In 2026, French companies sending employees on business trips fall under a binding regulatory framework: the Labour Code, the European directive on traveller safety and ISO 31030:2021. Three texts, three levels of obligations. And one reality: 68 % of mid-sized companies fail to meet all of them, often without knowing it.

68 %
of mid-sized companies non-compliant with at least one duty of care obligation
€45,000
maximum fine for breach of the safety obligation
ISO 31030
international standard applying to companies operating across multiple countries

The regulatory framework in 2026: three texts, one obligation

Duty of care refers to all the legal obligations an employer has toward employees on business travel. These obligations are not optional. They stem directly from article L4121-1 of the French Labour Code, which requires employers to "take the necessary measures to ensure the safety and protect the physical and mental health of workers".

In 2021, ISO published the ISO 31030:2021, Travel Risk Managementstandard, which establishes an international reference framework for managing risks linked to business travel. While not legally binding in France, this standard is the benchmark used by courts to assess whether an employer has fulfilled its reinforced obligation of means. In short: not complying with it exposes the company to a presumption of negligence.

Finally, EU directive 2015/849 and its revisions require traceability of high-risk trips, particularly for companies in the financial and pharmaceutical sectors subject to reinforced compliance obligations.

The 3 concrete legal obligations

Behind the regulatory terminology, three operational obligations apply to any company that sends employees on business travel:

01
Location tracking
Knowing, at all times, where your travellers are. Not just the planned itinerary: their actual position, in real time, in the event of an incident.
02
Information
Proactively alerting the traveller as soon as an identified risk affects their journey: travel disruption, security alert, or major weather event.
03
Repatriation
Having an operational repatriation procedure activatable within 2 hours in an emergency, and having tested it before it is needed.

These three obligations form an inseparable triad. Locating without informing is non-compliant. Informing without repatriation capacity is equally insufficient. Employment tribunals and insurance companies now systematically analyse all three dimensions when an incident involves a business traveller.

The cost of non-compliance

Non-compliance with duty of care is not a legal abstraction. It has a measurable cost, and that cost is asymmetric: penalties occur precisely when the company is already weakened by an incident.

RiskNatureExposure
Criminal fineBreach of safety obligation (L4121-1)Up to €45,000 for the legal entity
Executive liabilityGross negligence or deliberate endangermentPersonal criminal liability of the CEO/CHRO
Insurance cancellationNon-compliance with risk management clausesVoidance of travel coverage in the event of a claim
Employment tribunal claimDamages to the employeeDepending on harm: tens of thousands of euros
⚠ Insurance warning

Most business travel insurance contracts contain a clause conditioning coverage on the implementation of a risk management framework compliant with ISO 31030. If an incident occurs and your company cannot demonstrate compliance, the insurer can legitimately refuse to cover the claim, even if your policy is up to date.

In 2025, two French court of appeal rulings found employers liable not for the incident itself, but for the absence of a documented travel risk management procedure. Proof of compliance is as important as compliance itself.

How ZEPHYR automates compliance

The core challenge of duty of care is not travel managers' goodwill, it is scalability. A company with 50 active travellers can have 15 to 20 people travelling simultaneously across multiple continents. Manual compliance (periodic checks, individual calls, generic alert bulletins) is structurally insufficient. ZEPHYR replaces that approach with an automated compliance pipeline in three phases:

1

Continuous detection

ZEPHYR aggregates real-time data from more than 800 airports, aviation weather bulletins (SIGMET/AIRMET), MEAE diplomatic alerts and operational disruption feeds (strikes, airspace closures, health restrictions). As soon as an event affects a referenced traveller's trajectory, the system detects it, on average 4 hours before the disruption becomes visible in booking systems.

2

Graduated and traceable alerts

The alert is sent simultaneously to the traveller (SMS + email) and to the travel manager, with criticality level, available rerouting options and a certified timestamp. That timestamp is the key: in a dispute, you can demonstrate the traveller was informed at time T, before the incident, with available options.

3

Repatriation procedure activation

If the criticality level triggers a repatriation protocol, ZEPHYR automatically identifies the available alternatives (connecting flights, charter links, ground transport), communicates them to the traveller and opens a real-time tracking case until safe return is confirmed. The procedure is documented and exportable for your insurers.

The operational result for our clients: zero missed alerts on critical events, an average notification delay of 11 minutes after incident detection, and one-click exportable compliance documentation for your insurers or in case of audit.

On the regulatory side, this automation makes it possible to satisfy the three legal obligations simultaneously (location via real-time flight data, information via timestamped traceable alerts, repatriation via an activatable documented procedure) without adding operational load to your travel team.

For Finance and Pharma companies that also need to demonstrate compliance as part of their ESG reporting and governance obligations, ZEPHYR produces quarterly duty of care activity reports exportable in the format expected by auditors.

Conclusion: compliance is no longer optional

The regulatory framework for business travel duty of care has tightened significantly between 2021 and 2026. ISO 31030, recent case law and rising insurer expectations have turned what was perceived as best practice into a real obligation, with real sanctions.

The question is no longer whether your company is exposed. It is whether you can prove it, before an incident forces you to demonstrate it after the fact, in crisis mode.

Evaluate your real exposure in 3 minutes

Our simulator analyses your travel volume, destinations and sector to precisely calculate your exposure to disruptions, and the compliance of your current duty of care framework.

Simulate my exposure →