CNIL Publishes GDPR Guidance for Data Processors
Time 2 Minute Read

On September 29, 2017 the French Data Protection Authority (CNIL) published a guide for data processors to implement the new obligations set by the EU General Data Protection Regulation (“GDPR”). The guidance addresses the extended scope of the GDPR and the new and direct obligations data processors will have when the GDPR comes into force on May 25, 2018. The guidance elaborates a three-step checklist for data processors:

  1. Assess whether a DPO must be appointed.
  2. Review and analyze existing contracts. In this regard, the guide provides template data processing clauses to be inserted in service agreements.
  3. Create an inventory of data processing operations.

The guide also provides further explanations on the processor’s obligations in appointing a subprocessor, on processor’s liability in helping the data controller to conduct data protection impact assessments (“DPIA”) and in notifying data breaches. It also addresses the possibility to elect a lead supervisory authority if there is a cross-border data processing activity and the obligation to appoint a data representative if the processor is not established within the EU.

Finally, the guide summarizes the regime of sanctions for data processors and lists some of the GDPR violations that would trigger these sanctions, such as:

  • acting outside the scope of the data controller’s instructions;
  • failing to assist the data controller in its obligations;
  • failing to make available to the data controller information that demonstrates the processor’s compliance, including submitting to audits;
  • failing to inform the data controller that an instruction may violate the GDPR;
  • relying on a subprocessor without the prior approval of the data controller;
  • relying on a subprocessor that does not provide sufficient guarantees;
  • failing to appoint a data protection officer where necessary; and
  • failing to keep a data processing inventory for the data processed on behalf of the data controller.

You May Also Be Interested In

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 2 Minute Read

On January 30, 2026, the Cybersecurity Administration of China released a Q&A document on policies and regulations for the security management of cross-border data transfers. 

Time 1 Minute Read

On January 26, 2026, the Brazilian data protection authority (“ANPD”) announced that Brazil and the European Union agreed to mutually recognize the adequacy of each other’s data protection networks.

Time 2 Minute Read

On January 15, 2026, the UK Information Commissioner’s Office published updated guidance on international transfers of personal data under the UK GDPR.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page