Decision No MED-2025-001 of 6 January 2025 issuing an
order
(No MDM241025)
The President of the Commission nationale de l'informatique et des libertés (French Data
Protection Authority),
Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of
27 April 2016 on the protection of personal data and on the free movement of such data;
Having regard to the French Postal and Electronic Communications Code;
Having regard to Law No 78-17 of 6 January 1978 on data processing, data files and individual
liberties, as amended, in particular Article 20;
Having regard to Decree No 2019-536 of 29 May 2019 implementing Law No 78-17 of 6
January 1978 on data processing, data files and individual liberties;
Having regard to deliberation No 2013-175 of 4 July 2013 adopting the internal regulations of
the CNIL (French Data Protection Authority);
Having regard to Decision No 2023-017C of 21 December 2022 of the President of the French
Data Protection Authority to instruct the Secretary General to carry out, or instruct others to
carry out, verification of the processing of personal data implemented by or on behalf of the
company ;
Having regard to the other exhibits in the case file;
I. On the procedure
(hereinafter "the company"), located at ,
, is a single-member simplified joint stock company created in 1963
whose activity is the distance selling via a specialised catalogue of ready-to-wear articles,
decoration and games for children and pregnant women.
In 2022, the company had 901 employees and achieved revenue of 315,859,889 euros and a net
profit of 11,446,983 euros.
The company, whose main establishment is located in France, publishes several websites for
people located in Belgium, Spain, France, Portugal and the Netherlands. It is responsible for
the processing that it implements on its behalf in the context of commercial prospecting sent to
its customers who have made at least one purchase, by email, SMS, post and alert messages
sent from the wallet apps available on smartphones. It also carries out commercial prospecting
by email to its prospects, i.e. any person who has created an account on the website without
making a purchase, who has registered for the newsletter, who has participated in a competition
organised by the company or whose electronic contact details have been sent by a partner who
has obtained consent.
Pursuant to Decision No 2023-017C of 21 December 2022 of the President of the CNIL, a
delegation from the CNIL carried out, on 23 February 2023, an online inspection mission, then
on 1 March 2023, an on-site inspection mission with the company located at
in order to verify the compliance of the processing carried
out by the latter with all the provisions of Law No 78-17 of 6 January 1978 on information
technology, files and freedoms, as amended (hereinafter the “LIL” or the “French Data
Protection Act”) and Regulation (EU) 2016/679 of the European Parliament and of the Council
of 27 April 2016 (hereinafter the “Regulation” or “GDPR”), and Law No 78-17 of 6 January
1978 as amended and, where applicable, the provisions of the French Postal and Electronic
Communications Code.
Following the inspection, the company provided the delegation with the requested information
by email of 10 March 2023.
II. Application of the cooperation and consistency mechanism
In accordance with Article 56 GDPR, on 26 October 2023 the CNIL informed all the European
supervisory authorities of its competence to act as lead supervisory authority for cross-border
processing carried out by the company, a competence derived by the CNIL from the fact that
the company had its sole establishment in France.
After exchanges between the CNIL and the European data protection authorities within the
framework of the one-stop-shop mechanism, the following authorities are concerned:
Netherlands, Luxembourg, Italy, Belgium, Portugal and Spain.
Pursuant to Article 60(3) GDPR, the President's draft decision was forwarded to the relevant
European supervisory authorities on 11th April 2024.
As of 9th May 2024, none of the supervisory authorities concerned had raised any relevant and
supported objection to this draft decision, and therefore, pursuant to Article 60(6) GDPR, the
latter are deemed to have approved it.
III. As a preliminary point, on the improvements made within the privacy policy
In law, Article 13 GDPR requires the controller to provide the data subject with various items
of information relating in particular, in the case in point, to the retention period of the data
concerning him/her.
In the case in point, the delegation noted during the on-site inspection of 1 March 2023 that
the privacy policy informs users of its website that the retention period for prospective data is
five years whereas in practice the company retains it for a period of three years. Thus users are
not properly informed of the retention period actually applied to the data.
I take note of the change made to the information notices relating to the retention period
contained in the privacy policy, which now clearly show the retention periods for customer and
prospective customer data.
2
I consider that these measures are likely to ensure accurate information on the processing that
the company carries out in the context of its commercial prospecting activity.
IV. Breaches of GDPR
A. Failure to comply with the obligation to define and store data for a period of time
proportionate to the purpose of the processing (Article 5(1)(e) GDPR)
In law, Article 5(1)(e) GDPR states that personal data must be “kept […] in a form which
permits identification of data subjects for no longer than is necessary for the purposes for which
the personal data are processed”.
Under the aforementioned provisions, the length of time personal data is kept must be
determined according to the purpose for which it is processed. Once this purpose has been
fulfilled, the data must in principle be deleted, anonymised or archived as an interim measure,
where retention is necessary to comply with legal obligations or for pre-litigation or litigation
purposes. The effective implementation of a data retention policy is the necessary counterpart
to its definition, and ensures that data is kept in a form that enables data subjects to be identified
for no longer than is necessary for the purposes for which it is processed. In particular, this
makes it possible to reduce the risks of unauthorised use of the data in question, by an employee
or by a third party (CNIL, FR, 29 October 2021, Sanction, X, No SAN-2021-019, published,
points 56-57).
The CNIL indicates in its reference framework relating to the processing of personal data
implemented for the purposes of managing commercial activities1 that data relating to
customers used for commercial prospecting purposes may be retained during the commercial
relationship, then for a period of three years from the end of this relationship. It also indicates
that data relating to prospects and which is also used for prospecting purposes may be retained
for a period of three years from its collection or the last contact from the prospect.
In the case in point, the delegation was informed that the company retains for a period of five
years the data of its customers and for a period of three years the data of its prospects after their
last activity corresponding to a click on a link in an email, a purchase, logging in to the customer
account or responding to a questionnaire.
The delegation noted in the company's database the presence of 225,603 prospects whose last
contact date was more than three years old, and 3,105 customers whose last contact date was
more than five years old. When questioned on this point, the company justifies this discrepancy
by the fact that several people have both a customer account and are registered in the newsletter.
It specifies that in the event of duplication, it uses the activity of the most recent user to
determine the retention period of his/her data over three or five years.
The company informed the delegation that among the 225,603 prospects present in the active
database, 61,017 accounts should have been deleted since the last action was registered more
than three years ago.
1
https://www.cnil.fr/sites/cnil/files/atoms/files/referentiel traitements-donnees-caractere-personnel gestion-
activites-commerciales.pdf
3
It was noted in January 2024 that the privacy policy accessible from the company's website
clearly informs the user of these three- and five-year retention periods for prospect and customer
data.
It follows from the foregoing that the company does not apply its own privacy policy by keeping
in an active database data belonging to customers who have not placed an order or made an in-
store purchase for more than five years, as well as the data of tens of thousands of prospects
inactive for more than three years.
However, the retention in an active database of data belonging to former customers and inactive
prospects for periods of more than five and three years respectively is excessive with regard to
the purposes for which it was collected.
All these facts constitute a breach of Article 5(1)(e) GDPR.
Therefore, the company must apply the retention periods defined in its privacy policy, and must
effectively delete data that is not necessary for the purposes for which it was processed.
B. A breach of the obligation of transparency and the obligation to inform individuals
(Articles 12 and 13 GDPR)
In law, Article 12(1) GDPR provides that “[t]he controller shall take appropriate measures to
provide any information referred to in Articles 13 and 14 and […] relating to processing to the
data subject in a concise, transparent, intelligible and easily accessible form, using clear and
plain language […] The information shall be provided in writing, or by other means, including,
where appropriate, by electronic means.”
