French Data Protection Authority (CNIL) · 28 December 2021
SLIMPAY
Insufficient technical and organisational measures to ensure information security
Fine€180,000Fine issued
- Regulator
- French Data Protection Authority (CNIL)
- Decided
- 28 December 2021
- Country
- France
- Sector
- Finance, Insurance and Consulting
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/FR/005
What happened
The French DPA fined the payment service provider SLIMPAY €180,000 for failing to implement appropriate technical and organisational measures, and to report a data breach which affected over 12,000,000 data subjects.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 28ProcessorRead →
- Art. 32Security of processingRead →
- Art. 34Communication of a personal data breach to the data subjectRead →
- Data breach
- Data security
- Processor obligations
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/FR/005.