Source methodology

Implemented official source

CNIL personal data breach notifications

One anonymized notification row, published by Breach Gazette only as grouped counts

Published rows from May 2018 through December 2025; the official dataset excludes notifications received in the three months before each extraction.

Regulator
Commission nationale de l'informatique et des libertés
Jurisdiction
France
Reporting scheme
GDPR personal data breach notifications to CNIL
Publication level
Anonymized Notification
Coverage type
Complete Anonymized Dataset
Reporting threshold
The official dataset concerns GDPR notifications to CNIL of personal data breaches presenting a risk to the rights and freedoms of affected people.
Source population
Notifications received by CNIL and included in its published anonymized dataset; this is not a census of all breaches in France.
Licence state
Licence Ouverte / Open Licence 2.0. Breach Gazette publishes attributed grouped counts and does not redistribute raw row combinations.
Rights boundary reviewed
24 July 2026
Redistribution decision
Approved With Conditions
Automated health
Healthy
Snapshot completeness
Complete
Update checkpoint
Complete
Reviewed record floor
120
Accepted records
43,502
Rejected records
0
Bounded retrieval limit
100,000
Source revision
data-gouv-resource:4c176588-a444-4dc7-b6bf-60390ae7e5be:2026-05-19T16:13:29.568000+00:00
Snapshot checksum
9b98479c56f5a71d87bb076c7c72367b5b746ef363853a3f6aa089bc02f0b408
Latest update attempt
24 July 2026
Last successful update
24 July 2026

Limitations

  • The official source does not name the notifying or affected organization.
  • The latest three months are excluded by the source for confidentiality.
  • Published fields reflect information supplied to CNIL and may not reflect the Commission's assessment.
  • One processor incident can lead to many separate controller notifications, so row counts are not unique incident counts.
  • Breach Gazette retains only grouped metrics in durable state and does not publish raw row combinations.
  • Breach-nature and incident-cause membership counts can exceed the number of notification rows because one row may contain multiple categories.

Correction process

Check the current official data.gouv.fr resource and its extraction warnings. Preserve notification-row semantics and do not infer an organization or unique incident.

Attribution

Commission nationale de l'informatique et des libertés (CNIL), via data.gouv.fr