Internal regulations, IT charter and GDPR

29 Jul 2026 | Human Resources, News

 

Preamble

The implementation of certain documents within the company will improve its operation, its security and its compliance with the regulations in force. 

To do this, systems are designed to structure the company’s activity, protect sensitive data and ensure a good working environment.

In this case, the internal regulations, the IT charter and compliance with the General Data Protection Regulation (GDPR or “RGPD” in French) are set up.

We take stock of whether or not these measures will be mandatory and their usefulness.

1. Internal regulations

1.1 Is the implementation of internal regulations mandatory?

The implementation of internal regulations is mandatory for companies with a workforce of 50 employees for 12 consecutive months.

This obligation applies at the end of the 12-month period from the date on which the threshold of 50 employees was reached for 12 consecutive months after the creation of the company.

For example, if the threshold of 50 employees was reached 1 January 2025 and for 12 consecutive months thereafter, the employer must draw up internal regulations by 1 January 2026 at the latest.

NB: In the case of multiple establishments, the internal regulations must be put in place for each establishment with more than 50 employees. It can be similar for all establishments, but must strictly target its establishment of application.

1.2 How are the internal regulations drawn up?

The drafting of the internal regulations is the responsibility of the employer. The document must be written in French but may be accompanied by translations into one or more foreign languages.

The regulations are a document that sets out the rights and obligations of employees within the company or establishment. It shall specify exclusively the rules applicable to health, safety and discipline. In particular, it sets out the nature and scale of the sanctions that the employer may impose on the employee.

In addition, it may include provisions common to all employees or provisions specific to each category of staff.

The company must comply with the following steps to set up internal rules:

  • Draft regulations
  • Submit the project to the CSE for opinion
  • Notification to the Labour Inspectorate
  • Inform employees by any appropriate means

NB : Following the Act of 26 May 2026, employers are no longer required to file their internal rules and regulations with the registry of the Labour Court.

In addition, the internal regulations must contain all the mandatory clauses, failing which, the risk is the nullity of the internal regulations and the unenforceability on employees (in particular for disciplinary procedures).

NB: Since 2022, new mandatory provisions concerning whistleblowers, moral harassment and sexual harassment and employees’ rights of defence must be provided for and updated.

For information, the employment law department is at your disposal to establish or update the internal regulations within your company.

1.3 What is the point of setting up internal regulations on an optional basis?

Companies with fewer than 50 employees are not required to set up internal regulations, but can always decide to draw them up in order to provide a framework for the working community.

In this case, the internal regulations must be drawn up under the same conditions as for companies with at least 50 employees and must be applied as soon as they are set up.

The internal regulations will make it possible to strengthen transparency and the understanding of practices within the company by the employee. Indeed, by defining the rules and expected behaviors, the internal regulations guarantee a work environment that respects everyone, where each employee knows his or her rights and responsibilities.

In addition, the internal regulations will protect the company against certain disputes and claims. Indeed, the latter can serve as a reference in the event of disagreement or conflicts, providing a legal basis for disciplinary decisions.

 

2. The IT charter

2.1 What is an IT charter?

The IT charter is a document that:

  • Sets out the rights and duties of the employee in terms of the use of IT tools in the company.
  • Makes it possible to regulate the use of professional emails, Internet browsing or downloading files.
  • Determines the penalties applicable in the event of non-compliance with the charter.

The company is free to decide what it wants to include in the IT charter.

For example, it can include listing websites that are forbidden to browse, prohibiting the downloading of certain illegal files, limiting the size of attachments, etc.

The development of the IT charter is specific to each company and depends on the context and organizational concerns of the company.

Our employment law department is available to advise you in the development and implementation of an IT charter.

2.2 Is the implementation of an IT charter mandatory?

Legally, the implementation of the IT charter is not mandatory.

However, the National Commission for Information Technology and Civil Liberties (CNIL) points out that every company must have a charter, from the moment it collects and processes personal data. Indeed, the implementation of this document is essential to comply with the GDPR (General Data Protection Regulation).

2.3  What is the use of writing an IT charter?

The IT charter is of major interest in that it provides a framework for the use of digital resources and limits their misuse.

The IT charter helps the company protect sensitive information from cyber threats by defining clear security practices.

By specifying the responsibilities of each user, the IT charter encourages the responsible use of digital resources. Employees know what is expected of them and the sanctions that can be taken against them.

Finally, the IT charter helps to ensure that the company complies with the laws and regulations in force in terms of data protection and IT security. 

3. The GDPR (General Data Protection Regulation)

3.1 What is it about?

The GDPR is a European regulation that came into force on May 25, 2018, governing the processing of data in an egalitarian manner throughout the European Union (EU).

The GDPR was designed to meet three objectives:

  • Strengthen the rights of individuals;
  • Hold data processors accountable;
  • Give credibility to the regulation through enhanced cooperation between data protection authorities.

Thus, the GDPR protects the processing of personal data that can be characterized by direct identification (surname, first name, etc.) or indirect identification (identifier, number, etc.). When an operation involves personal data, it is considered to be a processing of personal data. For example, it can be a question of keeping a file of its customers, or collecting the contact details of prospects via a questionnaire.

3.2 Does the GDPR apply to every company?

Any company, regardless of its size, country of establishment and activity, is concerned by the GDPR. Compliance with the GDPR is therefore a legal obligation.

Indeed, the GDPR applies when the company:

  • Is established in the territory of the EU;
  • Or its activity directly targets European residents.

In addition, the GDPR also concerns processors who process or would collect personal data on behalf of another entity.

3.3 Why is the GDPR essential?

The GDPR ensures that the personal data of the company’s employees and customers is rigorously protected.

In addition, the GDPR provides rights to data subjects, such as the right to access, rectify, delete and transfer their data. This allows customers and employees to control their personal information and builds trust.

In principle, a clause or appendix to the employment contract, or any other related document, must specify to the employee the rules that the company respects, as well as the terms of the rights of access, rectification and deletion of personal data concerning him/her, in accordance with the European regulation.

                                                                                                                                                    ***

This fact sheet contains summary information. Please contact us for advice tailored to your situation. We cannot be held responsible for misinterpretation.

 

Contact

Claire APPELGHEM

Hear of HR/Employment Law

Claire.appelghem@groupe-aplitec.com

01 40 40 38 38

 

Share This