Rules of use of the common AMC standard
The AFNOR common AMC standard
The AFNOR AMC standard, reference NF P 99-508, allows a single medium, such as a card or a mobile phone, to be used to access the various services offered by a local authority, in compliance with the General Data Protection Regulation (GDPR) and in line with CNIL (French data protection authority) reference text RU-030.
Its main purpose is to give each user unique, predefined and unpredictable identifiers for each service sector.
In its full version, the standard provides for 35 identifiers, one for each service sector.
Originally designed for media compatible with Calypso Revision 3, the standard has been extended to other media, as described in the document « AMC sur supports non Calypso » (see AMC on non-Calypso media). For non-Calypso media, the standard limits use to a smaller number of sectors.
The AMC specification may not be redistributed freely: any entity wishing to consult it must purchase it from AFNOR.

User entities of the common AMC
A user entity of the common AMC is any public or private organisation that has access to several predefined identifiers of the common AMC.
For example, without this list being exhaustive:
- any public body involved in a project using the common AMC;
- a card manufacturer producing cards that contain the common AMC;
- a company developing a virtual AMC;
- a manufacturer of reading devices that access the common AMC;
- a software publisher with access to several predefined identifiers.
The following are not considered user entities:
- a transport authority that buys cards containing the common AMC but does not use the predefined identifiers;
- a software publisher that uses a reading device from another certified user entity to obtain a single predefined identifier, without access to the others.
Obligations of user entities
The development of the common AMC requires ADCET, as the body responsible for its governance and security, to be vigilant and rigorous. Every user entity must therefore sign a simple or full usage agreement with ADCET and be accredited by the association.
In addition to its security principles, the AMC relies on user entities complying with a number of management rules described in the application specifications. It is therefore important, in everyone’s interest, that ADCET can make sure these rules are respected. This is the commitment ADCET made to the CNIL when the standard was created.
Accreditation requires ADCET’s approval. ADCET may refuse an application if the entity does not offer every guarantee that it accepts and applies the security and usage rules of the common AMC.
Once approved, the entity wishing to take part in a project using the common AMC signs the usage agreement for the common AMC application with ADCET.
Running a project based on the common AMC is only possible because ADCET provides the resources needed to support, develop, secure and govern the common AMC, which represents a significant workload. Accreditation is therefore granted free of charge, provided that the user entity is a member of ADCET and up to date with its membership fees for the whole duration of its participation in the project.
The common AMC logo must appear on every medium that includes the common AMC. Each card manufacturer is asked to submit a visual for approval before any new production; if the logo is missing, ADCET will object to the production of the cards.
Obligations of organisations leading projects that use the common AMC
Organisations leading projects that use the common AMC must also make sure that each user entity is registered with ADCET as an accredited organisation. In particular, public bodies leading such projects must state this obligation in the calls for tenders and contracts they conclude with third parties for the use and/or production of the common AMC.
The lists of accredited public organisations and private companies are kept up to date on this website.