Reference decision: cc • No. 87-83.429 • 1987-11-03 • View the decision →
Imagine: you are a landlord in Parentis-en-Born and you manage the rental of your flat yourself. To keep track of rents, you have created a small Excel file with the names, addresses and telephone numbers of your tenants. A very handy tool, you think. But did you know that this simple spreadsheet may fall under the French Data Protection Act? The question every landlord asks is: how far does the protection of personal data go? The answer lies in a landmark decision of the Court of Cassation of 3 November 1987, which laid down a broad definition of "personal information": "information which allows, in any form whatsoever, directly or indirectly, the identification of the natural persons to whom it applies." A definition which, nearly 40 years later, remains the cornerstone of our data protection law.
The facts: a story that happens every day
In 1986, a person was prosecuted before the criminal court for implementing an automated processing of personal information without making the prior declaration required to the French Data Protection Authority (CNIL). In other words, they had created a computer file containing personal data without complying with the formalities provided for by the Act of 6 January 1978 on data processing, files and liberties. The case came before the Court of Cassation, not on the merits of guilt, but on a preliminary question of law: should the judge refer a priority question of constitutionality? The Court said no, holding that the offence was materially constituted as soon as there had been processing without a declaration. But the essential point lies elsewhere: in this decision, the Court recalls what personal information is. At the time, the debate was lively: was direct identification (first name + surname) required, or was it sufficient that the information could, by cross-referencing, identify a person? The Court ruled: even indirectly, as soon as identification is possible, the information is personal. In other words, a telephone number, an IP address, a bank account number can be personal data, even without the name. This decision had a considerable impact, as it gave judges and citizens a broad framework to protect privacy.
The reasoning of the court — dissected
The Court of Cassation relies on Article 4 of the Act of 6 January 1978, which defines personal information. It specifies that the personal nature does not depend on the medium (paper, computer) nor on whether the information is directly associated with a name. The essential point is that it "enables" identification. The judges use the verb "enable" in a broad sense: it is sufficient that the information can, by reasoning or cross-referencing, lead to a natural person. This reasoning is innovative because it anticipates future technologies. In 1987, DNA, facial recognition or geolocation were not yet talked about. Yet the definition given by the Court already encompasses these techniques. The Court thus confirms a broad, protective interpretation for citizens. The defence arguments — which sought to limit the notion solely to directly identifying data — are rejected. This decision is neither a confirmation nor a reversal: it is a landmark decision, the first to give such a clear definition. It has since been taken up by the General Data Protection Regulation (GDPR) in 2016, which speaks of "personal data" with the same logic. What few people know is that this decision influenced European case law.
What this means for you — practically
If you are a landlord in Mimizan and manage your rentals via software or a simple Excel file, you hold personal information: name, address, telephone, bank details, rent amount. You must comply with the law: inform your tenants, declare your processing to the CNIL if necessary (or appoint a data protection officer), and secure this information. In the event of a leak or misuse, you may be criminally prosecuted. For a tenant, this decision protects you: if your landlord collects data without your consent or uses it for other purposes (for example, to send you advertisements), you can file a complaint. For a buyer, during a sale, the notary processes your personal data; he must comply with the same rules. undefined, I have encountered cases where a landlord had posted on a website the names and addresses of his tenants to denounce them as bad payers. This is a clear violation of the law, punishable by a fine of up to €300,000 and 5 years' imprisonment. Another example: a managing agent who distributes the list of co-owners with their outstanding balances in everyone's mailbox. Again, this is prohibited. If you are in this situation, you must demand immediate removal and can refer the matter to the CNIL. The time limits for action are 5 years from the discovery of the facts.
Four tips to avoid this type of dispute
- Declare your data processing to the CNIL: if you use a customer file, property management software or a website, check whether you need to make a standard or simplified declaration. Most small organisations can use the free online form.
- Clearly inform the persons concerned: when signing a lease or a sale agreement, provide an information notice specifying what data you collect, why, and how long you keep it. This is a legal obligation.
- Secure your access: protect your files with a password, do not leave them on a shared computer, and do not transmit them by unsecured email. In case of computer theft, you could be held liable.
- Do not keep data longer than necessary: after the end of a lease, you must delete your tenant's data (except data required for accounting, which can be kept for 10 years). A 20-year-old file with former tenants is a ticking time bomb.
Besoin d'un conseil personnalisé ? Contactez Maître Zakine — première consultation 30 min à 45€.
Further reading: related case law and developments
Before 1987, the definition of personal information was vague. An earlier decision of the Conseil d'État (1982) had adopted a more restrictive view, requiring direct identification. The Court of Cassation, in 1987, chose the broad path, followed since by the CJEU (Court of Justice of the European Union) in the Google Spain ruling of 2014 (right to be delisted). The trend is therefore towards extending protection. The GDPR, which came into force in 2018, adopted this definition almost word for word. For the future, we can expect the courts to continue to interpret the notion broadly, particularly with the rise of artificial intelligence and biometrics. Landlords and real estate professionals must therefore be vigilant: a photo of your tenant, their fingerprint to open the door, or even their payment behaviour analysed by an algorithm, are personal data.
Key points to remember
- What is personal information? Any data that enables a person to be identified, directly (name) or indirectly (IP address, telephone number, licence plate).
- When must I declare a file? As soon as you collect personal data automatically (computer) or manually (paper) for professional use. Individuals who keep a file for their domestic use (personal address book) are exempt, but be careful not to exceed this use.
- What are the risks? A fine of up to €20 million or 4% of annual worldwide turnover for companies (GDPR), and criminal prosecution (fine of €300,000 and 5 years' imprisonment).
- How do I know if I am compliant? Ask yourself three questions: 1) Are the persons informed? 2) Is the data secure? 3) Is it kept for not too long? If in doubt, check the CNIL website or consult a lawyer.
- What to do in case of a breach? Contact the CNIL (online complaint) and your lawyer. If you are a victim, you can claim damages for the harm suffered.
Are you in a similar situation? A 30-minute initial consultation with Maître Zakine (€45) can save you months of proceedings — and often much more. Book an appointment →

