I. Introduction
On June 20, 2018, France adopted Law No. 2018-493 on the protection of personal data, in order to implement the General Data Protection Regulation (GDPR). This law revises and consolidates the 1978 Data Protection Act.
The Commission Nationale de l'Informatique et des Libertés (CNIL), as the national supervisory authority, is responsible for supervising, guiding, and enforcing the GDPR and its implementing texts in France.
Thus, France has implemented a personal data protection system that complies with the requirements of the European Union.
II. Scope
The GDPR regulation in France applies:
to any data controller or processor established on French territory;
to any organization located outside France that offers goods or services to individuals located in France, or monitors their behavior on French territory.
Regardless of where the processing is carried out, as long as it concerns the personal data of individuals located in France, the law applies.
It covers automated processing as well as non-automated processing that is part of a filing system.
Activities of an exclusively personal or domestic nature do not fall within its scope.
III. Principles of Data Processing
Lawfulness, fairness, and transparency: All processing must have a clear legal basis and be conducted transparently.
Purpose limitation: Data may only be used for specific and legitimate purposes.
Data minimization: Only strictly necessary data should be collected.
Accuracy: Data must be accurate and updated regularly.
Storage limitation: Data should only be kept for as long as strictly necessary, then deleted or anonymized.
Security and confidentiality: Appropriate technical and organizational measures must be put in place to prevent any breach, alteration, or loss of data.
IV. Data Subject Rights
In accordance with the GDPR and French law, natural persons have the following rights:
Right to information and access;
Right to rectification;
Right to erasure (right to be forgotten);
Right to restriction of processing;
Right to data portability;
Right to object.
For minors under 15, the processing of their data requires the consent of a parent or legal guardian, and information must be provided to them in clear and understandable language.
V. Obligations of Processors
Processors must:
strictly comply with the data controller's written instructions;
implement adequate security measures;
assist the data controller in fulfilling their obligations, particularly in responding to data subject requests;
notify the data controller without undue delay of any data breach, who must inform the CNIL within 72 hours.
Data controllers must maintain an internal record of processing activities when required by the GDPR and conduct a Data Protection Impact Assessment when processing is likely to result in a high risk.
Some organizations must also appoint a Data Protection Officer when the conditions provided for by the regulations are met. Data processing generally does not require prior declaration to the CNIL, unless a specific formality is expressly provided for by law.
VI. International Data Transfers
Data transfers to countries outside the European Union must be based on an appropriate legal mechanism and offer a level of protection compliant with the GDPR, notably through:
an adequacy decision adopted by the European Commission;
the European Commission's standard contractual clauses or any other guarantee recognized by the GDPR.
Transfers to certain organizations established in the United States may notably be based on the EU-U.S. Data Privacy Framework when the recipient organization is validly certified. Otherwise, the transfer must be framed by appropriate safeguards, such as standard contractual clauses and, where necessary, additional measures.
VII. Monitoring and Enforcement
The CNIL has extensive powers, including:
issuing warnings or formal notices;
restricting or prohibiting certain processing operations;
imposing fines of up to 20 million euros or 4% of global turnover, whichever is higher.
French law also allows individuals to issue directives concerning the use of their data after their death. Failing this, the processing must comply with the rules in force.
The French GDPR framework aims to guarantee individual rights, strengthen corporate compliance, and promote trust in the digital environment.
VIII. Contact
Store Name: Antik Möbel Berlin
Customer Service Number : +49 30 60955294
Email: info@antik-moebel-berlin.com
Address: Wühlischstr.56, 10245 Berlin, Germany
Opening Hours: Monday to Saturday, 9:00 AM to 6:00 PM (CET)