Free fined 300,000 euros for non-compliance with GDPR
After receiving a number of complaints against mobile operator Free, the CNIL (National Commission for Information Technology and Civil Liberties) decided to carry out checks, which revealed a number of shortcomings.
Firstly, with regard to complaints, users found it difficult to consider requests for access to and deletion of their personal data.
The checks that were carried out revealed breaches of the rights of the people concerned, particularly with regard to the right of access and the right to erasure, which users were having problems with. There were also breaches of personal data security, such as weak passwords.
As a result, the CNIL (National Commission for Information Technology and Civil Liberties) has imposed a fine of 300,000 euros on Free. This fine has now been made public.
Furthermore, the mobile phone operator is required to comply with its users' access requests and to justify its decision within three months of notification of the deliberation.
Violations of the Data Protection Act
Failure to respect the right of access
(art. 12 and 15 of the GDPR)
Failure to respect the right to erasure
(art. 12 and 21 of the GDPR)
Failure to ensure the security of personal data
(art. 32 of the GDPR)