Loi n° 2017-020, droits de la personne concernée
Loi n° 2017-020 du 22 juillet 2017, arts. 18-19, 50-63 (droits de la personne concernée)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 22 July 2017.
A data subject rights rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Do not process a person's personal data once they have validly objected, including where the processing serves commercial prospecting.
- Tell the person, at the time of collection, who is responsible for the processing, its purpose, the categories of data, whether a reply is mandatory or optional, and any recipients, and let them access, object to, correct, or delete their data on request.
- Where you did not collect the data from the person directly, give them the same information when you record it or, if you plan to disclose it, no later than the first disclosure.
- Do not access or write information on a user's terminal equipment, and do not condition access to a service on accepting that, without telling the user its purpose and how to object, unless the access only enables the communication or is strictly necessary for a service they expressly requested.
- Give a person, on written request, access to their data in an accessible and intelligible form and its origin, and a copy on payment of no more than the reproduction cost.
- Correct, complete, update, block, or delete a person's data within one month of a written request where it is inaccurate, incomplete, ambiguous, outdated, or unlawfully processed, notifying any third party the data was disclosed to, and honour the same request from their heir after their death.
- Do not base a decision producing legal effects for a person solely on automated profiling or an automated evaluation of their personality.
What it reaches
Obligation class
Data subject rights, Disclosure, Consent
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 50 requires a controller collecting data directly from the person to tell them, at the latest when collecting it, who is responsible for the processing, its purpose, the categories of data, the recipients, whether a reply is mandatory or optional and the consequences of not replying, their access, rectification and objection rights, the retention period, any transfer abroad, and their right to be removed from the file, subject to exemptions for state security, defence, public security, criminal enforcement, and major economic or financial interests of the State.
Article 51 requires that same information to be given, when data is not collected from the person, at the time it is recorded or, if disclosure is planned, no later than the first disclosure.
Article 52 requires a controller accessing or writing information on a user's terminal equipment to tell the user its purpose and how to object, bars conditioning access to a service on accepting that processing, unless the access only enables the communication or is strictly necessary for a service the user expressly requested.
Articles 53 and 54 give a person a written right to access their data in an accessible and intelligible form, its origin, and a copy on payment of no more than the reproduction cost, and article 55 lets them refer a suspected mismatch between the data disclosed and the data actually processed to the Authority for verification.
Article 56 lets a patient's access right be exercised through a physician they designate, article 57 lets a controller resist manifestly abusive requests while carrying the burden of proving abuse, and article 58 routes access to a state security, defence or public security processing through an Authority member who investigates and decides what can be disclosed.
Article 59 gives a person the right to object, without cost, to processing of their data, to be told before their data is first disclosed to or used by a third party for prospecting, and to object to that disclosure or use free of charge, unless the processing meets a legal obligation, and article 60 gives a right to object to the lifting of professional secrecy concerning them, subject to the legal exceptions, while article 18 separately bars sending a person direct marketing communications by any means before they have expressed prior consent to receive them.
Articles 61 through 63 let a person demand that inaccurate, incomplete, ambiguous, outdated, or unlawfully processed data about them be corrected, completed, updated, blocked, or deleted, require the controller to prove compliance within one month at no cost and to notify any third party the data was disclosed to, and let an heir make the same demand to reflect the person's death.
Article 19 bars a judicial decision assessing a person's conduct from resting on automated processing that evaluates aspects of their personality, and bars any decision producing legal effects from resting solely on automated profiling.
When LexLint raises it
crawls_webautomated_outreachhigh_risk_decisions
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.