Fino

CNIL (France) · 8 December 2020

Nestor SAS

About: Data security, Data subject rights, Transparency

Fine€20,000Violation found
Regulator
CNIL (France)
Decided
8 December 2020
Country
France
Sector
Not given
Regulator’s reference
SAN-2020-018
Fino case number
2020/FR/016
Export as PDF

What happened

The French DPA (CNIL) imposed a fine of €20,000 on the catering company Nestor. The company sent commercial emails without gathering consent (Article L. 34-5 Postal and Electronic Communication law), it did not provide sufficient information to data subjects (Articles 12 and 13 GDPR), it failed to respect data subjects' right of access (Article 15) and finally, it did not afford sufficient security to personal data it processed (Article 32).

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data security
  • Data subject rights
  • Transparency

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/FR/016.