France France

ÉLECTRICITÉ DE FRANCE

600,000 €

GDPR enforcement action by French Data Protection Authority (CNIL) on 2022-11-24.

Rank · Sector
#38
of 167 in Transportation and Energy
Rank · France
#30
of 74
Rank · All fines
#222
of 3,050

Case details

Authority
French Data Protection Authority (CNIL)
Date
2022-11-24
Controller / Processor
ÉLECTRICITÉ DE FRANCE
Sector
Transportation and Energy
Quoted Articles
Art. 7 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 15 GDPR, Art. 21 GDPR, Art. L. 34-5 CPCE
Type of violation
Insufficient fulfilment of data subjects rights

Summary

The French DPA has imposed a fine of EUR 600,000 on ÉLECTRICITÉ DE FRANCE (EDF), France's largest electricity supplier.

The DPA had received several complaints that individuals were experiencing difficulties in exercising their rights by EDF.

During its investigation, the DPA found that EDF's privacy policy did not provide sufficient information on various aspects of data processing, such as the retention period of personal data.

In addition, the DPA found that EDF had not responded to a number of data subject requests in a timely manner
Also, EDF failed to respect data subjects' right to object to advertising requests in some cases.

Furthermore, the DPA noted that EDF failed to demonstrate that it had obtained valid consent from data subjects in the context of a commercial solicitation campaign.

Finally, the DPA concluded that EDF had failed to implement sufficient technical and organizational measures to protect personal data.
EDF had insecurely stored passwords of more than 25,000 customer accounts. In addition, the company had merely hashed and not salted passwords of 2,4 million accounts.

Open original source Links to the regulator's original publication or another source.

Related fines