A useful Belgian DPA ruling outlining the practical limits of data subject access

Useful new decision by the Belgian Data Protection Authority on the limits of data subject access requests, in a case where a data subject complained that the response was (i) late and (ii) incomplete.

(i) Late response:

The response was late due to a long-term absence of the person normally managing data subject requests due to illness – and that access request was forgotten as a result.
The BDPA stated that this does not excuse a late response.
However, the controller took measures to ensure that this does not happen again (creation of a dedicated mailbox for requests, so that several have access to such requests).

=> Taken into account to say that only a reprimand was in order, not a fine

(ii) Incomplete response?

The controller refused to respond to certain questions asked by the data subject, such as whether there had been any data breaches and which security measures were taken.
The BDPA confirmed that the controller was entitled to refuse to provide information on security measures, as this topic is not covered by Articles 13(1), 13(2) or 15(1) GDPR.
The BDPA also confirmed that no information needed to be provided on data breaches, as there was no indication that there had been any high-risk data breaches concerning the data subject.

=> The response by the controller was complete

Link (decision in French):
https://lnkd.in/evsCzAnp

data protection privacy

🫖

Did this analysis get you thinking? Reach out!

DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!

Get in touch ↗   Let's connect on LinkedIn ↗