Failure to respect the rights of individuals: The CNIL fined EXTIA EUR 300 000
France's data protection authority, the CNIL, fined IT and engineering firm EXTIA €300,000 for violating individuals' rights under GDPR, including failures around transparency and the right to erasure. The case originated from complaints filed by former employees in 2024.
Why this matters: When you leave a job, you have a legal right to ask a company to delete your personal data. EXTIA apparently made that harder than it should be. A €300,000 fine is not small, but the real point is simpler: companies that collect data on workers and candidates have to honor deletion requests and communicate clearly about how data is used. Ignoring that is not a paperwork problem. It is a rights violation, and regulators are treating it that way.
Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.