# ACTIVE ASSURANCES (car insurer): Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: French Data Protection Authority (CNIL)
- Date: 2019-07-25
- Original: https://www.enforcementtracker.com/ETid-64
- Canonical: https://overview.legal/posts/46179
- Topics: Insurance, Data Breaches, Integrity and Confidentiality Principle, Access Controls, Security, Supervisory Authorities, Identification

## Summary

Large amount of customer accounts, clients' documents (including copies of driver's licences, vehicle registration, bank statements and documents to determine whether a person had been the subject of a licence withdrawal) and data were easily accesible online. The CNIL, between others, critizised the password management (unauthorized access was possible without any authentication).

## Full text

Large amount of customer accounts, clients' documents (including copies of driver's licences, vehicle registration, bank statements and documents to determine whether a person had been the subject of a licence withdrawal) and data were easily accesible online. The CNIL, between others, critizised the password management (unauthorized access was possible without any authentication).

GDPR Articles: Art. 32 GDPR
Industry: Finance, Insurance and Consulting

---
Generated by overview.legal · https://overview.legal/posts/46179 · 2026-08-22
