APD/GBA (Belgium) - 188/2025

From GDPRhub
APD/GBA - 188/2025
Authority: APD/GBA (Belgium)
Jurisdiction: Belgium
Relevant Law: Article 5(2) GDPR
Article 24(1) GDPR
Type: Complaint
Outcome: Upheld
Started:
Decided: 19.11.2025
Published:
Fine: n/a
Parties: n/a
National Case Number/Name: 188/2025
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): French
Original Source: APD (in FR)
Initial Contributor: dt

The DPA issued a reprimand to a municipality for failing to prevent its employees from misusing their access to the National Register for private purposes.

English Summary

Facts

On 4 February 2020, the data subject filed a complaint with the Belgian DPA (APD) on their own behalf and on behalf of their mother, against a municipality (the controller) for the alleged unlawful consultation of their personal data from the National Register by employees of the controller.

The Belgian National Register contains information relating to over 11 million individuals.

The first consultation of the National Register took place on 3 December 2019 and concerned personal data relating to the data subject’s mother. The controller informed the data subject that it was considering disciplinary proceedings against the employee who consulted the data for private purposes.

The second consultation took place on 16 December 2019. The employee who carried out this consultation allegedly intended to check the passport photo of the data subject in order to recognise them if they visited the municipal administration. The controller informed the data subject of these facts and mentioned that it was considering disciplinary proceedings against the employee once the employee was identified. Furthermore, the controller assured the data subject that further measures would be put in place to prevent such incidents from repeating.

At the time of the consultations, one of the relevant applications used by the controller in its activity, SAPHIR, provided only for the possibility to record a generic reason for consultations of the National Register. A requirement to record specific reasons for carrying out such consultations was introduced following the events of the case. No other control mechanism over the consultations carried out by employees was in place at the time of the events.

Moreover, according to the controller’s DPO, another application, Belpic (used for the purpose of issuing identity documents), did not require the indication of the purpose of the consultation and did not allow the municipal authority to control access to it.

The data subject filed a complaint with the DPA after finding the responses of the controller unsatisfactory.

In its response, the controller argued that the two employees who accessed the National Register for personal purposes must be classified as data controllers according to Article 4(7) GDPR. The controller added that the employees had signed a confidentiality clause undertaking to access the National Register strictly within the scope of their duties and acknowledging that other consultations constitute serious misconduct. Moreover, it explained that the guidelines of the workplace state that processing of personal data is conducted only for professional purposes.

Holding

The DPA initially found that the controller had violated Article 5(2) GDPR and Article 24(1) GDPR by failing to comply with the principle of accountability.

The DPA pointed out that processing takes place under the authority of the organisation when the employee of the organisation processes personal data in the course of its activities. However, when the employee unlawfully exceeds the authority given to them, the employee defines the purposes of the processing. Therefore, the DPA found that the municipal employees must be considered data controllers within the meaning of Article 4(7) GDPR for the unlawful consultations of the National Register which exceeded their duties.

However, the employees were not brought into the proceedings by the decision of the DPA. Instead, the DPA recognised the municipality as responsible for the processing of personal data in light of Article 5(2) GDPR and Article 24(1) GDPR.

The DPA analysed the controller’s compliance with Article 5(2) GDPR and Article 24(1) GDPR. It found that the controller was not exempt from the obligation to put in place the organisational and technical measures necessary to ensure that consultations of the National Register comply with the GDPR, in particular with the principles of security and purpose limitation. Moreover, it emphasised that the controller was obligated to demonstrate compliance with these articles.

The DPA found that there was no adequate control mechanism to ensure that authorised employees consulted the Register only for the purposes for which they had been authorised. Furthermore, it noted that the confidentiality clause alone did not allow for the verification of compliance with the principle of purpose limitation.

Therefore, the DPA found the controller in violation of Article 5(2) GDPR and Article 24(1) GDPR and issued a reprimand.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the French original. Please refer to the French original for more details.

1/15

Litigation Chamber

Decision on the merits 188/2025 of November 19, 2025

Case number: DOS-2020-00645

Subject: Complaint concerning unlawful access to the National Register within a

municipal administration

The Litigation Chamber of the Data Protection Authority;

Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the

protection of natural persons with regard to the processing of personal data and

on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the “GDPR”;

Having regard to the Law of 3 December 2017 establishing the Data Protection Authority (hereinafter referred to as the “LCA”);

Having regard to the Law of 8 August 1983 organizing a National Register of Natural Persons (hereinafter “Law”

RN);

Having regard to the internal rules of procedure as approved by the Chamber of Representatives on

20 December 2018 and published in the Belgian Official Gazette on 15 January 2019;

Having regard to the documents in the file;

Has taken the following decision concerning:

The complainant: X1, who filed a complaint in his own name but also on behalf of

his mother, X2, hereinafter “the complainant”.

The new internal rules of procedure of the Data Protection Authority (DPA), following the amendments made by the Law of 25 December 2023
amending the Law of 3 December 2017 establishing the Data Protection Authority (DPA), entered into force on
1 June 2024. In accordance with Article 56 of the Law of 25 December 2023, it applies only to complaints, mediation cases, requests, inspections, and proceedings before the Litigation Chamber initiated on or after that date:

https://www.autoriteprotectiondonnees.be/publications/reglement-d-ordre-interieur-de-l-autorite-de-protection-des-donnees.pdf Cases initiated before 01/06/2024, as in this instance, are subject to the provisions of the LCA (Law on the Protection of Data) as amended by the Law of 25 December 2023 and the internal regulations as they existed before that date. Decision on the merits 188/2025 — 2/15

The defendant: The municipality of Y, represented by its College of Mayors and Aldermen, hereinafter referred to as "the defendant".

I. Facts and Procedural Background

1. On February 4, 2020, the complainant filed a complaint with the Data Protection Authority (DPA) against the defendant (a municipality).

2. The complaint concerns the unauthorized access to personal data in the National Register by employees of the defendant and the responses provided by the defendant to the complainant's requests.

3. The complainant reports that the events began with an initial unauthorized access on December 3, 2019, to data in the National Register concerning his mother, whom he indicates he represents in these proceedings.

4. When questioned about this by the latter in letters dated December 8 and 9, 2019, the defendant replied to the plaintiff on December 10, 2019, that an identified employee of the population department had accessed her data for private purposes and that disciplinary proceedings were being considered against this employee.

5. The second unauthorized access occurred on December 16, 2019, and concerned data from the plaintiff's National Register, including her identity photograph.

6. The documents in the file show that the complainant reported this consultation to the

defendant on December 27 and 28, 2019.

7. By email dated December 27, 2019, the complainant received an initial response from the

Data Protection Officer (DPO) of the defendant at the time (Mr. Z.)

explaining that an employee of the population services department had improperly accessed his identity photo
in order to identify him should he present himself at the municipal administration.

8. A second response was sent to the complainant on December 30, 2019, stating that a

agent from the Civil and Social Affairs Department, yet to be identified, exceeded their authority by

checking their photo, presumably to ensure, as a precaution, that they were dealing with

the correct person in connection with a request submitted by the complainant on behalf of

their mother (the complainant having sent their request from the email address bearing

the name of their deceased father). The defendant adds that once this agent is identified, disciplinary proceedings will be considered against them. The defendant further specifies that

measures will be put in place to prevent this type of malfunction in the future.

9. Deeming these responses unsatisfactory, the complainant filed a complaint with the Data Protection Authority (DPA) on February 4, 2020.

as mentioned in point 1. Decision on the merits 188/2025 — 3/15

10. On March 3, 2020, the complaint was declared admissible by the DPA's Frontline Service (FLS)

on the basis of Articles 58 and 60 of the Federal Act on Administrative Procedure (FAAP), and the complaint was forwarded to the Litigation Chamber

pursuant to Article 62, § 1 of the FAAP.


11. On March 31, 2020, in accordance with Article 96, § 1 of the FAAP, the Litigation Chamber's request to conduct an investigation was forwarded to the Inspection Service (IS),

along with the complaint and the list of supporting documents.

12. On February 2, 2021, the SI investigation was closed, the investigation report was added to the file, and

this file was forwarded by the Inspector General to the Litigation Chamber (Art. 91, § 1 and § 2

of the LCA).

13. In his investigation report, the Inspector General found a violation of

Articles 5.2 and 24.1 of the GDPR by the defendant in the following terms:

“Finding: Failure to comply with the principle of accountability

“Article 17 of the National Register Law1 – which entered into force on December 23, 2018 –

requires the traceability of access: “Every public authority (…) must be able

to justify the consultations carried out, whether these are made by an

individual user or by an automated computer system.” To this end, in order

to ensure the traceability of consultations, each user maintains a log of

consultations. This log indicates the identification of the individual user or the

process or system that accessed the data, the data that was

consulted, how it was consulted, namely for reading or for

modification, the date and time of the consultation, as well as the purpose for which

the data in the National Register of Natural Persons was consulted.

As the Data Protection Authority mentioned in

its Recommendation 07/2017 of 30 August 2017, "stating the reason for the

consultation constitutes a necessary and mandatory safeguard for accessing the

National Register in a legitimate manner" (point 6). This obligation is also

reiterated in the decision on the merits of the Litigation Chamber 19/2020 of

29 April 2020, which states: “It is therefore incumbent upon the defendant to guarantee that

access to the National Register remains limited to the purposes for which such access was

authorized. It is also incumbent upon it to be able to demonstrate this. Compliance
with the principle of purpose limitation, a pillar of data protection, cannot in fact be

verified if the agents of an organization such as the defendant do not record the reason

for the consultation they are carrying out. It is equally essential in this regard that

in accordance with Article 24 of the GDPR, the defendant has an adequate

control mechanism ensuring that its authorized agents consult the National Register

only for these purposes.” The defendant must have a Decision on the merits 188/2025 — 4/15

computer application that allows for the legitimization of each consultation carried out

by its staff and thus demonstrates that the consultation took place within the scope of

the duties of the staff member who carried out the consultation.

In this case, the SAPHIR application used by the municipal administration [of the
defendant] at the time of the events only allowed for the recording of a

generic reason for consultation.

A requirement to provide a specific reason was implemented in the free text input field

of SAPHIR following the events, which allows for going beyond the generic purposes

(e.g., population) previously used.

According to the explanations of the Data Protection Officer of the municipal administration [of the

defendant], the Belpic application – which is provided by the Federal Public Service

Home Affairs – does not require users to indicate the purpose of the consultation, and

municipalities cannot control access to this application.

Furthermore, no control over consultations by the municipal administration [of the

defendant] existed at the time of the events.

The Inspection Service notes that the municipal administration did not have
at the time of the events an adequate control mechanism ensuring that

its authorized agents consulted the National Register only for

the purposes for which such access was authorized.

14. On March 3, 2021, the Litigation Chamber requested a supplementary investigation by the Information Service

based on Article 96, § 2 of the LCA.

15. The Litigation Chamber notes that it has found that the investigation report referred to

in points 12 and 13 above indicates, based on information provided by the DPO of the

defendant, that the Belpic application provided by the FPS Home Affairs does not comply with the

provisions of the Law organizing a National Register of Natural Persons (hereinafter “the

RN Law”). In particular, the Belpic application does not allow the reason for consultation

to be communicated as required by Article 17 of the aforementioned law. Therefore, the Litigation Chamber
requests the Information Service to conduct a further investigation on this aspect

with the FPS Home Affairs.

16. On February 25, 2022, the supplementary investigation report was transmitted by the Inspector

General to the Litigation Chamber.

17. This supplementary investigation report contains the following finding:

2Emphasis added by the Litigation Chamber. Decision on the merits 188/2025 — 5/15

“In light of these various elements, the Inspection Service finds that

the municipal administration [of the defendant] is in this case able to

monitor its employees’ access to the National Register via

the Belpic application and to ascertain its purpose, since the Belpic application
can only legitimately be used to issue identity documents.

The Inspection Service therefore considers that the general question of compliance by

the Belpic application with the provisions of the National Register Act, particularly

the obligation to record the reason for consulting the data in the National Register, is no longer relevant in this case and would excessively broaden the

scope of this case.”

18. On June 10, 2022, the Litigation Chamber decided, pursuant to Article 95, § 1, 1° and

Article 98 of the LCA, that the case could be heard on its merits.

19. On the same date, the complainant and the defendant were informed by registered mail

of the provisions of Articles 95, § 2 and 98 of the LCA. They are also informed, pursuant to

Article 99 of the LCA, of the deadlines for submitting their submissions regarding a
breach of Articles 5.2 and 24.1 of the GDPR as identified by the SI at the conclusion of its

investigation. The deadline for receiving the defendant's response submissions is

set at 22 July 2022, the deadline for the complainant's reply submissions at 16 August 2022

and the deadline for the defendant's reply submissions at 7 September 2022.

20. On 11 June 2022, the complainant requests a copy of certain documents in the file (Art. 95, §2,

3° LCA), which are provided to him on 29 June 2022.

21. On 20 July 2022, the Litigation Chamber receives the defendant's reply submissions, a brief summary of which is included below.

- The defendant does not dispute the unauthorized access, in line with the

letters it sent to the plaintiff and his mother on this matter as early as 2019 (see the statement of facts).

- The defendant indicates, as it did during the SI investigation, with supporting documents,

that the two offending municipal employees were subject to a disciplinary sanction (warning) in 2020 for unauthorized access to the National Register and Belpic.

- Following these sanctions, the defendant provided explanations and reminders of the confidentiality clause signed by the employees and the possible sanctions for breaching it. Decision on the merits 188/2025 — 6/15

- The defendant notes that the two employees must be classified as data controllers

within the meaning of Article 4.7 of the GDPR, in line with previous decisions

of the Litigation Chamber, in particular its decision 94/2021.

- It emphasizes that these two municipal employees, respectively on [date] and [date] (i.e., before
the events in question), signed a confidentiality agreement regarding the use of the National Register

under the terms of which they undertake to use their access to the National Register only within the strict scope of their duties and that they acknowledge that

consulting the National Register constitutes serious misconduct punishable by sanctions such as

immediate dismissal or disciplinary proceedings.

- The defendant adds that its municipal work regulations, an extract of which is

produced, also stipulate (Article 7) that the employee must perform their work with rigor

and integrity and refrain from any behavior that could undermine public confidence

in the administration. More specifically, Appendix VIII of these work regulations

entitled “Guidelines Relating to the Protection of Personal Data”

contains “Article 2 – Processing of Personal Data Only for

Professional Purposes” according to which “the employee processes the personal data of the individuals concerned solely for professional purposes
inherent to the activities of the municipality. It is forbidden to access personal data for personal purposes.”

- In support of these various elements, the defendant considers that it has implemented

the appropriate measures designed to prevent any unauthorized access to the National Register

and has thus complied with its obligations under

Articles 5.2 and 24.1 of the GDPR. She adds that whatever these measures are, they
can never absolutely prevent an isolated malfunction by one or

the other agent. Article 24.1 of the GDPR should be considered as imposing an

obligation of means on data controllers ((which the defendant has

fulfilled), not an obligation of result.)

- In conclusion, the defendant asks the Litigation Chamber to consider the
municipal agents at fault as data controllers within the meaning of Article 4.7

of the GDPR and, therefore, to dismiss the complaint filed against it by the

plaintiff.

22. On July 24, 2022, the plaintiff addressed the Litigation Chamber and informed it that he

notes that the defendant is “represented by Mr. Z, presenting himself as a

“legal expert”. The plaintiff questions a potential conflict of interest on the part of the latter

who, at the time of the The disputed facts, was the defendant's DPO and therefore, according to

3. It is the Litigation Chamber that emphasizes this. Decision on the merits 188/2025 — 7/15

its terms "determined the purposes and means of processing in order to comply with

the law of 30 July 2018 but also the law of 8 August 1983 organizing a national register of

natural persons." The complainant asks the Chamber to share its

viewpoint, which the Litigation Chamber declines to provide at this stage of the proceedings.

23. On 8 August 2022, the Litigation Chamber receives the complainant's reply submissions.

A summary of these is provided below.

- The complainant believes that the Data Protection Authority (DPA) should bring the two

municipal employees at fault of the defendant, as well as the Federal Public Service Home Affairs (FPS Home Affairs), into the proceedings. Regarding the two

employees at fault, the complainant questions the validity of the personal justification they provided for the consultation (sending greeting cards, in particular), what they did with his personal data once it had been accessed, whether they acted on orders, etc.

- The complainant emphasizes that the defendant's submissions were signed and transmitted by her former DPO, who has since become a lawyer. As he previously stated to the Litigation Chamber (paragraph 22), the complainant believes there is a conflict of interest on the part of the latter, since, in his words already quoted and reiterated: "(...) in his capacity as DPO, this person determined the purposes and means of the processing intended to comply with both the Law of 5 August 1983 relating to the National Register and the LTD." This former DPO also allegedly drafted a report implicating one of the agents. concerned.

Following this last point, the complainant requests that the Data Protection Authority (DPA) require the

production of the aforementioned report prepared by the Data Protection Officer (DPO).

- In general, the complainant is of the opinion that the defendant did not implement

sufficient measures to prevent the consultations that occurred,

regardless of the attempt to absolve itself of all responsibility and to shift

this responsibility onto the negligent municipal employees. In this regard, he emphasizes the defendant's admission that, when adopting appropriate measures to prevent similar

contentious consultations from recurring, there was, at

the time of the events, no access control to the National Register. The complainant also emphasizes
that Annex VIII to the work regulations, invoked by the defendant in

submissions (see point 21), was not in force at the time of the events. He relies more

generally on the findings of the Internal Security Service.

- The complainant also alleges a lack of transparency regarding the

replacement of the DPO (Mr. Z) by an external company.

- The complainant finally requests that the case be referred to the Public Prosecutor.

4. Read the Law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data. Decision on the merits 188/2025 — 8/15

24. On 7 September 2022, the defendant informed the Litigation Chamber that it did not intend

to reply, as its entire argument was contained in its response
submissions (point 21), which constituted its reply submissions.

25. On January 13, 2023, the complainant wrote to the Litigation Chamber that, pending its

decision, he had continued his investigations into the joint public contract organized by the

defendant (and its Public Social Welfare Centre) mentioned in the submissions regarding the replacement of the defendant's former

Data Protection Officer. He filed new documents on this matter, including a complaint

filed with respect to this public contract.

26. On January 24, 2023, the Litigation Chamber informed the parties that it would examine the

admissibility of these documents filed outside the procedural timetable when it

renders its decision.

II. Reasoning

II.1. Regarding the attribution of responsibility for unlawful consultations – the question of the data controller

27. In accordance with Article 4.7 of the GDPR, the data controller is defined as: “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.” This is an autonomous concept, specific to data protection regulations, the assessment of which must be based on the criteria it sets out: the determination of the purposes of the data processing concerned and the means thereof.

28. Regardless of the classification the parties may use, the Litigation Chamber

must concretely assess the role and status of the parties concerned and implicated

and, where appropriate, disregard the classification the parties may have used if

its analysis concludes that this classification cannot be upheld.

29. When an employee of an organization processes personal data
in the course of its activities, the processing is deemed to take place under

the authority of the organization. The employee is, in fact, considered a “person

acting under the authority of the controller” within the meaning of Article 29 of the GDPR in

this case.

5
See, in this regard, Brussels (Court of Markets), 8 June 2022, 2022/AR/42, p. 6.
Article 29 of the GDPR: A processor and any person acting under the authority of the controller or under that of the processor, who has access to personal data, may not process such data except on instructions from the controller, unless required to do so by Union or Member State law. Decision on the merits 188/2025 — 9/15

30. However, there are exceptional situations in which an employee has himself defined the purposes of processing personal data by unlawfully exceeding the authority conferred upon him.

31. In this case, the Litigation Chamber notes that, with regard to the processing of

data, which consists of consulting the National Register, it is—except in cases where its agents

are guilty of unauthorized consultation—the defendant who determines

the purposes and means of the processing. Indeed, consultations of the National Register are

to be carried out within the framework of the duties entrusted to the defendant in its capacity

as a municipal administration.

32. In this case, (unlawful) consultations of the National Register were carried out outside the framework

of these duties, for other purposes (i.e., for personal gain) by municipal agents.

Although these individuals used the resources made available to them by the defendant, these

municipal employees must each be considered a data controller

within the meaning of Article 4.7 of the GDPR for the unlawful consultation of which they are respectively

guilty, since they carried out the disputed consultations outside the scope

of their duties as employees of the defendant (this latter fact not being

disputed).

33. In light of the above, the Litigation Chamber concludes that the unlawfulness of these

8
consultations is not attributable to the defendant.

34. The Litigation Chamber adds that, however, it is not required to bring charges against

the two offending municipal employees, which the IT department also did not deem appropriate.

It is not required to bring the Federal Public Service Home Affairs into the proceedings since the initial complaint was not directed against it and, following the supplementary investigation conducted with regard to it, even at the request of the Litigation Chamber, the Inspector General found no wrongdoing on its part. The Litigation Chamber therefore did not include either party within the scope of its referral or invite them to submit conclusions (paragraph 19).

35. Generally speaking, it is not the responsibility of the Data Protection Authority to bring all actors involved in a given issue into the proceedings. The Litigation Chamber notes in this regard that the Court of Appeal

which hears appeals of its decisions, does not sanction the procedural choice of

the authority (nor, for that matter, that of the complainant, where applicable) not to involve all

persons, bodies, and other parties related to an issue and not to request a

7 European Data Protection Board (EDPB), Guidelines 07/2020 concerning the concepts of controller and processor in the GDPR, 7 July 2021, version 2, paragraph 19, available at:
https://www.edpb.europa.eu/system/files/2023-10/edpb guidelines 202007 controllerprocessor final fr.pdf .

8
For the avoidance of doubt, the Litigation Chamber adds that the fact that it will note below that the defendant
had not implemented all the technical and organizational measures intended to prevent such unlawful consultations,
does not invalidate its decision in this case. Indeed, the employees concerned were aware that such consultations were
prohibited since they had signed a confidentiality agreement to that effect. Decision on the merits 188/2025 — 10/15

investigation by the IT department with regard to them. For the avoidance of doubt, the Litigation Chamber specifies that

therefore, all considerations, questions, and assumptions raised by the complainant

concerning the offending agents are not examined in this decision.

36. On the other hand, the Market Court considers that proceedings and sanctions must be
directed against a party recognized as a data controller, which is

the case for the defendant in this instance, given its obligations under

Articles 5.2 and 24.1 of the GDPR, regardless of the fact that the unlawfulness of the

consultations of the National Register is not attributed to it in this case (see below).

37. Because the complainant considers that there is a conflict of interest on the part of the defendant's former DPO (Mr. Z), who has become a lawyer and who signs the correspondence and pleadings

exchanged in the proceedings before the Litigation Chamber in this latter capacity,

on the grounds that he allegedly determined the purposes and means of the disputed processing, the

Litigation Chamber wishes to clarify the following.

38. A DPO is not to be considered as determining the purposes and means of data processing. On the contrary, their role is to advise the data controller on the implementation of personal data processing in compliance with the GDPR. Their advisory, consultative, and GDPR compliance monitoring mission, as defined in Article 39 of the GDPR, is precisely incompatible with any determination of the purposes and means of processing. As such, the DPO acts with independence (Article 38.3 of the GDPR) and must be free from any conflict of interest (Article 38.6 of the GDPR). If, in the course of their duties, the person considered as DPO were to be required in practice to determine the purposes and means of processing, they cannot be a DPO. The same applies if such a conflict of interest were to arise during the performance of their duties. Furthermore, the argument raised by the complainant that the former DPO has a conflict of interest because, in that capacity, he determined the purposes and means of the processing at the time of the alleged events is inaccurate and unlawful. The Litigation Chamber is also in possession of no evidence to suggest that the DPO determined the purposes and means of the processing in question in this case and, in any event, did not invite the parties to defend themselves on this point (paragraph 19).

39. Furthermore, the Litigation Chamber is of the opinion that it is not within its jurisdiction to

rule on the internal personnel whom the defendant chooses to consult (DPO,

legal counsel, etc.) to analyze the facts as they occur or for its defense.

Thus, the involvement of the DPO in the examination of a practice alleged to be contrary to the

GDPR and the RN Law falls precisely within its role, since, in accordance with Article

38.1 of the GDPR, it must be appropriately and promptly involved in any matter

9 Brussels (Market Court), June 30, 2021, 2020/AR/111, pp. 6.9.1 and 6.9.2. Decision on the merits 188/2025 — 11/15

of data protection. The Litigation Chamber also does not intend to comment on

how the defendant prepared its defense in the context of these

proceedings, given that it is the defendant (and not the DPO, as it has just emphasized) who

is responsible for compliance with the GDPR. Finally, the Litigation Chamber clarifies that, according to

this decision, it holds the defendant responsible as the data controller,

not the lawyer who co-signs the letters or sends the submissions from their professional

email address.

II.2. Regarding compliance with Articles 5.2 and 24.1 of the GDPR

40. The finding that the unlawfulness of the consultations of the National Register is not

attributable to it in this case does not exempt the defendant from its obligation to

implement the organizational and technical measures designed to ensure the

compliance of consultations of the National Register with the GDPR, in particular compliance with the

principles of security and purpose limitation. It is bound to do so pursuant to Articles 5.1(f) and 32, 10, and 11

of the GDPR and the relevant provisions of the National Register Law applied in conjunction with

Articles 5.2, 12, and 24.1 of the GDPR. It is indeed the responsibility of the data controllers

authorized to consult the National Register to implement the conditions of the authorization

they have been granted, in compliance with its provisions and in accordance with the principle

13
of accountability set out in Articles 5.2 and 24 of the GDPR, the monitoring of which falls

to the Data Protection Authority (DPA). In this case, it was incumbent upon the defendant to guarantee that access to the National Register

remained limited to the purposes for which such access was authorized, excluding

any personal use by one of its employees. It was also incumbent upon it to be able to

demonstrate, as required by Articles 5.2 and 24 of the GDPR, that it had implemented

the organizational and technical measures for this purpose.

10. Article 5.1.f) of the GDPR provides that personal data shall be “processed in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (integrity and confidentiality).”

11. Article 32.1 of the GDPR provides that “taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risks, of varying likelihood and severity, to the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (…)”
14. Paragraph 5 of Article 32 states that “The controller and the processor shall take

measures to ensure that any natural person acting under the authority of the controller or of the
processor who has access to personal data does not process such data except on instructions from the controller
unless required to do so by Union or Member State law.”

12 Under Article 5.2 of the GDPR, controllers must be able to demonstrate compliance with paragraph 1 of

Article 5 of the GDPR (the principle of accountability).

13. Article 24 of the GDPR states in its first two paragraphs that: “1. Taking into account the nature, scope, context and purposes of the processing and the risks, of varying likelihood and severity, to the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and be able to demonstrate that processing is carried out in accordance with this Regulation. These measures shall be reviewed and updated where necessary. 2. Where proportionate to the processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.” Decision on the merits 188/2025 — 12/15

41. The Litigation Chamber underlines in this regard the specific nature of the consultation of the National Register. This consultation is strictly regulated and limited to certain entities and professions in particular. As the Litigation Chamber has already had occasion to

emphasize in several decisions, this database, containing a certain amount of information relating to more than 11 million people, inherently requires

particularly rigorous oversight, not only given its size,

but even more so because of its very purpose of recording, storing, and

communicating information relating to the unique identification of natural persons. It

is therefore absolutely essential that those who, like the defendant, have access to the

National Register scrupulously comply with its conditions.

42. In this case, as noted above, the defendant states in its submissions that, at the time of the alleged events, it had implemented sufficient technical

and organizational measures, such as the confidentiality clause signed by the offending employees,

relevant clauses in the work rules, and the required indication of a generic reason
for consultation to be provided for each consultation.

43. The Internal Security Service (ISS) notes that the defendant did not have, at the time of the events, an adequate

control mechanism ensuring that its authorized employees consulted the

National Register only for the purposes for which such access was authorized.

44. The Litigation Chamber is of the opinion in this regard that the evidence presented by the

defendant concerning measures in place at the time of the events does not

rebut the ISS's findings. Admittedly, the employees were bound by a confidentiality clause

(the necessity and relevance of which the Litigation Chamber does not dispute).

However, this measure alone does not allow for verification of compliance with the principle of

purpose. Similarly, the clauses invoked in the work rules—whose necessity and relevance the

Litigation Chamber does not question either—are

also not of a nature to allow for such verification. The Litigation Chamber further notes

that, with regard to the work rules, it does not appear that the relevant clauses

were applicable at the time of the events. The extract produced by the defendant states
in fact that it is the version applicable from July 19, 2022, that is, only after

the reported events.

45. In conclusion, the Litigation Chamber finds that the defendant, at the time of the events in question, failed to implement an adequate control system regarding compliance with the legal framework for consultations of the National Register, in violation of Articles 5.2 and 24.1 of the GDPR, on which it invited the defendant to defend itself in these proceedings.

46. The Litigation Chamber adds that it is aware that during the investigation, the defendant stated that it had implemented a number of new measures, including, in addition to the measures listed in the footnote, a policy of quarterly monitoring access to the National Register for the defendant's municipal administration staff.

47. However, these measures do not remedy the past breach. They may, however,

be taken into account by the Litigation Chamber when assessing the

corrective measure/sanction appropriate to the specific case (see Title III).

48. Regarding the questions raised by the complainant concerning the lack of transparency in

the decision to replace the internal DPO with an external DPO, the Litigation Chamber

specifies that this issue falls outside the scope of its jurisdiction. It notes, for

purely informational purposes, that Article 37.6 of the GDPR provides that "the data protection officer

may be a member of the staff of the controller or processor,

or perform their duties on the basis of a service contract" and that a DPO may

perform their function with regard to several authorities, companies, entities, and structures. It adds

that the question of compliance or non-compliance with public procurement regulations does

not fall within its jurisdiction.

III. Corrective Measures and Sanctions

49. Pursuant to Article 100.1.1° of the LCA (Law on the Protection of Personal Data), the Litigation Chamber has the power to:

1° dismiss the complaint;

2° order a dismissal of the case;

3° suspend proceedings;

4° propose a settlement;

5° issue warnings or reprimands;

6° order compliance with the requests of the person concerned to exercise their rights;

7° order that the person concerned be informed of the security issue;

8° order the freezing, limitation, or temporary or permanent prohibition of processing;

14. Service note on consulting the National Register with a validation form for the purpose by the head of department
Civil and Social Affairs for departments that do not have access to the National Register;

The addition of a free-text field to more precisely justify the purpose of the consultation, going beyond the generic purposes that were the only ones possible at the time;

A formal notice to the staff of the Social Affairs department to comply with data protection rules (including a reminder of the penalties for non-compliance, which can include dismissal for serious misconduct and referral to the public prosecutor);

A data protection awareness session for the municipal council;

A request to the municipal administration to ensure that the SAPHIR application is fully compliant with the regulations concerning the National Register.

15. Accordingly, the Litigation Chamber does not consider the documents filed on this matter by the complainant outside the time limits for filing submissions.

(paragraphs 25-26) Decision on the merits 188/2025 — 14/15

9. Order compliance of the processing

10. Order the rectification, restriction, or erasure of the data and notification thereof to the data recipients;

11. Order the withdrawal of the accreditation of the certification bodies;

12. Impose penalty payments;

13. Impose administrative fines;

14. Order the suspension of cross-border data flows to another State or an international organization;

15. Transmit the case to the Public Prosecutor's Office in Brussels, which informs it of the action taken on the case;

16. To decide on a case-by-case basis to publish its decisions on the website of the Data Protection Authority.

50. With regard to the potential violation of Articles 5.2 and 24.1 of the GDPR, on which the Litigation Chamber invited the parties to submit their arguments, the Litigation Chamber decided in paragraph 45

above that the defendant is guilty of a breach of these articles.

51. In assessing the appropriate sanction for this breach, the Litigation Chamber

takes into account all the specific circumstances of the case. The defendant's status as a public authority

is a factor that contributes to the seriousness of its breach.

Indeed, as the Litigation Chamber explained above, access to the National Register

is strictly regulated and limited. When it involves a public authority, as in

this case, it must set an exemplary standard. However, Belgian law

has not authorized the Litigation Chamber to impose an administrative fine on

public authorities for GDPR violations committed in

the performance of their duties, as is the case here. The Litigation Chamber

also notes that the defendant acknowledged the seriousness of the situation by
sanctioning its offending employees and implementing a number of

both technical and organizational measures (listed in paragraph 46 and footnote 14) after the reported events

to prevent this type of unlawful access from recurring and to ensure

control of the accesses carried out.

52. In light of the foregoing, the Litigation Chamber decides that a reprimand is,

pursuant to Article 100.1.5° of the LCA, the appropriate sanction in this case.

53. The Litigation Chamber adds that, furthermore, it is not required to explain

the reasons why it does not impose another of the sanctions listed in Article 100.1 of

the LCA, even when such a sanction has been requested by one or the other party.

Thus, the Litigation Chamber is not required to explain the reasons why it does not