TL;DR for the DPO
22 December 2025: the CNIL fines Nexpublica (a French software vendor) EUR 1,700,000. Its PCRM software, used by social services including disability support structures, let users access other people's personal documents, including data revealing a person's disability. The vulnerabilities had been identified in internal and external audits BEFORE the breach but were not fixed. Fine under Art. 32 GDPR.
The facts
In November 2022 PCRM portal users reported being able to access documents belonging to others. PCRM serves social services that handle highly sensitive data. The CNIL found insufficient measures and structural vulnerabilities that persisted over time, many stemming from a lack of basic cybersecurity knowledge. Decisively, several flaws had been flagged in prior audit reports yet were not corrected until after the incidents.
The point: known flaws ignored
It was not the existence of a flaw that triggered the fine, but knowing about it and not fixing it. For health and disability data (special categories, Art. 9) the CNIL demands a high level of security. An audit that finds a problem and is then ignored is, before the Authority, worse than no audit at all.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free