The President
THE PRESIDENT
Paris, on
Our ref. :
To be recalled in all correspondence
Registered letter with acknowledgement of receipt XXXXX
Dear Sir,
’s main activity is the publishing of the mobile app ‘ , which offers its users
the opportunity to take photographs, all of which are revealed at the same time on Sundays to their
contacts. The application is mainly used by users residing in France. It is also used in other EU countries,
including Belgium.
In accordance with my Decision no 2024-058C of 27 March 2024, the Commission nationale
de l’informatique et des libertés (CNIL) carried out, on 9 April 2024, an online inspection of the mobile
application ‘ ’ and the website ‘ . This investigation continued on 28 May 2024 by
a hearing at the CNIL’s premises.
The purpose of this inspection was to verify whether processing operations accessible from the
‘ ’ field and the application ‘ ’ (‘ ’) complied with the
provisions of Regulation (EU) 2016/679 on data protection (‘the GDPR’) and with the Law of 6 January
1978 as amended (French Data Protection Act).
The findings made during those checks, and the additional information provided on 30
May 2024, lead me to note the following facts.
As a preliminary point, removes all user data from the ‘ ’ application which
last date of connection is more than two years. That deletion is permitted by the use of an indicator
called ‘lastActiveDate’, created in November 2023. In May 2024, approximately 134 thousand accounts
had a lastActiveDate’ field which had not been provided. It was therefore not possible for those accounts
to identify the last date of connection.
The defined retention period should lead to users’ data not being retained if they have not been
connected to their account for more than two years from the date of their creation. That period will
expire in November 2025.
Without updating the deletion script, the company will retain, from November 2025,
the data of 134 thousand accounts for a period exceeding that which it defined.
I therefore invite you to take any appropriate measures to ensure, by that deadline, the obligation
to respect a retention period proportionate to the purpose of the processing, pursuant to Article 5(1)(e)
of the GDPR.
I. Analysis of the facts in question
1. On the breach of the obligation to inform the data subjects and obtain their prior consent
before registering information on their electronic communications terminal equipment or
accessing it (cookies and other trackers)
In law, Article 82 of the French Data Protection Act provides that “Any subscriber or user of
an electronic communications service must be informed in a clear and complete manner, unless he/she
has been informed in advance, by the controller or its representative, of:
1° The purpose of any action to access, by electronic transmission, information already stored
in his/her electronic communications terminal equipment, or to write information into that equipment;
2° The means available to him/her to oppose such action.
Such access or registration may only take place if the subscriber or user has expressed, after
receiving this information, his/her consent, which may result from the appropriate settings of his/her
connection device or any other device under his/her control.”
These provisions shall not apply if access to information stored in the user’s terminal equipment
or recording of information in the user’s terminal equipment:
1° either has the exclusive purpose of enabling or facilitating communication by electronic
means;
2° Either, it is strictly necessary for the provision of an online communication service at the
express request of the user.”
a) The ‘ app for Android
Article 4(11) GDPR defines “consent” as “any freely given, specific, informed and
unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear
affirmative action, signifies agreement to the processing of personal data relating to him or her".
2
In Resolution No 2020-091 of 17 September 2020 adopting guidelines on the application of
Article 82 of the amended Law of 6 January 1978 regarding operations of accessing and writing
information in a user’s terminal 1, the CNIL states that “a minimum, the provision of the following
information to users, prior to the collection of their consent, is necessary in order to ensure the informed
nature of that consent :
- the identity of the controller (s) for reading or writing;
- the purpose of reading or writing data;
- how to accept or refuse trackers;
- the consequences of a refusal or acceptance of trackers;
- the existence of the right to withdraw consent.’
In this case, the company has on the Android app ‘ , implemented user
tracking by its partner GOOGLE for the purpose of improving its services. The application, a contrario
of its iOS version, does not contain any reference to information relating to that processing before it is
implemented or to a consent collection interface. The company indicated that it relies on the legal basis
of the legitimate interest to implement this processing.
The sole purpose of that processing is not to enable or facilitate communication by electronic
means and requires reading and writing operations on the user’s terminal, which are not, as regards the
improvement of services, strictly necessary for the provision of the services of the ‘ application.
Thus, those operations require the collection of the prior consent of the users.
Consequently, I consider that infringed the provisions of Article 82 of the
French Data Protection Law by carrying out reading and writing operations on the user terminal
of the Android version of the ‘ app without informing them or obtaining their prior
consent.
(b) The ‘ ’ application for iOS
Article 7(3) of the GDPR provides that “The person shall have the right to withdraw consent
at any time. [...] The data subject shall be informed thereof before giving his or her consent. It is as easy
to withdraw as to give consent”.
In Resolution No 2020-091 of 17 September 2020 adopting guidelines on the application of
Article 82 of the amended Law of 6 January 1978 to reading and writing in a user’s terminal, the CNIL
recalls that ‘in accordance with Article 7.3 of the GDPR, it must be as easy to withdraw consent as it is
to give. Users who have given their consent to the use of trackers must be enabled to withdraw it simply
and at any time” and that “as a minimum, the provision of the following information to users, prior to
the collection of their consent, is necessary to ensure that consent is informed […] the existence of the
right to withdraw consent”.
In this case, the delegation found that obtains the consent of users of the ‘
app on iOS by means of the access permission mechanism (offered by Apple’s iOS operating system as
part of its App Tracking Transparency (ATT)), to carry out reading and writing operations intended to
improve its services.
1
https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000042388179
3
Where the user consents to such operations within the emerging window presented by the iOS
operating system (ATT), no information on how to withdraw consent is communicated to the user. Only
general information about the possibility for a person to withdraw consent is given within the privacy
policy.
In addition, the delegation was informed that the withdrawal of users’ consent for this processing
can take place by removing the authorisation at the level of the operating system parameters, without
the information and menus available within the application allowing it to access this settings interface.
This configuration does not allow users to withdraw their consent as easily as they have given.
Therefore, by failing to inform individuals sufficiently of the ways in which they may
withdraw their consent to the abovementioned processing, and by not offering any means of
withdrawing their consent with a degree of simplicity equivalent to that envisaged for obtaining
it, I consider that infringed the provisions of Article 82 of the French Data Protection
Law informed by Article 7.3 of the GDPR.
2. On the breach to ensure data protection by design and by default
The GDPR confers rights on data subjects, including the right to obtain from the controller the
erasure of personal data concerning them without undue delay and in any event within one month
(Article 12(3) and (17) of the GDPR).
Furthermore, Article 25(1) of the GDPR provides that “Taking into account the state of the
art, the cost of implementation and the nature, scope, context and purposes of processing as well as the
risks of varying likelihood and severity for rights and freedoms of natural persons posed by the
processing, the controller shall, both at the time of the determination of the means for processing and
at the time of the processing itself, implement appropriate technical and organisational measures, such
as pseudonymisation, which are designed to implement data-protection principles, such as data
minimisation, in an effective manner and to integrate the necessary safeguards into the processing in
order to meet the requirements of this Regulation and protect the rights of data subjects […].”
The European Data Protection Board (EDPB) states in its Guidelines 4/2019 of 20 October 2020
on Article 25 of the GDPR that “[...] the controller shall implement appropriate technical and
organisational measures which are designed to implement the data protection principles and to
integrate the necessary safeguards into the processing in order to meet the requirements and protect
the rights and freedoms of data subjects. [...] appropriate means that the measures and necessary
safeguards should be suited to achieve the intended purpose, i.e. they must implement the data protection
principles effectively. The requirement to appropriateness is thus closely related to the requirement of
effectiveness. [...] When implementing the appropriate technical and organisational measures, it is with
respect to the effective implementation of each of the aforementioned principles and the ensuing
protection of rights that the measures and safeguards should be designed.”.
Recital 38 of the GDPR recalls that “Children merit specific protection with regard to their
personal data, as they may be less aware of the risks, consequences and safeguards concerned and their
rights in relation to the processing of personal data […].
4
In this case, the delegation was informed that the public targeted by the mobile app “ ”
is young people from 15 to 25 years. These, by installing the app, may take photographs during a week,
all of which will be revealed at the same time, on Sundays, to their contacts. The delegation noted that
once the photograph has been taken, the return of the photo is hidden. The user is therefore not able to
view it or remove it himself from the application before it is revealed. The General Terms and Conditions
of Use, in the version found during the online check, stated with regard to the removal of content that
“You can choose to remove your content once revealed. If you nevertheless wish to remove content
before it is revealed, we invite you to send us a request to ”.
However, as recalled by the CNIL in its work to strengthen the protection of minors online, the
re-use or sharing of personal data can have a serious impact on the privacy and physical and
psychological integrity, family life and school background of minors. In this regard, it recommends that
specific safeguards to protect the interests of minors be put in place by application design.
In the context of the mobile app, it appears that users do not have the opportunity to
control the photographed content after the eyesight or to remove by themselves their photographs whose
publication is scheduled before they are revealed. Therefore, there is a risk that those photographs, which
may represent them and third parties, reveal information about their contacts which may undermine their
privacy or that of third parties.
In addition, although the general terms and conditions of the application mention the possibility
for the user to send an email to in order to request the erasure of a photograph which will be
carried out manually by an employee of the company, that method may require a processing period
exceeding the deadline for publication of the content concerned, in particular as regards requests sent
shortly before that date.
I therefore consider that infringed the provisions of Article 25 of the GDPR by
failing to provide users with an appropriate technical measure to protect data subjects’ rights
consisting of providing for a functionality enabling the photographed content to be controlled and
removed easily before it is shared with third parties.
I. Corrective measures ordered by the CNIL (Article 20 of the Act of 6 January 1978)
In view of all those factors and, in agreement with the other data protection authorities
concerned by that processing, in accordance with Article 20 of Law No 78-17 of 6 January 1978,
, established at the address indicated above, is ordered to bring processing operations
into compliance within three (3) months of notification of this decision and subject to any measures
which it could already have adopted:
- define and implement means to obtain free, specific, informed and unambiguous consent from
data subjects prior to any reading or writing on their terminal which is not exclusively intended
to enable or facilitate electronic communication or is not strictly necessary for the provision of
expressly requested services;
- define and implement a means for users of the “ ” application to withdraw their consent
as easily as to give it;
- take any appropriate technical and organisational measures to ensure data protection by design,
in particular by allowing users of the application to acquaint themselves with and remove their
photographs before they are revealed.
5
This decision, which does not require a response from you, entails the closure of procedure No
2024-058C. However, this closure is without prejudice to the right reserved by the CNIL to carry
out a new verification mission, in order to check that your company has complied with this formal
notice on expiry of the time limit.
In the event of a new verification procedure, if your company has not complied with this
decision, a Rapporteur will be appointed who may ask the Restricted Committee to impose one of
the penalties set forth in Article 20 of the French Data Protection Act.
This decision may be appealed before the Council of State within two months of its
notification.
For more information on the formal notice procedure, you can consult the CNIL website at:
https://www.cnil.fr/fr/la-procedure-de-mise-en-demeure-0.
The CNIL's departments ( Legal Officer in the Inspections Department
Legal Officer in the Inspections Department
IT Systems Auditor in the Inspections Department
) are at your disposal for any further information you may require.
Sincerely,
Marie-Laure Denis
The President
Copy sent by email to Mr President
6