APD/GBA (Belgium) - 101/2026
| APD/GBA - 101/2026 | |
|---|---|
| Authority: | APD/GBA (Belgium) |
| Jurisdiction: | Belgium |
| Relevant Law: | Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 5(1)(c) GDPR Article 5(1)(e) GDPR Article 5(1)(f) GDPR Article 5(2) GDPR Article 6(1) GDPR Article 6(1)(f) GDPR Article 12 GDPR Article 13 GDPR Article 15 GDPR Article 24 GDPR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | |
| Decided: | 12.05.2026 |
| Published: | |
| Fine: | 176,946.61 EUR |
| Parties: | n/a |
| National Case Number/Name: | 101/2026 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Dutch |
| Original Source: | APD (in NL) |
| Initial Contributor: | dalja10 |
The DPA fined a tech company a total of €176,946.61 for unlawfully keeping active the email account of a contractor after they left the company and for transparency obligation infringements. The DPA also ordered the company to comply with the contractor's access request, provide access logs, delete the personal data afterwards and take measures to ensure future compliance.
English Summary
Facts
An independent contractor (the data subject) used to be a part of the ‘extended workforce’ of a tech company (the controller) and had a professional email address on the controller’s domain.
The data subject ceased collaboration with the controller in May 2023 but, in the fall of the same year found out that their professional email address was still active.
The data subject contacted the controller in January 2024, informed them that the email address was still active and that the out-of-office message was misleading. Subsequently, they requested access to the emails received in the meantime. In addition, the data subject requested proof that no one accessed their mailbox after April 2023. In response, the controller offered access to the email account on its premises under supervision.
The data subject filed a complaint with the DPA.
Holding
The DPA acknowledged that the email account may contain both personal and business data and noted that there were three successive phases regarding the processing of personal data in the mailbox.
During the first phase (the collaboration), personal data were processed under Article 6(1)(b) GDPR within the framework of the agreement between the two parties.
In the second phase, the DPA found that, immediately after the end of the collaboration, the controller had a legitimate interest under Article 6(1)(f) GDPR for keeping the email account active for up to one month in order to inform the data subject’s contacts of the departure from the company and to provide a new contact point.
In addition, the DPA explained that the end of the collaboration meant, among other things, a change in the purpose and legal basis for the processing of personal data in the data subject’s mailbox, a change in the recipient of the emails and a loss of control for the data subject over the personal data in the mailbox. Since neither the data subject, not their contacts were informed about these changes, the DPA held that the controller breached Article 12 GDPR and Article 13 GDPR by failing to comply with its transparency obligations in relation to the data subject and their contacts after the data subject’s departure from the company.
In the third phase, after 1 June 2023, the DPA held that the controller breached Article 5(1)(a) GDPR in conjunction with Article 6(1) GDPR by continuing to process personal data without a legal basis since the controller no longer had a legitimate interest for keeping the mailbox active.
Furthermore, the DPA held that the controller also violated Article 5(1)(b) GDPR (‘purpose limitation), Article 5(1)(c) GDPR (‘data minimisation’) and Article 5(1)(e) GDPR (‘storage limitation’) by continuing to process personal data after 1 June 2023.
Moreover, the DPA found that the controller failed to take, or demonstrate that it had taken, sufficient technical and organizational measures to delete the data subject’s mailbox due to a lack of legal basis, thus violating Article 24 GDPR.
In addition, the DPA held that the controller failed to take appropriate measures to facilitate the data subject’s access right and limited their right without justification to emails without an out-of-office reply, thus violating Article 12 GDPR and Article 15 GDPR.
Specifically, the controller only allowed access to emails received from external (non-company) contacts starting from 1 May 2023 for the protection of trade secrets and because internal contacts received out-of-office messages in reply.
While the data subject did indeed only ask for access for the nine months after their departure, the DPA found that the limitation to external emails was unjustified since receiving an out-of-office message was not a criterion to restrict the right to access and because the controller could have filtered out sensitive business data prior to the data subject’s access. However, the DPA considered the exercise of the access right on the controller’s premises a proportionate measure due to the possible presence of trade secret in emails.
Finally, the DPA found violations of Article 5(1)(f) GDPR and Article 5(2) GDPR since the controller failed to demonstrate compliance with the principle of confidentiality and integrity. The DPA noted that the controller failed to prove that no one accessed the data subject’s mailbox after their departure from the company since the controller only presented log files for the period between 22 July 2024 and 20 August 2024.
Therefore, the DPA fined the controller €160,860.55 for the infringement of Article 5(1)(a) GDPR in conjunction with Article 6(1) GDPR and €16,086.06 for infringing of Article 12 GDPR and Article 13 GDPR.
The DPA also ordered the controller to bring its processing activities in compliance in relation to the mailboxes of employees and contractors when departing from the company in light of the violation of Article 24 GDPR.
Moreover, the DPA ordered the controller to comply with the data subject’s access request, delete their personal data afterwards and provide them with a record of access to their mailbox or demonstrate that the data is no longer available.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Dutch original. Please refer to the Dutch original for more details.
Decision on the merits 101/2026 — 2/60
I. Facts and procedure
1. The subject matter of the complaint concerns the closure of an employee's professional
mailbox in non-GDPR compliance following her departure from the defendant. As an independent consultant, the complainant falls under the category of employee or collaborator of the
defendant, more specifically within the category of the
2
defendant's ‘extended workforce’.
2. On 23 April 2024, the complainant lodged a complaint with the Data Protection Authority
against the defendant.
3. On 26 April 2024, the complaint was declared admissible by the Primary Care Service on the basis
of Articles 58 and 60 of the WOG and the complaint was transferred to the Disputes Chamber on the basis of Article 62, § 1 WOG.
4. On 21 May 2024, the Disputes Chamber decided pursuant to Article 95, § 1, 1° and Article 98
WOG that the file was ready for substantive consideration and the parties concerned were notified by registered mail of the provisions referred to in
Article 95, § 2, as well as those in Article 98 WOG. They were also notified pursuant to Article
99 WOG of the time limits for submitting their defenses.
The parties were requested to submit their defenses regarding the following
alleged violations:
• Violation of Article 5.1.a) read in conjunction with Article 6.1 of the GDPR due to the lack
of a legal basis to keep the complainant's mailbox active after 1 month following the
departure of the complainant;
• Violation of Article 5.1.b), Article 5.1.c) and Article 5.1.e) of the GDPR due to a
violation of the principle of purpose limitation in combination with data minimisation and
storage limitation of the personal data in the complainant's mailbox after 1 month
following the complainant's departure;
• Violation of Article 12 and Article 13 of the GDPR due to failure to provide
the necessary information regarding the processing of his personal data in the
complainant's mailbox after 1 month following the complainant's departure;
• Violation of Article 24 and Article 25 of the GDPR due to the lack of adequate
technical and/or organisational measures to properly manage and close the complainant's mailbox
during or after his departure;
2
Piece 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 135. Decision on the merits 101/2026 — 3/60
• Violation of Article 12 and Article 15 of the GDPR due to the failure to grant
access to the complainant's mailbox and due to the failure to provide a copy
of the complainant's mailbox;
• Violation of Article 5.1(f) read in conjunction with Article 5.2 of the GDPR due to the failure to sufficiently
demonstrate that the confidentiality of the personal data in the
complainant's mailbox was guaranteed after 1 month following the complainant's departure.
II. Reasoning
II.1. Description of the processing and the complaint
5. The complainant was employed by the respondent as an independent consultant. The defendant is
a high-profile Belgian tech company with a high turnover of employees, who
are either part of the company as internal employees or part of its
‘extended workforce’. In order to carry out her activities at the defendant,
the complainant, as a member of the ‘extended workforce’, had been assigned a unique identifiable professional e-
mail address on the defendant’s email domain. A few weeks
before her effective departure from the defendant, the complainant phased out her activities at the
defendant; She had set up two out-of-office messages for this purpose, in which she informed the defendant's internal employees that she was no longer reachable at this email address and redirected them to her personal email address, and in which she alerted the external contacts attempting to contact her that she would only check her email sporadically: “[…] I am currently offline with very limited internet access. Please accept some delay in my reply. […] .4
6. On May 1, 2023, the complainant permanently left the defendant. In the autumn of 2023, the complainant learned from various contacts that they had contacted her via her professional email address at the defendant, which appeared to still be functional.
7. On January 24, 2024, the complainant contacted the defendant to draw his attention to the fact that her professional email address was still active and to request access to the e-
mails that had arrived at this email address in the meantime. The defendant subsequently
placed an out-of-office message on the complainant's mailbox himself and offered
to grant access to the e-mails that arrived after her departure from the external
contacts in the premises and under the supervision of a neutral person, in order to be able to protect any
confidential or commercially sensitive information.
3 Document 18, the summary conclusion of [defendant] of 27 August 2024, paragraph 135.
4 Document 2, Complaint form of 19 April 2024, appendix p. 2. Decision on the merits 101/2026 — 4/60
8. Finally, the complainant also requested proof from the defendant that no one had consulted her mailbox
after she had left, as she suspected that certain e-
mails had not been logged and certain emails had been opened.
9. The complainant's counsel concluded the complaint with the following request to the GBA:
“I kindly request you to assess the current situation and to assist my client in
obtaining access to and a copy of the requested data, including the
correspondence she has received at her non-deactivated email address since
April 2023 and information about who has accessed her email account since April
2023. The email address was unlawfully kept active, and the available out-of-
office message was clearly misleading, suggesting that my client was still working at
[defendant]. She has the right to gain access to the said data
and to receive information regarding the use of her personal data and identity
by the company without her consent since the termination of her cooperation
with [defendant]. […] Therefore, my client’s suspicion that the email address was intentionally not deactivated is not unfounded. […]” .
II.2. Description of the processing of personal data in the complainant's mailbox
10. The Disputes Chamber establishes that the complainant was employed as an independent consultant at
the defendant until 1 May 2023 and, for her position, had access to an email address
of the type ‘firstname.lastname@defendant.be’. The mailbox linked to this email address
undeniably contains personal data of a uniquely
identifiable person within the meaning of Article 4.1 GDPR. The purpose of such a
type of mailbox is to allow the complainant to communicate within the framework of her cooperation
with the defendant.
11. Such a
type of mailbox is therefore inevitably a mix of
personal data of the unique user of the email address, of business-essential data, and of
personal data of correspondents of the unique user, such as:
• communication of personal data that falls within the
cooperation of the employee with the employer, such as, for example, leave requests to HR,
meeting requests with the confidential counsellor, evaluation reports, reports
of performance reviews, consultation with a colleague, team meetings,
hospitalisation insurance, etc.;
• communication that falls within the scope of the employee's function and business operations
such as contact with customers and suppliers, contributions to projects, quotations,
5
Document 2, Complaint form of April 23, 2024, p. 4. Decision on the merits 101/2026 — 5/60
contracts, etc. This communication may also contain commercially sensitive or
confidential data and possibly data protected by the intellectual property of the
company;
• communication that falls within the purely private life of the employee such as, for example,
arrangements with the employee's partner regarding the collection of the
children, any urgent appointment with the garage, etc. and
• personal data of third parties communicating with the unique user of the
mailbox, in this case the employee, such as, for example from a colleague (who is celebrating his/her birthday), the partner (because he/she has had car damage and will be home later), a specific correspondent of the person concerned (due to his/her dismissal), etc.
12. In such a type of mailbox, these personal data are sent to or from the employee's email address, after which they are received in the mailbox, stored there, organized, and can be filtered, sent, stored, printed, and deleted. These personal data are therefore inevitably processed within the meaning of Article 4.2 GDPR.
13. In the context of defining the scope of the complaint and to clarify this decision,
the Disputes Chamber establishes that there are 3 consecutive phases regarding the
processing of the personal data in the complainant's mailbox. These phases are
distinguished on the basis of the purpose and the legal basis of the processing.
II.2.1. Phase 1: during the cooperation
14. During the formal cooperation between the complainant and the defendant, the purpose of the
processing of the personal data in the mailbox is to communicate with internal and
external contacts within the framework of her agreement with the defendant, which immediately
also constitutes the legal basis for the processing in accordance with Article 6.1.b GDPR. 15. Regarding this communication, the Disputes Chamber refers to the Barbulescu case, in which the European Court of Human Rights (hereinafter ‘ECtHR’) ruled that “The
instructions of an employer may not reduce private life in the workplace to zero.
Respect for private life and for the confidentiality of the
correspondence remains” 6 (free translation by the Disputes Chamber) and thus “the
communication in the applicant’s workplace fell under the concepts of “private life” and
“correspondence” (free translation by the Disputes Chamber). The employee also has on
6
ECtHR, Case of Barbulescu v. Romania, 61496/08 of 5 September 2017, paragraph 80: “an employer’s instructions cannot
reduce private social life in the workplace to zero. Respect for private life and for the privacy of correspondence continues to
exist […]”.
7Ibid, paragraph 81: “the applicant’s communications in the workplace were covered by the concepts of “private life” and
“correspondence”. Decision on the merits 101/2026 — 6/60
the workplace the right to lead a private life and to enter into social contacts that
fall within the private sphere. This judgment confirms that the defendant cannot avoid that
personal correspondence also takes place via this e-mail address and this mailbox.
16. In her complaint and her conclusions, however, the complainant also mentions certain
sensitive communications regarding her expertise as a public figure, which go beyond
her assignment with the defendant. Given that this communication did not strictly fit
within the framework of the cooperation between the complainant and the defendant, given that this communication
also does not fall under the private social life of the complainant and given the sensitivity of
this correspondence, which apparently also had to be shielded from the defendant
(“She did her utmost to guarantee their confidentiality, despite the high
10
pressure from the media and the Defendant”), the Dispute Chamber rules that this specific
communication did not belong in the complainant's mailbox on the domain of the
defendant and the Dispute Chamber considers this specific, sensitive communication
no different from the other personal data processed in the complainant's mailbox.
II.2.2. Phase 2: immediately after the termination of the cooperation between the complainant and the
defendant
17. The complaint concerns the continued processing of personal data in the mailbox after the
cooperation, and thus the contract, between the complainant and the defendant was terminated. 11
Here too, the Disputes Chamber has already ruled in previous decisions that
such further processing can be lawfully based on the legitimate
interest of the employer, in this case the defendant, in accordance with Article 6.1.f GDPR.
18. As clarified in these previous decisions of the Disputes Chamber, this
legitimate interest is a priori limited to a duration of 1 month. A possible
extension of this duration by two months could be accepted, provided that a
clear balancing of interests substantiates this extension. In this balancing of interests,
it must be taken into account that the complainant has already left some time ago and no longer has any control
over her, sometimes sensitive, personal data in the mailbox in question.
8Piece 2, Complaint form of 23 April 2024, p. 3: “Since the email was not deactivated, very sensitive data was sent to this account, and it is of great importance to my client that this information be removed from [defendant]’s servers.”
9 Appendix Complete_with_Docusign_20240730_[complainant] to document 16, Conclusions and documents, paragraph 48: “Since Concluante is XXX, individuals and organizations entrust sensitive and confidential information to her. […] For example,
at the time of her departure, Concluante was involved in a very sensitive case relating to YYY. […] She did her utmost to guarantee their confidentiality, despite the high pressure from the media and the Defendant. Obtaining proof that her account has not been accessed and being able to remove all personal data and sensitive data of others from that account is essential for her as an individual and as an ethical and trustworthy professional.” 10Piece 16, Conclusions + Complainant's documents of 2 August 2024, paragraph 48.
11
Said inter alia decision 64/2020 of 29 September 2020, decision 133/2021 of 2 December 2021, decision 138/2024 of 19
November 2024, decision 134/2025 of 21 August 2025, decision 01/2026 of 6 January 2026. Decision on the merits 101/2026 — 7/60
19. Given the inevitable mix of personal data and business data in the mailbox,
it is prohibited for the defendant to gain further access to this mailbox
to consult business-necessary data, since he would then inevitably also
gain access to the personal data and private communications of the complainant (and
her contacts). In this context, the Disputes Chamber points out:
• Article 124 WEC: “Unless permission has been obtained from all
other persons directly or indirectly involved, no one may:
1° intentionally become aware of the existence of information of any kind that has been
sent electronically and that is not intended personally for him;
[…]
4° modify, delete, disclose, store or make any use of the information, identification or data that were
obtained intentionally or unintentionally.”
• Article 314bis of the Penal Code: “§ 1 He who:
1° [either, intentionally, by means of any device, intercepts or causes to be intercepted communication in which he does not participate,
takes notice of or causes to be taken, records or causes to be recorded, without the
consent of all participants in that communication;]
[…]
§ 2 He who knowingly keeps in his possession, reveals or disseminates to another
person, or knowingly makes any use of the content of communication not accessible to the public
or data from an information system that has been unlawfully intercepted or recorded
or of which knowledge has been unlawfully obtained, shall be punished
with [imprisonment of six months to three years] and with a fine of
five hundred euros to twenty thousand euros or with one of those penalties information obtained in this way
[...]”
20. Only on the basis of a sound data protection policy by design of
professional mailboxes, in which an effective distinction is made between
personal data/private communication on the one hand and business data/
business communication on the other hand, which can be technically
distinguished and filtered upon the departure of an employee, can the necessary business data
still be retrieved from these professional mailboxes in phase 2 without affecting the Substantive Decision 101/2026 — 8/60
personal data of the ex-employee. The only other option to recover the
business data in this phase consists of obtaining permission
from the ex-employee to consult the mailbox and to be able to extract the business data
from it. It is for this reason that Recommendation CM/Rec(2015)5 of the
Committee of Ministers of the Member States of the Council of Europe clearly states upon the departure of an
employee: “If employers need to recover the contents of an
employee's account for the efficient management of the organization, they should
12
do this before his or her departure and, where possible, in his or her presence. “
(free translation by the Dispute Chamber).
II.2.3. Phase 3: one month after the termination of the cooperation between the complainant and the
defendant
21. One month (or, subject to a clearly substantiated extension, up to a maximum of 3 months) after
the effective end of the cooperation, the personal data in the
complainant's mailbox, including the
email address itself, are no longer necessary and must be permanently deleted in accordance with the
principle of purpose limitation of Article 5.1.b GDPR and the
minimum data processing of
Article 5.1.c GDPR. Given the inevitable mix of
personal and business data in the mailbox, in practice this usually means
the permanent deletion of the entire mailbox.
II.3. Violation of Article 5.1(a) read in conjunction with Article 6.1 of the GDPR due to the lack of
a legal basis to keep the complainant's mailbox active after 1 month following the
departure of the complainant
22. Article 6 of the GDPR prescribes that all processing operations must be based on a
legal basis. This means that the controller may not start
or, as in this case, continue data processing without relying on one
of the criteria for lawfulness listed in Article 6.1 GDPR, which is the concretization of
the principle of lawfulness as referred to in Article 5.1(a) GDPR.
23. The complainant states in her complaint that her cooperation with the defendant had ended in
April 2023. After she had established that the mailbox was still active, she contacted the defendant
about this on 24 January 2024. On that same day, the defendant's Data Protection Officer (hereinafter ‘DPO’) confirmed that the email address had not yet been deactivated. As an explanation for this continued retention of the personal data in the complainant's mailbox, the DPO stated on 20 February 2024: “Given your position
within [the defendant], we felt that it seemed more opportune to have your out-of-office
12 Committee of Ministers, Recommendation CM/Rec(2015)5 of the Committee of Ministers to member States on the
processing of personal data in the context of employment of 1 April 2015, paragraph 14.5: “If employers need to recover
the contents of an employee’s account for the running of the organisation, they should do so before his or her departure
and, when feasible, in his or her presence.” Decision on the merits 101/2026 — 9/60
13
to retain notifications longer, rather than closing your mailbox after 1 month.” On the
day of the complaint on April 23, 2024, being 1 year after the end of the collaboration between
the complainant and the defendant, the mailbox was, according to her, still active.
24. The defendant confirms that the complainant was active with him as an independent consultant and, in
that context, possessed a personal email address on the defendant's domain.
The defendant also acknowledges that “the complainant's mailbox was indeed not (timely)
deleted after deactivation, and inadvertently remained in ‘backup’ mode”. The
process for closing and deleting mailboxes of departed employees was
at the time of the complainant's departure, limited to a monthly list of
departed employees, after which, on the day of departure, the IT department blocked all access
and manually deleted the mailboxes one month after the departure. The
defendant emphasizes that maintaining the complainant's mailbox was a one-time,
human error.
25. The defendant regards the deactivation of the mailbox as a kind of backup mode
and states “that the personal data contained in the complainant's mailbox have de facto already
‘deleted’ since they are no longer actively processed.” In this backup mode,
no one has access to the mailbox anymore, unless a specific procedure is followed
in which access is explicitly requested and must be authorized before
access is granted. This access procedure was not initiated on the
complainant's mailbox after it had been deactivated. 26. Finally, the defendant argues that the complainant also bears part of the responsibility, since she allegedly knew as early as September 2023 that her mailbox was still active and only reported this to the defendant in January 2024.
II.3.1. Assessment of the legal basis in phase 2
27. The Disputes Chamber rules that further processing in phase 2 can be based on the defendant's legitimate interest pursuant to Article 6.1.f GDPR. However, this legitimate interest is limited:
• in duration: specifically to a duration of 1 month. The Disputes Chamber may accept a possible extension of this duration by 2 months, provided that a clear, new balancing of interests substantiates this extension, taking into account the fact that the complainant has already left for more than a month and has not been able to exercise any control over her mailbox or account since then. 13 Appendix to document 2, Complaint form of April 23, 2024, email of February 20, 2024 at 14:48.
14
Document 18, the summary conclusion of [respondent] of August 27, 2024, paragraph 10.
15 Document 18, the summary conclusion of [respondent] of August 27, 2024, paragraph 35. Decision on the merits 101/2026 — 10/60
• in objective: specifically to inform the complainant's contact persons,
on the one hand to guarantee the continuity of business operations by designating another
contact person who has taken over the complainant's duties and
on the other hand to point out to all contact persons that they can no longer communicate with the complainant via the still existing e-mail address. This second objective is
important to be transparent to all of the complainant's contacts so that they know
that the emails (and the personal data contained therein) they send no longer
reach the intended correspondent.
28. Regarding the duration of this processing based on legitimate interest,
the Disputes Chamber establishes that the DPO indicated in his communication with the complainant that the
duration of one month would be extended: “It is true that your mailbox remained ‘active’
longer than is normally provided for in [the defendant]’s standard policy
in this regard. However, given your position within [the defendant], we believed that it seemed more
opportune to retain your out-of-office messages longer, rather than closing your mailbox after 1
month.” 16 In the conclusions, however, the defendant argues that an extension was not applicable: “In the case of the Complainant, the judge found no question
17
of a deliberate deviation from the standard term of one month.” Since no
any balancing of interests for a possible extension has been demonstrated, the
Dispute Resolution Chamber rules that the duration of one month was applicable and that the processing
of the complainant's personal data on 1 June 2023 could no longer be based on
the legitimate interest of the defendant.
29. Regarding the purpose of the processing under the legitimate interest, in particular the
informing of the complainant's contacts, the Dispute Resolution Chamber establishes that the
defendant, as the controller, had delegated the means to achieve this purpose, in this case
the out-of-office message, to the complainant. The defendant states: “It is, after all, not possible for
a company such as that of the Defendant to set up an out-of-office message for every departing
employee [sic]. […] Since this message can vary so much within
the Defendant and also to promote accuracy,
the drafting of the out-of-office message is delegated to the departing employee themselves.” 18
30. In addition to delegating this crucial responsibility in the context of the further
processing of the personal data based on legitimate interest, it appears from
the file itself that it was also not checked whether the out-of-office message was
(correctly) set up at the moment the complainant had left. It appears from the documents
after all, that no proper out-of-office message was sent after the departure of the
16Appendix 5, Email from Respondent of 20 February 2024 (4:11 PM) regarding document 18, the summary conclusion of [respondent] of 27 August 2024.
17
Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 11.
18Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 59. Decision on the merits 101/2026 — 11/60
complainant. The out-of-office message that was sent was set by the complainant herself,
according to her own statement, some time before her effective departure and consequently without the
information that should serve the legitimate interest. The deficiency was only
established by the DPO after the complainant had contacted the defendant in January
2024. Only on 6 April 2024 did the DPO propose to set the out-of-office correctly. 19
Despite this delegation and this lack of control, the Dispute Chamber rules that the
defendant did indeed have a legitimate interest to continue processing the personal data of
the complainant in her mailbox until one month after the complainant's departure.
31. Based on the documents added by the defendant to his submissions, the
Dispute Chamber establishes that the purpose for the continued processing was extended to
recovering information from the complainant's mailbox after her departure. After all, the 2016 management processes mention an
automatic email to the managers containing all the deactivated accounts of
that month:
• “[…]
• this list of deactivated accounts is automatically sent to a
defendant's recipient list to notify the managers that the accounts
will be deleted at the end of the month, unless an exception is
requested
• based on an ICT ticket, this exception can be requested, whereby the
account is set to ‘do not delete’
• […]”20
In this monthly internal email regarding the deletion of the mailboxes of the departed
employees, this exception is clarified, specifically regarding retrieving information from the
mailbox of the deactivated account before it is permanently
deleted. The message reads as follows:
“Below you will find a list of all paid colleagues and extended
employees who have left [the defendant] in the last month(s). Their
access to the systems of the [defendant] has already been blocked.
19
Appendix 12, Email correspondence between Complainant and Respondent of 6 April 2024 regarding document 18, the summary conclusion of [respondent] of 27 August 2024.
20 Appendix 22, Internal Personal Account Management Processes regarding document 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 12/60
Please be aware that the accounts and all personal data (file server
Windows and Unix, mailbox, OneDrive) will be effectively deleted on the
first working day after the 21st of this month.
Do you need more time to extract business-critical information from this or
transfer [respondent]-related information to a cloud environment?
"Then create an ICT ticket to postpone this data deletion (for a maximum of 3 months)." (emphasis in original) (free translation by the Disputes Chamber).
The Disputes Chamber rules that this objective (retrieving information from the mailbox of a deactivated account) does not fall under the legitimate interest of the defendant to further process a mailbox after the complainant's departure and would possibly be in violation of the Electronic Communications Act and the Criminal Code. However, there is no evidence that there was effective access to the complainant's mailbox, as a result of which the Disputes Chamber rules that any processing based on this second objective has not been demonstrated.
32. Based on the defendant's summary conclusion, the Disputes Chamber establishes that a third objective would exist to further process the personal data under the legitimate interest, specifically to provide access to the mailbox to the complainant after his departure: “Finally, the former employees' mailbox is placed in this backup mode precisely in order to comply, in addition to displaying an ‘out of office’ message after their departure, via a standardized procedure, with any requests from former employees
for which the Defendant would still require access to the relevant mailbox.” 23 The defendant's
policy regarding emails, which was drawn up after the complainant had filed a complaint
24
, states this as follows: “The mailbox is set up to a shared
25
mailbox so that if absolutely necessary, access to the mailbox can be granted.”
To illustrate this policy, the defendant provides two examples: “[…] Student has
left [defendant] and still needs documents from his mailbox for his PhD. […]
Employee has left [defendant] and still has an important email in his mailbox
regarding a specific contract, […]. 26 However, this third objective is already contained in
21Piece 18, the summary conclusion of [defendant] of 27 August 2024, paragraph 34; “Below, you find a list of all payroll colleagues and extended workers who have left [defendant] in the past month(s). Their access to the [defendant] systems has been disabled already. Be aware that the accounts and all personal data (fileserver Windows and Unix, mailbox, OneDrive) will be effectively removed on the first working day after the end of this month. Do you need more time to retrieve business-critical information or to transfer [defendant] related content to a cloud environment? Create an ICT ticket to postpone this removal (for a maximum of 3 months).”
22See paragraph 19 of this decision for this. 23 Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 39.
24 See paragraph 75 of this decision for this.
25 Annex 3, [respondent] policy regarding emails in connection with Document 18, the summary conclusion of [respondent] of 27 August 2024.
26
Annex 3, [respondent] policy regarding emails in connection with Document 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 13/60
the right of access under Article 15 GDPR, which can be exercised for as long as the
data are being processed, and therefore cannot be invoked as a separate
objective by the respondent to base a legal ground for processing on. 33. The Disputes Chamber rules that the defendant had a legitimate interest in
continuing to process the personal data in the complainant's mailbox for a period of 1 month
in order to inform the complainant's contacts that she was no longer
employed by the defendant and in order to be able to provide the
defendant with a new contact person to the complainant's professional contacts.
II.3.2. Assessment of the legal basis in phase 3
34. The Disputes Chamber establishes that the deletion of the (personal data in the)
mailbox did not take place 1 month after the end of the collaboration between the complainant and the
defendant, in this case on June 1, 2023. In the conclusions, the
27
defendant acknowledges that the mailbox had not been deleted.
35. The defendant argues that the mailbox had indeed been deactivated, as a result of which there was no
access to the data in the mailbox. The defendant considers the
personal data in the deactivated mailbox as “de facto already ‘deleted’ […] since
they are no longer actively processed”.8
36. However, the Dispute Chamber establishes that the personal data have not ‘de facto already been
deleted’:
• First, on 24 January 2024, the DPO confirmed to the complainant that the mailbox was still
active: “I indeed also saw that your mailbox is still active because I was able to send an email.[…]The fact remains, however, that the mailbox should have already been deleted[…]”. 29
On April 6, 2024, the DPO proposes to the complainant to take the mailbox offline, so that
no more emails could be received on it: “Your account is
disabled, in other words, no one can access it and it cannot be used, but
the mailbox is still open to receive emails. […] There are a few options
[…] – We can take the mailbox offline and store it in a PST at a secure location
so that no one can access it and no emails arrive on it either”. 30
27 Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 32.
28
Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 35.
29 Appendix 2, Email correspondence between Complainant and Respondent of 24 January 2024 regarding document 18, the summary conclusion of [respondent] of
27 August 2024.
30
Appendix 12, Email correspondence between Complainant and Respondent of 6 April 2024 regarding document 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 14/60
31
• Secondly, the DPO states in his letter to the GBA of 2 May 2024 that the mailbox
would have been deactivated since mid-February 2024, meaning no one would have access
but that the mailbox would still be able to receive emails.
• Thirdly, in response to the request for inspection by the
complainant, the defendant took out a new license on the mailbox, so that it would not be deleted
by the new system that had been introduced. In the summary conclusion of the
defendant dated 27 August 2024, it is stated that this license was ‘recently’ linked
to the complainant's mailbox. 32
• Fourthly, the documents state in the 2016 management processes that
a former employee no longer has any access to the account, but that the
mailbox is still visible in the defendant’s ‘Active Directory’:
“Deactivation of the account
Deactivation of an account will have the following consequences:
• The (former) employee cannot log in with this account
• All Office 365 licenses have been revoked
• The (former) employee no longer has access to the mailbox of this
account
• The (former) employee no longer has access to data of this
account
• The (former) employee cannot use applications located on the defendant’s
Active Directory/OpenLDAP
• The (former) employee is no longer a member of
security groups/distribution lists. Also for those using
the account based on name.
The account of the (former) employee is deactivated, but will be visible
in the Active Directory until the account is deleted.” 33 (emphasis and free
translation by the Disputes Chamber).
31 Appendix 1B, appendix to e-mail of 2 May 2024 addressed to the Data Protection Authority appendix 18, the summary conclusion
of [defendant] of 27 August 2024, p. 1 under factual account.
32
Document 18, the summary conclusion of [defendant] of 27 August 2024, paragraph 50.33Appendix 22, Internal Personal Account Management Processes in document 18, the summary conclusion of [respondent] of 27 August 2024, p. 6: Account inactivation
Inactivation of an account will have the following consequences:
• The (former) employee cannot log in with this account.
• All Office 365 licenses are revoked.
• The (former) employee cannot access the mailbox of this account. Decision on the merits 101/2026 — 15/60
37. The Disputes Chamber rules that restricting access to personal data
cannot be equated with the deletion of personal data. As long as the
data are still stored and remain accessible, even if access is very limited,
they are still being processed, risks consequently continue to exist and the
controller must be able to demonstrate that all principles of
data protection have been respected, including having and being able to demonstrate
a legal basis.
38. The Disputes Chamber notes that the ENISA publication of
18 October 2011 concerning ‘the right to be forgotten’, mentioned by the defendant, concerns rather a problem statement regarding
the right to erasure of data, where the focus lies on personal data in an open
system, such as the internet. This publication also speaks of closed systems, but
in the sense that it is easier to erase data with certainty in such
systems since more control is possible. The defendant's system can
be considered such a closed system. Restricting access to
personal data is not equated in this publication with the deletion of
data, which the defendant should have done. Also, the
35
recommendation of the Committee of Ministers of the Council of Europe mentioned by the defendant concerns
measures that must be taken at the moment of the employee's departure
and is not applicable in this case. This recommendation says nothing about the eventual
deletion of the mailbox, nor about any potential legal basis for processing after the
departure of the employee. On the other hand, this recommendation does state that the defendant
must take sufficient measures to
delete the business-necessary information from the mailbox before the complainant's departure.
39. Although the defendant does not submit any assessment regarding a legitimate
interest and states that the further processing was a human error and was not
intended, the Dispute Chamber will nevertheless make this assessment to determine whether
there might possibly be a legitimate interest. 40. In accordance with the case law of the Court of Justice, 36 the defendant must
show that:
• The (former) employee cannot access data […] of this account
• The (former) employee cannot use applications which authenticate to [defendant]'s ActiveDirectory/OpenLDAP
• The (former) employee is no longer a member of Security groups/Distribution lists. Also, for which 'account name
based' membership is used.
The account of the (former) employee is inactivated, but will be visible in ActiveDirectory until Account removal.”
34 ENISA, The right to be forgotten – between expectations and practice of 18 October 2011.
35 Committee of Ministers, Recommendation CM/Rec(2015)5 of the Committee of Ministers to member States on the
processing of personal data in the context of employment of 1 April 2015.
36 CJEU Judgment of 4 May 2017, RīgasSatiksme, C-13/16 ECLI:EU:C:2017:336, para. 28, and CJEU Judgment of 7 December 2023,
Joined cases C-26/22 and C-64/22, Schufa, ECLI:EU:C:2023:958, para. 74. Decision on the merits 101/2026 — 16/60
a. The interests it pursues by the processing, as justified can
be recognized (the “purpose test”);
b. The intended processing is necessary for the realization of those interests
(the “necessity test”);
c. The balancing of those interests against the interests, fundamental
freedoms and basic rights of the complainant outweighs in favour of the
defendant or of a third party (the “balancing test”).
41. With regard to the purpose test, the only purpose for which the complainant's mailbox could be processed for longer than
one month appears to lie in informing the contacts of
the complainant that she is no longer employed by the defendant.
The Disputes Chamber has already ruled above that this processing could not lawfully rely on
a legitimate interest, being the granting of access to the mailbox to third parties in the context of recovering commercially sensitive information or to the complainant herself.
42. With regard to the necessity test, the Disputes Chamber establishes that the out of office
messages that served to inform these contacts were not sufficient
for the complainant's external contacts, as this message merely assumed that the
complainant would only be able to respond to emails sporadically, without it being made clear
that the complainant no longer worked for the defendant. In neither of the two
out-of-office messages was mention made of another employee at the defendant who
had taken over or was following up on the complainant's files. Since the processing was not
sufficient for the intended purpose, the processing could not have been necessary
for this purpose either. The lack of necessity in itself is sufficient to judge
that this processing cannot be based on the legitimate interest of the
defendant.
43. For the sake of completeness, the Disputes Chamber establishes regarding the balancing test that the
complainant was not aware of this continued processing under a new
legal basis with a different purpose. It also appeared from the documents that the complainant had already been employed for some time in
38
a limited regime at the defendant, as a result of which the further processing
of her personal data in her mailbox after she had eventually left fell outside
the reasonable expectations of the complainant, certainly if this processing
continued over time: “Concluante assumed that her account would be deleted immediately after her departure
and that the sender would receive a standard non-Delivery
Report or a bounce-back message clearly stating that the
37See paragraphs 31 and 32 of this decision for this.
38Piece 16, Conclusions + Complainant's Documents of 2 August 2024, paragraph 1. Decision on the merits 101/2026 — 17/60
39
account had been deleted.” Since the complainant was unaware of this ongoing
processing, did not expect this ongoing processing, and was not informed
of this ongoing processing, the complainant no longer had any control over
her personal data. The Disputes Chamber rules that the ongoing further
processing of these personal data for reasons of business continuity
is disproportionate to the total lack of any control over this further processing.
44. Based on what is stated in paragraphs 41-43, the Disputes Chamber rules that the
defendant could not base the ongoing processing of personal data in the
complainant's mailbox on his legitimate interest.
45. The Disputes Chamber rules that the defendant unlawfully processed the personal data of the complainant
and her contacts in her professional mailbox after
a legitimate interest no longer existed to
further process these personal data, in this case after June 1, 2023, and has therefore committed an infringement of Article 5.1.a
GDPR read in conjunction with Article 6.1 GDPR.
46. The defendant argues that following the complainant's request for access, the defendant
again had a legitimate interest in retaining the mailbox without deleting it.
The Disputes Chamber emphasizes that such an argument cannot possibly justify the earlier
lack of a legal basis, given that the complaint and the
request for access arose precisely because the mailbox had not been deleted in a timely manner.
For the sake of completeness, the Disputes Chamber emphasizes that the mailbox was kept intact,
while other technical possibilities exist to safely
preserve the contents of the mailbox, without it having to remain active.
The defendant himself made a proposal for this in his email of April 6, 2024: “[…] but the mailbox is still
open to receive mail. This is certainly not ideal and we would like to see it differently but
not without your (sic) input. There are a few options we can pursue to somewhat improve this skewed
situation: […] We can take the mailbox offline and store it in a
PST in a secure location so that no one can access it and no emails arrive there
40
[…]”. The Disputes Chamber notes that the defendant does not choose to use this most
safe option immediately when he determines that something has gone wrong. With
this technical measure, he could have
limited the processing of the personal data within the framework of the new purpose (granting access to the complainant) and the new
legal basis (legitimate interest of the defendant given this ongoing procedure).It is not the responsibility of the former employee, in this case the complainant, to decide on this matter; this decision rests with the controller.
39
Ibid.
40 Appendix 12, Email correspondence Complainant and Respondent of 6 April 2024 regarding document 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 18/60
II.4. Violation of Article 5.1.b), Article 5.1.c) and Article 5.1.e) of the GDPR due to a
violation of the principle of purpose limitation in combination with data minimisation and
storage limitation of the personal data in the complainant's mailbox after 1 month following
the complainant's departure
47. Given that these principles were assessed in conjunction with the assessment of the
other alleged infringements, the Dispute Resolution Chamber will not explicitly address this
alleged violation. The parties' arguments regarding this alleged
violation will be included in the assessment of the other alleged
violations.
II.5. Violation of Articles 12 and 13 of the GDPR due to failure to provide the necessary
information regarding the processing of personal data in the
complainant's mailbox after 1 month following the complainant's departure
48. The departure of an employee from an organisation constitutes a significant change in the
processing of the personal data of this employee and of his contacts. Ten
first, the purpose and legal basis of processing change; second, the e-
mails no longer reach the recipient of the e-mail, being the ex-employee; and
third, the data subject loses all control over his personal data stored in the mailbox on the employer's domain. In accordance with Articles 12 and 13
GDPR, the ex-employee and his contacts must be informed of these changed processing operations.
49. Upon her departure, the complainant therefore had to be informed that her
personal data in her mailbox are being (further) processed for a different purpose, on the basis of a different legal ground and with a limited retention period. This transparency
must enable her to take any measures to control these
data and processing, even though she loses all direct control over these
personal data. 50. The complainant's contacts, who believe they are sharing their own personal data with the complainant, must also be informed that the complainant no longer has access to her mailbox and that their personal data will therefore no longer reach the complainant, so that these contacts can stop sharing their personal data via this channel and exercise any rights regarding this personal data.
51. The complainant states that she did not have sufficient information regarding the processing of her personal data in the mailbox after her departure, and that there was likewise no procedure to gain access to her mailbox after her departure. The complainant also states that she never received the standard policy regarding the defendant's termination of employment, nor was she assisted in her departure from the defendant. The complainant [Decision on the merits 101/2026 — 19/60]
considers that the defendant approached its privacy policy merely theoretically,
but did not apply it in practice.
52. The defendant refers to its privacy policy, of which the privacy statement and various
transparency documents form part. One of these transparency documents
concerns the standard policy regarding termination of employment with an attached checklist.
This checklist states that the complainant himself should have set up an out-of-office message
since this responsibility was
delegated to the departing employee for reasons of scale and accuracy.
Moreover, the
41
defendant considers deactivating the mailbox after the complainant's departure as
equivalent to deleting the personal data, as a result of which no further
notifications had to be sent to the complainant. 53. Finally, the DPO responded to the complainant's questions and concerns and encouraged the complainant to contact him if there were any further questions or problems, which the complainant did not address.
54. The defendant is therefore of the opinion that a one-off human error, as a result of which the mailbox was not deleted in a timely manner, does not detract from his general GDPR-compliant policy, including the transparency of the processing.
II.5.1. Assessment of the transparency obligation in phase 2
55. The Dispute Resolution Chamber has already ruled that deactivating the complainant's mailbox does not constitute a de facto deletion of the complainant's personal data. Therefore, there was indeed a transparency obligation regarding the processing of the personal data that were present and were still arriving in the complainant's mailbox. 56. Despite the various documents added to the file by the defendant,
the Disputes Chamber notes that there is no evidence to be found anywhere that the closing of the
mailbox, the changed legal basis and the changed purpose of the processing, and the
retention period of the personal data were communicated to the complainant.
Nor does the defendant demonstrate that this information was available on his website, on
his intranet, or in his privacy statement. The only two documents that approximate such a
communication are document 17 (offboarding checklist) and document 26 (Knowledge article via
[defendant] Employee Center). Both documents instruct the complainant to report to ICT
that she would leave the defendant and set up an out-of-office message herself,
41
Throughout his conclusions, the defendant speaks of deactivating and placing in backup mode, but states himself that both
mean essentially the same thing: “The complainant's mailbox was therefore in a sort of ‘backup mode’ after the deactivation.” in Document
18, the summary conclusion of [defendant] of 27 August 2024, paragraph 35.
42 See paragraphs 36-37 of this decision for this. Decision on the merits 101/2026 — 20/60
but was otherwise not transparent about how her personal data in the mailbox would be further
processed or deleted.
57. With regard to transparency towards third parties, the Disputes Chamber establishes that the
following out-of-office messages were set:
• To internal correspondents: “This email address is no longer in use. You can contact [complainant] at [XXX].” (free translation Disputes Chamber).
• To external correspondents: “Dear, thank you for your message. I am currently offline with very limited internet access. Please take into account
some delay in my replies. Kind regards, [complainant].” (free translation
43 Disputes Chamber).
58. The message to the internal colleagues sufficiently informed that the complainant was no longer part of the defendant, so that the correspondents were aware that their
personal data was no longer being received by the complainant. Given that it concerned internal colleagues of
the same organization, one could assume that they had access to
sufficient information to be able to
contact another correspondent at the defendant regarding their communication.
59. However, the message to the external colleagues suggests that the complainant was only temporarily
absent or difficult to reach and therefore does not make clear to third parties that their
correspondence and their personal data would no longer be
processed by the complainant. The complainant also demonstrates this in the complaint with several examples of
communication in which her correspondent remained unaware whether the communication had
reached the complainant or not.44
60. Although the defendant delegates the responsibility for
proper communication in the form of an out-of-office message to the complainant in its policy and in its conclusions,
the defendant is the data controller and is therefore also
responsible for this transparency. Even though the defendant requests in its policy
the complainant to set up a compliant out-of-office message, this does not relieve the defendant
of its responsibility to be sufficiently transparent to third parties
regarding the processing of their personal data that end up in the
complainant's mailbox via e-mail after the latter's departure, not least because the complainant no longer has any
control over these personal data located on the servers under the control of
the defendant. The Disputes Chamber establishes that the defendant did not
43Document 18, the summary conclusion of [defendant] of August 27, 2024, paragraph 8: •
To internal correspondents: “This email address is no longer in use. You can contact [Complainant] on [XXX]”
To external correspondents: “Dear, thanks for your email. I am currently offline with very limited access to the internet. Please
accept some delay in my reply. Regards, [complainant]”
44Appendices 3 and 4 to document 2, Complaint form of April 23, 2024. Decision on the merits 101/2026 — 21/60
conducted a check on both out-of-office messages from the complainant and only after
the email from the complainant of January 24, 2024, being 7 months after the departure of the
complainant, determined that this transparency obligation to third parties, external to the
organization, had not complied.
61. The Disputes Chamber rules that the defendant has failed to comply with its
duty of transparency regarding the continued processing of the personal data
of the complainant and of her contacts external to the organization following the departure
of the complainant from the defendant and has thereby committed a breach of Articles 12
and 13 of the GDPR.
62. The Disputes Chamber establishes that the measures regarding transparency towards the contacts
of the complainant, in particular the setting of an out-of-office message on the deactivated
mailbox of the complainant, have not been included in the management processes, even though they are
substantially part of them. Moreover, the state of the art allows this
measure to be automated to prevent human errors and/or a technical
control on this measure to identify
and correct any human errors. In that regard, the Disputes Chamber notes that an automatic
email is sent to the defendant's managers to report that accounts will be
deleted so that they can request an exception to this deletion.45
63. With similar technical measures, the defendant could also have automatically sent the knowledge document and the
checklist with the appropriate technical measures to the complainant
before her departure.
II.5.2. Assessment of the transparency obligation in phase 3
64. The Disputes Chamber notes that the processing of the complainant's personal data
after the period of 1 month following her departure did not fit within the policy regarding the
processing of personal data in the complainant's mailbox. The defendant refers
repeatedly to a one-off human error in this regard, as a result of which phase 2 was extended,
without ever deleting the personal data. The issue of transparency is therefore located
in this case in phase 2, as a result of which the Dispute Chamber will not address the
transparency regarding phase 3.
II.6. Assessment of the violation of Article 24 GDPR
65. Article 24 GDPR considers it the responsibility of the controller
to take sufficient technical and organisational measures in order to ensure and demonstrate compliance between the processing of personal data and the principles of the
45See bullet number 6 of paragraph 70 of this decision. Decision on the merits 101/2026 — 22/60
GDPR. Recital 39 of the GDPR clarifies: ‘In order to ensure that personal data are not retained for longer than necessary, the controller shall establish periods for the erasure of data or for periodic review thereof’.
66. The complainant argues that the defendant did not take sufficient technical and organizational measures to properly manage and close her mailbox after her departure, certainly in light of the current state of technology. The complainant points out in particular that this management still had to be done manually, creating an unnecessary risk of human error. The complainant is therefore of the opinion that a review of this practice should have been undertaken much earlier.
67. The defendant refers to its standard policy and states that sufficient technical and organizational measures exist regarding the handling of the mailboxes of its employees. The problems concerning the complainant's mailbox referred to in her complaint concern a one-off human error. The defendant states that a change process had already been initiated prior to the complaint. This change process was intended to automate the deletion of deactivated accounts, so that this error could no longer occur. However, such a change process is complex and expensive, according to the defendant, which means it takes time to realize. Furthermore, the defendant points out the deactivation of the mailboxes and the removal of the associated license, as a result of which no one had access to this mailbox anymore.
68. The Disputes Chamber establishes that there were 65 persons on the list of departed employees as of June 1, 2023, who had left the organization in May 2023. 46 The defendant himself states that he is a large organization where approximately one thousand persons arrive and leave per year. Regarding this turnover of personnel, the defendant himself states
in his conclusion that:
• on the one hand it is “after all not possible for a company such as that of the Defendant to
set up an out-of-office message for every departing employee (sic). […]
Since this message can vary so widely within the Defendant […] the
setting up of the out-of-office message is delegated to the departing employee himself.” 48
and
46 Appendix 13, Email correspondence ICT department regarding the deletion of accounts in document 18, the summary conclusion of
[defendant] of 27 August 2024.
47
Document 34, Minutes of Hearing of 3 December 2025, p. 3.
48Piece 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 59. Decision on the merits 101/2026 — 23/60
• on the other hand, the “(e-mail) account as well as the corresponding mailbox within the
Microsoft environment of the Respondent proverbially dragged to the ‘trash can’
49
[is].”
69. Given the quantity and diversity of personal data in a mailbox of an
employee, as already cited above 50, the risks regarding the
processing of the personal data in these mailboxes, including those of the complainant
and her contacts, are considerable. Consequently, closing such mailboxes and
means of communication requires sufficient technical and organizational
measures to protect these personal data. The state of the art has
allowed for quite some time to automate these measures and/or to verify them thoroughly,
even if the process were still to be carried out manually.
70. Based on the information in the file, the Disputes Chamber establishes that closing
the mailboxes of departing employees is a very frequently
recurring task for the defendant, which already appears to be carried out according to a specific, standardized procedure.
Based on the defendant's management processes in the documents,
the Disputes Chamber establishes that the process proceeds as follows:
• based on information from the human resources department, the
accounts to be deactivated are automatically prepared for deactivation on the correct day after verification;
• all necessary information regarding the accounts to be deactivated is automatically
collected in preparation for the deactivation;
• every account to be deactivated is automatically added to the list of accounts to be deactivated, after which the list is automatically sent to the helpdesk;
helpdesk;
• on the appropriate day, the account is manually deactivated by the ICT second-line service;
• on the first day of every month, an overview of deactivated accounts is automatically created;
deactivated accounts;
• this list of deactivated accounts is automatically sent to a recipient list of the defendant to notify the managers that the accounts will be deleted at the end of the month, unless an exception is requested;
49Piece 18, the summary conclusion of [defendant] of 27 August 2024, paragraph 31.
50
See paragraph 11 of this decision for this. 51Appendix 22, Internal Personal Account Management Processes to document 18, the summary conclusion of [defendant] of 27 August 2024. Decision on the merits 101/2026 — 24/60
• based on an ICT ticket, this exception can be requested, whereby
the account is set to ‘do not delete’;
• after verification by the ICT second-line service, the list of accounts to be deleted is sent by the employee to the ICT infrastructure service;
• the ICT infrastructure service manually deletes all accounts to be deleted and sends a
list of effectively deleted accounts back to the ICT second-line service;
• the ICT second-line service sets the account to ‘deleted’. 71. With regard to the complainant's mailbox, the Disputes Chamber establishes that her account was indeed
on the list of mailboxes to be deleted by the ICT second-line service and
52
that this list was indeed sent to the ICT infrastructure service. The facts show that
the mailbox was not deleted, however.
72. First, the Disputes Chamber establishes that the effective deletion of the mailbox was not
automated, whereas it is a typical process that, given the state of the
art, can easily be automated. Second, the Disputes Chamber
establishes that a control measure did exist regarding the deletion of the mailbox, namely the return of the list of effectively deleted mailboxes. However, this measure
was clearly not followed. Moreover, there was no technical control whatsoever over the implementation of this measure, even though this was possible, for example by technically comparing the list of mailboxes to be deleted with the list of deleted mailboxes to trigger an alert when these two lists do not match.
73. Since there is no control over the deletion of the mailboxes and since these
processes did not take place automatically, the defendant cannot in any way
demonstrate, in accordance with Articles 5.2 and 24 of the GDPR, that the complainant was effectively the only one
for whom the manual process had failed. In that context, the Dispute Chamber established
on the basis of the list of departing employees from May 2023 that there was an
employee who, according to the data, had already left the organization on October 4, 2022,
but whose mailbox deletion was only
communicated to the ICT department on June 1, 2023. 53
74. The defendant points out that he had initiated an improvement process, whereby a
tender was issued in mid-2022. In the conclusions, however, the defendant states
that only the final step of the process would be fully automated and
52
Appendix 13, Email correspondence ICT service regarding the deletion of accounts in document 18, the summary conclusion of
[defendant] of August 27, 2024.
53 Appendix 13, Email correspondence ICT service regarding the deletion of accounts in document 18, the summary conclusion of
[defendant] of August 27, 2024. Decision on the merits 101/2026 — 25/60
this only from September 2024. 54 The Disputes Chamber establishes that this improvement process
offered no relief at the time of the complainant's departure, since the
procedures were still manual proceeded. Despite the fact that the need for new
processes had already been acknowledged in June 2022, the
effective control of the manual processes was not initiated at that time, although this was provided for in the
management processes.
75. In this regard, the defendant refers to his standard policy regarding mailboxes, which is
attached in the documents. However, the standard policy submitted by the defendant was
drawn up after the complainant's departure. Indeed, the policy speaks of an old and a
55 56
new process, whereas the new process was in force in March early December 2023, specifically 7 months after the complainant's departure. The defendant submits no policy other than the management processes that was valid at the time of the complaint. 57
76. The management processes date from 31 May 2016 and have therefore never been modified since
the introduction of the GDPR and its application by the Disputes Chamber regarding the
closing of the mailboxes of departed employees, of which the defendant should have been
aware. From these management processes, the Disputes Chamber infers that
the procedure that was valid at the time of the complainant's departure was still this
procedure of 2016 and that the defendant can hardly speak of “Defendant
(re)evaluates and analyzes its processes in order to optimize them, taking into account
the new state of the art and the implementation costs” 58
or of “This proactive approach [which] underscores that Defendant takes its
responsibilities seriously and strives for continuous compliance with the
59
GDPR.”
77. The Disputes Chamber rules that the defendant had taken, or demonstrates having taken, insufficient technical and
organizational measures to delete the
complainant's mailbox after there was no longer a legal basis to further process the
personal data in the mailbox and thereby committed an infringement
of Article 24 GDPR.
54 Document 18, the summary conclusion of [defendant] of 27 August 2024, paragraph 46.
55 Appendix 3, [defendant]'s policy regarding emails in document 18, the summary conclusion of [defendant] of 27 August 2024: “This
process is valid for the new and the old way of working”. 56
Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 12.
57 Appendix 22, Internal Personal Account Management Processes to Document 18, the summary conclusion of [respondent] of 27 August 2024.
58 Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 74.
59
Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 65. Decision on the merits 101/2026 — 26/60
78. The fact that the respondent was in an improvement process to rectify this shortcoming will be taken into account by the Disputes Chamber in the assessment of the appropriate corrective measures and sanctions.
II.7. Violation of Articles 12 and 15 GDPR
79. The complainant states that the defendant did not grant access to her mailbox, which had still not been deleted at the time of the request, nor to the requested
log data of the mailbox. The solution proposed by the defendant is very
unbalanced, given that the complainant would only be granted very limited access to the
personal data and this only after extensive filtering by and under the supervision of
the defendant. It was not clear to the complainant whether she would be allowed to copy personal data from the
mailbox, who the neutral person present during this would be,
whether this neutral person would also be able to view the content of the private emails and how
prior filtering would be performed. The justification for this practice would
also be based too generally on the ‘protection of trade secrets and
commercially sensitive information’. 80. The defendant argues that his DPO responded to the request for access in a timely and adequate manner, without disregarding other provisions of the GDPR or beyond. In this regard, the defendant refers to commercially sensitive data connected to his activities, to which the complainant also had access during the performance of her duties. The defendant therefore only wished to perform filtering when storing data from the mailbox, so that the rights and freedoms of third parties and the business secrecy of the defendant could be guaranteed. To achieve this, the DPO made a balanced proposal by inviting the complainant to the defendant's offices and only monitoring the data that would be copied from the mailbox. The complainant did not give the defendant the opportunity to explain this course of action, and to specify who would be engaged as a neutral person and how the supervision would take place. 81. The Disputes Chamber establishes that the complainant contacted the defendant on 24 January 2024 to report that her email address was still active, requesting also access to and a copy of her personal data in her mailbox for the last 9 months since her departure. On February 20, 2024, the DPO proposed the following procedure in order to grant the
request for access:
“In the presence of a neutral person, you will be granted access to the relevant
mailbox; this will take place from a [defendant] office and with the aid of a
[defendant] device. The available emails must be filtered for emails received
after your departure and for external senders, since all internal Decision on the Substantive Matters 101/2026 — 27/60
contacts received a correct out-of-office email. In this way, the
trade secrets of [defendant] are respected and you are still offered the opportunity
to filter your personal emails and, if desired, save them. […]” 60
On March 6, 2024, the DPO reiterated his proposal for access to the complainant's mailbox and
now imposed a time limit on the complainant:
“In addition, the proposal regarding access to your
personal data remains, as set out in our previous communication, naturally still
valid. If you still wish to accept this proposal, then we would like to hear from you within fourteen (14) days following this e-mail. […] If you inform us that you do not wish to accept this proposal or do not communicate a date to us within fourteen (14) days following this e-mail, then the
mailbox will be completely closed the day after your notification that you do not wish to accept
our proposal or the day after the expiry of the aforementioned period.”
That same day, the complainant initially indicated that she wished to accept the inspection procedure, to which
she later retracted and stated that she did not wish to come to the premises for inspection
but wished to receive a copy of her personal data in accordance with Article 15.3 GDPR.
The defendant sent the processed personal data of the complainant via email on 4 April 2024, including a screenshot of the activity log of her mailbox and clarified his position regarding access to the mailbox itself:
“By way of addition, I would like to point out that not making the mailbox available is not a matter of not wanting to, but a matter of not being allowed to
• [defendant] cannot deliver the entire mailbox because they might then infringe on confidentiality rules, as some emails may be subject to them
• [defendant] cannot deliver the latest or non-confidential emails because someone would then have to gain access to your mailbox and we do not allow that either
61
for privacy reasons.”
On the same day, the DPO makes a file available for inspection, clarifying:
“The information not included in this package is the information that they
• […]
60Appendix to document 2, Complaint form of April 23, 2024, email of February 20, 2024 at 14:48.61Appendix to document 2, Complaint form of 23 April 2024, email 1 of 4 April 2024 at 15:38. Decision on the merits 101/2026 — 28/60
• […]
• Unable to provide because they cannot access it, such as information from
mailboxes.” 62
82. Based on this communication, the Disputes Chamber establishes that the defendant limited the
right of access to emails that arrived after May 1, 2023, and only those e-
emails originating from external contacts. The reason invoked for this limitation was that, on the one hand, a correct out-of-office message had been set up on
the emails of internal colleagues and the protection of trade secrets. Only after this
filtering would the complainant be able to filter her personal emails and potentially retain them.
83. Regarding the prior filter that would prevent access to emails from internal colleagues,
the Disputes Chamber rules that whether or not an out-
of-office message is set up correctly is not a criterion for limiting the complainant's right of access,
especially since this out-of-office message concerns the responsibility of the defendant.
