Source methodology
Implemented official source
CNIL personal data breach notifications
One anonymized notification row, published by Breach Gazette only as grouped counts
Published rows from May 2018 through December 2025; the official dataset excludes notifications received in the three months before each extraction.
- Regulator
- Commission nationale de l'informatique et des libertés
- Jurisdiction
- France
- Reporting scheme
- GDPR personal data breach notifications to CNIL
- Publication level
- Anonymized Notification
- Coverage type
- Complete Anonymized Dataset
- Reporting threshold
- The official dataset concerns GDPR notifications to CNIL of personal data breaches presenting a risk to the rights and freedoms of affected people.
- Source population
- Notifications received by CNIL and included in its published anonymized dataset; this is not a census of all breaches in France.
- Licence state
- Licence Ouverte / Open Licence 2.0. Breach Gazette publishes attributed grouped counts and does not redistribute raw row combinations.
- Rights boundary reviewed
- 24 July 2026
- Redistribution decision
- Approved With Conditions
- Automated health
- Healthy
- Snapshot completeness
- Complete
- Update checkpoint
- Complete
- Reviewed record floor
- 120
- Accepted records
- 43,502
- Rejected records
- 0
- Bounded retrieval limit
- 100,000
- Source revision
- data-gouv-resource:4c176588-a444-4dc7-b6bf-60390ae7e5be:2026-05-19T16:13:29.568000+00:00
- Snapshot checksum
- 9b98479c56f5a71d87bb076c7c72367b5b746ef363853a3f6aa089bc02f0b408
- Latest update attempt
- 24 July 2026
- Last successful update
- 24 July 2026
Limitations
- The official source does not name the notifying or affected organization.
- The latest three months are excluded by the source for confidentiality.
- Published fields reflect information supplied to CNIL and may not reflect the Commission's assessment.
- One processor incident can lead to many separate controller notifications, so row counts are not unique incident counts.
- Breach Gazette retains only grouped metrics in durable state and does not publish raw row combinations.
- Breach-nature and incident-cause membership counts can exceed the number of notification rows because one row may contain multiple categories.
Correction process
Check the current official data.gouv.fr resource and its extraction warnings. Preserve notification-row semantics and do not infer an organization or unique incident.
Attribution
Commission nationale de l'informatique et des libertés (CNIL), via data.gouv.fr