Skip to content
← BlogComplianceAnalysis7 min read

Data minimization just became a fine, not a footnote

CNIL cited unlawful data retention in its €42M Free Mobile fine — a sign minimization is now an active regulatory check, not an ignored line item.

By Gabriel Lara, Developer Relations, Norbelys

Founder-reviewed ·How we research and correct articles

On January 8, 2026, France’s CNIL fined Free Mobile and its parent Free a combined €42 million over a breach that exposed roughly 24 million subscriber records — IBANs included — the previous October. Two of the three violations CNIL cited were the ones you’d expect from a breach case: inadequate security, and a delayed notification to those affected. The third one is the interesting part. CNIL also found that Free Mobile had kept personal data belonging to former subscribers well past the point it was needed for anything, a violation of Article 5(1)(e) — storage limitation, the “keep less, for less time” half of the minimization principle. That finding wasn’t incidental to the breach. It’s a separate line item in the sanction, and it’s the one that should worry anyone who treats minimization as a compliance nicety rather than an operational discipline.

The tell is what got cited alongside the breach

A breach investigation is exactly the moment a regulator ends up looking at everything a company was storing, not just what got exposed. That’s precisely why Free Mobile’s retention practice showed up in the sanction at all — CNIL wasn’t auditing the company’s data-retention policy in isolation, it fell out of the breach investigation, and it was serious enough to earn its own violation and its own weight in the fine. That’s the pattern worth internalizing: “we got breached” and “we were also keeping data we shouldn’t have had anymore” are increasingly treated as two separate failures with two separate price tags, not one story.

It also isn’t isolated to France. In August 2025, Poland’s UODO fined ING Bank Śląski roughly €4.3 million for scanning and retaining customer and prospective- customer ID documents without first assessing whether that was actually necessary — a combined Article 5(1)(c) and 6(1) finding, minimization and lawfulness cited together. The bank has appealed, but the shape of the finding is the same shape CNIL used five months later: not “did you have a reason to collect this,” but “did you keep collecting or holding onto more than the reason justified.”

Why this is a shift, not just one bad audit

The individual fines matter less than the trend they sit inside. Aggregated tracking from Kiteworks puts cumulative GDPR penalties at roughly €7.1 billion across 2,245 documented decisions since enforcement began in 2018 — and more fines were issued between January 2023 and March 2026 than in the entire five years before that. Enforcement isn’t just getting bigger, it’s getting faster and more granular, and minimization/retention findings are a recurring component rather than a rare specialty violation reserved for the worst offenders.

The practical read: a data protection authority reviewing your practices in 2026 is no longer only asking “did you have a lawful basis to collect this record.” It’s also asking “is this record still here for a reason, or is it just here” — and a database that’s grown past what any active process actually references is exactly what that second question is designed to catch.

What a minimization finding actually looks like from the inside

It’s worth being concrete about what regulators are checking, because “minimization” can sound abstract until it’s phrased as the specific question an investigator asks. In practice, the finding pattern across both the Free Mobile case and the ING Bank Śląski case reduces to a small set of checks: does a retention schedule exist at all, is it actually followed rather than written down and ignored, and can the company produce a reason — on request, not hypothetically — for why a given category of record is still in the database. None of that requires a regulator to prove the data was misused. Storage limitation is a violation independent of whether the retained data ever caused harm; keeping it past its purpose is the violation, full stop.

That’s a materially lower bar for enforcement than most companies plan around. A business that has never had a breach, never leaked anything, and never misused a customer’s data can still be found in violation purely on retention grounds — which is exactly what makes a breach investigation such an efficient way for a regulator to surface it. The investigator is already inside the systems looking at what’s stored; checking whether it’s still needed costs them almost nothing extra, and increasingly, they do.

What this means if you run outreach or hold contact data

None of this changes the underlying case for minimization — that case, and the practical playbook for applying it to a contact database, is covered in full in Norbelys’s own writeup on data minimization for cold email. What’s new in 2026 is the evidence that regulators treat it as an active audit line, not a theoretical obligation nobody checks. If your data-retention story amounts to “we’ve never gotten around to deleting anything,” that’s no longer just untidy — it’s the exact gap a breach investigation, or an unrelated audit, is now demonstrably likely to surface and price.

For anyone running a cold outreach program, the practical takeaway is narrow and specific: know why every field on a contact record exists, and have an actual answer for how long you keep a record that’s gone cold — bounced permanently, never engaged, no active campaign referencing it. “We might need it later” isn’t a retention policy a regulator will accept, and increasingly, it isn’t one they’re failing to check.

That answer is easier to have when the tooling treats it as a first-class question rather than a database migration nobody wants to run. Custom fields in Norbelys are archivable and mergeable on their own — a field a segment or template hasn’t referenced in months can be retired directly, not left sitting in the schema because touching it feels risky — and a contact that’s bounced permanently is enrolled out of every future send automatically rather than requiring someone to remember to exclude it campaign by campaign. Neither feature exists because of CNIL specifically, but both are exactly the kind of answer a regulator asking “is this record still here for a reason” is now demonstrably willing to check for.

FAQ

Frequently asked questions

Is data minimization a separate GDPR requirement from having a lawful basis to collect data?

Yes. Lawful basis (Article 6) covers whether you had a legal reason to collect a record in the first place. Minimization (Article 5(1)(c)) and storage limitation (Article 5(1)(e)) are separate, ongoing obligations about whether you're still holding only what's adequate, relevant, and necessary, and only for as long as necessary — a company can have a perfectly lawful basis for collecting a record and still violate GDPR by keeping it long after that basis stopped applying.

Does a minimization violation require proof the data was misused or leaked?

No. Storage limitation is violated by retention past its necessary period regardless of whether the retained data was ever accessed improperly or caused harm. That's what makes it a distinct finding from a security or breach-notification violation, even when both show up in the same sanction.

What's a reasonable first step if we don't have a documented retention policy?

Start by inventorying what's actually stored and why, field by field, rather than writing a policy in the abstract first. A retention rule is only defensible if it maps to what a regulator would actually find on inspection — usually a plain, specific answer for cold or bounced records, not a general statement about being GDPR-compliant.