{"id":101691,"date":"2025-12-08T22:58:50","date_gmt":"2025-12-08T21:58:50","guid":{"rendered":"https:\/\/www.ictrechtswijzer.be\/?p=101691"},"modified":"2025-12-08T23:11:11","modified_gmt":"2025-12-08T22:11:11","slug":"access-to-log-files-under-the-gdpr-are-you-allowed-to-know-which-employee-has-viewed-your-file","status":"publish","type":"post","link":"https:\/\/www.ictrechtswijzer.be\/en\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\/","title":{"rendered":"Access to log files under the GDPR: are you allowed to know which employee has viewed your file?"},"content":{"rendered":"<p class=\"wp-block-paragraph\">The right of access is one of the cornerstones of the <a href=\"https:\/\/www.ictrechtswijzer.be\/en\/data-protection\/\" target=\"_blank\" rel=\"noreferrer noopener\">General Data Protection Regulation (GDPR)<\/a>. Many citizens wonder how far this right extends: as a data subject, can you demand that an organization, such as a government agency or bank, disclose exactly which specific employee has accessed your file and at what time? The answer is nuanced. Although you have the right to access the processing history (log files), the Court of Justice of the European Union ruled in a ruling of 3 December 2025 (<a href=\"https:\/\/curia.europa.eu\/juris\/document\/document.jsf;jsessionid=38334C1BB5A0AD0576E9D580F055F89A?text=&amp;docid=306790&amp;pageIndex=0&amp;doclang=EN&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=1097193\" target=\"_blank\" rel=\"noreferrer noopener\">Cases T-318\/24 and T-362\/24<\/a>) that this does not automatically mean that you will be given the names of individual employees.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-de-feiten-en-context\">The facts and context<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This legal issue was addressed in a case before the General Court of the European Union (hereinafter: the General Court) between a job applicant and the European Personnel Selection Office (EPSO)<sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The applicant, who had participated in various selection procedures, submitted a request for access based on <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2018\/1725\/oj?locale=nl\">Regulation<\/a><a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2018\/1725\/oj?locale=nl\" target=\"_blank\" rel=\"noreferrer noopener\"> <\/a><a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2018\/1725\/oj?locale=nl\">(EU) 2018\/1725<\/a>. This is a specific regulation for EU institutions, which is virtually identical in content to the general GDPR that applies to Belgian companies and public authorities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Among other things, the applicant demanded full access to the \u201clog files\u201d of his profile. He wanted to know not only when his file had been consulted, but also by whom (the identity of the EPSO staff members) and for what specific purpose. EPSO refused to disclose the names of the staff members, citing the protection of their rights and freedoms. In addition, the applicant demanded the \u201crestoration\u201d of data that EPSO had deleted after a retention period of two years.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-de-beslissing-van-het-gerecht\">The decision of the General Court<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The General Court upheld the European Commission's (responsible for EPSO) position on all counts and dismissed the applicant's claims.<sup><\/sup>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. No automatic right to employee names<\/strong> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Court referred to the earlier <a href=\"https:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;docid=274867&amp;pageIndex=0&amp;doclang=NL&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=1098956\" target=\"_blank\" rel=\"noreferrer noopener\">Pankki S judgment<\/a> of the Court of Justice. It ruled that employees who process personal data under the authority of their employer are not considered \u201crecipients\u201d of that data within the meaning of data protection law. Although log files contain useful information about the lawfulness of the processing, the interest of the data subject in knowing the identity of the employee does not generally outweigh the rights and freedoms of those employees. Unless this information is essential for the data subject to exercise their rights (e.g., in the case of a concrete suspicion of abuse), the controller is not required to disclose the names of its staff.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. Deletion is permanent<\/strong> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Court confirmed that the deletion of data after the expiry of the retention period constitutes lawful processing. Data protection law does not recognize a \u201cright to restoration\u201d of lawfully deleted data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Access to data, not documents<\/strong> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, the Court reiterated that the right of access relates to the personal data itself, and not to the documents (such as internal notes, chats, or emails) as such. If the controller claims that certain data does not exist, there is a presumption of lawfulness that the applicant must rebut with evidence.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-juridische-analyse-en-duiding\">Legal analysis and interpretation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Thisruling confirms the consistent line in European case law on the balance between the right of access (Article 15 GDPR \/ Article 17 Regulation 2018\/1725) and the rights of third parties.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The key point is the interpretation of the term \u2018recipient\u2019.<strong>\u2018<\/strong>. The legislation requires organizations to be transparent about the recipients to whom data is provided. However, internal staff acting under the instructions of the controller do not legally qualify as \u2018recipients\u2019 (third parties), but as an extension of the organization itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is of great importance in practice. An unlimited right to access information about who clicks on which file internally could lead to the \u201cnaming and shaming\u201d of employees or civil servants who are simply doing their job. The Court applies a proportionality test here<strong>:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The log files must show the frequency and intensity of the consultations (so that citizens can check whether this is abnormal).<\/li>\n\n\n\n<li>The identity of the person seeking advice remains confidential, unless the citizen can demonstrate that this information is necessary for legal proceedings (e.g., in the case of a complaint about unlawful access by an ex-partner who works for the service).<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, the ruling emphasizes the importance of data minimization and storage limitation. The fact that EPSO deleted data after two years was not considered a violation, but rather compliance with Article 4(1)(e) (storage limitation) and Article 19 (erasure). The applicant's argument that this deletion was \u201cunlawful\u201d because he still needed the data was rejected. An organization may and must erase data when the need for processing ceases to exist.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-wat-dit-concreet-betekent\">What this specifically means<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The impact of this ruling extends beyond EU institutions; the principles are directly applicable to the Belgian private and public sectors under the GDPR.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>For the citizen (data subject):<\/strong> You have the right to know when your file has been accessed and why. However, do not expect to receive a list of names of individual bank employees, nurses, or civil servants as a matter of course. You will have to demonstrate why you need those specific names in order to defend your rights.<\/li>\n\n\n\n<li><strong>For employers and organizations:<\/strong> You are required to keep log files (\u201clogging\u201d) in order to demonstrate the security and legitimacy of the processing (accountability). However, in the event of a request for access, you may anonymize or redact the names of your employees, unless there are exceptional circumstances. This protects your staff from unnecessary exposure.<\/li>\n\n\n\n<li><strong>Regarding internal communication:<\/strong> A request for access is not a \u2018fishing expedition\u2019 for internal emails or Teams chats. You only need to provide the personal data from those documents, not the documents themselves, unless they are inextricably linked.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-faq-veelgestelde-vragen\">FAQ: Frequently asked questions <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Am I entitled to a list of names of everyone who has viewed my file?<\/strong> <br>No, in principle not. You have the right to access the processing activities (times, purposes), but the specific names of employees who performed their work are usually protected to safeguard their privacy, unless you can prove that you need these names for legal proceedings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Can I demand that an organization restore my deleted data?<\/strong> <br>No. If an organization has deleted your data in accordance with their retention periods (retention policy), this is a lawful action. The GDPR does not recognize a \u201cright to restoration\u201d of correctly deleted data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Does this also apply to internal memos and chat sessions about me?<\/strong> <br>The right of access gives you access to your personal data, not necessarily to the internal documents themselves. An organization can suffice with an overview of the processed data, without handing over copies of all internal chats or minutes, as long as you can verify that the data is correct.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-conclusie\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The recent ruling in the case <em>WS against the European Commission<\/em> confirms that data protection law is not an absolute right, but must always be balanced against the rights of others, including employees of the processing organization. Transparency is mandatory, but complete openness about internal personnel actions is not, unless there are valid reasons for it.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.ictrechtswijzer.be\/en\/contact\/\" target=\"_blank\" rel=\"noreferrer noopener\">Are you involved in a dispute about the processing of your personal data or are you faced with a complex request for access? Our attorneys, who specialize in data protection and GDPR compliance, are ready to analyze your case and defend your interests. Feel free to contact us for initial advice.<\/a><\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>","protected":false},"excerpt":{"rendered":"<p>Het recht op inzage is een van de hoekstenen van de Algemene Verordening Gegevensbescherming (GDPR\/AVG). Veel burgers vragen zich af hoe ver dit recht reikt: mag u als betrokkene eisen dat een organisatie, zoals een overheidsdienst of bank, exact meedeelt welke specifieke werknemer uw dossier heeft ingekeken en op welk tijdstip? Het antwoord is genuanceerd. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":101692,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[61],"tags":[],"class_list":["post-101691","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-gdpr"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Inzage in logbestanden onder de GDPR: mag u weten welke werknemer uw dossier heeft bekeken? - ICT Rechtswijzer Advocaat<\/title>\n<meta name=\"description\" content=\"Wie bekeek uw dossier? Een recent Europees arrest bevestigt: het GDPR-inzagerecht geeft geen automatisch recht op de namen van werknemers in logbestanden. Lees onze juridische analyse.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ictrechtswijzer.be\/en\/access-to-log-files-under-the-gdpr-are-you-allowed-to-know-which-employee-has-viewed-your-file\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Inzage in logbestanden onder de GDPR: mag u weten welke werknemer uw dossier heeft bekeken?\" \/>\n<meta property=\"og:description\" content=\"Wie bekeek uw dossier? Een recent Europees arrest bevestigt: het GDPR-inzagerecht geeft geen automatisch recht op de namen van werknemers in logbestanden. Lees onze juridische analyse.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ictrechtswijzer.be\/en\/access-to-log-files-under-the-gdpr-are-you-allowed-to-know-which-employee-has-viewed-your-file\/\" \/>\n<meta property=\"og:site_name\" content=\"ICT Rechtswijzer Advocaat\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-08T21:58:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-12-08T22:11:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/12\/analyst-6492859_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"797\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Joris Deene\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Joris Deene\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\\\/\"},\"author\":{\"name\":\"Joris Deene\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/person\\\/29025dc007e8d33a89422580a534d685\"},\"headline\":\"Inzage in logbestanden onder de GDPR: mag u weten welke werknemer uw dossier heeft bekeken?\",\"datePublished\":\"2025-12-08T21:58:50+00:00\",\"dateModified\":\"2025-12-08T22:11:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\\\/\"},\"wordCount\":1170,\"publisher\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/analyst-6492859_1280.jpg\",\"articleSection\":[\"GDPR - AVG\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\\\/\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\\\/\",\"name\":\"Inzage in logbestanden onder de GDPR: mag u weten welke werknemer uw dossier heeft bekeken? - ICT Rechtswijzer Advocaat\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/analyst-6492859_1280.jpg\",\"datePublished\":\"2025-12-08T21:58:50+00:00\",\"dateModified\":\"2025-12-08T22:11:11+00:00\",\"description\":\"Wie bekeek uw dossier? Een recent Europees arrest bevestigt: het GDPR-inzagerecht geeft geen automatisch recht op de namen van werknemers in logbestanden. Lees onze juridische analyse.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.ictrechtswijzer.be\\\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/analyst-6492859_1280.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/analyst-6492859_1280.jpg\",\"width\":1280,\"height\":797},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Inzage in logbestanden onder de GDPR: mag u weten welke werknemer uw dossier heeft bekeken?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#website\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/\",\"name\":\"ICT Rechtswijzer Advocaat\",\"description\":\"Advocaten in IP, AI, IT, privacy &amp; media\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Organization\",\"LegalService\"],\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#organization\",\"name\":\"ICT Rechtswijzer\",\"alternateName\":\"ICT Rechtswijzer, kennisplatform van Everest Advocaten\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg\",\"width\":638,\"height\":479,\"caption\":\"ICT Rechtswijzer\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/be.linkedin.com\\\/company\\\/everest-law\",\"https:\\\/\\\/www.everest-law.eu\\\/\"],\"description\":\"Kennisplatform van het departement intellectuele eigendom, IT-recht, AI-recht, gegevensbescherming en mediarecht van Everest Advocaten, onder leiding van mr. Joris Deene.\",\"parentOrganization\":{\"@type\":\"LegalService\",\"name\":\"Everest Advocaten\",\"url\":\"https:\\\/\\\/www.everest-law.eu\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"Bollebergen 2A bus 20\",\"postalCode\":\"9052\",\"addressLocality\":\"Gent\",\"addressCountry\":\"BE\"}}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/person\\\/29025dc007e8d33a89422580a534d685\",\"name\":\"Joris Deene\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g\",\"caption\":\"Joris Deene\"},\"description\":\"Mr. Joris Deene is advocaat-partner bij Everest Advocaten en leidt het departement intellectuele eigendom, IT-recht, AI-recht, gegevensbescherming en mediarecht. ICT Rechtswijzer is het kennisplatform van dat departement. Joris publiceert en doceert over auteursrecht, merkenrecht, softwarerecht, de AVG, de AI-Act, de DSA en het mediarecht.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/joris-deene-5144096\\\/\"],\"honorificPrefix\":\"Mr.\",\"knowsAbout\":[\"intellectuele eigendom\",\"auteursrecht\",\"merkenrecht\",\"IT-recht\",\"AI-recht\",\"gegevensbescherming\",\"AVG\",\"mediarecht\",\"digitaledienstenverordening\",\"AI-verordening\"],\"knowsLanguage\":[\"Nederlands\",\"Engels\",\"Frans\"],\"jobTitle\":\"Advocaat-partner, hoofd departement intellectuele eigendom, IT-recht, AI-recht, gegevensbescherming en mediarecht\",\"worksFor\":\"Everest Advocaten\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/en\\\/author\\\/joris-deene\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Access to log files under the GDPR: are you allowed to know which employee has viewed your file? - ICT Legal Guide Lawyer","description":"Who viewed your file? A recent European ruling confirms that the GDPR right of access does not automatically entitle you to the names of employees in log files. Read our legal analysis.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ictrechtswijzer.be\/en\/access-to-log-files-under-the-gdpr-are-you-allowed-to-know-which-employee-has-viewed-your-file\/","og_locale":"en_US","og_type":"article","og_title":"Inzage in logbestanden onder de GDPR: mag u weten welke werknemer uw dossier heeft bekeken?","og_description":"Wie bekeek uw dossier? Een recent Europees arrest bevestigt: het GDPR-inzagerecht geeft geen automatisch recht op de namen van werknemers in logbestanden. Lees onze juridische analyse.","og_url":"https:\/\/www.ictrechtswijzer.be\/en\/access-to-log-files-under-the-gdpr-are-you-allowed-to-know-which-employee-has-viewed-your-file\/","og_site_name":"ICT Rechtswijzer Advocaat","article_published_time":"2025-12-08T21:58:50+00:00","article_modified_time":"2025-12-08T22:11:11+00:00","og_image":[{"width":1280,"height":797,"url":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/12\/analyst-6492859_1280.jpg","type":"image\/jpeg"}],"author":"Joris Deene","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Joris Deene","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ictrechtswijzer.be\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\/#article","isPartOf":{"@id":"https:\/\/www.ictrechtswijzer.be\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\/"},"author":{"name":"Joris Deene","@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/person\/29025dc007e8d33a89422580a534d685"},"headline":"Inzage in logbestanden onder de GDPR: mag u weten welke werknemer uw dossier heeft bekeken?","datePublished":"2025-12-08T21:58:50+00:00","dateModified":"2025-12-08T22:11:11+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ictrechtswijzer.be\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\/"},"wordCount":1170,"publisher":{"@id":"https:\/\/www.ictrechtswijzer.be\/#organization"},"image":{"@id":"https:\/\/www.ictrechtswijzer.be\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/12\/analyst-6492859_1280.jpg","articleSection":["GDPR - AVG"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.ictrechtswijzer.be\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\/","url":"https:\/\/www.ictrechtswijzer.be\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\/","name":"Access to log files under the GDPR: are you allowed to know which employee has viewed your file? - ICT Legal Guide Lawyer","isPartOf":{"@id":"https:\/\/www.ictrechtswijzer.be\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.ictrechtswijzer.be\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\/#primaryimage"},"image":{"@id":"https:\/\/www.ictrechtswijzer.be\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/12\/analyst-6492859_1280.jpg","datePublished":"2025-12-08T21:58:50+00:00","dateModified":"2025-12-08T22:11:11+00:00","description":"Who viewed your file? A recent European ruling confirms that the GDPR right of access does not automatically entitle you to the names of employees in log files. Read our legal analysis.","breadcrumb":{"@id":"https:\/\/www.ictrechtswijzer.be\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ictrechtswijzer.be\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ictrechtswijzer.be\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\/#primaryimage","url":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/12\/analyst-6492859_1280.jpg","contentUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/12\/analyst-6492859_1280.jpg","width":1280,"height":797},{"@type":"BreadcrumbList","@id":"https:\/\/www.ictrechtswijzer.be\/inzage-in-logbestanden-onder-de-gdpr-mag-u-weten-welke-werknemer-uw-dossier-heeft-bekeken\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ictrechtswijzer.be\/"},{"@type":"ListItem","position":2,"name":"Inzage in logbestanden onder de GDPR: mag u weten welke werknemer uw dossier heeft bekeken?"}]},{"@type":"WebSite","@id":"https:\/\/www.ictrechtswijzer.be\/#website","url":"https:\/\/www.ictrechtswijzer.be\/","name":"ICT Lawyer","description":"Lawyers in IP, AI, IT, privacy &amp; media","publisher":{"@id":"https:\/\/www.ictrechtswijzer.be\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ictrechtswijzer.be\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Organization","LegalService"],"@id":"https:\/\/www.ictrechtswijzer.be\/#organization","name":"ICT Legal Guide","alternateName":"ICT Rechtswijzer, kennisplatform van Everest Advocaten","url":"https:\/\/www.ictrechtswijzer.be\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/logo\/image\/","url":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2018\/08\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg","contentUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2018\/08\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg","width":638,"height":479,"caption":"ICT Rechtswijzer"},"image":{"@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/be.linkedin.com\/company\/everest-law","https:\/\/www.everest-law.eu\/"],"description":"Knowledge platform of the Intellectual Property, IT Law, AI Law, Data Protection, and Media Law department at Everest Advocaten, led by Joris Deene, Esq.","parentOrganization":{"@type":"LegalService","name":"Everest Advocaten","url":"https:\/\/www.everest-law.eu","address":{"@type":"PostalAddress","streetAddress":"Bollebergen 2A bus 20","postalCode":"9052","addressLocality":"Gent","addressCountry":"BE"}}},{"@type":"Person","@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/person\/29025dc007e8d33a89422580a534d685","name":"Joris Deene","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g","caption":"Joris Deene"},"description":"Mr. Joris Deene is a partner at Everest Attorneys and heads the department of intellectual property, IT law, AI law, data protection, and media law. ICT Legal Guide is that department\u2019s knowledge platform. Joris publishes and teaches on copyright law, trademark law, software law, the GDPR, the AI Act, the DSA, and media law.","sameAs":["https:\/\/www.linkedin.com\/in\/joris-deene-5144096\/"],"honorificPrefix":"Mr.","knowsAbout":["intellectuele eigendom","auteursrecht","merkenrecht","IT-recht","AI-recht","gegevensbescherming","AVG","mediarecht","digitaledienstenverordening","AI-verordening"],"knowsLanguage":["Nederlands","Engels","Frans"],"jobTitle":"Advocaat-partner, hoofd departement intellectuele eigendom, IT-recht, AI-recht, gegevensbescherming en mediarecht","worksFor":"Everest Advocaten","url":"https:\/\/www.ictrechtswijzer.be\/en\/author\/joris-deene\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/posts\/101691","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/comments?post=101691"}],"version-history":[{"count":0,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/posts\/101691\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/media\/101692"}],"wp:attachment":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/media?parent=101691"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/categories?post=101691"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/tags?post=101691"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}