French Data Protection Authority Launches Public Consultation on Cloud Computing
Time 1 Minute Read

On October 17, 2011, the French Data Protection Authority (the “CNIL”) launched a public consultation on cloud computing (the “Consultation”). The Consultation seeks to gather opinions from stakeholders (clients, providers, consultants) regarding cloud computing services for businesses, to identify legal and technical solutions that address data protection concerns while taking into account the economic interests involved.

The Consultation addresses several specific topics about personal data protection in the cloud computing context, including:

  • The definition of cloud computing
  • Cloud computing providers as data processors
  • Applicable law (i.e., what law applies to cloud computing stakeholders?)
  • Regulation of data transfers (e.g., what legal instruments are best suited to regulate cloud computing? Would binding corporate rules for data processors be an appropriate legal mechanism for transferring personal data to cloud computing service providers?)
  • Data security (e.g., cloud-specific risks and proposed security measures)

Stakeholders may submit their contributions to the CNIL until November 17, 2011. The Consultation will then be used to draft specific guidelines that will be published on the CNIL’s website.

You May Also Be Interested In

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 2 Minute Read

On January 30, 2026, the Cybersecurity Administration of China released a Q&A document on policies and regulations for the security management of cross-border data transfers. 

Time 4 Minute Read

On January 20, 2026, the European Commission proposed a comprehensive new cybersecurity package aimed at strengthening the EU’s cybersecurity resilience and enhancing its capacity to manage evolving threats.

Time 1 Minute Read

On January 26, 2026, the Brazilian data protection authority (“ANPD”) announced that Brazil and the European Union agreed to mutually recognize the adequacy of each other’s data protection networks.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page