
The use of the Internet within companies is becoming more complex every year with the development of new uses and new threats associated with them: Shadow IT, SSL decryption, BYOD, SaaS, Cloud Act, teleworking, GDPR, etc.
CIOs and CISOs face many legal questions in the context of their duties to protect the interests of their organizations:
– Is it mandatory to implement web content access filtering?
– Should or can public access to the web be filtered?
– Is there a different legal regime for private companies and public entities?
– How can filtering be implemented while preserving employees' residual privacy and complying with the GDPR?
– Can an employee be disciplined based on data provided by the filtering tool?
– Is the filtering tool permitted even though it collects a large amount of personal data
? Should staff, external parties, or both be informed?
Is it mandatory to implement web filtering?
Web filtering is a process of controlling the content accessible on the Internet. It aims to block or allow access to websites based on predefined criteria, such as cybersecurity, compliance with company policies, or protection against inappropriate or illegal content. This helps ensure online safety, optimize productivity, and prevent access to malicious sites.
Although not mandatory, the relevant authorities (ANSSI, etc.) actively recommend its use and implementation. It should also be noted that version 2022 of the ISO 27001 standard makes filtering mandatory for certification.
It should be noted that the law requires certain parties, in particular legal entities or individuals whose business is to provide access to online communication services to the public, to implement "technical measures to restrict access to certain services or to select them." This refers to web filtering, even if this is implied.
What are the legal consequences of not implementing filtering?
Risk of criminal liability
According to Article 121-2 of the Penal Code, employers are criminally liable for the actions of their employees if the company benefits from the unlawful act. The company could therefore be held liable, in particular as an accomplice (provider of means), for illegal access by its bodies or representatives on behalf of the company, if the following content is viewed:
- Child pornography
- Illegal online gaming sites (those accessible from French territory
that have not been approved by the French Gaming Regulatory Authority
ligne) - Infringing websites that violate copyright protection
- To websites promoting terrorism
- Software that can be used to compromise an automated data processing system
- Software designed to circumvent technical protection measures or information
– To websites offering products and services such as:
– Human organs and body parts
– Drugs
– Child pornography
– Firearms and explosives
– Medicines
– Tobacco
– Alcohol
Risk of civil liability
According to Article 1242, paragraph 5 of the Civil Code, civil liability consists of being liable for any harm caused and therefore compensating for the damage caused. Consequently, the employer is liable for any damage caused by its employees in the performance of their duties and must compensate the victim by paying damages.
The subject essentially concerns the level of responsibility of the employer in the event of illegal use of the Internet by its employees and when it provides Internet access to third parties.
For example, the Court of Appeal of Aix-en-Provence convicted an individual for trademark infringement, as well as his company, on the grounds that the disputed website was created at the employee's workplace using computer equipment provided by his employer. The company was found liable as the principal for its employee's creation of an illegal personal website.
In the same vein, the Marseille Regional Court ruled against the employer of an employee who had created a controversial website, for having provided the employee with the technical means necessary to put the site online, regardless of whether the employee had acted outside the scope of his professional duties.
Is there a difference between administrations and local authorities?
In the event that a local authority has not implemented the necessary measures
for the security and control of the Internet used by its staff, and in particular has not used filtering software, it is not necessarily criminally liable for an offense committed by one of its staff members.
Indeed, as this scenario is not covered by Article 121-2 of the Criminal Code, the lack of
mplementation of filtering measures to secure Internet use by its staff is not one of the activities for which it can be held criminally liable.
Nevertheless, it may be held liable as the principal of its agent if the following conditions are met
. To defend itself, the administration must prove the following three cumulative elements, namely that the agent acted:
• Outside the scope of his duties
• Without authorization
• Outside his powers
But that will not always exclude his responsibility. Indeed, since the Lemonnier ruling, the same facts may constitute both personal misconduct on the part of the agent and misconduct in the service for which the administration will be held accountable.
In this regard, legal doctrine specifies that once the fault is linked to the service, this personal fault appears to be "not entirely unrelated to the service," because it was committed either during the performance of the agent's duties or because the performance of their duties may have facilitated its commission in some way.
Conclusion
Although not mandatory, except for a specific category of companies, web filtering provides a framework and legal protection that allows CIOs/CISOs to manage employee access in order to minimize legal risk.
In a future article, we will look at how to deploy a filtering solution while complying with the legal framework and labor law.
To explore this topic in greater depth, Olfeo has collaborated with the specialist law firm Lexing Bensoussan to produce a comprehensive white paper covering all the legal aspects of this subject. We invite you to download it for a complete overview of the topic.


