Back to Feed
GDPRJul 22, 2026

APD/GBA (Belgium) - 97/2026

Belgian DPA rules employer violated GDPR right of access by refusing timesheet copies.

Summary

Belgium's Data Protection Authority (APD/GBA) in decision 97/2026 found an employer violated Article 15 GDPR by refusing to provide copies of employee timesheets and offering only on-premises inspection instead. The DPA rejected the employer's claim that fulfilling the request was excessive due to its own archiving system, establishing that controller burden from poor data organization cannot justify denying access rights. The decision reinforces that data subjects have an absolute right to access their personal data without justifying their request, and controllers must implement systems to facilitate compliance from the outset.

Full text

Help APD/GBA (Belgium) - 97/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 11:25, 20 July 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators221 edits Tag: submission [1.0] Latest revision as of 08:21, 22 July 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators221 editsm Tag: Visual edit Line 69: Line 69: }}}} The DPA held that an employer violated an employee’s right of access by refusing to provide copies of their timesheets and offering only inspection in its premises. It also found that the workload required to fulfil the request because of its own archiving system did not make it excessive.The DPA held that an employer violated an employee’s right of access by refusing to provide copies of their timesheets and offering only an inspection on its premises. The DPA also found that the workload involved in fulfilling the access request was due to the controller’s own archiving system and not because the request was excessive. == English Summary ==== English Summary == Line 91: Line 91: Moreover, it rejected the controller’s reliance on [[Article 12 GDPR#5|Article 12(5) GDPR]]. The DPA held that the request was neither manifestly unfounded nor excessive as was clearly expressed and properly understood by the controller. It found that the controller did not demonstrate the excessiveness but relied exclusively on the workload resulting from its own archiving system.Moreover, it rejected the controller’s reliance on [[Article 12 GDPR#5|Article 12(5) GDPR]]. The DPA held that the request was neither manifestly unfounded nor excessive as was clearly expressed and properly understood by the controller. It found that the controller did not demonstrate the excessiveness but relied exclusively on the workload resulting from its own archiving system. The DPA also relied on C-526/24 (Brillen Rottler) and applied the abuse of rights test. It found that neither its objective nor its subjective element was established. It reasoned that the request pursued the purpose of [[Article 15 GDPR|Article 15 GDPR]], since the data subject sought to access and verify the accuracy of personal data concerning them, nor was there any evidence that the data subject had artificially created the conditions for obtaining an advantage under the GDPR. It further referred to EDPB Guidelines 01/2022 on the right of access, emphasizing that the time and effort required for a controller to fulfil an access request cannot, in itself, make the request excessive, particularly since the burden resulted from organisational choices made by the controller. It also emphasized that the data subject was also not required to justify the reasons for the request.The DPA also relied on C-526/24 (Brillen Rottler) and applied the abuse of rights test. It found that neither its objective nor its subjective element was established. It reasoned that the request pursued the purpose of [[Article 15 GDPR]], since the data subject sought to access and verify the accuracy of personal data concerning them, nor was there any evidence that the data subject had artificially created the conditions for obtaining an advantage under the GDPR. It further referred to EDPB Guidelines 01/2022 on the right of access, emphasizing that the time and effort required for a controller to fulfil an access request cannot, in itself, make the request excessive, particularly since the burden resulted from organisational choices made by the controller. It also emphasized that the data subject was also not required to justify the reasons for the request. The right of access under [[Article 15 GDPR|Article 15 GDPR]] does not include any general proportionality reservation regarding the controller’s efforts. Additionally, the term "appropriate" in [[Article 12 GDPR#1|Article 12(1) GDPR]] should not be used to limit the scope of data covered by the right of access. The DPA concluded that the alleged burden could not justify a refusal, especially since it stemmed from self-imposed organizational and administrative constraints related to the controller’s archiving system. A refusal may only apply if there is proven abusive intent, as defined by applicable requirements. Any other interpretation would undermine [[Article 15 GDPR|Article 15 GDPR]] and conflict with [[Article 12 GDPR#2|Article 12(2) GDPR]] and [[Article 25 GDPR|Article 25 GDPR]], which require controllers to facilitate access requests and implement technical and organizational measures from the outset to ensure effective exercise of this right.The right of access under [[Article 15 GDPR]] does not include any general proportionality reservation regarding the controller’s efforts. Additionally, the term "appropriate" in [[Article 12 GDPR#1|Article 12(1) GDPR]] should not be used to limit the scope of data covered by the right of access. The DPA concluded that the alleged burden could not justify a refusal, especially since it stemmed from self-imposed organizational and administrative constraints related to the controller’s archiving system. A refusal may only apply if there is proven abusive intent, as defined by applicable requirements. Any other interpretation would undermine [[Article 15 GDPR]] and conflict with [[Article 12 GDPR#2|Article 12(2) GDPR]] and [[Article 25 GDPR]], which require controllers to facilitate access requests and implement technical and organizational measures from the outset to ensure effective exercise of this right. The DPA further held that the controller had violated [[Article 12 GDPR#2|Article 12(2) GDPR]], [[Article 12 GDPR#3|Article 12(3) GDPR]] and [[Article 12 GDPR#4|Article 12(4) GDPR]]. It had neither responded within the applicable time limit nor formally notified the data subject of a reasoned refusal. It further emphasized that the controller by requiring the data subject to attend its premises and identify the relevant records, it improperly transferred to them a task that belonged to it. Moreover, it noted that on-site consultation of the records could have exposed the data subject to personal data relating to the controller’s clients. The DPA held that under [[Article 15 GDPR#4|Article 15(4) GDPR]], the controller was required to assess whether measures, such as partial anonymisation of third-party information, were necessary and that provision could not justify a blanket refusal to provide a copy.The DPA further held that the controller had violated [[Article 12 GDPR#2|Article 12(2) GDPR]], [[Article 12 GDPR#3|Article 12(3) GDPR]] and [[Article 12 GDPR#4|Article 12(4) GDPR]]. It had neither responded within the applicable time limit nor formally notified the data subject of a reasoned refusal. It further emphasized that the controller by requiring the data subject to attend its premises and identify the relevant records, it improperly transferred to them a task that belonged to it. Moreover, it noted that on-site consultation of the records could have exposed the data subject to personal data relating to the controller’s clients. The DPA held that under [[Article 15 GDPR#4|Article 15(4) GDPR]], the controller was required to assess whether measures, such as partial anonymisation of third-party information, were necessary and that provision could not justify a blanket refusal to provide a copy. Latest revision as of 08:21, 22 July 2026 APD/GBA - 97/2026 Authority: APD/GBA (Belgium) Jurisdiction: Belgium Relevant Law: Article 12(2) GDPR Article 12(3) GDPR Article 12(4) GDPR Article 15(1) GDPR Article 15(3) GDPR Article 15(4) GDPR Type: Complaint Outcome: Upheld Started: 27.07.2023 Decided: 06.05.2026 Published: Fine: n/a Parties: n/a National Case Number/Name: 97/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): French Original Source: APD (in FR) Initial Contributor: ds The DPA held that an employer violated an employee’s right of acc

Entities

Article 15 GDPR (Right of Access) (technology)Article 12 GDPR (Transparent Communication) (technology)EDPB Guidelines 01/2022 (Right of Access) (technology)