SLIMPAY – €180,000 Fine (France, 2021)

€180,000Commission Nationale de l'Informatique et des Libertés28 December 2021France
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

SLIMPAY, a payment service provider, was fined for improperly handling personal data during a testing project. They stored sensitive information, including bank details, on an unsecured server accessible to anyone online. This case highlights the critical need for companies to protect personal data with appropriate security measures.

What happened

SLIMPAY stored personal data on an unsecured server that was accessible from the Internet for several years.

Who was affected

Over 12 million individuals whose personal information, including names and bank details, was exposed due to SLIMPAY's negligence.

What the authority found

The French data protection authority found that SLIMPAY violated multiple GDPR provisions related to data security and processing agreements.

Why this matters

This case underscores the importance of implementing strong security measures for personal data. Companies must ensure that their data handling practices comply with GDPR to avoid significant fines.

GDPR Articles Cited

AI-verified

Art. 32(GDPR)
Art. 34(GDPR)
Art. 28(3) GDPR
Art. 28(4) GDPR
View original scraped data
Art. 28(3) GDPR
Art. 28(4) GDPR
Art. 32(GDPR)
Art. 34(GDPR)

Original data from scraper before AI verification against source document.

Source verified 10 March 2026
articles corrected
Full Legal Summary
Detailed

In 2015, SLIMPAY (a payment service provider) reused personal data contained in its databases for testing purposes, as part of a research project that ended in July 2016. The data used remained stored on a server without any particular security procedure and freely accessible from the Internet. SLIMPAY was warned of the issue by one of its client (a legal person) in 2020. Then, SLIMPAY took measures to put an end to the data breach and proceeded to notify it to the French Data Protection Authority (DPA), but decided not to notify it to the data subjects. Afterwards, the DPA decided to carry out an investigation of SLIMPAY's GDPR compliance. The DPA found out that SLIMPAY breached several GDPR provisions. = The DPA noted that some of the contracts concluded by SLIMPAY with its service providers (subprocessors) did not contain all of the clauses that would make it possible to ensure that these subcontractors undertake to process personal data in compliance with GDPR, whereas some other contracts did not even contain any of these clauses. = The DPA noted that the server in question was not subject to any appropriate security measures, and was freely accessible by anyone between November 2015 and February 2020. Furthermore, the categories of data aggravated the case, considering that civil status data (name, surname, first name), postal and e-mail addresses, telephone numbers and bank details (BIC/IBAN) of more than 12 million people were compromised. The DPA also held that the absence of proven harm to the data subjects has no bearing on the existence of the violation of Article 32 GDPR, contrary to what SLIMPAY claimed during the procedure. = The DPA considered that, given the nature of the personal data concerned by the breach, the number of data subjects affected (more than 12 million), and the possibility to identify them from the accessible data and the risks of phishing or identity theft that were implied because of the breach, the risk associated with

Related Enforcement Actions (0)

No other enforcement actions found for SLIMPAY in FR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

28 December 2021

Authority

Commission Nationale de l'Informatique et des Libertés

Fine Amount

€180,000

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. SLIMPAY - France (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: