Data breach: France Travail fined €5 million

  • National News

Background information

  • Date of final decision: 22 January 2026
  • National case
  • Controller: FRANCE TRAVAIL
  • Legal Reference: Article 32 (Security of processing)
  • Decision: Administrative fine
  • Key words: Administrative fine, Data security, Data breach

Summary of the Decision

Origin of the case

In the first quarter of 2024, one or more hackers managed to hack into the FRANCE TRAVAIL information system. They used techniques known as "social engineering", which involve exploiting people's trust, ignorance or credulity. This method enabled them to hijack the accounts of CAP EMPLOI advisers, i.e. the organisations responsible for supporting, monitoring and upholding the employment of people with disabilities.

Investigations established that the hackers accessed the data of all individuals who were registered or who had been registered over the past 20 years, as well as individuals with a candidate account on francetravail.fr (including their National Insurance numbers, email and postal addresses, and telephone numbers). However, the hackers did not access the complete files of job seekers, which may include health data.

The CNIL's investigation revealed that the technical and organisational measures implemented to ensure the security of the personal data processed were inadequate.

Key Findings

  • Breach of the obligation to secure personal data (Article 32 of the GDPR) 
    The restricted committee noted that FRANCE TRAVAIL had not implemented the technical and organisational measures that could have made the attack more difficult. As a reminder, the implementation of security measures appropriate to the risks is an obligation of means provided for in Article 32 of the GDPR.
    In particular, it noted that the authentication procedures allowing CAP EMPLOI advisers to access the FRANCE TRAVAIL information system were not sufficiently robust. 
    In addition, the restricted committee highlighted the inadequacy of logging measures to detect abnormal behaviour on its information system. 
    Finally, the restricted committee noted that CAP EMPLOI account access authorisations had been defined too broadly, allowing CAP EMPLOI advisers to access data on individuals they were not supporting, which increased the volume of data accessible to hackers. 
    In determining the sanction, the restricted committee took into account the fact that most of the appropriate security measures had been identified by FRANCE TRAVAIL, prior to the implementation of the processing, in the impact assessments, but had not actually been implemented.

Decision

As a result, the restricted committee – the CNIL body responsible for imposing sanctions – imposed a fine of €5 million on FRANCE TRAVAIL, considering the ignorance of essential security principles, the number of people affected, and the volume and sensitivity of the data processed. 
In addition, the restricted committee ordered FRANCE TRAVAIL to justify the corrective measures taken, with a precise implementation schedule.
Failing this, the organisation will have to pay a penalty of €5,000 per day of delay.

For further information:

Relevant topics
Personal data breaches
Fines

Latest news

  • EDPB News

Stakeholder event on guidelines on the interplay between data protection and competition law: express your interest

  • EDPB News

Stakeholder event on guidelines on the interplay between data protection and competition law: save the date

  • EDPB News

EOVP poziva k pravni podlagi za medzakonodajno izmenjavo informacij