CNIL imposes EUR 300,000 fine on EXTIA for failure to process data subject erasure requests
Original title: Failure to respect the rights of individuals: The CNIL fined EXTIA EUR 300 000
The French Data Protection Authority (CNIL) issued an administrative fine of EUR 300,000 against EXTIA, an IT and engineering consulting firm, for systematic failures to respect individuals' rights under the GDPR. The company failed to process or adequately process more than three-quarters of the 265 erasure requests received in 2024, and failed to inform 166 individuals of actions taken on their erasure requests, with 27 others receiving late notification. Organizations must ensure robust procedures for handling data subject rights requests within legal timeframes and provide timely confirmation of actions taken, as non-compliance exposes them to significant administrative penalties and reputational harm.
What changed
- CNIL audit of EXTIA (April 2025) identified that 12 erasure requests received in 2024 were not processed at all, and more than three-quarters of 265 total erasure requests were either not processed or not processed satisfactorily, violating Articles 12 and 17 GDPR
- EXTIA failed to inform 166 individuals who submitted erasure requests in 2024 of the action taken on their requests, and another 27 people received this information outside the legal one-month deadline with delays up to several months, violating Article 12 GDPR
- Administrative fine of EUR 300,000 imposed on EXTIA, determined by considering the infringement of essential principles relating to data subject rights, the number of persons affected (approximately 193+ individuals), and EXTIA's prior reminders of its obligations on two occasions
Who is affected
IT and engineering consulting firms recruiting personnel from client companies; organizations processing erasure requests from candidates and employees; French jurisdiction (CNIL enforcement)
Summary generated by a language model; the official text prevails. Not legal advice.