The CNIL and the DGCCRF entered into a MoU on January 6, 2011 in order to strengthen the protection of consumers’ personal data on the Internet.
This MoU is intended to inform the CNIL of any infringement regarding the Act of January 6, 1978 Act “loi informatique et libertés” that DGCCRF investigators may have been aware of in the course of their investigation.
As of now, when conducting an inspection regarding online merchants, DGCCRF investigators should not only check compliance with trade and consumers law, but also report to the CNIL any infringement they may be aware of regarding:
- Unfair/unlawfull data collection,
- data collection not related to the activity of the website,
- the collection of sensitive data without the consent of the buyer,
- the lack of security measures to protect personal data and the lack of information on the use of collected personal data.