Mobius Solutions Ltd – €1,000,000 Fine (France, 2025)

€1,000,000Commission Nationale de l'Informatique et des Libertés11 December 2025France
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A French data protection authority fined Mobius Solutions Ltd €1,000,000 for mishandling user data after a major data breach. This is significant because it shows that companies must follow strict rules about data retention and usage, especially after a breach. The ruling serves as a warning to all businesses about the importance of data protection.

What happened

Mobius Solutions Ltd failed to delete user data after their contract ended and used it for unauthorized purposes.

Who was affected

Approximately 46,900,000 users worldwide, including over 21 million in the EU and nearly 10 million in France.

What the authority found

The authority found that Mobius Solutions Ltd violated multiple GDPR articles by not properly managing user data.

Why this matters

This case underscores the financial risks of failing to comply with data protection rules. Companies must ensure they manage user data responsibly to avoid hefty fines.

GDPR Articles Cited

AI-verified

Art. 28(GDPR)
Art. 29(GDPR)
Art. 30(GDPR)
View original scraped data
Art. 28(GDPR)
Art. 29(GDPR)
Art. 30(GDPR)

Original data from scraper before AI verification against source document.

Source verified 10 March 2026
verified correct
Full Legal Summary
Detailed

DEEZER (the controller) notified the French DPA (CNIL) of a data breach affecting approximately 46,900,000 users worldwide, out if which 21,574,775 users located in the European Union and 9,849,354 users from France. The controller identified Mobius Solutions Ltd (the processor) as the likely source of the data breach. The DPA launched an investigation into the processor. Firstly, the DPA found that the processor should have deleted the users' data at the end of the contractual relationship with the controller. Failing to do so, even if the data were retained as a result of an unauthorised copy created by its employees, the DPA found a violation of Article 28(3)(g) GDPR. Secondly, the DPA found that the processor used the data for the development and testing of its own system, contrary to the contract stipulations between the processor and the controller. Therefore, the DPA found that the processing fell outside the limits of the contract, constituting a breach of Article 29 GDPR. Finally, the DPA found the processor in breach of Article 30 GDPR by failing to keep a record of the processing activities it carried out and for failing to provide the name and contact details of the data protection officer of the controller. Therefore, the DPA fined the processor €1,000,000 for violations of Article 28 GDPR, Article 29 GDPR, and Article 30 GDPR.

Related Enforcement Actions (0)

No other enforcement actions found for Mobius Solutions Ltd in FR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

11 December 2025

Authority

Commission Nationale de l'Informatique et des Libertés

Fine Amount

€1,000,000

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Mobius Solutions Ltd - France (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: