[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feBR5D2P36XDhnLKhJyFTNbJDe6_yf8KNJ0sjx8G0o10":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"67bbfec2-2185-4a3f-8c15-23f28de119d3","belgian-dpa-rules-employer-cannot-deny-gdpr-data-access-rights-due-to-poor-archiving","37ca22cf-d225-4414-b1a2-5f7f858da78d","Belgian DPA Rules Employer Cannot Deny GDPR Data Access Rights Due to Poor Archiving","Belgium's Data Protection Authority found that an employer violated Article 15 GDPR by refusing to provide copies of employee timesheets, citing its own disorganized archiving system as justification. This decision makes clear that operational inefficiency or poor data management on the controller's part is never a valid reason to deny a data subject their fundamental right of access. Controllers are legally required to design and maintain systems that can facilitate compliance with data subject rights from the outset, not as an afterthought. The ruling reinforces that data subjects do not need to justify access requests, and offering an on-premises inspection as a substitute for providing copies does not satisfy the controller's obligations under GDPR.","**Immediate actions:**\n- Audit all personal data repositories to ensure employee and customer data can be located, retrieved, and exported in response to Subject Access Requests (SARs) within the 30-day GDPR deadline.\n- Establish a formal SAR intake and tracking process with assigned ownership and documented response procedures.\n\n**Data governance improvements:**\n- Implement a data inventory and mapping exercise to record where personal data is stored, in what format, and how it can be retrieved.\n- Design archiving systems with data subject rights in mind, ensuring records are searchable, exportable, and attributable to specific individuals.\n- Create standardized templates and workflows for fulfilling access requests, including mechanisms for providing copies rather than inspection-only access.\n\n**Training & compliance measures:**\n- Train HR, legal, and IT staff on GDPR Article 15 obligations, including what constitutes a valid response to an access request.\n- Conduct periodic compliance reviews of data handling practices to identify gaps that could obstruct the fulfilment of data subject rights before a complaint is filed.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 15 (Right of Access)","GDPR Article 5(1)(e) (Storage Limitation)","GDPR Article 5(1)(f) (Integrity and Confidentiality)","GDPR Article 24 (Responsibility of the Controller)","GDPR Article 25 (Data Protection by Design and by Default)","NIST Privacy Framework PR.DS-P (Data Processing Policies)","NIST SP 800-53 IP-1 (Consent and Privacy Policy)","CIS Control 3 (Data Protection)","ISO\u002FIEC 27701 Section 7.3.2 (Fulfilling Data Subject Rights)","ITIL Service Design – Information Management Practices","published","2026-07-22T10:21:23.12605+00:00","2026-07-22T10:21:22.831+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=APD\u002FGBA_(Belgium)_-_97\u002F2026&diff=52439&oldid=52410","apd-gba-belgium-97-2026-47966d","APD\u002FGBA (Belgium) - 97\u002F2026",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]