• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
easy GDPR - we make compliance with GDPR easy

easyGDPR

We make implementing General Data Protection Regulation Easy

  • Home
  • Services
    • Software
      • easyGDPR Quickcheck
      • (DEP) easyGDPR lite
      • (DEP) easyGDPR Standard
      • Data Subject Requests
      • Sophos
    • IT Security
    • network checkup
    • SME digitization funding
    • Data protection consulting
      • Data protection
      • Cybersecurity
    • Training
      • Data protection
      • Cybersecurity
  • Partner
    • Resellerprogramm
    • Affiliate programm
  • GDPR
    • GDPR News
    • FAQ
    • GDPR Decisions
    • GDPR penalties
    • GDPR legal text
  • Shop
  • Contact
    • Contact
    • Newsletter registration
  • Login
    • Shop / Affiliate Program
    • easyGDPR Software
  • German
  • English

Recent decisions of the french. Data protection authority

21/11/2018 by Andreas Schindler

GDPR has teeth, dsgvo penalties in france

French data protection authority (CNIL) actively intervenes

The Austrian data protection authority is not the only one to punish companies that do not comply with the GDPR. The French data protection authority (CNIL) is also intervening more and more actively, as you can see in the following examples.

Personal data used unlawfully for marketing purposes

1. on October 18, the French data protection authority published five notices against three companies of the Gie Humanis Fonctions Group and against two companies of the Malakoff-Médéric Group. These companies have been found to have violated Article 6 (2) of the GDPR. Article 6 describes the lawfulness of the processing.

During its investigation, CNIL found that personal data was provided to the above-mentioned companies by two associations for the implementation of supplementary pension plans. However, these companies also used the personal data for marketing purposes. This was done without the authorization of these two associations.

These companies have thereby undoubtedly violated the GDPR, as there was no legitimate interest for this processing. The French data protection authority therefore demanded that these five companies immediately cease this processing and that the requirements of the GDPR be met within one month.

Illegal collection of personal data

2. the second case concerns the French company Singlespot, which collected the following data from its customers via its own mobile app: the IDs for mobile advertising (comparable to cookies, only for mobile apps), the name and version of the users’ mobile app, and also which operating system (Android or IOS) was used in the process. This data was then transferred to the company without specifically informing the customers about it and also without obtaining the customers’ consent for this transfer.

At the end of the CNIL inspection, over 14 million advertising IDs, based on which personalized ads are created, were found in Singlespot’s database. And over 5 million of these were additionally linked to geolocation, meaning the exact location of people was stored when they used the app.

This results in some violations of the legislation:

  • No legal ground for the implementation of this processing has been provided(a consent, in this case).
  • No appropriate retention period for this purpose of processing has been established or observed(principle of data minimization).
  • Data security and confidentiality werenot ensured as stated in the company’s privacy policy.

The CNIL has therefore decided that all 14 million records of clients/possible clients collected without complying with the GDPR must be deleted. Furthermore, future data collection must be brought in line with the GDPR, otherwise the data protection authority has already announced fines.

Source: Yes the GDPR has teeth

Category iconGDPR fines

Primary Sidebar

IT-Security Whitepaper Downloaden
  • German
  • English
  • Data Protection Statement
  • Terms and Conditions
  • Imprint
  • Licence terms for easyGDPR
  • GDPR terms
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking "Accept", you consent to the use of ALL the cookies.
SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.

Non Necessary

Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.

functionality

Diese Art von Cookies erhöht die Benutzerfreundlichkeit unserer Website. Beispielsweise wird darin die von Ihnen ausgewählte Sprache gespeichert. Auch die Verfügbarkeit von Videostreams und sonstigem Inhalt kann von diesen Cookies abhängig sein. Wenn Sie diese Cookies ablehnen, ist die Benutzerfreundlichkeit eingeschränkt.

Save & Accept