Back to all lessons
Awareness Lessons
2 weeks ago

EXTIA Fined €300K for Failing to Honor GDPR Data Erasure Requests

French consulting firm EXTIA was fined €300,000 by the CNIL for systematically failing to process data subject erasure requests, respond within legal timeframes, and notify individuals of outcomes — all core obligations under GDPR Article 17. The root cause was a combination of poor internal processes, departmental disorganization, and an over-reliance on assumed automatic deletion mechanisms that were never properly verified. This case illustrates that 'we meant to delete it' is not a defensible compliance posture under EU data protection law. Organizations handling personal data in recruitment or HR contexts must treat data subject rights as operational obligations, not administrative afterthoughts. The financial and reputational consequences of ignoring these duties are significant and growing.

Tactical Insight

Immediate actions

  • Establish a centralized Data Subject Rights (DSR) intake and tracking system to ensure no erasure, access, or rectification request goes unlogged.
  • Audit all existing unprocessed or overdue data subject requests and respond within GDPR's one-month deadline.
  • Verify that any claimed 'automatic deletion' mechanisms are actually functioning and document evidence of their operation.

Long-term improvements

  • Implement a formal DSR workflow with assigned ownership, escalation paths, and SLA-based alerting for approaching deadlines.
  • Conduct regular data mapping exercises to identify where personal data (especially recruitment data) is stored, duplicated, or retained beyond necessity.
  • Embed GDPR rights-handling procedures into HR and recruitment department onboarding and annual training programs.

Detection & monitoring measures

  • Deploy dashboards or ticketing system reports that surface open DSR requests nearing or exceeding the 30-day response window.
  • Schedule quarterly internal audits of DSR compliance rates and escalate failures to DPO and senior management.
  • Maintain immutable logs of all DSR requests received, actions taken, and notifications sent to data subjects as evidence of compliance.