Skip to content

Regulatory Pulse

CNIL fines EXTIA €300,000 over erasure-request failures and late responses

The final decision shows that back-end deletion does not replace the duty to respond: most 2024 erasure requests were not handled satisfactorily, and many requesters were not told the outcome.

France and European Union
GDPR rights requests, erasure and privacy operations
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Final GDPR enforcement decision · Reviewed 10 September 2026 · 7 min read

The 60-second summary

On 9 September 2026, the CNIL announced a €300,000 fine against IT and engineering consultancy EXTIA following complaints from former employees and candidates and an audit conducted in the EDPB’s 2025 coordinated enforcement action on erasure. Of 265 erasure requests received in 2024, more than three quarters were not handled or were not handled satisfactorily. The CNIL identified 12 requests that had not been processed, 166 requesters who had not been told what action was taken and 27 who received that information late, with some delays lasting several months. The regulator stressed that automatic back-end deletion does not remove the duty to inform the requester of the outcome.

Timeline that matters

  1. 2024

    Requests and complaints

    The controller received 265 erasure requests, while the CNIL received complaints from candidates and former employees.

  2. April 2025

    Audit conducted

    The CNIL audited the controller in the EDPB coordinated enforcement action on erasure.

  3. 21 July 2026

    Decision adopted

    The CNIL restricted committee adopted decision SAN-2026-010.

  4. 9 September 2026

    Decision announced

    The CNIL published its enforcement summary and €300,000 fine.

  5. 10 September 2026

    Editorial review

    PrivacyBuilt verified the official summary and sources.

  6. 10 October 2026

    Next review

    Check for appeal information or material regulator clarification.

What changed

The decision turns a common privacy-operations gap into a clear enforcement lesson: executing deletion and communicating the outcome are distinct obligations. Organisations need a traceable workflow that captures each request, verifies scope and identity, performs deletion or records a lawful exception, sends a timely response and retains evidence of every step.

Who should pay attention?

Privacy operations

Own intake, deadlines, triage, fulfilment, response and closure evidence end to end.

HR and recruitment teams

Locate candidate and former-worker data across applicant tracking, email, file shares and vendor systems.

Data and system owners

Return auditable confirmation of deletion, restriction, retention exceptions and downstream propagation.

Customer support

Recognise rights requests and route them immediately without losing the receipt date.

Vendors and processors

Meet assistance deadlines and provide evidence that instructions were completed across subprocessors.

What the guidance clarifies

Deletion and response are separate duties
Automatic deletion did not excuse the controller from telling candidates what action had been taken.
The one-month response period matters
The CNIL identified late communications, including delays of several months.
A workflow can fail even when some data disappears
The organisation must prove that each request was assessed, executed where required and closed with a response.
Valid limits still need documented reasoning
Where a requester cannot be identified or an exception applies, the decision and communication should be recorded.
Repeated warnings can increase enforcement risk
The CNIL considered that the controller had already been reminded of its obligations twice.

A rights request is not complete until action and communication are evidenced

Why this matters for global organisations

Deletion automation, retention jobs and informal messages do not by themselves create a defensible rights process. Organisations need a single accountable workflow that preserves the receipt date, identifies every relevant system, records the legal decision, verifies downstream action and delivers a timely, intelligible response.

  • Track one response deadline across every intake channel.
  • Separate deletion execution from requester communication and evidence both.
  • Reconcile primary systems, archives, email and vendor environments.
  • Record exceptions, identity issues, extensions and delivery evidence.

13 actions to start now

  1. Map every channel through which a rights request can arrive, including HR and recruitment channels.
  2. Create a central case record at first receipt and preserve the original timestamp.
  3. Define identity-verification steps proportionate to the request and risk.
  4. Set automated alerts before the applicable response deadline and escalation thresholds.
  5. Search applicant tracking, HR, CRM, email, file storage, analytics and archive systems.
  6. Assign each system an accountable fulfiller and service-level target.
  7. Document whether data is erased, restricted, anonymised, retained under an exception or cannot be located.
  8. Propagate valid instructions to processors and subprocessors and collect completion evidence.
  9. Reconcile automated deletion jobs with individual case records.
  10. Send a clear outcome response even where deletion occurred automatically.
  11. Document extensions, refusals, partial fulfilment and identity problems with reasons.
  12. Sample closed cases for completeness, timeliness and response-delivery evidence.
  13. Report volumes, ageing, exceptions, repeat contacts and control failures to accountable leaders.

Suggested next steps

  • Review a representative sample of recent erasure cases from receipt through requester communication. Reconcile automated deletion evidence, downstream completion and response timing, then remediate gaps with qualified specialists.

Evidence worth retaining

  • Rights-request channel inventory and routing procedures.
  • Case records showing receipt dates, identity checks and scope.
  • Deadline calculations, alerts, extensions and escalations.
  • System-search logs and data-owner attestations.
  • Deletion, restriction, anonymisation and exception records.
  • Processor instructions and downstream completion confirmations.
  • Copies of outcome communications and delivery evidence.
  • Records of refusals, partial fulfilment and inability to identify a requester.
  • Automated deletion-job logs reconciled to case records.
  • Quality-assurance samples, defects and remediation tickets.
  • Training records for recruitment, HR and support teams.
  • Management metrics and recurring control-test results.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Can requests received outside the privacy inbox enter the case system immediately?
  • Which date starts the response clock for each intake channel?
  • Can the organisation search candidate, employee and customer data across all systems?
  • How are archived email, backups and legal holds handled?
  • Who confirms deletion in each processor and subprocessor environment?
  • Does every closed case contain a copy of the requester’s outcome response?
  • How are automatic deletion events linked to individual requests?
  • Which circumstances justify an extension, refusal or continued retention?
  • How is response delivery proved if an address fails or the requester cannot be identified?
  • Which recurring defects require workflow, contractual or specialist legal changes?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.