Customer data compromised: Voyageurs du Monde risks a heavy financial penalty
Customer data compromised: Voyageurs du Monde risks a heavy financial penalty

The French tour operator Voyageurs du Monde could be fined €1,8 million following proceedings initiated by the French data protection authority (CNIL). The authority accuses the company of several IT security breaches discovered after a major cyberattack in 2023. This intrusion led to the online release of thousands of customers' personal documents, including approximately 8.000 passport copies.

Following this incident, the CNIL (French Data Protection Authority) conducted several audits to assess the company's compliance with its obligations regarding the protection of personal data. The investigations identified five shortcomings. While the company claims to have corrected most of the identified problems, one point remains a subject of debate: the retention period for its customers' information.

Data retention at the heart of the dispute

During the hearing, representatives from Voyageurs du Monde defended their data retention policy, which allows for data to be kept for up to ten years. According to management, this practice addresses the specific characteristics of the tailor-made travel market, where a significant portion of customers book repeat trips several years after their initial reservation. The company believes that detailed knowledge of travelers' preferences and history is essential to the quality of service offered.

The CNIL rapporteur, however, believes that these arguments do not justify such a long retention period for personal information. According to the authority, the commercial imperatives put forward by the company do not allow it to disregard the retention period limits stipulated by the European General Data Protection Regulation (GDPR). The commission's final decision will be issued in the coming weeks.

A sector particularly vulnerable to cyberattacks

This case comes amid a sharp increase in cybersecurity incidents. According to figures published by the CNIL (French Data Protection Authority), more than 6.100 data breaches were reported in 2025, a record high representing a year-on-year increase of nearly 10%. Tourism companies are among the prime targets of cybercriminals due to the amount of sensitive information they process daily and the complexity of their booking systems.

In recent years, several major players in the sector have faced cyberattacks resulting in personal data leaks. For the authorities, these cases underscore the importance of strengthening digital security measures to protect customer information and limit the financial and reputational consequences for the companies involved.

Community

Comments

Comments are open, but protected against spam. Initial posts and comments containing links undergo manual review.

Be the first to comment on this article.

Respond to this article

Comments are moderated. Promotional messages, automated emails, and abusive links are blocked.

Your first comment, or any message containing a link, may be placed pending approval.