FREE MOBILE – €27,000,000 Fine (France, 2026)

€27,000,000Commission Nationale de l'Informatique et des Libertés8 January 2026France
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

FREE MOBILE was fined EUR 27 million after a data breach exposed personal information of 24 million subscribers. This is significant because it emphasizes the need for companies to protect customer data and follow proper data retention practices. Businesses must regularly review their data storage to avoid similar issues.

What happened

FREE MOBILE suffered a data breach that compromised personal data of 24 million subscribers.

Who was affected

24 million subscribers whose personal information, including bank details, was accessed during the breach.

What the authority found

The French DPA found that FREE MOBILE failed to limit data storage and did not delete unnecessary subscriber data.

Why this matters

This ruling serves as a warning that companies must manage and protect customer data effectively. It encourages businesses to implement strict data retention policies.

GDPR Articles Cited

AI-verified

Art. 32(GDPR)
Art. 34(GDPR)
Art. 5(1)(e) GDPR
View original scraped data
Art. 5(1)(e) GDPR
Art. 32(GDPR)
Art. 34(GDPR)

Original data from scraper before AI verification against source document.

Source verified 10 March 2026
verified correct
Full Legal Summary
Detailed

The company FREE MOBILE (the “controller”), a subsidiary of the company ILIAD, operates as a mobile telephone operator and had, as of 31 December 2024, approximately 15.5 million mobile subscribers. In 2024, ILIAD's turnover was around €10 billion for a net profit of €367 million. In September 2024, an attacker managed to infiltrate the controller's information system and accessed personal data relating to 24 million subscriber contracts, including IBAN details, which the controller became aware in October 2024. The controller notified the DPA and informed the data subjects via email. Following a large number of complaints (more than 2,500) from individuals affected by this data breach, the DPA carried out an investigation to check the controller’s compliance with the GDPR and the French Data Protection Act. The DPA’s investigation revealed breaches of several obligations under the GDPR. Failure to adhere to the principle of storage limitation (Article 5(1)(e) GDPR) The DPA found that, at the time of the investigation, the controller had not implemented measures to separate the data of former subscribers, retain only what was required for accounting purposes, and delete the rest once it was no longer needed. Under Article 5(1)(e) GDPR, personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. The DPA reminded the controller that it must review its retained data periodically and ensure that the data is deleted at the end of its retention period. Based on the investigation and the controller’s own statements, the DPA concluded that the controller had kept millions of subscriber data without justification for an excessive period of time. During the proceedings, the controller began sorting the data in order to retain for ten years only the data necessary to comply with its accounting obligations and deleted some of the data that had been retai

Details

Fine Date

8 January 2026

Authority

Commission Nationale de l'Informatique et des Libertés

Fine Amount

€27,000,000

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. FREE MOBILE - France (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: