ACTIVE ASSURANCES (car insurer)

€180,000

Insufficient technical and organisational measures to ensure information security

Date de décision

25 juillet 2019

Autorité

French Data Protection Authority (CNIL)

FR

Secteur

Finance, Insurance and Consulting

Pays

FR

Droit

GDPR

Statut

FINAL

Description

Large amount of customer accounts, clients' documents (including copies of driver's licences, vehicle registration, bank statements and documents to determine whether a person had been the subject of a licence withdrawal) and data were easily accesible online. The CNIL, between others, critizised the password management (unauthorized access was possible without any authentication).

Citations légales

Art. 32

Questions et violations

Insufficient technical and organisational measures to ensure information security

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.