APD/GBA (Belgium) - 200/2025

From GDPRhub
APD/GBA - 200/2025
Authority: APD/GBA (Belgium)
Jurisdiction: Belgium
Relevant Law: Article 6(1) GDPR
Article 12(2) GDPR
Article 12(3) GDPR
Article 12(4) GDPR
Article 15(1) GDPR
Article 15(3) GDPR
Type: Complaint
Outcome: Partly Upheld
Started:
Decided: 28.11.2025
Published:
Fine: n/a
Parties: n/a
National Case Number/Name: 200/2025
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Dutch
Original Source: APD (in NL)
Initial Contributor: dt

The DPA issued a reprimand to a company for unlawfully transmitting information on a former employee in a phone conversation with another company during a recruitment process. The DPA also reprimanded both companies for failing to respond to access requests.

English Summary

Facts

The data subject was an employee of controller (1) between 1 June 2015 and 14 November 2016.

In 2020, the data subject applied for a job at a non-profit organisation (controller 2). Controller 2 informed the data subject that the organisation was not moving forward with them as a candidate, mentioning a conversation with a manager of controller (2) about the data subject's managerial experience.

Following the access request submitted by the data subject on 8 July 2020, controller (1) provided general information regarding personal data processing within the company and did not attach a copy of the requested data. Instead, it asked for further explanations regarding the access request previously submitted.  

The data subject made an access request to controller (2) as well but did not receive a response within one month.

The data subject lodged a complaint with the DPA against controller (1) since they were unsatisfied with the response received among other things. They also lodged a complaint against controller (2) concerning, among other things, the failure to respond in a timely manner to their access request and unlawful processing of their personal data.

The DPA decided to join the complaints of the data subject against controller (1) and against controller (2).  

Holding

The DPA issued a reprimand to controller (1) for the infringements of Article 6(1) GDPR, Article 12(2)-(4) GDPR, Article 15(1) and (3) GDPR. The DPA also issued a reprimand to controller (2) for the infringement of Article 12(3) GDPR.

With regard to controller (1), first the DPA found that it violated Article 6(1) GDPR by processing personal data without a legal basis when providing controller (2) with information on the data subject without the data subject’s consent.

The DPA pointed out that the transfer of personal data during an oral phone conversation constitutes processing of personal data (Endemol Shine Finland). Furthermore, since controller (1) knew or should have known that controller (2) would include the information in the recruitment file, the DPA found that the verbal provision of information constituted processing of personal data. However, as controller (1) did not obtain the data subject's consent for such processing, it violated Article 6(1) GDPR.

Secondly, the DPA found that controller (1) violated Article 12(2) GDPR, Article 12(3) GDPR and Article 15(3) GDPR by failing to provide a full copy of the data requested by the data subject in their access request. Furthermore, controller (1) violated Article 12(4) GDPR by not providing the copy within one month and failing to inform the data subject of the reasons for the refusal.

Thirdly, the DPA found that controller (1) violated Article 15(1) by failing to provide complete information to the data subject's access request.   

With regard to controller (2), the DPA found that the controller violated Article 12(3) GDPR by not responding to the data subject within one month of receipt due to sending the information to the incorrect email address.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Dutch original. Please refer to the Dutch original for more details.

1/33

Dispute Resolution Chamber

Decision on the merits 200/2025 of 28 November 2025

File numbers: DOS-2021-01940 and DOS-2021-04314

Subject: Complaint about a request for access and the basis for processing in a

job application procedure

The Dispute Resolution Chamber of the Data Protection Authority;

Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016
on the protection of natural persons with regard to the processing of

personal data and on the free movement of such data, and repealing

Directive 95/46/EC (General Data Protection Regulation), hereinafter GDPR;

Having regard to the Act of 3 December 2017 establishing the Data Protection Authority,

hereinafter WOG;

In view of the internal rules of procedure, as approved by the House of Representatives on 20 December 2018 and published in the Belgian Official Gazette on

15 January 2019;

In view of the documents in the case;

Has taken the following decision regarding:

The complainant: X, hereinafter referred to as "the complainant"

The defendants: Y1, represented by Mr. Frederic Debusseré and Mr. Ruben Roex,
hereinafter referred to as "the first defendant"

Y2, represented by Mr. Yves Vandendriessche and Mr. Bram Baert,

hereinafter referred to as "the second defendant" Decision on the merits 200/2025 - 2/33

I. Facts and Procedure

1. The complainant was employed by the first

defendant, Y1 (hereinafter referred to as "Y1"), from 1 June 2005 to 14 November 2016. Upon his dismissal, the complainant and Y1 entered into a

settlement agreement, which stipulated, among other things, that Y1, her management, and her
appointees would refrain from making any public negative comments about the complainant,

including to future employers.

2. On July 6, 2020, Y1 received a registered letter in which the complainant alleged that Y1 had breached the
settlement agreement. The complainant referred to an email

dated July 2, 2020, which he had received from the second defendant, the non-profit organization Y2 (hereinafter "Y2"),

to which he applied on June 26, 2020. In the aforementioned email, a Y2 employee informed the

complainant that he would not be selected as a candidate in the selection procedure. This

includes a reference to contact with a manager at Y1: “After our

conversation last week, I checked your references with […] Y1. […]. Y1’s manager
indicated that there were doubts and that you also have no management experience. Based on this

information, we have decided to retain you from the further selection procedure.” The complainant

therefore believes that Y2 did not recruit him based on the information provided by Y1.

3. On July 8, 2020, Y1 received an email from the complainant stating that the transfer of his

personal data to Y2 in the context of the reference check constituted processing of

personal data for which Y1 should be considered the controller.

The complainant also requests Y1 to provide information about the processing of his personal data and to receive a copy of all personal data concerning him that it holds, referring

to Articles 15.1 and 15.3 of the GDPR respectively. Finally, the complainant explicitly requests the legal basis

as referred to in Article 6.1 of the GDPR on which Y1 relies for the processing of his

personal data.

4. On July 9, 2020, Y1 informed the complainant by email and telephone that a special

authorized representative had been appointed to consult with him.

5. On July 13, 2020, at the complainant's request, a meeting took place

between the authorized representative and the complainant outside Y1's offices, during which it was agreed that a new

settlement proposal would be drawn up by Y1. On July 29, 2020, Y1 provided the complainant with a draft

of an amended settlement agreement. In an email dated August 3, 2020,

the complainant confirmed that he had reviewed the draft and that he wished to consult on it.

Subsequently, the complainant and Y1 attempted to set a date.

6. Pending an agreement on the date for the planned consultation, Y1 complied with the complainant's request for access on August 7, 2020. However, Y1 provided Decision on the merits 200/2025 - 3/33

only general information regarding the processing of personal data

within the company. Y1 did not attach a copy of the personal data as referred to

in Article 15.3 GDPR, but requested the complainant to further explain his request for access

in order to better assess which personal data and which processing activities the request pertains to. In addition, Y1 proposed new

dates for further consultation on the draft of the settlement agreement.

7. Y1 states that a new consultation took place on August 26, 2020,
during which the complainant indicated that he did not agree with the settlement proposal,

reason why he would submit his own proposal to Y1. This assertion is not disputed by

the complainant.

8. On September 8, 2020, the complainant formally served notice of default on Y1 for failing to comply
with its obligations under Articles 6.1, 15.1, and 15.3 of the GDPR, as well as for

exceeding the deadlines set in Article 12, paragraphs 3 and 4 of the GDPR for

responding to his request for access and a request for a copy of his personal data. The

complainant again argues that Y1 shared his

personal data with third parties on July 2, 2020, and between July 8 and July 29, 2020, causing him

damage. The complainant clarifies that he expects an adequate response to the questions he posed in his initial request of July 8, 2020, and also requests a full copy of

all personal data concerning him held by Y1, including all

reports and recruitment documents it obtained at the time of his

recruitment, such as his CV and the assessment from the recruitment agency.

9. On September 28, 2020, Y1 responded to the formal notice by letter from its counsel,

in which it entirely denies the alleged non-compliance with the aforementioned GDPR articles.

It reiterates that it has the right to ask the complainant to further specify

its access request so that it can respond appropriately.

10. On October 22, 2020, the complainant, in a letter from his counsel, reiterated his allegations against

Y1 regarding the late and insufficient response to his access request of July 8, 2020.

He pointed out to Y1 that he did not need to specify his access request and reiterated his
wish to receive a copy of all data in Y1's possession.

11. On November 3, 2020, Y1 reiterated her positions in a letter from her counsel.

On January 26, 2021, the complainant reiterated his allegations and
requests in a letter from his counsel.

12. In the absence of further explanation regarding the access request, Y1 provided the complainant,

at his request, with the personal data "which [she] could reasonably suspect to relate to

them." Y1 assumes that by providing this information, it has fully complied with the obligations under Article 15.3 of the GDPR. According to Y1, the other obligations under Article 15 of the GDPR have already been met.

13. Since the complainant cannot accept the information and copy provided by Y1 and

believes them to be incomplete, he filed a complaint with the Data Protection Authority against Y1 (first defendant) on March 24, 2021, through his then-judge.

The complainant believes that Y1 does not have a valid basis for processing his

personal data, both during and after the employment contract ends,

in violation of Article 6.1 GDPR, and that Y1 has violated his right of access (Article 15 GDPR)

by providing him with incomplete information after the expiry of the period

provided for in Article 12.3 GDPR.

Furthermore, the complainant states that Y1 has violated his rights to rectification (Article 16 GDPR), to erasure

of his personal data (Article 17 GDPR), to restriction (Article 18 GDPR), and to objection (Article 21 GDPR).

Finally, the complainant alleges that Y1 has not complied with the principles of lawfulness,

property and transparency (Article 5.1.a) of the GDPR in conjunction with Articles 12.1 and 13 of the GDPR), purpose limitation

(Article 5.1.b) of the GDPR), data minimization (Article 5.1.c) of the GDPR), and accuracy (Article 5.1.d)

of the GDPR) with respect to his personal data.

14. On April 13, 2021, the complaint against Y1 was declared admissible by the First Line Service

pursuant to Articles 58 and 60 of the Dutch Data Protection Act (Wet op de Gemeenschapsregeling), and the complaint was referred to the Dispute Resolution Chamber pursuant to Article 62, § 1

of the Dutch Data Protection Act (Wet op de Gemeenschapsregeling).

15. On April 21, 2021, the Primary Care Service received a letter from the judges of Y1

in which they refute the allegations in the complaint and request that they mediate between the

parties. The judges of Y1 also emphasized their suspicion "that the

exercise of his rights under the GDPR is merely a way for the gentleman to improve his

negotiating position for a new settlement and to obtain

compensation for an (alleged) violation of

the aforementioned settlement."

16. On May 18, 2021, the complainant, through his then-counselor, also filed a complaint with the Data Protection Authority against Y2 (second

respondent) by registered mail.

The subject of the complaint concerns the failure to respond in a timely manner to a request for

access (Article 12 in conjunction with 15 GDPR), as well as the lack of a valid basis (Article 6

GDPR) for the collection of the complainant's personal data by Y1 in the context of a

job application procedure and the subsequent processing of this personal data. Decision on the merits 200/2025 - 5/33

The complainant also considers that Y2 violated his rights to rectification (Article 16 GDPR),

to erasure of his personal data (Article 17 GDPR), to restriction (Article 18 GDPR), and

to object (Article 21 GDPR).

Finally, the complainant argues that Y2 violated Article 14 of the GDPR by failing to provide him with sufficient

information about the source of the personal data concerning him, as

part of the response to his access request (pursuant to Article 15.1.g) of the GDPR). The complainant

believes that Y2 is obligated to provide the first and last name of the

person within Y1 who allegedly shared his personal data with them.

17. On June 4, 2021, the complaint against Y2 was declared admissible by the First Line Service

pursuant to Articles 58 and 60 of the Dutch Data Protection Act (Wet op de Gemeenschapsregeling), and the complaint was transferred to the Dispute Resolution Chamber pursuant to Article 62, § 1 of the Dutch Data Protection Act

(Wet op de Gemeenschapsregeling). 18. Following the two aforementioned complaints concerning the same facts,

two files were therefore submitted to the Dispute Resolution Chamber: DOS-2021-01940 and

DOS-2021-04314. On August 2, 2021, the Dispute Resolution Chamber, based on the

documents submitted, decided to join both complaints, given their interrelationship.

This decision ruled on both complaints. On August 2, 2021, the

Dispute Resolution Chamber also decided, pursuant to Article 95, § 1, 1° and Article 98 of the Dutch Civil Code (WOG), that the file

is ready for consideration on the merits.

19. On August 2, 2021, the parties concerned were notified by registered mail

of the provisions referred to in Article 95, § 2, as well as those in Article 98 of

the WOG. They were also informed, pursuant to Article 99 of the WOG,

of the deadlines

for submitting their defenses. The deadline for receipt of the defendants' statement

of reply was set at September 27, 2021, this

for the complainant's statement of reply on October 18, 2021, and this for the defendants' statement

of rejoinder on November 8, 2021.

20. On August 3, 2021, the parties confirmed receipt of the aforementioned

registered mail, as well as their agreement to further exchanges regarding the case

by electronic means.

21. On 27 September 2021, the Litigation Chamber received the statements of reply from

Y1 and Y2 respectively.

22. On 18 October 2021, the Litigation Chamber received the statement of reply from the complainant.

23. On 8 November 2021, the Litigation Chamber received the statements of rejoinder from Y1

and Y2 respectively.

24. The Litigation Chamber is aware that a considerable period has elapsed between the filing of the last

statement and the judgment in this case. It wishes to express its sincere apologies to the parties for this. Despite this delay, the

Dispute Chamber considers it appropriate to issue a reasoned decision in this case,

which will be published anonymously on its website. This is done not only

to ensure careful handling of the present complaint, but also

with the intention of contributing to a correct and uniform understanding of the applicable

obligations for the parties involved. This dispute offers a suitable

opportunity to further clarify the applicable rules regarding the processing of personal data

in the context of reference checks for job applications.

II. Reasoning

II.1. Scope of the dispute

25. As an introduction, the Dispute Resolution Chamber notes that this case falls within a broader dispute

between the complainant and Y1 (the first defendant) concerning the breach of a mutually

concluded settlement agreement as a result of the complainant's dismissal in November

2016. The jurisdiction of the Dispute Resolution Chamber in the present case is naturally limited

to questions regarding data protection. The Dispute Resolution Chamber will

rule on the allegedly unlawful processing of references concerning

the complainant by both defendants (Section II.2.), as well as on the alleged violation of

his right of access following requests submitted by the complainant to each

of the defendants (Section II.3.). Furthermore, the Litigation Chamber will assess

the possible violation of other rights under the GDPR by both

respondents (Section II.4.), as well as the alleged violation of the basic principles

regarding the processing of personal data by Y1 (Section II.5.).

II.2. The processing of personal data in the context of a job application procedure

II.2.1. The concept of “personal data” — Art. 4.1 GDPR

26. First, the Litigation Chamber must assess the extent to which the respondents

have processed personal data relating to the complainant.

27. Article 4.1 GDPR defines the concept of “personal data” as “any information relating

to an identified or identifiable natural person (“data subject”); An identifiable natural person is considered to be one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. This definition therefore includes four constitutive and cumulative elements: Decision on the merits 200/2025 - 7/33

a. “any information”

28. The Litigation Chamber points out that the term “personal data,” as explained in Article 4.1 of the GDPR in conjunction with Recital 26 of the GDPR, Opinion 4/2007 of the Working Party, as well as the case law of the Court of Justice, should be interpreted broadly and encompass both objective and subjective information, regardless of whether this information is correct or proven. The term “any information” used in Article 4.1) of the GDPR must therefore be interpreted literally,

regardless of the nature, content, or form of the information concerned.

Recital 26 of the GDPR, moreover, emphasizes this extensive interpretation of the term

“personal data,” by stating that “the principles of data protection must apply to

any information relating to an identified or identifiable person.”

29. This was also confirmed by the Data Protection Working Party in its Opinion 4/2007

on the concept of personal data, where it states the following in this regard: “With regard to the

nature of the information, ‘personal data’ includes all kinds of statements about a

person. It also includes ‘subjective’ information, opinions, and judgments. […] In order to be considered

‘personal data,’ it is not necessary for the information to be true or

proven.” 3

30. The Court of Justice of the

European Union has emphasized the foregoing on several occasions. In its judgment in Nowak of 20 December 2017, the Court stated in this regard

specifically: “The use of the words ‘any information’ in the definition of the

term ‘personal data’ […] indicates that the

EU legislature intended to give this term a broad meaning, which is not limited to

sensitive or personal information but potentially extends to any type of information,

both objective information and subjective information in the form of opinions or

assessments, provided that this information ‘concerns’ the data subject.”

31. More specifically, the Court of Justice ruled in Nowak that the evaluation and

comments of an examiner regarding an examination taken by the data subject

must be considered personal data within the meaning of current Article 4(1) of the GDPR.

The Court also pointed out that not classifying this data as

personal data would completely remove it from the protection

of the principles and guarantees regarding personal data, and more specifically

1A. OCQUET (D.), Ulim ANNEKENS ENSOFIEDEPRE, Handboek Gegevensbescherming in de diep en in de praktijk, LeA

Publishers 2024, Leuven, p. 1 OCKSEY and H. IJMAN, “The Court of Justice as a Key Player in Privacy and Data Protection:
An Overview of Recent Trends” in Case Law at the Start of a New Era of Data Protection Law, EDPLReview 2019, pp. 302-304.
2 Emphasis by the Litigation Chamber.

3 Article 29 Data Protection Group, Opinion 4/2007, 20 June 2007, p. 6 (emphasis by the Litigation Chamber).

4
CJEU, 20 December 2017, C-434/16, Nowak v. Data Protection Commissioner, ECLI:EU:C:2017:994, paragraph 34. Decision on the merits 200/2025 - 8/33

rights of access, rectification, and objection, as well as the supervision by the supervisory

authorities.

32. The Data Protection Working Party and the Court of Justice further clarified that this

information may relate to both the personal life of the data subject and
6
their professional or public activities: “‘Personal data’ includes information

relating to a person’s private or family life in the strict sense, but

also information about all kinds of activities a person undertakes, for example, about a person’s

professional relationships or economic or social behavior. It therefore concerns information about

persons, regardless of their position or capacity (consumer, patient,

employee, customer, etc.).”7

33. Based on the above elements, the Litigation Chamber may conclude

that the first constitutive element is present in this case.

b. “about”

34. A second constitutive element of the definition of “personal data” in

Article 4.1) GDPR is that the information must be “about” a natural person, the

data subject. In its Opinion 4/2007, the Data Protection Working Party points out that this

may be the case both directly and indirectly, insofar as the information “refers to the

identity, characteristics or behaviour of a person or if such information

is used to determine or influence the way in which that person is treated or assessed.”

35. The Data Protection Working Party specifies in this regard that information that does not directly

relate to a natural person may still be considered “information about” the

natural person in the following two cases:

a. When the data are used or are likely to be used

for the purpose of assessing, treating or influencing the data subject’s status or behaviour; or

b. When the use of the data is likely to have an impact

on certain individuals, regardless of whether this impact is significant or minor.

5 CJEU, 20 December 2017, C-434/16, Nowak v. Data Protection Commissioner, ECLI:EU:C:2017:994, para. 49.
6
ECtHR, 16 February 2000, no. 27798.
7Article 29 Data Protection Working Party, Opinion 4/2007, 20 June 2007, p. 7. See, in the same vein, the Opinion of Advocate General E. Sharpston of 12 December 2013 in joined cases C-141/12 and C-372/12 (Y.S.), para. 45.

8Article 29 Data Protection Working Party, Opinion 4/2007, 20 June 2007, p. 10. Decision on the merits 200/2025 - 9/33

36. The Data Protection Working Party points out that, as long as there is a possibility that

the data subject will be treated differently, for example, as a result of the processing
of the data in question, there is an impact on the person.9

37. This was also confirmed by the Court of Justice, which stated in this regard that this

second condition “is met when the information, by reason of its content, purpose or effect,

is linked to a specific person.”10

38. In the present case, the Litigation Chamber finds that the information in question — i.e., references

regarding the relevant experience and qualifications of the complainant — can undeniably be traced

back to the complainant and may have an impact on him, with the result that the second

constitutive element is present.

c. “an identified or identifiable” “natural person”

39. A person is “identified” when that person is individually distinguished from

other persons within a given group, by means of one or more

identifiers.1

40. Given that the exchange of references about an individual candidate

necessarily entails that the data subject is at least indirectly

identifiable to the former and future employer, the

Litigation Chamber finds that the data subject has been irrefutably identified and that the information exchanged by

the respondents in this case thus relates to an

“identified or identifiable person” within the meaning of Article 4.1) GDPR.

41. It must therefore be concluded that the third and fourth constitutive elements

of the concept of personal data are also present in this case. The Litigation Chamber therefore rules

that the references concerning the complainant's relevant experience and qualifications

must indeed be considered personal data concerning him.

II.2.2. The concept of "processing" – Art. 4.2 GDPR

42. In accordance with Article 2.1 in conjunction with recital 15 of the GDPR, it applies to the
wholly or partly automated processing of personal data,

as well as to the non-automated processing of personal data which are contained in a

filing system or are intended to be contained in a filing system.

9 Data Protection Working Party Article 29, Opinion 4/2007, 20 June 2007, pp. 11-12.
10
CJEU, 20 December 2017, C-434/16, Nowak v. Data Protection Commissioner, ECLI:EU:C:2017:994, paragraph 1. 35 (own
emphasis).
1 Data Protection Working Party Article 29, Opinion 4/2007, 20 June 2007, p. 13. Decision on the merits 200/2025 - 10/33

According to Article 4.2) GDPR, "processing" of personal data shall mean:

"any operation or set of operations which is performed upon

personal data or on sets of personal data, whether or not by

automatic means, such as collection, recording, organization, structuring,

storing, adaptation or alteration, retrieval, consultation, use, disclosure by

transmission, dissemination or otherwise making available, alignment or

combination, restriction, erasure or destruction."

43. In the present case, both defendants argue that the disputed telephone conversation took place purely

orally, was not recorded or otherwise registered, nor
was its content processed in any way. Consequently, the defendants argue that there can be no question of

processing within the meaning of the GDPR. The complainant, on the other hand, believes that

the GDPR does apply, since, according to him, there has indeed been

processing of personal data. On July 2, 2020, Y2 received personal data

from the complainant via Y1, which Y2 subsequently processed in an email to the complainant, which

is a file.

44. The Litigation Chamber points out that the transfer of personal data during a

oral telephone conversation does indeed constitute “processing” of personal data

within the meaning of Article 4.2) GDPR. That article clearly stipulates that the “disclosure

by transmission, dissemination or otherwise making available” of

personal data constitutes “processing” within the meaning of the GDPR. The Litigation Chamber

also refers to the Endemol Shine Finland judgment, in which the Court of Justice

unambiguously established that the term “processing” within the meaning of Article 4.2)

of the GDPR necessarily encompasses the oral disclosure of personal data. 13

45. Since oral disclosure as such constitutes non-automated

processing, the Litigation Chamber must, in the present case, examine whether the data provided by Y1

are “included” in a “filing” or “intended to be included” in

a filing system. According to Article 4.6 of the GDPR, the term “filing system” should be

interpreted as “any structured set of personal data accessible according to specific

criteria, regardless of whether it is wholly centralized, decentralized, or

dispersed on a functional or geographical basis.” The Litigation Chamber points out

that this provision provides a broad definition of the term “filing system.” Moreover,

the requirement that the set of personal data must be “structured

according to specific criteria” is intended solely to ensure that the personal data

can be easily retrieved. In addition to this requirement, Article 4.6 of the GDPR contains

1 Emphasis by the Litigation Chamber
1 CJEU, 7 March 2024, C-740/22, Endemol Shine Finland, ECLI:EU:C:2024:216, para. 32 Decision on the merits 200/2025 - 11/33

no provision regarding the manner in which a file must be structured, and

the form such a file must have.14

46. In the present case, Y1 argues that it did not consult any file, such as the complainant's personnel file,

in order to provide the information contained therein to Y2. The
Litigation Chamber notes that it is not required to verify whether or not Y1 consulted a file

containing the complainant's personal data. The

Litigation Chamber finds that Y1 knew, or should have known, that the information she

provided about the complainant would be included in a file by

Y2, namely in the recruitment file that the latter maintains on the complainant. Given

these circumstances, the Dispute Resolution Chamber finds that Y1's verbal provision of information about the complainant to Y2

constitutes processing of personal data that

falls within the material scope of the GDPR.

47. The Dispute Resolution Chamber also considers it sufficiently proven that Y2 processed the complainant's personal data in the context of the application procedure within the meaning of Article 4.2)

of the GDPR, and furthermore that this personal data was included in a file. The

Dispute Resolution Chamber finds that Y2 recorded the content of the interview, although not

verbatim, at least in general terms, in writing in an email to

the complainant.

48. Consequently, the Dispute Resolution Chamber will have to address

the lawfulness of the processing by both respondents in a subsequent section (II.2.3).

II.2.3. Lawfulness of the processing — Art. 6.1 GDPR

49. Now that it has been established that both respondents have processed personal data about the complainant

within the meaning of the GDPR, the Dispute Resolution Chamber must address the

lawfulness of this processing. To ensure logical reasoning, the Board will

first assess the lawfulness of the collection and further processing of

references by Y2 (the second defendant). It will then examine the lawfulness

of the transfer of the complainant's personal data by Y1 (the first

defendant).

a. The lawfulness of the collection and further processing of
references by Y2 (the second defendant)

50. The Dispute Resolution Chamber finds that Y2 relies on the complainant's consent for

the collection and further processing of references. To this end, Y2 submits the minutes of the job interview she

prepared, which must demonstrate that the complainant has

1See also ECJ, 7 March 2024, C-740/22, Endemol Shine Finland, ECLI:EU:C:2024:216, paragraph 37; ECJ, 10 July 2018, C-25/17,
Jehovan todistajat, ECLI:EU:C:2018:551, paragraphs 57-58, Decision on the merits 200/2025 - 12/33

given consent to contact Y1. 15 Furthermore, Y2 argues that,

given that the complainant voluntarily mentioned Y1 in his CV, this can be considered

valid consent.

51. The Litigation Chamber recalls that Articles 4.11 and 7 of the GDPR, read together with

Recital 43 of the GDPR, indicate that in the context of a job application procedure, the data subject's consent

can only serve as a legitimate legal basis for the collection and further processing of references in exceptional cases. It is, in particular,

established that the relationship between a potential employer and an applicant is

characterized by the latter's dependent position, which leads to a

presumed imbalance within which consent cannot, in principle, be freely given.

52. The Litigation Chamber, on the other hand, accepts that consent can be used as a legal basis

if the controller has obtained the data subject's consent

by signing a declaration, the scope of which they could

clearly understand and which contains at least the following elements:

a. The identity of the organization or persons the prospective employer intends

to consult

b. The nature of the data requested

c. The reasons for collecting the data

d. The period during which the consent will be used

The Dispute Resolution Chamber emphasizes that such consent is only considered freely given

if the data subject does not risk any negative consequences if they do not give their consent.

In the context of a job application procedure, this means, for example,

that the potential employer may under no circumstances lead the applicant to expect that their application will be assessed unfavorably or will not be considered

if they do not consent to requesting references.

53. The Dispute Resolution Chamber also accepts that consent can be used as a valid legal basis

if the applicant spontaneously, without being asked by the potential

employer, explicitly indicates a reference person in their CV with the intention of contacting them.

The Dispute Resolution Chamber emphasizes that, also in this case, the

controller must comply with its information obligations under Article 14 GDPR.

15 Document 4 to the second defendant's statement of defense, dated 27 September 2021
16 EDPB, Guidelines 05/2020 on consent under Regulation 2016/679, version 1.1, 4 May 2020, pp. 8-10 Decision on the merits 200/2025 - 13/33

54. In view of the above and the parties' defenses, the

Litigation Chamber finds that Y2 has not demonstrated that the complainant's oral consent,

given during the job interview, meets the requirement under the GDPR of

free expression of will. Indeed, the minutes of a job interview cannot serve as valid consent in the absence

of a signature by the data subject, for

the simple reason that the minutes were not taken by the data subject. Finally, the

submitted documents also do not show that the complainant listed Y1 as a reference person

in his CV, which could, if necessary, serve as valid consent.

Y1 was only mentioned by the complainant in the section

"work experience," but is nowhere explicitly mentioned as a reference.

55. In view of the above, the Dispute Resolution Chamber finds that Y2 could not lawfully

rely on the complainant's consent pursuant to Article 6.1. a) GDPR for the

consultation and subsequent processing of references.

56. The Dispute Resolution Chamber finds that Y2 also relies

on its legitimate interest pursuant to Article 6.1. f) GDPR for the processing at issue. The Dispute Resolution Chamber has already pointed out in

its previous decisions that the controller

must designate a single legal basis for processing

the processing on the basis of which it wishes to carry out the processing of personal data. The different

grounds for lawfulness have different consequences, particularly with regard

to the rights of data subjects. For the aforementioned reason,

a controller is not permitted, depending on the circumstances, to rely on

one legal ground, then another, for the same processing.

57. However, since Y2 could not lawfully rely

on the complainant's consent for the collection of his references, the Litigation Chamber will now examine whether it could process the complainant's personal data based on its

legitimate interest.

58. The Court of Justice has clarified in its case law that three

cumulative conditions must be met for a controller to lawfully

rely on Article 6.1.f) GDPR. More specifically, the controller must demonstrate that:

a) the interests pursued by the processing can be considered legitimate (the "purpose test");

17 Decision on the merits 55/2021 of 22 April 2021 of the Dispute Resolution Chamber,
https://www.gegevensbeschermingsautoriteit.be/publications/besluit-ten-gronde-nr.-55-2021.pdf; Decision on the merits
138/2021 dated December 8, 2021 of the Disputes Chamber, https://dataprotectionauthority.be/publications/beslissing-
substantive-no.-138-2021.pdf
18
  CJEU, 4 May 2017, C-13/16, Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde v Rīgas pašvaldības SIA
“Rīgas satiksme”, ECLI:EU:C:2017:336, edge no. 28 (“Rīgas Judgment”).                                                                    Decision on the merits 200/2025 - 14/33

b) the intended processing is necessary for the realization of these interests (the

“necessity test”); and

c) the balancing of these interests against the interests, fundamental freedoms

and fundamental rights of the data subject outweighs the controller's interests (the “balancing test”).

59. With regard to the first condition, the so-called “purpose test,” the Litigation Chamber of

is of the opinion that checking references following a job interview

must indeed be considered to be carried out for a legitimate

interest. Employers have every interest in recruiting reliable and qualified

employees. The Litigation Chamber considers that consulting employers

who have previously worked with the complainant can provide a reliable and balanced picture

of their performance in a professional context. The Litigation Chamber thus

finds that the purpose test has been met.

60. In order to meet the second condition, the "necessity test," Y2 must demonstrate that the processing in this case was necessary to pursue the aforementioned legitimate interest.

The Litigation Chamber points out that when assessing whether processing is "necessary," the controller must examine whether the legitimate interest pursued cannot be achieved equally effectively by alternative means that are less intrusive on the fundamental rights and freedoms of the data subject. If reasonable and equally effective, but less intrusive alternatives exist, the processing cannot be considered "necessary."
19


Y2 argues that, although it had access to the complainant's resume, cover letter, and

information from the interview, it was necessary for it

to verify the complainant's assertions regarding his experience and leadership.

Y2 considers consulting references a necessary process to obtain a

overall picture of the complainant and to determine how he actually behaves in a

work environment, which could not be inferred from the complainant's statements, according to Y2,

one-sided in the aforementioned sources.

The Dispute Resolution Chamber is of the opinion that verifying references is a common and reasonable

means for employers to gain insight into an applicant's professional skills, provided that it cannot

request the collected information from the complainant himself. In view of this, the Litigation Chamber considers it necessary in this case for Y2

to gather work-related information relevant to assessing his suitability for the

position for which he applied, especially since Y2 had doubts about the veracity of the complainant's

claims, through consultation with the complainant's former employers. The Dispute Resolution Chamber points out that the information in question

may not have been objectively obtained from the complainant himself. Since the complainant, as an applicant, has a clear interest in a positive presentation of the facts,

the necessary independence and verification are lacking if Y2

has to make a decision solely based on his statements. In the present case,

the Dispute Resolution Chamber therefore considers Y2's consultation of references a necessary

processing of personal data in light of the legitimate interest pursued,

and thus concludes that the necessity test was also met.

61. In order to determine whether the third condition, the so-called "balancing test," is

met, it must be assessed whether Y2's legitimate interest outweighs

the fundamental rights and freedoms of the complainant. In accordance with Recital 47
of the GDPR, this balancing test must also take into account the complainant's reasonable

expectations. More specifically, it must be assessed whether "the data subject, at the time and in the context of the collection of the personal data,

can reasonably expect that the processing can take place for that purpose."

In this regard, the Dispute Resolution Chamber reiterates that Y2's interest, as a potential employer,

in conducting a careful selection process is legitimate, and that verifying references

in the present case constituted a proportionate and necessary means of assessing the complainant's

reliability and suitability. This interest is balanced by

the fundamental rights and freedoms of the complainant, whose personal data was processed following

a telephone conversation. The Dispute Resolution Chamber finds that the processing

was limited to relevant, job-related information and took place in a

context in which the data subject's reasonable expectations were not exceeded. The

Dispute Resolution Chamber finds that it falls within the complainant's reasonable expectation that Y2 would contact former employers, mentioned in his CV and explicitly

mentioned during the job interview, to

obtain or verify information. In light of this reasonable expectation, and considering

the manner in which the processing took place, the Dispute Resolution Chamber finds that

Y2's interest in this case outweighs the complainant's rights and freedoms.

62. The Dispute Resolution Chamber concludes that Y2 could legitimately rely on Article 6.1. f) GDPR

for the processing of personal data during the consultation of references for

the purpose of a job application procedure. The Litigation Chamber emphasizes that a

controller who relies on Article 6.1 f) GDPR in this context must inform the substantive decision 200/2025 - 16/33

of the data subject's

right to object, as stipulated in Article 21.4 GDPR, before requesting references.

b. Lawfulness of the transfer of the complainant's personal data

by the first respondent (Y1).

63. As explained, the Litigation Chamber has determined that the oral provision of

information from the complainant by Y1 to Y2 constitutes processing of personal data

for which Y1 must be considered the controller. Therefore,

Y1 had to have a legitimate legal basis for this processing. Since Y1 argues that

the aforementioned processing did not require a legal basis, the Dispute Resolution Chamber finds that

Y1 has violated Article 6.1 of the GDPR.

64. For the sake of completeness, the Dispute Resolution Chamber points out that the transfer of information

about a former employee to a potential employer in the context of a

reference check is generally only possible based on the consent of the

data subject. If the information provider can verify that the potential employer

is requesting the information based on the prior, free and informed consent

of the data subject, they do not need to request additional consent themselves. If

such consent is lacking, for example because the potential employer is acting on the basis of

legitimate interest, the information provider must obtain separate

consent from the data subject before disclosing their personal data.

II.3. Regarding the complainant's exercise of the right of access

65. In both complaints, the complainant believes that the respective respondent failed to respond promptly and
adequately to a request for access to his personal data. The

Dispute Resolution Chamber will therefore examine in the following sections, on the one hand, whether the respondents

responded to the complainant's request for access in a timely manner (II.3.1), and, on the other hand, whether the information provided by the

respondents is substantively in line with the obligations arising

from the GDPR (II.3.2).

II.3.1. Processing time for requests — Article 12 GDPR

66. The documents in the file show that the complainant's request for access was submitted

to Y1 (the first respondent) on July 8, 2020. On August 7, 2020,

Y1 complied with the request, providing only general information regarding
the processing of personal data within the company.

In addition, Y1 informed the complainant that, if he wishes to receive additional information, he must

include a description of the nature and context of his request, so that a Decision on the merits 200/2025 - 17/33

can better assess which personal data and processing activities the

access request relates to.

67. On September 8, 2020, the complainant formally served notice of default on Y1 for, among other things,

exceeding the deadlines set out in Article 12, paragraphs 3 and 4 of the GDPR for

answering his request for access to data and a request for a copy of his personal data. On

September 28, 2020, Y1 responded to the notice of default by letter from her legal counsel,

in which she stated, among other things, that, in accordance with Article 12.3 of the GDPR, she had informed the complainant within

one month about "what action" had been taken on his request for access to data.

Y1 pointed out to the complainant that this provision did not imply that she was also required to fully execute the request for access

within one month. On October 22, 2020, the complainant

denied this interpretation by letter from her legal counsel. He argues that, since no adequate response was provided to his access request within one

month, and Y1 failed to inform the complainant within one month of receipt of the request

of a possible extension of that period, an infringement of Article 12, paragraphs 3

and 4 of the GDPR has occurred.

68. The Litigation Chamber recalls that Article 12.3 of the GDPR requires the

controller to inform the data subject without delay and in any event within one month

of receipt of a request pursuant to Article 15 GDPR of the action

taken in response to the request. This period may be extended by a maximum of two months

taking into account the complexity and number of requests, provided

that the controller informs the data subject within one month of receipt of the request

of the reasons for the delay. This

information obligation regarding the extension of the period and the justification

for it should not be confused with the separate obligation, pursuant to

Article 12.4 GDPR, to inform the data subject without undue delay and at the latest within one

month if the controller decides not to comply with the request, and of the reasons for that decision.

69. Based on Y1's defenses, the Dispute Resolution Chamber finds that it partially refused to comply with the request for access pursuant to

Article 15.4 of the GDPR,

as further explained in paragraph 99 of this decision. This means that it should have informed the complainant

of this without delay and no later than within one month,

in accordance with Article 12.4 of the GDPR, as well as of the reasons for the refusal. The Dispute Resolution Chamber finds

that Y1 failed to do so, and thus finds that it violated

Article 12.4 of the GDPR.

70. The Litigation Chamber also points out that the receipt of the access request by the

controller generally constitutes the starting point for the one-month period

within which, in accordance with Article 12.3 GDPR, information must be provided. Decision on the merits 200/2025 - 18/33

20
on the action taken on the request. The Litigation Chamber specifies that this,
as a rule, means that the information listed in Article 15, paragraphs 1 and 2 GDPR, as well as the

copy of the personal data referred to in Article 15.3 GDPR, must be provided to the data subject without undue delay

and in full within one month at the latest. Contrary to what Y1 repeatedly argues, the Dispute Resolution Chamber emphasizes that a mere response within one month—for example, by simply stating that the request will be processed—is clearly not sufficient to comply with the obligations arising from Article 12.3 of the GDPR in conjunction with Article 15 of the GDPR.

71. In the present case, the Dispute Resolution Chamber notes that Y1 substantively responded to the complainant's access request on August 7, 2020, in accordance with the deadline stipulated in Article 12.3 of the GDPR. However, with regard to the copy of personal data, Y1, in line with the possibility provided for in Recital 63 of the GDPR, requested the complainant to further specify his access request.

72. The Litigation Chamber recalls that recital 63 of the GDPR states in fine that “where the controller processes a large amount of data relating to the data subject, […] the controller must be able, prior to providing the information, to request the data subject to specify which information or processing activities the request relates to.” The Litigation Chamber points out that

this recital must be read in conjunction with Article 12.2 of the GDPR, which stipulates

that the controller is obliged to facilitate the exercise of the data subject’s rights. It follows that the controller may request

specification if the access request is formulated in very general terms,

presenting the controller with the challenge of providing a comprehensive response,

while at the same time avoiding the provision of a plethora of

information that is irrelevant to the data subject and which they cannot

process effectively. In view of this, and in line with Guidelines 01/2022 of the European Data Protection

Board, the Litigation Chamber points out that in such a case, the start of the period referred to in Article 12.3

of the GDPR is suspended until the data subject provides the requested

clarification. In that case, the controller may await the data subject's response

before providing additional information

according to their request.22 The same applies, for example, when the

20EDPB, Guidelines 01/2022 on data subject rights – Right of access – version 2.1, 28 March 2023, para. 57

2Ibid., para. 35
22Ibid., para. 159 Decision on the merits 200/2025 - 19/33

controller contacts the data subject due to

uncertainty about their identity. 73. It is important to emphasize that the request for specification may not be used

to limit the scope of the response to the access request, nor to

withhold information about the processing or personal data of the data subject.

If the data subject, after being asked to specify their request in more detail, confirms that

they wish to receive all personal data relating to them,
24
the controller must, of course, provide this information in full.

74. In the present case, the Dispute Resolution Chamber notes that the complainant, in his notice of default dated 8

September 2020, unambiguously clarified for the first time what his access request

relates to. The complainant specifies that he expects a satisfactory answer to

the questions he posed in his original request of July 8, 2020, and also requests

a complete copy of all personal data concerning him that Y1 holds

in its possession, including all reports and recruitment documents it

obtained at the time of his recruitment, such as his resume and

the recruitment agency's assessment. In a letter from his legal counsel dated October 22, 2020, the complainant also clarifies that he wants a copy of all data that Y1

processes about him and is still in its possession. Finally, in a letter from his legal counsel dated January 26, 2021, the complainant again clarifies that he wants a copy of every file

(document, text, internal report, email, photo, video recording, etc.) that Y1 processes and

on which he is identifiable.

75. Therefore, the Dispute Resolution Chamber concludes that Y1 first received the requested clarification from the complainant on September 8, 2020. The

Dispute Resolution Chamber therefore finds that Y1's assertion in its letter of November 3,

2020 – namely, that the complainant refused to specify his request and that this was the only

reason why he had not yet received a copy of his personal data –

is unfounded. Since the complainant already clarified on September 8, 2020, that he wanted a complete

copy of all personal data concerning him, Y1 should have complied by October 8,

2020. However, the Dispute Resolution Chamber notes that Y1 only provided the complainant with a copy of the data "which [she] could reasonably

assume related to his request" on February 18, 2021.

76. In view of the above, the Litigation Chamber concludes that it has been demonstrated that Y1

infringed Article 12, paragraphs 2 and 3, of the GDPR.

23 Article 11.2 GDPR in conjunction with Article 12.6 GDPR
24
EDPB, Guidelines 01/2022 on data subject rights – Right of access – version 2.1, 28 March 2023, paragraph 35
25 Underlining by the Litigation Chamber Decision on the merits 200/2025 - 20/33

77. The access request addressed to Y2 (the second defendant) is also dated 8 July

2020. The Litigation Chamber notes that Y2 attempted to respond to this

request on 27 July 2020, but that its response did not reach the complainant on that date. Y2

declares that, due to a material error, her response was

sent to an incorrect email address that is almost identical to the complainant's.

Y2 states that she assumed her response had been delivered successfully since

she did not receive an error message. She therefore believed she had complied with the complainant's access request.

78. It was only through the formal notice of default of September 8, 2020, that Y2 was informed

that her email had not reached the complainant. In response, Y2 sent a new email to the complainant on September 10,
2020, this time to the correct email address, in which she provided the complainant with the data listed in

Article 15.1 GDPR. On September 16, 2020,

Y2 sent an email to the complainant explaining that its initial response had not reached him

because it was mistakenly sent to the wrong, though existing, email

address. Y2 also stated that it had notified the Data Protection Authority

of the data breach, receiving confirmation of receipt

on September 14, 2020.

79. Y2 argues that, although the data was forwarded to an incorrect email address,

it did respond to the complainant's request in a timely manner, so a violation of

Article 12.3 GDPR cannot be established.

80. The Dispute Resolution Chamber reiterates that Article 12.3 GDPR obliges the

controller to provide information on the action taken on the request without delay and in any event within one month

of receipt of the request. The Dispute Resolution Chamber points out that this provision logically implies

the actual delivery of that information to the data subject. Therefore, simply

sending a response to an incorrect email address, without it actually reaching the data subject,

cannot be considered a timely response.

81. In view of the above, the Dispute Resolution Chamber concludes that Y2 violated

Article 12.3 GDPR.

II.3.2. Handling of the access requests — Article 15 GDPR

82. The complainant argues that Y1 (the first respondent) has inadequately responded to his access request.

Since the Dispute Resolution Chamber has already established that Y1 has responded late,
26
it will, in the remainder of its assessment, address only the question of

whether Y1 has fulfilled its substantive obligations under Article 15, paragraphs 1 and 3,

26
See paragraphs 66 through 76 of this decision. Decision on the merits 200/2025 - 21/33

GDPR – regardless of whether this compliance occurred within or outside the one-month period.

a) In fact

83. In his request of July 8, 2020, the complainant informs Y1 that she allegedly shared personal data concerning him

with Y2. He also points out that he worked for Y1 from June 2005 to

November 2016, initially through a recruitment agency and later as a direct employee. The complainant then requests all the information

listed in Article 15.1 of the GDPR and expresses his wish to obtain a copy of all

data in Y1's possession in accordance with Article 15.3 of the GDPR. Finally, he requests

Y1 to state the legal basis, as referred to in Article 6.1 of the GDPR, for the processing

of his personal data and, insofar as this processing is based on consent,

to provide him with a copy of that consent.

84. In its response of 7 August 2020 to the complainant's access request, Y1 only provided

general information about the processing of personal data within the

company. In view of Y1's defences, the Dispute Resolution Chamber finds that Y1

only provided the information contained in its privacy statement, which

applies to active employees. As an illustration, the Dispute Resolution Chamber refers to the

example in which Y1, with regard to the processing purposes, states, among other things, that

the complainant's personal data would be processed "for the performance and follow-up

of the employment contract and the proper management of the personnel file." Also,

with regard to the processing grounds (Article 6.1 GDPR), the categories of personal data concerned

(Article 15.1 b GDPR), and the recipients of personal data (Article 15.1 c GDPR), Y1 refers to the general information contained in its privacy statement,

which applies to its active employees.

Finally, Y1 requests the complainant to include a description of the nature and context of the

request, so that it can better assess which

personal data and processing activities the request relates to.

85. In its response of 28 September 2020 to the complainant's notice of default, Y1 adds

that it also processes the complainant's personal data based on Article 6.1 f) GDPR,
specifically based on its legitimate interest in safeguarding its

evidence in the context of ongoing disputes. In its response of 18 February 2021,

Y1 adds, in accordance with Article 15.1 d) GDPR, that it will continue to process (store) the

complainant's personal data for as long as necessary for the purposes of evidence

in the context of ongoing disputes. Decision on the merits 200/2025 - 22/33

86. In the same response of 18 February 2021, Y1 points out that, with regard to the information

regarding the rights mentioned in Articles 15.1(e) GDPR and 15.1(f) GDPR, it did not provide this information to the complainant in its initial

response, as it was clear that the complainant already

was aware of these rights, as he quoted them verbatim in his access request of 8

July 2020. Regarding the information in Articles 15.1(g) GDPR and 15.1(h) GDPR, Y1 explains that

it could not provide any information on this matter, as these provisions are not applicable in this case. In the event

of a lack of clarification from the complainant regarding the scope of their

access request, Y1 also includes a copy of the complainant's personal data

“which [it] may reasonably assume are the subject of the

access request.”

87. By providing this information, Y1 indicates to the complainant that it has

fully complied with its obligations under Article 15, paragraphs 1 and 3 of the GDPR.

b) Position of Y1 (the first defendant)

88. In its defense, Y1 argues that the essence of the complaint filed against it can be

reduced to various alleged violations of the GDPR that it allegedly committed

when transferring personal data to Y2 in the context of a job application procedure.

According to Y1, this is the reason why the complainant submitted its access request to her, and it

also understood the complainant's request in this context. As further explained in section

II.2.2 of this decision, Y1 argues that the mere transmission of personal data by telephone does not constitute processing to which the GDPR applies. According to Y1, it was therefore impossible to comply with the complainant's request,

since the personal data he was seeking did not exist and the alleged

processing had never taken place. For this reason, in its letter of 7 August

2020, Y1 provided general information about the processing of personal data that

typically relates to an employment relationship and as described in its
27
privacy statement applicable to its employees.

89. Since the processing to which the complainant referred did not exist, and the request

was therefore unclear, according to Y1, it invited the complainant to provide additional information

about the nature and context of his request, in accordance with

recital 63 in fine of the GDPR. According to Y1, this request for clarification was also

justified, as the complainant had worked for her for 11 years, meaning that

she inevitably processes a substantial amount of personal data, despite the
28
fact that she also deleted a significant amount of the complainant's personal data, such as his mailbox.

27Y1, rejoinder of 8 November 2021, pp. 7-9
28Y1, rejoinder of 8 November 2021, pp. 9-11 Decision on the merits 200/2025 - 23/33

90. Y1 argues that, despite her repeated insistence, the complainant refused any clarification regarding his access request in subsequent
communications. According to Y1,

the complainant persistently requested information about an alleged, but non-existent,

processing, and a copy of personal data that she had not processed,

namely the verbal transfer of personal data during the telephone conversation with

Y2.29

91. Nevertheless, Y1 believes that, as the controller, it is obliged,

to the extent possible and reasonable, to comply with

the complainant's request. For this reason, in a letter dated 3 November 2020, it proposed

providing the complainant with a copy of the personal data she still holds in her

archived personnel file, as well as the email communications

regarding the complainant made in connection with this case. However,

Y1 makes the reservation that it will not provide emails already in the complainant's possession.

Y1 argues that, although the complainant agreed to this

proposal in his letter of January 26, 2021, he expanded his request for access at that time by also

requesting a copy of every file (document, text, internal report, email, photo,
video recording, etc.) that Y1 processes and on which he is identifiable.

Y1 argues that it fully and completely complied with this

request on February 18, 2021. However, it limited the provision of a copy of the personal data

by invoking Articles 12.5 and 15.4 of the GDPR in conjunction with recital 63

of the GDPR. First, Y1 argues that it is not required to provide a copy of the emails that the

complainant himself sent to it in the context of the present case, given that the complainant

logically already has full possession of these personal data. According to Y1, this would

completely miss the purpose of the right of access: the complainant is already aware

that Y1 processes the emails he sent and for what purpose.

Secondly, Y1 argues that it did not provide a copy of the internal communications and

communications with its lawyers relating to the dispute with the complainant,

as this would compromise its rights of defense. Finally, Y1 argues that it

is also permitted to withhold internal reports and emails relating to

company figures and affairs, which should therefore be considered business secrets,

from the complainant. According to Y1, it thus had the right, pursuant to

Articles 15.4 GDPR and 12.5 GDPR, to exclude the aforementioned information from the copy provided

to the complainant.

29 Ibid., p. 14-16
30 Ibid., 17-22 Decision on the merits 200/2025 - 24/33

c) Judgment of the Litigation Chamber

92. First, the Litigation Chamber emphasizes the importance of the possibility for data subjects to

exercise the right of access. The general purpose of this right

is to provide data subjects with sufficient, transparent, and easily accessible

information about the processing of their personal data. This

enables data subjects to inform themselves about the existence and nature of the processing, and

offers them the opportunity to assess the lawfulness and accuracy of the processed

data. Furthermore, the Dispute Resolution Chamber emphasizes that the exercise of

the right of access functions as an essential, but not a necessary, condition

for the effective exercise of other rights granted to data subjects by the GDPR,
31
such as the right to rectification and the right to erasure.

93. In addition, the Dispute Resolution Chamber points out that data subjects are under no circumstances obliged to

substantiate or justify their access request. As long as the requirements of Article

15 of the GDPR are met, the purposes behind the request must be considered irrelevant.

The Dispute Resolution Chamber therefore points out in this case that the bias on the part of

Y1 regarding the scope of the access request – namely, that it would only

relate to the oral transfer of personal data to Y2 – cannot

justify an incomplete or general response to the access request. The Dispute Resolution Chamber rules that, although the complainant's initial

access request indeed refers to the transfer of personal data to Y2, Y1

is not free to unilaterally limit the scope of the request to that specific

processing. The Dispute Resolution Chamber notes that the complainant also describes his request in

general terms, for example, by stating that he wants clear information

about "all provisions under Article 15, paragraph 1 of the GDPR," as well as by stating that he wants "a copy

of all data in your possession" as guaranteed in Article 15.3 of the GDPR. For this reason,

the Dispute Resolution Chamber finds Y1's argument, namely that it considered the complainant's
access request limited to the transfer of personal data to Y2,

unconvincing.

94. As previously mentioned, the Litigation Chamber finds that, with regard to the

processing purposes, the categories of personal data processed, and the

(categories of) recipients to whom these data have been or will be provided,

Y1 refers exclusively to information characteristic of an employment relationship, as

described in the privacy statement applicable to its employees. The

31
CJEU, 7 May 2009, C-553/07, Municipal Executive of Rotterdam v. M.E.E. Rijkeboer,
ECLI:EU:C:2008:773, paragraphs 49 and 51; CJEU, 17 July 2014, joined cases C-141/12 and C-372/12, YS et al. v. Minister for
Immigration, Integration and Asylum, ECLI:EU:C:2014:2081, paragraph 44
32 CJEU, 26 October 2023, C-307/22, FT (Copies of the medical file), ECLI:EU:C:2023:811, paragraph 38 Decision on the merits 200/2025 - 25/33

The Litigation Chamber notes in this regard that the general information provided is insufficient
to meet the obligations imposed by the GDPR, since the complainant had not been employed by Y1 for five years at the

time of his request. A reference to

a privacy statement that applies only to active employees is in that case not only

irrelevant, but also incorrect. The Dispute Resolution Chamber emphasizes that a

controller, in the context of a request for access, must update all available

information and align it with the specific processing that

is actually taking place with regard to the data subject submitting the request. The

Dispute Resolution Chamber therefore points out to Y1 that it was obligated to only provide

information about the complainant's personal data that is actually being processed or stored at the time of the

request for access.

95. Regarding retention periods, the Dispute Resolution Chamber notes that Y1 indicates that it will continue to retain the complainant's

personal data "for as long as necessary for

evidentiary purposes in the context of ongoing disputes." In this regard, the Dispute Resolution Chamber notes

that Y1 expressly states in its defense that, due to the long-standing

employment relationship with the complainant, it inevitably still processes a substantial amount

of personal data. From this, as well as from the documents in the file, the

Dispute Resolution Chamber infers that Y1 also processes the complainant's personal data

for other purposes. In this regard, the Dispute Resolution Chamber emphasizes that, if different retention periods apply to the complainant's

personal data, it must specify these periods

for all processing activities and/or data categories, which

34
it failed to do.

96. With regard to the information included in Article 15.1 e) and f) of the GDPR, the

Dispute Resolution Chamber notes that Y1 did not provide this information to the complainant

in its initial response, as it was clear that the complainant was already aware of these

rights. It also notes that Y1, in its response of 18 February 2021, failed to communicate this

information to the complainant. The Dispute Resolution Chamber reminds Y1 that the GDPR imposes an

objective information obligation on the controller, which

means that it must provide the data subject with the full information referred to in Article 15.1 of the GDPR,

without assessing their prior knowledge. Given the obligation to facilitate the exercise of the data subject's rights under Article 12.2 of the GDPR, the controller must be able to inform the complainant of their rights for each processing activity, which will depend on the legal basis. Information about rights that do not apply to the data subject in a specific situation should be avoided. 35

97. In view of the above, the Dispute Resolution Chamber finds that Y1 violated

Article 15.1(a) through (f) of the GDPR.

98. Regarding Y1's obligation, pursuant to Article 15.3 of the GDPR, not to provide a copy

of the personal data it processes, the Dispute Resolution Chamber notes

that on February 18, 2021, the defendant provided the complainant with a copy "of the

personal data that [it] may reasonably assume are the subject

of the request for access." However, the Dispute Resolution Chamber notes that neither

party submitted that copy as a document to the Registry of the Dispute Resolution Chamber,

therefore it cannot take cognizance of its content.

99. The Dispute Resolution Chamber further notes that Y1 relies on Article 12.5 of the GDPR and Article 15.4 of the GDPR

in conjunction with Recital 63 of the GDPR to refuse to provide certain documents containing the complainant's personal data. These documents include:

- Emails sent by the complainant to Y1 in connection with the present

dispute;

- Internal communications and communications with its counsel relating

to the present dispute, as their disclosure would prejudice Y1's rights of defense.

- Internal reports and emails relating to company figures and

matters and which, for that reason, must be considered business secrets.

100. The Dispute Resolution Chamber recalls that Article 15.4 of the GDPR limits the right to obtain a copy

with the following wording: "The right to obtain a copy

shall not adversely affect the rights and freedoms of others." Recital 63 of the GDPR

explicitly specifies in this regard: "that right must not adversely affect the rights

or freedoms of others, including trade secrets or intellectual property

and in particular the copyright protecting the software." Article 15.3 of the GDPR may

also be limited under Article 12.5 of the GDPR in the event of "manifestly

unfounded or excessive requests."

101. Therefore, the Litigation Chamber points out that neither Article 12.5 of the GDPR nor Article 15.4 of the GDPR

allows a controller to restrict the right to obtain a copy

on the grounds that the data subject already possesses those

personal data. The Litigation Chamber recalls that the right of access laid down in Article 15, of which the right to obtain a copy forms an integral part,

is the right to obtain a copy. 119 Decision on the merits 200/2025 - 27/33

must enable the complainant to verify that the personal data concerning them

are accurate and are processed lawfully, even if these

personal data are contained in emails that they themselves have sent to the

controller.

102. With regard to Article 15.4 of the GDPR in conjunction with Recital 63 of the GDPR, the Litigation Chamber notes

that the right of access may not adversely affect the rights or freedoms of others,
where “others” must be understood as any natural or

legal person other than the data subject exercising the right of access. Consequently, it is possible

that the right to obtain a copy is restricted if that right would adversely affect

the rights or freedoms of the controller himself, as is argued in the present case.

36

103. The Litigation Chamber recalls that the right of access is a fundamental right,
enshrined in Article 8, paragraph 2, of the Charter of Fundamental Rights of the EU. This means

that it may only be restricted in accordance with Article 52, paragraph 1,

of the Charter, which requires that any restriction on an EU fundamental right be “proportionate.” Article

15.4 of the GDPR must therefore be interpreted in light of the Charter,

which implies that conflicting rights must be carefully weighed against the data subject's right of access on a case-by-case basis.

As further explained in Recital 63 of the GDPR, this balancing should not result

in the data subject being denied all information. The controller

is therefore obliged, where possible, to provide the requested personal data

in a manner that does not adversely affect the rights or freedoms of others.

In the present case, this means that Y1 is obliged to provide the complainant's personal data

to the complainant. The Dispute Resolution Chamber therefore points out to Y1 that it can

fulfill its obligation under Article 15.3 of the GDPR by, for example: (i) granting partial

access to the files, so that the complainant can only access

their own personal data, (ii) applying anonymization or blocking of data

to protect sensitive business information, or (iii) providing a contextual

summary of the complainant's processed personal data. Such

measures are indeed appropriate when full access would prejudice Y1's

rights of defense or reveal its business secrets.

104. However, the Litigation Chamber finds that Y1 has in no way demonstrated that it

balanced its own rights against the complainant's right of access,

or attempted to provide the complainant with a copy of his personal data in

36 EDPB, Guidelines 01/2022 on data subject rights – Right of access – version 2.1, 28 March 2023, paragraph 171
37 Ibid., paragraph 173 Decision on the merits 200/2025 - 28/33

a manner that does not prejudice its own rights and freedoms. Furthermore, the

Litigation Chamber finds, more generally, that a copy of the personal data "which
[it] may reasonably assume to be the subject of the request for access"

is insufficient in light of Article 15.3 of the GDPR. As confirmed by the Court of Justice

of the European Union, the right to obtain a copy

from the controller implies that the data subject must receive a faithful and intelligible copy

of all personal data processed by the controller. 38 This therefore implies that the controller cannot, on its own initiative,

limit the scope of the copy, nor can it be sufficient to merely provide a copy of the

personal data it assumes are the subject of the request.

105. For the reasons listed above, the Litigation Chamber concludes that Y1

infringed Article 15.3 of the GDPR.

106. The complainant also argues that Y2 (the second defendant) has inadequately responded to his request for access. Now that the Dispute Resolution Chamber has already determined that Y2 has responded late,
39
it will, in the remainder of its assessment, focus solely on the question of whether Y2 has fulfilled its substantive obligations under Article 15, paragraphs 1 and 3,

of the GDPR – regardless of whether this compliance occurred within or outside the one-month period.

a) In fact

107. On July 8, 2020, the complainant exercises his right of access to Y2, requesting

information regarding the processing of his personal data in accordance with

Article 15.1 of the GDPR, specifically the information contained in sections a) through g) of

that article. On September 10, 2020, Y2 sends an email to the complainant, in which it formulates

a response to all the aforementioned sections of Article 15.1 of the GDPR.

108. The complainant argues that Y2 infringed Article 15.1(g) of the GDPR, as well as Article 14.1

a) and (b) of the GDPR, as it refused to disclose the identity of the person within Y1 whom it

contacted to obtain his personal data in the context of the

application procedure. The complainant argues that a mere reference to Y1 as a company

as a whole is insufficient in light of these provisions.

38
CJEU, 4 May 2023, C-487/21, F.F. v. Österreichische Datenschutzbehörde, ECLI:EU:C:2023:369, paragraph 45.
39See paragraphs 77 to 111. 81 of this decision Decision on the merits 200/2025 - 29/33

b) Position of Y2 (the second defendant)

109. Y2 denies having violated the aforementioned articles. It states that

in its email of July 2, 2020, in which the complainant was informed that he had not

been selected for the further selection procedure, it indicated that the manager

of Y1 had been contacted. Moreover, in its response to the access request,

it also informed the complainant that his personal data was being collected from Y1.

110. Y2 argues that it acted in accordance with Article 14.1 a) and b), and that Article 15.1 g)

nowhere stipulates that in this case the manager of Y1 should be referred to by name and

first name.

c) Judgment of the Litigation Chamber

111. The Litigation Chamber recalls that, in accordance with Article 15.1g) GDPR, the

data subject has the right to obtain all available information about the source of their

personal data if these were not collected from the data subject themselves.

112. The Litigation Chamber emphasizes that the use of the term "all available

information" indicates a high degree of specificity regarding the sources from which the

controller obtained the data. It is therefore not only

important that the controller provides information about the identity

of the source, but also which personal data were obtained from which source. The

controller is also obliged to inform the data subject

about the form in which the data were obtained.

40

The form in which the data were obtained.

113. However, similar to the information about the (categories of) recipients that must be provided to the data subject under

Article 15.1(c) GDPR, the purpose of the

information obligation under 15.1(g) GDPR is to enable the data subject to effectively exercise their rights under

the GDPR, both vis-à-vis the controller itself and

directly with the person or entity that provided the personal data (i.e., "the

data source").

Applied to the present case, the Litigation Chamber concludes that Y2 was not obliged

to communicate the surname and first name of the reference person within Y1 to the complainant.

In this case, it was sufficient that Y2 informed the complainant that his personal data

were obtained through Y1 "as an undertaking," given that this information was sufficient

to enable the complainant to exercise his rights with Y1, which he did in this case.

40 EDPB, Guidelines 01/2022 on data subject rights – Right of access – version 2.1, 28 March 2023, paragraph 120, Decision on the merits 200/2025 - 30/33

114. In view of the above, the Litigation Chamber decides that Y2 did not infringe

Article 15.1 g) GDPR, nor Article 14.1 a) and b) GDPR.

II.4. Regarding the alleged violation of other rights under the GDPR by

both respondents

115. In both complaints, the complainant argues that, in addition to his right of access, the respective

respondents also violated his other rights under the GDPR. More specifically,

the complainant alleges that both respondents violated his right to rectification (Article 16 GDPR),

to erasure (Article 17 GDPR), to restriction (Article 18 GDPR), and to object (Article

21 GDPR).

116. However, the Litigation Chamber finds that the complainant has not exercised his rights under the aforementioned articles with respect to either Y1 or

Y2. Although the

Litigation Chamber reiterates that the exercise of the right of access functions as an

essential condition for the effective exercise of the other rights that the GDPR

grants to data subjects, it finds that a violation of the right of access does not

automatically lead to a violation of other rights under the GDPR.

117. In view of the above, the Litigation Chamber finds that it has not been demonstrated that

the respondents in this case violated the complainant's rights as set out in Articles

17, 18, 19, and 21 of the GDPR.

II.5. Regarding the alleged violation of the basic principles regarding the processing

of personal data by Y1 (the first defendant)

118. Since it has already been established that Y1 (the first defendant) acted in violation of

Article 6.1 GDPR, the Litigation Chamber no longer considers it appropriate to further

investigate whether she also violated the basic principles regarding

data processing pursuant to Article 5.1 GDPR. The Litigation Chamber decides to dismiss this part

of the complaint.

III. Sanctions

119. In accordance with Article 100 of the Dutch Data Protection Act (WOG), the Litigation Chamber has the power to:

1° dismiss a complaint;

2° order a dismissal of the prosecution;

3° order a suspension of the judgment;

4° propose a settlement;

5° issue warnings and reprimands; Decision on the merits 200/2025 - 31/33

6. to order that the data subject's requests to exercise their rights be complied with;

7. to order that the data subject be informed of the security problem;

8. to order that the processing be temporarily or permanently frozen, restricted, or prohibited;

9. to order that the processing be brought into compliance;

10. to order the rectification, restriction, or erasure of data and the notification
thereof to the recipients of the data;

11. to order the withdrawal of the recognition of certification bodies;

12. to impose periodic penalty payments;

13. to impose administrative fines;

14. to order the suspension of cross-border data flows to another State or
an international institution;

15° to transfer the file to the Public Prosecutor's Office in Brussels, who
will inform it of the action taken on the file;

16° to decide, on a case-by-case basis, to publish its decisions on the website of
the Data Protection Authority.

120. The Dispute Resolution Chamber wishes to recall that it is its sovereign

responsibility as an independent administrative authority to determine, in compliance

with the relevant articles of the GDPR and the Data Protection Act (WOG), the appropriate corrective

measure(s) and sanction(s).

121. The Dispute Resolution Chamber ruled that Y1 (the first defendant) has violated

Articles 6, paragraph 1 of the GDPR, 12, paragraphs 2 through 4 of the GDPR, and 15, paragraph 1 and 3 of the GDPR. The Litigation Chamber

points out that a considerable amount of time has elapsed between the filing of the final conclusion

in this case and the adoption of the present decision. The Litigation Chamber takes this

passage of time into account when determining the appropriate measure in this case.

Nevertheless, it is still appropriate – at least to prevent recurrence of infringements in the future

– to establish the historical infringements and to point out to the defendant

its responsibility in this regard. This responsibility has been sufficiently pointed out in this case

by using the reprimand as a sanction.

122. The Litigation Chamber ruled that Y2 (the second defendant) has

committed an infringement of Article 12, paragraph 3 of the GDPR. However, the Litigation Chamber notes that this infringement

was unintentional and the result of a one-off human error. Therefore,

the Litigation Chamber decides that it is sufficient to issue a reprimand for

the aforementioned infringement. Decision on the merits 200/2025 - 33/33

42
in accordance with Article 1034quinquies of the Judicial Code, or via the e-Deposit

information system of the Ministry of Justice (Article 32ter of the Judicial Code).

(Government). Hielke HIJMANS

Director of the Litigation Chamber

42 The application and its appendix, in as many copies as there are parties involved, shall be sent by registered mail
to the clerk of the court or lodged with the court registry.