APD/GBA (Belgium) - 132/2025

From GDPRhub
APD/GBA - 132/2025
Authority: APD/GBA (Belgium)
Jurisdiction: Belgium
Relevant Law: Article 2 GDPR
Article 5(1)(a) GDPR
Article 6(1)(f) GDPR
Article 6(1)(b) GDPR
Article 12 GDPR
Article 13 GDPR
Article 15 GDPR
Law of 19 July 1991 on population registers, identity cards, aliens’ cards and residence documents.
Type: Complaint
Outcome: Upheld
Started:
Decided: 19.08.2025
Published:
Fine: n/a
Parties: n/a
National Case Number/Name: 132/2025
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Dutch
Original Source: APD/GBA (in NL)
Initial Contributor: Le

The DPA held that processing an ID card for the verification of a bike rental company’s customers was not necessary for the performance of the contract or for the purpose of fraud prevention.

English Summary

Facts

The controller is a bike rental company that operates on a subscription basis.

In order to rent a bike a customer must first register online. For electric bicycles, after registration, the controller required the verification of customers by requesting a photo of their ID card. Then it transmitted the ID image to a processor, a company specialising in identity verification software, which verified its authenticity. Only after the verification could a customer make an appointment to pick up a bicycle. At the time of the bike pick up, the customer had to present their identity card again.

Following a billing dispute, in January 2024, the data subject made an access request to which the controller did not respond.

In March 2024, the data subject lodged a complaint with the DPA (Autorité de protection des données/Gegevensbeschermingsautoriteit – APD/GBA), claiming that the photographing of the back of her identity card, on which her national registry number appeared, was not necessary, and that the processing of her photo in her ID card was unlawful. She further complained that she was not informed in advance about the processing of her ID photo, of her national registration number and of the processing of location data of the rental bicycle. Lastly, she complained that her access request was not answered.

The controller claimed that the processing of personal data for the verification was necessary in order to fulfill its contractual obligations, and, in any case, it was necessary for purposes of fraud prevention. It added that the processor used a privacy filter and only processed the personal data on the ID temporarily, before the masking of the data effectively took place. According to the controller, this processing was considered merely a ‘reading of data points’, which was permitted under Belgian law.

After the complaint was lodged, the controller stopped performing this verification process and deleted the data collected as a result of this processing.

Holding

First, the DPA held that the personal data objectively necessary for the performance of the contract were the data subject's name and date of birth. Then it examined whether the actual processing was in line with contractual necessity Article 6(1)(b) GDPR.

The DPA held that the mere visual checking of the data in the ID card at the moment of the bike pick up is not considered processing of personal data within the meaning of Article 2 GDPR, since these data are not intended to be included in a file.

On the other hand, the processor performed an elaborate verification which constituted processing of personal data on behalf of the controller. The DPA found that although a privacy filter was present in this processor's application, it was insufficient since processing of all personal data on the ID card still took place, albeit briefly. The DPA ruled that this reading of data points still constitutes processing of personal data, and must comply with the GDPR.

Consequently, it found that the processing of personal data on the ID card beyond name and date of birth was a separate processing, not covered by contractual necessity.

Second, the DPA held that the further processing was not covered by legitimate interest, applying the necessity test. It found that the controller did have a legitimate interest in fraud prevention, but the particular processing was not necessary for the intended purpose, since an equivalent alternative existed. Therefore, it found that the controller violated Article 6(1)(f) GDPR and Article 5(1)(a) GDPR for processing personal data without a legal basis.

Third, the DPA pointed out that since the verification procedure was judged as not lawful, alleged processing of the data subject’s national registry number in breach of the principle of data minimisation it no longer relevant.

Fourth, the DPA ruled that the controller also violated the transparency principle of Article 5(1)(a) GDPR in conjunction with Article 12 GDPR and Article 13 GDPR. It found that the controller did not address the processing of the ID card by the processor in its privacy notice. It noted that it was irrelevant that it was explicitly mentioned in the general terms and conditions. In addition, it was not clear whether the location tracker in the rented bicycle also collected location data all the time or only if it identified issues.

Fifth, the controller violated Article 12 and Article 15 GDPR for failing to respond to the data subject access request.

Lastly, the DPA decided to reprimand the controller for processing personal data of the data subject's ID card without a legal basis, for failing to respond to the access request and for the lack of transparency regarding the processing by the processor. It also issued a warning due to the lack of transparency regarding the location data processed in the context of bicycle rentals.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Dutch original. Please refer to the Dutch original for more details.

1/15

Dispute Resolution Chamber

Decision on the merits 132/2025 of 19 August 2025

File number: DOS-2024-01301

Regarding: the unlawful and non-transparent processing of personal data in the

context of a lease agreement

The Dispute Resolution Chamber of the Data Protection Authority (hereinafter ‘DPA’);

Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016

on the protection of natural persons with regard to the processing of

personal data and on the free movement of such data, and repealing

Directive 95/46/EC (General Data Protection Regulation) (hereinafter ‘GDPR’);

Having regard to the Act of 3 December 2017 establishing the Data Protection Authority

(hereinafter ‘WOG’);

Having regard to the internal rules of procedure, as approved by the House of

Representatives on 20 December 2018 and published in the Belgian Official Gazette on

15 January 2019;

Having regard to the documents in the case;

Has taken the following decision regarding:

Complainant: X, hereinafter "the complainant";

Defendant: Y, represented by Mr. Peter Craddock and Mr. Isaline d’Hoop de

Synghem, hereinafter "the defendant".

1
The DPA recalls that the law of 25 December 2023 amending the law of 3 December 2017 establishing
the Data Protection Authority (DPA), and the new internal rules of procedure of the DPA, entered into force on 1 June 2024. The new provisions apply to complaints, mediation files, requests, inspections, and proceedings before the Dispute Resolution Chamber that commence from this date. The new Dispute Resolution Act (WOG) is available via this link:
https://www.ejustice.just.fgov.be/cgi loi/change lg.pl?language=nl&la=N&cn=2017120311&taben namhetet,
the internal rules of procedure are available via this link: < https://www.gegevensbeschermingsautoriteit.be/publications/reglement-van-
interne-orde-van-de-gegevensbeschermingsautoriteit.pdf>. Files initiated before June 1, 2024, of which this file is a part, are, however, subject to the provisions of the Dispute Resolution Act and the internal rules of procedure as they existed before this date. Decision on the merits 132/2025 — 2/15

I. Facts and procedure

1. The subject of the complaint concerns the unlawful and non-transparent processing of

personal data in the context of a rental agreement.

2. On March 10, 2024, the complainant filed a complaint with the Municipal Personal Records Database (GBA) against the defendant.

3. On April 2, 2024, the complaint was declared admissible by the First Line Service pursuant to
Articles 58 and 60 of the Dutch Data Protection Act (WOG) and was transferred

to the Dispute Resolution Chamber pursuant to Article 62, § 1 of the WOG.

4. On June 10, 2024, the Dispute Resolution Chamber, pursuant to Article 56.3 of the GDPR, contacted the

presumed lead supervisory authority with the request to handle this case locally in accordance

with Article 56.2 of the GDPR, which this authority

accepted on June 17, 2024. Pursuant to Article 56.4 of the GDPR, the procedure under Article 60 of the GDPR is therefore

not applicable.

5. On January 17, 2025, the Dispute Resolution Chamber, pursuant to Article 95, § 1, 1° and Article 98

of the Dispute Resolution Act (WOG), decided that the file was ready for a hearing on the merits. The parties involved were

notified by registered mail of the provisions referred to in Article 95,

§ 2, as well as those in Article 98 of the WOG, and were informed, pursuant to Article 99 of the WOG,

of the deadlines for submitting their defenses.

The parties are requested to formulate their arguments regarding the following alleged

infringements:

▪ Infringement of Article 5.1.a in conjunction with 6.1 GDPR due to the lack of a

legal basis for processing the photo of the complainant's identity card;

▪ Infringement of Article 5.1.c GDPR due to the processing of the complainant's national register number

without there being a necessity to do so;

▪ Infringement of Article 12 in conjunction with Article 15 GDPR due to the failure to provide access to the complainant's

personal data after their explicit request; and

▪ Infringement of Article 5.1.a, Article 12, and Article 13 GDPR due to a lack of

transparency regarding the processing of the complainant's personal data, in

particularly the processing of the photo of the complainant's identity card, the processing of the

national register number, and the processing of the location data of the bicycle used

by the complainant.

6. On March 7, 2025, the Dispute Resolution Chamber received the defendant's statement of defense.

7. On March 28, 2025, the Dispute Resolution Chamber received the complainant's statement of reply.

8. On April 18, 2025, the Dispute Resolution Chamber received the defendant's statement of reply. Decision on the merits 132/2025 — 3/15

II. Reasons

II.1. Description of the processing and the complaint

9. The defendant rents bicycles on a subscription basis. A customer must first

register online. For electric bicycles, the customer's identity is verified after registration

by sending an image of the identity card to a processor,

who checks the authenticity of the identity card and the data on it. The purpose

of this verification is to combat fraud. Only after verification can an appointment be made

2
to collect a bicycle. When collecting the bicycle, the customer

must present their identity card again to prove their identity, so that the defendant

is certain that the recipient of the bicycle is the registered customer.

10. The complainant objected to having her identity card photographed for verification

online and by the employee at the defendant's branch. The complainant specifically objected

to having the back of her identity card, which shows her

national register number, photographed. Moreover, her request for access was not

answered and she was not informed in advance about the processing of the photo of

her identity card, her national register number, and the location data of the

rental bicycle.

II.2. Controller of the processing

11. The Dispute Resolution Chamber establishes that the defendant is a subsidiary of a

holding company established in a neighboring country. Since the lease agreement is in the name of the

Belgian branch, the privacy statement designates the Belgian branch as the

controller, all contacts between the complainant and the defendant took place in Belgium

and the general terms and conditions refer to the applicability of

Belgian law, the Dispute Resolution Chamber requested the leading supervisory authority

in accordance with Article 56.2 of the GDPR to handle the case locally, which

this authority granted. Therefore, the defendant is

considered the controller for the processing of the complainant's

personal data for this complaint.

II.3. Scope of the complaint

12. The Dispute Resolution Chamber agrees with the defendant that the complainant, in

her reply, extended her complaint to an invoicing dispute between the complainant and the

defendant. Although this dispute was already clear in the complaint, the

2
Appendix 2 to document 1, Complaint form of March 10, 2024. Decision on the merits 132/2025 — 4/15

Dispute Chamber considered the elements of this dispute irrelevant in the context of the assessment

of data processing in accordance with the GDPR. Consequently, the direct debit of the rental agreement and the

engagement of a debt collection agency by the defendant do not fall within the

scope of the complaint, nor within the jurisdiction of the Dispute Chamber. The

Dispute Chamber will therefore not rule on these issues.

II.4. Lawfulness of processing

13. To comply with the principle of lawfulness of processing under Article 5.1.a GDPR,

this processing must be based on one of the grounds listed in

Article 6.1 GDPR. Moreover, Article 5.2 of the GDPR stipulates that the defendant must be able to demonstrate compliance with this

principle.

14. The defendant refers to the necessity of processing the identity data of

the customer as a tenant to fulfill their contractual obligations, in accordance with Article

6.1.b of the GDPR.

15. In order to base processing of personal data on contractual

necessity, a contract must exist, the contract must be legally valid, and the
processing must be objectively necessary for the performance of the contract. The European Data

Protection Board (hereinafter ‘EDPB’) clearly states in its guidelines that “Merely

referencing or mentioning data processing in a contract […] is not sufficient

to bring the processing in question within the scope of Article 6(1)(b).” and that "necessary for the performance of a contract with the data subject (...) must be interpreted narrowly and does not cover situations in which the

processing is not actually necessary for the performance of a contract,

but rather unilaterally imposed on the data subject by the controller."5

16. The Litigation Chamber finds that a contract exists and that this contract is legally valid,

which the complainant does not dispute. The lease agreement contains the complainant's identity data, which is

necessary for the performance of the contract.

17. The Dispute Resolution Chamber also notes that initially and after March 2024, these identity details

were checked by means of a visual inspection, in which the employee compared the

identity card data with the registration details that the customer had entered online.

The legislator also takes this interest into account in the legislation regarding the use of the

identity card when it states: “For companies and the

3 EDPB, Guidelines of 8 October 2019 on the processing of personal data pursuant to Article 6(1)(b) of the GDPR in the context of the provision of online services to data subjects, version 2.0, paragraph 26.
4
Ibid, paragraph 27.
5 Ibid, paragraph 28. Decision on the merits 132/2025 — 5/15

non-governmental organizations, in their relationship with citizens, it is important to have certainty

about the identity of the customers with whom they establish legal relationships. A

correct identity is, after all, a sine qua non for the legal certainty of

contractual and economic relationships.” However, merely visually checking the (abundance of) data on the identity card is not considered processing of

personal data within the meaning of Article 2 GDPR, as this data is not intended

to be included in a file.

18. The Dispute Resolution Chamber rules that the processed identity data of the complainant

are necessary for the performance of the contract and that the defendant legitimately relies on the legal basis of Article 6.1.b GDPR for

processing this identity data of the complainant as a bicycle renter, in accordance with

Article 5.1.a GDPR.

19. However, at the time the complainant's personal data was processed, a

more extensive verification process was in place, in which a processor, namely a company

specializing in identity verification software, checked the authenticity of the identity card based on an image of the

identity card and could therefore verify the identity data with

greater certainty. However, this verification process did entail

data processing within the meaning of Article 2 GDPR, namely photographing or

scanning, filtering, forwarding, checking, storing, and deleting this data.

The purpose of this more extensive verification process was to prevent fraud.

20. Although a privacy filter was present in this processor's application,

all personal data on the identity card was still processed, albeit

briefly. The defendant himself puts it as follows: "While a photo of an

identity card is analyzed in a certain way and very temporarily, this

is only to extract certain information from it (sic) […]" and "At most, the

complainant can argue that extremely temporary 'processing' occurred before the

masking actually took place." In the appendix to his conclusions, the defendant includes an

analysis of the use of this verification procedure. Based on this, the

Dispute Chamber determines that the photo of the identity card must be uploaded to the

defendant's website, after which this photo is sent to the processor, who then

9
applies the privacy filter. The defendant confirms this in its conclusions:

6 Belgian Chamber of Representatives, Bill containing various provisions regarding the
National Register and the population registers of 6 November 2018, Doc54 3256/003, p. 9.
7
Document 21, Summary Conclusion and supplementary document of 18 April 2025, marginal number 30.
8 Ibid, marginal number 34.
9
Appendix 2, memorandum from State Attorney Pels Rijcken of 7 January 2022, appended to document 16, statement of defense and
documents of 7 March 2025, marginal number 1.2. Decision on the merits 132/2025 — 6/15

“The subscriber was required to take a photo of the identity document […]. […] Once uploaded,
10
an automatic privacy filter appeared on the photo […].”

Regarding the temporary nature of the processing, the defendant argues that this should be considered merely

a “reading of data points” and that this is permitted by the

legislator. The defendant refers to Article 6, §4 of the ID Act, which, however,

clearly states that reading the electronic identity card must be done “in

accordance with the legal and regulatory provisions regarding the protection

of privacy and the protection of personal data.” 12The

Litigation Chamber ruled that this reading of data points also constitutes processing

of personal data and, in accordance with the legislation on identity cards, must therefore

comply with the data protection principles of the GDPR.

21. Moreover, this filter was adjustable by the data subject, which also did not guarantee

that the processor did not process more data than the customer's surname, first name, and

date of birth. The controller is responsible for

ensuring that only the personal data necessary for
the purpose of the processing is processed.

22. The Dispute Resolution Chamber therefore rules that the processing of the personal data on the

identity card constitutes a separate processing of personal data and that the use of the

privacy filter was not a sufficient technical measure to ensure that no more

personal data from the identity card was processed than the surname, first name, and

date of birth, which are contractually necessary.

23. This separate processing was intended to combat fraud. As organized

in the verification process, this processing is not necessary within the contractual relationship,

as it was initially not necessary and was no longer performed in March 2024.

Moreover, it is also not necessary for the less expensive contracts for regular bicycles.

This separate processing cannot therefore be based on any necessity for the

performance of the agreement as referred to in Article 6.1.b of the GDPR. The Dispute Resolution Chamber also

establishes that the processing of personal data during the verification process is not

based on consent (Article 6.1.a of the GDPR), is not carried out in the context of

a legal necessity (Article 6.1.c of the GDPR) or a public interest (Article 6.1.e of the GDPR), and that

it cannot be considered a matter of vital interest (Article 6.1.d of the GDPR). Combating fraud, however,

can be part of the legitimate interest (Article 6.1.f of the GDPR) of the

defendant, specifically the prevention of economic damage.

10 Document 21, Summary Conclusion and Supplementary Document of April 18, 2025, marginal number 5.
11
Law of July 19, 1991, on population registers, identity cards, alien cards, and residence documents. 1. Document 21, Summary Opinion and supplementary document of April 18, 2025, paragraph 36. Decision on the merits 132/2025 — 7/15

24. The privacy statement explicitly refers to this legitimate interest by stating:
13
“<<quote from privacy statement>>” and, in the purposes of the processing: “<<quote from
14
privacy statement>>” The defendant also points to this interest in his conclusion: “This

verification is essential for fraud prevention and, given the high value of the e-bikes […],

to ensure that a bicycle is handed over to the correct person. [Defendant]

regularly experiences that subscriptions are taken out in the name of a third party,
15
resulting in the non-payment of invoices or the disappearance of bicycles.”

25. In accordance with the case law of the Court of Justice 16 regarding the legal basis

for legitimate interests under Article 6.1.f of the GDPR, the defendant must demonstrate that:

▪ The interests pursued by the processing can be recognized as legitimate

(the "purpose test");

▪ The intended processing is necessary for the realization of those interests (the

"necessity test");

▪ The balancing of those interests against the interests, fundamental freedoms

and fundamental rights of the complainant outweighs the defendant or

a third party (the "balancing test").

26. The Litigation Chamber finds that the defendant has not demonstrated a balancing of interests

with regard to this processing. The Dispute Resolution Chamber will conduct this

balancing of interests ex officio to determine whether the legitimate interest under Article 6.1.f of the GDPR

would constitute an appropriate legal basis for the processing.

Purpose Test

27. Given that the bicycles are only rented out and therefore remain the property of the defendant,

the Dispute Resolution Chamber finds that combating fraud and ensuring that the bicycle

is handed over to the correct person constitutes a legitimate interest of the defendant.

13Appendix 7 to document 1, complaint form dated March 10, 2024, p. 3.
14
Appendix 7 to document 1, complaint form of 10 March 2024, p. 4.
15 Document 21, Summary Opinion and supplementary document of 18 April 2025, marginal number 3.
16
CJEU Judgment of 4 May 2017, Rīgas Satiksme, C-13/16, ECLI:EU:C:2017:336, para. 28, andCJEU Judgment of 7 December 2023,
Joined Cases C-26/22 and C-64/22, Schufa, ECLI:EU:C:2023:958, para. 74. Decision on the merits 132/2025 — 8/15

Necessity test

28. For processing to be necessary, it must first be suitable, secondly

sufficient, and thirdly, necessary for the intended purposes.7

29. There is no doubt that the identity card is eminently suitable for verifying the identity of a

person and is also sufficient to establish this identity with certainty.

After all, an identity card is designed and secured for precisely this purpose. Processing by means of analyzing data points from a photo or scan of the

identity card is therefore also suitable and sufficient.

30. However, this analysis requires photographing or scanning the identity card and

sending this photo or scan via the internet, after which it is stored, analyzed

and deleted again after a certain period. Each of these actions increases the

risk of errors and possible breaches of confidentiality or integrity of all

data on the identity card. This processing is not necessary as an

equivalent alternative exists. The defendant already had a procedure in place that consisted

of physically comparing the registration data entered by the customer online in the store

with the data on the identity card before handing over the bicycle. This

procedure was also reintroduced in March 2024, as processing via the

photo or scan of the identity card did not provide sufficient added value for the purpose

of the processing, namely combating fraud.8

19
31. Given that the three conditions of Article 6.1.f GDPR are cumulative and the processing is not

necessary, the Dispute Resolution Chamber rules that the defendant could not process the

personal data on the complainant's identity card based on

a legitimate interest under Article 6.1.f GDPR.

32. The Dispute Resolution Chamber therefore finds that the respondent violates Article

5.1.a in conjunction with 6.1 GDPR due to the lack of a legal basis for

processing the personal data on the complainant's identity card.

II.5. Minimum data processing

33. The complainant objects to the photographing and uploading of her identity card and

considers the processing of her national registration number in particular to be unnecessary. In this respect,

the complainant does not object to the checking of her identity card in order to compare the

17 EDPB, Guidelines 3/2019 on the processing of personal data by means of video equipment, version 2.0
adopted on 29 January 2020, paragraph 24.
18
Document 21, Summary Opinion and supplementary document of 18 April 2025, paragraph 8.
19 CJEU Judgment of 7 December 2023, Joined Cases C-26/22 and C-64/22, Schufa, ECLI:EU:C:2023:958, para. 75. Decision on the merits 132/2025 — 9/15

data with the data available to the defendant through the
registration. The complainant considers this consultation sufficient.

34. The Dispute Resolution Chamber finds that the alleged processing of the complainant's national register number

is part of the processing of the identity card in the defendant's

verification procedure. Since this verification procedure was deemed unlawful in

paragraph 32, the possible processing of the

national register number is also unlawful, and an assessment based on the principle

of minimum data protection is no longer relevant.

II.6. Transparency of the processing

35. The complainant claims never to have been directly informed about the processing of her

personal data and states that she had to look up the privacy statement herself

online to obtain information about the processing.

36. The defendant demonstrates that a link to the privacy policy can be found in the

rental agreement with the complainant and that the privacy statement is available on the defendant's website, the same website through which the complainant had to register for the rental

of a bicycle.

37. The Dispute Resolution Chamber finds that the complainant was sufficiently informed of the existence of the privacy statement and its location prior to the processing of her

personal data under the lease agreement.

38. Although the privacy statement mentions the processing of identity data,

the use of the identity card in the verification procedure is not included, even though

it was a separate processing operation. Nor is the processor who carries out this verification via the

identity card mentioned in the privacy statement. It only refers to

processors in the context of "<<quote from privacy statement>>". The Dispute Resolution Chamber finds

that this processing is explicitly mentioned in the general terms and conditions. However, given that

it concerns a different document, this violates Article 12.1 of the GDPR. This article stipulates

that the information regarding data processing must be concise and easily accessible,

which is not the case if this information is split and distributed between

the privacy statement on the one hand and the general terms and conditions on the other. Moreover,

discrepancies between information in the privacy statement and the general

terms and conditions lead to confusion and ambiguity, which negatively impacts transparency.

39. Regarding the processing of the national register number, which is stated on the back of the complainant's

identity card, no information can be found in the

20 See marginal 19.
2 Appendix 7 to document 1, Complaints form of March 10, 2024, p. 6. Decision on the merits 132/2025 — 10/15

privacy statement. This is consistent with the defendant's argument that he

only processes the front of the identity card. Moreover, the complainant does not demonstrate

that the back of the identity card has been processed, nor can this be verified

since all personal data has allegedly been deleted by the processor since

March 2024.2

40. Regarding the processing of bicycle location data, the privacy statement mentions the
processing of the last known location in the context of recovering a lost

or stolen bicycle or in the context of non-payment. The privacy statement clarifies:

“<<quote from privacy statement>>.” However, the privacy statement leaves it unclear

whether location data is collected punctually, randomly, or discontinuously. The fact that location data can be continuously tracked implies that

a location tracker is present in the bicycle. By only communicating about continuous

use in the event of problems, the defendant is not transparent about the use without

any problems having been identified.

41. The Dispute Resolution Chamber rules that the defendant has violated the

transparency principle of Article 5.1.a in conjunction with Articles 12 and 13 of the GDPR, since the

processing of the identity card by a processor was not addressed in the

privacy statement and since it was unclear whether the location tracker in the

rented bicycle also collected location data without any problems having been

identified.

II.7. Right of access

42. Article 15.1 GDPR stipulates that the data subject has the right to obtain confirmation from the controller as to whether or not personal data concerning them are being processed, and, if so, to access

that personal data. Furthermore, Article 15.3 GDPR stipulates that the controller must provide a copy of the personal data that they are processing.

43. In addition, Article 12 GDPR regulates the manner in which data subjects can exercise their rights, and Article 12.2 GDPR stipulates that the controller must facilitate the exercise of those rights and, without undue delay and in any event within one month of receipt of the request, provide information on the measures taken in response to the request. Depending on the complexity of the requests and the number of requests, this period may be extended by a further two months, if necessary.

22 Document 21, Summary Conclusion and supplementary document of 18 April 2025, paragraph 8.
23 Annex 7 to document 1, Complaint Form of 10 March 2024, p. 2. Decision on the merits 132/2025 — 11/15

extended. The controller shall inform the data subject of such an extension within one month of

receiving the request (Article 12.3 GDPR).

If the controller does not comply with the data subject's request,

it shall inform the data subject without delay, and at the latest within one month of

receiving the request, of the reasons for not complying with the request, and inform the data subject

of the possibility of lodging a complaint with a supervisory authority and seeking judicial redress

(Article 12.4 GDPR).

44. In the attachment to the complaint, the complainant includes an email dated January 14, 2024, in which she requests access to

all personal data ever collected and processed about her. The

Dispute Chamber establishes, based on the documents, that no access was granted

within the foreseen period, nor that the respondent requested any extension of this period.

45. The respondent argues that the request for access ended up in spam

and was only discovered after the Dispute Chamber was invited to deliver its conclusions on January 17,

2025, one year later. The respondent adds that this is an exceptional

case.

46. The Dispute Resolution Chamber finds that the respondent's delay in responding to the complainant's

correct request for access made it impossible for the complainant

to verify whether her national register number had actually been processed,

whether the photo from her identity card had been removed, and whether location data of her

bicycle movements had been processed.

47. The Dispute Resolution Chamber finds that the respondent violated the

right of access under Article 12 in conjunction with Article 15 of the GDPR by failing to grant

access to the complainant's personal data following his explicit request within the

provided period of one month.

III. Corrective measures and sanctions

III.1. The seriousness of the infringement

48. Regarding the seriousness of the infringement, the Dispute Resolution Chamber finds that the principle of

lawfulness is a fundamental principle of the protection guaranteed by the GDPR.

It is also included in Article 8.2 of the Charter of

Fundamental Rights of the European Union. The Litigation Chamber finds that infringements of this

core principle therefore constitute serious infringements. Moreover, by not including this

24Appendix 5 to document 1, Complaint form of 10 March 2024. Decision on the merits 132/2025 — 12/15

disputed processing in the privacy statement and by not respecting the complainant's right of access

within the stipulated timeframe, the complainant was unable

to verify whether her personal data was adequately protected, which made this complaint

unavoidable.

49. However, the Litigation Chamber takes into account that the disputed processing was only carried out temporarily

and was already stopped on its own initiative in March 2024, including the

deletion of the data collected as a result of this processing.

Furthermore, the defendant had taken technical measures to limit the processing, although these technical measures were insufficient.

50. Finally, the Dispute Resolution Chamber also takes into account that the request for access was ultimately

granted by the defendant and that the processing of location data is

mentioned in the privacy statement, although not sufficiently to provide certainty about

this processing.

III.2. Corrective measures

51. According to Article 100 of the Dutch Data Protection Act (WOG), the Dispute Resolution Chamber has the authority to:

1° dismiss the complaint;

2° order that the prosecution be dismissed;

3° order a suspension of the judgment;

4° propose a settlement;

5° issue warnings and reprimands;

6° order that the data subject's requests to exercise their

rights be complied with;

7° to order that the data subject be informed of the

security problem;

8° to order that processing be temporarily or permanently frozen, restricted, or

prohibited;

9° to order that processing be brought into compliance;

10° to order the rectification, restriction, or erasure of data and

the notification thereof to the recipients of the data;

11° to order the withdrawal of the recognition of certification bodies;

12° to impose penalty payments;

13° to impose administrative fines; Decision on the merits 132/2025 — 13/15

14° to order the suspension of cross-border data flows to another

State or an international institution;

15° to transfer the file to the Public Prosecutor's Office of

Brussels, which will inform it of the action taken on the file;

16° to decide on a case-by-case basis to publish its decisions on the

website of the Data Protection Authority.

52. The Dispute Resolution Chamber decides, pursuant to Article 100, 5° of the Dutch Data Protection Act (WOG), to reprimand the defendant:

• for processing the personal data from the complainant's identity card without legal grounds;

• for failing to respond to a legitimate request for access from the

complainant within the stipulated timeframe; and

• for the lack of transparency regarding the processing of the

personal data from the complainant's identity card by a processor.

53. The Dispute Resolution Chamber decides, pursuant to Article 100, 5° of the WOG, to

warn the defendant for the lack of transparency regarding the location data

processed in the context of bicycle rental, since it was clear to the complainant

that location data was being processed, but it was not clear whether this

was being processed permanently. Decision on the merits 132/2025 — 15/15

26
in accordance with Article 1034quinquies of the Judicial Code, or via the e-Deposit

information system of the Ministry of Justice (Article 32ter of the Judicial Code).

(Government). Hielke H IJMANS

Director of the Litigation Chamber

26 The application and its appendix, in as many copies as there are parties involved, shall be sent by registered mail
to the clerk of the court or deposited at the registry.