CNIL Enforcement: Investigations, Sanctions, and Notable Decisions

The Commission Nationale de l’Informatique et des Libertés (CNIL) is the French data protection authority, established by the Law of 6 January 1978 (Loi Informatique et Libertés). The CNIL is an independent administrative authority responsible for ensuring compliance with data protection law, including the General Data Protection Regulation (GDPR) and the French Loi Informatique et Libertés. The CNIL has developed a reputation as one of the most active and effective data protection authorities in Europe, with a broad range of enforcement powers and a track record of significant sanctions.

The CNIL’s Powers

The CNIL has extensive powers under the GDPR and French law. These include: investigative powers, including the power to conduct on-site inspections, to request access to premises and data, and to obtain information from data controllers; corrective powers, including the power to issue warnings, reprimands, orders to comply, and administrative fines; and advisory powers, including the power to issue opinions on draft legislation and to publish guidance on data protection matters.

The CNIL also has the power to certify data protection officers and to approve binding corporate rules (BCRs). The CNIL participates in the European Data Protection Board (EDPB) and cooperates with other data protection authorities under the GDPR’s one-stop-shop mechanism.

Investigation Procedures

The CNIL conducts investigations in response to complaints, on its own initiative, or at the request of other authorities. The investigation may be conducted by correspondence or through on-site inspection. The CNIL’s investigators have the power to access all premises, to examine documents and data, and to interview relevant persons.

The investigation procedure respects the rights of the parties. The data controller is informed of the investigation and has the opportunity to respond to the allegations. The investigator prepares a report, which is submitted to the CNIL’s restricted committee (formation restreinte) for a decision on sanctions.

Sanctions Procedure

The CNIL’s sanctions procedure involves several stages. The restricted committee examines the investigation report and decides whether to initiate sanction proceedings. The data controller is notified of the proceedings and has the right to submit written observations and to request an oral hearing.

The restricted committee may impose a range of sanctions: a warning (avertissement); a reprimand (blâme); a temporary or permanent ban on data processing; a suspension of data flows; a fine (amende); and an injunction to comply (injonction) with or without a periodic penalty payment (astreinte). The fine may be up to €20 million or 4% of the worldwide annual turnover of the undertaking, whichever is higher.

GDPR Cooperation

Under the GDPR’s one-stop-shop mechanism, the CNIL acts as the lead supervisory authority for data controllers with their main establishment in France. As lead authority, the CNIL coordinates with other concerned supervisory authorities and prepares a draft decision for their review. If the other authorities disagree, the matter is referred to the EDPB for a binding decision.

The one-stop-shop mechanism has been tested in several high-profile cases involving major technology companies. The CNIL has acted as lead authority in cases against Google, Facebook, and other companies with their European headquarters in France or Ireland. The mechanism ensures consistent enforcement across the EU while respecting the lead authority’s role.

AI Audits

The CNIL has developed specialised capacity for auditing AI systems. The authority has conducted investigations into the use of AI by both public and private entities, focusing on compliance with data protection principles. The CNIL’s AI audits examine whether AI systems comply with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, and accuracy.

The CNIL has published guidance on AI auditing, setting out its methodology for evaluating AI systems. The guidance covers data collection and preparation, model training and validation, model deployment and monitoring, and AI governance. The CNIL has also developed tools for auditing AI systems, including software for testing compliance.

Data Breach Notifications

The GDPR requires data controllers to notify personal data breaches to the supervisory authority within 72 hours. The CNIL receives and processes breach notifications from French data controllers. The CNIL has published guidance on breach notification, setting out the information that must be provided and the procedures to be followed.

The CNIL also maintains a public register of data breaches. The register includes information about the nature and impact of the breach and the measures taken by the data controller. The publication of breach information raises awareness of data protection risks and encourages compliance.

Notable CNIL Decisions: Google

The CNIL imposed a €50 million fine on Google LLC in January 2019 for violations of the GDPR. The CNIL found that Google had not provided sufficient information to users about how their data was collected and used for personalised advertising. The CNIL also found that Google had not obtained valid consent for the processing of personal data for advertising purposes.

The Google decision was one of the first major fines under the GDPR and established the CNIL as a leading enforcer of European data protection law. The fine was calculated based on Google’s global turnover and reflected the seriousness and duration of the violations.

Notable CNIL Decisions: Meta/Facebook

The CNIL imposed a €60 million fine on Facebook Ireland Limited in December 2021 for violations of the GDPR relating to cookies. The CNIL found that Facebook did not provide users with a clear and simple mechanism for refusing cookies, making it as easy to refuse cookies as to accept them. The CNIL ordered Facebook to implement a solution within three months.

The Facebook decision was part of a broader CNIL campaign to enforce cookie compliance. The CNIL has also fined Google and other companies for cookie violations. The campaign has led to significant changes in cookie consent practices across the French internet.

Notable CNIL Decisions: Clearview AI

The CNIL imposed a €20 million fine on Clearview AI, a US company that operates a facial recognition database, in October 2021. The CNIL found that Clearview AI had collected and processed the biometric data of individuals in France without a legal basis, without their knowledge or consent, and in violation of the principles of purpose limitation and data minimisation.

The Clearview AI decision demonstrated the CNIL’s willingness to enforce European data protection law against non-EU companies. The CNIL ordered Clearview AI to cease the collection and processing of data and to delete the data already collected. The decision was coordinated with other European data protection authorities.

Other Notable Decisions

The CNIL has issued significant decisions in many other areas. In the health sector, the CNIL has fined hospitals and health technology companies for data protection violations. In the employment sector, the CNIL has fined companies for excessive monitoring of employees. In the public sector, the CNIL has sanctioned public authorities for non-compliance with data protection law.

The CNIL has also exercised its corrective powers in novel areas, including connected objects (IoT), smart cities, and algorithmic decision-making. The CNIL’s decisions provide guidance on the application of data protection law to new technologies and business models.