¶ ile paragrafa bağlantı verin veya alıntıyı künyesiyle kopyalayın. Üretilen bağlantı kimlikleri resmî paragraf numarası değildir.
CNIL.
COMMISSION NATIONALE
INFORMATIQUE & LIBERTÉS

Investigation of the case:
Paris, 16 JAN. 2024
N/Ref:
Referral
(to be included in all correspondence)
Dear Sir,
I am following up on the various exchanges that took place between the services of the French Data Protection Authority ("CNIL") and yourself, concerning a personal data breach of which became aware on August 28, 2022.
This security incident affected many people in Europe. In this context, a complainant lodged a complaint with his national data protection authority against on October 10, 2023, concerning the lack of information relating to a personal data breach. This complaint was then forwarded by the Lower Saxony state data protection authority to the CNIL services on October 28, 2022, pursuant to Article 56.1 of the General Data Protection Regulation ("GDPR").
In particular, the complainant is surprised to have been informed of this security incident on the https://www website by the "Have I been Pwned" platform and not by the company.
As part of the discussions that took place between and the CNIL departments in charge of data breaches, the latter adopted several measures to minimize the consequences of the data breach by :
- notifying the CNIL of the personal data breach on August 30, 2023, in accordance with Article 33 of the GDPR;
- correcting the security incident, by implementing the following measures: setting up a connection to a virtual private network, multi-factor authentication for all accesses to the administrative platform containing user data, and changing all employee passwords with access to the administrative platform;
- informing data subjects individually on November 19, 2022 of the personal data breach.
RÉPUBLIQUE FRANÇAISE
3 Place de Fontenoy, TSA 80715 - 75334 PARIS CEDEX 07 - 01 53 73 22 22 - www.cnil.fr
Les données personnelles nécessaires à l'accomplissement des missions de la CNIL sont traitées dans des fichiers destinés à son usage exclusif. Les personnes concernées peuvent exercer leurs droits informatique et Libertés en s'adressant au délégué à la protection des données (DPO) de la CNIL via un formulaire en ligne ou par courrier postal. Pour en savoir plus : www.cnil.fr/donnees-personnelles.
In view of the above, the measures taken to correct the security incident and to inform the persons concerned of the occurrence of a personal data breach lead the CNIL, in agreement with the other European data protection authorities, to close this complaint
However, please be aware that the CNIL reserves the right to make use of all the powers granted to it by the GDPR and by the French Data Protection Act of January 1978 as amended.
Yours sincerely,
For the the CNIL Chair and on her behalf,
