CNIL fines NEXPUBLICA FRANCE €1.7 million for insufficient data security measures

Original title: Data breach: the CNIL fined NEXPUBLICA FRANCE €1.7 million

The CNIL fined NEXPUBLICA FRANCE €1.7 million for breaching Article 32 of the GDPR by failing to implement adequate technical and organizational security measures for its PCRM software used in social action services. The company's information system had widespread security weaknesses, and it negligently allowed structural security problems to persist, resulting in a data breach in November 2022 where customers could access documents concerning third parties. The fine reflects the company's failure to comply with basic security principles, the number of people affected, and the particular sensitivity of the data processed, including disability information.

What changed

  • CNIL enforcement action: Administrative fine of €1.7 million issued to NEXPUBLICA FRANCE for Article 32 GDPR breach (decision finalized 22 December 2025)
  • Finding of insufficient security: NEXPUBLICA FRANCE's PCRM software lacked adequate technical and organizational measures to secure personal data, with widespread weaknesses in the information system
  • Data breach exposure: In November 2022, a data breach allowed NEXPUBLICA FRANCE customers to access documents concerning third parties, affecting sensitive data including disability information processed by departmental houses for the disabled (MDPH)

Who is affected

Companies providing user relationship management (CRM) software in France, particularly those serving the social action and disability services sector; organizations using software with insufficient security measures processing sensitive personal data including health and disability information

Summary generated by a language model; the official text prevails. Not legal advice.