systematic. There is no need for prior notice to be issued, as was the case before—
apart from in serious instances—to impose penalties.
38
The CNIL has become the national supervisory authority within the meaning of
the GDPR.
39 Apart from the CNIL (see above), the Act of 6 August 2004 had created
a new position: that of data protection correspondent (correspondant “informatique
et libertés” (CIL)),
40
“tasked with independently ensuring compliance with obligations” laid down in the LIL. Whenever there was a correspondent, there was no need
to file declarations unless personal data were to be transferred to a non EU member
state. The CIL could be held accountable in criminal law in some instances.
However, the presence of a CIL did not in any way dispense with requests for
authorisation.
With the coming into force of the GDPR, the CIL has become the data protection
officer (DPO).
41 The DPO assists the controller and its processor. While the designation of a CIL was optional, it has become mandatory to designate a DPO in three
cases: for the public authority or public body, for large-scale processing, and for
sensitive data and criminal offences.
Although the status of the CIL and the DPO are similar, the requirements as to
qualifications and training are specified and tasks reinforced, particularly in terms of
advice and cooperation with the supervisory authority.
42 Lastly, the DPO must be
afforded the resources necessary for the task.
The CIL was in charge of all processing by the body or just a part of it. The
position had been created to avert administrative or criminal sanctions for the body.
The role was to ensure the body complied with personal data protection rules. It has
now been replaced by the data protection officer (DPO) who is assigned specific
tasks by the regulation.
The CIL had no power of sanction and could only make recommendations to the
controller.
Under the GDPR the DPO is responsible for reporting any breach of personal
data. The CNIL has already published a number of documents explaining the role of
the new officer.
43 No doubt the “compliance” function will develop further within
business organizations.
44
Although Directive 95/46 is designed to promote self-regulation instruments,
these are little developed in France.
45
38 Debet et al. (2015), no 2-10.
39 LIL, Article 8.
40 JORF 7 August 2004, 14063. LIL, Article 22 III. Decree no 2005-1309 of 20 October 2005
(amended by Decree no 2007-451 of 25 March 2017), Article 42 ff.
41 LIL, Article 57. Desgens-Pasanau (2018b), p. 25; Carrera Mariscal (2018), p. 233.
42 https://www.cnil.fr/fr/devenir-delegue-la-protection-des-donnees.
43 https://www.cnil.fr/fr/le-delegue-la-protection-des-donnees-dpo.
44 Fauvarque-Cosson and Maxwell (2018), p. 1033.
45 See Conseil d’État (2014), pp. 274 ff.
164
L. Nicolas-Vullierme
Précédent

- 173/540

Suivant