Skip to content
MarketsIndicesCommoditiesFXRates
Technology

France CNIL to Inspect Tax Agency Over 700k Data Leak

France data protection agency CNIL will inspect tax authority DGFiP after summer intrusions compromised personal data of nearly 700,000 taxpayers.

France CNIL to Inspect Tax Agency Over 700k Data Leak

France's data protection regulator, the CNIL, will inspect the Directorate-General of Public Finances following summer intrusions that exposed personal data belonging to nearly 700,000 taxpayers.

CNIL President Marie-Laure Denis announced the inspection during an interview broadcast Thursday evening on national television channel France 2, stating that auditors would arrive at tax authority offices within days.

The interview for the investigative news program Cash Investigation was recorded on Monday. It follows multiple summer cyber intrusions into tax administration systems that sparked fierce debate over government cybersecurity standards.

The Commission nationale de l'informatique et des libertés, established in 1978, serves as France's independent administrative authority responsible for ensuring privacy laws apply to personal data collection. The Directorate-General of Public Finances, known as the DGFiP, operates under the Ministry of Economy and Finance to collect taxes, manage public accounting, and oversee government expenditures across France.

Targeted data and potential sanctions

Denis highlighted the severity of the security breach, emphasizing that attackers targeted highly sensitive financial details. The stolen information included citizens' reference tax income figures and their personal income tax withholding rates.

France operates a pay-as-you-earn income tax withholding system, known as prélèvement à la source, which requires the DGFiP to calculate individualized tax rates for workers and transmit them to employers. Reference tax income serves as the primary benchmark for determining household tax liabilities and eligibility for social benefits.

Denis explained that the watchdog must understand how the breaches occurred before determining regulatory action. Findings could result in a formal compliance notice issued by the end of the year or a sanction procedure lasting several additional months.

CNIL faces statutory limitations when taking enforcement action against central government bodies. Unlike private corporations, central state ministries cannot be fined by the data protection watchdog under French administrative law.

The regulatory framework was clarified in April when CNIL told television network TF1info that while it can issue monetary penalties against public establishments such as public hospitals or local municipalities, it lacks authority to fine state ministries directly.

Despite these legal restrictions, Denis stressed that government bodies bear a special obligation to maintain exemplary security standards. Safeguard measures for intimate personal data that citizens must hand over to public authorities represent a fundamental contract of trust between the state and the public, she told the program.

Senate findings and cybersecurity audit

The announcement comes alongside broader official reviews into the security failure. In August, Prime Minister Sébastien Lecornu instructed the National Agency for Cybersecurity of France, known as ANSSI, to conduct an in-depth audit of the tax system data theft.

ANSSI functions as France's national authority for cyberdefense and information security. Attached to the General Secretariat for National Defence and Security under the Prime Minister, the agency is tasked with protecting state networks and critical national infrastructure against cyber threats.

Parliamentary investigators have also identified system flaws. A note from the chairman and rapporteur of the Senate Finance Commission, consulted by news agency AFP, stated that the hack exposed multiple structural vulnerabilities within DGFiP information systems alongside shortcomings in post-incident checks.

The Senate Finance Commission is one of the permanent standing committees in the upper house of the French Parliament. It exercises parliamentary oversight over public finances, state budget execution, and administrative expenditures across government ministries.

Wider inspections and public body penalties

Denis confirmed that CNIL agents will also carry out an inspection of the National Agency for Secure Titles, known as ANTS. The secure document agency was hit by a massive cyberattack in April that resulted in the theft of personal data affecting nearly 12 million individuals and business professionals.

ANTS is the French administrative agency responsible for issuing official identity credentials across the country. Operating under the Ministry of the Interior, it processes applications for national identity cards, biometric passports, driving licenses, and vehicle registration certificates.

Unlike central ministries, public administrative entities like ANTS can face monetary fines. CNIL clarified in April that ANTS can face financial sanctions even though it operates under the direct supervision of the Ministry of the Interior.

Any fine imposed on a public administrative body creates no net financial burden for taxpayers, as penalty payments collected by the Treasury are returned directly to the state budget. In January, French national employment agency France Travail, which holds the same administrative status, was fined five million euros following a major data breach.

France Travail is the government agency responsible for managing unemployment benefits and job placement services nationwide. Formerly known as Pôle Emploi before its administrative rebranding, the organization processes personal and professional data for millions of job seekers across France.

Related

Leave a comment

Your email address will not be published. Required fields are marked *