French DPA Releases New Guidance on Outsourcing Activities
Time 2 Minute Read

On October 11, 2010, the French Data Protection Authority (the “CNIL”) released guidance (the “Guidance”) on data protection issues related to the outsourcing of data processing activities to non-EU countries (Les questions posées pour la protection des données personnelles par l’externalisation hors de l’Union européenne des traitements informatiques).

The Guidance was prepared following interviews held in 2009 by the CNIL’s international affairs department with consultancy groups, law firms advising on outsourcing deals, and companies actively engaged in offshore activities.  The interviews were conducted to provide the CNIL with insight regarding the impact of data protection requirements on outsourcing activities.  The Guidance is part of a broader analysis of the concepts of data controller and data processor carried out by the Article 29 Working Party (see the Working Party’s Opinion on the concepts of controller and processor).

The Guidance provides concrete examples of international data transfers and offers practical solutions to data controllers who transfer personal data to data processors located in non-EU countries.  In particular, the Guidance addresses the following topics:

  • Defining the roles of data controllers and data processors
  • Applying the legal restrictions on transfers of personal data outside the EU to outsourcing activities
  • Determining the responsibilities of data controllers and data processors
  • Specifying the registration formalities for data transfers
  • Supporting the efforts of countries that have established data protection regimes to help secure an adequacy decision from the EU Commission (e.g., Morocco, Tunisia)

You May Also Be Interested In

Time 2 Minute Read

On January 30, 2026, the Cybersecurity Administration of China released a Q&A document on policies and regulations for the security management of cross-border data transfers. 

Time 1 Minute Read

On January 26, 2026, the Brazilian data protection authority (“ANPD”) announced that Brazil and the European Union agreed to mutually recognize the adequacy of each other’s data protection networks.

Time 2 Minute Read

On January 15, 2026, the UK Information Commissioner’s Office published updated guidance on international transfers of personal data under the UK GDPR.

Time 3 Minute Read

Indiana’s comprehensive consumer privacy law, the Indiana Consumer Data Protection Act, is set to take effect on January 1, 2026. In advance of the law’s effective date, the Indiana Attorney General’s Office has published a Consumer Bill of Rights that provides guidance to both consumers and businesses.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page