Personal data: regulation alone is no longer enough
Personal Data: Regulation Is No Longer Enough. By prioritizing penalties over support, the CNIL is inadvertently creating a competitive advantage for those who are not accountable to it

Although independent, administrative authorities are nonetheless bound by a duty of transparency. Published in February, the CNIL’s annual report flew under the radar amid a news cycle dominated by international affairs and municipal elections. An institution of which France can be proud, respected across Europe, and embodying a certain vision of civil liberties, the CNIL cannot rely solely on punishment. As the true guardian of digital data, the authority boasts that “the cumulative amount of fines totals 486,839,500 euros,” a record. This figure is primarily due to two fines imposed on Google and Shein, which were ordered to pay 325 million euros and 150 million euros, respectively—accounting for 97.5% of the total—for failing to comply with cookie regulations. These ephemeral cookies, which track our web browsing, provide free access to the Internet and ensure media diversity.
In these times of budgetary constraints and political challenges to administrative authorities—particularly from the National Rally—one year ahead of the presidential election, demonstrating a significant contribution to the state coffers can only be beneficial. The sum is staggering, at the risk of obscuring blind spots.
83 sanctions were imposed for violations of cookie regulations, including failure to obtain user consent, insufficient information, as well as non-compliance with rules governing employee video surveillance and breaches of subcontractors’ obligations.
Zeal. Consequently, the desire to make a dramatic impact no longer allows for a balanced regulatory policy. Reading the report, one gets the impression that the authority is cracking down on cookies with the zeal of a prosecutor. In contrast, massive breaches of public data seem to be treated as mere administrative formalities. Inevitably, an imbalance to the detriment of citizens is created.
“There’s a lot of bluffing when it comes to data theft,” said Vincent Strubel, director general of the National Cybersecurity Agency (ANSSI), the national authority on cybersecurity, in Le Parisien on March 10, 2026. Massive data breaches, however, appear to be intensifying. With a 23% increase in one year, Anozr Way, in its annual study, estimates that “data leaks are reaching an unprecedented level.” Public organizations are particularly vulnerable and under attack. Thus, in 2025, the Ministries of the Interior and Sports, France Travail, and Pajemploi—the Urssaf service designed to simplify administrative formalities for parents who are employers—had millions of citizens’ personal data stolen. While criminal complaints were filed, both the CNIL and ANSSI received only a simple notification.
In the hands of fraudsters, a Social Security number becomes a weapon. It allows them to establish a relationship of trust with citizens in order to better deceive them, with the intention of creating fraudulent social benefits claims, for example.
While the URSSAF has urged its various stakeholders to remain vigilant, it is regrettable that an authority such as the CNIL is not organizing information and awareness campaigns for the general public, on whose behalf it acts. While two-factor authentication for databases containing over two million people is to be commended, the CNIL’s strengthened controls will not be enough unless they are accompanied by a commitment to supporting businesses and providing robust public education, explaining the real risks. The authority must also prioritize protection—not just punishment—among its prerogatives. Much like a police officer.
This article was originally published in French in l’Opinion
