CNIL (France) - SAN-2025-001
| CNIL - SAN-2025-001 | |
|---|---|
| Authority: | CNIL (France) |
| Jurisdiction: | France |
| Relevant Law: | Article 6(1)(a) GDPR Article 6(1)(f) GDPR Article 7 GDPR L. 34-5 CPCE |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | 18.10.2022 |
| Decided: | 15.05.2025 |
| Published: | 21.05.2025 |
| Fine: | 900,000 EUR |
| Parties: | SOLOCAL MARKETING SERVICES |
| National Case Number/Name: | SAN-2025-001 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | French |
| Original Source: | CNIL (in FR) |
| Initial Contributor: | ap |
The DPA fined a direct marketing company €900,000 for direct marketing and transferring user data without a valid legal basis. The company was also ordered to cease direct marketing activities in absence of valid consent.
English Summary
Facts
SOLOCAL MARKETING SERVICES (formerly known as PAGES JAUNES MARKETING SERVICES, referred to as the controller) is an advertising company that offers companies to carry out direct marketing campaigns on their behalf (by SMS or e-mail). The controller also transfers the data to the companies in order for them to carry out the direct marketing themselves. To do this, the controller purchases data subjects’ data from data brokers, who collect this data through websites’ entry forms for game contests or online product testing. According to the DPA’s findings, the forms are misleading as they make it significantly easier to consent to having their data being used for direct marketing than not.
The DPA carried out on site investigation in 2022, and informed the controller of its findings in July 2024. The controller argued that it should not be held liable for the way in which its partners collect consent, and that its contractual measures were sufficient to fulfill its obligations. The controller also argued that it could have not foreseen the DPA’s investigation because at the time of the investigation the DPA had not published recommendations specific to consent in the direct marketing sector.
Holding
The DPA considered that SOLOCAL acted as a controller in carrying out direct marketing on behalf of its customers and in transferring the data for companies to carry out the direct marketing themselves. The DPA considered SOLOCAL potentially as a joint controller with its partners.
First, the way in which consent was collected in the online forms did not comply with consent requirements under the GDPR or national law (Postal and Electronic Communications Code or CPCE[1]). The DPA found that the design of the forms did not allow the user to give free and unambiguous consent. The forms gave a significant prominence to the buttons allowing processing for direct marketing purposes compared to the option of not consenting to direct marketing. According to the DPA, the user’s expression of wishes must relate precisely with the processing and cannot be inferred. This was supported by CJEU case law such as Planet49. Any inappropriate influence preventing the data subject from exercising their will render the consent invalid. Therefore the controller could not rely on consent as a legal basis (Article 6(1)(a) GDPR), given that the conditions for consent under Article 4(11) GDPR or Article 7 GDPR were not met.
The DPA also dismissed the controller’s argument on foreseeability. The DPA stated that rules relating to direct marketing and consent were available years before the investigation took place. This was especially the case considering the case law, guidelines and legal provisions it had cited to support its arguments on consent above.
The DPA did not consider the controller’s contractual measures as sufficient. The contractual framework was broad and placed a significant responsibility on the collectors of the data. The controller had the proactive obligation to carry out regular checks and to implement necessary consequences for the lack of validity. Furthermore, the controller had also failed to demonstrate that the data subject gave consent to process their data for direct marketing purposes under Article 7(1) GDPR and Article L. 34(5) CPCE. This was especially serious for one of the data brokers, because the controller was unable to receive information despite several requests.
Finally, the DPA considered the legal basis to transfer the data unlawful. Under Article 6(1)(f) GDPR, the interests and fundamental rights of the data subject may prevail over those of the controller taking into account the reasonable expectations of the data subject. Here, the DPA stated that the controller could not rely on legitimate interests in this case, considering the fact that the data subjects were not informed and therefore could not have reasonably expected such processing.
The DPA fined the controller €900,000, and ordered it to cease direct marketing activities in absence of valid consent. The severity and high number of people concerned were considered aggravating factors.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the French original. Please refer to the French original for more details.
Deliberation of the Restricted Committee No. SAN-2025-001 of May 15, 2025, concerning the company SOLOCAL MARKETING SERVICES
The National Commission for Information Technology and Civil Liberties, meeting in its restricted committee composed of Mr. Philippe-Pierre CABOURDIN, President, Mr. Vincent LESCLOUS, Vice-President, and Ms. Laurence FRANCESCHINI and Ms. Isabelle LATOURNARIE-WILLEMS, members;
Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data;
Having regard to the French Postal and Electronic Communications Code;
Having regard to Law No. 78-17 of January 6, 1978, on information technology, data files, and civil liberties, in particular Articles 20 et seq. Having regard to Decree No. 2019-536 of May 29, 2019, implementing Law No. 78-17 of January 6, 1978, relating to information technology, data files, and civil liberties;
Having regard to Resolution No. 2013-175 of July 4, 2013, adopting the internal regulations of the National Commission for Information Technology and Civil Liberties;
Having regard to Decision No. 2022-129C of June 21, 2022, of the President of the National Commission for Information Technology and Civil Liberties, instructing the Secretary General to conduct, or have conducted, an audit of the processing operations implemented by SOLOCAL GROUPE and its subsidiaries, in particular SOLOCAL and SOLOCAL MARKETING SERVICES, or on their behalf, in any location likely to be affected by their implementation;
Having regard to the decision of the President of the National Commission for Information Technology and Civil Liberties of June 17, 2024, appointing a rapporteur to the restricted committee;
Having regard to the report of Mr. Fabien Tarissan, rapporteur-commissioner, served on SOLOCAL MARKETING SERVICES on July 18, 2024;
Having regard to the written observations submitted by the Board of Directors of SOLOCAL MARKETING SERVICES on September 6, 2024;
Having regard to the rapporteur's response to these observations, served on the company on October 4, 2024;
Having regard to the new written observations submitted by the Board of Directors of SOLOCAL MARKETING SERVICES on November 4, 2024;
Having regard to the closure of the investigation on November 28, 2024, served on the company on December 3, 2024;
Having considered the letter from the President of the Restricted Committee dated December 2, 2024, informing the company that the case was included on the agenda of the Restricted Committee meeting of December 19, 2024;
Having considered the oral observations made during the Restricted Committee meeting of December 19, 2024;
Having considered the other documents in the case file;
The following were present at the Restricted Committee meeting of December 19, 2024:
- Mr. Fabien Tarissan, Commissioner, having heard his report;
As representatives of SOLOCAL MARKETING SERVICES:
- […]
The President, having verified the identity of the representatives of the defendant, presented the proceedings of the meeting, and reminded the company that the defendants may, if they wish, present oral observations introductory or in response to questions from the members of the Restricted Committee;
SOLOCAL MARKETING SERVICES having spoken last;
The Restricted Committee adopted the following decision:
I. FACTS AND PROCEDURE
1. SOLOCAL MARKETING SERVICES (hereinafter, "the company" or "SOMS"), a public limited company with a board of directors whose registered office is located at 204 rond-point du Pont de Sèvres in Boulogne-Billancourt (92100), is a subsidiary of SOLOCAL GROUPE, formerly PAGES JAUNES GROUPE (hereinafter, the group).
2. SOMS employed 309 people as of December 31, 2023. In 2022, it generated revenue of €79.4 million and net income of €19.3 million. For 2023, this revenue amounted to €76.3 million and net income of €16.3 million.
3. Founded in 1999 under the name PAGES JAUNES MARKETING SERVICES (now SOLOCAL MARKETING SERVICES) as a subsidiary dedicated to the group's direct marketing business, the company stated that its main activity today is website design. However, it also specified that it still sells direct marketing products in parallel, which covers two types of services.
4. On the one hand, the company conducts sales prospecting operations by sending emails and text messages to prospects, benefiting approximately 300 direct clients. In 2022, it sent prospecting text messages to more than 4.7 million people on behalf of its clients, and more than 500,000 people were contacted by email.
5. On the other hand, the company transmits prospect data to its clients to enable them to conduct their own sales prospecting operations by mail and telephone. In the first ten months of 2022, nearly 1.4 million people had their data transferred.
6. All of these operations are carried out using a single database, referred to as […] (or […] in the General Terms and Conditions of Sale), compiled by the company using data transmitted and regularly updated by approximately fifteen data providers, such as companies [X1], [X2], or [X3], as well as by company [X4] for the postal addresses and landline telephone numbers of prospects. This database, which has approximately 75 million entries, contains the data of nearly 35 million distinct individuals. The company has specified that it only processes the data of French nationals, for the benefit of French advertisers.
7. On 18 and 19 October 2022, a delegation from the French National Commission for Information Technology and Civil Liberties (hereinafter, "the CNIL" or "the Commission") carried out an on-site inspection at the premises of SOLOCAL GROUPE and its subsidiaries, in particular SOLOCAL MARKETING SERVICES. The purpose of this operation was to verify compliance with the provisions of Law No. 78-17 of 6 January 1978 relating to information technology, files and civil liberties (hereinafter, "the Data Protection Act" or "the Act of 6 January 1978 as amended") and other provisions relating to the protection of personal data provided for by legislative and regulatory texts and European Union law. The minutes drawn up at the end of the hearing were notified to SOLOCAL MARKETING SERVICES on October 25, 2022.
8. The company provided the delegation with additional information on October 27, 2022, February 2 and June 15, 2023, and July 2, 2024.
9. To examine this information, the Chair of the Commission appointed Mr. Fabien Tarissan as rapporteur on June 17, 2024, on the basis of Article 22 of the amended Law of January 6, 1978.
10. On July 18, 2024, following his investigation, the rapporteur served the company with a report detailing the breaches of Articles L. 34-5 of the French Postal and Electronic Communications Code (hereinafter, "the CPCE") and Articles 6 and 7 of Regulation (EU) 2016/679 of April 27, 2016 (hereinafter, "the GDPR") that he considered to have occurred in this case. This report proposed that the restricted committee impose an administrative fine on the company, as well as an injunction to bring its practices into compliance with the aforementioned provisions, accompanied by a periodic penalty payment. It also proposed that this decision be made public, but that it would no longer be possible to identify the company by name after a period of two years from its publication. 11. Several exchanges of written submissions subsequently took place between the rapporteur and the company, until the investigation was closed and served on the company on December 3, 2024.
12. Following the written adversarial procedure, the rapporteur and the company presented oral observations at the restricted committee meeting.
II. REASONS FOR THE DECISION
A. On the processing operations in question and the company's liability
13. Article 4, paragraph 7 of the GDPR defines the data controller as "the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing."
14. The Restricted Committee notes that, in the commercial prospecting ecosystem, the capacity to be conferred on the various actors in the chain in terms of data controllership—namely, the advertiser on whose behalf the electronic prospecting is sent and the intermediary acting between the advertiser and the initial collector, who may, in particular, be responsible for sending electronic prospecting messages on behalf of the advertiser—depends on a number of parameters (such as, for example, the ownership of the database, its creation and management methods, the segmentation choices made, or the degree and precision of the instructions given by the advertiser). This allocation and distribution of responsibilities between the different actors may vary depending on the roles and actions carried out by each, depending on the specific case, and they must therefore be analyzed on a case-by-case basis. The qualification retained by the actors themselves, particularly in their contractual acts, constitutes an important element to take into account, but not decisive if it does not correspond to the reality of the criteria of Article 4 of the GDPR. Depending on the scenario, the advertiser, i.e. the entity wishing to promote its products or services, may be qualified as data controllers (see CNIL, FR, August 3, 2022, No. SAN-2022-017, published; CNIL, November 24, 2022, No. SAN-2022-021, published; CNIL, FR, October 12, 2023, No. SAN-2023-015, published; CE, March 23, 2015, GROUPE DSE, No. 357556, Rec.) or certain specialized providers offering advertising services and marketing products (see CE, March 11, 2015, TUTO4PC, no. 368624, T; CNIL, FR, December 7, 2020, SAN-2020-016, published). These providers include companies that create contact databases from various third-party sources (called "primo-collectants"), which they resell to partners or use to offer commercial prospecting services to advertisers. These actors may, depending on the configuration, be subcontractors of the advertiser or responsible for processing prospecting operations, without excluding possible joint liability between the advertiser and its service provider.
15. In the area of commercial prospecting, the Restricted Committee, for example, held that an organization whose activity is the creation of a database of contacts intended for commercial prospecting by electronic means and the sending of prospecting emails to advertisers is the data controller, on the basis of the following elements: "firstly, with regard to the determination of the purposes, the Restricted Committee notes that […] the company is the owner of the database used in the context of prospecting campaigns, the advertisers and web agencies not providing the personal data of the prospects to be contacted and not having access to the personal data of the prospects. Secondly, the Restricted Committee considers that the company determines the essential means of processing in that it defines the personal data that appear in its prospect database, the periods for which this data is kept there and any updates that need to be made. Consequently, and without it being necessary in this case to rule on a possible joint liability of the company's advertising partners […], the The Restricted Committee notes that the latter has defined the purposes and means of processing related to the management and provision of its personal database for the purposes of commercial prospecting by email" (CNIL, FR, December 7, 2020, SAN-2020-016, published).
16. In this case, the Restricted Committee notes that the services offered by SOMS and examined in the context of these proceedings are two in number.
17. First, the company offers its advertising clients a service consisting of carrying out prospecting campaigns on their behalf by email ("EmailConnect" offer) or by SMS ("ContactConnect" offer).
18. In this regard, the Restricted Committee notes that it is clear from the general terms and conditions of sale of the offers proposed by SOMS that "in the event that the data processed comes from the SOMS database, the parties [SOMS and the advertisers] acknowledge that they are acting as joint data controllers. In the event that the data processed comes from the customer's contact file, the parties acknowledge that the customer acts as the controller of the personal data, with SOMS acting as the processor."
19. While it is thus provided that these campaigns may, in theory, target prospects whose data has been transmitted to SOMS by its customers, it is clear from the evidence in the case that, in practice, in the vast majority of cases, these operations are carried out using data from the […] database (or […] database), which the company itself created from prospect data transmitted by its partners and of which it is the owner. In such a case, the company's customers not only do not provide the data used, but also have no access to it. Furthermore, no access.
20. The Restricted Committee thus notes that, on the one hand, the company defines the data contained in its database […], which it collects from various partners, the periods for which this data is retained, and the purposes for which it is used. It is therefore responsible for processing the creation and administration of this database, which it acknowledges.
21. On the other hand, the company offers its customers the option of conducting commercial prospecting operations electronically. It is apparent from the documents in the case file that, with regard to these operations, the company acts at least in part as data controller when these operations are carried out using data from the […] database (or […] database). In this regard, for this case, it should be noted that, in addition to the information contained in the general terms and conditions of sale, the company confirmed its status as data controller, first during the inspection carried out on October 18, 2022, and then in its observations in response to the sanction report. Furthermore, and without it being While it is necessary in this case to rule on the possible joint liability of its clients, the Restricted Committee notes that SOMS's liability does not exclude that of the advertisers, who act as joint controllers, as the company also indicates in its general terms and conditions of sale. It is also possible that in certain cases, SOMS acts as a processor for its clients, but these hypotheses are not at issue in this case.
22. In view of all of the above, the Restricted Committee wishes to clarify that, with regard to these electronic prospecting operations carried out by the company for the benefit of advertising clients, from its database, this decision concerns exclusively the processing for which SOMS is, and acknowledges itself to be, the data controller.
23. Secondly, the Restricted Committee notes that, as part of its "ListConnect" offering, the company transmits data from its database to its clients […], granting them a certain number of rights over this data, including the right to use it for commercial prospecting purposes by post and by telephone.
24. The Restricted Committee considers that by transmitting to its customers a targeted segment of data from a database it has itself created and owned, and by contractually determining the use that may be made of this data, the company determines both the purposes and the means of such an operation. In this regard, the company confirmed that it assumes the role of data controller with regard to the transmission of this data.
25. Under these conditions, the Restricted Committee considers that the company must be considered the data controller, both for the electronic commercial prospecting operations carried out for the benefit of its customers using its database—notwithstanding the possible joint liability of said customers and excluding cases where it acts only as a processor—and for the transmission of prospect data to advertisers, so that they can themselves carry out commercial prospecting by mail or telephone.
B. On the regularity of the proceedings brought against the Company
1) On the complaint alleging breach of the right to a fair trial
26. The company argues that the manner in which the investigation was conducted violates its right to a fair trial, guaranteed by Article 6 of the European Convention on Human Rights, which requires not only respect for the adversarial principle but also the company's ability to reasonably present its case. It considers, in particular, that its observations were not sufficiently taken into consideration by the rapporteur and that the latter's reasoning does not take into account the facts of the case and the company's practice.
27. The company further argues that, with regard to the breach of Article 6 of the GDPR, the rapporteur, in his response, raised a new argument alleging the alleged inadequacy of the information communicated to individuals, abandoning the basis of legitimate interest and failing to take into account the observations submitted by the company.
28. First, the Restricted Committee recalls that the adversarial principle implies the right of the parties to to communicate and be able to discuss any evidence or observations submitted to the judge with a view to influencing his decision (ECHR, Grand Chamber, 20 February 1996, Vermeulen v. Belgium, no. 19075/91).
29. The Restricted Committee notes that, in preparing his report, the rapporteur relied on the evidence gathered during inspections carried out in compliance with the provisions of the Data Protection Act, and that he examined the facts found in light of the applicable rules on the protection of personal data. It notes that the company was aware of all of this evidence and was able to make observations, first in writing - several exchanges of submissions having taken place during the investigation - and then orally at the hearing of 19 December 2024.
30. Secondly, with regard to the breach of Article 6 of the GDPR, the Restricted Committee notes that this will be examined in II, D) of this deliberation. It nevertheless notes from this point of view that, contrary to what the company maintains, it does not appear from the rapporteur's written submissions or his oral observations at the meeting of December 19, 2024, that he intended to raise new grounds or change the basis for the breach initially noted in his report, his observations relating to the information of individuals being part, among other elements, of the assessment of the conditions that must be met for the legal basis of legitimate interest to apply. In any event, the rapporteur is free to modify the legal basis for a breach or his legal analysis during the proceedings, if the company is given the opportunity to respond. It appears in this case that the company was indeed given the opportunity to respond to all the grounds raised.
31. More generally, the Restricted Committee recalls that it is its responsibility, pursuant to Article 20-IV of the French Data Protection Act and the in light of all the evidence presented to it by both the rapporteur and the company, to decide whether or not the breaches noted appear to have been established and to pronounce, if necessary, the corrective measure(s) that it deems justified. It notes that in this case, all the submissions and documents produced by both the company and the rapporteur have been brought to its attention and that it therefore has the necessary evidence to enable it to rule on the processing in question.
32. Under these circumstances, the Restricted Committee considers that the right to a fair trial was not violated and that the proceedings were conducted properly, in compliance with the procedural rules defined in Articles 22 of the French Data Protection Act, Articles 39 to 45 of the Decree of May 29, 2019, and Articles 61 to 70-1 of the CNIL's internal regulations.
2) On the complaint alleging breach of the principle of legal certainty and the principle of the legality of offences and penalties
33. The company considers that the content of the rapporteur's submissions breaches the principle of legal certainty (a general principle of EU law enshrined by the Court of Justice of the European Union, hereinafter "the CJEU"), as well as the principle of the legality of offences and penalties, guaranteed by Articles 8 of the Declaration of the Rights of Man and of the Citizen, 7 of the European Convention on Human Rights, and 49 of the Charter of Fundamental Rights of the Union. It emphasizes that the rules the rapporteur intends to apply were not sufficiently clear at the time of the audit and that the CNIL had not published any recommendations relating to the collection of consent in the marketing sector, as it has done in other sectors (e.g., cookies or mobile applications). It also argues that certain decisions cited by the rapporteur postdate the audit and that, to the extent that they lay down stricter rules, their application to the facts of this case would be contrary to the principle of non-retroactivity.
34. The Restricted Committee wishes to clarify that the applicable legal framework will be examined, within the framework of this deliberation, for each of the breaches identified. It nevertheless reiterates at this stage that the decisions cited by the company as post-dating the audit operations constitute only the application of pre-existing rules and, under these circumstances, cannot be invoked under the principle of non-retroactivity of repressive rules, which only applies to mandatory rules.
35. It also underlines that, while the CNIL has the power to publish "guidelines, recommendations or reference documents intended to facilitate compliance of the processing of personal data with the texts relating to the protection of personal data" (pursuant to Article 8, paragraph 2, b) of the Data Protection Act), the legal rules are set by French and European legislators and interpreted by the competent courts, and are directly applicable to the organizations concerned. Therefore, the adoption by the CNIL of reference documents or guidelines is not a prerequisite for the obligation to comply with the rules already laid down and for the application of sanctions provided for by the GDPR or the Data Protection Act in the event of a violation. The Restricted Committee also notes that in this case, the established rules regarding commercial prospecting, informed by CNIL publications such as its commercial management framework adopted in September 2021 and the pages dedicated to the issue on its website, as well as by Guidelines 5/2020 on consent within the meaning of Regulation (EU) 2016/679 adopted by the European Data Protection Board (hereinafter, "the EDPB"), allowed the parties involved to understand, with sufficient precision, the applicable legal framework and the obligations incumbent upon them.
36. Finally, the Restricted Committee wishes to emphasize that it follows from the principle of accountability, as defined by the GDPR, that it is up to the organization carrying out the processing to define and implement the measures enabling compliance with the applicable legal provisions. In this regard, Recital 74 of the GDPR provides that "the controller should be held liable for any processing of personal data carried out by the controller or on its behalf. It is important, in particular, that the controller be required to implement appropriate and effective measures and be able to demonstrate compliance with this Regulation, including the effectiveness of the measures. These measures should take into account the nature, scope, context, and purposes of the processing, as well as the risk it poses to the rights and freedoms of natural persons." It thus appears that it is up to the controllers—and not the data protection authorities—to determine the practical arrangements for implementing the processing that they consider most appropriate, provided that these arrangements enable them to demonstrate compliance with the obligations imposed by national and European legislation.
C. On the breaches relating to the electronic marketing operations carried out by the company for the benefit of its Customers
37. The Restricted Committee notes that the company conducts commercial prospecting operations via SMS and email, for the benefit of approximately 300 customers, using prospect data transmitted by its partners. The lifecycle of this data can be summarized as follows: the data is collected from the data subjects by companies such as [X2], [X1], or [X3] (referred to as "first-time collectors"), contractually responsible for obtaining the consent of the data subjects to be the subject of commercial prospecting by electronic means. The collection of this data and the gathering of consent are carried out through online competition entry forms designed by these companies. This data is then transmitted to SOMS, which integrates it into its database […] and then uses it to conduct commercial prospecting operations by electronic means for its customers. To do this, it relies on the consent previously collected by its first-time collector partners, on its behalf, using the aforementioned forms. During In 2022, the company contacted more than 4.7 million unique individuals via SMS, whose data was provided by its partners, and more than 500,000 via email.
Regarding the failure to obtain the consent of data subjects for the implementation of commercial prospecting by electronic means pursuant to Article L. 34-5 of the French Postal and Electronic Communications Code (data provided by companies [X1] and [X2])
38. Under Article L. 34-5 of the French Postal and Electronic Communications Code (CPCE), "direct prospecting by means of an automated electronic communications system within the meaning of Article L. 32, paragraph 6, a fax machine, or emails using the contact details of a natural person, subscriber, or user, who has not previously expressed their consent to receive direct prospecting by this means is prohibited.
For the purposes of this article, consent means any freely given, specific, and informed expression of will by which a person agrees to the use of their personal data for the purpose of direct marketing.
Direct marketing is the sending of any message intended to promote, directly or indirectly, goods, services, or the image of a person selling goods or providing services. For the purposes of this article, calls and messages intended to encourage users or subscribers to call a premium-rate number or send a premium-rate text message also fall under direct marketing […].
39. Under Article 4, paragraph 11 of the GDPR, "consent" of the data subject means "any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her."
40. The rapporteur considers, in essence, that the design of the online competition entry forms from which the company's partners collect the data used by the company to carry out its prospecting operations does not allow for the collection of free and unambiguous consent from the user, and strongly encourages the user to accept the transmission of their data and their use for commercial prospecting purposes. He considers that, under these conditions, the company cannot rely on such consent to carry out its prospecting operations electronically and that a breach of Article L. 34-5 of the CPCE has occurred.
41. In defense, the The company disputes the alleged breach and maintains that it complied with all of its obligations, given the legal framework applicable at the time of the audit.
1.1. On the applicable legal framework and the liability of SOMS
1.1.1. On the conditions for the validity of consent
42. The company considers that at the time of the audit, in October 2022, the applicable legal framework did not allow it to conclude that the consent collection mechanisms implemented by its partners were invalid. It maintains that it was only through a deliberation of December 29, 2023 (CNIL, FR, December 29, 2023, Sanction, No. 2023-025, published) that the restricted committee ruled on the specific methods of this collection in the context of competitions organized by first-time collectors, and that it was not in a position to anticipate such a decision. The company insists on the principle of non-retroactivity. repressive rules. It also argues that the recommendations and guidelines relating to cookies, cited in the report, cannot be applied to commercial prospecting.
43. The Restricted Committee recalls that all the rules applicable to electronic prospecting, as well as those relating to consent, have been established for many years and precede not only the publication of the aforementioned decision, but also the audit operations carried out in October 2022 at SOMS.
44. The Restricted Committee thus recalls that the specific consent required by the provisions of Article L. 34-5 of the CPCE, combined with those of Article 4 of the GDPR, must be understood as a free, specific, informed, and unequivocal expression of will and can only result from the express consent of the user, given with full knowledge of the facts after adequate information on the use to which their personal data will be put. 45. It notes that the Court of Justice of the European Union stated, in its 2019 Planet49 GmbH decision, which concerned the validity of consent given in the context of participation in an online competition, that: "Article 7(a) of Directive 95 provides that the consent of the data subject may render such processing lawful provided that that consent is "unambiguously" given by the data subject. However, only active conduct on the part of that person with a view to manifesting consent is capable of satisfying that requirement" (CJEU, Grand Chamber, 1 October 2019, Planet49 GmbH, C-673/17, ECLI:EU:C:2019:801, paragraph 54). Therefore, it must be considered that if consent is not given unambiguously, it must be considered as lacking, which renders the processing unlawful for lack of a legal basis. More specifically, regarding the collection procedures, the CJEU states that "the expression of will referred to in Article 2(h) of Directive 95/46 must, in particular, be specific, in the sense that it must relate precisely to the data processing in question and cannot be inferred from an expression of will having a distinct purpose. In this case, contrary to what Planet49 argued, the fact that a user activates the participation button in the promotional game organized by that company cannot therefore be considered sufficient to consider that the user has validly given their consent to the placement of cookies" (ibid., paragraphs 58-59).
46. Furthermore, the Council of State held that "free, specific, informed, and unambiguous consent can only be the express consent of the user, given in full knowledge of the facts and after adequate information on the use that will be made of their personal data. "(EC, 10th and 9th Chambers Jointly, June 19, 2020, Google LLC, No. 430810, paragraph 21).
47. The Restricted Committee also notes, by way of illustration, that as early as 2017, the Article 29 Working Party (now the European Data Protection Board) published guidelines on consent aimed at clarifying the new provisions introduced by the GDPR. New Guidelines 5/2020 on consent were adopted on May 4, 2020, and specify that the free nature of consent "implies choice and real control for data subjects. As a general rule, the GDPR provides that if the data subject is not genuinely able to exercise a choice, feels coerced into consenting, or will suffer significant negative consequences if they do not consent, consent is not valid. […] In general terms, any inappropriate pressure or influence exerted on the data subject (which may manifest itself in various ways) preventing them from exercising their will will render consent invalid.
48. Finally, the Restricted Committee emphasizes that the work conducted by the Commission on cookie practices in relation to consent collection banners can usefully be used to assess more generally the conditions for obtaining free, unambiguous, specific, and informed consent, and serve as a reference in commercial prospecting when it is based on consent collection. It should be noted that the general rules relating to the conditions for the validity of consent, drawn in particular from Article 4 of the GDPR, are not intended to differ depending on the sector concerned, and that the CNIL is not required to issue sector-specific recommendations. In this regard, Deliberation No. 2020-091 of September 17, 2020, adopting guidelines relating to "cookies and other trackers," expressly reiterates that the consent required by Article 82 of the French Data Protection Act refers to the definition and conditions set out in Articles 4.11 and 7 of the GDPR (§§ 5 and 6). 49. Thus, by way of illustration and comparison, the restricted committee notes that in its deliberation no. 2020-092 of 17 September 2020 adopting a recommendation proposing practical methods of compliance in the event of the use of "cookies and other trackers", the Commission recommends that the organisations concerned ensure "that users take full advantage of the options available to them, in particular through the design chosen and the information provided (§ 10) […] In order not to mislead users, the Commission recommends that data controllers ensure that the interfaces for collecting choices do not include potentially misleading design practices that lead users to believe that their consent is mandatory or that visually highlight one choice more than another. It is recommended to use buttons and fonts of the same size, offering the same ease of reading, and highlighted in the same way" (§ 34). It adds that "care should be taken to ensure that the information accompanying each actionable element allowing consent or refusal to be expressed is easily understandable and does not require concentration or interpretation efforts on the part of the user. Thus, it is particularly recommended to ensure that it is not written in such a way that a quick or inattentive reading could lead to the belief that the selected option produces the opposite of what users thought they were choosing. "(§ 23). Otherwise, the unequivocal nature of consent would not be established.
50. The Restricted Committee also notes that studies conducted on digital interface practices, particularly regarding cookies, highlight the considerable impact of the appearance of consent banners on user choice, which can encourage users to make choices that do not reflect their preferences regarding data sharing.
51. Furthermore, contrary to the company's claims, the Restricted Committee notes that the sanction decision of December 29, 2023 (CNIL, FR, December 29, 2023, SAN-2023-025, published) is based on all of the above-mentioned elements, without imposing any new requirements. It merely applies pre-existing rules that the company was perfectly capable of understanding.
52. It is thus clear from all of these elements that the rules relating to the consent of data subjects well predate the inspection operations carried out against of SOMS and that they appeared sufficiently clear and precise to allow the latter to assess the validity of the consent collected by its partners and on which it relies to carry out its prospecting operations.
1.1.2. On the obligations incumbent on SOMS
53. The company criticizes the rapporteur for seeking to establish a regime of joint and several liability, not provided for in the legislation, between it and its primary collection partners. It considers that its liability should not be assessed in light of the legality of the consent collection mechanisms implemented by its partners – the latter having sole control over the collection media they publish – but in light of the obligations incumbent on it, itself, at the time of the findings.
54. In this regard, it argues that the legal framework applicable at the time of the inspection did not allow digital marketing players to make the obligations incumbent on each of them predictable, nor did the requirement to carry out verifications of the conditions for obtaining consent from recipients. data having been collected, according to the Commission, only in connection with the decisions rendered by the Restricted Committee at the beginning of 2024. It considers that the principle of non-retroactivity of repressive rules precludes it from being sanctioned on the basis of these decisions.
55. The company considers, in any event, to have implemented the necessary measures to ensure that it had valid consent, in accordance with the rules and recommendations applicable at the time of the inspection. In this regard, it emphasizes that it has, on the one hand, regulated its contractual relationships with its primary data collector partners and, on the other hand, carried out checks on the forms implemented, even though it was not legally required to do so.
56. The Restricted Committee notes that the data brokerage sector is characterized by the existence of a processing chain involving several parties, starting with the collection of data by the primary data collectors, followed by their transmission to one or more partners to enable to the latter to carry out commercial prospecting operations. In this context, each of the organizations involved must, according to its own responsibility, ensure the lawfulness of the operations in which it participates in this processing chain.
57. The Restricted Committee recalls that, pursuant to the combined provisions of Articles L. 34-5 of the CPCE and 4 of the GDPR, this lawfulness requires that the data controller who intends to carry out or have carried out commercial prospecting operations electronically have the unambiguous, specific, freely given, and informed consent of the data subjects.58. When prospect data has not been collected directly from them by the data controller, this consent may have been obtained at the time of initial data collection by the initial data collector, on behalf of the data controller. Failing this, it is the data controller's responsibility to collect or arrange for the collection of such consent before carrying out any prospecting activities (CNIL, FR, November 24, 2022, Sanction, No. SAN-2022-021, published; Deliberation No. 2021-131 of September 23, 2021, adopting a standard for the processing of personal data implemented for the purpose of managing commercial activities). 59. In this regard, the Restricted Committee upheld the liability of an organization, considering that a simple contractual commitment by the organization providing the data to comply with the GDPR and the applicable rules on commercial prospecting did not constitute a sufficient measure (CNIL, FR, November 24, 2022, Sanction No. SAN-2022-021, published; CNIL, FR, January 31, 2024, Sanction No. SAN-2024-003, published; CNIL, FR, April 4, 2024, Sanction No. SAN-2024-004, published).
60. The Restricted Committee emphasizes that, like the rules governing the conditions for the validity of consent, these requirements are not new and that they derive from the texts to which any organization that intends to carry out commercial prospecting operations electronically is subject in its capacity as data controller. 61. In this case, it is indeed the company SOMS which, as the person responsible for the direct electronic prospecting operations that it carries out, is subject to the provisions of Article L. 34-5 of the CPCE (and not the first-time collectors who do not directly prospect the persons concerned) which clearly requires, since the transposition into French law of the ePrivacy Directive in 2004, to obtain the consent of the persons concerned. It is therefore up to it, in this respect, to guarantee the lawfulness of these operations by ensuring the validity of the consent on which it intends to rely or, failing that, by obtaining said consent itself. It should be noted that Article 7 of the GDPR provides in this regard that "where processing is based on consent, the controller shall be able to demonstrate that the data subject has given consent to the processing of personal data concerning them."
62. Furthermore, the Restricted Committee reiterates that, regardless of the body responsible for collecting the consent of data subjects, the validity of that consent—and therefore the lawfulness of processing based on such consent—can only be assessed at the time it is collected, which, in this case, requires examining the collection forms implemented by the company's partners.
63. Thus, to the extent that SOMS has chosen not to collect this consent itself and to rely on that collected by its partners, ensuring the validity of said consent necessarily requires reviewing the collection mechanisms implemented by the primary data collectors.
1.2. On the Characterization of the Breach
64. The Restricted Committee notes that, to attest to the validity of the consent given by the individuals who received electronic sales prospecting, the company provided examples of forms implemented by two of its main suppliers, companies [X1] and [X2] (company [X3], according to the company, did not respond to its requests).
65. An examination of these forms reveals that a large majority of them (eight out of eleven for the forms implemented by company [X1], fourteen out of eighteen for those implemented by company [X2]) are presented in a similar manner (so-called "one-button" forms). After completing their contact details (and, where applicable, having checked a box to accept the rules of the game), the user has the choice between clicking on a button "I PARTICIPATE" or "I VALIDATE" (which can also be titled "VALIDATE, "VALIDATE MY DETAILS, "VALIDATE MY PARTICIPATION, "CONFIRM, "I PLAY" or even "I ANSWER THE QUESTIONS TO APPLY"), located at the bottom of the form and allowing both to validate their participation in the game and to consent to their data being transmitted to partners and used by them for commercial prospecting purposes, or to click on a link allowing them to participate only in the competition, refusing the transmission and use of their data for commercial prospecting purposes (link which can be contained in the sentence "if I wish to continue without receiving offers from partners of […], I click here, or "I wish to go to the next step without accept commercial offers from […] by clicking on this link").
66. The Restricted Committee considers that, as designed, the proposed forms do not allow data subjects to validly express a choice reflecting their preferences regarding the transmission and use of their data for commercial prospecting purposes. Indeed, the overall overview of the interfaces particularly highlights the "I PARTICIPATE" or "I VALIDATE" buttons, which, by their size – significantly larger than the rest of the information – and their color – which contrasts with the background used – stand out from the other information provided. Similarly, their title suggests the conclusion of the user journey rather than the use of data for commercial prospecting purposes, since, in everyday language, one "validates" the information entered in a form and "authorizes" or "accepts" the use of data. Finally, their placement gives the impression that they must be clicked to complete the registration and participate in the competition. Conversely, the hyperlink allowing participants to participate in the competition without agreeing to the use of their data by the partners is presented in the body of the text above or below the acceptance buttons, in font size significantly smaller than that used for the buttons and without any particular emphasis, so it does not appear intuitive that it is possible to participate without clicking on one of the aforementioned buttons and therefore without transmitting their data to third parties for prospecting purposes. The consent obtained is, under these conditions, neither unequivocal nor free. 67. The Restricted Committee also notes that some of the forms implemented by companies [X2] and [X1] include not a single button, but two buttons (so-called "two-button forms"), one titled "I VALIDATE" and the other titled "I REFUSE".
68. However, while the information above the "I VALIDATE" button clearly states that by clicking on this button, the user agrees to their data being transmitted to partners for commercial prospecting purposes, it appears, however, that the user is not able to understand the consequences of clicking on the "I REFUSE" button. Indeed, either these consequences are not specified (as is the case with the form accessible from the consoavenue.fr website), and the user may therefore believe that such a click makes it impossible to participate in the competition; That is, even when it is specified that clicking on the "I REFUSE" button allows users to participate without agreeing to the transmission and use of their data for prospecting purposes, a quick reading may lead the user to believe, given the language used, that "refusing" also implies refusing to participate in the competition, which is not the case here.
69. Under these conditions, the Restricted Committee considers that, like the single-button forms and for the same reasons, the very design of these two-button forms provided by the company does not allow for the collection of free and unequivocal consent, since their presentation strongly encourages the user to agree to the transmission of their data for commercial prospecting purposes.
70. The Restricted Committee recalls that, while the design of these forms is not attributable to it as such, the company should have, as indicated in points 53 to 63 of this deliberation, ensured the validity of the consent it intends to rely on to carry out its prospecting operations.
71. The Restricted Committee notes in this regard that the company indicated that, on the one hand, it has provided in its contractual relations with its primary collection partners that the latter undertake to validly collect the consent of the data subjects and, on the other hand, that it has implemented certain procedures for verifying the collection forms since the beginning of 2022. Regarding the contractual framework, the restricted committee notes that the clauses contained in the contracts entered into with its partners appear very general – the latter undertaking to validly collect the consent of the persons concerned, to document said consent and to transmit a trace thereof to SOMS – and that in any event, whatever the contractual clauses surrounding these relationships, the company receiving the data cannot be satisfied with them and must carry out concrete checks on the conditions for collecting the consent on which it intends to rely to carry out its prospecting operations. With regard to these checks, the company indicated that it regularly examines the collection forms implemented by its partners. However, the findings demonstrate that these checks were clearly insufficient and that in any event, the company did not draw the necessary conclusions regarding the lack of validity of the consent collected and continued to use the data transmitted to carry out its commercial prospecting operations. It appears that, in light of the documents in the file, none of the forms submitted as part of the inspection procedure allowed valid consent to be obtained from the persons concerned, even though the checks carried out by the company had begun several months previously.72. Under these conditions, the company's failure to obtain valid consent from the data subjects to carry out its electronic marketing operations constitutes a breach of Article L. 34-5 of the CPCE.
73. For its future electronic marketing operations, the company must take the necessary steps to address the identified breach by refraining from carrying out these operations without valid consent. 2. On the failure to demonstrate that the data subject has given their consent (data provided by the company [X3])
74. Article 7(1) of the GDPR provides that "where processing is based on consent, the controller shall be able to demonstrate that the data subject has given their consent to the processing of personal data relating to them."
75. By way of illustration, as the European Data Protection Board emphasizes in its Guidelines 5/2020 on consent, adopted on 4 May 2020, these provisions place the burden of proof on the controller, who "shall bear the burden of proving that valid consent has been obtained from the data subject" (107). "For example, the controller may keep a record of the declarations of consent received in order to be able to certify how and when consent was obtained, and the information provided to the data subject." data subject at the time. The controller must be able to demonstrate that the data subject was informed and that the workflow met all relevant criteria for valid consent. The reason for this obligation established by the GDPR is that controllers must be accountable for obtaining valid consent from data subjects and for the consent mechanisms they have established" (108).
