Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR
Cybersecurity Classified by Officially
Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR
EXTIA, which specialises in IT and engineering, recruits consultants for various technical projects from its client companies.
In 2024, the French Data Protection Authority (CNIL) received several complaints from former employees or candidates, relating to difficulties encountered in exercising their right to erasure or ‘right to be forgotten’. With a view to investigating these complaints, and also in the context of the Coordinated Enforcement Framework action on the ‘Right to erasure’ launched on the initiative of the European Data Protection Board in 2025, an audit of EXTIA was carried out in April 2025. It identified breaches of several obligations under the GDPR regarding transparency and respect for individuals’ rights.
Of the 265 requests for erasure received by the company in 2024, the majority of which came from candidates and, occasionally, former employees, more than three quarters had not been dealt with or had not been dealt with satisfactorily.
Failure to process erasure requests (Articles 12 and 17 GDPR)
The CNIL’s restricted committee – the body responsible for issuing sanctions – noted that 12 requests for erasure received by the company in 2024 had not been processed. It considered that that failure had adversely affected the rights of those persons, including the right to retain control over their data.
Failure to inform individuals of the action taken on their request for erasure (Article 12 GDPR)
This is an extract. The publication continues at the source.
Read the original at the source: https://www.edpb.europa.eu/news/failure-to-respect-the-rights-of-individuals-the-cnil-fined-extia-300-000-eur_en
Officially imported this from European Data Protection Board’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
3 versions recorded. The original is kept in full — nothing is overwritten.
- v3 imported change on current
- v2 imported change on
- v1 as first published on
Provenance
- Organization
- European Data Protection Board — imported from official source
- Official source
- https://www.edpb.europa.eu/feed/news_en RSS
- Imported
- September 15, 2026 19:08
- Versions
- 3 recorded
- Identity
9cce9bb5-3b4a-441b-a006-9f0ca73ef17f