French Data Protection Authority (CNIL) · 18 November 2020
Carrefour France
Non-compliance with general data processing principles
- Regulator
- French Data Protection Authority (CNIL)
- Decided
- 18 November 2020
- Country
- France
- Sector
- Industry and Commerce
- Regulator’s reference
- Not recorded
- Fino case number
- 2020/FR/004
What happened
The French DPA (CNIL) imposed a € 2250000 fine on Carrefour France for several violations of the GDPR and French data protection law. These include: excessive data retention periods, incomplete and unclear information on data processes, lack of proper answer to data subjects' requests, security breaches and illicit use of cookies.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal dataRead →
- Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subjectRead →
- Art. 13Information to be provided where personal data are collected from the data subjectRead →
- Art. 15Right of access by the data subjectRead →
- Art. 17Right to erasure (‘right to be forgotten’)Read →
- Art. 21Right to objectRead →
- Art. 32Security of processingRead →
- Art. 33Notification of a personal data breach to the supervisory authorityRead →
- Data breach
- Data principles
- Data security
- Data subject rights
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/FR/004.