Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR
CNIL fines EXTIA €300,000 for failing to respect data subject rights.
Summary
The French Data Protection Authority (CNIL) has fined EXTIA, an IT and engineering recruitment firm, €300,000 for failing to adequately process erasure requests from former employees and candidates. The company failed to act on over three-quarters of erasure requests in 2024 and did not properly inform individuals about the actions taken, violating GDPR articles 12 and 17.
Full text
Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR National News 11 September 2026 fr Background informationDate of final decision: 21 July 2026National caseLegal Reference(s): Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 17 (Right to erasure ‘right to be forgotten’)Decision: Administrative fineKey words: Data subject rightsSummary of the DecisionOrigin of the case EXTIA, which specialises in IT and engineering, recruits consultants for various technical projects from its client companies. In 2024, the French Data Protection Authority (CNIL) received several complaints from former employees or candidates, relating to difficulties encountered in exercising their right to erasure or ‘right to be forgotten’. With a view to investigating these complaints, and also in the context of the Coordinated Enforcement Framework action on the ‘Right to erasure’ launched on the initiative of the European Data Protection Board in 2025, an audit of EXTIA was carried out in April 2025. It identified breaches of several obligations under the GDPR regarding transparency and respect for individuals’ rights.Of the 265 requests for erasure received by the company in 2024, the majority of which came from candidates and, occasionally, former employees, more than three quarters had not been dealt with or had not been dealt with satisfactorily.Key FindingsFailure to process erasure requests (Articles 12 and 17 GDPR)The CNIL’s restricted committee – the body responsible for issuing sanctions – noted that 12 requests for erasure received by the company in 2024 had not been processed. It considered that that failure had adversely affected the rights of those persons, including the right to retain control over their data.Failure to inform individuals of the action taken on their request for erasure (Article 12 GDPR)The CNIL’s restricted committee considered that the company had failed to fulfil its obligation to inform the persons who had requested the erasure of their data. It noted that 166 persons who had made a request for erasure in 2024 had not been informed of the action taken on that request. Another 27 people had received this information late (outside the legal one-month deadline), with delays of up to several months.DecisionConsequently, the restricted committee imposed a fine of 300 000 EUR on EXTIA, taking into account the infringement of essential principles relating to the rights of individuals, the number of persons concerned and the fact that EXTIA had already been reminded of its obligations on two occasions.For further information: Failure to respect the rights of individuals: EUR 300,000 fine against EXTIANon-respect des droits des personnes : sanction de 300 000 euros à l’encontre de la société EXTIA Relevant topics Data subject rights Latest news RSS Feed National News fr Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR09 September 2026 National News ie Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE)03 September 2026 EDPB News Stakeholder event on guidelines on the interplay between data protection and competition law: overview of topics available30 July 2026All news