Compliances

10 min read
8/10/2026

Electronic invoicing: a new source of vulnerability for personal data?

At a time when personal data has become a major economic resource, the widespread adoption of electronic invoicing is further increasing the circulation of sensitive information.

‍

This reform is presented as a tool for modernization and combating tax fraud.

‍

It deserves to be viewed in the context of regulations regarding the protection of personal data. Invoices can indeed contain personal data, information covered by professional secrecy, or strategic information protected by trade secrets.

‍

Furthermore, the reform raises crucial cybersecurity issues.

‍

These are all the more significant in a climate where numerous public information systems have been hit by cyberattacks, exposing vast amounts of personal data. The attacks on the ANTS, France Travail, and the DGFiP illustrate the limitations of existing security measures and put the trust that businesses and citizens can place in electronic invoicing to the test.

The electronic invoicing reform: tax modernization leading to increased data centralization

‍

As of September 1, 2026, the electronic invoicing reform has come into effect in France. It profoundly changes the invoicing procedures for VAT-registered businesses. From this date, all affected companies must be able to receive electronic invoices.

‍

The obligation to issue electronic invoices is being rolled out in phases. Since September 1, 2026, it has applied to large companies and mid-sized enterprises. SMEs and micro-businesses will be subject to this requirement starting September 1, 2027.

‍

An electronic invoice must comply with a standardized electronic format. It contains structured data that can be directly identified and processed by computer systems. Invoices between affected French companies now pass through authorized platforms.

‍

These platforms are responsible for receiving and transmitting invoices. They also extract specific data from the invoices to send to the tax authorities. The reform is therefore accompanied by a second mechanism: "e-reporting." Under this mechanism, in certain situations, data relating to transactions and payments must be transmitted to the tax authorities.

‍

Electronic invoicing does not just transform the format of the invoice. It also organizes a more structured and systematic flow of invoicing information between companies, authorized platforms, and the tax authorities.

A reform that leads to significant data collection and circulation: the issue of personal data protection.

‍

The electronic invoicing reform involves the circulation of data that may, in some cases, be personal data. For example, an invoice may allow a client to be identified. It may also reveal the nature of a service and, in certain sectors, contain particularly sensitive information.

‍

Various provisions subject certain professions to professional secrecy. For example, the Public Health Code subjects members of healthcare establishments to professional secrecy. Furthermore, codes of ethics also subject certain professions to this secrecy, such as lawyers.

‍

Consequently, certain information cannot be disclosed by a lawyer or a doctor due to professional secrecy. Professional secrecy is designed as a fundamental right for the client and an obligation for the professional. It is an absolute right that only yields to overriding general interests.

‍

However, this is not the case for the objectives pursued by the electronic invoicing reform.

‍

The stakes are high, especially since the violation of professional secrecy can lead to criminal and disciplinary sanctions. Professional secrecy entails a duty to keep certain information confidential.

‍

For lawyers, it covers everything related to the relationship between them and their client. For doctors, they must keep secret any information regarding their patient that they have learned in the course of their practice.

‍

When professional secrecy is confronted with the electronic invoicing reform, a tension arises between two obligations.

‍

On one hand, we have professional secrecy, and on the other, an obligation to transmit data necessary for invoicing and tax auditing. Invoicing data can be of various types: the identity of the parties, the nature of the transaction, amounts, VAT, and other supplementary information. ‍

‍

A specific mechanism has been provided to prevent the precise nature of the service performed from being transmitted to the tax authorities.

‍

The aforementioned AFNOR XP Z12-014 experimental standard provides, in its use case no. 36 regarding "transactions subject to professional secrecy and the exchange of sensitive data" a dissociation between the information transmitted to the tax authorities and that intended solely for the client. Indeed, the tax authorities do not need to know the exact nature of the transaction performed.

‍

For professions subject to professional secrecy, the field corresponding to the description of the service may contain a generic term, such as "service provision." The actual nature of the service will be specified in a different field.

‍

However, this mechanism does not allow for the preservation of professional secrecy in its entirety.

‍

Even when the precise nature of the service is not transmitted, the remaining information is not necessarily neutral. The lawyer's professional secrecy helps to concretely illustrate this issue. Other data related to the invoice remain necessary for the system to function: the client's identity, address, the service provider's identity, the invoice date, and the amounts billed.

‍

These pieces of information do indeed fall under professional secrecy.

‍

Article 2.2 of the National Internal Regulations of the legal profession specifies, in particular, that it covers "the names of clients" as well as "financial settlements and all handling of funds" carried out in a professional capacity.

‍

The difficulty is even greater when different pieces of information are combined.

‍

In isolation, the term "service provision" reveals very little. However, cross-referencing the client's identity, the firm's identity, its area of specialization, and the dates and amounts of invoices can make it possible to deduce, at least partially, the nature or context of the work performed.

‍

The reform therefore establishes a mechanism intended to preserve professional secrecy, but it primarily protects the specific description of the services provided. It does not prevent the circulation of other data which, when taken individually or, more importantly, combined, can reveal the existence and certain aspects of the relationship between a lawyer and their client.

‍

Let us now consider the perspective of trade secrets.

‍

The reform does not just involve the circulation of simple accounting data. It provides much greater visibility into the economic activity of businesses. Invoices can contain a wealth of strategic information, such as the identities of clients and suppliers, the nature of the services provided, and the amounts billed.

‍

The data concentration effect brought about by the reform is therefore concerning. The more data is aggregated, the easier it becomes to exploit.

‍

It is easy to imagine that a cyberattack, a permissions error, or unauthorized access could lead to significant consequences. The reform increases these risks, even as recent cyberattacks demonstrate that data (already highly protected in theory) can still be subject to fraudulent access and exfiltration.

‍

Finally, we will address one last risk regarding personal data protection. The reform also increases the number of parties involved in data processing.

‍

Data may circulate between the issuing company, the recipient company, approved platforms, and the tax authorities. While this architecture may allow for better organization of exchanges, it also expands the processing chain and increases the number of potential access points.

‍

The increase in intermediaries does not, in itself, constitute a weakness in the system, but it does raise the requirements for coordination, supervision, and security.

Data concentration: a security challenge in the face of multiplying cyberattacks

‍

The development of electronic invoicing necessarily relies on a relationship of trust. Yet, this trust is currently being tested by the rise in cyberattacks targeting not only secondary players, but major public administrations and services, such as the ANTS, France Travail, and the DGFiP.

‍

The ANTS is a public agency responsible for managing online procedures related to "official documents." It operates under the authority of the Ministry of the Interior.

‍

All procedures are handled online; there are no physical offices. France Travail (formerly Pôle emploi) is a public service that provides a system to simplify processes for job seekers. This platform also helps to better coordinate the various stakeholders.

‍

Given the concentration of data, these organizations are prime targets. The attack on France Travail exposed the data of 43 million people, while the incident at the ANTS could affect 11.7 million accounts.

‍

Concentrating data can facilitate cyberattacks and allow for the reconstruction of individual profiles, which leads to very serious consequences, as illustrated by the recent data breach suffered by the French Shooting Federation.

‍

In October 2025, the Federation suffered an intrusion into its information system. The stolen data made it possible to identify members and their home addresses. The information system did not contain data related to firearm ownership.

‍

However, in April 2026, the Minister of the Interior indicated that 20 to 30 burglaries could be directly linked to the stolen data, with some of it having been used in the context of weapon thefts, notably by individuals posing as police officers.

‍

Thus, cross-referencing multiple data points makes it possible to deduce certain information or reconstruct individual profiles.

‍

Today, announcements of data breaches are becoming commonplace. The phenomenon is no longer new or exceptional.

‍

Yet, some breaches could likely have been avoided by implementing basic security mechanisms, or at the very least, by having the ability to correctly identify and interpret signals as they appear.

‍

This situation is all the more concerning given that France is among the countries most exposed to cyberattacks, ranking first in Europe and second globally, behind the United States.

‍

Recent events provide a particularly striking illustration. In June and July 2026, fraudulent access to the DGFiP allowed for the viewing and extraction of data concerning approximately 678,000 individuals and professionals. The affected information included sensitive tax data, as well as data related to businesses and land registry records.

‍

Seized at the request of the Prime Minister, the ANSSI published a report on September 29, 2026, highlighting several failures in the detection of these intrusions.

‍

Security tools were indeed in place at the DGFiP, and some suspicious signals were spotted. However, this did not lead to the detection of the data exfiltration. The problem, therefore, lies less in the total absence of measures than in their limitations: a lack of visibility into certain systems, insufficient analysis tools, and a lack of effective correlation between different signals.

‍

This situation directly calls into question the actual effectiveness of the security measures in place: a security system cannot be considered fully effective if it identifies anomalies without being able to measure their scope or deduce that a data breach is underway.

‍

The ANSSI itself had detection capabilities. However, the absence of sufficiently relevant network markers and detection rules adapted to this threat was notable. Consequently, the ANSSI's systems were also unable to identify the suspicious behavior.

‍

The conclusion is therefore particularly worrying: none of the exfiltrations were detected by the supervision tools of either the DGFiP or the ANSSI.

‍

This event puts the risks associated with the electronic invoicing reform into direct perspective. The reform will organize the structured circulation of a considerable volume of data. Furthermore, more than ten million economic actors are affected by the new system.

‍

The issue of security is therefore central. The challenge is no longer just to put in place infrastructures that are compliant on paper. It is also necessary to guarantee their concrete effectiveness against fraudulent use and to be capable of reacting when an attack occurs.

‍

In its incident report published on September 23, 2026, ANSSI explicitly points out that having security mechanisms in place is not enough: you must also be able to identify unusual behavior and, above all, correlate various weak signals to understand that an attack is underway.

‍

Automated tools can detect, correlate, and flag anomalies. However, behind these tools, there must be an organizational capacity to define what constitutes abnormal behavior, configure detection rules, analyze alerts, and decide on a response.

‍

At a time when AI is playing an increasingly prominent role, this episode highlights an essential reality: security relies as much on the tools themselves as it does on an organization's ability to configure them, interpret their results, and act quickly.

‍

Furthermore, the report demonstrates the importance of system segmentation. Certain sensitive applications were exposed on the internet or accessible from the government's inter-ministerial network without sufficient segmentation. This notably allowed the attacker to move laterally to other public organizations.

‍

Ultimately, the ANSSI report highlights three essential requirements: strengthening authentication, segmenting systems, and improving the detection of suspicious behavior.  

‍

This is the paradoxical context in which the electronic invoicing reform is emerging.

‍

On one hand, the government is organizing an increasingly automated and structured flow of data to improve the efficiency of tax administration and combat fraud.

‍

On the other hand, the 2026 incidents highlighted concrete shortcomings in the oversight of information systems tasked with protecting some of the most sensitive tax data belonging to citizens and businesses.

‍

The success of electronic invoicing cannot be measured solely in terms of administrative simplification. It will also depend on the trust that businesses and citizens can place in the ecosystem being implemented.

‍

And this trust does not rely solely on the existence of cybersecurity tools. It requires that these tools effectively detect, prevent, and contain breaches of the very data they are meant to protect.

Other articles that may interest you

See all articles

Compliances

26/10/2025

7 min read

ARCEP vs HDS : discrepancy or convergence in reversibility requirements?

At a time when cloud hosting is growing, two standards intersect: the recommendation relating to the interoperability and portability of cloud computing services published on September 25, 2025 and requirement 27 present in the Health Data Host certification framework in its latest and recent version of May 16, 2024.

‍

Arcep's objective is to facilitate the change of cloud provider and thus to strengthen users' ability to choose, while the objective of the HDS framework is to ensure that health data is returned at the end of the contract in a secure manner.

Read the article

Innovations

13/1/2025

10 min read

AI ACT : Protection of rights and artificial intelligence

For several years, the European Union has sought to oversee the development of artificial intelligence in order to reconcile innovation and the protection of fundamental rights. In this context, Regulation EU 2024/1689 (AI Act) was adopted by the European Parliament and the Council on 13 June 2024, prior to its publication in the Official Journal of the European Union on 12 July 2024.

‍

This text establishes regulations based on a risk-based approach, prohibiting certain practices and imposing strict requirements, especially for high-risk AI systems. The application of this regulation is particularly significant in the field of health, where AI promises major advances while requiring compliance with numerous European laws, such as the RGPD and the MDR regulation.

Read the article

Compliances

12/2/2025

8 min read

RGPD vs IA: The challenges of protecting personal data in the implementation of AIS

At a time when the first provisions of the artificial intelligence regulation are coming into force, the compliance of AI systems is becoming an essential issue.‍

‍

Artificial intelligence (AI) is defined by Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 as follows: ” A system designed to work with elements of autonomy and capable, for a given set of human-defined goals, of generating results such as content, predictions, recommendations, or decisions that influence the environments with which it interacts.” The regulation distinguishes between artificial intelligence systems (AIS) and general-purpose AI models.

‍

AIS are AI applications designed for specific tasks or areas, such as medical diagnostic support systems. In contrast, general-purpose AI models are versatile systems, capable of being used in a variety of contexts and for a variety of applications. For example, a natural language processing model can be adapted to perform machine translation.

‍

Artificial intelligence raises complex issues, especially in the area of personal data protection. Indeed, artificial intelligence systems operate using a large or even massive quantity of data, justifying the establishment of a rigorous framework governing their use and processing, while ensuring respect for the fundamental rights of individuals, including respect for privacy.

‍

The challenges are multiple : how to ensure that algorithms do not compromise the privacy of individuals? How can we ensure that the data analysis carried out by AI systems remains ethical and in accordance with the principles of transparency, fairness and accountability?

‍

To face these challenges, which are not the same in the design phase and in the deployment phase, data protection authorities, such as the CNIL in France and the EDPS at the European level, must constantly reassess and adjust their doctrines to inform actors in the field on the compliance procedures to be carried out by integrating technological developments. Here we provide an overview of recent developments in this doctrinal and/or regulatory framework relating to AI and the RGPD.

Read the article

CONTACT

In need of customized
support ?

* Mandatory fields. We collect this data in order to send you the answers you have requested by email. To find out more about the management of your personal data and to exercise your rights, refer to our privacy policy.

Merci, votre message a bien été envoyé !
Veuillez réessayer d'envoyer votre message ou directement nous contacter par téléphone !