CNIL 2025 Report, reading a regulator in transition
Data processors, AI, cross-regulation, misleading record figures: what the CNIL's 2025 annual report really says about regulation in 2026.

What the chair admits without quite writing it down
Marie-Laure Denis opens her annual report with a word that deserves to be taken seriously. A pivotal year. The term comes up twice within a few lines, which does not read like an offhand rhetorical flourish. The chair of the CNIL chooses her vocabulary with the caution of a former member of the Conseil d'Etat, and when she says pivotal, she is describing an institutional shift that she observes without entirely controlling.
The question is: pivotal between what and what. The report offers an answer in the negative, provided you read it as a transition document rather than an activity review. Several deep currents cross through it, none of them reducible to a headline, and that is precisely what makes the reading interesting.
What does the CNIL's 2025 annual report actually say?
The document was published on 18 May 2026. The figures it puts forward read fast, and that is the problem.
The authority received 20,150 complaints during the year, up 10%, of which around 1,900 were directly linked to data leaks. It carried out 323 inspections and issued 259 decisions, including 143 formal notices and 83 penalties, for a total of 486,839,500 euros in fines. The breach register recorded 6,167 retained notifications, an all-time record since its creation, up nearly 10% year on year. Around forty of these breaches potentially concerned more than one million people, ten more than the previous year, and they hit public and private bodies alike. One breach in two was the result of hacking.
That is the review as it circulates. Taken together, these figures tell the story of an authority scaling up. Taken one by one, they tell something else, and that is the reading I am proposing here.
Why does the CNIL wait five years before issuing fines?
The first shift concerns the regulator's use of time. In April 2025, the CNIL published its guidance on the security of large databases after a 2024 that had already broken every record for notified breaches. It stresses multi-factor authentication, access logging, user awareness, and the oversight of data processors. It then announces, plainly, that it has given players time to adapt and that inspections will be carried out throughout 2026, with the absence of a second factor on a large database enough on its own to justify opening penalty proceedings.
Read quickly, that sentence looks like an administrative platitude. Read slowly, it is a doctrinal admission. The regulator builds into its method the fact that organizations will not move on the mere publication of a recommendation. It no longer expects spontaneous compliance. It calibrates its pressure over time.
The report contains enough to confirm that this doctrine is sound. Five years pass between the cookie guidelines, adopted in 2020, and the combined September 2025 penalties against Google and Shein, totaling 475 million euros. Five years during which the rules were known, documented, illustrated, and largely ignored by players who could not seriously plead ignorance. The restricted committee notes as much explicitly in its reasoning.
80%of the large-scale breaches in 2024 relied on an account protected by nothing more than a passwordCNIL, review of the large-scale 2024 breachesClose to eighty percent of the large-scale breaches recorded in 2024 were made possible by the takeover of an account protected by a password alone, with no second factor. Multi-factor authentication has existed for twenty years, its operational cost has collapsed, and its rollout is documented right down to consumer manuals. And yet the 2025 register received 17,802 raw notifications, a large share of them exploiting the exact vector the CNIL has been warning against for ten years. Knowing the risk was never enough to force the trade-off.
The data processor, the report's blind spot
The second shift concerns data processors, and this is where reading the report becomes uncomfortable for an informed observer. Two software vendors are compromised during the year. One serves wealth-management advisers, the other independent healthcare professionals. Each of these two incidents generates, in a cascade, several thousand breach notifications from client firms that discover they are the data controllers of a system they no longer really controlled. In all, 11,635 notifications for these two events alone, out of 17,802 received. The CNIL has to strip these figures out of its annual report so that the general trend stays readable, and that is how you arrive at the published figure of 6,167.
The best documented case is that of the vendor Weda, whose teams detect abnormal activity on several user accounts on the night of 10 November 2025. More than 23,000 healthcare professionals are affected. Each of them, as data controller for their own patients' records, has to notify the CNIL within seventy-two hours, on their own behalf. One intrusion, one system, thousands of separate declarations. The GDPR notification mechanism, designed for an identifiable data controller, ends up documenting in series an incident that had only one entry point.
The chair states the finding with restraint. A significant share of incidents involves a data processor with failing security. The report adds that sector concentration makes the phenomenon worse, since a single vendor can serve hundreds or even thousands of organizations in the same sector.
The discomfort comes from the fact that this finding is not a discovery. ENISA, in its 2030 foresight exercise published in 2023, already ranked the compromise of the software supply chain as the leading emerging threat of the decade. The technical incident reports of 2020 and 2021, starting with SolarWinds, had made the mechanism visible to anyone following the subject. CISOs of large organizations had been discussing it in conferences for five years. The CNIL's 2025 report treats this risk as a phenomenon to be analyzed from now on, when it had been documented, modeled, and anticipated by the technical community for half a planning cycle. Five years behind the experts who had warned, translated into the figures of an annual report.
This time lag is not an individual failing of the institution. It is inherent to how a legal regulator operates, one that folds a risk into its doctrine only after it has materialized statistically in its own data flows. But it raises a practical question for data controllers. If the authority formalizes the risk only after five years of converging signals, a compliance audit based on the state of the law cannot be confused with a resilience audit based on the state of the threat. Organizations that settle for the first accumulate an operational debt whose cost they will pay during the incident, not during the inspection.
Why is the record 487 million euros in fines misleading?
The report announces total fines of 486,839,500 euros, against 55.2 million in 2024, a multiplication by 8.8 from one year to the next. The figure is featured in the key numbers, in communications, in the roundups picked up by the trade press. It is worth pausing on, because its structure tells a different story from the one it claims to tell.
97.5%of the 2025 fine total comes from two decisions handed down on the same dayCNIL, 2025 enforcement reviewOf these 486 million, 475 come from two decisions taken on 1 September 2025 and made public on the 3rd, against Google for 325 million and against Shein for 150 million. Both decisions bear on the same subject: non-compliance with cookie legislation. Take these two cases out and the total in fines handed down over the year drops to around 11 million euros, five times less than the previous year. The record is not a record of enforcement activity, it is a concentration effect on two targeted, long-investigated cases.
This does not call the legitimacy of the penalties into question. Google had already been penalized twice for comparable conduct, and Shein operated at a massive scale in full knowledge of the rules. The breach is documented and the penalty looks proportionate. But the gap between the media framing of the figure and the reality of enforcement practice deserves to be named.
Cookies are a second-tier subject in the hierarchy of risks. Non-consented advertising tracking harms privacy but it does not bring down a health system, does not leak the data of several million citizens, does not paralyze a public administration. The massive breaches that hit a telecoms operator, a sovereign ministry, a sports federation are of a completely different risk nature, and it is on these subjects that players' maturity remains weakest.
Yet on those very subjects, the volume of fines stays modest. Failing on security is not a marginal subject for the authority, since Article 32 of the GDPR already grounds around a third of its inspections and nearly 30% of its penalties. It is a poorly paid subject. The simplified procedure hands down penalties capped at 20,000 euros per decision. Serious security failures, which demand a lengthy investigation and a fine technical demonstration, rarely end with exemplary amounts. The CNIL has the means to hit hard on legally clear subjects such as cookies, and it struggles to hit hard on operationally complex ones such as the failure of a data processor or the mapping of an intrusion.
The result produces an incentive asymmetry that has to be faced head-on. A rational economic player who reads these 486 million and wonders where to place its compliance priority will tend to invest in its cookie banner and its consent management platform before investing in its multi-factor authentication, its data-processor audits, or its remote-access monitoring. It is not that the cookie banner is pointless, it is that resource allocation is decided by signal, and the signal sent by the record figures is misleading about the real hierarchy of risks.
An irony of timing: the legal pillar that produced 97.5% of this record is itself being rewritten. The Digital Omnibus package presented by the European Commission on 19 November 2025 proposes moving the rules on trackers up into the GDPR itself, through a new Article 88a, ending the current dependence on the ePrivacy directive. The basis of the record fines of 2025 will not necessarily be the basis of the fines of 2028.
Cross-regulation and AI: four jobs for one institution
The third shift is the one the chair names explicitly and that deserves to be taken at her word. She speaks of a new era, that of cross-regulation. The term is not neutral. It acknowledges that the CNIL is no longer the sole authority in its field, that it now shares its remit with the DGCCRF on the AI Act, with ARCEP on the DGA, with ARCOM on political advertising and the DSA, with the competition authority on cross-cutting digital-economy topics. This entanglement mechanically increases the coordination burden, which the chair concedes plainly: implementing these new missions involves greater consultation with many other regulators, through procedures that often remain to be built.
Procedures that remain to be built, in a context where the texts have already entered into force. That sentence is heavy. It says that the European legislator stacked up regulations faster than national authorities could organize how they fit together, and that regulated entities operate within a formal framework that is not yet workable in practice. The Helsinki summit of July 2025, where the EDPB adopts a statement aimed at simplifying GDPR compliance for small and medium-sized organizations, is in fact an admission of this tension. The complexity of European regulation has itself become a driver of non-compliance, and the authorities collectively acknowledge it.
Artificial intelligence is the clearest case, and the report devotes a great deal of space to it. The CNIL is given four distinct roles in AI regulation. These four roles are not an extension of its missions, they are four different jobs. The first is the one it has performed for ten years, protecting personal data inside algorithms. The second consists of checking that no banned AI systems are in use, which requires technical expertise on what constitutes a prohibited system. The third is an alerting function on fundamental rights, which moves the CNIL closer to a quasi-constitutional authority. The fourth is market surveillance over a large part of high-risk AI systems, in areas as sensitive as biometrics, employment, education, migration and law enforcement.
The legal vehicle has been identified: the digital section of the bill on various provisions adapting French law to European Union law, passed by the Senate on 17 February 2026, amends the Data Protection Act of 1978 to hand these powers to the CNIL. France has chosen a fragmented governance, with some fifteen sector authorities completing the setup depending on the system's field of application: the DGCCRF for consumer affairs, Arcom for audiovisual and digital, the ACPR for banking and insurance, the AMF for financial markets, the ANSM and the HAS for health. Strategic coordination falls to the DGE, operational coordination to the DGCCRF, pooled technical expertise to ANSSI and PEReN. Four jobs for the CNIL, fifteen authorities around the table, and consultation procedures that the chair herself describes as remaining to be built.
The chair acknowledges that the market-surveillance role puts the institution in an operating mode it does not yet master. She talks about the challenge of adapting the way it works to this new job and of taking ownership of the AI Act from an operational angle. In other words, the authority is building its doctrine as it goes.
It has more time ahead of it than it asked for. On 16 June 2026 the European Parliament adopted, by 423 votes, the omnibus simplifying the AI Act, definitively approved by the Council on 29 June. The obligations applying to the standalone high-risk systems of Annex III shift from 2 August 2026 to 2 December 2027, and those covering systems embedded in already regulated products under Annex I to 2 August 2028. Still due on 2 August 2026 are Article 50 on transparency and Article 4 on AI literacy, along with the inspection and penalty powers of national authorities. The CNIL's fourth job has just been pushed back by sixteen months, while the systems concerned carry on being deployed.
The survey run by the CNIL with the AFCDP and the Ministry of Labour, whose results were published on 3 July 2026, measures the gap on the regulated side. Seventy percent of organizations use or plan to use AI, 81% of them generative AI. Fifty-five percent of DPOs say the AI Act is already part of their responsibilities and 71% want that scope officially broadened. But 85% have received no AI-specific training, only 27% consider they know the text well, and fewer than a quarter of organizations have formalized an AI governance policy.
The figure does not only say that DPOs are working on AI. It says that the role designed in 2018 to embody GDPR compliance is shifting toward a multi-text orchestration it was never sized to carry. Many DPOs in post today lack the technical background to assess training pipelines, memorization issues, or architecture choices. They say so themselves, and they are asking for the mandate that goes with it. The CNIL does not put it in these terms, but its own figures reveal it.
More missions, same resources: what will the CNIL inspect in 2026?
There remains the question of resources, which structures everything else without always being in the foreground. In 2025 the CNIL has a budget of 30.2 million euros and 303 staff, with six new posts during the year and zero planned for 2026. At the same time, its remit expands in every direction under the DSA, the DGA, the SREN law, the political-advertising regulation, and the AI Act. The deputy secretary general acknowledges that this twin trend, at a time when the budget context does not allow a proportionate increase in headcount, forces the CNIL to prioritize its activity better. Prioritizing better, in administrative language, means giving up certain inspections, certain responses, certain forms of support.
This time we know what it is giving up, because it has published the opposite. The priority inspection themes for 2026 are recruitment, the single electoral register managed by INSEE, sports federations, and cybersecurity. That last one is not a theme among others: the CNIL says it will devote half of its inspections for the year to it, on the basis of Article 32 of the GDPR, articulated with the NIS2 directive for critical sectors.
It has to be recognized for what it means. The criticism I make above about the asymmetry of the signal, the authority made before me in its own trade-offs. The choice of recruitment also prefigures its future market-surveillance role in the employment domain under the AI Act, and the choice of sports federations answers directly to a series of attacks on a sector that processes health data and children's data in very large volumes. This is no longer an announced doctrine, it is a workload plan.
The context, for its part, is not easing. In the first quarter of 2026 alone, the CNIL had already recorded more than 2,730 breach notifications, against around 2,500 over the same period in 2025. Marie-Laure Denis notes that the development of artificial intelligence automates, industrializes and democratizes attacks while making it possible to personalize them by combining data. The conclusion the authority draws from its year fits in three words: no one is spared.
For the rest of the economic fabric, inspection remains statistically improbable. This does not mean the effort should slacken, but that the motivation to comply can no longer come solely from fear of the regulator. It has to take root in an understanding of operational resilience, which is another conversation, slower, harder to have with an executive committee.
Pivot
The CNIL's 2025 report is therefore not a homogeneous document. It layers an activity review, a diagnosis of institutional strain, and an implicit program of transformation. The chair speaks of a pivot. The word is apt, but you have to hear in pivot the dual dimension of a shift and of fragility. A hinge articulates, and it can also give way.
Several questions remain open after reading. How will the authority actually exercise its market-surveillance role without technical expertise sized for it, now that it has sixteen more months and not one more post. How will coordination between fifteen national authorities and twenty-seven European regulators stabilize without adding still more to the burden on regulated entities. How will the DPO evolve into a role that now demands cross-disciplinary competence 85% of them have never been trained to acquire. How will organizations fold the data-processor cascade into a risk map that, for most of them, did not see it even three years ago. And how do you explain to an executive committee that the cookie banner is not the main issue, when the authority itself seems to say the opposite through its record figures.
On that last point, 2026 will provide a measurable answer. If the half of inspections announced on cybersecurity produces public decisions and amounts that carry weight, the signal corrects itself and the trade-offs made by management change. If it produces discreet formal notices and penalties of 20,000 euros, the gap between the discourse and the incentive will remain, and the next annual report will show it as clearly as this one.
The 2025 report answers none of these questions. It raises them, more or less explicitly, and leaves the players to sort them out. That is probably the clearest indication of the regulator's real position in 2026. It has stopped pretending to know everything, and it has started asking regulated entities to do the same.
Sources
- CNIL, 18 May 2026, "Annual report: the CNIL's 2025 review and key actions" and the full report in PDF
- CNIL, "Penalties and corrective measures: the CNIL presents its 2025 review"
- CNIL, decision of 1 September 2025, "Cookies dropped without consent: the CNIL fines SHEIN 150 million euros"
- CNIL, April 2025, "The CNIL issues its guidance to strengthen the security of large databases"
- CNIL, "Large-scale data breaches in 2024: what are the main lessons and measures to take?" (share of accounts with no second factor)
- CNIL, "Inspections in 2026: recruitment, the single electoral register and sports federations"
- CNIL, 3 July 2026, "The DPO role in the age of artificial intelligence: survey results"
- Leto, "CNIL 2025 annual report: review, inspections and cybersecurity priorities for DPOs" (259 decisions, 143 formal notices, share of Article 32)
- Leto, "DPOs and artificial intelligence: results of the CNIL/AFCDP survey"
- Leto, "AI Act France: competent authorities (CNIL, DGCCRF, Arcom)"
- franceinfo, "No one is spared: the number of data breaches hit a record in 2025, the CNIL says" (first-quarter 2026 figures, quotes from Marie-Laure Denis)
- Next, "Weda: a cyberattack and a week of misery for 23,000 doctors"
- Studeria, "AI Act 2 August 2026: real obligations and timetable" (votes of 16 and 29 June 2026, postponements to 2 December 2027 and 2 August 2028)
- Seban & Associés, "Digital Omnibus package: state of play on the simplification of the European digital framework"
- Banque des Territoires, "The Senate signs off on a jigsaw approach to AI regulation" (digital DDADUE, 17 February 2026)
- ENISA, Foresight 2030 Threat Landscape, 2023
- EDPB, Helsinki summit statement, July 2025
Frequently asked questions
When was the CNIL's 2025 annual report published and what does it contain?
