GDPR: CNIL fines EXTIA €300k for erasure failures
CNIL fines EXTIA €300,000 for breaches of GDPR Articles 12 and 17 on the right to erasure and one‑month response obligations.
CNIL fines EXTIA: €300k for failure to honor the right to erasure
On July 21, 2026, the CNIL imposed a €300,000 fine on EXTIA for breaches of GDPR Articles 12 and 17 in handling erasure requests from applicants and former employees. Key lesson: the one‑month response and information duties are non‑negotiable. CNIL source.
The case
EXTIA, an engineering consultancy, was audited as part of the EDPB’s 2025 coordinated enforcement on the right to erasure. The CNIL found that, out of 265 requests received in 2024, over three quarters were mishandled and 166 data subjects were not informed of outcomes, some beyond the one‑month legal deadline (Article 12 GDPR). The restricted committee sanctioned several infringements: failure to process requests (Articles 12 and 17), lack of outcome information (Article 12), and repeated delays despite prior reminders. Decision: €300,000 fine, with official reference to decision SAN‑2026‑010 published on Légifrance. CNIL, Sept 9, 2026; Légifrance – SAN‑2026‑010.
European context: on March 5, 2025, the EDPB launched a CEF action dedicated to the right to erasure (Article 17), to aggregate national findings and enable targeted follow‑ups. EDPB, March 5, 2025.
Legal reasoning
- Baseline: GDPR Articles 12 and 17. Article 12 mandates clear modalities: information that is “concise, transparent, intelligible” and a response “without undue delay and at the latest within one month” for requests under Articles 15–22; in case of inaction, the duty to inform the person of reasons and remedies. Article 17 establishes the right to erasure, subject to exceptions (legal retention, establishment/exercise/defense of legal claims, etc.). GDPR on EUR‑Lex, Arts. 12 and 17 — see also our GDPR reference page.
- CNIL’s view: controllers must not only erase where conditions are met, but also evidence effective handling of requests (traceability of flows and replies, including when erasure is automated). “Automatic” deletion does not dispense with individual outcome notices within one month (Article 12(3)‑(4)). CNIL – EXTIA.
- EDPB position: CEF 2025 reiterates that Article 17 is among the most exercised rights; the key requirement is implementing effective channels and procedures, with deadline tracking, exception handling, and notification to recipients (Article 19 GDPR). EDPB – CEF 2025.
- Luxembourg benchmark: the CNPD emphasizes the same requirements: one‑month response, duty to inform and justify any refusal, management of legal exceptions, and duty to notify recipients of erasure (Articles 12, 17 and 19). CNPD – Chapter III GDPR; CNPD – Right to erasure.
What this changes in practice
For executives, DPOs and CISOs in Luxembourg (and cross‑border), the EXTIA case confirms:
- A “data subject rights process” is a baseline control: request log, timestamps, a one‑month SLA, response templates, refusal grounds (Articles 12(5), 17(3), 21), traceability of erasures, and recipient notification (Article 19). Where operational support is needed, a structured DPO mandate helps industrialize the program.
- HR and recruiting are high‑risk: candidate CRMs, assessment platforms and ATS hold diverse data (CVs, assessments, history). “Technical” deletions (scheduled purges) must be linked to timely legal replies. Lack of a bridge between tooling and the legal front end leads to enforcement exposure.
- Exceptions do not waive communications: if a legal duty requires retention (e.g., labor law, statutes of limitation), reply within one month explaining the legal bases and categories retained; apply restriction (Article 18) in the interim and notify recipients (Article 19). CNPD – Duty to inform on retention.
- Cross‑border industrialization is expected: FR/LU/BE/DE groups should harmonize intake channels (portal, dedicated email, forms), playbooks (ID, verification, exceptions), and technical integrations (erasure APIs with processors) per Article 28 (demonstrate execution and enable audit). CNIL – Processor (Art. 28) — a key point for organizations in Luxembourg under CNPD oversight.
Concrete examples (HR and B2B marketing)
- Candidate requests “total deletion”: if payroll documents must be retained for social obligations, respond within one month explaining legal bases and retained categories; apply restriction (Article 18) meanwhile and notify recipients (Article 19). Basis: Articles 12, 17, 18, 19 GDPR; CNPD guidance. CNPD – Chapter III.
- B2B prospect exercises a right: if legitimate interest for direct marketing is invoked, document a partial refusal (opt‑out list) and delete non‑essential data; ensure alignment with EDPB work on Article 6(1)(f) and transparency. EDPB – Legitimate interest digest.
Common pitfalls
- Equating “automatic deletion” with “legal response”: scheduled purges do not replace an individualized, reasoned reply within one month (Article 12(3)‑(4)). This is central to the EXTIA sanction. CNIL – EXTIA.
- Forgetting recipients: Article 19 requires communicating erasure/rectification/restriction to each recipient, unless impossible or involving disproportionate effort duly justified. EUR‑Lex – Art. 19.
- Poor identity handling: lack of risk‑based identification and verification (e.g., requests from personal addresses) leads to unjustified refusals or disclosures. Keep a proportional evidence matrix (Article 12(6)).
- Invoking exceptions without documentation: citing “legal obligation” or “defense of claims” without referencing the text and without applying restriction (Article 18) is sanctionable. CNPD – Retention and information.
- Unaligned processors: controller‑side erasure is not synchronized with processors; Article 28 requires clauses, evidence of execution and audit rights. CNIL – Processor (Art. 28).
Official sources
- CNIL, “Non‑respect des droits des personnes: sanction de 300 000 € à l’encontre d’EXTIA,” Sept 9, 2026 (decision of July 21, 2026, SAN‑2026‑010). https://www.cnil.fr/fr/sanction-non-respect-droits-personnes-extia
- EDPB, “CEF 2025: Launch of coordinated enforcement on the right to erasure (Art. 17),” March 5, 2025. https://www.edpb.europa.eu/news/cef-2025-launch-of-coordinated-enforcement-right-erasure_ga
- GDPR (Articles 12, 17, 19) – EUR‑Lex. https://eur-lex.europa.eu/legal-content/FR-EN/TXT/?uri=CELEX%3A32016R0679
- CNPD Luxembourg – Chapter III (rights), right to erasure, and duty to inform on retention. https://cnpd.public.lu/fr/legislation/droit-europ/union-europeenne/rgpd/chapitre-3.html; https://cnpd.public.lu/fr/particuliers/vos-droits/droit-oubli.html; https://cnpd.public.lu/fr/dossiers-thematiques/psp/duree-conservation-donnes-service-paiement/obligation-informer.html
- CNIL – Processor (Article 28 GDPR). https://www.cnil.fr/fr/sous-traitant
Luxembourg focus: CNPD shares the one‑month response requirement and documentation rigor. For cross‑border entities (LU/FR/BE/DE), aligned processes and technical execution (workflows, processor erasure APIs, evidence) are now expected, and the EXTIA case shows the financial and reputational risk of a non‑industrialized rights framework.
Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →