All articles
News & Analysis 7 min read 28 September 2026 Primitra

Right to Erasure Under the DPDP Act: What a €300,000 Fine Over Job Applicants' Data Teaches Indian SMEs

France's CNIL fined IT consultancy EXTIA €300,000 for ignoring erasure requests from job candidates. Here is how Indian SMEs can build a DPDP-ready erasure process for HR and recruitment data before May 2027.

Most Indian companies think of privacy compliance as a customer problem. Consent banners, privacy notices, marketing opt-outs. But the fine that caught our attention this month came from somewhere far less glamorous: a recruiter's inbox. On 9 September 2026, France's data protection authority, the CNIL, published a €300,000 penalty against EXTIA, an IT and engineering consultancy, for mishandling erasure requests from job candidates and former employees. For Indian SMEs, it is a very practical preview of how the right to erasure under the DPDP Act will be tested once the core obligations switch on in May 2027.

What happened in the EXTIA case

The facts are ordinary, which is exactly why they matter. According to the CNIL's published decision (dated 21 July 2026), EXTIA received 265 erasure requests in 2024. Most came from people who had applied for jobs; a few came from former staff. More than three quarters were either not handled or not handled properly.

Break that down and the pattern becomes clear:

  • 12 requests were never processed at all.
  • 166 people never heard back about what happened to their request.
  • 27 people got an answer, but after the GDPR's one-month deadline, some of them months late.

EXTIA argued that many candidates' data had already been deleted automatically, so there was nothing to act on. The CNIL rejected that. Automatic deletion does not excuse you from telling the person what you did. It also noted that the company had been reminded of its obligations twice before.

The April 2025 audit was part of the European Data Protection Board's coordinated enforcement action on the right to erasure, a shared priority for regulators across Europe.

Why Indian SMEs should pay attention now

India's regime is younger, but the building blocks are the same. The DPDP Rules, 2025 were notified on 13 November 2025. The Data Protection Board of India is in place. Consent Manager registration opens around 13 November 2026, and the substantive duties on every Data Fiduciary, including notice, consent, rights handling and breach reporting, take effect around 13 May 2027. Penalties under the Schedule to the Act run up to ₹250 crore per instance for failing to take reasonable security safeguards, with other breaches carrying their own ceilings.

Two provisions do the heavy lifting on deletion:

Section 12 gives every Data Principal the right to ask for correction, completion, updating and erasure of their personal data, where it was processed on the basis of consent or voluntary provision.

Section 8(7) goes further. Even without a request, you must erase personal data once the person withdraws consent or once it is reasonable to assume the purpose is no longer being served, unless another law requires you to keep it. You also have to make your Data Processors erase it.

Rule 8 of the DPDP Rules adds detail, including a minimum one-year retention of processing logs and fixed retention periods (with a 48-hour advance notice before erasure) for certain large e-commerce, gaming and social media platforms listed in the Third Schedule. Rule 14 requires you to publish how people can exercise their rights and to respond to grievances within a period not exceeding 90 days.

The recruitment blind spot

Here is where the EXTIA case lands closest to home. HR data is where many Indian businesses are least organised.

Think about a typical 60-person startup in Pune or Bengaluru. CVs arrive through Naukri, LinkedIn, a careers page form, referral emails and a shared recruiting inbox. Shortlisted candidates move into a spreadsheet or an applicant tracking system. Interview feedback lives in Slack threads and Google Docs. Rejected candidates are rarely deleted from any of it.

Under the DPDP Act, applicants who send a CV for a specific role are arguably covered by Section 7(a), the legitimate use for data a person voluntarily provides for a specified purpose. That is a reasonable basis for considering them for that role. It is a much weaker basis for keeping their CV for three years "in case something comes up", adding them to a talent newsletter, or sharing their profile with a client.

Former employees are different again. Section 7(i) covers processing for employment purposes, and labour and tax laws may require you to keep certain payroll and statutory records. But the justification has to be tied to a specific law or purpose, not to habit.

Building a right to erasure process under the DPDP Act

You need a clear path and someone who owns it, not expensive software.

1. Map where people's data actually lives

List every place a candidate's or ex-employee's details can end up: job portals, email, ATS, spreadsheets, background verification vendors, cloud drives, WhatsApp groups. If you cannot find it, you cannot delete it. A privacy impact assessment of your hiring workflow is a practical place to start.

2. Set retention periods by category

Decide, in writing, how long you keep rejected applicants' CVs (six to twelve months is a common business choice), what you keep for ex-employees and under which law, and when interview notes are purged. Put the rule into your ATS or a monthly calendar task.

3. Create one intake channel

Publish a single email address or form for rights requests in your careers page notice and your privacy notice. Route everything there. Requests sent to a recruiter's personal inbox are the ones that disappear.

4. Always close the loop

This was EXTIA's biggest failure. Even if the data was already gone, send a short written reply confirming what was erased, what was retained, and why. Keep a log of the request, the date and the response.

5. Push the request down to vendors

Your background verification agency and ATS provider are Data Processors. Your contracts should require them to erase on instruction and confirm when they have done so.

A realistic timeline

With roughly seven and a half months to May 2027, a small team can finish the data map and retention schedule by December, set up the intake channel and response templates in January, and run a mock request in February. That leaves room to fix what breaks.

If you want a structured view of where your gaps sit, our DPDP compliance checklist covers rights handling alongside consent, notices and security. For businesses that also serve European clients, our GDPR compliance consulting team can align both processes so you are not running two parallel systems.

No hacker was involved in the EXTIA case, and no headline breach. The fine grew out of unanswered emails from people who once applied for a job, which is a problem most Indian SMEs can fix well before the deadline.

This article is general guidance and not legal advice. For advice on your specific situation, please consult a qualified professional. Ready to test your readiness? Start with the DPDP checklist or talk to our team.

Get help implementing this

Turn this reading into a compliance plan.

Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.

Book a free 30-minute consultation