The sanctions issued by the CNIL
02 January 2025
The sanctions issued by the CNIL’s restricted committee since the entering into force of the GDPR.
| Date | Type of organization | Main breaches/Theme subject | Adopted decision |
|---|---|---|---|
| 09/01/2025 | COMPANY CARRYING OUT INSULATION, ENERGY RENOVATION AND HEATING WORK (simplified procedure) |
Obligation to process data lawfully Data minimisation Obligation to process accurate data |
Fine of €15,000 and injunction |
| 16/01/2025 | DISTANCE LEARNING APPRENTICE TRAINING CENTRE (simplified procedure) |
Data minimisation (CCTV, telephone recordings) Data retention period Failure to respect the right to object Information of individuals (telephone recordings, exercise of rights, CCTV) |
Fine of €10,000 |
| 23/01/2025 | ROAD HAULAGE COMPANY (simplified procedure) |
Data minimisation (geolocation) Data retention period (geolocation) Information of individuals (geolocation) Obligation to carry out a Privacy Impact Assessment |
Fine of €8000 |
| 30/01/2025 | ENERGY BROKERAGE COMPANY (simplified procedure) | No response to injunction | Liquidation of the penalty payment of €4,000 |
| 27/03/2025 | BUSINESS AND MANAGEMENT CONSULTANCY COMPANY (simplified procedure) |
Obligation to process data lawfully (CCTV) Data minimisation (CCTV) Information of individuals |
Fine of €6000 |
| 03/04/2025 | COMPANY SPECIALISING IN THE SUPERMARKET SECTOR (simplified procedure) |
Failure to cooperate with the CNIL |
Fine of €5,000 and injunction |
| 03/04/2025 | WORKS BROKERAGE COMPANY, BUILDING AND PUBLIC WORKS CONSULTANCY, PURCHASE AND RESALE OF EQUIPMENT, PROPERTY TRANSACTIONS AND PROJECT MANAGEMENT (simplified procedure) |
Information of individuals (exercise of rights) Failure to cooperate with the CNIL |
Fine of €10,000 and injunction |
| 10/04/2025 | COMPANY SPECIALISING IN THE RETAIL SALE OF SPORTS GOODS IN SPECIALISED SHOPS (simplified procedure) |
Data minimisation (CCTV) Data retention period (CCTV) Information of individuals (CCTV) Register of processing activities Lack of data security |
Fine of €20,000 |
| 10/04/2025 | COMPANY OPERATING A CATERING BUSINESS (simplified procedure) |
Data minimisation (CCTV) Information of individuals (CCTV) Register of processing activities Obligation to carry out a Privacy Impact Assessment |
Fine of €6,000 |
| 30/04/2025 | COMPANY PUBLISHING A DATING WEBSITE AIMED AT PEOPLE WITH SIMILAR POLITICAL CONVICTIONS (simplified procedure |
Data retention period Consent of individuals (sensitive data) Information of individuals Framework for relations between the controller and the processor Lack of data security Obligation to notify a data breach to the supervisory authority Obligation to notify the data subject of a data breach |
Fine of €20,000 |
| 15/05/2025 | COMPANY OFFERING PRIVATE SECURITY SERVICES (simplified procedure) | Non-compliance (injunction procedure) | Liquidation of the penalty payment of €4,000 |
| 15/05/2025 | COMPANY WITH A MARKETING AND WEBSITE DESIGN BUSINESS |
Consent of individuals (commercial prospecting - article L. 34-5 CPCE) Proof of consent (art 7 GDPR) Lack of legal basis (art 6-1 GDPR) |
Fine of €900,000 and injunction |
| 15/05/2025 | COMPANY CARRYING OUT ELECTRONIC COMMERCIAL CANVASSING ON BEHALF OF ADVERTISERS, INCLUDING DATA BROKERAGE ACTIVITIES |
Consent of individuals (commercial prospecting - article L. 34-5 CPCE) Withdrawal of consent Lack of legal basis Data retention period |
Fine of €80,000 |
| 05/06/2025 | COMPANY ENGAGED IN THE MANUFACTURE AND SALE OF PHARMACEUTICAL PRODUCTS FOR THE FOOD SECTOR (simplified procedure) |
Data minimisation (CCTV) |
Fine of €5,000 |
| 05/06/2025 | COMPANY CARRYING OUT FOR-PROFIT HOSPITAL ACTIVITIES IN THE FIELD OF MEDICINE, SURGERY AND OBSTETRICS (simplified procedure) |
Limitation of purpose (CCTV) Data minimisation Information of individuals Obligation to carry out a Privacy Impact Assessment |
Fine of €5,000 |
| 05/06/2025 | COMPANY WHOSE MAIN ACTIVITY IS PUBLISHING (simplified procedure) | Failure to cooperate with the CNIL | Fine of €10,000 and injonction |
| 18/06/2025 | COMPANY ENGAGED IN DISTANCE SELLING FROM A GENERAL CATALOGUE (simplified procedure) | Consent of individuals (cookies) | Fine of €3,000 |
| 03/07/2025 | COMPANY ENGAGED IN THE DISTANCE SELLING OF FURNITURE, HOME DECORATION AND HOUSEHOLD EQUIPMENT (simplified procedure) |
Data retention period Information of individuals Information and consent (cookies) Consent of individuals (commercial prospecting - article L. 34-5 CPCE) |
Fine of €600,000 |
| 03/07/2025 | DOCTOR (simplified procedure) | Failure to cooperate with the CNIL | Fine of €3,000 and injunction |
| 17/07/2025 | LAWYER (simplified procedure) |
Failure to respect the right of access Failure to cooperate with the CNIL |
Fine of €3,000 and injunction |
| 25/08/2025 | ASSOCIATION FOR THE DEFENCE OF FUNDAMENTAL RIGHTS (simplified procedure) |
Failure to respect the right of erasure Failure to cooperate with the CNIL |
Fine of €10,000 and injunction |
| 01/09/2025 | COMPANY DEVELOPING SEVERAL ONLINE SERVICES |
Information and consent (cookies) Consent of individuals (commercial prospecting - article L. 34-5 CPCE) |
Fine of €325 million and injunction |
| 01/09/2025 | ONLINE RETAILER OF CLOTHING, SHOES AND ACCESSORIES | Information and consent (cookies) | Fine of €150 million |
| 03/09/2025 | COMPANY ENGAGED IN THE DEVELOPMENT OF RESIDENTIAL PROPERTIES (simplified procedure) | Failure to respect the right of access | Fine of €20,000 |
| 04/09/2025 | COMPANY DEVELOPING AND MARKETING RECRUITMENT SUPPORT SOFTWARE (simplified procedure) |
Framework for relations between the controller and the processor Register of processing activities Lack of data security Obligation to notify a data breach |
Fine of €7,000 |
| 04/09/2025 | COMPANY COLLECTING PROSPECT DATA FROM SEVERAL SOURCES, INCLUDING ONLINE CONTEST ENTRY FORMS (simplified procedure) |
Data retention period Lack of legal basis Information of individuals Consent of individuals (commercial prospecting - article L. 34-5 CPCE) Register of processing activities |
Fine of €17,000 |
| 04/09/2025 | COMPANY ENGAGED IN LARGE-SCALE DISTRIBUTION |
Obligation to process data lawfully (CCTV) Data minimisation (CCTV) Information of individuals (CCTV) Obligation to carry out a Privacy Impact Assessment |
Fine of €75,000 and injunction |
| 11/09/2025 | COMPANY ENGAGED IN BANKING AND INSURANCE ACTIVITIES (simplified procedure) |
Information of individuals (exercice of rights) Failure to respect the right of access |
Fine of €10,000 |
| 11/09/2025 | SPECIALISED CATALOGUE MAIL-ORDER COMPANY (simplified procedure) | Failure to cooperate with the CNIL | Fine of €5,000 |
| 11/09/2025 | ASSOCIATION MANAGING A SECONDARY SCHOOL AND BOARDING SCHOOL FOR YOUNG PEOPLE WHO HAVE DROPPED OUT OF SCHOOL (simplified procedure) |
Data minimisation (CCTV) Data retention period Lack of data security |
Fine of €7,000 and injunction |
| 11/09/2025 | MUNICIPALITY (simplified procedure) |
Data retention period (special data category) Register of processing activities |
Fine of €10,000 and call to order |
| 11/09/2025 | GENERAL PRACTITIONER (simplified procedure) | Failure to cooperate with the CNIL | Fine of €3,000 and call to order |
| 18/09/2025 | COMPANY OPERATING A DEPARTMENT STORE |
Obligation to process data lawfully and principle of responsability (CCTV) Data minimisation (CCTV) Obligation to notify a data breach Obligation to involve the data protection officer in matters relating to data protection |
Fine of €100,000 |
| 02/10/2025 | UNIVERSITY (simplified procedure) | Limitation of purpose | Fine of €15,000 |
| 09/10/2025 | COMPANY ENGAGED IN DISTANCE SELLING THROUGH A GENERAL CATALOGUE (simplified procedure) |
Consent of individuals (cookies) Information of individuals (cookies) |
Fine of €4,000 |
| 16/10/2025 | SUPERMARKET (simplified procedure) |
Obligation to process data lawfully (CCTV) Data minimisation (CCTV) Information of individuals |
Fine of €20,000 and injunction |
| 16/10/2025 | COMPANY ENGAGED IN DISTANCE SELLING THROUGH A SPECIALISED CATALOGUE | Consent of individuals (cookies) | Fine of €3,000 |
| 16/10/2025 | COMPANY ENGAGED IN THE PUBLICATION OF MAGAZINES AND PERIODICALS (simplified procedure) |
Consent of individuals (cookies) Information of individuals (cookies) |
Fine of €4,000 and injunction |
| 16/10/2025 | CALL CENTRE COMPANY |
Data minimisation Data retention period Lack of data security |
Fine of €250,000 |
| 16/10/2025 | COMPANY ENGAGED IN THE MANAGEMENT OF SPORTS AND LEISURE CENTRES (simplified procedure) |
Lack of data security Information of individuals Consent of individuals (cookies) |
Fine of €20,000 and injunction |
| 04/11/2025 | LOCAL AUTHORITY (simplified procedure) | Information of individuals (cookies) | Fine of €4,000 |
| 04/11/2025 | COMPANY PROVIDING CONSULTING AND MANAGEMENT SUPPORT SERVICES TO UNDERWATER SPORTS CLUBS (simplified procedure) |
Consent of individuals (cookies) Information of individuals (cookies) |
Fine of €4,000 |
| 05/11/2025 | LAW FIRM (simplified procedure) |
Failure to respect the right of erasure Failure to cooperate with the CNIL |
Fine of €5,000 |
| 13/11/2025 | COMPANY ENGAGED IN THE RETAIL SALE OF FOOTWEAR (simplified procedure) |
Consent of individuals (cookies) Information of individuals (cookies) |
Fine of €5,000 |
| 13/11/2025 | ECONOMIC INTEREST GROUP ENGAGED IN THE ORGANISATION, DEVELOPMENT AND PROMOTION OF SHOPPING CENTRES (simplified procedure) |
Obligation to process data lawfully (CCTV) Data minimisation (CCTV) Information of individuals Framework for relations between the controller and the processor Register of processing activities Lack of data security Obligation to carry out a Privacy Impact Assessment |
Fine of €20,000 |
| 13/11/2025 | COMPANY OPERATING A DISTRIBUTION BUSINESS WITH A FOCUS ON FOOD PRODUCTS (simplified procedure) |
Obligation to process data lawfully (CCTV) Data minimisation (CCTV) Data retention period Framework for relations between the controller and the processor Register of processing activities Lack of data security Obligation to carry out a Privacy Impact Assessment |
Fine of €20,000 |
| 13/11/2025 | COMPANY ENGAGED IN THE BUSINESS OF ‘INTERNET PORTALS’ PROVIDING ACCESS TO LEGAL AND FINANCIAL INFORMATION ABOUT COMPANIES (simplified procedure) |
Consent of individuals (cookies) Information of individuals (cookies) |
Fine of €5,000 |
| 20/11/2025 | COMPANY ENGAGED IN HOLDING COMPANY ACTIVITIES AND DEVELOPING HUMAN RESOURCES SOLUTIONS (simplified procedure) |
Failure to respond to a request to exercise rights Failure to cooperate with the CNIL |
Fine of €10,000 |
| 20/11/2025 | COMPANY ENGAGED IN THE PUBLICATION OF MAGAZINES AND PERIODICALS AND ADVERTISING MANAGEMENT |
Consent of individuals (cookies) Information of individuals (cookies) |
Fine of €750,000 |
| 27/11/2025 | COMPANY ISSUING AND MARKETING DEFERRED DEBIT PAYMENT CARDS | Consent of individuals (cookies) | Fine of €1,500,000 |
| 27/11/2025 | DISTANCE SELLING COMPANY |
Consent of individuals (cookies) Information of individuals (cookies) |
Fine of €500,000 and injunction |
| 27/11/2025 | COMPANY ENGAGED IN THE CREATION OF WEBSITES AND MOBILE APPLICATIONS FOR COMPANIES IN VARIOUS SECTORS (simplified procedure) |
Lack of data security Obligation to carry out a Privacy Impact Assessment |
Fine of €17,000 |
| 27/11/2025 | CANDIDATE IN THE 2024 EUROPEAN PARLIAMENT ELECTIONS (simplified procedure) |
Obligation to be able to justify the lawfulness of the processing (political prospecting) Failure to respect the right of erasure |
Fine of €8,000 and injunction |
| 27/11/2025 | COMPANY PROVIDING ADVICE AND SUPPORT IN THE FIELD OF HEALTHCARE |
Obligation to carry out a Privacy Impact Assessment Register of processing activities |
Injunction with penalty |
| 04/12/2025 | POLITICAL PARTY (simplified procedure) |
Data retention period Failure to respect the right of access Lack of data security |
Fine of €5,000 and injunction |
| 04/12/2025 | COMPANY ENGAGED IN THE HOTEL AND ACCOMMODATION BUSINESS (simplified procedure) | Failure to cooperate with the CNIL | Fine of €10,000 |
| 08/12/2025 | COMPANY ENGAGED IN RETAIL TRADE (simplified procedure) |
Obligation to process data lawfully Data minimisation (CCTV) Data retention period Information of individuals Framework for relations between the controller and the processor Lack of data security Obligation to carry out a Privacy Impact Assessment |
Fine of €20,000 |
| 11/12/2025 | CANDIDATE IN THE 2024 GENERAL ELECTIONS (simplified procedure) |
Misuse of purposes Information of individuals Failure to respect the right of opposition Framework for relations between the controller and the processor |
Fine of €5,500 |
| 11/12/2025 | CANDIDATE IN THE 2024 GENERAL ELECTIONS (simplified procedure) | Information of individuals | Fine of €2,500 |
| 11/12/2025 | CANDIDATE IN THE 2024 GENERAL ELECTIONS (simplified procedure) |
Obligation to be able to justify the lawfulness of the processing (political prospecting) Information of individuals Failure to respect the right of opposition Lack of data security |
Fine of €5,000 |
| 11/12/2025 | CANDIDATE IN THE 2024 GENERAL ELECTIONS (simplified procedure) |
Obligation to be able to justify the lawfulness of the processing (political prospecting) Information of individuals |
Fine of €2,500 |
| 11/12/2025 | COMPANY ENGAGED IN THE PERFORMING ARTS (simplified procedure) |
Consent of individuals (cookies) Information of individuals (cookies) |
Fine of €5,000 and injunction |
| 11/12/2025 | CONSTRUCTION BROKERAGE, BUILDING AND PUBLIC WORKS CONSULTING, PURCHASE AND RESALE OF EQUIPMENT, REAL ESTATE TRANSACTIONS AND PROJECT MANAGEMENT (simplified procedure) | Non-compliance (injunction procedure) | Liquidation of the penalty payment of €3,000 |
| 11/12/2025 | COMPANY ENGAGED IN THE DEVELOPMENT OF MARKETING TOOLS |
Unjustified retention of data by a processor Processing of data by a processor not authorised by the controller Register of processing activities |
Fine of €1,000,000 |
| 11/12/2025 | COMPANY ENGAGED IN THE SUPPORT, GUIDANCE AND EDUCATION OF VICTIMS OF INCEST (simplified procedure) |
Consent of individuals (commercial prospecting - article L. 34-5 CPCE) Information of individuals Failure to respect the right of access |
Fine of €20,000 and injunction |
| 11/12/2025 | PUBLIC INSTITUTION ENGAGED IN THE MANAGEMENT OF RENTAL PROPERTIES (simplified procedure) |
Limitation of purpose Data minimisation Information of individuals Failure to respect the right of opposition Lack of data security |
Fine of €20,000 and injunction |
| 15/12/2025 | COMPANY ENGAGED IN SOFTWARE PUBLISHING, IN PARTICULAR PAYROLL SOFTWARE (simplified procedure) | Lack of data security | Fine of €15,000 |
| 15/12/2025 | COMPANY ENGAGED IN THE SPECIALISED GENERAL FOOD TRADE (simplified procedure) |
Obligation to process data lawfully Data minimisation (CCTV) Data retention period |
Fine of €8,000 and injunction |
| 18/12/2025 | COMPANY ENGAGED IN THE COLLECTION OF DATA FROM COMPETITIONS, COMMERCIAL PROSPECTING AND THE TRANSMISSION OF DATA TO ITS CUSTOMERS (simplified procedure) |
Consent of individuals (commercial prospecting - article L. 34-5 CPCE) Data retention period Lack of data security |
Fine of €20,000 |
| 18/12/2025 | COMPANY ENGAGED IN COMPUTER PROGRAMMING (RENTAL AND CO-OWNERSHIP MANAGEMENT) (simplified procedure) |
Lack of legal basis (commercial prospecting) Information of individuals (commercial prospecting) Lack of data security |
Fine of €15,000 and injunction |
| 18/12/2025 | COMPANY ENGAGED IN THE BUSINESS OF CONDUCTING ELECTRONIC COMMERCIAL PROSPECTING ON BEHALF OF ADVERTISING AGENCIES (simplified procedure) |
Failure to respect the right of access Failure to respect the right of opposition |
Fine of €6,000 |
| 18/12/2025 | COMPANY ENGAGED IN LANDSCAPING, GARDEN AND SPORTS FIELD INSTALLATION (simplified procedure) |
Failure to respect the right of access Failure to cooperate with the CNIL |
Fine of €7,000 |
| 18/12/2025 | COMPANY ENGAGED IN TRAVEL AGENCY ACTIVITIES (simplified procedure) |
Information of individuals (cookies) Consent of individuals (cookies) |
Fine of €2,000 and injunction |
| 22/12/2025 | COMPANY ENGAGED IN IT SYSTEMS AND SOFTWARE CONSULTING | Lack of data security | Fine of €1,700,000 |
| 29/12/2025 | COMPANY ENGAGED IN NEWSPAPER PUBLISHING (simplified procedure) | Consent of individuals (cookies) | Fine of €5,000 |
| 29/12/2025 | COMPANY ENGAGED IN NEWSPAPER PUBLISHING (simplified procedure) | Consent of individuals (cookies) | Fine of €7,000 and injunction |
| 29/12/2025 | COMPANY ENGAGED IN LARGE-SCALE RETAIL TRADE (simplified procedure) |
Data minimisation (CCTV) Failure to cooperate with the CNIL |
Fine of €6,000 and injunction |
| 29/12/2025 | COMPANY PUBLISHING A MOBILE APPLICATION |
Lack of data security Consent of individuals (sensitive data) Consent of individuals (cookies) |
Fine of €270,000 |
| 30/12/2025 | COMPANY ENGAGED IN THE ACQUISITION AND MANAGEMENT OF HOTELS/HOTEL RESIDENCES (simplified procedure) |
Obligation to process data lawfully (CCTV) Information of individuals (CCTV) |
Fine of €5,000 |
| 30/12/2025 | COMPANY ENGAGED IN AIRPORT FREIGHT ACTIVITIES (simplified procedure) |
Obligation to process data lawfully (CCTV) Data retention period Lack of data security |
Fine of €10,000 |
| 30/12/2025 | DENTAL SURGEON (simplified procedure) | Failure to cooperate with the CNIL | Call to order |
| 30/12/2025 | TERTIARY SECTOR COMPANY |
Obligation to process data lawfully Information of individuals Obligation to carry out a Privacy Impact Assessment Lack of data security Consent of individuals (cookies) |
Fine of €3,500,000 |
| 31/12/2025 | UNIVERSITY (simplified procedure) | Limitation of purpose | Fine of €20,000 |