CNIL (France) - SAN-2026-002
| CNIL - SAN-2026-002 | |
|---|---|
| Authority: | CNIL (France) |
| Jurisdiction: | France |
| Relevant Law: | Article 32 GDPR Article 34 GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | |
| Decided: | 08.01.2026 |
| Published: | |
| Fine: | 15,000,000 EUR |
| Parties: | Free |
| National Case Number/Name: | SAN-2026-002 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | French |
| Original Source: | Legifrance (in FR) |
| Initial Contributor: | dt |
The DPA issued a €15,000,000 fine to a landline telephone provider for insufficient security measures and for failing to provide all necessary information to data subjects following a data breach affecting 7 million data subjects.
English Summary
Facts
Free is a landline telephone operator (the controller) in France.
A data breach took place in 2024 affecting two companies – Free Mobile, a mobile phone operator from the same group, and the controller. The data breach affected over 7 million among the controller’s subscribers.
Following the breach, the controller notified the DPA and informed the affected subscribers of the incident. Subsequently, the DPA launched an investigation into the controller.
Holding
Firstly, the DPA found that the controller failed to put in place sufficient security measures for the authentication of users to its Virtual Private Network (VPN), thus allowing a malicious actor to connect to it. Moreover, the DPA noted that the mechanism in place for detecting abnormal activity in the system was inadequate. Therefore, the DPA found a violation of Article 32 GDPR.
Secondly, the DPA found that the controller violated Article 34 GDPR by failing to provide all the necessary information regarding the breach to the data subjects.
Therefore, the DPA fined the controller €15,000,000 for breaches of Article 32 GDPR and Article 34 GDPR. In addition, the DPA issued an order for the controller to bring its activities into compliance with the GDPR at the risk of a penalty payment of €25,000 per day if failing to comply with the order.
Comment
This decision concerns the data breach that affected the company Free Mobile of the same group, which led to a €27,000,000 fine for Free Mobile in CNIL decision SAN-2026-001.
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the French original. Please refer to the French original for more details.
Decision SAN-2026-002 of January 8, 2026
National Commission for Information Technology and Civil Liberties
Nature of the decision: Sanction
Legal status: In force
Date of publication on Légifrance: Wednesday, January 14, 2026
Decision of the restricted panel No. SAN-2026-002 of January 8, 2026, imposing a financial penalty on the company FREE
- The sections of the decision containing personal data or secrets protected by law are replaced by the symbol […] -
The National Commission for Information Technology and Civil Liberties, meeting in its restricted panel composed of Mr. Philippe-Pierre CABOURDIN, Chairman, Mr. Vincent LESCLOUS, Vice-Chairman, Ms. Laurence FRANCESCHINI and Ms. Isabelle LATOURNARIE-WILLEMS, Mr. KLING, Members,
Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data;
Having regard to Law No. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties, in particular Articles 20 et seq.;
Having regard to Decree No. 2019-536 of 29 May 2019 implementing Law No. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties;
Having regard to Resolution No. 2013-175 of 4 July 2013 adopting the Rules of Procedure of the National Commission for Information Technology and Civil Liberties;
Having regard to Constitutional Council Decision No. 2025-1154 QPC of August 8, 2025;
Having regard to Decision No. 2024-205C of November 6, 2024, by the President of the National Commission for Information Technology and Civil Liberties (CNIL) instructing the Secretary General to conduct or have conducted an audit;
Having regard to the decision of the President of the CNIL appointing a rapporteur to the restricted panel on July 24, 2025;
Having regard to the report of Mr. Tarissan, rapporteur, notified to the company on July 25, 2025;
Having regard to the written observations of FREE received on September 15, 2025;
Having regard to the rapporteur's response notified to FREE on October 15, 2025;
Having regard to the written observations of FREE received on November 17, 2025;
Having regard to the closure of the investigation notified to FREE on November 18, 2025;
Having regard to the request for a closed hearing made on September 15, 2025, and refused on December 3, 2025;
Having regard to the oral observations made during the hearing of the restricted panel on December 15, 2025;
Having regard to the written submission filed by the company on December 19, 2025;
Having regard to the other documents in the file,
The following were present at the hearing of the restricted panel on December 15, 2025:
- Mr. Tarissan, Commissioner, who presented his report;
As representatives of FREE:
- […]
The presiding judge, having verified the identity of the defendant's representatives, outlined the proceedings and reminded the defendant that he or she might, if he or she wished, present introductory oral observations or answers to questions from the members of the restricted panel.
FREE, having been informed of its right to remain silent regarding the allegations against it, was given the last word.
After deliberation, the following decision was adopted:
I. Facts and Procedure
1. The ILIAD Group, specializing in telecommunications in Europe, has more than 50.2 million subscribers. The French company ILIAD is the parent company of the group of the same name. It wholly owns FREE (hereinafter "the Company"), which operates as a fixed-line telephone operator and had approximately 7.6 million fixed-line subscribers as of December 31, 2024. In 2024, ILIAD's revenue was €10.024 billion, with a net profit of €367 million.
2. On October 21, 2024, FREE was alerted by an attacker who had infiltrated FREE MOBILE's information system to a breach of subscriber data belonging to both companies. Following this alert, FREE conducted investigations that confirmed the occurrence of a data breach (hereinafter "the data breach in question"). This breach lasted from September 28 to October 22, 2024.
3. Through its subsidiary FREE MOBILE, FREE notified the French Data Protection Authority (CNIL) of this data breach on October 23, 2024, and supplemented this notification on November 5, 2024. Furthermore, it informed the affected individuals of the data breach by email, staggered between October 24 and 29, 2024, to avoid overloading its email servers.
4. As of the date of notification of the sanction report, the CNIL had received 2,614 complaints from individuals affected by this data breach.
5. By Decision No. 2024-205C of November 6, 2024, the Chair of the Commission instructed the Secretary General to conduct or have conducted an audit to verify compliance with Law No. 78-17 of January 6, 1978, as amended, concerning information technology, data files and civil liberties (hereinafter "the French Data Protection Act" or "LIL") and Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter "the GDPR" or "the Regulation"), of all data processing carried out by the companies FREE and FREE MOBILE.
6. Pursuant to this Decision, on November 8, 2024, a delegation conducted an on-site audit at the premises of the companies FREE and FREE MOBILE located at 16 rue de la Ville L’Évêque in Paris (75008).
7. For the purpose of examining these elements, the Chair of the Commission appointed Mr. Fabien TARISSAN as rapporteur on February 17, 2025, pursuant to Article 39 of Decree No. 2019-536 of May 29, 2019, implementing the French Data Protection Act.
8. On July 24, 2025, the Chair of the Commission decided to separate the sanction proceedings initially initiated against the two companies in order to pursue them through distinct procedures. To ensure all necessary steps are taken in the sanction proceedings against FREE, the Chair of the CNIL appointed Mr. Fabien TARISSAN as rapporteur. FREE and FREE MOBILE were informed on July 24, 2025, that they would now each be prosecuted through separate sanction proceedings.
9. Following his investigation, the rapporteur notified FREE on July 25, 2025, of a report detailing the breaches of Articles 32 and 34 of the GDPR that he considered to have occurred in this case. This report recommended that the restricted panel impose an administrative fine on the company and an injunction, with a penalty payment, to bring its data processing into compliance with the provisions of Article 32 of the GDPR. It also recommended that this decision be made public.
10. On September 15, 2025, the company submitted observations in response to the sanction report.
11. The rapporteur responded to the company's observations on October 15, 2025.
12. On November 17, 2025, the company submitted its second set of observations in response.
13. By letter dated November 18, 2025, the rapporteur, pursuant to paragraph III of Article 40 of Decree No. 2019-536 cited above, informed the company and the chair of the restricted panel that the investigation was closed.
14. By letter dated November 18, 2025, the company was informed that the case had been placed on the agenda for the restricted panel meeting of December 4, 2025.
15. On November 18, 2025, the company, through its counsel, requested a postponement of the restricted panel meeting. On November 25, 2025, the chair of the restricted panel granted this request for postponement and informed the company that the matter would be placed on the agenda for the hearing of December 15, 2025.
16. On December 3, 2025, the chair of the restricted panel rejected the company's request for a closed hearing, as stated in its observations of September 15, 2025. He noted that the procedure before the restricted panel was conducted in writing and that if the company did not wish to disclose potentially prejudicial information to third parties, it could refer to its written observations and appendices during the hearing.
17. The rapporteur and the company presented oral submissions during the hearing of the restricted panel.
II. The Data Breach in Question
18. The investigation conducted by FREE, following the alert received on October 21, 2024, revealed that the attacker first connected to FREE MOBILE's virtual private network (hereinafter "VPN") […].
19. The attacker then connected to FREE MOBILE's subscriber management tool […]. This tool allows access to data in both FREE MOBILE's mobile subscriber database and FREE's fixed-line subscriber database when customers are considered "convergent" (i.e., when a customer is a subscriber of both FREE MOBILE and FREE). The attacker was thus able to access personal data in FREE's "fixed-line" database (data related to the FREE contract, including the IBAN).
20. From October 6, 2024, the attacker exfiltrated a total of data relating to 24,633,469 fixed and mobile contracts, including 5,172,577 fixed contracts held by the company FREE.
III. Grounds for the decision
A. On the data processing responsibility of the company FREE
21. Pursuant to Article 4(7) of the GDPR, the data controller is "the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data."
22. In his report, the rapporteur emphasizes that the delegation was informed during the audit that, as part of its fixed-line telephone operator activities, FREE maintains its own fixed-line subscriber database, which it populates with its own customers' data (identity details, contact information, contract-related data, including IBANs) and manages using its customer management tool called "SIEBEL". FREE and FREE MOBILE informed the delegation that they are each responsible for the data processing related to the management of their respective customers, which is consistent with what is recorded in their registers. The rapporteur did not challenge this legal classification in the context of these proceedings.
23. The company does not dispute being responsible for the data processing related to the management of its own customers. However, it criticizes the rapporteur for indiscriminately attributing breaches to both FREE and FREE MOBILE, based on the same findings, without taking into account their respective data processing activities and responsibilities.
24. The restricted panel notes, as a preliminary matter, that the data breach affected both the information systems of FREE and FREE MOBILE, subsidiaries of the same group. During the CNIL's inspection of both companies, they were partly represented by the same individuals (in particular, the president and the network manager). It was observed that certain security measures were common to both companies [...].
25. Following its investigation, the rapporteur concluded, as did the two companies, that each implements data processing related to the management of its own subscribers, using its own tools, for which each is the data controller. Based on the evidence in the case file, the restricted panel shares this view.
26. The restricted panel observes that, given the specific responsibilities of each of the two companies, the Chair of the Commission decided on 24 July 2025 to initiate two separate sanction proceedings against FREE and FREE MOBILE. Thus, each company is responsible for the obligations relating to its own information system.
27. The restricted panel notes that the sanction report against FREE identifies alleged breaches by the company with regard to the processing of mobile subscriber management data for which it is solely responsible (hereinafter referred to as "the processing in question"). It is for the restricted panel to examine whether the alleged breaches are substantiated and attributable to FREE, in accordance with the principle of individual responsibility.
28. The restricted panel reiterates that it does not intend to rule on the occurrence of the data breach itself, but rather on determining whether or not the company failed to meet its obligations of due diligence under the GDPR, in its capacity as data controller.
29. Consequently, the restricted panel rejects the company's argument that the rapporteur indiscriminately attributes breaches to both FREE and FREE MOBILE based on the same findings, without taking into account their respective individual responsibilities.
B. On the failure to comply with the obligation to ensure data security pursuant to Article 32 of the GDPR
30. Article 32(1) of the GDPR provides that "taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing and the risks, of varying likelihood and severity, to the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia, as appropriate:
(a) the pseudonymisation and encryption of personal data;
(b) means to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
(c) means to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;
(d) a procedure for testing, to regularly analyze and evaluate the effectiveness of the technical and organizational measures to ensure the security of the processing […].
31. Article 32(2) of the GDPR provides that "when assessing the appropriate level of security, particular account shall be taken of the risks presented by the processing, in particular those arising from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed."
1. The scope of the security obligation under Article 32 of the GDPR and the predictability of the applicable legal framework
32. The company argues that the security obligation under Article 32 of the GDPR is an obligation of means and not of result, so that the occurrence of a data breach is not sufficient to constitute a breach of this article.
33. Furthermore, the company considers that, given the non-prescriptive nature of Article 32 of the GDPR and the binding nature of the guidelines and recommendations of the CNIL and ANSSI, the restricted panel cannot establish a breach of Article 32 of the GDPR based on soft law instruments without violating the principle of legality of offenses and penalties, which requires that the disregarded rule be sufficiently clear and foreseeable in its application. It adds that it has not been able to benefit from precedents that would have allowed it to assess the nature of the measures expected, as it would be the first organization, the victim of an external malicious act, to be subject to a CNIL sanction procedure based on Article 32 of the GDPR.
34. First, the restricted panel reiterates that the security obligation laid down in Article 32 of the GDPR is indeed an obligation of means, requiring the data controller to take measures which, in light of the characteristics of the processing in question, both reduce the likelihood of a data breach and, where appropriate, mitigate its severity. It is therefore not expected that security measures will eliminate all risk, and the mere occurrence of a data breach does not in itself constitute a breach of Article 32 of the GDPR.
35. This analysis was confirmed by the CJEU in its judgment in "National Revenue Agency of Bulgaria" (14 December 2023, C/2024/1065, paragraphs 29 to 31). The restricted panel notes that, in this judgment, the CJEU held that "the reference in Article 32, paragraphs 1 and 2, of the GDPR to 'a level of security appropriate to the risk' and to an 'appropriate level of security' demonstrates that this regulation establishes a risk management regime and in no way aims to eliminate the risks of personal data breaches. Thus, it is clear from the wording of Articles 24 and 32 of the GDPR that these provisions merely require the data controller to adopt technical and organizational measures designed to prevent, as far as possible, any personal data breach. The appropriateness of such measures must be assessed concretely, by examining whether these measures have been implemented by the controller taking into account the various criteria referred to in those articles and the data protection needs specifically inherent in the processing concerned, as well as the risks it entails. Consequently, Articles 24 and 32 of the GDPR cannot be interpreted as This means that an unauthorized disclosure of personal data or unauthorized access to such data by a third party is sufficient to conclude that the measures adopted by the data controller concerned were not appropriate within the meaning of those provisions, without even allowing the latter to provide evidence to the contrary.
36. The CJEU more recently reiterated that "this literal interpretation is corroborated by a combined reading of Articles 24 and 32 with Article 5(2) and Article 82 of that Regulation, read in the light of recitals 74, 76 and 83 thereof, from which it follows, in particular, that the data controller is required to mitigate the risks of personal data breaches, and not to prevent any breach of such data" (25 January 2024, C-687/21, paragraph 39).
37. Therefore, a breach of the security obligation can be established regardless of whether a personal data breach has occurred.
38. The restricted panel reiterates that it can sanction not the occurrence of a data breach itself, but rather the fact that it was made possible or facilitated by the absence or inadequacy of security measures implemented by a data controller, taking into account the state of the art. In this regard, it has already, on several occasions, found a breach of Article 32 of the GDPR, given the absence or inadequacy of the security measures deployed which was exploited by an attacker in the context of a personal data breach (deliberation no. SAN-2021-020 of 28 December 2021 § 61; deliberation of the restricted panel no. SAN-2020-014 of 7 December 2020 § 19; deliberation of the restricted panel no. SAN – 2019-005 of 28 May 2019 § 31; deliberation no. SAN-2018-011 of 19 December 2018). The restricted panel considers that, although the security measures referred to in these precedents differ from the present case, the fact remains that the company is not the first to be subject to a sanction procedure for a breach of Article 32 of the GDPR following a data breach and that it is responsible for the security measures it deploys to ensure the protection of the data it processes.
39. Regarding the assessment of the data controller's obligation to take reasonable steps, the CJEU considers that "the appropriateness of such technical and organizational measures must be assessed in two stages. First, the risks of personal data breaches arising from the processing in question and their potential consequences for the rights and freedoms of natural persons must be identified. This assessment must be carried out in a concrete manner, taking into account the likelihood and severity of the identified risks. Second, it must be verified whether the measures implemented by the data controller are appropriate to those risks, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing" (14 December 2023, C-340/21, paragraph 42).
40. Consequently, the restricted panel does not intend to sanction the data breach itself, but rather to determine whether, taking into account the state of the art, the characteristics of the processing, the likelihood and severity of the risks, and the scope of the security obligation specified above, FREE complied with its obligations under Article 32 of the GDPR by implementing appropriate technical and organizational measures.
41. Secondly, the restricted panel notes that the principle of legality of offenses and penalties, reiterated by the Constitutional Council in matters of administrative sanctions (Decision No. 88248 DC, January 17, 1989), requires that the obligations and penalties in the event of a breach be defined in advance.
42. The Council of State has clarified the scope of this principle, which implies that the constituent elements of offences must be defined precisely and completely (CE, 9 October 1996, Société Prigest, No. 170363, T.; CE, Section, 12 October 2009, M. P., No. 311641, Rec.). Regarding administrative sanctions, case law considers that "the requirement for a definition of the sanctioned offenses is satisfied […] as soon as the applicable texts refer to the obligations to which the individuals concerned are subject by virtue of the activity they carry out, the profession to which they belong, the institution to which they are attached, or their status" and that a sanction may be imposed if it is "reasonably foreseeable by the persons concerned, taking into account their status and the responsibilities they exercise, that the conduct in question constitutes a breach of these obligations" (French Council of State, October 3, 2018, SFCM, No. 411050, Rec.).
43. In this case, the restricted panel notes that, in its written submissions, the rapporteur focuses in particular on characterizing the company's breach of the obligations set out in Article 32 of the GDPR, as clarified by numerous recommendations from the CNIL (French Data Protection Authority) and the ANSSI (French National Cybersecurity Agency), which are publicly available and predate the alleged breaches.
44. The restricted panel reiterates that, while the recommendations of the Commission and the ANSSI are not legally binding, they clarify and illustrate the applicable legislative and regulatory provisions and provide stakeholders with guidance on the concrete, state-of-the-art measures to be implemented.
45. While a data controller can be sanctioned solely on the basis of the obligations set out in Article 32 of the GDPR, the French Council of State has nevertheless confirmed on several occasions that the restricted panel of the CNIL (French Data Protection Authority) can find a breach of Article 32 of the GDPR, characterized in light of its own recommendations (French Council of State, 11 March 2015, Société Total Raffinage Marketing, Nos. 368748 and 368819, para. 4; French Council of State, 30 April 2024, Commune de Beaucaire, No. 472864, para. 11).
46. Consequently, the restricted panel notes that the company holds a significant position in the French telecommunications sector and, as such, processes the data of millions of subscribers. It considers that the company has the material, human, and technical resources necessary to ensure its compliance and, where appropriate, to adapt its practices to meet its obligations under Article 32 of the GDPR, as clarified by the various security recommendations issued by the CNIL and ANSSI for many years.
47. It follows from the above that, since the elements constituting the breach of Article 32 of the GDPR alleged against the company are precisely and comprehensively defined, it cannot be validly argued that imposing a sanction would violate the principle of legality of offenses and penalties.
48. The restricted panel therefore dismisses the complaint based on a violation of the principle of legality of offenses and penalties.
2. On the risks of processing for data subjects
The rapporteur notes that the company must ensure a level of security for the personal data it processes, assessed in light of the risks associated with its disclosure and unauthorized access, taking into account the potential consequences for the data subjects. In this case, he emphasizes the massive scale of the processing (data from approximately 7.6 million fixed-line subscribers), as well as the highly personal nature of certain data (bank details), which presents significant risks for the data subjects in the event of a breach of confidentiality (identity theft, phishing attempts, and fraudulent use of their bank details).
49. The company considers that the processing it implements does not present a high risk for the data subjects in the absence of sensitive data as defined in Article 9 of the GDPR.
50. Furthermore, it maintains that the compromise of IBANs does not pose a particular risk, since an IBAN alone cannot be used to carry out a fraudulent withdrawal and banking institutions have implemented mechanisms to prevent this (requirement to obtain a signed SEPA mandate before any withdrawal, time limits for disputes and refunds in case of fraud).
51. In addition, the company believes that the increase in data breaches does not allow the harm alleged by some complainants (phishing, etc.) to be attributed to the attack of which it was a victim, which in this context did not create any additional risk for the individuals concerned.
52. The restricted panel recalls that recital 75 of the GDPR addresses "risks to the rights and freedoms of natural persons, of varying likelihood and severity, which may result from the processing of personal data which are likely to cause physical, material or moral harm, in particular: where the processing may lead to […] theft or identity fraud, financial loss, […] or where the processing involves a large volume of personal data and affects a large number of data subjects."
53. The restricted panel notes that, according to recital 76 of the GDPR, "the likelihood and severity of the risk to the rights and freedoms of the data subject should be determined in light of the nature, scope, context and purposes of the processing. The risk should be subject to an objective assessment to determine whether the data processing operations entail a risk or a high risk."
54. Furthermore, recital 83 of the GDPR specifies that "in the context of the data security risk assessment, account should be taken of the risks presented by the processing of personal data, such as accidental or unlawful destruction, loss or alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed, which may result in physical, material or moral damage."
55. In this case, the restricted panel notes that, as of 31 December 2024, FREE had approximately 7.6 million fixed-line subscribers.
56. Furthermore, the restricted panel observes that FREE allows FREE MOBILE to access, via its customer management tool, the data it holds concerning customers it shares with FREE MOBILE (the aforementioned "convergent" customers), including their bank details.
57. Given its role as data controller with regard to the processing related to the management of fixed-line subscribers, the restricted panel considers that FREE is responsible for the security of the data contained in its fixed-line subscriber database, and therefore for FREE MOBILE's access to this data.
58. The restricted panel considers that the unauthorized access to or disclosure of the data processed by the company is likely to cause moral and material harm to the individuals concerned. Indeed, as noted by the company in its notifications to the CNIL (French Data Protection Authority), its users are exposed to risks related to the resale of their data to malicious actors, identity theft, and phishing attempts (a practice in which a malicious actor impersonates an organization known to the individual concerned in order, for example, to request their bank details). The restricted panel notes that the rapporteur demonstrates, in his written submissions, the existence of a risk of fraudulent payments using a stolen IBAN. In fact, a malicious individual, possessing a stolen IBAN, can make a fraudulent payment on a website that offers to validate the SEPA direct debit mandate via a simple checkbox.
59. Furthermore, the restricted panel considers the probability of unauthorized disclosure and access to the company's data materializing to be high, particularly given the increase in data breaches over the past several years, as acknowledged by the company itself. In addition, the probability of risks related to the malicious exploitation of this data (identity theft, phishing attempts, and fraudulent withdrawals) materializing in the event of a breach of confidentiality is also high. As noted by the Public Interest Group for Action Against Cybercrime, phishing is the predominant threat in France ("Cybermalveillance.gouv.fr unveils cyber threat trends in France," March 27, 2025).
60. In this regard, the restricted panel notes that a number of complainants reported to the Commission fraudulent use of their data following the data breach in question, including phishing attempts. While it is not possible to determine with certainty that the fraudsters obtained the complainants' data through the data breach in question, and not through a breach suffered by a third party with the same data, it is clear that the loss of confidentiality of the data processed by FREE contributed to increasing the volume of data available to potential attackers. The existence of other data breaches does not, in any case, relieve the company of its obligation to implement security measures appropriate to the risk of compromise of the data it processes.
61. The restricted panel considers that the security measures implemented by FREE should have been sufficient to address the risks described above.
3. On the level of security deployed by the company
62. ANSSI applies the principle of "defense in depth" to information systems, which consists of not basing security "on a single element but on a coherent whole. This means that, in theory, there should be no single point on which the entire structure rests," that is to say, any potential security vulnerability in a software component must be compensated by at least a second level of security (see the Memento on the concept of defense in depth applied to information systems, version 1.1 of July 19, 2004). ANSSI bases this concept on the premise that "any component of a system can fail or be compromised. This premise, which also applies to the security functions of an IS [information system], is regularly confirmed by current events regarding the vulnerabilities of numerous products and software" (see the white paper Hybrid Information System and Security: A Return to Reality, August 10, 2021).
63. In this case, the restricted panel will have to analyze whether the company has implemented a "coherent set" of security measures to protect its information system.
3.1 On the lack of security of the interconnection channel
64. In a digital context, it is possible for an employee to connect remotely (for example, from home) to their company's information system using their laptop. This is known as digital nomadism.
65. The French National Cybersecurity Agency (ANSSI) defines digital nomadism as "any form of use of information technologies allowing a user to access the IS [information system] of their organization or place of employment from remote locations, these locations not being controlled by the organization" (ANSSI, "Recommendations on Digital Nomadism", 2018).
66. In its aforementioned recommendations, it notes that workplaces not controlled by an entity expose it to heightened risks of loss or theft of equipment, equipment compromise (for example, during a temporary absence of the user), compromise of information contained in stolen, lost, or borrowed equipment, unauthorized access to the company's information system (and therefore its compromise), and interception or even alteration of information (loss of confidentiality or integrity).
67. Thus, ANSSI emphasizes that "in the context of mobile work, the objective is to achieve alignment with the security level of the entity's internal IS [information system], by addressing the higher exposure risks listed above."
68. It considers that entities must adopt mobile-specific measures in their information system security policies in order to reduce or mitigate the aforementioned risks.
69. It specifies that, in order to allow a user to access an internal information system from an uncontrolled network, it is necessary to implement a channel that establishes a secure link between the mobile device and the entity's internal information system, using VPN (Virtual Private Network) technology.
70. ANSSI reiterates that "depending on the authentication methods implemented on the mobile device, an attacker may attempt to impersonate the user or the mobile device itself." Therefore, "it is important to use robust authentication mechanisms for setting up the interconnection channel for a mobile device."
71. In a mobile work environment, ANSSI (the French National Cybersecurity Agency) considers that "three levels of authentication must be considered:
- authentication of the user on the mobile device;
- authentication of the mobile device on the information system;
- authentication of the user on the information system."
72. More specifically, regarding the authentication of the mobile device on the entity's information system, ANSSI reiterates that the objective is to ensure that the device used to access the information system is controlled by the entity in order to reduce the risks that would result from the use of uncontrolled mobile devices whose security level does not comply with the entity's security policy. It recommends "authenticating the mobile device to the information system using a machine certificate [i.e., a certificate linked to the mobile device and not to the mobile device user]" and "protecting the integrity and confidentiality of the private key of this certificate to ensure that it cannot be accessed by either the mobile user or an attacker."
73. Consequently, since 2018, ANSSI has recommended authenticating a user's mobile device to an information system using a machine certificate, which is linked to the mobile device and not to its user.
74. In its "Guide to Personal Data Security" of March 2024, the CNIL also recommends "prioritizing multi-factor authentication whenever possible, particularly when the connection is accessible from outside the organization's network."
75. It follows from the above that both ANSSI and CNIL recommend authenticating a user on an information system by implementing strong multi-factor authentication, particularly when the connection to the entity's information system is accessible from outside its network.
76. The rapporteur criticizes the company for failing to implement appropriate security measures to secure user access to the company's VPN, [...]. He considers these vulnerabilities to constitute a breach of Article 32 of the GDPR. He notes that the company began deploying these measures during the sanction procedure in order to achieve compliance.
77. In its defense, the company maintains that, at the time of the audit, it had implemented sufficiently robust security measures for authenticating users and their workstations when connecting to its VPN.
78. [...]
79. [...]
80. [...]
81. […]
82. […]
83. As a preliminary matter, the restricted panel reiterates that, in the context of digital nomadism, it is the responsibility of the data controller to implement measures to ensure that both the person connecting and the machine they are using have the necessary authorizations to connect to internal resources. These measures are in addition to those that must be in place when a person is already authenticated on the network, such as robust authentication mechanisms when accessing tools.
84. […]
85. The restricted panel reiterates that connecting to an entity's VPN from workstations that do not belong to its IT infrastructure presents a risk to its information system if it does not control the security measures implemented on these devices, which may therefore not correspond to the security level defined in its internal policy.
86. […]
87. […]
88. […]
89. […]
90. […]
91. […]
92. […]
93. […]
94. […]
3.2 On the Failure to Detect Abnormal Behavior
95. In its deliberation no. 2021-122 of October 14, 2021, adopting a recommendation on logging, the CNIL (French Data Protection Authority) reiterates that "the implementation of a logging system contributes to compliance with the obligation to secure all processing of personal data, pursuant to Articles 5 and 32 of the GDPR."
96. Thus, it recommends that organizations collect information on individuals administering or accessing their resources, such as the user ID, the date and time of access, and the identifier of the device used (CNIL, "CNIL publishes a recommendation on logging measures," November 18, 2021).
97. In its aforementioned recommendation, the CNIL reiterates that "this security is essentially 'active': it relies on real-time or short-term processing of this data to detect abnormal activity in order to prevent attacks or intrusions, or to quickly address a computer incident by facilitating the identification of the problem."
98. In its "Security Recommendations for the Architecture of a Logging System" of January 28, 2022, ANSSI also reiterates that "continuous analysis of event logs makes it possible to identify unusual activity, while archiving logs allows for subsequent verification. In this sense, logging is also an essential prerequisite for implementing a capability to detect, analyze, and respond to security incidents."
99. In other words, simply collecting log data is not enough to secure an information system. The logging system is only effective if an entity is able to process the information recorded in the logs in order to be able to quickly detect suspicious behavior, if necessary.
100. The Commission therefore recommends, in its aforementioned recommendation, "implementing a system for processing and analyzing the collected data and formalizing a process for generating and processing alerts in cases of suspected abnormal behavior. This data can also be used ex post when a data breach (in particular through unlawful access, transmission, or use of data) is detected and the data controller seeks to establish responsibility."
101. The European Data Protection Board also considers, in its Guidelines 9/2022 on the notification of personal data breaches under the GDPR, that "the ability to detect a breach, remedy it, and communicate it as soon as possible should be considered an essential element."
The rapporteur considers that, on the date of the audit, the security measures implemented by the company to detect suspicious activity on its SIEBEL customer management tool were insufficient, which made possible, or at the very least facilitated, the loss of confidentiality of millions of the company's subscribers' personal data between September 28 and October 22, 2024. He notes that the company did, however, bring itself into compliance on this point during the proceedings.
102. In its defense, the company maintains that, on the date of the audit, it implemented sufficiently robust measures to detect malicious behavior on its information system. It specifies that it had, in particular, deployed a log monitoring and analysis system, generating several activity reports for FREE's information system security manager. These reports included information on the SIEBEL tool users who accessed the most fixed-line subscriber data, in order to detect the use of bots or information concerning user activity outside of business hours.
103. It specifies that, as of October 28, 2024, following the data breach in question, it deployed additional measures aimed in particular at detecting suspicious activity on its SIEBEL tool in real time (number of unique subscribers accessed and volume of searches performed by users in one hour) and implemented automatic blocking in the event that certain thresholds were exceeded.
104. It adds that, during the course of the proceedings, it notably put into operation a security operations center to detect abnormal behavior on its SIEBEL tool more quickly, and dedicated an internal team to responding to security incidents.
105. The restricted panel notes that FREE authorizes FREE MOBILE to access the data contained in its fixed-line database concerning so-called "convergent" customers (customers of both FREE and FREE MOBILE). When a FREE MOBILE employee performs a search on a subscriber using FREE MOBILE's customer management tool, MOBO, they will query FREE's fixed-line database via the web service (a server that allows the return of results to a query) provided by FREE. The restricted panel observes that the returned response included the personal data of the subscriber in question held by FREE (specifically, their IBAN). The restricted panel observes that, due to a technical anomaly related to FREE MOBILE's MOBO tool, on the day of the data breach, the response returned the entire IBAN of the subscriber in question, contained in FREE's fixed-line database.
106. First, the restricted panel notes that, on the day of the data breach, the activities carried out on the company's SIEBEL tool were indeed logged, a fact which is not disputed by the rapporteur.
107. Second, [...].
108. The restricted panel notes that the activity logging system on the SIEBEL tool, as implemented on the day of the data breach, did not allow the company to detect certain abnormal situations.
109. By way of example, it observes that the attacker was able to access convergent customer data contained in the company's SIEBEL tool for almost a month without an alert being issued or, assuming an alert was indeed issued, without it being acted upon. As a result, the company was unaware of the unauthorized access to the data until the attacker himself informed it.
110. Again by way of example, the restricted panel notes that, on October 15, 2024, the attacker was able to exfiltrate data from approximately […] fixed-term contracts without this behavior triggering an alert or, assuming an alert was indeed issued, without it resulting in the account from which the requests originated being blocked.
111. The restricted panel considers that this massive data exfiltration could not have gone unnoticed and should have triggered an alert or, if an alert had been issued, should have triggered its analysis, which would have allowed the company to identify an abnormal situation and quickly take the necessary measures to ensure the protection of its information system.
112. The restricted panel therefore considers that the mechanism for detecting abnormal behavior on the SIEBEL tool was inadequate on the day of the data breach [...].
113. The restricted panel notes that it was only after the data breach that the company implemented a real-time detection mechanism [...], monitoring the number of unique subscribers accessed and the volume of searches performed by users of its business tool in order to automatically block users exceeding the established thresholds, if necessary. Furthermore, it notes that during the sanction procedure, the company established a security operations center, enabling a dedicated team to analyze the logs generated by the SIEBEL tool in real time.
114. Thirdly, assuming that the company was able to detect abnormal behavior on its business tool on the day of the data breach, the restricted panel notes that it had not implemented a mechanism to automatically block the user in question. The restricted panel notes that the SIEBEL tool generated activity reports for the CISO and that human intervention was required to verify whether suspicious behavior was abnormal and, if so, to take appropriate action. The restricted panel considers that these conditions were not suitable and that automatic blocking would have been an appropriate measure to complement the existing system.
115. The restricted panel notes that the company deployed automatic blocking measures following the data breach and subsequently deployed a security operations center tasked with analyzing SIEBEL-related logs in real time in order to take the necessary blocking measures as needed.
116. In light of all these elements, the restricted panel considers that, on the date of the inspection, the company had not deployed sufficient resources to be able to detect suspicious activity on its subscriber management tool, which constitutes a breach of Article 32 of the GDPR.
117. The restricted panel notes that the company took measures following the data breach to remedy the identified breach. It therefore considers that there is no need to issue a compliance order.
C. On the failure to notify data subjects of a personal data breach pursuant to Article 34 of the GDPR
118. In law, under Article 34(1) of the GDPR, "where a personal data breach is likely to result in a high risk to the rights and freedoms of a natural person, the controller shall communicate the personal data breach to the data subject without undue delay."
119. Paragraph 2 of the aforementioned article specifies the information that must be included in the content of this communication. It must contain a description of the nature of the data breach, the likely consequences of the personal data breach, and the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. Furthermore, it must provide the name and contact details of the data protection officer or other contact point from which additional information can be obtained.
120. Recital 86 of the GDPR specifies that this communication must "provide recommendations to the data subject to mitigate the potential adverse effects" since its objective is to enable data subjects to "take the necessary precautions".
121. The rapporteur considers that the company has breached Article 34 of the GDPR because the information email sent by the company to the data subjects affected by the breach fails to inform them about the remedial measures it has taken, the likely consequences of the data breach, or the measures they should take to protect themselves from the risks to which the breach exposes them.
122. In its defense, the company maintains that it complied with Article 34 of the GDPR.
123. First, regarding the form of the communication, the company indicates that it adopted a multi-layered approach. On the one hand, an email was sent to the individuals concerned between October 24 and 29, 2024, to provide them with an initial summary of information. The company specifies that it used a staggered approach to avoid overloading the individuals' email servers. On the other hand, a second level of information was provided to the individuals via a freephone number available 7 days a week, as mentioned in the initial information email, and through an internal request management system ("DPO ticket"). The company states that the toll-free number enabled it to answer 58,239 calls and that, thanks to the DPO ticket system, it was able to process 1,081 requests.
124. Regarding the substance of the communication, the company considers that the initial information email was complete with regard to the requirements of Article 34, paragraph 2, of the GDPR. It argues that the company informed individuals of the data breach in question, alerted them to the risks of fraudulent emails, text messages, or calls, reminded them that its advisors never ask for passwords verbally, and invited them, in the event of any unusual activity, to consult the official website cybermalveillance.gouv.fr to report it.
125. The company justifies sending a general alert message by stating that it could not anticipate all forms of future exploitation of the data breach.
126. More specifically, the company maintains that Article 34(2) of the GDPR, which refers to Article 33(3), did not require it to detail to the individuals concerned all the measures taken to end the data breach. It considers that a contrary position would create a risk of compromising the security of the information system concerned.
127. Finally, the company considers that the large number of complaints received by the CNIL (French Data Protection Authority) resulted from the exceptional media coverage of the data breach, in which the CNIL played a role. It maintains that the fraud and attempted fraud reported by some complainants are not attributable to a lack of information on its part, given that it took the necessary measures to raise awareness among its subscribers about the risks of fraud (in particular, by publishing a dedicated phishing help page, conducting an email awareness campaign, and implementing proactive monitoring of websites likely to conduct phishing campaigns targeting its subscribers).
128. The restricted panel reiterates that Article 34 of the GDPR requires a data controller who is the victim of a data breach to provide certain information to the data subjects when the data breach is likely to result in a high risk to their rights and freedoms.
129. The restricted panel also recalls that, as the European Data Protection Board (hereinafter "EDPB") emphasizes in its guidelines on the notification of personal data breaches under Regulation (EU) 2016/679 adopted on 28 March 2023, "the main objective [of Article 34 of the GDPR] is to help data subjects understand the nature of the breach and the measures they can take to protect themselves."
130. Thus, Article 34(2) of the GDPR provides that the communication to data subjects must describe the nature of the personal data breach and contain "at least" the information and measures referred to in Article 33(3)(b), (c) and (d). This information concerns "the name and contact details of the data protection officer or other contact point where further information can be obtained" (point b), a description of the "likely consequences of the personal data breach" (point c), and a description of the "measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects" (point d).
131. The restricted panel considers that it follows from the wording of paragraph 2 of Article 34 of the GDPR that the information listed above is that which must, at a minimum, be provided to the data subjects affected by a personal data breach when it is likely to result in a high risk to their rights and freedoms.
132. Therefore, this information must be provided directly to the data subjects as a first step in the notification process, as it is essential to achieving the objective of the communication: enabling them to understand the nature of the breach and the measures they can take to protect themselves.
133. Furthermore, the restricted panel observes that the obligation for a data controller to provide "the name and contact details of the data protection officer or other contact point," as provided for in Article 33(2)(b) of the GDPR, aims to provide data subjects with "additional information." The restricted panel considers that this information therefore complements the essential information that must be included in the first step of the notification process and cannot replace it.
134. In this regard, the restricted panel notes that, in its guidelines on the notification of personal data breaches pursuant to Regulation (EU) 2016/679 adopted on 28 March 2023, the EDPB recalls that "a controller may choose to provide additional information to that presented here [Article 33(3)(b), (c) and (d)] as necessary."
135. In other words, Article 34(2) of the GDPR, which refers to Article 33(3)(b), provides for the possibility of communicating with data subjects at two levels of information: a first mandatory level containing the essential information and a second level containing additional information that the controller wishes to bring to the data subjects' attention.
136. In the present case, the restricted panel notes, firstly, that the company sent the data subjects affected by the breach an initial information email, which constitutes the first level of information. The company has also set up a toll-free number, accessible 7 days a week, from 9 a.m. to 6 p.m., the contact details of which were provided in its initial email, as well as a "DPO ticket" system to answer individuals' further questions, which constitutes a second level of information.
137. The restricted panel considers that the form of communication provided to the data subjects complies with the requirements of Article 34(2) of the GDPR.
138. Secondly, the restricted panel notes that the email sent to the data subjects informed them that the company had been the victim of a cyberattack targeting its management tool, resulting in unauthorized access to some of the personal data associated with subscribers' accounts (their surname, first name, email address, postal address, date and place of birth, telephone number, subscriber ID, and contractual data). This email also stated that "all necessary measures were taken immediately to stop this attack and strengthen the protection of [its] information systems," that the data breach had been reported to the CNIL (French Data Protection Authority) and the ANSSI (French National Cybersecurity Agency), and that a complaint had also been filed with the public prosecutor. Furthermore, the company urged those affected "to be extremely vigilant against the risk of fraudulent emails, text messages, or calls," specified that its advisors would never ask for passwords verbally, and encouraged them, in case of suspicion or unusual activity, to contact the official digital victim support service on the website cybermalveillance.gouv.fr to report the incident. Finally, "for any questions or requests for information," the email stated that the company had a toll-free number available to those affected, accessible 7 days a week, from 9 a.m. to 6 p.m.
139. The restricted panel considers that, although the majority of essential information was contained in the initial information email and the method of communication allowed the persons concerned to access other essential information through the second level of information, it remains nonetheless true that certain important elements were not mentioned.
140. Regarding information on remediation measures, it is accepted that, in certain cases, security measures deployed by an organization must indeed remain confidential in order to avoid exposing its information system to the risk of further attacks. The restricted panel clarifies, however, that not all security measures implemented by an organization pose a risk to the security of an information system and therefore do not necessarily have to remain confidential.
141. The restricted panel observes that the company only informed the individuals affected by the data breach in question that "all necessary measures were taken immediately to stop this attack and strengthen the protection of our information systems," which, according to the restricted panel, constitutes a formulation that is too general and abstract to comply with Article 34(2) of the GDPR. Indeed, Article 33(3)(d), to which the aforementioned article refers, provides for an obligation to "describe" these measures.
142. The restricted panel therefore considers that, without jeopardizing its own information system or that of FREE MOBILE, FREE should have described, even briefly and in simple terms, the main corrective measures taken to address the data breach in question. The restricted panel reiterates that the purpose of this communication is to reassure the individuals concerned about the effective protection of their personal data.
143. The restricted panel notes that, in the initial notification made to the CNIL a few days before the communication to the individuals concerned, the company had indeed described these measures, in accordance with Article 33 of the GDPR (obligation to notify the Commission of the data breach). Without going into detail about these measures to ensure the communication to the individuals is clear, the restricted panel considers that the company should have indicated, in particular, that the compromised accounts had been revoked, the vulnerabilities related to its business tool had been corrected, and access to personal data had been strengthened. This information is understandable to the individuals concerned and is not likely to compromise the company's information system.
144. Regarding information on the likely consequences of the data breach in question and the measures to be taken to mitigate any potential negative consequences, the restricted panel notes that the company informed the individuals concerned: "We urge you to be extremely vigilant regarding the risk of fraudulent emails, text messages, or calls. Please be aware that our advisors will never ask for your passwords verbally. In case of suspicion or unusual activity, we encourage you to contact the official digital victim support service at: www.cybermalveillance.gouv.fr to report the incident and assert your rights."
145. The restricted panel considers this wording too vague to achieve the objective of helping the individuals concerned understand the main risks to which they are exposed, as well as the measures they can implement to protect themselves.
146. Indeed, on the one hand, the restricted panel considers that the individuals concerned are not given the opportunity to understand the context in which they might be contacted by email, SMS, or telephone, nor to understand the necessary precautions to take to protect themselves from negative consequences. The restricted panel observes that the company had, however, clearly identified in the question/answer scripts provided to call center agents that there was a risk scenario related to "fraud attempts impersonating Free or any other organization." The restricted panel notes that it had also identified recommendations to be given to the individuals (for example: never share personal information by email, SMS, or during a call; never open an email attachment if in doubt). The restricted panel considers that this information, identified on the day the informational email was sent, should have been provided in a concise manner to the individuals concerned.
147. Furthermore, the restricted panel considers that by focusing solely on the "risk of fraudulent emails, SMS messages, or calls," the company failed to communicate all the main risks to which the individuals affected by the breach are exposed. The company had, however, identified these risks in its initial notification to the CNIL (French Data Protection Authority), as well as in the question/answer scripts provided to the advisors answering the calls. For example, regarding the risk of identity theft, since individuals generally discover it only after the fact, the restricted panel believes that mentioning this risk, which could cause significant harm if it materializes, combined with a link to the dedicated page on the cybermalveillance.gouv.fr website, which provides information on the main warning signs, would have been more effective than a link to its homepage, given the density of information on that site, not all of which is relevant to the specific case. The advantage of such an approach is that it communicates about the risk and provides more detailed information without compromising the usability or readability of the information.
148. Furthermore, given that some subscribers' IBANs were affected by the data breach, the restricted panel considers that the company should have specifically warned of the risks of fraudulent use of bank details, reassured users that the banks had been informed, and advised those affected to regularly check their bank accounts and remain vigilant in the event of fraudulent calls from someone impersonating a bank advisor.
149. Thirdly, the restricted panel notes that the CNIL communication entitled "Massive Data Breaches in 2024: What are the Main Lessons Learned and Measures to Take?" dated January 28, 2025, mentioned data breaches by various data controllers, including the company. On the one hand, it considers that this communication did not increase the number of complaints, since by December 2024, the CNIL had already received the vast majority of the 2,614 complaints received by the date of notification of the report on July 25, 2025, which was a record number. On the other hand, the communication did not increase the number of complaints filed against the other data controllers mentioned.
150. It follows from the above that the initial information email did not constitute appropriate communication, since the information it contained did not allow the millions of people affected by the data breach in question to be reassured that the company had indeed taken the necessary remedial measures, nor to understand the risks to which they were exposed, including those related to fraudulent emails, text messages, or calls, nor the measures to take to protect themselves.
151. Consequently, the restricted panel considers that the company breached Article 34 of the GDPR by failing to provide the individuals affected by the data breach with the necessary information from the outset.
IV. On corrective measures
152. Pursuant to Article 20-IV of Law No. 78-17 of 6 January 1978, as amended, "when the data controller or its processor fails to comply with the obligations arising from Regulation (EU) 2016/679 of 27 April 2016 or from this Law, the President of the National Commission for Information Technology and Civil Liberties may […] refer the matter to the restricted panel of the Commission for the issuance, after adversarial proceedings, of one or more of the following measures: […]
153. 2° An order to bring the processing into compliance with the obligations arising from Regulation (EU) 2016/679 of 27 April 2016 or from this Law or to comply with the requests made by the data subject to exercise their rights, which may be accompanied, except where the processing is carried out by the State, by a penalty payment, the amount of which may not exceed exceeding €100,000 per day of delay from the date set by the restricted panel;
154. 7° Except where processing is carried out by the State, an administrative fine may not exceed €10 million or, in the case of an undertaking, 2% of its total worldwide annual turnover for the preceding financial year, whichever is higher. In the cases referred to in points 5 and 6 of Article 83 of Regulation (EU) 2016/679 of 27 April 2016, these ceilings are increased, respectively, to €20 million and 4% of said turnover. The restricted panel shall take into account, in determining the amount of the fine, the criteria specified in the same Article 83.
155. Article 83 of the GDPR further stipulates that "each supervisory authority shall ensure that administrative fines imposed pursuant to this Article for infringements of this Regulation referred to in paragraphs 4, 5 and 6 are, in each case, effective, proportionate and dissuasive," before specifying the factors to be taken into account when deciding whether to impose an administrative fine and when determining its amount.
156. The second paragraph of Article 22 of the French Data Protection Act then provides that "the restricted panel may make public the measures it takes."
157. Recital 150 of the GDPR provides that "where administrative fines are imposed on an undertaking, that term shall, for that purpose, be understood as an undertaking in accordance with Articles 101 and 102 of the Treaty on the Functioning of the European Union."
158. The Guidelines on the application and setting of administrative fines for the purposes of Regulation 2016/679 specify that the concept of an undertaking should be understood as "an economic unit which may be formed by the parent company and all relevant subsidiaries. In accordance with Union law and case law, an undertaking shall be understood as the economic unit engaged in commercial or economic activities, irrespective of the legal entity involved."
159. In a judgment of 5 December 2023 (CJEU, Grand Chamber, C-807/21), the CUJE held, with regard to the concept of "undertaking", that, "as noted by the Advocate General in point 45 of his Opinion, it is in this specific context of calculating administrative fines imposed for infringements referred to in Article 83(4) to (6) of the GDPR that the reference, made in recital 150 of that Regulation, to the concept of "undertaking", within the meaning of Articles 101 and 102 TFEU, must be understood. In this regard, it should be emphasized that, for the purposes of applying the competition rules referred to in Articles 101 and 102 TFEU, this concept includes any entity carrying out an economic activity, irrespective of that entity's legal status and its method of financing. It thus designates an economic unit even if, From a legal perspective, this economic unit is made up of several natural or legal persons. This economic unit consists of a unified organization of personal, tangible, and intangible elements pursuing a specific economic objective on a lasting basis (judgment of 6 October 2021, Sumal, C-882/19, EU:C:2021:800, paragraph 41 and the case law cited therein). Thus, it follows from Article 83, paragraphs 4 to 6, of the GDPR, which concerns the calculation of administrative fines for the infringements listed in those paragraphs, that, where the recipient of the administrative fine is or is part of an undertaking, within the meaning of Articles 101 and 102 TFEU, the maximum amount of the administrative fine is calculated on the basis of a percentage of the total worldwide annual turnover of the undertaking concerned for the preceding financial year. Ultimately, as the Advocate General noted in point 47 of his Opinion, only an administrative fine whose The amount is determined based on the actual or material economic capacity of its recipient, and therefore imposed by the supervisory authority, relying, with regard to the amount of that capacity, on the concept of economic unit as defined in the case law cited in paragraph 56 of this judgment. It is likely to meet the three conditions set out in Article 83(1) of the GDPR, namely, to be effective, proportionate, and dissuasive. Consequently, when a supervisory authority decides, under the powers it holds pursuant to Article 58(2) of the GDPR, to impose an administrative fine on a controller who is or is part of an undertaking, within the meaning of Articles 101 and 102 TFEU, pursuant to Article 83 of that Regulation, that authority is required to base its calculation of administrative fines for the infringements referred to in Article 83(1) of that Regulation on Article 83(2) of that Regulation, as read in light of recital 150 of the same Regulation. Paragraphs 4 to 6 of Article 83, concerning the concept of "undertaking" within the meaning of Articles 101 and 102 TFEU (paragraphs 55 to 59).
160. This position was confirmed by the Court in its judgment of 13 February 2025 (CJEU, Fifth Chamber, C-383/23).
A. On the imposition of an administrative fine and its amount
161. As a preliminary matter, the company criticizes the rapporteur for penalizing the same facts twice by taking into account the turnover of the parent companies to penalize both FREE and FREE MOBILE, given the breach of data concerning convergent customers. The company considers that the rapporteur has thus disregarded the principle of "non bis in idem".
162. The rapporteur considers that the principle of "non bis in idem" was not violated by proposing to the restricted panel that the companies FREE and FREE MOBILE, two distinct legal entities, be sanctioned for distinct acts, which notably impacted the data of convergent subscribers.
163. The restricted panel recalls that it follows from Article 50 of the Charter of Fundamental Rights of the European Union, relating to the principle of "non bis in idem," that "no one shall be liable to be tried or punished again for an offence for which he or she has already been finally acquitted or convicted in the Union in accordance with the law."
164. It also recalls that this principle is intended to apply where a person has already been convicted or acquitted by a final judgment for acts constituting the same offence (CJEU, 7 January 2004, Aalborg Portland and Others v Commission, Case C-204/00 P, § 338).
165. In the present case, the restricted panel recalls that the data breach in question, which notably concerned the data of so-called "convergent" customers, was made possible or facilitated by vulnerabilities specific to both the information systems of FREE and FREE MOBILE. Given their respective responsibilities with regard to their own information systems, two separate sanction proceedings were initiated against the two companies. In the context of the sanction proceedings against FREE, the restricted panel considers that the company breached Article 32 of the GDPR, given the vulnerabilities inherent in its information system (lack of VPN connection security, which was not exploited by the attacker, and lack of means to detect suspicious behavior on its SIEBEL tool, which was exploited by the attacker). These facts and their attribution are distinct from those attributed to FREE MOBILE.
166. Therefore, the restricted panel considers that it did not violate the principle of "non bis in idem" by sanctioning two separate legal entities for distinct acts that partially affected the same data.
167. Consequently, the restricted panel dismisses the complaint based on a violation of the principle of "non bis in idem".
1. On the imposition of an administrative fine
168. The rapporteur proposes that the restricted panel impose an administrative fine on the company for breaches of Articles 32 and 34 of the GDPR.
169. In its defense, the company contests the rapporteur's analysis concerning the criteria in Article 83 of the GDPR for determining whether a fine should be imposed and its amount. First, regarding the seriousness of the data breach, it argues that, given the increase in cyber threats, the data in question had already been subject to previous breaches. It further argues that it has taken all necessary measures to remedy the data breach in question, which occurred within the context of a surge in cyberattacks, and to mitigate its consequences for the individuals concerned. Furthermore, it points out that it rectified the shortcomings identified by the rapporteur during the proceedings, before the investigation was closed. In addition, it maintains that it did not derive any financial benefit from the data breach and, on the contrary, suffered harm, as evidenced by a decrease in the number of new subscribers in the first half of 2025. Finally, it considers that the communication made by the CNIL to the complainants and on its website violates the confidentiality of the investigation and its presumption of innocence, and must be taken into account.
170. The restricted panel recalls that, in assessing the appropriateness of imposing a fine, it must take into account the criteria specified in Article 83 of the GDPR, such as the nature, seriousness, and duration of the infringement, the scope or purpose of the processing concerned, the number of data subjects, the measures taken by the controller to mitigate the damage suffered by the data subjects, whether the infringement was committed negligently, the degree of cooperation with the supervisory authority, the categories of data concerned, and the level of damage suffered by the data subjects.
171. First, the restricted panel considers that the criterion set out in subparagraph (a) relating to the seriousness of the infringement should be applied, taking into account the nature, scope, or purpose of the processing, as well as the number of data subjects affected and the level of damage they have suffered.
172. The restricted panel notes that the breaches affected a very large number of people, since, on the one hand, the data breach involved the data of more than 24 million subscriber contracts (including 7.6 million FREE contracts). The restricted panel observes that this volume reflects the central role played by the company in the French telecommunications sector.
173. Furthermore, the restricted panel considered that the inadequacy of the security measures deployed by the company to detect suspicious behavior enabled or facilitated the occurrence of the data breach. It believes that the context of the resurgence of cyberattacks requires particular attention from data controllers to ensure the security of the data they process. In this case, the data breach led to overexposure of the data and thus increased the risk of fraudulent use.
174. Furthermore, the restricted panel notes that of the 24,633,469 contracts affected (including 7.6 million FREE contracts) by the data breach, only 58,239 people called the toll-free number provided by FREE and FREE MOBILE and thus received complete information on the likely consequences of the breach and the measures they could take to avoid them. This failure to provide essential information to a very large number of people significantly increased the occurrence of the risks outlined in point 2 of this decision.
175. Finally, the restricted panel observes that the data breach in question generated an unprecedented number of complaints to the CNIL, reflecting the significant concern of the individuals affected. The restricted panel notes that the vagueness of the notification emails sent pursuant to Article 34 of the GDPR could only have fueled the fear and uncertainty of individuals regarding the consequences of the breach on their privacy.
176. It follows from the above that the breaches committed by the company are particularly serious.
177. Secondly, the restricted panel considers that the criterion laid down in Article 83(2)(b) of the GDPR, relating to whether the breach was committed intentionally or negligently, should be taken into account.
178. Regarding the breach of Article 32 of the GDPR, the restricted panel notes that the security measures that could have prevented or limited the breach are well-established in the state of the art, and that the company had the human, technical, and financial resources to implement them.
179. Regarding the breach of Article 34 of the GDPR, the restricted panel considers that the company was negligent in failing to inform the data subjects, in the notification email, of the risks they faced and the measures they should take to protect themselves against them, even though the company had identified these risks.
180. Consequently, the restricted panel considers that the breaches in question resulted from the company's negligence.
181. Thirdly, the restricted panel considers that the criterion set out in Article 83(2)(g) of the GDPR, concerning the categories of personal data affected by the breach, should be applied.
182. The restricted panel notes that FREE MOBILE processes "highly personal" data (bank details) which the attacker accessed in this case. The company should have exercised greater vigilance in implementing measures to ensure secure access to this data, given the risk of its loss of confidentiality for the individuals concerned (fraudulent withdrawals).
183. Fourth, the restricted panel considers that the criterion set out in Article 83(2)(k) of the GDPR concerning aggravating or mitigating circumstances applicable to the specific circumstances of the case should be applied, such as the financial benefits obtained or losses avoided, directly or indirectly, as a result of the breach.
184. In addition to the fact that the number of subscribers increased between the last quarter of 2024 and the first quarter of 2025, the restricted panel notes that the company has not demonstrated a causal link between the harm suffered as a result of the data breach and any potential loss of revenue that should be taken into account as a mitigating circumstance.
185. Furthermore, regarding the communication made by the CNIL to the complainants, the restricted panel notes that it falls within the scope of Article 8-I-2-d) of the amended French Data Protection Act, which requires the Commission to inform the complainant of the outcome of the investigation (the Chair's decision to close the audit procedure, and where applicable, the complaint, or to initiate sanction proceedings). In this case, the referral to the restricted panel and the appointment of a rapporteur mark the end of the investigation phase as defined in the aforementioned article, and it was therefore necessary to inform the complainant. The restricted panel specifies that the information provided to the complainants did not contain any confidential information, as it made no mention of the alleged breaches or the corrective measure proposed by the rapporteur.
186. The restricted panel also reiterates that, given its impartiality and independence, it is not bound by the requests made by the rapporteur within the framework of ongoing sanction proceedings. Therefore, the CNIL President's decision to initiate sanction proceedings against the company does not prejudge the decision to be rendered by the members of the restricted panel, a point also emphasized in the information letter sent by the Commission's services to the complainants.
187. Furthermore, regarding the communication published by the Commission on its website, the restricted panel notes that the article entitled "Data breach and theft of your IBAN: how to protect yourself if you are affected?" published on the CNIL website on August 8, 2025, outlines the risks incurred by individuals in the event of IBAN theft and provides advice on how to protect themselves. The restricted panel notes that this article does not mention the company. The only CNIL communication that mentions the company, as a victim of a data breach alongside other cited actors, is entitled "Massive Data Breaches in 2024: What are the Main Lessons Learned and Measures to Take?" and is dated January 28, 2025. Furthermore, the restricted panel notes that this article contains no information covered by the confidentiality of the investigation (for example, the scope of the audit, the identified breaches), which was ongoing at the time of its publication, nor any value judgment on the company. This article aims solely to raise awareness among organizations, in a context of increasing data breaches, of the methods used by attackers, who regularly exploit the same vulnerabilities. Furthermore, the restricted panel observes that, as of the date of publication of this article, the data breach suffered by the company was already public knowledge, having been reported on the website cybermalveillance.gouv.fr and in the press.
188. Consequently, the restricted panel considers that the CNIL's communications do not constitute a mitigating circumstance.
189. As a result, the restricted panel considers, in light of all these elements and with regard to the criteria set out in Article 83 of the GDPR, that an administrative fine should be imposed for the breaches in question.
2. On the amount of the administrative fine
190. In its defense, the company argues that the amount of the fine proposed by the rapporteur is disproportionate in light of the restricted panel's previous decisions. She adds that by imposing a particularly high fine, the restricted panel would send the wrong signal to other data controllers who are victims of a data breach, who might decide not to notify the Commission of the breach and give in to the demands of the attackers.
191. The restricted panel notes first that breaches of Articles 32 and 34 of the GDPR are liable, under Article 83 of the GDPR, to an administrative fine of up to €10,000,000 and up to 2% of annual turnover, whichever is higher. It reiterates that administrative fines must be dissuasive and proportionate.
192. It then considers that the concept of "undertaking" should be used in competition law, by virtue of the direct and explicit reference to this concept in recital 150 of the GDPR and in the guidelines on the application and setting of administrative fines for the purposes of Regulation 2016/679. It emphasizes that, in judgments delivered under the GDPR, the CJEU has confirmed that the concept of "undertaking" contained in Article 83 of the GDPR must indeed be interpreted in light of competition law, governed by Articles 101 and 102 of the TFEU (CJEU, Grand Chamber, 5 December 2023, C-807/21 and CJEU, Fifth Chamber, 13 February 2025, C-383/23).
193. Regarding the definition of "undertaking," the restricted panel notes that in its aforementioned judgment of December 5, 2023, the CJEU held that an undertaking is an economic unit, even if, from a legal standpoint, this economic unit is composed of several legal entities. The CJEU specifies that, as in competition law (French Court of Cassation, Commercial Chamber, June 7, 2023, appeal no. 22-10.545; French Competition Authority, decisions no. 21-D-10 of May 3, 2021, and no. 21-D-28 of December 9, 2021), when a subsidiary is wholly owned, directly or indirectly, by its parent company, there is a rebuttable presumption that the parent company exerts decisive influence over the company's conduct. To determine the amount of the proposed fine, and to ensure that it corresponds to the actual economic capacity of its recipient, it is then necessary, according to the two aforementioned rulings, if the two companies can materially be regarded as belonging to the same economic unit, to take into account the turnover of the parent company so that the fine is effective, proportionate and dissuasive.
194. In the present case, the restricted panel notes that ILIAD owns 100% of FREE and thus considers, in accordance with competition law, that there is a presumption that ILIAD exercises decisive influence over FREE's conduct on the market (CJEU, Grand Chamber, 5 December 2023, C-807/21; also CJEU, Third Chamber, 10 September 2009, Akzo C 97/08 P, paragraphs 58 to 61. See also, for the application of the presumption of decisive influence in cases of chain ownership: CJEU, Eni v Commission, 8 May 2013 (C-508/11 P, § 48). Consequently, ILIAD and FREE constitute a single economic entity and therefore form a single undertaking within the meaning of Article 101 of the TFEU.
195. In light of the foregoing, the restricted panel considers that the turnover of the undertaking should be used in the sense of an "economic unit", namely that of the group's parent company. It notes that in 2024, ILIAD's turnover was €10.024 billion with a net profit of €367 million. The restricted panel observes that in the first quarter of 2025, ILIAD's turnover was €2.5 billion, of which €1.6 billion came from its French subsidiaries, including FREE. The restricted panel also notes that ILIAD's turnover in the first quarter of 2025 was up 4.3% compared to the first quarter of the previous year.
196. As regards the amount of the fine, the restricted panel reiterates that it must be proportionate and dissuasive. Having regard to the responsibilities and financial capacity of the organization concerned and the relevant criteria of Article 83 of the GDPR, the amount of a fine is therefore determined on a case-by-case basis. In this particular case, the restricted panel notes the human, technical, and financial resources available to the company to comply with its obligations under the regulations relating to the protection of personal data, as well as the particularly high number of data and individuals affected by the data breach (including data concerning 7.6 million FREE contracts) and the breaches in question. In light of the foregoing, the restricted panel considers it appropriate to impose an administrative fine of €15,000,000 (fifteen million euros) on FREE, in view of the breaches established under Articles 32 and 34 of the GDPR. Contrary to the company's assertions, the restricted panel considers that the imposition of this fine will not result in a failure to notify the Commission by other data controllers. Data processing victims of a data breach. The restricted panel reiterates in this regard that notifying the CNIL (French Data Protection Authority) of a data breach posing a risk to the rights and freedoms of individuals is an obligation for data controllers, and failure to comply with this obligation constitutes a breach of Article 33 of the GDPR, which may lead to the issuance of a corrective measure by the restricted panel.
B. On the issuance of an injunction
197. In his initial report, the rapporteur proposed that the restricted panel issue an injunction against the company to bring its processing into compliance with the provisions of Article 32 of the GDPR, accompanied by a penalty payment.
198. In its defense, the company argues that issuing an injunction is unnecessary, since it has implemented compliance measures during the proceedings.
199. The restricted panel notes that, as of the date of the hearing, the company has not provided evidence of changes to all the practices in question. within the framework of the sanction procedure initiated against it. Therefore, it considers that, in order to ensure the company's compliance with the breach identified in Article 32 of the GDPR, the issuance of an injunction appears necessary.
200. The restricted panel considers that the company must adopt appropriate security measures [...].
201. Furthermore, to guarantee compliance with this injunction, the restricted panel considers that, in view of the company's turnover and the financial, human, and technical resources at its disposal to remedy the identified breaches, a daily penalty payment of €25,000 (twenty-five thousand euros) per day of delay should be imposed, payable after a period of three (3) months from the date of notification of the decision.
C. On the publication of the sanction
202. The company contests the rapporteur's proposal to make this decision public, particularly in light of of the sensitivity of the security measures targeted within the framework of the sanction procedure. It considers that disclosing these measures in a public decision could compromise the security of its information system.
203. The restricted panel considers that the publication of this decision is justified given the seriousness of the breaches, as well as the number of people affected. It considers that the publication will, in particular, inform all those affected by the breaches in question about the nature of the corrective measure taken by the restricted panel of the Commission against the company. However, it considers it necessary that certain details contained in this decision will be redacted.
204. It further considers that this measure appears proportionate since the decision will no longer identify the company by name after a period of two years from its publication.
FOR THESE REASONS
The restricted panel of the CNIL, after deliberation, decides to:
- impose an administrative fine of one The amount of €15,000,000 (fifteen million euros) in respect of the breaches of Articles 32 and 34 of the GDPR;
- to issue an injunction against the company FREE, requiring it to bring its data processing into compliance with the provisions of Article 32 of the GDPR, and in particular to implement appropriate technical and organizational measures within three months to ensure a level of security appropriate to the risk, including:
• […] ;
• […] ;
- to impose a penalty of €25,000 (twenty-five thousand euros) per day of delay, with supporting documentation of compliance to be submitted to the restricted panel within the aforementioned period;
- to publish its decision on the CNIL website and on the Légifrance website, which will no longer identify the company by name after a period of two years from its publication.
The President
Philippe-Pierre CABOURDIN
This decision may be appealed to the Council of State within two months of its notification.




