
Introduction
LM Oost-Vlaanderen is a Belgian social security mutuality serving members across the province of East Flanders. As a social security organisation, it operates under strict sector-specific regulations and handles some of the most sensitive personal data categories that exist: health records, financial entitlements, and member identity.
The problem
In 2023, LM Oost-Vlaanderen received a formal questionnaire from the Belgian Data Protection Authority (GBA/APD) about a data incident that had occurred two years earlier. They had 30 days to deliver a complete, legally sound response. Reconstructing events from that far back, aligning technical evidence with legal obligations, and producing a defensible submission, all under a fixed deadline, was beyond what their internal team could handle alone. For a social security organisation processing sensitive health and financial data, an inadequate response meant real exposure: regulatory sanctions, financial penalties, and damaged member trust.
LM Oost-Vlaanderen came to DTA mid-crisis. The GBA questionnaire had landed. The deadline was fixed. DTA's job was to move fast without cutting corners by building a response that was complete, legally defensible, and backed by evidence.
How we solved it
Mobilise a crisis response structure within days
DTA activated a structured coordination plan immediately. Together with the mutuality, DTA set up bi-weekly coordination meetings, assigned clear ownership for every question in the GBA questionnaire, and flagged high-risk items for priority treatment. No deadline extension was requested.
Reconstruct the incident timeline from existing governance documentation
Because LM Oost-Vlaanderen had maintained its processing records through the DPOaaS framework, DTA could reconstruct the sequence of events from two years prior quickly and accurately. DTA then aligned the third-party IT partner's technical evidence with the mutuality's sector-specific legal obligations, closing the gap between what happened technically and what had to be argued legally.
Build an audit-proof remediation dossier
DTA took a proactive stance rather than a defensive one. DTA compiled concrete evidence of the technical and organisational measures (TOMs) already implemented since the original incident. The result was a submission that didn't just answer the GBA's questions, it demonstrated that the mutuality had already moved on from the incident and was operating at a higher level of compliance maturity.
The results
One questionnaire. Thirty days. Three outcomes that changed how LM Oost-Vlaanderen thinks about compliance.
Full response delivered within the 30-day deadline
Every question in the GBA questionnaire was answered. Ownership was clear, coordination was tight, and no item was left incomplete. The deadline held.
Two-year-old incident fully reconstructed and legally aligned
The DPOaaS documentation framework meant DTA could go back in time, mapping the incident timeline, aligning technical facts with legal obligations, and presenting a coherent narrative to the supervisory authority.
Remediation evidence shifted the regulatory dynamic
By proactively presenting proof of implemented TOMs, LM Oost-Vlaanderen moved from a position of justification to a position of demonstrated maturity. What started as an investigation became evidence of a functioning compliance programme.
Key Learnings
Every crisis reveals something. Here is what this one confirmed.
Documentation
Ongoing documentation is the best crisis tool. Up-to-date processing records made it possible to reconstruct a two-year-old incident in days rather than weeks. Organisations that defer their documentation governance pay for it when regulators come knocking.
Demonstrate
Don't just defend, rather demonstrate progress. A purely reactive response answers the question; a proactive one shifts the regulator's frame. Presenting implemented TOMs turned a liability into proof of maturity.
Coordination
Assigning ownership per question and running tight bi-weekly syncs kept the process on track. In a high-pressure procedure, clarity about who owns what is more valuable than effort alone.
More case studies
We deliver impact where it matters most.


From fragmented controls to scalable regulatory data quality
Degroof Petercam is a Belgian investment house and private bank with deep roots in wealth management. Since 2024, it operates as part of Indosuez Wealth Management, the global wealth arm of Crédit Agricole Group. That integration created an immediate compliance pressure: the group needed a unified, scalable data quality framework across multiple entities... and fast.


Managing GDPR compliance across a complex stakeholder landscape
Mega is an internationally active energy-sector company with a complex supplier network spanning both the EU and non-EEA countries. Alongside external vendors, Mega relies on intra-group relationships with holding and sister organisations, each carrying its own data transfer risk profile.

From manual RoPA management to continuous compliance
Our client is a public railway infrastructure manager, responsible for building, maintaining, and operating the country's rail network. As a public-sector organisation handling a broad range of personal data across multiple domains and subdomains, maintaining a compliant and well-governed Register of Processing Activities (RoPA) is both a legal obligation and an operational challenge.

