INTELLIGENCE
ZERO|TOLERANCE
Intelligence Advisory
zerotolerance.me

Orange SA Fined €50M for Email Marketing Violations

2024 · €50M fine

Publication Date
2024-01-01
Category
Regulatory Enforcement
Author
K. Ellabban
Organization
Zero|Tolerance Security Research

Orange SA Fined EUR 50M for Email Marketing Violations The CNIL imposed a EUR 50 million fine on Orange SA, France's largest telecom provider, in November 2024 for inserting advertisements disguised as emails within the Orange webmail inbox without valid consent and for continuing to read cookies after users withdrew consent. Over 7.8 million users of the Orange email service were affected.

Executive Summary

KEY FACTS

  • WhatOrange ignored subscriber opt-outs, sending emails months after withdrawal.
  • Who4.5 million Orange France subscribers who opted out of marketing.
  • Data ExposedEmail addresses, telecom profiles, and marketing preference data.
  • OutcomeCNIL fined Orange EUR 50M for consent withdrawal failures.
References

SOURCES

CNIL Decision, GDPR Articles 6, 7, 21, ePrivacy Directive