Share This Article
GDPR data subject rights are becoming a significant enforcement risk for companies, even a single complaint can lead to large fines if it reveals weaknesses in the way personal data is managed across different systems, teams and business processes.
Two recent European decisions illustrate this very well.
The French CNIL has fined EXTIA €300,000 for failing to properly handle requests from individuals exercising their GDPR rights, while the Italian Garante has imposed a €5.508 million fine on BBVA following a complaint concerning a single individual.
The two cases are different, both in terms of the facts and the GDPR provisions involved, but they raise a common question: How much regulatory exposure can arise from the way a company handles one individual’s GDPR rights?
The EXTIA case shows that the process matters
On 21 July 2026, the French CNIL fined EXTIA €300,000 for several failures concerning the exercise of data subject rights, including the right to erasure under Article 17 GDPR. The case followed complaints from former employees and candidates who experienced difficulties when exercising their right to erasure. The case was also considered in the context of the EDPB’s coordinated enforcement action on the implementation of the right to erasure.
EXTIA received 265 erasure requests in 2024, most of which came from candidates and, occasionally, former employees. More than three quarters of these requests had either not been dealt with or had not been dealt with satisfactorily.
The CNIL found that 12 requests had not been processed at all, while 166 individuals had not been informed of the action taken following their request. A further 27 individuals were informed late, outside the applicable one-month period.
What I find particularly interesting about this decision is that the regulator did not simply look at whether personal data had ultimately been deleted. The focus was also on how the company managed the exercise of the right, including the way requests were received, processed and communicated to individuals.
This is an important distinction for companies because having a GDPR policy that explains how individuals can exercise their rights is very different from having a process that actually works when someone exercises those rights.
The EDPB’s work confirms that this is not an isolated issue. In its 2026 report following the coordinated enforcement action on the right to erasure, the EDPB described the right to erasure as one of the most frequently exercised data subject rights and one that generates a significant number of complaints across Europe.
The BBVA decision takes the issue much further
The decision of the Italian Garante against BBVA is even more striking from an enforcement perspective as it originated from a complaint by a single individual.
The individual had objected to receiving commercial communications through the BBVA app and had also contacted customer service. According to the Garante, the customer’s choice had been recorded in one system but had not been correctly synchronised with the CRM system used for sending commercial communications. The result was that the single individual continued to receive commercial communications despite having exercised the relevant right.
The Garante found violations concerning, among other matters, the right to object, the obligation to provide an appropriate response and the technical and organisational measures adopted by BBVA, with the situation continuing for approximately seven months.
The most remarkable point, however, is the amount of the sanction: €5.508 million for a case concerning one individual.
This does not mean that the number of individuals affected is irrelevant when a GDPR fine is calculated. The GDPR requires supervisory authorities to consider several factors, including the nature, gravity and duration of the infringement, the degree of negligence, previous infringements and the need for the sanction to be effective, proportionate and dissuasive.
However, the BBVA decision shows how the exercise of privacy rights might be a powerful weapon in the hands of individuals.
For large organisations, the size of the undertaking and its turnover can also have a significant impact on the amount of the fine, meaning that what starts as a complaint by one individual can ultimately have a very different financial dimension. Indeed, this is the first case in which the Garante took as parameter for the calculation of the GDPR fine the worldwide turnover of the company.
Why should companies pay attention to GDPR data subject rights?
I think these cases are particularly relevant for industries that process large databases like banks and insurance companies but also retail brands and gaming operators. A customer may interact with a company through its website, mobile application, customer support, CRM platform, payment systems, marketing platforms and several external service providers.
Personal data can therefore move between different systems and teams during a single customer journey, and this creates a significant operational risk when a player exercises a GDPR right.
For example, a customer may object to direct marketing through an app, while the CRM system continues to send communications because the objection has not been properly propagated across the organisation.
A customer may also request access to personal data, ask for the deletion of an account or exercise another data subject right through customer support, without the request being properly escalated to the privacy team.
The legal issue may therefore start as a relatively small operational failure, but the regulator may then examine what that failure says about the company’s overall ability to respect data subject rights.
This is where GDPR data subject rights become an enforcement issue rather than simply a privacy compliance issue.
When a GDPR request becomes part of a dispute
There is another aspect of these cases that deserves attention, particularly for companies dealing with large numbers of customers, employees and former employees. Data subject rights can increasingly become intertwined with employment, commercial and customer disputes.
An individual involved in a dispute with a company may exercise several GDPR rights, submit repeated requests or combine a data subject request with other complaints and legal claims.
This does not mean that such requests are abusive, and companies should be very careful before making such an assumption because GDPR rights are fundamental rights that controllers must respect.
At the same time, Article 12(5) GDPR expressly allows controllers to take action where requests are manifestly unfounded or excessive, while Article 17 contains exceptions that may be particularly relevant where personal data needs to be retained for the establishment, exercise or defence of legal claims.
The challenge for companies is therefore to distinguish between a legitimate exercise of a data subject right and a situation in which the request forms part of a broader dispute, while continuing to respect the individual’s rights throughout the process.
This is also why I think companies should avoid creating procedures that make it unnecessarily difficult for individuals to exercise their rights. The process should be designed to facilitate the exercise of the right, while giving the company sufficient information to identify the request, assess it properly and document the steps taken.
What should companies do?
The practical lesson from EXTIA and BBVA is not to create another GDPR policy that sits in a compliance folder.
Companies should instead have
- an operational process connecting privacy, customer service, IT, CRM, compliance and legal teams, particularly where the exercise of a data subject right can affect several systems.
- that process should establish how a request can be submitted, how it is identified and recorded, who is responsible for handling it, how it is escalated, how the relevant systems are updated and how the company can demonstrate what happened if a regulator subsequently asks questions.
- the process should also be tested to make sure that requests are easily identified and handled, easily accessible from customers and there is no inefficiency.
A company may have a perfectly drafted procedure stating that a customer can object to direct marketing, but if the objection does not actually stop the marketing because the relevant systems are not connected, the organisation may still face a regulatory investigation.
This is why I believe privacy governance needs to move closer to the way companies approach cybersecurity and operational resilience. The question is not only whether the legal right exists, but whether the organisation’s technology and processes are capable of making that right effective in practice.
One complaint can expose a much bigger problem
The EXTIA and BBVA decisions ultimately illustrate two sides of the same problem.
EXTIA shows that failing to establish an effective process for handling data subject rights can lead to enforcement when a significant number of requests are not properly managed.
BBVA shows that a much smaller incident can also result in a very significant sanction where the regulator identifies weaknesses in the organisation’s compliance and governance, particularly when the infringement continues over time and the company is a very large undertaking.
The starting point may therefore be one GDPR complaint, but the regulator’s questions may quickly become much broader.
GDPR data subject rights are fundamental, and companies should make sure that they can be exercised effectively. At the same time, companies need to ensure that their procedures are sufficiently robust to deal with difficult or repeated requests and, where appropriate, to demonstrate why a particular request could not be fulfilled or why certain data could legitimately be retained.
The lesson from EXTIA and BBVA is therefore quite simple: a GDPR complaint may start with one player, but the regulatory consequences can be much bigger.
On a similar topic, you can read the article “Enforcing data subjects’ privacy rights in the context of Artificial Intelligence (AI)“.

