FRANCE TRAVAIL – €5,000,000 Fine (France, 2026)

€5,000,000Commission Nationale de l'Informatique et des Libertés22 January 2026France
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

FRANCE TRAVAIL (the controller) , a public national institution managing employment data on behalf of the State, suffered a data breach in which attackers accessed its system using legitimate employee accounts. The breach resulted in the extraction of 25 GB of data, including sensitive personal data such as health information, disability status, NIR numbers, and other identifying information of millions of job seekers. The French Data Protection Authority (CNIL) initiated then an ex officio investigation. CNIL held that the controller failed to comply with Article 32 GDPR due to gross negligence in securing personal data. It imposed an administrative fine of €5,000,000, issued an injunction requiring the controller to justify implementation of robust password policies, multi-factor authentication, effective monitoring of activity logs and attached a daily penalty of €5,000 per day for non-compliance. CNIL emphasized that the controller had been previously warned about the need to implement effective logging and trace analysis systems, but failed to take adequate action. This prior warning, combined with the scale and nature of the breach, led the CNIL to conclude that the organization’s failure constituted gross negligence under Article 32 of the GDPR. The controller argued that its information system was highly complex and that, as a public administrative institution, imposing a fine would be disproportionate and could negatively affect its budget and operations. However, CNIL held that the controler was responsible for the processing because it acted on behalf of the State, not as the State itself, and retained financial and operational autonomy.

GDPR Articles Cited

AI-verified

Art. 32 GDPR
View original scraped data
Art. 32 GDPR

Original data from scraper before AI verification against source document.

Source verified 6 March 2026
verified correct
Full Legal Summary

FRANCE TRAVAIL (the controller) , a public national institution managing employment data on behalf of the State, suffered a data breach in which attackers accessed its system using legitimate employee accounts. The breach resulted in the extraction of 25 GB of data, including sensitive personal data such as health information, disability status, NIR numbers, and other identifying information of millions of job seekers. The French Data Protection Authority (CNIL) initiated then an ex officio investigation. CNIL held that the controller failed to comply with Article 32 GDPR due to gross negligence in securing personal data. It imposed an administrative fine of €5,000,000, issued an injunction requiring the controller to justify implementation of robust password policies, multi-factor authentication, effective monitoring of activity logs and attached a daily penalty of €5,000 per day for non-compliance. CNIL emphasized that the controller had been previously warned about the need to implement effective logging and trace analysis systems, but failed to take adequate action. This prior warning, combined with the scale and nature of the breach, led the CNIL to conclude that the organization’s failure constituted gross negligence under Article 32 of the GDPR. The controller argued that its information system was highly complex and that, as a public administrative institution, imposing a fine would be disproportionate and could negatively affect its budget and operations. However, CNIL held that the controler was responsible for the processing because it acted on behalf of the State, not as the State itself, and retained financial and operational autonomy.

Related Enforcement Actions (0)

No other enforcement actions found for FRANCE TRAVAIL in FR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

22 January 2026

Authority

Commission Nationale de l'Informatique et des Libertés

Fine Amount

€5,000,000

Enforcement Tracker ID

ETid-3026

GDPRhub ID

gdprhub-9780

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. FRANCE TRAVAIL - France (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: