All news
Enforcement January 13, 2026 7 min

CNIL fines Free Mobile and Free 42 million euros: 24 million customer data breach

January 13, 2026 decision: violations of Art. 32 GDPR on data security and Art. 34 on notification to data subjects

TL;DR for the DPO

On January 13, 2026, the CNIL fined Free Mobile 27M and Free SAS 15M (total 42M EUR) for a 2024 data breach exposing 24 million subscribers. Charges: insufficient technical measures (Art. 32), incomplete communication to data subjects (Art. 34), excessive data retention. For Italian DPOs: data breach communication to subjects must include ALL Art. 34(2) information - it cannot be generic.

What happened

In October 2024, an attacker infiltrated the information system of Free Mobile and Free SAS, accessing the personal data of approximately 24 million subscribers. Exposed data included: first and last name, address, email address, phone number, date of birth, and for subscribers to both services also the IBAN.

The breach was the subject of over 2,500 complaints by data subjects to the CNIL. The Authority launched an inspection that revealed GDPR violations attributable to both companies, each as data controller for its own subscribers.

24M
Affected subscribers
2,500+
Complaints to CNIL
42MEUR
Total fine

Violations identified

The CNIL identified three distinct issues, each relevant to working DPOs:

  • Art. 32 GDPR violation: insufficiency of technical and organizational security measures. Operator passwords were not adequately protected, granular access controls on systems hosting sensitive data were missing
  • Art. 34 GDPR violation: communication to data subjects was sent by email, but the content did not include all the information required by paragraph 2 of the article: nature of the breach, personal data involved, possible consequences, measures taken or proposed to mitigate effects
  • Art. 5(1)(e) and Art. 5(2) GDPR violation: excessive retention of former subscriber data, beyond the period necessary for accounting purposes. Free Mobile had not implemented automatic purging procedures

The critical point for the DPO

Art. 34(2) GDPR specifies what data subject communication MUST contain: (a) plain language description of the nature of the breach, (b) DPO name, (c) description of likely consequences, (d) description of measures taken or proposed. A communication saying only 'your personal data has been exposed' is not enough. The CNIL fined exactly this shortcoming.

Comparison with similar EU cases

The Free Mobile/Free case is part of a broader EU trend of data security enforcement. In 6 months:

  • France: Free Mobile + Free 42M EUR (January 13, 2026)
  • France: France Travail 5M EUR (January 22, 2026) - Art. 32 violation on 43 million job seeker data
  • Italy: Intesa Sanpaolo 31.8M EUR (March 26, 2026) - late-handled data breach
  • Ireland: TikTok 530M EUR (May 1, 2025) - extra-EU data transfer

The common message from European DPAs: Art. 32 GDPR is not a suggestion. 'Security appropriate to the risk' must be documented, tested, and updated. It's not enough to have 'planned' controls that were never implemented in production.

What to do in the next 30 days if you're DPO of a large-volume client

  • Audit of access credentials to critical systems: password strength, rotation, MFA for privileged access
  • Verify data breach communication procedure: use the Art. 34(2) template as a checklist (4 mandatory points)
  • Test a simulated data breach exercise: time from identification to complete notification
  • Retention policy review: former customer data must be deleted at the end of the necessary period, not 'when we find the time'
  • Document the audit trail of these actions: in case of inspection, accountability is demonstrated with logs, not with good intentions

The 4 mandatory information items in the data breach communication to subjects

Art. 34(2) GDPR template

(1) Description of the nature of the breach (e.g., 'unauthorized access to a database containing your name, email, phone number'). (2) Name and contact of the DPO (e.g., 'dpo@ourcompany.com'). (3) Description of likely consequences (e.g., 'risk of phishing, aggressive telemarketing, possible fraudulent use of data'). (4) Description of measures taken or proposed (e.g., 'we have reset passwords, activated monitoring, and recommend that you...').

In DPO Workspace

In the client's Data Breach section, the subject communication module is structured around the 4 mandatory points of Art. 34(2): you cannot send the communication if fields are missing. This way you avoid Free Mobile's mistake.

Additional resources

  • CNIL Free Mobile decision (in French, DeepL translation recommended)
  • EDPB Guidelines 01/2021 on data breach notification examples
  • Italian DPA Decision 230/2021 on data breaches in Italy
Official source:CNIL Decision January 13, 2026 - Free Mobile and Free

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min