Description

Issued CNIL ruling in investigation into DOCTISSIMO over alleged GDPR violations

On 11 May 2023, the French data protection authority (CNIL) closed its investigation into Doctissimo and imposed two fines over Data Protection Regulation (GDPR) violations. The platform Doctissimo publishes information on health and wellness. The CNIL identified that Doctissimo breached the GDPR data handling requirements, including the provisions related to retention periods, health data collection, data security and cookie usage. Doctissimo was fined EUR 280’000 for violations of the GDPR and an additional EUR 100’000 for cookie usage breaches.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
other service provider, platform intermediary: other
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2020-08-14
under deliberation

On 14 August 2020, the French data protection authority (CNIL) began an investigation into Doctissi…

2023-05-11
in force

On 11 May 2023, the French data protection authority (CNIL) closed its investigation into Doctissim…