SERGIC (Real Estate)
- Country
- France
- Fine
- 400,000 EUR
- Date
- 2019-05-28
- Sector
- Business Sector
- Articles
- Art. 32 GDPR
Insufficient technical and organisational measures to ensure information security
The CNIL based the penalty on two grounds: lack of security measures and excessive data retention. Details of the two reasons: The user documents uploaded by the tenant candidates (including identity cards, health cards, tax assessment notices, certificates from the Family Allowance Fund, divorce decrees, bank statements) were accessible online without any authentication procedure. Although the vulnerability had been known to the company since March 2018, it was not resolved until September 2018. Furthermore, the company kept the documents submitted by the candidates longer than necessary. The CNIL took into account, among other things, the seriousness of the breach (lack of diligence in remedying the vulnerability and the fact that the documents contained intimate aspects of users' lives), the size of the company and its financial situation. Authority: French Data Protection Authority (CNIL)
Reported by: Alain Bensoussan Avocats Lexing
