Enforcement · French Data Protection Authority (CNIL) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
ACTIVE ASSURANCES (car insurer): Insufficient technical and organisational measures to ensure information security
How it connects
Related across sources
Guidance EDPB Annual Report 2023 Guidance Guidelines 01/2022 on data subject rights - Right of access Guidance EDPB Annual Report 2021 Literature GDPR - General Data Protection Regulation on Sites Requiring Accessibility Guidance Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Case Law SG Nürnberg - S 5 SF 65/24 DS
Full text
Large amount of customer accounts, clients' documents (including copies of driver's licences, vehicle registration, bank statements and documents to determine whether a person had been the subject of a licence withdrawal) and data were easily accesible online. The CNIL, between others, critizised the password management (unauthorized access was possible without any authentication).
Industry: Finance, Insurance and Consulting
Original document at the source www.legifrance.gouv.fr