VDAI (Lithuania) - 3R-1007
| VDAI - 3R-1007 | |
|---|---|
| [[File:|center|250px]] | |
| Authority: | VDAI (Lithuania) |
| Jurisdiction: | Lithuania |
| Relevant Law: | Article 5(1)(d) GDPR Article 5(2) GDPR Article 12(3) GDPR Article 15 GDPR |
| Type: | Complaint |
| Outcome: | Partly Upheld |
| Started: | 02.09.2022 |
| Decided: | 01.08.2025 |
| Published: | |
| Fine: | n/a |
| Parties: | Vinted UAB |
| National Case Number/Name: | 3R-1007 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Lithuanian |
| Original Source: | VDAI (in LT) |
| Initial Contributor: | cci |
The DPA clarified that under the accountability principle, controllers must sometimes deviate from their general data retention policies in order to demonstrate compliance.
English Summary
Facts
Vinted (the controller) suspended the account of a user (the data subject) on grounds that they allegedly violated the controller’s terms of use by controlling multiple accounts on the platform, including accounts involved in the sale of counterfeit goods.
The data subject claimed that the controller’s allegations were false. They filed an access request and a request for the rectification of their personal data. Due to a human error, the controller accidentally misunderstood the requests as a request for erasure and dismissed them. The data subject then filed the same requests again and received no response.
The data subject later filed a complaint with the Spanish DPA, claiming that the controller violated the right of access, the right to rectification, and the principle of accuracy. The Spanish DPA forwarded the case to the Lithuania DPA (the lead supervisory authority for the case).
The controller only responded to the data subject’s request after the Lithuanian DPA notified it of the investigation. In its response, the controller stated that it had deleted the account because its general data retention time for inactive accounts (3 months) had expired in the meantime. Therefore, the controller was unable to grant access to the data or to rectify them. Likewise, the controller informed the DPA that it no longer controlled the data and, therefore, could not grant the data subject's requests.
Holding
The DPA held that the controller violated Articles 12(3), 15 and 16 GDPR by failing to understand the content of the data subject’s request the first time they were filed, and by failing to reply the second time they were filed.
Due to the erasure of the data, the controller could not examine the data subject's claim that their data were processed inaccurately[1]. However, the DPA also considered that by erasing the data, the controller put itself in a position where it could not demonstrate compliance with the accuracy principle.
In this regard, the DPA took the view that the principle of accountability sometimes requires controllers to deviate from their general data retention policies and store data for a longer time: “the retention periods must be determined taking into account all the circumstances relating to the specific processing. This means that the controller must not only ensure the timely deletion of data that are no longer necessary, but also ensure that some data are kept for longer periods (deviating from the standard deletion periods), taking into account the possible need to demonstrate the compliance of the processing with the GDPR”. Therefore, the DPA held that the controller violated the principle of accountability under Article 5(2) GDPR.
Overall, the DPA held that the controller violated Articles 5(2), 12(3), 15 and 16 GDPR and issued a reprimand.
Comment
With regards to the data subject’s claim that the controller violated the principle of accuracy, the Lithuanian DPA referred the case back to the Spanish DPA. In practice, this amounts to a dismissal of the claim.
The referral to the Spanish DPA is required under Article 60(9) GDPR: “Where the lead supervisory authority and the supervisory authorities concerned agree to dismiss or reject parts of a complaint and to act on other parts of that complaint, a separate decision shall be adopted for each of those parts of the matter. The lead supervisory authority shall adopt the decision for the part concerning actions in relation to the controller (…) while the supervisory authority of the complainant shall adopt the decision for the part concerning dismissal or rejection of that complaint (…)". In practice, this somewhat convoluted rule means that when a cross-border complaint is partly upheld, the decision is “split” in two so that both parties can challenge the unfavorable parts of the decision in their own jurisdiction (which is typically more practical than bringing a case to a foreign court or authority).
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Lithuanian original. Please refer to the Lithuanian original for more details.
Extract from an electronic document
STATE DATA PROTECTION INSPECTORATE
DECISION
1 August 2025 No 3R-1007 (2.13-1.E) Vilnius
On 2 September 2022, the State Data Protection Inspectorate (hereinafter referred to as 'the
Inspectorate') received a complaint from the complainant [DATA NOT DISCLOSED] (hereinafter referred to as
'the Complainant') against the actions of the company Vinted, UAB (hereinafter referred to as 'the Complained
Party'), which was transmitted to the Spanish supervisory authority through the Internal Market Information
System (IMI) (Inspectorate Reg. No 1R-3125(2.13.Mr) ('the Complaint').
In the Complaint, the Complainant stated that on 02.04.2022, the Complained Person was informed by
the Inspectorate of the blocking of his account. According to the Applicant, the Complainant falsely claimed
that the Applicant had used several accounts and linked him to criminal activities related to the sale of
counterfeit goods through other accounts. The Applicant notes that on 16 May 2022, the Complainant made
requests for access to and rectification of the data to the Complainant, which were not responded to. Instead,
the Applicant received a notice from the Complained Party refusing to act on the right to be forgotten.
The Inspectorate, being competent to act as the lead supervisory authority and to draw up a final
decision on the Complainant's Complaint (Articles 56, 60(7) of Regulation (EU) 2016/679 of the European
Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the
processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC
("General Data Protection Regulation") ("GDPR"),
has decided as follows:
The Inspectorate has received a reply from the Complainant on 02-02-2023 (Inspectorate reg. No 1R
912 (2.13.Mr)) (hereinafter referred to as the "Response"), in which the Complained Person explained that the
Complainant's account had been blocked for breaches of the platform rules and deleted on 02.07.2022 in
accordance with the standard retention periods for personal data. Accordingly, at the time of the submission of
the Response, the Complained Person is processing a very limited amount of the Applicant's personal data,
which makes it impossible for the Complained Person to indicate to the Inspectorate what exactly the
Applicant's personal data was processed prior to the deletion of the account. The Complained Party noted that
it undoubtedly processed the data that every registering user is required to provide (password, email address),
as well as other data that depend on the specific functions used by the Applicant, such as whether the
Applicant had uploaded ads and traded on the platform, whether he had only purchased goods, whether he
had left or received feedback, whether he had uploaded a free-form profile, etc.
In response to the Inspectorate's questions regarding the existence of multiple accounts on the
platform and the proper implementation of the accuracy principle, the Complained Person indicated that,
given the limited data available on the Applicant at the time of the submission of the Response, the
Complained Person is not in a position to provide detailed explanations and evidence regarding the proper
implementation of the accuracy principle. According to the Complained Person, having established that the
Applicant has breached the requirements of the Vinted General Rules by creating more than
one account, his account was blocked and, according to the correspondence provided, when the Applicant
contacted the customer service department, the Applicant's situation was reassessed and it was confirmed that
the Applicant's account had been blocked legitimately. Accordingly, the Complained Party considers that it has
properly implemented the principle of data accuracy.
With regard to the Applicant's right of access and rectification, the Complained Party submits that
these requests were received on 16/05/2022 and responded to on 17/05/2022, but that the Customer Service
Officer misjudged the nature of the Applicant's request, and therefore responded to the Applicant not with
regard to the right of access and rectification, but with regard to the impossibility of deletion of the account,
that is, with regard to the exercise of the right of deletion of data. The Applicant submitted a renewed request
via the customer service system on 17 May 2022 regarding the exercise of data subjects' rights, which was not
answered in time due to human error. The Applicant's request was replied to after the error was discovered,
i.e. on 01.02.2023.
Taking into account the circumstances set out in the Complaint and the Response, the Inspectorate
considers that the main dispute between the parties relates to the allegedly inadequate implementation of the
Applicant's rights as a data subject (the right of access to data and the right to request rectification of the data
(Articles 12, 15, 16 of the GDPR)), and the allegedly inadequate implementation of the principle of accuracy of
the data (Article 5(1)(d) GDPR).
Concerning the implementation of the applicant's right of access to data and the right to have them
rectified
During the examination of the complaint, it has been established that on 02.04.2022, the Applicant's
platform account was blocked due to a violation of the rules of the platform, as the Complainant was found by
the Respondent to have multiple accounts, which is contrary to the prohibition set out in point 11.2 of the
platform's General Rules. On the same day, the Applicant contacted the Complainant's customer service
specialists to "correct the error". The Complainant in turn indicated that the Applicant's case had been
reviewed again, but that the original decision would remain unchanged and that "the account will remain
blocked".
On 16 May 2022, the Applicant contacted the Complained Person with a request for access to data
(Article 15 of the GDPR), noting that he considered the data held/processed by the Complained Person to be
inaccurate. With regard to the inaccuracy of the data, the Applicant pointed out that the Complained Person
had incorrectly linked the personal data of his account with the data of another account and, consequently,
had applied the blocking of the account on this basis without justification (Article 16 GDPR).
On 17 May 2022, the Complained Party replied, stating that 'We have examined your request. Your
request does not meet the requirements for the application of the right to erasure set out in Article 17 of the EU
General Data Protection Regulation (GDPR). <...>". On the same day, the Applicant contacted the Complainant
again, stating that he had not applied for the right to erasure, but for the exercise of the rights of access and
rectification.
The Inspectorate notes that the Complained Person responded to the Applicant's repeated request for
access only on 1 February 2023, i.e. only after the Inspectorate had contacted the Complained Person with an
instruction to demonstrate the compliance of its actions with the GDPR. The Complained Person did not
respond at all to the Applicant's request for rectification. The Inspectorate also points out that, both in its
replies to the Inspectorate and in its delayed response to the Applicant's request for access to data, the
Complained Person had already erased most of the Applicant's personal data.
Article 15 of the GDPR regulates the data subject's right of access. GDPR
Article 15(1) provides that the data subject shall have the right to obtain from the controller a confirmation as
to whether personal data concerning him or her are being processed and, if such personal data are being
processed, to have access to the personal data and to the information referred to in points (a) to (h) of this
paragraph.
2
Article 15(3) to (4) of the GDPR provides that the controller shall provide the data subject with a copy of the
personal data processed upon request, but that the right to obtain a copy may not adversely affect the rights
and freedoms of others.
Article 16 of the GDPR provides that the data subject has the right to have inaccurate personal data
concerning him or her rectified by the controller without undue delay. Taking into account the purposes for
which the data have been processed, the data subject has the right to have incomplete personal data
completed, inter alia, by means of a supplementary statement.
Article 12(2) of the GDPR provides that the controller shall facilitate the exercise of the data subject's
rights set out in Articles 15 to 22. Paragraph 3 of the same Article provides that the controller shall provide the
data subject with information on the action taken following a request pursuant to Articles 15 to 22 without
undue delay and in any event within one month of receipt of the request. If the controller fails to act on the
data subject's request, the controller shall, without delay and at the latest within one month of receipt of the
request, inform the data subject of the reasons for the failure to act and of the possibility to lodge a complaint
with the supervisory authority and to seek a remedy (Article 12(4) GDPR).
The European Data Protection Board's Guideline No 01/2022 on the right of access states that the
general purpose of the right of access is to provide individuals with sufficient, transparent and easily accessible
information about the processing of their personal data to enable them to be informed and to check the
lawfulness of such processing and the accuracy of the data processed. This right is a means of facilitating the
exercise of other rights, such as the right to have data erased or rectified.
In the present case, it is evident from the circumstances established during the examination of the
Complaint that the Applicant's right of access to data, enshrined in Article 15 of the GDPR, as well as the right
to request rectification of the data, enshrined in Article 16 of the GDPR, have not been exercised and,
consequently, have been violated.
Although the Applicant contacted the Complainant on 16 May 2022, clearly stating that he disagreed
with the blocking of his account and therefore sought access to and rectification of the data processed, the
Complainant received a reply from the Complainant stating that he would not act on the alleged request for
the right to be forgotten. This means that the Complained Person not only failed to act on the Applicant's
requests, but also failed to properly determine the nature and substance of the Applicant's requests in general.
When on 17 May 2022 the Applicant contacted the Complainant again, explicitly stating that he wished
to exercise his right of access and rectification, the Applicant's request was not responded to at all, i.e. the
request was essentially ignored.
Accordingly, the Inspectorate considers that by not properly determining the nature of the Applicant's
request of 16 May 2022, as well as by not responding at all to the Applicant's repeated request of 17 May 2022,
the Appellant has infringed the provisions of Article 12(3), Article 15 and Article 16 of GDPR.
The above assessment of the Inspectorate is also not altered by the fact that on 1 February 2023, the
Complained Person did reply to the Applicant's request for access to data. This conclusion is reached for the
following reasons:
First, the reply to the Complainant was provided only after the Inspectorate had received the
Inspectorate's order of 20/01/2023 to provide information in implementation of the principle of
accountability1, i.e. the reply to the Complainant was provided only after the Inspectorate had been informed
that the supervisory authority had opened an investigation against the Complainant for the failure to provide a
reply.
1Inspectorate Registration No 2R-371 (2.13.Mr).
3
Secondly, at the time of the reply, the Complained Person had already deleted most of the Applicant's
personal data2which were relevant for the Applicant to effectively and realistically exercise his right to
rectification. This means that the deletion of the data and the delay in responding3rendered the real exercise of
the Applicant's right of access to the data essentially impossible and meaningless.
Finally, the lack of timely receipt of the necessary information has also prevented the Applicant from
effectively exercising his right to request rectification and, consequently, from proving the unjustifiability of the
blocking of his account.
On the basis of the above-mentioned considerations and legal provisions, the Applicant's Complaint, in
so far as it relates to the inadequate exercise of the data subject's rights of access to data and to obtain
rectification, is declared well-founded.
Concerning the proper implementation of the principle of data accuracy
In his complaint, the Applicant submits that the Complained Person erroneously linked his personal
data to another person's data, in breach of the principle of accuracy.
Article 5(1)(d) of the GDPR provides that personal data must be accurate and, where necessary, kept
up-to-date and that all reasonable steps must be taken to ensure that personal data which are not accurate in
relation to the purposes for which they are processed are erased or rectified without undue delay (the
accuracy principle). Article 29 of the Law on the Legal Protection of Personal Data of the Republic of Lithuania
(hereinafter referred to as the 'LPPD')
Paragraph 1(4) provides that the supervisory authority shall adopt a decision to discontinue the examination of
a complaint or a part of a complaint if, during the examination of a complaint or a part of a complaint, it
becomes apparent that it is not possible to examine it due to a lack of information or to other relevant
circumstances.
The Inspectorate notes that the decision it adopts following the examination of a complaint is
considered to be an administrative decision4, and must therefore comply with the criteria of legality and
reasonableness of an administrative decision set out in Article 10(5) of the Law on Public Administration of the
Republic of Lithuania ('the LPA'). Pursuant to Article 10(5)(5) of the Law, an administrative decision must, inter
alia, state the legal and factual grounds for the administrative decision or other circumstances which affected
the administrative decision. It should be noted that this requirement is intrinsically linked to the principle of
objectivity enshrined in Article 3(9) of the Law, which means that the adoption of an administrative decision
and other official acts of a public administration body must be impartial and objective. The Supreme
Administrative Court of Lithuania (hereinafter referred to as 'the Supreme Administrative Court of Lithuania')
has noted that, in accordance with the principle of objectivity, the decisions of a public administration body
must correspond to the actual factual circumstances, which are established after having ascertained all the
circumstances relevant for the adoption of the decision and after having assessed the evidence in a critical and
impartial manner.(5) This means that individual administrative decisions cannot be based on
2In its reply to the Inspectorate, the Complained Person indicated that the majority of the Applicant's personal data had been
erased between 2022-07
02 in accordance with the standard retention periods for personal data.
3Article 12(3) of the GDPR provides for a general rule that replies to requests from data subjects must be provided promptly, but in
any event not later than one month after receipt. In the context of the present complaint
the reply to the Applicant's request of 16 May 2022 could have been provided at the latest on 16 June 2022.
4An administrative decision is a single expression of the will of a public administration body concerning the application of law,
expressed in a manner and/or form prescribed by law, which is binding upon and addressed to a specific person or an
individually defined group of persons (Article 2(5) of the Law on Public Administration).
5E.g., the decision of the Supreme Administrative Court of 14 April 2014 in administrative case No A662-1010/2014.
4
6and must be justified in such a way as to leave no doubt as to the result of the decision7.
In the present case, it has been established that on 02.07.2022, the Complained Person deleted most of
t h e Applicant's personal data, including those from which it could be objectively determined whether the
Complained Person has properly implemented the principle of accuracy of the data arising from Article 5(1)(d)
of GDPR. As a result, the Inspectorate is not in a position to determine whether the Complained Party has
properly implemented the principle of accuracy. The supervisory authority concerned by the Complaint (in this
case the Spanish supervisory authority) shall take a final decision on the part of the Complaint to be closed and
shall inform the Complainant and the Complained Person thereof (Article 60(8), (9) GDPR).
Notwithstanding the above, the Inspectorate notes that the aforementioned lack of information, which
prevents the establishment of all the circumstances necessary for a proper examination of the Complaint, was
caused by the actions of the Complainant on 02/07/2022, when he deleted the necessary information.
Accordingly, the Inspectorate will address the implementation of the principle of accountability enshrined in
Article 5(2) of the GDPR in the context of the Complaint later in this Decision.
As regards the implementation of the principle of accountability
As mentioned above, in the absence of objective data concerning the processing of data by the
Complainant at the time of the Complainant's requests, the Inspectorate is not in a position to assess the
compliance of such processing with the GDPR. However, in the Inspectorate's view, such circumstance must be
assessed in the context of Article 5(2) GDPR. Otherwise, data controllers could in all cases avoid infringements
of the GDPR by simply deleting the data relevant for such investigation.
Article 5(2) of the GDPR provides that the controller is responsible for ensuring that
compliance with paragraph 1 and must be able to demonstrate compliance with it (principle of accountability).
Article 24(1) of the GDPR provides that, taking into account the nature, scope, context and purposes of
the processing, as well as the risks of varying likelihood and severity to the rights and freedoms of natural
persons, the controller shall put in place appropriate technical and organisational measures to ensure and be
able to demonstrate that the processing is carried out in accordance with the provisions of this Regulation.
Those measures shall be reviewed and updated as necessary.
In its case-law, the Supreme Court has indicated that the principle of accountability is at the heart of
the obligation for the controller to: establish measures which, in normal circumstances, will help to ensure
compliance with the data protection rules in the course of the processing operations; and keep available
documents from which data subjects and supervisory authorities can see the measures taken to ensure
compliance with the data protection rules.8
In the present case, it has been established that the deletion of the Applicant's personal data (and the
corresponding evidence of the proper implementation of the data accuracy principle deriving from Article
5(1)(d) of the GDPR) was caused by the expiry of the standard retention period for personal data set by the
Complained Party (3 months). After the expiry of this period, the data were automatically deleted.
It should be noted that the GDPR does not provide for specific retention periods for personal data. The
appropriate retention periods to be determined and in line with the principle of data minimisation are
6Resolution of the Supreme Administrative Court of 17 November 2014 in administrative case No A858-2430/2014.
7Order of the Supreme Administrative Court of the Republic of Latvia of 8 September 2015 in administrative case No A-2494
438/2015.
8Decision of the Supreme Administrative Court of 29 December 2021 in administrative case No eA-2483-822/2021.
5
In the Inspectorate's view, the retention periods must be determined taking into account all the circumstances
relating to the specific processing. This means that the controller must not only ensure the timely deletion of
data that are no longer necessary, but also ensure that some data are kept for longer periods (deviating from
the standard deletion periods), taking into account the possible need to demonstrate the compliance of the
processing with the GDPR.
As can be seen from point 2.8.410of the Complainant's privacy policy relevant to the Complaint, the
Complainant has provided for the retention of personal data for a longer period of time, taking into account
the need to protect its rights and interests in the event of a dispute. In the context of this provision of the
Privacy Policy, it is also relevant to take into account the Complainant's explanations to the Inspectorate dated
17.02.2022 (Inspectorate reg. No 1R-968 (2.13.Mr)), in which the Complained Person has explained that he/she
has adopted the interpretation of the term 'dispute' as meaning that personal data are stored for the purpose
of defending himself/herself against possible claims or conflicts where it becomes apparent that a certain fact
or question of law is perceived by the user in a different way from the perception of the Complained Person,
and that the Complained Person may need to protect his/her rights and legitimate interests as a result of the
disagreement. Such disputes include cases where the user lodges a complaint with a consumer protection
authority or a supervisory authority for the protection of personal data.11
In the present case, as can be seen from the communication between the parties, the Applicant
categorically disagreed with the basis for the blocking of his account and challenged it accordingly. Moreover,
in the correspondence with the platform's customer support specialists, the Applicant has explicitly stated that
if he does not receive the requested information from the Complainant, the latter will 'contact the Personal
Data Protection Agency'.12Given that the Complainant's dispute regarding the possible inaccuracy of his
personal data and the corresponding blocking of his account has not been resolved by the customer service
professionals,(13)nor has he been provided with the requested data, and given that the Complainant has
expressed a direct intention to contact the supervisory authority, The Inspectorate considers that the
Complained Person had clear indications that the retention of the Applicant's personal data (to the extent
necessary to substantiate compliance with Article 5(1)(d) of the GDPR) was necessary to continue to fulfil the
principle of accountability under Article 5(2) GDPR.
In the light of the above, the Inspectorate concludes that, in the context of the present Complaint, by
not being able to substantiate the proper implementation of Article 5(1)(d) of the GDPR, the Complained
Person has infringed the principle of accountability of the controller as referred to in Article 5(2) GDPR.
Concerning the imposition of sanctions against the Complainant
9Paragraph 39 of the GDPR Preamble provides that personal data should be adequate, relevant to the purposes for which they
are processed and limited to what is necessary for their possession in relation to the purposes for which they are processed,
which requires, in particular, that the retention period of the personal data be kept to a strict minimum.
10Clause 2.8.4 of the Privacy Policy provided that if you are involved in a dispute with Vinted, or if we need to enforce our Terms
or otherwise defend, enforce, exercise or maintain our rights, we will collect and use all of your personal data held by Vinted in
order to find a solution to the particular situation. We base such collection and use on the legitimate interest of protecting
Vinted's rights and interests (Article 6(1)(f) GDPR). Personal data collected and used for this purpose is stored for a period of 5
(five) years from the time we establish the need to defend our specific rights and interests, and in the event of a dispute, until
the final binding decision of the authorised authority has been implemented.
11Page 18 of the Complainant's explanations to the Inspectorate dated 17-02-2022.
12Annex 3 to the Complainant's Response, page 13.
13The Complainant's Customer Service Officer, in her communication with the Complainant and in response to the Complainant's
intention to refer the matter to the supervisory authority, stated that "I am sorry that you do not like our working procedures,
but if you wish to proceed with your complaint, we can only wish you good luck".
6
Article 31(2)(1) of the DPAA states that where a complaint or part of it is found to be justified, the
Inspectorate shall issue instructions, recommendations and/or apply other measures as specified in the
legislation on the protection of personal data and/or privacy to the controller and/or processor. Pursuant to
Article 12(2)(5) of the GDPR, the Inspectorate has the right to issue recommendations and instructions to data
controllers, data processors and other legal or natural persons with regard to the processing of personal data
and/or privacy protection.
Paragraph 129 of the GDPR preamble provides that any measure taken by the supervisory authority
must be appropriate, necessary and proportionate to ensure compliance with this Regulation, taking into
account the circumstances of each individual case. It should be noted that the GDPR provides for the discretion
of the Inspectorate to select remedies where a complaint is found to be justified, but it is important that any
remedy taken by the Inspectorate is appropriate, necessary and proportionate in the light of the infringement.
Article 58(2)(b) of the GDPR provides that each supervisory authority shall have the power to issue a
reprimand to a controller or processor where processing operations have infringed the provisions of this
Regulation.
Given that the Inspectorate has no evidence that the infringements found in this Decision are of a
systemic nature (involving not only the Applicant, but also other users of the platform), the Complainant is
reprimanded for infringements of Articles 12(3), 15, 16 and 5(2) of the GDPR.
In the Inspectorate's assessment, the provision of additional remedies (instructions) related to the
exercise of the Applicant's rights would be inappropriate, given that the personal data of the Applicant, which
the Applicant sought access to and rectification of, have already been erased, which makes it objectively
impossible for the proper exercise of the Applicant's rights (the right of access to the data and the right to
request rectification of the data) to take place.
In accordance with the above, as well as with Articles 31(1)(1), 31(2)(1) and 31(1) of the ADEA
Article 58(2)(b), Article 60(7) of the GDPR, the Inspectorate
h a s c o n c l u d e d :
1. The Complaint of the Applicant, in so far as it concerns the inadequate exercise of the rights of
access to data and
requesting rectification is justified.
The supervisory authority concerned with which the Complaint has been lodged (in this case the
Spanish supervisory authority) shall take a final decision on the part of the Complaint to be closed and shall
inform the Complainant and the Complained Person thereof (Article 60(8), (9) GDPR).
2. Declare that, by not being able to substantiate the adequate implementation of the principle of
data accuracy in the context of the Complainant's Complaint, the Complained Party has infringed the principle
of accountability enshrined in Article 5(2) of the GDPR.
3. reprimand the Complainant.
4. Inform the Complainant and the Applicant of the decision taken.
This decision may be appealed against to the Administrative Court of the Regions (address: Žygimantų
g. 2, Vilnius) within one month from the date of its notification, in accordance with the procedure laid down by
the Law on Administrative Proceedings of the Republic of Lithuania.
Director
Dijana Šinkūnienė
7
- ↑ With regards to the violation of the accuracy principle, the Lithuanian DPA referred the decision back to the Spanish DPA, in order for the Spanish DPA to dismiss the claim. The referral to the Spanish DPA is due to a procedural quirk under Article 60(9) GDPR: see Commentary this Article for more information.