Article 13 GDPR requires controllers to provide data subjects with a range of information at
the time their data is collected, in particular concerning their identity and contact details, the
purposes of the processing operation, its legal basis, the recipients or categories of recipients of
the data, and the fact that the controller intends to transfer the data to a third country. The
regulation also requires that, where it appears necessary to ensure “fair and transparent
processing” of personal data, that individuals are informed about the period of data retention,
the existence of the various rights enjoyed by individuals, the existence of the right to withdraw
consent at any time, and the right to lodge a complaint with a supervisory authority.
Furthermore, the CNIL2 recalls that when an organisation wishes to transmit personal data so
that its partners can carry out commercial prospecting, the data subjects must be informed and
able to object in a simple and free manner to the transmission of their data. It specifies that this
information must include information on the purpose of this transmission as well as on the
categories of data recipients in order to enable the data subjects to make a choice in full
knowledge of the facts.
In this respect, the CNIL recommends providing data subjects with an exhaustive and up-to-
date list of partners, including their identity and a link to the privacy policy of each partner.
1. On information relating to the rights of individuals
2
Prospecting for individuals (B to C): what are the rules for transmitting data to partners?
4
In the case in point, the delegation noted that the company’s privacy policy does not mention
the right for data subjects to lodge a complaint with a supervisory authority.
However, information relating to the right to lodge a complaint with the CNIL is one of those
to be communicated at the time of data collection in that it makes it possible, in the case of
processing involving commercial prospecting operations, to ensure fair and transparent
processing of the personal data of data subjects and that it facilitates their exercise and thus
contributes to ensuring control over the processing of their data.
These facts constitute a breach of Articles 12 and 13 GDPR.
Therefore, the company must inform the user of the right to lodge a complaint with a
supervisory authority.
2. On the information relating to commercial prospecting carried out by post
Firstly, with regard to the information provided to customers, the delegation noted that, during
its online purchasing process, customers are informed of the processing of their data for
prospecting purposes and of the right they have to object to it by clicking on the link of the
privacy policy located at the foot of the website.
It follows from the foregoing that the client is not directly informed, by means of a first level
of information, of the reuse of his/her data for prospecting purposes at the time it is collected,
nor of the right he/she has to object to it since it is up to him/her to search for the information
in the privacy policy accessible at the bottom of the website page.
However, the information is only satisfactory when the data subjects are informed before the
use of their data for prospecting purposes and are able to object to this use as soon as the data
is collected. This information may take the form, for example, of a tick box, accompanied by
the following message: “I object to my postal address being used to receive offers from
”.
Therefore, the company must provide its customers, at the time of data collection, with an initial
level of information relating to its reuse for prospecting purposes and the right they have to
object to it.
Secondly, with regard to the information relating to the transmission of customer data to
partners, the delegation noted that the information relating to this transmission is mentioned in
Article 2.3 of the privacy policy in these terms: “Unless you object when collecting your data,
may also share your personal data […] with ’s business
partners (including other group brands) who may send you their commercial
offers by post or email, if you have explicitly accepted it.”
It follows from the foregoing that the company does not satisfactorily provide the data subjects
with the information that it is required to communicate to them at the time of collecting the
data, provided the customer is not informed of its transmission to third parties and of the right
it has to object to it by seeking the information itself within the privacy policy. This information
may take the form, for example, of a tick box, accompanied by the following message: “I object
to my data being sent to ’s partners for commercial prospecting purposes”.
All these facts constitute a breach of Articles 12 and 13 GDPR.
5
Therefore, the company must provide its customers, when collecting their data, with an initial
level of information relating to the transmission of their postal and email addresses to its
partners for the sending of commercial offers as well as the right to object to them.
C. On the breach of the obligation to respect the right to object (Article 21 GDPR)
In law, Article 21 GDPR provides that “2. “Where personal data are processed for direct
marketing purposes, the data subject shall have the right to object at any time to processing of
personal data concerning him or her for such marketing, which includes profiling to the extent
that it is related to such direct marketing.
[…]
4. At the latest at the time of the first communication with the data subject, the right referred to
in paragraphs 1 and 2 shall be explicitly brought to the attention of the data subject and shall be
presented clearly and separately from any other information.”
In the case in point, the company informed the delegation that, in the context of the prospecting
it carries out by post and on its behalf with its customers, the latter may neither object to the
processing of their data for this purpose nor to their transmission to the company’s partners
other than by contacting the department in charge of the customer relationship by telephone.
The company specifies that data subjects may not express their objection from their customer
space or during their online shopping journey.
It follows from the foregoing that customers have the possibility to exercise their right to object
to the reuse and transmission of their data for commercial prospecting purposes by calling
customer service, after the processing has been carried out and once the data has been
transmitted to the company’s partners.
However, the company that reuses customer data and sends it to its partners for the sending of
commercial offers must allow the data subjects to easily object to this processing when
collecting the data and at any time by, for example, a tick box accompanied by the following
information message: “I object to my postal contact details and/or email address being sent to
the partners of for commercial prospecting purposes”.
These facts constitute a breach of Article 21 GDPR.
Therefore, the company must allow customers to object easily and at any time, including before
the processing of data for these purposes when collecting data, to the processing of their data
for prospecting purposes.
D. Failure to ensure data security (Article 32 GDPR)
In law, Article 32 GDPR requires that the controller, “[t]aking into account the state of the art,
the costs of implementation and the nature, scope, context and purposes of processing as well
as the risk of varying likelihood and severity for the rights and freedoms of natural persons,
[…] implement appropriate technical and organisational measures to ensure a level of security
appropriate to the risk”.
6
It follows from these provisions that the controller must store user passwords in a sufficiently
secure manner in order to avoid their compromise and to protect the personal data that may be
consulted and collected by accessing the databases.
In this respect, in its deliberation No 2022-100 of 21 July 2022 adopting a recommendation
relating to passwords and other shared secrets – which is certainly not imperative but which
provides relevant clarification on the measures to be taken in terms of security – the
Commission recommends that, in order to ensure a sufficient level of security and
confidentiality, any password useful for the verification of authentication must, before its
retention, be previously transformed by means of a specialised, non-reversible and secure
cryptographic function (i.e. using a reputable public algorithm whose software implementation
is free of known vulnerability), integrating a "salt" and parameters relating to the time and/or
memory costs required to attack it.
In the case in point, the delegation noted that the passwords of users of the website
are stored encrypted with the Advanced Encryption Standard (AES) algorithm, and that the
unique encryption key is contained in the company’s information system accessible to
developers.
However, the encryption of passwords is not sufficient to guarantee their confidentiality since
they can be decrypted and accessible in clear text by anyone with the encryption key. Thus a
data breach within the company’s information system could result in the disclosure of the
usernames and passwords of all users with an account on the company’s website.
It follows from the foregoing that by storing the encrypted user passwords as it does, i.e. by
means of an encryption key allowing any person with knowledge of this key to access the
password and therefore all the information contained in the user accounts, the company has not
put in place the necessary protection mechanisms aimed at ensuring a sufficient level of security
and confidentiality of the data present in its information system.
All these facts characterise a breach of Article 32 GDPR.
Therefore, the company will have to put in place a binding policy for the secure storage of user
passwords by transforming them using a non-reversible and secure hash function, incorporating
the use of a salt or key.
E. Failure to comply with the obligations set out in Article 82 of the French Data
Protection Act
In law, Article 82 of Law No 78-17 of 6 January 1978 on data processing, files and freedoms,
as amended, provides that “Any subscriber or user of an electronic communications service
must be informed in a clear and complete manner, unless he/she has been informed in advance,
by the controller or his/her representative: 1° The purpose of any action aimed at accessing,
by electronic transmission, information already stored in its electronic communications
terminal equipment, or recording information in this equipment; 2° The means at its disposal
to object to it. Such access or registration may only take place if the subscriber or user has
expressed, after receiving this information, his/her consent, which may result from the
appropriate settings of his/her connection device or any other device under his/her control.
These provisions are not applicable if access to the information stored in the user's terminal
7
equipment or registration of information in the user's terminal equipment: 1° Either, has the
exclusive purpose of enabling or facilitating communication by electronic means; 2° Or, is
strictly necessary for the provision of an online communication service at the express request
of the user.”
These provisions transpose into French law Article 5(3) of Directive 2002/58/EC of the
European Parliament and of the Council of 12 July 2002 on the processing of personal data and
the protection of privacy in the electronic communications sector (known as the "e-Privacy
Directive").
1. Failure to inform data subjects
In law, it follows from the combined provisions of Articles 82 of the French Data Protection
Act and 4.11 of General Regulation 2016/679 on data protection (GDPR) that trackers requiring
consent may only, subject to the exceptions provided for by these provisions, be used in writing
or reading mode provided the user has consented to it by positive action and in a free, specific,
unambiguous and informed manner. The validity of the consent is therefore linked in particular
to the quality of the information received.
By way of clarification, the guidelines of 17 September 2020 of the CNIL, the purpose of which
is to recall and explain the applicable law, relating to the application of Article 82 of the French
Data Protection Act to reading and/or writing operations on a user’s terminal (in particular to
“cookies and other trackers”), provides that “the information must be written in simple terms
that are understandable by all and that it must allow users to be duly informed of the different
purposes of the trackers used […]. The information must be complete, visible and highlighted.
A simple reference to the general terms and conditions of use cannot be sufficient” (§§ 22 and
23). The CNIL adds that “At least, the provision of the following information to users, before
obtaining their consent, is necessary to ensure the informed nature of the latter: the identity of
the controller(s) responsible for processing read or write operations, the purpose of the data
read or write operations, the manner of accepting or refusing trackers, the consequences
associated with a refusal or acceptance of trackers, the existence of the right to withdraw
consent” (§24).
The Commission indicates, by way of illustration, in the questions and answers on the amending
guidelines and the “cookies and other trackers” recommendation of the CNIL of 4 November
2022 that “in order for the user’s consent to be informed, all the information recalled in Article
2 of the “cookies and other trackers” guidelines must be available when collecting their choice.
It is recommended, on the first level of information, to clearly indicate the purposes of cookies,
to allow the user to access the list of controllers via, for example, a hypertext link or a button
accessible from the first level of information, to inform him/her of the possibility of withdrawing
consent at any time and, where relevant, of the consequences resulting from a refusal of
cookies.”
In the case in point, the delegation noted that the consent collection banner on the website only
mentions: “In order to provide you with an optimal experience, we and our selected partners
use cookies or similar technologies to improve our site and display personalised content as well
as essential features. Click on ‘Find out more’ for more information.” The delegation also noted
that by clicking on the “find out more” button located at the bottom of the information banner,
users are only informed of the purposes of reading and writing trackers on their terminal.
8
However, this information statement does not provide clear and complete information to the
user.
While it is possible to complete the information appearing at the first level via a hypertext link
to the privacy policy that identifies each controller involved and informs of the possibility of
withdrawing their consent to read and write operations, the fact remains that the information in
the consent collection banner must be sufficiently clear to allow the user to make an informed
choice at this stage.
In this case, the terms used are particularly imprecise. They do not make it possible to identify
the identity of all the controllers involved in the reading and writing operations on the user's
equipment, who is then unable to know the consequences of his/her choice at the time he/she
consents to these operations, or to inform the user of the right to withdraw his/her consent at
any time.
In addition, the referral made does not provide this information either when the user accesses
the information contained in the privacy policy, only after having consented to the deposit of
cookies on his/her terminal equipment.
These facts constitute a breach of Article 82 of the French Data Protection Act.
Therefore, the company must inform the data subjects at the time of obtaining their consent of
the identity of the partners on whose behalf trackers are deposited as well as the means at their
disposal to be able to withdraw their consent.
2. The lack of free consent of the user to the deposit of cookies
In law, the CNIL recalls that, in accordance with Article 2(f) of the aforementioned Directive
2002/58/EC, the consent given by a user or subscriber of an electronic communication service
to the deposit of a cookie must be understood according to the meaning given to this concept
by Directive 95/46/EC of the European Parliament and of the Council, of 24 October 1995, on
the protection of natural persons with regard to the processing of personal data and on the free
movement of such data, repealed on 25 May 2018 and since replaced by GDPR.
Article 4(11) GDPR states that consent is "‘any freely given, specific, informed and
unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a
clear affirmative action, signifies agreement to the processing of personal data relating to him
or her;" (emphasis added).
In this respect, Recital 42 GDPR, which clarifies the scope to be given to the concept of consent,
specifies that: “[c]onsent should not be regarded as freely given if the data subject has no
genuine or free choice or is unable to refuse or withdraw consent without detriment”.
For clarification purposes, the CNIL recommends in its deliberation No 2020-092 of 17
September 2020 on cookies and trackers that “each purpose is highlighted in a short and
highlighted title, accompanied by a brief description”. The CNIL adds that it is recommended
“to include, in addition to the purposes presented on the first screen, a detailed description of
these purposes, in a manner easily accessible from the consent collection interface”.
In the case in point, the delegation noted that the second screen of the cookie information
banner on the website offers the user to consent or refuse the “personal cookies &
9
AB Test” purpose. The delegation has been informed that the tool used by the company for the
deposit of trackers on the user’s terminal has a dual purpose which is, on the one hand, to offer
the user of the website the possibility of customising the navigation or display according to the
data he/she has previously entered (age of children) or according to his/her browsing and
purchase history, and, on the other hand, to measure the performance of the different versions
of the website. The company specified that the user consents in one go to the deposit of the
tracer for these two purposes.
It follows from the foregoing that by authorising the company to carry out a read and write
operation on its terminal equipment, the user consents both to a functionality to personalise its
browser and to a campaign to test the performance of the company’s website.
However, this coupling of the purposes of the tracker due to the use of a single tool is not
appropriate for these two distinct purposes since in the presence of several purposes, the data
subjects must be able to consent to one or other of these purposes without being forced to do so
and thus be offered a real choice for the processing of their data.
Thus, by not allowing the user to consent separately to one of the two purposes of the tracker,
the company does not offer the user of its website the possibility of freely consenting to the
deposit of trackers on its terminal equipment.
These facts constitute a breach of Article 82 of the French Data Protection Act since the
information relating to the purpose of each tracer does not allow it to give free and informed
consent to these operations.
Therefore, the company must implement a valid mechanism for obtaining the consent of
persons to read and/or write operations on their terminal.
F. Failure to comply with the obligations of Article L34-5 of the French Post and
Electronic Communications Code
In law, Article L34-5 of the French Postal and Electronic Communications Code (CPCE)
provides that “direct prospecting by means of an automated electronic communications system
within the meaning of 6° of Article L32, a fax or email using the contact details of a natural
person, subscriber or user, who has not previously expressed his/her consent to receive direct
marketing by this means, is prohibited.
For the purposes of this article, “consent” means any free, specific and informed expression of
will by which a person accepts that personal data concerning him or her may be used for the
purposes of direct prospecting.
Direct prospecting is the sending of any message intended to promote, directly or indirectly,
goods, services or the image of a person selling goods or providing services.
However, direct prospecting by e-mail is authorized if the recipient's contact details have been
collected directly from him/her, in compliance with the provisions of law no. 78-17 of 6 January
1978 on data processing, data files and individual liberties, on the occasion of a sale or
provision of services, if the direct prospecting concerns similar products or services provided
by the same natural or legal person, and if the recipient is offered, in an express and
unambiguous manner, the possibility of objecting, free of charge, apart from those linked to the
10
transmission of the refusal, and in a simple manner, to the use of his or her contact details when
these are collected and each time a prospecting e-mail is sent to him or her”.
In this case, firstly, with regard to consent, the delegation noted that the consent of website
users to receive electronic canvassing is not sought at any time, either when a customer account
is created, or during the purchasing process.
Canvassing by electronic means is only lawful if the person concerned has given his or her
consent before receiving canvassing.
However, the company did not obtain the consent of its website users when collecting their data
for electronic canvassing operations, in breach of the provisions of article L. 34-5 of the CPCE.
Secondly, with regard to opposition, the delegation noted that customers who have made an
online purchase are not able to oppose the use of their data for prospecting purposes when their
customer account is created, but only a posteriori in their customer area or via an unsubscribe
mechanism at the bottom of e-mails or “STOP SMS”.
Opposition to the receipt of prospecting e-mails or SMS messages under the exemption for
similar products or services must be exercisable at any time, in particular at the time the data is
collected.
However, the company does not provide customers, at the time their data is collected, with a
mechanism enabling them to object to receiving electronic prospecting for similar products or
services.
It follows from the above that customers cannot object to receiving prospecting for similar
products or services by electronic means at any time, in particular at the time their data is
collected.
All these facts constitute a breach of the obligations of Article L. 34-5 of the CPCE.
V. Corrective measures imposed by the CNIL (Article 20, paragraph II of the French
Data Protection Act)
In view of all these factors, and in agreement with the data protection authorities
concerned by this processing operation, the following corrective measures should be taken
against :
- A REMINDER OF THE LEGAL OBLIGATIONS, in accordance with the
provisions of Article 20, paragraph II of the French Data Protection Act with regard to
information provided to data subjects and relating to the retention period of the data, of
the obligation to provide accurate information at the time the data is collected;
- AN ORDER, in accordance with the provisions of Article 20.II of the Law of 3 January
1978, within three (3) months of notification of this decision and subject to any
measures it may have already adopted, to:
• process personal data for a period not exceeding that necessary for the
purposes for which it is processed in accordance with the provisions of Article
5(1)(e) GDPR, by applying its retention period policy for data belonging to
11
prospects and by deleting data that is not necessary for the purposes for which it was
processed;
• inform the data subjects in accordance with the provisions of Articles 12 and
13 GDPR, regarding the transmission of postal and prospecting contact details by
post;
• allow data subjects to object to commercial prospecting by post at any time, in
particular at the time of data collection;
• take security measures, pursuant to Article 32 GDPR, to preserve the security
of this data and prevent unauthorised third parties from having access to it, by
transforming user passwords before their storage into a database using a specialised,
non-reversible and secure cryptographic function;
• for operations to read and write information on users’ terminals:
o inform the user, in advance and in a clear and complete manner, of the
identity of the controllers for the reading or writing operations carried
out on his/her device, as well as his/her right to withdraw his/her consent
at any time, for example by completing the information banner relating to
cookies and appearing when the user first arrives on the website;
o allow the user to freely consent, upon his/her arrival on the website, to
the deposit of trackers on his/her terminal equipment;
• in the case of electronic canvassing, in accordance with article L. 34-5 of the
CPCE :
- to obtain the consent of website users prior to sending prospecting by electronic
means;
- not to send prospecting by electronic means for similar products or services
without first offering customers the possibility of objecting, free of charge and
in a simple manner, to the use of their data, at any time, including at the time it is
collected.
This order does not require any response from you to the CNIL. However, if the
persistence or repetition of the breaches referred to in the order were found during
subsequent verifications, I could appoint a Rapporteur within the CNIL and refer the
matter to the Restricted Committee of the CNIL, without a new order being sent to you
beforehand, so that one or more of the corrective measures set forth in Articles 20 et seq.
of the Law of 6 January 1978 may be pronounced.
The Chair
Marie-Laure Denis
12