Governance, Risk and Compliance, Government Regulations, Identity, Privacy, Data Security

CNIL fines Nexpublica €1.7M over GDPR security breach

Judge gavel

France's data protection authority, the CNIL, has imposed a 1.7 million GDPR fine on software company Nexpublica for severe cybersecurity failures that led to a significant data breach, according to The Cyber Express.

The penalty, announced in December 2025, stems from an incident in November 2022 where users of the company's PCRM software, a tool used by social services like Departmental Houses for the Disabled, could access sensitive personal documents belonging to other individuals.

The investigation concluded that Nexpublica violated Article 32 of the GDPR by failing to implement adequate security measures, despite being aware of long-standing vulnerabilities identified in prior internal and external audits. The CNIL emphasized the heightened responsibility given the sensitivity of the data processed, which can reveal personal disability information, and noted the company's delayed remediation only after the breach was reported.

In determining the fine, the regulator considered Nexpublica's financial capacity, the number of affected individuals, and the nature of the data, underscoring that known security weaknesses must be proactively addressed.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds