Mobius Solutions Ltd – €1,000,000 Fine (France, 2025)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A French data protection authority fined Mobius Solutions Ltd €1,000,000 for mishandling user data after a major data breach. This is significant because it shows that companies must follow strict rules about data retention and usage, especially after a breach. The ruling serves as a warning to all businesses about the importance of data protection.
What happened
Mobius Solutions Ltd failed to delete user data after their contract ended and used it for unauthorized purposes.
Who was affected
Approximately 46,900,000 users worldwide, including over 21 million in the EU and nearly 10 million in France.
What the authority found
The authority found that Mobius Solutions Ltd violated multiple GDPR articles by not properly managing user data.
Why this matters
This case underscores the financial risks of failing to comply with data protection rules. Companies must ensure they manage user data responsibly to avoid hefty fines.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
DEEZER (the controller) notified the French DPA (CNIL) of a data breach affecting approximately 46,900,000 users worldwide, out if which 21,574,775 users located in the European Union and 9,849,354 users from France. The controller identified Mobius Solutions Ltd (the processor) as the likely source of the data breach. The DPA launched an investigation into the processor. Firstly, the DPA found that the processor should have deleted the users' data at the end of the contractual relationship with the controller. Failing to do so, even if the data were retained as a result of an unauthorised copy created by its employees, the DPA found a violation of Article 28(3)(g) GDPR. Secondly, the DPA found that the processor used the data for the development and testing of its own system, contrary to the contract stipulations between the processor and the controller. Therefore, the DPA found that the processing fell outside the limits of the contract, constituting a breach of Article 29 GDPR. Finally, the DPA found the processor in breach of Article 30 GDPR by failing to keep a record of the processing activities it carried out and for failing to provide the name and contact details of the data protection officer of the controller. Therefore, the DPA fined the processor €1,000,000 for violations of Article 28 GDPR, Article 29 GDPR, and Article 30 GDPR.
Related Enforcement Actions (0)
No other enforcement actions found for Mobius Solutions Ltd in FR
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
11 December 2025
Authority
Commission Nationale de l'Informatique et des Libertés
Fine Amount
€1,000,000
About this data
Cite as: Cookie Fines. Mobius Solutions Ltd - France (2025). Retrieved from cookiefines.eu
Last updated: