Under article 11-I-3
b of the LIL, “at the request of professional organizations or
of institutions essentially comprising controllers” the CNIL “makes an appraisal of
the guarantees provided by professional rules that it has previously recognized to be
consistent with the provisions of this Act, in terms of adherence to fundamental
personality rights”. However, no clarification has been made by the legislator as to
the procedure.
The CNIL has not been the driving force in this domain.
46 Under this article, two
codes of professional ethics for marketing by electronic means have been recognized
as complying: one presented by the Syndicat National de la Communication Directe
(SNCD)
47 and one by the Union Française du Marketing Direct (UFMD).
48 To
promote their development, the Conseil d’État in its 2014 study recommended
adopting an approval procedure.
49 On 11 December 2014, the CNIL passed a
resolution to issue an accreditation.
50 This resolution was modified on 13 July
2017 to adapt it to the GDPR
51 : it supposes that the body meets 25 requirements
concerning the internal organization and management of personal data, the procedure for testing compliance, and the management of complaints and incidents.
52
Professional actors have not contributed further to the development of these selfregulation systems.
The GDPR should therefore further the development of such instruments. The
CNIL shall have to strengthen its production of reference standards in the future
because its practical information sheets are not specific enough.
53
2 Data Protection in the Internet
In the case of data processing by electronic means, apart from the LIL, the Civil
Code
54 and the Postal and Electronic Communications Code (CPCE) are applicable.
There are also simplified norms adopted by resolution by the CNIL.
46 Debet et al. (2015), pp. 193 ff, see in particular p. 195.
47 CNIL, Deliberation no 2005-047 of 22 March 2005: CNILTEXT000017653290.
48 CNIL, Deliberation no 2005-051 of 30 March 2005. https://www.cnil.fr/sites/default/files/typo/
document/projet-codeUFMD.pdf.
49 Conseil d’État (2014).
50 CNIL, Deliberation no 2014-500 of 11 December 2014, JORF 10 January 2015. Fauchoux et al.
(2017), no 327.
51 CNIL, Deliberation. No 2017-219 of 13 July 2017, JORF 20 September 2017.
52 Perray (2018), pp. 19 ff.
53 Desgens-Pasanau (2018a), p. 211.
54 Code civil, Article 1125 to Article 1127-4 (since the reform of the law of obligations from
10 February 2016) and CPCE, Article L 100 (electronic registered mail).
Data Protection in the Internet: French Report
165
Précédent

- 174/540

Suivant