Skip to content

CNIL Fines Free Mobile and Free €42M Over Massive Data Breach

January 16, 202659 second read

On 13 January 2026, France’s data protection authority CNIL imposed a combined €42 million fine on Free Mobile (€27M) and Free (€15M) following a large-scale personal data breach.

What Happened?
In October 2024, attackers accessed personal data linked to ~24 million subscriber contracts, including IBANs of customers holding both Free Mobile and Free accounts.

Key GDPR Failures Identified by CNIL
Inadequate security measures (Art. 32 GDPR): Weak VPN authentication and ineffective monitoring failed to detect abnormal access.
Incomplete breach notifications (Art. 34 GDPR): Customers were notified, but communications lacked clear explanations of risks and self-protection measures.
Excessive data retention (Art. 5(1)(e) GDPR): Free Mobile retained former subscribers’ data beyond what was necessary for legal and accounting purposes.

Why It Matters
Despite remediation efforts during the investigation, CNIL emphasized:
• The scale of affected individuals
• The sensitivity of financial data
• The real risk of harm.

Takeaway for Companies
This case reinforces that cybersecurity preparedness and breach-response compliance remain a top enforcement priority. Even large telecom operators are expected to implement proportionate, effective technical and organisational measures under the GDPR.

Source: https://lnkd.in/dJAuPVR5

S8fe.ai helps companies operationalize data security, retention, and breach-response obligations across multiple regulations through a single, auditable compliance workflow.

Share this article

Back To Top