Compliance
French Ministry Data Breach Prompts Fresh EU Privacy Concerns
.jpg)
At the nub of the problem is that cyber attacks, campaigners say, demonstrate the dangers of mass data transfers between governments for the presumed purpose of uncovering tax evasion and illicit financial transfers.
Government databases holding details of individuals’ tax and other financial affairs continue to be vulnerable to cyber attacks, as demonstrated by high-profile cases.
Last week, the Finance Ministry in France confirmed that the data
of 678,000 users had been stolen by a “malicious actor.”
Privacy campaigner Filippo Noseda, partner at international law
firm Mishcon
de Reya, who has for years flagged concerns that
government-to-government data transfers compromise citizens’
privacy, said in a letter to the European Union that the “French
Ministry of Finance only came clean after reports in the press,
confirming a culture of contempt and cover-up when it comes to
citizens’ personal data.”
Noseda’s letter, which he republished on his LinkedIn page, was
addressed to Michael McGrath, EU Commissioner for Democracy,
Justice and Rule of Law and Consumer Protection; Antonio Costa,
President of the European Council, Wojciech Wiewioroski, European
Data Protection Supervisor, and Anu Talus, Chair, European Data
Protection Board. Noseda has asked the EU for a temporary
halt, and data security audit, of all EU and EU member states'
systems that hold "sensitive personal and financial data of
individuals and businesses pursuant to measures requiring bulk
collection of information enacted by the EU."
Noseda also wrote to the Organisation for Economic Co-operation and Development, including Manal Corwin, director, Centre for Tax Policy and Administration, referring to "renewed concerns relating to OECD bulk collection of data."
The incident raises further concerns about whether government
data gathering on individuals’ business and financial affairs,
and associated demands for transparency, conflict with legitimate
financial privacy.
There is a particular concern when such data is transferred in
bulk to other governments under various international treaties,
such as the Common Reporting Standard (CRS)
Two weeks ago, the government of Liechtenstein said a register of
beneficial ownership had been attacked and that, as a result,
systems have been temporarily taken offline. (See analysis from
this news service
here.)
In its 13 August statement, the French ministry said: “In-depth
investigations conducted since 12 August 2026 have established
that, before access was cut off, these accounts had been used to
view and extract certain data concerning a total of 678,000
individuals and businesses, including tax data such as reference
taxable income, family quotient, and the withholding tax rate,
and, for businesses, data such as their company name or SIREN
number. Land registry data relating to property addresses
and surface areas was also accessed. As soon as this data theft
was identified, the DGFiP notified the CNIL (France's data
protection authority). The `Finances publiques’ online
accounts of individual and business users were not compromised.
Also, the login credentials and passwords of individuals and
businesses were not compromised.
"Following new findings from the ongoing investigations,
additional security measures were immediately implemented,
including preventive shutdowns of access to sensitive information
systems. Investigations are continuing in order to determine
precisely the nature and volume of the data extracted, as well as
the number of users affected,” the statement, originally
published in French, said. The DGFiP will contact affected
individuals and companies, it said. (DGFiP is Direction générale
des Finances publiques, the tax authority.)