[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTCufTxMUkrJccIrWQjlrdZk6RvkhL9T1aeKnx3NjzMo":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"8a54bbdb-493d-44ef-9564-16c5bc245ebf","extia-fined-300000-for-ignoring-gdpr-right-to-erasure-requests","01a0f4c2-c571-4d75-b18a-df34a3e75b67","EXTIA Fined €300,000 for Ignoring GDPR Right to Erasure Requests","EXTIA, a French IT and engineering consulting firm, was sanctioned €300,000 by the CNIL for failing to properly handle individuals' data erasure requests ('right to be forgotten') as required under GDPR. The company lacked adequate processes to respond to these requests in a timely and compliant manner, and failed to inform data subjects appropriately. This case highlights that GDPR obligations are not merely technical — they require robust operational workflows and clear accountability. Organizations that treat data subject rights as a low priority risk significant financial and reputational consequences from regulatory enforcement.","**Immediate actions:**\n- Establish a formal, documented process for receiving, tracking, and responding to all data subject rights requests (erasure, access, portability) within GDPR-mandated timeframes.\n- Appoint or confirm a responsible Data Protection Officer (DPO) with authority to enforce compliance across all business units.\n\n**Long-term improvements:**\n- Implement a Data Subject Request (DSR) management platform to automate intake, routing, and audit trails for all rights requests.\n- Conduct annual GDPR compliance audits covering data subject rights workflows, retention policies, and staff training records.\n- Maintain an up-to-date Record of Processing Activities (RoPA) to ensure all personal data locations are known and erasure can be executed completely.\n\n**Detection & monitoring measures:**\n- Set up internal SLA alerts to flag any data subject request approaching the 30-day statutory response deadline without resolution.\n- Regularly test the end-to-end erasure process across all systems and third-party processors to verify that deletion is complete and verifiable.",[12,13,14,15,16,17,18,19],"GDPR Article 17 – Right to Erasure ('Right to be Forgotten')","GDPR Article 12 – Transparent Information and Communication","GDPR Article 5(1)(e) – Storage Limitation Principle","GDPR Article 37-39 – Data Protection Officer Requirements","NIST Privacy Framework PR.PO-P1 – Policies and Procedures for Privacy","NIST SP 800-53 IP-1 – Consent and IP-2 Individual Access","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management System (PIMS)","published","2026-09-09T08:20:19.424667+00:00","2026-09-09T08:20:19.314+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.cnil.fr\u002Ffr\u002Fsanction-non-respect-droits-personnes-extia","non-respect-des-droits-des-personnes-sanction-de-300-000-euros-a-l-encontre-de-l-a257ef","Non-respect des droits des personnes : sanction de 300 000 euros à l’encontre de la société EXTIA",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]