Regulatory Watch  /  France  /  Fine
High impactFineDecided

CNIL fines French IT firm EXTIA €300,000 for failing to honor data erasure requests

Sources disagree
European Data Protection Board news gives penalty 500,000 EUR; event has 300,000 EUR. | European Data Protection Board news gives effective date 2026-09-03; event has 2026-07-21. | European Data Protection Board news gives penalty 500,000 EUR; event has 300,000 EUR.

In 2024 EXTIA received 265 requests for erasure, many of which were not processed or not communicated to the requesters. The CNIL audit found breaches of Articles 12 and 17 GDPR regarding transparency and the right to erasure. The CNIL imposed an administrative fine of €300,000 on EXTIA.

Why it matters: The fine underscores enforcement of GDPR data subject rights on erasure and transparency obligations.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR
European Data Protection Board news · primary source · Sep 11, 2026
Non-respect des droits des personnes : sanction de 300 000 euros à l’encontre de la société EXTIA
CNIL (France) · Sep 9, 2026
Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR
European Data Protection Board news · Sep 9, 2026
Failure to respect the rights of individuals: The CNIL fined EXTIA EUR 300 000
European Data Protection Board news · Sep 11, 2026
Health data breach: the CNIL fined Hôpital Privé de la Loire EUR 500 000
European Data Protection Board news · Sep 9, 2026
Details
JurisdictionFrance
RegulatorCNIL
LawGeneral Data Protection Regulation
StatusDecided
PublishedSeptember 11, 2026
EffectiveJuly 21, 2026
DecisionJuly 21, 2026
Penaltyimposed a fine of 300 000 EUR on EXTIA
OrganisationsEXTIA, Hôpital Privé de la Loire
Topicstransparency, deletion, privacy, security, breach notification, health, data brokers, access
Datapersonal, health, sensitive