French retail company –€3.5 million fine
- Author: Arno Schlösser, DP-Dock GmbH
- Last updated: June 2026
- Category: Enforcement, Data Security
Authority
French Data Protection Authority (CNIL)
Fine
€3,500,000
Infringement
Unauthorized disclosure of personal customer data to a social network
Facts
The French data protection authority CNIL has imposed a fine of €3.5 million on a French retail company. The reason was the unauthorised disclosure of personal customer data to a social network without a sufficient legal basis and without the valid consent of the data subjects. The given consent obtained did not provide sufficient information regarding the planned transfer of their data to the network or its use for advertising purposes.
Identified infringements
- Disclosure of customer data (including email addresses and user behaviour) to a social network without valid consent
- Lack of a legal basis under Article 6(1) of the GDPR for the data disclosure
- Insufficient information provided to the affected customers regarding data processing
- No verifiable verification of data protection requirements
Legal basis
The case relates in particular to infringements of Article 5(1)(a) of the GDPR (lawfulness, processing in good faith, transparency) and Article 6(1) of the GDPR (lawfulness of processing). The authority assessed the data transfer as a systemic deficiency in the handling of customer data.
Conclusion
The fine demonstrates once again that consent is only a valid legal basis if it is properly structured. Companies should therefore not treat their consent processes as a mere formality, but as a key component of compliance: what matters is how the consent is structured, i.e. whether it clearly, comprehensibly and specifically states why data is being processed or disclosed and for what purpose.
If you have any questions or require support regarding the validity of consent under the GDPR, please feel free to contact us.