaired by Madame Denis.
There is a five-member select committee with a separate chair from the chair of the
CNIL (currently Mr. Linden).
The tasks of the CNIL
35 are to inform, advice, especially through advisory
opinions and recommendations, supervise, and sanction.
36 Until now the CNIL
supervised processing both ex ante (via a system of declaration and authorisation)
and ex post. With the entry into force of the GDPR, the ex ante authorisation system
has all but vanished. It still holds for processing health data for research work and in
the absence of standard regulations, benchmarks or reference methodologies.
The entry into force of the GDPR went along with increased competences for the
CNIL. For example, the CNIL may carry out supervision under a borrowed identity.
37 The CNIL must also list the criminal files that may present a high risk for
individual rights and freedoms. The penalties it may order are heavier and more
27 Nicolas-Vullierme (2018), https://audeladudroit.fr/algorithme-droits-fondamentaux/. (Accessed
21 September 2018).
28 Bossi-Malafosse (2018), pp. 58 ff.
29 Act no 2006-64 of 23 January 2006, JORF 24 January 2006.
30 Act no 2008-696, 15 July 2008, JORF 16 July 2008.
31 Act no 2016-41 of 26 January 2016, JORF 27 January 2016.
32 Website: https://www.cnil.fr/.
33 Bourgeois (2017), No 39.
34 LIL, Article 9. Fauchoux et al. (2017), p. 58 ff.
35 LIL, Article 8.
36 Bourgeois (2017), pp. 22 ff.
37 LIL, Article 19 III.
Data Protection in the Internet: French Report
163
The question came under debate in France because of the use of such algorithms
for first-year university registrations. The previous “Admission Post Bac” system or
APB was replaced by a new “Parcours Sup” system because of a lack of transparency and of recourse to drawing lots for university places.
27
Lastly, the Act of 20 June 2018 introduces into the area of healthcare a general
regime for processing health data and a specific regime for processing data for
research purposes.
28
Although the LIL was initially enacted to protect citizens from the administration,
it applies to both public and private entities. Subsequently, specific or sector-wide
legislation has supplemented the personal data protection arrangements in areas as
diverse as the fight against terrorism,
29 archives,
30 or healthcare.
31
In France, the CNIL,
32 an independent administrative authority, is tasked with
data protection. Although it is not a legal entity, it does have locus standi.
33 It is
composed of 18 members who are elected or designated by assemblies or courts and
tribunals.
34 Since February 2019 the CNIL has been chaired by Madame Denis.
There is a five-member select committee with a separate chair from the chair of the
CNIL (currently Mr. Linden).
The tasks of the CNIL
35 are to inform, advice, especially through advisory
opinions and recommendations, supervise, and sanction.
36 Until now the CNIL
supervised processing both ex ante (via a system of declaration and authorisation)
and ex post. With the entry into force of the GDPR, the ex ante authorisation system
has all but vanished. It still holds for processing health data for research work and in
the absence of standard regulations, benchmarks or reference methodologies.
The entry into force of the GDPR went along with increased competences for the
CNIL. For example, the CNIL may carry out supervision under a borrowed identity.
37 The CNIL must also list the criminal files that may present a high risk for
individual rights and freedoms. The penalties it may order are heavier and more
27 Nicolas-Vullierme (2018), https://audeladudroit.fr/algorithme-droits-fondamentaux/. (Accessed
21 September 2018).
28 Bossi-Malafosse (2018), pp. 58 ff.
29 Act no 2006-64 of 23 January 2006, JORF 24 January 2006.
30 Act no 2008-696, 15 July 2008, JORF 16 July 2008.
31 Act no 2016-41 of 26 January 2016, JORF 27 January 2016.
32 Website: https://www.cnil.fr/.
33 Bourgeois (2017), No 39.
34 LIL, Article 9. Fauchoux et al. (2017), p. 58 ff.
35 LIL, Article 8.
36 Bourgeois (2017), pp. 22 ff.
37 LIL, Article 19 III.
Data Protection in the Internet: French Report
163
