{"id":700,"date":"2018-08-24T16:29:40","date_gmt":"2018-08-24T14:29:40","guid":{"rendered":"http:\/\/blog.eprivacy.eu\/?p=700"},"modified":"2020-12-13T16:30:19","modified_gmt":"2020-12-13T15:30:19","slug":"new-cnil-case-of-gdpr-enforcement","status":"publish","type":"post","link":"https:\/\/blog.eprivacy.eu\/?p=700","title":{"rendered":"New CNIL case of GDPR enforcement"},"content":{"rendered":"\n<p>Two medium-sized French companies have received warning notices&nbsp;from the CNIL (French data protection authority). Both companies affected &#8211; Teemo and Fidzup &#8211;&nbsp;collect geolocation data for targeted advertising.&nbsp;<\/p>\n\n\n\n<p>According to&nbsp;CNIL, the reason for the warning is gathering and processing data without informed consent. Fidzup is admonished for not being clear enough about what data was&nbsp;being collected and Teemo&nbsp;was&nbsp;collecting data&nbsp;only after users downloaded the&nbsp;app. Moreover storing geolocation data for 13 months in Teemo&#8217;s case was considered&nbsp;too long for the reason of targeted advertising, according to CNIL.<\/p>\n\n\n\n<p>Interesting to know is that the CNIL examined Teemo in the autumn of last&nbsp;year (2017), but made the case public first in July 2018 to create an industry showcase under GDPR.&nbsp;The CNIL has not imposed any fines (!) &#8211; well aware, as some of the points are based on interpretations,&nbsp;but has&nbsp;set a clear deadline for implementing the requirements.<\/p>\n\n\n\n<p><br>ePrivacy summarizes&nbsp;the viewpoint of CNIL&nbsp;on digital business models:<\/p>\n\n\n\n<ul><li>the CNIL sees the responsibility&nbsp;on the processor&#8217;s side (in this case: the SDK provider has&nbsp;to make sure that the controller&nbsp;has&nbsp;the valid consent)&nbsp;especially if data is also collected in a parallel model for own purposes (usually as a controller)<\/li><li>the CNIL considers high transparency and clear consents to geolocation data in general as&nbsp;critical<\/li><li>the CNIL considers longer data&nbsp;storage periods to be critical for certain business models<\/li><\/ul>\n\n\n\n<p>From ePrivacy&#8217;s point of view, this position is disputable.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two medium-sized French companies have received warning notices&nbsp;from the CNIL (French data protection authority). Both companies affected &#8211; Teemo and Fidzup &#8211;&nbsp;collect<\/p>\n<p class=\"link-more\"><a class=\"myButt \" href=\"https:\/\/blog.eprivacy.eu\/?p=700\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts\/700"}],"collection":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=700"}],"version-history":[{"count":1,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts\/700\/revisions"}],"predecessor-version":[{"id":701,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts\/700\/revisions\/701"}],"wp:attachment":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=700"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=700"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=700"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}