KG COM – €150,000 Fine (France, 2023)

€150,000Commission Nationale de l'Informatique et des Libertés8 June 2023France
final
ePrivacy
Fine

KG COM was fined for recording customer conversations without proper justification and for not securing personal data. This is important because it highlights the need for companies to protect customer information and only collect what they truly need.

What happened

KG COM recorded conversations with customers without adequately justifying the need for such recordings.

Who was affected

Customers who interacted with KG COM's services were affected.

What the authority found

The authority ruled that KG COM did not have a valid reason for recording conversations and failed to protect personal data properly.

Why this matters

This case serves as a reminder that businesses must have clear reasons for collecting data and must ensure that customer information is kept secure.

GDPR Articles Cited

AI-verified

Art. 6(GDPR)
Art. 9(GDPR)
Art. 12(GDPR)
Art. 13(GDPR)
Art. 28(GDPR)
Art. 32(GDPR)
Art. 33(GDPR)
Art. 5(1)(c) GDPR
View original scraped data
Art. 5(1) c) GDPR
e) GDPR
Art. 6(GDPR)
Art. 9(GDPR)
Art. 12(GDPR)
Art. 13(GDPR)
Art. 28(GDPR)
Art. 32(GDPR)
Art. 33(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 82 Loi informatique et libertés
Source verified 3 April 2026
articles corrected
Full Legal Summary
Detailed

The French DPA has imposed a fine of EUR 150,000 on the company KG COM. The company operates several websites and offers fortune-telling consultations to customers via chat or telephone. After the company suffered a data breach, the DPA conducted three investigations. During its investigation, the DPA found that the controller systematically recorded conversations with customers as well as potential customers without properly justifying why such extensive recording was necessary. In addition, the controller stored banking information of its customers for the purposes of conducting transactions and combating fraud, as well as to facilitate customers' purchase of further fortune-telling consultations. The DPA found that a legitimate interest of the controller could be affirmed for the storage of bank data for the purpose of fraud prevention, but not for the storage regarding further purchases. The DPA also found that the controller processed data on the health status as well as the sexual orientation of its customers without their explicit consent; implied consent through use of the consultations was not considered sufficient. In addition, the DPA found that the controller had failed to implement appropriate technical and organizational measures to protect personal data. The controller did not, for example, provide sufficiently robust passwords for the user accounts, which exposed the data to the risk of computer attacks. Finally, the DPA found that the controller failed to report a data leak to the DPA.

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for KG COM in FR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

8 June 2023

Authority

Commission Nationale de l'Informatique et des Libertés

Fine Amount

€150,000

Enforcement Tracker ID

ETid-1891

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified
Cookie relevance: 20%

Cite as: Cookie Fines. KG COM - France (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: