[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDOSGzUIxD0RdeKdMC8DQfS-t6o4W1luk2cKXV0pfocc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"fbf76e65-1f3a-48d8-9d34-08343c3ef78c","french-council-of-state-overturns-cnil-fine-on-google-over-gdpr-de-referencing-scope","3e8b71a7-5bb8-4224-8090-e4d33a0435a9","French Council of State Overturns CNIL Fine on Google Over GDPR De-Referencing Scope","The French Council of State ruled that GDPR Article 17 right-to-erasure (de-referencing) obligations are geographically limited to EU member states, not globally applicable, annulling a €100,000 fine against Google. This case highlights the critical importance of accurately interpreting the territorial scope of data protection regulations before implementing compliance measures. Organizations that over- or under-implement GDPR obligations risk both regulatory penalties and unnecessary operational burden. The ruling clarifies that blocking access to de-referenced content within EU member states constitutes sufficient compliance, even if content remains accessible outside EU borders. Understanding jurisdictional boundaries is essential for building proportionate and legally defensible data protection programs.","**Immediate actions:**\n- Conduct a legal review of all current GDPR compliance measures to ensure territorial scope is correctly interpreted and documented.\n- Map all data subject rights requests (erasure, rectification, access) to their applicable jurisdictional boundaries to avoid over-compliance or under-compliance.\n\n**Organizational & Policy improvements:**\n- Establish a cross-functional legal and privacy team to monitor regulatory rulings and update internal compliance policies accordingly.\n- Maintain a documented legal basis and scope assessment for each data subject rights process, referencing relevant supervisory authority guidance and case law.\n- Create a formal process for incorporating judicial and regulatory decisions (e.g., CJEU, national courts) into your data protection compliance framework.\n\n**Detection & Audit measures:**\n- Schedule periodic audits of data subject rights fulfilment procedures to validate alignment with current legal interpretations.\n- Implement a regulatory change management log to track evolving GDPR enforcement decisions and their impact on operational compliance obligations.",[12,13,14,15,16,17,18,19],"GDPR Article 17 (Right to Erasure \u002F Right to be Forgotten)","GDPR Article 3 (Territorial Scope)","GDPR Article 5(1)(a) (Lawfulness, Fairness and Transparency)","NIST Privacy Framework PR.PO-P1 (Policies, processes, and procedures for managing data subject rights)","NIST SP 800-53 PT-2 (Authority to Process Personally Identifiable Information)","ISO\u002FIEC 27701:2019 Section 7.3.3 (Obligations to Data Subjects)","CIS Control 18 (Penetration Testing \u002F Policy Compliance Review)","ITIL Service Management – Compliance and Legal Risk Management","published","2026-06-24T11:21:05.572714+00:00","2026-06-24T11:21:05.273+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CE_-_N%C2%B0_399922&diff=51970&oldid=24860","ce-n-399922-368392","CE - N° 399922",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]