The sanctions issued by the CNIL

02 January 2025


The sanctions issued by the CNIL’s restricted committee since the entering into force of the GDPR.

 

Sanctions issued

Sanctions issued in 2025

Date Type of organization Main breaches/Theme subject Adopted decision
09/01/2025 COMPANY CARRYING OUT INSULATION, ENERGY RENOVATION AND HEATING WORK (simplified procedure)

Obligation to process data lawfully
(commercial prospecting)

Data minimisation

Obligation to process accurate data

Fine of €15,000 and injunction

16/01/2025 DISTANCE LEARNING APPRENTICE TRAINING CENTRE (simplified procedure)

Data minimisation (CCTV, telephone recordings)

Data retention period

Failure to respect the right to object

Information of individuals (telephone recordings, exercise of rights, CCTV)

Fine of €10,000
23/01/2025 ROAD HAULAGE COMPANY (simplified procedure)

Data minimisation (geolocation)

Data retention period (geolocation)

Information of individuals (geolocation)

Obligation to carry out a Privacy Impact Assessment

Fine of €8000

30/01/2025 ENERGY BROKERAGE COMPANY (simplified procedure) No response to injunction Liquidation of the penalty payment of €4,000
27/03/2025 BUSINESS AND MANAGEMENT CONSULTANCY COMPANY (simplified procedure)

Obligation to process data lawfully (CCTV)

Data minimisation (CCTV)

Information of individuals

Fine of €6000
03/04/2025 COMPANY SPECIALISING IN THE SUPERMARKET SECTOR (simplified procedure)

Failure to cooperate with the CNIL

Fine of €5,000 and injunction
03/04/2025 WORKS BROKERAGE COMPANY, BUILDING AND PUBLIC WORKS CONSULTANCY, PURCHASE AND RESALE OF EQUIPMENT, PROPERTY TRANSACTIONS AND PROJECT MANAGEMENT (simplified procedure)

Information of individuals (exercise of rights)

Failure to cooperate with the CNIL

Fine of €10,000 and injunction
10/04/2025 COMPANY SPECIALISING IN THE RETAIL SALE OF SPORTS GOODS IN SPECIALISED SHOPS (simplified procedure)

Data minimisation (CCTV)

Data retention period (CCTV)

Information of individuals (CCTV)

Register of processing activities

Lack of data security

Fine of €20,000
10/04/2025 COMPANY OPERATING A CATERING BUSINESS (simplified procedure)

Data minimisation (CCTV)

Information of individuals (CCTV)

Register of processing activities

Obligation to carry out a Privacy

Impact Assessment

Fine of €6,000
30/04/2025 COMPANY PUBLISHING A DATING WEBSITE AIMED AT PEOPLE WITH SIMILAR POLITICAL CONVICTIONS (simplified procedure

Data retention period

Consent of individuals (sensitive data)

Information of individuals

Framework for relations between the controller and the processor

Lack of data security

Obligation to notify a data breach to the supervisory authority

Obligation to notify the data subject of a data breach

Fine of €20,000
15/05/2025 COMPANY OFFERING PRIVATE SECURITY SERVICES  (simplified procedure) Non-compliance (injunction procedure) Liquidation of the penalty payment of €4,000
15/05/2025 COMPANY WITH A MARKETING AND WEBSITE DESIGN BUSINESS

Consent of individuals (commercial prospecting - article L. 34-5 CPCE)

Proof of consent (art 7 GDPR)

Lack of legal basis (art 6-1 GDPR)

Fine of €900,000 and injunction
15/05/2025 COMPANY CARRYING OUT ELECTRONIC COMMERCIAL CANVASSING ON BEHALF OF ADVERTISERS, INCLUDING DATA BROKERAGE ACTIVITIES

Consent of individuals (commercial prospecting - article L. 34-5 CPCE)

Withdrawal of consent

Lack of legal basis

Data retention period

Fine of €80,000
05/06/2025 COMPANY ENGAGED IN THE MANUFACTURE AND SALE OF PHARMACEUTICAL PRODUCTS FOR THE FOOD SECTOR (simplified procedure)

Data minimisation (CCTV)

Fine of €5,000
05/06/2025 COMPANY CARRYING OUT FOR-PROFIT HOSPITAL ACTIVITIES IN THE FIELD OF MEDICINE, SURGERY AND OBSTETRICS (simplified procedure)

Limitation of purpose (CCTV)

Data minimisation

Information of individuals

Obligation to carry out a Privacy

Impact Assessment

Fine of €5,000
05/06/2025 COMPANY WHOSE MAIN ACTIVITY IS PUBLISHING (simplified procedure) Failure to cooperate with the CNIL Fine of €10,000 and injonction
18/06/2025 COMPANY ENGAGED IN DISTANCE SELLING FROM A GENERAL CATALOGUE (simplified procedure) Consent of individuals (cookies) Fine of €3,000
03/07/2025 COMPANY ENGAGED IN THE DISTANCE SELLING OF FURNITURE, HOME DECORATION AND HOUSEHOLD EQUIPMENT (simplified procedure)

Data retention period

Information of individuals

Information and consent (cookies)

Consent of individuals (commercial prospecting - article L. 34-5 CPCE)

Fine of €600,000
03/07/2025 DOCTOR (simplified procedure) Failure to cooperate with the CNIL Fine of €3,000 and injunction
17/07/2025 LAWYER (simplified procedure)

Failure to respect the right of access

Failure to cooperate with the CNIL

Fine of €3,000 and injunction
25/08/2025 ASSOCIATION FOR THE DEFENCE OF FUNDAMENTAL RIGHTS (simplified procedure)

Failure to respect the right of erasure

Failure to cooperate with the CNIL

Fine of €10,000 and injunction
01/09/2025 COMPANY DEVELOPING SEVERAL ONLINE SERVICES

Information and consent (cookies)

Consent of individuals (commercial prospecting - article L. 34-5 CPCE)

Fine of €325 million and injunction
01/09/2025 ONLINE RETAILER OF CLOTHING, SHOES AND ACCESSORIES Information and consent (cookies) Fine of €150 million
03/09/2025 COMPANY ENGAGED IN THE DEVELOPMENT OF RESIDENTIAL PROPERTIES (simplified procedure)  Failure to respect the right of access Fine of €20,000
04/09/2025 COMPANY DEVELOPING AND MARKETING RECRUITMENT SUPPORT SOFTWARE (simplified procedure)

Framework for relations between the controller and the processor

Register of processing activities

Lack of data security

Obligation to notify a data breach

Fine of €7,000
04/09/2025 COMPANY COLLECTING PROSPECT DATA FROM SEVERAL SOURCES, INCLUDING ONLINE CONTEST ENTRY FORMS (simplified procedure)

Data retention period

Lack of legal basis

Information of individuals

Consent of individuals (commercial prospecting - article L. 34-5 CPCE)

Register of processing activities

Fine of €17,000
04/09/2025 COMPANY ENGAGED IN LARGE-SCALE DISTRIBUTION

Obligation to process data lawfully (CCTV)

Data minimisation (CCTV)

Information of individuals (CCTV)

Obligation to carry out a Privacy Impact Assessment

Fine of €75,000 and injunction
11/09/2025 COMPANY ENGAGED IN BANKING AND INSURANCE ACTIVITIES (simplified procedure)

Information of individuals (exercice of rights)

Failure to respect the right of access

Fine of €10,000
11/09/2025 SPECIALISED CATALOGUE MAIL-ORDER COMPANY (simplified procedure) Failure to cooperate with the CNIL Fine of €5,000
11/09/2025 ASSOCIATION MANAGING A SECONDARY SCHOOL AND BOARDING SCHOOL FOR YOUNG PEOPLE WHO HAVE DROPPED OUT OF SCHOOL (simplified procedure)

Data minimisation (CCTV)

Data retention period

Lack of data security

Fine of €7,000 and injunction
11/09/2025 MUNICIPALITY (simplified procedure)

Data retention period (special data category)

Register of processing activities

Fine of €10,000 and call to order
11/09/2025 GENERAL PRACTITIONER (simplified procedure) Failure to cooperate with the CNIL Fine of €3,000 and call to order
18/09/2025 COMPANY OPERATING A DEPARTMENT STORE

Obligation to process data lawfully and principle of responsability (CCTV)

Data minimisation (CCTV)

Obligation to notify a data breach

Obligation to involve the data protection officer in matters relating to data protection

Fine of €100,000
02/10/2025 UNIVERSITY (simplified procedure) Limitation of purpose Fine of €15,000
09/10/2025 COMPANY ENGAGED IN DISTANCE SELLING THROUGH A GENERAL CATALOGUE (simplified procedure)

Consent of individuals (cookies)

Information of individuals (cookies)

Fine of €4,000
16/10/2025 SUPERMARKET (simplified procedure)

Obligation to process data lawfully (CCTV)

Data minimisation (CCTV)

Information of individuals

Fine of €20,000 and injunction
16/10/2025 COMPANY ENGAGED IN DISTANCE SELLING THROUGH A SPECIALISED CATALOGUE Consent of individuals (cookies) Fine of €3,000
16/10/2025 COMPANY ENGAGED IN THE PUBLICATION OF MAGAZINES AND PERIODICALS (simplified procedure)

Consent of individuals (cookies)

Information of individuals (cookies)

Fine of €4,000 and injunction
16/10/2025 CALL CENTRE COMPANY

Data minimisation

Data retention period

Lack of data security

Fine of €250,000
16/10/2025 COMPANY ENGAGED IN THE MANAGEMENT OF SPORTS AND LEISURE CENTRES (simplified procedure)

Lack of data security

Information of individuals

Consent of individuals (cookies)

Fine of €20,000 and injunction
04/11/2025 LOCAL AUTHORITY (simplified procedure) Information of individuals (cookies) Fine of €4,000
04/11/2025 COMPANY PROVIDING CONSULTING AND MANAGEMENT SUPPORT SERVICES TO UNDERWATER SPORTS CLUBS (simplified procedure)

Consent of individuals (cookies)

Information of individuals (cookies)

Fine of €4,000
05/11/2025 LAW FIRM (simplified procedure)

Failure to respect the right of erasure

Failure to cooperate with the CNIL

Fine of €5,000
13/11/2025 COMPANY ENGAGED IN THE RETAIL SALE OF FOOTWEAR (simplified procedure)

Consent of individuals (cookies)

Information of individuals (cookies)

Fine of €5,000
13/11/2025 ECONOMIC INTEREST GROUP ENGAGED IN THE ORGANISATION, DEVELOPMENT AND PROMOTION OF SHOPPING CENTRES (simplified procedure)

Obligation to process data lawfully (CCTV)

Data minimisation (CCTV)

Information of individuals

Framework for relations between the controller and the processor

Register of processing activities

Lack of data security

Obligation to carry out a Privacy Impact Assessment

Fine of €20,000
13/11/2025 COMPANY OPERATING A DISTRIBUTION BUSINESS WITH A FOCUS ON FOOD PRODUCTS (simplified procedure)

Obligation to process data lawfully (CCTV)

Data minimisation (CCTV)

Data retention period

Framework for relations between the controller and the processor

Register of processing activities

Lack of data security

Obligation to carry out a Privacy Impact Assessment

Fine of €20,000
13/11/2025 COMPANY ENGAGED IN THE BUSINESS OF ‘INTERNET PORTALS’ PROVIDING ACCESS TO LEGAL AND FINANCIAL INFORMATION ABOUT COMPANIES (simplified procedure)

Consent of individuals (cookies)

Information of individuals (cookies)

Fine of €5,000
20/11/2025 COMPANY ENGAGED IN HOLDING COMPANY ACTIVITIES AND DEVELOPING HUMAN RESOURCES SOLUTIONS (simplified procedure)

Failure to respond to a request to exercise rights

Failure to cooperate with the CNIL

Fine of €10,000
20/11/2025 COMPANY ENGAGED IN THE PUBLICATION OF MAGAZINES AND PERIODICALS AND ADVERTISING MANAGEMENT

Consent of individuals (cookies)

Information of individuals (cookies)

Fine of €750,000
27/11/2025 COMPANY ISSUING AND MARKETING DEFERRED DEBIT PAYMENT CARDS Consent of individuals (cookies) Fine of €1,500,000
27/11/2025 DISTANCE SELLING COMPANY

Consent of individuals (cookies)

Information of individuals (cookies)

Fine of €500,000 and injunction
27/11/2025 COMPANY ENGAGED IN THE CREATION OF WEBSITES AND MOBILE APPLICATIONS FOR COMPANIES IN VARIOUS SECTORS (simplified procedure)

Lack of data security

Obligation to carry out a Privacy Impact Assessment

Fine of €17,000
27/11/2025 CANDIDATE IN THE 2024 EUROPEAN PARLIAMENT ELECTIONS (simplified procedure)

Obligation to be able to justify the lawfulness of the processing (political prospecting)

Failure to respect the right of erasure

Fine of €8,000 and injunction
27/11/2025 COMPANY PROVIDING ADVICE AND SUPPORT IN THE FIELD OF HEALTHCARE

Obligation to carry out a Privacy Impact Assessment

Register of processing activities

Injunction with penalty
04/12/2025 POLITICAL PARTY (simplified procedure)

Data retention period

Failure to respect the right of access

Lack of data security

Fine of €5,000 and injunction
04/12/2025 COMPANY ENGAGED IN THE HOTEL AND ACCOMMODATION BUSINESS (simplified procedure) Failure to cooperate with the CNIL Fine of €10,000
08/12/2025 COMPANY ENGAGED IN RETAIL TRADE (simplified procedure)

Obligation to process data lawfully

Data minimisation (CCTV)

Data retention period

Information of individuals

Framework for relations between the controller and the processor

Lack of data security

Obligation to carry out a Privacy Impact Assessment

Fine of €20,000
11/12/2025 CANDIDATE IN THE 2024 GENERAL ELECTIONS (simplified procedure)

Misuse of purposes

Information of individuals

Failure to respect the right of opposition

Framework for relations between the controller and the processor

Fine of €5,500
11/12/2025 CANDIDATE IN THE 2024 GENERAL ELECTIONS (simplified procedure) Information of individuals Fine of €2,500
11/12/2025 CANDIDATE IN THE 2024 GENERAL ELECTIONS (simplified procedure)

Obligation to be able to justify the lawfulness of the processing (political prospecting)

Information of individuals

Failure to respect the right of opposition

Lack of data security

Fine of €5,000
11/12/2025 CANDIDATE IN THE 2024 GENERAL ELECTIONS (simplified procedure)

Obligation to be able to justify the lawfulness of the processing (political prospecting)

Information of individuals

Fine of €2,500
11/12/2025 COMPANY ENGAGED IN THE PERFORMING ARTS (simplified procedure)

Consent of individuals (cookies)

Information of individuals (cookies)

Fine of €5,000 and injunction
11/12/2025 CONSTRUCTION BROKERAGE, BUILDING AND PUBLIC WORKS CONSULTING, PURCHASE AND RESALE OF EQUIPMENT, REAL ESTATE TRANSACTIONS AND PROJECT MANAGEMENT (simplified procedure) Non-compliance (injunction procedure) Liquidation of the penalty payment of €3,000
11/12/2025 COMPANY ENGAGED IN THE DEVELOPMENT OF MARKETING TOOLS

Unjustified retention of data by a processor

Processing of data by a processor not authorised by the controller

Register of processing activities

Fine of €1,000,000
11/12/2025 COMPANY ENGAGED IN THE SUPPORT, GUIDANCE AND EDUCATION OF VICTIMS OF INCEST (simplified procedure)

Consent of individuals (commercial prospecting - article L. 34-5 CPCE)

Information of individuals

Failure to respect the right of access

Fine of €20,000 and injunction
11/12/2025 PUBLIC INSTITUTION ENGAGED IN THE MANAGEMENT OF RENTAL PROPERTIES (simplified procedure)

Limitation of purpose

Data minimisation

Information of individuals

Failure to respect the right of opposition

Lack of data security

Fine of €20,000 and injunction
15/12/2025 COMPANY ENGAGED IN SOFTWARE PUBLISHING, IN PARTICULAR PAYROLL SOFTWARE (simplified procedure) Lack of data security Fine of €15,000
15/12/2025 COMPANY ENGAGED IN THE SPECIALISED GENERAL FOOD TRADE (simplified procedure)

Obligation to process data lawfully

Data minimisation (CCTV)

Data retention period

Fine of €8,000 and injunction
18/12/2025 COMPANY ENGAGED IN THE COLLECTION OF DATA FROM COMPETITIONS, COMMERCIAL PROSPECTING AND THE TRANSMISSION OF DATA TO ITS CUSTOMERS (simplified procedure)

Consent of individuals (commercial prospecting - article L. 34-5 CPCE)

Data retention period

Lack of data security

Fine of €20,000
18/12/2025 COMPANY ENGAGED IN COMPUTER PROGRAMMING (RENTAL AND CO-OWNERSHIP MANAGEMENT) (simplified procedure)

Lack of legal basis (commercial prospecting)

Information of individuals (commercial prospecting)

Lack of data security

Fine of €15,000 and injunction
18/12/2025 COMPANY ENGAGED IN THE BUSINESS OF CONDUCTING ELECTRONIC COMMERCIAL PROSPECTING ON BEHALF OF ADVERTISING AGENCIES (simplified procedure)

Failure to respect the right of access

Failure to respect the right of opposition

Fine of €6,000
18/12/2025 COMPANY ENGAGED IN LANDSCAPING, GARDEN AND SPORTS FIELD INSTALLATION (simplified procedure)

Failure to respect the right of access

Failure to cooperate with the CNIL

Fine of €7,000
18/12/2025 COMPANY ENGAGED IN TRAVEL AGENCY ACTIVITIES (simplified procedure)

Information of individuals (cookies)

Consent of individuals (cookies)

Fine of €2,000 and injunction
22/12/2025 COMPANY ENGAGED IN IT SYSTEMS AND SOFTWARE CONSULTING Lack of data security Fine of €1,700,000
29/12/2025 COMPANY ENGAGED IN NEWSPAPER PUBLISHING (simplified procedure) Consent of individuals (cookies) Fine of €5,000
29/12/2025 COMPANY ENGAGED IN NEWSPAPER PUBLISHING (simplified procedure) Consent of individuals (cookies) Fine of €7,000 and injunction
29/12/2025 COMPANY ENGAGED IN LARGE-SCALE RETAIL TRADE (simplified procedure)

Data minimisation (CCTV)

Failure to cooperate with the CNIL

Fine of €6,000 and injunction
29/12/2025 COMPANY PUBLISHING A MOBILE APPLICATION

Lack of data security

Consent of individuals (sensitive data)

Consent of individuals (cookies)

Fine of €270,000
30/12/2025 COMPANY ENGAGED IN THE ACQUISITION AND MANAGEMENT OF HOTELS/HOTEL RESIDENCES (simplified procedure)

Obligation to process data lawfully (CCTV)

Information of individuals (CCTV)

Fine of €5,000
30/12/2025 COMPANY ENGAGED IN AIRPORT FREIGHT ACTIVITIES (simplified procedure)

Obligation to process data lawfully (CCTV)

Data retention period

Lack of data security

Fine of €10,000
30/12/2025 DENTAL SURGEON (simplified procedure) Failure to cooperate with the CNIL Call to order
30/12/2025 TERTIARY SECTOR COMPANY

Obligation to process data lawfully

Information of individuals

Obligation to carry out a Privacy Impact Assessment

Lack of data security

Consent of individuals (cookies)

Fine of €3,500,000
31/12/2025 UNIVERSITY (simplified procedure) Limitation of purpose Fine of €20,000

Sanctions issued in 2024


Sanctions issued in 2023


Sanctions issued in 2022


Sanctions issued in 2021


Sanctions issued in 2020


Sanctions issued in 2019


Sanctions issued in 2018