French Regulator Fines Auto Insurance Company For Failing To Prevent Web Crawling

Fox Rothschild LLP
Contact

Fox Rothschild LLPWeb crawling and data protection: CNIL has issued a 180,000 EUR fine against a provider of automobile insurance policies for failure to adequately protect data in violation of GDPR, specifically citing disallowing web crawling as a way to protect personal data from wrongful access.

In particular the company :
  1. sent usernames and passwords in cleartext
  2. allowed users to access other users accounts
  3. allowed users’ accounts to be accessible by the general public when entering a URL or changing the last numbers in a URL

The compromised information included copies of driver’s licenses, registration cards, bank identification records and documents to determine whether a person had been subject to a license withdrawal or hit-and-run.

Key takeaways:
  • Don’t send passwords in cleartext.
  • Adopt a strong password policy.
  • Ensure access controls to information are limited and accurate.
  • Use a “robot.txt” or other means to disallow SEO and crawling by search engines of internal web pages containing sensitive information.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Fox Rothschild LLP | Attorney Advertising

Written by:

Fox Rothschild LLP
Contact
more
less

Fox Rothschild LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide