Deliberation of Restricted Committee No SAN-2024-020 of 5th December 2024
concerning
The CNIL (French Data Protection Authority), meeting in its Restricted Committee made up of
Messrs Philippe-Pierre Cabourdin, President, Vincent Lesclous, Vice-President, Ms Laurence
Franceschini and Messrs Bertrand du Marais and Alain Dru, members;
Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of
27 April 2016 on the protection of personal data and on the free movement of such data;
Having regard to the French Data Protection Act No 78-17 of 6 January 1978, as amended, and
in particular Articles 20 et seq.;
Having regard to amended decree No 2019-536 of 29 May 2019, adopted for the application of
the Data Protection Act No 78-17 of 6 January 1978;
Having regard to deliberation No 2013-175 of 4 July 2013 adopting the internal regulations of
the CNIL (French Data Protection Authority);
Having regard to decision No 2022-104C of 21 June 2022 of the President of the CNIL (French
Data Protection Authority) to instruct the Secretary General to carry out, or have carried out,
an audit of the processing operations implemented by ;
Having regard to the report of Mr Fabien Tarissan, reporting auditor, notified to on 3
May 2024;
Having regard to the written observations submitted by the counsel of on 13 June 2024;
Having regard to the response of the Rapporteur to these observations served by the court
commissioner on on 12 July 2024;
Having regard to the written observations submitted by the counsel of , received on 19
August 2024;
Having regard to the oral observations made at the Restricted Committee session;
Having regard to the other exhibits in the case file;
The following were present at the Restricted Committee session of 19 September 2024:
- Mr Fabien Tarissan, commissioner, heard in his report;
As representatives of :
- , General Counsel, Cognism;
- , Deputy Director of Legal Affairs, Cognism;
- , lawyer at the Paris bar, law firm ;
- , lawyer at the Paris bar, law firm
;
- , lawyer at the Paris bar, law firm .
having spoken last;
The Restricted Committee implemented the following decision:
I. Facts and proceedings
1
13. By letter dated 6 September 2024, the company received a notice of the Restricted Committee
session of 19 September.
14. The company and the Rapporteur presented oral observations at the Restricted Committee
session of 19 September 2024.
I. Reasons for the decision
A. On the processing in question
15. The tool is an extension for the Chrome browser which, when visiting an individual’s
profile on LinkedIn, displays the business contact details (phone number and email address) of
natural persons that appear in the database. To access this service, the user must
purchase and spend “credits” to display the contact details of the desired person (the target
person). The number of credits the user receives is determined by the price of his/her
subscription, which may be monthly or annual.
16. In the case in point, the Restricted Committee notes that the company processes the personal
data of two distinct categories of persons:
- target persons, i.e. persons whose professional contact details have been collected by
the company from various sources, including the LinkedIn social network and entered
into its database;
- the users of the extension, i.e. the company’s customers whose subscription
enables them to visit the LinkedIn profiles of the target persons in order, in particular,
to obtain their professional contact details.
17. The purpose of the extension is to enable these users to contact the target persons, e.g.
for commercial prospecting, recruitment or identity verification, using the contact details of
professionals obtained. The only data that can be displayed by the extension when visiting a
LinkedIn profile are the phone number and email address. The data collected regarding the
contact data of the target persons are last name, first name, email address, phone number, URL
of the LinkedIn profile or other social networks, employer, company, job title, skills,
professional interest, career, hire and end date, training, workplace, data source and date of
collection
18. The Restricted Committee observes that the company collects data through three sources:
- “suppliers” themselves collecting data from publicly accessible professional sources
such as LinkedIn, Whois, GitHub;
- directories of domain name registers, which make it possible to search for information
on an already existing domain name and its holder;
- importing a user’s LinkedIn contacts when activating users sync the
extension with their LinkedIn account. The delegation was informed that this
makes it possible to retrieve the contact details available on LinkedIn from the direct
contacts of users but which are not necessarily visible to all visitors to the LinkedIn
website. The extension thus makes it possible to make available, in the
database, data that the LinkedIn contacts of users wanted to limit to their
contacts within the professional social network only.
3
19. Approximately 160 million contacts are included in the database created by the company,
including precisely 12,591,206 within the European Union, Norway, Iceland and Liechtenstein,
the geographical origin being determined by the address of the place of work.
B. On the competence of the CNIL and the application of the consistency
mechanism
20. Article 3(1) GDPR provides that “[t]his Regulation applies to the processing of personal data
in the context of the activities of an establishment of a controller or a processor in the Union,
regardless of whether the processing takes place in the Union or not”.
21. Pursuant to Article 56(1) of the Regulation, “the supervisory authority of the main
establishment or of the single establishment of the controller or processor shall be competent to
act as lead supervisory authority for the cross-border processing carried out by that controller
or processor in accordance with the procedure provided in Article 60”.
22. The criteria for determining whether a supervisory authority is concerned are set out in Article
4(22) GDPR, which provides that an authority is “concerned by the processing of personal data
because:
(a) the controller or processor is established on the territory of the Member State of that
supervisory authority;
(b) data subjects residing in the Member State of that supervisory authority are
substantially affected or likely to be substantially affected by the processing; or
(c) a complaint has been lodged with that supervisory authority”
23. The Rapporteur considers that pursuant to Article 3(1) GDPR, when the activities of the
controller take place on the territory of the Union, the obligations contained in GDPR apply to
all data subjects concerned by said processing, whether or not they are located within the
European Union.
24. Furthermore, the Rapporteur considers that, since the CNIL delegation found the presence in
the database of personal data of persons located in Sweden, Hungary and the Land of
Saxony, these authorities are concerned.
25. In defence, while the company does not dispute the capacity of competent authority of the
CNIL to determine the compliance with GDPR of the processing in question, it argues that the
CNIL is not competent to rule, as lead authority, on the compliance with GDPR of the
processing of personal data of persons located in Hungary, Sweden and the Land of Saxony
since these authorities have declared themselves not concerned. With regard to the territorial
scope of GDPR, the company considers that in assessing the number of persons concerned by
the breaches alleged against it, persons located outside the European Union cannot be taken
into account. The company argues that in its judgment of 24 September 2019, the Court of
Justice of the European Union considered in the context of a preliminary ruling on the territorial
scope of the right to de-referencing that GDPR could only have effect on the territory of the
European Union (CJEU, Grand Chamber, 24 September 2019, Google, No C-507/17).
26. The Restricted Committee notes that the sole establishment of is located in France,
that the processing in question therefore takes place in the context of the activity of this
establishment, and that the CNIL is thus the competent authority to determine the compliance
of processing with GDPR, which is not disputed by the company.
4
27. On 19 September 2023, in accordance with Article 56 GDPR, the CNIL informed all the
European supervisory authorities of its competence to act as lead supervisory authority for
cross-border processing carried out by the company, a competence derived by the CNIL from
the fact that the company’s principal place of business was in France. The Restricted Committee
notes in this regard that the form entitled “Article 56- Identification of LSA and CSA”, sent to
all the other European data protection authorities, is solely intended to enable the other
authorities to be aware of the opening of a file by the lead authority and is not intended to
irrefutably determine their status as the authority concerned at this stage. Conversely, the
Restricted Committee notes that the presence of data concerning persons established on the
territory of a particular Member State is decisive in the identification of the authorities
concerned.
28. In the case in point, the CNIL inspection delegation found that in addition to all the other
contacts present in the database, 503,190 contacts in the database were located in
Sweden, 92,688 contacts in Hungary and 940,814 contacts in Germany. Therefore, all the
European authorities are concerned within the meaning of Article 4(22) of the Regulation.
29. Thus the Restricted Committee considers that the criterion set forth in Article 4(22)(b) GDPR
is indeed met in the case in point, since it has been found that “data subjects residing in the
Member State of this supervisory authority are significantly affected by the processing or are
likely to be significantly affected by the processing”.
30. In addition, the Restricted Committee recalls that the controller whose establishment is located
in the territory of the Union is required to comply with GDPR with regard to all the persons
whose data it processes without making a distinction between persons according to their
location. The Restricted Committee observes that the facts in question in the case in point differ
from those referred to in the CJEU judgment on de-referencing.
31. Indeed, the necessary balancing was at issue between, on the one hand, the right to respect for
the privacy of a person located on the territory of the European Union and, on the other hand,
the right to information of a person located outside the European Union, who is thus not a data
subject since his/her data was not processed. This concerned a third party to the processing.
However, in the case in point, persons located outside the territory of the European Union have
their data collected and processed by , which is subject to compliance with GDPR.
Thus, under Article 83(2)(a), account should be taken of the fact that the company processes
160 million contacts, on the specification that the same natural person may correspond to more
than one contact.
32. Pursuant to Article 60(3) GDPR, the draft decision adopted by the Restricted Committee was
forwarded to the other competent European supervisory authorities, with a view to enabling
them to make relevant and reasoned objections to the processing operations and breaches which
concern them, on 5th November 2024.
33. As of 4th December 2024, none of the supervisory authorities concerned had raised any
relevant, reasoned objection to this draft decision regarding the breaches identified, so that,
pursuant to Article 60(6) of the GDPR, they are deemed to have approved it.
5
C. On the breach of the obligation to have a legal basis (Article 6 GDPR)
34. Pursuant to Article 6 GDPR, “1. Processing shall be lawful only if and to the extent that at least
one of the following applies:
(a) the data subject has given consent to the processing of his or her personal data for one or
more specific purposes;
(b) processing is necessary for the performance of a contract to which the data subject is party
or in order to take steps at the request of the data subject prior to entering into a contract;
(c) processing is necessary for compliance with a legal obligation to which the controller is
subject;
(d) processing is necessary in order to protect the vital interests of the data subject or of another
natural person;
(e) processing is necessary for the performance of a task carried out in the public interest or in
the exercise of official authority vested in the controller;
(f) processing is necessary for the purposes of the legitimate interests pursued by the controller
or by a third party, except where such interests are overridden by the interests or fundamental
rights and freedoms of the data subject which require protection of personal data, in particular
where the data subject is a child.”
35. The use of the legal basis of legitimate interest, pursuant to Article 6(1)(f) GDPR, as a legal
basis for processing is subject to three conditions: the interest pursued must be legitimate, it is
necessary to process the personal data for the purposes of the legitimate interests pursued and
the processing must not infringe the rights and interests of the persons whose data is being
processed, taking into account their reasonable expectations.
36. By way of clarification, with regard to the legal basis of legitimate interest, Recital 47 GDPR
states that such an interest may “provide a legal basis for processing, provided that the interests
or the fundamental rights and freedoms of the data subject are not overriding, taking into
consideration the reasonable expectations of data subjects based on their relationship with the
controller. Such legitimate interest could exist for example where there is a relevant and
appropriate relationship between the data subject and the controller in situations such as where
the data subject is a client or in the service of the controller.”
37. The Rapporteur specifies that the breach of Article 6 GDPR developed in the sanction report
only concerns data collected via the LinkedIn social network - in the case of persons who have
intended to restrict the display of their contact details - and not the other sources of collection.
He considers that the provision of the contact data of the target persons by to its users
when they had chosen not to make it public to all, exceeds what can reasonably be expected of
persons who register on a professional social network such as LinkedIn.
38. In defence, the company considers that the processing is based on the legal basis of legitimate
interest, since LinkedIn users register on this social network to benefit from a connection with
other professionals, and that it is therefore not necessary to collect their consent. It also argues
that the need for identity verification falls within the reasonable expectations of professionals
6
in a context of increased risks regarding the validity of digital profiles. However, it considers
that the risks of phishing and identity theft raised by the Rapporteur are in fact lacking and do
not take into account the safeguards put in place by . The company recalls that the
extension processes business contact information and is fed by legitimate public
business sources other than LinkedIn. The company adds that the validity of this legal basis for
the benefit of can only be limited to taking into account its sole interest and cites a
publication by the CNIL “Commercial prospecting by email, For professionals (BtoB) of 18
May 2009 which indicates that “prospecting to professionals may (perfectly) be based on the
legitimate interest of the organisation”.
39. Finally, the company notes that the collection of contact data is carried out in accordance with
the choices expressed by users of the LinkedIn social network. It specifies in these last entries
that they have the possibility of making their coordinates visible via the parameters of the
LinkedIn interface, by choosing from among four options: 1) “only visible to me”, 2) “everyone
on LinkedIn”, 3) “first-level relationships” and 4) “first- and second-level relationships”. The
company explains that it is only in these last two cases where the user makes his/her email
address visible through his/her first- and second-level relationships, that it collects the data.
When people have chosen option 1 “only visible to me”, their data is not collected.
40. As a preliminary point, the Restricted Committee specifies that the breach developed below
concerns the personal data collected on the LinkedIn social network of target persons who have
chosen to limit or hide the visibility of their contact details. The Restricted Committee also
notes in response to one of the company’s arguments that the fact that the database in question
is solely composed of the “professional” contact details of the target persons remains without
impact on the “personal” nature of this data when this data relates to natural persons, according
to well-established case law of the Court of Justice of the European Union (see, in particular,
CJEU, 9 November 2010, Volker e. a., joined cases C-92/09 and C-93/09, pt. 59).
41. With regard to the interest pursued - in that it is of a commercial nature and is consistent with
the company’s business model - the Restricted Committee considers that it can be categorised
as legitimate and that the data collected for the purposes of these interests may appear necessary,
an interest that may also extend to customers who actually benefit from an interest by
using these contacts for commercial prospecting or recruitment.
42. This legitimate interest pursued by the company must be considered with regard to the
balancing of the interests, freedoms and fundamental rights of the data subjects and the
legitimate interests pursued by the company, the Restricted Committee recalls that in order to
base processing on the basis of the legitimate interest, the processing must not infringe the rights
and interests of the persons whose data is processed, taking into account their reasonable
expectations.
43. However, in the case in point, the Restricted Committee considers that since persons make use
of their freedom of choice by restricting the visibility of their personal data, this choice is
necessarily imposed on third parties. Thus, if a professional who is registered on LinkedIn
chooses to limit the visibility of his/her contact details, it cannot be argued that the collection
of his/her data by falls within the reasonable expectations of this person.
44. The Restricted Committee observes that it emerges from the LinkedIn parameter interface that
if the target persons who chose to restrict the visibility of their contact details had actually
7
wanted their professional contact details to appear to all, they would have chosen to activate
the parameter enabling their contact details to be visible to all users. In the case in point, it
considers that the fact that the target persons have chosen to hide their contact details is
equivalent to a form of opposition, an essential corollary of the legitimate interest, which must
be taken into account by the company, which thus has no legitimate interest in collecting the
hidden contact details.
45. Thus, by revealing the data of the target persons to persons unknown to them when they had
chosen to restrict the visibility of their contact details (first- and/or second-level relationships),
the company is going directly contrary to their “reasonable expectations”, within the meaning
of Recital 47 GDPR. Furthermore, the Restricted Committee notes that it emerges from the
company’s impact assessment that as soon as the processing is invisible, the target persons may
“not be aware that or the end users of the profile data have collected their data”. Finally,
while the company maintains that it has taken measures to limit the risk for persons in its impact
assessment, the Restricted Committee notes that it does not consider the case of target persons
whose data is collected when they had chosen to hide the visibility of their contact details. It
has therefore not taken any measure to limit the risk of a breach of the personal data of the
target persons.
46. Contrary to what the company argues, it cannot be argued that the target persons, by authorising
some of their contacts to read their contact details, intended, through this action, to authorise
to collect such data. In this sense, no “relevant and appropriate relationship” within the
meaning of the aforementioned recital binds the target persons to the company, in that they are
not users of the extension but simply contacts of customers who use the
extension.
47. Furthermore, the Restricted Committee notes that several complainants who have been
approached by users of the extension, whether by electronic means or by phone, have
informed the Commission services of their interrogations on the basis and on the legitimacy of
the collection and provision of their personal data by the company.
48. Although not carried out by the company, this canvassing is made possible by the
extension, which reveals to its users the contact details of the target persons contained in its
database and leads some of its customer users to carry out this canvassing. In addition, while
the company maintains that the contact details of the persons approached may have been
collected from sources other than LinkedIn, this circumstance has no impact on the
characterisation of the breach in that the company was not entitled to collect the data of the
persons who had chosen to restrict its visibility.
49. The Restricted Committee emphasises that LinkedIn’s privacy policy rightly emphasises the
fact that the data processed from its social network is processed in accordance with users’
preferences: “Any data you include in your profile or in the content you post, as well as your
social media actions on social (…) made on our Services, are visible to others according to
your preferences.”
50. In view of all these elements, the Restricted Committee considers that the interests or
fundamental rights and freedoms of the data subjects, in particular their right to privacy,
prevailed over the legitimate interest of the controller to process their data in order to be able
to ensure the functioning of its extension, so that the legal basis of the legitimate interest of the
company cannot be upheld.
8
51. Finally, with regard to the other legal bases, the Restricted Committee notes that the persons
whose contact data has been extracted never consented in any way to the extraction of their
contact data, nor to their transmission to the company to operate the extension.
52. It also notes that no contract binds the data subjects to , which is not disputed by the
company.
53. Thus the Restricted Committee considers that neither the legal basis for consent, nor that of the
contract, nor any other legal basis (compliance with a legal obligation, safeguarding of the vital
interests of the data subject or performance of a public interest mission), appear to be a valid
legal basis for the processing in question.
54. It follows from the foregoing that the collection of contact data through the import of the
LinkedIn contacts of users who have decided not to make their contact data visible to all other
users, used to populate the database of the extension, is devoid of any legal basis, so
that a breach of Article 6 GDPR is constituted.
D. On the breach of the obligation to define and comply with a data retention period
proportionate to the purpose of the processing (Article 5(1)(e) GDPR)
55. Pursuant to Article 5(1)(e) GDPR, personal data must be “kept in a form which permits
identification of data subjects for no longer than is necessary for the purposes for which the
personal data are processed (…)”.
56. In accordance with these provisions, it is the responsibility of the controller to define a retention
period that is consistent with the purpose of the processing. Once this purpose has been fulfilled,
the data must be deleted or rendered anonymous, or be archived for a specific period of time
when its retention is necessary, e.g. to comply with legal obligations or for pre-litigation or
litigation purposes.
57. As a preliminary point, it should be noted that the company collects and stores, on the one hand,
the contact data of the target persons and, on the other hand, the data of the users of the
extension used by the company for commercial prospecting purposes.
58. The Rapporteur notes that although the extension was created in 2018, during the hearing
inspection of 28 July 2022, the CNIL was informed that had not yet formalised a data
retention policy. It is only in the context of these adversarial proceedings that the company
stated that it had considered its data retention policy from July 2021.
59. The Rapporteur considers, with regard to ’s customers, that, until the redefinition by
the company of its privacy policy updated in June 2024, it retained customer data for
commercial prospecting purposes in an unlimited manner as long as the latter had not objected
to it. He considers that this is incompatible with the principle of retention for a proportionate
period.
60. He then notes with regard to the target persons that the company had not, on the day of the
hearing inspection carried out by the Commission on 28 July 2022, defined a retention period
policy and that in any event, the company was not entitled to retain the data of the target persons
indefinitely, at the risk of irremediably losing control of their data to these persons.
9
61. The company argues, with regard to customers, that the starting point for the retention
period of their data for commercial prospecting purposes is automatically renewed on each
subscription term until the termination by customers of their subscription. It specifies that it
now retains the data for three years from the end of the subscription, since the drafting of the
note on data retention by in July 2021.
62. The company argues, with regard to the target persons, that the retention of this data is at the
core of the service offered by through its extension and that it has now provided for a
data retention period of five years, which begins to run with each periodic update of the personal
data of the target persons.
63. As a preliminary point, the Restricted Committee emphasises that the breach of Article 5(1)(e)
does not concern the data of the persons concerning which it has just been said in paragraphs
40 to 50 that it was processed without a valid legal basis, which should not have been added to
and stored in the database.
64. Firstly, the Restricted Committee notes, with regard to ’s customers, that on the day
of the inspection, the company’s privacy policy clearly indicated that customer data was kept
for commercial prospecting purposes until the latter objected to it. However, the Restricted
Committee observes that such retention must necessarily be limited in time and that the
company cannot be satisfied with the absence of opposition from users to retain their data
indefinitely after the end of the term of the business relationship.
65. The Restricted Committee nevertheless notes that, in its submissions, the company indicated
that the confidentiality policy in force on the date of the inspections did not reflect the
company’s practice. In this sense, it produces internal documents under the terms of which the
company indicates, on the one hand, applying a retention period of three years from the end of
the business relationship and, on the other hand, purging the data that had reached this retention
period.
66. The Restricted Committee therefore considers that, with regard to the retention of the data of
the company’s customers, no breach of Article 5(1)(e) is characterised.
67. Secondly, with regard to target persons whose data has not been collected illegally [i.e. persons
who have chosen to leave their contact details visible on LinkedIn], the Restricted Committee
does not dispute the need for the company to retain the data of target persons who have not
objected to the processing of their data insofar as its disclosure to the company’s customers
constitutes the principle of processing. However, it notes that initially, the company indicated
in its privacy policy that it retained the data without time limit and that it was only in 2021, i.e.
three years after the implementation of the processing, that the company began to redefine its
retention period policy.
68. In any event, the Restricted Committee notes that the retention policy established by the
company after the inspection provides that the data is retained for five years from each data
update, which generally occurs when a person changes position or employer.
69. However, the Restricted Committee notes that for persons who change position or employer
within an interval of less than five years, this renewal of the retention period leads to the
retention of their data for an indefinite and unlimited period.
70. The Restricted Committee considers that this “dynamic” retention by automation is not
compatible with compliance with the principle of proportionate retention.
10
71. Indeed, the target persons are not users of the service offered by and have no
relationship with the controller. The target persons are thus passive with regard to the
processing and captive of it, as long as they do not choose to be included in the database.
72. The Restricted Committee emphasises that, unlike persons who have created an online account
on a social network or e-commerce site and for whom it is possible to determine when they
have become inactive, it is not, by nature, possible to determine such a time for persons whose
data processes.
73. While the company explains that, since 18 May 2022, it has implemented an email information
campaign that enables persons to object to the processing of their data and therefore, to
terminate it, the Restricted Committee notes that for persons in the case described in point 70,
sending this message has so far been the only opportunity they have had to express their wish
to no longer appear in the company’s database.. In cases where persons do not object to
processing when receiving this message, the company will retain their data indefinitely.
74. Thus the Restricted Committee considers that the company should cease the automatic dynamic
renewal of the retention of the personal data of the target persons so that does not retain
their data indefinitely and for an unlimited duration, but for a maximum of five years.
75. It follows from the foregoing that the period retention policy defined by the company is not
proportionate with regard to the specifics of the processing, which constitutes a breach of
Article 5(1)(e) GDPR.
E. On the breach of the obligation of transparency and the obligation to inform
persons (Articles 12 and 14 GDPR)
76. Article 12 GDPR provides that “The controller shall take appropriate measures to provide any
information referred to in Articles 1 and 13 and any communication under Articles 14 to 15 and
22 relating to processing to the data subject in a concise, transparent, intelligible and easily
accessible form, using clear and plain language, in particular for any information addressed
specifically to a child. The information shall be provided in writing, or by other means,
including, where appropriate, by electronic means.”
77. Article 14 GDPR provides that when the personal data has not been collected from the data
subject by the processing, the controller will provide the data subject with the information
referred to in the same article “within a reasonable period after obtaining the personal data, but
at the latest within one month, having regard to the specific circumstances in which the personal
data are processed”.
78. Thus, under this article, the controller must provide the data subject with information, in
particular on the identity and contact details of the controller (and, where applicable, the contact
details of the data protection officer), the purposes of the processing, its legal basis, the
categories of personal data concerned, where applicable the recipients or categories of
recipients of the data, the fact that the controller intends to transfer the data to a third country
as well as, if necessary to ensure fair and transparent processing, the retention period of the
data, the existence of the various rights enjoyed by persons, including the right to request from
the controller access to the personal data, rectification or the right to object to the processing,
the source from which the data originates and the possible existence of automated decision-
making.
11
79. Under the terms of paragraph 5(b) of the same article, however, this obligation to provide
information is not imposed when “the provision of such information proves impossible or
would involve a disproportionate effort” or when compliance with this obligation to provide
information “is likely to render impossible or seriously impair the achievement of the objectives
of that processing”.
80. In its guidelines of 29 November 2017 revised on 11 April 2018 on transparency, the “Article
29” working group on data protection emphasises that “Articles 13 and 14 refer to the obligation
imposed on the controller to “[provide] all the following information...” The word ‘provide’ is
crucial here. It means that the controller must take concrete steps to provide the information in
question to the data subject or to actively direct the data subject to the location of the
information.” It thus emerges from the guidelines that “The data subject must not have to
actively search for the information covered by these articles among other information such as
the conditions of use of a website or app” (point 33).
81. The Rapporteur notes, with regard to the obligation to provide information, that it was only
from 18 May 2022 that the company began to inform data subjects that their personal data had
been collected in an email in English referring to a link enabling them to object to the
processing. However, the Rapporteur considers that the company was able to inform the target
persons, as soon as the app was deployed, that their data was processed, since among the data
it collects was an email address.
82. The Rapporteur then notes, with regard to the transparency obligation, that the information
provided in the information email sent since 18 May 2022 is exclusively written in English,
which does not make it possible to validly inform people who do not speak this language.
83. In defence, the company argues that between 2018 and 2022, i.e. between the creation of the
extension and the implementation of information emails relating to processing, persons were
informed through the privacy policies of LinkedIn and , and that while the
communication implemented on 18 May 2022 was only available in English, this does not
constitute a breach of the obligation of transparency since the extension is used by an
audience of professionals for whom this language can be considered to be commonly used
within the European Union.
84. As a preliminary point, the Restricted Committee emphasises that the breach of Articles 12 and
14 does not concern the provision of information to persons whose data has been collected
illegally, as set out in paragraphs 40 to 50, the obligation to inform these persons being,
therefore, irrelevant. The Restricted Committee notes, however, that if the company collected
(which it wrongly considered lawful) this data, it did not inform the data subjects either.
85. The Restricted Committee notes first of all, with regard to the obligation to provide
information, that the data of the target persons has been collected and processed for nearly four
years, without any information being sent to them by the company, the latter only providing in
its impact assessment since July 2022 that it “notifies all the data subjects present in its database
in accordance with its obligations provided for by Article 14 GDPR and constitutes a team
dedicated to the management of access requests within the given deadlines”.
12
86. The Restricted Committee considers that the company cannot avail itself of its privacy policy
or that of LinkedIn to consider that it has fulfilled its obligation to inform the persons concerned
by the processing. The Restricted Committee notes in this regard that in its privacy policy,
LinkedIn specifies “Any data you include in your profile or in the content you publish, as well
as your actions on social networks (…) made on our Services, are visible to others according
to your preferences”. However, the practice of , by making accessible data that a user
wanted to keep “private”, goes against their will. The privacy policy does not provide
any specific information, in particular on the source of the data collected, merely stating “We
collect this data from public sources, professional directories and from our partners from time
to time”.
87. In this respect, the Rapporteur considers that the provision of information to persons whose
contact details are processed by an email only available in English, does not meet the
requirement to provide transparent information set forth in Article 12 of the Regulation (CNIL,
FR, 29 December 2023, Sanction, No SAN 2023-023). The Restricted Committee recalls that
according to the guidelines of the “Article 29” working group on transparency within the
meaning of Regulation (EU) 2016/679, adopted on 11 April 2018, an essential aspect of the
principle of transparency lies in the fact that “the data subject should be able to determine in
advance what the scope and consequences of the processing encompass in order not to be caught
off guard at a later stage as to how his/her personal data has been used” and that “A translation
into one or more languages should be provided when the controller targets data subjects
speaking these languages”.
88. In the case in point, while the company argues that professionals whose data is collected speak
the English language when they work within the European Union, the Restricted Committee
considers that the mere fact that these persons are registered on the social network and work in
a country of the European Union does not prejudge their level of English. Anyone can register
on LinkedIn, without necessarily working in a profession that requires the use of English, as
the Dutch data protection authority recently pointed out in the context of a breach of the
obligation of transparency against the companies Uber Technologies Inc. and Uber BV. The
authority has in fact considered that the controller is obliged to translate the information
provided to the persons whose data is processed into a language that they understand, and that
it is not possible to prejudge their level of English (Dutch Data Protection Authority, 11
December 2023, Uber Technologies Inc. and Uber BV).
89. However, in the case in point, the absence of information understandable to individuals had the
consequence, until the establishment of information available in several languages which the
company provided in the context of its second observations, of depriving them of the possibility
of objecting to the processing and therefore to the transfer of this data to the company database.
90. While the company notes that some complainants sent their request to exercise rights in English,
the Restricted Committee recalls that it is not possible to presume the level of English of each
person whose contact is present in the database, and notes in this regard that even when
the complainants contacted the company in French, the latter responded in English.
91. Finally, the Restricted Committee notes that the company indicated for the first time in its
observations produced on 19 August 2024 that it now allowed people to select the language of
their choice concerning ’s information email and privacy policy in order to read them
in French, Spanish, Dutch or German, without, however, specifying the date on which this
option was implemented, or why these documents were not made available in all languages
spoken within the European Union.
13
92. It follows from the foregoing that between 2018 and 2022 no information was provided to target
persons who had not restricted the visibility of their data and that, since 2022, information has
been provided in English, which does not meet the requirement of transparency, so that a breach
of Articles 12 and 14 is established until the possibility for persons to select the language of
their choice is put in place.
F. On the breach of the obligation to grant requests to exercise the right of access
(Article 15 GDPR)
93. Pursuant to Article 15(1)(g) of the Regulation: “The data subject shall have the right to obtain
from the controller confirmation as to whether or not personal data concerning him or her are
being processed, and, where that is the case, access to the personal data and […] where that is
the case, access to the personal data and where the personal data are not collected from the data
subject, any available information as to their source”.
94. Article 12(3) GDPR provides that “[t]he controller shall provide information on action taken
on a request under Articles 15 to 22 to the data subject without undue delay and in any event
within one month of receipt of the request”.
95. The Rapporteur notes that it emerges from several referrals that the complainants who were
the subject of solicitation and who questioned on the origin of the data did not receive
any specific response from the company, the latter merely informing them that the data was
available on publicly accessible sources.
96. The Rapporteur considers that the company should have, since it is able to identify some of the
sources used to collect the data present in its database, cited the possible sources of collection
in the context of access requests, even if it was not able to indicate to the complainants the
precise source of collection of the personal data of the target persons.
97. In defence, the company argues that the consideration of complaints subsequent to the hearing
inspection infringes the rights of the defence in that it was only when preparing its observations
in response to the Rapporteur’s report that it had the opportunity to demonstrate how these
complaints had been handled.
98. The company adds that it did not have the technical capacity, before January 2022, to separately
retrace the different categories of data sources integrated into the database, and that it
was not able to do so retroactively from January 2022.
99. The Restricted Committee considers, firstly, that the company has had the necessary time and
facilities to provide any evidence likely to demonstrate the fate of the complaints communicated
by the Rapporteur in support of his initial report. It considers that no infringement of the rights
of the defence is established, as the breaches pre-date the imposition of the sanction.
100. The Restricted Committee considers, secondly, that the company must be able to indicate “any
information available as to the source” of the data it holds on persons pursuant to the
aforementioned Article 15, in particular where the person’s professional phone number has
been retrieved, in the event that it has this information. However, in the case in point, it emerges
14
from the referrals that the complainants questioned the way in which the company had obtained
their contact details, without a specific response being given to them, with the company merely
indicating that the data was available on publicly accessible sources. While the company argues
that it has, in accordance with the guidelines of the EDPB on the rights of data subjects - Right
of access No 01/2022 of 28 March 2023, responded to access requests by putting in place a
second-level referral mechanism to more precise information, the Restricted Committee notes
that it emerges from the same guidelines, which present an example, that: “While it is not
possible to determine ex ante which of the companies is to be involved in the processing, it is
sufficient to mention the names of the eligible companies in the privacy policy. In the context
of an Article 15 application, in addition to the information that solvency information has been
obtained, it would then be necessary (a posteriori) to indicate exactly which companies were
involved. It is clear from Article 15(1)(g) that information on data processing includes ‘any
information available as to its source’ where the personal data is not collected from the data
subject.”
101. The Restricted Committee considers that while the company could provide the information
required by the aforementioned Article 15 in the context of second-level information, i.e. by
including a link in the information email referring to the website and in particular to
its data privacy policy, it is not sufficiently precise in view of the information available to the
company on the data sources. Indeed, it is stated in the privacy policy in force at the time of the
response it provided to the complainants, with regard to the origin of the personal data of the
target persons: “We collect this data from public sources, professional directories and from our
partners from time to time”. However, it emerges from the documents in the case file that
nevertheless precisely identified part of the sources that feed its database.
102. Indeed, it has informed the supervisory delegation of three main sources of data (point 19),
which are now referred to in the latest version of its privacy policy: “We collect this data from
social networks such as LinkedIn, professional directories such as Whois and GitHub and from
our data providers from time to time.”
103. However, the Restricted Committee considers that the mention of “our data providers from time
to time” does not give any details on the various “suppliers” in question in the case in point and
considers that, as soon as is aware of the various precise sources, it is its responsibility
to inform them.
104. Thus the company was able to provide more information to the complainants regarding the
sources of the data, even though it was unable to indicate to the complainants the precise source.
105. The Restricted Committee recalls that the purpose of the right of access is to enable the data
subject to become aware of the processing of his/her data and to verify its lawfulness. The
exercise of this right therefore assumes that the information provided is as accurate as possible
(CNIL, FR, 30 November 2022, Sanction, No SAN 2022-022).
106. It follows from the foregoing that the company did not inform the target persons who exercised
their right of access on the source from which it had collected their data, so that a breach of
Article 15 GDPR is constituted.
II. On the pronouncement of corrective measures and publicity
15
107. According to Article 58(2) of the GDPR, "Each supervisory authority shall have all of the
following corrective powers: […]
c)to order the controller or the processor to comply with the data subject’s requests to exercise
his or her rights pursuant to this Regulation;
d)to order the controller or processor to bring processing operations into compliance with the
provisions of this Regulation, where appropriate, in a specified manner and within a specified
period; […]
i)to impose an administrative fine pursuant to Article 83, in addition to, or instead of measures
referred to in this paragraph, depending on the circumstances of each individual case; […]"
108. Article 20(III) of the Law of 6 January 1978, as amended, provides that: “when the controller
or its processor does not comply with the obligations resulting from Regulation (EU) 27 of 2016
April 2016 or this Law, the President of the French Data Protection Authority may […] refer
the matter to the Restricted Committee of the authority with a view to pronouncing, after
adversarial proceedings, one or more of the following measures: […]
2° An injunction to bring the processing into compliance with the obligations resulting from
Regulation (EU) 2016/679 of 27 April 2016 or this law or to comply with requests made by the
data subject to exercise his/her rights, which may be accompanied, except in cases where the
processing is implemented by the State, by a penalty whose amount may not exceed €100,000
per day of delay from the date set by the Restricted Committee; […]
7° With the exception of cases where the processing is implemented by the State, an
administrative fine may not exceed €10m or, in the case of a company, 2% of the total global
annual revenue of the previous period, whichever is higher. In the cases referred to in Article
83(5) and (6) of Regulation (EU) 2016/679 of 27 April 2016, these ceilings are increased to
€20m and 4% of said revenue respectively. In determining the amount of the fine, the Restricted
Committee will take into account the criteria specified in Article 83.”
109. Article 83 GDPR further provides that “Each supervisory authority shall ensure that the
imposition of administrative fines pursuant to this Article […] shall in each individual case be
effective, proportionate and dissuasive”, before specifying the elements to be taken into account
in deciding whether an administrative fine should be imposed and in deciding the amount of
this fine.
110. In determining the amount of the fine, the Restricted Committee must therefore take into
account criteria such as the number of breaches, their nature and seriousness, the number of
data subjects and the financial benefits obtained as a result of the breach.
111. The company argues that its processing is legitimate, that the imposition of a fine is devoid of
grounds in the absence of breaches actually constituted and that the imposition of a fine would
be tantamount to refusing to take into account compliance measures that nevertheless exist. The
company then argues that the amount of the fine is disproportionate to the seriousness of the
breaches and the behaviour of which should constitute a "mitigating factor". Finally,
the company argues that the proposed injunction is devoid of purpose and that the publication
of the sanction would be counterproductive with regard to a company that has invested in an
approach to compliance with GDPR.
112. Firstly, the Restricted Committee recalls that, while the imposition of an administrative fine is
conditional on the establishment of a wrongful breach by the prosecuted body, this fault may
result from deliberate behaviour but also from negligence, pursuant to Article 83(2)(b) GDPR
(CJEU, Grand Chamber, 5 December 2023, Deutsche Wohnen SE et al., C-807/21; CJEU,
16
Grand Chamber, 5 December 2023, Nacionalinis visuomenės sveikatos centras prie Sveikatos
apsaugos ministerijos et al., C-683/21).
113. The Restricted Committee considers that, in the case in point, the breaches committed by the
company reveal a certain negligence on its part. Indeed, the Restricted Committee emphasises,
on the one hand, that the rules recalled in this deliberation are subject to constant interpretation
by the CNIL. For example, the Restricted Committee has already ruled on the right of access
by indicating that the information provided must be as precise as possible (CNIL, FR, 30
November 2022, Sanction, No SAN 2022-022), but also on the obligation of transparency by
considering that the information of persons whose contact details are processed by an email
only available in English does not meet the requirement to provide transparent information laid
down in Article 12 of the Regulation (CNIL, FR, 29 December 2023, Sanction, No SAN 2023-
023). On the other hand, the Restricted Committee notes that the multiplicity of breaches
demonstrates negligence in the implementation of the processing carried out by the company.
114. Secondly, the Restricted Committee considers that the criterion set forth in Article 83(2)(a)
GDPR relating to the nature, severity and duration of the breach should be applied, taking into
account the nature and scope of the processing and the number of data subjects.
115. The Restricted Committee notes first of all that the breaches of Articles 5(1)(e) and 6 GDPR
concern the fundamental principles of data protection and are thus likely to be subject to a fine
of up to €20m or 4% of the company’s annual revenue for the previous period – i.e. the
maximum amount set forth by the texts –, pursuant to Article 83(5) GDPR. In this respect,
Guidelines 04/2022 on the calculation of administrative fines under GDPR adopted on 24 May
2023 by the European Data Protection Board recall that “through this distinction, the legislator
gave an initial indication of the seriousness of the breach, in an abstract manner. The more
serious the breach, the higher the fine is likely to be” (point 50).
116. The Restricted Committee then notes, as it explained in paragraph 31 of this deliberation, that
the breaches of Articles 5(1)(e), 12 and 14 raised are likely to concern a significant number of
persons, the database comprising nearly 160 million contacts on the day of the hearing
inspection, since it is necessary to take into account all the contacts present in the
database, these being persons concerned by GDPR.
117. The Restricted Committee also emphasises that for persons who have decided not to display
their contact details on LinkedIn, the processing presents a particularly serious infringement of
the rights of persons insofar as it goes against their wish to keep this data private in order, in
particular, to solicit it, as corroborated by the various complaints received by the Commission
services.
118. This uncertainty, given the extent of the breach of the confidentiality of their data, is
superimposed on the disruption caused by these untimely solicitations, denounced by the
complainants in the referrals received by the Commission.
119. Finally, the Restricted Committee notes that the examination of complaints also highlights the
failure of the procedures for exercising rights implemented within the company, which does not
respond precisely to complainants wishing to know the source from which their contact data
was obtained indirectly.
120. Thirdly, the Restricted Committee intends to apply the criterion set forth in paragraph (k) of
Article 83(2) GDPR, relating to the financial benefits obtained as a result of the breach.
17
121. It notes, in this respect, that the company derives all its revenue from invoicing its customers
for a service whose operation is based in part on data collected unlawfully and, until 2022,
without the knowledge of the data subjects.
122. Thus the entire business model of the company is based on the violation of major provisions of
GDPR, in that the database from which its extension works was partly unlawfully constituted.
123. Fourthly, the Restricted Committee intends to take into account the measures taken by the
company to mitigate breaches, pursuant to Article 83(2)(c) GDPR. It appears that, following
receipt of the sanction report, the company implemented a new retention period with regard to
the data of users, and deployed, for the information email and the company’s privacy
policy, the possibility for the data subjects to choose the language of the text in French, Spanish,
Dutch or German.
124. The Restricted Committee considers that all these elements justify the imposition of an
administrative fine.
125. With regard to the amount of the fine, the Restricted Committee would point out that,
pursuant to Article 83 GDPR, the breaches identified may be subject to an administrative fine
of up to €20m or up to 4% of the worldwide annual revenue for the previous period, whichever
is higher.
126. It took the view that the company’s business and financial situation should be taken into
account. It notes in this respect that generated, for 2022, revenue of for a
profit of . The following year, this revenue came to , for a profit of
127. In view of the company’s liability, its financial capacity and the relevant criteria of Article 83(2)
GDPR referred to above, the Restricted Committee considers that a fine of two hundred and
forty thousand (240 000) euros appears justified.
128. With regard to the pronouncement of an injunction accompanied by a penalty, in his report
to the Restricted Committee, the Rapporteur proposes to pronounce a compliance injunction
against the company, accompanied by a penalty, for breaches of Articles 5(1)(e), 6, 12, 14 and
15 GDPR.
129. The company considers that the injunction measures proposed by the Rapporteur are devoid of
purpose, since the company has brought its processing into compliance to the best of its ability
given its resources.
130. Firstly, on the legal basis, the Restricted Committee notes that the company continues to
process data that has been collected in the absence of a valid basis.
131. Consequently, the Restricted Committee considers it necessary to issue an injunction so that
the company complies with the applicable obligations in this area.
132. Secondly, on the obligation to define and comply with a data retention period proportionate to
the purpose of the processing, the Restricted Committee notes that the company has not
18
indicated that it has put in place a policy of a proportionate retention period with regard to the
target persons.
133. Consequently, the Restricted Committee considers it necessary to maintain the injunction on
these points.
134. Thirdly, on the breach of the obligation to grant requests to exercise the right of access, the
Restricted Committee notes that the complainants have still not been informed of the precise
source of the data concerning them collected by the company.
135. Consequently, the Restricted Committee considers that the injunction is justified on this point.
136. Finally, with regard to the terms of the injunction with a penalty payment, the Restricted
Committee notes that in order to maintain its comminatory function in the penalty payment, its
amount must be both proportionate to the seriousness of the breaches committed and adapted
to the financial capacities of the controller. It also considers that in determining this amount,
account must be taken of the fact that the breach concerned by the injunction directly contributes
to the profits generated by the controller.
137. In view of these elements, the Restricted Committee considers as justified the imposition of a
penalty payment of €10,000 per day of delay and liquidated at the end of a period of six months.
138. With regard to the publication of the sanction, the Restricted Committee considers that this
is justified in view of the seriousness of some of the breaches in question, the company’s
position on the market, the scope of the processing operations and the number of data subjects.
139. It also notes that this measure is intended in particular to inform the persons concerned by the
processing implemented by the company, whether they are users of the extension or target
persons. This provision of information would enable them to assert their rights if necessary.
140. Lastly, it took the view that this measure was proportionate given that the decision would no
longer identify the company by name two years after publication.
CONSEQUENTLY
The Restricted Committee of the CNIL, after deliberation, decided to:
• impose an administrative fine on in the amount of two hundred and forty
thousand (240,000) euros in respect of the breaches constituted by Articles 5(1)(e),
6, 12, 14 and 15 of Regulation (EU) 2016/679 of the European Parliament and of
the Council of 27 April 2016;
• order against :
o with regard to the breach of Article 6 GDPR,
- cease the collection of contact data from users who have chosen
to limit the visibility of their contact details;
19
- delete all contact data imported when synchronising the LinkedIn
accounts of users who have chosen to limit the visibility of their contact
details or, failing this, if it is impossible to distinguish this data whose
visibility has been limited from other data, to inform them, in a period of
3 months, of the processing of their data and the possibility of objecting
to it and only use their data for this purpose ;
o With regard to the breach of Article 5(1)(e) GDPR,
in the case of the target persons, cease automatically renewing the five-
year retention period for the data of the target persons as soon as their
profile is updated and retain the data only for a period proportionate to
the processing;
o with regard to a breach of Articles 12 and 14 GDPR: inform the data subjects
of all the information set out in this article in a language they speak;
o with regard to the breach of Article 15 GDPR,
- respond to individuals’ requests for access rights by providing them with
all available information as to the source that enabled their contact data to be
uploaded to the company’s database;
- and grant the right of access requests of the persons at the origin of referrals
22011319, P44-4270, P44-9423, P44-34651, 23011826, 23011828, and
23006170 under the same conditions, before deleting the data relating to
referrals P44-9423, P44-34651, 23011826, 23011828, P44-3322 and 22011319.
• attach to the injunction a penalty of ten thousand euros (€10,000) per day of delay
at the end of a period of six months following notification of this deliberation, with
proof of compliance having to be sent to the Restricted Committee within this
period;
• make public, on the CNIL website and on the Légifrance website, its deliberation,
which would no longer enable the company to be identified by name at the end of a
period of two years from its publication.
The President
This decision may be appealed before the Council of State within two months of its notification.
20