FPS Finance – Complaint Upheld (Belgium, 2020)
The Belgian Data Protection Authority found that FPS Finance wrongly required users to create a Microsoft account to access tax information on FisconetPlus. This violated GDPR rules because it forced users to share personal data with Microsoft unnecessarily. The decision highlights the importance of not making public services contingent on private data sharing.
What happened
FPS Finance required users to create a Microsoft account to access FisconetPlus, leading to unnecessary data sharing.
Who was affected
Users trying to access Belgian tax information on the FisconetPlus platform.
What the authority found
The authority decided that FPS Finance had no valid legal basis for requiring users to share personal data with Microsoft, violating GDPR rules.
Why this matters
This case emphasizes that public services should not force users to share personal data with third parties. It serves as a reminder for government bodies to ensure their digital services comply with privacy laws.
GDPR Articles Cited
The Federal Public Service of Finance maintain FisconetPlus, an online repository of Belgian tax laws, rulings and guidelines, aimed at informing tax payers on taxation questions and at easing their fiscal compliance. As a part of a revamp in 2018, FisconetPlus was moved to a SharePoint website, hosted in the Belgian federal government’s G-Cloud infrastructure. Thereafter, access to the repository was still free but required logging on to the portal with a Microsoft user account. As a part of their registration process for a Microsoft account, users needed to accept Microsoft’s privacy policy, which by default enabled certain tracking and advertising features. This change within FisconetPlus was examined by the Belgian Data Protection Authority, following a series of complaints. The DPA’s Inspection Service found in February 2019 that the update constituted a breach of the GDPR. The DPA considered that there was no legal basis that would allow the FPS Finance to force citizens to entrust their personal data to a private undertaking as a precondition for accessing public sector information. In June 2020, the DPA’s Inspection Service issued (for the first time in history!) a provisional measure that obliged the FPS Finance to provisionally suspend FisconetPlus, specifically the access to the repository via Microsoft’s SharePoint portal. This decision followed the recommendation published by the DPA’s in February 2019 on the obligation to create a user account with Microsoft for the purpose of consulting public service applications. As a result, the FPS Finance deactivated the access to its FisconetPlus portal via a Microsoft account, which however remained accessible through other means of access. The FPS Finance promised to rewrite FisconetPlus and switch from Microsoft tools to a platform developed internally and hosted entirely on its own infrastructure. Identification and authentication would then be done via the Federal Authentication Service ("FAS”); the creat
Outcome
Complaint Upheld
A data subject complaint that was upheld by the DPA.
Violations (2)
Cookie consent checkboxes are pre-selected by default, violating the requirement for active, affirmative consent.
Art. 4(11) GDPR
Third-party tracking cookies or scripts are loaded without obtaining prior user consent.
Art. 13, 14 GDPR
Related Enforcement Actions (0)
No other enforcement actions found for FPS Finance in BE
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
About this data
Cite as: Cookie Fines. FPS Finance - Belgium (2020). Retrieved from cookiefines.eu
Last updated: