CNIL Publishes List of Processing Operations Not Subject to DPIA
Time 2 Minute Read

On October 22, 2019, the French Data Protection Authority (the “CNIL”) published a list of processing operations (in French) that it considers not requiring a data protection impact assessment (“DPIA”). The CNIL had previously adopted and published a final list of processing operations requiring a DPIA on November 6, 2018. The final list includes 12 types of processing operations for which a DPIA is not considered mandatory. The CNIL provided concrete examples for each type of processing operation, including:

  • processing operations for HR purposes for companies employing less than 250 employees and excluding profiling (payroll, employees training, time management, use of communication tools, management of annual evaluations and expenses reimbursement);
  • processing operations for vendor management purposes (to perform administrative operations in relation to contracts, orders and billing; to establish vendors’ financial statistics and turnover, and to maintain vendors documentation); and
  • processing operations for controlling physical access to buildings or working hours (with the exclusion of biometric systems and under the condition that they do not include sensitive data).
The CNIL emphasized that this list was not exhaustive and some processing operations not included in the list also could be exempt from a DPIA, provided they are not presenting a high risk for the rights and freedoms of individuals.

You May Also Be Interested In

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 2 Minute Read

On November 17, 2025, the Council of the European Union adopted new rules designed to strengthen cooperation among national data protection authorities, enhancing the enforcement of the EU General Data Protection Regulation.

Time 1 Minute Read

On October 14, 2025, the European Data Protection Board announced that its fifth coordinated enforcement action will focus on compliance with the transparency and information requirements under the GDPR.

Time 1 Minute Read

On June 19, 2025, the UK Data (Use and Access) Act 2025 received Royal Assent. The same day, the UK Information Commissioner’s Office published a comprehensive suite of resources on the Act.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page