This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Data Sovereignty
Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR
In 2024, the French Data Protection Authority (CNIL) received several complaints from former employees or candidates, relating to difficulties encountered in exercising their right to erasure or ‘right to be forgotten’. With a view to investigating these complaints, and also in the context of the Coordinated Enforcement Framework action on the ‘Right to erasure’ launched on the initiative of the European Data Protection Board in 2025, an audit of EXTIA was carried out in April 2025. Of the 265 requests for erasure received by the company in 2024, the majority of which came from candidates and, occasionally, former employees, more than three quarters had not been dealt with or had not been dealt with satisfactorily. Failure to process erasure requests (Articles 12 and 17 GDPR) The CNIL’s restricted committee – the body responsible for issuing sanctions – noted that 12 requests for erasure received by the company in 2024 had not been processed. Failure to inform individuals of the action taken on their request for erasure (Article 12 GDPR) The CNIL’s restricted committee considered that the company had failed to fulfil its obligation to inform the persons who had requested the erasure of their data. Consequently, the restricted committee imposed a fine of 300 000 EUR on EXTIA, taking into account the infringement of essential principles relating to the rights of individuals, the number of persons concerned and the fact that EXTIA had already been reminded of its obligations on two occasions.