Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Privacy

Extia fined €300,000 for ignoring erasure requests

France's CNIL found the IT consultancy mishandled more than three quarters of 265 "right to be forgotten" requests in 2024.

By · Published · Updated · 9 min read

Extia fined €300,000 for ignoring erasure requests

The CNIL has fined IT and engineering consultancy EXTIA €300,000 for failing to respect people's data rights, especially the right to erasure, the CNIL announced.

What happened

  • In 2024, the CNIL received complaints from former employees and job candidates who could not get their data deleted.
  • An audit in April 2025 found that of 265 erasure requests in 2024, more than three quarters were not handled, or not handled properly.
  • 12 requests were not processed at all.
  • The decision was formally adopted on 21 July 2026, as deliberation n° SAN-2026-010 of the CNIL's restricted committee (*formation restreinte*), the body responsible for issuing sanctions (Lhermet & Lefranc-Bozmarov).

The fine took into account the number of people affected and that EXTIA had already been reminded of its obligations twice.

Who is EXTIA and why it collects so much personal data

EXTIA is a French consultancy specialising in IT and engineering recruitment: it hires technical consultants and places them with client companies on various projects (CNIL). Like most recruitment and staffing firms, this business model means EXTIA routinely collects CVs, contact details, employment history and sometimes identity documents from large numbers of job candidates — many of whom are never hired and have no ongoing relationship with the company, yet whose information can remain on file indefinitely unless deliberately deleted.

How the investigation unfolded

The case began with complaints filed in 2024 by former employees and job candidates who said they could not get EXTIA to honour their requests to delete personal data under Article 17 of the GDPR. The CNIL's investigation was also folded into a wider, coordinated European enforcement effort: the European Data Protection Board's 2025 "Coordinated Enforcement Framework" action specifically focused on the right to erasure across EU member states (CNIL). As part of that coordinated action, the CNIL carried out an audit of EXTIA in April 2025, which is what surfaced the full scale of the problem: of 265 erasure requests received in 2024 — the large majority from job candidates, with some from former employees — more than three-quarters had either not been processed at all or had been handled unsatisfactorily.

The CNIL's restricted committee specifically found two separate violations:

  • Failure to process erasure requests at all (Articles 12 and 17 GDPR): 12 requests received in 2024 were left completely unanswered, which the regulator found undermined those individuals' right to control their own data. The CNIL noted that EXTIA did eventually delete the disputed data and inform the affected people during the course of the proceedings, but only after the complaint and investigation process was underway.
  • Failure to inform people what happened to their erasure requests: according to French tech outlet Solutions Numériques, 166 people who asked for their data to be erased in 2024 never received any response at all, while a further 27 were informed only after missing the legal deadline, in some cases by several months (Solutions Numériques).

Why it matters

Recruiters and consultancies collect CVs, IDs and contact details from thousands of candidates who never work for them. That data often lingers for years, and every old record is something that can leak in a breach. The scale of unanswered requests here — more than three in four — suggests this was not an isolated administrative slip but a systemic failure in how EXTIA handled data subject rights, which is precisely the kind of structural non-compliance European regulators have said they want to crack down on through coordinated cross-border enforcement actions.

How to use your right to erasure

Under the GDPR (Article 17), you can ask a company to delete your personal data in many situations, such as when it is no longer needed. Companies normally have one month to respond. If they ignore you, you can complain to your national data protection authority.

The right to erasure explained

Article 17 of the GDPR — often called the "right to be forgotten" — lets you ask an organisation to delete your personal data when, for example, it is no longer needed, you withdraw consent, or it was processed unlawfully. The organisation must normally reply within one month, which can be extended by two further months for complex requests.

Some data may legitimately be kept, for instance employment records required by law. But a company must explain that clearly, not simply ignore the request.

Why job applicants should care

When you apply for a job, you often hand over your CV, address, phone number, work history, and sometimes copies of ID documents. If that data is kept for years in poorly protected recruitment systems, it adds to your exposure every time the company is breached.

France's CNIL recommends that, unless the candidate agrees otherwise, unsuccessful applicants' data generally should not be kept for more than two years after the last contact.

How to request deletion

  1. Email the company's data protection contact (usually found in its privacy policy) and say you are making a request under Article 17 of the GDPR.
  2. Specify what data you want deleted and keep a copy of your message.
  3. If you do not get a response within a month, you can complain to your data protection authority.

What readers should do

  • If you have applied for a job through a staffing or recruitment firm in the past and never heard back from them, you are entitled to ask what personal data they still hold and to request its deletion.
  • Keep a dated copy of any erasure request you send, by email or recorded post, since this evidence is what regulators like the CNIL rely on to establish how long a company took to respond — or whether it responded at all.
  • If a company fails to respond within the one-month legal deadline (extendable to three months for complex cases), you can escalate directly to your national data protection authority without needing a lawyer.
  • Consider periodically reviewing which companies — especially recruiters, former employers and online services you no longer use — might still hold years-old personal data about you, and proactively request deletion rather than waiting for a breach to force the issue.

Sources

Broader context: Europe's coordinated crackdown on erasure requests

The EXTIA sanction did not happen in isolation. It was part of a European-wide "Coordinated Enforcement Framework" action launched in 2025 by the European Data Protection Board, under which multiple national regulators across the EU simultaneously audited organisations' handling of erasure requests. This kind of coordinated action is designed to apply consistent pressure across borders, since companies that operate in multiple EU countries might otherwise treat a single national regulator's warning as a cost of doing business rather than a signal to fix systemic problems.

Read next