Duyurular
Health Data and Cookie Usage: DOCTISSIMO Fined by French Data Protection Authority
On May 11, 2023, the European Data Protection Board ("EDPB") published a press release that the French Supervisory Authority ("SA/CNIL") imposed two fines on DOCTISSIMO.
Following a complaint by PRIVACY INTERNATIONAL association, the CNIL conducted four investigations into DOCTISSIMO. The doctissimo.fr website primarily provides articles, tests, quizzes, and discussion forums on health and well-being for the general public.
During the investigations, CNIL identified several violations, including the improper retention of data, collection of health data through online tests, data security issues, and improper use of cookies on user devices.
The French Data Protection Authority found DOCTISSIMO guilty of four breaches of the General Data Protection Regulation (“GDPR”) and one breach of the French Data Protection Act:
- Failure to store data only for the necessary duration (Article 5.1(e) GDPR)
- Failure to obtain consent from individuals for collecting their health data (Article 9 GDPR)
- Failure to establish a proper legal framework for joint data processing with another controller (Article 26 GDPR)
- Failure to ensure the security of personal data (Article 32 GDPR)
- Failure to comply with obligations related to the use of cookies (Article 82 of the Data Protection Act)
The CNIL imposed two fines on DOCTISSIMO:
- A fine of EUR 280,000 for GDPR violations. This fine was issued in collaboration with other European data protection authorities under the one-stop shop procedure, as the website receives visitors from all EU member states.
- A second fine of EUR 100,000 for violations of the French Data Protection Act regarding rules on cookies and other trackers.
You can reach further information here.
Kind regards,
Zumbul Attorneys-at-Law
Türkçe
English