French retail company –€3.5 million fine

  • Author: Arno Schlösser, DP-Dock GmbH
  • Last updated: June 2026
  • Category: Enforcement, Data Security

Authority
French Data Protection Authority (CNIL)

Fine
€3,500,000

Infringement
Unauthorized disclosure of personal customer data to a social network

Facts
The French data protection authority CNIL has imposed a fine of €3.5 million on a French retail company. The reason was the unauthorised disclosure of personal customer data to a social network without a sufficient legal basis and without the valid consent of the data subjects. The given consent obtained did not provide sufficient information regarding the planned transfer of their data to the network or its use for advertising purposes.

Identified infringements

  • Disclosure of customer data (including email addresses and user behaviour) to a social network without valid consent
  • Lack of a legal basis under Article 6(1) of the GDPR for the data disclosure
  • Insufficient information provided to the affected customers regarding data processing
  • No verifiable verification of data protection requirements

Legal basis
The case relates in particular to infringements of Article 5(1)(a) of the GDPR (lawfulness, processing in good faith, transparency) and Article 6(1) of the GDPR (lawfulness of processing). The authority assessed the data transfer as a systemic deficiency in the handling of customer data.

Conclusion
The fine demonstrates once again that consent is only a valid legal basis if it is properly structured. Companies should therefore not treat their consent processes as a mere formality, but as a key component of compliance: what matters is how the consent is structured, i.e. whether it clearly, comprehensibly and specifically states why data is being processed or disclosed and for what purpose.

If you have any questions or require support regarding the validity of consent under the GDPR, please feel free to contact us.
  

businesswoman working on his phone in the office, select the icon security on the virtual display.Business, technology, internet and networking concept.
© Urupong / stock.adobe.com | #349881038

Privacy settings

We use cookies on our website. Some of them are essential, while others help us improve this website and your experience.

In this overview you can select and deselect individual cookies of a category or entire categories. You will also receive more information about the cookies available.
Group essential
Name Matomo
Technical name
Provider
Expire in days 72
Privacy policy
Use Use without cookies
Allowed
Group external media
Name Calendly
Technical name __cf_bm,__cfruid,OptanonConsent
Provider Calendly LLC
Expire in days 365
Privacy policy
Use To arrange appointments via the provider Calendly
Allowed
Name Contao CSRF Token
Technical name csrf_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy
Use Serves to protect the website from cross-site request forgery attacks. After closing the browser, the cookie is deleted again.
Allowed
Name Contao HTTPS CSRF Token
Technical name csrf_https_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy
Use Serves to protect the encrypted website (HTTPS) against falsification of cross-site requests. After closing the browser the cookie is deleted again
Allowed
Name PHP SESSION ID
Technical name PHPSESSID
Provider Contao
Expire in days 0
Privacy policy
Use PHP cookie (programming language), PHP data identifier. Contains only a reference to the current session. There is no information in the user's browser saved and this cookie can only be used by the current website. This cookie is used all used in forms to increase usability. Data entered in forms will be e.g. B. briefly saved when there is an input error by the user and the user receives an error message receives. Otherwise all data would have to be entered again
Allowed