GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

SERGIC (Real Estate)

Country
France
Fine
400,000 EUR
Date
2019-05-28
Sector
Business Sector
Articles
Art. 32 GDPR

Insufficient technical and organisational measures to ensure information security

The CNIL based the penalty on two grounds: lack of security measures and excessive data retention. Details of the two reasons: The user documents uploaded by the tenant candidates (including identity cards, health cards, tax assessment notices, certificates from the Family Allowance Fund, divorce decrees, bank statements) were accessible online without any authentication procedure. Although the vulnerability had been known to the company since March 2018, it was not resolved until September 2018. Furthermore, the company kept the documents submitted by the candidates longer than necessary. The CNIL took into account, among other things, the seriousness of the breach (lack of diligence in remedying the vulnerability and the fact that the documents contained intimate aspects of users' lives), the size of the company and its financial situation. Authority: French Data Protection Authority (CNIL)