French Data Protection Authority (CNIL) · 28 May 2019
SERGIC (Real Estate)
Insufficient technical and organisational measures to ensure information security
Fine€400,000Fine issued
- Regulator
- French Data Protection Authority (CNIL)
- Decided
- 28 May 2019
- Country
- France
- Sector
- Real Estate
- Regulator’s reference
- Not recorded
- Fino case number
- 2019/FR/004
What happened
The French DPA (CNIL) held that using an unprotected URL address to share documents containing personal data violates Article 32 GDPR. Retaining personal data of an applicant for a lease after another applicant has been selected also violates Article 5(1)(e) GDPR.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2019/FR/004.