# APD/GBA (Belgium) - 97/2026

- Type: Enforcement
- Source: APD/GBA (Belgium)
- Date: 2026-05-06
- Original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_97/2026
- Canonical: https://overview.legal/posts/144020
- Topics: Accuracy, Insurance, Marketing, Security, Right of Access Procedures, Risk Management System, Data Subject Rights Exercise Modalities and Procedures, Identification, Privacy by Design, Data Controller

## Summary

Facts — The data subject was a technician employed by the controller. The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained the technician’s working hours, journeys, services performed and the clients visited. On 10 May 2021, the data subject requested copies of their service sheets covering the previous five years in order to verify whether the hours they had reported corresponded to those recorded by the controller. The controller provided only the sheet concerning the week of 3 May 2021 to 9 May 2021 and subsequently proposed that the data subject arrange an appointment to consult the records at its premises. The data subject reiterated the request on 17 January 2022 and again in 2023, but never received the requested copies. On 27 July 2023, the data subject lodged a complaint with the Belgian DPA. The DPA issued the prima facie Decision 14/2025, where it ordered the controller to comply with the data subject’s access request and warned it of potential violations of Article 15(3) GDPR and Article 12(3) GDPR. The controller requested an examination on the merits. The controller argued that the data subject’s request had not clearly distinguished between the handwritten service sheets and a computer-generated statement. It further claimed that the request was excessive under Article 12(5) GDPR because the documents were stored by date rather than by employee in several dozen binders. Locating, copying and scanning the relevant records would therefore require considerable workload. For that reason, it had invited the data subject to inspect the binders in its premises and identify the relevant documents to be copied. The data subject maintained that their request had always been clear, that the computer-generated statement was incomplete and unintelligible and that the practical difficulties relied upon by the controller resulted from its own archiving practices. Holding — The DPA ruled that the data subject had made a sufficiently clear request for access and a copy under Article 15(1) GDPR and Article 15(3) GDPR. It further pointed out that the controller’s response demonstrated that it had understood that the data subject sought copies of the service sheets themselves. The DPA further held that the computer-generated statement did not satisfy the request. It noted that the data subject needed the handwritten records in order to compare the hours they had reported with those subsequently recorded by the controller. It referred to C-487/21 (Österreichische Datenschutzbehörde) and recalled that the copy provided must constitute a faithful and intelligible reproduction of the personal data and may require copies of documents where this is necessary for the effective exercise of the data subject’s rights. The DPA therefore determined that the controller’s invitation to inspect the documents at its premises therefore did not constitute an adequate response to the data subject’s request for a copy. It stated that if the controller had genuinely been uncertain about the scope of the request, it should have sought clarification in accordance with Article 12(2) GDPR. Moreover, it rejected the controller’s reliance on Article 12(5) GDPR. The DPA held that the request was neither manifestly unfounded nor excessive as was clearly expressed and properly understood by the controller. It found that the controller did not demonstrate the excessiveness but relied exclusively on the workload resulting from its own archiving system. The DPA also relied on C-526/24 (Brillen Rottler) and applied the abuse of rights test. It found that neither its objective nor its subjective element was established. It reasoned that the request pursued the purpose of Article 15 GDPR, since the data subject sought to access and verify the accuracy of personal data concerning them, nor was there any evidence that the data subject had artificially created the conditions for obtaining an advantage under the GDPR. It further referred to EDPB Guidelines 01/2022 on the right of access, emphasizing that the time and effort required for a controller to fulfil an access request cannot, in itself, make the request excessive, particularly since the burden resulted from organisational choices made by the controller. It also emphasized that the data subject was also not required to justify the reasons for the request. The right of access under Article 15 GDPR does not include any general proportionality reservation regarding the controller’s efforts. Additionally, the term "appropriate" in Article 12(1) GDPR should not be used to limit the scope of data covered by the right of access. The DPA concluded that the alleged burden could not justify a refusal, especially since it stemmed from self-imposed organizational and administrative constraints related to the controller’s archiving system. A refusal may only apply if there is proven abusive intent, as defined by applicable requirements. Any other interpretation would undermine Article 15 GDPR and conflict with Article 12(2) GDPR and Article 25 GDPR, which require controllers to facilitate access requests and implement technical and organizational measures from the outset to ensure effective exercise of this right. The DPA further held that the controller had violated Article 12(2) GDPR, Article 12(3) GDPR and Article 12(4) GDPR. It had neither responded within the applicable time limit nor formally notified the data subject of a reasoned refusal. It further emphasized that the controller by requiring the data subject to attend its premises and identify the relevant records, it improperly transferred to them a task that belonged to it. Moreover, it noted that on-site consultation of the records could have exposed the data subject to personal data relating to the controller’s clients. The DPA held that under Article 15(4) GDPR, the controller was required to assess whether measures, such as partial anonymisation of third-party information, were necessary and that provision could not justify a blanket refusal to provide a copy. The DPA reprimanded the controller for violating Article 12(2) GDPR, Article 12(3) GDPR, Article 12(4) GDPR, Article 15(1) GDPR and Article 15(3) GDPR and ordered it to provide copies of the timesheets within one month.

## Full text

1/24 Litigation Chamber Decision on the merits 97/2026 of May 6, 2026 Case number: DOS-2023-03100 Subject: Complaint concerning the failure to act on a request for access to a copy of service records The Litigation Chamber of the Data Protection Authority (hereinafter "DPA"); Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter "GDPR"; Having regard to the Law of 3 December 2017 establishing the Data Protection Authority (hereinafter “the Data Protection Authority”); Having regard to the Rules of Procedure as approved by the Chamber of Representatives on 20 December 2018 and published in the Belgian Official Gazette on 15 January 2019 (hereinafter “the Rules of Procedure”); Having regard to the documents in the file and having heard the parties at the hearing of 15 October 2025; The following decision has been taken concerning: The complainant: X, residing at […], represented by Steve Gilson, whose office is located at […], hereinafter “the complainant”; The defendant: Y-S.A., whose registered office is located at […], registered under company number […], represented by Hervé Deckers and Anne-Catherine Doyen, whose office is located at […], hereinafter referred to as “the defendant”. 1. The APD notes that the revised LCA (Law on Administrative Procedure) entered into force on June 1, 2024. It applies only to complaints, mediation cases, applications, inspections, and proceedings before the Litigation Chamber initiated on or after that date. mediation cases, applications, inspections, and proceedings before the Litigation Chamber initiated on or after that date. Cases initiated before June 1, 2024, such as this case, are subject to the provisions of the previous version of the Data Protection Act (LCA), accessible here: https://www.autoriteprotectiondonnees.be/publications/loi-organique-de-l-apd.pdf 2The new Internal Regulations (ROI), resulting from the amendments made by the Law of December 25, 2023, amending the Law of December 3, 2017, establishing the Data Protection Authority (LCA), entered into force on June 1, 2024. They apply only to complaints, mediation cases, requests, inspections, and proceedings before the Litigation Chamber initiated on or after that date. Cases initiated before June 1, 2024, are subject to the provisions of the ROI as it existed before that date. Decision on the merits 97/2026 — 2/24 I. Facts and procedure 1. The complainant is a technician employed by the defendant. He filed this complaint following the defendant's refusal to respond to a request for access to a copy of his service records for the period from May 10, 2016, to May 10, 2021 (also referred to as "route sheets" or "work sheets" by the parties). These service records (one per week) detail, for each day worked, the sequence of trips and services performed, based on handwritten notes prepared by the technician (including the times of interventions, the services performed, and the clients at whose premises the intervention took place). 2. On May 10, 2021, the plaintiff requested that the defendant provide corrections to all the timesheets for the past 5 years: “Therefore, I request that by this date all technicians, myself included, have received corrections to all their timesheets in order to check for any anomalies or omissions during these past 5 years, or, if they have been with the company for less than 5 years, from their start date.” 3. On the same day, the defendant provided the plaintiff with only one copy of his timesheets, for week 18 (May 3, 2021 to May 9, 2021), which was the subject of discussion between the parties. 4. On May 31, 2021, following a meeting held on May 25, 2021, the defendant clarified to the plaintiff the procedures for providing copies: “If you require a copy of a route sheet for a specific date, you can contact Z1, who will scan the route sheet. If you require a copy of all your past route sheets: - Make an appointment with Z2, 7 business days in advance, - We prepare folders containing only services rendered, - To ensure clarity in the future, we will consider using electronic route sheets to facilitate future exchanges,…). » 5. On January 17, 2022, by registered mail and email, the complainant reiterated his request for access in the following terms: 3. The time sheets, also referred to as time sheets by the parties, constituted the defendant's system for recording working time, fulfilling a function similar to that of a time clock, in handwritten form. Decision on the merits 97/2026 — 3/24 “Mr. X was also concerned to see discrepancies between the time sheets submitted by the workers and what was actually declared to the payroll department and therefore paid. Mr. X reported this to the company and requested that the worker be given access to the time sheets for the last five years (…). Mr. X also requests the production of all his timesheets in accordance with the General Data Protection Regulation (GDPR) so that he can verify the accounting of his hours in light of the irregularities he has observed.” 6. On (…), the Labor Court of (…) renders a judgment concerning a labor law dispute between the parties. 7. On February 17, 2023, the defendant writes to the plaintiff in the following terms: “Mr. X has demanded that Company Y produce his timesheets since the beginning of his employment, under threat of referring the matter to the Labor Inspectorate. Although this request was not justified, my client confirmed to her that she would do what was necessary, with all rights reserved and without any acknowledgment, provided that she understood that relations with Mr. X would continue peacefully and that no reproach of any kind could be made against her. She however, she would not accept being subjected to any form of blackmail by Mr. X ”. 8. On February 18, 2023, the plaintiff responded to the defendant as follows: “Mr. X is not engaging in any blackmail by requesting his timesheets . This is a request that has been made for a very long time and which we do not understand why the employer is not complying with. This request does not need to be justified. Its justification is very simple.” 9. On February 23, 2023, the complainant informed the defendant that he had gone to “City 2” on February 20, 2023, to request his service records, which the defendant had allegedly refused to provide. 10. On March 2, 2023, the defendant replied to the complainant as follows: “Regarding the complainant’s request for his service records, I confirm – again and as needed – that the complainant can review them at the defendant’s head office, located in “City 1,” outside of business hours and by making an appointment beforehand.” Decision on the merits 97/2026 — 4/24 These documents may be consulted electronically as soon as within the framework of the digitization process in place at the (defendant), these documents are stored electronically. 11. On March 31, 2023, the complainant replied to the defendant as follows: “Regarding consultation of the service sheets, (the complainant) has already gone to “city 1” in the past with his colleague, (…), and access was refused. Even based solely on the IT policy, obtaining the route sheets in question should not pose any difficulty. Mr. Z2 also sent an email (to the complainant) indicating that he could consult the service sheets at “city 2” or “city 1” in a folder.” What is the concrete situation? 12. On April 14, 2023, the defendant replied: “Regarding the consultation of the benefit records, I can only refer you to our previous exchanges.” 13. On July 27, 2023, the complainant filed a complaint with the Data Protection Authority (DPA) against the defendant. 14. On October 13, 2023, the complaint was deemed admissible by the Frontline Service based on Articles 58 and 60 of the LCA (Law on Insurance Contracts) and the complaint was forwarded to the Litigation Chamber pursuant to Article 62, § 1 of the LCA. 15. On February 14, 2024, the Litigation Chamber sent a letter to the complainant, requesting that the complainant provide, no later than February 28, 2024, a dated copy of their correspondence with the respondent, and in particular the email(s) indicating their refusal to provide a copy of their service records. 16. On October 22, 2024, the Litigation Chamber sent a letter to the parties in 5 containing several pieces of information. It indicated that the file did not sufficiently present the respondent's position regarding their refusal to comply with the complainant's access request. The Litigation Chamber considered it essential to have the respondent's position in order to properly assess the arguments with regard to Articles 15.4 and 12.5 of the GDPR. The complainant's position, on the other hand, was sufficiently developed. 4 Pursuant to Article 61 of the LCA, the Litigation Chamber hereby informs the parties that the complaint has been declared admissible. 5. Pursuant to Article 95, §2 of the LCA, by letter of October 22, 2024, the Litigation Chamber informs the parties that, following this complaint, the file has been forwarded to it, as well as the possibility of consulting and copying said file. Decision on the merits 97/2026 — 5/24 The Litigation Chamber therefore requests the defendant to provide reasons for why it considers it is not required to respond to the complainant's request for access, based on Article 15.3 of the GDPR, seeking a copy of his performance records since he entered service, i.e., from May 10, 2016, to May 10, 2021. It requests the defendant to submit its response by November 25, 2024. 17. On November 4, 2024, the defendant contests having refused to respond to a request for access from the complainant. She produced the letters of March 2, 2023, and April 14, 2023 (points 10 and 12), in which she had proposed arrangements allowing the complainant to review his service records. The defendant indicated that following these two letters, she received no response from either the complainant or his counsel. 18. On January 23, 2025, the Litigation Chamber adopted prima facie decision No. 14/2025. In this decision, the Litigation Chamber decides: - pursuant to Article 58.2.c) of the GDPR and Article 95, § 1, 5° of the Swiss Federal Act on Administrative Procedure (LAC), to order the defendant to comply with the data subject's request to exercise their rights, and more specifically, to comply with the complainant's request for access and a copy of the data (Article 15 of the GDPR), within 30 days from the date of notification of Decision No. 14/2025; and - pursuant to Article 58.2.c) of the GDPR and Article 95, § 1, 4° of the LCA, to issue a warning to the defendant regarding potential violations of Articles 15.3 and 12.3 of the GDPR. 19. On February 19, 2025, the defendant exercised the option provided in the decision "prima facie" to request a hearing on the merits of the case pursuant to Articles 98 et seq. of the LCA. 20. On February 25, 2025, the Litigation Chamber decided, pursuant to Article 95, § 1, 1° and Article 98 of the LCA, that the case could be heard on its merits. The parties concerned were notified by registered mail of the provisions as set out in Article 95, § 2 and Article 98 of the LCA. They were also informed, pursuant to Article 99 of the LCA, of the deadlines for submitting their pleadings. Having regard to the documents in the file, including the complaint form, the Litigation Chamber invited the parties to submit their arguments regarding compliance with and applicability of the following provisions of the GDPR: - Alleged violations of Articles 12.3, 12.4, 15.1 and 15.3 of the GDPR due to the lack of response and follow-up to the exercise of the right of access aimed at obtaining a copy of the service records. Decision on the merits 97/2026 — 6/24 - Applicability of Article 12.5 of the GDPR to the complainant's access requests, in that the defendant alleges that these requests are unfounded or, at the very least, excessive. The complainant's submissions: 21. On April 30, 2025, the Litigation Chamber received the complainant's submissions. The plaintiff requests that the Litigation Chamber rule that the defendant has violated Articles 12 and 15 of the GDPR, and order the defendant to comply with the plaintiff's request for access and a copy, by ordering the defendant to provide, within eight days of the decision, a copy of its service records for the last five years, in response to its request of May 10, 2021, under penalty of a fine of €10,000 per missing document and per day of delay. The plaintiff's arguments can be summarized as follows. - As a first ground of appeal, the plaintiff characterizes the defendant as the data controller. The defendant does not contest this; - As a second ground of appeal, the complainant maintains that he exercised his right of access with the defendant on several occasions, in accordance with Article 15.3 of the GDPR, in particular on May 10, 2021, by requesting a copy of his service records. - As a third ground of appeal, the complainant considers that the defendant violates Articles 12 and 15 of the GDPR, insofar as, firstly, contrary to what it claims for the first time in its submissions, it did not comply with the complainant's request for a copy; and, secondly, the defendant does not legally justify its refusal to provide a copy of the service records. Indeed, the complainant believes that this refusal cannot be justified by the cumbersome nature of this delivery, resulting from the defendant's own filing choices, nor by the alleged impossibility of identifying the service records. - As a fourth ground of appeal, and in addition, the complainant argues that the defendant deprived him of all access to the service records, and not only refused to comply with his request for a copy. Decision on the merits 97/2026 — 7/24 The defendant's submissions: 22. On May 13, 2025, the Litigation Chamber received the defendant's summary submissions. The defendant's arguments can be summarized as follows: - The defendant maintains that it did not violate Articles 12.3 and 15.3 of the GDPR. She believes she responded favorably to the complainant's request for access and copies within one month of his request. - She also believes that if she did not comply with a request for a copy, it was because she was unable to identify the documents targeted by the request for access and copies, and because providing such a copy would constitute a considerable undertaking requiring adherence to a specific procedure. For these reasons, without refusing to comply with the request, the defendant invited the complainant to make an appointment at least seven business days in advance for an on-site review of the service records at the company's headquarters. The defendant believes the complainant did not comply with this procedure. - Finally, the defendant considers that the complainant's request is manifestly unfounded or, at the very least, excessive, within the meaning of Article 12.5 of the GDPR, and that in such a case, it may refuse to grant the request for access to the service records. II. Reasoning II.1. Regarding the scope and purpose of the request for access and a copy (Articles 15.1 and 15.3 of the GDPR) i. Applicable principles 23. The right of access provided for in Article 15 of the GDPR consists of three elements, namely (i) confirmation of whether or not personal data is being processed (“Confirmation component”), (ii) access to that data (hereinafter “Access component”), and (iii) information about the processing (“Information component”). This connection is reiterated by the European Data Protection Board (hereinafter “EDPB” for European Data Protection Board) in its Guidelines 01/2022 on the right of access. Indeed, under Article 15.1 of the GDPR, the data subject has the right to obtain from the controller confirmation as to whether or personal data concerning him or her are being processed. Where this is the case, the data subject has the right to obtain access 6The European Data Protection Board (hereinafter “EDPB” for European Data Protection Board) brings together the data protection authorities of the Member States of the European Union and aims to ensure the consistent application of the GDPR. EDPB, Guidelines 01/2022 on the rights of data subjects – right of access, adopted on 28 March 2023 (hereinafter referred to as the “Guidelines 01/2022 on the right of access”), available at: https://www.edpb.europa.eu/system/files/2024-04/edpb guidelines 202201 data subject rights access v2 fr.pdf. Decision on the merits 97/2026 — 8/24 to said personal data as well as to a series of information listed in Article 15.1 a) to h) such as the purpose of the processing of his data, the possible recipients of his data as well as information relating to the existence of his rights, including the right to request the rectification or erasure of his data or the right to lodge a complaint with the Data Protection Authority. 24. Pursuant to Article 15.3 of the GDPR, the data subject has the right to obtain a copy of the personal data which are the subject of the processing. This possibility of obtaining a copy of the personal data processed is not an additional right of the data subject, but simply the means of accessing the data. This provision also specifies that when the data subject submits their request electronically, the information must be provided in a commonly used electronic format, unless the data subject requests otherwise. Article 15.4 of the GDPR stipulates that this right to a copy must not infringe upon the rights and freedoms of others. 25. Regarding the procedures that a data controller must follow in response to a data subject's access request, the Litigation Chamber reiterates that the obligation to provide a copy, as provided for in Article 15.3 of the GDPR, should not be understood as an additional right of the data subject, but rather as a means of granting access to the data. Therefore, access to data under Article 15.1 of the GDPR must include all information concerning all data, and this access cannot be understood as granting access only to a summary of the data. The obligation to provide a copy serves the purposes of the right of access, namely to allow the data subject to be informed of the lawfulness of the processing and to control it (Recital 63 of the GDPR). To achieve these purposes, it is in most cases not sufficient for the data subject to be able to temporarily consult the information, and they must be able to access their data by being provided with a copy of it. 26. In its judgment C-487/21 of 4 May 2023, the Court of Justice of the European Union (CJEU) held that Article 15.3 of the GDPR must be interpreted as meaning that “the right to obtain from the controller a copy of the personal data undergoing processing implies that the data subject must be provided with a faithful and intelligible reproduction of all such data.” This right implies the right to obtain a copy of extracts of documents, or even entire documents, or extracts from databases which contain, among other things, said data, if the provision of such a copy is essential to enable the person concerned to effectively exercise the rights 8EDPB, Guidelines 01/2022 on the right of access, point 3. Decision on the merits 97/2026 — 9/24 conferred upon him by this Regulation, it being stressed that, in this regard, the rights and freedoms of others must be taken into account.” ii. Positions of the parties 27. The defendant essentially argues that the complainant’s request for access was never sufficiently precise to allow for a useful response and that it considers, moreover, that it has validly responded to it. She argues that the initial request, made on May 10, 2021, in the context of the complainant's union duties, concerned corrections to route sheets, a request to which she claims to have responded the same day. Subsequently, when the complainant reiterated his requests in 2023, the defendant states that she did not know precisely which documents were involved, particularly because she had already provided him, as part of the legal proceedings, with a summary of the service records covering the requested period, and that the complainant had never specified which documents were still missing. The defendant maintains that it was only during the proceedings before the Litigation Chamber that the request was clarified, namely that it concerned individual handwritten records and not computerized records, whereas this distinction had never been clearly stated before. It is in this context that the defendant claims to have offered an on-site consultation at the head office, with prior appointment, a solution it presents as reasonable insofar as it would allow the complainant to identify for himself the documents he needs, given the considerable volume of records filed not by employee but by day worked. 28. The complainant strongly contests these claims. He maintains that his requests have always been clear and that the defendant has never complied with them. In this regard, he notes that the documents actually provided by the defendant in no way satisfy his request for copies, which concerned all timesheets since he started working. However, he only received a service record from the defendant following his request on May 10, 2021, as well as an incomprehensible computerized statement, which he found to be only partially documenting the services actually performed. CJEU, Judgment of May 4, 2023, Österreichische Datenschutzbehörde and CRIF GmbH, C-487/21, ECLI:EU:C:2023:369, § 45. Emphasis added by the Litigation Chamber. Decision on the merits 97/2026 — 10/24 iii. Position of the Litigation Chamber 29. Regarding the request of 10 May 2021, the Litigation Chamber is of the opinion that, notwithstanding the absence of an explicit reference to Article 15 of the GDPR, the request made by the complainant seeking corrections to all its roadmaps in order to check for any anomalies over the past five years, can be interpreted as a request for access to and communication of a copy within the meaning of Articles 15.1 and 15.3 of the GDPR, and is sufficiently clear in its purpose. The defendant's own reaction confirms this, since in response to this request, the defendant (i) on May 10, 2021, provided the complainant with a copy of a "corrected" benefits statement that was the subject of a discussion between the parties (who had rightly refused to provide the benefits statements of other individuals) and (ii) on May 31, 2021, asked the complainant either to identify the specific benefits statements he wished to obtain (in which case he could receive a scan of the statement in question), or to follow a specific procedure to obtain a copy of all his benefits statements, which demonstrates that the defendant understood that the complainant was indeed seeking copies of the benefits statements themselves (paragraph 4). 30. Secondly, regarding the request of January 17, 2022, any remaining ambiguity has, in any event, been dispelled. Indeed, on that date, the plaintiff's counsel expressly requested the production of all service records, invoking the GDPR (point 5), specifying that this request, covering the last five years, was part of the verification of his client's timekeeping. Such a formulation is unambiguous, both in terms of its purpose and its legal basis. The Litigation Chamber notes in particular that the plaintiff intended to obtain the service records themselves, in order to verify whether the hours he had himself declared corresponded to those actually recorded by the defendant. 31. The Litigation Chamber cannot therefore accept the argument that the defendant was unaware, until the proceedings before it, that the request concerned all the individual handwritten service records and that there was confusion regarding the precise subject of the request, on the grounds that it had produced, in the context of the judicial proceedings, a computerized record of the service records covering the period in question, a record which, according to it, satisfied the request. However, the plaintiff's request concerned not a record transcribing the data appearing on the records, but rather all the service records themselves. This request was expressed consistently and unequivocally in the plaintiff's repeated requests. The complainant explained to the defendant, from the outset, that he intended to obtain these copies in order to verify the recording of his hours, given the irregularities he had observed. However, it could not have escaped the defendant's notice that the provision of a computerized record did not in any way allow the complainant to carry out this verification, which could only be done by comparing it to the source documents, namely the handwritten forms that the complainant himself had completed. 32. Furthermore, the defendant's offer of on-site consultation cannot constitute an adequate response to the complainant's request. This request clearly concerned the provision of a copy within the meaning of Article 15.3 of the GDPR, and not merely a temporary consultation of the documents. The Litigation Chamber reiterates in this regard that the provision of a copy of the processed data constitutes the access method enshrined in this provision and gives the data subject the possibility of obtaining a faithful reproduction of their data, in a form that allows them to dispose of it freely and permanently. Inviting the complainant to consult the filing cabinets on the defendant's premises cannot therefore be considered an adequate response to a request for a copy, even if this consultation could, in practice, have been accompanied by the possibility of making photocopies on-site. 33. Moreover, if the defendant had any real doubt regarding the scope of the access request, it would have been incumbent upon it to clarify this with the complainant, in accordance with the obligation to facilitate access under Article 12.2 of the GDPR. 34. As for the temporal scope of the request, the Litigation Chamber finds no further uncertainty. Several of the successive requests expressly targeted the complainant's last five years of employment with the defendant, starting from the first request of May 10, 2021. 35. It is clear from all the evidence in the file that the request for a copy was clearly formulated by the complainant as early as May 10, 2021, and that it was manifestly understood as such by the defendant. The defendant's continued reluctance to provide the copy reveals that the alleged misunderstanding of the request was not the true reason for its inaction. This inaction stemmed, in reality, from the sheer volume of work that fulfilling the request represented. The Litigation Chamber considers that it is this consideration, and not any lack of clarity, that explains why the defendant systematically limited the complainant to an on-site consultation rather than providing a copy of all the requested documents. It is therefore necessary to examine whether this reason, based on the allegedly excessive nature of the request, is sufficient to justify the defendant's failure to respond. Decision on the merits 97/2026 — 12/24 II.2. Regarding the alleged excessive nature of the request for a copy (Article 12.5 of the GDPR) i. Applicable Principles 36. Article 12.5 of the GDPR establishes, first and foremost, the principle that exercising the right of access should not incur any costs for the data subject. This provision, however, considers two circumstances in which a data controller may either charge a reasonable fee taking into account administrative costs, or refuse to comply with a 11 access request. These circumstances relate to cases of abuse of rights, in which the requests of the data subject must be considered as being “manifestly unfounded” or “excessive,” the repetitive nature of the request being, in particular, a factor to be taken into account. Article 12.5 of the GDPR pursues, in this respect, the same objective as Article 57.4 of the same regulation and constitutes an expression of the general principle of Union law under which individuals may not fraudulently or abusively 14 rely on Union standards. 37. Article 12.5 of the GDPR establishes an exception to the obligation to facilitate the rights of the data subject, and in particular the right of access, which must be interpreted 15 restrictively. Similarly, the principles of transparency and free access to the rights of data subjects may only be compromised in exceptional circumstances. It follows that the data controller can only claim that a request is manifestly unfounded or excessive in exceptional circumstances and according to high standards, Article 12.5, paragraph 2, of the GDPR explicitly placing the burden of proof on the data controller, which must be demonstrated on a case-by-case basis, in light of the context in which the request was made. Apart from the limits, derogations, and limitations expressly provided for, the GDPR does not authorize any other exemption or derogation from the right of access. 38. In the aforementioned Guidelines 01/2022 on the right of access, the EDPB clarifies what is meant by “manifestly unfounded” and “excessive” within the meaning of Article 12.5 of the GDPR. 10. Article 12.5 of the GDPR states that “No payment shall be required for providing the information referred to in Articles 13 and 14 and for making any communication and taking any action referred to in Articles 15 to 22 and Article 34.” 11. Article 12.5 of the GDPR states that “where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive nature, the controller may: (a) charge a reasonable fee which takes into account the administrative costs of providing the information, making the communications or taking the action requested; or (b) refuse to comply with such requests.” It is incumbent upon the controller to demonstrate that the request is manifestly unfounded or excessive.” 12CJEU, Judgment of 26 October 2023, FT (Copies of the medical file), C-307/22, EU:C:2023:811, paragraph 31. 13See CJEU, Judgment of 19 March 2026, Brillen Rottler, C-526/24, EU:C:2026:216, paragraphs 26 to 35, in which the Court held that a first request for access can, in principle, be considered excessive within the meaning of Article 12.5 of the GDPR. 14 CJEU, Brillen Rottler, op. cit., paragraphs 23 to 30. 15 CJEU, Judgment of 9 January 2025, Österreichische Datenschutzbehörde (Excessive Requests), C-416/23, EU:C:2025:3, paragraph 33; CJEU, Brillen Rottler, op. cit., paragraph 29. Decision on the merits 97/2026 — 13/24 GDPR. Regarding the "manifestly unfounded" nature of the request, such a classification presupposes that the requirements of Article 15 of the GDPR are, according to an objective approach, clearly not met. Since there are very few prerequisites for the right of access, the cases in which a request can be deemed “manifestly unfounded” are very limited. Regarding the “excessive” nature of a request, the EDPB considers that, apart from the case of a repetitive request, a request can only be considered excessive in the event of abusive use of Article 15 of the GDPR, that is to say, when the data subject uses their right of access for the sole purpose of causing harm to the controller of the 18 processing. 39. This interpretation is consistent with the CJEU’s settled case law on the prohibition of abuse of rights. Proof of an abusive practice requires the presence of two elements: firstly, an objective element, consisting of a set of objective circumstances from which it follows that, despite formal compliance with the conditions laid down by the Union regulation, the objective pursued by this regulation has not been achieved; secondly, a subjective element, consisting of the intent of the person concerned to obtain an advantage resulting from the Union regulation by artificially creating the conditions required for obtaining it. 19 40. More specifically regarding the subjective element, the Court clarifies that an abusive intent can be established when the data subject submits their access request “ for a purpose other than to become aware of the processing of their data and to verify its lawfulness, in order to subsequently obtain protection of the rights they 20 are entitled to under this Regulation”. It is incumbent upon the data controller to demonstrate unequivocally that the data subject submitted an access request not to become aware of this processing, but to artificially create the conditions required for obtaining redress from said data controller. For the purposes of this assessment, the Court invites consideration of all the circumstances of the case, including the fact that the data subject provided personal data without being compelled to do so, the purpose for which this data was provided, the time elapsed between the provision of this data and the access request, and the conduct of that person. 16EDPB, Guidelines 01/2022 on the right of access. To submit an access request, it is sufficient for the requesting persons to specify that they wish to know what personal data concerning them is being processed by the data controller. No formal requirements are stipulated by the GDPR. For further details, see Guidelines 01/2022 on the Right of Access, section 3. 18EDPB, Guidelines 01/2022 on the Right of Access, paragraph 188 (emphasis added by the Litigation Chamber), see also the examples cited in paragraphs 189 and 190. 19 CJEU, Brillen Rottler, op. cit., paragraph 36 and the case law cited therein. 20 CJEU, Österreichische Datenschutzbehörde (Excessive Requests), op. cit., paragraphs 50 and 56. 21 CJEU, Brillen Rottler, op. cit., paragraph 41. 22 CJEU, Brillen Rottler, op. cit., paragraph 42. Decision on the merits 97/2026 — 14/24 ii. Positions of the parties 41. In the present case, the defendant argues, in substance, that the complainant's request is excessive, because providing the requested copy would represent a considerable workload, 23 given its archiving system. She explains in this regard that the timesheets are filed by workday in several dozen binders and not by worker, so that she would have to assign one or two members of her staff for several hours, or even several days, to isolate the complainant's timesheets, make copies, scan them, and send them to him. She adds that a company with more than fifty technicians would have to hire staff specifically for this purpose if such a request were to be fulfilled. It is for these reasons that she suggested the complainant come to the premises to identify for himself, in the binders, the timesheets he would like to have copied, with the company's administrative staff then making photocopies of the selected documents. 42. The complainant disputes this characterization. First, it is noted that the defendant did not, at any point during the exchanges preceding the complaint, invoke the manifestly unfounded or excessive nature of the request within the meaning of Article 12.5 of the GDPR. The complainant then argues that the practical difficulties invoked by the defendant stem exclusively from its own archiving choices (filing by day and not by employee), which it cannot use to evade its obligations under the GDPR. According to him, it would suffice to sort the relevant records and scan them to send a copy. iii. Position of the Litigation Chamber 43. In light of the principles recalled above, the Litigation Chamber considers that the defendant has not established the manifestly unfounded or excessive nature of the complainant's request within the meaning of Article 12.5 of the GDPR, for the following reasons. 