CNIL fines EXTIA €300,000 for failure to process erasure requests and inform data subjects

Original title: Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR

The French Data Protection Authority (CNIL) issued an administrative fine of €300,000 to EXTIA on 21 July 2026 for breaches of Articles 12 and 17 of the GDPR concerning data subject rights. Of 265 erasure requests received in 2024, the majority from candidates, over three-quarters were not processed or not processed satisfactorily. The company failed to process at least 12 erasure requests and did not inform 166 persons about the action taken on their erasure requests, directly undermining individuals' control over their personal data and their right to be forgotten.

What changed

  • EXTIA failed to process 12 erasure requests received in 2024, in breach of Articles 12 and 17 GDPR, thereby preventing data subjects from exercising their right to erasure and right to be forgotten.
  • EXTIA failed to inform 166 individuals who submitted erasure requests about the action taken on their requests, violating Article 12 GDPR's transparency requirement.
  • Of 265 total erasure requests received by EXTIA in 2024, more than three-quarters (over 199 requests) were either not dealt with or not dealt with satisfactorily.

Who is affected

EXTIA, an IT and engineering recruitment company operating in France, which recruits consultants for technical projects. The affected parties are candidates and former employees who submitted erasure requests but did not receive proper processing or communication about their requests.

Summary generated by a language model; the official text prevails. Not legal advice.