Société & Droit des affaires
CYBERSECURITE

Businesses & Cybersecurity – The Perpetual Risk of Phishing

Entreprises Cybersecurite Le risque perpetuel dHameconnage Phishing 1

2024 has seen several major cyberattacks, with the total cost in France estimated at 129 billion US dollars—an increase of 35.5 billion compared to 2023[1]. Phishing is the most common technique among these attacks, accounting for 60% of incidents[2] and targeting both individuals and businesses.

Phishing is a technique that involves impersonating an organization or an acquaintance to obtain information[3]. It takes various forms, such as emails prompting recipients to click a link, make a payment, or share information; phone calls impersonating a company; SMS messages; social media messages; URL hijacking, and more. The goal is often to harvest the victim’s personal details—such as name, photo, phone number, social security number, or banking information—for fraudulent use.

Phishing is on the rise, with a 108% increase in phishing sites compared to the previous year[4] and three times as many users clicking on these sites[5]. This surge is driven by the growing credibility of phishing attempts—fueled by AI technologies like deepfakes and chatbots—and the rise of “spear phishing,” which involves sending personalized messages to the victim.

In response to this threat, various stakeholders are mobilizing for large-scale operations, such as “PhishOFF” and “Nebulae,” which targeted the “LabHost” platform—a provider of phishing services. These operations bring together both public entities, such as Europol, and private sector players, including Microsoft and Chainalysis.

Entreprises Cybersecurite Le risque perpetuel dHameconnage Phishing 1 2

Phishing – Prosecuting Perpetrators: A Challenge for Criminal Law Effectiveness

The fight against phishing takes place on two fronts: prosecuting and punishing the perpetrators, and compensating the victims. However, it is important to note the variety of practices and criminal legal classifications involved (A), and that prosecuting perpetrators can only be contemplated within a framework of global co-regulation (B).

Phishing: A Variety of Practices and Criminal Classifications

Overview. Efforts to combat phishing and other forms of online fraud naturally extend to the realm of criminal law[6]. Various offenses may be established, notably online identity theft[7][8], fraud[9], counterfeiting of trademarks and registered content[10], counterfeiting and fraudulent use of payment methods[11], fraudulent collection of personal data[12], unauthorized access to an automated data processing system[13], etc.

Increasing Complexity. Given the digital nature of phishing techniques, the concurrence of offenses is common, with the initial offenses serving as the means to commit the subsequent ones. Other offenses may also apply[14], depending on the nature of the parties disclosing information[15].

Consequently, a single instance of phishing may often give rise to multiple criminal charges. Case law has only recently accepted the possibility of such a cumulative approach[16], except in cases of incompatible classifications or where a single act constitutes both an element of one offense and an aggravating circumstance of another. Furthermore, under the principle of specialia generalibus derogant (specific provisions override general ones), an offense specifically created for the facts at hand must take precedence over an offense covering more general cases. The possibility of cumulative charges necessarily entails the possibility of cumulative penalties. However, such cumulation of penalties is not permitted for penalties of the same nature; in such cases, as a general rule, only a single penalty of that type may be imposed, subject to the highest statutory maximum[17]. An exception exists, however, for identity theft, where the penalties imposed are cumulative with those imposed for the offense during which the identity theft occurred[18]. Regarding the cumulation of convictions, a foreign conviction may be combined with a French conviction for the same acts, but the penalty imposed abroad is deducted from the penalty imposed by the French court[19]. However, such cumulation is prohibited for decisions rendered by courts in EU Member States concerning the same acts (Article 50 of the Charter of Fundamental Rights).

In the context of phishing, further complexities arise: the international nature of the offenses, the identification of those responsible, and the determination of applicable law and competent authorities. Anonymization techniques make it difficult to identify the perpetrator; even when identified, the perpetrator is often located abroad, making prosecution difficult and costly. To address these challenges inherent to cybersecurity, specialized cybersecurity units have been established.

Specialized units. At the national level, several specialized cybersecurity authorities have been created: the Cybercrime Unit (BLCC) of the Paris Central Directorate of the Judicial Police, the Anti-Cybercrime Office (OFAC), and the Digital Crime Fighting Center (C3N). There is also an administrative authority dedicated to cybersecurity—ANSSI—as well as specialized websites for reporting phishing attempts that collaborate with public services, such as Phishing Initiative.

2023.10.05.A

Combating phishing: a global co-regulatory effort

Efforts to combat phishing take place on a global scale, involving a wide range of stakeholders.

States and law enforcement agencies. Given the international nature of cybercrime, states have established cooperation mechanisms to prosecute offenses. Consequently, all member states of the Council of Europe—along with other nations such as Australia and the United States—are bound by the Budapest Convention on Cybercrime. This treaty mandates cooperation “for the purpose of investigations or proceedings concerning criminal offenses related to computer systems and data, or for the collection of evidence in electronic form of a criminal offense” (Article 23 of the Budapest Convention). Interpol plays a major role in fostering global collaboration; for instance, in 2020, it established the “ASEAN Cybercrime Operations Desk” (Southeast Asia) to coordinate the actions of relevant authorities.

At the European level, Europol and its European Cybercrime Centre coordinate actions and facilitate information exchange among EU member states and non-EU partner countries. Notably, Europol hosts the “Joint Cybercrime Action Taskforce” (J-CAT), where experts from various countries collaborate on joint investigations. In the judicial sphere, Eurojust and its European Judicial Cybercrime Network bring together judicial bodies specializing in cybercrime. For example, Eurojust coordinated judicial cooperation between France, Italy, and Romania regarding a phishing campaign involving fake court summonses that targeted several European countries.

Administrative authorities. There is an administrative authority dedicated to cybersecurity: the National Cybersecurity Agency of France (ANSSI), which holds national jurisdiction over cybersecurity and cyber defense matters.

At the same time, other administrative authorities have jurisdiction—such as the Audiovisual and Digital Communication Regulatory Authority (ARCOM), which handles internet fraud (Article 12 of the LCEN). Notably, if ARCOM finds that a site is clearly designed to scam users—by directing them to an interface that mimics an existing online platform in a way likely to cause confusion and induce users to provide personal data or transfer money—it can order internet service providers or domain name resolution providers to block access to that site.

For its part, the Financial Markets Authority (AMF) maintains a blacklist of unauthorized companies and websites, particularly those that impersonate regulated entities. The CNIL (French Data Protection Authority) may also investigate if a GDPR violation is alleged.

Private sector actors. Whether acting independently or in collaboration with public sector entities, private sector actors are also mobilizing against phishing.

Overall, 91% of executives at large French companies view cybersecurity as a major strategic issue, and 80% have at least one IT security expert on their board of directors[20]. In this regard, Société Générale invests significant effort in raising client awareness through information campaigns on recognizing phishing attempts, regular notifications reminding clients of best practices, online practical guides, and more[21]. There are also companies specializing in cybersecurity—and specifically in phishing prevention—such as Mantra, which offers phishing simulation exercises. They collaborate with public authorities to prevent or penalize phishing—for instance, with Interpol’s Cybercrime Fusion Centre (CFC), which brings together private-sector experts and issues alerts to warn countries about cyber threats.

These stakeholders implement a wide range of measures, spanning prevention and enforcement as well as awareness-raising.

Prevention and awareness-raising. ANSSI publishes several recommendations on its website to prevent phishing[22]: avoiding clicking on suspicious links or attachments, not replying to suspicious emails, checking email security settings, and enabling two-factor authentication. Its role also involves ensuring the availability of trusted security products capable of protecting highly sensitive data and countering cyber threats. To achieve this, it must stay abreast of the state of the art in cybersecurity, regarding both existing technologies and threats and risks within cyberspace. Drawing on this knowledge, ANSSI shares recommendations, methods, and tools with relevant stakeholders.

At the European level, regulations such as DORA (for the financial sector) and NIS 2 (for essential and important entities) aim to strengthen cybersecurity levels for specific entities of particular importance (covering risk management measures, incident reporting, etc.).

Combating phishing: a coordinated technical and legal effort. Phishing incidents can be reported to the competent authorities. Reports may be filed directly by a victim or service user, or by hosting providers, who are legally required to report any notifications they receive to the authorities (Article 6 IV of the LCEN).

Online services are available for making these reports. Examples include SignalSpam for emails (which liaises with the CNIL) and Phishing Initiative or PHAROS for websites; these services can subsequently forward reports to the authorities. If the reported content or behavior is unlawful, an investigative unit from the National Police or National Gendarmerie may be tasked with an investigation under the authority of a Public Prosecutor. However, for foreign content, the report is forwarded to Interpol, which redirects it to the authorities of the country concerned. It is also possible to file a complaint directly with a police station or gendarmerie unit, or in writing to the Public Prosecutor. Victims can receive free support from the victims’ association France Victimes[23].

To facilitate the identification of phishing perpetrators, internet service providers and hosting providers are required to retain for one year—and transmit—data enabling the identification of anyone who contributed to setting up the phishing attempt (Article 6 V. A. LCEN). An order may subsequently be issued to the content host to remove the content or block access to it, under penalty of potential liability (Article 6 DSA).

Entreprises Cybersecurite Le risque perpetuel dHameconnage Phishing 3

Phishing – Redress for the Victim: A Liability and Compensation Issue

Alongside efforts to combat these practices, the question of civil liability for the costs associated with cyber-offenses involves various parties: victims, banking institutions, insurance companies, IT service providers, and so forth. Compensation for civil damages is primarily governed by payment law, which is subject to a specific legal framework (A). Case law appears to be adapting the relevant rules, establishing a duty of vigilance for both banks and cardholders (B).

Cybersecurity & Phishing: Primary Bank Liability

Liability regime. Historically, regarding disputed banking transactions, the cardholder bore liability even in the absence of fault on their part[24]. While this position was challenged by the laws of November 15, 2001, and the ordinance of July 15, 2009[25], case law has effectively supplemented the legal framework governing the triggering of liability. The cardholder now bears a capped risk for transactions made prior to reporting the loss (blocking the card). Beyond this cap, the bank bears the consequences of the fraudulent use of the payment instrument[26]. The bank is thus subject to a security obligation regarding the period prior to the client’s notification of loss—a timeframe that may be contractually modified after two full days have elapsed since the card’s loss or theft.

Exemption criteria. Banking institutions are now required to compensate clients who dispute a banking transaction within the time limits and in the manner prescribed by law. However, in addition to clear cases of fraudulent conduct or intentional fault by the client, “gross negligence”—subsequently reclassified as “serious negligence”[27]—also allows the bank to be absolved of liability for compensation. More recently, case law has identified a cumulative condition for exempting the banking institution: based on the statutory obligation regarding transaction security[28], the bank must also prove that the transaction was authenticated, recorded, and accounted for without technical failure[29]. The Court of Cassation has previously ruled that “serious negligence” was not established where the banking institution committed a contractual breach by failing to enforce an overdraft prohibition on the stolen account[30].

Burden of proof. By cumulatively applying the statutory obligations incumbent upon banking institutions[31] and civil rules regarding the burden of proof, the highest court has placed the burden of proof on payment service providers seeking to avoid liability[32]. The Court of Cassation reinforces the limitation of the cardholder’s liability[33] by making it particularly difficult[34] for the bank to prove gross negligence[35]. Indeed, this relies solely on statements by the customer that characterize their own negligence[36]—whether made to the bank or to the police or gendarmerie when filing a complaint of which the bank has contractually requested a copy. It remains to be determined whether a customer’s refusal to provide potentially self-incriminating information could preclude their reimbursement by the bank.

Entreprises Cybersecurite Le risque perpetuel dHameconnage Phishing 4 1
Source : www.fix-dessinateur.com

Phishing: A Shared Duty of Vigilance

Case law regarding gross negligence appears to absolve cardholders of responsibility, even though they are regularly warned and educated about phishing fraud by banks, various other stakeholders, and government authorities. To balance the conditions for liability in the event of an unauthorized transaction, the courts have established a duty of vigilance applicable to both banks and cardholders.

Banks are indeed liable for material or intellectual anomalies[37]—provided they are obvious and apparent[38]—in their clients’ banking transactions[39], while still respecting the obligation of non-interference. Clients are now also subject to a similar duty of vigilance regarding solicitations involving their personal and banking information[40].

Regarding fraud—specifically phishing—case law historically favored an in concreto (case-specific) assessment to establish gross negligence. It fell to the judge in each case, based on “findings and sovereign assessment”[41], to determine whether the client’s good faith or the characteristics of the email received indicated gross negligence[42]. Notably, the courts clarified that the mere use of personal codes by a third party could not, in itself, constitute gross negligence under the law[43]. By extension, the cardholder’s contractual obligation regarding the safekeeping of credentials constitutes an obligation of means—specifically regarding confidentiality—rather than an obligation of result[44].

Applying these same criteria to establish bank liability, courts have taken into account factors such as anomalies in the form or content of messages, spelling errors, difficulties or errors in identifying senders[45], recipients, account holders, or the contracts cited[46], as well as unusual requested amounts or payment methods, among others. This case-by-case analysis by trial and appellate courts has been called into question by recent case law establishing the criteria of the diligent and reasonably attentive user and of “reasonable doubt” [47], thereby abandoning the criterion of the holder’s good faith [48].


[1] La cyber-sécurité – Faits et chiffres | Statista

[2] Le 9e baromètre de la cybersécurité des entreprises

[3] Bonnes pratiques – Protégez-vous ! | ANSSI

[4] Rapport anti-phishing 2024

[5] Malgré la sensibilisation, les taux de clics de phishing ont triplé en 2024 – Le Monde Informatique

[6] PE et Cons. UE, dir. n° 2019/713, 17 avr. 2019, concernant la lutte contre la fraude et la contrefaçon des moyens de paiement autres que les espèces, not. art. 3 a) et 5 d). Le texte devra être transposé d’ici le 31 mai 2021.

[7] article 434-23 du Code pénal

[8] l’article 226-4-1 de Code pénal

[9] article 313-1 du Code péna

[10] articles L. 713-2 et L. 713-3 du Code de la propriété intellectuelle.

[11] articles L163-3 et L163-4 CMF

[12] article 226-18 du Code pénal

[13] ’article 323-3 du Code pénal,

[14] Exclusion d’une infraction pénale de violation de secret des affaires

[15] violation du secret de fabrique (C. trav., art. L. 1227-1. – CPI, art. L. 621-1) ou celle du secret professionnel (C. pén., art. 226-13),

[16] Cass. crim., 15 déc. 2021, n° 21-81.864 

[17] article 132-3 du Code pénal

[18] article 434-23 du Code pénal

[19] Cass. crim., 23 oct. 2013, n° 13-83.499

[20] L’état des lieux de la cybersécurité en France (2024)

[21] Les techniques de fraude par e-mail les plus répandues – SG

[22] Bonnes pratiques – Protégez-vous ! | ANSSI

[23] Que faire en cas de phishing ou hameçonnage ? – Assistance aux victimes de cybermalveillance

[24] Cass. com., 1er mars 1994, pourvoi no 91-21.144, Bull. civ. IV, no 82, p. 63 ; D. 1995, p. 167, note F. Ekollo ; JCP G 1994. II. 22286, note Ch. Gavalda ; RTD com. 1994, p. 538, obs. R. Cabrillac et B. Teyssie ; J. Lasserre Capdeville, Précisions sur la question de la preuve en cas de fraude au paiement sur internet, La Semaine Juridique Edition Générale n° 10, 6 Mars 2017, 241.

[25] Ordonnance n° 2009-866 du 15 juillet 2009 relative aux conditions régissant la fourniture de services de paiement et portant création des établissements de paiement fondée sur la directive 2007/64/CE du Parlement européen et du Conseil du 13 novembre 2007 concernant les services de paiement dans le marché intérieur (dite « DSP 1 ») complété par la directive 2015/2366 du 25 novembre 2015 (dite « DSP 2 ») ; D. Legeais, Synthèse – Responsabilité du banquier , JurisClasseur Banque – Crédit – Bourse, 4 Octobre 2021.

[26] D. Legeais, Synthèse – Responsabilité du banquier , JurisClasseur Banque – Crédit – Bourse, 4 Octobre 2021

[27] Com. 1er mars 2016, n° 14-22.946 ; Cass. com., 16 oct. 2012, n° 11-19981 : Reconnaissant une « imprudence grave » pour avoir conservé sa carte et son code à proximité dans un lieu sans surveillance, ce dernier avait commis une faute lourde. ; Par exemple, CA Toulouse, 1re ch., section 1, 20 mars 2017, n° 16/01256 concernant l’envoi de la copie recto-verso de la carte bancaire avec la copie du passeport constituant une faute lourde ; CA Montpellier, 2e ch., 20 sept. 2016, n° 15/00171 qualifiant de faute une carte bancaire laissée dans la boîte aux lettres pendant les vacances  X. Delpech, Négligence grave du titulaire de carte bancaire victime de « hameçonnage », Dalloz Actualité, 07.11.2017, https://www.dalloz-actualite.fr/flash/negligence-grave-du-titulaire-de-carte-bancaire-victime-de-hameconnage; D. R. Martin, H. Synvet, Droit bancaire juillet 2015 – septembre 2016, Recueil Dalloz 2016, p. 2305.

[28] Art. L133-15 et L133-23, al. 1 C. mon. fin. notamment en cas de négligence (CA Versailles, 18 nov. 2010, n° 09/06634)

[29] Cass, Com. 12 nov. 2020, n° 19-12.112 ; V. Larcheron, Opération de paiement non autorisée : la négligence grave du client ne dispense pas la banque de ses propres obligations, 20.03.2021, https://larcheron.law/operation-de-paiement-non-autorisee-la-negligence-grave-du-client-ne-dispense-pas-la-banque-de-ses-propres-obligations/; S. Claude-Fendt, Même négligent, le titulaire d’un compte victime d’un hameçonnage peut être remboursé par sa banque, EFL, 11.12.2020, https://www.efl.fr/actualite/negligent-titulaire-compte-victime-hameconnage-rembourse-banque_f8bcc9958-de7d-45e5-8570-fa13004a72e5; G. Raymond, Jurisclasseur, Synthèse – Entreprise et consommateur : Mercatique (méthodes de vente), LexisNexis, 08.04.2021

[30] Cass. 1re civ., 28 mars 2008, n° 07-10186 ; Com. 17 mai 2017, n° 15-28.209, Inédit

[31] PE et Cons. CE, dir. n° 2007/64, 13 nov. 2007, concernant les services de paiement dans le marché intérieur ; PE et Cons. UE, dir. n° 2015/2366, 25 nov. 2015, concernant les services de paiement dans le marché intérieur.

[32] Cass. com., 2 oct. 2007, n° 05-19899, confirmé par Cass. 1re civ., 28 mars 2008, n° 07-10186 et Cass. com., 21 sept. 2010, n° 09-16534 mettant fin aux décisions contradictoires des juges du fond notamment CA Lyon (ch. 6), 3 juin 2004 et CA Chambéry, 5 mars 2002.

[33] La Base Lextenso, Le renforcement de la sécurité des titulaires de cartes bancaires, Petites Affiches n°54 du 14 mars 2008, https://www-labase-lextenso-fr.docelec-u-paris2.idm.oclc.org/petites-affiches/PA200805405#ftn5-anchor.

[34] Pour certains considéré comme impossible voire diabolique, Voir notamment É. A. Caprioli, Phishing – Responsabilité du particulier en cas d’hameçonnage, CCE n° 9, Septembre 2018, comm. 68

[35] Définie comme « une négligence d’une extrême gravité confinant au dol et dénotant l’inaptitude du débiteur de l’obligation à l’accomplissement de sa mission » (Cass. com., 16 janvier 2007, pourvoi no 05-16.415) ou de manière plus large à un « manquement à une obligation essentielle (Cass. civ. 1re, 18 janvier 1984, n°85-15.103).

[36] En ce sens, Cass. com., 25 oct. 2017, n° 16-11.644 : « sans rechercher, au regard des circonstances de l’espèce, si Mme Y… n’aurait pas pu avoir conscience que le courriel qu’elle avait reçu était frauduleux et si, en conséquence, le fait d’avoir communiqué son nom, son numéro de carte bancaire, la date d’expiration de celle-ci et le cryptogramme figurant au verso de la carte, ainsi que des informations relatives à son compte SFR permettant à un tiers de prendre connaissance du code 3D Secure ne caractérisait pas un manquement, par négligence grave, à ses obligations mentionnées à l’article L. 133-16 du code monétaire et financier, la juridiction de proximité a privé sa décision de base légale »

[37] CA Lyon, 31 mars 2016, n° 15/06043, SASU Lavatec France c/ Caisse Régionale

[38] Cass. com., 16 oct. 2012, n° 11-19.981 concernant des carte bancaire et code confidentiel laissé à proximité de celle-ci constituant une faute lourde par imprudence ; Cass. com., 1er mars 2016, n° 14-22.946.

[39] CA Paris, 19 févr. 2015, n° 13/21614 :  CA Paris, 5 févr. 2015, n° 13/21817 CA Paris, 18 déc. 2014, n° 12/19837 : CA Rennes, 10 févr. 2016, n° 14/00931 ; Vigilance potentiellement renforcée en matière de comptes d’incapables majeurs ; CA Chambéry, 17 mai 2016, n° 14/02371

[40] Cass. com., 3 oct. 2018, n° 17-21.395, les juges n’avaient pas recherché si la réponse qu’avait adressée la victime à l’auteur du courriel d’hameçonnage « ne résultait pas d’un manquement » de celle-ci « par négligence grave » ; S. BERNHEIM-DESVAUX, Hameçonnage – La négligence grave de la victime d’un phishing en matière de carte bancaire est retenue, Contrats Concurrence Consommation n° 6, Juin 2018, comm. 121.

[41] Com. 31 mai 2016, n° 14-29.906.

[42] M. Rees, La victime d’un phishing bancaire n’a droit à aucun remboursement en cas de « négligence grave », NextInpact, 12.10.2018, https://www.nextinpact.com/article/28842/107165-la-victime-dun-phishing-bancaire-na-droit-a-aucun-remboursement-en-cas-denegligence-grave

[43] Cass. com., 18 janv. 2017, n° 15-18102, PBI ; Cass. com., 18 janv. 2017, n° 15-26058 ; Cass. com., 18 janv. 2017, n° 15-18224 ; Cass. com., 18 janv. 2017, n° 15-22783 ; Cass. com., 18 janv. 2017, n° 15-18466 ; Cass. com., 21 nov. 2018, n° 17-18888 ; Cass. com., 3 avr. 2019, n° 18-11293 ; Cass. com., 29 mai 2019, n° 17-28271 ; Cass. com., 29 mai 2019, n° 18-10147 ; Cass. com., 26 juin 2019, n° 18-12581 ; CA Paris, 16 mars 2017, n° 15/18646 ; CA Aix en Provence, 16 mars 2017, n° 15/03953.  CA Aix-en-Provence, 8 oct. 2015 ; CA Paris, Pôle 4 chambre 9, 22 sept. 2016, n° 14/09630 ; CA Douai, 29 janv. 2014, n° 13/0285.

[44] Les banques pensaient couvrir leur responsabilité par la mise en place de système de sécurisation personnalisés (Tous modes de sécurisation confondus : Code d’authentification envoyé par SMS, dit 3DSecure, identifiant « CMNE Direct » avec mot de passe associé et codes de validation présents sur une carte personnelle d’authentification renforcée, système Payweb reposant sur un numéro de carte virtuel) qui devaient légalement et contractuellement prouver en cas de faille la responsabilité de l’auteur ; Déjà en ce sens, CA Orléans, 9 février 2006, JCP E 2006, no 48, 2697, obs. N. Mathey.

[45] X. Delpech, Négligence grave du titulaire de carte bancaire victime de « hameçonnage », Dalloz Actualité, 07.11.2017, https://www.dalloz-actualite.fr/flash/negligence-grave-du-titulaire-de-carte-bancaire-victime-de-hameconnage.

[46] Cass. com., 6 juin 2018, n° 16-29.065 « l’examen attentif du courriel de rappel de paiement révélait de sérieuses irrégularités, de nature à faire douter de sa provenance, telles que l’inexactitude de l’adresse de l’expéditeur et du numéro du contrat mentionné, ainsi que la discordance entre les montants réclamés » ;

[47] Notamment Com. 28 mars 2018, n° 16-20.018 et Cass, Com. 12 nov. 2020, n° 19-12.112 ; CA Colmar, 3e civ., sect. A, 12 avr. 2021, n° 19/03528 visant l’absence de vérifications élémentaire sur le courriel reçu (informations personnelles & piratage de la carte SIM utilisé pur déjouer le système Secure 3D) ; F. Dannenberger, Responsabilité civile – Phishing, attention à l’obligation de préservation des données personnelles, La Semaine Juridique Edition Générale n° 3, 24 Janvier 2022, 112.

[48] Cass. com .,1er juill. 2020, n° 18-21.487 ; Hameçonnage d’un payeur crédule : de bonne foi peut-être, mais responsable tout de même !, Gazette du Palais, n°36 du 20 octobre 2020, Lextenso ; G. Raymond, Jurisclasseur, Synthèse – Entreprise et consommateur : Mercatique (méthodes de vente), LexisNexis, 08.04.2021.

Écrit par :

Publié le : 20/08/2026

PX Chomiac de Sas