PrivacySignal
Enforcement

Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR

EDPB · · EU · Enforcement

France's data protection authority, the CNIL, fined IT and engineering firm EXTIA €300,000 following complaints from former employees about violations of transparency requirements and the right to erasure under GDPR. The July 2026 decision found the company failed to respect individuals' rights over their personal data.

Why this matters: When you leave a job, you have a legal right to ask a company to delete your data. EXTIA apparently made that harder than it should be. Multiple former employees had to complain to a regulator just to get basic answers. That is the problem this fine is addressing. The GDPR rights on paper only matter if companies actually honor them without a fight. A €300,000 penalty is a signal that ignoring erasure requests is not a low-risk choice, even for mid-sized firms.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Enforcement
noyb (None of Your Business) · · EU

SCHUFA insists on shadow database. noyb lawsuit now certain

German privacy group noyb will file an injunction against credit agency SCHUFA after the company rejected a cease-and-desist letter over its so-called shadow database. SCHUFA has publicly denied the allegations, and noyb is also inviting people to register interest in a potential class action.

Who should care: Lawyers · Privacy officers · Compliance

#enforcement Read original →
Enforcement
EFF — Deeplinks · · International

Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR

Police departments across the United States are actively concealing their use of surveillance tools — including license plate readers, cell-site simulators, and facial recognition — by instructing officers to omit these technologies from reports and structuring records to evade public disclosure requests.

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity · General readers · Policy

#enforcement#surveillance#privacy Read original →
Enforcement
The Record · · International

Grindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 million

Grindr has agreed to a $35 million settlement with UK users who sued the dating app over claims it shared their HIV status data without proper consent, in violation of British privacy law. The lawsuit was filed in April 2024.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
N News4JAX · · International

Netflix lawsuit: Florida AG alleges streaming giant tracked kids, broke data privacy promises

Florida's Attorney General has filed a lawsuit against Netflix, alleging the company tracked children's data and violated its own privacy commitments to users. The suit centers on claims that Netflix broke promises it made about how it handles personal information.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
HIPAA Journal · · US Federal

FBI Raises Alarm About OAuth Consent Phishing Activity

The FBI has issued a public warning about an active phishing campaign that exploits OAuth consent flows, a legitimate authorization mechanism used across countless apps and services. The technique is sophisticated enough to warrant a formal federal alert.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals · General readers · Policy

#enforcement#healthcare#privacy#security Read original →
Enforcement
CNIL · · EU / France

Failure to respect the rights of individuals: EUR 300,000 fine against EXTIA

France's data protection authority, the CNIL, fined consulting firm EXTIA €300,000 for failing to respect individuals' rights under data protection law. The penalty reflects a formal finding that the company did not meet its legal obligations toward the people whose data it held.

Who should care: Lawyers · Privacy officers · Compliance

#enforcement Read original →