Before sending a consultant’s details to a client, decide what the mission requires and who needs to see each item. In France, portage salarial involves an employment relationship with the portage company, so sharing consultant data with clients should reflect that model—not a separate commercial intermediary arrangement.
This guide covers portage consultant personal data GDPR checks for setting up and managing a mission. It focuses on French portage salarial data protection, the parties’ roles, and practical steps for sharing consultant data with clients under the EU GDPR and French labor rules.
For a real-world example of how a company explains its data practices, see emagine’s privacy policy. It is not a substitute for checking the rules that apply to a French portage mission.
Table of Contents
Key Takeaways
- Share only the personal data needed to set up or manage the mission.
- Clarify which party handles each part of the data process.
- Tell consultants why their information is shared and who may receive it.
- Record the GDPR legal basis for each purpose.
- Set clear access, transfer, and retention safeguards before sharing.
Portage consultant personal data GDPR: Understand roles and lawful sharing in France

French portage salarial brings together a consultant, a portage company, and a client company. Understanding portage salarial France GDPR roles helps each party handle personal data with care.
Explain French portage salarial and identify who handles the consultant’s data
The French portage company employer hires the consultant under an employment contract. The client company has a services contract with the portage company. This employment model is distinct from an intermediary that arranges a business-to-business service without making the provider an employee.
The portage company usually manages payroll, contracts, and employment records. The client may handle mission access, work contacts, and site security. Each organization must assess its role under GDPR based on how it decides why and how personal data is used.
Map the consultant data shared for a client mission
Share only details the client needs to run the mission. This may include the consultant’s name, business contact information, skills, and access requirements. Payroll details, home address, or other private records should not be sent without a clear need.
Good portage consultant privacy practices start with a simple data map. Record what is shared, who receives it, why they need it, and how long they will keep it.
Choose and document the appropriate GDPR legal basis
The consultant data sharing lawful basis depends on the purpose and the party making that decision. A portage company may rely on a legal obligation for payroll records or a contract to manage employment. A client may use legitimate interests to control secure access to its workplace, where that basis fits the facts.
Document the purpose, data, recipients, and chosen legal basis before sharing. Consent is not a default solution in an employment relationship, since the employee may not feel free to refuse.
GDPR checklist for sharing portage consultant data with clients

Before sharing mission data, confirm that the consultant understands what will be shared and why. This GDPR checklist for portage consultants can help your team set clear steps for each client assignment.
Be transparent about recipients, purposes, and data rights
Tell the consultant who may receive their data, how it will be used, and how long it will be kept. For data collected directly, check the notice rules under Article 13. For data received from another source, check Article 14.
Give consultants a clear way to request access, correction, objection, restriction, or erasure. Rights depend on the situation and may have legal limits. A practical guide to CNIL consultant data rights should explain how to submit a request and who will respond.
Limit access, secure transfers, and set retention rules
Share only the details the client needs for the mission. Use approved channels, restrict access to relevant people, and remove data when its purpose ends or the retention period expires. These steps support secure client data sharing France.
Check processor terms and international data transfers
Confirm each party’s role before data is sent. If a provider processes data on your instructions, record the required duties, safeguards, and return or deletion terms. Review data retention and processor agreement details, including any transfer outside the European Economic Area.
Use a practical pre-sharing checklist for each mission
- Confirm the purpose, legal basis, and data recipients.
- Check that the privacy notice covers the planned sharing.
- Set access controls, transfer safeguards, and a retention date.
- Record processor terms and the process for handling rights requests.
Keep the notice, processing records, and any breach forms together. GDPR templates and registers can help organize these records for each mission.
Conclusion
GDPR compliance portage salarial France starts with clarity. For each mission, identify who uses consultant data, why it is shared, and which legal basis applies. Explain this to the consultant before sharing begins.
Use the portage mission data-sharing checklist to confirm recipients, access, retention periods, and security measures. Share only what the client needs, and protect consultant personal data from collection through deletion.
Keep records of your decisions and review them when a mission or process changes. Consultants can also consult Jump’s privacy policy to learn about data use, retention, and their rights.
FAQ
What is French portage salarial, and how is it different from commercial portage?
In French portage salarial, the portage company employs the consultant under an employment contract. The client company has a separate commercial services agreement with the portage company and receives the consultant’s services. A separate commercial or administrative portage model is a business-to-business arrangement and does not, by itself, make the service provider an employee.
Who is responsible for consultant personal data in a portage mission?
The role depends on what each party actually does with the data. The portage company will often act as a data controller for employment, payroll, and mission administration. The client may be a separate controller for its own business purposes. A party is a processor when it handles data on another controller’s documented instructions. If parties jointly decide the purposes and essential means of processing, they may need a joint-controller arrangement under GDPR Article 26.
What consultant data may be shared with a client?
Share only information the client needs to set up and manage the mission. This may include professional contact details, skills, qualifications, availability, assignment details, and time or activity records. Avoid sending unrelated employment, payroll, identity, or sensitive information unless it is necessary and there is a valid legal basis and suitable protection.
What legal basis can support sharing consultant data with a client?
The right legal basis depends on the purpose and the parties’ roles. It may include performing a contract, meeting a legal obligation, or pursuing a legitimate interest where that interest is appropriate and the consultant’s rights are protected. Do not assume that consent is always required or that it is always the best basis. Record the reasoning for each purpose and sharing activity.
What privacy information must the consultant receive before data is shared?
The consultant should receive clear information about why their data is used, who may receive it, how long it is kept, and how to exercise applicable rights. GDPR Article 13 applies when data is collected from the consultant; Article 14 applies when it comes from another source. The notice should also explain how to contact the relevant party about a privacy request.
What rights can a consultant exercise over their personal data?
Depending on the circumstances, a consultant may request access or correction, or ask for restriction, erasure, or object to certain processing. These rights can be subject to legal limits. Provide a practical contact route and ensure the request reaches the party responsible for the relevant processing. The CNIL explains individuals’ rights at cnil.fr.
How should a portage company and client protect shared mission data?
Limit access to people who need the information, use secure transfer methods, and set clear retention and deletion rules. Keep only the data needed for the mission, protect it throughout its lifecycle, and document the safeguards in use. These steps support GDPR principles such as data minimization, storage limitation, and security.
When are processor terms or international transfer safeguards needed?
If a party processes personal data on another party’s behalf, the parties should assess whether GDPR Article 28 terms are required. If data is transferred outside the European Economic Area, check the transfer conditions and safeguards under the GDPR before sending it. The parties’ actual roles and the transfer route matter; contract labels alone do not decide them.
What should a client or consultant check before data is sent for a mission?
Confirm the purpose and legal basis, the data being shared, the recipients, and who can access it. Check that the consultant has received the required privacy information, that retention and security measures are clear, and that any processor terms or international transfer safeguards are in place. The French Labor Code is available on Legifrance, and the GDPR text is available on EUR-Lex.
Official and professional resources
- France's official portage salarial guide
- French Labor Code: financial guarantee requirements
- CNIL: working with a data processor
Compare your assignment assumptions with the portage salary simulator. Results are estimates based on the inputs provided.
