Failure to respect the rights of individuals: EUR 300,000 fine against EXTIA

09 September 2026


On 21 July 2026, the CNIL fined EXTIA EUR 300,000 for various breaches relating to respect for the rights of individuals, in particular the right to erasure of personal data (‘right to be forgotten’).

The context

EXTIA, which specialises in IT and engineering, recruits consultants for various technical projects from its client companies. 

In 2024, the CNIL received several complaints from former employees or candidates, relating to difficulties encountered in exercising their right to erasure or ‘right to be forgotten’ (Article 17 of the General Data Protection Regulation). With a view to investigating these complaints, and also in the context of the coordinated action (CEF) ‘Right to erasure’ launched on the initiative of the European Data Protection Board in 2025, an audit of EXTIA was carried out in April 2025. It identified breaches of several obligations under the GDPR regarding transparency and respect for individuals’ rights.

Of the 265 requests for erasure received by the company in 2024, the majority of which came from candidates and, occasionally, former employees, more than three quarters had not been dealt with or had not been dealt with satisfactorily.

Consequently, the restricted panel – the body of the CNIL responsible for issuing sanctions – imposed a fine of EUR 300,000 on EXTIA, taking into account the infringement of essential principles relating to the rights of individuals, the number of persons concerned and the fact that EXTIA had already been reminded of its obligations on two occasions.

The infringements sanctionned

Failure to process erasure requests (Articles 12 and 17 GDPR)

The restricted committee noted that 12 requests for erasure received by the company in 2024 had not been processed. It took the view that that failure had adversely affected the rights of those persons, including the right to retain control over their data.

On the other hand, the restricted committee noted that the company had taken measures in the course of the procedure to remedy the infringement, by deleting the data in question and informing individuals of the action taken on their request.

Failure to inform individuals of the action taken on their request for erasure (Article 12 GDPR)

The restricted committee took the view that the company had failed to fulfil its obligation to inform the persons who had requested the erasure of their data.

It noted that 166 persons who had made a request for erasure in 2024 had not been informed of the action taken on that request. Another 27 people had received this information late (outside the legal one-month deadline), with delays of up to several months.

While the company contested the seriousness of the infringement, stating that many of those requests concerned candidates whose data had been automatically deleted, the restricted committee pointed out that that automatic deletion did not exempt the company from informing those candidates of the outcome of their requests.

However, the restricted committee noted that, during the procedure, the company had informed the persons of the outcome of their application. For a residual number of requests, it considered that the company had provided valid reasons as to why the information could not be made (e.g. impossibility to identify the person concerned).