Another Belgian DPA decision on how long to keep the e-mail address of an ex-employee alive.
The Belgian DPA repeats its position that is now almost constant (but in cases that do not appear to have been appealed): block access to a mailbox on the day of departure, then kill the e-mail address within 3 months maximum.
Para. 33: “Depending on the context and, in particular, the degree of responsibility exercised by the data subject (such as a position as managing director or another key position that he or she is the only person to exercise, as in this case), a longer period may be allowed, ideally not exceeding 3 months. Reasons must be given for any such extension and it must be made with the agreement of the data subject or, at the very least, after notifying him or her. An alternative solution must also be sought and put in place as quickly as possible, without necessarily waiting for the extension to expire.
The legitimate interest assessment in the decision is worth the read (para. 55 is key).
Yet I continue to be dubious that this is the best approach.
First, re the continued use of an e-mail address, there will inevitably be *some* situations where contracts were tied to an individual’s e-mail address – and not all situations can be detected within 3 months. Why not allow the continued processing, but purely in the form of an e-mail alias?
(Yes, that’s easy to set up – the mailbox then doesn’t exist but all e-mails to employee@abc.com are actually sent to boss@abc.com)
Next, re the mailbox itself, business continuity remains a very relevant concern, one that all too often is set aside in similar cases. The reality remains that – despite policies that say otherwise – *many* have their entire professional correspondence in their mailbox. If there is a restrictive access policy in place (e.g. mailbox archived, only accessible by the supervisor with input from the DPO, etc.), why would that not be sufficient?
Of course, the company could have done better.
But if contractual notices or logins that are hard to change happen to be linked to a particular ex-employee’s e-mail address, they might not all be immediately detected and changed. Even 3 months is a short period of time after someone has left.
So I continue to have my doubts as to the legal reasoning behind this position (hey, I’m data law litigator). At the same time I must applaud the Belgian DPA for its consistency on this and for introducing a little bit of extra pragmatism here (“at the very least, after notifying him or her” – a notable evolution compared to their very first consent-first positions on the topic that did not work at all in the case of an employee who gets fired instead of leaving of his/her own accord).
Decision in French: https://lnkd.in/e79xSFyK
data protection gdpr privacy
Did this analysis get you thinking? Reach out!
DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!
Get in touch ↗ Let's connect on LinkedIn ↗