digital

Conferences

Jonathan L. ZITTRAIN

Gaining Power, Losing Control

Full reference: Zittrain, J. L., "Gaining Power, Losing Control", Clare Hall Tanner Lecture 2020, 2020 See the intervention Read the intervention's report   This intervention is divided in two parts:  Between Abdication and Suffocation: Three Eras of Governing Digital Platforms  With Great Power Comes Great Ignorance: What’s Wrong When Machine Learning Gets It Right 

Books

VERGNOLLE, Suzanne

L’effectivité de la protection des personnes par le droit des données à caractère personnel (The effectiveness of the protection of people by personal data Law)

Full reference: Vergnolle, S., L'effectivité de la protection des personnes par le droit des données à caractère personnel (The effectiveness of the protection of people by personal data Law (our translation)), Passa, J. (dir.), thesis, Law, Panthéon-Assas University (Paris II), 2020, 531 p.   Read the thesis (in French) Read directly and only the table of contents (in French)     To go further about regulation of personal data, read:  Frison-Roche, M.-A., Rethinking the world from the notion of data, 2016 Frison-Roche, M.-A., The regulatory conséquences of a world redesigned from the concept of data, 2016. 

Articles

💬Facebook: Quand le Droit de la Compliance démontre sa capacité à protéger les personnes (Facebook: When Compliance Law proves its ability to protect people)

Full reference: Frison-Roche, M.-A., Facebook: Quand le Droit de la Compliance démontre sa capacité à protéger les personnes (Facebook: When Compliance Law proves its ability to protect people), interview with Olivia Dufour, Actu-juridiques Lextenso, 23rd of November 2020 Read the interview (in French) Read the news of the Newsletter MAFR – Law, Compliance, Regulation about this question

Articles

FRISON-ROCHE, Marie-Anne

💬 “Health Data Hub est un coup de maître du Conseil d’État” (“Health Data Hub is a stroke of genius of the Conseil d’État”)

Full reference: Frison-Roche, M.-A., "Health Data Hub est un coup de maître du Conseil d'État", interview realized by Olivia Dufour for Actu-juridiques, Lextenso, 22nd of October 2020 Read the news of 19th of October 2020 of the Newsletter MAFR – Law, Compliance, Regulation on which relies this interview: Conditions for the legality of a platform managed by an American company hosting European health data​: French Conseil d'État decision  To go further, on the question of Compliance Law concerning Health Data Protection, read the news of 25th of August 2020: The always in expansion "Right to be Forgotten"​: a legitimate Oxymore in Compliance Law built on Information. Example of​ Cancer Survivors Protection 

Reports

Commission Nationale de l'Informatique et des Libertés (CNIL)

Lignes directrices et recommendations de la CNIL sur les cookies et autres traceurs (CNIL’s guidelines and recommendation about cookies and other trackers)

Full reference of the guidelines: Commission Nationale de l'Informatique et des Libertés (CNIL), Délibération n°2020-091 du 17 septembre 2020 portant adoption de lignes directrices relatives à l'application de l'article 82 de la loi du 6 janvier 1978 modifiée aux opérations de lecture et écriture dans le terminal d'un utilisateur (notamment aux "cookies et autres traceurs") et abrogeant la délibération n°2019-093 du 4 juillet 2019  Full reference of the recommendation: Commission Nationale de l'Informatique et des Libertés (CNIL), Délibération n°2020-092 du 17 septembre 2020 portant adoption d'une recommandation proposant des modalités pratiques de mise en conformité en cas de recours aux "cookies et autres traceurs".  Read the guidelines (in French) Read the recommendation (in French) Read the presentation of these guilines and of this recommendation by the CNIL (in French)  Read Marie-Anne Frison-Roche's comment about this in the Newsletter MAFR – Law, Regulation & Compliance of 1st of October 2020

Articles in a legal collective publication

📝 Se tenir bien dans l’espace digital (Having a good behavior in the digital space), in 📙Penser le droit de la pensée

Full reference: M.-A. Frison-Roche, Se tenir bien dans l'espace numérique, in Penser le droit de la pensée. Mélanges en l'honneur de Michel Vivant, Lexis Nexis and Dalloz, 2020, pp. 155-168. - 📝Read the article (in French) - 🚧Read the working paper, written in English, on which this article is based, with additional developments, technical references, and hyperlinks   English summary of the article: The digital space is one of the scarce spaces not framed by a specific branch of Law, Freedom also offering opportunity to its actors to not "behave well", that is to express and diffuse broadly and immediately hateful thoughts through Hate speechs, which remained before in private or limited circles. The intimacy of Law and of the legal notion of Person is broken: Digital permits to individuals or organizations to act as demultiplied and anonymous characters, digital depersonalized actors who carry behaviors that are hurtful to other's dignity.  Against that, Compliance Law offers an appropriate solution: internalizing in digital crucial operators the mission to disciplinary and substantially hold the digital space. The digital space has been structured by powerful firms able to maintain order. Because Law must not reduce digital space to be only a neutral market of digital prestations, these crucial operators, like social networks or search engines, must be forced to substantially control behaviors. It could be about an obligation of internet users to act with their face uncover, "real identity" policy controlled by firms, and to respect others' rights, privacy rights, dignity, intellectual property rights. In their Regulatory function, digital crucial firms must be supervised by public authorities.  Thus, Compliance law substantially defined is the protector of the person as "subject of law" in the digital space, by the respect that others must have, this space passing from the status of free space to the one of civilized space, in which everyone is obliged to behave well.  -   Read to go further:  Frison-Roche, M.-A., L'apport du Droit de la Compliance à la gouvernance d'Internet, 2019 Frison-Roche, M.-A. (dir.), Internet, un espace d'interrégulation, 2016 - 🌐follow Marie-Anne Frison-Roche on LinkedIn 🌐follow Marie-Anne Frison-Roche on Instagram 🌐subscribe to the Newsletter MAFR Regulation, Compliance, Law 

Articles

Responding to an email with “serious anomalies”​,transferring personal data, blocks reimbursement by the bank: French Cour de cassation, July 1st 2020

Full reference: Frison-Roche, M.-A., Responding to an email with "serious anomalies"​,transferring personal data, blocks reimbursement by the bank: French Cour de cassation, July 1st 2020, Newsletter MAFR – Law, Compliance, Regulation, 10th of September 2020 Read by freely subscribing other news of the Newsletter MAFR – Law, Compliance, Regulation   Summary of the news "Phishing" is a kind of cyber criminality aiming to obtain, by sending fraudulent emails which look like to those sent by legitimate organisms, recipient's personal information in order to impersonate or steal him or her. As it is difficult to find the authors of "phishing" and to prove their intentionality in order to punish them directly, on mean to fight against "phishing" could be to entitle banks to secure their information network and, to accompany this obligation with a strong incentive, to convict them to reimburse the victims in case of robbery of their personal data.   In 2015, a client victime of this kind of fraud asked to his bank, the Crédit Mutuel, to reimburse him the amount stole, what the bank refused to do on the grounds that the client committed a fault, transferring its confidential information without checking the email, however grossly counterfeit. The Court of first instance gave reason to the client because although he committed this fault, he was in good faith. This judgment was broken by the Chambre commerciale de la Cour de cassation (French Judicial Supreme Court) by a decision of 1st of July 2020 which states that this serious negligence, exclusive of any consideration of good faith, justifies the absence of reimbursement by the bank. -   From this particular case, we can draw three lessons:  The Cour de Cassation states that good faith is not a salient criterion and that, as the bank must react when a banking account is objectively abnormal, the client must react face to an obviously abnormal email.  The Cour de Cassation describes the repartition of proof burden. Proof obligations are alternatively distributed between the bank and its client. First, the bank must secure its information network but, secondly, the client must take every reasonable measure to preserve its safety. It results from this that, if the email seems normal, phishing damages must be supported by the bank, and more generally of by the firm, while if the email is obviously abnormal, they must be supported by the client, but the burden to prove the abnormality of the email must be supported by the firm and not by the client.  Such a proof system shows that Compliance Law includes a pedagogic mission by educating each client in order to he or she would be able to distinguish among his or her emails, those which are normal and those which are obviously suspect. This pedagogic dimension, with the legal consequences associated to it, will not stop to spread.    -

Articles

For regulating or supervising, technical competence is required: example of the French creation of the “Pôle d’expertise de la régulation numérique “​

Full reference: Frison-Roche, M.-A., For regulating or supervising, technical competence is required: example of the French creation of the "Pôle d'expertise de la régulation numérique"​, Newsletter MAFR – Law, Regulation, Compliance, 2nd of September 2020 Lire par abonnement gratuit d'autres news de la Newsletter MAFR – Law, Regulation, Compliance   Summary of the news Through a decree of 31st of August 2020, the government created a national service, the "Pôle d'expertise de la régulation numérique" (digital regulation expertise pole). It has to furnish to State services a technical expertise in computer science, data science and algorithm processes in order to assist them in their role of control, investigation and study. The aim is to favor information sharing between researchers and State services in charge of regulating digital space.  As its acronym indicates, this pole of expertise aims to represents constance in a changing world. Moreover, more than being a national service, this organism must adopt a transversal dimension, its creation decree being signed by the Prime Minister, Minister of Economy, Minister of Culture and Minister of Digital Transition. The creation of such a pole shows the awareness of the government of the importance of technical competency in the regulation of digital space and of the necessity to centralize these expertises in one organ.  However, as the decree indicates, this pole of expertise could be consulted only by "State services", that excludes regulators which are independent from the State and which could put the pole in conflict of interest, and courts even if they are supposed to play a central role in the regulation of digital space and even if they are allowed to ask the advice of the regulator about some cases. But if regulators cannot size the pole, to whom does it benefit except the legislator and a few officials?  It would therefore have been better for this pole of expertise to be placed under the direction of regulatory and supervisory bodies, which would have enabled it to be able to be consulted both by regulators and by judges, both of whom are key players in digital regulation.

Articles

Compliance by Design, a new weapon? Opinion of Facebook about Apple new technical dispositions on Personal Data protection.

Full reference: Frison-Roche, M.-A., Compliance by Design, a new weapon? Opinion of Facebook about Apple new technical dispositions on Personal Data protection, Newsletter MAFR – Law, Compliance, Regulation, 31st of August 2020 Read by freely subscribing other news of the Newsletter MAFR – Law, Compliance, Regulation   Summary of the news: Personal Data, as they are information, are Compliance Tools. They represent a precious resource for firms which must implement a vigilance plan in order to prevent corruption, money laundering or terrorism financing, for examples. It is the reason why personal data are the angular stone of "Compliance by design" systems. However, the use of these data cannot clear the firm of its simultaneous obligation to protect these same personal data, that is also a "monumental goal" of Compliance Law.  In order to be able to exploit these data in an objective of Compliance and protecting them in the same time, the digital firm Apple adopted for example new dispositions in order to the exploitation of the Identifier For Advertisers (IDFA) integrated in the iPad and in the iPhone and broadly used by targeted advertising firms, is conditioned to the consumer's consent. Facebook reacted to this new disposition explaining that such measures will restrict the access to data for advertisers who will suffer from that. Facebook suspects Apple to block the access to advertisers in order to develop its own advertising tool. Facebook guaranteed to advertisers who work with it that it will not take similar measures and that it will always favor consultation before decision making in order to concile sometimes divergent interests.  We can sleep and already make some remarks: GDPR imposing to companies that they guarantee a minimal level of protection for personal data does not apply in the United-States. It is then possible that Apple acted through Corporate Social Responsibility (CSR), more than through legal obligation.  The mode of regulation used here is the "conversational regulation" theorized by Julia Black. Indeed, regulators let the forces in presence discuss.  This "conversational regulation" does not seem to be very efficient in this case and an intervention of administrative authorities or of judges could be justified via Competition Law, Regulation Law or Compliance Law, knowing that Competition Law will favor access right to information and Regulation or Compliance Law private life right.  The whole paradox of Compliance Law rests in the equilibrium between circulation of information and secret. 

