Carrefour France

€2,250,000

Non-compliance with general data processing principles

決定日

2020年11月18日

権威

French Data Protection Authority (CNIL)

FR

セクター

Industry and Commerce

国名

FR

法律

GDPR

ステータス

FINAL

説明

The French DPA (CNIL) fined Carrefour France EUR 2,250,000 for several violations of data protection regulations, including the GPDR. During its investigation, the CNIL found that the information on personal data provided to users of the carrefour.fr websites and those wishing to join the loyalty program was neither easily accessible nor easily comprehensible. The CNIL also found that the information regarding the transfer of data to countries outside the EU and regarding the duration of data storage was incomplete. The CNIL also notes that the company did not comply with the storage time limits. Furthermore, the data of more than twenty-eight million customers who were inactive for five to ten years were stored for the purposes of the loyalty program. This was also the case for 750,000 users of the carrefour.fr site, who were inactive for five to ten years. The CNIL states that the company required proof of identity for almost every user request to exercise a right. However, this automatic requirement was not justified, as in most cases there was no doubt regarding the identity of the data subjects. Furthermore, the company did not respond to several requests from individuals who wanted to access their personal data. Also, in numerous cases, the company did not carry out the erasure of data requested by individuals. Finally, the company has not responded to several requests from persons who did not agree to receive advertising by SMS or e-mail.

法的引用

Art. 5Art. 12Art. 13Art. 15Art. 17Art. 21Art. 32Art. 33

問題と違反

Non-compliance with general data processing principles

プライバシー保護に関する最新情報

あなたのプライバシーを尊重します。メール配信は月1回、迷惑メールはありません。