⏱ 9 min read

A data breach exposes a company to three risks: the CNIL’s enforcement procedure, in which a fine is not the only possible outcome, the criminal liability of the legal entity and, on the top floor, that of the director in person. That exposure is prepared before the incident and, in any event, managed from the moment it is discovered: everything written, decided and declared thereafter may be examined by the CNIL and by the judicial authorities, and may engage the liability of the company or its director.

Since 17 August 2026, 678,000 individuals and professionals have been receiving a message from the French tax administration (Direction générale des finances publiques) informing them that their data (names, income, postal addresses and telephone numbers) was stolen in the June cyberattack on the DGFiP’s information system, and is now offered for sale online. The Paris public prosecutor has opened an investigation.

This breach is no isolated accident. It belongs to a bleak year: according to the Surfshark study published in July 2026, more than 43 million French accounts were compromised in the first half of the year alone, making France the second most affected country in the world. Files held by the ANTS and France Titres, three intrusions at the DGFiP, sports federations plundered one after another, healthcare software vendors, telecoms operators: no sector has been spared.

Public debate has focused on one understandable grievance: the State, victim of the largest breaches, faces no fine. That is correct. But stopping there means missing what matters for a company director: the same breach, transposed into the private sector, triggers a three-tier enforcement mechanism, administrative, civil and criminal, whose final tier targets a natural person, the director himself.

What the company risks: CNIL fines and corporate criminal liability

One claim recurs throughout the public debate: after a data breach, a company “risks 4% of its global turnover”. That is legally imprecise.

The ceiling of 20 million euros or 4% of global turnover (Article 83(5) GDPR) sanctions certain categories of infringement: breaches of the fundamental principles of processing, of data subjects’ rights, of transfer rules. The typical data-breach scenario, however, is a failure to secure processing within the meaning of Article 32 GDPR, and that falls under Article 83(4), whose ceiling is 10 million euros or 2% of total worldwide annual turnover. French law reproduces that architecture faithfully in Article 20, IV, 7° of the Act of 6 January 1978.

Applicable provision
Article 20, IV, 7° of Act No. 78-17 of 6 January 1978

The administrative fine may not exceed 10 million euros or 2% of total worldwide annual turnover, whichever is higher. Those ceilings rise to 20 million euros and 4% only in the situations referred to in Article 83(5) and (6) GDPR.

View on Légifrance →

Two per cent of global turnover remains a substantial sum, and recent practice shows the threat is not theoretical.

On 13 January 2026, the CNIL issued two decisions against Free Mobile and Free, imposing fines of 27 and 15 million euros, 42 million in total, following the October 2024 intrusion that exposed data relating to 24 million subscriber contracts, bank account details included. The restricted committee noted in particular that the authentication procedure for virtual private network access was insufficiently secure. More than 2,500 customer complaints had been filed with the authority. On 22 January 2026, France Travail was fined 5 million euros for failing to secure jobseekers’ data.

The CNIL’s enforcement record confirms the underlying trend: data security ranks among the leading grounds for sanction, and the simplified procedure under Article 22-1 of the 1978 Act now allows fast-track penalties of up to 20,000 euros, rising to 100,000 euros where turnover exceeds 50 million euros. In other words, sanctions are no longer reserved for the digital giants. Small and mid-sized companies have entered the firing line.

To this must be added the obligations triggered by the breach itself: notification to the CNIL within 72 hours (Article 33 GDPR) and individual communication to the data subjects where the risk is high (Article 34). Late notification, or the absence of notification, constitutes a free-standing infringement, punishable in its own right, independently of the original security failure.

Administrative sanctions do not exhaust the company’s exposure: the legal entity itself may be prosecuted. Article 121-2 of the French Criminal Code makes legal persons, with the exception of the State, criminally liable for offences committed on their behalf by their organs or representatives. Applied to a failure to secure personal data (Article 226-17 of the Criminal Code), the mechanism of Article 131-38 raises the fine incurred by the company to five times that provided for natural persons, namely 1,500,000 euros. Nor is the fine the only issue: through the cross-reference in Article 226-24 of the Criminal Code to the penalties in Article 131-39, the legal entity also incurs exclusion from public procurement, permanently or for up to five years, a ban on carrying out the activity in the course of which the offence was committed, and publication or dissemination of the judgment.

What the director risks: the criminal layer

This is where published commentary generally stops.

Article 226-17 of the Criminal Code punishes by five years’ imprisonment and a fine of 300,000 euros the act of processing personal data without implementing the security measures prescribed, in particular, by Article 32 GDPR. The offence does not target an abstraction: it may be charged against the legal entity, but also, as the final paragraph of Article 121-2 of the Criminal Code makes clear, against the natural persons who committed the same acts. The director who set the budgets, postponed the updates and ignored the warnings of the company’s IT provider stands in the front line.

Applicable provision
Article 226-17 of the French Criminal Code

Processing, or causing the processing of, personal data without implementing the measures prescribed by Articles 24, 25, 30 and 32 GDPR is punishable by five years’ imprisonment and a fine of 300,000 euros.

View on Légifrance →

Convictions on this basis have remained rare. Three converging developments are changing that.

The first is mechanical: every notification sent to victims under Article 34 GDPR is, in practice, an invitation to file a complaint. The Free case and its 2,500 complaints give the measure of the phenomenon. When 678,000 taxpayers receive an email telling them their income figures are for sale online, some of them will go to the police station. The same reasoning applies to any customer database.

The second is judicial: cyber litigation has become criminal litigation. Investigations by the Paris prosecutor into this summer’s breaches, arrests of those behind attacks on sports federations, dismantling of groups specialising in school data. Any judicial investigation opened into a breach explores both sides: that of the attacker, and that of the target’s own failings. The evidence gathered to convict the former documents, along the way, the negligence of the latter.

The third is legislative: the NIS 2 Directive raises cybersecurity to board level, requiring management bodies to approve risk-management measures, oversee their implementation and be capable of being held liable. Its French transposition, the “Résilience” bill, was adopted by the Senate at first reading on 11 and 12 March 2025, then unanimously by the National Assembly’s special committee on 9 and 10 September 2025; debate in plenary session is announced for September 2026, the transposition deadline of 17 October 2024 having been missed by nearly two years. ANSSI has already published its framework of measures, the ReCyF, in March 2026, and some 15,000 French entities will fall within the scope of the legislation. Any management body waiting for enactment before taking an interest will discover that the standard of care already exists, and that it will be applied to them retrospectively.

The 72 hours that shape everything that follows

From this threefold exposure follows the most important point of this article, and the least understood: in the 72 hours after an intrusion is discovered, everything the company writes may be examined by the CNIL and by the judicial authorities.

The notification to the CNIL describes the company’s security failings. The breach register fixes the chronology of what it knew, and since when. Crisis emails between management and the IT department establish who decided what. The incident-response provider’s report characterises the exploited vulnerability in technical terms. Each of these documents is produced under stress, against a regulatory deadline. Each may become an exhibit in a criminal file, in support of a victim’s complaint or a preliminary investigation.

Everything the company writes in those 72 hours may be examined by the CNIL and by the judicial authorities.

That is why a cyber crisis unit should never consist solely of an IT director, a data protection officer and a communications officer. The notification under Article 33 is not a technical form: it is a legal act whose every formulation shapes what comes next. The choice whether to inform the data subjects (Article 34) is not merely a question of image: it determines the flow of complaints to come. And one decision is too often forgotten in the panic: the company under attack is first and foremost a victim, with an interest in filing a complaint without delay, fraudulent access to and continued presence within an automated data processing system being punishable under Articles 323-1 et seq. of the Criminal Code. Establishing declared victim status, preserving evidence without altering the systems, documenting with the awareness that every word counts: this is a defence strategy built in the first hour, not after the summons.

The State enjoys a double immunity, and that is the law

That leaves the question fuelling the controversy since the start of the summer: why does the State, victim of the largest breaches, face none of this? The texts are unambiguous.

First, an administrative fine from the CNIL is legally impossible against the State. Article 20, IV, 7° of the Data Protection Act of 6 January 1978 reserves the administrative fine for controllers “save where the processing is carried out by the State”. The same exception applies to the periodic penalty payment that may accompany a compliance order (Article 20, IV, 2°). Faced with a breach such as the DGFiP’s, the restricted committee retains its other corrective powers, from a reprimand to an order, and as far as limiting or prohibiting the processing (Article 20, IV, 3°), but none of them is measured in euros. What the State escapes is the financial penalty.

