A €300,000 CNIL fine against EXTIA in July 2026 highlighted a concern for every DSAR operator: more than three-quarters of 265 erasure requests in 2024 were either unprocessed or mishandled. The issue wasn't technical complexity or system failure. It was a basic process breakdown, failing to respond to requests for data deletion.
This checklist guides you through the operational requirements for handling erasure requests under Article 17 of GDPR. Each item aligns with a compliance obligation and shows what "done right" looks like in practice.
What This Checklist Covers
You'll ensure your erasure request workflow meets GDPR's requirements: deleting data when obligated and informing the requester of your decision within one month. The EXTIA case shows that automation doesn't excuse you from communication obligations. Even if your retention policies automatically delete data after six months, you must still confirm that deletion to anyone who submits a formal erasure request.
This isn't about theoretical policies. It's about proving your intake-to-completion process works for every request.
Prerequisites
Before starting the checklist, confirm you have:
- Request intake log showing all erasure requests received this year, with submission dates and requester contact information.
- Response tracking system recording when and how you communicated outcomes to each requester.
- Data inventory mapping where personal data resides across systems (CRM, applicant tracking, email archives, backup systems).
- Legal basis documentation for any ongoing processing that justifies refusing an erasure request.
If you're missing any of these, your erasure workflow has structural gaps that will surface under regulatory scrutiny.
Erasure Request Compliance Checklist
Request Processing
1. Acknowledge every erasure request within 72 hours.
Check: Pull your intake log. For each request, verify you sent a confirmation email stating you received the request and will respond within one month per Article 12(3).
Good looks like: Automated acknowledgment sent same-day, logged in your ticketing system, with a unique reference number for follow-up.
2. Verify the requester's identity before processing any erasure.
Check: Review your identity verification workflow. Confirm you're not deleting data based solely on an email address match, especially for former employees or candidates who might share names.
Good looks like: Multi-factor verification (e.g., matching at least two data points: date of birth, employee ID, application date) documented in the request record before proceeding with deletion.
3. Complete your erasure assessment within one month of receiving the request.
Check: Calculate the time between request receipt and your final decision (erase or refuse). Article 12(3) allows a two-month extension only if the request is complex, and you must inform the requester of the extension within the first month.
Good looks like: 95%+ of requests resolved within 30 days. Any extension communicated in writing before day 30, with specific reasons for complexity.
4. Document why you refused any erasure request you denied.
Check: For every "no" decision, verify you recorded which Article 17(3) exception applies (e.g., legal obligation to retain, establishment of legal claims, public health reasons).
Good looks like: A written justification tied to a specific GDPR provision, reviewed by someone with legal training, stored with the request record.
Data Deletion
5. Delete data from all systems where it resides, not just your primary database.
Check: Cross-reference your data inventory. For three recent erasure requests, trace whether you removed the data from backup systems, archived emails, shadow IT tools, and third-party processors.
Good looks like: Deletion checklist completed for each request, covering every system in your inventory, with deletion timestamps logged per system.
6. Instruct third-party processors to erase data they hold on your behalf.
Check: Review your processor agreements. Confirm you have a documented process to notify processors (recruitment platforms, background check vendors, payroll systems) when you receive an erasure request.
Good looks like: Erasure instruction sent to all relevant processors within 5 business days of receiving the request, with confirmation of deletion received and logged.
Communication
7. Inform every requester of your decision, even when the data was already deleted automatically.
Check: This is where EXTIA failed. Pull every erasure request from the past 12 months. Verify that 100% received a response, including requests where your retention policy had already purged the data.
Good looks like: Zero unacknowledged requests. Every person receives a written confirmation stating either "we deleted your data on [date]" or "we cannot delete because [specific legal basis]."
8. Explain what you deleted and from which systems.
Check: Review five recent erasure confirmations. Do they specify categories of data deleted (application materials, interview notes, email correspondence) and systems affected?
Good looks like: "We deleted your candidate profile from our applicant tracking system (Workday) and removed associated email correspondence from our recruitment team inboxes. Deletion completed on [date]."
9. Provide a clear path for requesters to escalate if they're unsatisfied.
Check: Verify your erasure response template includes information about how to file a complaint with your supervisory authority (the CNIL for France-based processing, your local DPA otherwise).
Good looks like: Every response includes supervisory authority name, contact information, and a statement of the requester's right to lodge a complaint.
Common Mistakes
Assuming automation satisfies communication obligations. EXTIA's defense, that most requests came from candidates whose data had already been auto-deleted, didn't hold. Article 12 requires you to inform the requester regardless of whether you took manual action.
Treating "one month" as a soft deadline. The CNIL noted delays of several months for 27 requesters. Each late response is a separate Article 12 violation, compounding your exposure.
Failing to track requests that arrive via non-standard channels. If someone submits an erasure request via LinkedIn message, customer support chat, or a phone call to HR, it counts. You need intake procedures that funnel all channels into your tracking system.
Deleting data you're legally required to retain. Before you erase, check employment law retention periods, tax obligations, and active litigation holds. Document these checks, your refusal must be defensible.
Next Steps
Run this checklist against your last 90 days of erasure requests. If you find gaps, unacknowledged requests, missing response documentation, incomplete deletions, you're operating with the same vulnerabilities that cost EXTIA €300,000.
Fix the process gaps before you receive a complaint. The CNIL's 2025 coordinated enforcement action on erasure rights signals that supervisory authorities are actively auditing this workflow. Your request log is the first document they'll examine.





