CNIL Fines EXTIA EUR 300,000 Over GDPR Erasure Request Failures

Independently fact-checkedBy Recording Law Editorial Team10 min read

Independently fact-checked against primary sources (last audited September 9, 2026). · 7 primary sources cited on this page. How we verify our legal content

CNIL Fines EXTIA EUR 300,000 Over GDPR Erasure Request Failures

Frequently Asked Questions

What exactly did the CNIL fine EXTIA for?

For two breaches of the GDPR. First, under Articles 12 and 17, it never processed 12 erasure requests received in 2024. Second, under Article 12, it failed to tell people the outcome of their requests: 166 people were never informed and a further group was informed only after the one-month deadline. The fine was EUR 300,000.

Is the date of the decision the same as the date the CNIL made it public?

No, and the difference matters when you are citing it. The formation restreinte decided the case on July 21, 2026 in deliberation no. SAN-2026-010. The CNIL published the sanction on September 9, 2026. Cite July 21, 2026 for the decision and September 9, 2026 for the CNIL's publication of it.

How long does a company have to answer a GDPR erasure request?

Article 12(3) of the GDPR requires the controller to tell you what action it has taken without undue delay and in any event within one month of receiving your request. That period can be extended by two further months where necessary, taking account of the complexity and the number of requests, but only if the controller notifies you of the extension and the reasons for the delay inside the original month.

If a company deletes my data automatically, has it complied with the GDPR?

Not on its own, according to this decision. EXTIA argued that candidate data was deleted automatically in any event. The panel held that automatic deletion did not relieve the company of its separate duty under Article 12 to inform the person of the outcome of their request. Deleting the data and reporting the deletion are two obligations, not one.

Can a company ever refuse to delete my data?

Yes. Article 17(1) applies only where one of six listed grounds is met, such as the data no longer being necessary for the purpose it was collected for. Article 17(3) then sets out situations where the right does not apply at all, including compliance with a legal obligation and the establishment or defence of legal claims. A refusal can be lawful, but it still has to be communicated within the deadline.

What can I do if a company in France ignores my erasure request?

Complaining to the CNIL is the general route where the controller is established in France, and every EU and EEA country has an equivalent authority for controllers established there. This is general information and not advice on your circumstances. Keeping a record of when you sent the request and any acknowledgement you received is useful, and the CNIL's own complaints guidance tells people to keep the evidence of having exercised the right.

Do the people who complained receive any of the EUR 300,000?

No. An administrative fine imposed by the CNIL is paid to the state, not distributed to complainants. A complaint to the regulator is a route to enforcement and to having your data dealt with. Compensation for harm is a separate matter pursued before the civil courts.

Does this decision apply to companies outside France?

The decision itself binds only EXTIA and was issued under French procedure by the CNIL. The provisions it applies, Articles 12 and 17, are provisions of the GDPR and apply across the European Union and the EEA. The reasoning on the duty to inform is therefore relevant well beyond France, though it is the national authority in each country that enforces it.

Updates

Independently fact-checked against the cited primary sources

Sources and References

  1. CNIL, Non-respect des droits des personnes : sanction de 300 000 euros a l'encontre de la societe EXTIA (published 9 September 2026)(cnil.fr).gov
  2. Deliberation de la formation restreinte n° SAN-2026-010 du 21 juillet 2026 concernant la societe EXTIA(legifrance.gouv.fr).gov
  3. GDPR Chapter III, Articles 12 and 17 (text hosted by the CNIL)(cnil.fr).gov
  4. EDPB, CEF 2025: Launch of coordinated enforcement on the right to erasure (5 March 2025)(edpb.europa.eu).gov
  5. GDPR Chapter VIII, Article 77 (right to lodge a complaint with a supervisory authority, in particular in the Member State of the complainant's habitual residence, place of work, or place of the alleged infringement), text hosted by the CNIL(cnil.fr).gov
  6. Loi no. 78-17 du 6 janvier 1978 relative a l'informatique, aux fichiers et aux libertes, consolidated text hosted by the CNIL. Article 20 gives the formation restreinte its power to make its measures public and Article 22 provides that financial penalties are recovered as debts owed to the State.(cnil.fr).gov
  7. CNIL, Adresser une plainte, the regulator's own complaints guidance, which states what the CNIL cannot do (including obtaining damages) and tells complainants to exercise the right and keep the evidence of the request(cnil.fr).gov
Share: