Skip to main content
European Data Protection Board logo
Back Search Menu
Close menu

Main navigation

  • Home
  • Topics
  • Documents
  • Registers
  • Public consultations

Top navigation

  • About EDPB
  • News
  • Meetings
  • Contact
  • Guide for SMEs
EN

Select your language

  • BGбългарски
  • CSčeština
  • DAdansk
  • DEDeutsch
  • ELελληνικά
  • ESespañol
  • ETeesti
  • FIsuomi
  • FRfrançais
  • GAGaeilge
  • HRhrvatski
  • HUmagyar
  • ITitaliano
  • LTlietuvių
  • LVlatviešu
  • MTMalti
  • NLNederlands
  • PLpolski
  • PTportuguês
  • ROromână
  • SKslovenčina
  • SLslovenščina
  • SVsvenska
Close language switcher

Breadcrumb

  1. Home

Data breach: the CNIL fined MOBIUS SOLUTIONS LTD €1 million

Fri, 21/08/2026
Background information Date of final decision: 11 December 2025 National case Controller: MOBIUS SOLUTIONS LTD Legal Reference: Article 28 (Processor), Article 29 (Processing under the authority of the controller and processor), Article 30 (Records of processing activities) Decision: Administrative fine Key words: Administrative fine, Data security, Data breach Summary of the Decision Origin of the case In November 2022, the CNIL was notified of a data breach by DEEZER. The company reported that its users' data had been posted on the dark web and that its former processor, MOBIUS SOLUTIONS LTD
  • Read more about Data breach: the CNIL fined MOBIUS SOLUTIONS LTD €1 million

Data breach: the CNIL fined NEXPUBLICA FRANCE €1.7 million

Fri, 21/08/2026
Background information Date of final decision: 22 December2025 National case Controller: NEXPUBLICA FRANCE Legal Reference: Article 32 (Security of processing) Decision: Administrative fine Key words: Administrative fine, Data security, Data breach Summary of the Decision Origin of the case NEXPUBLICA FRANCE has developed a user relationship management software named PCRM which is used in the field of social action, in particular by departmental houses for the disabled (MDPH). In November 2022, the CNIL was notified of a data breach by NEXPUBLICA FRANCE customers for being able to access
  • Read more about Data breach: the CNIL fined NEXPUBLICA FRANCE €1.7 million

Data breach: FREE MOBILE and FREE fined €42 million

Fri, 21/08/2026
Background information Date of final decision: 13 January 2026 National case Controller: FREE MOBILE and FREE Legal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), Article 5 (Principles relating to processing of personal data) Decision: Administrative fine Key words: Administrative fine, Data security, Data breach Summary of the Decision Origin of the case In October 2024, an attacker managed to infiltrate the companies' information system and access personal data relating to 24 million subscriber contracts, including
  • Read more about Data breach: FREE MOBILE and FREE fined €42 million

Data breach: France Travail fined €5 million

Fri, 21/08/2026
Background information Date of final decision: 22 January 2026 National case Controller: FRANCE TRAVAIL Legal Reference: Article 32 (Security of processing) Decision: Administrative fine Key words: Administrative fine, Data security, Data breach Summary of the Decision Origin of the case In the first quarter of 2024, one or more hackers managed to hack into the FRANCE TRAVAIL information system. They used techniques known as "social engineering", which involve exploiting people's trust, ignorance or credulity. This method enabled them to hijack the accounts of CAP EMPLOI advisers, i.e. the
  • Read more about Data breach: France Travail fined €5 million

Stakeholder event on guidelines on the interplay between data protection and competition law: express your interest

Wed, 29/07/2026
Brussels, 30 July – The EDPB and the European Commission organise a remote stakeholder event in the context of their joint work on upcoming guidelines on the interplay between competition and data protection. The event will take place on 15 October 2026 and is an opportunity for stakeholders to inform and support the ongoing work on this topic. The event reflects the EDPB’s commitment to stakeholder engagement and cross-regulatory cooperation, as outlined in the Helsinki statement and in the EDPB Strategy 2024-2027. Who can participate? The EDPB and the European Commission welcome
  • Read more about Stakeholder event on guidelines on the interplay between data protection and competition law: express your interest

