26 March 2024
The practice guide for the security of personal data aims at reminding the safety measures to be put in place. This new version overhauls the previous guide and introduces new factsheets, including ones on artificial intelligence, mobile applications, cloud computing and application programming interfaces (APIs).

The security obligation regarding the processing of personal data, enshrined in French law since 1978, has been reinforced by the GDPR. It might however be difficult, especially when unfamiliar with risk management methods, to implement such initiative and to ensure that the appropriate and necessary actions have been taken.
Through these factsheets, the CNIL’s practice guide for the security of personal data recalls both the elementary precautions that should be taken as well as the security measures intended for reinforcing data protection.
For this edition:
Additional and more sparse updates and improvements have been made in order to keep up with threats’ evolutions and knowledge’s development.
This guide is a reference whom data protection officers (DPO), chief information security officers (CISO), computer scientists or legal experts may use in the context of their activities for data security. This guide is also a reference used by the CNIL in order to asses the security of personnal data processing.