Isabel SA – €120,000 Fine (Belgium, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Isabel SA was fined €120,000 for failing to respond to a user's requests about their data. The company did not reply to emails from a manager who wanted to know how their personal information was being used. This case shows that businesses must be responsive to user inquiries about their data rights.
What happened
Isabel SA failed to respond to a user's emails regarding their personal data processing.
Who was affected
A company manager who used Isabel SA's TruliUs service for digital authentication.
What the authority found
The data protection authority ruled that Isabel SA violated GDPR rules by not addressing the user's requests for information about their data.
Why this matters
This ruling stresses the importance of timely communication with users about their data rights. Companies should ensure they have processes in place to handle such inquiries effectively.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The data subject was the manager of a company who used TruliUs. TruliUs was a digital authentication and identification service developed by Isabel SA (the controller), allowing natural persons to prove their identity and authority to act on behalf of a company when accessing third party business platforms. In that capacity, the data subject used this solution to authenticate themselves and prove that they were authorised to act on behalf of their company when accessing their accountant’s digital platform. The data subject had sent two emails to the DPO contact address indicated in Trulius’ privacy notice, on 11 and 19 March 2021, but received no reply. On 29 March, 2021, the data subject lodged a complaint with the DPA against the controller. The controller argued that, for the TruliUs authentication and identification processing, it acted only as a processor and not as a controller. It submitted that TruliUs was a standardised service made available to its clients, who freely decided whether to use it and thereby determined the purposes and essential means of the processing. According to the controller, the purpose of authentication and identification served only its clients’ interests. It further argued that the clients determined key elements such as the recipients of the data, the data subjects concerned and the duration of the processing. Also, that the use of the service was optional because traditional identification methods remained available. The controller further relied on the service’s terms and its internal documentation, which classified itself as a processor acting on behalf of the client. Therefore, the controller considered the data subject’s company to be the controller. The data subject contested this position. They argued that their company could not be considered responsible for processing carried out through this platform, where their data were collected and processed. They stressed that neither they nor their platform had practical control ov
Related Enforcement Actions (0)
No other enforcement actions found for Isabel SA in BE
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
12 May 2026
Authority
Autorité de Protection des Données
Fine Amount
€120,000
GDPRhub ID
gdprhub-10006About this data
Cite as: Cookie Fines. Isabel SA - Belgium (2026). Retrieved from cookiefines.eu
Last updated: