News

๐Ÿ‡ซ๐Ÿ‡ท Excessive data collection by an online clairvoyance company

Retention & Minimisation, Confidentiality & Security | 25/03/2025

๐Ÿ”ฎ CNIL Fines an Online Fortune-Telling Company

Source :
SAN 2023-008 of June 8, 2023

Violations:

  • ๐Ÿ›‘ EXCESSIVE DATA COLLECTION
  • ๐Ÿ“‹ CONSENT
  • ๐Ÿ’‰ SENSITIVE DATA
  • โณ DATA RETENTION
  • ๐ŸŽ™๏ธ CALL RECORDINGS
  • โš ๏ธ DATA BREACH

Facts:

In 2020, following a news article revealing a data breach from an online fortune-telling site, CNIL conducted several investigations.

The company KG COM offers online fortune-telling consultations via its website, chat, or phone. CNIL identified several violations, including:

  • ๐ŸŽ™๏ธ Systematic recording of phone conversations.
  • ๐Ÿ’‰ Collection of sensitive data such as information related to sexual orientation and health status.
  • ๐Ÿ’ณ Retention of banking data without the consent of the individual concerned.
  • ๐Ÿšจ Failure to notify the data breach.


Identified Violations:

  1. ๐ŸŽ™๏ธ Phone Call Recordings:
    • Lack of data minimization, Article 5.1.c of the GDPR.
  2. ๐Ÿ’‰ Sensitive Data:
    • Failure to obtain prior consent for the collection of sensitive data, Article 9 of the GDPR.
  3. ๐Ÿšจ Data Breach:
    • Failure to notify CNIL of a data breach, Article 33 of the GDPR.
  4. ๐Ÿ” Data Security:
    • Insufficient protection of data (weak website password, site using HTTP instead of HTTPS), Article 32 of the GDPR.

Consequences:

  • ๐Ÿ’ฐ 120,000 euro fine for the online fortune-telling company KG COM.
  • ๐Ÿ’ธ 30,000 euro fine for using cookies without prior consent (absence of informational banners, placing 3 cookies on users' devices without their consent).

 

The GDPR, Even in Fortune-Telling ๐Ÿ”ฎ

This sanction serves as a reminder of the importance of complying with data protection regulations, even for businesses in niche sectors like online fortune-telling.

Back to news list

Explore all our areas of expertise:

]]>