The Information Commissioner's Office investigated the two organisations after complaints about the way they processed and stored personal information.
The ICO found security failings that led to customers being able to view other customers' account details online. In addition, the ICO found that the companies had not responded to requests by individuals for information held about them.
It also revealed that Carphone Warehouse and TalkTalk had been opening customer accounts in the wrong name and passing inaccurate information on to credit reference agencies and debt collection agencies.
Mick Gorrill, assistant commissioner at the ICO, said, "Carphone Warehouse and TalkTalk's use of inaccurate and incorrect personal data has caused real damage and distress to customers. We have now ordered them to take the necessary steps to ensure customers' personal information is sufficiently protected."
The ICO has issued Carphone Warehouse and TalkTalk with Enforcement Notices ordering them to comply with the principles of the Data Protection Act.
In response, Carphone Warehouse said, "We are aware that a very small number of our customers raised concerns with the ICO some time ago. The issues were primarily caused by the significant interest in TalkTalk's introduction of free broadband, over 18 months ago.
"We take these matters very seriously indeed, and as soon as these concerns were brought to our attention we took immediate steps to resolve them and to ensure we are fully compliant with the Data Protection Act. We apologise for any inconvenience that may have been caused and we will continue to work with the ICO in meeting and exceeding their expectations in this and any other respect."
If the watchdog is not satisfied with remedial action taken by the two companies it may initiate a prosecution.