Mobius Solutions Ltd – €1,000,000 Fine (France, 2025)

€1,000,000Commission Nationale de l'Informatique et des Libertés11 December 2025France
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

DEEZER (the controller) notified the French DPA (CNIL) of a data breach affecting approximately 46,900,000 users worldwide, out if which 21,574,775 users located in the European Union and 9,849,354 users from France. The controller identified Mobius Solutions Ltd (the processor) as the likely source of the data breach. The DPA launched an investigation into the processor. Firstly, the DPA found that the processor should have deleted the users' data at the end of the contractual relationship with the controller. Failing to do so, even if the data were retained as a result of an unauthorised copy created by its employees, the DPA found a violation of Article 28(3)(g) GDPR. Secondly, the DPA found that the processor used the data for the development and testing of its own system, contrary to the contract stipulations between the processor and the controller. Therefore, the DPA found that the processing fell outside the limits of the contract, constituting a breach of Article 29 GDPR. Finally, the DPA found the processor in breach of Article 30 GDPR by failing to keep a record of the processing activities it carried out and for failing to provide the name and contact details of the data protection officer of the controller. Therefore, the DPA fined the processor €1,000,000 for violations of Article 28 GDPR, Article 29 GDPR, and Article 30 GDPR.

GDPR Articles Cited

AI-verified

Art. 29 GDPR
Art. 30 GDPR
Art. 28(3)(g) GDPR
View original scraped data
Art. 28 GDPR
Art. 29 GDPR
Art. 30 GDPR

Original data from scraper before AI verification against source document.

Source verified 6 March 2026
verified correct
Full Legal Summary

DEEZER (the controller) notified the French DPA (CNIL) of a data breach affecting approximately 46,900,000 users worldwide, out if which 21,574,775 users located in the European Union and 9,849,354 users from France. The controller identified Mobius Solutions Ltd (the processor) as the likely source of the data breach. The DPA launched an investigation into the processor. Firstly, the DPA found that the processor should have deleted the users' data at the end of the contractual relationship with the controller. Failing to do so, even if the data were retained as a result of an unauthorised copy created by its employees, the DPA found a violation of Article 28(3)(g) GDPR. Secondly, the DPA found that the processor used the data for the development and testing of its own system, contrary to the contract stipulations between the processor and the controller. Therefore, the DPA found that the processing fell outside the limits of the contract, constituting a breach of Article 29 GDPR. Finally, the DPA found the processor in breach of Article 30 GDPR by failing to keep a record of the processing activities it carried out and for failing to provide the name and contact details of the data protection officer of the controller. Therefore, the DPA fined the processor €1,000,000 for violations of Article 28 GDPR, Article 29 GDPR, and Article 30 GDPR.

Related Enforcement Actions (0)

No other enforcement actions found for Mobius Solutions Ltd in FR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

11 December 2025

Authority

Commission Nationale de l'Informatique et des Libertés

Fine Amount

€1,000,000

Enforcement Tracker ID

ETid-2995

GDPRhub ID

gdprhub-9718

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Mobius Solutions Ltd - France (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: