FREE SAS
Insufficient fulfilment of data subjects rights
Decision Date
December 8, 2022
Authority
French Data Protection Authority (CNIL)
FR
Sector
Media, Telecoms and Broadcasting
Country
FR
Law
GDPRStatus
FINALDescription
The French DPA has imposed a fine of EUR 300,000 on FREE SAS. The DPA had received several complaints from individuals experiencing difficulties in exercising their rights to access and delete their personal data at FREE. During its investigation, the DPA found that the company did not process the requests for access and deletion of personal data in a timely manner. The DPA also found that the company failed to ensure the security of personal data. For example, the company allowed users to use insecure passwords and user passwords were stored unencrypted in the company's databases. Finally, the DPA found that the company had not adequately documented a data breach.