KG COM – €150,000 Fine (France, 2023)
KG COM was fined for recording customer conversations without proper justification and storing sensitive data without consent. This case is important because it shows that companies must be transparent about how they handle personal information and ensure they have a valid reason for data collection.
What happened
KG COM recorded conversations with customers without properly justifying the need for such recordings.
Who was affected
Customers who used KG COM's fortune-telling services and had their conversations recorded.
What the authority found
The authority ruled that KG COM violated GDPR by failing to justify extensive data recording and not obtaining explicit consent for sensitive data processing.
Why this matters
This case highlights the need for businesses to have clear consent processes and justifications for data collection. Companies should review their data practices to avoid similar penalties.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The French DPA has imposed a fine of EUR 150,000 on the company KG COM. The company operates several websites and offers fortune-telling consultations to customers via chat or telephone. After the company suffered a data breach, the DPA conducted three investigations. During its investigation, the DPA found that the controller systematically recorded conversations with customers as well as potential customers without properly justifying why such extensive recording was necessary. In addition, the controller stored banking information of its customers for the purposes of conducting transactions and combating fraud, as well as to facilitate customers' purchase of further fortune-telling consultations. The DPA found that a legitimate interest of the controller could be affirmed for the storage of bank data for the purpose of fraud prevention, but not for the storage regarding further purchases. The DPA also found that the controller processed data on the health status as well as the sexual orientation of its customers without their explicit consent; implied consent through use of the consultations was not considered sufficient. In addition, the DPA found that the controller had failed to implement appropriate technical and organizational measures to protect personal data. The controller did not, for example, provide sufficiently robust passwords for the user accounts, which exposed the data to the risk of computer attacks. Finally, the DPA found that the controller failed to report a data leak to the DPA.
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for KG COM in FR
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
8 June 2023
Authority
Commission Nationale de l'Informatique et des Libertés
Fine Amount
€150,000
Enforcement Tracker ID
ETid-1891
About this data
Cite as: Cookie Fines. KG COM - France (2023). Retrieved from cookiefines.eu
Last updated: