Article · 8 MIN

Cyberattack Liability in France: Is the IT Provider Always Responsible?

Cyberattack Liability in France: Is the IT Provider Always Responsible?

When a cyberattack brings an information system to a standstill, the immediate reaction is often to identify the technical party to blame: the hosting provider, managed service provider, software vendor, cybersecurity provider, or cloud operator.

French law requires a more nuanced analysis.

A cyberattack does not automatically make the IT provider liable. Conversely, the fact that the attack was carried out by a malicious third party does not automatically release the provider from liability.

The analysis must return to the contract, the respective obligations of the parties, the security measures actually implemented, and the causal link between any failure and the damage suffered.

A judgment issued by the Reims Court of Appeal on April 28, 2026, case no. 24/01502, provides a particularly useful illustration. The IT provider breached its duty to advise, but the customer had also contributed to the loss.

The court ultimately allocated liability equally between them.

1. A Cyberattack Does Not Automatically Eliminate Contractual Liability

The first question is whether the cyberattack can excuse the party that failed to perform its contractual obligations.

Article 1218 of the French Civil Code defines force majeure in contractual matters as an event beyond the debtor’s control that could not reasonably have been foreseen when the contract was entered into and whose effects could not have been avoided by appropriate measures.

A cyberattack can therefore theoretically qualify as force majeure.

It does not do so automatically.

The court must examine the specific attack, whether it could reasonably have been anticipated, whether appropriate measures could have reduced or avoided its effects, and which contractual obligation was actually prevented from being performed.

In an environment where cyber threats have become a recurring business risk, simply pointing to the involvement of a hacker is not enough to erase contractual responsibility.

Article 1231-1 of the French Civil Code then brings the analysis back to contractual performance. A party may be liable for damages resulting from non-performance or delayed performance unless it can establish an applicable excuse such as force majeure.

The practical question therefore becomes: what exactly was the IT provider required to do?

A hosting company, managed service provider, cybersecurity monitoring provider, and software vendor do not perform the same functions.

Liability must be assessed against the actual contractual scope and, where relevant, the professional duty to advise.

2. Reims Court of Appeal, April 28, 2026: Both the Provider and the Customer Failed

The Reims case is particularly useful because the court refused to identify a single responsible party.

A French industrial company had hired an IT provider to redesign its information system, including the integration of management software and remote working services.

No detailed specifications document had been prepared before the project.

Following a ransomware attack, the customer sought damages from the provider.

The court noted that the installed system complied with the accepted quotation.

That was not enough to release the IT professional from liability.

The provider knew that no specifications document had been prepared and was dealing with a customer that did not have demonstrated expertise in information technology.

As the professional party, it should have required the customer to clarify its needs, warned it about cybersecurity requirements, expressed reservations, conducted additional investigations, or refused to proceed if it lacked sufficient information.

Its failure to do so constituted a breach of its duty to advise.

The customer was not treated as a passive victim, however.

It also had a responsibility to define its needs adequately. The absence of a specifications document and the incomplete information provided to the IT provider contributed to the loss. The backup arrangements were also not clearly defined in the contractual documentation.

The result was a 50/50 allocation of liability.

The provider was ordered to compensate half of several losses, including business interruption, remediation costs, and the ransom paid.

The judgment provides a straightforward lesson: outsourcing IT does not mean outsourcing the entire cyber risk.

3. Contract Drafting Matters, but So Does the Parties’ Conduct

The Reims judgment also shows why contractual documentation becomes critical after a cyber incident.

The IT provider attempted to rely on general terms limiting its liability for the customer’s data and backups.

The court found that those terms had not been attached to the accepted quotation and were not signed in a manner demonstrating the customer’s acceptance.

They could therefore not be enforced against the customer.

For legal departments, the practical lesson is significant.

A limitation-of-liability clause is useful only if it actually forms part of the contract.

Cybersecurity contracts should also allocate responsibility clearly for matters such as:

  • backups;
  • software patching;
  • remote access;
  • multi-factor authentication;
  • monitoring and detection;
  • updates and obsolescence;
  • incident response;
  • business continuity;
  • and escalation when a vulnerability is identified.

The more these issues remain undefined, the more a court may later have to reconstruct the parties’ respective responsibilities.

4. The GDPR Confirms That Outsourcing Does Not Remove Security Responsibility

Where a cyberattack affects personal data, the GDPR adds another layer.

Article 32 of the GDPR requires both controllers and processors to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

Those measures may include maintaining confidentiality, integrity, availability and resilience, restoring access after an incident, and regularly testing the effectiveness of security measures.

For the customer, this means that outsourcing infrastructure or IT operations does not automatically transfer the controller’s own security obligations.

The organization must select appropriate providers, define responsibilities contractually, and ensure that the overall security level remains proportionate to the risk.

Where the IT provider qualifies as a processor under the GDPR, it also has its own legal obligations.

The same principle therefore appears in both contract law and data protection law: cybersecurity responsibility is usually distributed across several actors.

5. After the Attack, Evidence Becomes Critical

Cyber liability disputes are not decided only through technical logs.

Courts will reconstruct the entire decision-making chain.

Who knew about the vulnerability?

Who was supposed to install the patch?

Was a warning sent?

Did the customer follow the recommendation?

Were reservations documented?

Did the contract clearly allocate backup responsibilities?

Did the provider explain that additional protection was required?

Emails, tickets, audit reports, incident reports, meeting minutes, warnings, and contractual documents can become decisive evidence.

For both providers and customers, what was never documented will be significantly harder to prove after an incident.

6. Cyber Insurance: The French 72-Hour Complaint Requirement

French law also contains a specific rule for certain cyber insurance claims.

Article L.12-10-1 of the French Insurance Code provides that, within its scope, payment under insurance coverage for losses caused by specified attacks on automated data-processing systems is conditional on the victim filing a complaint with the competent authorities within 72 hours after becoming aware of the attack.

The rule applies to legal entities and individuals acting in a professional capacity.

This deadline should not be confused with the GDPR’s separate 72-hour data-breach notification mechanism.

They serve different legal purposes.

A corporate incident-response plan should therefore coordinate contractual obligations, regulatory notifications, evidence preservation, and insurance requirements from the outset.

Key Takeaways

A cyberattack does not automatically determine who is legally responsible.

An IT provider may be liable where it failed to perform its contractual obligations, failed to address risks within its scope, or breached its professional duty to advise.

The customer may also bear part of the responsibility where it failed to define its needs, ignored recommendations, or failed to implement security measures under its own control.

The Reims Court of Appeal judgment of April 28, 2026 captures this principle particularly well: cyber liability depends on the actual allocation of obligations and the causal contribution of each party, not simply on who is labelled the IT provider.

The best time to determine who is responsible for each security task is therefore not after the attack.

It is when the contract is drafted.

Is an IT provider automatically liable after a cyberattack in France?

No. Liability depends on the provider’s contractual obligations, any breach of those obligations, its professional duty to advise where applicable, and the causal connection with the damage.

Can a cyberattack qualify as force majeure under French law?

Potentially. However, the requirements of Article 1218 of the French Civil Code must be established in the specific circumstances. The fact that a third-party attacker caused the incident is not sufficient by itself.

Can the customer also be liable?

Yes. In the April 28, 2026 Reims Court of Appeal case, the customer’s failure to define its requirements adequately contributed to the damage, resulting in a 50/50 allocation of liability.

Does outsourcing IT transfer GDPR security obligations?

No. Article 32 of the GDPR imposes appropriate security obligations on both controllers and processors according to their respective roles.

Is there a specific cyber-insurance deadline in France?

Yes. Within the scope of Article L.12-10-1 of the French Insurance Code, a complaint must be filed within 72 hours after the victim becomes aware of the attack in order to benefit from the relevant insurance coverage.