Following the theft of personal data affecting nearly 700,000 individuals, Marie-Laure Denis, president of France’s data protection authority, has raised the possibility of issuing a sanction against the Direction générale des finances publiques (DGFiP). The security breach at the tax administration has triggered an imminent regulatory intervention.
CNIL Control and Inspection of Tax Services
The security of personal records held by France’s tax administration is facing formal scrutiny. CNIL President Marie-Laure Denis announced during an interview on France 2’s “Cash Investigation” program that she has ordered agency teams to visit the offices of the DGFiP in the coming days. The targeted administration was hit by multiple digital intrusions over the summer, compromising the records of approximately 700,000 people.
The upcoming inspection aims to establish the precise circumstances surrounding the security incidents and evaluate the protective measures currently enforced by the DGFiP. « J’ai demandé aux équipes de la Cnil de se rendre dans les tout prochains jours dans les locaux de la Direction générale des finances publiques », stated Marie-Laure Denis. The findings will dictate whether the authority issues a formal notice to comply by the end of the year or initiates disciplinary proceedings leading to a sanction. Because the target is a state administration, the CNIL cannot issue a financial penalty.
Broader Government Audits and Secure Titles Agency
The tax agency is not the only government body facing scrutiny over digital vulnerabilities. The CNIL is also scheduled to audit the Agence nationale des titres sécurisés (ANTS), an agency responsible for processing identity documents. In April, ANTS suffered a cyberattack that exposed data belonging to roughly 12 million private citizens and professionals. Highlighting the stakes of these breaches, Marie-Laure Denis noted that the state holds a specific duty of exemplary conduct, emphasizing that data security forms a core part of the trust contract between the government and citizens required to share intimate personal details.
This oversight runs parallel to technical investigations already underway. Following the tax administration data theft, Prime Minister Sébastien Lecornu requested an in-depth audit of the DGFiP’s cybersecurity from the Anssi (Agence nationale de sécurité des systèmes d’information) in August. Furthermore, a memorandum issued by the president and the rapporteur of the Senate Finance Commission indicated that the tax authority’s cyber breach exposed structural fragilities within its information systems alongside shortcomings in post-incident oversight.