CNIL Hits Free and Free Mobile with €42 Million GDPR Fine After Major Data Breach
- Author: Arno Schlösser, DP-Dock GmbH
- Last updated: February 2026
- Category: Enforcement, Data Security, General Obligations
France's data protection authority (CNIL) has imposed significant fines totalling €42 million on Free Mobile (€27 million) and its parent company Free (€15 million) following a massive data breach that exposed millions of customers' personal information.
The CNIL's restricted committee found that both companies failed to implement appropriate security measures (TOMs) to protect subscriber data, including robust authentication and effective detection of unusual activity on internal systems.
The breach occurred in October 2024, when an attacker accessed the companies' systems and obtained personal data from approximately 24 million subscriber contracts, including data of "highly" personal nature. Furthermore, data which could pose a high risk for individuals was affected (IBAN).
In addition to weak security, the CNIL found that the companies did not meet GDPR standards in their communication with affected individuals, as the notification emails lacked essential information about the breach's consequences and protective measures. The regulator also noted that Free Mobile had retained data well beyond what was necessary, failing to delete outdated personal information in line with GDPR requirements.
Importantly, the decision requires the companies to complete ongoing security improvements within a set timeframe, reinforcing that compliance goes beyond financial penalties and requires organizations to embed strong data protection practices into their day-to-day operations. For more information: Data breach: FREE MOBILE and FREE fined €42 million | CNIL.
If you feel the need to improve the technical and organizational measures within your corporation, please feel free to reach out to us to receive specific guidance under the GDPR: service@dp-dock.com.