DAC6 France: Legal professional privilege questioned by Supreme Administrative Court

The French Supreme Administrative Court has requested a preliminary ruling from the European Court of Justice (ECJ) regarding the DAC6 filing rules applicable to intermediaries in the case of legal professional privilege.

French domestic law states that intermediaries relying on legal professional privilege are still subject to DAC6 rules, and need to obtain their client’s permission to waive privilege and make a report within a 30 day period. If the relevant intermediary does not obtain their client’s consent, then they have to notify other intermediaries of their reporting obligations and a report needs to be made by a different intermediary within 90 days of notification.

What is the issue?

The French National Council of Bars, the Conference of the French Bar Presidents and the Paris Bar Association argued to the French Supreme Administrative Court that the legal professional privilege rules in relation to DAC6 are contrary to EU law. While the French  Supreme Administrative Court annulled some sections of the French tax authorities as a result of the arguments, additional questions remain. 

These are the issues that have been put forward to the ECJ:

  1. Is the right to a fair trial infringed because legal professional privilege does not exclude lawyers acting in legal proceedings from the scope of intermediaries subject to the obligation of declaration or notification?
  2. Is the right to respect for private life and communications infringed, as lawyers evaluating the legal situation of their clients are not excluded from the scope of the filing obligations?

What happens now?

Until the ECJ answers the questions raised, French intermediaries who are affected by legal professional privilege will have to ensure that they adhere to the DAC6 filing and notification deadlines. Once the ECJ issues their decision, it will affect how legal professional privilege is interpreted in all EU Member States.

How are you managing your GDPR compliance requirements?

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

“In a world older and more complete than ours they move finished and complete, gifted with extensions of the senses we have lost or never attained, living by voices we shall never hear.”

Picture of James

James

VinciWorks CEO, VInciWorks

Spending time looking for your parcel around the neighbourhood is a thing of the past. That’s a promise.

How are you managing your GDPR compliance requirements?

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

How are you managing your GDPR compliance requirements?

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.