Personal data and security of the registration process (DILE)

Verified 24 September 2021 - Directorate for Legal and Administrative Information (Prime Minister)

The Directorate of Legal and Administrative Information (DILA), Prime Minister's Office, and the Directorate of Modernization and Territorial Administration (DMAT), Department of the Ministry of the Interior, are co-responsible for processing, under Regulation (EU) 2016/679 of 27 April 2016 (GDPR), in the context of this approach.

The respective coordinates of these directions are as follows:

Directorate for Legal and Administrative Information,

Represented by its Director Anne Duclos-Grisier

26 Desaix Street

75727 Paris cedex 15

Tel. Standard: 01 40 58 75 00

Directorate for Modernization and Territorial Administration,

Represented by its Director

Director of Modernization and Territorial Administration

Ministry of the Interior

Beauvau Square

75800 Paris Cedex 08

E-mail: donnees-personnelles-dmat@interieur.gouv.fr

The respective roles and responsibilities of these directorates, in the context of the management of the online application process for registration on the electoral lists (hereinafter referred to as the “Service”), are specified in the general conditions of use accessible via the following link: https://www.service-public.fr/P10128.

The Service allows the user, after authentication (see article 4.1 below), to register online on the municipal electoral lists. His application is then forwarded to the National Institute of Statistics and Economic Studies (INSEE) for inclusion in the Single Electoral Directory (REU), which makes it available to the municipality in which he has applied for registration.

The user is then informed, by means of a paperless receipt, of the deposit and of the transmission of his request for registration to the municipality concerned. The monitoring of the processing of his request by this municipality passes through the UER, before being transmitted to the DILA which informs the user.

Once the request has been transmitted to the municipality, the user can no longer modify it. If necessary, he must make a new request or contact the municipality of registration.

The legal basis for this processing is theorder of 16 november 2018 laying down the conditions for the approval of the teleapplication procedure for online registration in the electoral lists and supplementary electoral lists, adopted pursuant to decree no. 2018-343 of 9 may 2018 and of theOrder of 24 February 2016 integrating into the ‘service-public.fr’ website an online service enabling the user to complete all or part of the paperless administrative procedures and to have access to personalized information services (see article n°X of the DILE GTC).

The DILA and the DMAT undertake to take all necessary measures to guarantee the security and confidentiality of the information provided by the user. They undertake not to market any information and documents transmitted by the user by means of the Service, and not to communicate them to third parties, except in cases provided for by law, in particular in the case of judicial requisition.

On the management of "authentication credentials"

The Service is accessible by creating identifiers or by identification via FranceConnect. The identification allows the opening of a session during which the user can carry out his approach (see article 4.2 below).

Creation of identifiers:

The following personal data are mandatory for access to the Service:

  • a user login (a valid email address), knowing that for security and confidentiality reasons it is strongly recommended to use a personal email address specific to the user;
  • the password chosen by the user, knowing that this password must contain a minimum of eight characters with:

at least one capital letter;

at least one lowercase letter;

at least one digit;

the use of the same password on several different services is to be prohibited.

(See the usage guidelines for managing your passwords in theNational Agency for Security of Information Systems.)

The ID and password are valid for 7 days and are then destroyed by the DILA. During these 7 days, the user has the possibility to reset his password, by clicking on "Forgot password? ”.

After this period of 7 days, the user must start the authentication procedure again from the beginning.

Identification via FranceConnect:

The user's surnames, first names and e-mail are transmitted to the Service by the FranceConnect identity provider (cf. FrenchConnect UGC )

Traceability of access

The personal data recorded for the traceability of the "user session" data corresponding to the identifiers (excluding authentication via FranceConnect) are the following: IP address of the user, date and time of connection. These are stored for 7 days (see above).

The personal data stored in the logging system are the following: the IP address of the user, the date and time of connection. These are kept for 180 days.

On the management of the process or Service

After identification and opening of a session (see article 4.1 above), the user accesses the Service and can carry out his/her procedure. If the user remains inactive for 30 minutes, the session is cut off. He must then identify himself again to carry out his procedure.

The collection of certain personal information is necessary to process the request by the registration municipality chosen by the user, these being defined in Articles 3 et seq. of theorder of 16 november 2018 pursuant to Articles A. 5, A. 6 and A. 60 the electoral code.

This includes data aimed at:

  • to identify the user: name of birth, surname, given names, sex, date and place of birth and nationality;
  • to provide proof of the municipal attachment which is the subject of the application: the address under which the user may apply for registration;

The supporting documents relating to identity and connection which must accompany the application for registration differ according to the personal case of the user.

(This information is available on the following pages:

Register to vote: what proof of identity?

Register on the list of electors in town hall: what proof of residence?

This data is automatically destroyed, 7 days after the date of confirmation of receipt of the request by the municipality.

The case is processed as follows:

After validation by the user of his request, the file is being transmitted to the municipality of the place of registration which is processing the request.

The following statuses are the subject of sending an email to the user:

  • In the course of processing by the municipality;
  • Application rejected by the municipality;
  • Application accepted by the municipality.

Case 1 - The application is not validated by the user, therefore not transmitted to the registration municipality:

The personal data entered is never saved.

The supporting documents uploaded by the user are automatically destroyed within a maximum of 24 hours.

Case 2 - The application has been validated by the user, it is therefore transmitted to the municipality of registration:

From the receipt of the status, "in process", the telefiles are kept for 7 days.

Systematically after 7 days, the folders are deleted.

During these 7 days, upon receipt of the "Application Accepted" or "Application Rejected" status, the files are immediately destroyed.

Traceability of access

The data recorded for the management of access traceability are: the telefile number, with for each event the date and time of status. (cf. Article III.2 of the General Terms and Conditions mentioning the list of the status of the application).

This data is kept for 180 days by the DILA.

Summary

Use

Data

Shelf life

Connection with FranceConnect:

E-mail

Password

Technical ID

7 days

Login with email and password

E-mail

Password

Technical ID

7 days

User Session Data

IP

Date and time logged in

30 minutes during user session

180 days in the logs (cf. CNIL deliberation of 2021-008 of 14/01/21, for the detection and prevention of illegitimate operations on the main data of the processing)

Data necessary for the request to process the request by the registration municipality chosen by the user

All these data constitute the user's telefile, with which a status is associated as a function of the progress of his processing.

Identity :

surname, surname, given names, sex, date and place of birth, nationality

Data relating to the municipal attachment :

address in respect of which the elector is registered on the list of electors

Applicant Contact Data as described in the table below

Supporting documents :

personal data contained in the stored documents (see details below)

From the receipt of the status, “in process”, the telefiles are kept for 7 days.

Systematically after 7 days, the folders are deleted

During these 7 days, upon receipt of the “accepted” or “rejected” status, the files are immediately destroyed.

IF the request is not validated by the user: The personal data entered are never recorded.

The supporting documents uploaded by the user are automatically destroyed within a maximum of 24 hours.

For the management of access traceability and DILE monitoring (statistical monitoring and processing of user requests by the support)

Telefile Number

For each event (related to the status of the request), the date and time of the status.

180 days

Access to personal data is strictly limited to DILA, INSEE (as a partner organization) and, where applicable, to subcontractors contributing to the management of the Service, as listed below:

Subcontractors

Role

Outscale

Server Hosting and Data

CGI

Functional support of the approach

GFI Inetum

Exploitation

Sendinblue

Solution for sending emails to users

Baleen

CDN Content Delivery network technical solution)

The subcontractors listed above are subject to a confidentiality obligation and may only use the personal data in accordance with the applicable legislation and contractual provisions specifically concluded in the context of the implementation of the approach.

In accordance with the applicable legal and regulatory provisions, the data subject may exercise his or her right of access to the controller of the DILA by e-mail to the following address: mailto:rgpd@dila.gouv.frrgpd@dila.gouv.fr.

The processing of the application will be carried out in conjunction with the DMAT, in accordance with a partnership agreement established between these two entities.

If the user is not satisfied with the answer, he or she can then contact the data protection officer of the Prime Minister's Office by e-mail at the following address: dpd@pm.gouv.fr

and by mail to:

Prime Minister's Office

To the Data Protection Officer (DPO)

56 rue de Varenne

75700 Paris

In any case, the user also has the right to lodge a complaint or complaint with the National Commission of Informatics and Freedoms via the following address: https://www.cnil.fr/fr/plaintes

The right to rectification, the right to erasure, the right to restriction of processing or the right to object cannot be exercised because this processing is necessary for the performance of a public service mission (cf. Article 6 of the GDPR) and because it meets an obligation under Articles L9 and II of Article L11 of the Electoral Code). However, in order to rectify his data, the user can make a new request, directly to the registration municipality or by using the Service again.

No transfer of personal data is made to a non-EU Member State.

This Service uses cookies (so-called “cookies”1) that are placed on the user's computer, mobile phone or tablet.

The data collected by the Service is not cross-checked with other processing operations.

The cookies placed do not allow the user to follow the navigation on other sites.

The user can, at any time, deactivate these cookies via the “Cookie Management” link, in the footer of each of the pages of the Service.

The cookies concerned are the following

These cookies are strictly necessary for the proper functioning of the Service. In the event of deactivation by the user, the latter will not be able to carry out the procedure.

These cookies only store information relating to the user's session (IP address dates and times).

These cookies expire after 10 hours.

Third-party cookies to improve site interactivity

Type

Provider

Use

Cookies for statistical use

ATInet

"Privacy Policy"

Google Analytics

"Privacy Policy

The data collected corresponds to information about the computer used for browsing, connection mode, type and version of the internet browser, operating system, URL address of connections, including date and time.

This data makes it possible to obtain anonymous traffic statistics on the site in order to optimize its ergonomics, navigation and content.

Testing

AB Tasty

"Privacy Policy

The AB Tasty cookie makes it possible to offer, randomly and for a limited time, an alternative version of certain pages of the site to a selection of users. The goal is to test the effectiveness of new features or optimize existing pages of the site.

Video Streaming

YouTube

"Privacy Policy

Dailymotion

"Privacy Policy"

These cookies allow the playback of videos on the service-public.fr website from content hosting sites.

Social networks

LinkedIn

"Privacy Policy

Twitter

"Privacy Policy

Facebook

"Privacy Policy

They make it possible to display on the site flows of information or exchanges from social networks.

The period of storage of cookies relating to navigation does not exceed 6 months.

It is possible to manage the cookie settings via the link available at the bottom of the site: Cookie Management