Spanish Data Protection Authority (AEPD) · 14 March 2025
CENTROS COMERCIALES CARREFOUR, S.A.
Insufficient technical and organisational measures to ensure information security
- Regulator
- Spanish Data Protection Authority (AEPD)
- Decided
- 14 March 2025
- Country
- Spain
- Sector
- Industry and Commerce
- Regulator’s reference
- Not recorded
- Fino case number
- 2025/ES/069
What happened
The DPA fined Carrefour €3,200,000 in the wake of a series of data breaches. The DPA found that Carrefour had not implemented adequate security measures and that they had failed to report the breach to the affected data subjects. Carrefour was ordered to inform the affected data subjects of the breaches, subject to further fines for noncompliance.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 32Security of processingRead →
- Art. 34Communication of a personal data breach to the data subjectRead →
- Data breach
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2025/ES/069.