CNIL Launches New Public Consultation on the GDPR
Time 2 Minute Read

On February 23, 2017, the French Data Protection Authority (“CNIL”) launched an online public consultation on three topics identified by the Article 29 Working Party (“Working Party”) in its 2017 action plan for the implementation of the EU General Data Protection Regulation (“GDPR”). The three topics are consent, profiling and data breach notification.

This is the second online public consultation that the CNIL has launched on the GDPR. In June 2016, the CNIL launched a public consultation on the right to data portability, the data protection officer, data protection impact assessments (“DPIAs”) and certification. In November 2016, the CNIL published the results of the June 2016 public consultation.

The CNIL’s purpose for launching these consultations is to collect concrete questions regarding the GDPR, potential difficulties in interpreting the GDPR and examples of best practices. The responses are intended to inform the Working Party’s discussion regarding various GDPR topics. The Working Party will finalize guidelines on certification and DPIAs, issue new guidelines on the topics of consent and profiling, and update its opinions and guidance on data breach notifications.

The new consultation will be open through March 23, 2017. It will be followed by a second “FabLab” organized by the Working Party in Brussels on April 5 and 6, 2017, in which relevant stakeholders will be invited to present their views on the new 2017 priorities.

You May Also Be Interested In

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 7 Minute Read

As we ring in the New Year, one thing remains the same: understanding the definitions and conditions in your insurance policy is critical. In a recent decision, a Florida federal court in Ohio Security Insurance Co. v. E Kelly Enterprises Inc. et al., No. 3:22-cv-24754, held that an insurer had no duty to defend or indemnify a general contractor and no duty to indemnify a subcontractor for damages from defective work on a naval base, based on the policy’s definition of “suit,” “property damage,” and allocation requirements. The decision highlights the importance of numerous issues in the context of commercial general liability policies, including the nuances of policy definitions, obtaining insurer consent when necessary, and allocation between covered and uncovered claims.

Time 1 Minute Read

On December 15, 2025, the Federal Trade Commission announced that it, along with 21 states and the District of Columbia, filed an amended complaint in the U.S. District for the Northern District of California alleging that Uber used unfair and deceptive billing and cancellation practices. 

Time 5 Minute Read

On November 19, 2025, the European Commission unveiled the much-anticipated digital omnibus legislative package (the “Digital Omnibus”), setting the stage for a new era of digital governance and regulatory simplification across the European Union. According to the Commission, this initiative is designed to enable European businesses to devote more energy to innovation and growth, rather than navigating complex compliance landscapes.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page