Articles

“Interregulation”​ between Payments System and Personal Data Protection: how to organize this “interplay”​?

Full reference: Frison-Roche, M.-A., "Interregulation"​ between Payments System and Personal Data Protection: how to organize this "interplay"​?, Newsletter MAFR – Law, Compliance, Regulation, 27th of August 2020 Read by freely subscribing the other news of the Newsletter MAFR – Law, Compliance, Regulation   Summary of the news Regulation Law, in order to recognize and draw the consequences from the specificities of some objects, has been build, at the start, around the notion of "technical sector" although their delimitation is partially related to a political choice. But, in facts, there are multiple points of contacts between sectors, actors moving from one to another as objects. The regulatory solution is so to climb over some technical borders through the methodology of interregulation which is by the way the only one to enable the regulation of some phenomena going beyond the notion of sector and related to Compliance Law.  This news takes the exemple of companies furnishing new payment services. In order to they can provide these services, these firms needs to access to banking accounts of concerned people and so to very sensitive personal data. Regulation of such a configuration needs a cooperation between the banking regulator and the personal data regulator. Legislation being not sufficient to organize in Ex Ante this interregulation, the European Data Protection Board has published some guidelines on 17th of July 2020 about the way it conceives the articulation between the PSD2 (European directive about payment services) and GDPR and has announced that it intended to expand the circle of its interlocutors to do this interregulation. Such an initiative from EDPB can be justified by the uncertainty  about how interpreting both texts and articulating them.   

Articles

Is Regulating Hate and Infox a legal obligation imposed to the Digital Enterprises or the expression of their free will to contribute to Democracy?

Full reference: Frison-Roche, M.-A., Is Regulating Hate and Infox a legal obligation imposed to the Digital Enterprises or the expression of their free will to contribute to Democracy?, Newsletter MAFR – Law, Compliance, Regulation, 14th of August 2020 Read, by freely subscribing, other news in the Newsletter MAFR – Law, Compliance, Regulation   Summary of the news Internet permits to access to expanded knowledge but also make easier the broadcasting of fake news and hate speeches. Unfortunately, public powers cannot know who broadcast these fake news and hate speeches and are so not able to fight efficiently against this. A solution would be to expect from digital firms that they find a way to contain these fake news and hate speeches that they structurally contribute to diffuse.  Digital firms already do that and especially Facebook which plans to sensibilize its American users to 2020 presidential elections. However, digital firms explain that if they fight against fake news and hate speeches, it is only because of its Corporate Social Responsibility (CSR). But, even if it is a calculus to get a better reputation and avoid boycott actions, this remains a willingness of the firm which is therefore neither forced to succeed, nor even to act.  The solution proposed by Compliance Law is to make of this effort a legal obligation by internalizing in crucial operators (digital firms) the "monumental goal" to fight against fake news and hate speeches so that digital companies are required to act and that they are supervised by public authorities in this task. The forthcoming law about digital services will impose to digital firms Ex Ante obligations while the law of 22 of December 2018 related to the fight against information manipulation already forces platforms operators a legal obligation to "cooperate" in the fight against fake news.    To go further, read :  Frison-Roche, M.-A., When Facebook "Invite" Each Internet User to Act Against COVID-19 by Redirecting Him or Her Towards Public Information Center, Is It by Legal Obligation (Compliance) or by Corporate Social Responsibility (CSR)? With Which Consequences?, working paper, 2020 Frison-Roche, M.-A., Having a Good Behavior in the Digital Space, working paper, 2020

Reports

Bilan Infox, 2019

Books

QUEMENER, Myriam, DALLE, Frédérique, WIERRE, Clément

Quels droits face aux innovations numériques ?

Full reference : Quéméner, M., Dalle, F. and Wierre, Cl., Quels droits face aux innovations numériques ? Législations, jurisprudences et bonnes pratiques du cyberespecac. Défis et protections face aux dérives du numérique, preface by Agathe Lepage, Gualino-Lextenso, 223 pages, 2020.   Read the back cover.   Read the table of contents.   Read the preface.

