By a ruling dated 21 July 2026 and made public on 9 September 2026, the restricted committee of CNIL sanctioned EXTIA. The decision concerns the handling of erasure requests submitted by applicants and former employees. It is relevant to any company that manages a CV database.
Background
EXTIA employs approximately 2,000 people and specialises in IT and engineering. It recruits consultants and assigns them to technical projects for its clients. In 2024, CNIL received several complaints from former employees and applicants reporting difficulties in exercising their right to erasure. After reminding the company of its obligations twice, in April and then in June 2024, CNIL carried out an on-site inspection in April 2025. The inspection responded to those complaints and formed part of the coordinated European action on the right to erasure launched in 2025 by the European Data Protection Board.
The inspection found that, out of the 28,322 applications received by the company in 2024, 265 erasure requests had been recorded. Most had been submitted by applicants, and more than three quarters had either not been processed or had not been handled satisfactorily.
Two separate infringements
The first infringement concerned the handling of the requests themselves. Twelve erasure requests received in 2024 had not been processed, in breach of art. 12 and art. 17 GDPR. CNIL considered that this infringement undermined individuals’ right to remain in control of their data.
The second, particularly instructive infringement concerned the information provided to requesters. In 2024, 166 people who had requested the erasure of their data received no information at all about the action taken on their requests. A further 26 people were informed late, after the statutory one-month deadline, with delays sometimes lasting several months.
The company argued that many of these requests concerned applicants whose data had been automatically deleted. CNIL nevertheless rejected that argument. Automatic deletion does not relieve the company of its obligation to inform applicants about the action taken on their requests.
A standalone information obligation
Art. 12, paragraph 3, GDPR requires the controller to inform the data subject of the measures taken without undue delay and, in any event, no later than one month after receiving the request. This period may be extended by a further two months where necessary, taking into account the complexity or number of requests, provided that the data subject is informed of the extension and the reasons for it within the initial one-month period.
Paragraph 4 goes further. Where the controller does not take action on the request, it must nevertheless inform the data subject of the reasons for its inaction, the possibility of lodging a complaint with a supervisory authority and the possibility of seeking a judicial remedy. The information obligation therefore applies regardless of the outcome of the request.
The lesson for companies
The decision distinguishes between two obligations that organisations often conflate: carrying out the erasure and reporting back to the data subject. An automatic purge configured in an ATS or CV database may satisfy the first obligation, while doing nothing to satisfy the second.
EXTIA took remedial measures during the proceedings by deleting the data and informing the individuals concerned. This was not enough to neutralise the infringements. CNIL imposed a fine of 300,000 €, representing approximately 0.15% of the company’s annual turnover. In setting the amount, CNIL took into account the number of people concerned and the fact that the company had already been reminded of its obligations twice.
In practice, start by checking the configuration of your automatic deletion processes. If your tool purges profiles without triggering a response to the requester or retaining evidence of the process, you are in the situation sanctioned here. Automatic deletion may satisfy the erasure requirement itself. However, when a person actually submits an erasure request, you must still reply and inform them of the measures taken.
Sources: Decision of the CNIL Restricted Committee No. SAN-2026-010 of 21 July 2026 (CNIL, EXTIA); GDPR, Art. 12; GDPR, Art. 17; Law No. 78-17 of 6 January 1978, as amended.




