Personal Data

Conferences

conference

🎥”Compliance” et “conformité” : les distinguer/mieux les articuler afin que le DPO trouve sa juste place (Compliance Law” and “conformity” : distinguish between them/better articulate them so that the DPO finds their rightful place), in 🧮19ème Université AFCDP des DPO, in 🧮19ème Université AFCDP des DPO, in 🧮19ème Université AFCDP des DPO

► Full Reference: M.-A. Frison-Roche, "Compliance" et "conformité" : les distinguer/mieux les articuler afin que le DPO trouve sa juste place" ("Compliance Law" and "conformity" : distinguish between them/better articulate them so that the DPO finds their rightful place"), , in  Association française des correspondants à la protection des données à caractère personnel (AFCDP),  19ème Université AFCDP des DPO – La gouvernance des données ("Data Governance"), Maison de la Chimie, Paris, 7 February 2025 , 10h-10h45. - 🧮 see this manifestation full program (in French) - ⬜ see les slides on which this conference is done (in French)  - ► English Presentation of this conference: 'Compliance' and 'conformité' are often considered to be synonymous, notably in French in which the term "Compliance" is so often used to express only the "conformity" (conformité). This is a misunderstanding and a reduction, particularly of the role of professionals, notably DPOs. In fact, 'conformity' consists solely of ensuring that regulations are respected. Of course, an"active" conformity and "proven" conformity with these regulations, in particular the European GDPR. That and only that. If that's the case, then on the one hand this task impossible, because no one can comply with all the regulations, and it's the obsession with avoiding or reducing penalties that actually replaces the desire to do the right thing. On the other hand, algorithms are going to replace the DPO, a human being, because algorithms will identify 'non-conformity', then conformity, then write it down by "smart" contracts. But Compliance Law is more than conformity, which is only one of its tools. Compliance Law aim is to protect the human beings involved in the systems. Data protection is one of the best examples of this, and it underpins all the other areas of Compliance Law. Companies are asked to do less (obligation of means) and more: to help protect, by distinguishing between what must be revealed and what must be kept secret, sometimes to resolve conflicts between the 2 prescriptions, to educate, to make alliances. To built a real "governance". In this human and humanist mission that anchors Europe, the algorithm is flat. We are waiting for the DPO. In this human and humanist mission that anchors Europe, the algorithm is flat. We are waiting for the DPO. There is the role of guardian of the spirit of the texts, of strategic aid for the data controller, of adjuster of complementary or contradictory subjective rights, of adjustment of the texts in the European puzzle of a Regulatory Europe, which is being put in place in the humanist tradition which is its own to preserve the durability of the systems to protect the people who are forcibly or voluntarily involved in them. - 🌐suivre Marie-Anne Frison-Roche sur LinkedIn 🌐suivre Marie-Anne Frison-Roche sur Instagram 🌐s'abonner à la Newsletter MAFR Regulation, Compliance, Law 🌐s'abonner à la Newsletter en vidéo MAFR Surplomb/Overhang

Articles in The Journal of Regulation & Compliance « JoRC »

LATOUR, Daphné🕴️

📝Internal investigations within companies, in 🕴️M-A. Frison-Roche (ed.), 📘Compliance Jurisdictionalisation

► Full Reference: D. Latour, "Internal investigations within companies", in M.-A. Frison-Roche (ed.), Compliance Jurisdictionalisation,  Journal of Regulation & Compliance (JoRC) and Bruylant, "Compliance & Regulation" Serie, 2024, pp. 184-201 - 📘read a general presentation of the book, Compliance Jurisdictionalisation, in which this article is published - ► Summary of the article ():  - 🦉This article is available in full text to those registered for Professor Marie-Anne Frison-Roche's courses -

Articles in The Journal of Regulation & Compliance « JoRC »

GAVANON, Isabelle🕴️

📝Data Protection Law in the Digital Economy Confronted to Monumental Goals, in 🕴️M.-A. Frison-Roche (ed.), 📘Compliance Monumental Goals

► Full Reference: I. Gavanon, "Data Protection Law in the Digital Economy Confronted to Monumental Goals", in M.-A. Frison-Roche (ed.), Compliance Monumental Goals, coll. "Compliance & Regulation", Journal of Regulation & Compliance (JoRC) and Bruylant, 2023, pp. 137-146. - 📘read a general presentation of the book, Compliance Monumental Goals, in which this article is published. - ► Summary of the article:  -

Articles in a legal collective publication

LINDEN, Alexandre🕴️

📝Motivation and publicity of the decisions of the Restricted formation of the French Data Protection Authority (Commission nationale de l’informatique et des libertés – CNIL) in a compliance perspective, in 🕴️M.-A. Frison-Roche (ed.), 📘Compliance Jurisdictionalisation

► Full Reference : A. Linden, "Motivation and publicity of the decisions of the Restricted formation of the French Data Protection Authority (Commission nationale de l'informatique et des libertés – CNIL) in a compliance perspective", in M.-A. Frison-Roche (ed.), Compliance Jurisdictionalisation, Journal of Regulation & Compliance (JoRC) and Bruylant, coll. "Compliance & Regulation", to be published.  - 📘read a general presentation of the book, Complinace Jurisdictionalisation, in which this article is published - ► Summary of the article (done by the Journal of Regulation and Compliance): In the event of a breach of the personal data protection rules, the restricted formation of the French personal data protection Commission (CNIL) pronounces fines, injunctions of "compliance" or calls to order. It can order the publication of these measures, which can be contested before the French High Administrative supreme court (Conseil d'État). It is essential that these decisions be justified, not only in order to respect this principle of law but also concretely to obtain the public concerned, being very heterogeneous, understand them, the educational role of the CNIL also being applicable. The principle of publicity is handled with nuance, the data controllers often requesting a closed door and, in fact, very few public attending the hearing. The publicity of decisions is in itself a sanction. The publication may moreover not be total or may only have a time, anonymization often allowing the balance between necessary pedagogy and preservation of interests, the CNIL taking great attention to the very modalities of publication, even if it cannot control the circulation and the media use which is then made of it. - 🦉This article is available in full text to those registered for Professor Marie-Anne Frison-Roche's courses -

Breaking news

📧 Compliance and Ethics. Technologies may be inacceptable “in themselves” and designing their “ethical use” is therefore not acceptable: practical case on the control of workers’ emotions

► An article from March 3, 2021, Smile for the camera: the dark side of China's emotion-recognition tech, then an article from June 16, 2021, "Every smile you fake" – an AI emotion – recognition system can assess how "happy" China's workers are in the office describes how a new technology of emotional recognition is able, through what will soon be out of fashion to call "facial recognition", to distinguish a smile that reflects a mind state of real satisfaction from a smile which does not correspond to it. This allows the employer to measure the suitability of the human being for his or her work. It is promised that it will be used in an ethical way, to improve well-being at work. But isn't it in itself that this technology is incompatible with any compensation through ethical support? The technology developed by a Chinese technology company and acquired by other Chinese companies with many employees, allows to have information on the actual state of mind of the person through and beyond his or her facial expressions and bodily behavior. Previously, the technology of emotional recognition had been developed to ensure security, by fighting against people with hostile plans, public authorities using it for example in the controls at airports to detect the criminal plans which some passengers could have. It is now affirmed that it is not about fighting against some evil people ("dangerousness") to protect the group before the act is committed ("social defense”) but that it is about helping all workers. Indeed, the use that will be made of it will be ethical, because first the people who work for these Chinese companies with global activity, like Huawaï, do it freely and have accepted the operation of these artificial intelligence tools (which is not the case with people who travel, control being then a kind of necessary evil that they do not have to accept, which is imposed on them for the protection of the group), but even and above all, the purpose is itself ethical: if it turns out that the person does not feel well at work, that they are not happy there, even before they are perhaps aware, the company can assist. Let’s take this practical case from the perspective of Law and let’s imagine that it is contested before a judge applying the principles of Western Law. Would this be acceptable? No, and for three reasons. 1. An "ethical use" cannot justify an unethical process in itself 2. The first freedoms are negative 3. "Consent" should not be the only principle governing the technological and digital space   I. AN "ETHICAL USE" CAN NEVER LEGITIMATE AN UNETHICAL PROCESS IN ITSELF These unethical processes in themselves cannot be made "acceptable" by an "ethical use" which will be made of them. This principle was especially reminded by Sylviane Agacinski in bioethics: if one cannot dispose of another through a disposition of his or her body which makes his or her very person available (see not. Agacinski, S., ➡️📗Le tiers-corps. Réflexions sur le don d’organes, 2018). Except to make the person reduced to the thing that his or her body is, which is not ethically admissible in itself, that is excluded, and Law is there in order to this is not possible. This is even why the legal notion of "person", which is not a notion that goes without saying, which is a notion built by Western thought, acts as a bulwark so that human beings cannot be fully available to others, for example by placing their bodies on the market (see Frison-Roche, M.-A., ➡️📝To protect human beings, the ethical imperative of the legal notion of person, 2018). This is why, for example, as Sylviane Agacinski emphasizes, there is no ethical slavery (a slave who cannot be beaten, who must be well fed, etc.). That the human being agrees ("and what about if it pleases me to be beaten?") does not change anything.   II. THE FIRST FREEDOM IS THE ONE TO SAY NO, FOR EXAMPLE BY REFUSING TO REVEAL YOUR EMOTIONS: FOR EXAMPLE HIDING IF YOU ARE HAPPY OR NOT TO WORK The first freedom is not positive (being free to say Yes); it is negative (being free to say No). For example, the freedom of marriage is having the freedom not to marry before having the freedom to marry: if one does not have the freedom not to marry, then the freedom to marry loses any value. Likewise, the freedom to contract implies the freedom not to contract, etc. Thus, freedom in the company can take the form of freedom of speech, which allows people, according to procedures established by Law, to express their emotions, for example their anger or their disapproval, through the strike. But this freedom of speech, which is a positive freedom, has no value unless the worker has the fundamental freedom not to express his or her emotions. For example if he or she is not happy with his or her job, because he or she does not appreciate what he or she does, or he or she does not like the place where he or she works, or he or she does not like people with whom he or she works, his or her freedom of speech demands that he or she have the right not to express it. If the employer has a tool that allows him or her to obtain information about what the worker likes and dislikes, then the employee loses this first freedom. In the Western legal order, we must be able to consider that it is at the constitutional level that the infringement is carried out through Law of Persons (on the intimacy between the Law of Persons and the Constitutional Law, see Marais , A., ➡️📕Le Droit des personnes, 2021).   III. CONSENT SHOULD NOT BE THE ONLY PRINCIPLE GOVERNING THE TECHNOLOGICAL AND DIGITAL SPACE   We could consider that the case of the company is different from the case of the controls operated by the State for the monitoring of airports, because in the first case observed people are consenting. "Consent" is today the central notion, often presented as the future of what everyone wants: the "regulation" of technology, especially when it takes the form of algorithms ("artificial intelligence"), especially in digital space. "Consent" would allow "ethical use" and could establish the whole (on these issues, see Frison-Roche, M.-A., ➡️📝Having a good behavior in the digital space, 2019). "Consent" is a notion from which Law is today moving away in Law of Persons, in particular as regards the "consent" given by adolescents on the availability of their body, but not yet on digital. No doubt because in Contract Law, "consent" is almost synonymous with "free will", whereas they must be distinguished (see Frison-Roche, M.-A., ➡️📝Remarques sur la distinction entre la volonté et le consentement en Droit des contrats, 1995). But we see through this case, which precisely takes place in China, that "consent" is in Law as elsewhere a sign of submission. It is only in a probative way that it can constitute proof of a free will; this proof must not turn into an irrebuttable presumption. The Data Regulatory Authorities (for example in France the CNIL) seek to reconstitute this probative link between "consent" and "freedom to say No" so that technology does not allow by "mechanical consents", cut off from any connection with the principle of freedom which protects human beings, from dispossessing themselves (see Frison-Roche, M.-A., Yes to the principle of will, No to pure consents, 2018). The more the notion of consent will be peripheral, the more human beings will be able to be active and protected. -

Breaking news

📧 COMPLIANCE: LAW IS SLOW, BUT FIRM. BY ITS JUDGMENT OF JUNE 15, 2021, “FACEBOOK”, THE EUROPEAN UNION COURT OF JUSTICE WIDELY INTERPRETS THE POWER OF NATIONAL AUTHORITIES SINCE IT SERVES THE PROTECTION OF PEOPLE IN THE DIGITAL SPACE

► Law is slow, but firm. By its judgment of June 15, 2021, Facebook , the European Union Court of Justice widely interprets the powers of National Authorities, since they serve the people protection in the digital space (➡️📝(CJEU, June 15, 2021, Facebook).    Law is slow. The reproach is so often made. But the bottom line is that, in the noise of changing regulations, it establishes clear and firm principles, letting everyone know what to stand for. The more the world is changing, the more Law is required. When Law degenerates into regulations, then it is up to the Judge to make Law. "Supreme Courts" appear, de jure as in the United States, de facto as in the European Union by the Court of Justice of the European Union which lays down the principles, before everyone else, as it did for the "right to be forgotten" in 2014 (➡️📝CJEU, Google Spain, May 13, 2014), and then with the impossibility of transferring data to third countries without the consent of the people concerned (➡️📝CJEU, Schrems, October 6, 2015). Facebook litigation is kind of a novel. The company knows that it is above all to the Courts that it speaks. In Europe, it is doing it behind the walls of the Irish legal space, from which it would like to be able not to leave before better dominating the global digital space, while national regulatory authorities want to take it to protect citizens. There is therefore a technical question of "jurisdictional competence". The texts have provided for this, but Law is clumsy because it was designed for a world still anchored in the ground: the GDPR of 2016 therefore organizes cooperation between national regulatory authorities through a "one-stop-shop", forcing the authorities to relinquish jurisdiction so that the case is only handled by the "lead" National Authority. This avoids splintering and contradiction. But before the adoption of the GDPR, the Belgian data protection regulator had opened a procedure against Facebook concerning cookies. The "one-stop-shop" mechanism, introduced in 2016, is therefore only mentioned before the Brussels Court of Appeal, which is asked to relinquish jurisdiction in favor of the Irish Regulatory Authority, since the company has in Europe its head office in this country. The Court of Appeal referred to the CJEU for a preliminary ruling. By its judgment of June 15, 2021 (➡️📝CJUE, Facebook, June 15, 2021), it follows the conclusions of its Advocate General and maintains the jurisdiction of the Belgian National Regulator because, even after the GDPR, the case still undergoes national treatment. In this decision, the most important is its reasoning and the principle adopted. The Court notes that the "one-stop-shop" rule is not absolute and that the national regulatory authority has the power to maintain its jurisdiction, in particular if cooperation between national authorities is difficult. Even more, will it not one day have to adjust Law more radically? We need to consider the fact that the digital space is not bound by borders and that the ambition of "cross-border cooperation" is ill-suited. It is of course on this observation of inefficiency, consubstantial with the digital space, that the European Public Prosecutor's Office (EPPO) was designed and set up, which is not a cooperation, nor a "one-stop shop", but a body of the Union, acting locally for the Union, directly linked to Compliance concerns (➡️📝Frison-Roche, M.-A. "The European Public Prosecutor's Office is a considerable contribution to Compliance Law", 2021 and ., European Public Prosecutor's Office comes on stage: the company having itself become a private prosecutor, are we going towards an alliance of all prosecutors ?, 2021). So that's what we should be inspired by.

Articles

💬”Let’s Use the Power of GAFAMs in the Service of General Interest!” (“Utilisons la puissance des GAFAMs au service de l’intérêt général!”)

Full reference: Frison-Roche, M.-A., "Let's Use the Power of GAFAMs in the Service of General Interest!" ("Utilisons la puissance des GAFAMs au service de l'intérêt général!"), interview done by Olivia Dufour, Actu-juridiques Lextenso, 11st of January 2021 Read the interview (in French) To read the article translated in English by us, read the working paper on which this interview is based   Summary of the interview by Olivia Dufour: Marie-Anne Frison-Roche, Professor of Regulation and Compliance Law, reported to the government in 2019 about Internet governance. For this expert, giving a disciplinary power to GAFAMs is the only effective solution. And the suppression of Donald Trump's account is not likely to call this analysis into question.   The three questions (translated in English here by ourselves) asked by Olivia Dufour are:  The deletion of Donald Trump's Twitter account arouses strong emotions on social networks, and not only among his supporters. What do you think about this ? However, this incident does raise concern. Are we not giving too much power to these private companies? This raises the question in France of the relevance of the Avia system … Should we therefore resolve by default to give our freedoms to private and opaque mastodons?   Read the answers to these three questions (in French)   To go further, especially about the logics that guide the Avia system, see: Frison-Roche, M.-A., "Hate on internet: we need to responsibilize digital operators" ("Haine sur internet: il faut responsabiliser les opérateurs numériques"), 2020 Frison-Roche, M.-A., The contribution of Compliance Law to Internet Governance, report to Government, 2019

Books

VERGNOLLE, Suzanne

L’effectivité de la protection des personnes par le droit des données à caractère personnel (The effectiveness of the protection of people by personal data Law)

Full reference: Vergnolle, S., L'effectivité de la protection des personnes par le droit des données à caractère personnel (The effectiveness of the protection of people by personal data Law (our translation)), Passa, J. (dir.), thesis, Law, Panthéon-Assas University (Paris II), 2020, 531 p.   Read the thesis (in French) Read directly and only the table of contents (in French)     To go further about regulation of personal data, read:  Frison-Roche, M.-A., Rethinking the world from the notion of data, 2016 Frison-Roche, M.-A., The regulatory conséquences of a world redesigned from the concept of data, 2016. 

Articles

💬Facebook: Quand le Droit de la Compliance démontre sa capacité à protéger les personnes (Facebook: When Compliance Law proves its ability to protect people)

Full reference: Frison-Roche, M.-A., Facebook: Quand le Droit de la Compliance démontre sa capacité à protéger les personnes (Facebook: When Compliance Law proves its ability to protect people), interview with Olivia Dufour, Actu-juridiques Lextenso, 23rd of November 2020 Read the interview (in French) Read the news of the Newsletter MAFR – Law, Compliance, Regulation about this question