← All articles

consultant

Mandatory DPIA: CNPD vs CNIL on HR (GDPR Art. 35)

The CNPD and CNIL apply the same GDPR yet diverge on HR surveillance and analytics: a narrower scope in Luxembourg, broader in France. Result: a DPIA may be mandatory in FR and conditional in LU.

The CNPD and the CNIL each published their “Article 35(4) GDPR” list of processing operations requiring a DPIA. They diverge on HR surveillance and analytics: in Luxembourg the scope is narrower; in France it is broader and more prescriptive.

The case

  • Luxembourg: the CNPD targets “regular and systematic monitoring of employees’ activity — insofar as it produces legal effects or similarly significantly affects employees,” “systematic tracking of individuals’ location,” and biometric/genetic data subject to cumulative criteria. Source: CNPD, Data Protection Impact Assessment.
  • France: the CNIL lists cases where a DPIA is required (e.g., “HR profiling to detect high potentials, algorithmic recruitment support, personalized training, churn prediction,” and “constant employee activity monitoring, DLP, CCTV for cash handlers, tachograph”) and cases where it is not (e.g., “working time control without biometrics”). Sources: CNIL, DPIA-required list; CNIL, DPIA-not-required list.
  • EU consistency: the EDPB reviewed national draft lists and adopted Opinion 26/2018 on the Luxembourg draft, recalling common criteria from WP248 rev.01. Sources: EDPB Opinion 26/2018; EDPB DPIA topic page.
  • Legal basis: Articles 35 (DPIA) and 36 (prior consultation) GDPR on EUR‑Lex: consolidated text. See also Article 35 GDPR explained.

Legal reasoning

  • Framework: Article 35(1) mandates a DPIA where processing is likely to result in a high risk to individuals’ rights and freedoms. Article 35(3) lists three typical cases; Article 35(4) tasks each authority to set a national list, subject to consistency mechanism (Arts. 35(6)/64).
  • Common guidance: WP29/EDPB (WP248 rev.01) recommends a multi‑criteria approach (systematic monitoring, vulnerable data subjects — e.g., employees —, scale, sensitive data, innovative use, etc.). Ref.: WP248 rev.01.
  • CNPD (LU) — targeted approach: a shorter, often conditional list: biometrics “for identification” + at least one extra criterion; employee monitoring if legal effects/similarly significant effects; systematic location tracking listed per se. Source: CNPD.
  • CNIL (FR) — extensive HR approach: specific HR use cases make the DPIA mandatory even without strict “legal effects” when scoring/evaluation and employee vulnerability are at stake (high‑potential detection, algorithmic pre‑screening, churn prediction). Targeted exemptions for classic HR processing (payroll, time control without biometrics). Sources: required list and not‑required list.
  • EDPB consistency: Opinion 26/2018 requested methodological tweaks to CNPD (e.g., cumulative criteria for biometrics/genetics) while leaving national leeway.

What it changes in practice

HR analytics and internal AI

  • Luxembourg: an internal “high‑potential” scoring algorithm may require a DPIA if it leads to legal or similarly significant effects (promotions, transfers, terminations, access to key training) or if enough WP248 criteria are met. See the CNPD list and document your criteria. To frame AI uses, consider robust AI governance (AI Act and GDPR).
  • France: the same uses appear on the CNIL DPIA-required list (high‑potential detection, algorithmic recruiting, churn prediction) — DPIA is near‑systematic.

DLP, EDR and cybersurveillance

  • Luxembourg: a DLP that “regularly and systematically monitors employees’ activity” triggers a DPIA only if it produces legal or similarly significant effects; otherwise, apply WP248 criteria. Operationally, a managed SOC for EDR/XDR can be governed to mitigate risks.
  • France: the CNIL explicitly includes DLP and “constant monitoring of activity” on the DPIA-required list.

Fleet geolocation

  • Luxembourg: “systematic tracking of location” — DPIA required (CNPD).
  • France: “large‑scale location” — DPIA required (CNIL).

Internal video surveillance

  • Luxembourg: DPIA is not automatic; it may be required depending on cumulative criteria (scope, “smart” tech, public areas, etc.).
  • France: certain cases are explicitly listed (e.g., cash handling, high‑value warehouses) — DPIA required.

Common pitfalls

  1. Reducing the decision to “on the list or not”. Wrong: Article 35(1) requires a DPIA as soon as high risk is identified, even if not on the national list. Ref.: GDPR Art. 35(1) and WP248 rev.01.
  2. Underestimating “similarly significant effect”. Managerial decisions based on internal scores (assignments, bonuses, training access) can meet the CNPD threshold. Ref.: CNPD list; GDPR Arts. 22 and 35.
  3. Confusing tool and purpose. A “passive” DLP ≠ a setup leading to automated disciplinary measures. Describe decision chains and human safeguards. Ref.: CNIL DPIA-required list.
  4. Forgetting prior consultation (Art. 36). If residual risk remains high after the DPIA, consultation is mandatory. Ref.: CNPD — consultation; GDPR Art. 36.
  5. Copy‑pasting a template from another country. Align with Article 35(7) (description, necessity/proportionality, risks, measures) and consider EDPB opinions. Ref.: GDPR Art. 35(7); EDPB Opinion 26/2018.

Official sources

Need help to scope your DPIA and algorithmic HR use cases? A DPO mandate can steer compliance and coordinate prior consultation if needed. You can also contact us for a quick assessment.

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →