Administrative fine in the amount of 250 000 euros applied by the French Data Protection Authority to INFOGREFFE for the infringement of Article 5.1.e and Article 32 of the GDPR
The National Center for Personal Data Protection (NCPDP), for information and application purposes, communicates about the fine in the amount of 250 000 euros applied by the French Data Protection Authority (CNIL) to INFOGREFFE for the infringement of Article 5.1.e and Article 32 of the GDPR
Following a complaint, CNIL, carried out an online investigation of the infogreffe.fr website, which allows users to consult legal information on companies and order documents certified by the commercial court registries. The investigations focused in particular on the data retention periods defined and the security measures implemented by the economic interest group INFOGREFFE, which provides the legal information publishing service on companies via the website.
Following the investigation was found:
· Failure to comply with the obligation to keep data for a period of time proportionate to the purpose of the processing (Article 5.1.e of the GDPR);
· Failure to comply with the obligation to ensure the security of personal data (Article 32 of the GDPR);
On the basis of these findings, CNIL issued a fine of 250 000 euros on INFOGREFFE, and decided to make it public. This decision was taken in cooperation with the other European authorities concerned, as user accounts were created from all EU Member States.
The NCPDP, as national supervisory authority for personal data processing, emphasizes the responsibility of personal data controllers to comply with the provisions of legal framework on personal data protection and to ensure that personal data processing operations are in accordance with the legislation in force.