CNIL fines EXTIA EUR 300,000 for failure to process erasure requests
Original title: Failure to respect the rights of individuals: The CNIL fined EXTIA EUR 300 000
The French Data Protection Authority (CNIL) imposed an administrative fine of EUR 300,000 on EXTIA, an IT and engineering company, for breaches of Articles 12 and 17 GDPR. Of 265 erasure requests received in 2024, more than three-quarters were not processed or not processed satisfactorily: 12 requests were not processed at all, and 166 individuals were not informed of action taken on their requests (with 27 others receiving this information late). This enforcement action demonstrates the importance of properly handling data subject rights requests within statutory deadlines and maintaining transparent communication with individuals exercising their rights under the GDPR.
What changed
- CNIL issued an administrative fine of EUR 300,000 against EXTIA for failures to respect data subject rights under Articles 12 and 17 GDPR
- Of 265 erasure requests received by EXTIA in 2024, more than three-quarters were not dealt with or not dealt with satisfactorily
- 12 erasure requests were completely unprocessed by EXTIA, adversely affecting individuals' right to retain control over their data
- 166 individuals who requested erasure were not informed of action taken on their requests, with another 27 receiving this information late (outside the one-month legal deadline)
- The fine took into account the infringement of essential principles relating to individual rights, the number of affected persons, and EXTIA's prior reminders about its obligations
Who is affected
Private sector companies in IT and engineering industries in the EU handling personal data from employees and candidates; organizations receiving large volumes of erasure requests
Summary generated by a language model; the official text prevails. Not legal advice.