APD/GBA (Belgium) - 97/2026

From GDPRhub
APD/GBA - 97/2026
Authority: APD/GBA (Belgium)
Jurisdiction: Belgium
Relevant Law: Article 12(2) GDPR
Article 12(3) GDPR
Article 12(4) GDPR
Article 15(1) GDPR
Article 15(3) GDPR
Article 15(4) GDPR
Type: Complaint
Outcome: Upheld
Started: 27.07.2023
Decided: 06.05.2026
Published:
Fine: n/a
Parties: n/a
National Case Number/Name: 97/2026
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): French
Original Source: APD (in FR)
Initial Contributor: ds

The DPA held that an employer violated an employee’s right of access by refusing to provide copies of their timesheets and offering only an inspection on its premises. The DPA also found that the workload involved in fulfilling the access request was due to the controller’s own archiving system and not because the request was excessive.

English Summary

Facts

The data subject was a technician employed by the controller. The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained the technician’s working hours, journeys, services performed and the clients visited.

On 10 May 2021, the data subject requested copies of their service sheets covering the previous five years in order to verify whether the hours they had reported corresponded to those recorded by the controller. The controller provided only the sheet concerning the week of 3 May 2021 to 9 May 2021 and subsequently proposed that the data subject arrange an appointment to consult the records at its premises. The data subject reiterated the request on 17 January 2022 and again in 2023, but never received the requested copies.

On 27 July 2023, the data subject lodged a complaint with the Belgian DPA. The DPA issued the prima facie Decision 14/2025, where it ordered the controller to comply with the data subject’s access request and warned it of potential violations of Article 15(3) GDPR and Article 12(3) GDPR. The controller requested an examination on the merits.

The controller argued that the data subject’s request had not clearly distinguished between the handwritten service sheets and a computer-generated statement. It further claimed that the request was excessive under Article 12(5) GDPR because the documents were stored by date rather than by employee in several dozen binders. Locating, copying and scanning the relevant records would therefore require considerable workload. For that reason, it had invited the data subject to inspect the binders in its premises and identify the relevant documents to be copied.

The data subject maintained that their request had always been clear, that the computer-generated statement was incomplete and unintelligible and that the practical difficulties relied upon by the controller resulted from its own archiving practices.

Holding

The DPA ruled that the data subject had made a sufficiently clear request for access and a copy under Article 15(1) GDPR and Article 15(3) GDPR. It further pointed out that the controller’s response demonstrated that it had understood that the data subject sought copies of the service sheets themselves.

The DPA further held that the computer-generated statement did not satisfy the request. It noted that the data subject needed the handwritten records in order to compare the hours they had reported with those subsequently recorded by the controller. It referred to C-487/21 (Österreichische Datenschutzbehörde) and recalled that the copy provided must constitute a faithful and intelligible reproduction of the personal data and may require copies of documents where this is necessary for the effective exercise of the data subject’s rights. The DPA therefore determined that the controller’s invitation to inspect the documents at its premises therefore did not constitute an adequate response to the data subject’s request for a copy. It stated that if the controller had genuinely been uncertain about the scope of the request, it should have sought clarification in accordance with Article 12(2) GDPR.

Moreover, it rejected the controller’s reliance on Article 12(5) GDPR. The DPA held that the request was neither manifestly unfounded nor excessive as was clearly expressed and properly understood by the controller. It found that the controller did not demonstrate the excessiveness but relied exclusively on the workload resulting from its own archiving system.

The DPA also relied on C-526/24 (Brillen Rottler) and applied the abuse of rights test. It found that neither its objective nor its subjective element was established. It reasoned that the request pursued the purpose of Article 15 GDPR, since the data subject sought to access and verify the accuracy of personal data concerning them, nor was there any evidence that the data subject had artificially created the conditions for obtaining an advantage under the GDPR. It further referred to EDPB Guidelines 01/2022 on the right of access, emphasizing that the time and effort required for a controller to fulfil an access request cannot, in itself, make the request excessive, particularly since the burden resulted from organisational choices made by the controller. It also emphasized that the data subject was also not required to justify the reasons for the request.

The right of access under Article 15 GDPR does not include any general proportionality reservation regarding the controller’s efforts. Additionally, the term "appropriate" in Article 12(1) GDPR should not be used to limit the scope of data covered by the right of access. The DPA concluded that the alleged burden could not justify a refusal, especially since it stemmed from self-imposed organizational and administrative constraints related to the controller’s archiving system. A refusal may only apply if there is proven abusive intent, as defined by applicable requirements. Any other interpretation would undermine Article 15 GDPR and conflict with Article 12(2) GDPR and Article 25 GDPR, which require controllers to facilitate access requests and implement technical and organizational measures from the outset to ensure effective exercise of this right.

The DPA further held that the controller had violated Article 12(2) GDPR, Article 12(3) GDPR and Article 12(4) GDPR. It had neither responded within the applicable time limit nor formally notified the data subject of a reasoned refusal. It further emphasized that the controller by requiring the data subject to attend its premises and identify the relevant records, it improperly transferred to them a task that belonged to it. Moreover, it noted that on-site consultation of the records could have exposed the data subject to personal data relating to the controller’s clients. The DPA held that under Article 15(4) GDPR, the controller was required to assess whether measures, such as partial anonymisation of third-party information, were necessary and that provision could not justify a blanket refusal to provide a copy.

The DPA reprimanded the controller for violating Article 12(2) GDPR, Article 12(3) GDPR, Article 12(4) GDPR, Article 15(1) GDPR and Article 15(3) GDPR and ordered it to provide copies of the timesheets within one month.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the French original. Please refer to the French original for more details.

1/24

Litigation Chamber

Decision on the merits 97/2026 of May 6, 2026

Case number: DOS-2023-03100

Subject: Complaint concerning the failure to act on a request for access to

a copy of service records

The Litigation Chamber of the Data Protection Authority (hereinafter "DPA");

Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the

protection of natural persons with regard to the processing of personal data and

on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter "GDPR";

Having regard to the Law of 3 December 2017 establishing the Data Protection Authority (hereinafter

“the Data Protection Authority”);

Having regard to the Rules of Procedure as approved by the Chamber of Representatives on

20 December 2018 and published in the Belgian Official Gazette on 15 January 2019 (hereinafter “the Rules of Procedure”);

Having regard to the documents in the file and having heard the parties at the hearing of 15 October 2025;

The following decision has been taken concerning:

The complainant: X, residing at […], represented by Steve Gilson, whose office is located at

[…], hereinafter “the complainant”;

The defendant: Y-S.A., whose registered office is located at […], registered under company number

[…], represented by Hervé Deckers and Anne-Catherine Doyen,

whose office is located at […], hereinafter referred to as “the defendant”.

1. The APD notes that the revised LCA (Law on Administrative Procedure) entered into force on June 1, 2024. It applies only to complaints, mediation cases, applications, inspections, and proceedings before the Litigation Chamber initiated on or after that date.

mediation cases, applications, inspections, and proceedings before the Litigation Chamber initiated on or after that date. Cases initiated before June 1, 2024, such as this case, are subject to the provisions of the previous version of the Data Protection Act (LCA), accessible here: https://www.autoriteprotectiondonnees.be/publications/loi-organique-de-l-apd.pdf
2The new Internal Regulations (ROI), resulting from the amendments made by the Law of December 25, 2023, amending the Law of December 3, 2017, establishing the Data Protection Authority (LCA), entered into force on June 1, 2024. They apply only to complaints, mediation cases, requests, inspections, and proceedings before the Litigation Chamber initiated on or after that date. Cases initiated before June 1, 2024, are subject to the provisions of the ROI as it existed before that date. Decision on the merits 97/2026 — 2/24

I. Facts and procedure

1. The complainant is a technician employed by the defendant. He filed this complaint

following the defendant's refusal to respond to a request for access to a

copy of his service records for the period from May 10, 2016, to May 10, 2021 (also

referred to as "route sheets" or "work sheets" by the parties). These service records

(one per week) detail, for each day worked, the sequence of

trips and services performed, based on handwritten notes prepared by the

technician (including the times of interventions, the services performed, and
the clients at whose premises the intervention took place).

2. On May 10, 2021, the plaintiff requested that the defendant provide corrections to

all the timesheets for the past 5 years:

“Therefore, I request that by this date all technicians, myself included, have received

corrections to all their timesheets in order to check for any

anomalies or omissions during these past 5 years, or, if they have been with the company for less than 5 years, from their start date.”

3. On the same day, the defendant provided the plaintiff with only one copy of his timesheets,
for week 18 (May 3, 2021 to May 9, 2021), which was the subject of

discussion between the parties.

4. On May 31, 2021, following a meeting held on May 25, 2021, the defendant clarified to the plaintiff the procedures for providing copies:

“If you require a copy of a route sheet for a specific date, you

can contact Z1, who will scan the route sheet.

If you require a copy of all your past route sheets:

- Make an appointment with Z2, 7 business days in advance,

- We prepare folders containing only services rendered,

- To ensure clarity in the future, we will consider using

electronic route sheets to facilitate future exchanges,…). »


5. On January 17, 2022, by registered mail and email, the complainant reiterated his request

for access in the following terms:

3. The time sheets, also referred to as time sheets by the parties, constituted the defendant's system for recording working time, fulfilling a function similar to that of a time clock, in handwritten form. Decision on the merits 97/2026 — 3/24

“Mr. X was also concerned to see discrepancies between the time sheets

submitted by the workers and what was actually declared

to the payroll department and therefore paid. Mr. X reported this to

the company and requested that the worker be given access to the time sheets

for the last five years (…).

Mr. X also requests the production of all his timesheets

in accordance with the General Data Protection Regulation (GDPR) so that he can

verify the accounting of his hours in light of the irregularities he has
observed.”

6. On (…), the Labor Court of (…) renders a judgment concerning a labor law dispute

between the parties.

7. On February 17, 2023, the defendant writes to the plaintiff in the following terms:

“Mr. X has demanded that Company Y produce his timesheets since

the beginning of his employment, under threat of referring the matter to the Labor Inspectorate.

Although this request was not justified, my client confirmed to her that she

would do what was necessary, with all rights reserved and without any acknowledgment, provided

that she understood that relations with Mr. X would continue peacefully

and that no reproach of any kind could be made against her. She

however, she would not accept being subjected to any form of blackmail by Mr. X

”.

8. On February 18, 2023, the plaintiff responded to the defendant as follows:

“Mr. X is not engaging in any blackmail by requesting his timesheets

. This is a request that has been made for a very long time and which

we do not understand why the employer is not complying with. This request does not need

to be justified. Its justification is very simple.”

9. On February 23, 2023, the complainant informed the defendant that he had gone to “City 2” on February 20, 2023, to request his service records, which the defendant had allegedly refused to provide.

10. On March 2, 2023, the defendant replied to the complainant as follows:

“Regarding the complainant’s request for his service records, I confirm – again and as needed – that the complainant can review them at the defendant’s head office, located in “City 1,” outside of business hours and by making an appointment beforehand.” Decision on the merits 97/2026 — 4/24

These documents may be consulted electronically as soon as

within the framework of the digitization process in place at the (defendant), these
documents are stored electronically.

11. On March 31, 2023, the complainant replied to the defendant as follows:

“Regarding consultation of the service sheets, (the complainant) has already gone to

“city 1” in the past with his colleague, (…), and access was refused.

Even based solely on the IT policy, obtaining the route sheets

in question should not pose any difficulty.

Mr. Z2 also sent an email (to the complainant) indicating that he

could consult the service sheets at “city 2” or “city 1” in a

folder.” What is the concrete situation?

12. On April 14, 2023, the defendant replied:

“Regarding the consultation of the benefit records, I can only

refer you to our previous exchanges.”

13. On July 27, 2023, the complainant filed a complaint with the Data Protection Authority (DPA) against the

defendant.

14. On October 13, 2023, the complaint was deemed admissible by the Frontline Service

based on Articles 58 and 60 of the LCA (Law on Insurance Contracts) and the complaint was forwarded to the

Litigation Chamber pursuant to Article 62, § 1 of the LCA.

15. On February 14, 2024, the Litigation Chamber sent a letter to the complainant, requesting that

the complainant provide, no later than February 28, 2024, a dated copy of their correspondence

with the respondent, and in particular the email(s) indicating their refusal to

provide a copy of their service records.

16. On October 22, 2024, the Litigation Chamber sent a letter to the parties in

5
containing several pieces of information.

It indicated that the file did not sufficiently present the respondent's position regarding their refusal to comply with the complainant's access request. The

Litigation Chamber considered it essential to have the respondent's position in order to

properly assess the arguments with regard to Articles 15.4 and 12.5 of the

GDPR. The complainant's position, on the other hand, was sufficiently developed.

4
Pursuant to Article 61 of the LCA, the Litigation Chamber hereby informs the parties that the complaint has been declared admissible. 5. Pursuant to Article 95, §2 of the LCA, by letter of October 22, 2024, the Litigation Chamber informs the parties that, following this complaint, the file has been forwarded to it, as well as the possibility of consulting and copying said file. Decision on the merits 97/2026 — 5/24

The Litigation Chamber therefore requests the defendant to provide reasons

for why it considers it is not required to respond to the

complainant's request for access, based on Article 15.3 of the GDPR, seeking a copy of his

performance records since he entered service, i.e., from May 10, 2016, to May 10, 2021.

It requests the defendant to submit its response by November 25, 2024.

17. On November 4, 2024, the defendant contests having refused to respond to a request
for access from the complainant. She produced the letters of March 2, 2023, and April 14, 2023 (points 10 and 12), in which she had proposed arrangements allowing the complainant to review his service records. The defendant indicated that following these two letters, she received no response from either the complainant or his counsel.

18. On January 23, 2025, the Litigation Chamber adopted prima facie decision No. 14/2025.

In this decision, the Litigation Chamber decides:

- pursuant to Article 58.2.c) of the GDPR and Article 95, § 1, 5° of the Swiss Federal Act on Administrative Procedure (LAC),

to order the defendant to comply with the data subject's request to exercise their

rights, and more specifically, to comply with the complainant's request

for access and a copy of the data (Article 15 of the GDPR), within 30 days

from the date of notification of Decision No. 14/2025; and

- pursuant to Article 58.2.c) of the GDPR and Article 95, § 1, 4° of the LCA, to

issue a warning to the defendant regarding potential violations

of Articles 15.3 and 12.3 of the GDPR.

19. On February 19, 2025, the defendant exercised the option provided in the decision

"prima facie" to request a hearing on the merits of the case pursuant to Articles 98 et seq. of the LCA.

20. On February 25, 2025, the Litigation Chamber decided, pursuant to Article 95, § 1, 1° and
Article 98 of the LCA, that the case could be heard on its merits. The parties concerned were

notified by registered mail of the provisions as set out in Article 95, § 2 and

Article 98 of the LCA. They were also informed, pursuant to Article 99 of the LCA,

of the deadlines for submitting their pleadings.

Having regard to the documents in the file, including the complaint form, the Litigation Chamber

invited the parties to submit their arguments regarding compliance with and applicability of the following provisions

of the GDPR:

- Alleged violations of Articles 12.3, 12.4, 15.1 and 15.3 of the GDPR due to

the lack of response and follow-up to the exercise of the right of access aimed at

obtaining a copy of the service records. Decision on the merits 97/2026 — 6/24

- Applicability of Article 12.5 of the GDPR to the complainant's access requests, in that

the defendant alleges that these requests are unfounded or, at the very least,

excessive.

The complainant's submissions:

21. On April 30, 2025, the Litigation Chamber received the complainant's submissions. The plaintiff

requests that the Litigation Chamber rule that the defendant has violated

Articles 12 and 15 of the GDPR, and order the defendant to comply with the plaintiff's request

for access and a copy, by ordering the defendant to provide, within eight
days of the decision, a copy of its service records for the last five years,

in response to its request of May 10, 2021, under penalty of a fine of €10,000 per

missing document and per day of delay. The plaintiff's arguments can be

summarized as follows.

- As a first ground of appeal, the plaintiff characterizes the defendant as the data controller.

The defendant does not contest this;

- As a second ground of appeal, the complainant maintains that he exercised his

right of access with the defendant on several occasions, in accordance with Article 15.3 of the GDPR,

in particular on May 10, 2021, by requesting a copy of his

service records.

- As a third ground of appeal, the complainant considers that the defendant violates Articles

12 and 15 of the GDPR, insofar as, firstly, contrary to what it claims

for the first time in its submissions, it did not comply with the complainant's request for a

copy; and, secondly, the defendant does not legally justify

its refusal to provide a copy of the service records. Indeed, the

complainant believes that this refusal cannot be justified by the cumbersome nature of this

delivery, resulting from the defendant's own filing choices, nor by the
alleged impossibility of identifying the service records.

- As a fourth ground of appeal, and in addition, the complainant argues that the

defendant deprived him of all access to the service records, and not only refused

to comply with his request for a copy. Decision on the merits 97/2026 — 7/24

The defendant's submissions:

22. On May 13, 2025, the Litigation Chamber received the defendant's summary submissions. The defendant's arguments can be summarized as follows:

- The defendant maintains that it did not violate Articles 12.3 and 15.3 of the GDPR. She

believes she responded favorably to the complainant's request for access and copies

within one month of his request.

- She also believes that if she did not comply with a request for a copy, it was

because she was unable to identify the documents targeted by the request

for access and copies, and because providing such a copy would constitute a considerable undertaking

requiring adherence to a specific procedure. For these

reasons, without refusing to comply with the request, the defendant invited the

complainant to make an appointment at least seven business days in advance for an

on-site review of the service records at the company's headquarters. The

defendant believes the complainant did not comply with this procedure.

- Finally, the defendant considers that the complainant's request is manifestly

unfounded or, at the very least, excessive, within the meaning of Article 12.5 of the GDPR, and that in

such a case, it may refuse to grant the request for access to the service records.

II. Reasoning

II.1. Regarding the scope and purpose of the request for access and a copy (Articles 15.1 and 15.3 of the

GDPR)

i. Applicable principles

23. The right of access provided for in Article 15 of the GDPR consists of three elements, namely (i) confirmation of whether or not personal data is being processed (“Confirmation component”), (ii) access to that data (hereinafter “Access component”), and (iii) information about the processing (“Information component”). This connection is reiterated

by the European Data Protection Board (hereinafter “EDPB” for European Data Protection Board) in its Guidelines 01/2022 on the right of access. Indeed,

under Article 15.1 of the GDPR, the data subject has the right to obtain from the controller

confirmation as to whether or

personal data concerning him or her are being processed. Where this is the case, the data subject has the right to obtain access

6The European Data Protection Board (hereinafter “EDPB” for European Data Protection Board) brings together the
data protection authorities of the Member States of the European Union and aims to ensure the consistent application of the GDPR.

EDPB, Guidelines 01/2022 on the rights of data subjects – right of access, adopted on 28 March 2023 (hereinafter referred to as the “Guidelines 01/2022 on the right of access”), available at:
https://www.edpb.europa.eu/system/files/2024-04/edpb guidelines 202201 data subject rights access v2 fr.pdf. Decision on the merits 97/2026 — 8/24

to said personal data as well as to a series of information listed in Article

15.1 a) to h) such as the purpose of the processing of his data, the possible recipients of

his data as well as information relating to the existence of his rights, including the right to

request the rectification or erasure of his data or the right to lodge a complaint

with the Data Protection Authority.

24. Pursuant to Article 15.3 of the GDPR, the data subject has the right to obtain a copy

of the personal data which are the subject of the processing. This possibility of obtaining

a copy of the personal data processed is not an additional right of

the data subject, but simply the means of accessing the data. This provision also specifies that when the data subject submits their request electronically, the information must be provided in a commonly used electronic format, unless the data subject requests otherwise. Article 15.4 of the GDPR stipulates that this right to a copy must not infringe upon the rights and freedoms of others.

25. Regarding the procedures that a data controller must follow in response to a data subject's access request, the Litigation Chamber reiterates that the obligation to provide a copy, as provided for in Article 15.3 of the GDPR, should not be understood as an additional right of the data subject, but rather as a means of granting access to the data. Therefore, access to data under Article 15.1 of the GDPR

must include all information concerning all data, and this access cannot

be understood as granting access only to a summary of the data.

The obligation to provide a copy serves the purposes of the right of access, namely to allow the

data subject to be informed of the lawfulness of the processing and to control it

(Recital 63 of the GDPR). To achieve these purposes, it is in most cases not

sufficient for the data subject to be able to temporarily consult the information, and

they must be able to access their data by being provided with a copy of it.

26. In its judgment C-487/21 of 4 May 2023, the Court of Justice of the European Union (CJEU) held that Article 15.3 of the GDPR must be interpreted as meaning that “the right to obtain from the controller a copy of the personal data undergoing processing implies that the data subject must be provided with a faithful and intelligible reproduction of all such data.” This right implies the right to obtain a copy

of extracts of documents, or even entire documents, or extracts from databases

which contain, among other things, said data, if the provision of such a copy is

essential to enable the person concerned to effectively exercise the rights

8EDPB, Guidelines 01/2022 on the right of access, point 3. Decision on the merits 97/2026 — 9/24

conferred upon him by this Regulation, it being stressed that, in this regard,

the rights and freedoms of others must be taken into account.”

ii. Positions of the parties

27. The defendant essentially argues that the complainant’s request for access was never

sufficiently precise to allow for a useful response and that it considers, moreover,

that it has validly responded to it. She argues that the initial request, made on May 10, 2021, in the context of the complainant's union duties, concerned corrections to route sheets, a request to which she claims to have responded the same day. Subsequently, when the complainant reiterated his requests in 2023, the defendant states that she did not know precisely which documents were involved, particularly because she had already provided him, as part of the legal proceedings, with a summary of the service records covering the requested period, and that the complainant had never specified which documents were still missing. The defendant maintains that it was only during the proceedings before the Litigation Chamber that the request was clarified, namely that it concerned individual handwritten records and not computerized records, whereas this distinction had never been clearly stated before. It is in this context that the defendant claims to have offered an on-site consultation at the head office, with prior appointment, a solution it presents as

reasonable insofar as it would allow the complainant to identify for himself the

documents he needs, given the considerable volume of records filed not by

employee but by day worked.

28. The complainant strongly contests these claims. He maintains that his requests have

always been clear and that the defendant has never complied with them. In this regard, he notes that

the documents actually provided by the defendant in no way satisfy his

request for copies, which concerned all timesheets since he

started working. However, he only received a service record from the defendant following his

request on May 10, 2021, as well as an incomprehensible computerized statement, which he found to be

only partially documenting the services actually performed.

CJEU, Judgment of May 4, 2023, Österreichische Datenschutzbehörde and CRIF GmbH, C-487/21, ECLI:EU:C:2023:369, § 45. Emphasis added by the Litigation Chamber. Decision on the merits 97/2026 — 10/24

iii. Position of the Litigation Chamber

29. Regarding the request of 10 May 2021, the Litigation Chamber is of the opinion
that, notwithstanding the absence of an explicit reference to Article 15 of the GDPR, the request

made by the complainant seeking corrections to all its roadmaps

in order to check for any anomalies over the past five years,

can be interpreted as a request for access to and communication of a copy within the meaning

of Articles 15.1 and 15.3 of the GDPR, and is sufficiently clear in its purpose. The defendant's own reaction confirms this, since in response to this request, the defendant (i) on May 10, 2021, provided the complainant with a copy of a "corrected" benefits statement that was the subject of a discussion between the parties (who had rightly refused to provide the benefits statements of other individuals) and (ii) on May 31, 2021, asked the complainant either to identify the specific benefits statements he wished to obtain (in which case he could receive a scan of the statement in question), or to follow a specific procedure to obtain a copy of all his benefits statements, which demonstrates that the defendant understood that the complainant was indeed seeking copies of the benefits statements themselves (paragraph 4).

30. Secondly, regarding the request of January 17, 2022, any remaining ambiguity has, in any event, been dispelled. Indeed, on that date, the plaintiff's counsel expressly requested the production of all service records, invoking the GDPR (point

5), specifying that this request, covering the last five years, was part of the verification of his client's timekeeping. Such a formulation is unambiguous, both in terms of its purpose and its legal basis.

The Litigation Chamber notes in particular that the plaintiff intended to obtain the service records themselves, in order to verify whether the hours he had himself declared corresponded to those actually recorded by the defendant.

31. The Litigation Chamber cannot therefore accept the argument that the defendant

was unaware, until the proceedings before it, that the request concerned all the
individual handwritten service records and that there was confusion regarding

the precise subject of the request, on the grounds that it had produced, in the context of the

judicial proceedings, a computerized record of the service records covering the period in question,

a record which, according to it, satisfied the request. However, the plaintiff's request concerned not

a record transcribing the data appearing on the records, but rather all the service records themselves.

This request was expressed consistently and unequivocally in the plaintiff's repeated requests. The complainant explained to the

defendant, from the outset, that he intended to obtain these copies in order to verify the

recording of his hours, given the irregularities he had observed. However, it could not have escaped the defendant's notice that the provision of a computerized record did not

in any way allow the complainant to carry out this verification, which could only

be done by comparing it to the source documents, namely the handwritten forms

that the complainant himself had completed.

32. Furthermore, the defendant's offer of on-site consultation cannot

constitute an adequate response to the complainant's request. This request clearly

concerned the provision of a copy within the meaning of Article 15.3 of the GDPR, and not merely a

temporary consultation of the documents. The Litigation Chamber reiterates in this regard that
the provision of a copy of the processed data constitutes the access method enshrined in

this provision and gives the data subject the possibility of obtaining a

faithful reproduction of their data, in a form that allows them to dispose of it freely

and permanently. Inviting the complainant to consult the filing cabinets on the defendant's

premises cannot therefore be considered an adequate response to a request for a

copy, even if this consultation could, in practice, have been accompanied by the possibility of
making photocopies on-site.

33. Moreover, if the defendant had any real doubt regarding the scope of the access request, it would have been incumbent upon it to clarify this with the complainant, in accordance with the obligation to facilitate access under Article 12.2 of the GDPR.

34. As for the temporal scope of the request, the Litigation Chamber finds no further uncertainty. Several of the successive requests expressly targeted the complainant's last five years of employment with the defendant, starting from the first request of May 10, 2021.

35. It is clear from all the evidence in the file that the request for a copy was clearly formulated by the complainant as early as May 10, 2021, and that it was manifestly understood as such by the defendant. The defendant's continued reluctance to provide the copy reveals that the alleged misunderstanding of the request

was not the true reason for its inaction. This inaction stemmed, in reality, from the sheer volume of work

that fulfilling the request represented. The Litigation Chamber considers

that it is this consideration, and not any lack of clarity, that explains why the

defendant systematically limited the complainant to an on-site consultation

rather than providing a copy of all the requested documents. It is therefore necessary
to examine whether this reason, based on the allegedly excessive nature of the request, is

sufficient to justify the defendant's failure to respond. Decision on the merits 97/2026 — 12/24

II.2. Regarding the alleged excessive nature of the request for a copy (Article 12.5 of the GDPR)

i. Applicable Principles

36. Article 12.5 of the GDPR establishes, first and foremost, the principle that exercising the right of access

should not incur any costs for the data subject. This provision, however, considers

two circumstances in which a data controller may either charge a reasonable fee

taking into account administrative costs, or refuse to comply with a

11
access request. These circumstances relate to cases of abuse of rights, in which the

requests of the data subject must be considered as being “manifestly

unfounded” or “excessive,” the repetitive nature of the request being, in particular,

a factor to be taken into account. Article 12.5 of the GDPR pursues, in this respect, the same objective as

Article 57.4 of the same regulation and constitutes an expression of the general principle of Union law

under which individuals may not fraudulently or abusively

14
rely on Union standards.

37. Article 12.5 of the GDPR establishes an exception to the obligation to facilitate the rights of the

data subject, and in particular the right of access, which must be interpreted

15
restrictively. Similarly, the principles of transparency and free access to the rights of data subjects

may only be compromised in exceptional circumstances. It follows that

the data controller can only claim that a request is manifestly

unfounded or excessive in exceptional circumstances and according to high standards,

Article 12.5, paragraph 2, of the GDPR explicitly placing the burden of proof on the data controller, which must be demonstrated on a case-by-case basis, in light of the context in

which the request was made. Apart from the limits, derogations, and limitations

expressly provided for, the GDPR does not authorize any other exemption or derogation from the right

of access.

38. In the aforementioned Guidelines 01/2022 on the right of access, the EDPB clarifies what is meant by “manifestly unfounded” and “excessive” within the meaning of Article 12.5 of the GDPR.

10. Article 12.5 of the GDPR states that “No payment shall be required for providing the information referred to in Articles 13 and 14

and for making any communication and taking any action referred to in Articles 15 to 22 and Article 34.”

11. Article 12.5 of the GDPR states that “where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive nature, the controller may: (a) charge a reasonable fee which takes into account the administrative costs of providing the information, making the communications or taking the action requested; or (b) refuse to comply with such requests.” It is incumbent upon the
controller to demonstrate that the request is manifestly unfounded or excessive.”

12CJEU, Judgment of 26 October 2023, FT (Copies of the medical file), C-307/22, EU:C:2023:811, paragraph 31.

13See CJEU, Judgment of 19 March 2026, Brillen Rottler, C-526/24, EU:C:2026:216, paragraphs 26 to 35, in which the Court held that a
first request for access can, in principle, be considered excessive within the meaning of Article 12.5 of the GDPR.

14
CJEU, Brillen Rottler, op. cit., paragraphs 23 to 30.
15
CJEU, Judgment of 9 January 2025, Österreichische Datenschutzbehörde (Excessive Requests), C-416/23, EU:C:2025:3, paragraph 33;
CJEU, Brillen Rottler, op. cit., paragraph 29. Decision on the merits 97/2026 — 13/24

GDPR. Regarding the "manifestly unfounded" nature of the request, such a classification presupposes

that the requirements of Article 15 of the GDPR are, according to an objective approach,

clearly not met. Since there are very few prerequisites for the right

of access, the cases in which a request can be deemed “manifestly unfounded”

are very limited. Regarding the “excessive” nature of a request, the EDPB considers that, apart from the case

of a repetitive request, a request can only be considered excessive in the event of

abusive use of Article 15 of the GDPR, that is to say, when the data subject

uses their right of access for the sole purpose of causing harm to the controller of the

18
processing.

39. This interpretation is consistent with the CJEU’s settled case law on the

prohibition of abuse of rights. Proof of an abusive practice requires the presence of two elements:

firstly, an objective element, consisting of a set of objective circumstances

from which it follows that, despite formal compliance with the conditions laid down by the

Union regulation, the objective pursued by this regulation has not been achieved;

secondly, a subjective element, consisting of the intent of the person concerned

to obtain an advantage resulting from the Union regulation by artificially creating the

conditions required for obtaining it. 19

40. More specifically regarding the subjective element, the Court clarifies that an abusive intent

can be established when the data subject submits their access request “

for a purpose other than to become aware of the processing of their data and

to verify its lawfulness, in order to subsequently obtain protection of the rights they

20
are entitled to under this Regulation”. It is incumbent upon the data controller to demonstrate unequivocally

that the data subject submitted an access request not to

become aware of this processing, but to artificially create the conditions

required for obtaining redress from said data controller. For the purposes of this assessment, the Court invites consideration of all the circumstances of the case, including the fact that the data subject provided personal data without being compelled to do so, the purpose for which this data was provided, the time elapsed between the provision of this data and the access request, and the conduct of that person.

16EDPB, Guidelines 01/2022 on the right of access.

To submit an access request, it is sufficient for the requesting persons to specify that they wish to know what personal data concerning them is being processed by the data controller. No formal requirements are stipulated by the GDPR. For further details, see Guidelines 01/2022 on the Right of Access, section 3.

18EDPB, Guidelines 01/2022 on the Right of Access, paragraph 188 (emphasis added by the Litigation Chamber), see also the examples cited in paragraphs 189 and 190.
19
CJEU, Brillen Rottler, op. cit., paragraph 36 and the case law cited therein.

20
CJEU, Österreichische Datenschutzbehörde (Excessive Requests), op. cit., paragraphs 50 and 56.

21
CJEU, Brillen Rottler, op. cit., paragraph 41.

22
CJEU, Brillen Rottler, op. cit., paragraph 42. Decision on the merits 97/2026 — 14/24

ii. Positions of the parties

41. In the present case, the defendant argues, in substance, that the complainant's request is

excessive, because providing the requested copy would represent a

considerable workload,

23
given its archiving system. She explains in this regard that the timesheets

are filed by workday in several dozen binders and

not by worker, so that she would have to assign one or two members of her staff
for several hours, or even several days, to isolate the complainant's timesheets, make

copies, scan them, and send them to him. She adds that a company with more than

fifty technicians would have to hire

staff specifically for this purpose if such a request were to be fulfilled. It is for these reasons that she suggested the complainant

come to the premises to identify for himself, in the binders, the timesheets he

would like to have copied, with the company's administrative staff then

making photocopies of the selected documents.

42. The complainant disputes this characterization. First, it is noted that the defendant did not, at

any point during the exchanges preceding the complaint, invoke the manifestly unfounded or excessive nature of the request within the meaning of Article 12.5 of the GDPR. The

complainant then argues that the practical difficulties invoked by the defendant

stem exclusively from its own archiving choices (filing by day

and not by employee), which it cannot use to evade its obligations under the

GDPR. According to him, it would suffice to sort the relevant records and scan them to

send a copy.

iii. Position of the Litigation Chamber

43. In light of the principles recalled above, the Litigation Chamber considers that the

defendant has not established the manifestly unfounded or excessive nature of the

complainant's request within the meaning of Article 12.5 of the GDPR, for the following reasons.

44. First, the Litigation Chamber notes that the complainant's request cannot be considered

manifestly unfounded within the meaning of Article 12.5 of the GDPR. As

recalled above, such a classification can only be applied in

exceptional cases where, following an objective approach, the requirements of Article 15 of the GDPR are clearly

not met. In this instance, however, the complainant's request fulfills

all the conditions to which the exercise of the right of access is subject. Indeed, the
access request originates from an identified data subject, who requests the

disclosure of personal data concerning them and which are actually

processed by the defendant in its capacity as data controller, namely the timesheets

Page 11 of the defendant's submissions: "The timesheets are filed by day worked in several
dozens of binders. They are not filed by employee. Therefore, S.A. Y must isolate Mr.
X's timesheets before Mr. X can consult them and, if necessary, make a copy." Decision on the merits 97/2026 — 15/24

of timesheets that she herself completed in the course of performing her

employment. The defendant, moreover, provides no evidence to support the claim that

the request was manifestly unfounded, its entire argument being in fact

based on the allegedly excessive nature of the request, examined below.

45. Secondly, regarding the excessive nature of the request, the Litigation Chamber

observes that the defendant's allegation of unfairness demonstrates that the plaintiff's request

was made with abusive intent within the meaning of the aforementioned case law (paragraphs

36 to 40). It should be recalled that, pursuant to Article 12.5(2) of the GDPR, it is the

controller who bears the burden of establishing whether the request is manifestly unfounded or

excessive, according to the strict requirements outlined above. However, the

defendant relied exclusively, in support of its refusal, on the workload

that fulfilling the request would entail, due to its own archiving system.

The Litigation Chamber notes, moreover, that the defendant only raised the argument

based on Article 12.5 of the GDPR at the stage of its submissions before the Litigation Chamber,

without having invoked this qualification during the exchanges preceding

the complaint.

46. Thirdly, the application of the abuse of rights test to the present case does not allow

the establishment of an abusive intent on the part of the complainant, either with regard to its

objective element or with regard to its subjective element.

- Regarding the objective element, the objective pursued by Article 15 of the GDPR cannot

be considered as not having been achieved in this case. The plaintiff's request

specifically seeks to access the personal data

24
concerning the data processed by the defendant and to verify its accuracy, namely

the consistency between the services he himself recorded on the handwritten forms

and those transcribed into the defendant's computer system.

Even assuming that the complainant was also motivated by a reason unrelated to the

purposes referred to in recital 63 of the GDPR — which is not the case —, this circumstance

would remain irrelevant since the CJEU has ruled that the obligation to provide a

copy applies to the data controller, even when this request is

motivated by a purpose unrelated to those referred to, because, according to recital 63, the pursuit

of a possible unrelated purpose, assuming it to be established, would not be such as to deprive

the request of the objective that Article 15 of the GDPR is intended to serve.

24EDPB, Guidelines 01/2022 on the right of access, point 10: “The purpose of the right of access is to enable data subjects to understand how their personal data is processed and the consequences of such processing, and to verify the accuracy of the data processed without having to justify their intent. In other words, the objective of the right of access is to provide natural persons with sufficient, transparent, and easily accessible information on data processing, regardless of the technologies used, and to enable them to verify different aspects of a particular processing activity under the GDPR (e.g., lawfulness, accuracy).”

25CJEU, Order of 27 May 2024, Addiko Bank, C-312/23, EU:C:2024:458. Decision on the merits 97/2026 — 16/24

- Regarding the subjective element, the defendant remains unable to provide any

evidence whatsoever to establish that the complainant intended to artificially create

the conditions required to obtain an advantage under the GDPR. The

complainant did not, in fact, provide his personal data to the defendant

on his own initiative with a view to triggering processing and being able to rely on it

later: the disputed timesheets were drawn up in the normal course of
performing a pre-existing employment relationship. The provision of this

data and the filing of the access request are, moreover, separated by several

years—the request of May 10, 2021, concerns records created since May 10,

2016. Neither of the two cumulative elements of abuse of rights is therefore present in

this case.

47. Fourth, and contrary to the defendant's assertion, the Litigation Chamber

notes that the volume of documents covered by the request remains, in

this instance, limited and easily identifiable. Since the timesheets were created at a rate of

one per week per worker, the complainant's request, covering the period from

May 10, 2016, to May 10, 2021, concerns approximately 250 documents, all

clearly identified by worker and by time period. This is therefore by no means

a general and indiscriminate request targeting all data potentially

processed by the defendant (such as emails, HR documents, etc.), but rather a

request focused on a single category of documents.

48. Fifth, even assuming that the workload invoked by the defendant

is proven, this alone cannot render the request excessive within

the meaning of Article 12.5 of the GDPR. The EDPB expressly emphasizes this in its Guidelines

01/2022 cited above, stating that "the fact that it would take a great deal of time and effort for the

controller to provide the information or a copy to the data subject

cannot, in itself, render a request excessive," since many

processing activities inherently involve significant effort to satisfy

data subject requests. Furthermore, the right of access does not include any

general reservation regarding proportionality concerning the efforts that the

controller must make to respond to the request of the data subjects

under Article 15 of the GDPR. Moreover, the term "appropriate" appearing

in particular in Article 12.1 of the GDPR cannot be interpreted as "a means of limiting

the scope of the data covered by the right of access". It follows that the alleged burden

cannot in itself justify a refusal, especially when it results, as

26EDPB, Guidelines 01/2022 on the right of access, paragraph 188.
27
Ibid., paragraph 166.
28Ibid., paragraph 129. Decision on the merits 97/2026 — 17/24

in this case, organizational and administrative constraints arising from the archiving system

that the defendant imposed upon itself. Such a refusal is only likely

to occur in the presence of an established abusive intent, in accordance with the requirements recalled

above. Any other interpretation would render the right enshrined in Article 15 of the

GDPR meaningless and would be contrary to both Article 12.2 and Article 25 of the same Regulation, which

require the controller, respectively, to facilitate the exercise of the data subject's right

of access and to implement, from the design stage of the processing,

the appropriate technical and organizational measures to ensure its effective exercise.

49. Finally, it appears from the exchanges between the parties that the defendant intended

to criticize the complainant for the lack of justification for his request for a copy (see in particular

paragraph 7). The Litigation Chamber reiterates in this regard that the data subject is

under no obligation whatsoever to justify the reasons why he intends to exercise his right of access.

The CJEU has expressly ruled that neither Article 12.5 nor Articles 15.1 and 15.3 of the GDPR

make the provision, free of charge, of a first copy conditional upon the

data subject invoking a reason justifying his request. The defendant could not, therefore,

make its response conditional upon the communication of such reasons.

50. In light of all these elements, the Litigation Chamber considers that the defendant has not established either the manifestly unfounded or excessive nature of the complainant's request within the meaning of Article 12.5 of the GDPR. It could not, therefore, legitimately rely on this provision to refrain from complying with the request for a copy.

II.3. Regarding compliance with other procedures for exercising the right of access (Articles 12.2, 12.3 and 12.4 of the GDPR)

51. Article 12 of the GDPR, concerning how data subjects may exercise their rights, stipulates, in particular, that the data controller must facilitate the exercise of rights by the data subject (Article 12.2 of the GDPR) and provide them with information on the measures taken in response to their request as soon as possible and at the latest within one month of their request (Article 12.3 of the GDPR). When the data controller does not intend to comply with the request, they must notify their refusal within one month, providing information that an appeal against this refusal may be lodged with the data protection supervisory authority (Article 12.4 of the GDPR).

52. In the event of a refusal to comply with a request, the Litigation Chamber

emphasizes the importance of providing reasons for this refusal. Article 12.4 of the GDPR must be read in

CJEU, FT (Copies of the medical file), op. cit., paragraphs 38 to 52. Decision on the merits 97/2026 — 18/24

in conjunction with Article 12.2: to facilitate the exercise of the rights of data subjects,

a data controller must state in clear and plain language the

reason for their refusal. If this refusal is based on a legal provision, the relevant legal provision

must be communicated to the data subject. Indeed, it would be difficult for

a data subject to assess the validity of a refusal and to exercise their rights if the

reason for such a refusal is based on an incorrect or missing legal basis.

53. The defendant maintains that it did not refuse to comply with the plaintiff's request, but

implemented a specific procedure that the plaintiff was required to follow in order to obtain

a copy of the disputed documents. This procedure, communicated to the plaintiff, stipulated that

the plaintiff must make an appointment at least seven business days in advance for a consultation

on-site at the defendant's registered office. The defendant justifies this approach as follows:

"Although isolating all of Mr. X's roadmaps over several years

requires considerable work, Company Y is willing to undertake this work

provided that Mr. X complies with the established procedure. Company Y did not refuse

Mr. X's request when it was in a position to do so, but established a

procedure to be followed, given the scale of the work involved in this request."

54. While asserting that it did not refuse to comply with the request, the defendant maintains

at the same time that the request is manifestly unfounded or, at the very least, excessive within

the meaning of Article 12.5 of the GDPR, and that it is therefore entitled to reject it.

55. The Litigation Chamber cannot accept this presentation of the facts. It has been established that the

complainant's request was clear and that the defendant has, in fact, refused to comply with it

since May 10, 2021, on the grounds of the workload it entailed. In doing so, the

defendant never formally notified the complainant of a refusal as required

by Article 12.4 of the GDPR. On the contrary, it left the complainant in limbo,

offering him alternative procedures that placed a burden on him that should have fallen

on the data controller, thereby simultaneously disregarding

the obligation to facilitate the exercise of rights imposed by Article 12.2 of the GDPR. By

making the release of documents conditional upon the complainant coming to its premises and by
requiring him to identify the records he wishes to copy himself, the defendant

is in fact transferring to him the burden that falls on him as the data controller.

56. The Litigation Chamber further notes that the on-site consultation solution proposed

by the defendant raises an additional difficulty with regard to the GDPR. The service records

contain not only the complainant's personal data, but
also the names and information relating to the defendant's clients. However, allowing the

complainant to freely consult the filing cabinets on the company's premises would expose him

30Defendant's Submissions, p. 13. Decision on the Merits 97/2026 — 19/24

necessarily to the personal data of third parties, in violation of the reservation

provided for in Article 15.4 of the GDPR, which stipulates that the right to obtain a copy may not

infringe on the rights and freedoms of others. This element supports the analysis that it was

the defendant's responsibility, as the data controller, to extract
the relevant records itself and, where applicable, to anonymize the data

relating to third parties before communicating them to the complainant, rather than delegating this

task to the data subject.

57. Faced with the complainant's access request, if the respondent did not intend to comply within the one-month period stipulated by Article 12.3 of the GDPR, several alternative avenues were available to it, provided the conditions for application were met. It could have, in particular, in accordance with the same article, informed the complainant of an extension of the response period by two additional months, provided that it notified the complainant of this extension within one month of receiving the request and provided reasons for it. It could also have formally notified the complainant of a reasoned refusal in accordance with Article 12.4 of the GDPR, where appropriate by invoking and justifying the manifestly unfounded or excessive nature of the request within the meaning of Article 12.5 of the GDPR, or, on the same grounds, required payment of reasonable costs for complying with it. She could have finally invoked Article 15.4 of the

GDPR to refuse, in whole or in part, to provide the requested copies, insofar as

this would infringe upon the rights and freedoms of others. However, the defendant did not pursue

any of these avenues. She merely offered an on-site consultation, without ever
notifying the complainant of a formal response to their request for a copy within the time limit prescribed by

Article 12.3 of the GDPR, thus leaving the access request unanswered.

58. It follows from all of the above that the defendant failed to comply with its obligations under Article 12(2), (3) and (4) of the GDPR by failing to respond within the prescribed time limits to the complainant's request for a copy, by failing to formally notify the complainant of the reasons for its inaction, and by not facilitating the exercise of the complainant's right of access.

II.4. Conclusions

59. Based on the foregoing, the Litigation Chamber finds that the defendant
has committed the following violations:

- The defendant, in practice, refused to comply with the complainant's request for copies of his

service records, without formally notifying him of this refusal. By merely

offering the complainant an on-site consultation procedure that placed the burden of identifying and reproducing the documents on him, the defendant did not

facilitate the complainant's exercise of his right of access and failed to comply with its obligations. Decision on the merits 97/2026 — 20/24

incumbent upon it. The defendant thus violated Articles 12.2, 12.3 and 12.4, as well as

Articles 15.1 and 15.3 of the GDPR.

- The defendant failed to comply with the request for a copy within the prescribed time limits.

The complainant submitted an initial access request on May 10, 2021, and reiterated it

on several occasions, notably on January 17, 2022, and during 2023, without

ever receiving the requested copy. As of the date of this decision, the

request remains unanswered, in violation of Article 12.3 of the GDPR.

60. The Litigation Chamber gave the defendant the opportunity to comment on

the applicability of Article 15.4 of the GDPR to the complainant's requests (paragraph 16). The

defendant, however, based its argument exclusively on the allegedly excessive nature

of the request and its purported lack of precision, without invoking or demonstrating

that the exception provided for in Article 15.4 of the GDPR would apply to justify a refusal
to provide the requested copy, in whole or in part.

61. The Litigation Chamber nevertheless considers that it cannot rule out that this provision

is likely to apply in this case, given the nature of the documents in question. It will therefore be up to the defendant, when implementing this decision,

to examine whether it is necessary to partially anonymize the information relating to

third parties appearing on the service records.

62. The Litigation Chamber recalls that Article 15.4 of the GDPR provides that the right to obtain
a copy within the meaning of Article 15.3 of the GDPR may not infringe upon the rights and freedoms

of others. The concept of “others” must be interpreted broadly: it covers any person

or entity other than the data subject exercising their right of access, so that

the rights and freedoms of the controller

itself may be taken into consideration, such as the preservation of the confidentiality of its trade secrets

or the protection of its intellectual property, as well as the rights of third parties whose personal data
may appear in the requested documents.

63. The Litigation Chamber emphasizes, however, that this exception provided for in Article 15.4 of the

GDPR must, like any exception, be interpreted and applied restrictively. Recital 63 of the GDPR expressly states: “These considerations should not lead to refusing to provide any information to the data subject.” In other words, Article 15.4 of the GDPR cannot be used as grounds for a blanket refusal to provide a copy, but at most can justify, where appropriate, targeted measures such as partial anonymization of information relating to third parties, when its disclosure would disproportionately infringe upon their rights. Decision on the merits 97/2026 — 21/24

III. Sanctions and corrective measures

64. Pursuant to Article 100, § 1, of the LCA, the Litigation Chamber has the power to:

“1° dismiss the complaint;

2° order a dismissal;

3° suspend the proceedings;

4. Propose a settlement;

5. Issue warnings and reprimands;

6. Order compliance with the data subject's requests to exercise their rights;

7. Order that the data subject be informed of the security issue;

8. Order the freezing, limitation, or temporary or permanent prohibition of processing;

9. Order the processing to be brought into compliance;

10. Order the rectification, restriction, or erasure of data and notification of this to the data recipients;

11. Order the withdrawal of accreditation of certification bodies;

12. Impose penalty payments;

13. Impose administrative fines;

14. Order the suspension of cross-border data flows to another State or an international organization;

15. To forward the file to the Public Prosecutor's Office in Brussels, which will inform it of the

follow-up actions taken on the case;

16. To decide on a case-by-case basis whether to publish its decisions on the website of the Data Protection Authority.

65. The Litigation Chamber considers that, based on the aforementioned facts, it is necessary to

conclude that the defendant violated Articles 12.2, 12.3, 12.4, 15.1, and 15.3 of the GDPR, and that Article

12.5 of the GDPR cannot, in this instance, justify the refusal of the complainant's request.

These violations justify the Chamber taking a decision in accordance with Article

100, §1, 5° of the Belgian Law on Access to Information Technology (LCA), more specifically, issuing a reprimand to the defendant.

66. Regarding the violation of Article 12.2 of the GDPR, the Litigation Chamber emphasizes that

this provision, which requires the data controller to facilitate the exercise of the rights

of data subjects, is closely linked to Articles 12.3, 12.4,

15.1 and 15.3 of the GDPR, on which the Litigation Chamber invited the parties to reach an agreement

in its letter of 25 February 2025 (paragraph 20). Articles 12 and 15 of the GDPR being

intrinsically linked in that they jointly govern the procedures for exercising the right

of access, the finding of a violation of Article 12.2 does not prejudice the rights of the

defendant, since the latter was expressly invited to comment
on the data subject's compliance with the procedures for exercising the right of access in its Decision on the merits 97/2026 — 22/24

in its entirety, and could reasonably expect to have to defend itself on this aspect,

which constitutes a method of exercising this right.

67. The Litigation Chamber accompanies this reprimand with an order to comply, within

one month of notification of this decision, with the exercise of the complainant's right of access and copy under Article 15.3 of the GDPR, based on Article 100, paragraph 6 of the LCA.

When

executing this order, the defendant may find it useful to take into account the

foregrounded considerations concerning the scope and application of Article 15.4

of the GDPR (see paragraphs 60 to 63).

68. The defendant has one month from the date of notification of this

decision to provide the complainant with a copy of all service records

for the period from May 10, 2016 to May 10, 2021, in accordance with Article 12.3 of the GDPR. If the

defendant intends to rely on the complexity of the request to benefit from the extended three-month period provided for by this same provision, it is incumbent upon it to provide

proof thereof and to inform the Litigation Chamber, as well as the complainant, without delay,

within the aforementioned one-month period.

69. In all cases, the defendant is required to provide the Litigation Chamber,

within the allotted time, with proof of the effective transmission of the documents to the

complainant, in order to allow the Chamber to verify the proper execution of this decision.

70. The Litigation Chamber considers that a reprimand, accompanied by an order to comply with the complainant's request for access and a copy, constitutes, in this case, a proportionate

and sufficient measure. This assessment takes into account all the circumstances of the case,

and in particular the defendant's internal organization and resources, as it

itself described throughout the proceedings, arguing that fulfilling

the access request would represent a considerable workload for it. While this

circumstance, as mentioned above, does not affect the existence of the violations

found, it remains relevant at this stage of the assessment of the

corrective measure. Indeed, imposing an administrative fine in addition to the order to

compliance, which will itself require internal resources for its execution,

would appear disproportionate to the objective pursued, which is primarily to ensure the

restoration of the complainant's rights and the defendant's future compliance with the

requirements of the GDPR. Decision on the merits 97/2026 — 23/24

IV. Publication of the Decision

71. Given the importance of transparency regarding the decision-making process of the Litigation Chamber,

this decision is published on the APD website. However, it is not

necessary for this purpose for the parties' identifying data to be directly

communicated.

FOR THESE REASONS,

the Litigation Chamber of the Data Protection Authority decides, after

deliberation:

- Pursuant to Article 58.2.c) of the GDPR and Article 100, § 1, 6° of the LCA,

to order the defendant to comply, within one month of notification of

this decision, with the complainant's right of access pursuant to Article

15.3 of the GDPR, in accordance with the procedures specified in paragraphs 67 to 69 and the

considerations raised in paragraphs 60 to 63 of this decision.

- Pursuant to Article 100, § 1, 5° of the LCA, to issue a reprimand to the

defendant for violating Articles 12.2, 12.3, 12.4, 15.1 and 15.3 of the GDPR,

Article 12.5 of the GDPR cannot, in this instance, justify the refusal of the

complainant's request.

In accordance with Article 108, § 1 of the LCA, an appeal against this decision may be lodged,

within thirty days of its notification, with the Market Court (Brussels Court of Appeal), with the Data Protection Authority as the defendant.

Such an appeal may be lodged by means of an interlocutory application, which must contain the information listed in Article 1034ter of the Judicial Code.

The interlocutory application must be filed with the Registry of the Market Court in accordance with Article 1034quinquies of the Judicial Code.

The application must, under penalty of nullity, contain:

1° the date of the day, month, and year;

2° the applicant's surname, first name, and address, as well as, where applicable, their capacity and national registration number or company number;

3° the surname, first name, address, and, where applicable, capacity of the person to be summoned;

4° the subject matter and a summary of the grounds for the application;

5° the name of the judge seized of the application;

6° the signature of the applicant or their lawyer. Decision on the merits 97/2026 — 24/24

32
judicial, or via the e-Deposit information system of the Federal Public Service Justice (Article 32ter of the

Judicial Code).

(Se). Hielke H IJMANS

Director of the Litigation Chamber

32The application, together with its annex, is sent, in as many copies as there are parties involved, by registered letter to the clerk of the court or filed with the registry.