SGAM AG2R LA MONDIALE – €1,750,000 Fine (France, 2021)

€1,750,000Commission Nationale de l'Informatique et des Libertés20 July 2021France
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The French privacy authority fined SGAM AG2R LA MONDIALE EUR 1,750,000 for keeping people's data longer than allowed and not informing them properly during phone marketing. This matters because it shows companies must respect data retention rules and inform customers about data use. The ruling highlights the importance of following privacy laws to avoid hefty fines.

What happened

SGAM AG2R LA MONDIALE kept customer data longer than legally allowed and failed to inform them during phone marketing campaigns.

Who was affected

Millions of customers whose data was retained too long and people contacted during phone marketing without proper information.

What the authority found

The French authority found SGAM AG2R LA MONDIALE violated GDPR by keeping data too long and not informing people during phone marketing.

Why this matters

This case emphasizes the need for companies to adhere to data retention limits and transparency requirements. Businesses should ensure they have clear data policies and inform customers about how their data is used to avoid penalties.

GDPR Articles Cited

AI-verified

Art. 13 GDPR
Art. 14 GDPR
Art. 5(1)(e) GDPR
View original scraped data
Art. 5(1)(e) GDPR
Art. 13 GDPR
Art. 14 GDPR

Original data from scraper before AI verification against source document.

Source verified 5 March 2026
national law identified
Full Legal Summary
Detailed

The French DPA (CNIL) has fined private insurer SGAM AG2R LA MONDIALE EUR 1,750,000. The CNIL had carried out an inspection at the AG2R LA MONDIALE group in 2019. On this occasion, the CNIL found that the controller kept the data of millions of individuals for an excessive period of time and did not comply with their information obligations in the context of telephone canvassing campaigns. With regard to the data of prospects, the controller did not comply with the maximum retention period of three years defined in the reference framework and in the Group's processing register. As a result, the controller retained the data of nearly 2,000 customers who had not been in contact with the controller for more than three years, and in some cases five years. In relation to customer data, the controller did not comply with the maximum statutory retention periods stipulated in the Insurance Code and the Commercial Code. In this case, the controller retained the data of more than 2 million customers, some of which were sensitive (health) or specific (banking data), beyond the legally permitted retention periods after the end of the contract.

Related Enforcement Actions (0)

No other enforcement actions found for SGAM AG2R LA MONDIALE in FR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

20 July 2021

Authority

Commission Nationale de l'Informatique et des Libertés

Fine Amount

€1,750,000

Enforcement Tracker ID

ETid-771

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. SGAM AG2R LA MONDIALE - France (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: