The sanctions issued by the CNIL

14 April 2026


The sanctions issued by the CNIL’s restricted committee since the entering into force of the GDPR.

 

Sanctions issued

Sanctions issued in 2026

Date Type of organisation Main breaches / Theme subject Decision
08/01/2026 MOBILE PHONE OPERATOR

Data retention period

Lack of data security

Obligation to notify the data subject of a data breach

Fine of €27 million and injunction
08/01/2026 LANDLINE TELEPHONE OPERATOR

Lack of data security

Obligation to notify the data subject of a data breach

Fine of €15 million and injunction

15/01/2026 CANDIDATE IN THE GENERAL ELECTION (simplified procedure)

Information of individuals (exercice of rights)

Failure to respect the right of access

Fine of €2,000 and injunction
22/01/2026 PUBLIC ADMINISTRATIVE BODY Lack of data security Fine of €5 million and injunction
29/01/2026 PUBLIC BODY OPERATING AN URBAN TRANSPORT SERVICE (simplified procedure)

Obligation to process data lawfully (CCTV)

Information of individuals

Lack of data security

Fine of €20,000
29/01/2026 RELIGIOUS ASSOCIATION (simplified procedure)

Obligation to process data lawfully (CCTV)

Information of individuals (CCTV)

Fine of €10,000 and injunction
05/02/2026 DOCTOR (simplified procedure) No response to injunction Liquidation of the penalty payment of €1,000
05/02/2026 LAWYER (simplified procedure) No response to injunction Liquidation of the penalty payment of €1,000
05/03/2026 ASSOCIATION DEDICATED TO PROMOTING ACCESS TO DENTAL CARE FOR THE UNDERPRIVILEGED (simplified procedure)

Information of individuals

Lack of data security

Fine of €6,000 and injunction
05/03/2026 ASSOCIATION FOR THE DEFENCE OF FUNDAMENTAL RIGHTS (simplified procedure) No response to injunction Liquidation of the penalty payment of €5,100
12/03/2026 MINISTRY

Obligation to process data lawfully

Data retention period

Lack of data security

Call to order and injunction
12/03/2026 COMPANY ENGAGED IN DISTANCE SELLING VIA A SPECIALIST CATALOGUE (simplified procedure)

Information of individuals (exercice of rights)

Failure to respect the right of access

Fine of €5,000
26/03/2026 COMPANY ORGANISING EVENTS THROUGH THE PROMOTION AND SALE OF TICKETS (simplified procedure)

Data retention period

Obligation to process data lawfully

Information of individuals

Failure to respect the right of erasure

Consent of individuals (cookies)

Fine of €15,000 and injunction
26/03/2026 COMPANY ACTIVE IN THE PERFORMING ARTS (simplified procedure) No response to injunction Liquidation of the penalty payment of €850
26/03/2026 COMPANY ENGAGED IN THE TOURIST ACCOMMODATION BUSINESS (simplified procedure)

Data minimisation

Data retention period

Framework for relations between the controller and the processor

Fine of €3,000
02/04/2026 COMPANY OPERATING TOILET FACILITIES (simplified procedure)

Obligation to process data lawfully (CCTV)

Data minimisation (CCTV)

Framework for relations between the controller and the processor

Obligation to carry out a Privacy Impact Assessment

Fine of €7,500

Sanctions issued in 2025


Sanctions issued in 2024


Sanctions issued in 2023


Sanctions issued in 2022


Sanctions issued in 2021


Sanctions issued in 2020


Sanctions issued in 2019


Sanctions issued in 2018