Accor – €600,000 Fine (France, 2022)

€600,000Commission Nationale de l'Informatique et des Libertés3 August 2022France
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Accor was fined for mishandling user consent and failing to provide clear information about data processing. This is significant because it affects how companies must communicate with customers about their data. Businesses should ensure they have clear consent processes and privacy policies.

What happened

Accor used pre-ticked consent boxes and made it difficult for users to unsubscribe from marketing emails.

Who was affected

Millions of users who registered on Accor's website and received promotional emails were affected.

What the authority found

The French data authority found that Accor violated GDPR by not obtaining valid consent and failing to provide necessary information about data processing.

Why this matters

This case sets a precedent for how companies must handle user consent and transparency. Businesses should review their consent mechanisms and ensure clear communication about data usage.

GDPR Articles Cited

AI-verified

Art. 13(GDPR)
Art. 32(GDPR)
Art. 12(1) GDPR
Art. 12(3) GDPR
Art. 15(1) GDPR
Art. 21(2) GDPR
Art. 55(1) GDPR
Art. 83(1) GDPR
View original scraped data
Art. 12(1) GDPR
Art. 12(3) GDPR
Art. 13(GDPR)
Art. 15(1) GDPR
Art. 21(2) GDPR
Art. 32(GDPR)
Art. 55(1) GDPR
Art. 83(1) GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Article L34-5 CPCE
Source verified 2 April 2026
articles corrected
national law identified
Full Legal Summary
Detailed

The controller, Accor, is a large, multinational chain that operates hotels in 110 countries. Between December 2018 and September 2019, the French DPA (CNIL) received several complaints concerning the controller's various potential violations of the GDPR. On 24 Feburary 2020, the CNIL conducted an investigation of the controller's website. Users supplied their contact information, including email address, when they registered an account with the controller. The registration process featured a pre-ticked box indicating consent to receive promotional materials. Data subjects subsequently started receiving these promotional materials in their inboxes. They were unable to unsubscribe from direct marketing emails, as various technical glitches prevented the emails' "unsubscribe" button from working. Several million people received these emails at valid addresses, though the CNIL's published decision redacted the exact amount. Additionally, the website did not provide data subjects with information about the controller's contact details, the purposes of processing for the data collected, the legal basis for processing, the period for which the data would be retained, potential transfers, or the right to lodge a complaint under the GDPR, and there was no link to a privacy policy that might contain this information. The CNIL also received one complaint regarding difficulties encountered exercising the right of access to personal banking data processed by the controller. The controller had failed to respond to an access request after locking a data subject's account for suspected fraudulent activity even after data subject verified their identity. Finally, for the controller to access the "Adobe Campaign" account responsible for managing these email communications, a weak password consisting of seven capital letters and one special character was required, although access was only possible from a terminal connected to the ACCOR network. Ten other supervisory author

Violations (3)

Pre-ticked Consent Boxes
high

Cookie consent checkboxes are pre-selected by default, violating the requirement for active, affirmative consent.

Art. 4(11) GDPR

Unclear Cookie Information
high

The cookie banner or cookie policy provides vague, incomplete, or unclear information about what cookies are used and why.

Art. 12, 13 GDPR

Cannot Withdraw Cookie Consent
critical

No accessible mechanism exists for users to withdraw previously given cookie consent.

Art. 7(3) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Accor in FR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

3 August 2022

Authority

Commission Nationale de l'Informatique et des Libertés

Fine Amount

€600,000

GDPRhub ID

gdprhub-5193

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Accor - France (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: