APD/GBA (Belgium) - 101/2026

From GDPRhub
APD/GBA - 101/2026
Authority: APD/GBA (Belgium)
Jurisdiction: Belgium
Relevant Law: Article 5(1)(a) GDPR
Article 5(1)(b) GDPR
Article 5(1)(c) GDPR
Article 5(1)(e) GDPR
Article 5(1)(f) GDPR
Article 5(2) GDPR
Article 6(1) GDPR
Article 6(1)(f) GDPR
Article 12 GDPR
Article 13 GDPR
Article 15 GDPR
Article 24 GDPR
Type: Complaint
Outcome: Upheld
Started:
Decided: 12.05.2026
Published:
Fine: 176,946.61 EUR
Parties: n/a
National Case Number/Name: 101/2026
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Dutch
Original Source: APD (in NL)
Initial Contributor: dalja10

The DPA fined a tech company a total of €176,946.61 for unlawfully keeping active the email account of a contractor after they left the company and for transparency obligation infringements. The DPA also ordered the company to comply with the contractor's access request, provide access logs, delete the personal data afterwards and take measures to ensure future compliance.

English Summary

Facts

An independent contractor (the data subject) used to be a part of the ‘extended workforce’ of a tech company (the controller) and had a professional email address on the controller’s domain.

The data subject ceased collaboration with the controller in May 2023 but, in the fall of the same year found out that their professional email address was still active.

The data subject contacted the controller in January 2024, informed them that the email address was still active and that the out-of-office message was misleading. Subsequently, they requested access to the emails received in the meantime. In addition, the data subject requested proof that no one accessed their mailbox after April 2023. In response, the controller offered access to the email account on its premises under supervision.

The data subject filed a complaint with the DPA.

Holding

The DPA acknowledged that the email account may contain both personal and business data and noted that there were three successive phases regarding the processing of personal data in the mailbox.

During the first phase (the collaboration), personal data were processed under Article 6(1)(b) GDPR within the framework of the agreement between the two parties.

In the second phase, the DPA found that, immediately after the end of the collaboration, the controller had a legitimate interest under Article 6(1)(f) GDPR for keeping the email account active for up to one month in order to inform the data subject’s contacts of the departure from the company and to provide a new contact point.

In addition, the DPA explained that the end of the collaboration meant, among other things, a change in the purpose and legal basis for the processing of personal data in the data subject’s mailbox, a change in the recipient of the emails and a loss of control for the data subject over the personal data in the mailbox. Since neither the data subject, not their contacts were informed about these changes, the DPA held that the controller breached Article 12 GDPR and Article 13 GDPR by failing to comply with its transparency obligations in relation to the data subject and their contacts after the data subject’s departure from the company.

In the third phase, after 1 June 2023, the DPA held that the controller breached Article 5(1)(a) GDPR in conjunction with Article 6(1) GDPR by continuing to process personal data without a legal basis since the controller no longer had a legitimate interest for keeping the mailbox active.

Furthermore, the DPA held that the controller also violated Article 5(1)(b) GDPR (‘purpose limitation), Article 5(1)(c) GDPR (‘data minimisation’) and Article 5(1)(e) GDPR (‘storage limitation’) by continuing to process personal data after 1 June 2023.

Moreover, the DPA found that the controller failed to take, or demonstrate that it had taken, sufficient technical and organizational measures to delete the data subject’s mailbox due to a lack of legal basis, thus violating Article 24 GDPR.

In addition, the DPA held that the controller failed to take appropriate measures to facilitate the data subject’s access right and limited their right without justification to emails without an out-of-office reply, thus violating Article 12 GDPR and Article 15 GDPR.

Specifically, the controller only allowed access to emails received from external (non-company) contacts starting from 1 May 2023 for the protection of trade secrets and because internal contacts received out-of-office messages in reply.

While the data subject did indeed only ask for access for the nine months after their departure, the DPA found that the limitation to external emails was unjustified since receiving an out-of-office message was not a criterion to restrict the right to access and because the controller could have filtered out sensitive business data prior to the data subject’s access. However, the DPA considered the exercise of the access right on the controller’s premises a proportionate measure due to the possible presence of trade secret in emails.

Finally, the DPA found violations of Article 5(1)(f) GDPR and Article 5(2) GDPR since the controller failed to demonstrate compliance with the principle of confidentiality and integrity. The DPA noted that the controller failed to prove that no one accessed the data subject’s mailbox after their departure from the company since the controller only presented log files for the period between 22 July 2024 and 20 August 2024.

Therefore, the DPA fined the controller €160,860.55 for the infringement of Article 5(1)(a) GDPR in conjunction with Article 6(1) GDPR and €16,086.06 for infringing of Article 12 GDPR and Article 13 GDPR.

The DPA also ordered the controller to bring its processing activities in compliance in relation to the mailboxes of employees and contractors when departing from the company in light of the violation of Article 24 GDPR.

Moreover, the DPA ordered the controller to comply with the data subject’s access request, delete their personal data afterwards and provide them with a record of access to their mailbox or demonstrate that the data is no longer available.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Dutch original. Please refer to the Dutch original for more details.

Decision on the merits 101/2026 — 2/60

I. Facts and procedure

1. The subject matter of the complaint concerns the closure of an employee's professional

mailbox in non-GDPR compliance following her departure from the defendant. As an independent consultant, the complainant falls under the category of employee or collaborator of the

defendant, more specifically within the category of the
2
defendant's ‘extended workforce’.

2. On 23 April 2024, the complainant lodged a complaint with the Data Protection Authority

against the defendant.

3. On 26 April 2024, the complaint was declared admissible by the Primary Care Service on the basis

of Articles 58 and 60 of the WOG and the complaint was transferred to the Disputes Chamber on the basis of Article 62, § 1 WOG.

4. On 21 May 2024, the Disputes Chamber decided pursuant to Article 95, § 1, 1° and Article 98

WOG that the file was ready for substantive consideration and the parties concerned were notified by registered mail of the provisions referred to in

Article 95, § 2, as well as those in Article 98 WOG. They were also notified pursuant to Article

99 WOG of the time limits for submitting their defenses.

The parties were requested to submit their defenses regarding the following

alleged violations:

• Violation of Article 5.1.a) read in conjunction with Article 6.1 of the GDPR due to the lack

of a legal basis to keep the complainant's mailbox active after 1 month following the

departure of the complainant;

• Violation of Article 5.1.b), Article 5.1.c) and Article 5.1.e) of the GDPR due to a

violation of the principle of purpose limitation in combination with data minimisation and

storage limitation of the personal data in the complainant's mailbox after 1 month
following the complainant's departure;

• Violation of Article 12 and Article 13 of the GDPR due to failure to provide

the necessary information regarding the processing of his personal data in the

complainant's mailbox after 1 month following the complainant's departure;

• Violation of Article 24 and Article 25 of the GDPR due to the lack of adequate

technical and/or organisational measures to properly manage and close the complainant's mailbox

during or after his departure;

2

Piece 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 135. Decision on the merits 101/2026 — 3/60

• Violation of Article 12 and Article 15 of the GDPR due to the failure to grant
access to the complainant's mailbox and due to the failure to provide a copy

of the complainant's mailbox;

• Violation of Article 5.1(f) read in conjunction with Article 5.2 of the GDPR due to the failure to sufficiently

demonstrate that the confidentiality of the personal data in the

complainant's mailbox was guaranteed after 1 month following the complainant's departure.

II. Reasoning

II.1. Description of the processing and the complaint

5. The complainant was employed by the respondent as an independent consultant. The defendant is

a high-profile Belgian tech company with a high turnover of employees, who

are either part of the company as internal employees or part of its

‘extended workforce’. In order to carry out her activities at the defendant,

the complainant, as a member of the ‘extended workforce’, had been assigned a unique identifiable professional e-

mail address on the defendant’s email domain. A few weeks

before her effective departure from the defendant, the complainant phased out her activities at the

defendant; She had set up two out-of-office messages for this purpose, in which she informed the defendant's internal employees that she was no longer reachable at this email address and redirected them to her personal email address, and in which she alerted the external contacts attempting to contact her that she would only check her email sporadically: “[…] I am currently offline with very limited internet access. Please accept some delay in my reply. […] .4

6. On May 1, 2023, the complainant permanently left the defendant. In the autumn of 2023, the complainant learned from various contacts that they had contacted her via her professional email address at the defendant, which appeared to still be functional.

7. On January 24, 2024, the complainant contacted the defendant to draw his attention to the fact that her professional email address was still active and to request access to the e-

mails that had arrived at this email address in the meantime. The defendant subsequently

placed an out-of-office message on the complainant's mailbox himself and offered

to grant access to the e-mails that arrived after her departure from the external

contacts in the premises and under the supervision of a neutral person, in order to be able to protect any

confidential or commercially sensitive information.

3 Document 18, the summary conclusion of [defendant] of 27 August 2024, paragraph 135.

4 Document 2, Complaint form of 19 April 2024, appendix p. 2. Decision on the merits 101/2026 — 4/60

8. Finally, the complainant also requested proof from the defendant that no one had consulted her mailbox

after she had left, as she suspected that certain e-

mails had not been logged and certain emails had been opened.

9. The complainant's counsel concluded the complaint with the following request to the GBA:

“I kindly request you to assess the current situation and to assist my client in

obtaining access to and a copy of the requested data, including the

correspondence she has received at her non-deactivated email address since
April 2023 and information about who has accessed her email account since April

2023. The email address was unlawfully kept active, and the available out-of-

office message was clearly misleading, suggesting that my client was still working at

[defendant]. She has the right to gain access to the said data

and to receive information regarding the use of her personal data and identity

by the company without her consent since the termination of her cooperation

with [defendant]. […] Therefore, my client’s suspicion that the email address was intentionally not deactivated is not unfounded. […]” .

II.2. Description of the processing of personal data in the complainant's mailbox

10. The Disputes Chamber establishes that the complainant was employed as an independent consultant at

the defendant until 1 May 2023 and, for her position, had access to an email address

of the type ‘firstname.lastname@defendant.be’. The mailbox linked to this email address

undeniably contains personal data of a uniquely
identifiable person within the meaning of Article 4.1 GDPR. The purpose of such a

type of mailbox is to allow the complainant to communicate within the framework of her cooperation

with the defendant.

11. Such a

type of mailbox is therefore inevitably a mix of

personal data of the unique user of the email address, of business-essential data, and of

personal data of correspondents of the unique user, such as:

• communication of personal data that falls within the

cooperation of the employee with the employer, such as, for example, leave requests to HR,

meeting requests with the confidential counsellor, evaluation reports, reports
of performance reviews, consultation with a colleague, team meetings,

hospitalisation insurance, etc.;

• communication that falls within the scope of the employee's function and business operations

such as contact with customers and suppliers, contributions to projects, quotations,

5
Document 2, Complaint form of April 23, 2024, p. 4. Decision on the merits 101/2026 — 5/60

contracts, etc. This communication may also contain commercially sensitive or

confidential data and possibly data protected by the intellectual property of the
company;

• communication that falls within the purely private life of the employee such as, for example,

arrangements with the employee's partner regarding the collection of the

children, any urgent appointment with the garage, etc. and

• personal data of third parties communicating with the unique user of the

mailbox, in this case the employee, such as, for example from a colleague (who is celebrating his/her birthday), the partner (because he/she has had car damage and will be home later), a specific correspondent of the person concerned (due to his/her dismissal), etc.

12. In such a type of mailbox, these personal data are sent to or from the employee's email address, after which they are received in the mailbox, stored there, organized, and can be filtered, sent, stored, printed, and deleted. These personal data are therefore inevitably processed within the meaning of Article 4.2 GDPR.

13. In the context of defining the scope of the complaint and to clarify this decision,

the Disputes Chamber establishes that there are 3 consecutive phases regarding the

processing of the personal data in the complainant's mailbox. These phases are

distinguished on the basis of the purpose and the legal basis of the processing.

II.2.1. Phase 1: during the cooperation

14. During the formal cooperation between the complainant and the defendant, the purpose of the

processing of the personal data in the mailbox is to communicate with internal and

external contacts within the framework of her agreement with the defendant, which immediately

also constitutes the legal basis for the processing in accordance with Article 6.1.b GDPR. 15. Regarding this communication, the Disputes Chamber refers to the Barbulescu case, in which the European Court of Human Rights (hereinafter ‘ECtHR’) ruled that “The

instructions of an employer may not reduce private life in the workplace to zero.

Respect for private life and for the confidentiality of the

correspondence remains” 6 (free translation by the Disputes Chamber) and thus “the

communication in the applicant’s workplace fell under the concepts of “private life” and

“correspondence” (free translation by the Disputes Chamber). The employee also has on

6
ECtHR, Case of Barbulescu v. Romania, 61496/08 of 5 September 2017, paragraph 80: “an employer’s instructions cannot
reduce private social life in the workplace to zero. Respect for private life and for the privacy of correspondence continues to
exist […]”.
7Ibid, paragraph 81: “the applicant’s communications in the workplace were covered by the concepts of “private life” and

“correspondence”. Decision on the merits 101/2026 — 6/60

the workplace the right to lead a private life and to enter into social contacts that

fall within the private sphere. This judgment confirms that the defendant cannot avoid that

personal correspondence also takes place via this e-mail address and this mailbox.

16. In her complaint and her conclusions, however, the complainant also mentions certain

sensitive communications regarding her expertise as a public figure, which go beyond

her assignment with the defendant. Given that this communication did not strictly fit

within the framework of the cooperation between the complainant and the defendant, given that this communication

also does not fall under the private social life of the complainant and given the sensitivity of

this correspondence, which apparently also had to be shielded from the defendant

(“She did her utmost to guarantee their confidentiality, despite the high
10
pressure from the media and the Defendant”), the Dispute Chamber rules that this specific

communication did not belong in the complainant's mailbox on the domain of the

defendant and the Dispute Chamber considers this specific, sensitive communication

no different from the other personal data processed in the complainant's mailbox.

II.2.2. Phase 2: immediately after the termination of the cooperation between the complainant and the

defendant

17. The complaint concerns the continued processing of personal data in the mailbox after the

cooperation, and thus the contract, between the complainant and the defendant was terminated. 11
Here too, the Disputes Chamber has already ruled in previous decisions that

such further processing can be lawfully based on the legitimate

interest of the employer, in this case the defendant, in accordance with Article 6.1.f GDPR.

18. As clarified in these previous decisions of the Disputes Chamber, this

legitimate interest is a priori limited to a duration of 1 month. A possible

extension of this duration by two months could be accepted, provided that a

clear balancing of interests substantiates this extension. In this balancing of interests,

it must be taken into account that the complainant has already left some time ago and no longer has any control

over her, sometimes sensitive, personal data in the mailbox in question.

8Piece 2, Complaint form of 23 April 2024, p. 3: “Since the email was not deactivated, very sensitive data was sent to this account, and it is of great importance to my client that this information be removed from [defendant]’s servers.”

9 Appendix Complete_with_Docusign_20240730_[complainant] to document 16, Conclusions and documents, paragraph 48: “Since Concluante is XXX, individuals and organizations entrust sensitive and confidential information to her. […] For example,
at the time of her departure, Concluante was involved in a very sensitive case relating to YYY. […] She did her utmost to guarantee their confidentiality, despite the high pressure from the media and the Defendant. Obtaining proof that her account has not been accessed and being able to remove all personal data and sensitive data of others from that account is essential for her as an individual and as an ethical and trustworthy professional.” 10Piece 16, Conclusions + Complainant's documents of 2 August 2024, paragraph 48.
11
Said inter alia decision 64/2020 of 29 September 2020, decision 133/2021 of 2 December 2021, decision 138/2024 of 19
November 2024, decision 134/2025 of 21 August 2025, decision 01/2026 of 6 January 2026. Decision on the merits 101/2026 — 7/60

19. Given the inevitable mix of personal data and business data in the mailbox,

it is prohibited for the defendant to gain further access to this mailbox

to consult business-necessary data, since he would then inevitably also

gain access to the personal data and private communications of the complainant (and

her contacts). In this context, the Disputes Chamber points out:

• Article 124 WEC: “Unless permission has been obtained from all

other persons directly or indirectly involved, no one may:

1° intentionally become aware of the existence of information of any kind that has been

sent electronically and that is not intended personally for him;

[…]

4° modify, delete, disclose, store or make any use of the information, identification or data that were

obtained intentionally or unintentionally.”

• Article 314bis of the Penal Code: “§ 1 He who:

1° [either, intentionally, by means of any device, intercepts or causes to be intercepted communication in which he does not participate,

takes notice of or causes to be taken, records or causes to be recorded, without the

consent of all participants in that communication;]

[…]

§ 2 He who knowingly keeps in his possession, reveals or disseminates to another

person, or knowingly makes any use of the content of communication not accessible to the public

or data from an information system that has been unlawfully intercepted or recorded
or of which knowledge has been unlawfully obtained, shall be punished

with [imprisonment of six months to three years] and with a fine of

five hundred euros to twenty thousand euros or with one of those penalties information obtained in this way


[...]”

20. Only on the basis of a sound data protection policy by design of

professional mailboxes, in which an effective distinction is made between

personal data/private communication on the one hand and business data/
business communication on the other hand, which can be technically

distinguished and filtered upon the departure of an employee, can the necessary business data

still be retrieved from these professional mailboxes in phase 2 without affecting the Substantive Decision 101/2026 — 8/60

personal data of the ex-employee. The only other option to recover the

business data in this phase consists of obtaining permission

from the ex-employee to consult the mailbox and to be able to extract the business data

from it. It is for this reason that Recommendation CM/Rec(2015)5 of the

Committee of Ministers of the Member States of the Council of Europe clearly states upon the departure of an

employee: “If employers need to recover the contents of an

employee's account for the efficient management of the organization, they should

12
do this before his or her departure and, where possible, in his or her presence. “

(free translation by the Dispute Chamber).

II.2.3. Phase 3: one month after the termination of the cooperation between the complainant and the

defendant

21. One month (or, subject to a clearly substantiated extension, up to a maximum of 3 months) after

the effective end of the cooperation, the personal data in the

complainant's mailbox, including the

email address itself, are no longer necessary and must be permanently deleted in accordance with the

principle of purpose limitation of Article 5.1.b GDPR and the

minimum data processing of

Article 5.1.c GDPR. Given the inevitable mix of

personal and business data in the mailbox, in practice this usually means

the permanent deletion of the entire mailbox.

II.3. Violation of Article 5.1(a) read in conjunction with Article 6.1 of the GDPR due to the lack of
a legal basis to keep the complainant's mailbox active after 1 month following the
departure of the complainant

22. Article 6 of the GDPR prescribes that all processing operations must be based on a

legal basis. This means that the controller may not start

or, as in this case, continue data processing without relying on one

of the criteria for lawfulness listed in Article 6.1 GDPR, which is the concretization of

the principle of lawfulness as referred to in Article 5.1(a) GDPR.

23. The complainant states in her complaint that her cooperation with the defendant had ended in

April 2023. After she had established that the mailbox was still active, she contacted the defendant

about this on 24 January 2024. On that same day, the defendant's Data Protection Officer (hereinafter ‘DPO’) confirmed that the email address had not yet been deactivated. As an explanation for this continued retention of the personal data in the complainant's mailbox, the DPO stated on 20 February 2024: “Given your position

within [the defendant], we felt that it seemed more opportune to have your out-of-office

12 Committee of Ministers, Recommendation CM/Rec(2015)5 of the Committee of Ministers to member States on the
processing of personal data in the context of employment of 1 April 2015, paragraph 14.5: “If employers need to recover
the contents of an employee’s account for the running of the organisation, they should do so before his or her departure
and, when feasible, in his or her presence.” Decision on the merits 101/2026 — 9/60

13
to retain notifications longer, rather than closing your mailbox after 1 month.” On the

day of the complaint on April 23, 2024, being 1 year after the end of the collaboration between

the complainant and the defendant, the mailbox was, according to her, still active.

24. The defendant confirms that the complainant was active with him as an independent consultant and, in

that context, possessed a personal email address on the defendant's domain.

The defendant also acknowledges that “the complainant's mailbox was indeed not (timely)

deleted after deactivation, and inadvertently remained in ‘backup’ mode”. The

process for closing and deleting mailboxes of departed employees was

at the time of the complainant's departure, limited to a monthly list of

departed employees, after which, on the day of departure, the IT department blocked all access

and manually deleted the mailboxes one month after the departure. The

defendant emphasizes that maintaining the complainant's mailbox was a one-time,

human error.

25. The defendant regards the deactivation of the mailbox as a kind of backup mode

and states “that the personal data contained in the complainant's mailbox have de facto already

‘deleted’ since they are no longer actively processed.” In this backup mode,

no one has access to the mailbox anymore, unless a specific procedure is followed

in which access is explicitly requested and must be authorized before

access is granted. This access procedure was not initiated on the

complainant's mailbox after it had been deactivated. 26. Finally, the defendant argues that the complainant also bears part of the responsibility, since she allegedly knew as early as September 2023 that her mailbox was still active and only reported this to the defendant in January 2024.

II.3.1. Assessment of the legal basis in phase 2

27. The Disputes Chamber rules that further processing in phase 2 can be based on the defendant's legitimate interest pursuant to Article 6.1.f GDPR. However, this legitimate interest is limited:

• in duration: specifically to a duration of 1 month. The Disputes Chamber may accept a possible extension of this duration by 2 months, provided that a clear, new balancing of interests substantiates this extension, taking into account the fact that the complainant has already left for more than a month and has not been able to exercise any control over her mailbox or account since then. 13 Appendix to document 2, Complaint form of April 23, 2024, email of February 20, 2024 at 14:48.

14
Document 18, the summary conclusion of [respondent] of August 27, 2024, paragraph 10.
15 Document 18, the summary conclusion of [respondent] of August 27, 2024, paragraph 35. Decision on the merits 101/2026 — 10/60

• in objective: specifically to inform the complainant's contact persons,

on the one hand to guarantee the continuity of business operations by designating another

contact person who has taken over the complainant's duties and

on the other hand to point out to all contact persons that they can no longer communicate with the complainant via the still existing e-mail address. This second objective is

important to be transparent to all of the complainant's contacts so that they know

that the emails (and the personal data contained therein) they send no longer

reach the intended correspondent.

28. Regarding the duration of this processing based on legitimate interest,

the Disputes Chamber establishes that the DPO indicated in his communication with the complainant that the

duration of one month would be extended: “It is true that your mailbox remained ‘active’

longer than is normally provided for in [the defendant]’s standard policy

in this regard. However, given your position within [the defendant], we believed that it seemed more

opportune to retain your out-of-office messages longer, rather than closing your mailbox after 1

month.” 16 In the conclusions, however, the defendant argues that an extension was not applicable: “In the case of the Complainant, the judge found no question
17
of a deliberate deviation from the standard term of one month.” Since no

any balancing of interests for a possible extension has been demonstrated, the

Dispute Resolution Chamber rules that the duration of one month was applicable and that the processing

of the complainant's personal data on 1 June 2023 could no longer be based on

the legitimate interest of the defendant.

29. Regarding the purpose of the processing under the legitimate interest, in particular the

informing of the complainant's contacts, the Dispute Resolution Chamber establishes that the

defendant, as the controller, had delegated the means to achieve this purpose, in this case

the out-of-office message, to the complainant. The defendant states: “It is, after all, not possible for

a company such as that of the Defendant to set up an out-of-office message for every departing

employee [sic]. […] Since this message can vary so much within

the Defendant and also to promote accuracy,

the drafting of the out-of-office message is delegated to the departing employee themselves.” 18

30. In addition to delegating this crucial responsibility in the context of the further

processing of the personal data based on legitimate interest, it appears from

the file itself that it was also not checked whether the out-of-office message was

(correctly) set up at the moment the complainant had left. It appears from the documents

after all, that no proper out-of-office message was sent after the departure of the

16Appendix 5, Email from Respondent of 20 February 2024 (4:11 PM) regarding document 18, the summary conclusion of [respondent] of 27 August 2024.

17
Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 11.

18Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 59. Decision on the merits 101/2026 — 11/60

complainant. The out-of-office message that was sent was set by the complainant herself,

according to her own statement, some time before her effective departure and consequently without the
information that should serve the legitimate interest. The deficiency was only

established by the DPO after the complainant had contacted the defendant in January

2024. Only on 6 April 2024 did the DPO propose to set the out-of-office correctly. 19

Despite this delegation and this lack of control, the Dispute Chamber rules that the

defendant did indeed have a legitimate interest to continue processing the personal data of

the complainant in her mailbox until one month after the complainant's departure.

31. Based on the documents added by the defendant to his submissions, the

Dispute Chamber establishes that the purpose for the continued processing was extended to

recovering information from the complainant's mailbox after her departure. After all, the 2016 management processes mention an

automatic email to the managers containing all the deactivated accounts of

that month:

• “[…]

• this list of deactivated accounts is automatically sent to a

defendant's recipient list to notify the managers that the accounts

will be deleted at the end of the month, unless an exception is

requested

• based on an ICT ticket, this exception can be requested, whereby the

account is set to ‘do not delete’

• […]”20

In this monthly internal email regarding the deletion of the mailboxes of the departed

employees, this exception is clarified, specifically regarding retrieving information from the

mailbox of the deactivated account before it is permanently

deleted. The message reads as follows:

“Below you will find a list of all paid colleagues and extended

employees who have left [the defendant] in the last month(s). Their

access to the systems of the [defendant] has already been blocked.

19
Appendix 12, Email correspondence between Complainant and Respondent of 6 April 2024 regarding document 18, the summary conclusion of [respondent] of 27 August 2024.

20 Appendix 22, Internal Personal Account Management Processes regarding document 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 12/60

Please be aware that the accounts and all personal data (file server

Windows and Unix, mailbox, OneDrive) will be effectively deleted on the

first working day after the 21st of this month.

Do you need more time to extract business-critical information from this or

transfer [respondent]-related information to a cloud environment?

"Then create an ICT ticket to postpone this data deletion (for a maximum of 3 months)." (emphasis in original) (free translation by the Disputes Chamber).

The Disputes Chamber rules that this objective (retrieving information from the mailbox of a deactivated account) does not fall under the legitimate interest of the defendant to further process a mailbox after the complainant's departure and would possibly be in violation of the Electronic Communications Act and the Criminal Code. However, there is no evidence that there was effective access to the complainant's mailbox, as a result of which the Disputes Chamber rules that any processing based on this second objective has not been demonstrated.

32. Based on the defendant's summary conclusion, the Disputes Chamber establishes that a third objective would exist to further process the personal data under the legitimate interest, specifically to provide access to the mailbox to the complainant after his departure: “Finally, the former employees' mailbox is placed in this backup mode precisely in order to comply, in addition to displaying an ‘out of office’ message after their departure, via a standardized procedure, with any requests from former employees

for which the Defendant would still require access to the relevant mailbox.” 23 The defendant's

policy regarding emails, which was drawn up after the complainant had filed a complaint

24
, states this as follows: “The mailbox is set up to a shared

25
mailbox so that if absolutely necessary, access to the mailbox can be granted.”

To illustrate this policy, the defendant provides two examples: “[…] Student has

left [defendant] and still needs documents from his mailbox for his PhD. […]

Employee has left [defendant] and still has an important email in his mailbox

regarding a specific contract, […]. 26 However, this third objective is already contained in

21Piece 18, the summary conclusion of [defendant] of 27 August 2024, paragraph 34; “Below, you find a list of all payroll colleagues and extended workers who have left [defendant] in the past month(s). Their access to the [defendant] systems has been disabled already. Be aware that the accounts and all personal data (fileserver Windows and Unix, mailbox, OneDrive) will be effectively removed on the first working day after the end of this month. Do you need more time to retrieve business-critical information or to transfer [defendant] related content to a cloud environment? Create an ICT ticket to postpone this removal (for a maximum of 3 months).”

22See paragraph 19 of this decision for this. 23 Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 39.
24 See paragraph 75 of this decision for this.

25 Annex 3, [respondent] policy regarding emails in connection with Document 18, the summary conclusion of [respondent] of 27 August 2024.
26
Annex 3, [respondent] policy regarding emails in connection with Document 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 13/60

the right of access under Article 15 GDPR, which can be exercised for as long as the

data are being processed, and therefore cannot be invoked as a separate

objective by the respondent to base a legal ground for processing on. 33. The Disputes Chamber rules that the defendant had a legitimate interest in

continuing to process the personal data in the complainant's mailbox for a period of 1 month

in order to inform the complainant's contacts that she was no longer

employed by the defendant and in order to be able to provide the

defendant with a new contact person to the complainant's professional contacts.

II.3.2. Assessment of the legal basis in phase 3

34. The Disputes Chamber establishes that the deletion of the (personal data in the)

mailbox did not take place 1 month after the end of the collaboration between the complainant and the

defendant, in this case on June 1, 2023. In the conclusions, the

27
defendant acknowledges that the mailbox had not been deleted.

35. The defendant argues that the mailbox had indeed been deactivated, as a result of which there was no

access to the data in the mailbox. The defendant considers the

personal data in the deactivated mailbox as “de facto already ‘deleted’ […] since

they are no longer actively processed”.8

36. However, the Dispute Chamber establishes that the personal data have not ‘de facto already been

deleted’:

• First, on 24 January 2024, the DPO confirmed to the complainant that the mailbox was still

active: “I indeed also saw that your mailbox is still active because I was able to send an email.[…]The fact remains, however, that the mailbox should have already been deleted[…]”. 29

On April 6, 2024, the DPO proposes to the complainant to take the mailbox offline, so that

no more emails could be received on it: “Your account is

disabled, in other words, no one can access it and it cannot be used, but

the mailbox is still open to receive emails. […] There are a few options

[…] – We can take the mailbox offline and store it in a PST at a secure location

so that no one can access it and no emails arrive on it either”. 30

27 Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 32.

