Datatilsynet (Denmark) - 2023-31-0321
| Datatilsynet - 2023-31-0321 | |
|---|---|
| Authority: | Datatilsynet (Denmark) |
| Jurisdiction: | Denmark |
| Relevant Law: | Article 12(2) GDPR Article 12(3) GDPR Article 12(4) GDPR Article 15 GDPR |
| Type: | Complaint |
| Outcome: | n/a |
| Started: | |
| Decided: | |
| Published: | |
| Fine: | n/a |
| Parties: | n/a |
| National Case Number/Name: | 2023-31-0321 |
| European Case Law Identifier: | n/a |
| Appeal: | n/a |
| Original Language(s): | Danish |
| Original Source: | Datatilsynet (in DA) |
| Initial Contributor: | sf |
The DPA reprimanded a bank for making the reimbursement of a fee to a customer conditional upon the withdrawal of an access request, thus violating its obligation to facilitate the exercise of data subject rights, particularly by failing to respond in time.
English Summary
Facts
A customer of a bank ('the data subject'), suspected that their former spouse, who was employed by the same bank ('the controller'), was accessing their accounts and decided to switch banks. In order to make this change, the data subject was charged a number of fees, and subsequently filed a complaint with the Financial Appeals Board. The director of the bank offered to reimburse the fees in return for the case at the Appeals Board to be closed.
On 20 March 2023 the data subject agreed to the reimbursement and requested access to the employee's access log’s pertaining to the data subject's accounts between the period of 2015-2021. One day later the director made the reimbursement of the fees conditional upon the complainant giving up their access request.
20 June 2023 the controller informed the data subject that they requested the data subject's former spouse to explain and substantiate the access to the account. The former spouse stated that they where looking at the account as a customer and not an employee.
The controller investigated, however the logs of the use of the system did not go that far back. Correspondingly, the controller requested its data center to recover the logs but was faced with costs of about DKK 300,000 without the guarantee of the recovery being successful. The controller emphasised that customers may not request employees’ access logs, and that the costs would not be proportionate to the clarification which the data subject would receive. This was communicated to them.
Holding
The DPA, following the CJEU in C-579/21 Pankki S, maintained that the information appearing within the logs concerning employees access to a customer’s account are covered by the right of access in Article 15 GDPR. Nonetheless, considering the controller informed the data subject that the requested log information is no longer available, and that the requested logs do not fall under the retention obligation pursuant to Article 30 of the national Anti-Money Laundering Act, the DPA rejected the explanations of the controller regarding the requested logs.
Considering the data subject's access request, the DPA considers that the controller infringed Article 12(2) GDPR, whereby controllers are to facilitate the exercise of data subject rights.
The DPA emphasised that controller made the repayment of the fees conditional upon the complainant revoking their access request.
The DPA further considered that between 23 March 2023 and 20 June 2023 the controller did not reach out to the complainant. The DPA held that if that were the case, the controller should have, no later than a month after the data subject's request, informed the data subject about the reasoning, and possibility of complaining to the DPA or bringing the matter to court under Article 12(4) GDPR.
The DPA reprimanded the controller as regards the insufficient handling of the data subject’s request for access under Article 12(2), (3), (4) GDPR.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Danish original. Please refer to the Danish original for more details.
Skip the main navigation Financial Institution Criticized for Handling of Request for Access Date: May 28, 2026 Decision Private Companies Criticism Complaint Right of Access Exercise of Rights The Danish Data Protection Agency has determined that a financial institution’s handling of a request for access to log files did not comply with data protection regulations Case Number: 2023-31-0321. Summary The Danish Data Protection Agency has issued a decision in a specific complaint case in which the complainant suspected that the complainant’s former spouse, who was employed by a financial institution, had accessed the complainant’s accounts. The complainant therefore requested access to the financial institution’s log files and was denied. The financial institution stated, among other things, that the log data no longer existed and that the log file had been deleted in accordance with standard practice. The Danish Data Protection Agency found no basis for rejecting the financial institution’s explanation that the requested log had been deleted as part of the institution’s deletion procedures. However, based on an overall assessment of the circumstances of the case, the Danish Data Protection Agency found grounds to criticize the financial institution’s handling of the complainant’s request for access. 1. Decision After reviewing the case, the Danish Data Protection Agency finds that there are grounds to criticize the fact that [the financial institution’s] handling of the complainant’s request for access did not comply with the provisions of Article 12(2), (3), and (4) of the General Data Protection Regulation[1]. Below is a detailed review of the case and the grounds for the Danish Data Protection Agency’s decision. 2. Statement of Facts 2.1. Case Details The case file shows that the complainant, who was a customer of [a financial institution], suspected that the complainant’s former spouse, who was employed by [the financial institution], had accessed the complainant’s bank accounts. The complainant subsequently switched banks and was charged a number of fees as a result. Prior to filing the complaint with the Danish Data Protection Agency, the complainant had lodged a complaint with the Financial Appeals Board regarding the imposition of these fees. It appears from the correspondence between [the financial institution], and the complainant, which was part of the case before the Financial Appeals Board, that the [financial institution’s] director, in an email dated March 16, 2023, offered to refund all fees if the case before the Appeals Board were closed. On March 20, 2023, the complainant indicated in an email that he agreed to this, and at the same time requested access to the bank’s log showing who had accessed the complainant’s accounts during the period 2015–2021. On March 21, 2023, [the financial institution] sent a letter to the complainant stating that the offer to refund the fees remained valid, “but on the condition that [the financial institution] not have to spend any additional time or resources on the matter, including any related issues.” On March 23, 2023, the complainant reiterated his request for access to the records. On June 2, 2023, the complainant followed up with [the financial institution] regarding a response to the request for access. On June 20, 2023, [the financial institution] responded to the complainant’s inquiry and stated that [the financial institution] had asked the complainant’s former spouse to provide an explanation of whether, and if so on what basis, [the complainant’s former spouse] had accessed the complainant’s accounts. It emerged, among other things, that the complainant’s former spouse had stated that: “[The complainant’s former spouse] had access to the accounts solely because they were grouped together in a single account group. In other words, you also had joint accounts. [The complainant’s former spouse] states, in other words, that [the complainant’s former spouse] accessed the accounts in question as a customer and not as an employee of [the financial institution].’ [The financial institution] further stated that [the financial institution] had investigated whether the complainant’s former spouse’s explanation could be substantiated, but that it was not possible to go that far back in the system usage log. [The financial institution] had inquired with [the financial institution’s] data center, [X], as to whether the log could be reconstructed. The data center had offered to attempt to reconstruct the information if [the financial institution] covered the costs equivalent to 182 consultant hours and approximately 300,000 DKK, with no guarantee that it would be possible to determine whether the complainant’s former spouse had accessed the complainant’s accounts. [The financial institution] further stated that customers of Danish financial institutions cannot demand a log showing which employees have accessed their account information. In addition, [the financial institution] stated that the costs would not be commensurate with the clarity that might potentially be achieved. On June 21, 2023, [the financial institution] sent a response to the complainant with a copy of the information that [the financial institution] had processed regarding the complainant. 2.2. The Complainant’s Comments The complainant has generally argued that, pursuant to a judgment handed down by the Court of Justice of the European Union[2], [the financial institution] is obligated to disclose information regarding who has unlawfully obtained information about the complainant’s financial circumstances, and that [the financial institution] was required to retain the requested log data until November 24, 2026, in accordance with the provisions of Section 30 of the Anti-Money Laundering Act. The complainant believes that the requested log data was either deliberately destroyed to cover up an employee’s unauthorized access to information regarding the complainant’s financial circumstances, or that [the financial institution] did not have adequate programs and guidelines to ensure compliance with, among other things, the General Data Protection Regulation. Since March 2023, the complainant has requested that [the financial institution] provide a copy of the requested log, and the director of [the financial institution] did not indicate at that time that the log in question was no longer in their possession. The complainant believes that [the financial institution] deliberately refused to provide the log to cover up the fact that the complainant’s former spouse had improperly obtained information about the complainant’s finances even after the end of their cohabitation. 2.3. [The Financial Institution’s] Comments [The Financial Institution] has generally stated that it responded to the complainant’s request for access on June 21, 2023. On June 20, 2023, [the financial institution] sent a letter to the complainant in which [the financial institution] explained the reason why [the financial institution] could not comply with the complainant’s request for access to the requested log file. Neither [the financial institution] nor [the financial institution’s] data center [X] is in possession of a log file for the period 2015–2021, and, in [the financial institution]’s view, it would violate any principle of proportionality if [the financial institution] were to incur a cost of 300,000 DKK for the data center [X], which may not necessarily be able to reconstruct the log file. [The financial institution] has further stated that all financial institutions on [X] have the same system configuration and that all internal log files are deleted after 6 months. The deletion occurs automatically and is in accordance with applicable law, as the retention of log files is not covered by Section 30 of the Anti-Money Laundering Act. The requested log file no longer exists, and [the financial institution] has deleted the log file in accordance with standard practice. 3. Rationale for the Danish Data Protection Agency’s Decision 3.1. It follows from Article 15(1) of the General Data Protection Regulation that the data subject has the right to obtain confirmation from the data controller as to whether personal data concerning the data subject are being processed, and, if so, to access that personal data. Under the Danish Data Protection Agency’s previous practice, personal data contained in a log was not covered by the right of access under Article 15 of the General Data Protection Regulation. This was because the log was considered a system security feature in which no independent processing of data takes place, but rather the log entries are derived from the processing of the original data. In a judgment of June 22, 2023[3], the Court of Justice of the European Union ruled on the issue of access to log files. The Court of Justice held that Article 15, paragraph 1, must be interpreted as meaning that information concerning searches of a person’s personal data and concerning the dates and purposes of those searches constitutes information that the data subject is entitled to receive from the data controller under that provision. With regard to information concerning the identity of the data controller’s employees who carried out the searches under the data controller’s supervision and on its instructions, Article 15(1) of the Regulation does not provide for such a right, unless such information is necessary for the data subject to effectively exercise their rights under the Regulation, and provided that the rights and freedoms of the employees are respected. It is the Danish Data Protection Agency’s assessment that the information contained in [the financial institution’s] log of employees’ access to a customer’s account is covered by the right of access in accordance with the aforementioned judgment. However, the Danish Data Protection Agency has noted that on June 20, 2023, [the financial institution] informed the complainant that the requested log information no longer exists. The Danish Data Protection Agency finds no basis for disregarding [the financial institution’s] explanation that the requested log was deleted as part of [the financial institution’s] data center’s standard deletion procedures. Nor does the Danish Data Protection Agency have grounds to disregard the [financial institution’s] assessment that the requested log files are not subject to the retention requirement under Section 30 of the Anti-Money Laundering Act. The Danish Data Protection Agency therefore has no grounds for comment on the fact that [the financial institution] did not provide the requested log files to the complainant. 3.2. However, based on an overall assessment of the circumstances of the case, the Danish Data Protection Agency finds grounds to criticize the [financial institution’s] handling of the complainant’s request for access, cf. Article 12 of the General Data Protection Regulation. In this connection, the Danish Data Protection Agency has, among other things, taken into account the fact that [the financial institution]’s refund of the fee for switching banks was conditional on the complainant withdrawing his request for access. It is the Data Protection Authority’s view that [the financial institution] thereby violated the provision in Article 12(2) of the General Data Protection Regulation, according to which the data controller must facilitate the exercise of the data subject’s rights under Articles 15–22 of the Regulation. Furthermore, based on the information provided, the Danish