CNIL (France) - SAN-2025-015
| CNIL - SAN-2025-015 | |
|---|---|
| Authority: | CNIL (France) |
| Jurisdiction: | France |
| Relevant Law: | Article 4 GDPR Article 28 GDPR Article 32 GDPR Article 6 ECHR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 22.11.2022 |
| Decided: | 22.12.2025 |
| Published: | 24.12.2025 |
| Fine: | 1700000 EUR |
| Parties: | NEXTPUBLICA France MDPH Nord |
| National Case Number/Name: | SAN-2025-015 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | French |
| Original Source: | JO (in FR) |
| Initial Contributor: | claratab |
The DPA imposed a €1,700,000 fine to a processor who had incorrectly configured a software that processed files relating to persons with disabilities, leading to a massive data breach.
English Summary
Facts
Nextpublica, a software consulting company (the processor) provided the Maison Départementale pour les Personnes Handicapées MDPH, a public interest group (the controller), with software for processing files relating to persons with disabilities. This software enabled users (data subjects) to upload their files and track their progress via an online portal.
On 2 November and 10 November 2022, data subjects using the portal reported to the controller that they had access to files relating to other data subjects.
On 22 November 2022, the controller notified the data breach to the DPA. The breach was found to be due to a configuration mistake, made by the processor.
After an on-site inspection, the DPA opened an investigation.
Holding
The dispute related to the processor’s responsibility for implementing adequate security measures, under Article 32 GDPR.
On the fairness of the procedure:
At first, the DPA rejected the argument based on a violation of Article 6 ECHR. The DPA pointed out that the right not to incriminate oneself is not incompatible with the sharing of the complainant’s internal reports, even under coercive measures. What’s more, the disclosed reports are evidence on which the DPA can base its argument.
About responsibilities:
The DPA jointly appreciated article 4(8) GDPR, article 28 (3)(a) GDPR and article 32 GDPR. The DPA noted that the contract binding the processor and the controller, as well as the processor’s expertise as a software consulting company, show that the processor was responsible for ensuring data security.
As a result, the processor was also responsible for its sub-processors compliance to GDPR, especially when they introduced a block of computer code on the software’s code.
On the violation of article 32 GDPR:
The DPA recalled that the definition of security measures must take into account the state of art, the cost of such measures, but also the risks of the processing and the category of personal data processed. The rapporteur noted that the personal data processed were sensitive data, and that the security measures must be adapted to such circumstances.
To evaluate the measures taken, the DPA referred to a principle of the National Agency for Information Systems Security (French ANSSI). The principle is that the security of an information system must be based on a coherent whole, rather than on specific security points, so that, in theory, the whole does not depend on a few security points. With this principle, the information system is supposed to balance the failure of one of its security points.
Here, the DPA highlighted that the software was processing a large amount of personal data, even sensitive data, with a high risk for data subjects in case of a violation, due to the aggregation of extremely precise and various data (health related, national identifier, financial status, identification data).
The processor was aware of critical and significant vulnerabilities, thanks to reports he commissioned. In addition, an internal report had identified the weakness of the information system security, particularly the use of an obsolete encryption system.
However, the processor has not taken any measures to remedy the situation before a breach occurred.
The DPA considered that the processor had not taken sufficient measures to ensure the security of the personal data processed, and so violated article 32 GDPR.
A fine of €1,700,000 is imposed to the processor.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the French original. Please refer to the French original for more details.
Decision of the restricted panel No. SAN – 2025-015 of December 22, 2025, imposing a financial penalty on the company NEXPUBLICA FRANCE The French Data Protection Authority (CNIL), meeting in its restricted panel composed of Mr. Philippe-Pierre CABOURDIN, Chairman, Mr. Vincent LESCLOUS, Vice-Chairman, Ms. Laurence FRANCESCHINI, Ms. Isabelle LATOURNARIE-WILLEMS, and Mr. Didier KLING, Members, Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data; Having regard to Law No. 78-17 of January 6, 1978, on Data Processing, Data Files and Individual Liberties, in particular Articles 20 et seq.; Having regard to Decree No. 2019-536 of 29 May 2019 implementing Law No. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties; Having regard to Resolution No. 2013-175 of 4 July 2013 adopting the Rules of Procedure of the National Commission for Information Technology and Civil Liberties; Having regard to Decision No. 2025-1154 QPC of 8 August 2025 of the Constitutional Council; Having regard to Decision No. 2023-063C of 20 March 2023 of the President of the National Commission for Information Technology and Civil Liberties instructing the Secretary General to conduct or have conducted an audit; Having regard to the decision of the President of the National Commission for Information Technology and Civil Liberties (CNIL) appointing a rapporteur to the restricted panel on May 13, 2025; Having regard to the report of Mr. Fabien TARISSAN, rapporteur, dated June 16, 2025, served on NEXPUBLICA FRANCE on June 17, 2025; Having regard to the written observations of NEXPUBLICA FRANCE received on July 29, 2025; Having regard to the rapporteur's response notified to NEXPUBLICA FRANCE on August 29, 2025; Having regard to the written observations of NEXPUBLICA FRANCE received on October 10, 2025; Having regard to the closure of the investigation notified to NEXPUBLICA FRANCE on October 29, 2025; Having regard to the oral submissions made during the hearing of the restricted panel on November 27, 2025; Having regard to the other documents in the file, The following were present at the hearing of the restricted panel: - Mr. Fabien TARISSAN, Commissioner, who presented his report; As representatives of NEXPUBLICA FRANCE: - (…) NEXPUBLICA FRANCE, having been informed of its right to remain silent on the allegations against it and having been given the last word; After deliberation, adopted the following decision: I. Facts and Procedure 1. NEXPUBLICA FRANCE (hereinafter, "the Company") is a simplified joint-stock company located at 4-10, rue Mozart in Clichy (92110). In 2024, it employed approximately 1,000 people, its revenue was (…) and its net income was (…) euros. 2. As of January 21, 2025, the company is no longer a subsidiary of the INETUM Group. Formerly "INETUM SOFTWARE FRANCE," the company also changed its corporate name by publication in the Official Bulletin of Civil and Commercial Announcements on March 28, 2025, becoming "NEXPUBLICA FRANCE." INETUM and NEXPUBLICA FRANCE are now separate legal entities, pursuing distinct economic activities and with no capital link. 3. NEXPUBLICA FRANCE continues the IT systems and software consulting activities of INETUM SOFTWARE FRANCE. It develops and markets a software package called "Public CRM" (hereinafter, "PCRM"), which is a tool for managing user relationships in the field of social services. The first version of this management tool was put into production at the MDPH (Departmental Center for Disabled Persons) of the Nord department on December 24, 2019. 4. The Public Interest Group (GIP) Departmental Center for Disabled Persons (hereinafter, "MDPH") of the Nord department uses PCRM to fulfill its role as a single point of contact for information for people with disabilities and their families, as well as the administrative and medical-social processing of all applications for disability compensation. For example, the MDPH processes applications for priority cards, disability cards, parking permits, and educational allowances for children with disabilities; it provides support for schooling or professional integration for the individuals within its remit; It directs individuals to medical and social care facilities or services, and processes applications for disability compensation benefits. 5. NEXPUBLICA FRANCE publishes and hosts the PCRM (Personalized Care and Resource Management System), which allows the MDPH (Departmental Center for Disabled Persons) of the Nord department to monitor the applications under its responsibility, and enables users to track the progress of their cases via the PCRM's online platform, "portail-autonomie-usager.lenord.fr". 6. NEXPUBLICA FRANCE subcontracts the hosting and user access management of its information system to the company (…) which belongs to (…), certified as a "health data host" within the meaning of Article L. 1111-8 of the French Public Health Code. 7. As of May 2023, approximately (…) user accounts had been created for the MDPH of the Nord department since the software went live (December 24, 2019). The barometer established by the National Solidarity Fund for Autonomy indicates that the MDPH (Departmental House for Persons with Disabilities) of the Nord department issued (…) decisions and opinions in 2022 and that, in the same year, (…) people had at least one open entitlement with the MDPH. 8. On November 2 and 10, 2022, users of the MDPH portal reported having access to documents concerning third parties. On November 29, 2022, the MDPH of the Nord department notified the National Commission for Information Technology and Civil Liberties (hereinafter "the Commission" or "the CNIL") of a personal data breach. Following investigations that clarified the characteristics of the breach, the MDPH supplemented its notification on March 6, 2023. 9. These data breach notifications sent to the CNIL report the occurrence of two security incidents, which the MDPH attributes to configuration errors by the company NEXPUBLICA FRANCE. 10. The first incident occurred from October 26 to November 8, 2022. The MDPH (Departmental House for Persons with Disabilities) indicated in its breach notification that an incorrect configuration by NEXPUBLICA FRANCE allowed users to access third-party data to which they were not entitled. The breach notification states that 366 people were thus able to access third-party data stored in PCRM. The company indicates that among these 366 people, only two users had the technical means to access third-party personal data through these incorrect settings. 11. The second incident occurred from October 26 to November 14, 2022. According to the MDPH, this breach was also due to a configuration error by NEXPUBLICA FRANCE and led to page display anomalies. Some users gained read-only access to the first 5,000 records in the database through six different web pages on the portal. The company indicated that nine people logged in during this period and were able to access the data of 14,170 individuals (a single record could relate to multiple people). 12. In both cases, the company was unable to list the data affected by the breaches. However, it was able to rule out access to attachments (e.g., identity documents or medical certificates) included in the PCRM. 13. Pursuant to Decision No. 2023-063C of 20 March 2023 issued by the Chair of the Commission, a delegation from the CNIL (French Data Protection Authority) conducted an on-site inspection of the INETUM group to verify compliance with the provisions of Law No. 78-17 of 6 January 1978, as amended, concerning information technology, data files and civil liberties (hereinafter "the Law of 6 January 1978, as amended" or "the Data Protection Act") and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter "the GDPR" or "the Regulation"). 14. This on-site inspection resulted in report no. 2023-063/1 dated May 24, 2023. 15. On June 14 and September 6 and 29, 2023, the company provided additional information requested by the delegation during the on-site inspection. 16. For the purpose of reviewing this information, the Chair of the Commission appointed Mr. Fabien TARISSAN as rapporteur on May 13, 2025, pursuant to Article 22 of the amended Law of January 6, 1978. 17. On June 17, 2025, following his review, the rapporteur served the company with a report in which he concluded that the company had breached Article 32 of the GDPR and recommended that the restricted panel impose an administrative fine. He also proposed that this decision be made public, but that it would no longer be possible to identify the company by name after a period of two years from its publication. 18. On July 29, 2025, the company submitted observations in response to the report. 19. On August 29, 2025, the rapporteur's response was notified to the company. 20. On October 10, 2025, the company submitted further observations in response. 21. By letter dated October 29, 2025, the rapporteur, pursuant to Article 40, III, of Decree No. 2019-536 of May 29, 2019, implementing the French Data Protection Act, informed the company that the investigation was closed. 22. By letter dated November 3, 2025, the company was informed that the case was on the agenda for the meeting of the restricted panel on November 27, 2025. 23. The rapporteur and the company presented oral submissions at the meeting of the restricted panel. II. Grounds for the Decision A. Respect for the Right to a Fair Trial 24. NEXPUBLICA FRANCE considers that the conditions under which the sanction proceedings against it were conducted violate Article 6 of the European Convention for the Protection of Human Rights and Fundamental Freedoms (ECHR) and Articles 41 and 47 of the Charter of Fundamental Rights of the European Union. 25. It argues, firstly, that its right not to participate in its own incrimination was violated insofar as it was compelled to produce the audit reports that largely form the basis for the characterization of the breach. Furthermore, it considers that the proceedings are flawed in that the CNIL did not itself conduct its own investigations to establish the materiality of the vulnerabilities identified in the aforementioned audit reports. Finally, the company argues that it was unable to mount an adequate defense, as the scope of the alleged offenses was too vague. 26. First, the restricted panel notes that the provisions of Article 19 of the French Data Protection Act authorize the data protection authority to "request all documents necessary for the performance of its duties." It also notes that, according to the settled case law of the European Court of Human Rights (ECtHR), the right against self-incrimination does not prohibit the use, in criminal proceedings, of data obtained from the accused through the use of coercive powers but which exist independently of the suspect's will, for example, documents collected pursuant to a warrant (Saunders v. United Kingdom [GC], § 68, O'Halloran and Francis v. United Kingdom [GC], § 47). 27. Accordingly, the restricted panel considers that the audit reports were transmitted in accordance with the provisions of Article 19 of the French Data Protection Act, in the same way as the other documents in the investigation, without prejudging any potential breaches, and therefore without the company contributing to its own incrimination. Pursuant to the case law of the European Court of Human Rights, these documents may be examined by the restricted panel when ruling on whether or not a breach has occurred and, if so, on the merits of imposing a sanction. 28. Secondly, the restricted panel notes that the probative value of the documents submitted to the proceedings cannot be called into question. Indeed, the audits in question were either commissioned directly by the company (automated code audit) or by the data controller (penetration tests). Thus, these are assessments that form an integral part of the company's internal documentation, which a supervisory authority can use to evaluate the company's compliance with its obligations. 29. In this regard, the restricted panel emphasizes that the audits in question do not constitute value judgments that the rapporteur simply adopted, but rather the result of objective analyses of the company's information system, carried out according to a precise and documented methodology. It also notes that the purpose of these audits was not to determine the company's compliance or non-compliance; this assessment was the responsibility of the restricted panel, based on the explanations provided by the rapporteur and the company, who were free to discuss the probative value of these documents. 30. The restricted panel notes more specifically that the assessment and analysis of these documents were carried out by the rapporteur, who linked, on the one hand, the risk posed by the processing to the data subjects and, on the other hand, the level of security implemented by the company in light of this risk. It observes that in his written submissions, the rapporteur did not simply reiterate the content of the audits but focused on analyzing the nature of the vulnerabilities identified, their severity, their persistence, and their potential risks to the personal data of the data subjects. The reports were also supplemented by all the documents submitted, by the direct observations made by the audit team, and by the company's statements recorded in minutes no. 2023-063/1 of May 24, 2023. 31. The company was able to discuss all of these elements within the framework of these adversarial proceedings. 32. Accordingly, the restricted panel considers that the complaint based on the lack of evidence of the alleged facts must be dismissed. 33. Finally, the restricted panel notes that it is clear from the case file that the scope of the breach alleged against the company by the rapporteur is established with sufficient precision, the latter having considered in his submissions that, in light of the state of the art and the characteristics of the processing, the overall level of security of personal data ensured by the company was insufficient with regard to Articles 5(1)(f) and 32 of the GDPR. 34. Finally, the restricted panel notes that the company was able to present its observations in its defense in both written submissions, as well as orally during the restricted panel hearing of November 27, 2025. Furthermore, at the company's request, the chair of the restricted panel granted it an additional ten days to submit an expert report in support of its second set of observations in defense. 35. Accordingly, the panel considers that the sanction report, supplemented by the rapporteur's response, enabled NEXPUBLICA FRANCE to understand the scope of the alleged breach and that the company was thus able to mount an adequate defense. 36. In light of all the foregoing, the restricted panel finds that the complaint based on the violation of the rights of the defense must be dismissed. B. On the liability of NEXPUBLICA FRANCE with regard to the processing in question 37. According to Article 4(8) of the GDPR, a data processor is "a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller." 38. The rapporteur considers that NEXPUBLICA FRANCE is a data processor for the MDPH (Departmental House for Persons with Disabilities) of the Nord department for the implementation of the PCRM (Personalized Care and Medical Response) system, and that it is therefore responsible for ensuring an adequate level of security for the solution it provides. 39. While the company does not dispute its status as a data processor, it nevertheless intends to limit the scope of its liability for the implementation of the PCRM. On the one hand, it considers that it has only limited autonomy vis-à-vis the controller, who defines the expected level of security for the PCRM. On the other hand, it believes that its responsibility in the deployment of the PCRM should be put into perspective. Indeed, it maintains that certain vulnerabilities are the responsibility of its hosting provider (...), and that, moreover, it cannot be held responsible for components that are part of technological building blocks that it did not design. Finally, the company questions the fact that it is being held solely responsible in the context of these proceedings, given that it is not the CNIL's usual practice to sanction only the subcontractor. 40. As a preliminary matter, the restricted panel reiterates that the decision to initiate sanction proceedings rests solely with the Chair of the Commission. This decision is based on the information gathered during the audit. 1) Regarding NEXPUBLICA FRANCE's responsibility towards the data controller 41. Pursuant to Article 28(3)(a) of the GDPR, "processing by a processor shall be governed by a contract or other legal act [which] provides, in particular, that the processor shall process personal data only on documented instructions from the controller […]". 42. Article 32(1) of the GDPR provides: "Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risks, of varying likelihood and severity, to the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk […]". 43. Guidelines 07/2020 concerning the concepts of controller and processor in the GDPR, adopted by the EDPB on 7 July 2021, state that "the processor must process data only on the instructions of the controller. These instructions may, however, allow the processor some discretion as to how best to serve the interests of the controller, enabling the processor to choose the most appropriate technical and organizational means [...]" and that "the level of detail of the instructions given by the controller to the processor concerning the measures to be implemented will depend on the specific circumstances. [...] In other cases, it may describe the minimum security objectives to be achieved, while asking the processor to propose the implementation of specific security measures." 44. The restricted panel notes that, pursuant to Article 32 of the GDPR, the processor is required to ensure that the automated data processing carried out on behalf of the controller is sufficiently secure. The adequacy of the security measures is assessed, firstly, in light of the characteristics of the processing and the risks it entails and, secondly, taking into account the state of the art and the cost of the necessary security measures. 45. It considers that, independently of the obligations incumbent upon the data controller, it is the responsibility of the data processor to propose and implement appropriate technical and organizational solutions regarding the security of data processing. 46. In this case, given its expertise in developing IT solutions and its obligations, it was incumbent upon NEXPUBLICA FRANCE to identify technical and organizational measures to ensure the confidentiality of the personal data processed. 47. This is also evident from the Special Technical Specifications (CCTP), which govern the subcontracting relationship between the MDPH (Departmental House for Persons with Disabilities) of the Nord department and NEXPUBLICA FRANCE. The company is responsible for hosting, operational maintenance, software development, and technical support for the PCRM solution. The Technical Specifications (CCTP) define a number of obligations incumbent upon NEXPUBLICA FRANCE to ensure the proper functioning of the software (for example, by defining functional and technical specifications, conducting integration tests, or more generally by providing publisher maintenance services). 48. The training notes that, as the data controller, the MDPH retains control over the purposes of implementing the processing, for example, by defining its needs or by validating quotes related to the PCRM. However, it is clear from the CCTP that NEXPUBLICA FRANCE has significant leeway to ensure the security of the PCRM. For example, it specifies that NEXPUBLICA FRANCE is bound "by an obligation to advise, warn, and make recommendations in terms of security and compliance with best practices," as well as to implement "the measures necessary to comply with the declared processing activities. In particular, [it] ensures the security of personal data that may be entrusted to it by the Nord Department." 49. Thus, the restricted panel considers that, without prejudice to the controller's own responsibility, NEXPUBLICA FRANCE is responsible for ensuring the security of the personal data processed in the PCRM. 2) Regarding NEXPUBLICA FRANCE's responsibility towards its subsequent processors 50. Pursuant to Article 28(4) of the GDPR, "where a processor engages another processor to carry out specific processing activities on behalf of the controller [and] […] where that other processor fails to fulfill its data protection obligations, the initial processor remains fully responsible to the controller for the performance by the other processor of its obligations." 51. On the one hand, the restricted panel notes that NEXPUBLICA FRANCE subcontracts the hosting of the PCRM to its subsequent processor (…). 52. While Article 28(2) of the GDPR stipulates that "processing by a processor shall be governed by a contract or other legal act [which] provides, in particular, that the processor shall process personal data only on documented instructions from the controller […]", the restricted panel observes that the Technical Specifications indicate that the controller authorized NEXPUBLICA FRANCE to engage a subsequent processor. 53. It also appears from the subcontracting agreement concluded between (…) and NEXPUBLICA FRANCE that the company (…) is solely responsible for hosting the data, providing virtual machines, and ensuring compliance with authentication procedures, and that NEXPUBLICA FRANCE provides (…) with the "instructions and guidelines necessary for the performance of the services". The company (…) undertakes to process data only on the basis of and in accordance with the documented instructions of the client and the contracting authority [INETUM SOFTWARE FRANCE]. 54. While the EDPB, in its Opinion 22/2024 concerning certain obligations arising from the use of one or more sub-processors or subsequent sub-processors, specifies that the final decision to engage a subsequent sub-processor and the resulting responsibility, including with regard to verifying the adequacy of the safeguards provided by the subsequent sub-processor, rests with the controller, the restricted panel notes that the EDPB also indicates that "the initial sub-processor should ensure that it proposes subsequent sub-processors providing sufficient safeguards. […] This is also consistent with the fact that, regardless of the criteria suggested by the controller for selecting additional sub-processors, the initial sub-processor remains fully responsible to the controller for the performance of the obligations of subsequent sub-processors (Article 28(4) of the GDPR)." 55. As the company indicates, the subcontractor's liability to the supervisory authority is not automatic for the actions of subsequent subcontractors. However, in this case, the restricted panel considers that NEXPUBLICA FRANCE remains primarily responsible for ensuring its subsequent subcontractor complies with the rules regarding the protection of personal data, without prejudice to the specific liability of the MDPH (Departmental House for Disabled Persons) of the Nord department. The restricted panel also notes that it appears from the case file that NEXPUBLICA FRANCE was, in any event, aware of potential security vulnerabilities resulting from the measures—or lack thereof—implemented by the company (…). 56. Furthermore, the restricted panel observes that while the company did not develop the PCRM application in its entirety and, in particular, integrated a technological component (…) developed by the company (…), this choice did not result from an express request by the data controller. Indeed, it appears from the case file that while the MDPH (Departmental House for Disabled Persons) of the Nord department specifies the use of certain software in the technical specifications, this is not the case for the software component developed by the company (…). 57. The restricted panel thus notes that the use of (…) stems from a technical choice made by NEXPUBLICA FRANCE and that, as such, it is incumbent upon the company to ensure that this software component is free of vulnerabilities, with regard to the purposes, means, and risks for the processing in question. 58. In light of the aforementioned elements, NEXPUBLICA FRANCE cannot, in this case, limit its own liability towards third parties. C. On the failure to comply with the obligation to ensure the security of processed personal data 59. Article 32(1) of the GDPR provides: "Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risks, of varying likelihood and severity, to the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia, as appropriate: (a) the pseudonymisation and encryption of personal data; (b) means to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) means to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident; (d) a procedure for regularly testing, analyse and assessing the effectiveness of the technical measures and organizational measures to ensure the security of the processing […]”. 60. Article 32(2) of the GDPR provides: “When assessing the appropriate level of security, particular account shall be taken of the risks presented by the processing, in particular those arising from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.” 61. The rapporteur considers that the level of security ensured by a controller or processor must be assessed in light of the risk related to the disclosure of and unauthorized access to the data contained in the PCRM. In this case, he emphasizes that the processing involves a large amount of personal data, including special categories as defined in Article 9(1) of the GDPR. It considers that the company breached Article 32 of the GDPR by failing to ensure a sufficiently high level of security for the data processed for the PCRM (Personalized Care and Medical Rehabilitation) program, within the framework of its subcontracting activities for the MDPH (Departmental House for Disabled Persons) of the Nord department. 62. In its defense, NEXPUBLICA FRANCE argues that the rapporteur merely outlined the sensitivity of the processed data and the risks to the data subjects in order to conclude that the security measures implemented were inadequate, without demonstrating how it failed to meet the obligations—of means, not of result—stipulated by Article 32 of the GDPR, nor indicating what measures it should have implemented. 63. While acknowledging "the theoretical existence of a cybersecurity risk," it maintains that neither the mere fact that a vulnerability could theoretically be exploited, nor the occurrence of a security incident, is sufficient to constitute a breach of the GDPR. She adds that the data breaches were not caused by a structural failure of the PCRM but by isolated operational errors in the software, unrelated to the vulnerabilities. In support of her statements, the company provides an external assessment conducted by an expert in IT and IT law, demonstrating that she allocated significant material and human resources to the development and maintenance of the PCRM, in accordance with best practices. Finally, she disputes the vulnerabilities identified by the rapporteur, arguing that he fails to consider all the technical measures implemented for the PCRM, and that in any event, they were promptly corrected. 64. As a preliminary matter, the restricted panel reiterates that the security obligation stipulated in Article 32 of the GDPR is an obligation of means. Therefore, not every security defect necessarily constitutes a breach of this provision. Compliance with the obligation of means by a data controller or processor is assessed based on the appropriateness of the technical and organizational measures implemented, taking into account the risks and evaluating whether the nature, content, and implementation of these measures are commensurate with those risks. 65. This analysis was confirmed by the CJEU in its judgment in "Natsionalna agentsia za prihodite" (14 December 2023, C/2024/1065, paragraph 47), which reiterates that the absence of a personal data breach is not sufficient to demonstrate the absence of a breach, just as the occurrence of a data breach is not in itself sufficient to establish the existence of a breach of Article 32 of the GDPR. Security flaws can be sanctioned as such due to the risk they posed to the integrity of the data processed. The restricted panel regularly sanctions breaches of security obligations, even if these breaches do not necessarily lead to a data breach. Examples include an insufficiently robust password policy (Restricted Panel Decision No. SAN-2018-009 of September 6, 2018, published), the storage of passwords in plain text (Restricted Panel Decision No. SAN-2022-018 of September 8, 2022), the absence of an authorization policy (Restricted Panel Decision No. SAN-2021-019 of October 29, 2021, published), and the use of an outdated version of the TLS protocol (Restricted Panel Chairman's Decision No. SANPS-2024-011 of January 31, 2024, unpublished). 66. Similarly, a failure to ensure the security of processed data can be characterized by the widespread weakness of an information system, which has already been sanctioned in the past (Restricted Panel Decision No. SAN-2023-022 of December 29, 2023, unpublished). 67. On this point, the Restricted Panel notes that ANSSI applies the principle of "defense in depth" to information systems, which consists of not basing security "on a single element but on a coherent whole. This means that, in theory, there should be no single point on which the entire structure rests," that is to say, any potential security vulnerability in a software component must be compensated by at least a second level of security (see the Handbook on the concept of defense in depth applied to information systems, version 1.1 of July 19, 2004). The restricted panel notes that ANSSI bases this concept on the premise that "any component of a system can fail or be compromised. This premise, which also applies to the security functions of an IS [information system], is regularly confirmed by current events concerning the vulnerabilities of numerous products and software" (see the white paper "Hybrid Information System and Security: A Return to Reality," August 10, 2021). 68. In this case, the restricted panel notes that the PCRM contains a large amount of personal data, including identity data, health data, data relating to disability, the social security number (NIR), as well as data revealing information about the financial situation, personal and professional life, family life, daily life, school life, and professional life of the individuals concerned. The compromise of this data can have serious consequences for individuals (identity theft, phishing attempts, falsification of medical documents, blackmail or bogus distress messages, risk of discrimination, etc.). The restricted panel also emphasizes that the accumulation of this data, which can be aggregated and combined, provides extremely precise information on many aspects of the lives of the individuals concerned (for example, on the institutions attended and the exact type of support the individual receives, their level of independence, the adaptations and level of assistance they receive for their daily life, etc.). (i) Regarding the findings of the audits carried out by the solution (…) on the PCRM application 69. The rapporteur considers that the various code audits (…) carried out on the PCRM reveal numerous critical and significant vulnerabilities. 70. In its defense, NEXPUBLICA FRANCE intends to limit the scope of these audits, as they result from automated code analyses that can generate false positives due to the lack of technical context. It emphasizes that several identified vulnerabilities were in fact not exploitable. Finally, it adds that it quickly corrected the flaws identified by the two 2021 audits, independently of any intervention by the CNIL (French Data Protection Authority), as evidenced by the results of the 2023 and 2024 audits. 71. The restricted panel observes that the reports (…) are automated code audits (which perform an initial analysis of the source code to detect potential security vulnerabilities and known programming errors) that require interpretation to ensure their reliability, particularly to eliminate "false positives," that is, when the analysis tool incorrectly reports that a security rule has been violated. It nevertheless believes that these audits provide an initial analysis of the code's robustness and the presence or absence of known vulnerabilities. 72. The restricted panel notes in this regard that the first assessment on April 14, 2021, listed 199 vulnerabilities, including 14 "critical" and 129 "high" vulnerabilities; the second assessment on October 14, 2021, listed 103 vulnerabilities, including 34 "critical" and 65 "high" vulnerabilities. The restricted panel notes, on the one hand, the increase in the number of "critical" vulnerabilities and, on the other hand, the persistence of numerous vulnerabilities between the two audits, which took place six months apart. It considers that when critical vulnerabilities are identified, whether confirmed or even potential, it is the responsibility of the entity in charge of security to take swift action to prevent them from being exploited by an attacker. 73. It also notes the presence of 14 vulnerabilities in the first audit and 18 in the second, which are among the top 10 most critical risk categories for web application security listed by OWASP (Open Worldwide Application Security Project, an online community working on web application security and publishing recommendations in this area). ANSSI recommends that open-source software be compliant with OWASP recommendations. 74. Among the numerous vulnerabilities identified, the restricted panel notes that several can compromise the confidentiality or integrity of the data processed (for example, (...). 75. For example, the vulnerability (...). 76. As with other vulnerabilities, the company does not dispute its existence but maintains that it does not pose a risk in practice because other factors prevent its exploitation (in this case, it states (...). However, the restricted panel notes that (…). An individual aware of the vulnerability could therefore exploit it, and for example delete messages between a user and the administrator (…). This precisely demonstrates the need for a "defense in depth" and for not relying on the security of a single component for the entire PCRM software, as this component could be bypassed. 77. Furthermore, the restricted panel notes that the rapporteur identified other vulnerabilities during the audits that posed a critical risk to the confidentiality of data processed in the PCRM, such as (…). The restricted panel notes that while the company indicated that it had corrected these vulnerabilities, it did not dispute their existence or their criticality. 78. The restricted panel emphasizes that it was only following the data breaches in 2022 that the company gradually mobilized its resources to eliminate almost all of the vulnerabilities affecting the PCRM. However, the persistence of so many critical vulnerabilities over several months (at least from the first report (…) in April 2021, and until the data breach at the end of 2022) highlights the company's lack of attention to securing the data it processes on behalf of the data controller. 79. The restricted panel notes that the report (…) of February 14, 2023, listed only three vulnerabilities, none of which were critical or significant, and that the report of December 12, 2024, listed no vulnerabilities at all – reflecting the corrective actions taken by NEXPUBLICA FRANCE following the data breaches. (ii) Regarding the findings of the company's audits (…) 80. The rapporteur considers that the insufficient security level of the PCRM is also evident from the two audits carried out by the company (…), which revealed numerous vulnerabilities. 81. The company does not dispute the vulnerabilities highlighted by the two audit reports (…). It nevertheless emphasizes that it corrected them promptly and regrets that the rapporteur did not take into account the ongoing correction and improvement process of the PCRM – as evidenced, for example, by the decrease in the relative vulnerability's criticality (…). 82. The restricted panel notes firstly that it was the data controller who commissioned the company (…) to conduct audits to assess the security level of the PCRM application following the data breaches. It further notes that the first report, dated December 2022, highlighted "an average level of security" with significant vulnerabilities, including a "critical" flaw allowing a user, in the absence of access control to resources, to read documents not belonging to them. 83. The company states that the vulnerability was due to human error and that it was still present in the penetration test (…) of December 2022, because the patches deployed immediately after the November 2022 security incident only took effect in January 2023. 84. The restricted panel notes that the second audit report of March 2023 revealed that certain vulnerabilities identified in the December 2022 report had not been remedied. For example, the restricted panel notes a vulnerability related to (…). 85. The two vulnerabilities mentioned above, which are only examples among others of the critical vulnerabilities affecting the PCRM, demonstrate that NEXPUBLICA FRANCE has not implemented the necessary conditions to guarantee the confidentiality and integrity of the PCRM data, given its characteristics as outlined in paragraph 68. 86. NEXPUBLICA FRANCE indicates that it has since corrected the vulnerabilities identified in the reports (...), which the restricted panel acknowledges. (iii) Regarding the encryption of PCRM data 87. The rapporteur believes that the company is not using state-of-the-art technologies for encrypting PCRM data. 88. The company did not respond to this point. 89. The restricted panel notes that ANSSI indicated in its CERTFR-2017-ACT-013 bulletin of March 27, 2017, that "the use of cryptographic signature mechanisms based on SHA-1 is now subject to an immediately exploitable vulnerability and must be abandoned [...]." Data controllers using the SHA-1 function have already been sanctioned by the CNIL, as this technology is no longer considered state-of-the-art (see restricted panel decision no. SAN-2023-023 of December 29, 2023, published). 90. The restricted panel reiterates that state-of-the-art hashing guarantees data integrity by associating a message, file, or directory with a unique fingerprint that can be calculated and verified by all. It reiterates the importance, for software such as the PCRM, of detecting whether a message or information has been modified. Indeed, this is a platform for exchanging information with the administration, enabling the submission and tracking of applications for social benefits for people with disabilities. 91. The restricted panel therefore considers that by using the SHA-1 function for certain cryptographic suites of the TLS 1.2 protocol, within the framework of (…) and given that this function has known vulnerabilities since 2017, NEXPUBLICA FRANCE is not using state-of-the-art technologies and is failing to meet its obligation under Article 32 of the GDPR to guarantee data integrity. (iv) Regarding other measures implemented by the company 92. The company highlights other measures taken for the PCRM to demonstrate the level of security and maturity of the software. In this regard, it indicates, for example, that it implemented multi-factor authentication from the outset of the PCRM, well before the CNIL issued a recommendation on this subject. Furthermore, it indicates that since February 2023, it has implemented a supplementary logging system, allowing for the time-stamped recording of each user action. 93. The restricted panel acknowledges the implementation of the supplementary logging measures to allow for greater granularity in monitoring PCRM activities. However, as the rapporteur notes, it observes that the company's inability to specify which data was breached highlights inefficient traceability of actions performed on the PCRM. The restricted panel reiterates in this regard that it is recommended to implement "active" traceability, that is, to formalize a process for generating and processing alerts in the event of suspected abnormal behavior (see in this respect deliberation no. 2021-122 of October 14, 2021, adopting a recommendation on logging). 94. Furthermore, the restricted panel emphasizes that the rapporteur did not criticize the company for not having implemented multi-factor authentication, and that in any event, this is a basic security measure that must be implemented, particularly for processing involving sensitive data, as is the case with PCRM. 95. In conclusion, the restricted panel considers that the lack of coordinated lines of defense, the multiplicity of known vulnerabilities, and their failure to be quickly corrected demonstrate that the measures implemented by NEXPUBLICA FRANCE were insufficient to ensure the security of the data processed in the PCRM. 96. The restricted panel considers that the expert report submitted by the company in support of its second set of observations in defense does not call into question this conclusion regarding the insufficient level of security of the PCRM. The restricted panel notes that the analysis details the software development stages and explains that software is by nature "a living and evolving product, susceptible to anomalies, which must be corrected as part of maintenance." It concludes that it was such anomalies, during a PCRM update, that led to the data breaches, and not a weakness in the design of that version of the software. 97. The restricted panel does not dispute that the PCRM (Data Processing and Maintenance Management System) followed these various production deployment stages, nor that the software lifecycle may require patches and, in any case, ongoing maintenance. However, while the expert report focuses on demonstrating that the security incidents were linked to isolated errors during a software upgrade, the restricted panel reiterates that it is not the data breaches themselves that constitute the breach, but rather the widespread weakness of the PCRM's security measures. The submitted expert report does not address the vulnerabilities identified by the rapporteur. 98. Yet it is precisely the obvious nature of the identified flaws, relating to vulnerabilities documented by best practices and industry standards, as well as their persistence, that demonstrate that NEXPUBLICA FRANCE failed to fulfill its obligation to take the necessary steps to ensure the security of the processed data, and that constitute a breach of Article 32 of the GDPR. The restricted panel considers that the investigation revealed that NEXPUBLICA FRANCE allowed structural problems in its PCRM to persist, leading to an overall low level of security and the absence of a defense-in-depth system. 99. The restricted panel adds that the company's specialization in IT systems and software consulting renders its arguments ineffective, namely that the PCRM was in the initial production phase and that it therefore necessarily had limited knowledge to guarantee the software's compliance. Indeed, while the production deployment of software can be accompanied by malfunctions and requires regular patches and updates—which are, moreover, good practices—a company specializing in developing IT solutions cannot claim a lack of knowledge when one of its products reveals blatant vulnerabilities that it allowed to persist for several months. 100. The restricted panel notes that the company implemented patches following the data breaches. However, it reiterates that the company is not being criticized for its lack of response to the security incidents, but rather for putting the PCRM into production with such vulnerabilities, and then for failing to quickly correct them after they were identified in the various audit reports. 101. In light of all these elements, the restricted panel considers that the company did not implement sufficient measures to guarantee an appropriate level of security for the personal data contained in the PCRM. 102. While the restricted panel notes that corrective measures have been implemented following the reported data breaches, as evidenced in particular by the most recent audit reports, it nevertheless considers that the company failed to meet its obligations under Article 32 of the GDPR and that this breach is established retroactively. III. On corrective measures 103. Article 20-IV of Law No. 78-17 of 6 January 1978, as amended, provides that: "when the data controller or its processor fails to comply with the obligations arising from Regulation (EU) 2016/679 of 27 April 2016 or from this Law, the President of the National Commission for Information Technology and Civil Liberties may […] refer the matter to the restricted panel of the Commission for the issuance, after adversarial proceedings, of one or more of the following measures: […] 104. 7° Except where the processing is carried out by the State, an administrative fine not exceeding €10 million or, in the case of an undertaking, 2% of its total worldwide annual turnover for the preceding financial year, whichever is higher. In the cases referred to in points 5 and 6 of Article 83 of Regulation (EU) 2016/679 of 27 April 2016, these ceilings are raised to €20 million and 4% of turnover, respectively. The restricted panel takes into account, in determining the amount of the fine, the criteria specified in Article 83. 105. Article 83 of the GDPR, as referred to in Article 20(4) of the French Data Protection Act, provides that: "Each supervisory authority shall ensure that administrative fines imposed pursuant to this Article for infringements of this Regulation referred to in paragraphs 4, 5 and 6 are, in each case, effective, proportionate and dissuasive," before specifying the factors to be taken into account in deciding whether to impose an administrative fine and in determining its amount. 106. The CJEU has reiterated in this regard that "only an administrative fine whose amount is determined based on the actual economic or material capacity of its recipient […] is capable of meeting the three conditions set out in Article 83(1) of the GDPR, namely that it be effective, proportionate and dissuasive" (CJEU, Grand Chamber, 5 December 2023, C-807/21, "Deutsche Wohnen"; CJEU, Fifth Chamber, 13 February 2025, C-383/23, "Ilva A/S"). 107. Article 22(2) of the French Data Protection Act further provides that "the restricted panel may make public the measures it takes." A. On the imposition of an administrative fine and its amount 108. The restricted panel recalls that the relevant criteria of Article 83 of the GDPR must be examined to determine whether an administrative fine should be imposed on the company and, if so, to determine its amount. 1. On the imposition of the fine 109. The rapporteur proposes that the restricted panel impose an administrative fine on the company in view of the breach of Article 32 of the GDPR. 110. In its defense, the company argues that the administrative fine proposed by the rapporteur is manifestly disproportionate in light of the criteria of Article 83 of the GDPR and that a formal warning would be a more appropriate corrective measure. The company argues, firstly, that the identified breach is not serious, particularly because the PCRM (Personalized Contact Risk Management) system is deployed with only two clients, the vulnerabilities were limited in time, and the rapporteur overestimates the number of individuals and the sensitivity of the data affected by the breaches. The absence of harm is demonstrated, in particular, by the fact that no complaints from data subjects have been registered. Furthermore, the company denies any negligence, emphasizing that it has never been sanctioned by the restricted panel before. Its good faith is demonstrated, according to the company, by its full cooperation with the CNIL (French Data Protection Authority) and by the speed with which it implemented the necessary corrective measures. Finally, the company asks the restricted panel to take into account its limited autonomy in implementing the processing, both with respect to the data controller, the MDPH (Departmental House for Disabled Persons), and the subsequent data processor, the company (…). 111. As a preliminary matter, the restricted panel recalls that, in assessing the appropriateness of imposing a fine, it must take into account the criteria specified in Article 83 of the GDPR, such as the nature, seriousness, and duration of the infringement, the scope or purpose of the processing concerned, the number of data subjects, the measures taken by the controller to mitigate the damage suffered by the data subjects, whether the infringement was committed negligently, the degree of cooperation with the supervisory authority, the categories of data concerned, and the level of damage suffered by the data subjects. 112. Firstly, the restricted panel considers that the criterion laid down in Article 83(2)(a) of the GDPR relating to the nature, seriousness, and duration of the infringement should be applied, taking into account the nature, scope, or purpose of the processing concerned, as well as the number of data subjects. 113. The restricted panel considers the identified breach to be serious and that the failure to comply with best practices and basic security principles posed a risk to the security of the personal data of the individuals concerned. Adding to the seriousness of the breach is the fact that the processing primarily concerns vulnerable individuals as defined by the Guidelines on Data Protection Impact Assessment (DPIA) and the method for determining whether the processing is "likely to result in a high risk" for the purposes of Regulation (EU) 2016/679. This vulnerability is reflected, among other things, in the blatant imbalance between society and the individuals concerned, who have no choice but to have their data processed by the PCRM if they wish to benefit from certain services. 114. The restricted panel further notes that the PCRM had (…) user accounts in May 2023 and the MDPH (Departmental House for Persons with Disabilities) of the Nord department processes approximately (…) active cases per year. Furthermore, the company indicated that the breaches potentially affected two individuals in the first instance and 14,170 in the second, representing approximately (…)% of users and an approximate number of (…) records. 115. The fact that no third-party intrusion into the PCRM was detected, and that the data was only made accessible in read-only mode, does not mitigate the seriousness of the breach. Indeed, the fact remains that the data was made accessible to unauthorized third parties, and displayed data, even in read-only mode, can still be copied. 116. Secondly, the restricted panel considers that the criterion set out in Article 83(2)(b) of the GDPR, relating to whether the breach was committed intentionally or negligently, should be taken into account. 117. The restricted panel considers that the breach resulted from negligence on the part of NEXPUBLICA FRANCE, which failed to take into account best practices in implementing technical and organizational measures for the PCRM – especially given that IT systems and software consulting is its core business. It was only after the data breaches occurred in October 2022, and following the intervention of the data controller who conducted penetration tests, that the company addressed some of the identified vulnerabilities – even though audits carried out by the company had already highlighted critical vulnerabilities in 2021. As indicated in Section II.C of this decision, and contrary to the company's claims, it did not provide evidence of having corrected all the vulnerabilities as soon as they were brought to its attention and before the CNIL's audit. 118. Third, the restricted panel considers that, pursuant to Article 83(2)(d) of the GDPR, the degree of responsibility of the data processor must be taken into account, given the technical and organizational measures it has implemented under Articles 25 and 32 of the GDPR. 119. However, as demonstrated in point II.B., the restricted panel considers that NEXPUBLICA FRANCE cannot be relieved of its responsibility to implement appropriate technical and organizational measures for the PCRM. 120. Fourth, the restricted panel intends to take into account the categories of personal data concerned by the breach, pursuant to Article 83(2)(g) of the GDPR. 121. The restricted panel notes that the processing in question involves health data, and in particular data relating to disability, which are special categories of data within the meaning of Article 9 of the GDPR, known as "sensitive" data. The restricted panel emphasizes that although no medical documents have been reported to have been compromised, the security vulnerabilities nonetheless posed a significant risk to the confidentiality of this "sensitive" data. 122. Furthermore, the data that was indeed compromised, relating to descriptions of services linked to user files, provides considerable information about the identity and personal circumstances of the individuals concerned, including data on minors. The restricted panel adds that the mere fact of being included in the processing and receiving benefits allows for the inference that the individual has a disability. 123. Finally, it is also the aggregation of all the processed data that makes it possible to provide precise and comprehensive information on almost all aspects of the private lives of the individuals concerned and their relatives. 124. In light of all these elements, the restricted panel considers that the imposition of a fine appears justified. 2. On the amount of the fine 125. In its defense, the company argues that the amount of the fine proposed by the rapporteur is disproportionate to its turnover, recent decisions of the restricted panel, and (…). Furthermore, and by analogy with the rules of competition law, it believes that the proportion of turnover related to PCRM within its overall turnover should be taken into account in determining the amount of the fine, instead of its overall turnover. 126. The restricted panel first recalls that Article 83 of the GDPR, for the purpose of determining the amount of the fine, refers to a fixed amount (up to €10,000,000) or, in the case of an undertaking, to a percentage of annual turnover (up to 2%), whichever is higher. It reiterates that administrative fines must be dissuasive and proportionate. 127. Regarding the comparison with fines imposed in other proceedings, the company cannot usefully compare its situation with those of other companies that have been penalized for allegedly similar breaches, since the amount of a fine must be determined on a case-by-case basis. In this respect, the Council of State held that "the fact that fines of a lower amount, in proportion to their global turnover, may have been imposed by the CNIL's restricted panel against other companies has no bearing on the proportionality of the sanction imposed on the applicant company" (French Council of State, 10th and 9th Chambers sitting together, May 14, 2024, VOODOO company, No. 472221). 128. Furthermore, the restricted panel reiterates that while factors such as the company's profits and losses, or the turnover specifically generated by the PCRM, may be taken into account when assessing the criteria of Article 83 of the GDPR, they cannot replace the company's turnover, which remains the sole factor in determining the maximum applicable fine. The CJEU held that "only an administrative fine whose amount is determined based on the actual economic or material capacity of its recipient […] is likely to meet the three conditions set out in Article 83(1) of the GDPR, namely that it be effective, proportionate and dissuasive" (see "Deutsche Wohnen" and "Ilva A/S" cited above). Thus, the restricted panel considers that the applicable law does not require it to limit itself to the turnover of the product in question – in this case, the PCRM – to determine the maximum amount of the fine incurred. 129. Finally, the restricted panel considers that (…) – in this case, non-public correspondence exchanged with third parties in the context of instructions – cannot be usefully invoked. Indeed, the restricted panel only takes into account, in determining the amount of the fine, the breach found in connection with the PCRM in these proceedings. 130. In light of the foregoing, the restricted panel considers that the company's turnover should be taken into account. It notes that in 2024, NEXPUBLICA FRANCE generated a turnover of (…) euros, with a net profit of (…) euros. 131. Therefore, in view of NEXPUBLICA FRANCE's responsibility, its financial capacity, and the relevant criteria of Article 83(2) of the GDPR mentioned above, the restricted panel considers that an administrative fine of one million seven hundred thousand euros (€1,700,000), in light of the breach of Article 32 of the GDPR, appears justified. B. On the publication of the penalty 132. The company contests the rapporteur's proposal to make this decision public, considering this measure unnecessary given that the breaches have now been rectified. It believes that (...). Publicizing the decision would cause serious and immediate damage to its image, especially since it has just achieved legal and organizational autonomy. 133. The restricted panel considers that (...). Furthermore, although the company has changed its corporate name, the restricted panel notes that it continues to publish and host the PCRM (Personalized Care and Resource Management) for the MDPH (Departmental House for Disabled Persons) of the Nord department, in line with the activities of INETUM SOFTWARE FRANCE. Therefore, publication is justified given the proven seriousness of the breach, the sensitivity of the data processing, the negligence demonstrated by the company, and the number of individuals concerned, who must be informed. 134. It considers this measure proportionate since the decision will no longer identify the company by name after a period of two years from its publication. FOR THESE REASONS The restricted panel of the CNIL (French Data Protection Authority), after deliberation, decides: - to impose on the company NEXPUBLICA FRANCE an administrative fine of one million seven hundred thousand euros (€1,700,000) for breach of Article 32 of the GDPR; - to publish its decision on the CNIL website and on the Légifrance website, which will no longer identify the company by name after a period of two years from its publication. The President Philippe-Pierre CABOURDIN This decision may be appealed to the Council of State within two months of its notification.




