In July 2016 the French Data Protection Authority issued a fine of €30,000 to BrandAlley for breaching the main data protection legislation in the country. This study takes a look at why BrandAlley was fined and how to design more effective data protection policies and procedures to avoid such breaches.