FRANCE TRAVAIL – €5,000,000 Fine (France, 2026)

€5,000,000Commission Nationale de l'Informatique et des Libertés22 January 2026France
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

FRANCE TRAVAIL, a public institution, faced a major data breach that exposed sensitive information of millions of job seekers. The French data authority fined them €5 million for not securing their data properly. This case shows that organizations must take data protection seriously to avoid severe penalties.

What happened

FRANCE TRAVAIL was fined for gross negligence in securing personal data after a data breach allowed attackers to access sensitive information.

Who was affected

Millions of job seekers had their sensitive personal data compromised in the breach.

What the authority found

The French data authority found that FRANCE TRAVAIL failed to implement adequate security measures, violating Article 32 of the GDPR.

Why this matters

This case highlights the importance of robust data security practices, especially for organizations handling sensitive information. It serves as a warning that neglecting security can lead to significant financial penalties.

GDPR Articles Cited

AI-verified

Art. 32(GDPR)
View original scraped data
Art. 32(GDPR)

Original data from scraper before AI verification against source document.

Source verified 10 March 2026
verified correct
Full Legal Summary
Detailed

FRANCE TRAVAIL (the controller) , a public national institution managing employment data on behalf of the State, suffered a data breach in which attackers accessed its system using legitimate employee accounts. The breach resulted in the extraction of 25 GB of data, including sensitive personal data such as health information, disability status, NIR numbers, and other identifying information of millions of job seekers. The French Data Protection Authority (CNIL) initiated then an ex officio investigation. CNIL held that the controller failed to comply with Article 32 GDPR due to gross negligence in securing personal data. It imposed an administrative fine of €5,000,000, issued an injunction requiring the controller to justify implementation of robust password policies, multi-factor authentication, effective monitoring of activity logs and attached a daily penalty of €5,000 per day for non-compliance. CNIL emphasized that the controller had been previously warned about the need to implement effective logging and trace analysis systems, but failed to take adequate action. This prior warning, combined with the scale and nature of the breach, led the CNIL to conclude that the organization’s failure constituted gross negligence under Article 32 of the GDPR. The controller argued that its information system was highly complex and that, as a public administrative institution, imposing a fine would be disproportionate and could negatively affect its budget and operations. However, CNIL held that the controler was responsible for the processing because it acted on behalf of the State, not as the State itself, and retained financial and operational autonomy.

Related Enforcement Actions (0)

No other enforcement actions found for FRANCE TRAVAIL in FR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

22 January 2026

Authority

Commission Nationale de l'Informatique et des Libertés

Fine Amount

€5,000,000

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. FRANCE TRAVAIL - France (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: