Skip to content
← All posts

10 September 2026

4 min read

Written by

Clément Lacaille

Clément Lacaille

Founder, Tech-Bharat

About the author
Business & compliance

CNIL fines Extia €300,000 over botched erasure requests: what it changes for any SMB that recruits

On September 9, 2026, the CNIL published a €300,000 fine against IT staffing firm Extia for mishandling 265 erasure requests from candidates and former employees in 2024 — more than three-quarters were not processed correctly. The ruling draws a sharp line most small recruiting teams miss: deleting the data is not enough if you never tell the person you did it.

On September 9, 2026, the CNIL published a €300,000 fine against Extia, an IT and engineering staffing firm that recruits consultants and places them on client projects. The decision (deliberation SAN-2026-010, adopted July 21, 2026) follows several complaints the CNIL received in 2024 from candidates and former employees who struggled to get their personal data erased under RGPD Article 17 — the right to be forgotten. Of the 265 erasure requests Extia received that year, mostly from job candidates, more than three-quarters were not handled satisfactorily: 12 requests were never processed at all, 166 people were left without any information on the follow-up given to their request, and 27 responses arrived late. The CNIL also noted that Extia had already been reminded of its obligations twice before this sanction.

What the decision actually establishes

  • →A €300,000 fine for breaching RGPD Article 17 (right to erasure) and Article 12 (obligation to inform data subjects of the follow-up given to their request).
  • →265 erasure requests received in 2024, mostly from job candidates and some former employees; more than 75% not handled correctly.
  • →12 requests never processed; 166 people never informed whether or how their request was handled; 27 responses sent after the legal deadline.
  • →A key legal point for any employer: failing to erase data and failing to inform the person of the outcome are two separate, cumulative RGPD violations — deleting the data silently does not clear the second one.
  • →Extia had already received two prior reminders of its obligations, a factor the CNIL cited in setting the fine.

A gap documented well beyond Extia

Extia is not an outlier. A 2025 academic study by Pöhn and Gruschka, Qualitative In-Depth Analysis of GDPR Data Subject Access Requests and Responses from Major Online Services, found that even large, well-resourced online services routinely fail to fully satisfy GDPR requirements when responding to data subject requests, and that response quality varies widely from one organization to the next years after the regulation took effect. If major platforms with dedicated privacy teams still get this wrong, a small HR department juggling recruitment on top of payroll and onboarding is exactly the profile most exposed — not because the rule is unclear, but because no one owns the deadline.

What it changes for your SMB

Any SMB that recruits — job postings, unsolicited CVs, an applicant-tracking tool, a simple recruitment inbox — sits under the exact same obligation as Extia, regardless of headcount. The CNIL’s own reference framework on retention periods in HR management recommends erasing an unsuccessful candidate’s CV no later than two years after the last contact, unless the candidate consented to a longer hold (CNIL retention-period framework). The harder trap in the Extia case is the one most SMBs would fall into too: deleting a candidate’s file and simply moving on, without sending back a short confirmation. The CNIL treats that silence as its own violation, separate from whether the deletion itself happened correctly. For a small team without a dedicated DPO, a candidate erasure request that arrives in a shared recruitment inbox is easy to act on and just as easy to forget to answer — which is precisely the gap a regulatory-watch or email-triage agent is built to close: flagging an RGPD request the moment it lands and tracking its one-month legal deadline until a reply actually goes out.

Concrete steps

  • →Keep a simple log of every erasure or access request with its received date and legal deadline (one month, extendable to three with justification) — a spreadsheet is enough if someone actually owns it.
  • →Never close a request by deleting data alone: always send the person a short written confirmation of what was done, even when the answer is "already deleted."
  • →Set a default retention period for unsuccessful candidates’ CVs (two years after last contact, per the CNIL’s own framework) and purge automatically rather than relying on someone to remember.
  • →If recruitment emails land in a shared inbox with no formal process, route them through an email-triage agent that flags GDPR-relevant requests on arrival and tracks the deadline — the same discipline Extia’s case shows a company twice the size still got wrong.

The €300,000 figure is what made headlines, but the more useful number in this decision is 166 — the people Extia never bothered to write back to, even in cases where the data had already been deleted. That is the gap a small recruiting team can close with a log and a habit, at a fraction of the cost of finding out about it from the CNIL.

Frequently asked questions

What did the CNIL sanction Extia for?+

For failing to properly handle 265 erasure requests received in 2024, mostly from job candidates: 12 were never processed, 166 people were never informed of the follow-up given to their request, and 27 responses were late. The CNIL fined the company €300,000 for breaching RGPD Articles 17 and 12.

Does this apply to an SMB that only occasionally recruits?+

Yes. The obligation to process erasure requests and inform the requester of the outcome applies to any employer holding candidate or employee data, regardless of size. The CNIL’s own guidance recommends deleting an unsuccessful candidate’s CV within two years of last contact.

What is the one thing most SMBs get wrong, based on this case?+

Deleting the data without confirming it to the person who asked. The CNIL treats failing to inform the data subject as a separate violation from failing to erase the data — so silently deleting a file is not enough to close the request.

Free resource

The self-assessment grid: 20 tasks AI can automate

Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.

Read next