Sanction RGPD Belgian Data Protection Authority (APD) — Company : 8 k€ (2022)

Autorité de contrôle
Belgian Data Protection Authority (APD)
Pays
Belgique
Entreprise / secteur
Company
Montant de l'amende
8 k€
Date de la décision
1 avril 2022
Fondement juridique
Art. 5 (1) a), Art. 6 (1) f), Art. 15, Art. 17, Art. 18, Art. 21, Art. 28
Manquement
Droits des personnes non respectés

Résumé des faits

The Belgian DPA has imposed a fine of EUR 7,500 on a company. A former managing director had filed a complaint against the company with the DPA. In the context of being dismissed, the former managing director deleted all data on the work laptop before handing over the technical equipment. According to the managing director, only the private data, such as the private e-mail inbox, had been deleted. However, the company stated that the managing director had deleted both private and work-related data. The company then restored the data that had previously been on the laptop. For this reason, the former managing director requested to exercise their right to delete, restrict the processing of their personal data and object. However, the company refused the request. In the course of its investigation, the DPA found that the company had breached its obligation under the GDPR to grant the former managing director the exercise of these rights. In addition, the DPA found that due to the lack of a valid legal basis at the time of the restoration, the company unlawfully processed the data.

Décision officielle

Belgian Data Protection Authority (APD)

Évaluer votre conformité RGPD avec Data Comply One