News

πŸ‡«πŸ‡· Data security and real estate

Retention & Minimisation, Confidentiality & Security | 28/03/2025

🏠 Real Estate & Personal Data: €400,000 Fine
πŸ“… CNIL Decision – May 28, 2019 (Ref: 2019-995)
πŸ” A security breach + excessive data retention = double GDPR violation

πŸ“Œ Context:
In 2019, a company specialized in rental management was fined €400,000 for two major GDPR breaches:

πŸ” 1. Inadequate security (Art. 32 GDPR)
πŸ‘‰ A technical flaw allowed access to 290,000 confidential documents simply by modifying the URL.
πŸ’₯ Result: Unauthorized access to ID cards, bank details, divorce judgments, CAF attestations, etc.
⚠️ No access control, no filtering, and no emergency measures taken after the breach was discovered.
πŸ‘₯ 29,440 people affected

πŸ“ 2. Excessive data retention (Art. 5-1.e GDPR)
⏳ The company retained all supporting documents for 6 years, even for unsuccessful applicants.

πŸ’Έ Aggravating factors:
• No authentication on the online portal
• Lack of responsiveness despite being alerted
• High sensitivity of the data exposed
• No secure archiving safeguards

 

Back to news list

Explore all our areas of expertise:

]]>