The Danish authority criticizes a bank for its handling of a data access request
The Danish Data Protection Authority issued a formal criticism against a credit institution, not for deleting access logs, but for its faulty handling of a right of access request, notably by attempting to condition a refund on the withdrawal of the request and by failing to meet response deadlines.
Facts and context
The Danish Data Protection Authority (Datatilsynet) published a criticism decision against a credit institution for breaches related to the handling of a right of access request.
The case originated from a complaint by a client who, suspecting their ex-partner employed by the institution had accessed their accounts without authorization, exercised their right of access to connection logs for the period 2015-2021.
Grounds for the decision
The authority first recalled that, according to the case law of the Court of Justice of the European Union (case C-579/21 of 22 June 2023), information relating to the dates and purposes of personal data consultations contained in access logs is indeed covered by the right of access. However, the authority found no reason to challenge the institution's explanation that the requested logs had been deleted in accordance with its usual procedures (six months retention) and were not subject to the retention obligations of anti-money laundering legislation. The breach therefore does not lie in the non-provision of the logs, but in the way the request was handled.
Obligation to facilitate the exercise of rights and to respond within deadlines (Article 12 of the GDPR): The authority noted several breaches of this article. First, the credit institution conditioned the refund of banking fees on the complainant withdrawing their access request, which contravenes the obligation to "facilitate the exercise of rights" under paragraph 2. Second, the institution responded to the request nearly three months after receipt (maintained on 23 March 2023, response on 20 June 2023), thus violating the one-month maximum deadline set by paragraph 3. Finally, in its late response, the institution wrongly stated that clients could not demand access logs; if it intended to refuse the request, it should have informed the complainant without delay and at the latest within one month, providing reasons for the refusal and informing them of their remedies, as required by paragraph 4.
Authority's decision
Consequently, the authority issued a criticism against the credit institution.
Lessons learned
This decision reminds that:
The exercise of a data subject's rights cannot be conditioned on the withdrawal of another procedure or a financial advantage, such practice constituting a breach of the obligation to facilitate the exercise of these rights.
The one-month response deadline to a rights exercise request is mandatory, even if the requested information is no longer held by the controller.
Following the CJEU ruling (case C-579/21), information on the dates and purposes of personal data consultations contained in access logs is covered by the right of access.
In case of refusal to grant a request, the controller must notify their motivated decision to the data subject within one month, informing them of their remedies.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire