CNIL Publishes Latest Edition of Its Practice Guide for the Security of Personal Data
Time 1 Minute Read

On March 26, 2024, the French data protection authority (the “CNIL”) published the 2024 edition of its Practice Guide for the Security of Personal Data (the “Guide”). The Guide is intended to support organizations in their efforts to implement adequate security measures in compliance with their obligations under Article 32 of the EU General Data Protection Regulation. In particular, the Guide targets DPOs, CISOs, computer scientists and privacy lawyers.

The Guide is divided into the following five parts, each addressing key security themes: 1) users; 2) information technology and equipment; 3) control over data; 4) preparing for an incident; and 5) focus. The five parts are further divided into factsheets that provide a more detailed analysis of the relevant security requirements. The 2024 edition of the Guide includes several modifications and updates. Additionally, this edition integrates new factsheets on: 1) cloud computing; 2) mobile applications; 3) artificial intelligence; 4) application programming interfaces (APIs); and 5) data management security.

Read the Guide and the press release.

You May Also Be Interested In

Time 3 Minute Read

On March 24, 2026, Washington Governor Bob Ferguson signed House Bill 2225, an Act regulating artificial intelligence companion chatbots.

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 1 Minute Read

As reported on the Hunton Employment & Labor Perspectives blog, SB 574 is a California bill that would set specific duties for attorneys who use generative artificial intelligence and would restrict how arbitrators may use such tools in decision-making.

Time 3 Minute Read

SB 574 is a California bill that would set specific duties for attorneys who use generative artificial intelligence and would restrict how arbitrators may use such tools in decision-making. It would amend provisions in the Business and Professions Code and the Code of Civil Procedure to address confidentiality, accuracy, bias, and citation verification for attorneys, and to prohibit delegation of arbitral decision-making to AI while adding disclosure and responsibility requirements for arbitrators.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page