Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public
It set up an online shop within a few days and made it publicly accessible to its customers on 28 March 2020.
How it connects
Related across sources
Full text 21 findings
] Obvious spelling, grammar, and punctuation errors have been corrected. DECISION RULING The Data Protection Authority decides on the data protection complaint filed by Richard A*** (complainant) on April 1, 2020, against N*** Textil GmbH (respondent) regarding a violation of the principles of data processing of personal data pursuant to Article 5 GDPR and the right to information pursuant to Article 13 GDPR as follows: – The complaint is upheld, and it is determined that the respondent thereby violated the complainant's principles of data processing of personal data pursuant to Article 5 GDPR and the right to information pursuant to Article 13 GDPR. The complaint alleges that the respondent violated Article 13 of the GDPR by setting cookies when the respondent's website was accessed without a cookie banner or privacy policy. The complaint is upheld, and it is determined that the respondent violated the complainant's rights regarding the principles of data processing under Article 5 of the GDPR and the right to information under Article 13 of the GDPR by setting cookies when the respondent's website was accessed without a cookie banner or privacy policy.
2016, p. 1. Sections 18(1) and 24(1) and (5) of the Data Protection Act (DSG), Federal Law Gazette I No. 165/1999 as amended. Legal basis: Articles 4, 5, 6, 13, 51(1), 57(1), letter f, and 77(1) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR), Official Journal No. L 119 of 4 May 2016, page 1; Sections 18(1) and 24(1) and (5) of the Data Protection Act (DSG), Federal Law Gazette Part One, No. 165 of 1999 as amended. ] JUSTIFICATIONS A. Submissions of the Parties and Procedural History 1. In the initial submission dated April 1, 2020, transmitted by the German (North Rhine-Westphalian) supervisory authority, the complainant (hereinafter: bP) stated that it had visited the homepage of the respondent (hereinafter: BG), accessible at the URL , and that 14 cookies had been set during this visit without the option to reject them. By setting these cookies, bP's data had been processed by BG, and bP's right to information and the lawfulness of the processing had been violated.
2. 577 dated November 6, 2020, and sent on November 11, 2020, the Austrian Data Protection Authority requested a statement from the respondent and forwarded the complaint filed by the applicant to the respondent as an attachment. 3. In its statement dated December 6, 2020, T*** Protect Medizinprodukte GmbH, representing BG (N*** Textil GmbH), summarized that at the end of March 2020, in the wake of the initial COVID-19 outbreak, the company decided to offer face masks and protective masks to the general public as quickly and easily as possible. Due to the shortage of masks of all kinds at that time, this was an extremely urgent matter. BG had not previously offered business-to-consumer products, and due to the lack of direct sales options and the closure of its brick-and-mortar stores, online sales were the best possible solution under the circumstances. The online shop was created within a few days and went live at the end of March (March 28, 2020).
at. At the time to which the alleged violation relates (April 1, 2020), the online shop did not yet meet all technical requirements. It is correct that at that time no cookie pop-up informed users about the use of their data. This issue has since been rectified. 4. The Austrian Data Protection Authority forwarded the BG's statement via the Internal Market System to the German (North Rhine-Westphalian) supervisory authority on December 23, 2020, and again on August 29, 2022, requesting that the documents be made available to the BG as part of the hearing process. The BG did not submit any further statements during the ongoing investigation. B. Subject of the Complaint Based on the submissions of the complainant, it is clear that the subject of the complaint is whether the complainant's rights to lawful data processing under Article 6 GDPR and their right to information under Article 13 GDPR were violated by the BG (Berufsgenossenschaft, the German statutory pension insurance institution), because no cookie banner was implemented when the complainant accessed the BG's website, yet 14 cookies were still set.
Based on the submissions of the complainant, it is clear that the subject of the complaint is whether the complainant's rights to lawful data processing under Article 6 GDPR and their right to information under Article 13 GDPR were violated by the BG, because no cookie banner was implemented when the complainant accessed the BG's website, yet 14 cookies were still set. C. Findings of Fact 1. BG is a legal entity in the form of a limited liability company (GmbH) with company registration number and its registered office at . BG's business purpose is the production, distribution, and trade of textiles of all kinds. 031. 2. According to its own statements, BG decided at the end of March 2020, in the wake of the first COVID-19 outbreak, to offer face masks and protective masks to the general public. 1. Within a few days, it created an online shop, which was accessible at least from March 28, 2020, to April 1, 2020, at the URL , and made it publicly available to its customers.
At least on April 1, 2020, no privacy policy was publicly accessible to users on the website. 2. bP accessed BG's online shop on April 1, 2020, and at that time no cookie banner was implemented, but 14 cookies were set. 3. Cookies allow the collection of information generated by a website and stored via an internet user's browser. They are small files or pieces of text (usually less than one kilobyte) that a website places on the hard drive of a user's computer or mobile device via their browser. Websites use cookies to identify users, remember their preferences, and allow users to complete tasks without having to re-enter information when they navigate to another page or revisit the website later. Cookies can also be used to gather information based on online behavior for targeted advertising and marketing. For example, companies use software to track user behavior and create personal profiles that allow them to show users advertising tailored to their previous searches.
4. The website with the URL is no longer accessible as of the date of issue of this notice (effective date: November 24, 2025). Screenshot of the official retrieval of the homepage with the URL (formatting not shown verbatim): [Editor's note: The screenshot of an error message ("This connection is invalid. 4: These findings are based on the initial submission of April 1, 2020, by the bP, in which the bP stated that no cookie banner had been implemented on the homepage, accessible at the URL , and that 14 cookies had been set simultaneously. This finding was not disputed by the BG in its statement of December 6, 2020; rather, it confirmed that it had not implemented a cookie banner at that time and that the homepage had technical deficiencies which were only rectified at a later date. The finding that the privacy policy was not accessible to users is based on the BG's statement of December 6, 2020, which indicates that while a privacy policy had been created, it was not publicly accessible to users during the initial days of the online shop's operation.
3, regarding cookies and how they function, are based on the Opinion of Advocate General Maciej Szpunar in Case C-673/17, Planet49 GmbH, paragraphs 36 et seq. The finding that the BG's homepage is no longer accessible is based on the official search of the URL on November 24, 2025. D. 1. General Information Pursuant to Article 77(1) GDPR and Section 24(1) of the Austrian Data Protection Act (DSG), every data subject has the right to lodge a complaint with the data protection authority if they believe that the processing of their personal data infringes the GDPR or Section 1 of Chapter 1 of the DSG. Pursuant to Article 4(1) GDPR, “personal data” means any information relating to an identified or identifiable natural person. A natural person is considered identifiable, among other things, if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or an online identifier.
According to the CJEU, the term "personal data" is to be interpreted very broadly (see CJEU 20 December 2017, C-434/16 – still concerning the Data Protection Directive, but the case law is applicable to the GDPR: see CJEU 7 March 2024, C-604/22, paragraph 33). According to Article 4(1) of the GDPR, "personal data" means any information relating to an identified or identifiable natural person. A natural person is considered identifiable, among other things, if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or an online identifier. The term "personal data" is to be interpreted very broadly by the CJEU (see CJEU 20 December 2017, C-434/16 – which refers to the Data Protection Directive, but the case law is applicable to the GDPR: see CJEU 7 March 2024, C-604/22, paragraph 33). The CJEU considers the term "personal data" to be extremely broad (see CJEU 20 December 2017, C-434/16 – which refers to the Data Protection Directive, but the case law is applicable to the GDPR: see CJEU 7 March 2024, C-604/22, paragraph 33).
2024, C-604/22, paragraph 36 with further references). Paragraph 36 (see also references). Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction (see Article 4(2) GDPR). Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction (see Article 4(2) GDPR).
The controller, as defined in Article 4(7) of the GDPR, is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. The decisive criterion is therefore the power to decide on the purpose and means of the processing. The role of the controller thus arises primarily from the fact that a specific entity has decided to process personal data for its own purposes. The controller, as defined in Article 4(7) of the GDPR, is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. The decisive criterion is therefore the power to decide on the purpose and means of the processing. The role of the controller thus arises primarily from the fact that a specific entity has decided to process personal data for its own purposes.
It is undisputed that BG is the controller responsible for the data processing in question, because at the relevant date (April 1, 2020), it determined the purposes and means for the website, and not its subsidiary, , which only subsequently took over the business area, including the website. Furthermore, it is undisputed from the investigation that bP accessed BG's website on April 1, 2020, using a terminal device, and that at least its IP address was processed along with the cookies placed on the website. The applicability of the GDPR is therefore affirmed in this case. Furthermore, it is undisputed that bP accessed BG's website on April 1, 2020, using a terminal device, and that its IP address was processed in connection with the cookies placed on the website. According to the established case law of the CJEU, in order to be lawful within the meaning of the GDPR, data processing must at all times comply with all the principles set out in Article 5(1) GDPR and, in addition, be able to be based on at least one legal basis under Article 6(1) GDPR (see the judgment of 11 December 2019, C-708/17 and the judgment of 4 May 2023, C-60/22, paragraphs 56 and 57).
, paragraphs 53 and 54). According to the established case law of the CJEU, in order to be lawful within the meaning of the GDPR, data processing must at all times comply with all the principles set out in Article 5(1) GDPR and, moreover, be able to be based on at least one of the grounds listed in Article 6(1) GDPR (see the judgment of 11 December 2019, C-708/17, and the judgment of 4 May 2023, C-60/22, paragraphs 56 and 57). , paragraphs 53 and 54). 2. 1. 1 of the legal assessment, according to the established case law of the CJEU, the general principles for the processing of personal data laid down in Article 5 of the GDPR must be legally binding rules that are specifically effective and must be taken into account when assessing the lawfulness of data processing pursuant to Article 6 of the GDPR. 1 of the legal assessment, according to the established case law of the CJEU, the general principles for the processing of personal data laid down in Article 5 of the GDPR must be legally binding rules that are specifically effective and must be taken into account when assessing the lawfulness of data processing pursuant to Article 6 of the GDPR.
