CNIL (France) · 28 July 2020
SPARTOO SAS
About: Data principles, Data security, Transparency
- Regulator
- CNIL (France)
- Decided
- 28 July 2020
- Country
- France
- Sector
- Not given
- Regulator’s reference
- SAN-2020-003
- Fino case number
- 2020/FR/009
What happened
In the context of an investigation against SPARTOO SAS, a company specialised in online footwear shopping with activities in thirteen EU countries, the French DPA (Commission Nationale de l'Informatique et des Libertés- CNIL), as the lead supervisory authority in cooperation with DPAs from other EU countries held that the processing activities of SPARTOO SAS did not comply with a series of GDPR provisions (art. 5§1(c), 5§1(e), 13, 32 GDPR). In that respect, CNIL imposed a fine of 250,000 euros and called SPARTOO SAS to bring its processing activities in conformity with GDPR in a period of three months since the publication of the decision.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(c) · 5(1)(e)Read →
- Art. 13Information to be provided where personal data are collected from the data subjectRead →
- Art. 32Security of processing32(1)Read →
- Art. 56Competence of the lead supervisory authority56(1)Read →
- Data principles
- Data security
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/FR/009.