Doctissimo – €380,000 Fine (France, 2023)
Doctissimo was fined €380,000 for using cookies on its website without getting consent from users. The site collected personal data through quizzes and other features without proper transparency. This ruling is important because it reinforces the need for websites to obtain user consent before tracking their data.
What happened
Doctissimo was fined €380,000 for placing cookies on its website without user consent.
Who was affected
Website visitors who interacted with Doctissimo's online content and had their data tracked.
What the authority found
The authority found that Doctissimo violated data protection rules by using cookies without obtaining proper consent.
Why this matters
This case serves as a reminder for website operators to ensure they have clear consent mechanisms in place for tracking user data.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Doctissimo (controller) operates a website that offers articles, tests, quizzes and discussion forums about health and well-being. On 26 June 2020, Privacy International filed a complaint with the French DPA against the controller. This complaint concerned all the processing operations carried out by the controller on its website and, in particular, the use of cookies without consent, the legal basis for the processing related to online health tests, the obligation of transparency and data security. The DPA carried out several investigations, both online and at the controller's office. Since the controller operated cross-border processing operations but the controller's principal place of business was in France, in accordance with Article 56 GDPR, the French DPA informed other authorities of its competence as lead supervisory authority. No relevant and reasoned objection was raised by any authority. The investigation service noted various elements. In particular: (1) As regards the quizzes data, the controller outsourced this processing and stored the data, as well as the email address of the users, for 24 months. The controller explained that these data were kept for three purposes: communicating the result to the user, enabling the user to share the result and producing statistics. During the procedure, the controller changed the retention period to 3 months and asked their processor to anonymise the data. (2) On the retention period of accounts created by users of the website, the controller explained that data is anonymised when a user is inactive for three years. However, the investigation showed that it was still possible to individualise users indirectly. (3) Regarding consent to process special categories of personal data, the controller did not obtain specific consent to process health data. The controller explained that there was confusion about the definition of sensitive data. (4) There was no contract under Article 26 GDPR although the controller con
Violations (2)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Third-party tracking cookies or scripts are loaded without obtaining prior user consent.
Art. 13, 14 GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Doctissimo in FR
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
11 May 2023
Authority
Commission Nationale de l'Informatique et des Libertés
Fine Amount
€380,000
GDPRhub ID
gdprhub-5936About this data
Cite as: Cookie Fines. Doctissimo - France (2023). Retrieved from cookiefines.eu
Last updated: