Fino

French Data Protection Authority (CNIL) · 28 May 2019

SERGIC (Real Estate)

Insufficient technical and organisational measures to ensure information security

Fine€400,000Fine issued
Regulator
French Data Protection Authority (CNIL)
Decided
28 May 2019
Country
France
Sector
Real Estate
Regulator’s reference
Not recorded
Fino case number
2019/FR/004
Export as PDF

What happened

The French DPA (CNIL) held that using an unprotected URL address to share documents containing personal data violates Article 32 GDPR. Retaining personal data of an applicant for a lease after another applicant has been selected also violates Article 5(1)(e) GDPR.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2019/FR/004.