Stakeholder event on guidelines on the interplay between data protection and competition law: save the date

Thu, 23/07/2026
Brussels, 23 July – The EDPB and the European Commission organise a remote stakeholder event in the context of their joint work on upcoming guidelines on the interplay between competition and data protection. The event will take place on 15 October 2026 and is an opportunity for stakeholders to inform and support the ongoing work on this topic. The event reflects the EDPB’s commitment to stakeholder engagement and cross-regulatory cooperation, as outlined in the Helsinki statement and in the EDPB Strategy 2024-2027. Join the event to have your say This is your chance to contribute directly to
  • Read more about Stakeholder event on guidelines on the interplay between data protection and competition law: save the date

EDPB calls for legal basis for cross-regulatory information sharing

Fri, 17/07/2026
Dublin, 17 July– At a high-level meeting in Dublin on 16 and 17 July 2026, the European Data Protection Board (EDPB) called for a clear legal basis for the sharing of information among regulators with different competences. The Board also discussed how to further expand efforts to support a consistent application of the General Data Protection Regulation (GDPR), including through more intense cooperation between Data Protection Authorities (DPAs). A clear legal basis for efficient cross-regulatory cooperation The Board underlines the growing need in the current regulatory environment for
  • Read more about EDPB calls for legal basis for cross-regulatory information sharing

EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint

Tue, 14/07/2026
Brussels, 14 July–The EDPB has published its binding decision of 28 May 2026 under Art.65(1)(a) GDPR*. The decision concerns a dispute submitted by the Belgian Data Protection Authority (DPA) about a complaint against Vlaamse Radio-en Televisieomroeporganisatie (VRT) – a public broadcasting company based in Belgium. The complaint was lodged with the Austrian DPA by the Austrian-based NGO Noyb on behalf of an individual. It concerns the use of cookie banners on the website of VRT . The Belgian DPA, acting as Lead Supervisory Authority (LSA), submitted a draft decision proposing to dismiss the
  • Read more about EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint

EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain

Wed, 08/07/2026
Brussels, 8 July– During its latest plenary, the EDPB has adopted guidelines on anonymisation and guidelines on web scraping in the context of generative AI. In addition, the Board has adopted the final version of its guidelines on the processing of personal data through blockchain technologies. Understanding anonymous data The new EDPB guidelines bring clarity to the notion of anonymous data, taking also into account the ruling of the Court of Justice of the EU in the case C-413/23 P EDPS v SRB of 4 September 2025 and other CJEU jurisprudence. The guidelines mark a significant milestone in
  • Read more about EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain

Acknowledgement of receipt

  • Read more about Acknowledgement of receipt

Pagination

  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Page 5
  • Page 6
  • Page 7
  • Page 8
  • Page 9
  • …
  • Next page Next ›
  • Last page Last »
Subscribe to
European Data Protection Board logo

Footer mainnavigation

  • Main menu items
    • Topics
    • Documents
    • Registers
    • Consultations
    • News
    • Meetings
  • About us menu items
    • Task and duties
    • Our members
    • EDPB Secretariat
    • Strategy and work programme
    • Legacy: Art. 29 Working Party

Footer

  • Career opportunities
  • Copyright
  • Cookies
  • General Data Protection Notice
  • Public access to documents
Coordinated Supervision Committee
The CSC ensures the coordinated supervision by data protection authorities.
CSC
Logo of Linkedin Logo of X
×

We use cookies

When you visit our website, if you give your consent, we will use cookies to allow us to collect data for aggregated statistics to improve our services and remember your choice for future visits.
If you don't want this, we will only use cookies to remember your choice for future visits (i.e., essential cookies).
If you don't select any of the two options, no cookies will be deployed, but the banner will re-appear every time you enter our website.
More information on cookies and data protection.