Cybersecurity Policy Report, Tech Company Fined Over Privacy Lapse in Belgium, (May 13, 2026)
The Belgian data protection authority (APD) has fined an unnamed “large technology company” 176,000 euros ($206,231) after it failed to delete a former employee’s e-mail account after the employee realized the account was still active six months after leaving the job and requested that it be deleted.
Among other things, the personal data in the former employee’s e-mail had been processed unlawfully, the company failed in its obligation of transparency, and it did not take the necessary technical and organizational measures to ensure that the e-mail account was deleted, the APD said in a news release.
Based on those failures, the APD fined the company 160,000 euros for unlawful data processing and 16,000 euros for transparency shortcomings. The company was also ordered to comply with the former employee’s request for access and erasure of the data.
News: InternationalLegislation DataPrivacy LitigationEnforcement