Hogan Lovells logo
  • Our people
  • What we do
    Sectors Practices Legal Tech
    • Aerospace and Defense
    • Automotive and Mobility
    • Consumer
    • Education
    • Energy
    • Financial Institutions
    • Insurance
    • Life Sciences and Health Care
    • Manufacturing and Industrials
    • Private Capital
    • Real Estate
    • Sports, Media and Entertainment
    • Technology
    • Transportation and Logistics
    • Corporate & Finance
    • Disputes
    • Intellectual Property
    • Regulatory
  • Case studies
  • Our thinking
    • All Our thinking
    • Comparative guides
    • Digital Client Solutions
    • Events and webinars
    • Podcasts
    News image_2

    Reflecting on President Trump’s first 100 days in office

  • ESG
  • Careers
Search Search
close
Search Search Search
lang-sel-icon English
  • Deutsch
  • English
  • Español
  • Français
  • 日本語
  • 中文
False
people-new
Mobile area
  • About us
    • Overview
    • Our history
    • Global management team
  • Where we are
    • Our locations
    • Law Firm Network
  • Media center
    • Media contacts
    • Press releases
    • Awards & rankings
  • Responsible Business
  • HL Inclusion
  • Alumni
LinkedIn
Youtube
twitter
Wechat
News

New CNIL’s guidelines on AI models: a practical approach amidst EU’s regulatory tangles

18 February 2025
""
""
wechat x linkedin
hogan-lovells-logo
Share by email
Enter email
Enter Subject
Cancel
Send
News
New CNIL’s guidelines on AI models: a practical approach amidst EU’s regulatory tangles
Chapter
  • Chapter

  • Chapter 1

    Main takeaways of CNIL's new AI guidelines
  • Chapter 2

    CNIL's pragmatic approach does not make a European solution...yet

Key takeaways

Finding a European consensus around the regulation of artificial intelligence (AI) does not start with the adoption of laws. It results from their common interpretation and articulation within a broader digital regulatory framework, in the context of a fierce global race for innovation and power. While each stone makes a building, some of them provide some foundations for further accomplishments. These latest guidelines from the CNIL illustrate a more pragmatic approach than other regulatory positions addressing multiple issues raised by AI. The truth will depend on further consensuses, but there is still room for ambition and action.

On February 7, 2025, the French Data Protection Authority (CNIL), following a public consultation, has issued two new guidelines on (i) the information of data subjects and (ii) the respect for their rights in the context of AI models.

These new guidelines, together with several other guidance and recommendations in relation to AI already published by the CNIL, demonstrate the practical approach taken by the CNIL to balance innovation with the protection of individuals' rights and compliance with applicable regulations.

The CNIL approach also reflects a divergence at the EU level, which will necessitate arbitration and clear position from the European institutions and other EU regulators of digital services.

Chapter 1

1

Main takeaways of CNIL's new AI guidelines

expanded collapse

Information of data subjects

The CNIL's guidelines on informing data subjects about AI data processing emphasize the importance of transparency and accountability. Following the public consultation, the CNIL has refined its approach to balance the need for detailed information with practical considerations, particularly concerning indirect data collection and web scraping.

One of the key adjustments after the public consultation involves the details to be provided into the information notice regarding the sources of training data containing personal data. For scenarios where data is collected from numerous public sources, CNIL recommends providing an information notice that only indicates categories or typical sources of training data, rather than listing each source individually. For example, if an AI model is trained using data from numerous news websites, CNIL advises that the notice states that data is sourced from "online news outlets" rather than specifying each of them. CNIL recommends similar approach in the context of data scraping, by mentioning only that data may be collected from “social media sites”, without listing every platform individually. This method allows for transparency while acknowledging the practical limitations of providing exhaustive details. 

Exercise of data subjects' rights

The CNIL's guidelines also place a strong emphasis on respecting and facilitating the exercise of data subjects’ rights. Under GDPR, these rights include the right to access, rectify and erase personal data, as well as the right to object to some of their processing.

As part of the key recommendations, the CNIL guidelines highlight the importance of establishing clear mechanisms for responding to data subjects’ requests for rectification. For instance, if a data subject requests the correction of inaccurate personal data used to train or to run an AI model, the developer should implement a verification process and update the data promptly. The CNIL suggests using version control systems to track changes and ensure that rectifications are applied consistently across datasets.

The CNIL also recommends using filtering techniques to manage data outputs without necessitating a complete re-training of the AI model. This specific recommendation for ‘outputs’ seems much more practical than the right of access or rectification applied to training data (‘inputs’). For example, if a data subject requests the removal of their data from an AI system, filters can be applied to ensure that the data is not used in future outputs. This approach allows for compliance with data subjects’ rights without the need for resource-intensive re-training processes.

Indeed, the CNIL acknowledges that the exercise of data subjects’ rights must be balanced against operational realities. Therefore, since re-training an AI model to accommodate a data subject's request is deemed disproportionately burdensome, CNIL suggests that alternative measures such as data anonymization or pseudonymization should be considered. It provides examples of scenarios where such measures can be effectively implemented at ‘input’ or even ‘scraping’ levels, to protect data subjects' rights, while minimizing further operational disruptions.

Chapter 2

2

CNIL's pragmatic approach does not make a European solution...yet

expanded collapse

The timing of the CNIL approach reflects a wise communication strategy in the context of the AI Action Summit which took place right after in Paris (Feb. 10-13, 2025) and the massive private investments appraised by the French government for the coming years for the development of AI infrastructures (mainly data centers) and tools and to support EU-based companies developing AI-based services and products. 

The CNIL still recognizes the need to balance data protection with the practical realities of AI-related developments. It has shown flexibility in its previous approach of legitimate interest as a workable legal basis, as well as in addressing with these newly published guidelines the powerful feedbacks and concerns expressed during the consultation process by numerous industry professionals, researchers, and civil society organizations, to ensure that data protection measures are both effective and feasible.

This contrasts with the general approach at the EU level. The European AI Act, while essential for establishing a governance framework for AI, has for example been criticized for its complexity. The contrast between the CNIL's flexible approach and the more rigid stance at the EU institutions’ level (Parliament and Commission) underscores the need for a balanced and coordinated regulatory environment that supports both data protection – among others EU values – and innovation.

This also highlights the urgent need for harmonization among EU data protection authorities. A unified EU approach could provide a consistent regulatory environment that supports innovation, balancing the need for clear guidelines with the flexibility required to adapt to the rapidly evolving AI landscape. Ultimately, the success of AI and privacy regulations in Europe will depend on finding this balance, ensuring that individuals’ rights are protected without impeding the progress of AI technologies. As always with AI and innovation, articulating complexity with timing is of essence.

Authored by Etienne Drouard, Julie Schwartz, Rémy Schlich, and Sarina Singh.

CNIL’s new guidelines on AI models and individuals’ rights: https://www.cnil.fr/en/ai-and-gdpr-cnil-publishes-new-recommendations-support-responsible-innovation

Contacts

bio-image

Etienne Drouard

Partner

location Paris

email Email me

bio-image

Julie Schwartz

Counsel

location Paris

email Email me

bio-image

Rémy Schlich

Senior Associate

location Paris

email Email me

View more

Additional Resources

  • Digital Transformation Academy

Related topics

  • Artificial Intelligence
  • Data, Privacy and Cybersecurity
Load more

Related countries

  • Belgium
  • France
  • Spain
  • United States
  • Poland
  • Netherlands
  • Germany
  • Italy
  • Luxembourg
  • Ireland
  • Hungary
Load more

Related keywords

  • AI
  • privacy
  • CNIL
Load more

Articles you may be interested in

image_1
News

Confronting social engineering in the age of artificial intelligence

19 February 2025

image_1
News

Emerging Technologies and Data Protection Compliance Considerations from the National Retail Federation "Big Show"

27 January 2025

image_1
News

CNIL 2025-2028 strategic plan: AI, Minors, Mobile Apps & Cybersecurity

17 January 2025

image_1
News

Model inversion and membership inference: Understanding new AI security risks and mitigating vulnerabilities

06 December 2024

image_1
Insights and Analysis

The AI Investment Summit 2024

December 2024

image_1
Insights and Analysis

Decoding the EU Data Act: Data types covered by data access and sharing rights

30 October 2024

image_1
News

What is quantum computing and what’s all the fuss about it?

06 September 2024

image_1
News

Amid booming demand, NTIA seeks comment on U.S. data centers’ growth, resilience, and security

05 September 2024

image_1
Insights and Analysis

"Europe needs a data revolution" – The role of competition law in access to data

14 August 2024

left_arrow
right_arrow

View more insights and analysis

arrow
arrow
"" ""
Digital Client Solutions
Empowering you to lead change through our digital solutions.
Learn more

Register now to receive personalized content and more!

 

Register
close
See benefits
Register
Hogan Lovells logo
Contact us
Quick Links
  • About us
  • Careers
  • Case studies
  • Contact us
  • HL Inclusion
  • Our people
  • Our thinking
  • Responsible Business
  • Cookies
  • Disclaimer
  • Fraudulent and Scam Emails
  • Legal notices
  • Modern Slavery Statement
  • Our thinking terms of use
  • Privacy
  • RSS
Connect with us
LinkedIn
Youtube
Twitter
Wechat
Stay in the know

© 2025 Hogan Lovells. All rights reserved. "Hogan Lovells" or the “firm” refers to the international legal practice that comprises Hogan Lovells International LLP, Hogan Lovells US LLP and their affiliated businesses, each of which is a separate legal entity. Attorney advertising. Prior results do not guarantee a similar outcome.

Subscribe to Our thinking
Connect with us
LinkedIn
Youtube
Twitter
Wechat