Recent fines imposed by the CNIL on companies like MOBIUS SOLUTIONS LTD and NEXPUBLICA FRANCE highlight the financial consequences of data protection failures. With fines of €1 million and €1.7 million, these cases underscore the critical importance of robust data protection measures.
MOBIUS SOLUTIONS LTD — user data kept after the contract ended, instructions exceeded, records of processing missing
NEXPUBLICA FRANCE — known security flaws left uncorrected until breaches were reported (Article 32)
For businesses, these fines serve as a stark reminder of the financial risks associated with inadequate data protection. The CNIL’s actions reflect a broader trend among regulators to enforce data protection laws strictly, particularly in the wake of data breaches. Companies must recognise that failing to protect personal data can lead to significant financial penalties and damage to their reputation.
The two cases show different routes to the same outcome. MOBIUS SOLUTIONS LTD was fined €1 million as a processor: it retained a copy of the data of more than 46 million Deezer users after its contractual relationship ended, used data beyond the controller’s instructions, and did not maintain the required records of processing. NEXPUBLICA FRANCE was fined €1.7 million for insufficient security under Article 32: known vulnerabilities in its case-management software persisted despite audit reports identifying them, and were only corrected after breaches were reported. Neither failure is exotic — contract-end deletion and basic security hygiene are exactly the obligations that go wrong quietly, until a regulator looks.
To protect themselves, companies should conduct regular data protection audits and implement robust security measures. This includes ensuring that data is encrypted, access is restricted to authorised personnel, and that there are clear protocols for responding to data breaches. Additionally, staff training on data protection practices can help prevent breaches and ensure compliance with regulations.
For businesses seeking to enhance their data protection strategies, Privacy Core Services offers Article 37 readiness reviews to help identify potential vulnerabilities and ensure compliance with data protection laws.
Sources: EDPB — the CNIL fined MOBIUS SOLUTIONS LTD €1 million; CNIL — NEXPUBLICA FRANCE fined €1,700,000.

