All news
Tech & AI August 18, 2026 5 min

French tax data stolen, and no passwords: that is what makes this one dangerous

Reference income, family quotient, withholding rate, company numbers and land registry data. The CNIL will check whether the measures matched the state of the art, and liability can reach the processor too

In short

Tax and land registry data extracted; passwords not. The ministry notified the CNIL and will inform data subjects individually. The CNIL does not want individual complaints and will check whether the security measures matched the state of the art: sanctions can hit controllers and processors alike.

What got out

  • Tax data: reference taxable income, family quotient, withholding tax rate, company registration number and company name.
  • Land registry data: addresses and floor areas of properties.
  • Identifiers and passwords appear not to be affected.

That last line usually reassures, and here it is the problem. Without credentials nobody gets into anyone's account; with income, family quotient, tax rate and the address of the property, you can write a message that knows more about a person than their bank does. It is high-grade phishing material, and the CNIL says so openly in its recommendations: distrust any «urgent» request by email or phone built on that information.

The sentence that concerns anyone doing DPO work

«The CNIL may carry out investigations on documents or on site to check, in particular, whether the security measures in place comply with the state of the art in information security.» Not «whether a procedure existed», not «whether there was a DPO»: whether the measures matched the state of the art at the time.

That is the Article 32 yardstick, and it is proved with dates. A list of measures with no adoption date and no document behind it does not survive that check: nobody can establish afterwards what was in force in August and what was added in September.

The CNIL adds that any sanction can reach controllers <strong>and processors</strong>. Whoever supplies services to a public body is not sheltered because the name in the papers is the client's.

No individual complaints

The CNIL is already seized of the breach and asks not to be sent individual complaints about it, unless you hold specific material useful to the ongoing investigation. It is a practical point worth passing to a client before they spend time preparing a complaint that will be set aside.

Three questions to put to clients today

1) If a request arrived quoting accurate tax data, how would we verify it? A call-back channel defined in advance is worth more than any training given afterwards. 2) Do our Article 32 measures have a date and a document behind them, or are they a list? 3) We act as processor for a public body: do we know the investigation can reach us as well?

Official source:CNIL — Piratage du système d'information des impôts : les vérifications sont en cours (18 août 2026)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free