French Data Protection Authority (CNIL) · 8 January 2026
FREE MOBILE
Insufficient technical and organisational measures to ensure information security
- Regulator
- French Data Protection Authority (CNIL)
- Decided
- 8 January 2026
- Country
- France
- Sector
- Media, Telecoms and Broadcasting
- Regulator’s reference
- Not recorded
- Fino case number
- 2026/FR/003
What happened
The DPA fined a telecommunications company €27,000,000 for failing to ensure the security of personal data enabling a successful infiltration of its IT-system. Further, the DPA held that the controller failed to provide the affected data subjects with sufficient information regarding the data breach.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(e)Read →
- Art. 32Security of processingRead →
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/FR/003.