CNIL Fines EXTIA EUR 300,000 Over GDPR Erasure Request Failures
Independently fact-checked against primary sources (last audited September 9, 2026). · 7 primary sources cited on this page. How we verify our legal content

CNIL Fines EXTIA EUR 300,000 Over GDPR Erasure Request Failures
France's data protection regulator made public on September 9, 2026 a EUR 300,000 fine against EXTIA, an IT and engineering consultancy. The rule it enforced is simple: acting on an erasure request is not enough, you must also tell the person what you did.
Information last verified on September 9, 2026.
Jurisdiction scope: This article covers French and European Union law. It describes the GDPR as applied by the CNIL in France. It does not describe US state privacy law, and nothing here should be read as a statement of any US state's rules on data deletion requests.
What Happened
The Commission Nationale de l'Informatique et des Libertés, France's data protection authority, published the sanction on September 9, 2026. The decision itself is older. It was taken on July 21, 2026 by the CNIL's formation restreinte, the restricted committee that is the organ of the CNIL responsible for issuing sanctions, and it is recorded as délibération no. SAN-2026-010. Those two dates are not interchangeable, so cite the July date for the decision and the September date for its publication.
EXTIA works in IT and engineering. It recruits consultants and assigns them to technical projects at client companies, which means it holds a large volume of applicant and former-employee data. What actually brought it to the CNIL was a set of complaints from those two groups, arriving in a year when erasure handling was already a European enforcement priority.
During 2024 the CNIL received several complaints from former employees and candidates who said they were having difficulty exercising their right to erasure under Article 17 of the GDPR, the right often called the droit à l'oubli or right to be forgotten. To investigate those complaints, and also as part of the European Data Protection Board's 2025 coordinated enforcement action on the right to erasure, the CNIL inspected EXTIA in April 2025.
The numbers the inspection produced are the heart of the case. EXTIA received 265 erasure requests in 2024, coming mostly from candidates and occasionally from former employees. In the CNIL's words, more than three quarters "n'avaient pas été traitées ou ne l'avaient pas été de manière satisfaisante": they had not been processed, or had not been processed satisfactorily.
The panel found two breaches. The first, under Articles 12 and 17 together, was that 12 requests received in 2024 were simply never processed. The panel said this harmed the rights of those people, including their ability to keep control of their own data. It also recorded that EXTIA fixed the problem during the proceedings by deleting the data and telling the people concerned what had happened.
The second breach, under Article 12 alone, is the one that carried the volume. The panel found that 166 people who made an erasure request in 2024 were never informed of the outcome. A further group was informed late, outside the one-month legal deadline, with delays of up to several months. The CNIL's published decision summary puts that second group at 27 people.
EXTIA contested the seriousness of this breach, arguing that a large number of the requests came from candidates whose data had been deleted automatically anyway. The panel's answer was that automatic deletion "ne dispensait pas la société d'informer ces candidats des suites apportées à leur demandes", that it did not relieve the company of the duty to inform those candidates of the outcome of their request. The panel did credit EXTIA for informing people during the proceedings, and accepted that for a residual number of requests the company had valid reasons why it could not, such as being unable to identify the person.
On the amount, the CNIL pointed to three things: the disregard of essential principles on the rights of individuals, the number of people affected, and the fact that the company had already been reminded of its obligations on two prior occasions.
Under the loi Informatique et Libertes the restricted committee may make its decisions public, and this one was published on the CNIL site and on Legifrance.
What the Law Actually Says
Article 17(1) of the GDPR gives a person the right to obtain erasure of their personal data without undue delay where one of six grounds applies. The ground that usually carries a rejected job applicant is the first: the data are no longer necessary for the purposes for which they were collected. Article 17(3) then carves out situations where the right does not apply, including freedom of expression, compliance with a legal obligation, and the establishment or defence of legal claims. A recruiter that keeps an application file for a defined and lawful retention period is not automatically in breach. The CNIL found two distinct failures here: a substantive one under Articles 12 and 17, where 12 requests were never acted on at all, and a much larger procedural one under Article 12 alone, where people were never told what had happened to their request.
Article 12 is the provision that decides what an adequate response looks like, and it is the reason EXTIA's automation argument failed. Article 12(3) requires the controller to provide the person with information on the action taken on a request under Articles 15 to 22 without undue delay and in any event within one month of receiving it. That month can be extended by two further months where necessary, taking account of the complexity and the number of requests, but only if the controller tells the person about the extension and the reasons for the delay within the original month. Article 12(4) closes the gap: if the controller does not act on the request, it must still tell the person, at the latest within one month, why it is not acting and that they can lodge a complaint with a supervisory authority and seek a judicial remedy.
Read together, those provisions make the response a two-part obligation: doing the thing and reporting the thing are separate duties, and the second survives even when the first happens by itself. Our guide to how the GDPR is enforced in France sets out the wider framework the CNIL operates within.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
The striking thing about this decision is where the weight sits. Twelve unprocessed requests is a small number. The finding that drove the case involved 166 people who got no answer, plus the group answered late. A company can be substantially compliant on the substance of erasure and still be exposed on the paperwork of telling people, and the CNIL set the amount by reference to three things it named: the disregard of essential principles on the rights of individuals, the number of people affected, and the two earlier reminders the company had already received.
In this case the exposure sat in recruitment data. Almost all of the 265 requests came from candidates, with former employees making up the remainder. A consultancy that places engineers accumulates applicant records continuously, and at EXTIA it was candidates who made most of the erasure requests once a hiring process had ended. Someone in that position often has no continuing relationship through which to chase the request, which is one way a request ends up unanswered. The overlap with employment practice is direct, and readers dealing with the surveillance side of the same relationship may want our explanation of what French employers may and may not monitor at work alongside the broader rules governing the employment relationship in France.
The rejection of the automation defence is the part worth carrying into other jurisdictions. EXTIA's position was, in substance, that the outcome was correct so the process did not matter. Read that way, the automated purge is a retention control rather than a rights process: a deletion schedule is not a response to a request, because it runs regardless of whether a request was ever made.
The aggravating factor deserves attention too. The company had already been reminded of these obligations twice, and the CNIL named that history as one of the three things it weighed in setting the amount.
The timing was also not accidental. The inspection was carried out partly under the European Data Protection Board's coordinated enforcement action for 2025, launched on March 5, 2025, which put the implementation of Article 17 under simultaneous scrutiny by authorities across Europe. Erasure handling was a European enforcement priority that year, and EXTIA was inspected inside that programme.
How This Affects You
If you asked a company to delete your data and heard nothing back, the silence is itself a failure to comply with Article 12, unless the controller can show it was unable to identify you. What follows is general information rather than advice about your situation.
The controller owes you a response within one month of receiving your request. If it needs longer because the request is complex, it has to tell you that within the same month and explain why. If it decides not to act at all, it still has to tell you within a month, give its reasons, and inform you that you can complain to a supervisory authority. A company that deletes your data and never writes back has not complied, and the EXTIA decision is the CNIL saying so with a figure attached.
Article 77 of the GDPR lets you lodge a complaint with the supervisory authority of the country where you live, where you work, or where the breach happened. Against a controller established in France the CNIL is one available route; if you are elsewhere in the EU or EEA your own national authority is another, and a cross-border case is then allocated between authorities through the lead authority mechanism. We set out the steps involved in bringing a matter to the CNIL separately, including what the regulator can realistically do.
Two practical points are worth knowing before you start. A fine of this kind is paid to the state, not to the people who complained, so a complaint is a route to enforcement and to getting your data deleted rather than to compensation; a separate claim before the civil courts is the route to damages. And documentation matters. The CNIL's own guidance for complainants tells people to exercise the right first and keep the evidence of having done so, so keeping the date you sent your request and any acknowledgement you received puts you in a much stronger position than a recollection does.
Disclaimer: This article is general legal information about French and European Union data protection law, not legal advice, and it does not create a lawyer-client relationship. It describes a single CNIL decision as published and verified on September 9, 2026, and the law and its application can change. For advice about your own situation, consult a lawyer qualified in the relevant jurisdiction.
Related articles
- France Data Privacy Laws: GDPR and CNIL Compliance Guide
- How to File a CNIL Complaint in France
- Employee Monitoring in France
- France Employment Law
Last updated: 2026-09-09. Details verified as of 2026-09-09.
Frequently Asked Questions
What exactly did the CNIL fine EXTIA for?
For two breaches of the GDPR. First, under Articles 12 and 17, it never processed 12 erasure requests received in 2024. Second, under Article 12, it failed to tell people the outcome of their requests: 166 people were never informed and a further group was informed only after the one-month deadline. The fine was EUR 300,000.
Is the date of the decision the same as the date the CNIL made it public?
No, and the difference matters when you are citing it. The formation restreinte decided the case on July 21, 2026 in deliberation no. SAN-2026-010. The CNIL published the sanction on September 9, 2026. Cite July 21, 2026 for the decision and September 9, 2026 for the CNIL's publication of it.
How long does a company have to answer a GDPR erasure request?
Article 12(3) of the GDPR requires the controller to tell you what action it has taken without undue delay and in any event within one month of receiving your request. That period can be extended by two further months where necessary, taking account of the complexity and the number of requests, but only if the controller notifies you of the extension and the reasons for the delay inside the original month.
If a company deletes my data automatically, has it complied with the GDPR?
Not on its own, according to this decision. EXTIA argued that candidate data was deleted automatically in any event. The panel held that automatic deletion did not relieve the company of its separate duty under Article 12 to inform the person of the outcome of their request. Deleting the data and reporting the deletion are two obligations, not one.
Can a company ever refuse to delete my data?
Yes. Article 17(1) applies only where one of six listed grounds is met, such as the data no longer being necessary for the purpose it was collected for. Article 17(3) then sets out situations where the right does not apply at all, including compliance with a legal obligation and the establishment or defence of legal claims. A refusal can be lawful, but it still has to be communicated within the deadline.
What can I do if a company in France ignores my erasure request?
Complaining to the CNIL is the general route where the controller is established in France, and every EU and EEA country has an equivalent authority for controllers established there. This is general information and not advice on your circumstances. Keeping a record of when you sent the request and any acknowledgement you received is useful, and the CNIL's own complaints guidance tells people to keep the evidence of having exercised the right.
Do the people who complained receive any of the EUR 300,000?
No. An administrative fine imposed by the CNIL is paid to the state, not distributed to complainants. A complaint to the regulator is a route to enforcement and to having your data dealt with. Compensation for harm is a separate matter pursued before the civil courts.
Does this decision apply to companies outside France?
The decision itself binds only EXTIA and was issued under French procedure by the CNIL. The provisions it applies, Articles 12 and 17, are provisions of the GDPR and apply across the European Union and the EEA. The reasoning on the duty to inform is therefore relevant well beyond France, though it is the national authority in each country that enforces it.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- CNIL, Non-respect des droits des personnes : sanction de 300 000 euros a l'encontre de la societe EXTIA (published 9 September 2026)(cnil.fr).gov
- Deliberation de la formation restreinte n° SAN-2026-010 du 21 juillet 2026 concernant la societe EXTIA(legifrance.gouv.fr).gov
- GDPR Chapter III, Articles 12 and 17 (text hosted by the CNIL)(cnil.fr).gov
- EDPB, CEF 2025: Launch of coordinated enforcement on the right to erasure (5 March 2025)(edpb.europa.eu).gov
- GDPR Chapter VIII, Article 77 (right to lodge a complaint with a supervisory authority, in particular in the Member State of the complainant's habitual residence, place of work, or place of the alleged infringement), text hosted by the CNIL(cnil.fr).gov
- Loi no. 78-17 du 6 janvier 1978 relative a l'informatique, aux fichiers et aux libertes, consolidated text hosted by the CNIL. Article 20 gives the formation restreinte its power to make its measures public and Article 22 provides that financial penalties are recovered as debts owed to the State.(cnil.fr).gov
- CNIL, Adresser une plainte, the regulator's own complaints guidance, which states what the CNIL cannot do (including obtaining damages) and tells complainants to exercise the right and keep the evidence of the request(cnil.fr).gov