On 15 May 2025 the French data protection authority issued two sanctions on the same day, against two players in the same chain. Nine hundred thousand euros for one, eighty thousand for the other.
Neither company had collected the addresses it was exploiting. That is precisely what is held against them.
The first: being unable to show
SOLOCAL MARKETING SERVICES bought prospect data from brokers, what the industry calls data brokers, then ran prospecting campaigns.
The CNIL describes its line of inquiry without hedging:
“Dans le cadre de sa thématique prioritaire de contrôle sur la prospection commerciale en 2022, la CNIL s’est intéressée aux pratiques des professionnels du secteur, en particulier de ceux qui procèdent à la revente de données, y compris des nombreux intermédiaires de cet écosystème appelés courtiers en données ou data brokers en anglais.”
The central breach is not the purchase. It is the inability to prove:
“La société n’a pas été en mesure de fournir à la CNIL la preuve du consentement des personnes dont les données lui ont été transmises par l’un de ses principaux fournisseurs. La CNIL n’a ainsi pas pu examiner les formulaires de collecte mis en œuvre par ce fournisseur et, donc, la validité du consentement des personnes concernées.”
Then the sentence that moves the entire burden:
“Il appartient bien à la société, en sa qualité de responsable de traitement, d’apporter la preuve que ses opérations de prospection réalisées sont licites (notamment la preuve du consentement).”
The buyer is the controller. The contract binding it to its supplier does not transfer that responsibility: at best it documents it.
The authority adds a circumstance that weighs heavily: “après avoir constaté que son partenaire n’était pas en capacité de lui fournir cette preuve, la société a attendu près de 17 mois pour cesser d’utiliser les données transmises”.
Seventeen months between the finding and the stop. That delay, as much as the breach itself, explains the amount.
Contractual guarantees are not enough
SOLOCAL had taken precautions. It imposed contractual requirements on its suppliers and claimed to carry out checks.
The enforcement panel found those measures “manifestement insuffisantes”.
And on the quality of upstream forms, it laid down a principle that applies to any buyer of lists:
“La formation restreinte considère que l’apparence trompeuse des formulaires mis en œuvre par les courtiers en données ne permet pas de recueillir un consentement libre et univoque, conforme aux exigences du RGPD, qui permettrait de fonder les opérations de prospection réalisées par la société SOLOCAL MARKETING SERVICES.”
The defect in the original form contaminates everyone who exploits the data afterwards, however many intermediaries sit in between.
The second: the form itself
CALOGA, sanctioned the same day, sat higher up the chain. It bought from prize-draw and product-testing site operators, what the authority calls first collectors, and resold in turn.
The description of the typical form is a lesson in deceptive design:
“La mise en valeur des boutons entraînant l’utilisation de ses données à des fins de prospection commerciale (par leur taille, leur couleur, leur intitulé et leur emplacement), comparée aux liens hypertextes permettant de participer au jeu sans accepter cette utilisation (d’une taille nettement inférieure et se confondant avec le corps du texte) pousse fortement l’utilisateur à accepter.”
Size, colour, wording, placement. Four formatting elements, and consent falls.
On resale, the authority restates a distinction many players refuse to see:
“Dans le cadre de son activité de courtier en données, la société transmettait également des bases de données à d’autres partenaires […]. Elle fondait ce traitement de transmission des données sur la base légale de l’intérêt légitime. Or, ce traitement doit être fondé sur le consentement des personnes concernées, dont la société CALOGA ne disposait pas.”
Passing a database to a commercial partner is not processing that legitimate interest covers. Legitimate interest has a perimeter, and it stops before transfer.
The unsubscribe that was not one
A third breach in the CALOGA decision deserves to be known by anyone running several databases.
“Il n’était pas possible, pour le prospect, de se désinscrire en un seul clic des différentes bases de données de CALOGA dans lesquelles il était inscrit. Pour ce faire, il devait adresser une demande par courrier électronique au délégué à la protection des données. Il n’était donc pas aussi facile pour un prospect de retirer son consentement que de le donner.”
The symmetry required by Article 7(3) of the GDPR is applied literally here: if you subscribe in one click, you unsubscribe in one click. A link that only exits one list out of five does not meet that requirement.
And this is a point where the legal requirement meets the technical one: one-click unsubscribe is also a mailbox provider requirement, for entirely different reasons.
What the authority did next
These two decisions are not isolated. In its 2025 sanctions review, the CNIL writes:
“La prospection, qu’elle soit commerciale ou politique, a également fait l’objet de 10 décisions de sanction.”
Ten decisions in one year on a single theme. Electronic prospecting is not a secondary enforcement subject: it has been a stated priority since 2022, and it produces decisions every quarter.
One practical consequence of the procedure is worth noting: the authority unpublishes its press releases once the publicity period expires, and the entities are then anonymised. Several prospecting decisions from 2024 and 2025 can no longer be consulted under the company’s name. What remains are the principles.
What to do tomorrow morning
If you exploit a purchased list, ask your supplier a precise question: for an address of my choosing, can you show me the collection form as it was displayed, the date, and the purpose accepted?
If the answer is slow or stays general, you now know the delay that cost SOLOCAL dearly. Seventeen months is the time you must not take.
Then look at your own forms against the four criteria of the CALOGA decision. Compare the size, colour, wording and placement of the accept button and the decline link. If the gap is obvious, the authority has already qualified it.
Finally, check that an unsubscribe exits all of your databases, and not merely the list the message came from. It is the easiest breach to fix and the most common.
And if you are looking for professional contacts, at least know where they come from. Sestaro’s contact search is free and unlimited: you only pay when you reveal an address, which lets you qualify a target before building any list at all.
Sources
- CNIL (15 May 2025). Prospection commerciale : sanction de 900 000 euros à l’encontre de la société SOLOCAL MARKETING SERVICES, decision SAN-2025-001
- CNIL (15 May 2025). Prospection commerciale : sanction de 80 000 euros à l’encontre de la société CALOGA, decision SAN-2025-002
- CNIL. Sanctions et mesures correctrices : bilan 2025
- European Union (27 April 2016). Regulation (EU) 2016/679 (GDPR), Articles 6, 7 and 14
LaFactory works email on the evidence: headers, DNS records, rejection logs. No open rate promises, ever. Get in touch for a deliverability audit.
