France Travail’s €5m security fine

Security controls need to be implemented, not just written down in an assessment.

By GDPRFix · Published · 2 min read
AI-assisted reporting and commentary · Official sources linked below.
Source / announcement date: 29 January 2026

Regulator announcement; this article does not establish payment or the outcome of any subsequent appeal.

What happened

CNIL announced a €5 million fine against France Travail in January 2026. Its findings included weak authentication, inadequate logging and access rights that were too broad. The authority said some safeguards had already been identified in impact assessments but had not actually been implemented. This was a security case under GDPR Article 32.

Source: CNIL — original source ↗

What it means for your website

The website equivalent is a checklist that says access is restricted when every administrator still has full permissions. Ask for demonstrations instead of accepting reassuring labels: show which accounts exist, what each role can do and where sensitive actions are recorded. Keep the review specific to your systems. A charity or public body may have several teams, external developers and inherited platforms, so ownership can easily become unclear. A public cookie scan does not inspect your access management or replace a security assessment. It can form one small part of a wider evidence file.

Three useful next steps

  1. Compare documented safeguards with real settings.
  2. Remove access that is no longer needed.
  3. Assign a named owner to each unfinished security action.

Sources & context

Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.

CNIL — original source

Our practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.

Keep reading