CNIL fines MOBIUS SOLUTIONS LTD €1 million for data breach and GDPR violations
Original title: Data breach: the CNIL fined MOBIUS SOLUTIONS LTD €1 million
The French Data Protection Authority (CNIL) fined MOBIUS SOLUTIONS LTD €1 million on 11 December 2025 following a data breach notification from DEEZER in November 2022 that exposed over 46 million users' data. The processor violated GDPR Article 28.3(g) by retaining customer data after contract termination despite the obligation to delete it, violated Article 29 by using data without controller authorization to improve its own services, and failed to maintain processing records as required by Article 30. Organizations using processors must ensure contractual terms clearly restrict data usage and include binding deletion obligations, while processors must implement controls to delete all personal data upon contract termination and maintain comprehensive documentation of all processing activities.
What changed
- MOBIUS SOLUTIONS LTD retained a copy of data belonging to more than 46 million DEEZER users after the end of their contractual relationship, in breach of Article 28.3(g) of the GDPR which requires processors to delete or return personal data without undue delay after the end of processing activities.
- The processor copied and used DEEZER's data without any instructions from the data controller in order to improve the performance of its own services, in breach of Article 29 of the GDPR which requires processors to act only on instructions from the controller.
- MOBIUS SOLUTIONS LTD failed to maintain a record of processing activities as required by Article 30 of the GDPR, which mandates processors keep documentation of all processing operations.
- The unlawful storage of data led to a risk for the security of individuals' data and resulted in a significant data breach affecting over 46 million users whose personal information was posted on the dark web.
Who is affected
Data controllers and processors across the EU, particularly those in digital services and advertising sectors; organizations that engage third-party processors for customer data handling; individuals whose personal data was processed by MOBIUS SOLUTIONS LTD.
Summary generated by a language model; the official text prevails. Not legal advice.