Sanction RGPD French Data Protection Authority (CNIL) — Company : 3,5 M€ (2025)
- Autorité de contrôle
- French Data Protection Authority (CNIL)
- Pays
- France
- Entreprise / secteur
- Company
- Montant de l'amende
- 3,5 M€
- Date de la décision
- 30 décembre 2025
- Fondement juridique
- Art. 6 (1) a), Art. 13, Art. 32, Art. 35
- Manquement
- Non-respect des principes de traitement
Résumé des faits
The French DPA has imposed a fine of EUR 3,500,000 on a company. The controller operated a loyalty program in France and 16 other EU countries, using customer data obtained through the program to transfer it to a third party for marketing purposes. The controller had no sufficient legal basis for this transfer and also failed to inform the data subjects. Furthermore, the controller used an inadequate method to store passwords. Finally, the controller failed to conduct a data protection impact assessment, which would have been mandatory given the amount of data being processed and the cross-referencing of data.