CNPD
COMMISSION
NATIONALE
POUR LA
PROTECTION
DES DONNEES
Deliberation No 81_RECL62_2025 of 26 September 2025 of the National Data Protection Commission, in a plenary session, on complaint file No 4.358 lodged against the company [REDACTED] via IMI Article 61 procedure 93092
Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the 'GDPR');
Having regard to the Act of 1 August 2018 on the organisation of the National Data Protection Commission and the general data protection framework (hereinafter: the 'Law of 1 August 2018');
Having regard to the Rules of Procedure of the National Data Protection Commission adopted by Decision No 07AD/2024 of 23 February 2024 (hereinafter: the 'ROP');
Having regard to the Procedure for complaints before the National Data Protection Commission adopted on 16 October 2020 (hereinafter: the 'Complaint Procedure before the CNPD');
Having regard to the following:
# I. Facts and procedure
1. In the framework of the European cooperation, as provided for in Chapter VII of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation or GDPR), the Supervisory Authority of Germany (Bavaria) submitted to the National Data Protection Commission (hereinafter: "the CNPD") a complaint (national reference of the concerned authority: LDA-1085.3-11937/19-I) via IMI in accordance with Article 61 procedure - 93092.
2. The complaint was lodged against the controller [REDACTED] (hereafter [REDACTED] or "the Controller"), who has its main establishment in Luxembourg. Under Article 56 GDPR, the CNPD is therefore competent to act as the lead supervisory authority.
3. The original IMI claim stated the following:
"The complainant states that a request for access was sent via email to [REDACTED] on 08 July 2019 which is, according to [REDACTED] privacy policy, the correct procedure. [REDACTED] has not fulfilled this request, but send email communication for the complainant to follow a different process."
4. In essence, the complainant asks the CNPD to order the Controller to comply with her access request.
1
CNPD
COMMISSION
NATIONALE
POUR LA
PROTECTION
DES DONNEES
Deliberation No 81_RECL62_2025 of 26 September 2025 of the National Data Protection Commission, in a plenary session, on complaint file No 4.358 lodged against the company [REDACTED] via IMI Article 61 procedure 93092
5. The complaint is therefore based on Article 15 GDPR.
6. On the basis of this complaint and in accordance with Article 57(1)(f) GDPR, the CNPD requested [REDACTED] to take a position on the facts reported by the complainant and to provide a detailed description of the issue relating to the processing of the complainant's personal data, in particular with regard to her right of access.
7. The CNPD received the requested information within the deadlines set.
## II. In law
### 1. Applicable legal provisions
8. Article 77 GDPR provides that "without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, (...) if the data subject considers that the processing of personal data relating to him or her infringes this Regulation."
9. In accordance with Article 15 GDPR "The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information (...)";
10. Recital 57 of the GDPR indicates that "If the personal data processed by a controller do not permit the controller to identify a natural person, the data controller should not be obliged to acquire additional information in order to identify the data subject for the sole purpose of complying with any provision of this Regulation. However, the controller should not refuse to take additional information provided by the data subject in order to support the exercise of his or her rights. Identification should include the digital identification of a data subject, for example through authentication mechanism such as the same credentials, used by the data subject to log-in to the on-line service offered by the data controller".
2
CNPD
COMMISSION
NATIONALE
POUR LA
PROTECTION
DES DONNEES
Deliberation No 81_RECL62_2025 of 26 September 2025 of the National Data Protection Commission, in a plenary session, on complaint file No 4.358 lodged against the company [REDACTED] via IMI Article 61 procedure 93092
11. Furthermore, in application of Article 12(2) GDPR "the controller shall facilitate the exercise of data subject rights under Articles 15 to 22". Recital 59 GDPR emphasises that "Modalities should be provided for facilitating the exercise of the data subject's rights under this Regulation, including mechanisms to request and, if applicable, obtain, free of charge, in particular, access to and rectification or erasure of personal data and the exercise of the right to object. The controller should also provide means for requests to be made electronically, especially where personal data are processed by electronic means."
