TL;DR for the DPO
On January 13, 2026, the CNIL fined Free Mobile 27M and Free SAS 15M (total 42M EUR) for a 2024 data breach exposing 24 million subscribers. Charges: insufficient technical measures (Art. 32), incomplete communication to data subjects (Art. 34), excessive data retention. For Italian DPOs: data breach communication to subjects must include ALL Art. 34(2) information - it cannot be generic.
What happened
In October 2024, an attacker infiltrated the information system of Free Mobile and Free SAS, accessing the personal data of approximately 24 million subscribers. Exposed data included: first and last name, address, email address, phone number, date of birth, and for subscribers to both services also the IBAN.
The breach was the subject of over 2,500 complaints by data subjects to the CNIL. The Authority launched an inspection that revealed GDPR violations attributable to both companies, each as data controller for its own subscribers.
Violations identified
The CNIL identified three distinct issues, each relevant to working DPOs:
- Art. 32 GDPR violation: insufficiency of technical and organizational security measures. Operator passwords were not adequately protected, granular access controls on systems hosting sensitive data were missing
- Art. 34 GDPR violation: communication to data subjects was sent by email, but the content did not include all the information required by paragraph 2 of the article: nature of the breach, personal data involved, possible consequences, measures taken or proposed to mitigate effects
- Art. 5(1)(e) and Art. 5(2) GDPR violation: excessive retention of former subscriber data, beyond the period necessary for accounting purposes. Free Mobile had not implemented automatic purging procedures
The critical point for the DPO
Art. 34(2) GDPR specifies what data subject communication MUST contain: (a) plain language description of the nature of the breach, (b) DPO name, (c) description of likely consequences, (d) description of measures taken or proposed. A communication saying only 'your personal data has been exposed' is not enough. The CNIL fined exactly this shortcoming.
Comparison with similar EU cases
The Free Mobile/Free case is part of a broader EU trend of data security enforcement. In 6 months:
- France: Free Mobile + Free 42M EUR (January 13, 2026)
- France: France Travail 5M EUR (January 22, 2026) - Art. 32 violation on 43 million job seeker data
- Italy: Intesa Sanpaolo 31.8M EUR (March 26, 2026) - late-handled data breach
- Ireland: TikTok 530M EUR (May 1, 2025) - extra-EU data transfer
The common message from European DPAs: Art. 32 GDPR is not a suggestion. 'Security appropriate to the risk' must be documented, tested, and updated. It's not enough to have 'planned' controls that were never implemented in production.
What to do in the next 30 days if you're DPO of a large-volume client
- Audit of access credentials to critical systems: password strength, rotation, MFA for privileged access
- Verify data breach communication procedure: use the Art. 34(2) template as a checklist (4 mandatory points)
- Test a simulated data breach exercise: time from identification to complete notification
- Retention policy review: former customer data must be deleted at the end of the necessary period, not 'when we find the time'
- Document the audit trail of these actions: in case of inspection, accountability is demonstrated with logs, not with good intentions
The 4 mandatory information items in the data breach communication to subjects
Art. 34(2) GDPR template
(1) Description of the nature of the breach (e.g., 'unauthorized access to a database containing your name, email, phone number'). (2) Name and contact of the DPO (e.g., 'dpo@ourcompany.com'). (3) Description of likely consequences (e.g., 'risk of phishing, aggressive telemarketing, possible fraudulent use of data'). (4) Description of measures taken or proposed (e.g., 'we have reset passwords, activated monitoring, and recommend that you...').
In DPO Workspace
In the client's Data Breach section, the subject communication module is structured around the 4 mandatory points of Art. 34(2): you cannot send the communication if fields are missing. This way you avoid Free Mobile's mistake.
Additional resources
- CNIL Free Mobile decision (in French, DeepL translation recommended)
- EDPB Guidelines 01/2021 on data breach notification examples
- Italian DPA Decision 230/2021 on data breaches in Italy
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free