France · Question · Question écrite
16032
Question 16032 — digital
Introduced
16 June 2026
Last action
—
Status
posée
Sponsors
—
Subjects
Discovery layer
Source updated
16 June 2026
Summary
Mr. Alexandre Dufosset draws the attention of the Minister Delegate to the Minister of the Economy, Finance and Industrial, Energy and Digital Sovereignty, responsible for artificial intelligence and digital technology, to the multiplication of massive leaks of personal data in France and to the inadequacy of the protection and compensation mechanisms for citizens. For several years, personal data breaches are experiencing a worrying progression. The CNIL indicates that in 2024, 5,629 data breaches were notified to it, an increase of 20% compared to the previous year and that the number of breaches affecting more than a million people has doubled in one year. These incidents no longer only concern private actors, but now affect public platforms, health services or administrations processing data particularly sensitive. Recent examples illustrate the extent of the phenomenon. The CNIL sanctioned France Travail to the tune of 5 million euros after an intrusion which allowed access to the data of people registered or having been registered over the last twenty years, including in particular social security numbers. It also sanctioned the companies Free Mobile and Free for a cumulative amount of 42 million euros after a leak concerning 24 million subscriber contracts, including IBANs. Even more recently, the Ministry of the Interior confirmed that a security incident relating to the ANTS-France Titles portal could concern 11.7 million accounts, exposing in particular identification data such as surname, first names, email address, date of birth or account identifier. The accumulation of these incidents could concern a significant part of the French population, exposing citizens to increased risks of identity theft, fraud and lasting invasion of their privacy. These leaks do not constitute simple abstract invasions of privacy; they directly expose French people to identity theft, targeted phishing, bank fraud, etc. However, as shown in a recent report from the Génération ideas laboratory Free, the current model is mainly based on the notification of incidents, administrative sanctions pronounced by the CNIL and individual appeals that are often long, complex and difficult to access. Article 82 of the GDPR certainly recognizes a right to compensation in the event of material or moral damage, but, in practice, victims must still establish their damage and the causal link, which strongly limits the effectiveness of their compensation. Consequently, he asks whether the Government intends to initiate a discussion aimed at strengthening the minimum technical security obligations applicable to public and private databases. He also asks whether the creation of a direct and automatic compensation mechanism for victims of massive data leaks is being considered, so that the sanctions imposed do not only benefit the State, but also make it possible to concretely repair the damage suffered by citizens.
Machine translation from French. The official text remains authoritative.
Timeline
No timeline events have been ingested for this record yet.
Votes
No vote records are attached yet.
Versions
No version snapshots stored. Document URLs remain at the source.
Documents
No documents linked.
Sponsors
No sponsors or actors listed by the source.
Related records
No cross-record relationships stored yet.
Sources
PoliticalRepo is an index and interpretation layer, not the authoritative legal source.
- Official source: https://www.assemblee-nationale.fr/dyn/17/questions/QANR5L17QE16032
- Open data entity: https://www.assemblee-nationale.fr/dyn/opendata/QANR5L17QE16032