
On 13 January 2026, France’s data protection authority CNIL imposed a combined €42 million fine on Free Mobile (€27M) and Free (€15M) following a large-scale personal data breach.
What Happened?
In October 2024, attackers accessed personal data linked to ~24 million subscriber contracts, including IBANs of customers holding both Free Mobile and Free accounts.
Key GDPR Failures Identified by CNIL
• Inadequate security measures (Art. 32 GDPR): Weak VPN authentication and ineffective monitoring failed to detect abnormal access.
• Incomplete breach notifications (Art. 34 GDPR): Customers were notified, but communications lacked clear explanations of risks and self-protection measures.
• Excessive data retention (Art. 5(1)(e) GDPR): Free Mobile retained former subscribers’ data beyond what was necessary for legal and accounting purposes.
Why It Matters
Despite remediation efforts during the investigation, CNIL emphasized:
• The scale of affected individuals
• The sensitivity of financial data
• The real risk of harm.
Takeaway for Companies
This case reinforces that cybersecurity preparedness and breach-response compliance remain a top enforcement priority. Even large telecom operators are expected to implement proportionate, effective technical and organisational measures under the GDPR.
Source: https://lnkd.in/dJAuPVR5
S8fe.ai helps companies operationalize data security, retention, and breach-response obligations across multiple regulations through a single, auditable compliance workflow.
