Call us on +(33)4 28 70 91 81

GDPR: CNIL report on data breaches – July 2021

Introduction

In 2021-07, several personal data breaches were reported to the CNIL, affecting various sectors of activity. These incidents highlighted the vulnerability of personal data and the importance of adequate protection.

Sectors concerned

The sectors most affected by data breaches are:
– Specialized, scientific and technical activities: 481 times
– Human health and social action: 67 times
– Public administration: 39 times
– Financial and insurance activities: 34 times
– Other service activities: 26 times
– Information and communication: 21 times
– Trade; repair of automobiles and motorcycles: 21 times
– Manufacturing industry: 18 times
– Transportation and storage: 18 times
– Teaching: 16 times
– Construction: 13 times
– Administrative and support services activities: 12 times
– Real estate activities: 9 times
– Arts, entertainment and recreational activities: 5 times
– Accommodation and catering: 4 times
– Production and distribution of electricity, gas, steam and air conditioning: 4 times

Nature of violations

The types of violations encountered this month are:
– Loss of privacy: 425 times
– Loss of availability: 474 times
– Loss of integrity: 267 times

Number of people impacted

The number of people affected by these incidents is distributed as follows:
– Between 0 and 5 people: 237 times
– Between 301 and 5000 people: 190 times
– Between 6 and 50 people: 130 times
– More than 5000 people: 121 times
– Between 51 and 300 people: 110 times

Typologies of impacted data

The data typologies affected by the breaches are:
– Identification or access data (e.g. identifier: 305 times
– password: 305 times
– customer number...): 305 times
– The breach concerns other data: 245 times
– The data concerned is not known at the moment: 275 times
– Marital status (eg: name: 488 times
– gender: 488 times
– date of birth: 488 times
– age...): 488 times
– Contact details (e.g. postal or email address: 447 times
– landline or mobile phone numbers...): 447 times
– Data relating to financial information (e.g. income: 326 times
– credit card number: 326 times
– bank details): 326 times
– economical: 326 times
– NIR (Directory Registration Number): 257 times
– Official documents (Passports: 288 times
– ID: 288 times
– etc.): 288 times
– Location data: 82 times
– Data relating to offenses: 67 times
– convictions: 67 times
– security measures: 67 times

Origins of incidents

The main causes of these violations are:
– Hacking: 528 times
– malware (e.g. ransomware) and/or phishing: 528 times
– Other: 164 times
– Unvoluntary publication of information: 48 times
– Bad person data displayed on customer portal: 9 times
– Personal data sent to the wrong recipient: 35 times
– Equipment lost or stolen: 24 times
– Personal information disclosed verbally: 3 times
– Lost paper: 4 times
– stolen or left accessible in an unsecured location: 4 times
– Mail lost or opened before being returned to sender: 2 times

Conclusion

Data Comply One (formerly Mission RGPD) offers a complete solution for complying with the GDPR thanks to its GDPR Software, its DPO Coaches, and its outsourced DPO services. These tools help prevent data breaches by ensuring the security and compliance of processing practices. We invite you to use our free Diag GDPR tool to assess your company's compliance.

Consult the CNIL interactive map to find out more.
For more information on notifications to the CNIL and the follow-up taken.
Data on notifications to the CNIL.