CEGEDIM SANTÉ
800,000 €
GDPR enforcement action by French Data Protection Authority (CNIL) on 2024-09-12.
Rank · Sector
#12
of 270 in Health Care
Rank · France
#27
of 74
Rank · All fines
#202
of 3,050
Case details
- Authority
- French Data Protection Authority (CNIL)
- Date
- 2024-09-12
- Controller / Processor
- CEGEDIM SANTÉ
- Sector
- Health Care
- Quoted Articles
- Art. 5 (1) a) GDPR, Art. 66 Loi n° 78-17 du 6 janvier 1978
- Type of violation
- Non-compliance with general data processing principles
Summary
The French DPA has imposed a fine of EUR 800,000 on CEGEDIM SANTÉ. The company, which provides software for medical practices, had transferred customer data for research purposes. However, the DPA found that this data was not anonymous but only pseudonymized, making re-identification possible.
Open original source
Links to the regulator's original publication or another source.
Related fines
France
2025-09-01
200,000,000 €
ETid-2862
GOOGLE LLC
Media, Telecoms and Broadcasting
France
2025-09-01
150,000,000 €
ETid-2864
INFINITE STYLES SERVICES CO. LIMITED
Industry and Commerce
France
2025-09-01
125,000,000 €
ETid-2863
GOOGLE IRELAND LIMITED
Media, Telecoms and Broadcasting
France
2021-12-31
90,000,000 €
ETid-978
Google LLC
Media, Telecoms and Broadcasting
France
2021-12-31
60,000,000 €
ETid-979
Google Ireland Ltd.
Media, Telecoms and Broadcasting
France
2021-12-31
60,000,000 €
ETid-980
Facebook Ireland Ltd.
Media, Telecoms and Broadcasting