# Decision No MED 2024-158 of 4th December 2024 issuing an order to
(No MDM241031)
The President of the Commission nationale de l'informatique et des libertés (French Data Protection Authority),
Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of personal data and on the free movement of such data, in particular Articles 56 and 60;
Having regard to Law No 78-17 of 6 January 1978 on data processing, data files and individual liberties, as amended, in particular Article 20;
Having regard to Decree No 2019-536 of 29 May 2019, as amended, for the application of Law No 78-17 of 6 January 1978 on data processing, data files and individual liberties;
Having regard to deliberation No 2013-175 of 4 July 2013 adopting the internal regulations of the CNIL (French Data Protection Authority);
Having regard to decision No 2022-044C of 16 March 2022 of the President of the French Data Protection Authority to instruct the Secretary General to carry out or have carried out a verification mission of the data processing implemented by
Having regard to the online inspection reports 2022-044/1 and 2022-044/2 of 17 March and 23 May 2022;
Having regard to the on-site inspection reports 2022-044/3 and 2022-044/4 of 29 and 30 June 2022;
Having regard to the other exhibits in the case file;
# I. Context
(hereinafter “the company”), a simplified joint stock company, having its registered office at was created in June 2000 and had 217 employees in 2022. Its revenue in 2021 was
It is a travel agency that distributes and markets passenger transport services for and partner carriers through the “” website and the app, which enables the distribution of travel tickets and passenger information. As of June 2022, the app had approximately 13 million users.
As part of the use of this app, the company implements processing for the purpose, in particular, of route search as well as mobility studies and analyses.
This processing is based on the collection of geolocation data from users. Geolocation data is processed only if the user consents. This consent must be granted at the operating system level
1
to enable the app to access geolocation data. This authorisation may be given either from time to time, permanently when the app is in use, or be refused.
Pursuant to my decision No 2022-044C of 16 March 2022, a delegation from the Commission nationale de l’informatique et des libertés (hereinafter the “CNIL” or the “Commission”) carried out an online inspection of this company on 17 March 2022 using the “[REDACTED]: Trains & Trajets” app or relating to personal data collected from the latter for the purpose of verifying the compliance of the processing implemented with all the provisions of Act No 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties, as amended (hereinafter the “Data Processing and Liberties Act” or the “LIL”) and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter the “Regulation” or “GDPR”).
This inspection was followed by a second online inspection carried out on 23 May 2022 and two on-site inspections carried out on 29 and 30 June 2022.
Additional requests were sent by the CNIL on 19 May and 20 September 2022 as well as 24 January and 6 February 2023, to which the company responded on 7 June and 27 September 2022 as well as on 30 January and 8 February 2023.
On 31 October 2024, as part of the cooperation procedure, a draft decision was submitted to the authorities concerned on the basis of Article 60 GDPR.
This draft did not give rise to any relevant and reasoned objections.
## II. On breaches relating to GDPR
### 1. A breach of the obligation to define and respect a retention period proportionate to the purpose of the processing
According to Article 5(1)(e) GDPR, “personal data must be […] (e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (storage limitation)”.
The retention period for personal data must be determined according to the purpose of the processing. Once this purpose has been fulfilled, the data must be deleted or rendered anonymous, or be archived for a specific period of time when its retention is necessary, e.g. to comply with legal obligations or for pre-litigation or litigation purposes. The effectiveness of the implementation of a data retention period policy makes it possible to ensure in practice that the data is kept in a form that enables the identification of the data subjects for a period not exceeding that necessary for the purposes for which it is processed. This also makes it possible,
2
in particular, to reduce the risks of unauthorised use of the data in question, by an employee or by any third party (see CNIL, FR, 29 October 2021, Sanction, SAN-2021-019, published; CNIL, FR, 7 July 2022, Sanction, SAN-2022-015, published).
In the case in point, the delegation was informed that the [REDACTED] app had been collecting geolocation data since 25 January 2022, the date on which it was implemented under this name.
This geolocation data is stored in a database divided into two tables "Journeys" (geolocation data linked to a specific journey) and "Usual Activities" (journey data fed by the "Journeys" table and enriched to correspond to an activity). This database is hosted on an [REDACTED] ([REDACTED]).
The data, collected for route search purposes but also for mobility studies and analyses, is associated with an identifier generated randomly at each installation of the app, present in the database. These mobility analyses are carried out through the [REDACTED] application using raw geolocation data, enriched by an algorithm to identify common routes and locations. The [REDACTED] tool only allows an aggregated data display in which the identifier does not appear. The geolocation data collected, in view of its quantity and diversity, appears sufficient to make it possible, by cross-checking it with the lifestyle habits of a user, to reidentify the person, thus leading to the categorisation of personal data, which is not disputed by the company.
For all intents and purposes, it may be specified that, in the context of its opinion 05/2014 on Anonymisation Techniques of 10 April 2014, the “Article 29” Working Party (now EDPB) states that “it is only if the data is aggregated by the controller at a level where the individual events are no longer identifiable that the resulting set of data can be categorised as anonymous. For example: if an organisation collects data on individual trips, travel patterns at the level of individual events could still be considered personal data for any interested party, as long as the controller (or any third party) continues to have access to the original raw data, even if direct identifiers have been removed from the dataset transmitted to third parties.” (p. 10)
The retention periods for geolocation data defined by [REDACTED] are as follows:
- raw geolocation data (latitude, longitude, timestamp, accelerometer, altitude, direction, speed) are stored for 60 days, to prevent malfunctions of raw data enrichment scripts;
- data enriched by algorithms is stored in the database for a period of 24 months. They also make it possible to supply the functionalities of recommendations to users based on geolocation (preferred station, daily journey, etc.);
- after 24 months, this enriched data is anonymised by random sampling of identifiers, i.e. by modifying the attributes of these identifiers so as to make it less precise, and by aggregation. It is retained for mobility study purposes and is deleted 12 months after its anonymisation.
Thus it is possible for persons with access to the database, legitimately or otherwise, to have a 24-month history of all a user’s positions, including at his/her supposed homes and regular places. This risk is all the greater since it emerges from the information provided by the company that the random identifier generated during the installation of the app is intrinsically linked to the raw data collected.
3
In addition, if the user has accepted continuous geolocation and has left it active for a long period of time without uninstalling the app, it is then possible to know all his/her movements for a period of 24 months, regardless of the chosen travel method (on foot or by vehicle).
The company considers that 12 months alone are not sufficient for the mobility analysis because comparisons for the same months of different years are necessary (e.g. in case of strikes, pandemic, etc., these comparisons could be distorted).
Nevertheless, such a retention period appears excessive in that the processing in question reveals precise and intrusive information on the data subjects, possibly continuously (depending on the configuration option chosen) and without this information being directly linked to a service request from the user (the app escalating the geolocation without the user necessarily searching for a journey or ticket, for example).
It should be noted that the collection of all movements that a user makes with his/her mobile phone is particularly revealing of his/her travel habits and visits to places, including any religious establishments, health establishments, etc. Compliance with the principle of a retention period limited to what is strictly necessary is therefore particularly important.
On this point, with regard to the retention of geolocation data for the purpose of enriching the recommendation service provided to the user, it emerges from the information provided by the company that a retention period of 24 months is disproportionate to meet this purpose. Indeed, it emerges from the information provided by the company that the recommendations to users correspond to daily or monthly use of the app. The retention period for this purpose is therefore disproportionate to the actual use of the data.
With regard to the mobility analysis as such, it should be noted that the company carries out such an analysis, beyond 24 months, with anonymised data by aggregating geolocation data.
It does not appear from the information provided by the company that the mobility analyses carried out by the company are fundamentally different between the first 24 months of retention and the following 12 months in anonymised form. In the absence of demonstration by the company of the impossibility of carrying out mobility analyses on anonymised data, it therefore appears possible to consider that these analyses could be carried out on the basis of anonymised data within a period of less than 24 months.
Under these conditions, the company could anonymise travel in a shorter time frame without compromising the achievement of this purpose. The anonymised data could allow seasonal analyses over several years.
Consequently, the retention period for geolocation data for a period of 24 months is not proportionate to the purposes for which it is collected.
**These facts therefore constitute a breach of Article 5(1)(e) of GDPR. [REDACTED] must therefore ensure that it defines a retention period for data enriched by geolocation proportionate to the purposes for which it is collected.**
## **2. Failure to inform individuals**
4
Article 12(1) GDPR provides that “The controller shall take appropriate measures to provide any information referred to in Articles 1 and 13 and any communication under Articles 14 to 15 and 22 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The information shall be provided in writing, or by other means, including, where appropriate, by electronic means.”
Article 13 GDPR requires the controller to provide the data subject with various items of information, in particular regarding the identity and contact details of the controller, the purposes of the processing carried out, its legal basis, the recipients or categories of recipients of the data, and whether the controller intends to transfer data to a third country. The regulation also requires that, where it appears necessary to ensure “*fair and transparent processing*” of personal data, that individuals are informed about the period of data retention, the existence of the various rights enjoyed by individuals, the existence of the right to withdraw consent at any time, and the right to lodge a complaint with a supervisory authority.
Firstly, the privacy policy is not sufficiently accessible.
The Article 29 working group (known as the “G29” and now the European Data Protection Board) specifies, in its guidelines of 11 April 2018 on transparency within the meaning of Regulation (EU) 2016/679, that “*the ‘easily accessible’ criterion means that the data subject should not have to search for the information but should be able to access it immediately: for example, this information could be communicated to the data subjects directly or by means of a link sent to them [...]” (§11).*
It considers that “every company with a website should publish a privacy statement or notice on its website. A direct link to this statement or privacy notice should be clearly visible on each page of this website under a commonly used term (such as “Privacy”, “Privacy Policy” or “Privacy Notice”). Texts or links whose layout or colour choice makes them less visible or difficult to find on a web page are not considered to be easily accessible” and recommends that “in an online context, a link to the declaration or privacy notice be provided at the point of collection of personal data, or that this information be available on the same page as that where the personal data is collected” (§11).
In the case in point, although the privacy policy is directly accessible from the app, no access is provided when the “Authorise us to guide you” window appears. However, it is in this context that consent to the collection of geolocation data for the personalisation of journeys and offers is requested from the user.
Secondly, the delegation noted that the company had a confidentiality charter, accessible from the order form for a train journey or from the app’s “Account” tab. However, it does not contain all the information provided for in Article 13 GDPR.
Indeed, it does not mention the legal basis for processing, the right to restriction and the right to withdraw consent, whereas all this information appears necessary in the case in point.
In addition, although the charter clearly details the retention periods, they do not correspond to the periods indicated by the company to the CNIL.
5
Indeed, the charter states that geolocation data is stored “only for the duration of the navigation session, or in the background if you have accepted it” whereas it is stored in an identifying form for 24 months.
**Consequently, [REDACTED] disregarded the provisions of Articles 12 and 13 GDPR. It must therefore complete its privacy charter and provide this information to users on the windows where consent is collected.**
### **3. Breach of the obligation to ensure data security and confidentiality**
**In law**, Article 32(1) GDPR, “[t]aking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk [...]” and in particular “the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services” *and* “a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing”.
As part of the basic security measures, it is in principle necessary that access to an information system containing personal data that is not intended to be published is through an individual account, to which the user logs in using an identifier and an authentication factor specific to it. Indeed, only individual accounts enable good traceability of accesses and actions carried out on the system. Shared accounts make accountability much more difficult and complicate investigation work in the event of a security incident or data breach.
Furthermore, with regard to passwords, in accordance with the basic rules relating to the security of information systems, a password must, to be effective, remain secret and individual. However, when an account is shared between more than one person, this rule is no longer respected.
This requirement to individualise accounts is particularly acute for administrators, who have more extensive rights over the personal data processed by the system, making them targets for cyberattacks and making it necessary to be able to quickly and effectively detect a data breach by one of them. Failing this, and in particular when systems or equipment do not make it possible to have more than one administration account, additional measures must be implemented to ensure the accountability of the actions (e.g. bastion, handbook, etc.) and ensure the protection of secrecy.
**In the case in point**, the company indicated that the account enabling access to the [REDACTED] back office was shared between two directors. However, this practice does not make it possible, without additional measures, to reidentify the authors of the operations carried out in the system, traced within the log files, since it could be one or other of the users.
**These facts disregard Article 32 GDPR. The company must therefore impose a method of connecting to the [REDACTED] application back office ensuring individual authentication, either by ceasing to enable the use of generic accounts, or by duplicating the use of these**
6
generic accounts with traceability of their use and by renewing the password in the event of a change of administrator.
### III. On the breaches relating to the French Data Protection Act
[Breaches not submitted to the cooperation procedure – Art 60 of the GPR]
**Breach relating to the obligation to inform the data subjects and obtain their consent before registering information on or accessing their electronic communications terminal equipment (cookies and other trackers)**
Article 82 of Law No 78-17 of 6 January 1978 on data processing, files and freedoms, as amended, provides that “Any subscriber or user of an electronic communications service must be informed in a clear and complete manner, unless he/she has been informed in advance, by the controller or his/her representative: 1° The purpose of any action aimed at accessing, by electronic transmission, information already stored in its electronic communications terminal equipment, or recording information in this equipment; 2° The means at its disposal to object to it. Such access or registration may only take place if the subscriber or user has expressed, after receiving this information, his/her consent, which may result from the appropriate settings of his/her connection device or any other device under his/her control. These provisions are not applicable if access to the information stored in the user's terminal equipment or registration of information in the user's terminal equipment: 1° Either, has the exclusive purpose of enabling or facilitating communication by electronic means; 2° Or, is strictly necessary for the provision of an online communication service at the express request of the user.”
According to Article 4(11) GDPR:
“'consent' of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.”
In its guidelines 5/2020 on consent, the European Data Protection Board (EDPB) specified that “a controller must ensure that consent is provided on the basis of information that enables data subjects to easily identify who is the controller and understand what they are consenting to”¹. It adds that “consent must be clear and distinct from other issues, and must be presented in an understandable and easily accessible form”².
*As regards the validity of the consent regarding the reading of information on the user's terminal for advertising, personalisation and audience measurement purposes:*
The delegation noted, at the first opening of the [REDACTED] app, the opening of a consent collection window (Consent Mangament Platform) as follows:
¹ EDPS, Guidelines 5/2020 on consent within the meaning of Regulation (EU) 2016/679, §68.
² *Idem*, §67.
7

This window is used to obtain the consent of the user, in particular to enable the personalisation of the content and advertising. It also states that this consent may be used to “access precise geolocation data”. By clicking on “FIND OUT MORE”, the following screen appears:

8
The delegation was informed that for each purpose, the push button is located in the middle and greyed out. This default position is equivalent to a lack of consent.
However, the purposes described on the second screen mix technical operations (“Storing and/or accessing information on a device”) and purposes within the meaning of GDPR such as “Selecting personalised advertisements”. In addition, some of the purposes are unclear in their description and in what differentiates them (for example: “Select custom content” and “Create a profile to display custom content”).
Under these conditions, the user does not have easily understandable information relating to the purposes enabling him/her to give his/her consent in an informed manner.
### **These facts constitute a breach of Article 82 of the French Data Protection Act.**
It should be noted that the consent collection window is implemented by [REDACTED], which uses the purposes defined by the standards of the *Transparency Consent Framework* (TCF) developed by [REDACTED]. However, [REDACTED] introduced a new TCF standard in May 2023, which modifies the purposes and their title.
It is therefore up to [REDACTED] to ensure that this new standard makes it possible to obtain informed consent from users.
### ***As regards the information and validity of consent with regard to the reading of geolocation:***
As a preliminary point, it is recalled that the operation to read geolocation on the user’s terminal falls within the scope of Article 82 of the French Data Protection Act when it is carried out by access, on the user’s terminal, to position data.
In the case in point, once the user has made his/her choice on the consent collection window, a second screen is immediately presented in order to collect his/her consent to the collection of his/her geolocation in order to “propose personalised routes and offers”:
9

By clicking on "next", the consent collection screen for the geolocation of the terminal operating system appears:

As part of the online inspection of 17 March 2022, it was noted that the terminal parameters relating to the app, with regard to geolocation, indicate the following mention: "Your position helps us offer you personalised itineraries and offers. It remains anonymous and used for statistical purposes only."
10

On the one hand, the consent obtained is not free. Indeed, by combining two purposes (personalisation of the journey and personalisation of offers), the company obtains the consent of the user by a single act for two different purposes. It is therefore not possible to consent to a purpose without consent to the second, including on another level of information. The free nature of consent is not guaranteed.
On the other hand, the CNIL services have found that users are not sufficiently informed, either through the consent collection interface or by any other means, of the third purpose, relating to the analysis of mobility. Indeed, it emerges from the company’s register of processing activities that geolocation data is used for mobility analysis purposes. However, the sections of the privacy policy dedicated to the purposes of processing or geolocation data do not mention that the user data used to “provide the best mobility service” includes geolocation data. Therefore, neither the consent collection interface nor the privacy policy contain a sufficient level of information relating to the use of geolocation data.
Furthermore, it should be noted that the information communicated at the level of the terminal parameters is not accurate since the data collected is not immediately anonymised.
This lack of precision and accuracy has the consequence that the informed nature of the consent is not satisfied.
These facts constitute a breach of Article 82 of the French Data Protection Act. must therefore ensure that it obtains free and informed consent for each of the purposes concerned by the collection of geolocation data.
11
# **IV. Corrective measures imposed by the CNIL (Article 20, paragraph II of the French Data Protection Act)**
It follows from the foregoing that the following corrective measures are ordered against [REDACTED], located at [REDACTED]:
- A **REPRIMAND**, with regard to the absence of valid consent collected within the framework of the consent collection window, noted during the inspection mission of 17 March 2022 and linked to the lack of information relating to the purposes, easily understandable by the user;
- AN **ORDER**, within six (6) months of notification of this decision and subject to any measures it may have already adopted, to:
- define and implement a retention period policy for geolocation data that does not exceed the period necessary for the purposes for which it is collected in accordance with the provisions of Article 5(1)(e) GDPR;
- provide accurate and complete information to the data subjects, in accordance with the provisions of Articles 12 and 13 of the Regulation, on the processing of personal data put in place, and provide this information to users on the windows where their consent is collected;
- take measures to preserve the security of the data and prevent unauthorised third parties from gaining access to it:
- by imposing a connection method to the [REDACTED] application back office providing individual authentication, either by ceasing to allow the use of generic accounts, or by duplicating the use of these generic accounts with traceability of their use and by renewing the password in the event of a change of administrator;
- inform the data subjects and implement a valid mechanism for obtaining a free, informed, unambiguous and specific consent from the persons to the registration of information on their terminal equipment and access thereto, for all purposes not having the exclusive purpose of enabling or facilitating communication by electronic means or not strictly necessary for the provision of an online communication service at the express request of the user;
- prove to the CNIL that all the aforementioned requests have been complied with within the allotted time.
At the end of this period, if [REDACTED] has complied with this order, it will be considered that this procedure is closed and a letter will be sent to it to this effect.
12
Conversely, if [REDACTED] has not complied with this order, it is recalled that a Rapporteur may be appointed to request that the Restricted Committee impose one of the sanctions provided for in Article 20 of the Law of 6 January 1978 as amended.
Marie-Laure Denis
13