France: CNIL publishes guidance on health authorisation requests
The French data protection authority ('CNIL') announced, on 6 February 2023, that it had published two sets of guidelines on health authorisation requests. In particular, CNIL explained that the guidance aims to aid data controllers in submitting their requests for authorisation of processing in the field of healthcare for research and non-research purposes.
In addition, CNIL clarified that any request for authorisation filed with CNIL must detail the characteristics of the envisaged processing, both in terms of its legal and technical aspects, so that CNIL can ensure that the processing project complies with the relevant provisions of the General Data Protection Regulation (Regulation (EU) 2016/679) ('GDPR'). Notably, CNIL explained that the guidance covers the main characteristics of data processing in the health field, and provides input on key aspects that data controllers should consider before filing an application for authorisation with CNIL.
Lastly, CNIL indicates what information needs to be provided by data controllers in order for CNIL to give its authorisation.
You can read the press release here and the guidelines here and here, all only available in French.