Skip to content
Enforcement · French Data Protection Authority (CNIL) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

ACCOR SA: Insufficient fulfilment of data subjects rights

The French DPA (CNIL) has imposed a fine of EUR 600,000 on ACCOR SA.

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The French DPA (CNIL) has imposed a fine of EUR 600,000 on ACCOR SA. Both CNIL and other European DPAS had received complaints against ACCOR from several individuals. In the course of its investigation, CNIL found that hotel guests who made a booking directly with the hotel or on one of the hotel group's websites automatically became recipients of an advertising newsletter as the box for consent to receive the newsletter was pre-ticked. In addition, the CNIL found that due to technical problems, many individuals were unable to opt-out of receiving the promotional emails. In this context, CNIL found that ACCOR had not sufficiently informed data subjects about the processing of their personal data in the context of promotional messages and thus violated Art. 12 GDPR and Art. 13 GDPR. Further, ACCOR had failed to respond to data subjects' requests for access to personal data in a timely manner, and thus the CNIL found a violation of Art. 12 GDPR and Art. 15 GDPR.

§

The company had also failed to comply with the data subjects' right to object due to the technical problems. The CNIL therefore found a violation of Art. 12 GDPR and Art. 21 GDPR. Finally, the CNIL found a violation of Art. 32 GDPR because ACCOR allowed the use of passwords that were not sufficiently secure. In imposing the fine, CNIL considered aggravatingly that the violations affected several fundamental principles of personal data protection and constituted a fundamental infringement of the rights of the data subjects, as well as the number of data subjects involved. GDPR Articles: Art. 12 GDPR, Art. 13 GDPR, Art. 15 GDPR, Art. 21 GDPR, Art. 32 GDPR, L. 34-5 CPCE Industry: Accomodation and Hospitality

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-154/21 RW v Österreichische Post AG The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article… First Chamber Jan 12, 2023 Right of Access Personal Data Recipient
C-741/21 GP v juris GmbH In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject… Third Chamber Apr 11, 2024 Liability Personal Data Integrity and Confidentiality Principle
HvJ EU 9 januari 2025, C‑394/23 (Mousse) Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20… HvJ EU 9 januari 2025, C‑394/23 (Mousse). Jan 9, 2025 IP Address Retention Period Identification
C-203/22 CK v Magistrat der Stadt Wien In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien… First Chamber Feb 27, 2025 Profiling Automated Decision-Making Marketing