On May 28th, the Commission nationale de l’informatique et des libertés (“CNIL”), the French authority responsible for data privacy, published guidance on breach notification law affecting electronic communications service providers. The guidance was issued with reference to European Directive 2002/58/EC, the e-Privacy Directive, which imposes specific breach notification requirements on electronic communication service providers.
French legislator recently amended Article 34 of the Data Protection Act to reflect the EU e-Privacy Directive’s breach notification requirement.According to Article 34 of the French data protection law (as revised), the notification obligations are applicable if:
- Personal data is processed;
- By an electronic communications service provider;
- During the course of its business of providing electronic communications services (e.g. telephone service or internet access)