Sociálna poisťovňa, the social insurance agency (the controller), processes applications for foreign invalidity pensions and forwards related documents to the social insurance institutions of other EU Member States
A data subject applied for a Danish invalidity pension.
On 22 October 2018, the controller sent the data subject's sensitive personal data (including health data, personal identification number and a Danish personal identifier) to the Danish social insurance institution by ordinary (uninsured, untracked) second-class mail rather than by registered mail. The data subject could not confirm delivery and, in November 2018, filed a request with the Slovak DPA alleging that sending sensitive data by ordinary mail, without any proof of dispatch or protection against loss, violated their data protection rights. The controller resent the documents by the same method in December 2018. The DPA's first-instance decision (13 June 2019) found that the controller had violated Article 24(1) in conjunction with Article 32(1) and (2) GDPR, because sending sensitive personal data by ordinary rather than registered mail did not ensure a level of security appropriate to the risk. The DPA ordered the controller to use registered mail for such dispatches going forward and imposed a fine of €50,000. The controller's appeal was rejected, and the Slovak DPA president upheld the first-instance decision. The controller then brought an action before the Regional Administrative Court Bratislava, arguing among other things that: the parcel had in fact been delivered (as confirmed by the Danish institution by email), registered mail offers no greater protection against loss of confidentiality than ordinary mail, only one data subject was concerned and no damage had occurred and the decision's operative part improperly referred to the data of pension applicants generally, not just the individual data subject who had filed the complaint. Holding — The court did not rule on the substance of the security measures dispute, since it found the DPA's decision unreviewable on procedural grounds. First, the court held that the operative part of the DPA's decision was contradictory and imprecise. The administrative proceedings had been triggered by, and the evidence had concerned, an alleged violation of rights of one specific data subject (loss of their parcel). However, the decision extended the finding of violation to the controller's general practice of sending all pension applicants' data by ordinary mail. The court noted that a systemic pattern affecting other data subjects could, at most, be taken into account as an aggravating circumstance when setting the fine, but it could not itself form part of the sanctioned conduct in a proceeding limited to one individual's complaint. Second, the court found that the DPA had failed to properly assess evidence submitted by the controller showing that the parcel had actually been delivered to the Danish institution. The DPA only addressed this evidence for the first time in its written observations in the court proceedings, not in the administrative decision itself, even though the decision's entire reasoning rested on the (contested) premise that the parcel had been lost. Third, the court observed that the fine had been imposed under a provision of the national Data Protection Act that only permits fines for breaches of Articles 25 to 32 GDPR, whereas the DPA's decision had also relied on Article 24(1) GDPR, which is not covered by that provision. Because of these defects, the court annulled the DPA's decision and remanded the case for further proceedings, without addressing the parties' remaining arguments on the merits . The court instructed the DPA to first clearly establish the specific conduct underlying the alleged offence and then decide the case again, addressing all evidence submitted by the controller. The court awarded the controller full reimbursement of costs.
How it connects
Related across sources
Full text 67 paragraphs
29 Augusta 8 a 10, 813 63 Bratislava, IČO: 30 807 484 against the defendant: Office for Personal Data Protection, with its registered office in Park One Building, Námestie 1. mája 18, 811 06 Bratislava, IČO: 36 064 220, on the review of the legality of the defendant's decision No. k.: 00334/2019-Op-4 dated 27.09.2019, as follows decision: I. The Administrative Court in Bratislava quashes the measure of the defendant's Office for Personal Data Protection No. k.: 00334/2019-Op-4 dated 27.9.2019 and remits the case to the defendant for further proceedings. II. The plaintiff is granted the right to full reimbursement of the costs of the proceedings against the defendant. REASONS: I. Course of the administrative proceedings
On 28.11.2018, the plaintiff A. B., with address A. XXX/XX, XXX XX A. (hereinafter referred to as the plaintiff) served the defendant with a motion to initiate proceedings on the protection of personal data, in which he stated that the plaintiff was violating the protection of his personal data by sending sensitive documents relating to his person, in particular the shipment "Application for a foreign disability pension" by ordinary unregistered mail, i.e. without any confirmation of dispatch, a registered number and without any guarantee that the shipment would be delivered in order and not lost or misused by a third party. This concerns a shipment that contained his sensitive personal information such as a medical report, a statement of his employment in Denmark, including his birth number and Danish CPR number (personal identifier) and other forms required for an application for a disability pension. Based on this proposal, the defendant initiated proceedings on the protection of personal data pursuant to the provisions of Section 100(1) of Act No. 18/2018 Coll. on the protection of personal data and on amendments and supplements to certain acts, as amended (hereinafter referred to as the PDA).