44. First, the Litigation Chamber notes that the complainant's request cannot be considered manifestly unfounded within the meaning of Article 12.5 of the GDPR. As recalled above, such a classification can only be applied in exceptional cases where, following an objective approach, the requirements of Article 15 of the GDPR are clearly not met. In this instance, however, the complainant's request fulfills all the conditions to which the exercise of the right of access is subject. Indeed, the access request originates from an identified data subject, who requests the disclosure of personal data concerning them and which are actually processed by the defendant in its capacity as data controller, namely the timesheets Page 11 of the defendant's submissions: "The timesheets are filed by day worked in several dozens of binders. They are not filed by employee. Therefore, S.A. Y must isolate Mr. X's timesheets before Mr. X can consult them and, if necessary, make a copy." Decision on the merits 97/2026 — 15/24 of timesheets that she herself completed in the course of performing her employment. The defendant, moreover, provides no evidence to support the claim that the request was manifestly unfounded, its entire argument being in fact based on the allegedly excessive nature of the request, examined below. 45. Secondly, regarding the excessive nature of the request, the Litigation Chamber observes that the defendant's allegation of unfairness demonstrates that the plaintiff's request was made with abusive intent within the meaning of the aforementioned case law (paragraphs 36 to 40). It should be recalled that, pursuant to Article 12.5(2) of the GDPR, it is the controller who bears the burden of establishing whether the request is manifestly unfounded or excessive, according to the strict requirements outlined above. However, the defendant relied exclusively, in support of its refusal, on the workload that fulfilling the request would entail, due to its own archiving system. The Litigation Chamber notes, moreover, that the defendant only raised the argument based on Article 12.5 of the GDPR at the stage of its submissions before the Litigation Chamber, without having invoked this qualification during the exchanges preceding the complaint. 46. Thirdly, the application of the abuse of rights test to the present case does not allow the establishment of an abusive intent on the part of the complainant, either with regard to its objective element or with regard to its subjective element. - Regarding the objective element, the objective pursued by Article 15 of the GDPR cannot be considered as not having been achieved in this case. The plaintiff's request specifically seeks to access the personal data 24 concerning the data processed by the defendant and to verify its accuracy, namely the consistency between the services he himself recorded on the handwritten forms and those transcribed into the defendant's computer system. Even assuming that the complainant was also motivated by a reason unrelated to the purposes referred to in recital 63 of the GDPR — which is not the case —, this circumstance would remain irrelevant since the CJEU has ruled that the obligation to provide a copy applies to the data controller, even when this request is motivated by a purpose unrelated to those referred to, because, according to recital 63, the pursuit of a possible unrelated purpose, assuming it to be established, would not be such as to deprive the request of the objective that Article 15 of the GDPR is intended to serve. 24EDPB, Guidelines 01/2022 on the right of access, point 10: “The purpose of the right of access is to enable data subjects to understand how their personal data is processed and the consequences of such processing, and to verify the accuracy of the data processed without having to justify their intent. In other words, the objective of the right of access is to provide natural persons with sufficient, transparent, and easily accessible information on data processing, regardless of the technologies used, and to enable them to verify different aspects of a particular processing activity under the GDPR (e.g., lawfulness, accuracy).” 25CJEU, Order of 27 May 2024, Addiko Bank, C-312/23, EU:C:2024:458. Decision on the merits 97/2026 — 16/24 - Regarding the subjective element, the defendant remains unable to provide any evidence whatsoever to establish that the complainant intended to artificially create the conditions required to obtain an advantage under the GDPR. The complainant did not, in fact, provide his personal data to the defendant on his own initiative with a view to triggering processing and being able to rely on it later: the disputed timesheets were drawn up in the normal course of performing a pre-existing employment relationship. The provision of this data and the filing of the access request are, moreover, separated by several years—the request of May 10, 2021, concerns records created since May 10, 2016. Neither of the two cumulative elements of abuse of rights is therefore present in this case. 47. Fourth, and contrary to the defendant's assertion, the Litigation Chamber notes that the volume of documents covered by the request remains, in this instance, limited and easily identifiable. Since the timesheets were created at a rate of one per week per worker, the complainant's request, covering the period from May 10, 2016, to May 10, 2021, concerns approximately 250 documents, all clearly identified by worker and by time period. This is therefore by no means a general and indiscriminate request targeting all data potentially processed by the defendant (such as emails, HR documents, etc.), but rather a request focused on a single category of documents. 48. Fifth, even assuming that the workload invoked by the defendant is proven, this alone cannot render the request excessive within the meaning of Article 12.5 of the GDPR. The EDPB expressly emphasizes this in its Guidelines 01/2022 cited above, stating that "the fact that it would take a great deal of time and effort for the controller to provide the information or a copy to the data subject cannot, in itself, render a request excessive," since many processing activities inherently involve significant effort to satisfy data subject requests. Furthermore, the right of access does not include any general reservation regarding proportionality concerning the efforts that the controller must make to respond to the request of the data subjects under Article 15 of the GDPR. Moreover, the term "appropriate" appearing in particular in Article 12.1 of the GDPR cannot be interpreted as "a means of limiting the scope of the data covered by the right of access". It follows that the alleged burden cannot in itself justify a refusal, especially when it results, as 26EDPB, Guidelines 01/2022 on the right of access, paragraph 188. 27 Ibid., paragraph 166. 28Ibid., paragraph 129. Decision on the merits 97/2026 — 17/24 in this case, organizational and administrative constraints arising from the archiving system that the defendant imposed upon itself. Such a refusal is only likely to occur in the presence of an established abusive intent, in accordance with the requirements recalled above. Any other interpretation would render the right enshrined in Article 15 of the GDPR meaningless and would be contrary to both Article 12.2 and Article 25 of the same Regulation, which require the controller, respectively, to facilitate the exercise of the data subject's right of access and to implement, from the design stage of the processing, the appropriate technical and organizational measures to ensure its effective exercise. 49. Finally, it appears from the exchanges between the parties that the defendant intended to criticize the complainant for the lack of justification for his request for a copy (see in particular paragraph 7). The Litigation Chamber reiterates in this regard that the data subject is under no obligation whatsoever to justify the reasons why he intends to exercise his right of access. The CJEU has expressly ruled that neither Article 12.5 nor Articles 15.1 and 15.3 of the GDPR make the provision, free of charge, of a first copy conditional upon the data subject invoking a reason justifying his request. The defendant could not, therefore, make its response conditional upon the communication of such reasons. 50. In light of all these elements, the Litigation Chamber considers that the defendant has not established either the manifestly unfounded or excessive nature of the complainant's request within the meaning of Article 12.5 of the GDPR. It could not, therefore, legitimately rely on this provision to refrain from complying with the request for a copy. II.3. Regarding compliance with other procedures for exercising the right of access (Articles 12.2, 12.3 and 12.4 of the GDPR) 51. Article 12 of the GDPR, concerning how data subjects may exercise their rights, stipulates, in particular, that the data controller must facilitate the exercise of rights by the data subject (Article 12.2 of the GDPR) and provide them with information on the measures taken in response to their request as soon as possible and at the latest within one month of their request (Article 12.3 of the GDPR). When the data controller does not intend to comply with the request, they must notify their refusal within one month, providing information that an appeal against this refusal may be lodged with the data protection supervisory authority (Article 12.4 of the GDPR). 52. In the event of a refusal to comply with a request, the Litigation Chamber emphasizes the importance of providing reasons for this refusal. Article 12.4 of the GDPR must be read in CJEU, FT (Copies of the medical file), op. cit., paragraphs 38 to 52. Decision on the merits 97/2026 — 18/24 in conjunction with Article 12.2: to facilitate the exercise of the rights of data subjects, a data controller must state in clear and plain language the reason for their refusal. If this refusal is based on a legal provision, the relevant legal provision must be communicated to the data subject. Indeed, it would be difficult for a data subject to assess the validity of a refusal and to exercise their rights if the reason for such a refusal is based on an incorrect or missing legal basis. 53. The defendant maintains that it did not refuse to comply with the plaintiff's request, but implemented a specific procedure that the plaintiff was required to follow in order to obtain a copy of the disputed documents. This procedure, communicated to the plaintiff, stipulated that the plaintiff must make an appointment at least seven business days in advance for a consultation on-site at the defendant's registered office. The defendant justifies this approach as follows: "Although isolating all of Mr. X's roadmaps over several years requires considerable work, Company Y is willing to undertake this work provided that Mr. X complies with the established procedure. Company Y did not refuse Mr. X's request when it was in a position to do so, but established a procedure to be followed, given the scale of the work involved in this request." 54. While asserting that it did not refuse to comply with the request, the defendant maintains at the same time that the request is manifestly unfounded or, at the very least, excessive within the meaning of Article 12.5 of the GDPR, and that it is therefore entitled to reject it. 55. The Litigation Chamber cannot accept this presentation of the facts. It has been established that the complainant's request was clear and that the defendant has, in fact, refused to comply with it since May 10, 2021, on the grounds of the workload it entailed. In doing so, the defendant never formally notified the complainant of a refusal as required by Article 12.4 of the GDPR. On the contrary, it left the complainant in limbo, offering him alternative procedures that placed a burden on him that should have fallen on the data controller, thereby simultaneously disregarding the obligation to facilitate the exercise of rights imposed by Article 12.2 of the GDPR. By making the release of documents conditional upon the complainant coming to its premises and by requiring him to identify the records he wishes to copy himself, the defendant is in fact transferring to him the burden that falls on him as the data controller. 56. The Litigation Chamber further notes that the on-site consultation solution proposed by the defendant raises an additional difficulty with regard to the GDPR. The service records contain not only the complainant's personal data, but also the names and information relating to the defendant's clients. However, allowing the complainant to freely consult the filing cabinets on the company's premises would expose him 30Defendant's Submissions, p. 13. Decision on the Merits 97/2026 — 19/24 necessarily to the personal data of third parties, in violation of the reservation provided for in Article 15.4 of the GDPR, which stipulates that the right to obtain a copy may not infringe on the rights and freedoms of others. This element supports the analysis that it was the defendant's responsibility, as the data controller, to extract the relevant records itself and, where applicable, to anonymize the data relating to third parties before communicating them to the complainant, rather than delegating this task to the data subject. 57. Faced with the complainant's access request, if the respondent did not intend to comply within the one-month period stipulated by Article 12.3 of the GDPR, several alternative avenues were available to it, provided the conditions for application were met. It could have, in particular, in accordance with the same article, informed the complainant of an extension of the response period by two additional months, provided that it notified the complainant of this extension within one month of receiving the request and provided reasons for it. It could also have formally notified the complainant of a reasoned refusal in accordance with Article 12.4 of the GDPR, where appropriate by invoking and justifying the manifestly unfounded or excessive nature of the request within the meaning of Article 12.5 of the GDPR, or, on the same grounds, required payment of reasonable costs for complying with it. She could have finally invoked Article 15.4 of the GDPR to refuse, in whole or in part, to provide the requested copies, insofar as this would infringe upon the rights and freedoms of others. However, the defendant did not pursue any of these avenues. She merely offered an on-site consultation, without ever notifying the complainant of a formal response to their request for a copy within the time limit prescribed by Article 12.3 of the GDPR, thus leaving the access request unanswered. 58. It follows from all of the above that the defendant failed to comply with its obligations under Article 12(2), (3) and (4) of the GDPR by failing to respond within the prescribed time limits to the complainant's request for a copy, by failing to formally notify the complainant of the reasons for its inaction, and by not facilitating the exercise of the complainant's right of access. II.4. Conclusions 59. Based on the foregoing, the Litigation Chamber finds that the defendant has committed the following violations: - The defendant, in practice, refused to comply with the complainant's request for copies of his service records, without formally notifying him of this refusal. By merely offering the complainant an on-site consultation procedure that placed the burden of identifying and reproducing the documents on him, the defendant did not facilitate the complainant's exercise of his right of access and failed to comply with its obligations. Decision on the merits 97/2026 — 20/24 incumbent upon it. The defendant thus violated Articles 12.2, 12.3 and 12.4, as well as Articles 15.1 and 15.3 of the GDPR. - The defendant failed to comply with the request for a copy within the prescribed time limits. The complainant submitted an initial access request on May 10, 2021, and reiterated it on several occasions, notably on January 17, 2022, and during 2023, without ever receiving the requested copy. As of the date of this decision, the request remains unanswered, in violation of Article 12.3 of the GDPR. 60. The Litigation Chamber gave the defendant the opportunity to comment on the applicability of Article 15.4 of the GDPR to the complainant's requests (paragraph 16). The defendant, however, based its argument exclusively on the allegedly excessive nature of the request and its purported lack of precision, without invoking or demonstrating that the exception provided for in Article 15.4 of the GDPR would apply to justify a refusal to provide the requested copy, in whole or in part. 61. The Litigation Chamber nevertheless considers that it cannot rule out that this provision is likely to apply in this case, given the nature of the documents in question. It will therefore be up to the defendant, when implementing this decision, to examine whether it is necessary to partially anonymize the information relating to third parties appearing on the service records. 62. The Litigation Chamber recalls that Article 15.4 of the GDPR provides that the right to obtain a copy within the meaning of Article 15.3 of the GDPR may not infringe upon the rights and freedoms of others. The concept of “others” must be interpreted broadly: it covers any person or entity other than the data subject exercising their right of access, so that the rights and freedoms of the controller itself may be taken into consideration, such as the preservation of the confidentiality of its trade secrets or the protection of its intellectual property, as well as the rights of third parties whose personal data may appear in the requested documents. 63. The Litigation Chamber emphasizes, however, that this exception provided for in Article 15.4 of the GDPR must, like any exception, be interpreted and applied restrictively. Recital 63 of the GDPR expressly states: “These considerations should not lead to refusing to provide any information to the data subject.” In other words, Article 15.4 of the GDPR cannot be used as grounds for a blanket refusal to provide a copy, but at most can justify, where appropriate, targeted measures such as partial anonymization of information relating to third parties, when its disclosure would disproportionately infringe upon their rights. Decision on the merits 97/2026 — 21/24 III. Sanctions and corrective measures 64. Pursuant to Article 100, § 1, of the LCA, the Litigation Chamber has the power to: “1° dismiss the complaint; 2° order a dismissal; 3° suspend the proceedings; 4. Propose a settlement; 5. Issue warnings and reprimands; 6. Order compliance with the data subject's requests to exercise their rights; 7. Order that the data subject be informed of the security issue; 8. Order the freezing, limitation, or temporary or permanent prohibition of processing; 9. Order the processing to be brought into compliance; 10. Order the rectification, restriction, or erasure of data and notification of this to the data recipients; 11. Order the withdrawal of accreditation of certification bodies; 12. Impose penalty payments; 13. Impose administrative fines; 14. Order the suspension of cross-border data flows to another State or an international organization; 15. To forward the file to the Public Prosecutor's Office in Brussels, which will inform it of the follow-up actions taken on the case; 16. To decide on a case-by-case basis whether to publish its decisions on the website of the Data Protection Authority. 65. The Litigation Chamber considers that, based on the aforementioned facts, it is necessary to conclude that the defendant violated Articles 12.2, 12.3, 12.4, 15.1, and 15.3 of the GDPR, and that Article 12.5 of the GDPR cannot, in this instance, justify the refusal of the complainant's request. These violations justify the Chamber taking a decision in accordance with Article 100, §1, 5° of the Belgian Law on Access to Information Technology (LCA), more specifically, issuing a reprimand to the defendant. 66. Regarding the violation of Article 12.2 of the GDPR, the Litigation Chamber emphasizes that this provision, which requires the data controller to facilitate the exercise of the rights of data subjects, is closely linked to Articles 12.3, 12.4, 15.1 and 15.3 of the GDPR, on which the Litigation Chamber invited the parties to reach an agreement in its letter of 25 February 2025 (paragraph 20). Articles 12 and 15 of the GDPR being intrinsically linked in that they jointly govern the procedures for exercising the right of access, the finding of a violation of Article 12.2 does not prejudice the rights of the defendant, since the latter was expressly invited to comment on the data subject's compliance with the procedures for exercising the right of access in its Decision on the merits 97/2026 — 22/24 in its entirety, and could reasonably expect to have to defend itself on this aspect, which constitutes a method of exercising this right. 67. The Litigation Chamber accompanies this reprimand with an order to comply, within one month of notification of this decision, with the exercise of the complainant's right of access and copy under Article 15.3 of the GDPR, based on Article 100, paragraph 6 of the LCA. When executing this order, the defendant may find it useful to take into account the foregrounded considerations concerning the scope and application of Article 15.4 of the GDPR (see paragraphs 60 to 63). 68. The defendant has one month from the date of notification of this decision to provide the complainant with a copy of all service records for the period from May 10, 2016 to May 10, 2021, in accordance with Article 12.3 of the GDPR. If the defendant intends to rely on the complexity of the request to benefit from the extended three-month period provided for by this same provision, it is incumbent upon it to provide proof thereof and to inform the Litigation Chamber, as well as the complainant, without delay, within the aforementioned one-month period. 69. In all cases, the defendant is required to provide the Litigation Chamber, within the allotted time, with proof of the effective transmission of the documents to the complainant, in order to allow the Chamber to verify the proper execution of this decision. 70. The Litigation Chamber considers that a reprimand, accompanied by an order to comply with the complainant's request for access and a copy, constitutes, in this case, a proportionate and sufficient measure. This assessment takes into account all the circumstances of the case, and in particular the defendant's internal organization and resources, as it itself described throughout the proceedings, arguing that fulfilling the access request would represent a considerable workload for it. While this circumstance, as mentioned above, does not affect the existence of the violations found, it remains relevant at this stage of the assessment of the corrective measure. Indeed, imposing an administrative fine in addition to the order to compliance, which will itself require internal resources for its execution, would appear disproportionate to the objective pursued, which is primarily to ensure the restoration of the complainant's rights and the defendant's future compliance with the requirements of the GDPR. Decision on the merits 97/2026 — 23/24 IV. Publication of the Decision 71. Given the importance of transparency regarding the decision-making process of the Litigation Chamber, this decision is published on the APD website. However, it is not necessary for this purpose for the parties' identifying data to be directly communicated. FOR THESE REASONS, the Litigation Chamber of the Data Protection Authority decides, after deliberation: - Pursuant to Article 58.2.c) of the GDPR and Article 100, § 1, 6° of the LCA, to order the defendant to comply, within one month of notification of this decision, with the complainant's right of access pursuant to Article 15.3 of the GDPR, in accordance with the procedures specified in paragraphs 67 to 69 and the considerations raised in paragraphs 60 to 63 of this decision. - Pursuant to Article 100, § 1, 5° of the LCA, to issue a reprimand to the defendant for violating Articles 12.2, 12.3, 12.4, 15.1 and 15.3 of the GDPR, Article 12.5 of the GDPR cannot, in this instance, justify the refusal of the complainant's request. In accordance with Article 108, § 1 of the LCA, an appeal against this decision may be lodged, within thirty days of its notification, with the Market Court (Brussels Court of Appeal), with the Data Protection Authority as the defendant. Such an appeal may be lodged by means of an interlocutory application, which must contain the information listed in Article 1034ter of the Judicial Code. The interlocutory application must be filed with the Registry of the Market Court in accordance with Article 1034quinquies of the Judicial Code. The application must, under penalty of nullity, contain: 1° the date of the day, month, and year; 2° the applicant's surname, first name, and address, as well as, where applicable, their capacity and national registration number or company number; 3° the surname, first name, address, and, where applicable, capacity of the person to be summoned; 4° the subject matter and a summary of the grounds for the application; 5° the name of the judge seized of the application; 6° the signature of the applicant or their lawyer. Decision on the merits 97/2026 — 24/24 32 judicial, or via the e-Deposit information system of the Federal Public Service Justice (Article 32ter of the Judicial Code). (Se). Hielke H IJMANS Director of the Litigation Chamber 32The application, together with its annex, is sent, in as many copies as there are parties involved, by registered letter to the clerk of the court or filed with the registry.

---
Generated by overview.legal · https://overview.legal/posts/144020 · 2026-07-21