Second, the State also escapes the criminal courts as a legal person. Article 121-2 of the Criminal Code, the basis of corporate criminal liability, excludes it expressly: “Legal persons, with the exception of the State, shall be criminally liable…”.

Applicable provision
Article 121-2 of the French Criminal Code

Legal persons, with the exception of the State, are criminally liable for offences committed on their behalf by their organs or representatives. Their liability does not exclude that of the natural persons who committed or were accomplices to the same acts.

View on Légifrance →

The irony of the scheme deserves emphasis: the legislature did, by contrast, think to toughen the response against those who attack the State. Since the Act of 24 January 2023, fraudulent access to an automated system processing personal data operated by the State is punishable by seven years’ imprisonment and a fine of 300,000 euros (Article 323-1, paragraph 3, of the Criminal Code), against three years and 100,000 euros for an ordinary system. The State has thus equipped itself with reinforced criminal protection as a victim, while remaining structurally immune as a failing custodian of data.

One may think of that what one will. The finding itself is settled: for the same data breach, the company answers on every front while the State faces none.

Key takeaways

This asymmetry is not a reason for indignation, it is a reason to get organised: the private-sector director does not enjoy the luxury of immunity. The difference between a contained incident and a criminal charge rarely turns on technology: it turns on what was written, decided and declared in the first few days. A criminal case can always be defended, including late in the day. But it is defended with the documents that exist: those who prepared their 72 hours defend themselves with chosen documents, the others with documents they are stuck with.

The firm acts alongside directors and companies, both in advance and under pressure: preparation of the crisis protocol and of the 72-hour framework, assistance within the crisis unit, legal review of notifications, filing criminal complaints and joining proceedings as a civil party, defence before the CNIL and the criminal courts. Contact the firm →

Frequently asked questions

1. What fine does a company face after a data breach?

For a failure to secure processing (Article 32 GDPR), the administrative fine may reach 10 million euros or 2% of total worldwide annual turnover, not 4%, a ceiling reserved for other categories of infringement. The CNIL’s simplified procedure also allows fast-track penalties of up to 20,000 euros (100,000 euros for companies with turnover above 50 million euros), which now reach small and mid-sized companies as well.

2. Can a director be held criminally liable for a cyberattack suffered by the company?

Yes. Article 226-17 of the French Criminal Code punishes by five years’ imprisonment and a fine of 300,000 euros the processing of personal data without adequate security measures. The offence may target the legal entity as well as natural persons, including the director. The NIS 2 Directive, currently being transposed, will further strengthen the liability of management bodies.

3. Can the company itself be criminally convicted after a data breach?

Yes. Under Article 121-2 of the French Criminal Code, a legal person is liable for offences committed on its behalf by its organs or representatives. For a failure to implement security measures (Article 226-17 of the Criminal Code), the fine incurred by the company is five times that applicable to natural persons (Article 131-38), namely 1,500,000 euros, without prejudice to the CNIL’s administrative fine, the two being capable of cumulating.

4. Must the CNIL be notified after a cyberattack?

Yes, within 72 hours of becoming aware of a personal data breach (Article 33 GDPR), unless the breach presents no risk to individuals. The absence or lateness of notification is a punishable infringement in itself. Where the risk is high, the data subjects must also be informed individually (Article 34).

5. Why does the French State pay no fine for its own data breaches?

Because the law excludes it expressly: Article 20 of the Data Protection Act prohibits the CNIL from imposing a fine or a periodic penalty payment where the processing is carried out by the State, and Article 121-2 of the Criminal Code excludes the State from corporate criminal liability. The authority’s other corrective measures, from a reprimand to limiting the processing, do however remain available.

The author

Maître Mehdy Kadri is a member of the Paris Bar. He practises at Cabinet Kadri Avocat (Paris 8th arrondissement) in general and serious criminal law, white collar crime, tax criminal law, cybercrime and crypto-assets, media law and human rights. He regularly publishes in AJ Pénal (Dalloz) and the Encyclopédie Doctrine.

Contact the firm →

This analysis forms part of the firm’s practice in white collar crime and in cybercrime and digital criminal law.