A €300,000 fine, imposed on July 21, 2026
On July 21, 2026, CNIL, the French data protection authority, imposed a €300,000 fine against EXTIA. The company operates in IT consulting and engineering, and places consultants with client companies. The legal basis for the decision is Articles 12 and 17 of Regulation (EU) 2016/679, the GDPR, which has been in force since May 25, 2018.
Jurisdiction is French; the rule applied is valid in all twenty-seven Member States.
CNIL's restricted formation, the body that decides on sanctions, contested two distinct practices: erasure requests left unprocessed and individuals kept unaware of the outcome. The EDPB registry published the case entry on September 11, 2026.
The case originated from complaints by former employees and candidates that reached CNIL during 2024. The inspection of the company took place in April 2025 and covered the entire data management cycle for individuals under recruitment.
Articles 12 and 17: the obligation and the numbers of the case
Article 17 recognizes the right to erasure, the so-called right to be forgotten. Article 12 imposes a different and often overlooked duty: to respond to the data subject within one month of receiving the request.
These two obligations are independent. Erasing the data is the first. Informing the person of the action taken is the second, and it remains due even when the erasure has occurred.
In 2024 EXTIA received 265 erasure requests, mostly from candidates and to a lesser extent from former employees: more than three-quarters remained unprocessed or were handled irregularly, according to the entry published by the EDPB[1].
The breakdown weighs more than the total. Twelve requests received no processing whatsoever. One hundred sixty-six individuals remained unaware of the outcome, and another twenty-seven received the response beyond the legal deadline, with delays of up to several months.
The fine amount reflects three factors stated by the authority: the essential nature of the violated principles, the number of individuals involved, and two prior warnings already issued to the same company. Recidivism is the third factor, and the most costly.
The coordinated European action on the right to erasure
The April 2025 inspection has a twofold origin. On one hand, individual complaints; on the other, the coordinated action on the right to erasure launched by the European Data Protection Board in 2025.
The Coordinated Enforcement Framework is the instrument by which the EDPB selects a theme each year and has it verified in parallel by national authorities. In 2025 the theme was the right to be forgotten.
This changes the nature of the risk. A French decision on the right to erasure becomes the local result of a continental control grid. The same questions reach controllers in Italy, Spain, Germany and the Netherlands, with the same methodology and within the same timeframe.
The case should be read as a sample of a European verification, rather than as a French exception.
The governance signal: the missing role has a name
The governance signal: when the data subject's right lacks an internal owner designated by name, compliance remains on paper.
An erasure request travels through multiple systems. The recruitment ATS, the commercial CRM, individual recruiters' mailboxes, backups, locally maintained spreadsheets. Each step has a different manager, and coordination is the weak link.
Which role, designated by name and in writing, is responsible for the outcome of each erasure request, before the request arrives? This is the question the General Counsel poses to the Data Protection Officer, and the answer must be put in a dated document.
A framework lacking that name produces documentation: governance is something else. The EXTIA case measures in euros the distance between the two.
Candidates, recruitment archives, and automated systems
The affected population here consists predominantly of candidates. This is the category of data subjects with the weakest contractual relationship and the longest digital memory.
A resume enters a recruitment archive and stays there for years. It feeds internal searches, matching scores, queues of applications ordered automatically. Erasure thus touches also the data that these systems use as raw material.
Annex III of Regulation (EU) 2024/1689, the AI Act, places systems used for personnel selection and evaluation among those at high risk. The implementation timeline for those obligations remains in flux at the European level, and prudent organizations treat it as ongoing implementation.
CNIL's decision concerns the right to erasure and leaves out the issue of automated decisions. The two regimes nevertheless converge on the same archive, and the audit needed is one.
The objection on the amount and the case's response
A recurring objection concerns the amount: €300,000 weighs little in the income statement of a consulting group. The argument hits the wrong target.
The value of the decision lies in its reasoning. A national authority has put in writing that silence toward the data subject is a standalone violation, contestable even when the data appears to have been deleted.
A second reading describes the case as a resource problem: 265 requests in a year are a manageable load with dedicated staff. The numbers support this reading in part, and weaken it in detail: 166 people were waiting for a message, rather than a complex technical operation.
CNIL's sanction against EXTIA comes after two prior warnings, and this detail shifts the center of gravity of the analysis. The authority counted people, and set aside the count of work hours.
Three decisions for the board
The case leaves three decisions on the table, and each has a specific recipient.
One, for the General Counsel and Chief Compliance Officer: count the erasure requests from the past twenty-four months, with date of receipt, date of response and outcome. An incomplete register is itself already a finding.
Two, for the Chief Risk Officer: update the risk matrix by distinguishing failure to erase from failure to inform. These are two separate violations, with two separate controls and two different owners.
Three, for the Board Audit & Risk Committee: ask for the name of the role responsible for data subjects' rights and the date of its designation. That name belongs to internal disclosure, even before external disclosure.
Regulatory horizon
Articles 12 and 17 of the GDPR have been in force since May 25, 2018 and apply directly in all Member States. The response deadline remains one month, extendable by two months for complex requests, with reasoned notice to the data subject.
The EDPB's coordinated action on the right to erasure opened the inspection season in 2025 and produces national decisions during 2026. The EXTIA case, decided on July 21, 2026 and published on September 11, 2026, belongs to that sequence.
On the front of automated personnel selection systems, Regulation (EU) 2024/1689 remains in the implementation phase, with a European timeline still settling. Organizations that build now the register of requests and the chain of responsibility arrive at that deadline with the work already done.
The question on the right to erasure has had an answer. A second question has opened: who, by name, is responsible for the answer?
This article was written by an AI editorial author with human supervision, in compliance with transparency obligations under Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by ATLAS
Sources
- the entry published by the EDPB 11 Sep 2026 (edpb.europa.eu)