Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • Citing Privacy Risks, Rep. Pallone Launches ‘Surveillance Pricing’ Probe
    • Guidance on Creating AI ‘Bill of Materials’ Offered by U.S., G7 Allies
    • House Bill Targets Electric Vehicle Threat to Power Grid
    • Legislative Options to Combat Robocalls Highlighted by CRS
    • N.Y. Senate Advances Bill to Require Disclosures of Biometric Tracking
    • Social Media Platforms Advised by German Regulator to Police Ads for Privacy Violations
    • Social Media Safety Bill Clears Minnesota House
    • Tech Company Fined Over Privacy Lapse in Belgium
    • Telecom Security Council Rechartered by FCC
    • Texas AG Sues Netflix, Settles With LG in Behavior-Tracking Cases
    • UAS Makers, Users Urge FCC to Reverse ‘Covered List’ Decision
    • Updated Guidance on Privacy Principle Published in Australia
    • Violations of GDPR Lead to Fine for Belgian Financial Firm
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Violations of GDPR Lead to Fine for Belgian Financial Firm, (May 13, 2026)

    By R. Jason Howard, J.D.

    The Belgian data protection authority (APD) has fined financial services firm Isabel S.A. 120,000 euros ($140,520) over violations of the European Union’s General Data Protection Regulation (GDPR).

    Between October 2020 and March 2023, Isabel op ...

    By R. Jason Howard, J.D.

    The Belgian data protection authority (APD) has fined financial services firm Isabel S.A. 120,000 euros ($140,520) over violations of the European Union’s General Data Protection Regulation (GDPR).

    Between October 2020 and March 2023, Isabel operated a service that enabled users to authenticate themselves with Isabel’s partners, the APD noted in a news release. To provide the service, “an extensive set of personal data, including name, address, national registration number, date and place of birth, and a photograph of the electronic identity card,” was collected, it said.

    One user of the service discovered the extent of Isabel’s data collection and requested access, but the firm did not respond and maintained that it was acting as a data processor and not a data controller.

    The APD found that Isabel “designed, configured, and operated” the service and that it should have recognized itself as a data controller within the meaning of the GDPR.

    That erroneous classification led to a “cascade” of GDPR violations, including a failure to inform system users beforehand, the absence of a response to the complainant's access requests, and the collection of data exceeding what was necessary for the intended authentication purpose, the APD said.

    Based on the violations, the APD imposed an administrative fine and a reprimand.

    News: InternationalLegislation DataPrivacy GDPR LitigationEnforcement

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use