{"id":11486,"date":"2021-12-14T15:25:18","date_gmt":"2021-12-14T14:25:18","guid":{"rendered":"https:\/\/www.cabinetbouchara.com\/cnil\/"},"modified":"2024-11-01T14:26:24","modified_gmt":"2024-11-01T13:26:24","slug":"cnil","status":"publish","type":"post","link":"https:\/\/www.cabinetbouchara.com\/en\/cnil\/","title":{"rendered":"CNIL"},"content":{"rendered":"<p style=\"text-align: justify;\">The National Commission for Information Technology and Civil Liberties, known as the &#8220;CNIL&#8221;, is an independent administrative authority created in 1978 by the law &#8220;Informatique et Libert\u00e9s&#8221; of January 6, 1978 relating to data processing, files and freedoms, amended on numerous occasions in order to comply with the General Data Protection Regulation known as &#8220;RGPD&#8221; (Regulation (EU) 2016\/679 of the European Parliament and of the Council of April 27, 2016, on the protection of individuals with regard to the processing of personal data and on the free movement of such data).<\/p>\n<p style=\"text-align: justify;\"><span style=\"float: left; font-size: 8em; line-height: 100%; margin: -.1em 0px; padding-right: .1em; color: #f5b63f;\">T<\/span><\/p>\n<p style=\"text-align: justify;\">he CNIL ensures in particular that <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/personal-data\/\" target=\"_blank\" rel=\"noopener noreferrer\">personal data<\/a> on the Internet are well protected, and that the <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/data-processing\/\" target=\"_blank\" rel=\"noopener noreferrer\">processing of these personal data<\/a> respects the individual freedoms and fundamental rights of the persons to whom the data belong.<\/p>\n<div class=\"PartieFicheCommentaire\">\n<h2>Rights protected<\/h2>\n<p style=\"text-align: justify;\">The transmission of personal data is very often done on the Internet.<\/p>\n<p style=\"text-align: justify;\">From filling out registration forms to simple clicks, organizations collect an enormous amount of information about users, which is why the Data Protection Act, particularly following the changes imposed by the <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/gdrp\/\" target=\"_blank\" rel=\"noopener noreferrer\">RGPD<\/a>, has provided for several rights of the Internet user to ensure, among other things\u00a0:<\/p>\n<ul style=\"text-align: justify;\">\n<li><strong><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/right-of-access\/\" target=\"_blank\" rel=\"noopener noreferrer\">The right of access<\/a>:<\/strong> allows to ask the person in charge of a file which holds information on an Internet user to communicate all the data that it holds on him.<\/li>\n<\/ul>\n<ul style=\"text-align: justify;\">\n<li><strong><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/right-to-rectification\/\" target=\"_blank\" rel=\"noopener noreferrer\">The right of rectification<\/a>:<\/strong> allows an Internet user to request the rectification of inaccurate information concerning him or her.<\/li>\n<\/ul>\n<ul style=\"text-align: justify;\">\n<li><strong><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/right-to-information\/\" target=\"_blank\" rel=\"noopener noreferrer\">The right to information<\/a>:<\/strong> allows a user to obtain concise and readable information on how his data is processed and how to assert his rights.<\/li>\n<\/ul>\n<ul style=\"text-align: justify;\">\n<li><strong><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/right-to-portability\/\" target=\"_blank\" rel=\"noopener noreferrer\">The right to portability<\/a>:<\/strong> allows the retrieval of personal data in order to transfer them elsewhere.<\/li>\n<\/ul>\n<ul style=\"text-align: justify;\">\n<li><strong><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/right-to-object\/\" target=\"_blank\" rel=\"noopener noreferrer\">The right to object<\/a>:<\/strong> allows the Internet user to object to his data being distributed, transmitted, stored, and to being included in a file.<\/li>\n<\/ul>\n<ul style=\"text-align: justify;\">\n<li><strong><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/right-to-limitation\/\" target=\"_blank\" rel=\"noopener noreferrer\">The right to limit the processing<\/a>:<\/strong> allows the user to request the freezing of the use of his data following a request for rectification or opposition.<\/li>\n<\/ul>\n<ul style=\"text-align: justify;\">\n<li><strong><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/right-to-erasure\/\" target=\"_blank\" rel=\"noopener noreferrer\">The right to erasure<\/a>:<\/strong> allows the user to request the deletion of his data held by an organization when\u00a0:<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul style=\"text-align: justify;\">\n<li style=\"list-style-type: none;\">\n<ul>\n<li>The data is used for prospecting purposes\u00a0;<\/li>\n<li>The data is not necessary for the purposes of the collection\/processing\u00a0;<\/li>\n<li>The consent is withdrawn\u00a0;<\/li>\n<li>The processing is unlawful\u00a0;<\/li>\n<li>Data was collected when the individual was a minor\u00a0;<\/li>\n<li>The data must be deleted in compliance with a legal obligation\u00a0; or<\/li>\n<li>An objection has been made and the person in charge has no legitimate or compelling reason to retain them.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li><strong style=\"font-size: 16px; text-align: left;\">The right to dereferencing:<\/strong><span style=\"font-size: 16px; text-align: left;\"> Allows you to request the dereferencing of a web page associated with your name.<\/span><\/li>\n<\/ul>\n<ul>\n<li><strong>The right of access to police, gendarmerie, intelligence, tax administration files:<\/strong>\u00a0allows access to data concerning us in these files.<\/li>\n<\/ul>\n<div class=\"PartieFicheCommentaire\">\n<h2>Missions of the CNIL<\/h2>\n<p style=\"text-align: justify;\">The <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/commission-nationale-de-linformatique-et-des-libertes-cnil\/\" target=\"_blank\" rel=\"noopener noreferrer\">CNIL<\/a> has several missions\u00a0which derive from the Law &#8221;\u00a0<em> Informatique et Libert\u00e9s\u00a0&#8221; and the RGPD, including:<\/em><\/p>\n<ul>\n<li style=\"text-align: justify;\"><strong>Examination of complaints, reports or disputes<\/strong> submitted to it for behaviour that does not comply with the Law &#8221;\u00a0Informatique et Libert\u00e9s\u00a0&#8221; or the RGPD. The <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/national-commission-for-information-technology-and-civil-liberties-cnil\/\" target=\"_blank\" rel=\"noopener noreferrer\">CNIL<\/a> may also be required to carry out control missions. These two procedures may result in sanctions being imposed on operators.<\/li>\n<\/ul>\n<p style=\"text-align: justify;\">It has the power to impose various sanctions\u00a0: warning, injunction, or financial penalty which can amount to up to 4% of the company&#8217;s turnover or 20 million euros.<\/p>\n<p style=\"text-align: justify;\">For example, it has initiated a sanction procedure against the company &#8221;\u00a0Cdiscount\u00a0&#8220;, for lack of security of online banking data and serious breaches.<\/p>\n<p style=\"text-align: justify;\">The company &#8221;\u00a0Cdiscount\u00a0&#8221; had indeed kept 4000 bank details in an unsecured way.<\/p>\n<p style=\"text-align: justify;\">The CNIL thus issued a public warning on September 20, 2016 (Deliberation No. 2016-265) and gave formal notice on September 26, 2016 (Deliberation No. 2016-083) to the company Cdiscount.<\/p>\n<p style=\"text-align: justify;\">The press group PRISMA MEDIA has also been sanctioned by the CNIL for non-compliance with the regulations on email prospecting (Deliberation n\u00b02015-155 of June 1, 2015).<\/p>\n<p style=\"text-align: justify;\">The company did not systematically or sufficiently inform Internet users <em>registered<\/em> on the group&#8217;s newsletter <em>list<\/em> of the publications they would receive.<\/p>\n<p style=\"text-align: justify;\">The CNIL has given the press group formal notice to cease its actions. Since they have continued, the CNIL has imposed a fine of 15000\u20ac on PRISMA MEDIA.<\/p>\n<p style=\"text-align: justify;\">In November 2020, two of the Carrefour Group&#8217;s companies were also sanctioned for numerous violations of the RGPD including in particular a violation relating to the length of time personal data are kept (Deliberation of the restricted panel n\u00b0SAN-2020-008 and n\u00b0SAN-2020-009 of November 18, 2020 concerning the company CARREFOUR FRANCE).<\/p>\n<p style=\"text-align: justify;\">To this end, the Carrefour companies have been fined 2,\u00a0250\u00a0,000 euros and 800\u00a0,000 euros respectively.<\/p>\n<p style=\"text-align: justify;\">In this case, it was because of numerous complaints filed by consumers that the CNIL conducted examinations of the Carrefour companies to verify the proper handling of their customer&#8217;s personal data.<\/p>\n<p style=\"text-align: justify;\">The CNIL did not need to issue an injunction because the Carrefour companies quickly complied.<\/p>\n<ul>\n<li style=\"text-align: justify;\"><strong>Anticipation<\/strong> by monitoring the Internet and social networks to detect and analyze the consequences that new technologies and their uses may have on private life. She reflects on the ethical and social issues raised by the evolution of digital technologies.<\/li>\n<\/ul>\n<p style=\"text-align: justify;\">As part of its anticipatory mission, the CNIL will verify that companies do not collect data without having made the necessary declarations, that the <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/consent\/\" target=\"_blank\" rel=\"noopener noreferrer\">consent<\/a> of the persons whose data is collected is well collected for the transmission of these data to third parties, for sending advertisements by SMS, etc &#8230; (OPT IN\/OPT OUT).<\/p>\n<ul>\n<li style=\"text-align: justify;\"><strong>The examination of bills and decrees<\/strong> submitted to it for opinion by the Government. It was thus brought to give its opinion on the bill for a &#8220;Digital Republic&#8221; of Mrs Lemaire for example. This law extends the prerogatives of the CNIL by creating new rights for citizens, and therefore new regulatory missions for the CNIL.<\/li>\n<\/ul>\n<div class=\"PartieFicheCommentaire\">\n<h2>General recommendations<\/h2>\n<p style=\"text-align: justify;\">Companies that collect user data must be very vigilant and\u00a0:<\/p>\n<ul style=\"text-align: justify;\">\n<li>Make the necessary declarations\u00a0;<\/li>\n<li>Solicit the consent of the persons whose data is collected for the transmission of their data to third parties, or for the sending of advertisements by SMS for example\u00a0;<\/li>\n<li>Publish the legal notice and their personal data policy on their website\u00a0;<\/li>\n<li>Provide users with the opportunity to effectively exercise their right to access and modify their data\u00a0;<\/li>\n<li>Ensure that emails sent to users always include the option to unsubscribe.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The National Commission for Information Technology and Civil Liberties, known as the &#8220;CNIL&#8221;, is an independent administrative authority created in 1978 by the law &#8220;Informatique et Libert\u00e9s&#8221; of January 6, 1978 relating to data processing, files and freedoms, amended on numerous occasions in order to comply with the General Data Protection Regulation known as &#8220;RGPD&#8221; &#8230; <a title=\"CNIL\" class=\"read-more\" href=\"https:\/\/www.cabinetbouchara.com\/en\/cnil\/\" aria-label=\"Read more about CNIL\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":8840,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[146,23],"tags":[],"class_list":["post-11486","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-rgpd-donnees-personnelles-en","category-rgpd-donnees-personnelles"],"_links":{"self":[{"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/posts\/11486","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/comments?post=11486"}],"version-history":[{"count":4,"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/posts\/11486\/revisions"}],"predecessor-version":[{"id":16638,"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/posts\/11486\/revisions\/16638"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/media\/8840"}],"wp:attachment":[{"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/media?parent=11486"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/categories?post=11486"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/tags?post=11486"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}