76. The aforementioned guidelines also recall that "controllers are free to develop methods appropriate to their daily operations to comply with this provision […] (106) The GDPR does not prescribe precisely how this should be done. The data controller must, however, be able to prove that a data subject has given their consent in a specific case" (107).
77. Pursuant to the provisions of Article 7 of the GDPR, combined with those of Article L. 34-5 of the CPCE, the data controller for electronic commercial prospecting operations must have unambiguous, specific, freely given, and informed consent from the data subjects and be able to demonstrate it. In the event that the prospects' data has not been collected directly from them by the prospecting organization and that consent has been obtained, on behalf of the data controller, by the initial collector, it is up to the prospecting organization to prove that it has this consent (CNIL, FR, November 2, 2022, Sanction, No. SAN-2022-021, published; CNIL, FR, October 12, 2023, Sanction, No. SAN-2023-015, published).
78. The rapporteur notes that the company was unable to provide the delegation with evidence of the conditions for obtaining consent from individuals whose data was transmitted to it by the company [X3]. He considers that, since the company bases its electronic marketing operations on such consent, it should be able to provide proof thereof, and that failing this, a breach of Article 7 of the GDPR appears to have occurred.
79. In defense, the company argues that the provisions of Article 7 of the GDPR must be interpreted as requiring the data controller to be able to provide individual proof of consent from a single individual, and not comprehensive proof of the consent collection mechanisms implemented.
80. Regarding individual proof of consent, it states that its primary data collection partners have contractually undertaken to retain such proof and to provide it to it upon first request, without it being required to retain proof of consent itself. It emphasizes that it has always been able to respond favorably to the requests made to it by the data subjects.
81. Regarding the proof of the existence of valid consent mechanisms, which it describes as "global proof," it considers that it does not fall within the scope of Article 7 of the GDPR and that there is a concurrent violation between the alleged breach of these provisions and the breach of Article L. 34-5 of the CPCE. It maintains that, in any event, it cannot be held liable for the failure of its partner, the company [X3], to comply with its obligations, since it itself complied with its obligations.
82. In this case, the Restricted Committee notes that in 2022, more than 100,000 people whose data was transmitted to it by the company [X3] were contacted by SOMS by email, and more than 1.1 million by SMS. The company stated that the company [X3] was contractually responsible for collecting, on its behalf, the consent of the persons concerned, for retaining proof thereof and for transmitting this proof to it upon first request. The restricted committee notes that the company was not able to provide the delegation with the requested information concerning the number of forms used to collect the data of the individuals approached, and for each of the forms, the number of unique individuals whose data was collected by this form and who received electronic prospecting, the scripts or models used to generate all of these collection forms or, failing that, the screenshots of each of the said forms. It stated that "despite [its] written requests and [its] exchanges with the company [X3], [it] had not succeeded in obtaining a response from them within the time limits set.
83. First, the restricted committee notes that the breach alleged against the company under Article 7 of the GDPR and that alleged against it under Article L. 34-5 of the CPCE arise from two very distinct acts of conduct and relate to distinct facts and are therefore not likely to be confused. Indeed, it is clear from the investigation that the company was able to provide proof of the mechanisms for obtaining the consent of individuals whose data was transmitted to it by two of its partners, the companies [X1] and [X2]. However, to the extent that it was found that these mechanisms did not allow for the collection of free, specific, informed and unequivocal consent, the company could not rely on them to base its operations on electronic canvassing and, therefore, a breach of Article L. 34-5 of the CPCE appears to have been established.
84. With regard to the data provided by the company [X3], the complaint is different insofar as SOMS, which bases its processing on the consent allegedly obtained by the company [X3], was unable to provide the supervisory delegation with proof of the consent given by the individuals whose data was transmitted to it by this partner. This state of affairs made it impossible for the CNIL to examine the validity of the conditions for obtaining said consent and made it impossible for the company to prove its compliance with the obligations arising from Article 7, paragraph 1 of the GDPR.
85. The Restricted Committee thus notes that the two breaches in question concern very distinct data, suppliers, and behaviors and that the company cannot therefore rely on the existence of a competitive qualification process.
86. Secondly, the Restricted Committee observes that, in order to verify that the company was Although the company was able to provide proof of the consent given by the individuals whose data had been transmitted to it by the company [X3], the delegation, in view of the number of individuals concerned (more than 1.2 million), requested that it be provided with evidence of the consent collection mechanisms implemented (number of forms used to collect the data, number of unique individuals whose data had been collected through each of the forms and who had been recipients of electronic sales prospecting, scripts or templates used to generate all the forms or, failing that, screenshots of each of these forms). The company indicated that it was unable to provide such evidence, specifying that despite requests made to the company [X3], the latter had refused to provide it with the requested information. The restricted committee thus observes that the company was unable to present this evidence, even though it was provided for in its contractual clauses: it was not even able to provide a precise description, with copies of blank forms, of the mechanisms implemented to obtain consent. These facts are sufficient to establish that it is unable to demonstrate that the individuals whose data is transmitted to it by company [X3], and which is used for commercial prospecting purposes electronically, have consented to this prospecting.
87. Third, the Restricted Committee notes that the company is free to adopt the method it deems appropriate to comply with the provisions of Article 7, paragraph 1 of the GDPR. However, regardless of the means chosen, it is up to the company, as data controller, to be able to provide proof of the lawfulness of the prospecting operations carried out. Therefore, the company cannot hide behind the lack of cooperation of its partner to exonerate itself from its own liability, as the fact of being dependent on other organizations is a matter of its own choice.88. The Restricted Committee notes in this regard that, having found that its partner was unable to provide it with the requested evidence – and that it itself was therefore unable to comply with the provisions of Article 7(1) of the GDPR – it was up to the company either to cease using the data transmitted or to obtain the consent of the data subjects itself. However, it is clear from the investigation that, as early as May 30, 2023, SOMS contacted [X3] to provide it with the evidence requested by the delegation and that, despite the lack of a response from its partner, it continued to use the data transmitted to carry out its electronic sales prospecting operations until October 18, 2024, allowing a period of nearly 17 months to elapse before suspending their use. 89. Taking all of these elements into account, the Restricted Committee considers that, since the company has failed to implement a system enabling it to effectively demonstrate that the individuals whose data was collected by the company [X3] have given their consent to receive electronic marketing messages from the company SOMS, there has been a breach of Article 7, paragraph 1 of the GDPR. D. On the failure to transmit prospect data to partners so that they can conduct prospecting themselves by post or telephone: failure to comply with the requirement to have a legal basis
90. In law, with regard to the requirement to have a legal basis, Article 6(1) of the GDPR provides that "processing shall be lawful only if, and to the extent that, at least one of the following conditions is met:
(a) the data subject has consented to the processing of his or her personal data for one or more specific purposes;
[…]
(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child […].
91. The Court of Justice of the European Union has repeatedly stated that, for an organization to be able to To base its processing on the legal basis of legitimate interest, provided for in f) of the aforementioned article, three cumulative conditions must be met, namely the pursuit of a legitimate interest by the controller or by a third party, the necessity of processing personal data for the purposes of the legitimate interest pursued, and the condition that the interests or fundamental rights and freedoms of the data subject do not prevail over the legitimate interest of the controller or a third party (in particular, CJEU, 4 July 2023, Meta, C-252/21).
92. With regard to this last condition, the Court has clarified that it involves "a weighing up of the competing rights and interests at issue which depends, in principle, on the specific circumstances of the particular case" (CJEU, 17 June 2021, M.I.C.M., C 597/19, paragraph 111; CJEU, 4 July 2023, Meta, C-252/21).
93. It also emphasized (ibid.) that the interests and fundamental rights of the data subject may, in particular, prevail over the interests of the controller when personal data are processed in circumstances where they would not reasonably expect such processing. In this regard, it follows from recital 47 of the GDPR that "the legitimate interests of a controller, including those of a controller to whom the personal data may be disclosed, or of a third party, may constitute a legal basis for processing, unless the interests or fundamental rights and freedoms of the data subject prevail, taking into account the reasonable expectations of data subjects based on their relationship with the controller. Such a legitimate interest could, for example, exist where there is a relevant and appropriate relationship between the data subject and the controller in situations such as those where the data subject is a client of the controller or is employed by the controller." In any event, the existence of a legitimate interest should be carefully assessed, in particular to determine whether a data subject can reasonably expect, at the time and in the context of the collection of personal data, that the personal data will be processed for a given purpose. The interests and fundamental rights of the data subject may, in particular, prevail over the interests of the controller when personal data are processed in circumstances where data subjects do not reasonably expect further processing. 94. Furthermore, the Article 29 Working Party (now the European Data Protection Board) stressed in its Opinion 06/2014 on the concept of legitimate interest (adopted on 9 April 2014, under Directive 95/46/EC) that the concepts of "interests" and "rights" should be interpreted broadly, meaning that "all relevant interests of the data subject should be taken into account". It also specified that when assessing the impact of processing, "in addition to the negative consequences that may be specifically foreseen, moral repercussions must also be taken into account, such as irritation, fear, and distress that may result from the loss of control exercised by the data subject over their personal information, or from the discovery of misuse […] of this information […]. […] The term "impact", as used in this opinion, covers all possible consequences (potential or actual) of data processing.
95. Finally, by way of illustration, the CNIL recalls, in its framework relating to the processing of personal data implemented for the purposes of managing commercial activities, adopted on September 23, 2021, that the transmission of data to partners (for payment or within the framework of commercial agreements between two companies), for the purpose of carrying out non-electronic prospecting operations, may be carried out on the basis of the legitimate interest of the organization transmitting the data. The latter must then inform the data subjects, on the data collection medium, of the purpose of this transmission and the categories of partners to whom the data will be sent. It must also offer the data subjects, expressly and unambiguously, the opportunity to object, free of charge and in a simple manner, to the transmission of their personal data at the time it is collected and at any time. 96. In law, with regard to personal data contained in public directories based on telephone operator data and their use for prospecting purposes, Article L. 34 of the French Postal and Electronic Communications Code provides that "the publication of lists of subscribers or users of electronic communications networks or services is free, subject to the protection of the rights of individuals.
97. Among the rights guaranteed are the right of any person to be included in the lists of subscribers or users published in directories or consultable through an information service or not to be included, to object to the inclusion of certain data concerning them to the extent compatible with the requirements of compiling the directories and information services for which these lists are intended, to be informed in advance of the purposes for which directories and information services are compiled from these lists and of the possibilities for using them based on search functions integrated into their electronic version. to prohibit the use of personal information concerning them in commercial transactions, as well as to be able to obtain disclosure of said personal information and demand that it be rectified, completed, clarified, updated, or deleted, under the conditions provided for in Articles 49 and 50 of Law No. 78-17 of January 6, 1978, relating to information technology, files, and civil liberties.
98. The prior consent of subscribers to a mobile telephone operator is required for any inclusion of personal data concerning them in the subscriber or user lists established by their mobile operator, intended to be published in directories or consultable through an information service.
99. Upon any request submitted to publish a universal directory or provide a universal information service, even if limited to a specific geographical area, operators are required to communicate, under non-discriminatory conditions and at a rate reflecting the costs of the service provided, the list of all subscribers or users to whom they have assigned, directly or through a distributor, one or more numbers from the national telephone numbering plan provided for in Article L. 44. (…)"
100. Article R. 10 of the same code provides that "any person who has subscribed to the public telephone service has the right to be included free of charge on a list of subscribers or users intended for publication. They may obtain free of charge from the operator to which they subscribe or from the distributor of their service:
1. Not to be included on lists of subscribers or users published or likely to be consulted by information services;
2. That these lists do not include their full home address except when the professional activity mentioned consists of providing goods or services to consumers;
(…)
4. That personal data concerning them from lists of subscribers or of users are not used in direct prospecting operations either by post or by electronic communications, without prejudice to the provisions of Article L. 34-5, with the exception of operations concerning the provision of telephone service to the public and falling within the contractual relationship between the operator and the subscriber.
(…) The prior consent of subscribers to a mobile telephone operator is required for any inclusion of personal data concerning them in the subscriber or user lists mentioned in the first paragraph. Failing this, they are automatically entitled to the provisions of paragraph 1 above. (…)"
101. It follows from the provisions of I of Article R. 10-3 of the same code that the lists provided to directory publishers include "the surnames, first names and, where applicable, the business names or company names, addresses, and telephone numbers of subscribers to the public telephone service and its users" and that these lists "reveal the objections that subscribers or users have made pursuant to Article R. 10.
102. Under the first paragraph of II of Article R. 10-4, "the use of lists obtained pursuant to the fourth paragraph of Article L. 34 for purposes other than the provision of universal directories or universal telephone directory information services is prohibited. Unless otherwise stipulated in the contract, any sale of lists obtained pursuant to the fourth paragraph of Article L. 34 is prohibited.
103. Finally, in its Opinion No. 2002-145 of On February 21, 2002, regarding the draft decree relating to the universal directory and amending the Post and Telecommunications Code, the Telecommunications Regulatory Authority (now the Regulatory Authority for Electronic Communications, Posts and Press Distribution, hereinafter "ARCEP") highlighted the existence of "two markets, with different list transfer regimes:
- on the one hand, a regulated market for transfers for the purpose of directory and universal information services, under technical and financial conditions governed by specific telecommunications law, with disputes relating to the transfer conditions falling within the jurisdiction of the Authority;
- on the other hand, a free market for transfers for other purposes, and in particular for commercial prospecting purposes, under conditions governed by common law and competition law, with disputes falling under the jurisdiction of the ordinary courts or the Competition Council.
These provisions also show that telecommunications operators or their distributors remain, in practice, the sole source for the market of data used for commercial prospecting purposes, unless there are contractual provisions to the contrary between them and providers of directory or universal information services.
For example, France Télécom, as an operator, may freely transfer data concerning its own subscribers, but, as a provider of a directory and universal information service, it may not transfer the complete list of subscribers it has compiled for this purpose without the consent of all the operators who provided their lists.
104. The rapporteur considers that, in order to transmit data from its database […] to its customers, so that they can use it to carry out commercial prospecting operations by post or telephone, the company cannot, in this case, rely on any valid legal basis with regard to the methods used to implement its processing. While it notes that data transmission processing for non-electronic commercial prospecting purposes may be based on the company's legitimate interests, pursuant to Article 6, paragraph 1, f) of the GDPR and as recalled by the aforementioned framework, it considers that to the extent that this transmission is carried out without being brought to the attention of the data subjects – and that they are therefore not able to exercise their rights in this context – the interests and fundamental rights of the data subjects are not sufficiently protected and must prevail over the interests pursued by the company.
105. In its defense, the company considers, on the contrary, that the conditions allowing it to rely on the legal basis of legitimate interest are met.
106. The company states, on the one hand, that the vast majority of the data transmitted to its partners comes from the company [X4], which is subject to the legal regime applicable to telecommunications operators, particularly in terms of information and the right to object. In this regard, it recalls that the persons concerned have the option, at any time, to register on anti-prospecting lists such as the red list, anti-prospecting list (formerly the [X4] list), chamois list, or Robinson list. Thus, it notes that the data transmitted to it by [X4], and which it forwards to its advertising clients (after having carried out further checks itself via the Bloctel service), never concerns individuals who have opted out of receiving commercial prospecting.
107. Furthermore, the company specifies that it may also happen that its primary data collection partners, such as [X1] or [X2], transmit landline telephone numbers and postal addresses to it. In this case, the data is "reliable" based on the data transmitted by [X4], and SOMS therefore considers that the data transmitted is, ultimately, that of [X4]. The company also indicated that, incidentally, it may be required to transmit to its customers mobile phone numbers collected by its partners, for the exclusive purpose of conducting telephone prospecting operations (and not by SMS). In this context only, it may be required to directly transmit the data collected by companies such as [X1] or [X2]. The company considers that, as with landline numbers and postal addresses, the interests of the data subjects are protected to the extent that they have consented to receive commercial prospecting, including by telephone, and have been informed through the data protection policy of the primary data collector, as well as that of SOMS. 108. The company reiterates that, even though it is not in direct contact with the data subjects, it itself implements certain measures to ensure that the rights of individuals are respected, such as the deduplication of databases transmitted by its partners with its own deterrent database (to ensure that individuals who previously objected to receiving commercial prospecting do not end up re-registered in the database [...]), the carrying out of checks with the Bloctel service, and the contractual supervision of the use of transmitted files.
109. The company also notes that Articles 13 and 14 of the GDPR only require the data controller to provide information on the categories of recipients, but do not, however, require that individuals be informed of each secondary transmission, nor that the precise identity of these subsequent recipients be revealed to them (especially when these are not yet known). It considers that the concept of "reasonable expectations" cannot be used to artificially expand the scope of the information obligations provided for by the GDPR. 110. The Restricted Committee notes that, as part of its "ListConnect" offering, the company transmits data from its database […] to its customers, so that they can carry out prospecting operations by post or telephone. The company specified that the data thus transmitted (postal and telephone contact details of the data subjects) came, for the most part, from the company [X4], but also, for some, from data providers such as the companies [X1], […] or […]. In the first ten months of 2022, the company transferred more than 1.2 million landline telephone numbers and more than 125,000 postal addresses to its customers.
111. It thus appears that the data of the data subjects is subject to successive transmissions and is ultimately processed by three different organizations: first, the initial data providers, namely the telephone operators (including the company [X4]) or other partners of the company such as [X1], which transmits them to SOMS (first level of transmission); secondly, SOMS, the recipient of the data, which records them in its database, updates them where necessary (in particular by verifying that the data subjects are not registered on anti-prospecting lists or that they have not previously objected to such prospecting operations with SOMS) and in turn transmits them, depending on the segment requested, to its advertising clients (second level of transmission); thirdly, SOMS's clients, who receive the data and use them to carry out commercial prospecting operations by post or telephone. Since the company has indicated that it bases this transmission on its legitimate interest, pursuant to Article 6(1)(f) of the GDPR, it is necessary to verify whether the conditions allowing it to rely on such a legal basis are met.
112. With regard to the first two conditions set out by the CJEU, the Restricted Committee considers that the interest pursued can be characterized as legitimate, in that it is of a commercial nature and is consubstantial with the company's economic model, and that the data collected for the purposes of these interests may appear necessary. It has also long been accepted that databases of prospects can be transmitted between economic actors, on the legal basis of consent or legitimate interest, if the rules relating to the type of prospecting in question and to data protection are respected, so that individuals retain control over their personal data.113. Regarding the third condition, it is appropriate to examine whether, in this case, the interests or fundamental rights and freedoms of the data subjects must prevail over the legitimate interests of the company. The Restricted Committee reiterates that, in assessing this condition, it is necessary to examine, in particular, whether these data subjects could reasonably expect such processing.
114. In examining this third condition, the Restricted Committee considers that, in accordance with what SOLOCAL has indicated, a distinction must be made between data originating from [X4] and data originating from other primary data collectors.
115. First, with regard to data originating from [X4], the Restricted Committee considers that the latter's status as a telephone operator and directory publisher and the legal framework governing directory listings must be taken into consideration. 116. The Restricted Committee first notes that it follows from the provisions cited above that the data transmitted by [X4] - which includes, associated with subscriber identities, telephone numbers and postal addresses - are also, by default, made available to any directory publisher or information service and published in the directories. Thus, the natural persons whose data are processed can only expect that this data will be used by third parties, within certain limits. 117. Next, the Restricted Committee notes that in this case, the contract concluded between [X4] and SOMS provides that "[X4] provides the beneficiary [PAGES JAUNES MARKETING SERVICES, now SOMS] with the right […] to use the Directory Data in order to enable it to provide its "Customers" with its "Service".
118. The Restricted Committee considers that these elements alone do not allow it to determine whether the data transmitted by [X4] to SOMS are exclusively those concerning its own subscribers – in which case [X4] may freely transmit these data to its commercial partners – or whether these are data available to it in its capacity as a directory operator (and which were therefore collected by it but also by other operators). It should be recalled that in this second case, while Article R.10-4, II of the CPCE prohibits in principle any sale of lists obtained pursuant to Article L. 34 for purposes other than the provision of directories or information services, it also provides for the possibility of derogating from this prohibition through contractual stipulations. The company [X4] could then only transmit these lists to the company SOMS subject to having obtained the consent of all the operators who carried out the initial data collection. The Restricted Committee considers that, insofar as the present proceedings are not directed against the company [X4], and in the absence of evidence suggesting that the latter is not complying with the provisions of the CPCE, it must be considered that the conditions allowing it to transmit the data concerned to the company SOMS, in a lawful manner, were met.
119. The Restricted Committee notes that in any event, the persons concerned have the possibility of objecting ab initio to the publication of their data in the directories or to their use for prospecting purposes with their operator, pursuant to Article L. 34 of the CPCE (through their inclusion on the "red" or "anti-prospecting" lists). Indeed, these provisions provide that the persons concerned may "prohibit the use of personal information concerning them in commercial operations," operations that Article R. 10 of the French Postal and Electronic Communications Code specifies may be "direct prospecting operations either by post or by electronic communications, without prejudice to the provisions of Article L. 34-5." In this regard, the Restricted Committee notes that the contract concluded between [X4] and SOMS specifies that the database transmitted is expurgated from the "Red," [X4] (now the anti-prospecting list), and Chamois lists.
120. It follows that, for individuals who have not objected to publication or, specifically, to prospecting, the postal or telephone contact details in directories may be used for postal or telephone prospecting, which does not fall under Article L. 34-5 of the same code (text messages and automated dialers in this case). This use must comply with the GDPR but corresponds to the reasonable expectations of individuals who have not objected. 121. Therefore, for these three reasons, the Restricted Committee considers that the use of contact details published in directories by companies carrying out prospecting operations falls within the reasonable expectations of the data subjects, who have the right to object to it, and that [X4] was thus entitled, on the basis of its legitimate interest within the meaning of Article 6 of the GDPR, to communicate to its commercial partners, for remuneration and provided that the provisions of the CPCE are complied with, a structured list of the contact details of subscribers who have not objected to being contacted pursuant to Article L. 34 of the CPCE, for the purposes of postal and telephone prospecting (excluding SMS and automated calling). Similarly, these partners may rely on their legitimate interest, subject to a specific examination of each situation, to forward the data to another prospecting company. 122. It follows from all of the above that the complaint that the transmission by SOMS of data from [X4] to its customers, for the purpose of postal and telephone prospecting (excluding SMS and automated calling), lacked a legal basis, is unfounded.
123. The Restricted Committee nevertheless reiterates that transmissions, which constitute the processing of personal data within the meaning of Article 4 of the GDPR, must comply with all the provisions of the GDPR, particularly with regard to information and the right to object. Regarding the right to object, data subjects have the option to object ab initio to the publication or use of their data for prospecting purposes by their operator (by registering on "red" or "anti-prospecting" lists), which then prevents the telephone operator or directory publisher from transmitting their data to commercial partners for prospecting purposes. They may also, more generally and at any time, express their wish not to be contacted by registering with services such as Bloctel (a public service designed to ensure the proper dissemination of subscribers objecting to telephone prospecting) or the Robinson list (a service set up by FEVAD to properly process objections to postal prospecting). These measures are implemented without prejudice to other forms of objection based on the GDPR. 124. As regards information, it is necessary to provide sufficient information to the persons concerned about the categories of recipients of the data. The Restricted Committee considers in particular that if, as in this case, the data are transmitted successively to first-tier recipients (such as SOMS) and then to second-tier recipients (such as SOMS's customers), the data subjects must be informed of the existence of these "second-tier" recipients, either by the telephone operator or by the recipients.
125. The Restricted Committee notes that the rapporteur based his argument on a failure to inform the data subjects. The evidence in the case file does not, in fact, establish whether the information was provided correctly. However, since the complaint relates to the lack of a legal basis, it must be dismissed, without this rejection being understood as validating the conditions for informing data subjects about these successive transmissions of their data, which the Restricted Committee invites the respondent to reconsider.
126. Second, with regard to mobile phone numbers collected by companies such as [X1] or [X2] through competitions (and transmitted by SOMS to its advertising clients so that the latter could use them exclusively for telephone prospecting, and not by SMS), the Restricted Committee recalls that, as demonstrated above, the consent collected through the forms implemented by these first-time collectors cannot be considered valid.
127. It also notes that, while individuals were well informed through these forms of the transmission of their data to SOMS, no information was provided to them regarding a possible retransmission of said data by SOMS to other organizations, which they therefore could not reasonably expect. The Restricted Committee does not dispute that the information to be provided may be limited to categories of recipients when it is not possible to do otherwise, but it nevertheless considers it essential that the information provided allows individuals to assess the consequences of their choice regarding this transmission, by informing them of the extent of it, which does not appear to be the case here. The Restricted Committee therefore considers that the legitimate interest of SOMS cannot be invoked.
128. Therefore, the transmission of this data to SOMS's customers cannot be based on the consent of the individuals or on the legitimate interest of SOMS. It is indeed devoid of any legal basis.129. In conclusion, the Restricted Committee considers that a breach of Article 6 of the GDPR has occurred exclusively with respect to data collected through online competitions and transmitted by SOMS to its advertising clients so that the latter can conduct prospecting operations by mail or telephone (excluding SMS and automated dialers). The Restricted Committee notes the residual nature of the data concerned (78,172 mobile phone numbers were transmitted in 2022, out of a total volume of 840,293 landline numbers and postal addresses).
III. ON CORRECTIVE MEASURES AND THEIR PUBLICITY
130. Under Article 20-IV of Law No. 78-17 of January 6, 1978, as amended, "when the data controller or its processor fails to comply with the obligations arising from Regulation (EU) 2016/679 of April 27, 2016, or this Law, the President of the National Commission for Information Technology and Civil Liberties may […] refer the matter to the Commission's restricted committee with a view to issuing, after an adversarial procedure, one or more of the following measures: […]
2° An injunction to bring the processing into compliance with the obligations arising from Regulation (EU) 2016/679 of April 27, 2016, or this Law, or to comply with requests made by the data subject to exercise their rights, which may be accompanied, except in cases where the processing is carried out by the State, a penalty payment in an amount not exceeding €100,000 per day of delay from the date set by the restricted committee;
7° Except in cases where the processing is carried out by the State, an administrative fine not exceeding €10 million or, in the case of an undertaking, 2% of the total worldwide annual turnover for the previous financial year, whichever is higher. In the cases mentioned in points 5 and 6 of Article 83 of Regulation (EU) 2016/679 of 27 April 2016, these ceilings are increased to €20 million and 4% of said turnover, respectively. The restricted committee shall take into account, in determining the amount of the fine, the criteria specified in the same Article 83.
131. Article 83 of the GDPR further provides that "each supervisory authority shall ensure that the administrative fines imposed under this Article for infringements of this Regulation referred to in paragraphs 4, 5 and 6 are, in each case, effective, proportionate and dissuasive, before specifying the factors to be taken into account when deciding whether to impose an administrative fine and when deciding the amount of that fine. 132. Finally, Article 22, paragraph 2 of the Data Protection Act provides that "the restricted committee may make public the measures it takes."
A. On the imposition of an administrative fine and its amount
133. The rapporteur proposes that the restricted committee impose an administrative fine on the company in light of the breaches established under Articles L. 34-5 of the CPCE and Articles 6 and 7 of the GDPR.
134. In defense, the company requests that the restricted committee not impose a fine or, failing that, to drastically reduce the amount proposed by the rapporteur.
135. It considers that, considering the established breaches, they are not of a serious nature. It considers that the rapporteur did not take into consideration all the criteria set out in Article 83, paragraph 2 of the GDPR, and notes in particular that the processing operations in question are not particularly sensitive. that they are implemented solely at the national level and that the data subjects have not suffered any harm. It considers that it has not committed any negligence and that it has been sufficiently diligent, highlighting the measures taken before and after the inspection as well as its full cooperation with the CNIL services. It emphasizes that it has never been convicted for failing to comply with its obligations relating to consent or data transmission and states that it has cooperated fully with the CNIL.
136. The company also believes that the economic difficulties encountered by the SOLOCAL group must be taken into account when determining the amount of a possible fine. The company also notes that its direct marketing activities represent only €1,689,725 in 2023, or 2.21% of its turnover (compared to 97.79% for its website creation business), and that only a portion of this figure is affected by the breaches. It therefore requests the Restricted Committee to limit the basis for calculating the fine to the portion of the turnover generated by the activities affected by the breaches.
137. Furthermore, the company considers that the amount of the fine proposed by the rapporteur appears disproportionate in light of the EDPB Guidelines on the calculation of administrative fines and other sanctions imposed by the Restricted Committee.
138. As a preliminary point, the Restricted Committee recalls that the requirement to state reasons for an administrative sanction does not require the Restricted Committee to rule on all the criteria provided for in Article 83 of the GDPR, nor does it imply that the figures relating to the method of determining the amount of the proposed or imposed sanction must be provided (EC, 10th/9th ch., 19 June 2020, No. 430810; EC, 10th/9th ch., 14 May 2024, No. 472221). Furthermore, if the guidelines adopted by the European Committee While the Data Protection Regulation aims to establish harmonized starting amounts and common guidelines on the basis of which administrative fines can be calculated, supervisory authorities "are under no obligation to follow all the steps if they are not applicable in a given case, nor to provide reasons for those aspects of the guidelines that are not applicable. However, the reasoning should include, at a minimum, the factors that made it possible to determine the degree of seriousness, the turnover applied, and the aggravating or mitigating factors that were taken into consideration."
139. That being said, the Restricted Committee considers that it is appropriate, in this case, to examine the relevant criteria of Article 83 of the GDPR to decide whether to impose an administrative fine on the company and, if so, to determine its amount.
1) On the imposition of the fine
140. First, the Restricted Committee considers that, pursuant to Article 83(2)(a) of the GDPR, it is appropriate to take into account the nature, seriousness, and duration of the violations, taking into account the nature, scope, or purpose of the processing operations concerned, as well as the number of data subjects affected and the level of damage they have suffered.
141. It notes that in this case, two of the breaches found fall within the provisions of Article 83(5) of the GDPR and are liable to be punished by the highest fine provided for by the European legislature, namely €20 million or, in the case of a company, up to 4% of its turnover. For clarification, the guidelines on the application and setting of administrative fines adopted by the Article 29 Working Party on October 3, 2017, emphasize that by "setting two different maximum amounts for the administrative fine (€10 million and €20 million), the regulation already indicates that violations of certain provisions of the regulation may be more serious than violations of other provisions."
142. The Restricted Committee emphasizes that these breaches concern the basic principles of processing and relate in particular to its lawfulness, with some of the commercial prospecting operations carried out occurring without a valid legal basis (the company does not have the consent of the data subjects to solicit them electronically and cannot rely on the legal basis of legitimate interest to transmit certain data of prospects to its customers to be contacted by telephone). The Restricted Committee also emphasizes the particularly high number of individuals whose data the company processes, with its database […] containing more than 75 million entries, for a deduplicated total of 35 million unique individuals, or approximately half of the French population.
143. With regard more specifically to the breach of Article L. 34-5 of the CPCE, the Restricted Committee wishes to emphasize its particular seriousness, as it was found that none of the forms submitted by the company allowed valid consent to be obtained from the individuals concerned. This proportion attests to the systemic and not isolated nature of the breach, noting that the forms examined come from two of the company's three largest data providers. Furthermore, the Restricted Committee wishes to emphasize the number of individuals affected by the breach, as the company indicated that it had canvassed nearly 5.2 million individuals electronically during 2022.
144. With regard to the breach of Article 7 of the GDPR, the Restricted Committee notes that the company was unable to provide proof of consent obtained, on its behalf, by one of its main data providers. Such a breach also concerns: a particularly large number of individuals, with the company having indicated that it had contacted, in 2022, more than 1.2 million individuals (including SMS and emails) whose data was transmitted to it by this provider.
145. Finally, with regard to the breach of Article 6 of the GDPR, the Restricted Committee notes that the company transmitted to its customers, in 2022, the mobile phone numbers of 78,172 individuals, individuals without them having any reasonable expectation of doing so, this processing having thus taken place without the company being able to legitimately rely on the legal basis of legitimate interest to do so.146. Second, the Restricted Committee considers that the criterion provided for in Article 83(2)(b) of the GDPR, relating to whether the violation was committed deliberately or negligently, should be taken into account.
147. As already noted, the Restricted Committee emphasizes that the rules relating to commercial prospecting have been defined for many years and that the company was fully aware that in order to carry out its prospecting operations electronically, it required valid consent. The Restricted Committee notes in this regard that the company implemented procedures, since the beginning of 2022, to conduct audits of its suppliers and verify the validity of the consent obtained. Despite these verifications, the company has not taken the necessary measures to ensure its compliance. On the contrary, the company continued to use the transmitted data and only after several months (17 months in the case of the breach of Article 7 of the GDPR) did it take measures to put an end to the observed breaches. The Restricted Committee considers that by failing to comply with these rules, the company was, at the very least, grossly negligent.
148. Third, the Restricted Committee considers that the criterion relating to the measures taken by the data controller to mitigate the harm suffered by the data subjects must also be taken into account, pursuant to Article 83(2)(c) of the GDPR.
149. It appears that, since the inspections were carried out, the company has taken measures to strengthen the checks carried out on the collection forms implemented by its initial data collection partners. It has also ceased to use the data transmitted by the company [X3]. The Restricted Committee nevertheless notes that this latter measure was taken only late, almost eighteen months after it had noted that its partner was unable to provide it with the information necessary to comply with the provisions of Article 7 of the GDPR.
150. Fourth, the Restricted Committee intends to take into account certain other circumstances applicable to the facts of the case, pursuant to Article 83(2)(k) of the GDPR.
151. The Restricted Committee considers, in particular, that the company derived a clear financial advantage from the violations committed, insofar as it was remunerated by its customers for providing the data in question. 152. Furthermore, more generally, the Restricted Committee considers that, even though the company currently focuses its business on website design, to the point that the activity in question represents less than 3% of its turnover, it remains a significant player in the market, a market it has been operating for a long time, as it was created to handle the marketing activities of the PAGES JAUNES group, and that the entire portion of this activity is based on the purchase, use, and transmission of personal data. It considers that, under these conditions, the company was fully aware of the rules governing commercial prospecting and that it had a duty to be particularly vigilant to ensure the compliance of its practices with the regulations on the protection of personal data.
153. In light of all these elements, the Restricted Committee considers that the imposition of a fine appears justified with regard to the breaches of Articles L. 34-5 of the CPCE and 7 of the GDPR. 154. The Restricted Committee notes the residual portion of data affected by the breach of Article 6 of the GDPR (the data transmitted without a legal basis representing approximately 8.5% of "ListConnect" activity in 2022, this activity itself representing a very marginal portion of the company's overall activity).
2) On the amount of the fine
155. The Restricted Committee first notes that, pursuant to Article 83 of the GDPR, an administrative fine of up to €20 million or, in the case of a company, 4% of the total worldwide annual turnover for the previous financial year, whichever is higher, may be imposed.
156. The Restricted Committee then reiterates that administrative fines must be both dissuasive and proportionate.
157. First, regarding the calculation of the basis for the fine—which the company intends to limit to the sole portion of the turnover generated by the breaches—the Restricted Committee notes that such a limitation is not provided for in any legislation and that the seriousness of the breaches identified is not necessarily linked to the revenue they generated. Thus, in order to ensure the dissuasive and proportionate nature of the penalty imposed, the Restricted Committee considers that it is appropriate to base the fine on the company's total turnover, as provided for in Article 83 of the GDPR.
158. Second, the Restricted Committee notes that the company's turnover for 2023 amounts to €76.3 million, with a net profit of €16.3 million. It should be noted that, while the rest of the SOLOCAL group does not exert any influence over the company's operational activities, these figures, which specifically concern SOLOCAL MARKETING SERVICES, the only company affected by the penalty procedure, have not undergone any significant decline over the past three years.
159. Therefore, in light of the company's liability, its financial capacity, and the relevant criteria of Article 83 of the GDPR, the Restricted Committee considers that an administrative fine of nine hundred thousand (900,000) euros appears dissuasive and proportionate to sanction breaches of Articles L. 34-5 of the CPCE and Article 7 of the GDPR.
B. On the issuance of injunctions subject to a penalty payment
160. The rapporteur considers that the issuance of injunctions subject to a penalty payment is necessary to ensure the company's compliance.
161. The company considers that such a measure appears unjustified and that the amount of the penalty payment proposed by the rapporteur is disproportionate.
162. Regarding the breach of the provisions of Article L. 34-5 of the CPCE, the company reiterates that, while it can continue to carry out regular checks – or even strengthen its control procedures – it is unable to control the data transmitted to it by the first-time collectors.
163. Regarding the breach of the provisions of Article 7, paragraph 1 of the GDPR, the company considers that it is not justified since the contractual relationship with company [X3] is in the process of being terminated. 164. Regarding the breach of the provisions of Article 6 of the GDPR, the company states that it will cease this activity no later than December 31, 2024, due to the termination of its contract with [X4]. It therefore considers that such an injunction appears to be pointless.
165. Furthermore, the company considers that, in any event, if injunctions were to be issued, it should be granted a reasonable and sufficient period of time, taking into account the technical and organizational measures to be implemented.
166. The Restricted Committee notes, regarding the breach of Article L. 34-5 of the CPCE, that an injunction should be issued against the company to cease carrying out commercial prospecting operations by electronic means in the absence of valid consent. In this context, the company must no longer use data collected from forms that do not allow for the collection of such consent or, failing that, collect such consent itself.
167. Regarding the breach of Article 7 of the GDPR, the company stated that it would no longer use the data transmitted by [X3] as of October 18, 2024. It specified that the contract with this partner would be definitively terminated as of January 9, 2025. Under these circumstances, and since the breach noted only concerned data collected by [X3], the Restricted Committee considers that there is no need to issue an injunction.
168. Regarding the breach of Article 6 of the GDPR, the Restricted Committee notes that, according to the information provided by the company, it has ceased its "ListConnect" business, which consisted of transmitting data to its customers so that they could carry out their own commercial prospecting operations by mail or telephone. As a result, the issuance of an injunction appears to be pointless.
169. Furthermore, to ensure compliance with the injunction issued regarding the breach of Article L. 34-5 of the CPCE, the Restricted Committee considers that, in view of the company's turnover and the financial, human, and technical resources at its disposal to remedy the breaches noted, it is appropriate to impose a daily penalty payment of ten thousand (10,000) euros per day of delay, payable after a period of nine (9) months from notification of the decision.
C. On the publicity of the Sanction
170. The company considers that publication of the decision does not appear justified, particularly given the minor seriousness of the breaches identified. It notes that the individuals concerned have not suffered any harm and have not filed any complaints. It emphasizes the impact it could have on its business, as it would lead to a loss of trust among its customers, but also on the group as a whole.
171. The Restricted Committee considers, on the contrary, that such a measure is necessary given the seriousness of the breaches in question and the number of individuals concerned who will thus be informed. It reiterates that the absence of a complaint filed with the CNIL does not mean that the individuals concerned have not suffered any harm, which could consist, in this case, of feeling a certain discomfort or irritation upon receiving commercial prospecting messages without having consented, or of having their data transmitted to third parties without being able to reasonably expect it.
172. It further considers that this measure appears proportionate since the decision will no longer identify the company by name after a period of two years from its publication.
FOR THESE REASONS
The CNIL's restricted committee, after deliberation, decides to:
• impose an administrative fine of nine hundred thousand (900,000) euros against SOLOCAL MARKETING SERVICES for breaches of Articles L. 34-5 of the French Postal and Electronic Communications Code and Article 7 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016;
• issue an injunction against SOLOCAL MARKETING SERVICES to cease conducting commercial prospecting operations by electronic means without valid consent;
• attach a penalty payment of ten thousand (10,000) euros per day of delay to the injunction after a period of nine (9) months following notification of this notice. deliberation, with supporting documents demonstrating compliance to be sent to the restricted committee within this timeframe;
• publish its deliberation on the CNIL website and the Légifrance website, which will no longer allow the company to be identified by name after a period of two years from its publication.
The President
Philippe-Pierre CABOURDIN
This decision may be appealed to the Council of State within two months of its notification.
- ↑ Code des postes et des communications électroniques, https://www.legifrance.gouv.fr/codes/texte_lc/LEGITEXT000006070987/




