CNIL (France) - SAN-2026-010
CNIL fines EXTIA €300,000 for GDPR violations related to data erasure requests.
Summary
France's CNIL has fined consulting firm EXTIA €300,000 for failing to properly handle data erasure requests and inform data subjects of the outcomes. The company received numerous complaints regarding difficulties in exercising data subject rights, leading to an on-site inspection. The investigation revealed that a significant portion of erasure requests were not processed, data subjects were not informed of the outcomes, and responses were often delayed, violating Articles 12 and 17 of the GDPR.
Full text
Help CNIL (France) - SAN-2026-010: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 13:07, 24 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators336 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 13:07, 24 September 2026 CNIL - SAN-2026-010 Authority: CNIL (France) Jurisdiction: France Relevant Law: Article 12 GDPR Article 17 GDPR Article 20, Law No. 78-17 of 6 January 1978 relating to data processing, files and freedoms Type: Complaint Outcome: Upheld Started: Decided: 21.07.2026 Published: 09.09.2026 Fine: 300000.0 EUR Parties: EXTIA National Case Number/Name: SAN-2026-010 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): French Original Source: CNIL (in FR) Initial Contributor: bms The DPA fined consulting firm EXTIA €300,000 for failing to properly handle erasure requests and to inform data subjects of the outcome of their requests in accordance with Articles 12 and 17 GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts EXTIA, the controller, is a French consulting company specialising in IT and engineering services. As part of its recruitment activities, the controller processed personal data of job applicants and employees. Following complaints received in 2024 concerning difficulties in exercising the rights of access and erasure, the French Data Protection Authority (CNIL) sent the controller two formal notices reminding it of its obligations under the GDPR. As the controller failed to provide satisfactory responses, further complaints were lodged with the DPA. On 10 April 2025, the DPA conducted an on-site inspection of the controller's premises. The investigation revealed that the controller had received 265 erasure requests in 2024, mainly from unsuccessful job applicants, but had failed to properly handle a significant proportion of them. In particular, the investigation identified requests that had not been processed, requests for which data subjects had not been informed of the outcome, and requests to which the controller had responded after the applicable deadline. The controller argued that many of the requests concerned unsuccessful applicants whose personal data had already been automatically deleted 60 days after their applications were received. It also attributed the shortcomings to the temporary disorganisation of its legal department and a substantial increase in erasure requests. The DPA initiated sanction proceedings against the controller for alleged infringements of Articles 12, 13 and 17 GDPR. During the proceedings, the controller submitted additional evidence of the deletion of personal data and the measures taken to inform the affected data subjects. Holding The DPA found that the controller infringed Articles 12 and 17 GDPR by failing to properly handle erasure requests and inform data subjects of the outcome of their requests. First, the DPA established that the controller had failed to process 12 erasure requests in violation of Articles 12 and 17 GDPR. Although the controller argued that many applicants' personal data had already been automatically deleted after 60 days, the DPA found that this did not exempt it from its obligations regarding the exercise of data subject rights. Second, the DPA found an infringement of Article 12 GDPR because 166 data subjects had not been informed of the outcome of their erasure requests. The DPA recalled that controllers must inform data subjects of the measures taken in response to their requests, regardless of whether their personal data has already been erased or can lawfully be retained. Third, the DPA found a further infringement of Article 12 GDPR because the controller had responded late to 26 erasure requests and one access request. The DPA emphasised that controllers must respond within one month unless a justified extension is communicated to the data subject within that period. In total, 204 erasure requests received in 2024 had not been properly handled, representing more than three-quarters of the requests received that year. The alleged infringement of Article 13 GDPR concerning information provided to employees was withdrawn and was not established. The DPA imposed a €300,000 administrative fine, taking into account the number of affected data subjects, the controller's negligence and its failure to comply with its obligations despite two previous formal notices. Although the controller had subsequently implemented corrective measures, these did not remove its responsibility for the infringements. The DPA decided not to issue an injunction, as the controller had demonstrated that it had addressed the infringements. It also ordered the publication of the decision, which will be anonymised after two years. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the French original. Please refer to the French original for more details. Decision SAN-2026-010 of July 21, 2026 National Commission for Information Technology and Civil Liberties Nature of the decision: Sanction Date of publication on Légifrance: Wednesday, September 9, 2026 Decision No. SAN-2026-010 of the Select Panel dated July 21, 2026, concerning the company EXTIA The National Commission for Information Technology and Civil Liberties, meeting in its select panel composed of Mr. Philippe-Pierre CABOURDIN, Chair; Mr. Vincent LESCLOUS, Vice Chair; Ms. Isabelle LATOURNARIE-WILLEMS; Mr. Didier KLING and Mr. Bertrand du MARAIS, members; Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data; Pursuant to Law No. 78-17 of January 6, 1978, on Information Technology, Filing Systems, and Civil Liberties, in particular articles 20 et seq.; Having regard to Decree No. 2019-536 of May 29, 2019, adopted to implement Law No. 78-17 of January 6, 1978, on Information Technology, Filing Systems, and Civil Liberties; Having regard to Resolution No. 2013-175 of July 4, 2013, adopting the regulations of the National Commission for Information Technology and Civil Liberties; Having regard to Decision No. 2025-1154 QPC of August 8, 2025, of the Constitutional Council; Pursuant to Decision No. 2025-054C of April 8, 2025, by the Chair of the National Commission for Information Technology and Civil Liberties, instructing the Secretary General to conduct or arrange for an audit of the processing operations carried out by or on behalf of the company EXTIA; Having regard to the decision of the President of the National Commission on Information Technology and Civil Liberties appointing a rapporteur before the select panel on March 4, 2026; Whereas the report of Ms. Sophie LAMBREMON, reporting commissioner, dated March 12, 2026, was served on EXTIA on March 13, 2026; Whereas the written observations submitted by EXTIA on April 13, 2026; Having regard to the rapporteur’s response, served on EXTIA on May 7, 2026; Having regard to the new written observations submitted by EXTIA on June 8, 2026; Having regard to the notification to EXTIA on June 15, 2026, that the investigation had been closed; Having regard to the letter from the Chair of the select panel dated June 15, 2026, informing the company that the case was on the agenda for the select panel’s meeting on July 2, 2026; Having regard to the oral arguments presented during the session of the restricted panel on July 2, 2026; Having regard to the other documents in the file; The following were present at the session of the select panel on July 2, 2026: - Ms. Sophie LAMBREMON, Commissioner, whose report was heard; As