From may 25,  2018, all companies using personal data must implement a personal data governance policy. 

 

The CNIL (National Commission of Informatique and Liberty) has published a 6-step guide to setting up confidentiality governance :

https://www.cnil.fr/sites/default/files/atoms/files/pdf_6_etapes_interactifv2.pdf

 

 

Cnil condamnation in 2018 :

http://www.lemonde.fr/pixels/article/2018/01/09/darty-sanctionne-par-la-cnil-pour-atteinte-a-la-securite-des-donnees-clients_5239344_4408996.html