French software company fined $2 million for cyber failings leading to data breach
法国数据保护机构CNIL因Nexpublica France公司网络安全措施不足导致数据泄露对其处以170万欧元罚款。调查发现该公司在数据安全方面存在严重缺陷,并在已知问题未解决情况下发生事故。罚款基于公司财务状况、缺乏安全知识、受影响人数及敏感数据处理等因素。 2025-12-29 17:31:27 Author: therecord.media(查看原文) 阅读量:0 收藏

France’s data protection regulator has fined the software company Nexpublica France €1.7 million ($2 million) for poor cybersecurity practices in the wake of a data breach.

In November 2022, users of a Nexpublica portal reported they could access documents about third parties. France’s data regulator, known as CNIL, investigated the incident and found that Nexpublica’s data security program was inadequate, according to an agency press release.

On December 22, CNIL levied the fine, which it said is based on the company’s “financial capacity, its lack of knowledge of basic security principles, the number of people affected and the sensitivity of the data processed.” 

Nexpublica’s poor security practices violated Europe’s General Data Protection Regulation, CNIL said.

The security problems were known to the company before the breach, but it did not address them until after the incident, the agency added.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/french-software-fined-cnil
如有侵权请联系:admin#unsafe.sh