Skip to content
Enforcement · CNIL ·SAN-2025-014 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

CNIL fines data processor €1,000,000 for unlawful retention, purpose conflict, and no ROPA

Original title: CNIL (France) - SAN-2025-014

€1,000,000 Fine
France
Summary

The data protection authority (DPA) has imposed a fine of 1 million euros on a data processor for failing to delete user personal data, processing that data for purposes that conflict with contractual agreements, and failing to maintain a record of processing activities. The data protection authority (DPA) has imposed a fine of €1,000,000 on a data processor for failing to delete user personal data, processing that data for purposes that conflict with contractual agreements, and failing to maintain a record of processing activities. Finally, the DPA found that...

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Data Protection Authority has imposed a fine of 1 million euros on a data processor for failing to delete user personal data, processing that data for purposes that conflict with contractual agreements, and failing to maintain a register of processing activities. The Data Protection Authority has imposed a fine of €1,000,000 on a data processor for failing to delete user personal data, processing that data for purposes that conflict with contractual agreements, and failing to maintain a register of processing activities. In summary (in English): Finally, the Data Protection Authority found that the data processor violated Article 30 of the GDPR because it did not maintain a register of processing activities and because it did not provide the name and contact details of the data protection officer of the controller. Finally, the Data Protection Authority found that the data processor violated Article 30 of the GDPR because it did not maintain a register of processing activities and because it did not provide the name and contact details of the data protection officer of the controller.

§

Therefore, the Data Protection Authority... --- *This content has been automatically translated using machine translation. The original version is available in the source language.* --- *This content was automatically translated using machine translation. The original version is available in the source language.*

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… CJEU ·Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data
C-46/23 Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság In a preliminary ruling requested by the Budapest High Court, the Court of Justice interpreted whether Article 58(2)(d) and (g) of the GDPR permits a national supervisory… CJEU ·Fifth Chamber Mar 14, 2024 Right to be Forgotten Personal Data Right to Restriction
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision