Skip to content
Enforcement · French Data Protection Authority (CNIL) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Carrefour France: Non-compliance with general data processing principles

The French DPA (CNIL) fined Carrefour France EUR 2,250,000 for several violations of data protection regulations, including the GPDR.

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The French DPA (CNIL) fined Carrefour France EUR 2,250,000 for several violations of data protection regulations, including the GPDR. During its investigation, the CNIL found that the information on personal data provided to users of the carrefour.fr websites and those wishing to join the loyalty program was neither easily accessible nor easily comprehensible. The CNIL also found that the information regarding the transfer of data to countries outside the EU and regarding the duration of data storage was incomplete. The CNIL also notes that the company did not comply with the storage time limits. Furthermore, the data of more than twenty-eight million customers who were inactive for five to ten years were stored for the purposes of the loyalty program. This was also the case for 750,000 users of the carrefour.fr site, who were inactive for five to ten years. The CNIL states that the company required proof of identity for almost every user request to exercise a right.

§

However, this automatic requirement was not justified, as in most cases there was no doubt regarding the identity of the data subjects. Furthermore, the company did not respond to several requests from individuals who wanted to access their personal data. Also, in numerous cases, the company did not carry out the erasure of data requested by individuals. Finally, the company has not responded to several requests from persons who did not agree to receive advertising by SMS or e-mail. GDPR Articles: Art. 5 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 15 GDPR, Art. 17 GDPR, Art. 21 GDPR, Art. 32 GDPR, Art. 33 GDPR Industry: Industry and Commerce

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-154/21 RW v Österreichische Post AG The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article… CJEU ·First Chamber Jan 12, 2023 Right of Access Personal Data Recipient
C-507/17 Google LLC v CNIL C-507/17 (Google Territorial Scope) CJEU Sep 24, 2019 Territorial scope (GDPR) Right to be Forgotten Direct Marketing
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities IP Address Supervision
CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69) Jun 29, 2010 Personal Data Legitimate Interest Right to Restriction
2025 EDPB Annual Report 2024 De EDPB heeft het Jaarraport van 2024 gepubliceerd. Met ook een handzame samenvatting voor degene die geen tijd hebben. Er wordt ook een lijst met zaken van enkele DPAs… Apr 23, 2025 Direct Marketing Legitimate Interest Privacy by Design
SAN 3154/2026 National court annuls DPA sanction against KFC Spain over website privacy information In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website.… Jul 16, 2026 Supervisory Authorities Personal Data Controllers