Articles in The Journal of Regulation & Compliance « JoRC »

When Facebook “Invite” Each Internet User to Act Against COVID-19 by Redirecting Him or Her Towards Public Information Center, Is It by Legal Obligation (Compliance) or by Corporate Social Responsibility? With Which Consequences?

Without any request, on his or her newsfeed, those who surfs on the social network built by Facebook, has found on 23 of March 2020, in the morning, the following message : « X (prénom de l'internaute), agissez maintenant pour ralentir la propagation du coronavirus (COVID-19) Retrouvez les actualités des autorités sanitaires et institutions publiques, des conseils pour ralentir la propagation du coronavirus et des ressources pour vous et vos proches dans le Centre d’information sur le coronavirus (COVID-19)" ("X (user's name), act now to slow down the spread of the Coronavirus (COVID-19). Find the health authorities and public institutions' news, advices to slow down the spread of the Coronavirus for you and your entourage in the Information Center about Coronavirus (COVID-19) »). This corresponds to the more general declaration done the same day by Kang-Xing Jin, director of Health at Facebook, who declares : "In response to the coronavirus outbreak, Facebook is supporting the global public health community’s work to keep people safe and informed. Since the World Health Organization declared the coronavirus a public health emergency in January, we’ve taken steps to make sure everyone has access to accurate information, stop misinformation and harmful content, and support global health experts, local governments, businesses and communities.". Thanks, Facebook to indicate how to do ; by the way, thanks to having invited me to do it. By the way, is it really an « invitation » ? Since the expression is « act now ». Just miss the exclamation point, and the pointed finger of Uncle Sam for « war effort ». If in Law, we can consider « invitation », it would be not to the "invitation" that in the past Bank of France did to shareholders banks to refinance a bank which risks to be soon into difficulties that we could consider, invitation from which the invited cannot really escape. No, obviously no, it is just the same message that you and me can write on our Facebook pages to tell similar things about the same purpose ! But, Facebook would be, like you and me, editor of contents ? Questions and difficulties which encourage to proceed to the legal analysis to know under which title Facebook posted such a message. The first hypothesis is that this firm has acted spontaneously, following its « Corporate Social Responsibility » (I) If it is the right qualification, with regards to the content of the message, legal consequences are important because this firm, without generalizing to others, by the expression of its care of common good, shows, by transitivity, that it is an editor. The second hypothesis starts from the observation that Facebook is a « crucial digital operator ». In this perspective, the firm is constraint to Compliance Law (II). It is the reason why, it is constraint by specific obligations, that excludes the spontaneous message emission qualification. If it is the right qualification, with regards to the content of the message, legal consequences are also important and of a totally different nature. Indeed, the qualification leads to develop the relation between the obligation to fight against fake news and malicious websites towards those of redirecting towards public websites, benefiting for the operator of a reliability presumption. Read the developments below.

Articles

Compliance Law to Regulate the Internet

Reference Frison-Roche, M.-A., Le droit de la compliance pour réguler l'internet  (Compliance Law to Regulate the Internet), Interview given in French to Sylvie Rozenfeld, Expertises, December 2019, pp. 385-390.   Summary. Law seems increasingly powerless to stem the social disorder generated by the Internet. For Marie-Anne Frison-Roche, Law professor and specialist in Regulatory Law, the solution is to be found in Law, and more particularly in Compliance Law. This specific Law is already applied in the banking and finance sector, or in the area of ​​personal data. As it has done for green finance and through the GDPR, Europe could impose a compliance system which internalizes concern for the individual in large digital operators. It is up to them to put in place the means and bear the cost, such as the right to be forgotten erected by the CJEU. Marie-Anne Frison-Roche does not offer anything revolutionary, she is content to take elements of positive law that already exist and to correlate them.   Read the interview (in French)   Read the presentation of the official Report for the French Government about which this interview is given:: The contribution of Compliance Law to the Governance of Internet.