Enforcement · French Data Protection Authority (CNIL) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Spartoo: Non-compliance with general data processing principles
How it connects
Related across sources
Case Law VB v Natsionalna agentsia za prihodite Guidance Guidelines 04/2022 on the calculation of administrative fines under the GDPR Guidance Guidelines 9/2022 on personal data breach notification under GDPR Guidance Guidelines 07/2022 on certification as a tool for transfers News Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures News Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations
Full text
A fine of EUR 250000 was imposed on the online retailer Spartoo. The reason for this was that the company, which has its headquarters in France but supplies a large number of European countries, fully recorded all telephone hotline conversations (including personal data such as address and bank details of orders) and in addition stored bank details partially unencrypted. Among other things, this represents a violation of the principle of data minimization. Furthermore, the supervisory authority also found a violation of the information obligations according to Art. 13 GDPR, as the company's data protection information was partially incorrect.
Industry: Industry and Commerce
Original document at the source www.cnil.fr