Alongside this new measure, the Act of 30 November 2015 on surveillance
measures for international electronic communications
162 has introduced into the
Code of internal security a chapter on “Surveillance measures for international
electronic communications”.
163
It should be added that the Defence Code has provisions designed to ensure the
security of state and operator information systems.
164
6 Remedies and Sanctions
Failure to comply with the rules for personal data protection is a matter of public
policy. There are administrative, criminal, and civil law sanctions.
Victims may file a complaint with the CNIL but they may also seek remedy via
the public prosecutor’s office and the fraud office (DGCCRF).
Should rules on data protection be disregarded, the CNIL may impose administrative penalties.
165 Appeals against its decisions may be made to the Conseil d’État
within one month. More specifically, the CNIL may impose penalties after issuing
notice that is not acted on, issuing warnings, fines, injunctions, after withdrawal of
CNIL authorisation, and the lockdown of data for three months. These penalties have
been gradually increased. The maximum penalty, which was raised from €150,000
to €3 million by the LRN, has been raised again. It may now come to €10 million or
2% of the total worldwide annual turnover for the preceding financial year
166 and in
cases covered by the GDPR €20 million or 4%.
167 Moreover the select committee
may now impose penalties without prior notice.
168
Under articles 226-16 to 226-24 of the Criminal Code, the various offences may
give rise to up to five years’ imprisonment and a €300,000 fine. The usual appeals in
criminal law may be made.
By way of civil law penalties, the data transfer operation may be cancelled if the
formalities are not observed.
169 A first class action was created by the Act of
20 January 2017 to enable associations to force compliance. A second for remedy
for damage arising from a breach of personal data was introduced by the Act of
20 June 2018.
170
162 Act no 2015-1556 of 30 November 2017, JORF 1 December 2015, p. 22185.
163 CSI, Article L 854-1 to Article 854-9.
164 Code de la défense, Article L 2321-3 and Article L 2321-4.
165 LIL, Articles 20 ff; Decree No 2019-536, Article 38 ff.
166 LIL, Article 20 III.
167 LIL, Article 20 III and GDPR, Article 83, §§ 5 & 6.
168 CNIL, Deliberation no SAN-2017-012 of 16 November 2017.
169 Judgement of the Commercial Chamber of the French Supreme Court of 25 June 2013, Appeal
No 12-17037.
170 LIL, Article 37.
178
L. Nicolas-Vullierme
measures for international electronic communications
162 has introduced into the
Code of internal security a chapter on “Surveillance measures for international
electronic communications”.
163
It should be added that the Defence Code has provisions designed to ensure the
security of state and operator information systems.
164
6 Remedies and Sanctions
Failure to comply with the rules for personal data protection is a matter of public
policy. There are administrative, criminal, and civil law sanctions.
Victims may file a complaint with the CNIL but they may also seek remedy via
the public prosecutor’s office and the fraud office (DGCCRF).
Should rules on data protection be disregarded, the CNIL may impose administrative penalties.
165 Appeals against its decisions may be made to the Conseil d’État
within one month. More specifically, the CNIL may impose penalties after issuing
notice that is not acted on, issuing warnings, fines, injunctions, after withdrawal of
CNIL authorisation, and the lockdown of data for three months. These penalties have
been gradually increased. The maximum penalty, which was raised from €150,000
to €3 million by the LRN, has been raised again. It may now come to €10 million or
2% of the total worldwide annual turnover for the preceding financial year
166 and in
cases covered by the GDPR €20 million or 4%.
167 Moreover the select committee
may now impose penalties without prior notice.
168
Under articles 226-16 to 226-24 of the Criminal Code, the various offences may
give rise to up to five years’ imprisonment and a €300,000 fine. The usual appeals in
criminal law may be made.
By way of civil law penalties, the data transfer operation may be cancelled if the
formalities are not observed.
169 A first class action was created by the Act of
20 January 2017 to enable associations to force compliance. A second for remedy
for damage arising from a breach of personal data was introduced by the Act of
20 June 2018.
170
162 Act no 2015-1556 of 30 November 2017, JORF 1 December 2015, p. 22185.
163 CSI, Article L 854-1 to Article 854-9.
164 Code de la défense, Article L 2321-3 and Article L 2321-4.
165 LIL, Articles 20 ff; Decree No 2019-536, Article 38 ff.
166 LIL, Article 20 III.
167 LIL, Article 20 III and GDPR, Article 83, §§ 5 & 6.
168 CNIL, Deliberation no SAN-2017-012 of 16 November 2017.
169 Judgement of the Commercial Chamber of the French Supreme Court of 25 June 2013, Appeal
No 12-17037.
170 LIL, Article 37.
178
L. Nicolas-Vullierme
