CNIL (France) · 30 November 2022
Free
About: Data breach, Data security, Data subject rights, Transparency
Fine€300,000Violation found
- Regulator
- CNIL (France)
- Decided
- 30 November 2022
- Country
- France
- Sector
- Not given
- Regulator’s reference
- SAN-2022-022
- Fino case number
- 2022/FR/018
What happened
The French DPA fined a telecommunications provider €300,000 for several GDPR violations. Among other things, the DPA rejected that the controller's sources of personal data were deemed "business secrets" and held that the controller failed to adequately respond to access and erasure requests.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subject12(3)Read →
- Art. 15Right of access by the data subjectRead →
- Art. 17Right to erasure (‘right to be forgotten’)17(1)(a)Read →
- Art. 32Security of processingRead →
- Art. 33Notification of a personal data breach to the supervisory authorityRead →
- Data breach
- Data security
- Data subject rights
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/FR/018.