FRANCE TRAVAIL – €5,000,000 Fine (France, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
FRANCE TRAVAIL, a public institution, faced a major data breach that exposed sensitive information of millions of job seekers. The French data authority fined them €5 million for not securing their data properly. This case shows that organizations must take data protection seriously to avoid severe penalties.
What happened
FRANCE TRAVAIL was fined for gross negligence in securing personal data after a data breach allowed attackers to access sensitive information.
Who was affected
Millions of job seekers had their sensitive personal data compromised in the breach.
What the authority found
The French data authority found that FRANCE TRAVAIL failed to implement adequate security measures, violating Article 32 of the GDPR.
Why this matters
This case highlights the importance of robust data security practices, especially for organizations handling sensitive information. It serves as a warning that neglecting security can lead to significant financial penalties.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
FRANCE TRAVAIL (the controller) , a public national institution managing employment data on behalf of the State, suffered a data breach in which attackers accessed its system using legitimate employee accounts. The breach resulted in the extraction of 25 GB of data, including sensitive personal data such as health information, disability status, NIR numbers, and other identifying information of millions of job seekers. The French Data Protection Authority (CNIL) initiated then an ex officio investigation. CNIL held that the controller failed to comply with Article 32 GDPR due to gross negligence in securing personal data. It imposed an administrative fine of €5,000,000, issued an injunction requiring the controller to justify implementation of robust password policies, multi-factor authentication, effective monitoring of activity logs and attached a daily penalty of €5,000 per day for non-compliance. CNIL emphasized that the controller had been previously warned about the need to implement effective logging and trace analysis systems, but failed to take adequate action. This prior warning, combined with the scale and nature of the breach, led the CNIL to conclude that the organization’s failure constituted gross negligence under Article 32 of the GDPR. The controller argued that its information system was highly complex and that, as a public administrative institution, imposing a fine would be disproportionate and could negatively affect its budget and operations. However, CNIL held that the controler was responsible for the processing because it acted on behalf of the State, not as the State itself, and retained financial and operational autonomy.
Related Enforcement Actions (0)
No other enforcement actions found for FRANCE TRAVAIL in FR
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
22 January 2026
Authority
Commission Nationale de l'Informatique et des Libertés
Fine Amount
€5,000,000
About this data
Cite as: Cookie Fines. FRANCE TRAVAIL - France (2026). Retrieved from cookiefines.eu
Last updated: