France's data protection authority has fined IT and engineering consultancy EXTIA 300,000 euros after finding that 204 of the 265 deletion requests the company received during 2024 were never processed, never answered, or answered months late. The decision, taken on 21 July 2026, was published on the CNIL website and on Legifrance on 9 September 2026, and summarised by the European Data Protection Board two days later.

In Short

A French consulting firm that collects CVs from job applicants got a 300,000 euro fine because it did not reply to people who asked it to delete their data. More than three quarters of the deletion requests it received in one year were either ignored, answered too late, or handled without ever telling the person what happened. The regulator made clear that deleting data automatically on a timer does not count as an answer: the company still had to write back within a month, and it did not.

A recruitment database, not an advertising one

EXTIA is a simplified joint-stock company created in 2007 with its registered office at 1 avenue de la Cristallerie in Sevres, in the Hauts-de-Seine department. According to the deliberation, it operates around twenty establishments across France and employed 2,000 people in 2025, of whom between 1,600 and 1,700 were consultants placed on technical, digital and engineering projects at client companies.

The processing at issue is human resources processing, covering both candidate data and employee data. Recruitment runs on two tracks. Passive search collects applications submitted against job postings published on the company's own site or on specialist job boards. Active search works the other way: EXTIA approaches individuals who have posted a curriculum vitae on specialist sites. Both tracks feed the same internal tool, which the company designed, developed, administers and maintains itself, and which digitises the handling of applications.

The restricted committee treated EXTIA as the controller for that processing. Three elements supported the finding. The company told the inspection delegation during the on-site visit of 10 April 2025 that it was responsible for recruitment processing. Its record of processing activities names it as controller for human resources operations spanning personnel administration, payroll, recruitment and communication. And it built the software layer through which applications are managed.

Candidates move through five internal categories set out in the company's defence: unshortlisted spontaneous applicants, shortlisted spontaneous applicants, qualified candidates, qualified candidates not retained, and qualified candidates retained. Spontaneous applications land in a database that EXTIA says purges automatically 60 days after submission. Shortlisted files move to a separate qualified-candidates database, where they join profiles sourced through active search and where a candidate record is created. Qualified candidates who are not hired are kept by default for two years from their last interaction with the company. Those who are hired become employees, and their data moves again.

The volume matters for reading the enforcement numbers. According to the decision, EXTIA received 28,322 applications during 2024 and 265 erasure requests, almost all of them from former candidates.

What the restricted committee established

The case did not start with an inspection. Two complaints reached the CNIL on 16 April and 17 June 2024 from individuals reporting difficulty exercising rights of access and erasure. The regulator responded with two formal reminders of the law, sent on 19 April and 20 June 2024, setting out the company's obligations when it receives rights requests. Two further complaints followed, on 3 June and 7 November 2024, after what the decision describes as an absence of satisfactory response.

The CNIL president signed a verification order on 8 April 2025. The on-site inspection took place at EXTIA's head office on 10 April 2025. The record of that inspection had to be served twice, on 11 and 25 April 2025, because of a material error in the first version. The company supplied additional material on 30 April and 12 May 2025.

Sophie Lambremon was appointed rapporteure on 4 March 2026, nearly eleven months after the inspection. Her report, dated 12 March 2026 and served the following day, alleged breaches of Articles 12, 13 and 17 of the General Data Protection Regulation and proposed an administrative fine, an injunction backed by a periodic penalty payment, and publication of the decision. EXTIA filed observations on 13 April 2026, the rapporteure replied on 7 May, and the company filed a second set on 8 June. The investigation closed on 15 June 2026 and the case was heard on 2 July.

Three findings survived that exchange, and one did not.

Twelve requests never processed

The report initially identified 145 erasure requests from 2024 that had not been handled despite containing enough information to identify the person. EXTIA contested the figure in two stages, first putting the number of unsatisfied requests at seven, then revising it to twelve.

Its argument on the bulk of the disputed cases was that 125 of the 145 concerned unshortlisted candidates whose data had already been deleted automatically after 60 days, making the requests moot. The company added that the rejection email sent to that category of applicant had stated a retention period of two years by mistake, when the period actually applied was 60 days, and that the error had triggered an unusually large wave of deletion requests while its legal team was going through what the decision calls a temporary disorganisation.

The rapporteure pushed back on the evidentiary basis. The 60-day period had not been mentioned during the on-site inspection, did not appear in any internal data governance document, and was first raised only in response to the sanction report. The restricted committee took note of the company's position on those 125 cases and did not find an Article 17 breach for them, moving the question to the information obligation instead.

Eight further cases were set aside as genuinely particular: two people could not be identified, four were former employees whose data was partly retained under legal obligations, one request had been handled before the inspection, and one read more like a comment than a request. On the four former employees, the committee held that EXTIA could not rely on their status alone without giving precise reasons for refusing deletion.

What remained was twelve erasure requests received in 2024 that were never processed, a breach of Articles 12 and 17 taken together.

One hundred and sixty-six people never told what happened

The second finding is the largest by volume and the most consequential in principle. The rapporteure's report named 37 people who had not been informed of the outcome of their request by the date of the inspection. The final count is 166.

The arithmetic is set out in the decision. To the 37 the committee added 129 more: the 125 unshortlisted candidates whose data EXTIA said had been purged on the 60-day timer, and the four former employees whose data was partly retained under legal prescription. The inspection delegation had received the complete individual files for every erasure request made in 2024 along with any replies sent. None of the 166 files contained an email informing the person of the outcome, a point the company did not contest.

The reasoning here is the part with the broadest reach. Actual deletion of the data, the committee held, has no bearing on the separate duty to tell the person what was done. Article 12(3) requires information on the measures taken within one month. Article 12(4) requires, where the controller does not act on a request, that it explain why and mention the right to complain to a supervisory authority and to seek a judicial remedy. Neither obligation is discharged by a retention schedule running in the background.

The committee put the point bluntly in its assessment of the overall gravity: the automatic deletion of the data of 125 unshortlisted candidates after 60 days, advanced by the company to limit its responsibility, cannot conceal that none of those 125 requests was actually examined when it arrived.

Twenty-six late, or twenty-seven

The third finding concerns timing. The report alleged at least 27 erasure requests and one access request answered late, with delays running to several months.

The committee reduced the erasure count by one. A request dated 2025 fell outside the temporal scope of the proceedings, was not among the 265 requests communicated to the CNIL after the inspection, and had in any case been granted. That left 26 erasure requests answered late, with delays reaching more than five to six months, plus one access request received in 2024 where the person was informed of the outcome more than a year late.

Here a discrepancy runs between the documents. The operative decision on Legifrance states 26 erasure requests and one access request, a total of 27 people. The CNIL's own summary page and the EDPB's English-language summary both describe 27 people who received the information late without separating the access request from the erasure requests. The totals reconcile at 27 individuals either way, but the composition differs depending on which document is read, and the deliberation is the authoritative text.

EXTIA did not contest the late-response finding. It argued that ten of the 26 concerned unshortlisted candidates whose data had already gone, and that the delays stemmed from the 2024 disorganisation of its legal service, which forced it to prioritise handling requests over informing the people who made them. The committee restated that the one-month response duty is an autonomous obligation that automatic deletion does not offset.

The transparency grievance that was dropped

The rapporteure had also alleged a breach of Article 13, on the ground that the data processing attestation handed to new employees omitted any mention of retention periods. After reviewing the documentation and explanations filed in defence, she abandoned the grievance in her reply and at the hearing. The committee recorded that it was no longer maintained and in any event not established.

How 300,000 euros was reached

Articles 12 and 17 sit in the upper penalty tier. Under Article 83(5) of the GDPR, breaches of those provisions expose a company to the higher ceiling of 20 million euros or 4 percent of total worldwide annual turnover, whichever is greater. Article 20-IV of the French Data Protection Act mirrors that structure and caps any periodic penalty payment attached to an injunction at 100,000 euros per day of delay.

Four assessment criteria did the work.

On nature, gravity and duration, the committee emphasised the proportion rather than the absolute count: more than three quarters of the erasure requests received in 2024 were not handled or not handled satisfactorily. It also noted that the failure persisted. Two formal reminders had been issued in April and June 2024. By the inspection on 10 April 2025, the position had not changed. On the information point it was still unresolved when the sanction report went out on 12 March 2026.

On negligence, the committee found the volume of affected individuals revealing in itself, and treated the two earlier reminders as aggravating. At the hearing, EXTIA acknowledged it had been slow to react to a situation that had already produced two reminders. The negligence was judged more marked because the company had the resources to do better, with an internal team and a written procedure dedicated to handling rights requests.

On cooperation, the committee declined to credit it. Essential information arrived late, at the defence stage rather than during the investigation, and some of it was insufficiently substantiated. The shifting figures between the first and second sets of observations were read as evidence of how carefully the company had checked its own records after receiving the report. Citing the EDPB's guidelines 04/2022 on the calculation of administrative fines, the committee treated the ordinary duty of cooperation under Article 31 as a neutral factor rather than a mitigating one.

On financial capacity, the published text is redacted. Turnover and net income for 2023, 2024 and the provisional 2025 figure are blanked out. The decision does record a mismatch the committee raised at the hearing: the revenue figures EXTIA publishes on its own website are considerably higher than those in the accounts filed with the CNIL. Asked about it, the company explained that the website figures are worldwide revenue while the filed accounts cover French revenue only.

The committee concluded that 300,000 euros was dissuasive and proportionate. According to the CNIL summary page, the amount reflects the disregard of essential principles concerning individuals' rights, the number of people affected, and the fact that the company had already been reminded of its obligations twice.

No injunction, but publication

The rapporteure had proposed an injunction with a periodic penalty payment. She withdrew that request before the hearing.

The reason is documented in the file. In its 8 June 2026 observations, EXTIA produced evidence that the data of the people covered by the findings had been deleted and that they had been informed of the outcome of their requests wherever that was materially possible. For the great majority, that information went out as an email on 14 April 2026, one day after the company filed its first set of observations and a month after the sanction report was served. Twelve people could not be reached at all, for reasons the committee accepted: contact details already deleted, full mailboxes, undeliverable addresses, or an inability to identify the person.

The committee still ordered publication. EXTIA had argued that publicity would be disproportionate and would damage the relationship of trust with clients and partners on which its business model rests. The committee held that the proportion of affected individuals and the unheeded earlier reminders justified the measure, and calibrated it by anonymising the company name two years after publication. The deliberation is appealable to the Conseil d'Etat within two months of notification.

One procedural detail sits in the preamble and reflects recent French constitutional law. The decision records that EXTIA was informed of its right to remain silent on the facts alleged against it, and cites decision 2025-1154 QPC of the Conseil constitutionnel, dated 8 August 2025.

The coordinated enforcement backdrop

The EXTIA inspection was not a standalone file. According to both the CNIL and the EDPB, it was carried out in the context of the Coordinated Enforcement Framework action on the right to erasure, launched on the initiative of the European Data Protection Board in 2025.

That action was the fourth of its kind, following coordinated exercises on cloud services in the public sector, data protection officers, and the right of access. Thirty-two supervisory authorities across the EEA ran investigations through 2025, and 764 controllers answered a common questionnaire. The resulting report was published in February 2026 and identified seven recurring problems, with non-binding recommendations attached. Rights complaints are the dominant input into European enforcement, and the right to erasure is among the most frequently exercised of them.

EXTIA is one of the first published national sanctions to name that action as part of its origin story. The decision shows what a CEF file looks like when it converts from fact-finding into a formal procedure: a questionnaire exercise merging with pre-existing individual complaints, then an on-site inspection, then a sanction.

Enforcement outcomes across the regime remain contested. Analysis published in May 2026 found that close to 40 percent of the 7.1 billion euros in announced GDPR fines has been annulled or is under active challenge. National authorities issued 1,145,760,374 euros in fines during 2025, according to the EDPB annual report. A six-figure French penalty against a domestic company with no cross-border establishment question is, by comparison, relatively durable.

What the Article 12 reasoning means for marketing data operations

The database at issue is an applicant tracking system, not an advertising platform. The operating assumption the decision dismantles is not confined to recruitment.

Retention-based auto-purge is standard architecture in marketing data stacks. Customer records expire after a set window. Suppression lists age out. Audience segments rebuild on a schedule. The reasoning in this decision holds that a timer, however reliable, does not answer a request. The duty to respond within one month under Article 12 is autonomous, and it attaches at the moment the request arrives, not at the moment the data happens to disappear.

The point has already surfaced in adjacent files. When France's highest administrative court upheld the 40 million euro fine against Criteo in March 2026, part of the reasoning concerned incomplete execution of erasure: the company had stopped serving personalised advertising to people who withdrew consent while retaining the underlying identifiers. In Italy, the Garante fined Piaggio 460,000 euros over the handling of two former employees' corporate mailboxes, a case that also turned on Articles 12 and following. Sweden's IMY issued a reprimand to Flightradar24 over erasure request handling and identity verification demands in 2025.

A second read-across concerns the evidentiary standard. EXTIA's 60-day retention period was not written down anywhere. It was not in the governance documentation, it was not mentioned during the inspection, and the automated email sent to applicants stated a different period. Article 5(2) of the GDPR places the burden of demonstrating compliance on the controller, and the committee applied it: an undocumented retention practice, asserted for the first time in defence, did not carry the weight the company needed it to carry. The gap between what a privacy notice says and what a system actually does is a familiar condition in advertising technology, where retention windows are frequently inherited from vendor defaults rather than chosen.

Third, the internal tracking spreadsheet. EXTIA argued that the table it kept of rights requests was a simple internal tool with no probative value, and that it was unreliable during the period in question. The committee rejected that framing, noting that the inspection had collected the complete individual files alongside the table, that both had been discussed in adversarial exchanges, and that the company ultimately did not dispute the underlying documents. Internal trackers become evidence.

The sequencing of the remediation is the last detail worth marking. The 14 April 2026 mass email went out a month after the sanction report landed, and the committee said so explicitly: the corrective measures followed, for the most part, the opening of a sanction procedure, and do not relieve the company of responsibility for the past. The injunction was dropped because the remediation worked. The fine was not.

Timeline

  • 2007 - EXTIA is created as a simplified joint-stock company with its registered office in Sevres
  • 16 April 2024 - First complaint reaches the CNIL over difficulties exercising access and erasure rights
  • 19 April 2024 - CNIL issues a first formal reminder of the law to EXTIA
  • 17 June 2024 - Second complaint reaches the CNIL
  • 20 June 2024 - CNIL issues a second formal reminder
  • During 2024 - EXTIA receives 28,322 applications and 265 erasure requests
  • 3 June and 7 November 2024 - Two further complaints are filed
  • December 2024 - EXTIA says it puts a new organisation in place for handling rights requests
  • February 2025 - The company says it corrects the erroneous retention information sent to unshortlisted applicants
  • 8 April 2025 - The CNIL president signs the verification order
  • 10 April 2025 - On-site inspection at EXTIA's head office
  • 11 and 25 April 2025 - The inspection record is served twice after a material error
  • 30 April and 12 May 2025 - EXTIA supplies additional material
  • 2025 - Thirty-two supervisory authorities run the EDPB coordinated action on the right to erasure, with 764 controllers responding
  • 8 August 2025 - The Conseil constitutionnel issues decision 2025-1154 QPC, later cited in the preamble
  • February 2026 - The EDPB publishes the coordinated enforcement report on the right to erasure
  • 4 March 2026 - Sophie Lambremon is appointed rapporteure
  • 4 March 2026 - The Conseil d'Etat confirms the 40 million euro fine against Criteo, covering Articles 12, 15 and 17 among others
  • 12 March 2026 - The sanction report alleging breaches of Articles 12, 13 and 17 is finalised
  • 13 March 2026 - The report is served on EXTIA
  • 13 April 2026 - EXTIA files its first observations
  • 14 April 2026 - The company emails the great majority of affected individuals about their requests
  • 7 May 2026 - The rapporteure replies
  • May 2026 - Analysis finds close to 40 percent of announced GDPR fines annulled or challenged
  • 8 June 2026 - EXTIA files second observations with evidence of remediation
  • 15 June 2026 - The investigation is closed and the hearing date is notified
  • 2 July 2026 - The restricted committee hears the case
  • 21 July 2026 - The restricted committee adopts deliberation SAN-2026-010 and the 300,000 euro fine
  • 9 September 2026 - The decision is published on the CNIL website and on Legifrance
  • 11 September 2026 - The EDPB publishes its English-language summary

Summary

Who: The restricted committee of France's Commission nationale de l'informatique et des libertes, composed of Philippe-Pierre Cabourdin as president, Vincent Lesclous as vice-president, Isabelle Latournarie-Willems, Didier Kling and Bertrand du Marais, with Sophie Lambremon as rapporteure, acting against EXTIA, an IT and engineering consultancy employing 2,000 people.

What: An administrative fine of 300,000 euros for breaches of Articles 12 and 17 of the GDPR, covering twelve erasure requests never processed, 166 people never informed of the outcome of their request, and 27 people informed outside the one-month deadline. An Article 13 transparency grievance was abandoned during the procedure, and the proposed injunction was dropped after the company produced evidence of remediation. Publication was ordered, with the company name to be removed after two years.

When: Complaints reached the CNIL in April and June 2024, followed by formal reminders in the same months. The on-site inspection took place on 10 April 2025. The sanction report was served on 13 March 2026, the hearing was held on 2 July 2026, and the deliberation was adopted on 21 July 2026. Publication followed on 9 September 2026, with the EDPB summary on 11 September 2026.

Where: France, at EXTIA's head office in Sevres, with the decision published on the CNIL website and on Legifrance, and the inspection carried out within the EDPB coordinated enforcement action on the right to erasure conducted across the European Economic Area during 2025.

Why: More than three quarters of the 265 erasure requests EXTIA received in 2024 were not handled or not handled satisfactorily, the company had already been reminded of its obligations twice before the inspection, and the restricted committee held that automatic deletion of data on a retention timer does not discharge the separate duty under Article 12 to tell a person what was done with their request.