Carrefour France – €2,250,000 Fine (France, 2020)
Carrefour France was fined EUR 2,250,000 for not properly informing customers about how their personal data was used. The company failed to make this information clear and accessible, which is important for customer trust. This case highlights the need for businesses to be transparent about data practices.
What happened
Carrefour France did not provide clear and accessible information about personal data usage on its website and loyalty program.
Who was affected
Over twenty-eight million customers who participated in Carrefour's loyalty program were affected.
What the authority found
The French data protection authority found that Carrefour violated multiple GDPR rules regarding data transparency and user rights.
Why this matters
This ruling emphasizes that companies must clearly communicate how they handle personal data. Other businesses should ensure their privacy notices are straightforward and comply with data protection laws.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
The French DPA (CNIL) fined Carrefour France EUR 2,250,000 for several violations of data protection regulations, including the GPDR. During its investigation, the CNIL found that the information on personal data provided to users of the carrefour.fr websites and those wishing to join the loyalty program was neither easily accessible nor easily comprehensible. The CNIL also found that the information regarding the transfer of data to countries outside the EU and regarding the duration of data storage was incomplete. The CNIL also notes that the company did not comply with the storage time limits. Furthermore, the data of more than twenty-eight million customers who were inactive for five to ten years were stored for the purposes of the loyalty program. This was also the case for 750,000 users of the carrefour.fr site, who were inactive for five to ten years. The CNIL states that the company required proof of identity for almost every user request to exercise a right. However, this automatic requirement was not justified, as in most cases there was no doubt regarding the identity of the data subjects. Furthermore, the company did not respond to several requests from individuals who wanted to access their personal data. Also, in numerous cases, the company did not carry out the erasure of data requested by individuals. Finally, the company has not responded to several requests from persons who did not agree to receive advertising by SMS or e-mail.
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Carrefour France in FR
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
18 November 2020
Authority
Commission Nationale de l'Informatique et des Libertés
Fine Amount
€2,250,000
About this data
Cite as: Cookie Fines. Carrefour France - France (2020). Retrieved from cookiefines.eu
Last updated: