Nexpublica
Credit: Nexpublica

French software company fined $2 million for cyber failings leading to data breach

France’s data protection regulator has fined the software company Nexpublica France €1.7 million ($2 million) for poor cybersecurity practices in the wake of a data breach.

In November 2022, users of a Nexpublica portal reported they could access documents about third parties. France’s data regulator, known as CNIL, investigated the incident and found that Nexpublica’s data security program was inadequate, according to an agency press release.

On December 22, CNIL levied the fine, which it said is based on the company’s “financial capacity, its lack of knowledge of basic security principles, the number of people affected and the sensitivity of the data processed.” 

Nexpublica’s poor security practices violated Europe’s General Data Protection Regulation, CNIL said.

The security problems were known to the company before the breach, but it did not address them until after the incident, the agency added.

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Suzanne Smalley

Suzanne Smalley

is a reporter covering privacy, disinformation and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop and Reuters. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.