Data Protection Agency must assume that, during the period from March 23, 2023 —during which the complainant maintained his request for access—and until June 20, 2023, the complainant heard nothing from [the financial institution]. In its response dated June 20, 2023, [the financial institution] stated, among other things, that customers of financial institutions cannot demand to be provided with a log of which employees have accessed their account information. Furthermore, it appeared that [the financial institution] had attempted to clarify whether the complainant’s former spouse had had access to the complainant’s accounts and whether [the complainant’s former spouse’s] explanation in this regard could be substantiated. It is the Data Protection Authority’s view that if the [financial institution] believed that access to log files could not be granted, [the financial institution] should have informed the complainant immediately, and no later than one month after receiving the request, of the reason for this and of the possibility of filing a complaint with a supervisory authority and bringing the matter before a court, pursuant to Article 12(4) of the General Data Protection Regulation. Furthermore, based on the information provided, the Danish Data Protection Agency must assume that [the financial institution] also treated the complainant’s request as a general request for access, as [the financial institution] on June 21, 2023 —that is, approximately three months after the complainant’s request for access—sent a response to the complainant with a copy of the information that [the financial institution] processed about the complainant It is the Data Protection Authority’s view that [the financial institution] thereby violated the provision in Article 12(3) of the Regulation, according to which the data controller must, without undue delay and in any event no later than one month after receipt of the request, inform the data subject of the measures taken in response to a request pursuant to Articles 15–22. This period may be extended by two months if the request is complex; in such cases, the data subject must be notified of the extension and the reasons for it no later than one month after receipt of the request. Overall, the Danish Data Protection Agency finds that [the financial institution’s] handling of the complainant’s request for access did not comply with Article 12(2), (3), and (4) of the General Data Protection Regulation, which provides the Danish Data Protection Agency with grounds for issuing a criticism. [1] Regulation (EU) (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). [2] C-579/21 of June 22, 2023 [3] C-579/21 of June 22, 2023 The Danish Data Protection Agency Carl Jacobsens Vej 35 2500 Valby Tel. 33 19 32 00 dt@datatilsynet.dk About Us About the Danish Data Protection AgencyPressWebsitePrivacy PolicyAccessibility Statement Quick Links GDPR Guidance | File a Complaint with the Danish Data Protection Agency | Call Us | Newsletter | The National Whistleblower Scheme Follow Us The Danish Data Protection Agency on LinkedIn Search | Search Clear Load More Financial Institution Criticized for Handling of Request for Access Date: May 28, 2026 Decision Private Companies Criticism Complaint Right of Access Exercise of Rights The Danish Data Protection Agency has determined that a financial institution’s handling of a request for access to log files did not comply with data protection regulations Case Number: 2023-31-0321. Summary The Danish Data Protection Agency has issued a decision in a specific complaint case in which the complainant suspected that the complainant’s former spouse, who was employed by a financial institution, had accessed the complainant’s accounts. The complainant therefore requested access to the financial institution’s log files and was denied. The financial institution stated, among other things, that the log data no longer existed and that the log file had been deleted in accordance with standard practice. The Danish Data Protection Agency found no basis for rejecting the financial institution’s explanation that the requested log had been deleted as part of the institution’s deletion procedures. However, based on an overall assessment of the circumstances of the case, the Danish Data Protection Agency found grounds to criticize the financial institution’s handling of the complainant’s request for access. 1. Decision After reviewing the case, the Danish Data Protection Agency finds that there are grounds to criticize the fact that [the financial institution’s] handling of the complainant’s request for access did not comply with the provisions of Article 12(2), (3), and (4) of the General Data Protection Regulation[1]. Below is a detailed review of the case and the grounds for the Danish Data Protection Agency’s decision. 2. Statement of Facts 2.1. Case Details The case file shows that the complainant, who was a customer of [a financial institution], suspected that the complainant’s former spouse, who was employed by [the financial institution], had accessed the complainant’s bank accounts. The complainant subsequently switched banks and was charged a number of fees as a result. Prior to filing the complaint with the Danish Data Protection Agency, the complainant had lodged a complaint with the Financial Appeals Board regarding the imposition of these fees. It appears from the correspondence between [the financial institution], and the complainant, which was part of the case before the Financial Appeals Board, that the [financial institution’s] director, in an email dated March 16, 2023, offered to refund all fees if the case before the Appeals Board were closed. On March 20, 2023, the complainant indicated in an email that he agreed to this, and at the same time requested access to the bank’s log showing who had accessed the complainant’s accounts during the period 2015–2021. On March 21, 2023, [the financial institution] sent a letter to the complainant stating that the offer to refund the fees remained valid, “but on the condition that [the financial institution] not have to spend any additional time or resources on the matter, including any related issues.” On March 23, 2023, the complainant reiterated his request for access to the records. On June 2, 2023, the complainant followed up with [the financial institution] regarding a response to the request for access. On June 20, 2023, [the financial institution] responded to the complainant’s inquiry and stated that [the financial institution] had asked the complainant’s former spouse to provide an explanation of whether, and if so on what basis, [the complainant’s former spouse] had accessed the complainant’s accounts. It emerged, among other things, that the complainant’s former spouse had stated that: “[The complainant’s former spouse] had access to the accounts solely because they were grouped together in a single account group. In other words, you also had joint accounts. [The complainant’s former spouse] states, in other words, that [the complainant’s former spouse] accessed the accounts in question as a customer and not as an employee of [the financial institution].’ [The financial institution] further stated that [the financial institution] had investigated whether the complainant’s former spouse’s explanation could be substantiated, but that it was not possible to go that far back in the log of system usage. [The financial institution] had inquired with [the financial institution’s] data center, [X], as to whether the log could be reconstructed. The data center had offered to attempt to reconstruct the information if [the financial institution] covered the costs equivalent to 182 consultant hours and approximately 300,000 DKK, with no guarantee that it would be possible to determine whether the complainant’s former spouse had accessed the complainant’s accounts. [The financial institution] further stated that customers of Danish financial institutions cannot demand a log showing which employees have accessed their account information. In addition, [the financial institution] stated that the costs would not be commensurate with the clarity that might be achieved. On June 21, 2023, [the financial institution] sent a response to the complainant with a copy of the information that [the financial institution] had processed regarding the complainant. 2.2. The Complainant’s Comments The complainant has generally argued that, pursuant to a judgment handed down by the Court of Justice of the European Union[2], [the financial institution] is obligated to disclose information regarding who has unlawfully obtained information about the complainant’s financial circumstances, and that [the financial institution] was required to retain the requested log data until November 24, 2026, in accordance with the provisions of Section 30 of the Anti-Money Laundering Act. The complainant believes that the requested log data was either deliberately destroyed to cover up an employee’s unauthorized access to information regarding the complainant’s financial circumstances, or that [the financial institution] did not have adequate programs and guidelines to ensure compliance with, among other things, the General Data Protection Regulation. Since March 2023, the complainant has requested that [the financial institution] provide a copy of the requested log, and the [financial institution’s] director did not indicate at that time that the log in question was no longer in their possession. The complainant believes that [the financial institution] deliberately refused to provide the log to cover up the fact that the complainant’s former spouse had improperly obtained information about the complainant’s finances even after the end of their cohabitation. 2.3. [The Financial Institution’s] Comments [The Financial Institution] has generally stated that it responded to the complainant’s request for access on June 21, 2023. On June 20, 2023, [the financial institution] sent a letter to the complainant in which [the financial institution] explained the reason why [the financial institution] could not comply with the complainant’s request for access to the requested log file. Neither [the financial institution] nor [the financial institution’s] data center [X] is in possession of a log file for the period 2015–2021, and, in [the financial institution]’s view, it would violate any principle of proportionality if [the financial institution] were to incur a cost of 300,000 DKK for the data center [X], which may not necessarily be able to reconstruct the log file. [The financial institution] has further stated that all financial institutions on [X] have the same system configuration and that all internal log files are deleted after 6 months. The deletion occurs automatically and is in accordance with applicable law, as the retention of log files is not covered by Section 30 of the Anti-Money Laundering Act. The requested log file no longer exists, and [the financial institution] has deleted the log file in accordance with standard practice. 3. Rationale for the Danish Data Protection Agency’s Decision 3.1. It follows from Article 15(1) of the General Data Protection Regulation that the data subject has the right to obtain confirmation from the data controller as to whether personal data concerning the data subject is being processed, and, where applicable, to access that personal data. Under the Danish Data Protection Agency’s previous practice, personal data contained in a log was not subject to the right of access under Article 15 of the General Data Protection Regulation. This was because the log was considered a systemic security feature in which no independent processing of data takes place, but rather the log processing is derived from the processing of the original data. In a judgment of June 22, 2023[3], the Court of Justice of the European Union ruled on the issue of access to log files. The Court of Justice held that Article 15, paragraph 1, must be interpreted as meaning that information concerning searches of a person’s personal data and concerning the dates and purposes of those searches constitutes information that the data subject is entitled to receive from the data controller under that provision. With regard to information concerning the identity of the data controller’s employees who carried out the searches under the data controller’s supervision and on its instructions, Article 15(1) of the Regulation does not provide for such a right, unless such information is necessary for the data subject to effectively exercise their rights under the Regulation, and provided that the rights and freedoms of the employees are respected. It is the Danish Data Protection Agency’s assessment that the information contained in [the financial institution’s] log of employees’ access to a customer’s account is covered by the right of access in accordance with the aforementioned judgment. However, the Danish Data Protection Agency has noted that on June 20, 2023, [the financial institution] informed the complainant that the requested log information no longer exists. The Danish Data Protection Agency finds no basis for disregarding [the financial institution’s] explanation that the requested log was deleted as part of [the financial institution’s] data center’s standard deletion procedures. Nor does the Danish Data Protection Agency have grounds to disregard the [financial institution’s] assessment that the requested log files are not subject to the retention requirement under Section 30 of the Anti-Money Laundering Act. The Danish Data Protection Agency therefore has no grounds for comment on the fact that [the financial institution] did not provide the requested log files to the complainant. 3.2. However, based on an overall assessment of the circumstances of the case, the Danish Data Protection Agency finds grounds to criticize the [financial institution’s] handling of the complainant’s request for access, cf. Article 12 of the General Data Protection Regulation. In this connection, the Danish Data Protection Agency has, among other things, taken into account the fact that [the financial institution]’s refund of the fee for switching banks was conditional on the complainant withdrawing his request for access. It is the Data Protection Authority’s view that [the financial institution] thereby violated the provision in Article 12(2) of the General Data Protection Regulation, pursuant to which the data controller must facilitate the exercise of the data subject’s rights under Articles 15–22 of the Regulation. Furthermore, based on the information provided, the Danish Data Protection Agency must conclude that during the period from March 23, 2023 —during which the complainant maintained his request for access—and until June 20, 2023, the complainant heard nothing from [the financial institution]. In its response of June 20, 2023, [the financial institution] stated, among other things, that customers of financial institutions cannot demand a log of which employees have accessed their account information. Furthermore, it appeared that [the financial institution] had attempted to clarify whether the complainant’s former spouse had had access to the complainant’s accounts and whether [the complainant’s former spouse’s] explanation in this regard could be substantiated. It is the Data Protection Authority’s view that if the [financial institution] believed that access to log files could not be granted, [the financial institution] should have informed the complainant immediately, and no later than one month after receiving the request, of the reason for this and of the possibility of filing a complaint with a supervisory authority and bringing the matter before a court, pursuant to Article 12(4) of the General Data Protection Regulation. Furthermore, based on the information provided, the Danish Data Protection Agency must assume that [the financial institution] also treated the complainant’s request as a general request for access, as [the financial institution] on June 21, 2023 —that is, approximately three months after the complainant’s request for access—sent a response to the complainant with a copy of the information that [the financial institution] processed about the complainant It is the Data Protection Authority’s view that [the financial institution] thereby violated the provision in Article 12(3) of the Regulation, according to which the data controller must, without undue delay and in any event no later than one month after receipt of the request, inform the data subject of the measures taken in response to a request pursuant to Articles 15–22. This period may be extended by two months if the request is complex; in such cases, the data subject must be notified of the extension and the reasons for it no later than one month after receipt of the request. Overall, the Danish Data Protection Agency finds that [the financial institution’s] handling of the complainant’s request for access did not comply with Article 12(2), (3), and (4) of the General Data Protection Regulation, which provides the Danish Data Protection Agency with grounds for issuing a criticism. [1] Regulation (EU) (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). [2] C-579/21 of June 22, 2023 [3] C-579/21 of June 22, 2023




