From regulatory scrutiny to demonstrated compliance

Introduction

LM Oost-Vlaanderen is a Belgian social security mutuality serving members across the province of East Flanders. As a social security organisation, it operates under strict sector-specific regulations and handles some of the most sensitive personal data categories that exist: health records, financial entitlements, and member identity.

Client

LM Oost-Vlaanderen

Client since

2023

Services

Technologies

No items found.

The problem

In 2023, LM Oost-Vlaanderen received a formal questionnaire from the Belgian Data Protection Authority (GBA/APD) about a data incident that had occurred two years earlier. They had 30 days to deliver a complete, legally sound response. Reconstructing events from that far back, aligning technical evidence with legal obligations, and producing a defensible submission, all under a fixed deadline, was beyond what their internal team could handle alone. For a social security organisation processing sensitive health and financial data, an inadequate response meant real exposure: regulatory sanctions, financial penalties, and damaged member trust.

LM Oost-Vlaanderen came to DTA mid-crisis. The GBA questionnaire had landed. The deadline was fixed. DTA's job was to move fast without cutting corners by building a response that was complete, legally defensible, and backed by evidence.

How we solved it

Mobilise a crisis response structure within days

DTA activated a structured coordination plan immediately. Together with the mutuality, DTA set up bi-weekly coordination meetings, assigned clear ownership for every question in the GBA questionnaire, and flagged high-risk items for priority treatment. No deadline extension was requested.

Reconstruct the incident timeline from existing governance documentation

Because LM Oost-Vlaanderen had maintained its processing records through the DPOaaS framework, DTA could reconstruct the sequence of events from two years prior quickly and accurately. DTA then aligned the third-party IT partner's technical evidence with the mutuality's sector-specific legal obligations, closing the gap between what happened technically and what had to be argued legally.

Build an audit-proof remediation dossier

DTA took a proactive stance rather than a defensive one. DTA compiled concrete evidence of the technical and organisational measures (TOMs) already implemented since the original incident. The result was a submission that didn't just answer the GBA's questions, it demonstrated that the mutuality had already moved on from the incident and was operating at a higher level of compliance maturity.

The results

One questionnaire. Thirty days. Three outcomes that changed how LM Oost-Vlaanderen thinks about compliance.

Full response delivered within the 30-day deadline

Every question in the GBA questionnaire was answered. Ownership was clear, coordination was tight, and no item was left incomplete. The deadline held.

Two-year-old incident fully reconstructed and legally aligned

The DPOaaS documentation framework meant DTA could go back in time, mapping the incident timeline, aligning technical facts with legal obligations, and presenting a coherent narrative to the supervisory authority.

Remediation evidence shifted the regulatory dynamic

By proactively presenting proof of implemented TOMs, LM Oost-Vlaanderen moved from a position of justification to a position of demonstrated maturity. What started as an investigation became evidence of a functioning compliance programme.

Key Learnings

Every crisis reveals something. Here is what this one confirmed.

Documentation

Ongoing documentation is the best crisis tool. Up-to-date processing records made it possible to reconstruct a two-year-old incident in days rather than weeks. Organisations that defer their documentation governance pay for it when regulators come knocking.

Demonstrate

Don't just defend, rather demonstrate progress. A purely reactive response answers the question; a proactive one shifts the regulator's frame. Presenting implemented TOMs turned a liability into proof of maturity.

Coordination

Assigning ownership per question and running tight bi-weekly syncs kept the process on track. In a high-pressure procedure, clarity about who owns what is more valuable than effort alone.

Degroof Petercam

From fragmented controls to scalable regulatory data quality

Degroof Petercam is a Belgian investment house and private bank with deep roots in wealth management. Since 2024, it operates as part of Indosuez Wealth Management, the global wealth arm of Crédit Agricole Group. That integration created an immediate compliance pressure: the group needed a unified, scalable data quality framework across multiple entities... and fast.

Mega

Managing GDPR compliance across a complex stakeholder landscape

Mega is an internationally active energy-sector company with a complex supplier network spanning both the EU and non-EEA countries. Alongside external vendors, Mega relies on intra-group relationships with holding and sister organisations, each carrying its own data transfer risk profile.

Transport Infrastructure Organization

From manual RoPA management to continuous compliance

Our client is a public railway infrastructure manager, responsible for building, maintaining, and operating the country's rail network. As a public-sector organisation handling a broad range of personal data across multiple domains and subdomains, maintaining a compliant and well-governed Register of Processing Activities (RoPA) is both a legal obligation and an operational challenge.