| APD/GBA - 94/2026 | |
|---|---|
| Authority: | APD/GBA (Belgium) |
| Jurisdiction: | Belgium |
| Relevant Law: | Article 17 GDPR Article 31 GDPR Article 56 GDPR Article 58(2)(i) GDPR Article 83 GDPR Art.100 LCA |
| Type: | Complaint |
| Outcome: | Other Outcome |
| Started: | 28.08.2022 |
| Decided: | 28.04.2026 |
| Published: | 28.04.2026 |
| Fine: | 1000 EUR |
| Parties: | X (Data Subject) Foundation Y (Data Controller) |
| National Case Number/Name: | 94/2026 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | French |
| Original Source: | APD (in FR) |
| Initial Contributor: | Orla |
The DPA fined an NGO €1,000 for failing to cooperate with the DPA in accordance with Article 31 GDPR in course of a complaint procedure concerning a data subject’s erasure request.
English Summary
Facts
On 28 August 2022, a data subject lodged a complaint with the French DPA against an NGO (the controller), concerning an alleged failure to respond to an erasure request. On 15 March 2023, the French DPA initiated a procedure to identify the lead supervisory authority, in accordance with Article 56 GDPR. The Belgian DPA declared itself the lead supervisory authority.
On 24 April 2023, both parties were informed of the deadlines for submitting written submissions. No submissions were filed by either party. On 7 July 2025, the DPA scheduled a hearing for 30 October 2025, but neither party attended.
On 7 November 2025, the controller requested a copy of the case file, which was sent on 14 November 2025. On the same day, the controller informed the DPA that it had erased the data subject’s personal data and provided proof.
On 27 January 2026, the DPA informed the controller of its intention to impose an administrative fine against it. On 11 February 2026, the controller responded that it had not effectively received the registered letters or postal notices, as they had arrived during holiday or absence periods. It also claimed that it had not become aware of the erasure request earlier because the data subject had not used the official channel. The controller further stated that it had acted immediately after becoming aware of the case and argued that even a €1,000 fine would constitute a significant burden for a non-profit organisation with no employees. On 18 February 2026, the DPA asked the controller to submit its 2025 financial documents. By 23 March 2026, the DPA had not received a response.
Holding
- Resolution of the underlying erasure complaint:
The DPA noted that, on 14 November 2025, the controller had erased the data subject’s personal data and therefore considered the erasure-related matter resolved.
- Violation of Article 31 GDPR and subsequent administrative fine calculation:
However, the DPA found a violation of Article 31 GDPR. The controller had failed to attend the hearing scheduled for 30 October 2025, which the DPA had convened in order to obtain additional information necessary to decide the case. According to the DPA, where it summons the parties to a hearing for that purpose, failure to attend amounts to a lack of cooperation with the supervisory authority.
The DPA held that cooperation with supervisory authorities is essential to the effectiveness of GDPR enforcement. It further held that controllers must organise themselves so as to receive and respond to official communications sent through the channels they use or have made public, such as postal or electronic communication. The controller’s failure to take notice of such communications therefore constituted negligence.
The DPA imposed a fine of €1,000 under Article 58(2)(i) GDPR and Article 83 GDPR for the violation of Article 31 GDPR regarding the controller’s failure to cooperate with the supervisory authority.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the French original. Please refer to the French original for more details.
1/12 Litigation Chamber Decision on the merits 94/2026 of April 28, 2026 Case number: DOS-2023-01272 Subject: Complaint regarding the lack of response to a request for erasure The Litigation Chamber of the Data Protection Authority; Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the “GDPR”; Having regard to the Law of December 3, 2017 establishing the Data Protection Authority (hereinafter referred to as the “LCA”); Having regard to the Rules of Procedure as approved by the Chamber of Representatives on December 20, 2018 and published in the Belgian Official Gazette on January 15, 2019; 2 Having regard to the documents in the file; Has taken the following decision concerning: The complainant: X, residing at […], hereinafter referred to as “the complainant” The defendant: Foundation Y, whose registered office is located at […], registered under company number […], hereinafter referred to as “the defendant” 1 The Data Protection Authority (DPA) notes that the revised Organic Law entered into force on June 1, 2024. It applies only to complaints, mediation cases, applications, inspections, and proceedings before the Litigation Chamber initiated on or after that date. Cases initiated before June 1, 2024, such as this case, are subject to the provisions of the previous version of the Data Protection Act (DPA), accessible here: https://www.autoriteprotectiondonnees.be/publications/loi-organique-de-l-apd.pdf 2. The new rules of procedure of the Data Protection Authority (DPA), resulting from the amendments introduced by the Law of December 25, 2023, amending the Law of December 3, 2017, establishing the Data Protection Authority (DPA), entered into force on June 1, 2024. They apply only to complaints, mediation cases, requests, inspections, and proceedings before the Litigation Chamber initiated on or after that date. Cases initiated before June 1, 2024, are subject to the rules of procedure as they existed before that date. Decision on the merits 94/2026 — 2/12 I. Facts and procedure 1. The complaint concerns the failure to respond to a request for erasure. The respondent is a non-profit foundation. 2. On August 28, 2022, the complainant filed a complaint with the French Data Protection Authority (CNIL) against the defendant. 3. On March 15, 2023, the CNIL initiated proceedings as provided for in Article 56 of the GDPR in order to identify the lead supervisory authority. 4. The Data Protection Authority (DPA) declares itself the lead supervisory authority. 5. On April 24, 2023, the parties concerned were notified by registered mail of the provisions set forth in Article 95, § 2, and Article 98 of the LCA (Law on Administrative Procedure). They were also informed, pursuant to Article 99 of the LCA, of the deadlines for submitting their pleadings. No pleadings were filed by either party. 6. On July 7, 2025, the Litigation Chamber summoned the parties to a hearing on October 30, 2025. Neither party appeared at the hearing despite the summons from the Litigation Chamber. 7. On November 3, 2025, the Litigation Chamber sent the parties the minutes of the hearing for their information. 8. On November 7, 2025, the defendant requested a copy of the case file (Art. 95, §2, 3° LCA), which was sent to her on November 14. 9. On November 14, 2025, the Litigation Chamber sent a copy of the case file to the defendant. 10. On the same day, the defendant informed the Litigation Chamber that she had deleted the plaintiff's data that same day and provided proof of this. She explained that she had not received the letters inviting her to submit her pleadings or summoning her to the hearing. She justified her delay in responding to the plaintiff's exercise of his right. 11. On January 27, 2026, the Litigation Chamber informed the defendant of its intention to impose an administrative fine and its amount, in order to give the defendant an opportunity to defend herself before the sanction was imposed. 12. On February 11, 2026, the Litigation Chamber received the defendant's response regarding the intention to impose an administrative fine and its amount. The defendant argued that she had not actually received the registered letter or the delivery notices from the post office and explained that the mailings arrived during periods of vacation or absence, which resulted in gaps in mail handling. She also explains that she was unaware of the expungement request before her Decision on the merits 94/2026 — 3/12 correspondence with the Data Protection Authority (DPA) because the complainant had not used the official channel to submit their request. Furthermore, she states that she reacted immediately after becoming aware of this request and alleges that this demonstrates a willingness to cooperate with the DPA. She supports the reasoning of the Litigation Chamber in the sanction form which states that the violation is minor, that she complied as soon as she became aware of the procedure, and that this is the first complaint against the defendant. She believes that a warning is sufficient. She also asserts that the proposed fine of €1,000 would constitute a significant burden for the foundation, which has no employees, and also highlights that it is a non-profit organization. 13. On February 18, 2026, the Litigation Chamber requested that the defendant send it the 2025 financial documents because their response to the sanction form did not contain them. 14. As of March 23, 2026, the Litigation Chamber had not received a response from the defendant. II. Reasoning Regarding the obligation to cooperate with the supervisory authority 15. Article 31 of the GDPR requires data controllers to cooperate with the supervisory authority in the following terms: “The controller and the processor and, where applicable, their representatives, shall cooperate with the supervisory authority, at its request, in the performance of its tasks.” 16. In this case, the defendant did not file any submissions nor did it appear at the hearing to which it had been summoned. The Litigation Chamber considers that the filing of submissions is an option available to the defendant in order to exercise its rights of defense. However, when the Litigation Chamber summons the parties to a hearing under Article 93 without such a hearing being requested by the parties themselves, this means that it needs additional information to be able to make a fully informed decision. The Litigation Chamber considers that by failing to appear at the hearing, the defendant did not cooperate with it. 17. The Litigation Chamber therefore finds that the defendant has violated Article 31 of the GDPR. Regarding the deletion of the complainant's data 18. The defendant informed the Litigation Chamber on November 14, 2025, that it had deleted the complainant's data that same day. It explains that it did not receive a request from the complainant to delete the data. However, it explains that while deleting the complainant's data, it found an article he had intended to publish that contained his deletion request. The complainant allegs that he sent a request to delete his data and provides as proof of sending a screenshot showing a preview of a message asking the defendant to delete his data. 19. The Litigation Chamber finds that the complainant's screenshot does not prove the actual sending of his deletion request. However, it notes that the complainant's data was indeed deleted by the defendant on November 14, 2025, and therefore considers that the grievance must be deemed resolved. 20. The Litigation Chamber takes into account the fact that the data was deleted in its deliberations. 21. The Litigation Chamber wishes to reiterate that the GDPR requires the data controller to respond to a data subject's request to exercise their rights within one month of receiving the request. 22. The Litigation Chamber therefore takes into account the fact that the defendant deleted the complainant's data and thus considers the complainant's grievance to be resolved. III. Sanction 23. The Litigation Chamber decided to impose an administrative fine, the purpose of which is not to put an end to an infringement committed, but rather to ensure the effective application of the rules of the GDPR. As is clear from recital 148, the GDPR provides that sanctions, including administrative fines, may be imposed for any serious breach—therefore including the first finding of a breach—in addition to, or in place of, the appropriate measures that are imposed. The Litigation Chamber demonstrates below that the violation of Article 31 of the GDPR committed by the defendant is in no way a minor violation and that the fine would not constitute a disproportionate burden on a natural person within the meaning of recital 148 of the GDPR, two cases which would allow for waiving a fine. The fact that this is a first 3 Article 12.3 of the GDPR.4Recital 148 states the following: “In order to strengthen the application of the rules of this Regulation, sanctions, including administrative fines, should be imposed for any infringement of this Regulation, in addition to or instead of appropriate measures imposed by the supervisory authority under this Regulation.” In the event of a minor infringement, or if the fine that could be imposed constitutes a disproportionate burden for a natural person, a warning may be issued instead of a fine. However, due account must be taken of the nature, seriousness, and duration of the infringement, the intentional nature of the infringement and the measures taken to mitigate the damage suffered, the degree of responsibility or any relevant previous infringements, the manner in which the supervisory authority became aware of the infringement, compliance with measures ordered against the controller or processor, the application of a code of conduct, and any other aggravating or mitigating circumstances. The application of sanctions, including administrative fines, should be subject to appropriate procedural safeguards in accordance with the general principles of EU law and the Charter, including the right to effective judicial protection and due process. [emphasis added] Decision on the merits 94/2026 — 5/12 The finding of a GDPR infringement by the defendant does not in any way affect the possibility for the Litigation Chamber to impose an administrative fine. The Litigation Chamber imposes an administrative fine pursuant to Article 58(2)(i) of the GDPR and Articles 83 and 100 of the LCA. The administrative fine instrument is not intended to put an end to infringements. 24. In view of Article 83 of the GDPR and the case law of the Market Court, the Litigation Chamber provides concrete reasons for imposing an administrative penalty: 25. For the violation of Article 31 of the GDPR, in accordance with Article 83.4(a) of the GDPR, the maximum administrative fine may be up to €10,000,000 or up to 2% of the company's worldwide annual turnover for the preceding financial year, whichever is higher. Seriousness of the violation a. Article 83.2(a) of the GDPR - The nature, seriousness, and duration of the violation: Regarding the nature of the violation, the Litigation Chamber notes that cooperation with the supervisory authority is an essential element that enables the effectiveness of data protection regulation in the European Union. Without cooperation with the supervisory authority, the effectiveness of data protection regulations is greatly diminished. Cooperation with the supervisory authority is therefore an important element of the GDPR that must be protected. Regarding the seriousness of the breach, the Litigation Chamber observes that if the data controller does not cooperate with the supervisory authority, this can have consequences for all individuals whose data it processes, who will see the effectiveness of the protection of their data protection rights diminished. In this particular case, a request for erasure could have been resolved quickly if the defendant had cooperated directly with the supervisory authority. The lack of cooperation contributed to prolonging the proceedings and delaying the effective exercise of the rights of the person concerned. Regarding the duration of the violation, the Litigation Chamber notes that it summoned the defendant on July 2, 2025, to a hearing scheduled for October 30, 2025, which she failed to attend. The defendant only responded to the complaint after receiving the transcript of the hearing. The violation of non-cooperation therefore extends from October 30, 2025, the date of the missed sentence, to November 14, 2025, the date on which the defendant provided information despite the close of proceedings. b. Article 83.2.b) of the GDPR – The intentional and negligent nature of the infringement: In this case, according to the Litigation Chamber, there is no manifest intention on the part of the defendant to deliberately infringe Article 31 of the GDPR, but the Litigation Chamber finds that there was negligence, which meets the requirements of the case law of the Court of Justice of the European Union. The obligation to cooperate provided for in Article 31 of the GDPR implies that the Data Protection Authority must be able to effectively contact the controller through the communication channels it uses or has made public, such as postal mail or email. It is therefore incumbent upon the 5 Brussels Court of Appeal (Market Court Section), X v. APD, Judgment 2020/1471 of 19 February 2020. 6See Judgment C-807/21, Deutsche Wohnen, ECLI:EU:C:2023:950, paragraph 78. Decision on the merits 94/2026 — 6/12 the data controller to put in place an organization enabling it to be aware of official communications addressed to it and to react to them appropriately. Failure to comply with this duty of care, consisting of not being aware of the content of the correspondence received, constitutes negligence which has resulted in an infringement of Article 31 of the GDPR. c. Article 83.2.g) of the GDPR – Categories of personal data concerned by the infringement: In this case, the infringement identified by the Litigation Chamber does not relate to the disputed processing but rather to an obligation of the data controller that was not fulfilled. Therefore, the nature of the data processed by the defendant is not directly called into question in the assessment of the infringement. Finally, it also appears that the processing carried out by the defendant generally concerns data that does not fall under the special categories of data, except where the data subject makes public data that falls under the special categories of data on their own initiative by mentioning it in an article. This criterion is considered neutral in this case. 26. Based on an assessment of the aforementioned factors, the seriousness of the infringement is established. The Litigation Chamber concludes, taking into account the detailed elements above, that this is a minor infringement. In accordance with paragraph 60 of the EDPB Guidelines, the Litigation Chamber must set the starting amount for the subsequent calculation between 0 and 10% of the applicable maximum legal amount.7 Given that the defendant committed the infringement negligently and clearly did not do so intentionally, the Litigation Chamber decides to reduce the starting amount. 27. The Litigation Chamber will set the starting amount for the subsequent calculation at 5% of the maximum legal amount set out in Article 83.4 of the GDPR. The company's turnover as a relevant factor to be taken into account for the purpose of imposing an effective, dissuasive, and proportionate fine pursuant to Article 83.1 of the GDPR 28. In accordance with Article 83.1 of the GDPR, the Litigation Chamber must ensure that the administrative fines imposed are effective, proportionate, and dissuasive. It therefore also establishes a distinction in the initial amounts based on the size of the company. 29. Articles 83.4 to 83.6 of the GDPR stipulate that the total worldwide annual turnover of the preceding financial year must be used for calculating the administrative fine. In this regarding this, the term "precedent" must be interpreted in accordance with the case law of the Court of Justice in matters of competition law, so that the relevant event 7 EDPB - Guidelines 04/2022 on the calculation of administrative fines under the GDPR (v2.1, 24 May 2023), paragraph 60. Decision on the merits 94/2026 — 7/12 for the calculation of the fine is the supervisory authority's decision on the fine, and not the time of the sanctioned infringement. 30. Since no financial statements more recent than those for the 2010 financial year are available, the Litigation Chamber does not have updated turnover figures to base its calculation on a more recent basis. Furthermore, the defendant has not provided more recent figures to the Litigation Chamber despite an explicit request. 31. The defendant's last available financial statement, for the 2010 fiscal year, shows a turnover of €106,665. In the absence of more recent, objectively verifiable data, the Litigation Chamber accepts this amount as the basis for calculation. 32. Based on the foregoing, the Litigation Chamber notes that 2% of the turnover in the last available financial statement represents €2,133.30, which is less than €10,000,000. The maximum administrative fine is therefore €10,000,000, in accordance with Article 83.5 of the GDPR. In concrete terms, this leads to the following starting amount: ▪ Regarding the violation of Article 31 of the GDPR, the Litigation Chamber set the starting amount for the subsequent calculation at 5% of the maximum legal amount, which is repeated in Article 83.5 of the GDPR. In this case, this results in a starting amount of €500,000. 33. In accordance with the EDPB9 Guidelines, the Litigation Chamber may, for companies with an annual turnover of less than €2 million, consider continuing the calculation on the basis of an amount between 0.2% and 0.4% of the initial amount set. The Litigation Chamber concludes that, in this case, this is appropriate, which leads to the following adjusted amount: ▪ Regarding the violation of Article 31 of the GDPR, the initial amount of €500,000 is reduced to €1,500 (0.3% of the initial amount). Aggravating and Mitigating Circumstances 34. According to the GDPR, after assessing the nature, severity, and duration of the breach, whether the breach was intentional or negligent, and the categories of personal data affected by the breach (see above), the supervisory authority must take into account other aggravating or mitigating factors as set out in Article 83.2 of the GDPR. a. Article 83.2(c) of the GDPR – Any measure taken by the controller or processor to mitigate the damage suffered by the data subjects: The Litigation Chamber takes into account the fact that the defendant after receiving the transcript of the hearing, insisted on deleting the complainant's data in order to resolve the initial grievance raised against it by the complainant. 8EDPB - Guidelines 04/2022 on the calculation of administrative fines under the GDPR (v2.1, 24 May 2023), paragraph 131. 9EDPB - Guidelines 04/2022 on the calculation of administrative fines under the GDPR (v2.1, 24 May 2023), paragraph 65. 10EDPB - Guidelines 04/2022 on the calculation of administrative fines under the GDPR (v2.1, 24 May 2023), paragraph 70. Decision on the merits 94/2026 — 8/12 b. Article 83.2.d) of the GDPR - The degree of responsibility of the controller or processor, taking into account the technical and organizational measures they have implemented pursuant to Articles 25 and 32: Does not apply. c. Article 83.2.e) of the GDPR - Any relevant infringement previously committed by the controller or processor: The Litigation Chamber notes that this is the first complaint concerning the defendant. d. Article 83.2.f) of the GDPR - The degree of cooperation established with the supervisory authority with a view to remedying the infringement and mitigating its potential negative effects: Cooperation with the supervisory authority is the subject of this sanction. This criterion is therefore not taken into account either as an aggravating circumstance or as a mitigating circumstance. e. Article 83.2.h) of the GDPR - The manner in which the supervisory authority became aware of the infringement, in particular whether, and to what extent, the controller or processor notified the infringement: Does not apply. f. Article 83.2.i) of the GDPR - Where measures referred to in Article 58(2) have previously been ordered against the controller or the relevant processor for the same purpose, compliance with those measures does not apply. (g) of Article 83.2.j) of the GDPR - The application of codes of conduct approved pursuant to Article 40 or certification mechanisms approved pursuant to Article 42 does not apply. (h) of Article 83.2.k) of the GDPR - Any other aggravating or mitigating circumstances applicable to the specific circumstances, such as financial gains obtained or losses avoided, directly or indirectly, as a result of the infringement, does not apply. 35. The Litigation Chamber takes into account the fact that the defendant deleted the complainant's data after receiving the hearing transcript, despite not having appeared at the hearing, and that this is the first complaint against the defendant. This is considered a mitigating circumstance. The Litigation Chamber decides to reduce the fine from €1,500 to €1,000. 36. The Litigation Chamber concludes that no other circumstances are relevant enough to be taken into account as aggravating or mitigating circumstances. Harmonization with maximum amounts 37. The maximum fine in this case has already been calculated above. In accordance with Article 83.4(a) of the GDPR, this amount may be up to: €10,000,000 or up to 2% of the total worldwide annual turnover of the preceding financial year whichever is higher. 38. The defendant's turnover in 2010, the last year for which the defendant's financial statements are available, amounts to €106,665. The Litigation Chamber notes that 2% of the turnover in 2010 represents €2,133.30, which is less than €10,000,000. The maximum administrative fine therefore amounts to €10,000,000, in accordance with Article 83.5 of the GDPR. Decision on the merits 94/2026 — 9/12 39. The fine in this case amounts to €1,000, which is less than the maximum fine of €10,000,000. Effective, proportionate, and dissuasive effect A. Effectiveness 40. Recital 148 of the GDPR emphasizes that administrative fines must be imposed "[a] in order to strengthen the enforcement of the rules of this Regulation." The fine imposed must therefore be sufficiently high to achieve this objective. 41. The Litigation Chamber considers that the €1,000 fine is appropriate to strengthen the defendant's compliance with the principle of cooperation. B. Proportionality 42. The principle of proportionality implies that the amounts of fines cannot be disproportionate to the objectives pursued and that the fine imposed must be proportionate to the infringement, considered as a whole, taking into account in particular its seriousness. 43. In the present case, the infringement in question was deemed to be of low seriousness. In accordance with paragraph 60 of the EDPB Guidelines, in the case of infringements of low seriousness, the Litigation Chamber must set the starting amount for the subsequent calculation at between 0 and 10% of the maximum applicable statutory amount.11 The Litigation Chamber notes that the infringement concerned one of the pillars of the effectiveness of personal data protection. Therefore, the Litigation Chamber set the starting amount for the subsequent calculation at 5% of the maximum legal amount referred to in Article 83.5 of the GDPR. 44. However, the Litigation Chamber also takes into account the defendant's last known turnover which is why it only used 0.3% of the starting amount for calculating the fine (see above). At this stage, there is no concrete evidence to establish that the €1,000 fine would jeopardize the economic viability of the company or that the defendant would be financially unable to pay it. Indeed, the defendant explains that "its business has declined sharply in recent years and that its financial resources are now very limited." It explains that even a €1,000 fine would represent a significant burden for it. However, despite 11 EDPB - Guidelines 04/2022 on the calculation of administrative fines under the GDPR (v2.1, 24 May 2023), paragraph 60. Decision on the merits 94/2026 — 10/12 the explicit invitation from the Litigation Chamber to provide figures, the respondent provides no evidence of its reduction in financial resources. 45. Furthermore, the Litigation Chamber decided to reduce the fine by 500 euros due to the resolution, albeit belated, of the complainant's grievance by the respondent. 46. The Litigation Chamber considers the fine to be proportionate. C. Deterrent effect 47. When imposing a fine, the Litigation Chamber takes into account both specific and general deterrence. A fine is dissuasive when it deters an individual from violating the purposes and regulations set out in European Union law. 48. The deterrent effect of the fine must have two dimensions. It must deter the defendant against whom the fine is imposed from repeating the violation in the future, but it must also deter other data controllers from repeating the conduct constituting the first person's violation. 49. Several factors determine the deterrent effect of a fine: the nature and amount of the fine and the likelihood of the fine being imposed are decisive in this regard. A fine must be high enough to have a significant financial impact on the company committing the violation, while remaining proportionate to the seriousness of the violation. In other words, the deterrence criterion overlaps with that of effectiveness. It is important that companies cannot make financial profits based on unlawful processing of personal data. 50. In this case, the initial fine is reduced to €1,000. This amount remains sufficiently dissuasive to deter the defendant from repeating its violation of the GDPR. Furthermore, the aim is also to deter other companies from committing similar violations. This fine, proportionate to the seriousness of the violation and taking into account the defendant's turnover, aims to have both a specific and a general deterrent effect. 51. In view of the previous assessment of the relevant documents and the specific characteristics of this case, the Litigation Chamber considers it appropriate, pursuant to Articles 58(2)(i) and 83 of the GDPR and Article 100(1)(13) of the Swiss Federal Act on Administrative Procedure (FAAP) in conjunction with Article 101 of the FAAP, to impose on the defendant an administrative fine of €1,000 for the violation of Article 31 of the GDPR concerning the failure to respond to a summons from the supervisory authority. 52. All the factors set out above justify an effective, proportionate, and dissuasive sanction, as referred to in Article 83 of the GDPR, taking into account the assessment criteria contained therein. The Litigation Chamber draws attention to the fact that the other criteria of Article 83.2 of the GDPR are not, in this case, such as to lead to an administrative fine other than that defined by the Litigation Chamber in the context of this decision. Decision on the merits 94/2026 — 12/12 IV. Publication of the decision 53. Given the importance of transparency regarding the decision-making process of the Litigation Chamber, this decision is published on the website of the Data Protection Authority. However, it is not necessary for this purpose that the identifying data of the parties be directly communicated. FOR THESE REASONS, the Litigation Chamber of the Data Protection Authority decides, after deliberation: - Pursuant to Articles 58.2.i) and 83 of the GDPR and Article 100 of the Belgian Code of Administrative Procedure (LCA), to impose an administrative fine of €1,000 due to the defendant's violation of Article 31 of the GDPR. In accordance with Article 108, § 1 of the LCA, an appeal against this decision may be lodged, within thirty days of its notification, with the Market Court (Brussels Court of Appeal), with the Data Protection Authority as the defendant. Such an appeal may be lodged by means of an interlocutory application which must contain the information listed in Article 1034ter of the Judicial Code. The interlocutory application must be filed with the Registry of the Market Court in accordance with Article 1034quinquies of the Judicial Code, or via the e-Deposit information system of the Ministry of Justice (Article 32ter of the Judicial Code). (Sé). Hielke H IJMANS Director of the Litigation Division The application must contain, under penalty of nullity: 1° the date (day, month, and year); 2° the applicant's surname, first name, and address, as well as, where applicable, their capacity and national registration number or company number; 3° the surname, first name, address, and, where applicable, capacity of the person to be summoned; 4° the subject matter and a summary of the grounds for the application; 5° the name of the judge seized of the application; the signature of the applicant or their lawyer. 13 The application, together with its annex, is sent, in as many copies as there are parties involved, by registered letter to the clerk of the court or filed with the registry.




