{"id":14221,"date":"2026-07-01T09:02:11","date_gmt":"2026-07-01T09:02:11","guid":{"rendered":"https:\/\/viqtor.eu\/?p=14221"},"modified":"2026-07-02T08:39:33","modified_gmt":"2026-07-02T08:39:33","slug":"violations-de-donnees-cnil-tire-sonnette-alarme","status":"publish","type":"post","link":"https:\/\/viqtor.eu\/en\/cnil-raises-alarm-about-data-breaches\/","title":{"rendered":"Data breaches: the CNIL raises the alarm, and we do too."},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"14221\" class=\"elementor elementor-14221\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2d75f86 ot-traditional elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2d75f86\" data-element_type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6e589fb ot-flex-column-vertical elementor-invisible\" data-id=\"6e589fb\" data-element_type=\"column\" data-settings=\"{&quot;animation&quot;:&quot;fadeInLeft&quot;,&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t<div class=\"elementor-background-overlay\"><\/div>\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a030734 elementor-widget elementor-widget-heading\" data-id=\"a030734\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Data breaches: the CNIL raises the alarm, and we agree.<\/h1>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7345c5d5 ot-traditional elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7345c5d5\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-11f89eef ot-flex-column-vertical\" data-id=\"11f89eef\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6dd20d9a elementor-widget elementor-widget-text-editor\" data-id=\"6dd20d9a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Two weeks ago, an executive called me in a panic. One of his service providers had just suffered a cyberattack. His customer files, which he thought were well protected with a &quot;certified&quot; SaaS provider, were out in the open. The first question he asked me was: &quot;Well, that&#039;s their problem, right?&quot; Well, no. It&#039;s his too. And that&#039;s precisely one of the key takeaways from the annual report published by the <b>CNIL <\/b>May 18th: <b>data leaks<\/b> explode, and the subcontracting chain is almost always in the equation.<\/p><p>6,167 notifications of <b>data breach<\/b> recorded in 2025. A record. 9.5 % more than in 2024, and the first quarter of 2026 is already following the same trend with 2,730 incidents. Behind these figures are millions of French people affected, businesses shaken, and a clear message from Marie-Laure Denis, president of the <b>CNIL<\/b> : there <b>cybersecurity <\/b>that of the State, as well as that of companies, is &quot;far from satisfactory&quot;.<\/p><div class=\"wp-block-buttons\"><p><!-- \/wp:button --><\/p><\/div><p><!-- \/wp:buttons --><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c6ed5c5 ot-traditional elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c6ed5c5\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5b31466 ot-flex-column-vertical\" data-id=\"5b31466\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f1dd04c elementor-widget elementor-widget-text-editor\" data-id=\"f1dd04c\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<h2>In summary<\/h2><ul><li>Absolute record of <b>data breaches<\/b> In France in 2025: 6,167 notifications, +9.5 % over one year, and the first quarter of 2026 confirms the trend.<\/li><li>THE <b>data leaks<\/b> are becoming increasingly massive, with the public administration at the forefront, and very often involve a service provider.<\/li><li>The evaluation and contractual framework of the <b>GDPR subcontractor<\/b> have become a primary obligation: a <b>DPA <\/b>Compliance, audits and monitoring are the basis.<\/li><li><b>Multi-factor authentication <\/b>(<b>MFA<\/b>) is now the measure that the <b>CNIL <\/b>waits by default. In 2026, 50 % of its controls will focus on the <b>cybersecurity<\/b>.<\/li><li>A procedure of <b>violation notification<\/b> tested, the update of <b>processing activities register<\/b> and the realization of <b>AIPD <\/b>make all the difference on the big day.<\/li><li>Compliance is not proven by intentions, but by documents: that&#039;s what it is.<b>accountability.<\/b><\/li><\/ul>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c26d073 ot-traditional elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c26d073\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-258e34b ot-flex-column-vertical\" data-id=\"258e34b\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e634570 elementor-widget elementor-widget-text-editor\" data-id=\"e634570\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<h2><span style=\"color: black;\">What the CNIL&#039;s annual report (really) says<\/span><\/h2><div><h3>&quot;Increasingly massive&quot; violations<\/h3><p>The report doesn&#039;t just count. It paints a picture. Around forty incidents in 2025 each affected more than a million people\u2014ten more than in 2024. The public administration leads the way with 19 million reported incidents, followed by healthcare, social services, and then financial and insurance activities. And that&#039;s not all: this figure doesn&#039;t even include cyberattacks against Weda and Harvest software, which alone generated more than 11,600 customer notifications. A single incident upstream, thousands of businesses downstream. That says it all.<\/p><h3>Three lessons that must be learned<\/h3><p>There <b>CNIL <\/b>Three key observations emerge that every leader should write prominently on the executive committee board. First: no one is spared. Sports federations, hotel chains, mutual insurance companies, local authorities, SMEs as well as large corporations\u2014the threat no longer has a typical profile. Second: the <b>data leaks<\/b> They concern increasingly considerable volumes. Thirdly, and this is where the subject ties back to our previous articles: these incidents often involve service providers. The <b>GDPR subcontractor<\/b> has become the most exposed link.<\/p><h3>The attackers&#039; method is becoming commonplace.<\/h3><p>Hacking accounts for half of all reported incidents. Behind this word lies a whole range of issues: <b>ransomware, phishing, credential stuffing<\/b>, theft of legitimate user accounts. Alongside this, 13 of the incidents stem from an incorrect recipient being copied on an email, 7 from hardware loss, and 7 from accidental posting. In short, human error remains a significant factor. And then there&#039;s generative AI, which, in the words of the president of the <b>CNIL<\/b>The ANTS case, in which a 15-year-old minor \u2014 &quot;not a prodigy,&quot; the prosecutor specified \u2014 is implicated after the hacking of the secure documents agency, is a chilling demonstration of this.<\/p><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b930d9d ot-traditional elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b930d9d\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-772bccc ot-flex-column-vertical\" data-id=\"772bccc\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f1cad34 elementor-widget elementor-widget-text-editor\" data-id=\"f1cad34\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<h2>Why your subcontractors are (still) at the heart of the problem<\/h2><div><h3>When a service provider falls, their clients fall with them.<\/h3><p>Let&#039;s return to the story of the Weda and Harvest software. These were two cyberattacks, but the authority received 11,600 notifications. Because each time, behind the software publisher, there are hundreds of medical practices, hundreds of wealth management advisors, who are also affected. <b>data controller<\/b> and must report the leak to their own customers. This is exactly the scenario of the subcontractor Mobius\/Deezer that the <b>CNIL <\/b>It was fined one million euros by the end of 2025 \u2014 except that here, the cost multiplies. One attack, a thousand professional victims, millions of people affected.<\/p><h3>The preliminary assessment: your best (and only) protection<\/h3><p>The GDPR leaves no room for doubt: a <b>data controller<\/b> &quot;only uses subcontractors who offer sufficient guarantees.&quot; This obligation, set out in Article 28, paragraph 1, is not wishful thinking. It&#039;s what the inspectors will be looking for. Specifically, do you send an evaluation questionnaire to each service provider? Do you ask about their safety policy, their <b>processing activities register<\/b>, the name of their <b>DPO<\/b>Their certifications? Have you identified your <b>data transfers<\/b> Outside the EU? If the answer to any of these questions is &quot;uh,&quot; you have your first operational priority.<\/p><h3>The contract alone is not enough, nor is the audit, but both together, yes.<\/h3><p>A <b>GDPR subcontracting agreement<\/b> well written \u2014 that is to say a <b>DPA<\/b> Reiterating the eight mandatory clauses of Article 28 \u00a73 \u2014 is the starting point. Not the end goal. Long-term management is also essential: annual audits, reviews of subsequent subcontractors, monitoring of <b>technical and organizational measures <\/b>effectively applied. To structure this approach, the <a href=\"https:\/\/viqtor.eu\/en\/subcontractor-module\/\">Viqtor Subcontractors Module<\/a> centralizes assessments, contracts, audits, and transaction history in a single repository. This is the kind of evidence that a controller <b>CNIL <\/b>Love to see.<\/p><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-06a5fd8 ot-traditional elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"06a5fd8\" data-element_type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-b73a781 ot-flex-column-vertical\" data-id=\"b73a781\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-16bd074 elementor-widget elementor-widget-text-editor\" data-id=\"16bd074\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Are your subcontractor contracts and evaluations up to date? <a href=\"https:\/\/viqtor.eu\/en\/contact\/\">Get the facts from a Viqtor expert<\/a><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a1d3388 elementor-align-center elementor-widget elementor-widget-button\" data-id=\"a1d3388\" data-element_type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-lg\" href=\"https:\/\/viqtor.eu\/en\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-long-arrow-alt-right\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Talk to a Viqtor\u00ae expert<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-5a1ad9a ot-traditional elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5a1ad9a\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c6404d5 ot-flex-column-vertical\" data-id=\"c6404d5\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ab57fe7 elementor-widget elementor-widget-text-editor\" data-id=\"ab57fe7\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<h2>What the government is doing \u2014 and what you should do in turn<\/h2><div><h3>200 million euros and a new digital authority<\/h3><p>At the end of April, Prime Minister S\u00e9bastien Lecornu unveiled his plan: 200 million euros to strengthen the <b>cybersecurity <\/b>of the State, merger of the interministerial directorate for digital affairs and that for public transformation to create a digital authority attached to the Prime Minister&#039;s office. Following this, the<b>ANSSI<\/b> has published new guidelines for ministries: each must appoint an advisor <b>cybersecurity<\/b>This is not insignificant. When the state reorganizes at this level, it means it considers the house to be on fire. However, in the chain, government departments outsource a great deal \u2014 and each service provider is a potential point of entry.<\/p><h3>Multi-factor authentication: the measure that could have prevented many tragedies<\/h3><p>There <b>CNIL <\/b>hammers home a simple message: the majority of recent major attacks could have been avoided with a <b>multi-factor authentication<\/b> correctly deployed. The <b>MFA<\/b>It is this dual factor that renders a large part of the techniques ineffective. <b>credential stuffing<\/b> and <b>phishing<\/b>The authority published its recommendation as early as March 2025, allowing organizations time to adapt, and is now announcing targeted controls. In 2026, 50% of enforcement actions will focus on the <b>cybersecurity<\/b>, compared to a quarter to a third in 2025. For bases that contain more than one million people, checks will be a priority.<\/p><h3>Some concrete projects to be launched this week<\/h3><p>Without overburdening the teams, there are a few actions that can be taken quickly and make a real difference in the event of an incident. Here&#039;s what I recommend to my executive clients when they ask me where to start.<\/p><ul><li>Activate the <b>MFA <\/b>on all privileged accounts and on access to tools containing <b>personal data<\/b>.<\/li><li>Update your list of subcontractors, verify that each one has a <b>DPA <\/b>signed, and identify those who carry out <b>data transfers<\/b> outside the EU.<\/li><li>Test your procedure <b>violation notification<\/b> Who notifies whom? Are you able to trace the chain of events back to the... <b>CNIL <\/b>within the legal time limit of <b>72 hours<\/b> ?<\/li><li>Documenting a <b>AIPD<\/b> (<b>impact analysis<\/b>) for your high-risk treatments \u2014 that&#039;s the other point that the <b>CNIL <\/b>systematic checks.<\/li><li>Take another quick look at your <b>processing activities register<\/b> : it is rarely as up-to-date as one might think.<\/li><\/ul><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-391fcbf ot-traditional elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"391fcbf\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-d9991cf ot-flex-column-vertical\" data-id=\"d9991cf\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-67924a8 elementor-widget elementor-widget-text-editor\" data-id=\"67924a8\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<h2>And what happens after the leak? Incident management, where everything hinges.<\/h2><div><h3>The first 72 hours decide the rest<\/h3><p>When a service provider alerts you, you have <b>72 hours<\/b> to notify the <b>CNIL <\/b>if the <b>data leak<\/b> presents a risk to people. Not three weeks. Not enough time to convene a steering committee. The procedure must be ready, written, tested, and ready to be activated on a Sunday evening. Our page dedicated to the <a href=\"https:\/\/viqtor.eu\/en\/data-breach-declaration\/\">data breach statement<\/a> details the steps to avoid doing it backwards.<\/p><h3>Informing those concerned, the moment of truth<\/h3><p>If the breach poses a high risk to individuals&#039; rights and freedoms, the GDPR also requires that each individual be informed directly. It is often at this point that crisis communication takes precedence over legal action. If poorly managed, trust collapses\u2014Marie-Laure Denis even speaks of &quot;the erosion of the bond of trust between the state and its citizens&quot; in relation to government leaks. For a private company, it means the customer leaves, and the lawyer arrives.<\/p><h3>The sanction, and what it says about the organization&#039;s maturity<\/h3><p>There <b>CNIL <\/b>It does not penalize the act of fleeing itself; it penalizes the failings that made it possible or aggravated it. Absence of<b>multi-factor authentication<\/b>incomplete register, generic subcontracting contracts, late notification, <b>accountability <\/b>non-existent. This is where the defense\u2014or the condemnation\u2014is built. To make this whole structure reliable, our <a href=\"https:\/\/viqtor.eu\/en\/guide-on-gdpr-compliance-auditing\/\">A complete guide to GDPR compliance audits<\/a> outlines the methodology used by our consultants.<\/p><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1c2f757 ot-traditional elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1c2f757\" data-element_type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-02dad30 ot-flex-column-vertical\" data-id=\"02dad30\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b25d845 elementor-widget elementor-widget-heading\" data-id=\"b25d845\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">FAQ <\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1131cac elementor-widget elementor-widget-toggle\" data-id=\"1131cac\" data-element_type=\"widget\" data-widget_type=\"toggle.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-toggle\">\n\t\t\t\t\t\t\t<div class=\"elementor-toggle-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-1801\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-1801\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon elementor-toggle-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-closed\"><i class=\"fas fa-angle-down\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-opened\"><i class=\"elementor-toggle-icon-opened fas fa-angle-up\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-toggle-title\" tabindex=\"0\">My service provider has suffered a data breach. Am I responsible?<\/a>\n\t\t\t\t\t<\/h3>\n\n\t\t\t\t\t<div id=\"elementor-tab-content-1801\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-1801\"><p>Inasmuch as <b>data controller<\/b>Yes, you remain legally responsible for the data processing, even if the leak originates from your subcontractor. You must analyze the risk and notify the <b>CNIL<\/b> if necessary in the <b>72 hours<\/b>and, where appropriate, inform the people concerned. Your <b>subcontracting agreement<\/b> <b>GDPR <\/b>must plan how the service provider alerts you and cooperates.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-toggle-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-1802\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-1802\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon elementor-toggle-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-closed\"><i class=\"fas fa-angle-down\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-opened\"><i class=\"elementor-toggle-icon-opened fas fa-angle-up\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-toggle-title\" tabindex=\"0\">Is multi-factor authentication mandatory?<\/a>\n\t\t\t\t\t<\/h3>\n\n\t\t\t\t\t<div id=\"elementor-tab-content-1802\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-1802\"><p>It is not explicitly stated in the GDPR, but the <b>CNIL <\/b>considers it an expected technical measure for any access to <b>personal data<\/b> sensitive or large-scale. Its March 2025 recommendation is explicit, and the 2026 audits will primarily target organizations that have not implemented it. In short: it is no longer optional.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-toggle-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-1803\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-1803\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon elementor-toggle-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-closed\"><i class=\"fas fa-angle-down\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-opened\"><i class=\"elementor-toggle-icon-opened fas fa-angle-up\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-toggle-title\" tabindex=\"0\">What is the deadline for notifying the CNIL of a data breach?<\/a>\n\t\t\t\t\t<\/h3>\n\n\t\t\t\t\t<div id=\"elementor-tab-content-1803\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-1803\"><p><b>72 hours<\/b> from the moment the incident is reported, unless the violation is unlikely to pose a risk to the rights and freedoms of individuals. Beyond this point, a late notification must be justified. The report is made via the online service of the <b>CNIL<\/b> and must describe the nature of the breach, the categories of data involved, and the measures taken.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-toggle-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-1804\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-1804\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon elementor-toggle-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-closed\"><i class=\"fas fa-angle-down\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-opened\"><i class=\"elementor-toggle-icon-opened fas fa-angle-up\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-toggle-title\" tabindex=\"0\">What are the first actions to be implemented for an SME?<\/a>\n\t\t\t\t\t<\/h3>\n\n\t\t\t\t\t<div id=\"elementor-tab-content-1804\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-1804\"><p>Mapping treatments and maintaining a <b>processing activities register<\/b> keep up to date, identify and properly contract each subcontractor via a <b>DPA<\/b>deploy the <b>MFA<\/b>write a procedure for <b>violation notification<\/b>, and designate a referent or a <b>DPO<\/b>These five construction sites cover the essential control points. <b>CNIL<\/b>.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-toggle-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-1805\" class=\"elementor-tab-title\" data-tab=\"5\" role=\"button\" aria-controls=\"elementor-tab-content-1805\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon elementor-toggle-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-closed\"><i class=\"fas fa-angle-down\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-opened\"><i class=\"elementor-toggle-icon-opened fas fa-angle-up\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-toggle-title\" tabindex=\"0\">What is the purpose of a Data Protection Impact Assessment (DPIA) and when should one be carried out?<\/a>\n\t\t\t\t\t<\/h3>\n\n\t\t\t\t\t<div id=\"elementor-tab-content-1805\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"5\" role=\"region\" aria-labelledby=\"elementor-tab-title-1805\"><p>L&#039;<b>AIPD<\/b> (<b>impact analysis<\/b>A risk assessment is mandatory for processing activities that present a high risk to rights and freedoms: large-scale surveillance, sensitive data, automated profiling, etc. It documents the risks, the measures to mitigate them, and demonstrates your risk management approach.<b>accountability<\/b>This is one of the first documents that the <b>CNIL <\/b>request in case of inspection.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t<script type=\"application\/ld+json\">{\n    \"@context\": \"https:\\\/\\\/schema.org\",\n    \"@type\": \"FAQPage\",\n    \"mainEntity\": [\n        {\n            \"@type\": \"Question\",\n            \"name\": \"Mon prestataire a subi une fuite de donn\\u00e9es. Est-ce que je suis responsable ?\",\n            \"acceptedAnswer\": {\n                \"@type\": \"Answer\",\n                \"text\": \"<p>En tant que <b>responsable de traitement<\\\/b>, oui, vous restez juridiquement responsable du traitement, m\\u00eame si la fuite vient de votre sous-traitant. Vous devez analyser le risque, notifier la <b>CNIL<\\\/b> si n\\u00e9cessaire dans les <b>72 heures<\\\/b>, et le cas \\u00e9ch\\u00e9ant informer les personnes concern\\u00e9es. Votre <b>contrat de sous-traitance<\\\/b> <b>RGPD <\\\/b>doit pr\\u00e9voir comment le prestataire vous alerte et coop\\u00e8re.<\\\/p>\"\n            }\n        },\n        {\n            \"@type\": \"Question\",\n            \"name\": \"L'authentification multifacteur est-elle obligatoire ?\",\n            \"acceptedAnswer\": {\n                \"@type\": \"Answer\",\n                \"text\": \"<p>Elle n&rsquo;est pas inscrite noir sur blanc dans le RGPD, mais la <b>CNIL <\\\/b>la consid\\u00e8re comme une mesure technique attendue pour tout acc\\u00e8s \\u00e0 des <b>donn\\u00e9es personnelles<\\\/b> sensibles ou \\u00e0 grande \\u00e9chelle. Sa recommandation de mars 2025 est explicite, et les contr\\u00f4les 2026 viseront en priorit\\u00e9 les organismes qui ne l&rsquo;auraient pas d\\u00e9ploy\\u00e9e. En clair : ce n&rsquo;est plus une option.<\\\/p>\"\n            }\n        },\n        {\n            \"@type\": \"Question\",\n            \"name\": \"Quel d\\u00e9lai pour notifier une violation de donn\\u00e9es \\u00e0 la CNIL ?\",\n            \"acceptedAnswer\": {\n                \"@type\": \"Answer\",\n                \"text\": \"<p><b>72 heures<\\\/b> \\u00e0 compter de la prise de connaissance de l&rsquo;incident, sauf si la violation n&rsquo;est pas susceptible d&rsquo;engendrer un risque pour les droits et libert\\u00e9s des personnes. Au-del\\u00e0, une notification tardive doit \\u00eatre motiv\\u00e9e. La d\\u00e9claration se fait via le t\\u00e9l\\u00e9service de la <b>CNIL<\\\/b> et doit d\\u00e9crire la nature de la violation, les cat\\u00e9gories de donn\\u00e9es concern\\u00e9es et les mesures prises.<\\\/p>\"\n            }\n        },\n        {\n            \"@type\": \"Question\",\n            \"name\": \"Quelles sont les premi\\u00e8res actions \\u00e0 mettre en place pour une PME ?\",\n            \"acceptedAnswer\": {\n                \"@type\": \"Answer\",\n                \"text\": \"<p>Cartographier les traitements et tenir un <b>registre des activit\\u00e9s de traitement<\\\/b> \\u00e0 jour, identifier et contractualiser correctement chaque sous-traitant via un <b>DPA<\\\/b>, d\\u00e9ployer le <b>MFA<\\\/b>, \\u00e9crire une proc\\u00e9dure de <b>notification de violation<\\\/b>, et d\\u00e9signer un r\\u00e9f\\u00e9rent ou un <b>DPO<\\\/b>. Ces cinq chantiers couvrent l&rsquo;essentiel des points de contr\\u00f4le <b>CNIL<\\\/b>.<\\\/p>\"\n            }\n        },\n        {\n            \"@type\": \"Question\",\n            \"name\": \"\\u00c0 quoi sert une AIPD et quand faut-il en faire une ?\",\n            \"acceptedAnswer\": {\n                \"@type\": \"Answer\",\n                \"text\": \"<p>L&rsquo;<b>AIPD<\\\/b> (<b>analyse d&rsquo;impact<\\\/b>) est obligatoire pour les traitements pr\\u00e9sentant un risque \\u00e9lev\\u00e9 pour les droits et libert\\u00e9s : surveillance \\u00e0 grande \\u00e9chelle, donn\\u00e9es sensibles, profilage automatis\\u00e9, etc. Elle documente les risques, les mesures pour les r\\u00e9duire, et d\\u00e9montre votre d\\u00e9marche d&rsquo;<b>accountability<\\\/b>. C&rsquo;est l&rsquo;un des premiers documents que la <b>CNIL <\\\/b>demande en cas de contr\\u00f4le.<\\\/p>\"\n            }\n        }\n    ]\n}<\/script>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-58cdd38 ot-traditional elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"58cdd38\" data-element_type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-42fa8a7 ot-flex-column-vertical\" data-id=\"42fa8a7\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-73cfdbe elementor-widget elementor-widget-text-editor\" data-id=\"73cfdbe\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Do you want to turn these lessons into a concrete action plan?<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d84722f elementor-align-center elementor-widget elementor-widget-button\" data-id=\"d84722f\" data-element_type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-lg\" href=\"https:\/\/viqtor.eu\/en\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-long-arrow-alt-right\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\"> Let&#039;s talk to a Viqtor expert about it<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c3438bb ot-traditional elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c3438bb\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-d9aacbe ot-flex-column-vertical\" data-id=\"d9aacbe\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-566c278 elementor-widget elementor-widget-text-editor\" data-id=\"566c278\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>To learn more, find all our resources on the <a href=\"https:\/\/viqtor.eu\/en\/data-governance\/\">data governance<\/a> and GDPR compliance on the <a href=\"https:\/\/viqtor.eu\/en\">Viqtor platform<\/a>.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Record number of data breaches expected in 2025 according to the CNIL. Subcontractors, MFA, 72-hour notification: what you need to know and do now.<\/p>","protected":false},"author":3,"featured_media":14327,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"elementor_header_footer","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[37],"tags":[],"class_list":["post-14221","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Violations de donn\u00e9es : la CNIL tire la sonnette d&#039;alarme<\/title>\n<meta name=\"description\" content=\"Record de violations de donn\u00e9es en 2025 selon la CNIL. Sous-traitants, MFA, notification sous 72h : ce qu&#039;il faut retenir et faire.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/viqtor.eu\/en\/cnil-raises-alarm-about-data-breaches\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Violations de donn\u00e9es : la CNIL tire la sonnette d&#039;alarme\" \/>\n<meta property=\"og:description\" content=\"Record de violations de donn\u00e9es en 2025 selon la CNIL. Sous-traitants, MFA, notification sous 72h : ce qu&#039;il faut retenir et faire.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/viqtor.eu\/en\/cnil-raises-alarm-about-data-breaches\/\" \/>\n<meta property=\"og:site_name\" content=\"Viqtor\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-01T09:02:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-02T08:39:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/viqtor.eu\/wp-content\/uploads\/2026\/04\/widget-viqtor.png\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1365\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"hedi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"hedi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/\"},\"author\":{\"name\":\"hedi\",\"@id\":\"https:\/\/viqtor.eu\/#\/schema\/person\/0afd87c59ae4bd97a30bbbf61efe2bdc\"},\"headline\":\"Violations de donn\u00e9es : la CNIL tire la sonnette d&rsquo;alarme, et nous avec\u200b\",\"datePublished\":\"2026-07-01T09:02:11+00:00\",\"dateModified\":\"2026-07-02T08:39:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/\"},\"wordCount\":2198,\"publisher\":{\"@id\":\"https:\/\/viqtor.eu\/#organization\"},\"image\":{\"@id\":\"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/viqtor.eu\/wp-content\/uploads\/2026\/07\/Violation-des-donnees-scaled.jpg\",\"articleSection\":[\"Blog\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/\",\"url\":\"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/\",\"name\":\"Violations de donn\u00e9es : la CNIL tire la sonnette d'alarme\",\"isPartOf\":{\"@id\":\"https:\/\/viqtor.eu\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/viqtor.eu\/wp-content\/uploads\/2026\/07\/Violation-des-donnees-scaled.jpg\",\"datePublished\":\"2026-07-01T09:02:11+00:00\",\"dateModified\":\"2026-07-02T08:39:33+00:00\",\"description\":\"Record de violations de donn\u00e9es en 2025 selon la CNIL. Sous-traitants, MFA, notification sous 72h : ce qu'il faut retenir et faire.\",\"breadcrumb\":{\"@id\":\"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#primaryimage\",\"url\":\"https:\/\/viqtor.eu\/wp-content\/uploads\/2026\/07\/Violation-des-donnees-scaled.jpg\",\"contentUrl\":\"https:\/\/viqtor.eu\/wp-content\/uploads\/2026\/07\/Violation-des-donnees-scaled.jpg\",\"width\":2560,\"height\":1365},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/viqtor.eu\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Violations de donn\u00e9es : la CNIL tire la sonnette d&rsquo;alarme, et nous avec\u200b\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/viqtor.eu\/#website\",\"url\":\"https:\/\/viqtor.eu\/\",\"name\":\"Viqtor\",\"description\":\"Faites du RGPD une opportunit\u00e9 pour votre entreprise.\",\"publisher\":{\"@id\":\"https:\/\/viqtor.eu\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/viqtor.eu\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/viqtor.eu\/#organization\",\"name\":\"viqtor.eu\",\"url\":\"https:\/\/viqtor.eu\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/viqtor.eu\/#\/schema\/logo\/image\/\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"viqtor.eu\"},\"image\":{\"@id\":\"https:\/\/viqtor.eu\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/viqtor.eu\/#\/schema\/person\/0afd87c59ae4bd97a30bbbf61efe2bdc\",\"name\":\"hedi\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/viqtor.eu\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b453727309969140a2f5c858b970fe7a21afb4251c92a7bb2c6582a5ce6ebba8?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b453727309969140a2f5c858b970fe7a21afb4251c92a7bb2c6582a5ce6ebba8?s=96&d=mm&r=g\",\"caption\":\"hedi\"},\"url\":\"https:\/\/viqtor.eu\/en\/author\/hedi\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Violations de donn\u00e9es : la CNIL tire la sonnette d'alarme","description":"Record de violations de donn\u00e9es en 2025 selon la CNIL. Sous-traitants, MFA, notification sous 72h : ce qu'il faut retenir et faire.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/viqtor.eu\/en\/cnil-raises-alarm-about-data-breaches\/","og_locale":"en_US","og_type":"article","og_title":"Violations de donn\u00e9es : la CNIL tire la sonnette d'alarme","og_description":"Record de violations de donn\u00e9es en 2025 selon la CNIL. Sous-traitants, MFA, notification sous 72h : ce qu'il faut retenir et faire.","og_url":"https:\/\/viqtor.eu\/en\/cnil-raises-alarm-about-data-breaches\/","og_site_name":"Viqtor","article_published_time":"2026-07-01T09:02:11+00:00","article_modified_time":"2026-07-02T08:39:33+00:00","og_image":[{"width":2560,"height":1365,"url":"https:\/\/viqtor.eu\/wp-content\/uploads\/2026\/04\/widget-viqtor.png","type":"image\/jpeg"}],"author":"hedi","twitter_card":"summary_large_image","twitter_misc":{"Written by":"hedi","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#article","isPartOf":{"@id":"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/"},"author":{"name":"hedi","@id":"https:\/\/viqtor.eu\/#\/schema\/person\/0afd87c59ae4bd97a30bbbf61efe2bdc"},"headline":"Violations de donn\u00e9es : la CNIL tire la sonnette d&rsquo;alarme, et nous avec\u200b","datePublished":"2026-07-01T09:02:11+00:00","dateModified":"2026-07-02T08:39:33+00:00","mainEntityOfPage":{"@id":"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/"},"wordCount":2198,"publisher":{"@id":"https:\/\/viqtor.eu\/#organization"},"image":{"@id":"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#primaryimage"},"thumbnailUrl":"https:\/\/viqtor.eu\/wp-content\/uploads\/2026\/07\/Violation-des-donnees-scaled.jpg","articleSection":["Blog"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/","url":"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/","name":"Violations de donn\u00e9es : la CNIL tire la sonnette d'alarme","isPartOf":{"@id":"https:\/\/viqtor.eu\/#website"},"primaryImageOfPage":{"@id":"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#primaryimage"},"image":{"@id":"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#primaryimage"},"thumbnailUrl":"https:\/\/viqtor.eu\/wp-content\/uploads\/2026\/07\/Violation-des-donnees-scaled.jpg","datePublished":"2026-07-01T09:02:11+00:00","dateModified":"2026-07-02T08:39:33+00:00","description":"Record de violations de donn\u00e9es en 2025 selon la CNIL. Sous-traitants, MFA, notification sous 72h : ce qu'il faut retenir et faire.","breadcrumb":{"@id":"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#primaryimage","url":"https:\/\/viqtor.eu\/wp-content\/uploads\/2026\/07\/Violation-des-donnees-scaled.jpg","contentUrl":"https:\/\/viqtor.eu\/wp-content\/uploads\/2026\/07\/Violation-des-donnees-scaled.jpg","width":2560,"height":1365},{"@type":"BreadcrumbList","@id":"https:\/\/viqtor.eu\/violations-de-donnees-cnil-tire-sonnette-alarme\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/viqtor.eu\/"},{"@type":"ListItem","position":2,"name":"Violations de donn\u00e9es : la CNIL tire la sonnette d&rsquo;alarme, et nous avec\u200b"}]},{"@type":"WebSite","@id":"https:\/\/viqtor.eu\/#website","url":"https:\/\/viqtor.eu\/","name":"Viqtor","description":"Faites du RGPD une opportunit\u00e9 pour votre entreprise.","publisher":{"@id":"https:\/\/viqtor.eu\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/viqtor.eu\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/viqtor.eu\/#organization","name":"viqtor.eu","url":"https:\/\/viqtor.eu\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/viqtor.eu\/#\/schema\/logo\/image\/","url":"","contentUrl":"","caption":"viqtor.eu"},"image":{"@id":"https:\/\/viqtor.eu\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/viqtor.eu\/#\/schema\/person\/0afd87c59ae4bd97a30bbbf61efe2bdc","name":"hedi","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/viqtor.eu\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b453727309969140a2f5c858b970fe7a21afb4251c92a7bb2c6582a5ce6ebba8?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b453727309969140a2f5c858b970fe7a21afb4251c92a7bb2c6582a5ce6ebba8?s=96&d=mm&r=g","caption":"hedi"},"url":"https:\/\/viqtor.eu\/en\/author\/hedi\/"}]}},"_links":{"self":[{"href":"https:\/\/viqtor.eu\/en\/wp-json\/wp\/v2\/posts\/14221","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/viqtor.eu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/viqtor.eu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/viqtor.eu\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/viqtor.eu\/en\/wp-json\/wp\/v2\/comments?post=14221"}],"version-history":[{"count":26,"href":"https:\/\/viqtor.eu\/en\/wp-json\/wp\/v2\/posts\/14221\/revisions"}],"predecessor-version":[{"id":14331,"href":"https:\/\/viqtor.eu\/en\/wp-json\/wp\/v2\/posts\/14221\/revisions\/14331"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/viqtor.eu\/en\/wp-json\/wp\/v2\/media\/14327"}],"wp:attachment":[{"href":"https:\/\/viqtor.eu\/en\/wp-json\/wp\/v2\/media?parent=14221"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/viqtor.eu\/en\/wp-json\/wp\/v2\/categories?post=14221"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/viqtor.eu\/en\/wp-json\/wp\/v2\/tags?post=14221"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}