The implementation of the GDPR in the practice of towns and municipalities Implementation of the GDPR in France share of practice In « Département du Loiret » 1/8
French organization of public administrations Population : 65 billions - 1 State - 13 Regions - 101 " Départements " - 1263 EPCI (group of municipalities) - 35416 municipalities 2/8
Region « Département du « Centre Val de Loiret » Loire » Population : Population : 675 000 2.6 millions Is a « Département » with : - 16 EPCI Population b. 6900 & 282 000 - 326 municipalities Population b. 42 & 114 644 3/8
GDPR in France : GDPR was « long » to start : - 05.25.2018 : GDPR was going on - 06.20.2018 : The law on the protection of personnal data was promulgated - 08.01.2018 : French Regulation on protection of personal data is adopted. But, French government /Parliament want to be more efficient : - this law & regulation adapt both GDPR and the directive EC 2016/680 of the European Parliament & of the Council (personal data in the area of criminal offences & execution on the criminal penalties). - in 2018, some laws & regulations about cybersecurity was promulgated. 4/8
French Data Protection Authority (DPA) is called « CNIL » : Commission Nationale Informatique et Libertés => Liberty & Digital National Commission It provides advises to start the GDPR : 1 - Designate a DPO 2 - Design a data map 3 - Define priorities 4 - Manage risks 5 - Organize process 6 - Document conformity All tools helping us to work. 5/8
GDPR in « Le e Loir oiret et » I have 2 missions : - manage the GDPR in the « Département », our public administration, - Advise EPCI & municipalities on the territory of "Le Loiret" about GDPR. 3 most frequently discussed subjects (public actors) : - DPO designation - Confusion between consent (art. 7) & public interest (art. 6 - e) - Knowledge of the storage period of public datas 6/8
So Solu lutio tions ns th that at I am I am de deve velopin loping g : - An internal network : with digital risk officer, lawyer, IT engineer, open data & filing specialists - An external network : in my case with the DPO of all « Départements » in France - A legal monitoring - Training personal data correspondent previously identified in each team/organization. 7/8
Thank you for your attention 8/8
Recommend
More recommend