GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Telecom Company Description

Country
France
Fine
250,000 EUR
Date
2018-12-26
Sector
Business Sector
Articles
pre-GDPR

Fine

The company experienced a data breach involving the personal information of more than 2 million customers over a two-year period because the company failed to reactivate an authentication feature on its website that had been disabled for a trial period. The company was fined for failing to ensure the security of its customers' personal information. The CNIL determined the amount of the fine taking into account the company's rapid reactivity in remedying the security breach and the many measures taken to limit the consequences of the breach. Authority: CNIL - French Data Protection Autority (National Commission for Informatics and Liberties)

Source: https://www.legifrance.gouv.fr/affichCnil.do?id=CNILTEXT000037856073

Reported by: Alain Bensoussan Avocats Lexing