84. Regarding the filter that prevents access to e-mails prior to the complainant's departure from the defendant
would prevent, the Disputes Chamber rules that the time of receiving or
processing the personal data is not a criterion for limiting the
complainant's right of access. The personal data are still in the mailbox and are therefore
still being processed, meaning they can therefore still be the subject of a request
for access. However, the Disputes Chamber establishes that the complainant only requested access to her
personal data in the mailbox for emails received in the last one-eight months after her departure,
making this filter by the defendant acceptable.
85. Regarding the filter for the sake of trade secrets or the intellectual property of the
defendant, as stated in Recital 63 of the GDPR, the Disputes Chamber rules that this
filter does indeed constitute a criterion for
limiting the complainant's right of access.
In that context, the Disputes Chamber establishes on the basis of the hearing that the
the defendant employs a classification system that divides the data into ‘public’, ‘restricted’,
‘confidential’ and ‘strictly confidential’ data and that the title of the email would be sufficient
63
to determine whether the email concerned a project that needed to be protected.
Based on this classification, the defendant could have, without risk to his trade secrets, in a
first step reviewed all emails together with the complainant for metadata, in order to then filter out the
business-sensitive data. In a second step, the complainant could then obtain full
insight and a copy of all data that had not been filtered out in this way.
62 Appendix to document 2, Complaint form of 23 April 2024, email 2 of 4 April 2024 at 15:38.
63 Document 34, Minutes of hearing of 3 December 2025, p. 5. Decision on the merits 101/2026 — 29/60
86. Given the possible presence of trade secrets in the complainant's mailbox,
the Disputes Chamber deems it proportionate that the complainant should be required to exercise this access
within the secure perimeter of the defendant's offices and on a
defendant's device in the presence of a neutral person during step 1. The role
of this neutral person would be limited to removing the commercially sensitive
data from the mailbox based on the classification and metadata of the messages.
87. In his conclusions, the defendant amends his argumentation for the filtering by stating
that the complainant would be granted access to her entire mailboxes and that this filtering was only
applicable in the event that the complainant wished to copy certain personal data.
The Disputes Chamber notes that this interpretation does not correspond with what the DPO
had communicated to the complainant in his emails of 20 February 2024 and March 6, 2024,
in which there is a first filter, after which the complainant could filter the rest of the emails. The position that the “Complainant did not even give the Respondent the opportunity to
explain the entire procedure[…]” goes directly contrary to the principle of transparency of
Article 12 GDPR and confirms the lack of clarity in the communication regarding any
filtering of the mailbox before the complainant would be allowed to inspect it.
88. The Dispute Chamber rules that the respondent did not take appropriate measures
to facilitate the complainant's right of access to her personal data after her
departure from the respondent and has
unjustifiably limited this right of access
to only the emails for which no correct out-of-office message was set,
thereby committing a breach of Articles 12 and 15 GDPR.
II.8. Violation of Article 5.1.f GDPR in conjunction with Article 5.2 GDPR
89. Article 5.2 GDPR states that the controller must guarantee and be able to demonstrate compliance with the GDPR principles. One of these principles concerns guaranteeing the confidentiality and integrity of the personal data of the data subject, in accordance with Article 5.1.f GDPR.
90. The complainant argues that the defendant took insufficient measures in the organization of its processing of personal data to subsequently be able to demonstrate to the complainant that there was no access to her mailbox after her departure and that, consequently, the confidentiality and integrity of her personal data were guaranteed. In this regard, the complainant refers to an email that arrived in her mailbox on August 13, 2023, which is also recorded as opened. The complainant obtains this information from the screenshot of the activity log of her mailbox that she received on April 4, 2024, following her repeated request for access.
64Stuk 18, the summary conclusion of [defendant] of 27 August 2024, paragraph 105. Decision on the merits 101/2026 — 30/60
91. The defendant again refers to the deactivation and removal of the license of
the complainant's mailbox, as a result of which no one had access to this mailbox anymore and the
confidentiality and integrity of the personal data were thus guaranteed.
Regarding the allegedly opened email, the defendant points out that the time of
receipt of the email and the time of the alleged opening of the email are the same and occur in the middle of the night. When an email containing a link or an attachment
arrives at the defendant's domain, it is scanned for harmful content within the framework of
information security. This scan leaves a trace in the
activity log as if the email had been opened. This explains the
nightly time and the simultaneous registration of arrival and opening the email.
Furthermore, the defendant states: “Despite what the Complainant attempts to insinuate in this regard in
her conclusion, the Defendant naturally gladly substantiates this assertion by means of log
files (document 23).
92. Regarding the continued processing of the personal data in the
mailbox of the complainant after her departure, the Disputes Chamber establishes that the mailbox was never deleted after there was no longer a
legal basis for the processing and that various elements in the documents
point to an additional purpose, besides informing the contact persons, namely
retrieving business-sensitive information from the mailbox closed to the complainant. 66
From the complainant's point of view, the fear that this actually happened is therefore not
unjustified and it is up to the defendant to demonstrate, in accordance with Articles 5.2, that there was
no access to the mailbox after her departure. 93. Specifically, the complainant established that a specific email in her mailbox was opened
after her departure. To this end, the complainant refers to the screenshots of the Customer
Relationship Management system (CRM) that she received on April 4, 2024, following her
request for access. The Disputes Chamber establishes in the activity logs of the CRM of the
complainant's mailbox, which the defendant attaches to his documents, that on August 13,
2023, thus after the complainant's departure, an email was received at 01:20 and
at the same moment the same email was opened. The defendant refers to his
information security policy and the screening of incoming emails to explain
why the mail appears to have been opened in the system.
94. In accordance with Article 5.2 of the GDPR, it is up to the defendant to demonstrate that no further access was taken to her mailbox after the departure
of the complainant. The most suitable
means to demonstrate whether or not there was access to this mailbox are the log files of the
authentication and access attempts to this mailbox, which also in the context of
65Piece 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 116.
66
See paragraph 31 of this decision for this.
67Appendix 25, screenshots CRM system with piece 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 31/60
information security always be recorded. The respondent refers in his conclusions
to piece 23 (‘Logs regarding the mailbox’) to demonstrate that there has been no access to
the complainant's mailbox. It has therefore been irrefutably demonstrated that the defendant has possession of
the ‘log files’ of the authentication and access attempts to the complainant’s account.
95. However, the Disputes Chamber notes that in document 23, the defendant only added the ‘log files’ from
July 22, 2024 to August 20, 2024 to the documents. The defendant
confirms this in his conclusion: “The defendant can demonstrate that no
actions or manipulations took place in the mailbox during the past month since the departure of
the Complainant (document 23)” (emphasis by Disputes Chamber). With this limited time period
in which the ‘log files’ were included in the documents, the defendant cannot demonstrate
that there was no access to the complainant’s mailbox from May 1, 2023 to July 22, 2024. 96. The Disputes Chamber notes that the defendant does not include log files regarding access to the
mailbox from 1 May 2023 to 1 June 2023, the period during which he did still have a
legitimate interest in processing the complainant's mailbox, but also the
period during which the managers could
request an exception to the deletion of the mailbox in order to recover business-sensitive data. 69 The defendant argues that
such an exception was not requested and that, therefore, no access was taken to the
mailbox, but fails to demonstrate this. In that same period, specifically on 15 May 2023,
the email which the complainant stated in her complaint had been opened upon receipt is also included, which
led her to suspect that there was indeed access to the mailbox. She obtained this information
70
from the activity logs of the mailbox which she received following her request for access. The defendant referred to his
information security policy regarding the opening of this email, but nowhere demonstrates that no access was
taken to the mailbox that day/night, which his assertion could have irrefutably demonstrated to the
Dispute Resolution Chamber.
97. The Dispute Resolution Chamber also establishes that the defendant (except for the log files mentioned in
paragraph 95 for a limited period) does not add log files
from the period after June 1, 2023, the moment at which the mailbox should have been deleted,
unless a manager had received an exception. During this period, specifically on
August 13, 2023, the Dispute Resolution Chamber establishes that another email was listed which
according to the activity logs, was allegedly opened at the same time of receipt. Also1
68
Document 18, the summary conclusion of [respondent] of 27 August 2024, paragraph 83.
69See bullet number 6 of paragraph 70 of this decision for this.
70
Document 2, complaint form of 23 April 2024, p. 3.
7Document 25, Screenshots CRM system accompanying document 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 32/60
for this period and this e-mail, the respondent does not demonstrate that there has been no access
to the mailbox. 98. Finally, the Disputes Chamber establishes that on 20 February 2024, the DPO informed the complainant
that there had been no access to the complainant's mailbox and stated: “Moreover, this was explicitly confirmed by our IT department.” Here too, the defendant
fails to add any evidence of the absence of access to the mailbox or of the control
thereof by the IT department, whereas this control was apparently indeed
possible and had been carried out.
99. The Disputes Chamber rules that the defendant has not sufficiently demonstrated that
the confidentiality and integrity of the complainant's personal data in her
mailbox were guaranteed, whereas it has been demonstrated that the defendant was
capable of doing so and thereby committed a breach of Article 5.1.f GDPR in conjunction with Article
5.2 GDPR. 100. Regarding the argumentation concerning the setting of the out-of-office message, the Disputes Chamber refers to the earlier assessment regarding the transparency obligation of the
defendant in this regard and does not elaborate further on this.
II.9. Conclusion: established infringements
101. In this decision, the Disputes Chamber ruled that the defendant committed an infringement
of
• Article 5.1a GDPR read in conjunction with Article 6.1 GDPR by unlawfully processing the personal data of the
complainant and her contacts in her professional mailbox
after there was no longer a legitimate interest to further process these
personal data, in this case after 1 June 2023;
• Articles 12 and 13 GDPR by failing to comply with his transparency obligation
with regard to the further processing of the personal data of the complainant and
of her contacts external to the organization after the complainant's departure from the
defendant;
• Article 24 GDPR because he had taken or demonstrates having taken insufficient technical and organizational measures
to delete the complainant's mailbox
after there was no longer a legal basis to further process the personal data in the mailbox;
72 Appendix 5, Email from the Respondent of 20 February 2024 (14:48) regarding document 18, the summary conclusion of [respondent] of 27 August 2024. Decision on the merits 101/2026 — 33/60
• Articles 12 and 15 GDPR because he did not take appropriate measures
to facilitate the complainant's right of access to her personal data after her departure from
the respondent and has unjustifiably limited this right of access to
only the emails for which no correct out-of-office message had been set;
• Article 5.1.f GDPR read in conjunction with Article 5.2 GDPR because he has not sufficiently demonstrated
that the confidentiality and integrity of the complainant's personal data in
her mailbox were guaranteed, whereas it has been demonstrated that the defendant was
capable of doing so.
III. Corrective measures and sanctions
102. According to the wording of Article 100.1 of the WOG, the Disputes Chamber has the
power to:
1° dismiss a complaint;
2° order a decision to be dismissed;
3° order a suspension of the decision;
4° propose a settlement;
5° issue warnings and reprimands;
6° order compliance with the requests of the data subject to exercise his rights;
7° order that the data subject be informed of the security issue;
8° to order that the processing be temporarily or permanently frozen, restricted or prohibited;
9° to order that the processing be brought into compliance;
10° to order the rectification, restriction or deletion of data and notification thereof to the recipients of the data;
11° to order the withdrawal of the accreditation of certification bodies;
12° to impose penalty payments;
13° to impose administrative fines;
14° to order the suspension of cross-border data flows to another State
or an international institution;
15° to transfer the file to the Public Prosecutor's Office in Brussels,
which notifies it of the action taken on the file; 16° to decide on a case-by-case basis to make its decisions known on the website of Decision on the merits 101/2026 — 34/60
the Data Protection Authority.
103. It is up to the Dispute Resolution Chamber to decide on the most appropriate sanction in light
of the established infringements.
III.1. Corrective measures
104. Due to the infringement of Article 24 GDPR, because the defendant had taken or demonstrates having taken insufficient technical and organizational measures to delete the complainant's mailbox after there was no longer a legal basis
to continue processing the personal data in the mailbox, the Disputes Chamber orders
pursuant to Article 58.2.d GDPR and Article 100, § 1, 9° WOG, to take sufficient technical and
organizational measures in order to continue processing and closing the personal data in the mailboxes
of departing employees in accordance with this decision, and to demonstrate this to the Disputes Chamber.
Given that, according to the defendant, these measures have already been taken, he only
remains to demonstrate this to the Disputes Chamber, and the Disputes Chamber considers a period of
30 days to be more than sufficient to comply with this order. This order is necessary to avoid similar unlawful processing at the defendant in the short term, in particular in light of the high turnover of
employees at the defendant.
105. Due to the infringement of Articles 12 and 15 of the GDPR, because the defendant did not take the
appropriate measures to facilitate the complainant's right of access to her
personal data after her departure from the defendant and
unjustifiably limited this right of access to only the emails for which no proper out-of-
office message was set, the Dispute Resolution Chamber orders, pursuant to Article 58.2.c
GDPR and Article 100, § 1, 6° WOG, to grant the complainant access to all her
personal data in accordance with this decision.
106. This order is necessary to enable the complainant to exercise full control
over her personal data which were unlawfully processed after her departure
and over which she has not yet been able to exercise any control to date, given
this personal data was stored
under the full control of the defendant and the request for access had not yet been granted. Specifically, this also enables the complainant
to recover any missed communication due to insufficient
transparency towards her contacts in order to potentially restore this
communication relationship.
73Piece 39, Defense of [defendant] of 24 April 2026, p. 18, paragraph 8. Decision on the merits 101/2026 — 35/60
107. The Disputes Chamber takes note of the defendant's request regarding the modalities
for the execution of this right of access. However, the Disputes Chamber is of the opinion that it is the responsibility of the defendant to determine the modalities of the inspection in consultation with the complainant and, in doing so, possibly to call upon a neutral third party.
108. Due to the infringement of Article 5.1.a of the GDPR read in conjunction with Article 6.1 of the GDPR, because the defendant unlawfully processed the personal data of the complainant and her contacts in her professional mailbox after a legitimate interest no longer existed to continue processing these personal data, in this case after 1 June 2023, the Disputes Chamber orders, pursuant to Article 58.2.g of the GDPR and Article 100, § 1, 10° of the WOG, to delete all personal data concerning the complainant's mailbox after access has been granted.
This order is necessary since the purpose and necessity to continue processing the personal data in the mailbox in accordance with the initial legal basis or the legitimate interest has long since expired within the period of 1 month following the complainant's departure and
since the continued retention of this mailbox in the context of these proceedings
is likewise no longer necessary. 109. In view of the infringement of Article 5.1.f GDPR read in conjunction with Article 5.2 GDPR, because the
defendant has not sufficiently demonstrated that the confidentiality and integrity of
the complainant's personal data in her mailbox were guaranteed, whereas it has been
demonstrated that the defendant was capable of doing so, the Dispute Resolution Chamber orders
pursuant to Article 58.2.d GDPR and Article 100, § 1, 9° WOG, to transfer the registration of access
to the complainant's mailbox from 1 May 2023 until the deletion of the mailbox
to the complainant, without however leaving third-party personal data visible, or to
demonstrate that these data are no longer available to the defendant.
This order is necessary to enable the complainant to verify whether or not the
confidentiality of her personal data was violated after she no longer had
any control over these personal data. 110. Only by granting the complainant access to all personal data in this mailbox,
by subsequently deleting this mailbox and by demonstrating that there has been no access
to this mailbox in the meantime, will the complainant regain full control over
her own personal data processed on the domain and on behalf of the
defendant. The defendant is granted a period of 30 days, calculated from the
notification of this decision, to execute these four orders and to give the complainant
back control over her personal data in her mailbox. Decision on the merits 101/2026 — 36/60
III.2. Administrative fine
111. In addition to the corrective measures to bring the processing into conformity
with the principles of the GDPR, the Dispute Resolution Chamber also decides to impose an
administrative fine with a view to vigorous enforcement of the rules of the
GDPR. As is clearly evident from Recital 148 of the GDPR, the GDPR establishes that in the event of any serious infringement—including the initial finding of an infringement—penalties, including administrative fines, shall be imposed in addition to or instead of appropriate measures.
112. The Disputes Chamber also points out that it is its sovereign responsibility as an independent administrative authority—with due observance of the relevant Articles of the GDPR and the WOG—to determine the appropriate corrective measures and sanctions. This follows from Article 83 of the GDPR itself, but the Market Court has also emphasized in its case law the existence of broad discretionary power of the Disputes Chamber regarding the choice of the sanction and its scope,
74
as, inter alia, in its judgments of 7 July 2021 and 6 September 2023. 113. The fact that this concerns a first finding of an infringement of the GDPR committed by the defendant does not in any way prejudice the possibility for the Dispute Chamber to impose an administrative fine. The Dispute Chamber imposes the administrative fine pursuant to Article 58.2.i) of the GDPR. The instrument of administrative fine is by no means intended to terminate infringements; to that end, the GDPR and the WOG provide for a number of corrective measures, including the orders referred to in Article 100, § 1, 8° and 9° of the WOG.
114. Article 83.3 of the GDPR prescribes the factors that must be taken into account in each specific case when deciding whether an administrative fine is imposed and the amount thereof. The Disputes Chamber takes into account in particular
the severity of the infringements, the duration of the infringements, and the necessary
deterrent effect to prevent future infringements. To avoid
repeating the assessment of each factor, the Disputes Chamber refers to the
assessment below, in which the imposition of an administrative fine and the
amount thereof are assessed together. 115. In order to impose an effective, proportionate and dissuasive fine in any event,
the supervisory authorities are expected to adjust the administrative fines
and thereby remain within the margins set out in the EDPB Guidelines 04/2022 for
the calculation of administrative fines under the GDPR (Version 2.1, Adopted
74 Brussels Court of Appeal, Market Section A, Market Affairs Chamber, 2021/AR/320, pp. 37-47; Brussels Court of Appeal, Market Section, 19 Chamber A, Market Affairs Chamber, 2020/AR/1160, p. 34. Decision on the merits 101/2026 — 37/60
provided for on 24 May 2023). This may lead to significant increases or decreases in
the fine, depending on the circumstances of the case. The application of these
Guidelines is necessary to ensure the coherence of the application of the GDPR.
In accordance with the EDP B Guidelines, administrative fines
for infringements of the GDPR are calculated on the basis of a method consisting of five steps.
These five steps are systematically reviewed in the following paragraphs. The
Dispute Chamber recalls that it is not obliged to examine criteria that are not
applicable.
III.2.1. Concurrence of infringements and the application of Article 83.3 of the GDPR
One infringing act
116. As a first step, the Dispute Chamber establishes that there is one and the same infringing act.
The infringing processing of personal data constitutes a
series of processing activities carried out by a single will that are contextually, spatially and temporally interconnected. They must be considered as “related” and as
a single act. Specifically, it concerns the continued
processing of personal data in the complainant's mailbox over the long term after the latter had terminated the
collaboration with the defendant.
117. On the basis of this act, the Dispute Resolution Chamber ruled that two of the
established infringements must be punished with an administrative fine,
namely the infringement of Article 5.1a GDPR read in conjunction with Article 6.1 GDPR and the infringement of Articles
12 and 13 GDPR. Unity of operations
118. The Dispute Chamber rules that the infringement of Articles 12 and 13 GDPR can be attributed alongside the infringement
of Article 5.1a GDPR in conjunction with Article 6.1 GDPR when calculating
the fines. The provisions that were infringed pursue
independent objectives (the principle of transparency and the principle of lawfulness),
whereby one provision is not excluded or encompassed by the applicability of the
other, which justifies the imposition of separate fines.
119. In this case, the principle of lawfulness concerns the lack of legal grounds to continue processing the
personal data of the complainant and her contacts after the
defendant no longer had a legitimate interest. Even if the continued processing
after the processing based on legitimate interest had been transparent, the
lawfulness of the processing would still have been violated. 120. In this case, the principle of transparency concerns informing the complainant regarding
the further processing of her personal data in her mailboxes of her contacts Decision on the merits 101/2026 — 38/60
regarding the termination of the cooperation between the complainant and the defendant.Even if the processing had been lawful, the principle of transparency
would still have been violated.
121. The Dispute Chamber refers as an example to Binding Decision 1/2021: “With regard to
the meaning of Article 83(3) GDPR, the Committee notes that, taking into account the
views of the supervisory authorities concerned, in the event of multiple
infringements, multiple amounts may be set.” Furthermore, Article 83(3) GDPR provides that if a controller intentionally or negligently in
relating to the same or related processing activities in an infringement of
multiple provisions of this Regulation, the total amount of the
fine may not exceed the permitted maximum amount for the most serious
infringement. Conclusion
122. In summary, the Dispute Resolution Chamber rules that it may impose two separate fines,
and that the total fine cannot exceed the maximum amount for the
most serious infringement.
III.2.2. Starting amount for the calculation
123. The calculation of administrative fines starts with a harmonised
starting amount based on EDPB Guidelines 04/2022. This takes
account of the classification of infringements according to their nature pursuant to Article
83, paragraphs 4 to 6, GDPR, the severity of the infringement and the turnover of the
undertaking. Classification of infringements under Article 83, paragraphs 4 to 6 of the GDPR
124. The GDPR distinguishes between two categories of infringements: infringements that
are punishable under Article 83.4 of the GDPR on the one hand, and infringements that are punishable under
Articles 83.5 and 83.6 of the GDPR on the other hand. The first category of infringements carries a
maximum fine of EUR 10,000,000 or 2% of the total worldwide annual turnover in the
preceding financial year, if this figure is higher. The second category may result in a
fine of up to EUR 20,000,000 or 4% of the total worldwide annual turnover
in the preceding financial year, if this figure is higher. 125. For the infringement of Article 5.1a GDPR read in conjunction with Article 6.1 GDPR, the maximum administrative fine in accordance with Article 83.5a) GDPR amounts to EUR 20,000,000 or
up to 4% of the total worldwide annual turnover in the preceding financial year, if this figure is higher.
Decision on the merits 101/2026 — 39/60
126. For the infringement of Articles 12 and 13 GDPR, the maximum administrative
fine in accordance with Article 83.5a) GDPR amounts to EUR 20,000,000 or up to 4% of the
total worldwide annual turnover in the preceding financial year, if this figure is higher. 127. Since the higher fine applies, in accordance with Article 83.5(a) of the GDPR,
the Dispute Resolution Chamber may impose an administrative fine of up to EUR 20,000,000
or up to 4% of the total worldwide annual turnover in the preceding financial year, if
this is higher.
Severity of the infringements in each individual case
128. Regarding the infringement of Article 5.1(a) of the GDPR read in conjunction with Article 6.1 of the GDPR (hereinafter ‘infringement of
lawfulness’)
a. Article 83.2(a) of the GDPR – The nature, seriousness and duration of the infringement:
129. Regarding the nature of the infringement, the Dispute Resolution Chamber takes into account that the
principle of lawfulness is a fundamental principle of the protection guaranteed by
the GDPR. It is also included in Article 8.2 of the
Charter of Fundamental Rights of the European Union. The Disputes Chamber rules that
infringements of this core principle are of high severity.
130. With regard to the seriousness of the infringement, the Disputes Chamber takes the following
elements into account:
• Nature of the processing: it concerns further processing of the
personal data in the complainant's mailbox in which both her personal data
and personal data of her contacts are processed. The initial processing
was lawful for both the complainant and her contacts.
• Scope of the processing: it concerns the further processing of
personal data in the complainant's mailbox and consequently her personal data
but also the personal data of her contacts who communicated with her.
However, the complainant had already wound down her activities at the defendant, a fact
of which the contacts were already aware due to the out-of-office setting of
the complainant. • Purpose of processing: the sole purpose of any further processing of
the personal data of the complainant and her contacts in the mailbox after the limited
period of processing under legitimate interest, consisted in being able to recover
potentially commercially sensitive data from the
complainant's mailbox. This objective was formulated in internal communication of the
defendant. Decision on the merits 101/2026 — 40/60
• Number of data subjects: this concerns the mailbox of 1 person, in which personal data
of the complainant and an unknown number of contacts were further processed.
• Extent of the damage: There is no information that the unlawful further
processing has led to an abuse of the personal data of the complainant or
of her contacts. Given the professional context of the mailbox, one can
expect that these personal data are rather limited and non-sensitive,
although urgent, personal messages can also be expected in such a mailbox. Moreover, the complainant herself had already previously informed her correspondents that she was only accessible via that email address to a limited extent (for external parties)
or no longer accessible (for internal parties).
Based on this assessment, the Disputes Chamber rules that the severity of the infringement
is of low weight, since it has not been demonstrated that the personal data were effectively
used, while they were retained.
131. Regarding the duration of the infringement, the Disputes Chamber notes that the
personal data of the complainant and her contacts in the mailbox should have been
deleted on June 1, 2023, which was not carried out. As of June 1, 2023, the defendant therefore
no longer had a legal basis to process the personal data. It appears from the conclusions of
2025 that all personal data are still in the mailbox and are available. Although the defendant claims that, since the complainant's notification regarding a
potential procedure against the defendant, he once again has a legal basis to retain the
personal data, this new situation is a direct consequence of the
failure to delete and thus further processing of the personal data without a legal basis
and of the failure to grant full access to the personal data despite the request
of the complainant. After all, the complainant first wanted to check which communications she had missed,
before her mailbox was to be deleted, which was a legitimate concern, given the
unlawful continued processing of the personal data in this mailbox. The
Dispute Chamber considers the duration of the infringement to be of average severity because the
retention of all personal data continues to this day. The
argument that the mailbox had to remain in existence because of this procedure is
unfounded since the absence of a legal basis is precisely what caused this procedure
and since there are other, technically safer ways to retain the necessary
information for this procedure.
b. Article 83.2.b) GDPR – The intentional or negligent nature of the infringement:
132. In the present case, according to the Dispute Chamber, there was no intention on the part of the defendant to
intentionally continue to unlawfully process the personal data, but there was at least a case of negligence, which satisfies the requirements of the case law of
75
the Court of Justice of the EU. Although the defendant argues that the continued
processing involved a one-off human error, it is clear from the decision that the
defendant was negligent with regard to the minimum technical and
organizational measures, in particular the automatic deletion of (all
personal data in) the mailbox of a departed employee after a period of
processing under legitimate interest. Moreover, the file shows that the
defendant was aware of previous decisions by the Disputes Chamber regarding the
correct closure of an ex-employee's mailbox. Given that the defendant himself
speaks of approximately 1,000 departing employees per year, he should have taken sufficient measures earlier and
sooner to rule out any human error.
The Disputes Chamber rules that the negligent nature of the infringement must be considered to be of
average severity.
c. Article 83.2.g) GDPR – The categories of personal data to which the infringement
relates:
133. The disputed processing concerns the personal data of the complainant and of her
contacts in her professional mailbox. Although prima facie such personal data are not of a sensitive or special nature, the Disputes Chamber rules that they
nevertheless belong to categories of personal data which data subjects
would generally not reasonably expect to be further
processed by the defendant. This category is assessed as neutral.
134. In his response to the sanction form, the defendant argues that the duration of the infringement
is not attributable to him, given that on 2 May 2024 he had asked the DPA for advice
regarding the deletion of the mailbox after the complainant had requested that it not be
deleted until she had had access to it. The defendant feels supported in this view since
the Disputes Chamber also imposes an order for access on the defendant. The defendant
states: “[defendant] therefore believes that a ‘medium severity’ for the duration of the
infringement is unjustified, given that this duration is entirely due to the DPA’s choice
not to answer [defendant]’s legitimate question as to whether she was allowed to
delete the mailbox, and the long duration of the proceedings before the Disputes Chamber. A low
76
severity is therefore appropriate.”
75
CJEU, Deutsche Wohnen SE v. Staatsanwaltschaft Berlin, judgment of 5 December 2023, C-807/21, ECLI:EU:C:2023:950,
paragraph 78.
76Piece 39, Defence of [defendant] of 24 April 2026, p. 16, paragraph 3. Decision on the merits 101/2026 — 42/60
135. The Dispute Resolution Chamber establishes that the complainant left the defendant on 1 May 2023
and ruled that the defendant could continue to process the personal data of the
complainant for one month for the sake of its legitimate interest. 136. First, the complainant herself informs the defendant that her data is still being processed unlawfully in January 2024, eight months after the defendant no longer had a legitimate interest and at that time 8x the duration of the processing under the legitimate interest.
137. Second, the complainant informs the defendant on 20 February 2024 that she will open a file at the GBA and reports to the defendant on 6 March 2024 that her email will be added to the complaint at the GBA. The defendant was therefore aware of the complainant's intention to file a complaint with the GBA no later than 6 March 2024. This complaint was effectively filed on 23 April 2024. The submission of a request for advice by the defendant to the GBA, when he knows that a complaint has been filed or will be filed, is no argument to allow a breach of the GDPR to continue until the GBA has responded to the request for advice or has taken a decision regarding the complaint, precisely because the processing time for such complaints at the Disputes Chamber can be long. After all, it is the defendant who is the controller for this processing. This responsibility does not transfer to the GBA in the event of a request for advice regarding this. The Disputes Chamber hereby points out, for the sake of completeness, that accountability (Article 5.2 GDPR) is central to the GDPR. It is not the task of the supervisory authority to give advice regarding an individual case, certainly not if proceedings concerning precisely this case are pending before that same supervisory authority. 138. Thirdly, this complaint is precisely the result of the defendant's breaches of the
protection of the complainant's personal data. One of those breaches was the
unjustified restriction of the complainant's right of access, who was looking for the e-
mails that she had all missed because the defendant had not taken compliant
transparency measures towards her contacts and because the processing
continued after the defendant's legitimate interest had ended. The dilemma the defendant was therefore confronted with was caused entirely by his
own failure to monitor the complainant's mailbox and his limitations on her
right of access. The defendant could therefore have communicated more transparently with the complainant regarding the granting of access, which he did do in the submissions to the
Dispute Resolution Chamber, so that a settlement might have been
found, the complainant could have checked her missed emails and the
77
See paragraph 87 of this decision for this. Decision on the merits 101/2026 — 43/60
the defendant could have deleted the mailbox before a complaint was filed, in this case in
the spring of 2024.
139. Fourthly, the Disputes Chamber establishes that the defendant chose
to allow the mailbox to continue to exist in a deactivated state for the duration of these proceedings
and to link a license to this mailbox again, while technical possibilities
exist to export the contents of the mailbox to a PST file and to completely delete the mailbox itself. The defendant was aware of this technical possibility, because he
proposed it himself to the complainant on 6 April 2024. Although the personal data
would still be processed unlawfully, this technical measure would have substantially reduced the
risk of processing the complainant's personal data
and would have allowed the mailbox to be deleted already without restricting the complainant's right of
access, possibly in the future. 140. The Disputes Chamber rules that the continued processing of personal data without a legal basis for at least eight months is already sufficient grounds to assess the duration of the infringement as being of average severity. Given that the concerns of the complainant were clear from her communication, in particular that she wanted access to the emails she had missed, the defendant had the opportunity to stop and remedy these infringements, but chose to wait for a response from the GBA regarding a request for advice and the eventual outcome of this procedure. Due to this indecisiveness of the defendant, a situation has now arisen whereby the unlawfully processed personal data of the complainant (and her contacts) have already been processed for almost 3 years in an existing mailbox with an active license. The Disputes Chamber sees no grounds to reduce the average severity for the duration of the infringement to a low severity. 141. In his response to the sanction form, the defendant also states that the infringement was caused
by a one-off human error and that there was therefore no question of negligence
as the Dispute Chamber had stated. Moreover, the defendant had already taken proactive
measures to automate the deletion of the mailboxes and had
at the time of the hearing already added a validation step to the existing process to
verify whether all deactivated accounts were also deleted after one month.
142. As regards the intentionality or negligence of the infringements (criterion as
included in Article 83.2.b GDPR), there is no clear intent on the part of the
defendant to unlawfully process the complainant's personal data. The
moral element of the infringement has nevertheless been established on the basis of case law
78
of the CJEU. After all, negligence requires an element of awareness, but not
78 CJEU, Deutsche Wohnen SE v. Staatsanwaltschaft Berlin, judgment of 5 December 2023, C-807/21, ECLI:EU:C:2023:950,
paragraph 78. Decision on the merits 101/2026 — 44/60
element of will. This element of awareness is satisfied when the person addressed
should have known of a provision the criminal nature of his conduct, regardless of whether
he was aware of violating these provisions. The decisive factor is therefore
whether the person addressed could have known of a provision whether his conduct was unlawful and not whether
he was actually aware of it. A controller is
expected, within the framework of his duty of care, to inform himself and familiarize himself
with the legislation and obligations applicable to him. In this regard,
Articles 5.1a and 6.1 of the GDPR are very clear and specify that the defendant may only process
personal data if this processing is lawful and is therefore
based on one of the legal grounds listed in Article 6.1 of the GDPR.
143. The Disputes Chamber establishes that the defendant is aware of the management of
mailboxes of departed employees, of the continued processing of these mailboxes
under the legitimate interests of closing these mailboxes after one month.
It was already provided for in the 2016 management processes that the mailbox would remain for one
month and then be irrevocably deleted. Since the defendant was aware of these
rules regarding the closing of a mailbox, but these were not applied to the
mailbox of the complainant, there is already sufficient reason for the Disputes Chamber to speak
of negligence. 144. The Disputes Chamber also established that the list of deactivated profiles
dated June 1, 2023, on which the complainant was listed, included another profile,
whose profile, according to the list, had left the defendant on October 4, 2022, being 6 months before his profile was deactivated and passed on to be deleted.
145. Furthermore, the Disputes Chamber established that those same
management processes also involved a final step, namely the transfer
of the list of effectively deleted mailboxes by the competent service to the person who had requested the
deletion of the mailboxes. The applicant for the deletion, in this case the ‘ICT
second line service’, could therefore perform a monthly check on the effective deletion
by comparing the list of requests with the list of effectively deleted mailboxes.Moreover, following this check, the ICT second-line service was expected to set the account status to
‘removed’. Thus, not only was the defendant aware of the correct
closing of a mailbox, but there was also a control mechanism for this process, which
apparently was not applied at the time of the complainant's departure.
146. Finally, the defendant states that he had already started a change process in 2022
to automate the closing of the mailboxes, not least because
it involved approximately 1,000 profiles per year. Although the defendant had thus
established that he ran a risk by still performing this process manually and Decision on the merits 101/2026 — 45/60
although he had a procedure to monitor this process, the defendant
therefore failed to introduce a new, temporary control measure in 2022 or to apply the
existing control measure to avoid this risk of errors in the manual
process. The provisional solution that the defendant thus proposes as a
mitigating measure to avoid negligence and which was introduced at the time of the
hearing, in this case in November 2025, already existed in the
management processes in 2016 but was never applied, not even when the defendant
determines in 2022 that this process entails risks and should be automated
or when he determines that the complainant's mailbox has not been deleted in January 2024.
147. The Dispute Chamber rules that the defendant was negligent because he was aware
of the correct closing of a mailbox of a departed employee, but did not apply this
in the case of the complainant and rules that this negligence is of
moderate severity because he did not apply a control procedure existing since 2016 which could have prevented or at least noticed the
breach of the complainant's mailbox, not even temporarily when he initiated a procedure to this process to
automate or when the complainant informed him that her mailbox was not deleted as
it should be.
148. Based on an assessment of the above factors, the severity of the
infringement is determined. The Disputes Chamber takes into account that the infringement concerns a
fundamental principle of data processing that was
committed with negligence for a continuous period. The Disputes Chamber concludes that
this concerns an infringement of moderate severity. 149. In accordance with paragraph 60 of the EDPB Guidelines, the Dispute Chamber shall set the
base amount for further calculation at a point between 10 and 20
% of the applicable statutory maximum amount. Since the defendant had already initiated a
corrective procedure, the Dispute Chamber decides to set the
base amount at the lower end of the range. The Dispute Chamber will set the
base amount for further calculation at 10% of the statutory
maximum amount contained in Article 83.5 GDPR. 150. Regarding the infringement of Articles 12 and 13 GDPR (hereinafter ‘infringement of the
transparency obligation’)
a. Article 83.2(a) GDPR – The nature, seriousness and duration of the infringement:
151. Regarding the nature of the infringement, the Dispute Resolution Chamber notes that the defendant must ensure the
fair and transparent processing of personal data.
First, the complainant must at least be informed that data concerning her
are being (further) processed and for how long, so that she can potentially exercise control over this data Decision on the merits 101/2026 — 46/60
and processing. Secondly, the complainant's contacts, who share their
own personal data with the complainant, must be informed that the complainant
no longer has access to her mailbox and that their personal data will therefore no longer reach the complainant, so that they can stop sharing their
personal data via this channel. The Disputes Chamber rules that the nature of this
infringement is of high severity.
152. With regard to the severity of the infringement, the Disputes Chamber takes the following
elements into account:
• Nature of the processing: it concerns further processing of the
personal data in the complainant's mailbox in which both her personal data
and personal data of her contacts are processed. The initial processing
was transparent to both the complainant and her contacts. • Scope of processing: this concerns the further processing of
personal data in the complainant's mailbox and consequently her personal data,
but also the personal data of third parties who communicated with her. By not being
transparent about the termination of the collaboration with the complainant, the
volume of the personal data of the contacts increased unnecessarily. However, the complainant had
already scaled down her activities at the defendant, a fact of which the
complainant's contacts were already aware through the complainant's set out-of-office
messages. Due to the actions of the complainant, the volume was therefore already
limited, but due to a lack of transparency on the part of the defendant, the
volume was not further limited once the complainant no longer had control over her
mailbox.
• Purpose of processing: the purpose of the further processing of personal data
in the mailbox for a limited period consists precisely in
informing the complainant's contacts that the complainant was no longer employed by the defendant. Given the mix of personal data and commercially sensitive data in this
mailbox, the lack of transparency regarding this is problematic and
creates at least the perception of an additional purpose for further processing. Moreover,
internal documents of the defendant show that there was indeed an
additional purpose, namely the retrieval of commercially sensitive data
from the complainant's mailbox.
• Number of data subjects: this concerns the mailbox of 1 person, in which personal data
of the complainant and an unknown number of contacts were further processed.
• Extent of the damage: although damage is difficult to estimate in this case,
the complainant argues that she suffered at least reputational damage by leaving several e-mails unanswered, since she did not know that these e-mails
had been sent to her. With sufficient transparency, this potential
damage could have been minimized. However, there is no information indicating that the non-transparent further processing led to a misuse of the complainant's personal data. Given the professional context of the mailbox,
one can expect that this personal data is rather limited and non-sensitive,
although urgent, personal messages can also be expected in such a mailbox.
Moreover, the complainant herself had previously informed her correspondents that she was only accessible to a limited extent via that email address (for external parties) or no longer accessible (for internal parties).
Based on this assessment, the Disputes Chamber rules that the severity of the infringement is
of low weight, given that it concerns a professional context in which it can be expected
that no sensitive personal data were shared via this channel,
since the complainant herself had already informed her correspondents of her
limited accessibility and since it has not been demonstrated that misuse was made
of the personal data of the complainant or her contacts, which were not processed further in a transparent manner.
153. With regard to the duration of the infringement, the file shows that the complainant left the defendant on 1 May 2023 and that she received confirmation in January 2024 from the defendant's DPO that her data in her mailbox was continuing to be processed.
This confirmation was provided after she herself had requested this transparency. However, the complainant had already noticed in September 2023 that her mailbox was still active, without immediately contacting the defendant about this and thus obtaining transparency regarding this continued processing. Given the limited duration of the infringement, the Disputes Chamber considers the duration of the infringement to be of low severity.
b. Article 83.2.b) GDPR – The intentional or negligent nature of the infringement:
154. In this case no clearly evident intent on the part of the defendant has been established to
intentionally violate his duty of transparency, but there is at least negligence,
which satisfies the requirements of the case law of the Court of Justice of
79
the EU. Although the defendant argues that it concerned a one-off, human error,
it is clear from the decision that the defendant was negligent in the area of the
minimal technical and organisational measures, in particular the automation of
an out-of-office message, to ensure the transparency of further processing.
79 CJEU, Deutsche Wohnen SE v. Public Prosecution Service Berlin, judgment of 5 December 2023, C-807/21, ECLI:EU:C:2023:950, paragraph 78. Decision on the merits 101/2026 — 48/60
Moreover, it appeared that the defendant had already established this vulnerability and initiated a
improvement process in 2022, without, however, taking a minimum of provisional
measures to already address the vulnerability. It was only after the complaint that
the defendant initiated an initial check on the vulnerable procedure. The
file also shows that the defendant was aware of previous decisions of the
Dispute Resolution Chamber regarding the correct, and therefore transparent, continued processing of the mailbox
of a former employee. Given that the defendant himself speaks of approximately 1,000
departing employees per year, he should have taken sufficient measures
earlier and sooner to rule out any human error. The Disputes Chamber
rules that the negligent nature of the infringement must be
considered to be of average severity.
c. Article 83.2(g) GDPR – The categories of personal data to which the infringement relates:
155. The disputed processing concerns the personal data of the complainant and of her contacts in her professional mailbox. Although prima facie such personal data are not of a sensitive or special nature, the Dispute Resolution Chamber rules that they nevertheless belong to categories of personal data which data subjects would generally not reasonably expect to be further processed by the defendant. This category is assessed as neutral.
156. The severity of the infringement is determined on the basis of an assessment of the above factors. The Dispute Resolution Chamber takes into account that the transparency of the processing is fundamental to a data subject. A data subject must know that his personal data are being (further) processed before he can exercise any control over this processing. However, this concerns a further processing of personal data
where the initial processing was fully transparent and it concerns the processing of
personal data in a professional context, where it can be expected that the
data subjects do not exchange sensitive personal data. Moreover, the complainant
had already set up two out-of-office messages herself that made it clear that she was only reachable to a limited extent (for external parties) or no longer reachable (for internal parties) via that e-
email address. The Disputes Chamber concludes that this concerns an infringement of minor severity.
157. In his response to the sanction form, the defendant states that he agrees with this
conclusion, although he refers to his earlier
comment for the assessment of the negligence. 158. In accordance with paragraph 60 of the EDPB Guidelines, the Dispute Chamber shall determine the
base amount for further calculation at a point between 0 and 10% of the applicable statutory maximum amount. Since the defendant had already initiated a
corrective procedure, the Dispute Chamber decides to determine the
base amount at the lower end of the range. The Dispute Chamber will determine the
base amount for further calculation at 1% of the statutory
maximum amount contained in Article 83.5 GDPR.
The defendant's turnover shall be taken into account as a relevant element of the calculation with a view to
imposing an effective, deterrent and proportionate fine pursuant to
Article 83.1 GDPR.
159. In accordance with Article 83.1 of the GDPR, the Dispute Resolution Chamber must ensure that the administrative fines imposed are effective, proportionate, and dissuasive. Thus, it also reflects a distinction based on the size of the undertaking in the initial amounts.
160. Articles 83.4 to 83.6 of the GDPR stipulate that the total worldwide annual turnover of the preceding financial year must be used for the calculation of the administrative fine. In this regard, the term “previous” must be interpreted in accordance with the case law of the Court of Justice in competition law, so that the relevant event for the calculation is the decision to fine the supervisory authority, and not the time of the sanctioned infringement. 161. In calculating the fine in the sanction form, the Dispute Chamber based its calculation on the annual turnover of 2024, as that of 2025 was not yet known. However, the defendant confirmed in his response to the sanction form that the annual turnover for 2025 amounted to EUR 804,
302,737.71. The Dispute Chamber proceeds to calculate using this turnover figure.
162. Based on the foregoing, the Dispute Chamber establishes that 4% of the turnover in the
preceding financial year amounts to EUR 32,172,109.51, which is higher than EUR 20,000,000.
Thus, the maximum total administrative fine in accordance with
Article 83.5 GDPR amounts to EUR 32,172,109.51. In concrete terms, this leads to the following
base amount:
• regarding the infringement of lawfulness, the Dispute Resolution Chamber set the
base amount for further calculation at 10% of the statutory
maximum amount included in Article 83.5 GDPR. In this case, this leads to a
base amount of EUR 3,217,210.95;
• regarding the infringement of the transparency obligation, the Dispute Resolution Chamber set the
base amount for further calculation at 1% of the statutory
maximum amount included in Article 83.5 GDPR. In this case, this leads to a
base amount of EUR 321,721.10.
The base amount for the total administrative fine is EUR 3,538,932.15. Decision on the merits 101/2026 — 50/60
163. In accordance with the EDPB Guidelines, the Dispute Chamber rules that a
further adjustment of this baseline amount based on the defendant's turnover is not
appropriate.
III.2.3. Aggravating and mitigating circumstances
164. Under the GDPR, the supervisory authority, after having made an assessment
of the nature, seriousness and duration of the infringement, the intentional or negligent nature
of the infringement and the categories of personal data to which the infringement relates (see above), must take into account the other aggravating and mitigating
factors referred to in Article 83.2 GDPR. For reasons of
efficiency, the Dispute Chamber will make this assessment for both infringements together.
• Article 83.2.c) GDPR – The measures taken by the controller or processor
to limit the damage suffered by the data subjects:
The Dispute Chamber establishes that the defendant communicated immediately with the
complainant as soon as the latter had expressed her concerns. A proper out-of-office
was set up so that the contacts were informed of the
complainant's departure. These constitute mitigating circumstances. • Article 83.2.d) GDPR – The extent to which the controller or the
processor is responsible in view of the technical and organisation
measures which he has implemented in accordance with Articles 25 and 32 GDPR:
The Dispute Chamber established in its decision that the correct further processing
of the personal data of departing employees and the closing of the
mailbox and deletion of this personal data was a manual process, in which
one can expect that this process, given the state of the art and the scale of
the defendant, would proceed fully automated, which would
exclude human errors. The defendant had already started
automating this procedure one year before the complainant's departure, which, however, was still not in force at the
time that the complainant discovered the further processing. The Dispute Chamber
rules that the fact that the defendant had already initiated a procedure for
automating the process is a mitigating circumstance. • Article 83.2(e) GDPR – Previous relevant infringements by the
controller or processor:
80EDPB–Guidelines 04/2022 on the calculation of administrative fines under the GDPR(v2.1, 24 May 2023),
paragraph 70. Decision on the merits 101/2026 — 51/60
No previous, relevant infringements have been established on the part of the defendant, as regards a
mitigating circumstance.
• Article 83.2.f) GDPR – The extent to which cooperation with the supervisory authority has taken place
to remedy the infringement and to limit the possible negative consequences
thereof:
Not applicable
• Article 83.2.h) GDPR – The manner in which the supervisory authority became aware
of the infringement, in particular whether, and if so to what extent, the
controller or processor reported the infringement:
The DPA became aware of the infringement through a complaint.
• Article 83.2.i) GDPR – Compliance with the measures referred to in Article 58, paragraph 2,
insofar as these have previously been taken with regard to the controller or
processor in question in relation to the same matter:
Not applicable.
• Article 83.2.j) GDPR – Adherence to approved codes of conduct in accordance with
Article 40 or to approved certification mechanisms in accordance with Article
42:
Not applicable. • Article 83.2.k) GDPR – Any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial gains made or losses avoided, whether or not directly resulting from the infringement:
There is no information in the file indicating that the unlawful and non-
transparent further processing of the personal data of the complainant and her contacts
has yielded any benefit to the defendant, which indicates a mitigating
circumstance.
165. The Dispute Chamber takes into account that the defendant's DPO responded immediately
to the complainant's concerns, that the defendant had already initiated a
procedure to automate the management of the mailboxes, that there were no
previous complaints against this defendant, although it concerns a large, diffuse organization
, and that no information in the file indicates that the defendant would have derived any
benefit from these infringements. These circumstances are assessed as
mitigating circumstances.
166. The Disputes Chamber decides Decision on the merits 101/2026 — 52/60
• to reduce the base amount of EUR 3,217,210.95 for the infringement of lawfulness
by 95%, resulting in a reduction from EUR 3,056,350.40 to EUR 160,
EUR 860.55.
• to reduce the base amount of EUR 3,217,21.10 for the infringement of the transparency obligation
by 95%, resulting in a reduction from EUR 305,635.01 to EUR 16,
EUR 086.06.
167. The Disputes Chamber concludes that no other circumstance is of such relevance that
it should be taken into account as an aggravating or mitigating circumstance.
III.2.4. Alignment with the maximum amount
168. The maximum amount for both fines combined in the present case has already been calculated above.
This amounts to 2,000,000 EUR in accordance with Article 83.5(a) GDPR or to 4% of the total worldwide annual turnover in the preceding financial year, if this figure is higher.
169. The defendant's annual turnover for 2025 amounts to EUR 804,302,737.71. The
Dispute Chamber establishes that 4% of the annual turnover in the preceding financial year amounts to EUR 32,172,109.51, which is higher than EUR 20,000,000. Thus, the
maximum administrative fine in accordance with Article 83.5 GDPR amounts to EUR 32,172,109.51.
EUR.
170. In this case, the two fines amount to EUR 1,608,60.55 and EUR 1,608,606.06 respectively,
resulting in a total fine of EUR 176,946.61, which is below the maximum
fine of EUR 32,172,109.51.
III.2.5. Effectiveness, reasonableness and deterrent effect
Effectiveness
171. Recital 148 of the GDPR emphasizes that administrative fines must be
imposed “[with] a view to the stronger enforcement of the rules of this
Regulation”. The fine imposed must therefore be high enough to achieve this
objective.
Given the defendant's annual turnover, the total fine amounts to just above
0.02% of this annual turnover and therefore appears less effective. The Disputes Chamber is
however, of the opinion that imposing a limited fine can in itself be effective,
certainly in the case of a first offense. Decision on the merits 101/2026 — 53/60
The Disputes Chamber considers that the total fine of EUR 176,946.61 in this case
is suitable to vigorously enforce the fundamental principles that were infringed.
Proportionality
172. The principle of proportionality entails that the amounts of the fines must not be
disproportionate to the objectives pursued and that the imposed
fine must be proportionate to the infringement, viewed as a whole, with due regard to
in particular its seriousness.
173. In this case, the infringements in question were assessed as being of low and medium severity. In accordance with paragraph 60 of the EDPB Guidelines, the
Dispute Chamber shall:
• in the case of minor infringements, set the baseline amount for further calculation
at a point between 0 and 10% of the applicable statutory
maximum amount. The Dispute Chamber notes that the defendant had already initiated an
adjustment procedure. Therefore, it set the baseline amount
for further calculation at 1% of the statutory
maximum amount contained in Article 83.5 GDPR.
• in the case of minor infringements, set the baseline amount for further
calculation at a point between 10 and 20% of the applicable
statutory
maximum amount. The Dispute Chamber notes that the defendant had already
initiated an adjustment procedure. Therefore, the Dispute Chamber set
the baseline amount for further calculation at 10% of the statutory
maximum amount contained in Article 83.5 GDPR. 174. Moreover, the Disputes Chamber took into account as mitigating circumstances
that the defendant's DPO responded immediately to the complainant's
concerns, that the defendant had already initiated proceedings to
automate the management of the mailboxes, that there were no prior complaints against this
defendant, although it concerns a large, diffuse organization, and that no
information in the file indicates that the defendant would have derived any benefit
from these infringements. On the basis of these mitigating circumstances, the
Disputes Chamber reduced both fines by 95%.
175. The Disputes Chamber rules that the fine is proportionate.
176. In his response to the sanction form, the defendant states that the proposed fines
are absolutely not proportionate because they allegedly do not take into account:
• the fact that access to the complainant's mailbox was restricted; Decision on the merits 101/2026 — 54/60
• the duration of the proceedings before the DPA and the lack of a response to the
defendant's request for advice to the DPA, as a result of which the defendant was compelled by the
request of the complainant to retain the alleged infringements;
• the defendant's strict compliance with the GDPR, his prompt responses and his
cooperative attitude;
• the fact that the alleged infringements constitute only a one-off infringement and
• the fact that the defendant has already proactively
automated the deletion of the mailboxes.
177. With regard to the restriction of access to the mailbox, the Disputes Chamber has already
established earlier in the decision that the defendant does not demonstrate this restriction, although
he is capable of doing so and he could also have exported the mailbox and stored it separately,
without it having to remain in existence deactivated with a license at the processor, in
this case the defendant's mail provider. The risk of a still existing mailbox with
a license is immeasurably greater for the data in the mailbox, including the
personal data of the complainant and her contacts, than an exported and protected
stored file. Moreover, the mailbox remained available to the
defendant, albeit with a strict procedure that had to be followed for any
access, while the complainant had no control over this whatsoever and of which it has been established
that her right of access to this mailbox was also limited. The Disputes Chamber also takes
account of the fact that the mailbox should have been deleted as early as June 1, 2023 in order to
consider that the fine is proportionate to the complainant's complete loss of control
over her personal data in the mailbox held by the defendant and the risk that remains
existing on the personal data in this deactivated mailbox with limited access.
178. Regarding the duration, the Disputes Chamber has already previously addressed the remarks
of the defendant. The continued processing of various personal data of the complainant
and her contacts without legal basis for a period of nearly a year before the
defendant proposes to export these to a file, which ultimately does not
happen, causing the mailbox to continue to exist to this day, is proportionate to
the amount of the fine.
179. Regarding the strict compliance with the GDPR by the defendant, the Dispute Resolution Chamber establishes
in this file alone breaches of lawfulness, transparency, the
technical and organizational measures to guarantee the principles of the GDPR,
the right of access and the principle of confidentiality and integrity in conjunction with the accountability principle. Moreover, the Dispute Resolution Chamber has no
insight into any other processing of personal data by the defendant, making it impossible for it to take this compliance into account in order to potentially
adjust the amount of the fine, upwards or downwards.
Decision on the merits 101/2026 — 55/60 180. Regarding his prompt responses, the Disputes Chamber points out to the defendant the
mitigating circumstances, in which the DPO's response to the complaint was
taken into account in the assessment to reduce the fine by 95%.
181. Regarding the cooperative attitude, the Disputes Chamber judges this attitude to be
neutral, without further ado, and sees no reasons to increase or decrease the amount of the fine on the basis of this
argument.
182. Regarding the fact that these infringements constitute the first infringement established
by the Disputes Chamber, it points out to the defendant the mitigating circumstances,
in which the fact that no prior complaints were filed against the defendant was
taken into account in the assessment to reduce the fine by 95%. 183. Regarding the fact that the defendant had proactively initiated and carried out the automation of closing the mailboxes, the Disputes Chamber points to the mitigating circumstances, in which the fact that the defendant had already initiated proceedings was taken into account in the assessment to reduce the fine by 95%.
184. The Disputes Chamber is aware of the magnitude of the absolute amount of the fine in this case, but in relation to the defendant's annual turnover, it considers this fine to be rather on the low side, specifically only 0.02% of his annual turnover.
Deterrent effect
185. When imposing a monetary fine, the Disputes Chamber takes into account both the specific and the general deterrent effect. A monetary fine is deterrent when the fine prevents a private individual from violating the objectives and regulations contained in EU law. 186. The deterrent nature of the fine must have two dimensions. It must deter the
person to whom the fine is imposed from repeating the infringement in the future,
but it must also deter other persons from repeating the infringing
behavior of the first person.
187. Various factors determine the deterrent effect of a fine: the nature and the
amount of the fine and the likelihood that the fine will be imposed are decisive in this
respect. A fine must be high enough to have a significant financial
impact on the undertaking committing the infringement, while the fine must be proportionate
to the seriousness of the infringement. In other words, the criterion of
deterrence overlaps with that of effectiveness. It is important that undertakings
cannot make a financial profit on the basis of unlawful processing of
personal data.
188. In the present case, the total fine is low relative to the turnover of the
defendant. However, given its absolute amount, the fine amount remains sufficiently
deterrent to prevent the defendant from repeating its infringement of the GDPR rules. Moreover, it is also intended to deter other undertakings from committing
similar infringements. This fine, which is proportionate to the severity of the infringement
and takes into account the turnover of the defendant, is intended to have both a specific
and a general deterrent effect.
189. In his response to the sanction form, the defendant states that the fine has no
specific deterrent effect on him because all measures have already been
taken to avoid future similar infringements. The defendant also refers
to the judgment of the Market Court of 22 January 2025, which concerned a
specific, isolated violation caused by negligence and was not
81 82
the result of an intentional act. The Disputes Chamber reiterates that an administrative fine is not intended to bring the processing into conformity with the principles of the GDPR, for which corrective measures have already been imposed, but rather to guarantee robust enforcement of the rules of the GDPR, both towards the defendant and towards other controllers in a similar situation. Regarding the reference to decision 2024/AR/1615 of the Market Court, the Disputes Chamber points out that
• the imposition of an administrative fine is an assessment of expediency that the Disputes Chamber must make in full jurisdiction based on the concrete elements of the case;
• five different infringements were established within the scope of this complaint, of which an administrative fine is imposed for only two infringements and
The Disputes Chamber sees no reason to adjust the amount of the fine based on these arguments of the defendant. 190. The totality of the elements set out above justifies an effective,
proportionate and deterrent sanction as referred to in Article 83 GDPR, taking into account
the assessment criteria set out therein. The Dispute Resolution Chamber points out that the
other criteria of Article 83.2 GDPR are in this case not of a nature to lead to a
81Piece 39, Defence of [respondent] of 24 April 2026, p. 19, paragraph 12.
82See paragraph 106 of this decision for this. Decision on the merits 101/2026 — 57/60
an administrative fine other than that which the Dispute Resolution Chamber has imposed in the context of
this decision. Decision on the merits 101/2026 — 58/60
IV. Publication of the decision
191. In view of the importance of transparency regarding the decision-making of the
Dispute Chamber, this decision is published on the website of the
Data Protection Authority. However, it is not necessary for the
identification details of the parties to be disclosed directly for this purpose. Decision on the merits 101/2026 — 60/60
Pursuant to Article 108, § 1 of the WOG, an appeal against this decision may be lodged with the Market Court (Brussels Court of Appeal) within a period of thirty days from the
notification, with the Data Protection Authority as defendant. Such an appeal may be lodged by means of a petition in opposition which must contain the particulars listed in Article 1034ter of the Judicial Code. The 83
petition in opposition must be submitted to the registry of the Market Court
in accordance with Article 1034quinquies of the Judicial Code, or via the Justice e-Deposit
information system (Article 32ter of the Judicial Code).
(Signed). Hielke H IJMANS
Director of the Disputes Chamber
83 The petition shall state, under penalty of nullity:
1° the day, the month and the year;
2° the name, first name, place of residence of the petitioner and, where applicable, his capacity and his national register or
enterprise number; 3° the name, first name, place of residence and, where applicable, the capacity of the person to be summoned;
4° the subject matter and a brief summary of the grounds of the claim;
5° the judge before whom the claim is brought;
6° the signature of the petitioner or of his lawyer.
84 The petition with its annex shall be sent, in as many copies as there are parties concerned, by registered mail
to the registrar of the court or deposited at the registry.




