Administrative fine of 300,000 euros imposed by the French Data Protection Authority on EXTIA for violation of the right to delete personal data

The National Center for Personal Data Protection (CNPDCP), informatively and applicatively, announces an administrative fine of 300,000 euros imposed by the French Data Protection Authority (CNIL) on EXTIA for violating Article 12 (Transparency of information, communication, and exercising data subject rights) and Article 17 (Right to erasure of data, "right to be forgotten") of GDPR. In 2024, CNIL received several complaints from former employees and candidates of EXTIA, a company specializing in information technology and engineering, regarding difficulties in exercising the right to delete personal data. In this context, and as part of the "right to erasure" initiative launched in 2025 by the European Data Protection Committee, CNIL conducted an audit at EXTIA in April 2025, identifying deficiencies in transparency and respect for data subjects' rights. Of the 265 deletion requests received by the company in 2024, most from candidates and some from former employees, over three-quarters were not properly managed. Consequently, CNIL imposed a fine of 300,000 euros on EXTIA, considering the significance of the violations concerning data subjects' rights, the number of affected individuals, and the fact that EXTIA had been previously informed twice about its data protection obligations. CNPDCP, as the national authority overseeing personal data processing, emphasizes the responsibility of operators to ensure compliance with data subjects' rights and to examine and resolve their requests within the legal framework for data protection.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source