All news
Enforcement June 9, 2026 6 min

France: EUR 1.7 million to Nexpublica - health and disability data accessible to other users through long-known flaws

December 2025 - a social-services software let users view other people's documents. Vulnerabilities flagged in earlier audits but never fixed

TL;DR for the DPO

22 December 2025: the CNIL fines Nexpublica (a French software vendor) EUR 1,700,000. Its PCRM software, used by social services including disability support structures, let users access other people's personal documents, including data revealing a person's disability. The vulnerabilities had been identified in internal and external audits BEFORE the breach but were not fixed. Fine under Art. 32 GDPR.

The facts

In November 2022 PCRM portal users reported being able to access documents belonging to others. PCRM serves social services that handle highly sensitive data. The CNIL found insufficient measures and structural vulnerabilities that persisted over time, many stemming from a lack of basic cybersecurity knowledge. Decisively, several flaws had been flagged in prior audit reports yet were not corrected until after the incidents.

1.7MEUR
CNIL fine

The point: known flaws ignored

It was not the existence of a flaw that triggered the fine, but knowing about it and not fixing it. For health and disability data (special categories, Art. 9) the CNIL demands a high level of security. An audit that finds a problem and is then ignored is, before the Authority, worse than no audit at all.

Official source:The Cyber Express - CNIL fine on Nexpublica

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min