back to article France fines telcos €42M for sub-par security prior to 24M customer breach

The French data protection regulator, CNIL, today issued a collective €42 million ($48.9 million) fine to two French telecom companies for GDPR violations stemming from a data breach. Free and Free Mobile are two separate businesses, respectively overseeing fixed-line and mobile services, owned by Iliad Group. The fines relate …

  1. Dan 55 Silver badge
    Alert

    Looks like it's open season, that's four data breaches reported just today.

    I'd go back to paper billing if my data weren't held in the same database reachable from the Internet for everyone who uses online billing.

    1. FrogsAndChips

      This one was reported more than 1 year ago, it's only the fine that was issued today.

  2. IGotOut Silver badge

    Booooo...

    Europe picking on poor hard done by US companies, better raise the tarrifs?

    Oh wait, the law applies to non-US companies as well? But, but, but Europe only attacks poor hard done by multi-billion dollar US companies, Donald told me so.

  3. JessicaRabbit Silver badge

    This is crazy, the fine amounts to only 0.42% of turnover (11.4% of profit) and is barely above the 20 million max they'd have to pay if 4% of their turnover was less than that. I also wouldn't be surprised if they contest this and it ends up being reduced to an even lower amount. One wonders just how egregiously a company has to fuck up to actually get a fine of 4%.

    1. Fazal Majid

      They have indeed announced they will appeal to the Conseil d'etat, France's top administrative law court.

      World's smallest violin, etc.

      1. Korev Silver badge
        Thumb Down

        €42 / 24 = €1.75 for each customer affected - all of whom now have the risk of fraud using the leaked details...

        1. Anonymous Coward
          Anonymous Coward

          I'm already getting spam on the, fortunately throwaway, email address they had.

    2. FrogsAndChips

      Yeah, I got my initial math wrong and thought they had indeed been hit with a 4% fine, which I believe would have been a first for GDPR fines.

      That said, the leaked data was not considered sensitive as per GDPR criteria (even bank details are not), so it was probably a mitigating factor, because they have no excuses for poor security measures and late notification.

  4. Blackjack Silver badge

    €1.75 by each person breach? What a bargain!

  5. Anonymous Coward
    Anonymous Coward

    And this leak is actively exploited. I've received quite a few targeted phishing emails since, using my actual bank logo, or from "Prime Video" including my full name, address and bank information. The only revealing detail was the bogus sending email address, a technical detail which many MUAs hide.

    I'm sure it comes from that leak as they're using the unique email address I created for Free.

    Free is generally less bad than the others but they really fucked this one up.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon