NS Cards France – €105,000 Fine (France, 2023)

€105,000Commission Nationale de l'Informatique et des Libertés29 December 2023France
final
ePrivacy
Fine

NS Cards France was fined for collecting personal information without properly deleting old data. This matters because it highlights the importance of managing user data responsibly and keeping privacy policies up-to-date.

What happened

NS Cards France collected personal data from users and failed to delete inactive accounts for over ten years.

Who was affected

Users who created accounts with NS Cards France and had their personal information stored without proper management.

What the authority found

The CNIL found that NS Cards France violated GDPR rules by not deleting outdated personal data and not providing clear privacy information.

Why this matters

This case emphasizes the need for companies to regularly review their data retention practices. Businesses should ensure they comply with data protection rules to avoid hefty fines.

GDPR Articles Cited

AI-verified

Art. 12(GDPR)
Art. 13(GDPR)
Art. 32(GDPR)
Art. 5(1)(e) GDPR
View original scraped data
Art. 5(1)(e) GDPR
Art. 12(GDPR)
Art. 13(GDPR)
Art. 32(GDPR)
Art. 82 Loi Informatique et Libertés

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 82 Loi Informatique et Libertés
Source verified 3 April 2026
articles corrected
national law identified
Full Legal Summary
Detailed

In the context of its investigations, the French DPA (CNIL) undertook online and an on-the-spot checks of the controller’s website and premises. The controller, NS Cards France, is an electronic money distributor that facilitates online payments. The CNIL found that when creating a user account on the controller's website, surname, first name, date of birth, postal address, email address, telephone number, and, if applicable, bank details were collected, as well as personal documents, such as proof of identity and residence. While the controller specified a retention period of ten years for this data from the last transaction carried out on the account, in fact, no deletion had been carried out in the databases since the beginning of the controller's activity in 2005. An estimated 70,049 accounts had been inactive for more than ten years. Additionally, 51,735 accounts were kept for no purpose, as they were "unconfirmed", i.e. the email address had not been confirmed when the account was created. Furthermore, the information provided by the company on the website and its mobile application via the privacy policy was incomplete, not up-to-date and only in English. The controller also allowed users to create account passwords of six characters, composed of only three categories of characters (uppercase, lowercase and numbers), and the CNIL found that no access restrictions in the event of authentication failure were implemented. 49,214 passwords were also stored in clear text in the company's database and associated with their email address and identifier. Additionally, the rapporteur noted that thirteen cookies were deposited before any action, including consent, could be taken by the user upon arrival on the home page of the website. The Google reCaptcha module, to block robots on the registration and connection page to the website and mobile application, was also used without asking for user consent. On 10 May 2023, under Article 56 GDPR, the CNIL informed all E

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for NS Cards France in FR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

29 December 2023

Authority

Commission Nationale de l'Informatique et des Libertés

Fine Amount

€105,000

GDPRhub ID

gdprhub-7510

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. NS Cards France - France (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: