# **Decision No MED-2025-009 of 9$^{th}$ January 2025 issuing an order to [REDACTED] and [REDACTED]**
(No MDM241066)
The President of the Commission nationale de l'informatique et des libertés (French Data Protection Authority),
Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of personal data and on the free movement of such data, in particular Articles 56 and 60;
Having regard to Law No 78-17 of 6 January 1978 on data processing, data files and individual liberties, as amended, in particular Article 20;
Having regard to Decree No 2019-536 of 29 May 2019, as amended, for the application of Law No 78-17 of 6 January 1978 on data processing, data files and individual liberties;
Having regard to deliberation No 2013-175 of 4 July 2013 adopting the internal regulations of the CNIL (French Data Protection Authority);
Having regard to decision No 2022-006C of 21 December 2021 of the President of the French Data Protection Authority to instruct the Secretary General to carry out or have carried out a mission to verify the processing carried out by [REDACTED] or by its subsidiaries, including in particular [REDACTED] and [REDACTED];
Having regard to online findings report No 2022-006/1 of 3 February 2022;
Having regard to on-site inspection report No 2022-006/2 of 22 March 2022;
Having regard to on-site inspection report No 2022-006/3 of 23 March 2022;
Having regard to online inspection report No 2022-006/4 of 19 January 2024;
Having regard to the other exhibits in the case file;
## **I. The procedure**
The [REDACTED] is the result of the merger of the [REDACTED] and [REDACTED] in 2016.
[REDACTED] (hereinafter “[REDACTED]”) is a public limited company with a board of directors, subsidiary of the holding company [REDACTED], whose activity is the distribution and dissemination of all goods or services intended for the home, leisure, education, training and information. The legal, technical and marketing teams working on the implementation of the websites of the [REDACTED] and [REDACTED] are pooled within [REDACTED], including the management of information systems.
is a simplified joint stock company subsidiary of , itself a subsidiary of . publishes and operates the website .
and (hereinafter '') are both located at .
In 2021, generated revenue of , and generated revenue of
The jointly assume responsibility for the processing carried out from the website and the ' ' mobile app. The relationship is governed by a data protection agreement signed on 19 January 2022.
In May 2021, the French Data Protection Authority (hereinafter referred to as "CNIL") received a complaint about the impossibility of deleting an customer account.
Pursuant to my decision No 2022-006C of 21 December 2021, a delegation from the CNIL carried out, on 3 February 2022, an online inspection mission, then, on 22 and 23 March 2022, an on-site inspection mission with , at the premises of the parent company, , in order to verify the compliance of the processing with all the provisions of the French Data Protection Act of 6 January 1978 (hereinafter the "French Data Protection Act") and Regulation 2016/679 of 27 April 2016 (hereinafter "GDPR").
Subsequently, the provided the delegation with additional information in particular by letters dated 11 March, 4 April, 30 May and 25 November 2022, as well as 5 July 2023.
In November 2023, the CNIL received further complaints about the presence of pre-ticked boxes when registering on the website, as well as in the account settings, authorising the sharing of users' personal data with partners.
A CNIL delegation then carried out an online inspection mission on 19 January 2024, following which the provided additional information by letter of 1 March 2024.
On 21 November 2024, as part of the cooperation procedure, a draft decision was submitted to the authorities concerned on the basis of Article 60 GDPR.
This draft decision did not give rise to any relevant or reasoned objections.
## II. On the breaches of GDPR
### 1- A breach of the obligation to carry out fair and transparent processing of data
In law, Article 5(1)(a) GDPR provides that "Personal data shall be [...] processed lawfully, fairly and in a transparent manner in relation to the data subject ('lawfulness, fairness and transparency')."
2
In addition, Recital 39 GDPR specifies that “Any processing of personal data should be lawful and fair. It should be transparent to natural persons that personal data concerning them are collected, used, consulted or otherwise processed and to what extent the personal data are or will be processed. The principle of transparency requires that any information and communication relating to the processing of those personal data be easily accessible and easy to understand, and that clear and plain language be used. That principle concerns, in particular, information to the data subjects on the identity of the controller and the purposes of the processing and further information to ensure fair and transparent processing in respect of the natural persons concerned and their right to obtain confirmation and communication of personal data concerning them which are being processed. Natural persons should be made aware of risks, rules, safeguards and rights in relation to the processing of personal data and how to exercise their rights in relation to such processing. [...]”
# A) On the transmission by the [REDACTED] of their customers’ postal contact details to third-party data brokers
In the case in point, the [REDACTED] informed the delegation, during the on-site inspection of 22 March 2022, that they transmitted “the postal addresses and phone numbers related to the user accounts of the [REDACTED] website to data brokers belonging to the [REDACTED], i.e. [REDACTED] and [REDACTED]”, adding that “once the account was created, the person’s phone and postal contact details may be sent to data brokers”. [REDACTED] subsequently specified that the data sent to [REDACTED] concerned only data relating to customers who made a purchase.
In addition, the [REDACTED] indicated that in 2021, they had sent information to data brokers concerning approximately 15 million people with a [REDACTED] account and on more than 25 million transactions. The data provided included the last name, first name, postal address, phone number, date of birth, landline and mobile phone numbers, and the categories of products purchased from the brand.
With regard to information on the transmission on the one hand, the delegation noted during the online inspection of 19 January 2024 that at the account creation stage, the web page included in the first part an insert, a predominant visual element, in which the user was invited to enter his/her last name, first name and password. In the second part of this insert, there was a text containing various information notices.
The insert contained four boxes through which the user could express certain choices, including a checkbox and two pre-checked boxes enabling him/her to agree, in particular, to receive personalised offers from the [REDACTED]’s business partners by text message, to be contacted by the partners of the [REDACTED] for offers by phone, and to share his/her customer profile with the partners of [REDACTED] to benefit from personalised offers.
3

Thus, at this stage, only prospecting by phone and email was expressly addressed with regard to the transmission of data to partners for commercial prospecting. In this insert, the user did not have information on the other prospecting channels likely to be used by the partners of
Prospecting by post was only dealt with on a secondary basis.
It was thus mentioned, under this main insert, among other information notices: “configure the main uses of your data here and find all the choices available to you in the personal data preference manager accessible at any time in your account. If you have not opposed it [...], your customer profile may also be shared with advertising partners, as well as for telephone and postal prospecting.”
It was also mentioned during an online purchase, once the account had been created and the choices relating to commercial prospecting had been made. Thus the page on which the user entered his/her address for delivery mentioned the sharing of this address with “partners”, “for telephone and postal prospecting purposes”, depending on his/her choices expressed when creating the account or in his/her preferences manager. Users were also invited to go to the “my preferences” section of their account to “express [their] choices on the use of [their] data”.
# Ajouter cette adresse
En fonction des choix exprimés à la création du compte ou dans le gestionnaire de préférences du compte fnac.com vos coordonnées principales (Adresse de livraison par défaut) peuvent être utilisées à des fins de prospection téléphonique ou postale et partagées avec des partenaires. Pour exprimer vos choix sur l'usage de vos données rendez-vous dans votre compte rubrique «Mes préférences». Vous pouvez également exercer vos droits RGPD depuis la Politique de protection des données personnelles.
4
The information provided to website users when creating their account relating to the transmission of their data to brokers for commercial prospecting by post, thus dispersed, was not clear or easily accessible.
**With regard to the objection to processing on the other hand**, the user wishing to object to this transmission could uncheck the corresponding boxes in the main insert.
Nevertheless, it emerged from the inspection report that, even after unticking these boxes, and in particular the box with the general heading “I agree that my customer profile may be used within the [REDACTED] and shared with its partners to benefit from a personalised offer”, the possibility of prospecting by post remained activated in the preferences management section on the user’s account. The right to object open to users was therefore not effective.

However, a user who had unticked said boxes once his/her account was created might legitimately expect not to have to express his/her objection once again in the preference manager, both at the account creation stage and at the time of any subsequent purchase on the website.
Therefore, although the [REDACTED] indicated, by letter of 1 March 2024, that the fact of objecting to the sharing of profiles to third parties, by the unticking of the corresponding box, led to an entry on a push-back list concerning “Address company” and “[REDACTED]” having the effect of excluding the user from the lists of shared contact data, the user was not in fact able, when collecting his/her data, to effectively object to its transmission to commercial partners.
It follows from all these elements that the [REDACTED] did not fairly and lawfully process the data of users who had created an account on the website [REDACTED], in breach of the provisions of Article 5(1)(a) GDPR.
# B) On commercial prospecting by the [REDACTED] by post
In the case in point, with regard to information on prospecting by post, on the one hand, it emerged from the online inspection of 19 January 2024 that, when creating an account, the check boxes to be ticked/pre-ticked in the main insert, by which the user expressed his/her choices relating to commercial prospecting, expressly mentioned prospecting by email and text message from the [REDACTED] (see extract above). Similarly, a mention under this insert
5
indicated that: “if you have not objected to it, you will receive information and commercial offers concerning products and services”.
Thus, at the account creation stage, postal services were not expressly cited as prospecting channels likely to be used by .
Prospecting by post was only mentioned later, during an online purchase, once the account had been created and the choices relating to prospecting expressed by the user (see extract above).
It follows from the above that the information provided to the user concerning commercial prospecting by post was not clear or easily accessible.
With regard to opposition to commercial prospecting by post, on the other hand, a user who had expressed his/her opposition to such prospecting by , when creating his/her account, might legitimately expect his/her data not to be subsequently used by for commercial prospecting by post, even if he/she had also been informed of the possibility of configuring his/her choices through the preferences manager of his/her user account.
However, it emerged from the aforementioned online inspection report that mail prospecting was kept activated in the preference manager, even though the user has expressed his/her opposition to commercial prospecting, in general, when creating his/her account.

Similarly, during an online purchase during which the user entered his/her postal delivery data, he/she might legitimately expect not to be the subject of subsequent commercial prospecting by the , since he/she had objected to it when creating his/her account, without having to express his/her choices again in his/her preferences manager.
Thus users were not able to effectively object to the use of their data, when it was collected, for prospecting by by post.
Consequently, the companies did not fairly and transparently process the data of users of the website, in breach of the provisions of Article 5(1)(a) GDPR.
# 2- A breach of the obligations relating to processing (Article 28 GDPR)
In law, Article 28(3) GDPR provides that any processing carried out by a processor must be governed by a contract, concluded between the controller and the processor, which binds both parties, “sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller”. This contract must therefore provide for a set of mandatory information, detailed in points (a) to (f) of the same article.
6
**In the case in point**, the delegation was informed that [REDACTED] used more than one processor, and in particular [REDACTED] (formerly [REDACTED]) for the provision of a software package to manage prospecting campaigns, the support and maintenance of this tool, as well as [REDACTED] for the provision of a [REDACTED] predictive analysis solution enabling in particular the segmentation of the populations targeted by the prospecting campaigns.
It follows that [REDACTED] and [REDACTED] process the personal data of the data subjects on behalf of [REDACTED] and [REDACTED] and, as such, have the capacity of the latter’s processor.
Many of the mentions set forth in Article 28(3) GDPR are missing from these contracts, namely the nature of the processing, the type of personal data processed, the categories of data subjects, the obligation of the processor to carry out audits by the controller, and the provision of information to the controller by the processor in the event of an instruction constituting a breach of GDPR or other provisions of Union or Member State data protection law.
In particular, the contract concluded with [REDACTED] did not contain any information relating to the assistance of the controller required by Article 28(3) GDPR in terms of data protection impact assessments, in terms of the follow-up given to requests made by data subjects to exercise their rights, as well as in terms of notification of personal data breaches to the supervisory authority, or provisions relating to processing as set out in Article 28(4) GDPR.
The aforementioned facts constitute a breach of the obligations set forth in Article 28 GDPR.
### 3- Failure to ensure data security (Article 32 GDPR)
**In law**, Article 32 GDPR requires the controller, “*[t]aking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk*”, in particular by ensuring “the ongoing confidentiality, integrity, availability and resilience of processing systems and services”.
It follows from this article that the controller must store user passwords securely, in order to avoid its compromise and to protect the personal data that may be consulted and collected by accessing the accounts.
In the current state of the art, the Commission has established specific recommendations in its developer guide,$^{1}$ recommending that passwords be stored “in hash form using a proven library, such as Argon2, yescrypt, scrypt, balloon, bcrypt and, to a lesser extent, PBKDF2.” On the other hand, the SHA-1 algorithm is a hash function subject to known vulnerabilities that can be exploited immediately by attackers. It therefore does not guarantee the security of the data concerned. Similarly, the SHA-256 algorithm is a function that is not designed for storing passwords, and does not guarantee the security of the data concerned.
$^{1}$ CNIL. GDPR Guide to Developing Their, v2, 13 December 2021, sheet 6, https://lincnil.github.io/Guide-RGPD-du-developpeur/
7
In addition, the controller is required to ensure that the automated data processing it implements is sufficiently secure. The sufficiency of the security measures is assessed (a) with regard to the characteristics of the processing and the risks it entails, and (b) with consideration of the state of knowledge and the cost of the measures.
**In the case in point, firstly**, the delegation was informed that the passwords of [REDACTED] user accounts were stored with the SHA-1 or SHA-256 hashing functions. An algorithm change was made to replace the SHA-1 function with the SHA-256 function. Thus, during the on-site inspection, the Delegation found that 32,485,327 passwords had been hashed with the SHA-1 algorithm and that 22,775,918 passwords had remained hashed with the SHA-256 function.
In a letter of 4 April 2022, the [REDACTED] indicated that the change of hash for the SHA-256 function had taken place on 28 March 2019 and that it could only be carried out when the customer was re-authenticated on the site [REDACTED]. They stated that they were developing a project (CIAM project) to strengthen account security by ensuring constant maintenance of authentication methods for customers and optimised security and, in the meantime, accelerating the algorithm change for passwords stored with the remaining SHA-1 hash function. In their letter of 30 May 2022, the [REDACTED] planned to reset all the remaining accounts by mid-July 2022. In their letter of 5 July 2023, the [REDACTED] did not provide any information or element that would make it possible to confirm this.
In any event, it follows from the above that the storage of passwords within the database of the companies’ website does not comply with the state of the art on the date of this decision, whether it is the SHA-1 or SHA-256 hashing function.
Therefore, it is up to the [REDACTED] to store passwords using a proven hash algorithm, such as those cited in the Commission’s developer guide.
**Secondly**, during the online observations, the delegation found that the HTTPS configuration of the web server of the website [REDACTED] used a TLS 1.2 protocol version of which several cryptographic suites used the SHA-1 hashing function.
However, the evolution of processors and in particular their speed of calculation has led to a weakening of the robustness of certain cryptographic algorithms. For example, recent attacks have highlighted proven vulnerabilities that facilitate the decryption of encrypted data by malicious actors.
In the current state of the art, the ANSSI has drawn up a guide to recommendations relating to TLS,[3] which states that “the hash functions of the SHA-2 family must be used” in the TLS protocol.
Therefore, the cryptographic suites used by the [REDACTED] do not comply with the state of the art and therefore do not meet the current security requirements.
[3] ANSSI. TLS security recommendations, 23 May 2022, https://cyber.gouv.fr/sites/default/files/2017/07/anssi-guide-recommandations_de_securite_relatives_a_tls-v1.2.pdfhttps://cyber.gouv.fr/sites/default/files/2017/07/anssi-guide-recommandations_de_securite_relatives_a_tls-v1.2.pdf
8
Such a security requirement is all the more justified given the large volume of data processed by the [REDACTED] through their website, as well as the sensitive nature of certain data item contained in the customer file.
Indeed, the [REDACTED] indicated that they had recorded, in mainland France, more than 12 million visits to the website [REDACTED] of users with a [REDACTED] account, according to their billing address. In addition, the customer file may in particular contain their bank details, which they may choose to save when making a payment on the website.
Consequently, with regard to the personal data processed by the [REDACTED] and the risks incurred by persons in the event of a breach, the [REDACTED] are asked to ensure secure client-server communications, in particular by using only the hashing functions recommended by the ANSSI and mentioned above.
These facts constitute a breach of the provisions of Article 32 GDPR, in that the technical measures implemented do not guarantee an appropriate level of security.
Consequently, [REDACTED] and [REDACTED], located at [REDACTED] are issued an order within three (3) months of notification of this decision and subject to the measures that they may have already adopted, to:
- Stop sending brokers the data collected in accordance with the procedures established online by the CNIL on 19 January 2024, or regularise the information provided to users of the [REDACTED] website once their data is collected, and put in place a mechanism enabling their right to object to prospecting by post to be effectively taken into account;
- formalise the relationship between them and their service providers by concluding processing contracts in accordance with the provisions of Article 28(3) and (4) GDPR;
- take measures to preserve the security of the personal data processed and to prevent unauthorised third parties from gaining access to it, in accordance with Article 32 GDPR:
- using a public hash algorithm known to be strong and suitable for storing passwords whose software implementation is free of known vulnerabilities to store the passwords of users who are not yet securely stored;
- ensuring that only cryptographic chains using secure algorithms are authorised for the use of the HTTPS protocol on the website [REDACTED];
- prove to the CNIL that all the aforementioned requests have been complied with within the allotted time.
At the end of this period, if the [REDACTED] have complied with this order, it will be considered that this procedure is closed and a letter will be sent to them to this effect.
9
Conversely, if they have not complied with this order, it is recalled that a Rapporteur may be appointed to request that the Restricted Committee impose one of the sanctions set forth in Article 20 of the Law of 6 January 1978 as amended.
The President
Marie-Laure Denis
10