[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvNp7qD6FcqcJgUnh13VZbi7T1C5liSY6TloKnhf1qdI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"9aa775b4-ebce-4f40-9e83-14257a389788","extia-fined-300k-for-failing-to-honor-gdpr-erasure-requests","3200f418-cb3c-4a5b-92d2-d830aca6dd90","EXTIA Fined €300K for Failing to Honor GDPR Erasure Requests","French consulting firm EXTIA was fined €300,000 by CNIL for systematically failing to process data subject erasure requests and neglecting to inform individuals of outcomes, violating GDPR Articles 12 and 17. The root cause reflects a lack of mature internal processes and accountability for managing data subject rights, a critical operational obligation under GDPR. This matters because organizations handling personal data must treat rights requests as a formal, time-bound compliance workflow—not an ad hoc administrative task. Failure to do so exposes companies to significant regulatory penalties, reputational damage, and erosion of public trust in data handling practices.","**Immediate actions:**\n- Audit all outstanding data subject rights requests (erasure, access, rectification) and resolve any backlog within GDPR's 30-day response window.\n- Designate a named Data Protection Officer or rights-request coordinator accountable for tracking and responding to every incoming request.\n\n**Process & Workflow improvements:**\n- Implement a dedicated ticketing or case management system to log, track, and escalate data subject rights requests with automated deadline reminders.\n- Establish templated response communications to ensure data subjects are formally notified of the outcome of every request, whether fulfilled or refused.\n- Define and document an internal SLA for rights requests that is stricter than the GDPR statutory deadline to build in buffer time for review.\n\n**Long-term compliance measures:**\n- Conduct periodic internal audits and simulated rights-request exercises to validate that processes function correctly end-to-end.\n- Integrate GDPR rights-request handling into employee onboarding and annual compliance training so all relevant staff understand their obligations.\n- Maintain a structured Record of Processing Activities (RoPA) that maps where personal data resides, enabling faster and more complete erasure execution.",[12,13,14,15,16,17,18,19],"GDPR Article 12 – Transparent information and communication","GDPR Article 17 – Right to erasure ('right to be forgotten')","GDPR Article 5(1)(f) – Integrity and confidentiality","NIST SP 800-53 IP-3 – Information Management and Retention","NIST Privacy Framework: Respond-RS.CM-P1","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management (PIMS)","ITIL Service Management – Request Fulfilment Process","published","2026-09-24T19:21:07.416518+00:00","2026-09-24T19:21:05.814+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CNIL_(France)_-_SAN-2026-010&diff=53187&oldid=0","cnil-france-san-2026-010-70ce6e","CNIL (France) - SAN-2026-010",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]