Optical Retail Company
- Country
- France
- Fine
- 250,000 EUR
- Date
- 2018-05-07
- Sector
- Business Sector
- Articles
- pre-GDPR
Fine
The CNIL found that the company had not implemented an appropriate method of authenticating customers on its website to allow them to access their invoices. As a result, customers were able to access the documents (which included names, addresses, health records and, in some cases, social security numbers) of another customer. In determining the amount of the fine, the CNIL took into account the sensitivity of the information, the number of clients involved and the fact that more than 334,000 records were compromised in the course of the infringement. Note: A decision of the Conseil d'État (Supreme Administrative Court) of 17 April 2019 reduced the administrative fine to 200,000 euros, as the company reacted quickly to remedy the lack of security of its website. Authority: CNIL - French Data Protection Autority (National Commission for Informatics and Liberties)
Source: https://www.legifrance.gouv.fr/affichCnil.do?id=CNILTEXT000037013610
Reported by: Alain Bensoussan Avocats Lexing
