Authority
CNIL
Country
France
Date Issued
July 26, 2021
Industry
Pharmaceuticals
Summary
The organization failed to provide adequate information to data subjects and failed to properly establish contractual safeguards with its data processor, violating GDPR requirements for transparency and processor obligations. CNIL issued a €400,000 fine for these compliance failures.
Violation Types
TransparencyProcessor Obligations
Articles Violated
Avoid enforcement risk with automated compliance
IQWorks helps organizations automate GDPR compliance before regulators come knocking.
Talk to an Expert