All news
Enforcement June 9, 2026 6 min

France: CNIL fines France Travail EUR 5 million - 36.8 million data subjects and a social-engineering attack

January 2026 - the public employment agency sanctioned for inadequate security under Art. 32. Attackers got in by tricking staff, not by breaching systems

TL;DR for the DPO

22 January 2026: France's CNIL fines France Travail (the public employment agency) EUR 5,000,000. A social-engineering attack in Q1 2024 compromised the accounts of Cap Emploi advisers (who support people with disabilities) and exposed the data of around 36.8 million people registered over the last 20 years. The fine is for breaching Art. 32 GDPR (security), not for the attack itself.

The facts

In Q1 2024 attackers infiltrated France Travail's information system not via a technical vulnerability but through social engineering: they tricked Cap Emploi advisers and hijacked their accounts, gaining access to data of everyone registered over the past 20 years. The CNIL found the technical and organisational measures did not sufficiently reduce the risk of unauthorised access through compromised accounts.

5MEUR
CNIL fine
36.8M
Data subjects affected

The point: an obligation of means

The CNIL reiterated that Art. 32 is an obligation of means: measures must be demonstrable and risk-appropriate. 'We had plans' is not a defence if the controls were not actually live in production. For a public body the fine is not based on turnover: the cap for a security breach is EUR 10 million.

Official source:CNIL - Data breach: France Travail fined 5 million

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min