Fino

French Data Protection Authority (CNIL) · 13 September 2022

GIE INFOGREFFE

Insufficient technical and organisational measures to ensure information security

Fine€250,000Fine issued
Regulator
French Data Protection Authority (CNIL)
Decided
13 September 2022
Country
France
Sector
Public Sector and Education
Regulator’s reference
Not recorded
Fino case number
2022/FR/005
Export as PDF

What happened

The French DPA fined a company €250,000 for infringing Article 5(1)(e) GDPR. It violated the provision by storing personal data for an excessive period of time and by lacking adequate security as passwords were stored without encryption and sent in plain text by email.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/FR/005.