Back to Feed
PolicyAug 21, 2026

Data breach: the CNIL fined NEXPUBLICA FRANCE €1.7 million

CNIL fines NEXPUBLICA FRANCE €1.7 million for data security failures in PCRM software.

Summary

The CNIL has fined NEXPUBLICA FRANCE €1.7 million for failing to implement adequate security measures for its PCRM user relationship management software. Investigations revealed insufficient technical and organizational safeguards, leading to a data breach where customers could access third-party documents. The fine reflects the company's negligence, the sensitivity of the data processed, and the number of affected individuals.

Full text

Data breach: the CNIL fined NEXPUBLICA FRANCE €1.7 million National News 24 December 2025 fr Background informationDate of final decision: 22 December2025National caseController: NEXPUBLICA FRANCELegal Reference: Article 32 (Security of processing)Decision: Administrative fineKey words: Administrative fine, Data security, Data breachSummary of the DecisionOrigin of the caseNEXPUBLICA FRANCE has developed a user relationship management software named PCRM which is used in the field of social action, in particular by departmental houses for the disabled (MDPH). In November 2022, the CNIL was notified of a data breach by NEXPUBLICA FRANCE customers for being able to access documents concerning third parties. The CNIL then carried out investigations which revealed insufficient technical and organizational measures to secure personal data of the PCRM software.Key FindingsBreach of the obligation to secure personal data (Article 32 of the GDPR)NEXPUBLICA FRANCE did not comply with the requirements provided for by the article 32 of the GDPR for the implementation of its PCRM, given the widespread weakness of the information system and the negligence it showed in allowing structural security problems to persist.DecisionOn the basis of these investigations, the restricted committee – the CNIL body responsible for imposing sanctions – considered that the company had failed to comply with the article 32 of the GDPR.The restricted committee therefore issued a fine of €1.7 million and decided to make its decision public. This decision took into account the company’s financial capacity, its failure to comply with basic security principles, the number of people affected and the sensitivity of the data processed (in particular, revealing a disability).For further information:[FR]: https://www.cnil.fr/fr/securite-des-donnees-sanction-de-1-700-000-euros-lencontre-de-la-societe-nexpublica-france[EN]: https://www.cnil.fr/en/data-security-nexpublica-france-fined-eur1700000 Relevant topics Personal data breaches Fines Latest news EDPB News Stakeholder event on guidelines on the interplay between data protection and competition law: express your interest30 July 2026 EDPB News Stakeholder event on guidelines on the interplay between data protection and competition law: save the date23 July 2026 EDPB News EDPB calls for legal basis for cross-regulatory information sharing17 July 2026All news

Entities

NEXPUBLICA FRANCE (vendor)PCRM (product)