Right to erasure: deleting data is not enough

Right to erasure: deleting data is not enough

Key takeaways

 

In a decision dated July 21, 2026, the CNIL fined EXTIA €300,000 for failures in handling requests for erasure of personal data.

 

 

Managing requests to exercise data protection rights is not limited to the technical deletion of data. In a decision dated July 21, 2026, the French supervisory authority (CNIL) fined EXTIA €300,000 for failures in handling requests to exercise data protection rights, mainly erasure requests. (1)

 

Deleting data is not enough. Under Article 12 of the GDPR, every erasure request must not only be reviewed, but must also be followed by a response to the data subject. In accordance with the accountability principle, the controller must also be able to demonstrate compliance with its obligations through consistent documentation and adequate traceability.

 

 

1. Deleting data is not enough: every request must be reviewed and receive a response

 

1.1 The EXTIA case

 

In 2024, the CNIL received several complaints concerning difficulties encountered by data subjects in exercising their right of access and the right to erasure. After reminding EXTIA of its legal obligations on two occasions and receiving further complaints, the CNIL carried out an on-site inspection at the company’s headquarters on April 10, 2025.

 

EXTIA, an IT consulting company, received 265 erasure requests during 2024, mainly from former job applicants. At the end of the proceedings, the CNIL found that 204 of these requests had not been properly handled: 12 had not been processed, 166 individuals had not been informed of the action taken on their requests, and 26 individuals had received a response after the applicable deadline.

 

EXTIA argued that, for many applicants, the data had been automatically deleted after 60 days. According to the company, the right to erasure had therefore been respected.

 

The CNIL considers that the actual deletion of data does not exempt the controller from its obligation to inform the data subject of the action taken in response to the request. Failure to provide this information constitutes a breach of Article 12 of the GDPR.

 

In addition, 26 erasure requests had received late responses, with delays in some cases exceeding five or six months. One access request was answered more than a year late. The company attributed these delays to temporary disruption within its legal department and to the need to prioritize the actual handling of requests.

 

The CNIL rejects this argument and points out that the obligation to respond to requests to exercise rights within one month constitutes an “independent obligation” that cannot be offset by the automatic erasure of data.

 

1.2 Automatic deletion of data does not replace the processing of a request

 

The right to erasure provided for in Article 17 of the GDPR, often referred to as the “right to be forgotten,” is not limited to the actual deletion of data. The actual or automatic deletion  of data does not exempt the controller from reviewing the request, responding to it, and informing the data subject within the time limits set forth in the GDPR.

 

The GDPR distinguishes between data erasure and the obligation to process a request to exercise rights. An automatic data purging mechanism does not, by itself, constitute a GDPR rights management system.

 

When an individual submits a request for erasure, that request must be processed in a manner that allows the individual to be identified, the relevant processing activities and data to be determined, the conditions for erasure to be verified, and a response to be sent to the individual.

 

Article 12(3) thus requires the controller to provide the data subject with information on action taken following a request to exercise his or her rights (rights of access, rectification, erasure, portability, etc.) within one month of receipt of the request. This period may be extended by two further months where necessary, taking into account the complexity and number of requests. In that case, the data subject must be informed of the extension and the reasons for it within the initial one-month period.

 

The CNIL notes that the fact that the data was actually deleted has no bearing on the obligation to inform individuals of the action taken in response to their requests. In this case, it found that 166 individuals who had submitted an erasure request in 2024 had received no information about the action taken on their requests.

 

In addition, where the controller decides not to take action on a request, the data subject must be informed of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

 

1.3 The retention of certain data must be justified

 

An erasure request does not necessarily result in the immediate and complete deletion of all data relating to an individual. The GDPR provides for several exceptions to the right to erasure, and certain legal obligations, including accounting and tax obligations, may require specific categories of data to be retained for a defined period.

 

In this case, EXTIA relied on the fact that some of the individuals concerned were former employees and on legal obligations requiring certain data to be retained.

 

The restricted committee acknowledges that retaining certain data may be legitimate, but considers that the mere fact that an individual is a former employee does not justify leaving the request unprocessed. (2) The company must be able to explain the reasons justifying the retention of the data in question.

 

The response to a request for erasure must therefore be tailored to each individual: some data may be deleted, while other data may be retained on an identified legal basis that the company must be able to explain to the individual.

 

 

2. The accountability principle requires controllers to be able to demonstrate GDPR compliance

 

This decision is a reminder that managing the rights set forth in the GDPR constitutes a compliance process in its own right that falls under the principle of accountability for the data controller. The controller must not only comply with the applicable rules, but must also be able to demonstrate such compliance, in accordance with Article 5(2) of the GDPR.

 

The existence of an automated data deletion tool, a data protection team, or even an internal procedure is not sufficient if the process in place does not ensure that each request is effectively handled and that evidence of its handling can be produced.

 

2.1 Implement a rights management procedure covering both technical action and the response to the request

 

Managing data subjects’ rights is part of GDPR compliance. Accordingly, companies must implement a comprehensive rights management procedure covering both the operations to be performed on the data (erasure of all or part of the data) and the review of the request and response to the data subject. A process for handling data deletion requests could therefore delete data in accordance with a retention policy while still leaving the company non-compliant if the request received is not recorded, reviewed, and followed by a response.

 

The rights management procedure could be broken down into seven steps for each request, i.e.:

 

1.     recording the request and its date of receipt;

2.     identifying the individual and the processing activities concerned;

3.     forwarding the request to the teams responsible for its handling;

4.     reviewing the request and any applicable exceptions;

5.     carrying out the necessary operations on the data;

6.     sending a response to the individual within the applicable deadline;

7.     retaining evidence demonstrating how the request was handled.

 

2.2 Document the practices used

 

The decision concerning EXTIA highlights the importance of documentation in demonstrating compliance.

 

During the proceedings, EXTIA stated that a 60-day retention period applied to the data of certain applicants. The CNIL notes, however, that this retention period had not been mentioned during the inspection and was not reflected in any internal document relating to personal data governance.

 

In practice, it is necessary to ensure consistency between, on the one hand, retention periods, deletion procedures, the handling of requests and decisions made where an exception applies, and on the other hand, the tools, internal procedures and information provided to individuals.

 

2.3 Do not wait for an inspection to correct existing procedures

 

EXTIA implemented several corrective measures during the proceedings. Although the CNIL did not issue the injunction initially contemplated, these corrective measures did not eliminate the company’s liability for the earlier infringements.

 

In assessing the penalty, the restricted committee notes in particular that more than three quarters of the erasure requests received in 2024 had either not been handled or had been handled inadequately. It also takes into account the two previous formal warnings issued to the company and notes “particular negligence,” given the number of individuals affected and the repeated nature of the infringements.

 

The decision therefore shows that bringing practices into compliance after sanction proceedings have been initiated may lead the CNIL to limit certain corrective measures, without disregarding past infringements or precluding the imposition of a financial penalty.

 

* * * * * * * * * * *

 

(1) CNIL, Restricted Committee Deliberation No.SAN-2026-010 of July 21, 2026 concerning EXTIA

 

(2) “Restricted committee” (“formation restreinte”) is an internal CNIL committee consisting of five members and a chairperson which may impose various sanctions on controllers who fail to comply with the law.

 

Bénédicte DELEPORTE

Avocat

 

Deleporte Wentz Avocat

www.dwavocat.com

 

September 2026