GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Optical Retail Company

Country
France
Fine
250,000 EUR
Date
2018-05-07
Sector
Business Sector
Articles
pre-GDPR

Fine

The CNIL found that the company had not implemented an appropriate method of authenticating customers on its website to allow them to access their invoices. As a result, customers were able to access the documents (which included names, addresses, health records and, in some cases, social security numbers) of another customer. In determining the amount of the fine, the CNIL took into account the sensitivity of the information, the number of clients involved and the fact that more than 334,000 records were compromised in the course of the infringement. Note: A decision of the Conseil d'État (Supreme Administrative Court) of 17 April 2019 reduced the administrative fine to 200,000 euros, as the company reacted quickly to remedy the lack of security of its website. Authority: CNIL - French Data Protection Autority (National Commission for Informatics and Liberties)

Source: https://www.legifrance.gouv.fr/affichCnil.do?id=CNILTEXT000037013610

Reported by: Alain Bensoussan Avocats Lexing