
PERSONAL DATA – DGFIP data breach: who is liable?

DGFIP data breach – Who is liable?
On 14 August, the French Ministry of Finance confirmed that unauthorised access had been gained to the DGFiP’s systems as early as June 2026 using stolen login credentials, resulting in the viewing and extraction of data relating to 678,000 individuals and businesses.
Is the State responsible?
The State is subject to the requirements of the GDPR. However, State authorities are, in principle, not liable to administrative fines. Nevertheless, certain public bodies with legal personality may be subject to financial penalties, as recently illustrated by the €5 million fine imposed on France Travail. The absence of a fine does not, however, mean there is no liability. Data subjects may lodge a complaint with the CNIL and, if they can prove they have suffered harm, seek to hold the State liable. European case law is particularly illuminating: in Case C-340/21 of 14 December 2023, which specifically concerned a cyber-attack against the Bulgarian tax authorities, the CJEU recognised that the fear of future misuse of data could constitute compensable non-pecuniary damage. State liability is not, however, automatic: it is still necessary to establish a breach of the GDPR, damage and a causal link between the two.
What about pirates?
Fraudulent access to an automated data-processing system is punishable under Article 323-1 of the Criminal Code. The unauthorised extraction, possession, reproduction or transmission of data is covered by Article 323-3. Where such offences target a personal data system operated by the State, the penalty may be up to 7 years’ imprisonment and a fine of 300,000 euros. The transmission or resale of data is also a criminal offence.
678,000 potential victims: can we take collective action?
Since the Act of 30 April 2025, French class actions may be brought against a legal person governed by public law and may result in compensation being awarded for damages, of whatever nature, suffered by several persons in a similar situation.En matière de données personnelles, l’action peut notamment être portée par une association agréée ou certaines organisations syndicales représentatives.
Individuals do not, therefore, initiate the class action themselves. If liability is established, the court defines the criteria for the class, and those affected may then join the class in order to seek compensation for their own loss. They also retain their individual rights of redress.
FIRSH’s inputs |
FIRSH supports businesses and senior executives both at the outset – in setting up their cyber governance and compliance frameworks – and subsequently, when they are faced with a cyberattack, a breach or a data leak.
Claire Poirson & Samuel Brami