Free – €15,000,000 Fine (France, 2026)

€15,000,000Commission Nationale de l'Informatique et des Libertés8 January 2026France
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Free is a landline telephone operator (the controller) in France. A data breach took place in 2024 affecting two companies – Free Mobile, a mobile phone operator from the same group, and the controller. The data breach affected over 7 million among the controller’s subscribers. Following the breach, the controller notified the DPA and informed the affected subscribers of the incident. Subsequently, the DPA launched an investigation into the controller. Firstly, the DPA found that the controller failed to put in place sufficient security measures for the authentication of users to its Virtual Private Network (VPN), thus allowing a malicious actor to connect to it. Moreover, the DPA noted that the mechanism in place for detecting abnormal activity in the system was inadequate. Therefore, the DPA found a violation of Article 32 GDPR. Secondly, the DPA found that the controller violated Article 34 GDPR by failing to provide all the necessary information regarding the breach to the data subjects. Therefore, the DPA fined the controller €15,000,000 for breaches of Article 32 GDPR and Article 34 GDPR. In addition, the DPA issued an order for the controller to bring its activities into compliance with the GDPR at the risk of a penalty payment of €25,000 per day if failing to comply with the order.

GDPR Articles Cited

Art. 32(GDPR)
Art. 34(GDPR)
Full Legal Summary

Free is a landline telephone operator (the controller) in France. A data breach took place in 2024 affecting two companies – Free Mobile, a mobile phone operator from the same group, and the controller. The data breach affected over 7 million among the controller’s subscribers. Following the breach, the controller notified the DPA and informed the affected subscribers of the incident. Subsequently, the DPA launched an investigation into the controller. Firstly, the DPA found that the controller failed to put in place sufficient security measures for the authentication of users to its Virtual Private Network (VPN), thus allowing a malicious actor to connect to it. Moreover, the DPA noted that the mechanism in place for detecting abnormal activity in the system was inadequate. Therefore, the DPA found a violation of Article 32 GDPR. Secondly, the DPA found that the controller violated Article 34 GDPR by failing to provide all the necessary information regarding the breach to the data subjects. Therefore, the DPA fined the controller €15,000,000 for breaches of Article 32 GDPR and Article 34 GDPR. In addition, the DPA issued an order for the controller to bring its activities into compliance with the GDPR at the risk of a penalty payment of €25,000 per day if failing to comply with the order.

Details

Fine Date

8 January 2026

Authority

Commission Nationale de l'Informatique et des Libertés

Fine Amount

€15,000,000

Enforcement Tracker ID

ETid-2994

GDPRhub ID

gdprhub-9739

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Free - France (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: