The Conventional Wisdom
Many DSAR teams think they've nailed erasure compliance by using automated deletion workflows. They set up retention policies, configure systems to purge records after a set period, and maybe add a quarterly cleanup. When erasure requests come in for data that's already gone, they assume they're done. The system handled it, no manual work needed, no response necessary.
This logic seems solid: you can't fail to delete data that no longer exists.
Why This Approach Falls Short
Article 12 doesn't care about your automation. It requires you to provide information on action taken "without undue delay and in any event within one month." This applies whether you manually deleted the data, your system auto-purged it, or it never existed.
The CNIL's July 2026 decision against EXTIA highlights this. The company claimed many of the 166 people who didn't receive responses were candidates whose data had been automatically deleted. The CNIL's committee rejected this defense: "cette suppression automatique ne dispensait pas la société d'informer ces candidats." Automatic deletion doesn't exempt you from informing people.
This isn't a minor detail. It's central to what Article 17 requires. The right to erasure isn't just about making data disappear. It's about confirming that requests were received, understood, and acted upon. Skipping the response because "the system already handled it" treats erasure as a technical operation instead of a fundamental right.
The Evidence
EXTIA received 265 erasure requests in 2024, mostly from candidates and sometimes from former employees. More than three-quarters weren't handled properly. The supervisory authority found two main failures:
First, 12 requests weren't processed at all. The data stayed in EXTIA's systems. This is the failure most teams worry about, and it's what your automation is supposed to prevent.
Second, 166 people never learned what happened to their requests. Their data might have been deleted automatically, but they got no acknowledgment, no confirmation, no response. Another 27 people got responses outside the one-month window, with delays stretching to several months.
The CNIL imposed a 300,000 euro fine. The company had been reminded of its obligations twice before. The decision emphasizes this wasn't about technical complexity. It was about ignoring a transparency obligation that applies regardless of how deletion happens.
What to Do Instead
Separate your response workflow from your deletion workflow. They're different obligations under different articles.
When an erasure request arrives, log it immediately in a system that tracks response deadlines, not just deletion status. Your DSAR queue should show: request received date, one-month deadline, current status (pending review, data deleted, response sent), and any blockers.
If the data's already gone through auto-deletion, your response should say exactly that. Template language works here: "We received your request to erase your personal data. Our records show your candidate profile was automatically deleted on [date] in accordance with our 24-month retention policy. We have verified that no personal data relating to you remains in our systems."
If you deleted the data manually after receiving the request, say that too. If you're refusing erasure because an exception applies under Article 17(3), explain which exception and why. If you need more time, send an extension notice before the one-month mark.
The medium matters less than the fact of response. Email works. Portal notifications work. Even postal mail works if that's how the person contacted you. What doesn't work is silence.
For high-volume erasure environments, consider a two-tier approach: automated acknowledgment within 48 hours ("We received your request and will respond within one month"), then a substantive response once you've verified deletion status. This keeps you compliant even if your manual review process takes three weeks.
Track your response rate as rigorously as you track your deletion rate. If you're processing 200 erasure requests per quarter but only sending 150 responses, you've got 50 Article 12 violations waiting to happen.
When the Conventional Wisdom Is Right
Automated deletion workflows are still valuable. They reduce the volume of data you're holding, which reduces your risk exposure across multiple obligations. They make erasure requests faster to fulfill because you're not hunting through backup systems for old records.
The CNIL acknowledged that EXTIA took remedial steps during the procedure, deleting the outstanding data and informing people of the outcomes. The supervisory authority also accepted that some responses couldn't be sent for legitimate reasons, like inability to identify the requester. Automation that works correctly and is paired with proper notification is exactly what you should be building.
The conventional wisdom breaks down when teams treat automation as a substitute for communication rather than a tool that makes communication easier. Your retention policy should trigger both deletion and a response. Configure your DSAR system to flag auto-deleted records for acknowledgment, not to skip them entirely.
If you're processing dozens of erasure requests monthly and your system already purged half of them before the requests arrived, you're not off the hook. You're just in a position to send faster, more confident responses: "Already done, here's when, nothing remains." That's a better outcome for everyone than a non-response that leaves people wondering whether you ignored them or just never got the message.



