PrivacySignal
Enforcement

Failure to respect the rights of individuals: The CNIL fined EXTIA EUR 300 000

EDPB · · EU · Enforcement

France's data protection authority, the CNIL, fined IT and engineering firm EXTIA €300,000 for violating individuals' rights under GDPR, including failures around transparency and the right to erasure. The case originated from complaints filed by former employees in 2024.

Why this matters: When you leave a job, you have a legal right to ask a company to delete your personal data. EXTIA apparently made that harder than it should be. A €300,000 fine is not small, but the real point is simpler: companies that collect data on workers and candidates have to honor deletion requests and communicate clearly about how data is used. Ignoring that is not a paperwork problem. It is a rights violation, and regulators are treating it that way.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

Enforcement
BleepingComputer · · International

IQVIA fined $7.8 million for failing to properly anonymize health data

Italy's data protection authority fined IQVIA €7 million after finding that the company's anonymization practices were inadequate, leaving roughly one million patients at risk of being re-identified from their health data.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals · AI governance · General readers · Policy

#enforcement#healthcare#gdpr#privacy Read original →
Enforcement
DataBreaches.net · · International

South Korea’s President Lee Jae Myung orders thorough probe into data breaches at local banks

South Korean President Lee Jae Myung has ordered a formal investigation into a recent series of data breaches at financial and public institutions, amid growing concern about AI-powered cyberattacks targeting the sector.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · General readers · Policy

#enforcement#ai-governance#ai Read original →
Enforcement
C CT Mirror · · International

Data privacy lawsuit, subsidies for childcare staff: CT politics news

A data privacy lawsuit is among the political stories making news in Connecticut, alongside a separate measure involving subsidies for childcare workers. Details on the parties, claims, and current status of the lawsuit were not provided.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
T Top Class Actions · · International

$3.5M MDLive data privacy class action settlement

MDLive, a telehealth company, has agreed to a $3.5 million settlement to resolve a class action lawsuit over alleged data privacy violations.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
B BroBible · · International

Tennessee Woman Sues For $10M After False AI Facial Recognition Match Lands Her In Jail For 6 Months

A Tennessee woman is suing for $10 million after a false facial recognition match allegedly led to her spending six months in jail. The lawsuit centers on an AI identification error that, according to the claim, put an innocent person behind bars for half a year.

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity · General readers · AI governance · Policy

#enforcement#surveillance#ai#privacy Read original →