The Chairperson
,
Managing Director,
Par LRAR n°
Case investigator:
Ref. no.:
Case No.
(to be quoted in all correspondence)
Dear ,
I am following up on the various exchanges that took place between the French Data
Protection Authority (CNIL) and the Data Protection Officer (DPO) of
(hereinafter referred to as the "company") in connection with the investigation of the
complaint lodged by (hereinafter the "complainant") which was forwarded to us by
the Irish Data Protection Authority pursuant to Article 56 of the General Data Protection
Regulation (GDPR).
As the company is established at France, the CNIL
is competent to act as the lead supervisory authority within the meaning of Article 56(1) of
the GDPR.
As a reminder, following the receipt of an unsolicited marketing email on 20
December 2023, the complainant reports that he sent a request for a copy of his personal data
to on 16 January 2024. Despite several reminders, the last of which was
sent on 21 March 2024, this request reportedly remained unanswered.
The CNIL intervened with the company to question it about the facts brought to its
attention.
Following this intervention, the company granted the complainant's request by email
dated 18 December 2024, eleven months after his initial request. On 19 December 2024,
Personal data necessary for the CNIL to carry out its duties is processed in files intended for its exclusive use.
Data subjects may exercise their data protection rights by contacting the CNIL's Data Protection Officer (DPO)
\Yi/ G/n {nr y//jrzjrp mm /Îomæ nr/ nnr mr yrrJor norm/ Osyzr on cnäzmir m/yyr ’ 1a^*^a7 yes/
The latter responded that they were satisfied with the response provided.
The company states that the failure to process this request is due to the departure of
the agent responsible for responding to queries sent to its general contact email address, but
states that it has put measures in place to prevent this type of failure in the future. The
company states that it has:
- created a dedicated email address for requests relating to personal data protection;
- modified the contact form on its website;
- set up a ticketing system to track such requests; and
- reminded its agents of the rules and procedures concerning this type of request.
These facts lead me to remind you that, as the data controller, it is your responsibility
to respond to the data subject who has made a request for access as soon as possible "and in
any event within one month of receipt of the request".
For your information, I would like to point out that the CNIL provides professionals
with a practical guide on processing access requests on its website, which can be consulted at
the following address: httns://www.cni1.fr/fr/respecter-les-droits-des-
nersonnes/orofessionnels-comment-repondre-une-demande-de-droit-dacces.
In this context, the response provided by and the
measures adopted to ensure that access requests are processed within the time limits set out
in Article 12 of the GDPR lead me, in agreement with the other European data protection
authorities concerned by this processing, to close this complaint.
However, the CNIL reserves the right, in the event of further complaints, to exercise
all the powers conferred on it by the provisions of the GDPR and Law No. 78-17 of 6 January
1978, as amended, on information, files and freedoms.
Yours faithfully, On behalf of the President of the CNIL,
and by delegation,
Department
2