CNPD}| | Deliberation No 21_RECLEU16_2026 of 10 February 2026 of the
samen National Data Protection Commission, in a plenary session, on
complaint file No 11.244 lodged against the company
HE via (Mi Article 61 procedure 570820
Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27
April 2016 on the protection of natural persons with regard to the processing of personal data and
on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the “GDPR’);
Having regard to the Act of 1 August 2018 on the organisation of the National Data Protection
Commission and the general data protection framework;
Having regard to the Rules of Procedure of the National Data Protection Commission adopted by
Decision No 07AD/2024 of 23 February 2024;
Having regard to the Procedure for complaints before the National Data Protection Commission
adopted on 16 October 2020 (hereinafter referred to as the “Complaint Procedure before the
CNPD”);
Having regard to the following:
L. Facts and procedure
1. In the framework of the European cooperation, as provided for in Chapter VII of
Regulation (EU) 2016/679 on the protection of natural persons with regard to the
processing of personal data and on the free movement of such data, and repealing
Directive 95/46/EC (General Data Protection Regulation or GDPR), the
Supervisory Authority of Bavaria for the Private Sector submitted to the National
Data Protection Commission (hereinafter: “the CNPD”) a complaint (national
reference of the concerned authority: LDA-1085.3-6580/23-l1) via IMI in
accordance with Article 61 procedure - 570820.
2. The complaint was lodged against the controller
(hereinafter J or the “controller’), who has its main establishment in
Luxembourg. Under Article 56 GDPR, the CNPD is therefore competent to act as
the lead supervisory authority.
3. The original IMI claim stated that the complainant deleted his gy account in
2022. NS confirmed the complainant by telephone that all his personal data
had been deleted. However, the complainant received unsolicited/unordered
deliveries from J (e.g. 11 August 2023) and concluded that the company
did not delete his data.
4. In essence, the complainant asked the CNPD to verify if his personal data has
been deleted by the controller.
5. The complaint is therefore based on Article 17 GDPR.
1.
6.
7.
On the basis of this complaint and in accordance with Article 57(1)(f) GDPR, the
CNPD requested (J to take a position on the facts reported by the
complainant and to provide a detailed description of the issue relating to the
processing of the complainant's personal data, in particular with regard to his
request for erasure. Moreover, the CNPD required to proceed to the
deletion of the complainant’s personal data as soon as possible, unless legal
reasons prevent the former from doing so.
The CNPD received the requested information within the deadlines set.
In law
Applicable legal provisions
10.
11.
Article 77 GDPR provides that “without prejudice to any other administrative or
judicial remedy, every data subject shall have the right to lodge a complaint with
a supervisory authority, (...) if the data subject considers that the processing of
personal data relating to him or her infringes this Regulation.”
Pursuant to Article 17 GDPR, a data subject may request the erasure of his or her
personal data and the controller must erase the data subject's personal data
without undue delay if one of the grounds provided for in Article 17 (1) GDPR
applies unless the controller can demonstrate that the processing falls within the
scope of one of the exceptions set out in Article 17 (3) GDPR.
Furthermore, in application of Article 12(2) GDPR "the controller shall facilitate the
exercise of data subject rights under Articles 15 to 22”. Recital 59 GDPR
emphasises that “Modalities should be provided for facilitating the exercise of the
data subject's rights under this Regulation, including mechanisms to request and,
if applicable, obtain, free of charge, in particular, access to and rectification or
erasure of personal data and the exercise of the right to object. The controller
should also provide means for requests to be made electronically, especially
where personal data are processed by electronic means.”
Article 56(1) GDPR provides that “(...) the supervisory authority of the main
establishment or of the single establishment of the controller or processor shall be
competent to act as lead supervisory authority for the cross-border processing
carried out by that controller or processor in accordance with the procedure
provided in Article 60”;
12.
13.
14.
According to Article 60(1) GDPR, "The lead supervisory authority shall cooperate
with the other supervisory authorities concerned in accordance with this Article in
an endeavour to reach consensus. The lead supervisory authority and the
supervisory authorities concerned shall exchange all relevant information with
each other’;
According to Article 60(3) GDPR, "The lead supervisory authority shall, without
delay, communicate the relevant information on the matter to the other
supervisory authorities concerned. It shall without delay submit a draft decision to
the other supervisory authorities concerned for their opinion and take due account
of their views”;
. Inthe present case
Following the intervention of the Luxembourg supervisory authority, the controller
confirmed that they have investigated this matter and confirmed that there is no
customer account associated with the complainant’s email address.
HE @!so confirmed that the complainant was in contact with the customer
service in August and September 2023 regarding numerous fraudulent orders.
These orders were placed by a bad actor via a fraudulent customer account using
the complainant's personal information (name and address). The fraudulent
customer account has been blocked and all orders either cancelled or the debt
written off. To their knowledge, the complainant did not suffer any financial
damage.
The controller has no indication of a data breach on | Side regarding the
complainant’s personal information. To prevent the abuse of personal data,
MMMM has security measures in place to detect fraudulent behavior and
maintain physical, electronic as well as procedural safeguards. However, identity
thefts which takes place outside of jg can hardly be prevented by qa.
According to the controller, there are many different ways how the complainant's
name and address could have been obtained outside of NN, such as public
mailing lists, phone books or breaches on other websites.
Finally, the controller underlines that, to prevent similar cases in the future, they
have implemented additional measures to block the creation of fraudulent jy
accounts using the same data or patterns as those used in the blocked account.
CNPD
HE Will inform the complainant of the abuse of his personal information by a
third-party and of their further actions.
The CNPD therefore concludes that the controller has taken all appropriate
measures to resolve the matter.
3. Outcome of the case
15. The CNPD, in a plenary session, therefore considers that, at the end of the
investigation of the present complaint, the controller has taken appropriate
measures to grant the complainant's right to erasure, in accordance with Article
17 GDPR.
16. Thus, in the light of the foregoing, and the residual nature of the gravity of the
alleged facts and the degree of impact on fundamental rights and freedoms, it
does not appear necessary to continue to deal with that complaint.
In light of the above developments, the National Data Protection Commission, in a
plenary session, after having deliberated, decides:
- To close the complaint file 11.244 upon completion of its investigation, in accordance
with the Complaints Procedure before the CNPD. As per Article 60(7) GDPR, the lead
supervisory authority shall adopt and notify the decision to the main establishment or
single establishment of the controller.
Belvaux, dated 10 February 2026
The National Data Protection Commission
Chair Commissioner Commissioner Commissioner
Indication of remedies
This Administrative Decision may be the subject of an appeal for amendment within three months
of its notification. Such an action must be brought by the interested party before the administrative
court and must be brought by a lawyer at the Court of one of the Bar Associations.