What Your Mobile Operator Really Knows About You in 2026: Connection Data, Ad Targeting and Your Right of Access
L'équipe Texto SMS Gratuit

L'équipe Texto SMS Gratuit

29 August 2026 · 12 min read

Introduction: the one player that tracks you without an app

We worry a great deal about apps. We uninstall them, refuse cookies, switch to a more discreet browser. And all the while, there remains one player that needs no app, no cookie consent and no system permission to know where you are, at what time, and who you are exchanging messages with: your mobile operator.

This is a structural consequence of how the network works. For a call to reach your phone, the network must know at all times which location area you are attached to. For a text message to go out, it must be routed, time-stamped and logged. For a bill to be issued, a record must exist. None of these operations is optional, and none can be "declined" in the settings.

Close-up of a smartphone screen showing connectivity icons: mobile data, Wi-Fi, Bluetooth and aeroplane mode

So the real question is not "how do I stop my operator from collecting data", but where the line falls between what is technically and legally mandatory, and what is a commercial choice you can refuse. In 2026, that line has shifted: French operators have all industrialised audience-monetisation activities, on a scale that most subscribers never knowingly agreed to.

This guide sorts it out, category by category, and sets out the concrete procedure for retrieving your data and switching off whatever can be switched off.

The four families of data an operator holds

It helps to think in four distinct blocks, because they are governed by completely different legal rules.

1. Identification data

Name, address, date of birth, bank details, the ID document provided when signing up, the IMEI number of the associated handset, the SIM card number (ICCID). This baseline is kept for the entire duration of the contract, and for five years after termination under accounting and anti-fraud obligations.

2. Traffic data — the famous "fadettes"

This is the most sensitive block. The itemised call record (in French, fadette) does not contain the content of your communications, but their metadata: the number called or calling, date, time, duration, type of communication, the numbers of texts sent and received, and — crucially — the identifier of the cell tower used.

The French framework was thoroughly overhauled after the Court of Justice of the European Union's La Quadrature du Net ruling (2020) and the Conseil d'État's decision of April 2021. The current regime, codified in Article L34-1 of the French Postal and Electronic Communications Code, distinguishes between:

  • civil identity data: retained for five years;
  • other contract and payment information: one year;
  • traffic and location data: one year, but their general retention is only triggered by a decree finding a serious and present threat to national security — a decree that has been renewed without interruption since 2021.

In other words: in practice, in 2026, your traffic data is indeed kept for a year.

3. Location data

This comes in two levels. The first, passive, is generated continuously by the network: your phone signals its attachment to a cell even when you are not using it. The second, active, is tied to each communication.

Accuracy depends on how dense the network mesh is. In a dense city centre, a cell may cover 200 to 300 metres; in rural areas, several kilometres. Operators do, however, have triangulation and signal-strength analysis techniques that refine this result considerably — and it is precisely this raw material that feeds the "mobility data" offerings sold to local authorities and tourism operators.

4. Usage and browsing data

Data volumes consumed, times of day, type of network used (4G, 5G, Wi-Fi calling), and, for a fixed-line box, part of the connection logs. On mobile, the spread of HTTPS encryption and encrypted DNS has reduced operators' visibility into content, but not into the domain names resolved when you use the operator's default DNS resolver.

What is mandatory, what is commercial

This is the distinction that the brochures never draw clearly.

ProcessingLegal basisCan it be refused?
Billing and debt recoveryPerformance of the contractNo
Retention of itemised call recordsLegal obligation (Art. L34-1 CPCE)No
Fraud and identity-theft preventionLegitimate interestHardly
Anonymised internal audience measurementLegitimate interestPartly
Advertising targeted on your usageConsentYes
Resale of aggregated mobility dataLegitimate interest + anonymisationYes, by objecting
Marketing profile enrichmentConsentYes

The dividing line is clear: anything based on consent can be withdrawn at any time, as easily as it was given. This is an explicit GDPR requirement, repeatedly restated by the CNIL in its decisions sanctioning telecoms and advertising players.

The blind spot: operator-run ad targeting

This is the most misunderstood topic of 2026.

An operator has an asset no platform has: a stable, verified identifier tied to a real person. Your phone number does not change when you switch browsers, does not reset like a mobile advertising ID, and is not blocked by private browsing mode. Add the billing address, handset type, area of residence and data consumption, and the resulting profile is unusually rich.

In practice, all four French operators run schemes of this kind, under names that vary: audience programmes, in-house ad sales houses, "data marketing" offerings for advertisers. The principle is the same: segment the subscriber base into audiences ("parents of young children", "frequent travellers", "fibre customers for less than six months") and then sell access to those segments.

Telecom operator's shop lit up at night with a 5G sign and passers-by on the pavement

Two points deserve attention.

First, consent has often been obtained by default. Many subscribers accepted this processing when signing up online, via a pre-ticked box that would not be compliant today, or when accepting an update to the terms and conditions with a single click. Having "agreed" four years ago in no way prevents you from withdrawing that consent today.

Second, the anonymisation invoked is not always anonymisation. The CNIL draws a strict distinction between anonymisation (irreversible; the data falls outside the scope of the GDPR) and pseudonymisation (reversible; the data remains protected). A mobility dataset that preserves individual trajectories, even without names, remains re-identifiable from a handful of points: several studies published since 2013, notably by MIT researchers working on telecoms datasets, have shown that four spatio-temporal points are enough to re-identify the overwhelming majority of individuals.

The practical procedure: exercising your right of access

The right of access under Article 15 of the GDPR is probably the most under-used tool available to French consumers. Here is how to use it effectively.

Step 1 — Identify the right recipient

Every operator has a data protection officer (DPO) whose contact details must appear in the privacy policy at the bottom of its website. Write to that address, not to customer services: customer services has neither the mandate nor the tools to handle a GDPR request, and you will lose three weeks.

Step 2 — Draft a precise request

A vague request gets a vague answer. Ask explicitly for:

  • a copy of all personal data concerning you;
  • the list of categories of traffic and location data retained, with their exact retention periods;
  • the purposes of each processing operation and its legal basis;
  • the recipients or categories of recipients, including processors and advertising partners;
  • the possible existence of automated decision-making (creditworthiness scoring, churn-risk scoring) and the logic behind it;
  • transfers outside the European Union and the safeguards applied.

Enclose a copy of an identity document — this is accepted for verifying your identity — and keep a time-stamped record of the sending.

Step 3 — Count the deadlines

The operator has one month to respond, extendable by two months for complex requests, provided it informs you within the first month. Once that deadline has passed without a satisfactory reply, you can file a complaint online with the CNIL, free of charge, enclosing your initial request and the absence of a response.

Step 4 — Make use of what you receive

You will generally receive one or more large CSV files. Opening them on a smartphone is a false good idea: a desktop spreadsheet, or even a simple refurbished laptop dedicated to admin tasks, makes the exercise infinitely more readable. Look first for three columns: radio cell identifiers, marketing segmentation indicators, and the dates the profile was last updated.

Reducing your exposure: what actually works

None of these measures will make your line invisible — network location is inseparable from the service. But they clearly reduce the exploitable surface.

Withdraw advertising consents. In each operator's customer account area, a "My privacy preferences" or "Manage my data" section lets you disable targeting, profile enrichment and transmission to partners. Allow five minutes; the effect is immediate on campaigns, slower on segments already sold.

Change your DNS resolver. Using a third-party encrypted resolver rather than the one in your box prevents the operator from observing the domain names you visit. The setting can be changed on the phone (private DNS) or on the router.

Compartmentalise your usage. A second line — for instance a prepaid eSIM dedicated to sign-ups, classified ads and online services — keeps your main number, the one your bank and your family use, out of marketing databases. It is also the best protection against cold calling.

Look after the handset. The operator layer is only part of the problem: the operating system's advertising identifiers and app permissions often weigh more heavily. Periodically resetting the advertising ID, refusing "always" location permissions and preferring "while using the app" makes far more difference than most exotic settings.

Mobile phone masts and satellite dishes on a rooftop, city buildings blurred in the background

Physically secure access to the line. SIM swapping remains the weak link: whoever obtains your number obtains your two-factor authentication codes. Setting a non-trivial SIM PIN, and above all moving sensitive two-factor authentication away from SMS to a physical FIDO2 security key or a dedicated app, removes that dependency.

Three misconceptions to drop

"My operator reads my texts."

Technically, a text message travels unencrypted through the infrastructure and could be read. Legally, access to the content of communications falls under a separate regime, strictly reserved for interceptions authorised by judicial or administrative authorities, with heavy procedural requirements. It is not a routine commercial practice, and breaching it is a criminal offence. The real issue remains metadata, which is more than enough to reconstruct a life.

"Aeroplane mode makes me invisible."

It does cut the network attachment, but as soon as it is switched off again, the handset reattaches and the time-stamping resumes. An interruption creates a gap in the trail, not an erasure.

"I've got nothing to hide, so it doesn't matter."

The argument does not survive concrete examination. Traffic data reveals a medical appointment, a meeting with a lawyer, trade union membership, a night spent somewhere other than home. These are not secrets: they are elements of private life whose aggregation produces asymmetric power. That is precisely why the CJEU regulates their retention so strictly.

The right habit: an annual privacy review

Most readers will never repeat this exercise. That is a shame, because it takes an hour once a year:

  1. Open your operator's customer account area and check the "personal data" page — settings sometimes reset when you change plans.
  2. Check your registration on Bloctel, valid for three years and requiring renewal.
  3. Send a GDPR access request to your operator every two years, to check the consistency of the retention periods announced.
  4. Review the location permissions of apps installed over the past year.
  5. Check that sensitive accounts (bank, main email, tax) no longer rely on SMS as their sole second factor.

For those who want to get to the bottom of the subject, the CNIL's practical guides are free and remarkably clear, and there is solid literature for the general public: a popular guide to personal data protection is a good complement for understanding the logic of the GDPR rather than memorising its articles.

In summary

By design, your operator holds a map of your movements and your relationships over a rolling twelve months. That part is legal, regulated, and you cannot refuse it. What you can refuse — and what many people do not realise they agreed to — is the commercial layer: targeting, profile enrichment, audience segmentation, transmission to partners.

The distinction between these two layers is the one thing to remember. It turns a vague sense of powerlessness into a list of concrete actions: three clicks in your customer account area, an email to the DPO, and a free complaint to the CNIL if no answer comes.

Sources and references: Article L34-1 of the French Postal and Electronic Communications Code; Regulation (EU) 2016/679 (GDPR), Articles 15, 17 and 21; CJEU, judgment in La Quadrature du Net and Others, 6 October 2020; Conseil d'État, French Data Network decision, 21 April 2021; CNIL guides and decisions; Arcep work on the quality and use of mobile networks.

#Vie privée#Confidentialité#Opérateurs#Mobile#Réseau#Pratique#Sécurité

Related articles

Send your SMS for free

100% free service, no sign-up and no ads. Send unlimited SMS to France.

Send an SMS
bg wave