France France CNIL GDPR enforcement Big Tech

CNIL's €300,000 EXTIA Fine Shows Erasure Enforcement Targeting Basic Process Failures, Not Big Tech

CNIL fined recruiter EXTIA €300,000 after it mishandled over three-quarters of 265 erasure requests. The case shows what proportionate GDPR enforcement looks like.

EXTIA Erasure Failures at a Glance People of Internet Research · France €300,000 Fine imposed CNIL decision of 21 July 2026. 265 Erasure requests in 2024 Over three-quarters not handled pr… 166 People never told outcome Another 12 requests were never pro… 764 Controllers in EDPB survey 32 authorities took part in the 20… peopleofinternet.com
EXTIA Erasure Failures at a Glance People of Internet Research · France €300,000 Fine imposed 265 Erasure requests in 2024 166 People never told outcome 764 Controllers in EDPB survey peopleofinternet.com

Key Takeaways

On 9 September 2026 the CNIL announced a €300,000 fine on EXTIA, an IT-engineering recruitment and consulting firm. The decision is dated 21 July 2026. According to the CNIL's announcement, EXTIA received 265 erasure requests in 2024, mostly from job candidates and former employees. More than three-quarters were not handled properly: 12 were never processed, 166 people were never told the outcome, and 27 were answered after the one-month legal deadline. The CNIL cited breaches of Articles 12 and 17 GDPR and noted that EXTIA had already been reminded of its obligations twice.

This is not a Big Tech case, despite the topic tag it falls under. That is the interesting part.

The strongest case for the fine

The argument for strict enforcement is straightforward. Article 17 gives people a right to have their personal data erased in specified circumstances, including when keeping it infringes the Regulation. Article 12(3) requires a response "without undue delay and at the latest within one month". A right that a controller can ignore without consequence is a right in name only. Recruiters hold CVs, contact details and assessment notes, and a candidate who asks for deletion has usually concluded the relationship is over. Silence from the company leaves them not knowing whether their data is still circulating among clients.

The record also supports a firm response. By the CNIL's account, EXTIA's failure was not a single administrative slip. Roughly 77% of requests (12 + 166 + 27 of 265) went wrong in some way, and the company had been warned twice. The CNIL did note that EXTIA took remedial steps during the proceedings and eventually informed the affected people. A fine after two warnings is the escalation ladder doing what it is meant to do.

Why this is the right kind of enforcement

The public conversation about GDPR enforcement fixates on headline penalties against the largest platforms. Those cases involve contested legal theories, such as legitimate interest for advertising or the lawfulness of cross-border transfers. They take years and are usually litigated.

The EXTIA case is different. No one disputes that a request must be answered within a month, and there is no novel interpretation to challenge. The failure was operational: nobody owned the inbox, or the process did not work. Enforcement against this kind of failure is more predictable for businesses, because the compliance steps are knowable in advance. It is also more proportionate, because it punishes ignoring rules rather than reading ambiguous ones differently from a regulator. A pro-innovation regime benefits from this clarity. Companies can invest in a ticketing workflow and a retention schedule with confidence about what the regulator will treat as non-compliance.

The coordinated action behind the case

The CNIL found EXTIA through an April 2025 check run under the EDPB's coordinated enforcement action on the right to erasure. The EDPB's February 2026 report says 32 data protection authorities took part and 764 controllers, from SMEs to large enterprises, were surveyed. It identified seven recurring problems:

The report stresses that the right to erasure is not absolute. A Reed Smith summary adds that controllers apply the Article 17(3) exceptions, particularly "compliance with legal obligation", inconsistently and without case-by-case assessment. It also notes that nine authorities opened formal investigations, including in France, Ireland, Portugal, Slovenia and Germany, and that several authorities signal sector-specific inspections in 2026.

This matters because the EXTIA fine is likely an early result of a larger pipeline. Other firms with poor request handling can expect similar scrutiny.

Where the regime still needs discipline

Proportionality cuts both ways. Three cautions follow from the evidence.

First, the difficult parts of Article 17 are the ones the EDPB flagged: backups, retention periods and the balancing of competing rights. Regulators should avoid treating good-faith difficulty in those areas the way they treat a firm that left requests unanswered. EXTIA's alleged failures were of the second kind.

Second, the €300,000 figure sits far below the ceiling the GDPR permits. That restraint is sensible, and the CNIL should keep explaining its reasoning in terms firms can apply: the number of people affected, the repeat warnings, and the remediation.

Third, authorities should publish practical templates and response-time benchmarks alongside fines. Small and mid-sized firms are the ones most likely to lack a documented procedure. Guidance costs a regulator little and prevents more violations than a penalty does.

What companies should take from this

The practical lesson is mundane. Log every erasure request on the day it arrives. Assign a named owner. Track the one-month clock. Send a written outcome even when the answer is a lawful refusal under Article 17(3). Each of these is cheap compared with a six-figure fine, and none requires a legal theory. Enforcement that rewards basic operational discipline, and leaves firms free to innovate on products and services, is the kind of enforcement a pro-innovation observer can defend.

Sources & Citations

  1. CNIL: EXTIA sanction announcement
  2. EDPB: right to erasure coordinated action findings
  3. GDPR (Regulation (EU) 2016/679) text
  4. Reed Smith: EDPB erasure report key takeaways