What Changed
- Reviewed Apple ATT developments and adopted post-consultation recommendations on session replay tools.
- Renewed accreditations for BYCYB and Bureau Veritas Italia SPA as CISPE cloud code of conduct monitoring bodies.
- Evaluated draft decrees on prison body cameras, automated noise control radars, and the SI-Mandoline adult protection database.
The French Data Protection Authority (Commission nationale de l'informatique et des libertés, CNIL) released the agendas for its weekly plenary sessions held on 17 September, 24 September, 1 October, and 8 October 2026. The agendas detail regulatory evaluations, opinions on draft decrees, sectoral hearings, and European policy initiatives affecting organizations operating in France and across the European Union.
Key commercial and technical topics reviewed during the sessions include:
- Apple's App Tracking Transparency (ATT): A presentation on the history, stakes, and developments surrounding Apple's tracking solution.
- Session Replay Tools: Examination of a draft recommendation regarding session replay tools following a public consultation.
- Real Estate Data Collection: A hearing with the Union des syndicats de l'immobilier (UNIS) concerning data collection practices in property rentals.
- Cloud Infrastructure Codes of Conduct: Deliberations renewing the accreditations of BYCYB and Bureau Veritas Italia SPA as monitoring bodies for the European code of conduct established by CISPE (Cloud Infrastructure Service Providers Europe).
- European Processor Certification: A presentation regarding a CNIL-led European certification project for data processors, intended for approval by the European Data Protection Board (EDPB).
In the public and health sectors, CNIL examined several draft legislative and administrative measures. These include draft decrees on embedded cameras for prison surveillance personnel, automated noise monitoring systems ("radars sonores") for moving vehicles, an educational establishment questionnaire on gender-based and sexual violence, and the "SI-Mandoline" database for adult legal protection. Additionally, CNIL authorized BIG DATA SANTE (Octopize Mimethik Data) to process data for the "ONCOVAL" medical research project to build anonymized datasets.
These agendas demonstrate CNIL's active oversight across commercial tracking technologies, cloud governance, public sector surveillance, and health research. Entities processing personal data in France or offering cloud and digital services across the EU should monitor the publication of resulting final opinions and recommendations.
Who May Be Affected
Digital advertisers, app developers using tracking tools, cloud service providers under the CISPE code, medical research organizations, educational institutions, and public safety authorities in France.
Cross-Border Context
Affects international tech companies (Apple), European cloud service providers under the CISPE framework, and EU-wide processor certification initiatives overseen by the EDPB.
What to check next
- Final text of the CNIL recommendation on session replay tools following public consultation.
- EDPB approval status of the CNIL-led European processor certification scheme.
- Publication of adopted decrees in the Journal Officiel de la République Française regarding noise radars and prison cameras.
This article provides general information and does not constitute legal advice. Consult the official text and obtain advice appropriate to your circumstances where needed.