Skip to main content
166 Unanswered Erasure Requests in One YearData Subject Rights
4 min readFor DSAR Operators

166 Unanswered Erasure Requests in One Year

The CNIL's April 2025 audit of EXTIA revealed a compliance breakdown that should prompt every DSAR operator to reassess their processes. Of 265 erasure requests received in 2024, more than three-quarters weren't handled properly. The French supervisory authority imposed a 300,000 EUR fine, highlighting significant areas of failure.

Audit Findings

EXTIA, an IT and engineering firm, failed systematically in processing erasure requests from former employees and candidates. The audit identified three main issues:

12 erasure requests went unprocessed. These individuals received no response or acknowledgment. The CNIL's restricted committee found this failure directly harmed the right to control personal data.

166 people were left in the dark about their requests. They submitted erasure requests under Article 17, but EXTIA never informed them whether their data was deleted, retained under an exception, or still under review.

27 people received late responses. These responses came after the one-month deadline required by Article 12(3), with some waiting months for basic acknowledgment.

This wasn't EXTIA's first encounter with the CNIL over data subject rights. The company had been reminded of its obligations twice before, which influenced the penalty amount.

Key Takeaways

Communication is as crucial as processing. You can delete data and still violate Article 12 if you don't inform the requester. The CNIL treated the 166 uninformed individuals as a separate breach from the 12 unprocessed requests. Your obligation to respond exists whether you grant or deny the request.

Volume doesn't justify non-compliance. EXTIA handled 265 erasure requests in a year, about one per working day. The CNIL didn't accept volume as a mitigating factor. If your processes generate predictable request patterns, ensure your systems can scale accordingly.

Previous warnings increase penalties. The 300,000 EUR fine reflected not just current violations but EXTIA's history. The restricted committee cited two prior reminders about the same obligations. If your supervisory authority has flagged your DSAR processes before, expect heavier consequences in future audits.

Coordinated enforcement means more scrutiny. The CNIL's audit was part of the European Data Protection Board's Coordinated Enforcement Framework action on the right to erasure. When authorities coordinate on a theme, expect broader sweeps and shared findings. Your DSAR handling isn't just under local review.

Implications for Your Team

If you're processing erasure requests manually, you're managing three parallel deadlines: the one-month response window under Article 12(3), the obligation to inform the requester of your decision, and the requirement to delete (or document why you're retaining) the data. Missing any of these creates a compliance gap.

The EXTIA case shows that authorities distinguish between processing and communication failures. You can't fix a missed response by eventually deleting the data. The individual's right under Article 12 to receive information about their request is separate from their Article 17 right to erasure.

Consider your current erasure workflow. Can you answer these questions about last year's requests:

  • How many erasure requests did you receive?
  • How many responses went out within 30 days?
  • How many requesters received no response at all?
  • For requests you denied (legitimate interests, legal obligations, etc.), did you document and communicate the specific exception?

If you can't produce these numbers quickly, you're operating without visibility into your compliance posture.

Action Steps

Map every erasure request touchpoint immediately. Document where requests arrive (email, web form, postal mail), who triages them, what triggers an acknowledgment, and how you track resolution. If requests can enter your organization through multiple channels without hitting a central queue, you'll lose some. EXTIA's 12 unprocessed requests suggest this problem.

Implement automated acknowledgments within 72 hours. Article 12(3) gives you one month to respond substantively, but don't stay silent until day 29. Send an immediate confirmation that you received the request, assign a reference number, and set the expectation for when they'll hear back. This creates a paper trail and buys you time to investigate.

Build a response template library for common scenarios. You need different responses for: data deleted as requested, data retained under Article 17(3) exceptions (legal claims, legal obligations, public interest), requests from individuals with no relationship to your organization, and requests that need clarification. Each template should cite the specific GDPR article and explain your reasoning. Don't make your team write these from scratch under deadline pressure.

Create a dedicated tracking system with mandatory status updates. Whether you use a ticketing system, a spreadsheet, or privacy management software, every erasure request needs a logged status: received, acknowledged, under review, completed, or denied with reason. The 166 people who never heard back from EXTIA suggest no one was tracking resolution-to-communication handoffs.

Run a quarterly audit of your erasure request handling. Pull the last 90 days of requests. Calculate your response rate, your on-time rate, and your communication rate. If you're falling below 100% on any of these metrics, you're creating the same exposure EXTIA faced. Fix the process before a supervisory authority audit reveals it.

Document your exceptions with specificity. When you retain data despite an erasure request, Article 17(3) requires a lawful reason: compliance with a legal obligation, establishment or defense of legal claims, public health, archiving in the public interest, or exercise of freedom of expression. "We might need this later" isn't an exception. Record which Article 17(3) ground applies and when you expect that ground to expire.

By addressing these areas, your team can avoid the pitfalls that led to EXTIA's significant penalty and ensure compliance with GDPR requirements.

You Might Also Like