French Data Protection Authority Discloses Its 2013 Inspection Program
Time 1 Minute Read

On March 19, 2013, the French Data Protection Authority (“CNIL”) announced (in French) its annual inspection program, providing an overview of its inspections of data controllers in 2012 and a list of inspections that it plans to conduct in 2013. Under French data protection law, the CNIL is authorized to collect any useful information in connection with its investigations and has access to data controllers’ electronic data and data processing programs.

The CNIL reportedly conducted 458 “on-the-spot” investigations in 2012 (which is 19% more than in 2011). Of those, 173 inspections related to data controllers’ CCTV monitoring, some of which resulted in formal notices and administrative sanctions imposed by the CNIL.

The CNIL also announced that a target of 400 “on-the-spot” inspections was set for 2013 and that a quarter of these inspections will focus on CCTV. Other inspections are likely to be triggered by:

  • The processing of personal data by market research institutes;
  • The processing of personal data in the context of free access Internet services;
  • The processing by French local authorities of personal data relating to individuals’ social difficulties;
  • The processing of personal data related to incarcerated individuals; and
  • The data processing activities of the French police services.

You May Also Be Interested In

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 3 Minute Read

Indiana’s comprehensive consumer privacy law, the Indiana Consumer Data Protection Act, is set to take effect on January 1, 2026. In advance of the law’s effective date, the Indiana Attorney General’s Office has published a Consumer Bill of Rights that provides guidance to both consumers and businesses.

Time 2 Minute Read

On November 17, 2025, the Council of the European Union adopted new rules designed to strengthen cooperation among national data protection authorities, enhancing the enforcement of the EU General Data Protection Regulation.

Time 1 Minute Read

On October 14, 2025, the European Data Protection Board announced that its fifth coordinated enforcement action will focus on compliance with the transparency and information requirements under the GDPR.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page