12. Article 12(4) GDPR provides that "If the controller does not take action on the request of the data subject, the controller shall inform the data subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy."
13. Article 56(1) GDPR provides that "(...) the supervisory authority of the main establishment or of the single establishment of the controller or processor shall be competent to act as lead supervisory authority for the cross-border processing carried out by that controller or processor in accordance with the procedure provided in Article 60";
14. According to Article 60(1) GDPR, "The lead supervisory authority shall cooperate with the other supervisory authorities concerned in accordance with this Article in an endeavour to reach consensus. The lead supervisory authority and the supervisory authorities concerned shall exchange all relevant information with each other";
15. According to Article 60(3) GDPR, "The lead supervisory authority shall, without delay, communicate the relevant information on the matter to the other supervisory authorities concerned. It shall without delay submit a draft decision to the other supervisory authorities concerned for their opinion and take due account of their views";
## 2. In the present case
16. Following the intervention of the Luxembourg supervisory authority, the Controller confirmed that:
- For obvious security reasons, it requires its customers to provide evidence of their identity in connection with a DSAR.
3
CNPD
COMMISSION
NATIONALE
POUR LA
PROTECTION
DES DONNEES
Deliberation No 81_RECL62_2025 of 26 September 2025 of the National Data Protection Commission, in a plenary session, on complaint file No 4.358 lodged against the company [REDACTED] via IMI Article 61 procedure 93092
- It received the two e-mails from the complainant and replied to each of them by providing her with information regarding the DSAR process, including the steps she should take to self-authenticate her identity online through her [REDACTED] account as this was still the easiest way for the customer to identify themselves and for the controller to properly identify the requestor as holder of the respective customer account in order to make sure to only disclose personal data to the respective data subject.
- If the customer does not want this, the Controller will not refuse to use alternative ways of identification, especially where a customer no longer has access to his or her account or is unable to self-authenticate.
- In this case, the complainant did not follow up on the Controller's emails to tell it if she did not want to submit a DSAR through her account.
- It emailed the complainant again to ask her if she would like to submit a DSAR through an alternative method of verification other than submitting a request through her account and worked with her to carry out that request.
17. After a second intervention by the CNPD, [REDACTED] further informed the CNPD that:
- The complainant's account was previously blocked and that it became accessible again.
- The complainant could therefore submit a DSAR also via the contact form in her logged account.
### 3. Outcome of the case
18. The CNPD, in a plenary session, therefore considers that, at the end of the investigation of the present complaint, the Controller has taken appropriate measures to grant the complainant's right of access request, in accordance with Article 15 GDPR.
19. Thus, in the light of the foregoing, and the residual nature of the gravity of the alleged facts and the degree of impact on fundamental rights and freedoms, it does not appear necessary to continue to deal with that complaint.
4
CNPD
COMMISSION
NATIONALE
POUR LA
PROTECTION
DES DONNEES
Deliberation No 81_RECL62_2025 of 26 September 2025 of the National Data Protection Commission, in a plenary session, on complaint file No 4.358 lodged against the company [REDACTED] via IMI Article 61 procedure 93092
20. The CNPD then consulted the supervisory authority of Bavaria (Germany), pursuant to Article 60(1), whether it agreed to close the case. The Supervisory Authority of Bavaria has responded affirmatively, so that the CNPD has therefore concluded that no further action was necessary and that the cross-border complaint could be closed.
In light of the above developments, the National Data Protection Commission, in a plenary session, after having deliberated, decides:
- To close the complaint file 4.358 upon completion of its investigation, in accordance with the Complaints Procedure before the CNPD. As per Article 60(7) GDPR, the lead supervisory authority shall adopt and notify the decision to the main establishment or single establishment of the Controller.
Belvaux, dated 26 September 2025
The National Data Protection Commission
| | | | |
| --- | --- | --- | --- |
| Chair | Commissioner | Commissioner | Commissioner |
### Indication of remedies
This Administrative Decision may be the subject of an appeal for amendment within three months of its notification. Such an action must be brought by the interested party before the administrative court and must be brought by a lawyer at the Court of one of the Bar Associations.
5