By Decision No. 00050/2019-Os-16 of 13.06.2019 (hereinafter referred to as the first-instance decision), the defendant decided pursuant to Section 102(1)(a) and (b) of the PDA. f) of the Data Protection Act, in that the controller – plaintiff, when processing personal data of applicants for disability pension from the social insurance of the Member States of the European Union for the purpose of providing the data necessary for the social insurance bodies of the Member States of the European Union to decide on the disability pension of the applicants, violated Art. 24 para. 1 in conjunction with Art. 32 para. 1 and para. 2 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the “GDPR”) and violated the applicant’s right to the protection of his or her personal data by sending the applicants’ personal data, to the extent that it includes data relating to health, identifiers assigned for individual identification in information systems and data relating to economic and social identity, to the social security bodies of the Member States of the European Union via Slovak Post, a.s., always as a 2nd class letter and not as a registered letter, which provides a higher level of protection of the personal data processed, and therefore the operator has not taken appropriate measures to ensure a level of security appropriate to the risk to the rights of the data subjects, taking into account the scope and the content of the processed personal data and the nature of their processing, therefore, the Office, pursuant to Art. 58 (2) (d) of the GDPR, requires the operator to adopt organizational measures within 30 days of the date of entry into force of this decision to ensure that the personal data of applicants for disability pension from social insurance of the Member States of the European Union, which the operator sends to the relevant social insurance bodies by letter via Slovak Post, a.s., will be sent as registered mail (Section
(3) of Act No. 324/2011 Coll. on Postal Services and on Amendments to Certain Acts, as amended) (hereinafter referred to as the Postal Act); i) GDPR imposes a fine of EUR 50,000 (in words fifty thousand euros) on the controller based on Article 83(4)(a) GDPR with reference to Article 104(1)(a) ZOOÚ in connection with Article 83(7) GDPR for breach of obligations under Article 32(1) and (2) GDPR. 3 The plaintiff filed an appeal against the first-instance decision, in which he argued that in the given case it was not a case of delivery within the meaning of Article 212(3) of Act No. 461/2003 Coll. on Social Insurance as amended (hereinafter referred to as the Social Insurance Act), which regulates the obligation to send documents in person. In the case in question, the plaintiff sent documents of the institutions of the Kingdom of Denmark in the course of his activity. 2nd class registered and unregistered letters have exactly the same method of delivery, i.e. they pass through the same post offices and the same post office employees, with the exception that the Track and Trace service is provided for the registered letter, which can identify where the letter is and in what delivery process, but cannot prevent its possible loss. It is still a matter of the loss of a sealed envelope, which is protected by the secrecy of letters. Thus, even a registered item cannot prevent the risk of loss of personal data differently than an unregistered item. It is therefore not capable of providing a higher level of protection of personal data. The plaintiff pointed to the defendant's argument that the submission of the item at the post office is not proven, while at the same time stating that it was lost in the delivery process. In the case in question, the misuse of personal data has not been proven, the interference should consist only in the loss, which is not proven. On the contrary, the plaintiff has proven the delivery of the shipment, which was confirmed by the Danish Social Insurance Institution. At the same time, the plaintiff pointed out that in the case in question, there was one affected person who did not suffer any damage. The defendant should therefore have assessed this individual case, nevertheless, he states that it was a wide range of affected persons. It is not proven that the sending of the shipments in an ordinary manner interfered with the rights of any persons.
The plaintiff's appeal was decided by the defendant's president by decision No.: 00334/2019-Op-4 dated 27.09.2019 (the contested decision) by rejecting the plaintiff's appeal and confirming the first-instance decision. In the grounds of the contested decision, it stated that from a factual point of view, it is necessary to state, first of all, that it appears to be undisputed between the parties to the proceedings, and therefore the President of the Office considers it proven, that the documents containing personal data, including the special category of the applicant, which the applicant sent to the social insurance provider of the Kingdom of Denmark on 22 October 2018 via Slovak Post, a.s. as a 2nd class letter, were not delivered to the social insurance provider of the Kingdom of Denmark. It is also undisputed that the applicant, based on the applicant's request, sent the documents containing personal data to the social insurance provider of the Kingdom of Denmark via Slovak Post, a.s. as a 2nd class letter on 07 December 2018. In view of this, it cannot be assessed as evidence that the documents were not submitted for postal transport. Since the plaintiff chose to deliver the document by 2nd class letter mail, the social insurance provider of the Kingdom of Denmark did not confirm the delivery of the document sent on 22.10.2018 and the post office is unable to track the 2nd class mail, the President of the Office agreed with the conclusion that the document in question was lost in the delivery process.
The President pointed out the provision of Section 3(3) of the Postal Act, according to which a registered mail item shall be provided with a flat-rate guarantee against the risk of loss, theft or damage and a document shall be issued for the sender of its submission and, upon request, a document of its delivery to the addressee. For these reasons, the President agreed with the conclusion that a registered mail item provides a higher level of protection. By taking over the postal item, the postal company does not have an overview of the contents, since the sender does not notify the contents in any way. Unless one of the reasons listed exhaustively in the provision of Section 35 of the Postal Act occurs, the postal company will not learn about the content of the postal item. In relation to the processing of personal data, it is therefore the responsibility of the sender of the postal item to assess the criterion of adequacy of the security of the processing of personal data by choosing a method of delivery of the postal item corresponding to its content. In the case of sending the personal data of the claimant, including a special category, the appropriate measure was to deliver the postal item via a service that provides a flat-rate guarantee against the risk of loss, theft or damage to the letter item.
The President of the Office did not agree with the plaintiff's argument that the plaintiff is limited by the provision of Section 212 of the Social Insurance Act when delivering the items in his own hands. The plaintiff, as the controller, is responsible for the chosen method of delivery of the mail containing personal data, even if a specific law does not stipulate a specific form. The provision of § 212(3) of the Social Insurance Act did not apply to the delivery of the document at issue in the main proceedings. At the same time, the President pointed out that the plaintiff is entitled to choose a delivery agent of his choice, who also offers a registered mail service. Likewise, the plaintiff is not obliged to send documents containing personal data in paper form. Regulation (EC) No 987/2009 of the European Parliament and of the Council of 16 September 2009 laying down the procedure for implementing Regulation (EC) No 883/2004 on the coordination of social security systems (hereinafter referred to as Regulation 987/2009) provides that electronic communication constitutes an appropriate means for the rapid and reliable exchange of data between the institutions of the Member States. Delivery by electronic means is not excluded. The objection regarding the disproportionate increase in costs in connection with the sending of registered mail was assessed by the Chairperson as unfounded. Maximum savings should not be the main criterion for using a service that would be detrimental to the security of the personal data being sent.
In conclusion, the chairperson added that no other substantive decision had been issued in the case that would prevent the issuance of a first-instance decision, and neither was the decision on the complaint issued in the proceedings with the same subject matter before the plaintiff. II. Action
The plaintiff, by a timely filed action, sought a review of the legality of the contested decision as well as the first-instance decision, which he requested to be annulled and the case returned to the defendant for further proceedings. In his opinion, the contested decision is based on an incorrect assessment of facts and an incorrect assessment of the case in law and is unreviewable.
It is not clear to the plaintiff how the defendant can base his claim on the fact that the shipment in question was lost during the delivery process, when he subsequently states on page 3 that the shipment in question was not lost and was delivered to the institutions of the Kingdom of Denmark. The defendant's conclusion therefore does not correspond to the facts. The shipment was not lost, it was delivered to the social insurance provider of the Kingdom of Denmark on 14.11.2018, which the social insurance provider of the Kingdom of Denmark confirmed by email dated 25.06.2019, which was also attached to the appeal. A repeated shipment was also delivered to the social insurance provider of the Kingdom of Denmark, which was proven by email dated 09.01.2019. It is therefore indisputable that the shipment was not lost and there was no interference with the rights of the claimant. The fact that the mail was not delivered is therefore clearly disputed. The President did not deal with these facts in any way in the contested decision and did not take them into account. According to the plaintiff, this is a material fact, given that the entire first-instance decision of the defendant is based on an interference with the rights of the claimant, which was supposed to occur through the loss of the mail.
The plaintiff also points out that even if the mail containing the claimant's personal data were theoretically lost, this loss could also have occurred if the mail had been sent with a delivery note, since it would still only be a document wrapped in an envelope, the protection of which from a legal point of view is ensured by the secrecy of correspondence. The delivery receipt cannot ensure the security of the contents of a letter, it can only reveal at most at which stage of the delivery of the letter the loss occurred, while the loss does not automatically mean that there has been a breach of the secrecy of the letter and thus a potential interference with the personal rights of the person concerned. The plaintiff insists that the contents of the letter are subject to protection under Article 22 of the Constitution of the Slovak Republic, regardless of whether it is a letter with a delivery receipt or not.
The plaintiff does not agree with the defendant's claim that the subject matter of the case should have been an official letter pursuant to Section 5(7) of the Postal Act. In no case was it a case of delivery of an official letter, because according to the aforementioned provision this is only a letter intended for the personal hands of a party to proceedings before a public authority. In the present case, however, the claimant sent the consignment to the social security institution of the Kingdom of Denmark, i.e. not to a party to the proceedings.
The claimant is of the opinion that it has taken appropriate measures to ensure security proportionate to the risk for the rights of the data subjects with regard to the scope of the personal data processed, also because it proceeds in the manner provided for by Regulation 987/2009 during the transfer.
The claimant considers the contested decision to be unreviewable, since, like the first-instance decision, it is based on the fact that the personal data were not submitted to Slovenská pošta, a.s. for transport, because the claimant has no written evidence of this, but nevertheless imposes a penalty on the claimant for a breach of the provisions of the GDPR, which are factually based solely on the assumption that the claimant submitted a consignment to Slovenská pošta, a.s., which was lost in the delivery process. At the same time, the plaintiff is convinced that even if the shipment was lost, it is necessary to take into account the liability of Slovenská pošta, a.s., which, in accordance with the provisions of § 32, paragraph 2, letter g) of the Postal Act, is liable for the loss of postal items. This is a statutory provision that cannot be limited by postal regulations issued unilaterally by the post office. At the time of transport of the shipment, the sender no longer has any real impact or possibility of influencing the delivery of the shipment, regardless of whether it was sent by registered mail or not. The defendant illogically connects the loss of the shipment with the plaintiff's actions, which are supposed to consist in the fact that the shipment was not sent by registered mail. In the above case, there is therefore no causal link between the unlawful action and the consequence, which is supposed to be the loss of the shipment.
The plaintiff further points out that individual Member States assess Art. 77 of Regulation (EC) of the European Parliament and of the Council 883/2004 of 29 April 2004 on the coordination of social security systems (hereinafter referred to as the basic Regulation), which concerns the protection of personal data, as well as the plaintiff, they therefore send documents in the same way.
The plaintiff also points out that, pursuant to Article 5(1)(f) of the GDPR, it is required to ensure “adequate” security, not maximum. According to the plaintiff, the possibility of tracking a shipment has no potential to affect its loss, and therefore the factual basis for ensuring adequate security of personal data remains unchanged.
It follows from Article 32(1) of the GDPR that, when adopting appropriate security measures for the protection of personal data, controllers must also take into account the costs of implementing the measures. If the parcels were sent by registered mail, the costs would increase by approximately EUR 4,200,000, despite the fact that such a measure would have no effect on their potential loss.
In connection with the imposed sanction for the alleged violation pursuant to Art. 83(2) GDPR, it is also necessary to take into account the number of affected persons and the extent of the damage. The plaintiff points out that in this case there was one affected person, who, moreover, did not suffer any damage.
The plaintiff considers the imposed measure to send parcels by registered mail to be unsystematic given that it only affects a narrow range of affected persons and cases in the plaintiff's operating conditions. It is also necessary to point out that the defendant points to the use of electronic communication despite the fact that he himself obliges the plaintiff to proceed with communication in writing with a receipt, whereby he himself considers sending correspondence by post to be sufficiently secure.
As an aggravating circumstance, the defendant also assessed several allegedly relevant violations of obligations by the plaintiff, in which the plaintiff was imposed a sanction. However, the violations in question concerned factually different matters, while, unlike in this case, a proven interference with the rights of the person concerned occurred, in one case also publicly through media coverage. Despite this fact, a sanction of EUR 1,000 was imposed in both cases and not EUR 50,000 as in this case, where there was no interference with the rights of the person concerned. III. Defendant's statement
The defendant proposed in his written statement to dismiss the action. The argumentation in the filed action is largely based on that stated by the plaintiff in the filed appeal. The defendant considers the conclusions of the contested decision to be logical and correct. The essence of the entire personal data protection proceeding was the dispute over the plaintiff's loss of control over the personal data of the party to the proceeding - the claimant when sending the shipment dated 22.10.2018. The defendant acknowledges that the plaintiff argued in the filed appeal that the document in question dated 22.10.2018 was delivered to the social insurance provider of the Kingdom of Denmark, but he supported his argumentation only with an unconvincing copy of a regular email communication dated 25.06.2019 without any credibly verifiable evidence that could authenticate the authenticity of such a conclusion coming from the social insurance provider of the Kingdom of Denmark. The email response in question did not contain the designation of the institution of the sender of the email message, it was not a regular electronic communication, therefore this copy of the email response could not be used in the personal data protection proceedings as decisive evidence of the delivery of the shipment dated 22.10.2018.
The plaintiff diverts attention from the essence of the personal data protection proceedings. By the actions of the plaintiff, who submitted to the post office on 22.10.2018 a shipment containing the personal data of the claimant, including a special category of personal data, as a 2nd class letter without the possibility of subsequent tracking that the shipment was delivered to the addressee, the plaintiff lost any control over the processing of personal data in the sent document, whereby from the moment such a document was handed over to the post office, he failed to comply with the principle of liability under Art. 5 para. 2 GDPR to demonstrate compliance of its processing operations with the principle of integrity and confidentiality pursuant to Art. 5 para. 1 letter f) GDPR.
The defendant points out that the plaintiff was performing a legal obligation when sending the shipment, it was not a private matter. The plaintiff did not have the opportunity to influence the choice of how his personal data would be processed (delivered). Based on the plaintiff's request, the plaintiff stated that he could not prove the delivery of the shipment to the social security provider of the Kingdom of Denmark. At that time, the plaintiff could not prove to the plaintiff in any way that the document sent on 22.10.2018 was in the process of being delivered (which he could prove in the case of sending a registered shipment for which the Track and Trace service is provided, i.e. information on the submission and the result of the delivery of the registered shipment) or was lost. The plaintiff resolved the security incident by resending the document containing special categories of the claimant's personal data by second-class mail. The plaintiff's stated conduct can be considered an indifferent, uncritical and, above all, superficial approach to the security policy when processing personal data. It is clear from the approach in question that the plaintiff when sending documents containing the personal data of insured persons to the Member States of the European Union is unable to prove whether the sent item was lost or whether it was actually delivered to the addressee. In the event of a lost shipment, the plaintiff will never learn about such a security incident unless the data subject, whose data was not delivered, notifies him or the plaintiff of this fact by another entity (e.g. the addressee). It is clear that the plaintiff does not notify the defendant of security incidents in accordance with Art. 33 GDPR and does not notify the data subject in accordance with Art. 34 GDPR. Such a type of violation is very difficult to prove unless the data subject points it out, which the plaintiff apparently relied on. The defendant considers the diversion from the substance of the proceedings to be purposeful in an attempt to avoid any responsibility to reconcile and take appropriate measures.
As follows from the ruling of the first-instance decision, the fine imposed was not imposed for a one-off loss of the shipment, but was an administrative sanction for a systematic and long-term violation of security measures in accordance with Art. 24(1) in conjunction with Art. 32(1) and (2) GDPR, when the plaintiff did not take into account the risks of varying likelihood and severity for the rights and freedoms of natural persons when delivering mail containing special categories of personal data and always sends these to the social security institutions of the Member States as 2nd class letter mail.
The defendant set the amount of the fine mainly with regard to the fact that it would be a deterrent for the plaintiff to any further inconsistent assessment of the security risks in the processing of personal data. It is clear that the only criterion that the plaintiff took into account when sending documents containing a special category of personal data was the amount of the costs.
The plaintiff, in a speculative and purposeful manner, came to an incomprehensible conclusion for the defendant that if personal data were sent for any purpose other than the procedure for claiming a disability pension, they could continue to be sent as ordinary mail. By making the statement in question, the plaintiff confirmed that he did not understand the subject matter of the proceedings and the error he had committed. The measure was imposed in connection with a violation found within the subject matter of the proceedings, which concerned precisely the delivery of documents containing personal data of disability pension applicants necessary for the social insurance bodies of the EU Member States. The fine imposed is intended to serve as a warning to the plaintiff to reconsider its usual application practice in other processing operations and not to come to the illogical conclusion that since the measure was not imposed on it in other cases of delivery of documents, it is proceeding in accordance with the GDPR. If the claimant also violates the security standards in other processing operations and these are discovered in other proceedings on the protection of personal data, the claimant may be subject to further corrective measures as well as a fine. The subject of the proceedings was not to determine whether the claimant is also acting in breach of the GDPR in other cases.
The defendant does not understand how the claimant can consider the reasoning of the first-instance decision to be incomprehensible in the part in which the defendant states that the imposed measure does not affect the right to choose another postal operator that also offers a registered mail service. The imposed measure does not impose an obligation on the claimant to use exclusively the services of Slovenská pošta, a.s. for delivery. However, if the claimant chooses this postal operator, he is obliged to send the documents in question at least by registered mail. Regarding delivery by electronic means, the defendant expressed his opinion in light of the claimant's argument regarding increased costs. If, after reviewing the security policy for the processing of personal data, the claimant assesses that the introduction of appropriate technical measures for the electronic form of delivery of documents will be less costly than sending documents by registered mail, such a procedure will not be in conflict with the ruling of the first-instance decision. In the remainder of the application, the defendant refers to pages 6 to 10 of the grounds of the contested decision. IV. The claimant's reply
The claimant pointed out in his reply that the contested decision does not even mention the evaluation of the evidence with which the claimant demonstrated that the mail containing the claimant's personal data was delivered to the social security institution of the Kingdom of Denmark. The fact that the evidence of delivery of the shipment in question submitted by the plaintiff is considered by the defendant to be only unconvincing copies of a regular email communication dated 25.06.2019 without any credibly verifiable evidence that the shipment in question was delivered to the social security holder of the Kingdom of Denmark is only objected to by the defendant for the first time in the statement of claim dated 17.02.2020. It is clear that the defendant did not evaluate the documentary evidence in question at all in the administrative proceedings.
He repeatedly points out that in the case in question there was no loss of the shipment, i.e. there was no security incident, while the fact that there was supposed to be a security incident is only stated by the defendant for the first time in the statement of claim. The defendant therefore did not work with this possibility or evaluate it during the administrative proceedings and the contested decision.
According to the plaintiff's repeated opinion, tracking of shipments has no real potential to affect their potential loss and misuse of data. The factual basis for ensuring adequate security of personal data therefore remains unchanged. Given the adequacy of security, the plaintiff had to evaluate the costs associated with sending.
The defendant states throughout the statement of claim that the contested decision did not assess the personal data breach of the claimant alone, but rather the plaintiff's activities in a comprehensive manner, thus assessing the level of personal data protection in a comprehensive manner. However, the wording of the imposed measure is to adjust the plaintiff's specific activity, namely the sending of data of applicants for disability pensions to the relevant social insurance bodies of the EU Member States via Slovak Post, a.s., as a registered mail. The wording of the said measure is unambiguous and specific, meaning that the plaintiff is obliged to implement it as stated. Otherwise, the plaintiff continued to adhere to the arguments stated in the filed claim.
The defendant did not respond to the plaintiff's reply in writing. V. Another participant
Pursuant to the provisions of Section 32, Section 3 of Act No. 162/2015 Coll. Administrative Court Rules as amended by later regulations (hereinafter referred to as the SSP), participants in the proceedings before the administrative court are also those who were participants in the administrative proceedings. Given that the administrative proceedings were initiated upon a motion (Section 100, Paragraph 1 of the Act on the Protection of Personal Data), filed by the person concerned A. B., born XX.XX.XXXX, residing at A. XXX/XX, XXX XX A., who was demonstrably a participant in the administrative proceedings, the administrative court by resolution No.: BA-6S/221/2019-55 of 23.04.2025 added him to the proceedings as another participant. At the same time, the administrative court informed the other participant about the possibility of waiving participation in accordance with the provisions of Section 32, Paragraph 4 of the SSP. 33. By a submission dated 27.05.2025 signed with a guaranteed electronic signature, the other participant waived participation in the proceedings, stating that he was not interested in actively participating in the ongoing court proceedings. VI. Public announcement of the judgment
The Administrative Court in Bratislava draws attention to the fact that, pursuant to Section 3, Paragraph 3, Letter b) of Act No. 151/2022 Coll. on the establishment of administrative courts and on amendments and supplements to certain acts, as amended by Act No. 398/2022 Coll. (hereinafter referred to as Act No. 151/2022 Coll.) the exercise of justice has been transferred from regional courts to administrative courts in all matters from 1 June 2023, namely from the Regional Court in Bratislava, the Regional Court in Nitra and the Regional Court in Trnava to the Administrative Court in Bratislava. For the above reason, the file of the Regional Court in Bratislava file no. 6S/221/2019 is kept at the Administrative Court in Bratislava under file no. BA-6S/221/2019
The Administrative Court in Bratislava as a court with subject-matter and territorial jurisdiction pursuant to Section 10 and Section 13 of Act No. 162/2015 Coll. z. The Administrative Court Procedure as amended (hereinafter referred to as the SSP) in conjunction with Section 3(3)(b) of Act No. 151/2022 Coll., after having familiarized itself with the content of the case file and the administrative file, examined the contested decision, as well as the procedure preceding its issuance, in accordance with the provisions of Section 195 of the SSP and decided on the matter without ordering a hearing (Section 107(2) in conjunction with Section 137(4) of the SSP) by judgment on 25.6.2025, since neither the plaintiff nor the defendant requested a hearing. VII. Relevant legal provisions
According to Article 4(1) of the GDPR for the purposes of this Regulation: “personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or by reference to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person
According to Art. 5(1) GDPR, personal data must be: a) processed lawfully, fairly and transparently in relation to the data subject ("lawfulness, fairness and transparency"); f) processed in a manner that ensures adequate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, including through appropriate technical or organisational measures ("integrity and confidentiality").
According to Art. 5(1) GDPR, personal data must be: a) processed lawfully, fairly and transparently in relation to the data subject ("lawfulness, fairness and transparency"); f) processed in a manner that ensures adequate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, including through appropriate technical or organisational measures ("integrity and confidentiality"). 2 GDPR the controller is responsible for compliance with paragraph 1 and must be able to demonstrate such compliance (‘accountability’).
According to Art. 24(1) GDPR, taking into account the nature, scope, context and purposes of the processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and be able to demonstrate that the processing is carried out in accordance with this Regulation. Those measures shall be reviewed and updated as necessary.
According to Art. 32(1) GDPR 1 GDPR, the controller and the processor shall, taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk, including, where appropriate: a) pseudonymisation and encryption of personal data; b) the ability to ensure the permanent confidentiality, integrity, availability and resilience of processing systems and services; c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; d) a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures to ensure the security of the processing.
According to Article 32(2) of the GDPR, when assessing the appropriate level of security, particular account shall be taken of the risks represented by the processing, in particular as a result of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data which are transmitted, stored or otherwise processed.
According to Article 83(4)(a) of the GDPR, infringements of the following provisions shall be subject to administrative fines of up to EUR 10,000,000 or, in the case of an undertaking, up to 2% of the total worldwide annual turnover in the preceding business year, whichever is the higher: the obligations of the controller and the processor under Articles 8, 11, 25 to 39 and 42 and 43.
According to Article 83(4)(a) of the GDPR, infringements of the following provisions shall be subject to administrative fines of up to EUR 10,000,000 or, in the case of an undertaking, up to 2% of the total worldwide annual turnover in the preceding business year, whichever is the higher: the obligations of the controller and the processor under Articles 8, 11, 25 to 39 and 42 and 43. 7 GDPR, without prejudice to the remedial powers of the supervisory authorities pursuant to Article 58(2), each Member State may lay down rules on whether and to what extent administrative fines may be imposed on public authorities and public bodies established in that Member State.
Pursuant to § 100(1) of the Act on the Protection of Personal Data, proceedings shall be initiated upon the application of the data subject or a person who claims to be directly affected by his or her rights under this Act (hereinafter referred to as the “applicant”), or ex officio.
Pursuant to § 100(2) of the Act on the Protection of Personal Data, the Office shall initiate proceedings ex officio also on the basis of a finding made by the Office in the exercise of supervision over compliance with the obligations laid down in this Act or a special regulation.2)
Pursuant to § 102(1) of the Act on the Protection of Personal Data, proceedings shall be initiated ex officio. 1 of the Personal Data Protection Act, if the Office finds a violation of the rights of the data subject or a failure to comply with the obligations in the processing of personal data provided for by this Act or a special regulation2) for the protection of personal data by a party to the proceedings, it may, by decision, a) impose corrective measures and a deadline for the implementation of the ordered measure pursuant to paragraph 3, if this is justified and expedient, b) cancel the binding nature of the approved code of conduct for the operator or intermediary who has undertaken to comply with the approved code of conduct, c) withdraw the certificate, d) order the certification body to withdraw the certificate, e) withdraw the certificate of granting accreditation, f) impose a fine pursuant to Section 104.
Pursuant to Section 104, Section 104, Section 1, Letter a) a) of the Personal Data Protection Act, the Office may impose a fine of up to EUR 10,000,000 or, in the case of an undertaking, up to 2% of the total worldwide annual turnover for the previous financial year, whichever is the higher, on the controller, including public authorities and public institutions, for failure to comply with or breach of any of the obligations under Sections 15, 18, 31 to 35, 37, 39 to 45, 79 and 109 or under Articles 8, 11, 25 to 39, 42 and 43. 43 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4. 5. 2016) (hereinafter referred to as “Regulation (EU) 2016/679”).
According to Section 3(3) of the Postal Act in force until 31.11.2019, a registered item is a letter item for which the “registered” service is provided, providing a flat-rate guarantee against the risk of loss, theft or damage to the letter item and for which a document is issued for the sender of its submission and, upon request, of its delivery to the addressee.
According to Section 32(2)(g) of the Postal Act, effective until 31.11.2019, the postal company is obliged to protect postal items and remitted payments from loss, theft and damage.
According to Section 212(3) of the Social Insurance Act, the decision shall be notified to the party to the proceedings by delivering the decision in person or by registered mail with a receipt and the note "in person". The following decisions shall be delivered in person: a) on not granting a benefit, withdrawing a benefit, reducing a benefit or stopping the payment of a benefit, b) on imposing an obligation to return unduly paid amounts of a benefit, c) on insurance premiums, on contributions to old-age pension savings, 1) on imposing a fine and penalty, d) on the suspension of proceedings, e) on the suspension of proceedings.
According to Section 47, paragraph 2 of the Administrative Procedure Code, the ruling shall contain the decision on the matter, stating the provision of the legal regulation under which the decision was made, and, where applicable, the decision on the obligation to reimburse the costs of the proceedings. If the decision imposes an obligation on the party to the proceedings, the administrative authority shall set a deadline for it; the deadline may not be shorter than that provided for by a special law.
According to Section 47, paragraph 3 of the Administrative Procedure Code, in the justification of the decision, the administrative authority shall state which facts formed the basis for the decision, what considerations it was guided by in assessing the evidence, how it used sound judgment in applying the legal regulations on the basis of which it made the decision, and how it dealt with the proposals and objections of the parties to the proceedings and their statements on the basis of the decision. VIII. Assessment of the case by the administrative court
Based on Art. 6, paragraph 1 sentence one of the Convention for the Protection of Human Rights and Fundamental Freedoms (hereinafter referred to as the “Convention”), from Recommendation No. R(91) of the Committee of Ministers to member states on administrative sanctions approved by the Committee of Ministers on 13 February 1991 (hereinafter referred to as the “Recommendation on administrative sanctions”) and from the case-law of the European Court of Human Rights (for example, the judgment in the case of Lauko v. the Slovak Republic of 2 September 1998, application no. 26138/95; in the case of Öztürk v. the Federal Republic of Germany of 21 February 1984, application no. 8544/79; in the case of Čanády v. the Slovak Republic of 16 November 2004, application no. 53371/99, etc.) it follows that punishment for administrative offences (misdemeanours, administrative offences of legal persons and administrative offences natural persons - entrepreneurs) must be subject to the same regime as criminal sanctions for criminal offences. It is therefore necessary to provide guarantees and rights that are enshrined in the Criminal Code and the Criminal Procedure Code not only to the accused of a criminal offence, but also to the entity against whom administrative liability is imposed, which ultimately follows from principle No. 6 of the Recommendation on Administrative Sanctions, according to which it is necessary to provide, in the framework of administrative proceedings in matters of administrative sanctions, in addition to the guarantees of a fair administrative procedure within the meaning of Resolution (77) 31, also firmly established guarantees in criminal proceedings. It cannot be forgotten that the boundaries between criminal offences for which a penalty is imposed by a court and administrative offences for which sanctions are imposed by administrative authorities are determined by the will of the legislator and are not justified by natural law principles.
These aspects should be taken into account when assessing the necessity of specifying the act in the decision. The legal regulation is unambiguous with regard to criminal proceedings, because according to the Criminal Code, the judgment must precisely identify the criminal act to which it relates, not only by its legal name and by indicating the relevant legal provision, but also by indicating the place, time and manner of commission, and, if applicable, other facts necessary so that the act cannot be confused with another. There is a similar legal regulation for misdemeanors. The judgment of a misdemeanor must also contain a description of the act, indicating the place and time of its commission, the declaration of guilt, the type and amount of the sanction. However, the broad area of other administrative misdemeanors does not have such a clear definition of the judgment. Reference is made only to the Administrative Code (Section 47(2) of the Administrative Code), which does not mean, however, that this requirement does not have to be met in the case of other administrative offences.
In criminal decisions, which undoubtedly also include decisions on other administrative offences, it is necessary to define precisely for what specific action the subject is punished. This can only be guaranteed by specifying the data containing a description of the act, stating the facts that are necessary so that the act cannot be confused with another. Such a level of detail is necessary for the entire sanctioning procedure, in particular to exclude the obstacle of lis pendens, double punishment for the same act, to exclude the obstacle of res judicata, to determine the scope of evidence, as well as to ensure the proper right to defense. Only the issued decision will clearly determine what the offender committed and what the committed offence consists of. Individual factual data are decisive for determining the identity of the act, they exclude the possibility of confusion of the act and the possibility of repeated punishment for the same act for the next period, while it is necessary to reject the idea that it is sufficient if these particulars are stated only in the reasoning of the decision. The importance of the operative part of the decision lies in the fact that only this part of the decision can interfere with the rights and obligations of the parties to the proceedings. A properly formulated operative part and, first of all, a specific description of the act is an irreplaceable part of the decision, from which it is possible to determine whether and what obligation was violated and what measures or sanctions were imposed. Only a decision containing such a statement may be enforceable by execution (see Judgment of the Supreme Court of the Slovak Republic, file no. 2Sž/25/2011)
In the opinion of the administrative court, it is not clear from the wording of the statement of the contested decision what action the defendant should have taken to fulfill the act for which he is accused. First of all, it is necessary to point out that the subject of the proceedings in which the defendant imposed a sanction on the plaintiff was the violation of the plaintiff's rights as a result of the alleged loss of a shipment containing his personal data. The proceedings were initiated directly at the plaintiff's request. However, the defendant also included in the first-instance decision the violation of other legal persons when he stated that the plaintiff, when processing the personal data of applicants for disability pension from the social insurance of the Member States of the European Union for the purpose of providing the necessary data for the social insurance bodies of the Member States of the European Union to decide on the disability pension of the applicants, violated Art. 24 para. 1 in conjunction with Art. 32 para. 1 and para. 2 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the “Regulation”) and violated the applicant’s right to the protection of his or her personal data by sending the applicants’ personal data, to the extent that it includes data relating to health, identifiers assigned for individual identification in information systems and data relating to economic and social identity, to the social insurance institutions of the Member States of the European Union via Slovak Post, a.s. always as a 2nd class letter and not as a registered mail, which provides a higher level of protection of the processed personal data, and therefore the operator has not taken appropriate measures to ensure a level of security appropriate to the risk to the rights of the data subjects, taking into account the scope and content of the processed personal data and the nature of their processing. However, in the opinion of the Administrative Court, it is not possible to violate the claimant's right by sending personal data of persons other than the claimant.
As follows from the defendant's administrative files, the evidence of the plaintiff's unlawful conduct in the administrative proceedings in question concerned the loss of the parcel with the plaintiff's personal data. If the defendant, when imposing the sanction, took into account the fact that in the given case it was a systemic error of the plaintiff concerning other persons, he could only assess the aforementioned fact as an aggravating circumstance that has an impact on the amount of the imposed sanction, which he ultimately did in the reasoning of the first-instance decision. The administrative court does not question the defendant's authority to impose sanctions also for systemic errors and to initiate proceedings ex officio on the basis of the office's findings in exercising supervision over compliance with obligations stipulated by law. However, the decision of a public administration body as a result of a specific administrative proceeding must be based on the established facts and result from the administrative files. The opposite is then a reason for annulling such a decision. In the judgment on the commission of an administrative offence in the contested decision, however, in view of the subject matter of the proceedings, it is not possible to sanction the conduct of the perpetrator, which was not the subject of the administrative proceedings and was not the subject of the evidence, namely the sending of letters containing the personal data of other persons. In view of the above, the Administrative Court assessed the plaintiff's objection that the given administrative proceedings dealt with the violation of the rights of a specific claimant, i.e. concerned one person, as relevant.
The first-instance decision of the defendant, in the opinion of the Administrative Court, is confusing when, on the one hand, it states as a violation the loss of the parcel containing the claimant's personal data (which was not proven), the failure to send letters to social security providers of EU member states with a general acknowledgement of delivery, and the related violation of the obligation to take appropriate measures to protect personal data, or the violation of the obligation to prove the compliance of its processing operations with the principle of integrity.
The above-mentioned fact is supported by the statements of the defendant, who on the one hand states that: "By the action of the plaintiff, who submitted to the post office on 22.10.2018 a shipment containing the plaintiff's personal data, including a special category of personal data, as a 2nd class letter without the possibility of subsequent tracking that the shipment was delivered to the addressee, the plaintiff lost any control over the processing of the personal data in the sent document, whereby from the moment such a document was submitted to the post office, he was unable to demonstrate, in accordance with the principle of responsibility under Art. 5(2) GDPR, the compliance of his processing operations with the principle of integrity and confidentiality under Art. 5(1)(f) GDPR." and at the same time claims that "As follows from the operative part of the first-instance decision, the fine imposed was not imposed for a one-off loss of the shipment, but was an administrative sanction for a systematic and long-term violation of security measures pursuant to Article 24(1) in conjunction with Article 32(1) and (2) of the GDPR, when the plaintiff did not take into account the risks of varying probability and severity for the rights and freedoms of natural persons when delivering shipments containing special categories of personal data and always sends these to social security providers of the Member States as 2nd class letter mail." The defendant thus accuses the plaintiff of several errors which, although related, do not constitute a single act. In the light of the considered aspects mentioned above, this fact causes the operative part of the contested decision to be inaccurate and indefinite and results in the illegality of the first-instance decision due to its unreviewability. The precise specification of the unlawful act in the operative part of the decision is a prerequisite for assessing whether the state of affairs was sufficiently established by the public administration body and is decisive for the right to a defence. If the defendant in the contested decision identified himself with the first-instance decision and did not correct its operative part, the contested decision also suffers from the defect of unreviewability. The Administrative Court therefore concluded that the plaintiff's objection regarding the unreviewability and incomprehensibility of the contested decision in conjunction with the first-instance decision is well-founded.
In this context, the Administrative Court draws attention to the fact that if the defendant had also described in detail in the reasoning of the first-instance decision the act that he specifically considers to be a violation of Art. 24(1) in conjunction with Art. 32(1) of the Act, 1 and 2 GDPR and stated the reasons for which it considered that the claimant had committed a breach of a legal obligation by his act, the establishment of the act of breach of a legal obligation in the reasoning of the decision cannot remedy its absence in the operative part of the decision.
At the same time, the administrative court assessed as justified another objection of the claimant regarding the evidence provided and in this regard must convince the claimant that the defendant in the contested decision did not assess the evidence by which the claimant demonstrated that the parcel with the claimant's personal data was not lost (email of the social insurance provider of the Kingdom of Denmark dated 25.06.2019). It assessed this evidence for the first time only in the statement of claim dated 17.02.2020, while it was demonstrably already in possession of it in the appeal proceedings. If the defendant based its decision on the fact that the parcel containing the claimant's personal data had been lost (which it did not consider to be disputable) and inferred a breach of a legal obligation from this fact, it decided on the basis of insufficiently established facts, when this fact was not proven and the defendant disputed it in the appeal filed.
In conclusion, it is also necessary to draw attention to the fact that, according to the ruling of the first-instance decision, the fine was imposed on the basis of the provision of § 104(1)(a) of the Personal Data Protection Act. Referring to the above-quoted wording of this provision, it is not possible to impose a fine for a breach of Art. 24(1) GDPR as stated by the defendant, but only Art. 25-32 GDPR.
In view of the aforementioned defect of the unreviewability of the contested decision and the insufficiently established facts, the administrative court considered it unnecessary to address the plaintiff's further objections and considerations about the adequacy of the measures taken, or the equal degree of "security" of letter items sent in the ordinary manner and with a receipt.
Based on the aforementioned facts and the cited legal regulations, the administrative court concluded that the defendant's contested decision is unreviewable due to confusion, since it is not clear what specific actions of the plaintiff the defendant is sanctioning, and at the same time it is based on insufficiently established facts due to the failure to evaluate all the evidence presented, which is a reason for its annulment pursuant to Section 191(1)(d) and (e) of the SSP and returning the case to the defendant for further proceedings.
The public administration body is bound by the legal opinion expressed by the administrative court in the annulling judgment in further proceedings. If the public administration body did not act in accordance with the legal opinion of the administrative court in further proceedings and the administrative court has again annulled the decision of the public administration body or the measure of the public administration body for the same reasons, the administrative court may impose a fine on the public administration body in the annulling judgment even without a motion (Section 191(6) of the Administrative Procedure Code). In further proceedings, the defendant shall be obliged to establish the specific conduct of the plaintiff, by which he or she allegedly committed an administrative offence, and to decide on the matter anew, while in the new decision he or she shall be obliged to deal with all the evidence submitted.
The court decided on the reimbursement of the costs of the proceedings pursuant to Section 167 of the Administrative Procedure Code and granted the successful plaintiff the right to reimbursement of the costs of the proceedings in full against the unsuccessful defendant. The administrative court shall decide on the amount of compensation for the costs of the proceedings after the decision terminating the proceedings becomes final, by a separate resolution issued by a court officer (Section 175(2) of the Administrative Procedure Code).
This decision was adopted by the Senate of the Administrative Court in Bratislava with a vote of 3:0 (Section 139(4) of the Administrative Procedure Code). Note: A cassation appeal may be filed against this judgment within 30 days (Section 493e of the Administrative Procedure Code) from its delivery, to the Administrative Court in Bratislava. If a corrective resolution has been issued, the period shall run again from the delivery of the corrective resolution only to the extent of the correction made. In addition to the general requirements (Section 57 of the Code of Civil Procedure), the cassation appeal shall include the designation of the contested decision, the date when the contested decision was delivered to the complainant, a description of the decisive facts, so that it is clear to what extent and for what reasons it is being filed pursuant to Section 440 of the Code of Civil Procedure (points of complaint) and a draft of the ruling of the decision (draft of complaint). The points of complaint may only be changed until the expiry of the time limit for filing a cassation appeal. In cassation appeal proceedings, the complainant or omitted complainant must be represented by a lawyer within the meaning of Section 449, Paragraph 1 of the Code of Civil Procedure. The cassation appeal and other submissions by the complainant or omitted complainant must be drafted by a lawyer. Mandatory representation by a lawyer in cassation proceedings is not required if the complainant or the omitted complainant, his employee or member who acts for him or represents him at the Court of Cassation, has a second-degree university degree in law (subparagraph a); these are proceedings on an administrative action pursuant to Section 6, paragraph 2, subparagraphs c and d (subparagraph b); the defendant is the Legal Aid Centre (subparagraph c).