28 March 2017
123 : Operators and members of their personnel are bound to abide by
the secrecy of correspondence. Secrecy covers the contents of the correspondence,
the identity of the correspondents and, as the case may be, the heading of the
message and the documents enclosed with the correspondence.
The aim is to protect the individual against infringements by the state and its
agents (C. pén., art. 432-9) and against infringement by any other person or entity
(C. pén., art. 226-15). The correspondence covered is any that is “emitted, transmitted or received”. The message must be correspondence and be “personal”, that is,
addressed to one or more individualized persons.
For example, the CNIL fined Darty €100,000 for failing to ensure the security of
data of customers having made an online request for after-sales service.
124 The
sanction is generally imposed after a warning has been given. Sanctions have
changed with the entry into force of the GDPR.
Article 34bis of the LIL includes specific rules for the public provision of
electronic communications services over electronic communications networks
open to the public.
Breach of personal data applies to “any breach of security entailing accidentally
or unlawfully the destruction, loss, deterioration, disclosure of or unauthorised
access to personal data processed in the context of the supply to the public of
electronic communications services”.
125
In the event of any breach, the supplier must alert the CNIL promptly. The data
subject need only be alerted if the breach infringes their personal data or private life.
For failure to comply with these obligations, the supplier is liable to five years’
imprisonment and a fine of €300,000.
126
The CNIL is the competent authority for data protection. It may request an
advisory opinion of the others regulators (e.g. Autorité de Régulation des communications électroniques et des postes—ARCEP).
In addition to the possibility of issuing advisory opinions, the CNIL has a power
of supervision over controllers and subcontractors. Before imposing administrative
fines, the CNIL may issue a warning to the controller or processor and/or may issue a
notice to amend the processing. It may also issue a call to order or an enjoinder to
render compliant or limit, interrupt or even prohibit the processing, withdraw or
refuse certification, suspend data flow to foreign countries, certifications and
approvals.
The CNIL may also file observations or develop them verbally in criminal or civil
proceedings, which may lead to penalties.
123 Decree no 2017-428 of 28 March 2017 relative to the confidentiality of private electronic
correspondence: JORF 30 March 2017.
124 CNIL, Deliberation no SAN-2018-001 of January 8, 2018: CNILTEXT000036403140.
125 LIL, Article 83 I.
126 Code pénal (CP), Article 226-17-1 § 1
er .
Data Protection in the Internet: French Report
173
123 : Operators and members of their personnel are bound to abide by
the secrecy of correspondence. Secrecy covers the contents of the correspondence,
the identity of the correspondents and, as the case may be, the heading of the
message and the documents enclosed with the correspondence.
The aim is to protect the individual against infringements by the state and its
agents (C. pén., art. 432-9) and against infringement by any other person or entity
(C. pén., art. 226-15). The correspondence covered is any that is “emitted, transmitted or received”. The message must be correspondence and be “personal”, that is,
addressed to one or more individualized persons.
For example, the CNIL fined Darty €100,000 for failing to ensure the security of
data of customers having made an online request for after-sales service.
124 The
sanction is generally imposed after a warning has been given. Sanctions have
changed with the entry into force of the GDPR.
Article 34bis of the LIL includes specific rules for the public provision of
electronic communications services over electronic communications networks
open to the public.
Breach of personal data applies to “any breach of security entailing accidentally
or unlawfully the destruction, loss, deterioration, disclosure of or unauthorised
access to personal data processed in the context of the supply to the public of
electronic communications services”.
125
In the event of any breach, the supplier must alert the CNIL promptly. The data
subject need only be alerted if the breach infringes their personal data or private life.
For failure to comply with these obligations, the supplier is liable to five years’
imprisonment and a fine of €300,000.
126
The CNIL is the competent authority for data protection. It may request an
advisory opinion of the others regulators (e.g. Autorité de Régulation des communications électroniques et des postes—ARCEP).
In addition to the possibility of issuing advisory opinions, the CNIL has a power
of supervision over controllers and subcontractors. Before imposing administrative
fines, the CNIL may issue a warning to the controller or processor and/or may issue a
notice to amend the processing. It may also issue a call to order or an enjoinder to
render compliant or limit, interrupt or even prohibit the processing, withdraw or
refuse certification, suspend data flow to foreign countries, certifications and
approvals.
The CNIL may also file observations or develop them verbally in criminal or civil
proceedings, which may lead to penalties.
123 Decree no 2017-428 of 28 March 2017 relative to the confidentiality of private electronic
correspondence: JORF 30 March 2017.
124 CNIL, Deliberation no SAN-2018-001 of January 8, 2018: CNILTEXT000036403140.
125 LIL, Article 83 I.
126 Code pénal (CP), Article 226-17-1 § 1
er .
Data Protection in the Internet: French Report
173
