The Doctissimo site fined 380,000 euros for breaches relating to personal and health data

The Cnil notably criticizes the site specializing in health subjects for having collected health data without consent and for having kept them without time limit.

Article written by

Posted

Reading time : 1 min.

Screenshot of the site specializing in health topics, Doctissimo, May 17, 2023. (DOCTISSIMO)

The site specializing in health topics Doctissimo was fined 380,000 euros for several breaches relating to personal data, announced Wednesday May 17 the National Commission for Computing and Liberties (CNIL). Ihe authority responsible for data protection carried out several checks on Doctissimo, following a complaint from the British association Privacy International filed in 2020.

The website, owned by the Reworld Media group, will have to pay a fine of 280,000 euros under the European Data Protection Regulation (GDPR) for health data kept without time limit and collected without consent. Doctissimo also receives a fine of 100,000 euros for offenses relating to cookies, explains the Cnil in a press release.

The authority also noted a lack of security of personal data, with the use of an unencrypted communication protocol, and the storage of passwords in “an insufficiently secure format”. For the time being, Doctissimo has not yet commented on this sanction.


source site-14