{"id":64277,"date":"2024-10-22T19:24:24","date_gmt":"2024-10-22T17:24:24","guid":{"rendered":"https:\/\/www.cecile-zakine.fr\/?page_id=64277"},"modified":"2024-10-22T22:34:05","modified_gmt":"2024-10-22T20:34:05","slug":"quelle-est-la-procedure-avant-les-sanctions-cnil-rgpd-amende-que-faire","status":"publish","type":"page","link":"https:\/\/www.cecile-zakine.fr\/en\/quelle-est-la-procedure-avant-les-sanctions-cnil-rgpd-amende-que-faire\/","title":{"rendered":"What is the procedure before the CNIL GDPR sanctions? Fine what to do?"},"content":{"rendered":"

[et_pb_section fb_built=\u00a0\u00bb1″ _builder_version=\u00a0\u00bb4.27.2″ _module_preset=\u00a0\u00bbdefault\u00a0\u00bb global_colors_info=\u00a0\u00bb{}\u00a0\u00bb][et_pb_row _builder_version=\u00a0\u00bb4.27.2″ _module_preset=\u00a0\u00bbdefault\u00a0\u00bb global_colors_info=\u00a0\u00bb{}\u00a0\u00bb][et_pb_column type=\u00a0\u00bb4_4″ _builder_version=\u00a0\u00bb4.27.2″ _module_preset=\u00a0\u00bbdefault\u00a0\u00bb global_colors_info=\u00a0\u00bb{}\u00a0\u00bb][et_pb_text _builder_version=\u00a0\u00bb4.27.2″ _module_preset=\u00a0\u00bbdefault\u00a0\u00bb global_colors_info=\u00a0\u00bb{}\u00a0\u00bb]<\/p>\n

Steps to follow when the CNIL requests explanations on the processing of personal data: risks and recommendations<\/strong><\/h1>\n

When a company receives a letter from the French Data Protection Authority (CNIL) requesting explanations about its personal data processing practices, it is faced with a delicate situation that requires a rapid, rigorous response that complies with the requirements of the General Data Protection Regulation (GDPR). Indeed, an inadequate response can lead to serious consequences, including administrative penalties of up to \u20ac20 million or \u20ac4.1 billion of annual global turnover (Article 83 of the GDPR). This article examines the steps to take when faced with such a letter, the risks involved, the opportunity to submit a Data Protection Impact Assessment (DPIA), as well as the three key elements to provide in the response to avoid litigation.<\/strong><\/p>\n

1. Steps to follow in response to a letter from the CNIL<\/strong><\/h2>\n

The CNIL, as the supervisory authority responsible for ensuring compliance with data protection laws, can send a letter to companies to obtain information on the processing of personal data that they carry out. This letter may have different motivations: a complaint from an individual, a scheduled inspection, or a verification linked to a report. Whatever the reasons, it is essential to treat the request seriously and quickly.<\/p>\n

a. Carefully analyze the contents of the mail<\/em><\/h3>\n

The first step is to carefully read the application for the CNIL<\/a>The letter may request specific information on certain data processing, the justification of their legal basis, the security measures implemented, or even details on the internal procedures allowing the exercise of rights<\/a> of the persons concerned. It is crucial to understand what is expected, the response times indicated, and the documents to be provided.<\/p>\n

b. Prepare a complete file to respond to the request<\/em><\/h3>\n

After identifying the requested information, a complete and documented file should be put together. This file must include in particular:<\/p>\n