The CNIL public sanctions list is not a live feed
The lag, in dates
On 3 September 2026 the CNIL (France's data-protection authority) made public a sanction against the Hôpital privé de la Loire (opens in new tab), for a health-data breach, on the basis of Articles 32 and 34 of the GDPR. The délibération (decision), SAN-2026-009, is dated 21 July 2026 — forty-four days earlier.
What the public list shows, and does not
As of 7 September 2026 that decision does not appear on the public list of sanctions issued by the CNIL (opens in new tab). The most recent entry on that list is dated 30 December 2025, and its 2026 entries stop at 2 April 2026.
The method consequence
The public list runs months behind, and it does not individually carry sanctions issued under the simplified procedure. A company's absence from it therefore says nothing about the CNIL's activity, nor about what may have been issued concerning that company. A risk review resting on this page alone measures a publication delay while believing it measures a level of enforcement. The news items and the annual bilans are the reading that is missing.
What I report here are publication dates observed on 7 September 2026. I do not say which company is concerned by what, or what it faces. Legal characterisation is for your counsel.
Primary sources
The content of this site is provided for information only and does not constitute legal advice.