Skip to content
Enforcement
EN

FRANCE TRAVAIL: Insufficient technical and organisational measures to ensure information security

€5,000,000 fine - French Data Protection Authority (CNIL)

€5,000,000 Fine
FRANCE TRAVAIL
FRANCE
Insufficient technical and organisational measures to ensure information security

Content

The French DPA has imposed a fine of EUR 5,000,000 on FRANCE TRAVAIL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures, resulting in the leak of personal and special category data concerning 38,820,828 individuals. The attack was carried out using the 'social engineering' method, meaning that the attacker obtained goods or information by exploiting the trust, ignorance or credulity of third parties.

GDPR Articles: Art. 32 GDPR
Industry: Public Sector and Education