CNIL (France) · 8 December 2020
Nestor SAS
About: Data security, Data subject rights, Transparency
- Regulator
- CNIL (France)
- Decided
- 8 December 2020
- Country
- France
- Sector
- Not given
- Regulator’s reference
- SAN-2020-018
- Fino case number
- 2020/FR/016
What happened
The French DPA (CNIL) imposed a fine of €20,000 on the catering company Nestor. The company sent commercial emails without gathering consent (Article L. 34-5 Postal and Electronic Communication law), it did not provide sufficient information to data subjects (Articles 12 and 13 GDPR), it failed to respect data subjects' right of access (Article 15) and finally, it did not afford sufficient security to personal data it processed (Article 32).
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subject12(4)Read →
- Art. 13Information to be provided where personal data are collected from the data subjectRead →
- Art. 15Right of access by the data subject15(1) · 15(3)Read →
- Art. 32Security of processingRead →
- Data security
- Data subject rights
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/FR/016.