France's data protection authority, the CNIL, has imposed a €1.7 million GDPR fine on software company Nexpublica for severe cybersecurity failures that led to a significant data breach, according to The Cyber Express.
The penalty, announced in December 2025, stems from an incident in November 2022 where users of the company's PCRM software, a tool used by social services like Departmental Houses for the Disabled, could access sensitive personal documents belonging to other individuals.
The investigation concluded that Nexpublica violated Article 32 of the GDPR by failing to implement adequate security measures, despite being aware of long-standing vulnerabilities identified in prior internal and external audits. The CNIL emphasized the heightened responsibility given the sensitivity of the data processed, which can reveal personal disability information, and noted the company's delayed remediation only after the breach was reported.
In determining the fine, the regulator considered Nexpublica's financial capacity, the number of affected individuals, and the nature of the data, underscoring that known security weaknesses must be proactively addressed.
The penalty, announced in December 2025, stems from an incident in November 2022 where users of the company's PCRM software, a tool used by social services like Departmental Houses for the Disabled, could access sensitive personal documents belonging to other individuals.
The investigation concluded that Nexpublica violated Article 32 of the GDPR by failing to implement adequate security measures, despite being aware of long-standing vulnerabilities identified in prior internal and external audits. The CNIL emphasized the heightened responsibility given the sensitivity of the data processed, which can reveal personal disability information, and noted the company's delayed remediation only after the breach was reported.
In determining the fine, the regulator considered Nexpublica's financial capacity, the number of affected individuals, and the nature of the data, underscoring that known security weaknesses must be proactively addressed.

