Cybersecurity Policy Report, Violations of GDPR Lead to Fine for Belgian Financial Firm, (May 13, 2026)
The Belgian data protection authority (APD) has fined financial services firm Isabel S.A. 120,000 euros ($140,520) over violations of the European Union’s General Data Protection Regulation (GDPR).
Between October 2020 and March 2023, Isabel operated a service that enabled users to authenticate themselves with Isabel’s partners, the APD noted in a news release. To provide the service, “an extensive set of personal data, including name, address, national registration number, date and place of birth, and a photograph of the electronic identity card,” was collected, it said.
One user of the service discovered the extent of Isabel’s data collection and requested access, but the firm did not respond and maintained that it was acting as a data processor and not a data controller.
The APD found that Isabel “designed, configured, and operated” the service and that it should have recognized itself as a data controller within the meaning of the GDPR.
That erroneous classification led to a “cascade” of GDPR violations, including a failure to inform system users beforehand, the absence of a response to the complainant's access requests, and the collection of data exceeding what was necessary for the intended authentication purpose, the APD said.
Based on the violations, the APD imposed an administrative fine and a reprimand.
News: InternationalLegislation DataPrivacy GDPR LitigationEnforcement