惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Security Blog
Microsoft Security Blog
WordPress大学
WordPress大学
Stack Overflow Blog
Stack Overflow Blog
D
DataBreaches.Net
罗磊的独立博客
博客园 - 司徒正美
Last Week in AI
Last Week in AI
The Cloudflare Blog
大猫的无限游戏
大猫的无限游戏
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog RSS Feed
The GitHub Blog
The GitHub Blog
宝玉的分享
宝玉的分享
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
小众软件
小众软件
Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Hugging Face - Blog
Hugging Face - Blog
B
Blog
博客园 - 【当耐特】
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
酷 壳 – CoolShell
酷 壳 – CoolShell

EDPB News

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE) Stakeholder event on guidelines on the interplay between data protection and competition law: overview of topics available Stakeholder event on guidelines on the interplay between data protection and competition law: save the date EDPB calls for legal basis for cross-regulatory information sharing EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain EDPB and AMLA to develop Joint Guidelines on partnerships for information sharing One-Stop-Shop case digest on right to object and right to erasure updated Supporting GDPR consistency: EDPB launches dedicated form EDPB gets a new look: discover the new website and brand identity Coordinated Supervision Committee extends scope to include Eurodac Coordinated Supervision Committee extends scope to include Eurodac EDPB meets with EU Commissioner McGrath and adopts common data breach notification template EDPB meets with EU Commissioner McGrath and adopts common data breach notification template The Italian SA imposed a 40 000 EUR fine on a company for violating the confidentiality of a employee's email account after the end of his employment The Italian SA fined Poste Vita for data breach Imposition of fine on a telecommunications company for violations of data subject’s rights The Italian Supervisory Authority fined a company 120 000 EUR for tracking five employees who drove company cars Italian SA fines a company for post-sick leave questionnaires The Italian Supervisory Authority has fined Verisure Italia for unlawful processing of personal data for direct marketing purposes EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data Europe Day 2026: let’s celebrate together Marking 10 years of the GDPR: the evolution of the European data protection landscape Stakeholder event on competition and data protection: save the date Stakeholder event on competition and data protection EDPB brings clarity to data processing for scientific research, speeds up the finalisation of the anonymisation guidelines and approves first European data protection seal as a tool for transfers Enhancing compliance and consistency: EDPB adopts DPIA template EDPB annual report 2025: supporting stakeholders through guidance and dialogue EDPB conference on cross-regulatory cooperation: what we learned
Failure to respect the rights of individuals: The CNIL fi...
EDPB · 2026-09-11 · via EDPB News

Summary of the Decision

Origin of the case  

EXTIA, which specialises in IT and engineering, recruits consultants for various technical projects from its client companies. 

In 2024, the French Data Protection Authority (CNIL) received several complaints from former employees or candidates, relating to difficulties encountered in exercising their right to erasure or ‘right to be forgotten’. With a view to investigating these complaints, and also in the context of the Coordinated Enforcement Framework action on the ‘Right to erasure’ launched on the initiative of the European Data Protection Board in 2025, an audit of EXTIA was carried out in April 2025. It identified breaches of several obligations under the GDPR regarding transparency and respect for individuals’ rights.

Of the 265 requests for erasure received by the company in 2024, the majority of which came from candidates and, occasionally, former employees, more than three quarters had not been dealt with or had not been dealt with satisfactorily.

Key Findings

Failure to process erasure requests (Articles 12 and 17 GDPR)

The CNIL’s restricted committee – the body responsible for issuing sanctions –  noted that 12 requests for erasure received by the company in 2024 had not been processed. It considered that that failure had adversely affected the rights of those persons, including the right to retain control over their data.

Failure to inform individuals of the action taken on their request for erasure (Article 12 GDPR)

The CNIL’s restricted committee considered that the company had failed to fulfil its obligation to inform the persons who had requested the erasure of their data. It noted that 166 persons who had made a request for erasure in 2024 had not been informed of the action taken on that request. Another 27 people had received this information late (outside the legal one-month deadline), with delays of up to several months.

Decision

Consequently, the restricted committee imposed a fine of 300 000 EUR on EXTIA, taking into account the infringement of essential principles relating to the rights of individuals, the number of persons concerned and the fact that EXTIA had already been reminded of its obligations on two occasions.

For further information: