logo

CNIL Fines NEXPUBLICA FRANCE €1.7 Million for GDPR Security Failures

ID: 3b2a01c7-ad27-5cdc-a592-137e8497abca

STIX ID: report--3b2a01c7-ad27-5cdc-a592-137e8497abca

Feed Name: The Cyber Express

Threat Score
55/100

Date Published: 2025-12-30

Date Updated: 2026-04-23

Author: Samiksha Jain

...
...

CNIL fined Nexpublica France €1.7 million following a November 2022 incident where users of the company’s PCRM portal could access third-party documents containing highly sensitive personal data (including disability information). The regulator found long-standing technical and organisational deficiencies, identified prior audit findings that were not remediated before the breach, determined a violation of Article 32 of the GDPR, and imposed the penalty while noting corrective measures were implemented only after the exposure was reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.