APD/GBA (Belgium) - 200/2025
| APD/GBA - 200/2025 | |
|---|---|
| Authority: | APD/GBA (Belgium) |
| Jurisdiction: | Belgium |
| Relevant Law: | Article 6(1) GDPR Article 12(2) GDPR Article 12(3) GDPR Article 12(4) GDPR Article 15(1) GDPR Article 15(3) GDPR |
| Type: | Complaint |
| Outcome: | Partly Upheld |
| Started: | |
| Decided: | 28.11.2025 |
| Published: | |
| Fine: | n/a |
| Parties: | n/a |
| National Case Number/Name: | 200/2025 |
| European Case Law Identifier: | n/a |
| Appeal: | n/a |
| Original Language(s): | Dutch |
| Original Source: | APD (in NL) |
| Initial Contributor: | dt |
The DPA issued a reprimand to a company for unlawfully transmitting information on a former employee in a phone conversation with another company during a recruitment process. The DPA also reprimanded both companies for failing to respond to access requests.
English Summary
Facts
The data subject was an employee of controller (1) between 1 June 2015 and 14 November 2016.
In 2020, the data subject applied for a job at a non-profit organisation (controller 2). Controller 2 informed the data subject that the organisation was not moving forward with them as a candidate, mentioning a conversation with a manager of controller (2) about the data subject's managerial experience.
Following the access request submitted by the data subject on 8 July 2020, controller (1) provided general information regarding personal data processing within the company and did not attach a copy of the requested data. Instead, it asked for further explanations regarding the access request previously submitted.
The data subject made an access request to controller (2) as well but did not receive a response within one month.
The data subject lodged a complaint with the DPA against controller (1) since they were unsatisfied with the response received among other things. They also lodged a complaint against controller (2) concerning, among other things, the failure to respond in a timely manner to their access request and unlawful processing of their personal data.
The DPA decided to join the complaints of the data subject against controller (1) and against controller (2).
Holding
The DPA issued a reprimand to controller (1) for the infringements of Article 6(1) GDPR, Article 12(2)-(4) GDPR, Article 15(1) and (3) GDPR. The DPA also issued a reprimand to controller (2) for the infringement of Article 12(3) GDPR.
With regard to controller (1), first the DPA found that it violated Article 6(1) GDPR by processing personal data without a legal basis when providing controller (2) with information on the data subject without the data subject’s consent.
The DPA pointed out that the transfer of personal data during an oral phone conversation constitutes processing of personal data (Endemol Shine Finland). Furthermore, since controller (1) knew or should have known that controller (2) would include the information in the recruitment file, the DPA found that the verbal provision of information constituted processing of personal data. However, as controller (1) did not obtain the data subject's consent for such processing, it violated Article 6(1) GDPR.
Secondly, the DPA found that controller (1) violated Article 12(2) GDPR, Article 12(3) GDPR and Article 15(3) GDPR by failing to provide a full copy of the data requested by the data subject in their access request. Furthermore, controller (1) violated Article 12(4) GDPR by not providing the copy within one month and failing to inform the data subject of the reasons for the refusal.
Thirdly, the DPA found that controller (1) violated Article 15(1) by failing to provide complete information to the data subject's access request.
With regard to controller (2), the DPA found that the controller violated Article 12(3) GDPR by not responding to the data subject within one month of receipt due to sending the information to the incorrect email address.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Dutch original. Please refer to the Dutch original for more details.
1/33 Dispute Resolution Chamber Decision on the merits 200/2025 of 28 November 2025 File numbers: DOS-2021-01940 and DOS-2021-04314 Subject: Complaint about a request for access and the basis for processing in a job application procedure The Dispute Resolution Chamber of the Data Protection Authority; Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter GDPR; Having regard to the Act of 3 December 2017 establishing the Data Protection Authority, hereinafter WOG; In view of the internal rules of procedure, as approved by the House of Representatives on 20 December 2018 and published in the Belgian Official Gazette on 15 January 2019; In view of the documents in the case; Has taken the following decision regarding: The complainant: X, hereinafter referred to as "the complainant" The defendants: Y1, represented by Mr. Frederic Debusseré and Mr. Ruben Roex, hereinafter referred to as "the first defendant" Y2, represented by Mr. Yves Vandendriessche and Mr. Bram Baert, hereinafter referred to as "the second defendant" Decision on the merits 200/2025 - 2/33 I. Facts and Procedure 1. The complainant was employed by the first defendant, Y1 (hereinafter referred to as "Y1"), from 1 June 2005 to 14 November 2016. Upon his dismissal, the complainant and Y1 entered into a settlement agreement, which stipulated, among other things, that Y1, her management, and her appointees would refrain from making any public negative comments about the complainant, including to future employers. 2. On July 6, 2020, Y1 received a registered letter in which the complainant alleged that Y1 had breached the settlement agreement. The complainant referred to an email dated July 2, 2020, which he had received from the second defendant, the non-profit organization Y2 (hereinafter "Y2"), to which he applied on June 26, 2020. In the aforementioned email, a Y2 employee informed the complainant that he would not be selected as a candidate in the selection procedure. This includes a reference to contact with a manager at Y1: “After our conversation last week, I checked your references with […] Y1. […]. Y1’s manager indicated that there were doubts and that you also have no management experience. Based on this information, we have decided to retain you from the further selection procedure.” The complainant therefore believes that Y2 did not recruit him based on the information provided by Y1. 3. On July 8, 2020, Y1 received an email from the complainant stating that the transfer of his personal data to Y2 in the context of the reference check constituted processing of personal data for which Y1 should be considered the controller. The complainant also requests Y1 to provide information about the processing of his personal data and to receive a copy of all personal data concerning him that it holds, referring to Articles 15.1 and 15.3 of the GDPR respectively. Finally, the complainant explicitly requests the legal basis as referred to in Article 6.1 of the GDPR on which Y1 relies for the processing of his personal data. 4. On July 9, 2020, Y1 informed the complainant by email and telephone that a special authorized representative had been appointed to consult with him. 5. On July 13, 2020, at the complainant's request, a meeting took place between the authorized representative and the complainant outside Y1's offices, during which it was agreed that a new settlement proposal would be drawn up by Y1. On July 29, 2020, Y1 provided the complainant with a draft of an amended settlement agreement. In an email dated August 3, 2020, the complainant confirmed that he had reviewed the draft and that he wished to consult on it. Subsequently, the complainant and Y1 attempted to set a date. 6. Pending an agreement on the date for the planned consultation, Y1 complied with the complainant's request for access on August 7, 2020. However, Y1 provided Decision on the merits 200/2025 - 3/33 only general information regarding the processing of personal data within the company. Y1 did not attach a copy of the personal data as referred to in Article 15.3 GDPR, but requested the complainant to further explain his request for access in order to better assess which personal data and which processing activities the request pertains to. In addition, Y1 proposed new dates for further consultation on the draft of the settlement agreement. 7. Y1 states that a new consultation took place on August 26, 2020, during which the complainant indicated that he did not agree with the settlement proposal, reason why he would submit his own proposal to Y1. This assertion is not disputed by the complainant. 8. On September 8, 2020, the complainant formally served notice of default on Y1 for failing to comply with its obligations under Articles 6.1, 15.1, and 15.3 of the GDPR, as well as for exceeding the deadlines set in Article 12, paragraphs 3 and 4 of the GDPR for responding to his request for access and a request for a copy of his personal data. The complainant again argues that Y1 shared his personal data with third parties on July 2, 2020, and between July 8 and July 29, 2020, causing him damage. The complainant clarifies that he expects an adequate response to the questions he posed in his initial request of July 8, 2020, and also requests a full copy of all personal data concerning him held by Y1, including all reports and recruitment documents it obtained at the time of his recruitment, such as his CV and the assessment from the recruitment agency. 9. On September 28, 2020, Y1 responded to the formal notice by letter from its counsel, in which it entirely denies the alleged non-compliance with the aforementioned GDPR articles. It reiterates that it has the right to ask the complainant to further specify its access request so that it can respond appropriately. 10. On October 22, 2020, the complainant, in a letter from his counsel, reiterated his allegations against Y1 regarding the late and insufficient response to his access request of July 8, 2020. He pointed out to Y1 that he did not need to specify his access request and reiterated his wish to receive a copy of all data in Y1's possession. 11. On November 3, 2020, Y1 reiterated her positions in a letter from her counsel. On January 26, 2021, the complainant reiterated his allegations and requests in a letter from his counsel. 12. In the absence of further explanation regarding the access request, Y1 provided the complainant, at his request, with the personal data "which [she] could reasonably suspect to relate to them." Y1 assumes that by providing this information, it has fully complied with the obligations under Article 15.3 of the GDPR. According to Y1, the other obligations under Article 15 of the GDPR have already been met. 13. Since the complainant cannot accept the information and copy provided by Y1 and believes them to be incomplete, he filed a complaint with the Data Protection Authority against Y1 (first defendant) on March 24, 2021, through his then-judge. The complainant believes that Y1 does not have a valid basis for processing his personal data, both during and after the employment contract ends, in violation of Article 6.1 GDPR, and that Y1 has violated his right of access (Article 15 GDPR) by providing him with incomplete information after the expiry of the period provided for in Article 12.3 GDPR. Furthermore, the complainant states that Y1 has violated his rights to rectification (Article 16 GDPR), to erasure of his personal data (Article 17 GDPR), to restriction (Article 18 GDPR), and to objection (Article 21 GDPR). Finally, the complainant alleges that Y1 has not complied with the principles of lawfulness, property and transparency (Article 5.1.a) of the GDPR in conjunction with Articles 12.1 and 13 of the GDPR), purpose limitation (Article 5.1.b) of the GDPR), data minimization (Article 5.1.c) of the GDPR), and accuracy (Article 5.1.d) of the GDPR) with respect to his personal data. 14. On April 13, 2021, the complaint against Y1 was declared admissible by the First Line Service pursuant to Articles 58 and 60 of the Dutch Data Protection Act (Wet op de Gemeenschapsregeling), and the complaint was referred to the Dispute Resolution Chamber pursuant to Article 62, § 1 of the Dutch Data Protection Act (Wet op de Gemeenschapsregeling). 15. On April 21, 2021, the Primary Care Service received a letter from the judges of Y1 in which they refute the allegations in the complaint and request that they mediate between the parties. The judges of Y1 also emphasized their suspicion "that the exercise of his rights under the GDPR is merely a way for the gentleman to improve his negotiating position for a new settlement and to obtain compensation for an (alleged) violation of the aforementioned settlement." 16. On May 18, 2021, the complainant, through his then-counselor, also filed a complaint with the Data Protection Authority against Y2 (second respondent) by registered mail. The subject of the complaint concerns the failure to respond in a timely manner to a request for access (Article 12 in conjunction with 15 GDPR), as well as the lack of a valid basis (Article 6 GDPR) for the collection of the complainant's personal data by Y1 in the context of a job application procedure and the subsequent processing of this personal data. Decision on the merits 200/2025 - 5/33 The complainant also considers that Y2 violated his rights to rectification (Article 16 GDPR), to erasure of his personal data (Article 17 GDPR), to restriction (Article 18 GDPR), and to object (Article 21 GDPR). Finally, the complainant argues that Y2 violated Article 14 of the GDPR by failing to provide him with sufficient information about the source of the personal data concerning him, as part of the response to his access request (pursuant to Article 15.1.g) of the GDPR). The complainant believes that Y2 is obligated to provide the first and last name of the person within Y1 who allegedly shared his personal data with them. 17. On June 4, 2021, the complaint against Y2 was declared admissible by the First Line Service pursuant to Articles 58 and 60 of the Dutch Data Protection Act (Wet op de Gemeenschapsregeling), and the complaint was transferred to the Dispute Resolution Chamber pursuant to Article 62, § 1 of the Dutch Data Protection Act (Wet op de Gemeenschapsregeling). 18. Following the two aforementioned complaints concerning the same facts, two files were therefore submitted to the Dispute Resolution Chamber: DOS-2021-01940 and DOS-2021-04314. On August 2, 2021, the Dispute Resolution Chamber, based on the documents submitted, decided to join both complaints, given their interrelationship. This decision ruled on both complaints. On August 2, 2021, the Dispute Resolution Chamber also decided, pursuant to Article 95, § 1, 1° and Article 98 of the Dutch Civil Code (WOG), that the file is ready for consideration on the merits. 19. On August 2, 2021, the parties concerned were notified by registered mail of the provisions referred to in Article 95, § 2, as well as those in Article 98 of the WOG. They were also informed, pursuant to Article 99 of the WOG, of the deadlines for submitting their defenses. The deadline for receipt of the defendants' statement of reply was set at September 27, 2021, this for the complainant's statement of reply on October 18, 2021, and this for the defendants' statement of rejoinder on November 8, 2021. 20. On August 3, 2021, the parties confirmed receipt of the aforementioned registered mail, as well as their agreement to further exchanges regarding the case by electronic means. 21. On 27 September 2021, the Litigation Chamber received the statements of reply from Y1 and Y2 respectively. 22. On 18 October 2021, the Litigation Chamber received the statement of reply from the complainant. 23. On 8 November 2021, the Litigation Chamber received the statements of rejoinder from Y1 and Y2 respectively. 24. The Litigation Chamber is aware that a considerable period has elapsed between the filing of the last statement and the judgment in this case. It wishes to express its sincere apologies to the parties for this. Despite this delay, the Dispute Chamber considers it appropriate to issue a reasoned decision in this case, which will be published anonymously on its website. This is done not only to ensure careful handling of the present complaint, but also with the intention of contributing to a correct and uniform understanding of the applicable obligations for the parties involved. This dispute offers a suitable opportunity to further clarify the applicable rules regarding the processing of personal data in the context of reference checks for job applications. II. Reasoning II.1. Scope of the dispute 25. As an introduction, the Dispute Resolution Chamber notes that this case falls within a broader dispute between the complainant and Y1 (the first defendant) concerning the breach of a mutually concluded settlement agreement as a result of the complainant's dismissal in November 2016. The jurisdiction of the Dispute Resolution Chamber in the present case is naturally limited to questions regarding data protection. The Dispute Resolution Chamber will rule on the allegedly unlawful processing of references concerning the complainant by both defendants (Section II.2.), as well as on the alleged violation of his right of access following requests submitted by the complainant to each of the defendants (Section II.3.). Furthermore, the Litigation Chamber will assess the possible violation of other rights under the GDPR by both respondents (Section II.4.), as well as the alleged violation of the basic principles regarding the processing of personal data by Y1 (Section II.5.). II.2. The processing of personal data in the context of a job application procedure II.2.1. The concept of “personal data” — Art. 4.1 GDPR 26. First, the Litigation Chamber must assess the extent to which the respondents have processed personal data relating to the complainant. 27. Article 4.1 GDPR defines the concept of “personal data” as “any information relating to an identified or identifiable natural person (“data subject”); An identifiable natural person is considered to be one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. This definition therefore includes four constitutive and cumulative elements: Decision on the merits 200/2025 - 7/33 a. “any information” 28. The Litigation Chamber points out that the term “personal data,” as explained in Article 4.1 of the GDPR in conjunction with Recital 26 of the GDPR, Opinion 4/2007 of the Working Party, as well as the case law of the Court of Justice, should be interpreted broadly and encompass both objective and subjective information, regardless of whether this information is correct or proven. The term “any information” used in Article 4.1) of the GDPR must therefore be interpreted literally, regardless of the nature, content, or form of the information concerned. Recital 26 of the GDPR, moreover, emphasizes this extensive interpretation of the term “personal data,” by stating that “the principles of data protection must apply to any information relating to an identified or identifiable person.” 29. This was also confirmed by the Data Protection Working Party in its Opinion 4/2007 on the concept of personal data, where it states the following in this regard: “With regard to the nature of the information, ‘personal data’ includes all kinds of statements about a person. It also includes ‘subjective’ information, opinions, and judgments. […] In order to be considered ‘personal data,’ it is not necessary for the information to be true or proven.” 3 30. The Court of Justice of the European Union has emphasized the foregoing on several occasions. In its judgment in Nowak of 20 December 2017, the Court stated in this regard specifically: “The use of the words ‘any information’ in the definition of the term ‘personal data’ […] indicates that the EU legislature intended to give this term a broad meaning, which is not limited to sensitive or personal information but potentially extends to any type of information, both objective information and subjective information in the form of opinions or assessments, provided that this information ‘concerns’ the data subject.” 31. More specifically, the Court of Justice ruled in Nowak that the evaluation and comments of an examiner regarding an examination taken by the data subject must be considered personal data within the meaning of current Article 4(1) of the GDPR. The Court also pointed out that not classifying this data as personal data would completely remove it from the protection of the principles and guarantees regarding personal data, and more specifically 1A. OCQUET (D.), Ulim ANNEKENS ENSOFIEDEPRE, Handboek Gegevensbescherming in de diep en in de praktijk, LeA Publishers 2024, Leuven, p. 1 OCKSEY and H. IJMAN, “The Court of Justice as a Key Player in Privacy and Data Protection: An Overview of Recent Trends” in Case Law at the Start of a New Era of Data Protection Law, EDPLReview 2019, pp. 302-304. 2 Emphasis by the Litigation Chamber. 3 Article 29 Data Protection Group, Opinion 4/2007, 20 June 2007, p. 6 (emphasis by the Litigation Chamber). 4 CJEU, 20 December 2017, C-434/16, Nowak v. Data Protection Commissioner, ECLI:EU:C:2017:994, paragraph 34. Decision on the merits 200/2025 - 8/33 rights of access, rectification, and objection, as well as the supervision by the supervisory authorities. 32. The Data Protection Working Party and the Court of Justice further clarified that this information may relate to both the personal life of the data subject and 6 their professional or public activities: “‘Personal data’ includes information relating to a person’s private or family life in the strict sense, but also information about all kinds of activities a person undertakes, for example, about a person’s professional relationships or economic or social behavior. It therefore concerns information about persons, regardless of their position or capacity (consumer, patient, employee, customer, etc.).”7 33. Based on the above elements, the Litigation Chamber may conclude that the first constitutive element is present in this case. b. “about” 34. A second constitutive element of the definition of “personal data” in Article 4.1) GDPR is that the information must be “about” a natural person, the data subject. In its Opinion 4/2007, the Data Protection Working Party points out that this may be the case both directly and indirectly, insofar as the information “refers to the identity, characteristics or behaviour of a person or if such information is used to determine or influence the way in which that person is treated or assessed.” 35. The Data Protection Working Party specifies in this regard that information that does not directly relate to a natural person may still be considered “information about” the natural person in the following two cases: a. When the data are used or are likely to be used for the purpose of assessing, treating or influencing the data subject’s status or behaviour; or b. When the use of the data is likely to have an impact on certain individuals, regardless of whether this impact is significant or minor. 5 CJEU, 20 December 2017, C-434/16, Nowak v. Data Protection Commissioner, ECLI:EU:C:2017:994, para. 49. 6 ECtHR, 16 February 2000, no. 27798. 7Article 29 Data Protection Working Party, Opinion 4/2007, 20 June 2007, p. 7. See, in the same vein, the Opinion of Advocate General E. Sharpston of 12 December 2013 in joined cases C-141/12 and C-372/12 (Y.S.), para. 45. 8Article 29 Data Protection Working Party, Opinion 4/2007, 20 June 2007, p. 10. Decision on the merits 200/2025 - 9/33 36. The Data Protection Working Party points out that, as long as there is a possibility that the data subject will be treated differently, for example, as a result of the processing of the data in question, there is an impact on the person.9 37. This was also confirmed by the Court of Justice, which stated in this regard that this second condition “is met when the information, by reason of its content, purpose or effect, is linked to a specific person.”10 38. In the present case, the Litigation Chamber finds that the information in question — i.e., references regarding the relevant experience and qualifications of the complainant — can undeniably be traced back to the complainant and may have an impact on him, with the result that the second constitutive element is present. c. “an identified or identifiable” “natural person” 39. A person is “identified” when that person is individually distinguished from other persons within a given group, by means of one or more identifiers.1 40. Given that the exchange of references about an individual candidate necessarily entails that the data subject is at least indirectly identifiable to the former and future employer, the Litigation Chamber finds that the data subject has been irrefutably identified and that the information exchanged by the respondents in this case thus relates to an “identified or identifiable person” within the meaning of Article 4.1) GDPR. 41. It must therefore be concluded that the third and fourth constitutive elements of the concept of personal data are also present in this case. The Litigation Chamber therefore rules that the references concerning the complainant's relevant experience and qualifications must indeed be considered personal data concerning him. II.2.2. The concept of "processing" – Art. 4.2 GDPR 42. In accordance with Article 2.1 in conjunction with recital 15 of the GDPR, it applies to the wholly or partly automated processing of personal data, as well as to the non-automated processing of personal data which are contained in a filing system or are intended to be contained in a filing system. 9 Data Protection Working Party Article 29, Opinion 4/2007, 20 June 2007, pp. 11-12. 10 CJEU, 20 December 2017, C-434/16, Nowak v. Data Protection Commissioner, ECLI:EU:C:2017:994, paragraph 1. 35 (own emphasis). 1 Data Protection Working Party Article 29, Opinion 4/2007, 20 June 2007, p. 13. Decision on the merits 200/2025 - 10/33 According to Article 4.2) GDPR, "processing" of personal data shall mean: "any operation or set of operations which is performed upon personal data or on sets of personal data, whether or not by automatic means, such as collection, recording, organization, structuring, storing, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction." 43. In the present case, both defendants argue that the disputed telephone conversation took place purely orally, was not recorded or otherwise registered, nor was its content processed in any way. Consequently, the defendants argue that there can be no question of processing within the meaning of the GDPR. The complainant, on the other hand, believes that the GDPR does apply, since, according to him, there has indeed been processing of personal data. On July 2, 2020, Y2 received personal data from the complainant via Y1, which Y2 subsequently processed in an email to the complainant, which is a file. 44. The Litigation Chamber points out that the transfer of personal data during a oral telephone conversation does indeed constitute “processing” of personal data within the meaning of Article 4.2) GDPR. That article clearly stipulates that the “disclosure by transmission, dissemination or otherwise making available” of personal data constitutes “processing” within the meaning of the GDPR. The Litigation Chamber also refers to the Endemol Shine Finland judgment, in which the Court of Justice unambiguously established that the term “processing” within the meaning of Article 4.2) of the GDPR necessarily encompasses the oral disclosure of personal data. 13 45. Since oral disclosure as such constitutes non-automated processing, the Litigation Chamber must, in the present case, examine whether the data provided by Y1 are “included” in a “filing” or “intended to be included” in a filing system. According to Article 4.6 of the GDPR, the term “filing system” should be interpreted as “any structured set of personal data accessible according to specific criteria, regardless of whether it is wholly centralized, decentralized, or dispersed on a functional or geographical basis.” The Litigation Chamber points out that this provision provides a broad definition of the term “filing system.” Moreover, the requirement that the set of personal data must be “structured according to specific criteria” is intended solely to ensure that the personal data can be easily retrieved. In addition to this requirement, Article 4.6 of the GDPR contains 1 Emphasis by the Litigation Chamber 1 CJEU, 7 March 2024, C-740/22, Endemol Shine Finland, ECLI:EU:C:2024:216, para. 32 Decision on the merits 200/2025 - 11/33 no provision regarding the manner in which a file must be structured, and the form such a file must have.14 46. In the present case, Y1 argues that it did not consult any file, such as the complainant's personnel file, in order to provide the information contained therein to Y2. The Litigation Chamber notes that it is not required to verify whether or not Y1 consulted a file containing the complainant's personal data. The Litigation Chamber finds that Y1 knew, or should have known, that the information she provided about the complainant would be included in a file by Y2, namely in the recruitment file that the latter maintains on the complainant. Given these circumstances, the Dispute Resolution Chamber finds that Y1's verbal provision of information about the complainant to Y2 constitutes processing of personal data that falls within the material scope of the GDPR. 47. The Dispute Resolution Chamber also considers it sufficiently proven that Y2 processed the complainant's personal data in the context of the application procedure within the meaning of Article 4.2) of the GDPR, and furthermore that this personal data was included in a file. The Dispute Resolution Chamber finds that Y2 recorded the content of the interview, although not verbatim, at least in general terms, in writing in an email to the complainant. 48. Consequently, the Dispute Resolution Chamber will have to address the lawfulness of the processing by both respondents in a subsequent section (II.2.3). II.2.3. Lawfulness of the processing — Art. 6.1 GDPR 49. Now that it has been established that both respondents have processed personal data about the complainant within the meaning of the GDPR, the Dispute Resolution Chamber must address the lawfulness of this processing. To ensure logical reasoning, the Board will first assess the lawfulness of the collection and further processing of references by Y2 (the second defendant). It will then examine the lawfulness of the transfer of the complainant's personal data by Y1 (the first defendant). a. The lawfulness of the collection and further processing of references by Y2 (the second defendant) 50. The Dispute Resolution Chamber finds that Y2 relies on the complainant's consent for the collection and further processing of references. To this end, Y2 submits the minutes of the job interview she prepared, which must demonstrate that the complainant has 1See also ECJ, 7 March 2024, C-740/22, Endemol Shine Finland, ECLI:EU:C:2024:216, paragraph 37; ECJ, 10 July 2018, C-25/17, Jehovan todistajat, ECLI:EU:C:2018:551, paragraphs 57-58, Decision on the merits 200/2025 - 12/33 given consent to contact Y1. 15 Furthermore, Y2 argues that, given that the complainant voluntarily mentioned Y1 in his CV, this can be considered valid consent. 51. The Litigation Chamber recalls that Articles 4.11 and 7 of the GDPR, read together with Recital 43 of the GDPR, indicate that in the context of a job application procedure, the data subject's consent can only serve as a legitimate legal basis for the collection and further processing of references in exceptional cases. It is, in particular, established that the relationship between a potential employer and an applicant is characterized by the latter's dependent position, which leads to a presumed imbalance within which consent cannot, in principle, be freely given. 52. The Litigation Chamber, on the other hand, accepts that consent can be used as a legal basis if the controller has obtained the data subject's consent by signing a declaration, the scope of which they could clearly understand and which contains at least the following elements: a. The identity of the organization or persons the prospective employer intends to consult b. The nature of the data requested c. The reasons for collecting the data d. The period during which the consent will be used The Dispute Resolution Chamber emphasizes that such consent is only considered freely given if the data subject does not risk any negative consequences if they do not give their consent. In the context of a job application procedure, this means, for example, that the potential employer may under no circumstances lead the applicant to expect that their application will be assessed unfavorably or will not be considered if they do not consent to requesting references. 53. The Dispute Resolution Chamber also accepts that consent can be used as a valid legal basis if the applicant spontaneously, without being asked by the potential employer, explicitly indicates a reference person in their CV with the intention of contacting them. The Dispute Resolution Chamber emphasizes that, also in this case, the controller must comply with its information obligations under Article 14 GDPR. 15 Document 4 to the second defendant's statement of defense, dated 27 September 2021 16 EDPB, Guidelines 05/2020 on consent under Regulation 2016/679, version 1.1, 4 May 2020, pp. 8-10 Decision on the merits 200/2025 - 13/33 54. In view of the above and the parties' defenses, the Litigation Chamber finds that Y2 has not demonstrated that the complainant's oral consent, given during the job interview, meets the requirement under the GDPR of free expression of will. Indeed, the minutes of a job interview cannot serve as valid consent in the absence of a signature by the data subject, for the simple reason that the minutes were not taken by the data subject. Finally, the submitted documents also do not show that the complainant listed Y1 as a reference person in his CV, which could, if necessary, serve as valid consent. Y1 was only mentioned by the complainant in the section "work experience," but is nowhere explicitly mentioned as a reference. 55. In view of the above, the Dispute Resolution Chamber finds that Y2 could not lawfully rely on the complainant's consent pursuant to Article 6.1. a) GDPR for the consultation and subsequent processing of references. 56. The Dispute Resolution Chamber finds that Y2 also relies on its legitimate interest pursuant to Article 6.1. f) GDPR for the processing at issue. The Dispute Resolution Chamber has already pointed out in its previous decisions that the controller must designate a single legal basis for processing the processing on the basis of which it wishes to carry out the processing of personal data. The different grounds for lawfulness have different consequences, particularly with regard to the rights of data subjects. For the aforementioned reason, a controller is not permitted, depending on the circumstances, to rely on one legal ground, then another, for the same processing. 57. However, since Y2 could not lawfully rely on the complainant's consent for the collection of his references, the Litigation Chamber will now examine whether it could process the complainant's personal data based on its legitimate interest. 58. The Court of Justice has clarified in its case law that three cumulative conditions must be met for a controller to lawfully rely on Article 6.1.f) GDPR. More specifically, the controller must demonstrate that: a) the interests pursued by the processing can be considered legitimate (the "purpose test"); 17 Decision on the merits 55/2021 of 22 April 2021 of the Dispute Resolution Chamber, https://www.gegevensbeschermingsautoriteit.be/publications/besluit-ten-gronde-nr.-55-2021.pdf; Decision on the merits 138/2021 dated December 8, 2021 of the Disputes Chamber, https://dataprotectionauthority.be/publications/beslissing- substantive-no.-138-2021.pdf 18 CJEU, 4 May 2017, C-13/16, Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde v Rīgas pašvaldības SIA “Rīgas satiksme”, ECLI:EU:C:2017:336, edge no. 28 (“Rīgas Judgment”). Decision on the merits 200/2025 - 14/33 b) the intended processing is necessary for the realization of these interests (the “necessity test”); and c) the balancing of these interests against the interests, fundamental freedoms and fundamental rights of the data subject outweighs the controller's interests (the “balancing test”). 59. With regard to the first condition, the so-called “purpose test,” the Litigation Chamber of is of the opinion that checking references following a job interview must indeed be considered to be carried out for a legitimate interest. Employers have every interest in recruiting reliable and qualified employees. The Litigation Chamber considers that consulting employers who have previously worked with the complainant can provide a reliable and balanced picture of their performance in a professional context. The Litigation Chamber thus finds that the purpose test has been met. 60. In order to meet the second condition, the "necessity test," Y2 must demonstrate that the processing in this case was necessary to pursue the aforementioned legitimate interest. The Litigation Chamber points out that when assessing whether processing is "necessary," the controller must examine whether the legitimate interest pursued cannot be achieved equally effectively by alternative means that are less intrusive on the fundamental rights and freedoms of the data subject. If reasonable and equally effective, but less intrusive alternatives exist, the processing cannot be considered "necessary." 19 Y2 argues that, although it had access to the complainant's resume, cover letter, and information from the interview, it was necessary for it to verify the complainant's assertions regarding his experience and leadership. Y2 considers consulting references a necessary process to obtain a overall picture of the complainant and to determine how he actually behaves in a work environment, which could not be inferred from the complainant's statements, according to Y2, one-sided in the aforementioned sources. The Dispute Resolution Chamber is of the opinion that verifying references is a common and reasonable means for employers to gain insight into an applicant's professional skills, provided that it cannot request the collected information from the complainant himself. In view of this, the Litigation Chamber considers it necessary in this case for Y2 to gather work-related information relevant to assessing his suitability for the position for which he applied, especially since Y2 had doubts about the veracity of the complainant's claims, through consultation with the complainant's former employers. The Dispute Resolution Chamber points out that the information in question may not have been objectively obtained from the complainant himself. Since the complainant, as an applicant, has a clear interest in a positive presentation of the facts, the necessary independence and verification are lacking if Y2 has to make a decision solely based on his statements. In the present case, the Dispute Resolution Chamber therefore considers Y2's consultation of references a necessary processing of personal data in light of the legitimate interest pursued, and thus concludes that the necessity test was also met. 61. In order to determine whether the third condition, the so-called "balancing test," is met, it must be assessed whether Y2's legitimate interest outweighs the fundamental rights and freedoms of the complainant. In accordance with Recital 47 of the GDPR, this balancing test must also take into account the complainant's reasonable expectations. More specifically, it must be assessed whether "the data subject, at the time and in the context of the collection of the personal data, can reasonably expect that the processing can take place for that purpose." In this regard, the Dispute Resolution Chamber reiterates that Y2's interest, as a potential employer, in conducting a careful selection process is legitimate, and that verifying references in the present case constituted a proportionate and necessary means of assessing the complainant's reliability and suitability. This interest is balanced by the fundamental rights and freedoms of the complainant, whose personal data was processed following a telephone conversation. The Dispute Resolution Chamber finds that the processing was limited to relevant, job-related information and took place in a context in which the data subject's reasonable expectations were not exceeded. The Dispute Resolution Chamber finds that it falls within the complainant's reasonable expectation that Y2 would contact former employers, mentioned in his CV and explicitly mentioned during the job interview, to obtain or verify information. In light of this reasonable expectation, and considering the manner in which the processing took place, the Dispute Resolution Chamber finds that Y2's interest in this case outweighs the complainant's rights and freedoms. 62. The Dispute Resolution Chamber concludes that Y2 could legitimately rely on Article 6.1. f) GDPR for the processing of personal data during the consultation of references for the purpose of a job application procedure. The Litigation Chamber emphasizes that a controller who relies on Article 6.1 f) GDPR in this context must inform the substantive decision 200/2025 - 16/33 of the data subject's right to object, as stipulated in Article 21.4 GDPR, before requesting references. b. Lawfulness of the transfer of the complainant's personal data by the first respondent (Y1). 63. As explained, the Litigation Chamber has determined that the oral provision of information from the complainant by Y1 to Y2 constitutes processing of personal data for which Y1 must be considered the controller. Therefore, Y1 had to have a legitimate legal basis for this processing. Since Y1 argues that the aforementioned processing did not require a legal basis, the Dispute Resolution Chamber finds that Y1 has violated Article 6.1 of the GDPR. 64. For the sake of completeness, the Dispute Resolution Chamber points out that the transfer of information about a former employee to a potential employer in the context of a reference check is generally only possible based on the consent of the data subject. If the information provider can verify that the potential employer is requesting the information based on the prior, free and informed consent of the data subject, they do not need to request additional consent themselves. If such consent is lacking, for example because the potential employer is acting on the basis of legitimate interest, the information provider must obtain separate consent from the data subject before disclosing their personal data. II.3. Regarding the complainant's exercise of the right of access 65. In both complaints, the complainant believes that the respective respondent failed to respond promptly and adequately to a request for access to his personal data. The Dispute Resolution Chamber will therefore examine in the following sections, on the one hand, whether the respondents responded to the complainant's request for access in a timely manner (II.3.1), and, on the other hand, whether the information provided by the respondents is substantively in line with the obligations arising from the GDPR (II.3.2). II.3.1. Processing time for requests — Article 12 GDPR 66. The documents in the file show that the complainant's request for access was submitted to Y1 (the first respondent) on July 8, 2020. On August 7, 2020, Y1 complied with the request, providing only general information regarding the processing of personal data within the company. In addition, Y1 informed the complainant that, if he wishes to receive additional information, he must include a description of the nature and context of his request, so that a Decision on the merits 200/2025 - 17/33 can better assess which personal data and processing activities the access request relates to. 67. On September 8, 2020, the complainant formally served notice of default on Y1 for, among other things, exceeding the deadlines set out in Article 12, paragraphs 3 and 4 of the GDPR for answering his request for access to data and a request for a copy of his personal data. On September 28, 2020, Y1 responded to the notice of default by letter from her legal counsel, in which she stated, among other things, that, in accordance with Article 12.3 of the GDPR, she had informed the complainant within one month about "what action" had been taken on his request for access to data. Y1 pointed out to the complainant that this provision did not imply that she was also required to fully execute the request for access within one month. On October 22, 2020, the complainant denied this interpretation by letter from her legal counsel. He argues that, since no adequate response was provided to his access request within one month, and Y1 failed to inform the complainant within one month of receipt of the request of a possible extension of that period, an infringement of Article 12, paragraphs 3 and 4 of the GDPR has occurred. 68. The Litigation Chamber recalls that Article 12.3 of the GDPR requires the controller to inform the data subject without delay and in any event within one month of receipt of a request pursuant to Article 15 GDPR of the action taken in response to the request. This period may be extended by a maximum of two months taking into account the complexity and number of requests, provided that the controller informs the data subject within one month of receipt of the request of the reasons for the delay. This information obligation regarding the extension of the period and the justification for it should not be confused with the separate obligation, pursuant to Article 12.4 GDPR, to inform the data subject without undue delay and at the latest within one month if the controller decides not to comply with the request, and of the reasons for that decision. 69. Based on Y1's defenses, the Dispute Resolution Chamber finds that it partially refused to comply with the request for access pursuant to Article 15.4 of the GDPR, as further explained in paragraph 99 of this decision. This means that it should have informed the complainant of this without delay and no later than within one month, in accordance with Article 12.4 of the GDPR, as well as of the reasons for the refusal. The Dispute Resolution Chamber finds that Y1 failed to do so, and thus finds that it violated Article 12.4 of the GDPR. 70. The Litigation Chamber also points out that the receipt of the access request by the controller generally constitutes the starting point for the one-month period within which, in accordance with Article 12.3 GDPR, information must be provided. Decision on the merits 200/2025 - 18/33 20 on the action taken on the request. The Litigation Chamber specifies that this, as a rule, means that the information listed in Article 15, paragraphs 1 and 2 GDPR, as well as the copy of the personal data referred to in Article 15.3 GDPR, must be provided to the data subject without undue delay and in full within one month at the latest. Contrary to what Y1 repeatedly argues, the Dispute Resolution Chamber emphasizes that a mere response within one month—for example, by simply stating that the request will be processed—is clearly not sufficient to comply with the obligations arising from Article 12.3 of the GDPR in conjunction with Article 15 of the GDPR. 71. In the present case, the Dispute Resolution Chamber notes that Y1 substantively responded to the complainant's access request on August 7, 2020, in accordance with the deadline stipulated in Article 12.3 of the GDPR. However, with regard to the copy of personal data, Y1, in line with the possibility provided for in Recital 63 of the GDPR, requested the complainant to further specify his access request. 72. The Litigation Chamber recalls that recital 63 of the GDPR states in fine that “where the controller processes a large amount of data relating to the data subject, […] the controller must be able, prior to providing the information, to request the data subject to specify which information or processing activities the request relates to.” The Litigation Chamber points out that this recital must be read in conjunction with Article 12.2 of the GDPR, which stipulates that the controller is obliged to facilitate the exercise of the data subject’s rights. It follows that the controller may request specification if the access request is formulated in very general terms, presenting the controller with the challenge of providing a comprehensive response, while at the same time avoiding the provision of a plethora of information that is irrelevant to the data subject and which they cannot process effectively. In view of this, and in line with Guidelines 01/2022 of the European Data Protection Board, the Litigation Chamber points out that in such a case, the start of the period referred to in Article 12.3 of the GDPR is suspended until the data subject provides the requested clarification. In that case, the controller may await the data subject's response before providing additional information according to their request.22 The same applies, for example, when the 20EDPB, Guidelines 01/2022 on data subject rights – Right of access – version 2.1, 28 March 2023, para. 57 2Ibid., para. 35 22Ibid., para. 159 Decision on the merits 200/2025 - 19/33 controller contacts the data subject due to uncertainty about their identity. 73. It is important to emphasize that the request for specification may not be used to limit the scope of the response to the access request, nor to withhold information about the processing or personal data of the data subject. If the data subject, after being asked to specify their request in more detail, confirms that they wish to receive all personal data relating to them, 24 the controller must, of course, provide this information in full. 74. In the present case, the Dispute Resolution Chamber notes that the complainant, in his notice of default dated 8 September 2020, unambiguously clarified for the first time what his access request relates to. The complainant specifies that he expects a satisfactory answer to the questions he posed in his original request of July 8, 2020, and also requests a complete copy of all personal data concerning him that Y1 holds in its possession, including all reports and recruitment documents it obtained at the time of his recruitment, such as his resume and the recruitment agency's assessment. In a letter from his legal counsel dated October 22, 2020, the complainant also clarifies that he wants a copy of all data that Y1 processes about him and is still in its possession. Finally, in a letter from his legal counsel dated January 26, 2021, the complainant again clarifies that he wants a copy of every file (document, text, internal report, email, photo, video recording, etc.) that Y1 processes and on which he is identifiable. 75. Therefore, the Dispute Resolution Chamber concludes that Y1 first received the requested clarification from the complainant on September 8, 2020. The Dispute Resolution Chamber therefore finds that Y1's assertion in its letter of November 3, 2020 – namely, that the complainant refused to specify his request and that this was the only reason why he had not yet received a copy of his personal data – is unfounded. Since the complainant already clarified on September 8, 2020, that he wanted a complete copy of all personal data concerning him, Y1 should have complied by October 8, 2020. However, the Dispute Resolution Chamber notes that Y1 only provided the complainant with a copy of the data "which [she] could reasonably assume related to his request" on February 18, 2021. 76. In view of the above, the Litigation Chamber concludes that it has been demonstrated that Y1 infringed Article 12, paragraphs 2 and 3, of the GDPR. 23 Article 11.2 GDPR in conjunction with Article 12.6 GDPR 24 EDPB, Guidelines 01/2022 on data subject rights – Right of access – version 2.1, 28 March 2023, paragraph 35 25 Underlining by the Litigation Chamber Decision on the merits 200/2025 - 20/33 77. The access request addressed to Y2 (the second defendant) is also dated 8 July 2020. The Litigation Chamber notes that Y2 attempted to respond to this request on 27 July 2020, but that its response did not reach the complainant on that date. Y2 declares that, due to a material error, her response was sent to an incorrect email address that is almost identical to the complainant's. Y2 states that she assumed her response had been delivered successfully since she did not receive an error message. She therefore believed she had complied with the complainant's access request. 78. It was only through the formal notice of default of September 8, 2020, that Y2 was informed that her email had not reached the complainant. In response, Y2 sent a new email to the complainant on September 10, 2020, this time to the correct email address, in which she provided the complainant with the data listed in Article 15.1 GDPR. On September 16, 2020, Y2 sent an email to the complainant explaining that its initial response had not reached him because it was mistakenly sent to the wrong, though existing, email address. Y2 also stated that it had notified the Data Protection Authority of the data breach, receiving confirmation of receipt on September 14, 2020. 79. Y2 argues that, although the data was forwarded to an incorrect email address, it did respond to the complainant's request in a timely manner, so a violation of Article 12.3 GDPR cannot be established. 80. The Dispute Resolution Chamber reiterates that Article 12.3 GDPR obliges the controller to provide information on the action taken on the request without delay and in any event within one month of receipt of the request. The Dispute Resolution Chamber points out that this provision logically implies the actual delivery of that information to the data subject. Therefore, simply sending a response to an incorrect email address, without it actually reaching the data subject, cannot be considered a timely response. 81. In view of the above, the Dispute Resolution Chamber concludes that Y2 violated Article 12.3 GDPR. II.3.2. Handling of the access requests — Article 15 GDPR 82. The complainant argues that Y1 (the first respondent) has inadequately responded to his access request. Since the Dispute Resolution Chamber has already established that Y1 has responded late, 26 it will, in the remainder of its assessment, address only the question of whether Y1 has fulfilled its substantive obligations under Article 15, paragraphs 1 and 3, 26 See paragraphs 66 through 76 of this decision. Decision on the merits 200/2025 - 21/33 GDPR – regardless of whether this compliance occurred within or outside the one-month period. a) In fact 83. In his request of July 8, 2020, the complainant informs Y1 that she allegedly shared personal data concerning him with Y2. He also points out that he worked for Y1 from June 2005 to November 2016, initially through a recruitment agency and later as a direct employee. The complainant then requests all the information listed in Article 15.1 of the GDPR and expresses his wish to obtain a copy of all data in Y1's possession in accordance with Article 15.3 of the GDPR. Finally, he requests Y1 to state the legal basis, as referred to in Article 6.1 of the GDPR, for the processing of his personal data and, insofar as this processing is based on consent, to provide him with a copy of that consent. 84. In its response of 7 August 2020 to the complainant's access request, Y1 only provided general information about the processing of personal data within the company. In view of Y1's defences, the Dispute Resolution Chamber finds that Y1 only provided the information contained in its privacy statement, which applies to active employees. As an illustration, the Dispute Resolution Chamber refers to the example in which Y1, with regard to the processing purposes, states, among other things, that the complainant's personal data would be processed "for the performance and follow-up of the employment contract and the proper management of the personnel file." Also, with regard to the processing grounds (Article 6.1 GDPR), the categories of personal data concerned (Article 15.1 b GDPR), and the recipients of personal data (Article 15.1 c GDPR), Y1 refers to the general information contained in its privacy statement, which applies to its active employees. Finally, Y1 requests the complainant to include a description of the nature and context of the request, so that it can better assess which personal data and processing activities the request relates to. 85. In its response of 28 September 2020 to the complainant's notice of default, Y1 adds that it also processes the complainant's personal data based on Article 6.1 f) GDPR, specifically based on its legitimate interest in safeguarding its evidence in the context of ongoing disputes. In its response of 18 February 2021, Y1 adds, in accordance with Article 15.1 d) GDPR, that it will continue to process (store) the complainant's personal data for as long as necessary for the purposes of evidence in the context of ongoing disputes. Decision on the merits 200/2025 - 22/33 86. In the same response of 18 February 2021, Y1 points out that, with regard to the information regarding the rights mentioned in Articles 15.1(e) GDPR and 15.1(f) GDPR, it did not provide this information to the complainant in its initial response, as it was clear that the complainant already was aware of these rights, as he quoted them verbatim in his access request of 8 July 2020. Regarding the information in Articles 15.1(g) GDPR and 15.1(h) GDPR, Y1 explains that it could not provide any information on this matter, as these provisions are not applicable in this case. In the event of a lack of clarification from the complainant regarding the scope of their access request, Y1 also includes a copy of the complainant's personal data “which [it] may reasonably assume are the subject of the access request.” 87. By providing this information, Y1 indicates to the complainant that it has fully complied with its obligations under Article 15, paragraphs 1 and 3 of the GDPR. b) Position of Y1 (the first defendant) 88. In its defense, Y1 argues that the essence of the complaint filed against it can be reduced to various alleged violations of the GDPR that it allegedly committed when transferring personal data to Y2 in the context of a job application procedure. According to Y1, this is the reason why the complainant submitted its access request to her, and it also understood the complainant's request in this context. As further explained in section II.2.2 of this decision, Y1 argues that the mere transmission of personal data by telephone does not constitute processing to which the GDPR applies. According to Y1, it was therefore impossible to comply with the complainant's request, since the personal data he was seeking did not exist and the alleged processing had never taken place. For this reason, in its letter of 7 August 2020, Y1 provided general information about the processing of personal data that typically relates to an employment relationship and as described in its 27 privacy statement applicable to its employees. 89. Since the processing to which the complainant referred did not exist, and the request was therefore unclear, according to Y1, it invited the complainant to provide additional information about the nature and context of his request, in accordance with recital 63 in fine of the GDPR. According to Y1, this request for clarification was also justified, as the complainant had worked for her for 11 years, meaning that she inevitably processes a substantial amount of personal data, despite the 28 fact that she also deleted a significant amount of the complainant's personal data, such as his mailbox. 27Y1, rejoinder of 8 November 2021, pp. 7-9 28Y1, rejoinder of 8 November 2021, pp. 9-11 Decision on the merits 200/2025 - 23/33 90. Y1 argues that, despite her repeated insistence, the complainant refused any clarification regarding his access request in subsequent communications. According to Y1, the complainant persistently requested information about an alleged, but non-existent, processing, and a copy of personal data that she had not processed, namely the verbal transfer of personal data during the telephone conversation with Y2.29 91. Nevertheless, Y1 believes that, as the controller, it is obliged, to the extent possible and reasonable, to comply with the complainant's request. For this reason, in a letter dated 3 November 2020, it proposed providing the complainant with a copy of the personal data she still holds in her archived personnel file, as well as the email communications regarding the complainant made in connection with this case. However, Y1 makes the reservation that it will not provide emails already in the complainant's possession. Y1 argues that, although the complainant agreed to this proposal in his letter of January 26, 2021, he expanded his request for access at that time by also requesting a copy of every file (document, text, internal report, email, photo, video recording, etc.) that Y1 processes and on which he is identifiable. Y1 argues that it fully and completely complied with this request on February 18, 2021. However, it limited the provision of a copy of the personal data by invoking Articles 12.5 and 15.4 of the GDPR in conjunction with recital 63 of the GDPR. First, Y1 argues that it is not required to provide a copy of the emails that the complainant himself sent to it in the context of the present case, given that the complainant logically already has full possession of these personal data. According to Y1, this would completely miss the purpose of the right of access: the complainant is already aware that Y1 processes the emails he sent and for what purpose. Secondly, Y1 argues that it did not provide a copy of the internal communications and communications with its lawyers relating to the dispute with the complainant, as this would compromise its rights of defense. Finally, Y1 argues that it is also permitted to withhold internal reports and emails relating to company figures and affairs, which should therefore be considered business secrets, from the complainant. According to Y1, it thus had the right, pursuant to Articles 15.4 GDPR and 12.5 GDPR, to exclude the aforementioned information from the copy provided to the complainant. 29 Ibid., p. 14-16 30 Ibid., 17-22 Decision on the merits 200/2025 - 24/33 c) Judgment of the Litigation Chamber 92. First, the Litigation Chamber emphasizes the importance of the possibility for data subjects to exercise the right of access. The general purpose of this right is to provide data subjects with sufficient, transparent, and easily accessible information about the processing of their personal data. This enables data subjects to inform themselves about the existence and nature of the processing, and offers them the opportunity to assess the lawfulness and accuracy of the processed data. Furthermore, the Dispute Resolution Chamber emphasizes that the exercise of the right of access functions as an essential, but not a necessary, condition for the effective exercise of other rights granted to data subjects by the GDPR, 31 such as the right to rectification and the right to erasure. 93. In addition, the Dispute Resolution Chamber points out that data subjects are under no circumstances obliged to substantiate or justify their access request. As long as the requirements of Article 15 of the GDPR are met, the purposes behind the request must be considered irrelevant. The Dispute Resolution Chamber therefore points out in this case that the bias on the part of Y1 regarding the scope of the access request – namely, that it would only relate to the oral transfer of personal data to Y2 – cannot justify an incomplete or general response to the access request. The Dispute Resolution Chamber rules that, although the complainant's initial access request indeed refers to the transfer of personal data to Y2, Y1 is not free to unilaterally limit the scope of the request to that specific processing. The Dispute Resolution Chamber notes that the complainant also describes his request in general terms, for example, by stating that he wants clear information about "all provisions under Article 15, paragraph 1 of the GDPR," as well as by stating that he wants "a copy of all data in your possession" as guaranteed in Article 15.3 of the GDPR. For this reason, the Dispute Resolution Chamber finds Y1's argument, namely that it considered the complainant's access request limited to the transfer of personal data to Y2, unconvincing. 94. As previously mentioned, the Litigation Chamber finds that, with regard to the processing purposes, the categories of personal data processed, and the (categories of) recipients to whom these data have been or will be provided, Y1 refers exclusively to information characteristic of an employment relationship, as described in the privacy statement applicable to its employees. The 31 CJEU, 7 May 2009, C-553/07, Municipal Executive of Rotterdam v. M.E.E. Rijkeboer, ECLI:EU:C:2008:773, paragraphs 49 and 51; CJEU, 17 July 2014, joined cases C-141/12 and C-372/12, YS et al. v. Minister for Immigration, Integration and Asylum, ECLI:EU:C:2014:2081, paragraph 44 32 CJEU, 26 October 2023, C-307/22, FT (Copies of the medical file), ECLI:EU:C:2023:811, paragraph 38 Decision on the merits 200/2025 - 25/33 The Litigation Chamber notes in this regard that the general information provided is insufficient to meet the obligations imposed by the GDPR, since the complainant had not been employed by Y1 for five years at the time of his request. A reference to a privacy statement that applies only to active employees is in that case not only irrelevant, but also incorrect. The Dispute Resolution Chamber emphasizes that a controller, in the context of a request for access, must update all available information and align it with the specific processing that is actually taking place with regard to the data subject submitting the request. The Dispute Resolution Chamber therefore points out to Y1 that it was obligated to only provide information about the complainant's personal data that is actually being processed or stored at the time of the request for access. 95. Regarding retention periods, the Dispute Resolution Chamber notes that Y1 indicates that it will continue to retain the complainant's personal data "for as long as necessary for evidentiary purposes in the context of ongoing disputes." In this regard, the Dispute Resolution Chamber notes that Y1 expressly states in its defense that, due to the long-standing employment relationship with the complainant, it inevitably still processes a substantial amount of personal data. From this, as well as from the documents in the file, the Dispute Resolution Chamber infers that Y1 also processes the complainant's personal data for other purposes. In this regard, the Dispute Resolution Chamber emphasizes that, if different retention periods apply to the complainant's personal data, it must specify these periods for all processing activities and/or data categories, which 34 it failed to do. 96. With regard to the information included in Article 15.1 e) and f) of the GDPR, the Dispute Resolution Chamber notes that Y1 did not provide this information to the complainant in its initial response, as it was clear that the complainant was already aware of these rights. It also notes that Y1, in its response of 18 February 2021, failed to communicate this information to the complainant. The Dispute Resolution Chamber reminds Y1 that the GDPR imposes an objective information obligation on the controller, which means that it must provide the data subject with the full information referred to in Article 15.1 of the GDPR, without assessing their prior knowledge. Given the obligation to facilitate the exercise of the data subject's rights under Article 12.2 of the GDPR, the controller must be able to inform the complainant of their rights for each processing activity, which will depend on the legal basis. Information about rights that do not apply to the data subject in a specific situation should be avoided. 35 97. In view of the above, the Dispute Resolution Chamber finds that Y1 violated Article 15.1(a) through (f) of the GDPR. 98. Regarding Y1's obligation, pursuant to Article 15.3 of the GDPR, not to provide a copy of the personal data it processes, the Dispute Resolution Chamber notes that on February 18, 2021, the defendant provided the complainant with a copy "of the personal data that [it] may reasonably assume are the subject of the request for access." However, the Dispute Resolution Chamber notes that neither party submitted that copy as a document to the Registry of the Dispute Resolution Chamber, therefore it cannot take cognizance of its content. 99. The Dispute Resolution Chamber further notes that Y1 relies on Article 12.5 of the GDPR and Article 15.4 of the GDPR in conjunction with Recital 63 of the GDPR to refuse to provide certain documents containing the complainant's personal data. These documents include: - Emails sent by the complainant to Y1 in connection with the present dispute; - Internal communications and communications with its counsel relating to the present dispute, as their disclosure would prejudice Y1's rights of defense. - Internal reports and emails relating to company figures and matters and which, for that reason, must be considered business secrets. 100. The Dispute Resolution Chamber recalls that Article 15.4 of the GDPR limits the right to obtain a copy with the following wording: "The right to obtain a copy shall not adversely affect the rights and freedoms of others." Recital 63 of the GDPR explicitly specifies in this regard: "that right must not adversely affect the rights or freedoms of others, including trade secrets or intellectual property and in particular the copyright protecting the software." Article 15.3 of the GDPR may also be limited under Article 12.5 of the GDPR in the event of "manifestly unfounded or excessive requests." 101. Therefore, the Litigation Chamber points out that neither Article 12.5 of the GDPR nor Article 15.4 of the GDPR allows a controller to restrict the right to obtain a copy on the grounds that the data subject already possesses those personal data. The Litigation Chamber recalls that the right of access laid down in Article 15, of which the right to obtain a copy forms an integral part, is the right to obtain a copy. 119 Decision on the merits 200/2025 - 27/33 must enable the complainant to verify that the personal data concerning them are accurate and are processed lawfully, even if these personal data are contained in emails that they themselves have sent to the controller. 102. With regard to Article 15.4 of the GDPR in conjunction with Recital 63 of the GDPR, the Litigation Chamber notes that the right of access may not adversely affect the rights or freedoms of others, where “others” must be understood as any natural or legal person other than the data subject exercising the right of access. Consequently, it is possible that the right to obtain a copy is restricted if that right would adversely affect the rights or freedoms of the controller himself, as is argued in the present case. 36 103. The Litigation Chamber recalls that the right of access is a fundamental right, enshrined in Article 8, paragraph 2, of the Charter of Fundamental Rights of the EU. This means that it may only be restricted in accordance with Article 52, paragraph 1, of the Charter, which requires that any restriction on an EU fundamental right be “proportionate.” Article 15.4 of the GDPR must therefore be interpreted in light of the Charter, which implies that conflicting rights must be carefully weighed against the data subject's right of access on a case-by-case basis. As further explained in Recital 63 of the GDPR, this balancing should not result in the data subject being denied all information. The controller is therefore obliged, where possible, to provide the requested personal data in a manner that does not adversely affect the rights or freedoms of others. In the present case, this means that Y1 is obliged to provide the complainant's personal data to the complainant. The Dispute Resolution Chamber therefore points out to Y1 that it can fulfill its obligation under Article 15.3 of the GDPR by, for example: (i) granting partial access to the files, so that the complainant can only access their own personal data, (ii) applying anonymization or blocking of data to protect sensitive business information, or (iii) providing a contextual summary of the complainant's processed personal data. Such measures are indeed appropriate when full access would prejudice Y1's rights of defense or reveal its business secrets. 104. However, the Litigation Chamber finds that Y1 has in no way demonstrated that it balanced its own rights against the complainant's right of access, or attempted to provide the complainant with a copy of his personal data in 36 EDPB, Guidelines 01/2022 on data subject rights – Right of access – version 2.1, 28 March 2023, paragraph 171 37 Ibid., paragraph 173 Decision on the merits 200/2025 - 28/33 a manner that does not prejudice its own rights and freedoms. Furthermore, the Litigation Chamber finds, more generally, that a copy of the personal data "which [it] may reasonably assume to be the subject of the request for access" is insufficient in light of Article 15.3 of the GDPR. As confirmed by the Court of Justice of the European Union, the right to obtain a copy from the controller implies that the data subject must receive a faithful and intelligible copy of all personal data processed by the controller. 38 This therefore implies that the controller cannot, on its own initiative, limit the scope of the copy, nor can it be sufficient to merely provide a copy of the personal data it assumes are the subject of the request. 105. For the reasons listed above, the Litigation Chamber concludes that Y1 infringed Article 15.3 of the GDPR. 106. The complainant also argues that Y2 (the second defendant) has inadequately responded to his request for access. Now that the Dispute Resolution Chamber has already determined that Y2 has responded late, 39 it will, in the remainder of its assessment, focus solely on the question of whether Y2 has fulfilled its substantive obligations under Article 15, paragraphs 1 and 3, of the GDPR – regardless of whether this compliance occurred within or outside the one-month period. a) In fact 107. On July 8, 2020, the complainant exercises his right of access to Y2, requesting information regarding the processing of his personal data in accordance with Article 15.1 of the GDPR, specifically the information contained in sections a) through g) of that article. On September 10, 2020, Y2 sends an email to the complainant, in which it formulates a response to all the aforementioned sections of Article 15.1 of the GDPR. 108. The complainant argues that Y2 infringed Article 15.1(g) of the GDPR, as well as Article 14.1 a) and (b) of the GDPR, as it refused to disclose the identity of the person within Y1 whom it contacted to obtain his personal data in the context of the application procedure. The complainant argues that a mere reference to Y1 as a company as a whole is insufficient in light of these provisions. 38 CJEU, 4 May 2023, C-487/21, F.F. v. Österreichische Datenschutzbehörde, ECLI:EU:C:2023:369, paragraph 45. 39See paragraphs 77 to 111. 81 of this decision Decision on the merits 200/2025 - 29/33 b) Position of Y2 (the second defendant) 109. Y2 denies having violated the aforementioned articles. It states that in its email of July 2, 2020, in which the complainant was informed that he had not been selected for the further selection procedure, it indicated that the manager of Y1 had been contacted. Moreover, in its response to the access request, it also informed the complainant that his personal data was being collected from Y1. 110. Y2 argues that it acted in accordance with Article 14.1 a) and b), and that Article 15.1 g) nowhere stipulates that in this case the manager of Y1 should be referred to by name and first name. c) Judgment of the Litigation Chamber 111. The Litigation Chamber recalls that, in accordance with Article 15.1g) GDPR, the data subject has the right to obtain all available information about the source of their personal data if these were not collected from the data subject themselves. 112. The Litigation Chamber emphasizes that the use of the term "all available information" indicates a high degree of specificity regarding the sources from which the controller obtained the data. It is therefore not only important that the controller provides information about the identity of the source, but also which personal data were obtained from which source. The controller is also obliged to inform the data subject about the form in which the data were obtained. 40 The form in which the data were obtained. 113. However, similar to the information about the (categories of) recipients that must be provided to the data subject under Article 15.1(c) GDPR, the purpose of the information obligation under 15.1(g) GDPR is to enable the data subject to effectively exercise their rights under the GDPR, both vis-à-vis the controller itself and directly with the person or entity that provided the personal data (i.e., "the data source"). Applied to the present case, the Litigation Chamber concludes that Y2 was not obliged to communicate the surname and first name of the reference person within Y1 to the complainant. In this case, it was sufficient that Y2 informed the complainant that his personal data were obtained through Y1 "as an undertaking," given that this information was sufficient to enable the complainant to exercise his rights with Y1, which he did in this case. 40 EDPB, Guidelines 01/2022 on data subject rights – Right of access – version 2.1, 28 March 2023, paragraph 120, Decision on the merits 200/2025 - 30/33 114. In view of the above, the Litigation Chamber decides that Y2 did not infringe Article 15.1 g) GDPR, nor Article 14.1 a) and b) GDPR. II.4. Regarding the alleged violation of other rights under the GDPR by both respondents 115. In both complaints, the complainant argues that, in addition to his right of access, the respective respondents also violated his other rights under the GDPR. More specifically, the complainant alleges that both respondents violated his right to rectification (Article 16 GDPR), to erasure (Article 17 GDPR), to restriction (Article 18 GDPR), and to object (Article 21 GDPR). 116. However, the Litigation Chamber finds that the complainant has not exercised his rights under the aforementioned articles with respect to either Y1 or Y2. Although the Litigation Chamber reiterates that the exercise of the right of access functions as an essential condition for the effective exercise of the other rights that the GDPR grants to data subjects, it finds that a violation of the right of access does not automatically lead to a violation of other rights under the GDPR. 117. In view of the above, the Litigation Chamber finds that it has not been demonstrated that the respondents in this case violated the complainant's rights as set out in Articles 17, 18, 19, and 21 of the GDPR. II.5. Regarding the alleged violation of the basic principles regarding the processing of personal data by Y1 (the first defendant) 118. Since it has already been established that Y1 (the first defendant) acted in violation of Article 6.1 GDPR, the Litigation Chamber no longer considers it appropriate to further investigate whether she also violated the basic principles regarding data processing pursuant to Article 5.1 GDPR. The Litigation Chamber decides to dismiss this part of the complaint. III. Sanctions 119. In accordance with Article 100 of the Dutch Data Protection Act (WOG), the Litigation Chamber has the power to: 1° dismiss a complaint; 2° order a dismissal of the prosecution; 3° order a suspension of the judgment; 4° propose a settlement; 5° issue warnings and reprimands; Decision on the merits 200/2025 - 31/33 6. to order that the data subject's requests to exercise their rights be complied with; 7. to order that the data subject be informed of the security problem; 8. to order that the processing be temporarily or permanently frozen, restricted, or prohibited; 9. to order that the processing be brought into compliance; 10. to order the rectification, restriction, or erasure of data and the notification thereof to the recipients of the data; 11. to order the withdrawal of the recognition of certification bodies; 12. to impose periodic penalty payments; 13. to impose administrative fines; 14. to order the suspension of cross-border data flows to another State or an international institution; 15° to transfer the file to the Public Prosecutor's Office in Brussels, who will inform it of the action taken on the file; 16° to decide, on a case-by-case basis, to publish its decisions on the website of the Data Protection Authority. 120. The Dispute Resolution Chamber wishes to recall that it is its sovereign responsibility as an independent administrative authority to determine, in compliance with the relevant articles of the GDPR and the Data Protection Act (WOG), the appropriate corrective measure(s) and sanction(s). 121. The Dispute Resolution Chamber ruled that Y1 (the first defendant) has violated Articles 6, paragraph 1 of the GDPR, 12, paragraphs 2 through 4 of the GDPR, and 15, paragraph 1 and 3 of the GDPR. The Litigation Chamber points out that a considerable amount of time has elapsed between the filing of the final conclusion in this case and the adoption of the present decision. The Litigation Chamber takes this passage of time into account when determining the appropriate measure in this case. Nevertheless, it is still appropriate – at least to prevent recurrence of infringements in the future – to establish the historical infringements and to point out to the defendant its responsibility in this regard. This responsibility has been sufficiently pointed out in this case by using the reprimand as a sanction. 122. The Litigation Chamber ruled that Y2 (the second defendant) has committed an infringement of Article 12, paragraph 3 of the GDPR. However, the Litigation Chamber notes that this infringement was unintentional and the result of a one-off human error. Therefore, the Litigation Chamber decides that it is sufficient to issue a reprimand for the aforementioned infringement. Decision on the merits 200/2025 - 33/33 42 in accordance with Article 1034quinquies of the Judicial Code, or via the e-Deposit information system of the Ministry of Justice (Article 32ter of the Judicial Code). (Government). Hielke HIJMANS Director of the Litigation Chamber 42 The application and its appendix, in as many copies as there are parties involved, shall be sent by registered mail to the clerk of the court or lodged with the court registry.