It was published on 18 May 2026. It records 20,150 complaints received in 2025 (up 10%), of which 1,900 were linked to data breaches, 6,167 notified breaches, 323 inspections and 259 decisions including 83 penalties and 143 formal notices, for a total of 486,839,500 euros in fines.
Why is the CNIL's record 2025 fine figure misleading?
Of the 486.8M euros announced, 475M come from two decisions taken on the same day, 1 September 2025, against Google (325M) and Shein (150M) over cookie legislation, or 97.5% of the total. Remove them and the year's total in fines drops to around 11M euros, five times less than the 55.2M of 2024.
What is the main blind spot identified in the report?
The failure of data processors. The CNIL received 17,802 notifications in 2025, of which 11,635 came from two compromised software vendors, one serving wealth-management advisers, the other independent healthcare professionals. The cyberattack on the vendor Weda, detected on the night of 10 November 2025, affected more than 23,000 practitioners, each of whom had to notify on their own behalf. The CNIL stripped these notifications out of its review to keep the trend readable, hence the published figure of 6,167.
What will the CNIL inspect in 2026?
Four priorities: recruitment, the single electoral register managed by INSEE, sports federations, and above all cybersecurity. The CNIL will devote half of its 2026 inspections to data security under Article 32 of the GDPR, a basis that already accounts for around a third of its inspections and nearly 30% of its penalties.
What is the cross-regulation the CNIL mentions?
It is the sharing of the CNIL's remit with other authorities (DGCCRF, ARCEP, ARCOM, the competition authority) on the new European texts. The chair concedes that the coordination procedures remain to be built even though the texts are already in force.
What new roles is the CNIL taking on regarding AI?
Four distinct jobs: protecting personal data inside algorithms, checking against banned AI uses, issuing alerts on fundamental rights, and market surveillance of high-risk systems (biometrics, employment, education, migration, law enforcement). The digital section of the DDADUE bill, passed by the Senate on 17 February 2026, amends the French Data Protection Act to hand it these powers, alongside some fifteen sector authorities.
Are the CNIL's resources keeping pace with its expanding remit?
No. In 2025 the CNIL has a budget of 30.2M euros and 303 staff, with zero new posts planned for 2026, while its remit expands under the DSA, the DGA, the SREN law and the AI Act. The authority must therefore prioritize better, which means giving things up.
Sources & methodology
- CNIL, Annual report: the CNIL's 2025 review and key actions, published 18 May 2026:
- CNIL, 2025 Annual Report (PDF):
- CNIL, Penalties and corrective measures: the CNIL presents its 2025 review:
- CNIL, Cookies dropped without consent: the CNIL fines SHEIN 150 million euros, decision of 1 September 2025:
- CNIL, The CNIL issues its guidance to strengthen the security of large databases, April 2025:
- CNIL, Large-scale data breaches in 2024: what are the main lessons and measures to take?:
- CNIL, Inspections in 2026: recruitment, the single electoral register and sports federations:
- CNIL, The DPO role in the age of artificial intelligence: survey results, 3 July 2026:
- Leto, CNIL 2025 annual report: review, inspections and cybersecurity priorities for DPOs:
- Leto, DPOs and artificial intelligence: results of the CNIL/AFCDP survey:
- Leto, AI Act France: competent authorities (CNIL, DGCCRF, Arcom):
- franceinfo, No one is spared: the number of data breaches hit a record in 2025, the CNIL says:
- Next, Weda: a cyberattack and a week of misery for 23,000 doctors:
- Studeria, AI Act 2 August 2026: real obligations and timetable, on the adoption of the AI omnibus:
- Seban & Associés, Digital Omnibus package: state of play on the simplification of the European digital framework:
- Banque des Territoires, The Senate signs off on a jigsaw approach to AI regulation:
- ENISA, Foresight 2030 Threat Landscape (2023)
- EDPB, Helsinki summit statement, July 2025

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
