TL;DR for the DPO
22 January 2026: France's CNIL fines France Travail (the public employment agency) EUR 5,000,000. A social-engineering attack in Q1 2024 compromised the accounts of Cap Emploi advisers (who support people with disabilities) and exposed the data of around 36.8 million people registered over the last 20 years. The fine is for breaching Art. 32 GDPR (security), not for the attack itself.
The facts
In Q1 2024 attackers infiltrated France Travail's information system not via a technical vulnerability but through social engineering: they tricked Cap Emploi advisers and hijacked their accounts, gaining access to data of everyone registered over the past 20 years. The CNIL found the technical and organisational measures did not sufficiently reduce the risk of unauthorised access through compromised accounts.
The point: an obligation of means
The CNIL reiterated that Art. 32 is an obligation of means: measures must be demonstrable and risk-appropriate. 'We had plans' is not a defence if the controls were not actually live in production. For a public body the fine is not based on turnover: the cap for a security breach is EUR 10 million.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free