Cybersecurity Policy Report, France’s CNIL Publishes Guidance for App User Privacy, (Sep 25, 2024)
The French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL) released guidance for mobile application designers to enhance user privacy, given the increasing use of such apps by French citizens. In response to the release of the CNIL’s recommendations, the French competition authority, Autorité de la concurrence, published the opinion it issued to the CNIL in December 2023 as part of the preparation of the guidance.
The guidance targets all stakeholders involved in the development and provision of mobile apps to ensure enhanced protection of users’ personal data at every stage. The stakeholders include mobile application publishers, mobile application developers, software development kit providers, operating system providers, and app store providers.
The guidance clarifies and frames the role of each stakeholder, specifying the sharing of responsibilities between individuals and clarifying their respective obligations to provide legal certainty.
The guidance further provides advice and best practices to stakeholders in providing users information on how their data is being used. This ensures users understand whether the permissions requested are actually necessary for the application to function.
The guidance reminds stakeholders that apps must obtain consent to process data that is not necessary for their operation and specifies the conditions under which such consent must be requested. The guidance further stresses that consent should not be coerced and that consent can be refused or withdrawn as simply as it can be given.
To provide more certainty, the CNIL clarified its recommendations on several points. First, the CNIL distinguished between an obligation, which applies to everyone, from what is a recommendation or even good practice. It explained the interactions between its recommendations and the consideration of competitive issues, recalling that the recommendation must be applied in compliance with competition law and the European Union’s Digital Markets Act. Finally, the CNIL refocused its recommendations on permission systems by targeting so-called “technical” permissions, which allow the user to give or block access to certain information, regardless of the purposes for which they could be used.
In its 2023 opinion, which it issued to the CNIL as part of the preparation of its recommendations, the Autorité commented on the competition that may be raised by the CNIL’s guidance and made a series of recommendations to the CNIL. The Autorité stated that it generally believes privacy measures that go beyond what is strictly imposed by the EU’s General Data Protection Regulation (GDPR) are not per se unlawful but may be detrimental to the economic efficiency of the markets.
For this reason, they should be defined and implemented in a way that avoids generating anticompetitive effects that would not be counterbalanced by sufficient gains for consumers, it said. The Autorité called on the CNIL to take the competitive structure of the mobile application sector into account in its approach, being particularly attentive to ensuring that its recommendations do not risk strengthening the strong market power of certain players, especially those designated as gatekeepers for certain services or those that could be considered to be in a dominant position.
News: InternationalLegislation DataPrivacy