Skip to content

Swiss Chinese Law Association — Geneva

SCLA | Swiss Chinese Law Association

Legal Observatory / AI and Data

Legal Update European Union Regulatory guidance

CNIL Closes Injunction Against France Travail Following Compliance with GDPR Security Mandates

CNIL closed its compliance injunction against France Travail without levying daily penalties after the agency implemented required GDPR data security upgrades.

What Changed

  • CNIL adopted Deliberation SAN-2026-013 on 23 September 2026, closing the January 2026 injunction against France Travail.
  • France Travail demonstrated full implementation of multi-factor authentication, robust password policies, active log supervision, and access restrictions.
  • The restricted committee decided not to collect the conditional €5,000 daily penalty following verified compliance.

The French Data Protection Authority (CNIL) announced on 8 October 2026 that its restricted committee (formation restreinte) closed the injunction previously issued against France Travail on 22 January 2026. Following proof of full compliance within the designated timeframe, the regulator decided not to collect the conditional daily penalty payment (astreinte).

Background and Initial Sanctions

In January 2026, the CNIL's restricted committee imposed a €5 million fine on France Travail due to insufficient security measures protecting jobseekers' personal data, violating Article 32 of the General Data Protection Regulation (GDPR). Alongside the sanction, the CNIL issued an injunction ordering technical and operational remediations, backed by a potential daily non-compliance penalty of €5,000.

Required Remediation Measures

To achieve compliance, France Travail was required to implement specific security controls across four key operational areas:

1. Password Robustness: Adopting a stricter password policy incorporating account access restriction mechanisms.

2. Advisor Authentication: Enforcing multi-factor authentication (MFA) for CAP EMPLOI advisor accounts.

3. Activity Log Supervision: Establishing active monitoring and logging mechanisms for the MAP tool.

4. Access Control Management: Restricting CAP EMPLOI advisors' access strictly to personal data necessary for their support duties.

Closure of Injunction

Through Deliberation SAN-2026-013 on 23 September 2026, the CNIL formally confirmed that France Travail demonstrated timely adherence to all compliance requirements. The agency introduced enhanced authentication controls, robust password rules, MFA integration, upgraded log monitoring tools, and role-based access restrictions.

Because France Travail satisfied the remedial orders, the restricted committee decided not to liquidate the €5,000 daily penalty and officially closed the injunction procedure. The case highlights technical security expectations for public entities and large-scale data controllers under EU data protection law.

Who May Be Affected

France Travail, CAP EMPLOI advisors, and jobseekers in France whose personal data is processed by the agency.

Cross-Border Context

Relevant across the European Union as an example of administrative enforcement and technical security compliance standards under Article 32 GDPR.

What to check next

  • Consult CNIL Deliberation SAN-2026-013 and Deliberation SAN-2026-003 on Légifrance for full text details.
  • Review CNIL recommendations on multi-factor authentication and log monitoring under Article 32 GDPR.

This article provides general information and does not constitute legal advice. Consult the official text and obtain advice appropriate to your circumstances where needed.

Keep the issues that matter to you in view

Subscribe to SCLA updates and choose your interests.