28
Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 35.

29 Appendix 2, Email correspondence between Complainant and Respondent of 24 January 2024 regarding document 18, the summary conclusion of [respondent] of
27 August 2024.

30
Appendix 12, Email correspondence between Complainant and Respondent of 6 April 2024 regarding document 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 14/60

31
• Secondly, the DPO states in his letter to the GBA of 2 May 2024 that the mailbox

would have been deactivated since mid-February 2024, meaning no one would have access

but that the mailbox would still be able to receive emails.

• Thirdly, in response to the request for inspection by the
complainant, the defendant took out a new license on the mailbox, so that it would not be deleted

by the new system that had been introduced. In the summary conclusion of the

defendant dated 27 August 2024, it is stated that this license was ‘recently’ linked

to the complainant's mailbox. 32

• Fourthly, the documents state in the 2016 management processes that

a former employee no longer has any access to the account, but that the

mailbox is still visible in the defendant’s ‘Active Directory’:

“Deactivation of the account

Deactivation of an account will have the following consequences:


• The (former) employee cannot log in with this account

• All Office 365 licenses have been revoked

• The (former) employee no longer has access to the mailbox of this

account

• The (former) employee no longer has access to data of this

account

• The (former) employee cannot use applications located on the defendant’s

Active Directory/OpenLDAP

• The (former) employee is no longer a member of

security groups/distribution lists. Also for those using

the account based on name.

The account of the (former) employee is deactivated, but will be visible

in the Active Directory until the account is deleted.” 33 (emphasis and free

translation by the Disputes Chamber).

31 Appendix 1B, appendix to e-mail of 2 May 2024 addressed to the Data Protection Authority appendix 18, the summary conclusion
of [defendant] of 27 August 2024, p. 1 under factual account.

32
Document 18, the summary conclusion of [defendant] of 27 August 2024, paragraph 50.33Appendix 22, Internal Personal Account Management Processes in document 18, the summary conclusion of [respondent] of 27 August 2024, p. 6: Account inactivation

Inactivation of an account will have the following consequences:

• The (former) employee cannot log in with this account.

• All Office 365 licenses are revoked.

• The (former) employee cannot access the mailbox of this account. Decision on the merits 101/2026 — 15/60

37. The Disputes Chamber rules that restricting access to personal data

cannot be equated with the deletion of personal data. As long as the

data are still stored and remain accessible, even if access is very limited,

they are still being processed, risks consequently continue to exist and the

controller must be able to demonstrate that all principles of

data protection have been respected, including having and being able to demonstrate

a legal basis.

38. The Disputes Chamber notes that the ENISA publication of
18 October 2011 concerning ‘the right to be forgotten’, mentioned by the defendant, concerns rather a problem statement regarding

the right to erasure of data, where the focus lies on personal data in an open

system, such as the internet. This publication also speaks of closed systems, but

in the sense that it is easier to erase data with certainty in such

systems since more control is possible. The defendant's system can

be considered such a closed system. Restricting access to

personal data is not equated in this publication with the deletion of

data, which the defendant should have done. Also, the
35
recommendation of the Committee of Ministers of the Council of Europe mentioned by the defendant concerns

measures that must be taken at the moment of the employee's departure

and is not applicable in this case. This recommendation says nothing about the eventual

deletion of the mailbox, nor about any potential legal basis for processing after the

departure of the employee. On the other hand, this recommendation does state that the defendant

must take sufficient measures to

delete the business-necessary information from the mailbox before the complainant's departure.

39. Although the defendant does not submit any assessment regarding a legitimate

interest and states that the further processing was a human error and was not

intended, the Dispute Chamber will nevertheless make this assessment to determine whether

there might possibly be a legitimate interest. 40. In accordance with the case law of the Court of Justice, 36 the defendant must

         show that:




• The (former) employee cannot access data […] of this account

• The (former) employee cannot use applications which authenticate to [defendant]'s ActiveDirectory/OpenLDAP
• The (former) employee is no longer a member of Security groups/Distribution lists. Also, for which 'account name
based' membership is used.

The account of the (former) employee is inactivated, but will be visible in ActiveDirectory until Account removal.”
34 ENISA, The right to be forgotten – between expectations and practice of 18 October 2011.

35 Committee of Ministers, Recommendation CM/Rec(2015)5 of the Committee of Ministers to member States on the
processing of personal data in the context of employment of 1 April 2015.
36 CJEU Judgment of 4 May 2017, RīgasSatiksme, C-13/16 ECLI:EU:C:2017:336, para. 28, and CJEU Judgment of 7 December 2023,

Joined cases C-26/22 and C-64/22, Schufa, ECLI:EU:C:2023:958, para. 74. Decision on the merits 101/2026 — 16/60

a. The interests it pursues by the processing, as justified can
be recognized (the “purpose test”);

b. The intended processing is necessary for the realization of those interests

(the “necessity test”);

c. The balancing of those interests against the interests, fundamental

freedoms and basic rights of the complainant outweighs in favour of the

defendant or of a third party (the “balancing test”).

41. With regard to the purpose test, the only purpose for which the complainant's mailbox could be processed for longer than

one month appears to lie in informing the contacts of

the complainant that she is no longer employed by the defendant.

The Disputes Chamber has already ruled above that this processing could not lawfully rely on

a legitimate interest, being the granting of access to the mailbox to third parties in the context of recovering commercially sensitive information or to the complainant herself.

42. With regard to the necessity test, the Disputes Chamber establishes that the out of office

messages that served to inform these contacts were not sufficient

for the complainant's external contacts, as this message merely assumed that the

complainant would only be able to respond to emails sporadically, without it being made clear

that the complainant no longer worked for the defendant. In neither of the two

out-of-office messages was mention made of another employee at the defendant who

had taken over or was following up on the complainant's files. Since the processing was not
sufficient for the intended purpose, the processing could not have been necessary

for this purpose either. The lack of necessity in itself is sufficient to judge

that this processing cannot be based on the legitimate interest of the

defendant.

43. For the sake of completeness, the Disputes Chamber establishes regarding the balancing test that the

complainant was not aware of this continued processing under a new

legal basis with a different purpose. It also appeared from the documents that the complainant had already been employed for some time in
38
a limited regime at the defendant, as a result of which the further processing

of her personal data in her mailbox after she had eventually left fell outside

the reasonable expectations of the complainant, certainly if this processing

continued over time: “Concluante assumed that her account would be deleted immediately after her departure

and that the sender would receive a standard non-Delivery

Report or a bounce-back message clearly stating that the

37See paragraphs 31 and 32 of this decision for this.
38Piece 16, Conclusions + Complainant's Documents of 2 August 2024, paragraph 1. Decision on the merits 101/2026 — 17/60

39
account had been deleted.” Since the complainant was unaware of this ongoing

processing, did not expect this ongoing processing, and was not informed

of this ongoing processing, the complainant no longer had any control over

her personal data. The Disputes Chamber rules that the ongoing further

processing of these personal data for reasons of business continuity

is disproportionate to the total lack of any control over this further processing.

44. Based on what is stated in paragraphs 41-43, the Disputes Chamber rules that the

defendant could not base the ongoing processing of personal data in the

complainant's mailbox on his legitimate interest.

45. The Disputes Chamber rules that the defendant unlawfully processed the personal data of the complainant

and her contacts in her professional mailbox after

a legitimate interest no longer existed to

further process these personal data, in this case after June 1, 2023, and has therefore committed an infringement of Article 5.1.a

GDPR read in conjunction with Article 6.1 GDPR.

46. The defendant argues that following the complainant's request for access, the defendant

again had a legitimate interest in retaining the mailbox without deleting it.

The Disputes Chamber emphasizes that such an argument cannot possibly justify the earlier

lack of a legal basis, given that the complaint and the

request for access arose precisely because the mailbox had not been deleted in a timely manner.

For the sake of completeness, the Disputes Chamber emphasizes that the mailbox was kept intact,

while other technical possibilities exist to safely

preserve the contents of the mailbox, without it having to remain active.

The defendant himself made a proposal for this in his email of April 6, 2024: “[…] but the mailbox is still

open to receive mail. This is certainly not ideal and we would like to see it differently but

not without your (sic) input. There are a few options we can pursue to somewhat improve this skewed

situation: […] We can take the mailbox offline and store it in a

PST in a secure location so that no one can access it and no emails arrive there
40
[…]”. The Disputes Chamber notes that the defendant does not choose to use this most

safe option immediately when he determines that something has gone wrong. With

this technical measure, he could have

limited the processing of the personal data within the framework of the new purpose (granting access to the complainant) and the new

legal basis (legitimate interest of the defendant given this ongoing procedure).It is not the responsibility of the former employee, in this case the complainant, to decide on this matter; this decision rests with the controller.

39
Ibid.

40 Appendix 12, Email correspondence Complainant and Respondent of 6 April 2024 regarding document 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 18/60

II.4. Violation of Article 5.1.b), Article 5.1.c) and Article 5.1.e) of the GDPR due to a
violation of the principle of purpose limitation in combination with data minimisation and

storage limitation of the personal data in the complainant's mailbox after 1 month following
the complainant's departure

47. Given that these principles were assessed in conjunction with the assessment of the
other alleged infringements, the Dispute Resolution Chamber will not explicitly address this

alleged violation. The parties' arguments regarding this alleged

violation will be included in the assessment of the other alleged

violations.

II.5. Violation of Articles 12 and 13 of the GDPR due to failure to provide the necessary
information regarding the processing of personal data in the
complainant's mailbox after 1 month following the complainant's departure

48. The departure of an employee from an organisation constitutes a significant change in the

processing of the personal data of this employee and of his contacts. Ten

first, the purpose and legal basis of processing change; second, the e-

mails no longer reach the recipient of the e-mail, being the ex-employee; and

third, the data subject loses all control over his personal data stored in the mailbox on the employer's domain. In accordance with Articles 12 and 13

GDPR, the ex-employee and his contacts must be informed of these changed processing operations.

49. Upon her departure, the complainant therefore had to be informed that her

personal data in her mailbox are being (further) processed for a different purpose, on the basis of a different legal ground and with a limited retention period. This transparency

must enable her to take any measures to control these

data and processing, even though she loses all direct control over these

personal data. 50. The complainant's contacts, who believe they are sharing their own personal data with the complainant, must also be informed that the complainant no longer has access to her mailbox and that their personal data will therefore no longer reach the complainant, so that these contacts can stop sharing their personal data via this channel and exercise any rights regarding this personal data.

51. The complainant states that she did not have sufficient information regarding the processing of her personal data in the mailbox after her departure, and that there was likewise no procedure to gain access to her mailbox after her departure. The complainant also states that she never received the standard policy regarding the defendant's termination of employment, nor was she assisted in her departure from the defendant. The complainant [Decision on the merits 101/2026 — 19/60]

considers that the defendant approached its privacy policy merely theoretically,

but did not apply it in practice.

52. The defendant refers to its privacy policy, of which the privacy statement and various

transparency documents form part. One of these transparency documents

concerns the standard policy regarding termination of employment with an attached checklist.

This checklist states that the complainant himself should have set up an out-of-office message

since this responsibility was

delegated to the departing employee for reasons of scale and accuracy.

Moreover, the

41
defendant considers deactivating the mailbox after the complainant's departure as

equivalent to deleting the personal data, as a result of which no further

notifications had to be sent to the complainant. 53. Finally, the DPO responded to the complainant's questions and concerns and encouraged the complainant to contact him if there were any further questions or problems, which the complainant did not address.

54. The defendant is therefore of the opinion that a one-off human error, as a result of which the mailbox was not deleted in a timely manner, does not detract from his general GDPR-compliant policy, including the transparency of the processing.

II.5.1. Assessment of the transparency obligation in phase 2

55. The Dispute Resolution Chamber has already ruled that deactivating the complainant's mailbox does not constitute a de facto deletion of the complainant's personal data. Therefore, there was indeed a transparency obligation regarding the processing of the personal data that were present and were still arriving in the complainant's mailbox. 56. Despite the various documents added to the file by the defendant,

the Disputes Chamber notes that there is no evidence to be found anywhere that the closing of the

mailbox, the changed legal basis and the changed purpose of the processing, and the

retention period of the personal data were communicated to the complainant.

Nor does the defendant demonstrate that this information was available on his website, on

his intranet, or in his privacy statement. The only two documents that approximate such a

communication are document 17 (offboarding checklist) and document 26 (Knowledge article via

[defendant] Employee Center). Both documents instruct the complainant to report to ICT
that she would leave the defendant and set up an out-of-office message herself,

41
Throughout his conclusions, the defendant speaks of deactivating and placing in backup mode, but states himself that both
mean essentially the same thing: “The complainant's mailbox was therefore in a sort of ‘backup mode’ after the deactivation.” in Document
18, the summary conclusion of [defendant] of 27 August 2024, paragraph 35.

42 See paragraphs 36-37 of this decision for this. Decision on the merits 101/2026 — 20/60

but was otherwise not transparent about how her personal data in the mailbox would be further
processed or deleted.

57. With regard to transparency towards third parties, the Disputes Chamber establishes that the

following out-of-office messages were set:

• To internal correspondents: “This email address is no longer in use. You can contact [complainant] at [XXX].” (free translation Disputes Chamber).

• To external correspondents: “Dear, thank you for your message. I am currently offline with very limited internet access. Please take into account

some delay in my replies. Kind regards, [complainant].” (free translation

43 Disputes Chamber).

58. The message to the internal colleagues sufficiently informed that the complainant was no longer part of the defendant, so that the correspondents were aware that their

personal data was no longer being received by the complainant. Given that it concerned internal colleagues of

the same organization, one could assume that they had access to

sufficient information to be able to

contact another correspondent at the defendant regarding their communication.

59. However, the message to the external colleagues suggests that the complainant was only temporarily

absent or difficult to reach and therefore does not make clear to third parties that their

correspondence and their personal data would no longer be

processed by the complainant. The complainant also demonstrates this in the complaint with several examples of

communication in which her correspondent remained unaware whether the communication had

reached the complainant or not.44

60. Although the defendant delegates the responsibility for

proper communication in the form of an out-of-office message to the complainant in its policy and in its conclusions,

the defendant is the data controller and is therefore also

responsible for this transparency. Even though the defendant requests in its policy

the complainant to set up a compliant out-of-office message, this does not relieve the defendant

of its responsibility to be sufficiently transparent to third parties

regarding the processing of their personal data that end up in the

complainant's mailbox via e-mail after the latter's departure, not least because the complainant no longer has any

control over these personal data located on the servers under the control of

the defendant. The Disputes Chamber establishes that the defendant did not

43Document 18, the summary conclusion of [defendant] of August 27, 2024, paragraph 8: •

To internal correspondents: “This email address is no longer in use. You can contact [Complainant] on [XXX]”

To external correspondents: “Dear, thanks for your email. I am currently offline with very limited access to the internet. Please
accept some delay in my reply. Regards, [complainant]”

44Appendices 3 and 4 to document 2, Complaint form of April 23, 2024. Decision on the merits 101/2026 — 21/60

conducted a check on both out-of-office messages from the complainant and only after

the email from the complainant of January 24, 2024, being 7 months after the departure of the

complainant, determined that this transparency obligation to third parties, external to the

organization, had not complied.

61. The Disputes Chamber rules that the defendant has failed to comply with its

duty of transparency regarding the continued processing of the personal data

of the complainant and of her contacts external to the organization following the departure

of the complainant from the defendant and has thereby committed a breach of Articles 12

and 13 of the GDPR.

62. The Disputes Chamber establishes that the measures regarding transparency towards the contacts

of the complainant, in particular the setting of an out-of-office message on the deactivated

mailbox of the complainant, have not been included in the management processes, even though they are

substantially part of them. Moreover, the state of the art allows this

measure to be automated to prevent human errors and/or a technical

control on this measure to identify

and correct any human errors. In that regard, the Disputes Chamber notes that an automatic

email is sent to the defendant's managers to report that accounts will be

deleted so that they can request an exception to this deletion.45

63. With similar technical measures, the defendant could also have automatically sent the knowledge document and the

checklist with the appropriate technical measures to the complainant

before her departure.

II.5.2. Assessment of the transparency obligation in phase 3

64. The Disputes Chamber notes that the processing of the complainant's personal data

after the period of 1 month following her departure did not fit within the policy regarding the

processing of personal data in the complainant's mailbox. The defendant refers

repeatedly to a one-off human error in this regard, as a result of which phase 2 was extended,

without ever deleting the personal data. The issue of transparency is therefore located

in this case in phase 2, as a result of which the Dispute Chamber will not address the

transparency regarding phase 3.

II.6. Assessment of the violation of Article 24 GDPR

65. Article 24 GDPR considers it the responsibility of the controller

to take sufficient technical and organisational measures in order to ensure and demonstrate compliance between the processing of personal data and the principles of the

45See bullet number 6 of paragraph 70 of this decision. Decision on the merits 101/2026 — 22/60

GDPR. Recital 39 of the GDPR clarifies: ‘In order to ensure that personal data are not retained for longer than necessary, the controller shall establish periods for the erasure of data or for periodic review thereof’.

66. The complainant argues that the defendant did not take sufficient technical and organizational measures to properly manage and close her mailbox after her departure, certainly in light of the current state of technology. The complainant points out in particular that this management still had to be done manually, creating an unnecessary risk of human error. The complainant is therefore of the opinion that a review of this practice should have been undertaken much earlier.

67. The defendant refers to its standard policy and states that sufficient technical and organizational measures exist regarding the handling of the mailboxes of its employees. The problems concerning the complainant's mailbox referred to in her complaint concern a one-off human error. The defendant states that a change process had already been initiated prior to the complaint. This change process was intended to automate the deletion of deactivated accounts, so that this error could no longer occur. However, such a change process is complex and expensive, according to the defendant, which means it takes time to realize. Furthermore, the defendant points out the deactivation of the mailboxes and the removal of the associated license, as a result of which no one had access to this mailbox anymore.

68. The Disputes Chamber establishes that there were 65 persons on the list of departed employees as of June 1, 2023, who had left the organization in May 2023. 46 The defendant himself states that he is a large organization where approximately one thousand persons arrive and leave per year. Regarding this turnover of personnel, the defendant himself states

in his conclusion that:

• on the one hand it is “after all not possible for a company such as that of the Defendant to

set up an out-of-office message for every departing employee (sic). […]

Since this message can vary so widely within the Defendant […] the

setting up of the out-of-office message is delegated to the departing employee himself.” 48

and

46 Appendix 13, Email correspondence ICT department regarding the deletion of accounts in document 18, the summary conclusion of
[defendant] of 27 August 2024.

47
Document 34, Minutes of Hearing of 3 December 2025, p. 3.
48Piece 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 59. Decision on the merits 101/2026 — 23/60

• on the other hand, the “(e-mail) account as well as the corresponding mailbox within the

Microsoft environment of the Respondent proverbially dragged to the ‘trash can’
49
[is].”

69. Given the quantity and diversity of personal data in a mailbox of an

employee, as already cited above 50, the risks regarding the

processing of the personal data in these mailboxes, including those of the complainant

and her contacts, are considerable. Consequently, closing such mailboxes and

means of communication requires sufficient technical and organizational

measures to protect these personal data. The state of the art has

allowed for quite some time to automate these measures and/or to verify them thoroughly,

even if the process were still to be carried out manually.

70. Based on the information in the file, the Disputes Chamber establishes that closing

the mailboxes of departing employees is a very frequently

recurring task for the defendant, which already appears to be carried out according to a specific, standardized procedure.

Based on the defendant's management processes in the documents,

the Disputes Chamber establishes that the process proceeds as follows:

• based on information from the human resources department, the

accounts to be deactivated are automatically prepared for deactivation on the correct day after verification;

• all necessary information regarding the accounts to be deactivated is automatically

collected in preparation for the deactivation;

• every account to be deactivated is automatically added to the list of accounts to be deactivated, after which the list is automatically sent to the helpdesk;

helpdesk;

• on the appropriate day, the account is manually deactivated by the ICT second-line service;

• on the first day of every month, an overview of deactivated accounts is automatically created;

deactivated accounts;

• this list of deactivated accounts is automatically sent to a recipient list of the defendant to notify the managers that the accounts will be deleted at the end of the month, unless an exception is requested;

49Piece 18, the summary conclusion of [defendant] of 27 August 2024, paragraph 31.

50
See paragraph 11 of this decision for this. 51Appendix 22, Internal Personal Account Management Processes to document 18, the summary conclusion of [defendant] of 27 August 2024. Decision on the merits 101/2026 — 24/60

• based on an ICT ticket, this exception can be requested, whereby

the account is set to ‘do not delete’;

• after verification by the ICT second-line service, the list of accounts to be deleted is sent by the employee to the ICT infrastructure service;

• the ICT infrastructure service manually deletes all accounts to be deleted and sends a

list of effectively deleted accounts back to the ICT second-line service;

• the ICT second-line service sets the account to ‘deleted’. 71. With regard to the complainant's mailbox, the Disputes Chamber establishes that her account was indeed

on the list of mailboxes to be deleted by the ICT second-line service and

52
that this list was indeed sent to the ICT infrastructure service. The facts show that

the mailbox was not deleted, however.

72. First, the Disputes Chamber establishes that the effective deletion of the mailbox was not

automated, whereas it is a typical process that, given the state of the

art, can easily be automated. Second, the Disputes Chamber

establishes that a control measure did exist regarding the deletion of the mailbox, namely the return of the list of effectively deleted mailboxes. However, this measure

was clearly not followed. Moreover, there was no technical control whatsoever over the implementation of this measure, even though this was possible, for example by technically comparing the list of mailboxes to be deleted with the list of deleted mailboxes to trigger an alert when these two lists do not match.

73. Since there is no control over the deletion of the mailboxes and since these

processes did not take place automatically, the defendant cannot in any way

demonstrate, in accordance with Articles 5.2 and 24 of the GDPR, that the complainant was effectively the only one

for whom the manual process had failed. In that context, the Dispute Chamber established

on the basis of the list of departing employees from May 2023 that there was an

employee who, according to the data, had already left the organization on October 4, 2022,

but whose mailbox deletion was only

communicated to the ICT department on June 1, 2023. 53

74. The defendant points out that he had initiated an improvement process, whereby a

tender was issued in mid-2022. In the conclusions, however, the defendant states

that only the final step of the process would be fully automated and

52
Appendix 13, Email correspondence ICT service regarding the deletion of accounts in document 18, the summary conclusion of
[defendant] of August 27, 2024.
53 Appendix 13, Email correspondence ICT service regarding the deletion of accounts in document 18, the summary conclusion of

[defendant] of August 27, 2024. Decision on the merits 101/2026 — 25/60

this only from September 2024. 54 The Disputes Chamber establishes that this improvement process

offered no relief at the time of the complainant's departure, since the

procedures were still manual proceeded. Despite the fact that the need for new

processes had already been acknowledged in June 2022, the

effective control of the manual processes was not initiated at that time, although this was provided for in the

management processes.

75. In this regard, the defendant refers to his standard policy regarding mailboxes, which is

attached in the documents. However, the standard policy submitted by the defendant was

drawn up after the complainant's departure. Indeed, the policy speaks of an old and a
55 56
new process, whereas the new process was in force in March early December 2023, specifically 7 months after the complainant's departure. The defendant submits no policy other than the management processes that was valid at the time of the complaint. 57
76. The management processes date from 31 May 2016 and have therefore never been modified since

the introduction of the GDPR and its application by the Disputes Chamber regarding the

closing of the mailboxes of departed employees, of which the defendant should have been

aware. From these management processes, the Disputes Chamber infers that

the procedure that was valid at the time of the complainant's departure was still this

procedure of 2016 and that the defendant can hardly speak of “Defendant

(re)evaluates and analyzes its processes in order to optimize them, taking into account

the new state of the art and the implementation costs” 58

or of “This proactive approach [which] underscores that Defendant takes its

responsibilities seriously and strives for continuous compliance with the
59
GDPR.”

77. The Disputes Chamber rules that the defendant had taken, or demonstrates having taken, insufficient technical and

organizational measures to delete the

complainant's mailbox after there was no longer a legal basis to further process the

personal data in the mailbox and thereby committed an infringement

of Article 24 GDPR.

54 Document 18, the summary conclusion of [defendant] of 27 August 2024, paragraph 46.

55 Appendix 3, [defendant]'s policy regarding emails in document 18, the summary conclusion of [defendant] of 27 August 2024: “This
process is valid for the new and the old way of working”. 56
Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 12.
57 Appendix 22, Internal Personal Account Management Processes to Document 18, the summary conclusion of [respondent] of 27 August 2024.

58 Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 74.
59
Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 65. Decision on the merits 101/2026 — 26/60

78. The fact that the respondent was in an improvement process to rectify this shortcoming will be taken into account by the Disputes Chamber in the assessment of the appropriate corrective measures and sanctions.

II.7. Violation of Articles 12 and 15 GDPR

79. The complainant states that the defendant did not grant access to her mailbox, which had still not been deleted at the time of the request, nor to the requested

log data of the mailbox. The solution proposed by the defendant is very

unbalanced, given that the complainant would only be granted very limited access to the

personal data and this only after extensive filtering by and under the supervision of

the defendant. It was not clear to the complainant whether she would be allowed to copy personal data from the

mailbox, who the neutral person present during this would be,

whether this neutral person would also be able to view the content of the private emails and how

prior filtering would be performed. The justification for this practice would

also be based too generally on the ‘protection of trade secrets and

commercially sensitive information’. 80. The defendant argues that his DPO responded to the request for access in a timely and adequate manner, without disregarding other provisions of the GDPR or beyond. In this regard, the defendant refers to commercially sensitive data connected to his activities, to which the complainant also had access during the performance of her duties. The defendant therefore only wished to perform filtering when storing data from the mailbox, so that the rights and freedoms of third parties and the business secrecy of the defendant could be guaranteed. To achieve this, the DPO made a balanced proposal by inviting the complainant to the defendant's offices and only monitoring the data that would be copied from the mailbox. The complainant did not give the defendant the opportunity to explain this course of action, and to specify who would be engaged as a neutral person and how the supervision would take place. 81. The Disputes Chamber establishes that the complainant contacted the defendant on 24 January 2024 to report that her email address was still active, requesting also access to and a copy of her personal data in her mailbox for the last 9 months since her departure. On February 20, 2024, the DPO proposed the following procedure in order to grant the

request for access:

“In the presence of a neutral person, you will be granted access to the relevant

mailbox; this will take place from a [defendant] office and with the aid of a

[defendant] device. The available emails must be filtered for emails received

after your departure and for external senders, since all internal Decision on the Substantive Matters 101/2026 — 27/60

contacts received a correct out-of-office email. In this way, the

trade secrets of [defendant] are respected and you are still offered the opportunity

to filter your personal emails and, if desired, save them. […]” 60

On March 6, 2024, the DPO reiterated his proposal for access to the complainant's mailbox and

now imposed a time limit on the complainant:

“In addition, the proposal regarding access to your

personal data remains, as set out in our previous communication, naturally still

valid. If you still wish to accept this proposal, then we would like to hear from you within fourteen (14) days following this e-mail. […] If you inform us that you do not wish to accept this proposal or do not communicate a date to us within fourteen (14) days following this e-mail, then the

mailbox will be completely closed the day after your notification that you do not wish to accept

our proposal or the day after the expiry of the aforementioned period.”

That same day, the complainant initially indicated that she wished to accept the inspection procedure, to which

she later retracted and stated that she did not wish to come to the premises for inspection

but wished to receive a copy of her personal data in accordance with Article 15.3 GDPR.

The defendant sent the processed personal data of the complainant via email on 4 April 2024, including a screenshot of the activity log of her mailbox and clarified his position regarding access to the mailbox itself:

“By way of addition, I would like to point out that not making the mailbox available is not a matter of not wanting to, but a matter of not being allowed to


• [defendant] cannot deliver the entire mailbox because they might then infringe on confidentiality rules, as some emails may be subject to them


• [defendant] cannot deliver the latest or non-confidential emails because someone would then have to gain access to your mailbox and we do not allow that either
61
for privacy reasons.”

On the same day, the DPO makes a file available for inspection, clarifying:

“The information not included in this package is the information that they

• […]

60Appendix to document 2, Complaint form of April 23, 2024, email of February 20, 2024 at 14:48.61Appendix to document 2, Complaint form of 23 April 2024, email 1 of 4 April 2024 at 15:38. Decision on the merits 101/2026 — 28/60

• […]

• Unable to provide because they cannot access it, such as information from

mailboxes.” 62

82. Based on this communication, the Disputes Chamber establishes that the defendant limited the

right of access to emails that arrived after May 1, 2023, and only those e-

emails originating from external contacts. The reason invoked for this limitation was that, on the one hand, a correct out-of-office message had been set up on

the emails of internal colleagues and the protection of trade secrets. Only after this

filtering would the complainant be able to filter her personal emails and potentially retain them.

83. Regarding the prior filter that would prevent access to emails from internal colleagues,

the Disputes Chamber rules that whether or not an out-

of-office message is set up correctly is not a criterion for limiting the complainant's right of access,

especially since this out-of-office message concerns the responsibility of the defendant.

84. Regarding the filter that prevents access to e-mails prior to the complainant's departure from the defendant

would prevent, the Disputes Chamber rules that the time of receiving or

processing the personal data is not a criterion for limiting the

complainant's right of access. The personal data are still in the mailbox and are therefore

still being processed, meaning they can therefore still be the subject of a request

for access. However, the Disputes Chamber establishes that the complainant only requested access to her

personal data in the mailbox for emails received in the last one-eight months after her departure,

making this filter by the defendant acceptable.

85. Regarding the filter for the sake of trade secrets or the intellectual property of the

defendant, as stated in Recital 63 of the GDPR, the Disputes Chamber rules that this

filter does indeed constitute a criterion for

limiting the complainant's right of access.

In that context, the Disputes Chamber establishes on the basis of the hearing that the

the defendant employs a classification system that divides the data into ‘public’, ‘restricted’,

‘confidential’ and ‘strictly confidential’ data and that the title of the email would be sufficient
63
to determine whether the email concerned a project that needed to be protected.

Based on this classification, the defendant could have, without risk to his trade secrets, in a
first step reviewed all emails together with the complainant for metadata, in order to then filter out the

business-sensitive data. In a second step, the complainant could then obtain full

insight and a copy of all data that had not been filtered out in this way.

62 Appendix to document 2, Complaint form of 23 April 2024, email 2 of 4 April 2024 at 15:38.

63 Document 34, Minutes of hearing of 3 December 2025, p. 5. Decision on the merits 101/2026 — 29/60

86. Given the possible presence of trade secrets in the complainant's mailbox,

the Disputes Chamber deems it proportionate that the complainant should be required to exercise this access

within the secure perimeter of the defendant's offices and on a

defendant's device in the presence of a neutral person during step 1. The role

of this neutral person would be limited to removing the commercially sensitive

data from the mailbox based on the classification and metadata of the messages.

87. In his conclusions, the defendant amends his argumentation for the filtering by stating

that the complainant would be granted access to her entire mailboxes and that this filtering was only

applicable in the event that the complainant wished to copy certain personal data.

The Disputes Chamber notes that this interpretation does not correspond with what the DPO

had communicated to the complainant in his emails of 20 February 2024 and March 6, 2024,

in which there is a first filter, after which the complainant could filter the rest of the emails. The position that the “Complainant did not even give the Respondent the opportunity to

explain the entire procedure[…]” goes directly contrary to the principle of transparency of

Article 12 GDPR and confirms the lack of clarity in the communication regarding any

filtering of the mailbox before the complainant would be allowed to inspect it.

88. The Dispute Chamber rules that the respondent did not take appropriate measures

to facilitate the complainant's right of access to her personal data after her

departure from the respondent and has

unjustifiably limited this right of access

to only the emails for which no correct out-of-office message was set,

thereby committing a breach of Articles 12 and 15 GDPR.

II.8. Violation of Article 5.1.f GDPR in conjunction with Article 5.2 GDPR

89. Article 5.2 GDPR states that the controller must guarantee and be able to demonstrate compliance with the GDPR principles. One of these principles concerns guaranteeing the confidentiality and integrity of the personal data of the data subject, in accordance with Article 5.1.f GDPR.

90. The complainant argues that the defendant took insufficient measures in the organization of its processing of personal data to subsequently be able to demonstrate to the complainant that there was no access to her mailbox after her departure and that, consequently, the confidentiality and integrity of her personal data were guaranteed. In this regard, the complainant refers to an email that arrived in her mailbox on August 13, 2023, which is also recorded as opened. The complainant obtains this information from the screenshot of the activity log of her mailbox that she received on April 4, 2024, following her repeated request for access.

64Stuk 18, the summary conclusion of [defendant] of 27 August 2024, paragraph 105. Decision on the merits 101/2026 — 30/60

91. The defendant again refers to the deactivation and removal of the license of

the complainant's mailbox, as a result of which no one had access to this mailbox anymore and the
confidentiality and integrity of the personal data were thus guaranteed.

Regarding the allegedly opened email, the defendant points out that the time of

receipt of the email and the time of the alleged opening of the email are the same and occur in the middle of the night. When an email containing a link or an attachment

arrives at the defendant's domain, it is scanned for harmful content within the framework of

information security. This scan leaves a trace in the

activity log as if the email had been opened. This explains the

nightly time and the simultaneous registration of arrival and opening the email.

Furthermore, the defendant states: “Despite what the Complainant attempts to insinuate in this regard in

her conclusion, the Defendant naturally gladly substantiates this assertion by means of log

files (document 23).

92. Regarding the continued processing of the personal data in the

mailbox of the complainant after her departure, the Disputes Chamber establishes that the mailbox was never deleted after there was no longer a

legal basis for the processing and that various elements in the documents

point to an additional purpose, besides informing the contact persons, namely

retrieving business-sensitive information from the mailbox closed to the complainant. 66

From the complainant's point of view, the fear that this actually happened is therefore not

unjustified and it is up to the defendant to demonstrate, in accordance with Articles 5.2, that there was

no access to the mailbox after her departure. 93. Specifically, the complainant established that a specific email in her mailbox was opened

after her departure. To this end, the complainant refers to the screenshots of the Customer

Relationship Management system (CRM) that she received on April 4, 2024, following her

request for access. The Disputes Chamber establishes in the activity logs of the CRM of the

complainant's mailbox, which the defendant attaches to his documents, that on August 13,

2023, thus after the complainant's departure, an email was received at 01:20 and

at the same moment the same email was opened. The defendant refers to his

information security policy and the screening of incoming emails to explain

why the mail appears to have been opened in the system.

94. In accordance with Article 5.2 of the GDPR, it is up to the defendant to demonstrate that no further access was taken to her mailbox after the departure

of the complainant. The most suitable

means to demonstrate whether or not there was access to this mailbox are the log files of the

authentication and access attempts to this mailbox, which also in the context of

65Piece 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 116.

66
See paragraph 31 of this decision for this.

67Appendix 25, screenshots CRM system with piece 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 31/60

information security always be recorded. The respondent refers in his conclusions

to piece 23 (‘Logs regarding the mailbox’) to demonstrate that there has been no access to

the complainant's mailbox. It has therefore been irrefutably demonstrated that the defendant has possession of

the ‘log files’ of the authentication and access attempts to the complainant’s account.

95. However, the Disputes Chamber notes that in document 23, the defendant only added the ‘log files’ from

July 22, 2024 to August 20, 2024 to the documents. The defendant

confirms this in his conclusion: “The defendant can demonstrate that no

actions or manipulations took place in the mailbox during the past month since the departure of

the Complainant (document 23)” (emphasis by Disputes Chamber). With this limited time period

in which the ‘log files’ were included in the documents, the defendant cannot demonstrate

that there was no access to the complainant’s mailbox from May 1, 2023 to July 22, 2024. 96. The Disputes Chamber notes that the defendant does not include log files regarding access to the

mailbox from 1 May 2023 to 1 June 2023, the period during which he did still have a

legitimate interest in processing the complainant's mailbox, but also the

period during which the managers could

request an exception to the deletion of the mailbox in order to recover business-sensitive data. 69 The defendant argues that

such an exception was not requested and that, therefore, no access was taken to the

mailbox, but fails to demonstrate this. In that same period, specifically on 15 May 2023,

the email which the complainant stated in her complaint had been opened upon receipt is also included, which

led her to suspect that there was indeed access to the mailbox. She obtained this information

70
from the activity logs of the mailbox which she received following her request for access. The defendant referred to his

information security policy regarding the opening of this email, but nowhere demonstrates that no access was

taken to the mailbox that day/night, which his assertion could have irrefutably demonstrated to the

Dispute Resolution Chamber.

97. The Dispute Resolution Chamber also establishes that the defendant (except for the log files mentioned in

paragraph 95 for a limited period) does not add log files

from the period after June 1, 2023, the moment at which the mailbox should have been deleted,

unless a manager had received an exception. During this period, specifically on

August 13, 2023, the Dispute Resolution Chamber establishes that another email was listed which

according to the activity logs, was allegedly opened at the same time of receipt. Also1

68
Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 83.
69See bullet number 6 of paragraph 70 of this decision for this.
70
Document 2, complaint form of 23 April 2024, p. 3.
7Document 25, Screenshots CRM system accompanying document 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 32/60

for this period and this e-mail, the respondent does not demonstrate that there has been no access

to the mailbox. 98. Finally, the Disputes Chamber establishes that on 20 February 2024, the DPO informed the complainant

that there had been no access to the complainant's mailbox and stated: “Moreover, this was explicitly confirmed by our IT department.” Here too, the defendant

fails to add any evidence of the absence of access to the mailbox or of the control

thereof by the IT department, whereas this control was apparently indeed

possible and had been carried out.

99. The Disputes Chamber rules that the defendant has not sufficiently demonstrated that

the confidentiality and integrity of the complainant's personal data in her

mailbox were guaranteed, whereas it has been demonstrated that the defendant was

capable of doing so and thereby committed a breach of Article 5.1.f GDPR in conjunction with Article

5.2 GDPR. 100. Regarding the argumentation concerning the setting of the out-of-office message, the Disputes Chamber refers to the earlier assessment regarding the transparency obligation of the

defendant in this regard and does not elaborate further on this.

II.9. Conclusion: established infringements

101. In this decision, the Disputes Chamber ruled that the defendant committed an infringement

of

• Article 5.1a GDPR read in conjunction with Article 6.1 GDPR by unlawfully processing the personal data of the

complainant and her contacts in her professional mailbox

after there was no longer a legitimate interest to further process these

personal data, in this case after 1 June 2023;

• Articles 12 and 13 GDPR by failing to comply with his transparency obligation

with regard to the further processing of the personal data of the complainant and

of her contacts external to the organization after the complainant's departure from the

defendant;

• Article 24 GDPR because he had taken or demonstrates having taken insufficient technical and organizational measures

to delete the complainant's mailbox

after there was no longer a legal basis to further process the personal data in the mailbox;

72 Appendix 5, Email from the Respondent of 20 February 2024 (14:48) regarding document 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 33/60

• Articles 12 and 15 GDPR because he did not take appropriate measures

to facilitate the complainant's right of access to her personal data after her departure from

the respondent and has unjustifiably limited this right of access to

only the emails for which no correct out-of-office message had been set;

• Article 5.1.f GDPR read in conjunction with Article 5.2 GDPR because he has not sufficiently demonstrated

that the confidentiality and integrity of the complainant's personal data in

her mailbox were guaranteed, whereas it has been demonstrated that the defendant was

capable of doing so.

III. Corrective measures and sanctions

102. According to the wording of Article 100.1 of the WOG, the Disputes Chamber has the

power to:

1° dismiss a complaint;

2° order a decision to be dismissed;

3° order a suspension of the decision;

4° propose a settlement;

5° issue warnings and reprimands;

6° order compliance with the requests of the data subject to exercise his rights;

7° order that the data subject be informed of the security issue;

8° to order that the processing be temporarily or permanently frozen, restricted or prohibited;

9° to order that the processing be brought into compliance;

10° to order the rectification, restriction or deletion of data and notification thereof to the recipients of the data;

11° to order the withdrawal of the accreditation of certification bodies;

12° to impose penalty payments;

13° to impose administrative fines;

14° to order the suspension of cross-border data flows to another State

or an international institution;

15° to transfer the file to the Public Prosecutor's Office in Brussels,

which notifies it of the action taken on the file; 16° to decide on a case-by-case basis to make its decisions known on the website of Decision on the merits 101/2026 — 34/60

the Data Protection Authority.

103. It is up to the Dispute Resolution Chamber to decide on the most appropriate sanction in light

of the established infringements.

III.1. Corrective measures

104. Due to the infringement of Article 24 GDPR, because the defendant had taken or demonstrates having taken insufficient technical and organizational measures to delete the complainant's mailbox after there was no longer a legal basis

to continue processing the personal data in the mailbox, the Disputes Chamber orders

pursuant to Article 58.2.d GDPR and Article 100, § 1, 9° WOG, to take sufficient technical and

organizational measures in order to continue processing and closing the personal data in the mailboxes

of departing employees in accordance with this decision, and to demonstrate this to the Disputes Chamber.

Given that, according to the defendant, these measures have already been taken, he only

remains to demonstrate this to the Disputes Chamber, and the Disputes Chamber considers a period of

30 days to be more than sufficient to comply with this order. This order is necessary to avoid similar unlawful processing at the defendant in the short term, in particular in light of the high turnover of

employees at the defendant.

105. Due to the infringement of Articles 12 and 15 of the GDPR, because the defendant did not take the
appropriate measures to facilitate the complainant's right of access to her

personal data after her departure from the defendant and

unjustifiably limited this right of access to only the emails for which no proper out-of-

office message was set, the Dispute Resolution Chamber orders, pursuant to Article 58.2.c

GDPR and Article 100, § 1, 6° WOG, to grant the complainant access to all her

personal data in accordance with this decision.

106. This order is necessary to enable the complainant to exercise full control

over her personal data which were unlawfully processed after her departure

and over which she has not yet been able to exercise any control to date, given

this personal data was stored

under the full control of the defendant and the request for access had not yet been granted. Specifically, this also enables the complainant

to recover any missed communication due to insufficient

transparency towards her contacts in order to potentially restore this

communication relationship.

73Piece 39, Defense of [defendant] of 24 April 2026, p. 18, paragraph 8. Decision on the merits 101/2026 — 35/60

107. The Disputes Chamber takes note of the defendant's request regarding the modalities

for the execution of this right of access. However, the Disputes Chamber is of the opinion that it is the responsibility of the defendant to determine the modalities of the inspection in consultation with the complainant and, in doing so, possibly to call upon a neutral third party.

108. Due to the infringement of Article 5.1.a of the GDPR read in conjunction with Article 6.1 of the GDPR, because the defendant unlawfully processed the personal data of the complainant and her contacts in her professional mailbox after a legitimate interest no longer existed to continue processing these personal data, in this case after 1 June 2023, the Disputes Chamber orders, pursuant to Article 58.2.g of the GDPR and Article 100, § 1, 10° of the WOG, to delete all personal data concerning the complainant's mailbox after access has been granted.

This order is necessary since the purpose and necessity to continue processing the personal data in the mailbox in accordance with the initial legal basis or the legitimate interest has long since expired within the period of 1 month following the complainant's departure and

since the continued retention of this mailbox in the context of these proceedings

is likewise no longer necessary. 109. In view of the infringement of Article 5.1.f GDPR read in conjunction with Article 5.2 GDPR, because the

defendant has not sufficiently demonstrated that the confidentiality and integrity of

the complainant's personal data in her mailbox were guaranteed, whereas it has been

demonstrated that the defendant was capable of doing so, the Dispute Resolution Chamber orders

pursuant to Article 58.2.d GDPR and Article 100, § 1, 9° WOG, to transfer the registration of access
to the complainant's mailbox from 1 May 2023 until the deletion of the mailbox

to the complainant, without however leaving third-party personal data visible, or to

demonstrate that these data are no longer available to the defendant.

This order is necessary to enable the complainant to verify whether or not the
confidentiality of her personal data was violated after she no longer had

any control over these personal data. 110. Only by granting the complainant access to all personal data in this mailbox,

by subsequently deleting this mailbox and by demonstrating that there has been no access
to this mailbox in the meantime, will the complainant regain full control over

her own personal data processed on the domain and on behalf of the

defendant. The defendant is granted a period of 30 days, calculated from the

notification of this decision, to execute these four orders and to give the complainant

back control over her personal data in her mailbox. Decision on the merits 101/2026 — 36/60

III.2. Administrative fine

111. In addition to the corrective measures to bring the processing into conformity

with the principles of the GDPR, the Dispute Resolution Chamber also decides to impose an

administrative fine with a view to vigorous enforcement of the rules of the

GDPR. As is clearly evident from Recital 148 of the GDPR, the GDPR establishes that in the event of any serious infringement—including the initial finding of an infringement—penalties, including administrative fines, shall be imposed in addition to or instead of appropriate measures.

112. The Disputes Chamber also points out that it is its sovereign responsibility as an independent administrative authority—with due observance of the relevant Articles of the GDPR and the WOG—to determine the appropriate corrective measures and sanctions. This follows from Article 83 of the GDPR itself, but the Market Court has also emphasized in its case law the existence of broad discretionary power of the Disputes Chamber regarding the choice of the sanction and its scope,

74
as, inter alia, in its judgments of 7 July 2021 and 6 September 2023. 113. The fact that this concerns a first finding of an infringement of the GDPR committed by the defendant does not in any way prejudice the possibility for the Dispute Chamber to impose an administrative fine. The Dispute Chamber imposes the administrative fine pursuant to Article 58.2.i) of the GDPR. The instrument of administrative fine is by no means intended to terminate infringements; to that end, the GDPR and the WOG provide for a number of corrective measures, including the orders referred to in Article 100, § 1, 8° and 9° of the WOG.

114. Article 83.3 of the GDPR prescribes the factors that must be taken into account in each specific case when deciding whether an administrative fine is imposed and the amount thereof. The Disputes Chamber takes into account in particular

the severity of the infringements, the duration of the infringements, and the necessary

deterrent effect to prevent future infringements. To avoid

repeating the assessment of each factor, the Disputes Chamber refers to the

assessment below, in which the imposition of an administrative fine and the

amount thereof are assessed together. 115. In order to impose an effective, proportionate and dissuasive fine in any event,

the supervisory authorities are expected to adjust the administrative fines

and thereby remain within the margins set out in the EDPB Guidelines 04/2022 for

the calculation of administrative fines under the GDPR (Version 2.1, Adopted

74 Brussels Court of Appeal, Market Section A, Market Affairs Chamber, 2021/AR/320, pp. 37-47; Brussels Court of Appeal, Market Section, 19 Chamber A, Market Affairs Chamber, 2020/AR/1160, p. 34. Decision on the merits 101/2026 — 37/60

provided for on 24 May 2023). This may lead to significant increases or decreases in

the fine, depending on the circumstances of the case. The application of these

Guidelines is necessary to ensure the coherence of the application of the GDPR.

In accordance with the EDP B Guidelines, administrative fines

for infringements of the GDPR are calculated on the basis of a method consisting of five steps.

These five steps are systematically reviewed in the following paragraphs. The

Dispute Chamber recalls that it is not obliged to examine criteria that are not

applicable.

III.2.1. Concurrence of infringements and the application of Article 83.3 of the GDPR

One infringing act

116. As a first step, the Dispute Chamber establishes that there is one and the same infringing act.

The infringing processing of personal data constitutes a

series of processing activities carried out by a single will that are contextually, spatially and temporally interconnected. They must be considered as “related” and as

a single act. Specifically, it concerns the continued

processing of personal data in the complainant's mailbox over the long term after the latter had terminated the

collaboration with the defendant.

117. On the basis of this act, the Dispute Resolution Chamber ruled that two of the

established infringements must be punished with an administrative fine,

namely the infringement of Article 5.1a GDPR read in conjunction with Article 6.1 GDPR and the infringement of Articles

12 and 13 GDPR. Unity of operations

118. The Dispute Chamber rules that the infringement of Articles 12 and 13 GDPR can be attributed alongside the infringement

of Article 5.1a GDPR in conjunction with Article 6.1 GDPR when calculating

the fines. The provisions that were infringed pursue

independent objectives (the principle of transparency and the principle of lawfulness),

whereby one provision is not excluded or encompassed by the applicability of the

other, which justifies the imposition of separate fines.

119. In this case, the principle of lawfulness concerns the lack of legal grounds to continue processing the

personal data of the complainant and her contacts after the

defendant no longer had a legitimate interest. Even if the continued processing

after the processing based on legitimate interest had been transparent, the

lawfulness of the processing would still have been violated. 120. In this case, the principle of transparency concerns informing the complainant regarding

the further processing of her personal data in her mailboxes of her contacts Decision on the merits 101/2026 — 38/60

regarding the termination of the cooperation between the complainant and the defendant.Even if the processing had been lawful, the principle of transparency

would still have been violated.

121. The Dispute Chamber refers as an example to Binding Decision 1/2021: “With regard to

the meaning of Article 83(3) GDPR, the Committee notes that, taking into account the

views of the supervisory authorities concerned, in the event of multiple

infringements, multiple amounts may be set.” Furthermore, Article 83(3) GDPR provides that if a controller intentionally or negligently in

relating to the same or related processing activities in an infringement of

multiple provisions of this Regulation, the total amount of the

fine may not exceed the permitted maximum amount for the most serious

infringement. Conclusion

122. In summary, the Dispute Resolution Chamber rules that it may impose two separate fines,

and that the total fine cannot exceed the maximum amount for the
most serious infringement.

III.2.2. Starting amount for the calculation

123. The calculation of administrative fines starts with a harmonised

starting amount based on EDPB Guidelines 04/2022. This takes

account of the classification of infringements according to their nature pursuant to Article
83, paragraphs 4 to 6, GDPR, the severity of the infringement and the turnover of the

undertaking. Classification of infringements under Article 83, paragraphs 4 to 6 of the GDPR

124. The GDPR distinguishes between two categories of infringements: infringements that

are punishable under Article 83.4 of the GDPR on the one hand, and infringements that are punishable under

Articles 83.5 and 83.6 of the GDPR on the other hand. The first category of infringements carries a

maximum fine of EUR 10,000,000 or 2% of the total worldwide annual turnover in the

preceding financial year, if this figure is higher. The second category may result in a

fine of up to EUR 20,000,000 or 4% of the total worldwide annual turnover

in the preceding financial year, if this figure is higher. 125. For the infringement of Article 5.1a GDPR read in conjunction with Article 6.1 GDPR, the maximum administrative fine in accordance with Article 83.5a) GDPR amounts to EUR 20,000,000 or

up to 4% of the total worldwide annual turnover in the preceding financial year, if this figure is higher.

Decision on the merits 101/2026 — 39/60

126. For the infringement of Articles 12 and 13 GDPR, the maximum administrative

fine in accordance with Article 83.5a) GDPR amounts to EUR 20,000,000 or up to 4% of the

total worldwide annual turnover in the preceding financial year, if this figure is higher. 127. Since the higher fine applies, in accordance with Article 83.5(a) of the GDPR,

the Dispute Resolution Chamber may impose an administrative fine of up to EUR 20,000,000

or up to 4% of the total worldwide annual turnover in the preceding financial year, if

this is higher.

Severity of the infringements in each individual case

128. Regarding the infringement of Article 5.1(a) of the GDPR read in conjunction with Article 6.1 of the GDPR (hereinafter ‘infringement of

lawfulness’)

a. Article 83.2(a) of the GDPR – The nature, seriousness and duration of the infringement:

129. Regarding the nature of the infringement, the Dispute Resolution Chamber takes into account that the

principle of lawfulness is a fundamental principle of the protection guaranteed by

the GDPR. It is also included in Article 8.2 of the

Charter of Fundamental Rights of the European Union. The Disputes Chamber rules that
infringements of this core principle are of high severity.

130. With regard to the seriousness of the infringement, the Disputes Chamber takes the following

elements into account:

• Nature of the processing: it concerns further processing of the

personal data in the complainant's mailbox in which both her personal data

and personal data of her contacts are processed. The initial processing

was lawful for both the complainant and her contacts.

• Scope of the processing: it concerns the further processing of

personal data in the complainant's mailbox and consequently her personal data

but also the personal data of her contacts who communicated with her.

However, the complainant had already wound down her activities at the defendant, a fact

of which the contacts were already aware due to the out-of-office setting of

the complainant. • Purpose of processing: the sole purpose of any further processing of
the personal data of the complainant and her contacts in the mailbox after the limited

period of processing under legitimate interest, consisted in being able to recover

potentially commercially sensitive data from the

complainant's mailbox. This objective was formulated in internal communication of the

defendant. Decision on the merits 101/2026 — 40/60

• Number of data subjects: this concerns the mailbox of 1 person, in which personal data

of the complainant and an unknown number of contacts were further processed.

• Extent of the damage: There is no information that the unlawful further

processing has led to an abuse of the personal data of the complainant or

of her contacts. Given the professional context of the mailbox, one can

expect that these personal data are rather limited and non-sensitive,

although urgent, personal messages can also be expected in such a mailbox. Moreover, the complainant herself had already previously informed her correspondents that she was only accessible via that email address to a limited extent (for external parties)

or no longer accessible (for internal parties).

Based on this assessment, the Disputes Chamber rules that the severity of the infringement

is of low weight, since it has not been demonstrated that the personal data were effectively
used, while they were retained.

131. Regarding the duration of the infringement, the Disputes Chamber notes that the

personal data of the complainant and her contacts in the mailbox should have been

deleted on June 1, 2023, which was not carried out. As of June 1, 2023, the defendant therefore
no longer had a legal basis to process the personal data. It appears from the conclusions of

2025 that all personal data are still in the mailbox and are available. Although the defendant claims that, since the complainant's notification regarding a

potential procedure against the defendant, he once again has a legal basis to retain the

personal data, this new situation is a direct consequence of the

failure to delete and thus further processing of the personal data without a legal basis

and of the failure to grant full access to the personal data despite the request

of the complainant. After all, the complainant first wanted to check which communications she had missed,

before her mailbox was to be deleted, which was a legitimate concern, given the

unlawful continued processing of the personal data in this mailbox. The

Dispute Chamber considers the duration of the infringement to be of average severity because the

retention of all personal data continues to this day. The

argument that the mailbox had to remain in existence because of this procedure is

unfounded since the absence of a legal basis is precisely what caused this procedure

and since there are other, technically safer ways to retain the necessary

information for this procedure.

b. Article 83.2.b) GDPR – The intentional or negligent nature of the infringement:

132. In the present case, according to the Dispute Chamber, there was no intention on the part of the defendant to

intentionally continue to unlawfully process the personal data, but there was at least a case of negligence, which satisfies the requirements of the case law of
75
the Court of Justice of the EU. Although the defendant argues that the continued
processing involved a one-off human error, it is clear from the decision that the

defendant was negligent with regard to the minimum technical and

organizational measures, in particular the automatic deletion of (all

personal data in) the mailbox of a departed employee after a period of

processing under legitimate interest. Moreover, the file shows that the

defendant was aware of previous decisions by the Disputes Chamber regarding the

correct closure of an ex-employee's mailbox. Given that the defendant himself

speaks of approximately 1,000 departing employees per year, he should have taken sufficient measures earlier and

sooner to rule out any human error.

The Disputes Chamber rules that the negligent nature of the infringement must be considered to be of

average severity.

c. Article 83.2.g) GDPR – The categories of personal data to which the infringement

relates:

133. The disputed processing concerns the personal data of the complainant and of her

contacts in her professional mailbox. Although prima facie such personal data are not of a sensitive or special nature, the Disputes Chamber rules that they

nevertheless belong to categories of personal data which data subjects

would generally not reasonably expect to be further

processed by the defendant. This category is assessed as neutral.

134. In his response to the sanction form, the defendant argues that the duration of the infringement

is not attributable to him, given that on 2 May 2024 he had asked the DPA for advice

regarding the deletion of the mailbox after the complainant had requested that it not be

deleted until she had had access to it. The defendant feels supported in this view since

the Disputes Chamber also imposes an order for access on the defendant. The defendant

states: “[defendant] therefore believes that a ‘medium severity’ for the duration of the

infringement is unjustified, given that this duration is entirely due to the DPA’s choice

not to answer [defendant]’s legitimate question as to whether she was allowed to

delete the mailbox, and the long duration of the proceedings before the Disputes Chamber. A low

76
severity is therefore appropriate.”

75
CJEU, Deutsche Wohnen SE v. Staatsanwaltschaft Berlin, judgment of 5 December 2023, C-807/21, ECLI:EU:C:2023:950,
paragraph 78.
76Piece 39, Defence of [defendant] of 24 April 2026, p. 16, paragraph 3. Decision on the merits 101/2026 — 42/60

135. The Dispute Resolution Chamber establishes that the complainant left the defendant on 1 May 2023

and ruled that the defendant could continue to process the personal data of the

complainant for one month for the sake of its legitimate interest. 136. First, the complainant herself informs the defendant that her data is still being processed unlawfully in January 2024, eight months after the defendant no longer had a legitimate interest and at that time 8x the duration of the processing under the legitimate interest.

137. Second, the complainant informs the defendant on 20 February 2024 that she will open a file at the GBA and reports to the defendant on 6 March 2024 that her email will be added to the complaint at the GBA. The defendant was therefore aware of the complainant's intention to file a complaint with the GBA no later than 6 March 2024. This complaint was effectively filed on 23 April 2024. The submission of a request for advice by the defendant to the GBA, when he knows that a complaint has been filed or will be filed, is no argument to allow a breach of the GDPR to continue until the GBA has responded to the request for advice or has taken a decision regarding the complaint, precisely because the processing time for such complaints at the Disputes Chamber can be long. After all, it is the defendant who is the controller for this processing. This responsibility does not transfer to the GBA in the event of a request for advice regarding this. The Disputes Chamber hereby points out, for the sake of completeness, that accountability (Article 5.2 GDPR) is central to the GDPR. It is not the task of the supervisory authority to give advice regarding an individual case, certainly not if proceedings concerning precisely this case are pending before that same supervisory authority. 138. Thirdly, this complaint is precisely the result of the defendant's breaches of the

protection of the complainant's personal data. One of those breaches was the

unjustified restriction of the complainant's right of access, who was looking for the e-

mails that she had all missed because the defendant had not taken compliant

transparency measures towards her contacts and because the processing

continued after the defendant's legitimate interest had ended. The dilemma the defendant was therefore confronted with was caused entirely by his

own failure to monitor the complainant's mailbox and his limitations on her

right of access. The defendant could therefore have communicated more transparently with the complainant regarding the granting of access, which he did do in the submissions to the

Dispute Resolution Chamber, so that a settlement might have been

found, the complainant could have checked her missed emails and the

77

See paragraph 87 of this decision for this. Decision on the merits 101/2026 — 43/60

the defendant could have deleted the mailbox before a complaint was filed, in this case in

the spring of 2024.

139. Fourthly, the Disputes Chamber establishes that the defendant chose

to allow the mailbox to continue to exist in a deactivated state for the duration of these proceedings

and to link a license to this mailbox again, while technical possibilities

exist to export the contents of the mailbox to a PST file and to completely delete the mailbox itself. The defendant was aware of this technical possibility, because he

proposed it himself to the complainant on 6 April 2024. Although the personal data

would still be processed unlawfully, this technical measure would have substantially reduced the

risk of processing the complainant's personal data

and would have allowed the mailbox to be deleted already without restricting the complainant's right of

access, possibly in the future. 140. The Disputes Chamber rules that the continued processing of personal data without a legal basis for at least eight months is already sufficient grounds to assess the duration of the infringement as being of average severity. Given that the concerns of the complainant were clear from her communication, in particular that she wanted access to the emails she had missed, the defendant had the opportunity to stop and remedy these infringements, but chose to wait for a response from the GBA regarding a request for advice and the eventual outcome of this procedure. Due to this indecisiveness of the defendant, a situation has now arisen whereby the unlawfully processed personal data of the complainant (and her contacts) have already been processed for almost 3 years in an existing mailbox with an active license. The Disputes Chamber sees no grounds to reduce the average severity for the duration of the infringement to a low severity. 141. In his response to the sanction form, the defendant also states that the infringement was caused

by a one-off human error and that there was therefore no question of negligence

as the Dispute Chamber had stated. Moreover, the defendant had already taken proactive

measures to automate the deletion of the mailboxes and had

at the time of the hearing already added a validation step to the existing process to

verify whether all deactivated accounts were also deleted after one month.

142. As regards the intentionality or negligence of the infringements (criterion as

included in Article 83.2.b GDPR), there is no clear intent on the part of the

defendant to unlawfully process the complainant's personal data. The

moral element of the infringement has nevertheless been established on the basis of case law
78
of the CJEU. After all, negligence requires an element of awareness, but not

78 CJEU, Deutsche Wohnen SE v. Staatsanwaltschaft Berlin, judgment of 5 December 2023, C-807/21, ECLI:EU:C:2023:950,
paragraph 78. Decision on the merits 101/2026 — 44/60

element of will. This element of awareness is satisfied when the person addressed

should have known of a provision the criminal nature of his conduct, regardless of whether

he was aware of violating these provisions. The decisive factor is therefore

whether the person addressed could have known of a provision whether his conduct was unlawful and not whether
he was actually aware of it. A controller is

expected, within the framework of his duty of care, to inform himself and familiarize himself

with the legislation and obligations applicable to him. In this regard,

Articles 5.1a and 6.1 of the GDPR are very clear and specify that the defendant may only process

personal data if this processing is lawful and is therefore

based on one of the legal grounds listed in Article 6.1 of the GDPR.

143. The Disputes Chamber establishes that the defendant is aware of the management of

mailboxes of departed employees, of the continued processing of these mailboxes

under the legitimate interests of closing these mailboxes after one month.

It was already provided for in the 2016 management processes that the mailbox would remain for one
month and then be irrevocably deleted. Since the defendant was aware of these

rules regarding the closing of a mailbox, but these were not applied to the

mailbox of the complainant, there is already sufficient reason for the Disputes Chamber to speak

of negligence. 144. The Disputes Chamber also established that the list of deactivated profiles

dated June 1, 2023, on which the complainant was listed, included another profile,

whose profile, according to the list, had left the defendant on October 4, 2022, being 6 months before his profile was deactivated and passed on to be deleted.

145. Furthermore, the Disputes Chamber established that those same

management processes also involved a final step, namely the transfer

of the list of effectively deleted mailboxes by the competent service to the person who had requested the

deletion of the mailboxes. The applicant for the deletion, in this case the ‘ICT

second line service’, could therefore perform a monthly check on the effective deletion

by comparing the list of requests with the list of effectively deleted mailboxes.Moreover, following this check, the ICT second-line service was expected to set the account status to

‘removed’. Thus, not only was the defendant aware of the correct

closing of a mailbox, but there was also a control mechanism for this process, which

apparently was not applied at the time of the complainant's departure.

146. Finally, the defendant states that he had already started a change process in 2022

to automate the closing of the mailboxes, not least because

it involved approximately 1,000 profiles per year. Although the defendant had thus

established that he ran a risk by still performing this process manually and Decision on the merits 101/2026 — 45/60

although he had a procedure to monitor this process, the defendant

therefore failed to introduce a new, temporary control measure in 2022 or to apply the

existing control measure to avoid this risk of errors in the manual

process. The provisional solution that the defendant thus proposes as a
mitigating measure to avoid negligence and which was introduced at the time of the

hearing, in this case in November 2025, already existed in the

management processes in 2016 but was never applied, not even when the defendant

determines in 2022 that this process entails risks and should be automated

or when he determines that the complainant's mailbox has not been deleted in January 2024.

147. The Dispute Chamber rules that the defendant was negligent because he was aware

of the correct closing of a mailbox of a departed employee, but did not apply this

in the case of the complainant and rules that this negligence is of

moderate severity because he did not apply a control procedure existing since 2016 which could have prevented or at least noticed the

breach of the complainant's mailbox, not even temporarily when he initiated a procedure to this process to

automate or when the complainant informed him that her mailbox was not deleted as

it should be.

148. Based on an assessment of the above factors, the severity of the
infringement is determined. The Disputes Chamber takes into account that the infringement concerns a

fundamental principle of data processing that was

committed with negligence for a continuous period. The Disputes Chamber concludes that

this concerns an infringement of moderate severity. 149. In accordance with paragraph 60 of the EDPB Guidelines, the Dispute Chamber shall set the

base amount for further calculation at a point between 10 and 20

% of the applicable statutory maximum amount. Since the defendant had already initiated a

corrective procedure, the Dispute Chamber decides to set the

base amount at the lower end of the range. The Dispute Chamber will set the

base amount for further calculation at 10% of the statutory

maximum amount contained in Article 83.5 GDPR. 150. Regarding the infringement of Articles 12 and 13 GDPR (hereinafter ‘infringement of the

transparency obligation’)

a. Article 83.2(a) GDPR – The nature, seriousness and duration of the infringement:

151. Regarding the nature of the infringement, the Dispute Resolution Chamber notes that the defendant must ensure the

fair and transparent processing of personal data.

First, the complainant must at least be informed that data concerning her

are being (further) processed and for how long, so that she can potentially exercise control over this data Decision on the merits 101/2026 — 46/60

and processing. Secondly, the complainant's contacts, who share their

own personal data with the complainant, must be informed that the complainant

no longer has access to her mailbox and that their personal data will therefore no longer reach the complainant, so that they can stop sharing their

personal data via this channel. The Disputes Chamber rules that the nature of this

infringement is of high severity.

152. With regard to the severity of the infringement, the Disputes Chamber takes the following

elements into account:

• Nature of the processing: it concerns further processing of the

personal data in the complainant's mailbox in which both her personal data
and personal data of her contacts are processed. The initial processing

was transparent to both the complainant and her contacts. • Scope of processing: this concerns the further processing of

personal data in the complainant's mailbox and consequently her personal data,

but also the personal data of third parties who communicated with her. By not being

transparent about the termination of the collaboration with the complainant, the

volume of the personal data of the contacts increased unnecessarily. However, the complainant had

already scaled down her activities at the defendant, a fact of which the

complainant's contacts were already aware through the complainant's set out-of-office
messages. Due to the actions of the complainant, the volume was therefore already

limited, but due to a lack of transparency on the part of the defendant, the

volume was not further limited once the complainant no longer had control over her

mailbox.

• Purpose of processing: the purpose of the further processing of personal data

in the mailbox for a limited period consists precisely in

informing the complainant's contacts that the complainant was no longer employed by the defendant. Given the mix of personal data and commercially sensitive data in this

mailbox, the lack of transparency regarding this is problematic and

creates at least the perception of an additional purpose for further processing. Moreover,

internal documents of the defendant show that there was indeed an

additional purpose, namely the retrieval of commercially sensitive data

from the complainant's mailbox.

• Number of data subjects: this concerns the mailbox of 1 person, in which personal data

of the complainant and an unknown number of contacts were further processed.

• Extent of the damage: although damage is difficult to estimate in this case,

the complainant argues that she suffered at least reputational damage by leaving several e-mails unanswered, since she did not know that these e-mails

had been sent to her. With sufficient transparency, this potential

damage could have been minimized. However, there is no information indicating that the non-transparent further processing led to a misuse of the complainant's personal data. Given the professional context of the mailbox,

one can expect that this personal data is rather limited and non-sensitive,

although urgent, personal messages can also be expected in such a mailbox.

Moreover, the complainant herself had previously informed her correspondents that she was only accessible to a limited extent via that email address (for external parties) or no longer accessible (for internal parties).

Based on this assessment, the Disputes Chamber rules that the severity of the infringement is

of low weight, given that it concerns a professional context in which it can be expected

that no sensitive personal data were shared via this channel,

since the complainant herself had already informed her correspondents of her

limited accessibility and since it has not been demonstrated that misuse was made

of the personal data of the complainant or her contacts, which were not processed further in a transparent manner.

153. With regard to the duration of the infringement, the file shows that the complainant left the defendant on 1 May 2023 and that she received confirmation in January 2024 from the defendant's DPO that her data in her mailbox was continuing to be processed.

This confirmation was provided after she herself had requested this transparency. However, the complainant had already noticed in September 2023 that her mailbox was still active, without immediately contacting the defendant about this and thus obtaining transparency regarding this continued processing. Given the limited duration of the infringement, the Disputes Chamber considers the duration of the infringement to be of low severity.

b. Article 83.2.b) GDPR – The intentional or negligent nature of the infringement:

154. In this case no clearly evident intent on the part of the defendant has been established to

intentionally violate his duty of transparency, but there is at least negligence,

which satisfies the requirements of the case law of the Court of Justice of
79
the EU. Although the defendant argues that it concerned a one-off, human error,
it is clear from the decision that the defendant was negligent in the area of the

minimal technical and organisational measures, in particular the automation of

an out-of-office message, to ensure the transparency of further processing.

79 CJEU, Deutsche Wohnen SE v. Public Prosecution Service Berlin, judgment of 5 December 2023, C-807/21, ECLI:EU:C:2023:950, paragraph 78. Decision on the merits 101/2026 — 48/60

Moreover, it appeared that the defendant had already established this vulnerability and initiated a

improvement process in 2022, without, however, taking a minimum of provisional

measures to already address the vulnerability. It was only after the complaint that

the defendant initiated an initial check on the vulnerable procedure. The
file also shows that the defendant was aware of previous decisions of the

Dispute Resolution Chamber regarding the correct, and therefore transparent, continued processing of the mailbox

of a former employee. Given that the defendant himself speaks of approximately 1,000

departing employees per year, he should have taken sufficient measures

earlier and sooner to rule out any human error. The Disputes Chamber

rules that the negligent nature of the infringement must be
considered to be of average severity.

c. Article 83.2(g) GDPR – The categories of personal data to which the infringement relates:

155. The disputed processing concerns the personal data of the complainant and of her contacts in her professional mailbox. Although prima facie such personal data are not of a sensitive or special nature, the Dispute Resolution Chamber rules that they nevertheless belong to categories of personal data which data subjects would generally not reasonably expect to be further processed by the defendant. This category is assessed as neutral.

156. The severity of the infringement is determined on the basis of an assessment of the above factors. The Dispute Resolution Chamber takes into account that the transparency of the processing is fundamental to a data subject. A data subject must know that his personal data are being (further) processed before he can exercise any control over this processing. However, this concerns a further processing of personal data
where the initial processing was fully transparent and it concerns the processing of

personal data in a professional context, where it can be expected that the

data subjects do not exchange sensitive personal data. Moreover, the complainant

had already set up two out-of-office messages herself that made it clear that she was only reachable to a limited extent (for external parties) or no longer reachable (for internal parties) via that e-

email address. The Disputes Chamber concludes that this concerns an infringement of minor severity.

157. In his response to the sanction form, the defendant states that he agrees with this

conclusion, although he refers to his earlier

comment for the assessment of the negligence. 158. In accordance with paragraph 60 of the EDPB Guidelines, the Dispute Chamber shall determine the

base amount for further calculation at a point between 0 and 10% of the applicable statutory maximum amount. Since the defendant had already initiated a

corrective procedure, the Dispute Chamber decides to determine the

base amount at the lower end of the range. The Dispute Chamber will determine the

base amount for further calculation at 1% of the statutory

maximum amount contained in Article 83.5 GDPR.

The defendant's turnover shall be taken into account as a relevant element of the calculation with a view to

imposing an effective, deterrent and proportionate fine pursuant to

Article 83.1 GDPR.

159. In accordance with Article 83.1 of the GDPR, the Dispute Resolution Chamber must ensure that the administrative fines imposed are effective, proportionate, and dissuasive. Thus, it also reflects a distinction based on the size of the undertaking in the initial amounts.

160. Articles 83.4 to 83.6 of the GDPR stipulate that the total worldwide annual turnover of the preceding financial year must be used for the calculation of the administrative fine. In this regard, the term “previous” must be interpreted in accordance with the case law of the Court of Justice in competition law, so that the relevant event for the calculation is the decision to fine the supervisory authority, and not the time of the sanctioned infringement. 161. In calculating the fine in the sanction form, the Dispute Chamber based its calculation on the annual turnover of 2024, as that of 2025 was not yet known. However, the defendant confirmed in his response to the sanction form that the annual turnover for 2025 amounted to EUR 804,

302,737.71. The Dispute Chamber proceeds to calculate using this turnover figure.

162. Based on the foregoing, the Dispute Chamber establishes that 4% of the turnover in the
preceding financial year amounts to EUR 32,172,109.51, which is higher than EUR 20,000,000.

Thus, the maximum total administrative fine in accordance with

Article 83.5 GDPR amounts to EUR 32,172,109.51. In concrete terms, this leads to the following

base amount:

• regarding the infringement of lawfulness, the Dispute Resolution Chamber set the

base amount for further calculation at 10% of the statutory

maximum amount included in Article 83.5 GDPR. In this case, this leads to a

base amount of EUR 3,217,210.95;

• regarding the infringement of the transparency obligation, the Dispute Resolution Chamber set the

base amount for further calculation at 1% of the statutory

maximum amount included in Article 83.5 GDPR. In this case, this leads to a

base amount of EUR 321,721.10.

The base amount for the total administrative fine is EUR 3,538,932.15. Decision on the merits 101/2026 — 50/60

163. In accordance with the EDPB Guidelines, the Dispute Chamber rules that a

further adjustment of this baseline amount based on the defendant's turnover is not

appropriate.

III.2.3. Aggravating and mitigating circumstances

164. Under the GDPR, the supervisory authority, after having made an assessment

of the nature, seriousness and duration of the infringement, the intentional or negligent nature

of the infringement and the categories of personal data to which the infringement relates (see above), must take into account the other aggravating and mitigating

factors referred to in Article 83.2 GDPR. For reasons of

efficiency, the Dispute Chamber will make this assessment for both infringements together.

• Article 83.2.c) GDPR – The measures taken by the controller or processor

to limit the damage suffered by the data subjects:

The Dispute Chamber establishes that the defendant communicated immediately with the

complainant as soon as the latter had expressed her concerns. A proper out-of-office

was set up so that the contacts were informed of the

complainant's departure. These constitute mitigating circumstances. • Article 83.2.d) GDPR – The extent to which the controller or the

processor is responsible in view of the technical and organisation

measures which he has implemented in accordance with Articles 25 and 32 GDPR:

The Dispute Chamber established in its decision that the correct further processing

of the personal data of departing employees and the closing of the

mailbox and deletion of this personal data was a manual process, in which

one can expect that this process, given the state of the art and the scale of

the defendant, would proceed fully automated, which would

exclude human errors. The defendant had already started

automating this procedure one year before the complainant's departure, which, however, was still not in force at the

time that the complainant discovered the further processing. The Dispute Chamber

rules that the fact that the defendant had already initiated a procedure for
automating the process is a mitigating circumstance. • Article 83.2(e) GDPR – Previous relevant infringements by the

controller or processor:

80EDPB–Guidelines 04/2022 on the calculation of administrative fines under the GDPR(v2.1, 24 May 2023),
paragraph 70. Decision on the merits 101/2026 — 51/60

No previous, relevant infringements have been established on the part of the defendant, as regards a

mitigating circumstance.

• Article 83.2.f) GDPR – The extent to which cooperation with the supervisory authority has taken place

to remedy the infringement and to limit the possible negative consequences

thereof:

Not applicable

• Article 83.2.h) GDPR – The manner in which the supervisory authority became aware

of the infringement, in particular whether, and if so to what extent, the

controller or processor reported the infringement:

The DPA became aware of the infringement through a complaint.

• Article 83.2.i) GDPR – Compliance with the measures referred to in Article 58, paragraph 2,

insofar as these have previously been taken with regard to the controller or

processor in question in relation to the same matter:

Not applicable.

• Article 83.2.j) GDPR – Adherence to approved codes of conduct in accordance with

Article 40 or to approved certification mechanisms in accordance with Article

42:

Not applicable. • Article 83.2.k) GDPR – Any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial gains made or losses avoided, whether or not directly resulting from the infringement:

There is no information in the file indicating that the unlawful and non-

transparent further processing of the personal data of the complainant and her contacts

has yielded any benefit to the defendant, which indicates a mitigating
circumstance.

165. The Dispute Chamber takes into account that the defendant's DPO responded immediately

to the complainant's concerns, that the defendant had already initiated a

procedure to automate the management of the mailboxes, that there were no

previous complaints against this defendant, although it concerns a large, diffuse organization

, and that no information in the file indicates that the defendant would have derived any

benefit from these infringements. These circumstances are assessed as

mitigating circumstances.

166. The Disputes Chamber decides Decision on the merits 101/2026 — 52/60

• to reduce the base amount of EUR 3,217,210.95 for the infringement of lawfulness

by 95%, resulting in a reduction from EUR 3,056,350.40 to EUR 160,

EUR 860.55.

• to reduce the base amount of EUR 3,217,21.10 for the infringement of the transparency obligation

by 95%, resulting in a reduction from EUR 305,635.01 to EUR 16,

EUR 086.06.

167. The Disputes Chamber concludes that no other circumstance is of such relevance that

it should be taken into account as an aggravating or mitigating circumstance.

III.2.4. Alignment with the maximum amount

168. The maximum amount for both fines combined in the present case has already been calculated above.

This amounts to 2,000,000 EUR in accordance with Article 83.5(a) GDPR or to 4% of the total worldwide annual turnover in the preceding financial year, if this figure is higher.

169. The defendant's annual turnover for 2025 amounts to EUR 804,302,737.71. The

Dispute Chamber establishes that 4% of the annual turnover in the preceding financial year amounts to EUR 32,172,109.51, which is higher than EUR 20,000,000. Thus, the

maximum administrative fine in accordance with Article 83.5 GDPR amounts to EUR 32,172,109.51.

EUR.

170. In this case, the two fines amount to EUR 1,608,60.55 and EUR 1,608,606.06 respectively,

resulting in a total fine of EUR 176,946.61, which is below the maximum

fine of EUR 32,172,109.51.

III.2.5. Effectiveness, reasonableness and deterrent effect

Effectiveness

171. Recital 148 of the GDPR emphasizes that administrative fines must be

imposed “[with] a view to the stronger enforcement of the rules of this

Regulation”. The fine imposed must therefore be high enough to achieve this

objective.

Given the defendant's annual turnover, the total fine amounts to just above

0.02% of this annual turnover and therefore appears less effective. The Disputes Chamber is

however, of the opinion that imposing a limited fine can in itself be effective,

certainly in the case of a first offense. Decision on the merits 101/2026 — 53/60

The Disputes Chamber considers that the total fine of EUR 176,946.61 in this case

is suitable to vigorously enforce the fundamental principles that were infringed.

Proportionality

172. The principle of proportionality entails that the amounts of the fines must not be

disproportionate to the objectives pursued and that the imposed
fine must be proportionate to the infringement, viewed as a whole, with due regard to

in particular its seriousness.

173. In this case, the infringements in question were assessed as being of low and medium severity. In accordance with paragraph 60 of the EDPB Guidelines, the

Dispute Chamber shall:

• in the case of minor infringements, set the baseline amount for further calculation

at a point between 0 and 10% of the applicable statutory

maximum amount. The Dispute Chamber notes that the defendant had already initiated an

adjustment procedure. Therefore, it set the baseline amount

for further calculation at 1% of the statutory

maximum amount contained in Article 83.5 GDPR.

• in the case of minor infringements, set the baseline amount for further

calculation at a point between 10 and 20% of the applicable

statutory

maximum amount. The Dispute Chamber notes that the defendant had already

initiated an adjustment procedure. Therefore, the Dispute Chamber set

the baseline amount for further calculation at 10% of the statutory

maximum amount contained in Article 83.5 GDPR. 174. Moreover, the Disputes Chamber took into account as mitigating circumstances

that the defendant's DPO responded immediately to the complainant's

concerns, that the defendant had already initiated proceedings to

automate the management of the mailboxes, that there were no prior complaints against this

defendant, although it concerns a large, diffuse organization, and that no

information in the file indicates that the defendant would have derived any benefit

from these infringements. On the basis of these mitigating circumstances, the

Disputes Chamber reduced both fines by 95%.

175. The Disputes Chamber rules that the fine is proportionate.

176. In his response to the sanction form, the defendant states that the proposed fines

are absolutely not proportionate because they allegedly do not take into account:

• the fact that access to the complainant's mailbox was restricted; Decision on the merits 101/2026 — 54/60

• the duration of the proceedings before the DPA and the lack of a response to the

defendant's request for advice to the DPA, as a result of which the defendant was compelled by the

request of the complainant to retain the alleged infringements;

• the defendant's strict compliance with the GDPR, his prompt responses and his

cooperative attitude;

• the fact that the alleged infringements constitute only a one-off infringement and

• the fact that the defendant has already proactively

automated the deletion of the mailboxes.

177. With regard to the restriction of access to the mailbox, the Disputes Chamber has already

established earlier in the decision that the defendant does not demonstrate this restriction, although

he is capable of doing so and he could also have exported the mailbox and stored it separately,

without it having to remain in existence deactivated with a license at the processor, in

this case the defendant's mail provider. The risk of a still existing mailbox with

a license is immeasurably greater for the data in the mailbox, including the

personal data of the complainant and her contacts, than an exported and protected

stored file. Moreover, the mailbox remained available to the

defendant, albeit with a strict procedure that had to be followed for any

access, while the complainant had no control over this whatsoever and of which it has been established

that her right of access to this mailbox was also limited. The Disputes Chamber also takes

account of the fact that the mailbox should have been deleted as early as June 1, 2023 in order to

consider that the fine is proportionate to the complainant's complete loss of control

over her personal data in the mailbox held by the defendant and the risk that remains

existing on the personal data in this deactivated mailbox with limited access.

178. Regarding the duration, the Disputes Chamber has already previously addressed the remarks

of the defendant. The continued processing of various personal data of the complainant

and her contacts without legal basis for a period of nearly a year before the

defendant proposes to export these to a file, which ultimately does not

happen, causing the mailbox to continue to exist to this day, is proportionate to

the amount of the fine.

179. Regarding the strict compliance with the GDPR by the defendant, the Dispute Resolution Chamber establishes

in this file alone breaches of lawfulness, transparency, the

technical and organizational measures to guarantee the principles of the GDPR,

the right of access and the principle of confidentiality and integrity in conjunction with the accountability principle. Moreover, the Dispute Resolution Chamber has no

insight into any other processing of personal data by the defendant, making it impossible for it to take this compliance into account in order to potentially

adjust the amount of the fine, upwards or downwards.

Decision on the merits 101/2026 — 55/60 180. Regarding his prompt responses, the Disputes Chamber points out to the defendant the

mitigating circumstances, in which the DPO's response to the complaint was

taken into account in the assessment to reduce the fine by 95%.

181. Regarding the cooperative attitude, the Disputes Chamber judges this attitude to be

neutral, without further ado, and sees no reasons to increase or decrease the amount of the fine on the basis of this

argument.

182. Regarding the fact that these infringements constitute the first infringement established
by the Disputes Chamber, it points out to the defendant the mitigating circumstances,

in which the fact that no prior complaints were filed against the defendant was

taken into account in the assessment to reduce the fine by 95%. 183. Regarding the fact that the defendant had proactively initiated and carried out the automation of closing the mailboxes, the Disputes Chamber points to the mitigating circumstances, in which the fact that the defendant had already initiated proceedings was taken into account in the assessment to reduce the fine by 95%.

184. The Disputes Chamber is aware of the magnitude of the absolute amount of the fine in this case, but in relation to the defendant's annual turnover, it considers this fine to be rather on the low side, specifically only 0.02% of his annual turnover.

Deterrent effect

185. When imposing a monetary fine, the Disputes Chamber takes into account both the specific and the general deterrent effect. A monetary fine is deterrent when the fine prevents a private individual from violating the objectives and regulations contained in EU law. 186. The deterrent nature of the fine must have two dimensions. It must deter the

person to whom the fine is imposed from repeating the infringement in the future,

but it must also deter other persons from repeating the infringing

behavior of the first person.

187. Various factors determine the deterrent effect of a fine: the nature and the

amount of the fine and the likelihood that the fine will be imposed are decisive in this

respect. A fine must be high enough to have a significant financial

impact on the undertaking committing the infringement, while the fine must be proportionate

to the seriousness of the infringement. In other words, the criterion of

deterrence overlaps with that of effectiveness. It is important that undertakings

cannot make a financial profit on the basis of unlawful processing of

personal data.

188. In the present case, the total fine is low relative to the turnover of the

defendant. However, given its absolute amount, the fine amount remains sufficiently

deterrent to prevent the defendant from repeating its infringement of the GDPR rules. Moreover, it is also intended to deter other undertakings from committing

similar infringements. This fine, which is proportionate to the severity of the infringement

and takes into account the turnover of the defendant, is intended to have both a specific

and a general deterrent effect.

189. In his response to the sanction form, the defendant states that the fine has no

specific deterrent effect on him because all measures have already been

taken to avoid future similar infringements. The defendant also refers

to the judgment of the Market Court of 22 January 2025, which concerned a

specific, isolated violation caused by negligence and was not

81 82
the result of an intentional act. The Disputes Chamber reiterates that an administrative fine is not intended to bring the processing into conformity with the principles of the GDPR, for which corrective measures have already been imposed, but rather to guarantee robust enforcement of the rules of the GDPR, both towards the defendant and towards other controllers in a similar situation. Regarding the reference to decision 2024/AR/1615 of the Market Court, the Disputes Chamber points out that

• the imposition of an administrative fine is an assessment of expediency that the Disputes Chamber must make in full jurisdiction based on the concrete elements of the case;

• five different infringements were established within the scope of this complaint, of which an administrative fine is imposed for only two infringements and

The Disputes Chamber sees no reason to adjust the amount of the fine based on these arguments of the defendant. 190. The totality of the elements set out above justifies an effective,

proportionate and deterrent sanction as referred to in Article 83 GDPR, taking into account

the assessment criteria set out therein. The Dispute Resolution Chamber points out that the

other criteria of Article 83.2 GDPR are in this case not of a nature to lead to a

81Piece 39, Defence of [respondent] of 24 April 2026, p. 19, paragraph 12.

82See paragraph 106 of this decision for this. Decision on the merits 101/2026 — 57/60

an administrative fine other than that which the Dispute Resolution Chamber has imposed in the context of

this decision. Decision on the merits 101/2026 — 58/60

IV. Publication of the decision

191. In view of the importance of transparency regarding the decision-making of the

Dispute Chamber, this decision is published on the website of the

Data Protection Authority. However, it is not necessary for the

identification details of the parties to be disclosed directly for this purpose. Decision on the merits 101/2026 — 60/60

Pursuant to Article 108, § 1 of the WOG, an appeal against this decision may be lodged with the Market Court (Brussels Court of Appeal) within a period of thirty days from the

notification, with the Data Protection Authority as defendant. Such an appeal may be lodged by means of a petition in opposition which must contain the particulars listed in Article 1034ter of the Judicial Code. The 83

petition in opposition must be submitted to the registry of the Market Court

in accordance with Article 1034quinquies of the Judicial Code, or via the Justice e-Deposit

information system (Article 32ter of the Judicial Code).

(Signed). Hielke H IJMANS

Director of the Disputes Chamber

83 The petition shall state, under penalty of nullity:

1° the day, the month and the year;

2° the name, first name, place of residence of the petitioner and, where applicable, his capacity and his national register or
enterprise number; 3° the name, first name, place of residence and, where applicable, the capacity of the person to be summoned;

4° the subject matter and a brief summary of the grounds of the claim;

5° the judge before whom the claim is brought;

6° the signature of the petitioner or of his lawyer.

84 The petition with its annex shall be sent, in as many copies as there are parties concerned, by registered mail
to the registrar of the court or deposited at the registry.