The first French GDPR fine has been brought against a real estate company, costing the company €400,000.
The fine relates to user data which was available on the website by simply modifying the URL slightly, giving anyone access to rental applicant’s documents including IDs, tax returns, bank account details, and more.
After receiving the complaint in August 2018, the CNIL discovered that the company had been aware of the issue since March but didn’t resolve it until September – and, crucially, had not reported it.
As reported by JDSUPRA:
The CNIL identified two violations of the GDPR:
- The company failed to fulfil its obligation to preserve the security of the personal data of its website users, in breach of Article 32 of the GDPRThe company had not put in place a procedure to authenticate users of its website to ensure that the persons accessing the documents were the ones who had uploaded them, a basic measure. This failure was aggravated, on the one hand, by the nature of the data made available and, on the other hand, by the company’s particular lack of diligence in correcting it: the security issue was only resolved six months later and no emergency measures were taken to limit the impact of the issue in the meantime.
- The company kept the documents uploaded by candidates for an unlimited period of time. The documents uploaded by candidates who were not selected for the accommodations they had applied for were kept for a duration that was longer than necessary for the purpose of the processing. The CNIL noted that once the purpose for processing is achieved (e.g., managing the candidacies), the data must be deleted – or at least archived if it needs to be kept for compliance with legal obligations or for dispute management purposes in compliance.
Read the full article here: https://www.jdsupra.com/legalnews/france-s-first-gdpr-fine-costs-real-86375/
The key lessons to learn from this first French GDPR fine are: firstly, to always be aware of all the data you hold on users, and delete it when it is no longer needed. Secondly, the need to report potential data breaches to the relevant body, and to implement emergency measures when a data protection issue is detected.
If you’re concerned about the data your own company holds, our Gap Analysis service involves identifying where all the data is to allow you to take measures to protect it. Get in contact with us today!