When CNIL audited EXTIA in April 2025, investigators found that 265 erasure requests had arrived in 2024. More than three-quarters were either ignored or mishandled. Twelve people received no response at all. Another 166 never learned what happened to their requests. Twenty-seven more waited months past the legal deadline for a reply.
The result was a 300,000 EUR fine and a public enforcement decision detailing the company's failures.
This wasn't an isolated incident. CNIL had already reminded EXTIA of its obligations twice before the audit. The pattern matters more than the individual mistake, and the mistakes themselves follow predictable lines.
Why These Mistakes Keep Happening
Most organizations don't intend to violate Article 12 or Article 17. They fall into non-compliance through process gaps that seem minor until an auditor counts the backlog.
You build a request intake form, route emails to a shared inbox, and assign tickets to whoever has capacity. Then volume climbs, staff turns over, priorities shift, and the queue grows quietly in the background. No alarm sounds when request 47 sits unanswered for six weeks. No dashboard flags the 30 people still waiting for confirmation that you've acted.
The mistakes below emerge from that drift between intent and execution. Each one compounds the others, and all of them show up in enforcement decisions.
Mistake 1: Treating the Inbox as the Process
You receive requests via a contact form, a privacy@ email address, or a chatbot. Someone reads them, decides whether they're legitimate, and forwards the work to another team. That handoff is where requests disappear.
Why it happens: You assume the person reading the inbox will track every request to completion. In practice, they triage and move on. No single system holds the full record of what arrived, what you promised, and what you delivered.
Real consequence: When EXTIA failed to process 12 erasure requests, the breakdown likely occurred at this handoff. The request entered the organization but never landed in a system that enforced accountability or deadlines.
The fix: Log every request in a dedicated DSAR management system the moment it arrives. Assign a unique case ID. Set automatic reminders at day 20 (before the one-month deadline under Article 12(3)) and escalation triggers if no action is recorded. The log must capture receipt date, requester identity, request type, assigned owner, and status.
Mistake 2: Confusing Acknowledgment with Response
You send an auto-reply confirming receipt. The requester assumes you're working on it. You assume you've met your communication obligation. Neither is true.
Why it happens: Article 12(3) requires that you inform the data subject of action taken on the request, not merely that you received it. Teams conflate the acknowledgment (a courtesy) with the substantive response (a legal duty).
Real consequence: EXTIA failed to inform 166 people of the action taken on their erasure requests. Those individuals had no way to know whether their data had been deleted, whether the company was still processing the request, or whether they needed to escalate. The silence itself is the violation.
The fix: Build two communication steps into your workflow. First, acknowledge receipt within 48 hours and provide the case ID. Second, send a substantive response within one month that states exactly what you did: "We have erased your personal data from systems X, Y, and Z" or "We are retaining your data under Article 17(3)(b) because [specific legal obligation]." If you need to extend the deadline under Article 12(3), inform the requester within the first month and explain why.
Mistake 3: Running Manual Checks Across Disconnected Systems
You receive an erasure request. You check the CRM, then the email archive, then the backup system, then the vendor platforms. Each check requires a separate query, often in a different interface. You miss systems because no one maintains a complete data map.
Why it happens: Data sprawls faster than documentation. Marketing adds a new analytics tool. Sales starts using a prospecting database. Customer support logs tickets in a separate system. No central inventory tracks where personal data lives or who controls each system.
Real consequence: Even when you intend to comply, you erase data from three systems and overlook the fourth. The requester's information persists in an abandoned Slack workspace or a third-party recruiting platform you forgot you integrated two years ago. You've technically failed to fulfill the request, and the failure is invisible to you until an audit.
The fix: Maintain a living data inventory that maps personal data categories to specific systems, retention periods, and responsible teams. When a DSAR arrives, your workflow should auto-generate a checklist of every system that might hold the requester's data. Require sign-off from each system owner before you close the case.
Mistake 4: Letting Complexity Become an Excuse for Delay
You receive a request that touches multiple business units, legacy systems, or third-party processors. The technical work is legitimately complicated. You let weeks pass without updating the requester.
Why it happens: Article 12(3) allows you to extend the response period by two months "where necessary, taking into account the complexity and number of the requests." Teams interpret "where necessary" as permission to go silent while they figure out the internal mechanics.
Real consequence: EXTIA's 27 delayed responses stretched "up to several months" past the one-month deadline. Even if the company eventually acted, the delay itself violated Article 12(3). Complexity justifies extension, not silence. If you don't inform the requester of the extension and the reasons within the first month, you're non-compliant regardless of the technical difficulty.
The fix: If you need more than 30 days, send a message before day 30 that explains the specific complexity (e.g., "Your request requires coordination with three third-party processors under Article 28, and we are awaiting their confirmation of erasure") and states the new deadline (no more than three months from receipt). Provide a contact point for follow-up questions. Complexity buys you time only if you communicate it.
Mistake 5: Assuming Prior Warnings Don't Escalate Penalties
You receive a letter from your supervisory authority reminding you of your obligations. You fix the immediate issue but don't overhaul the underlying process. A year later, the same failure pattern reappears.
Why it happens: Remediation focuses on the symptom (the specific requests that triggered the complaint) rather than the system (the intake, tracking, and response workflow that allowed the failures). You treat the warning as a one-time correction instead of a signal that your process is structurally inadequate.
Real consequence: CNIL explicitly cited EXTIA's two prior reminders when calculating the 300,000 EUR fine. Repeated non-compliance demonstrates that informal enforcement didn't work, which justifies a harsher penalty. The pattern, not the volume, drove the financial impact.
The fix: Treat any supervisory authority contact as a process audit trigger. Document the root cause, not just the immediate failure. If the warning involved late responses, audit your entire DSAR workflow: intake logging, deadline tracking, system coverage, communication templates, and escalation paths. Assign ownership for each step. Run a tabletop exercise with a sample request to identify gaps before the next audit.
Prevention Checklist
- Every DSAR is logged in a dedicated system with a unique case ID on the day it arrives
- Automated reminders fire at day 20 and escalate at day 28 if no substantive response is recorded
- Acknowledgment and substantive response are distinct workflow steps with separate templates
- Your data inventory maps personal data categories to systems, and DSAR workflows reference it
- System owners sign off on erasure or retention before you close the case
- Extension notices go out before day 30 and explain the specific complexity
- Any supervisory authority contact triggers a root-cause analysis and process audit
- You run quarterly spot checks on closed DSARs to verify that responses met Article 12 requirements
The inbox will keep filling. The only question is whether your process can keep pace with the volume and withstand the audit that eventually arrives.





