American Express fined €1.5M for illegal cookie placement


American Express Carte France, the French subsidiary of credit card company American Express, has been fined €1.5 million for illegally installing cookies.

In January 2023, the Commission Nationale de l’Informatique et des Libertés (CNIL), France’s data protection authority, conducted several inspections into the website of American Express’ French division and the company’s premises.

The privacy supervisor found that the credit card company failed to comply with Article 82 of the French Data Protection Act, which dictates the rules regarding the installation of cookies.

ADVERTISEMENT

According to the data protection authority, cookies were installed as soon as visitors entered the company’s website, even before they had a chance to either accept or reject the cookies being placed on their devices.

The CNIL also found that cookies for advertising purposes were placed on the user’s device despite their expressed refusal.

browser cookies
Image by Cybernews

Lastly, the privacy supervisor discovered that when users accepted the installation of cookies and then withdrew their consent, the previously installed cookies continued to collect and send users’ information to the company.

For these violations, American Express Carte France is commissioned to pay a €1.5 million fine.

jurgita justinasv Izabelė Pukėnaitė vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google

“The amount of this fine took into account the fact that the company failed to comply with several obligations to protect the consent of internet users. It also took into account the fact that the rules regarding cookies are well known, due to their long history and widespread dissemination by the CNIL, but also the fact that the company complied with the rules during the proceedings,” France’s data protection authority says in a statement.

“We take the findings of the CNIL very seriously, and we are fully committed to respecting data protection standards and practices,” a spokesperson for American Express Carte France responded to press agency AFP after the CNIL’s ruling.

ADVERTISEMENT

Unlock more exclusive Cybernews content on YouTube.