with a statutory or regulatory duty and supervising compliance with rules; for
adapting resources. The processing must be necessary and proportionate.
Employees’ e-mails are for work-use by default and may as such be consulted by
the employer. However, employers may not have ready access to their employees’
personal e-mails. Such access should be gained in the presence of the employee or
after calling the employee or in the event of serious incidents. There are no longer
any such restrictions when a legal investigation is underway.
Files on computer are for work purposes by default.
Messages sent by the employee via Facebook or the MSN messaging site are
protected because such messages are “accessible only to those persons accredited by
the interested party, in a very limited number” and form “a community of interests”.
109 The absence of authorisation from users to share contents they publish on
their profile make them private: accordingly employers cannot rely on such messages as a basis for dismissal.
110 Case law in this domain is prolific.
111
Identifiers and passwords are confidential and are not to be passed on to the
employer unless the absent employee has essential information on his/her workstation for continuing the business activity. In this case, the employer may demand the
codes be disclosed if the network administrator is unable to provide access to the
workstation.
The LIL contains specific provisions on the transfer of personal data to states that
do not belong to the European Union.
112 It requires users to give consent before
storing information on their equipment or when there is access to information
already stored unless such data are required to ensure the best possible access to
the information transmitted.
113
In the event of a breach of personal data, the service provider must alert the CNIL
“promptly”.
114 The service provider must also alert the interested party unless
protective measures are considered appropriate by the CNIL, that is, the provider
has made the data incomprehensible to anyone not authorised to have access to them.
Self-regulation is little developed as yet (cf. above).
109 Cass. Civ., 1, 10 avr. 2013, pourvoi no 11-19.530.
110 Bourgeois (2017), pp. 376 ff.
111 Bourgeois (2017), p. 377.
112 LIL, Article 112ff.
113 CNIL, Deliberation no 2013-378 of December 5, 2013, cookies and others technologies
JORFTEXT000028380230.
114 LIL, Article 83 II.
Data Protection in the Internet: French Report
171
Précédent

- 180/540

Suivant