All processing of personal data must, firstly, comply with the principles for data processing set out in Article 5 of the GDPR and, secondly, comply with the principles regarding the lawfulness of processing set out in Article 6 of the GDPR (see CJEU, 22 June 2021, Case C-439/19, paragraph 96; CJEU, 4 May 2023, Case C-60/22, paragraphs 56 and 57). and 57). The Data Protection Authority acknowledges that the BG (Berufsgenossenschaft – German Federal Employment Agency) has stated that the website was created at short notice in 2020 and that it did not meet all technical requirements for a short period – including on April 1, 2020 (when the website was accessed by the bP – German Federal Employment Agency). Subsequently, a system change was implemented, which resulted in the implementation of a cookie banner and the publication of a privacy policy for all users online. Nevertheless, the BG, as the data controller pursuant to Article 4(7) GDPR, has failed to comply with its legal obligation to adhere to the principles of data processing pursuant to Article 5(1) GDPR.
The data protection authority acknowledges that the BG has stated that the website was created at short notice in 2020 and that it did not meet all technical requirements for a short period – including on April 1, 2020 (when the website was accessed by the bP). Subsequently, a system change was implemented, resulting in the implementation of a cookie banner and the publication of a privacy policy for all users. However, the BG, as the data controller pursuant to Article 4(7) GDPR, has still failed to comply with its legal obligation to adhere to the principles of data processing pursuant to Article 5(1) GDPR. The subject of these proceedings is that on April 1, 2020, bP accessed the website of the then-responsible data controller pursuant to Article 4, point 7 of the GDPR. At that time, the website did not have an implemented cookie banner, and furthermore, the privacy policy was not publicly accessible to users, including bP.
Specifically, when the website was accessed, 14 cookies were set. , user recognition, advertising, marketing, and creating the digital shopping cart). It is undisputed that data processing involving bP's personal data took place. At that time, the website did not have an implemented cookie banner, and the privacy policy was not publicly accessible to users, including bP. Article 5(1)(a) establishes, in addition to the two principles of processing personal data lawfully and fairly, the principle of transparency. The data protection principle of transparency means that data subjects must be able to understand the processing of their personal data in order to exercise their rights against the controller and demand fair processing that meets their reasonable expectations. Article 5(1)(a) of the GDPR emphasizes this obligation, already grounded in the principle of good faith, that personal data must be processed in a manner comprehensible to the data subject, by establishing it as a separate principle for the processing of personal data.
This principle serves as a fundamental condition for control over the use of one's own personal data and is a prerequisite for its effective protection. The substantive requirements for the traceability of data processing focus on informing the data subject about which personal data concerning them is being processed, for what purpose and to what extent, and what risks, rights, and safeguards are associated with this (see Heberlein in Ehmann/Selmayr, Commentary on the GDPR, 3rd edition, Art. 5 GDPR, para. 17 and para. 18). Transparency is intended to guarantee data protection, but also to enable the data subject to make an informed decision, if necessary, to object to data processing. The principle of transparency, of being visible, and of making visible is a factor in numerous other provisions of the General Data Protection Regulation and is significant for their interpretation and application (Frenzel in Paal/Pauly in the Commentary on the GDPR, Art.
5, para. 22, and Wolff in Schantz/Wolff, Data Protection Law, para. 394). ). Article 5, paragraph 1, letter a, stipulates, in addition to the two principles of processing the data subject's personal data lawfully and fairly, that processing must also be transparent. The data protection principle of transparency of processing means that the data subject must be able to understand the processing of their personal data in order to exercise their rights against the controller and demand fair processing that meets their reasonable expectations. Article 5, paragraph 1, letter a, GDPR emphasizes this obligation, already grounded in the principle of good faith, that personal data must be processed in a manner comprehensible to the data subject, by establishing it as a separate principle for the processing of personal data as a fundamental condition for control over the use of one's own personal data and a prerequisite for the effective protection of this data.
The substantive requirements for the traceability of data processing focus on informing the data subject about which personal data concerning them is being processed, for what purpose and to what extent, and what risks, rights, and guarantees are associated with it (see Heberlein in Ehmann/Selmayr, Commentary on the GDPR, 3rd edition, Article 5 GDPR, para. 17 and para. 18). Transparency is intended to guarantee data protection, but also to enable the data subject to make an informed decision, if necessary, to object to data processing. The principle of transparency, of being visible, and of making visible is a component of numerous other provisions of the General Data Protection Regulation and is significant for their interpretation and application (Frenzel in Paal/Pauly in the Commentary on the GDPR, Article 5, para. 22, and Wolff in Schantz/Wolff, Data Protection Law, para. 394). ). Due to the temporary technical deficiencies of the website at the time—specifically, the lack of a cookie banner and a publicly accessible privacy policy—BG failed to transparently inform users about the cookies it used (whether technically necessary or not).
This constitutes a violation of the principle of transparency under Article 5(1)(a) GDPR and the information obligations under Article 13 GDPR, especially since, for the data controller, BG was neither transparent about the data processing associated with the cookies it used at that time, nor did it comply with its information obligations under Article 12 in conjunction with Article 13 GDPR. , via a cookie banner or privacy policy). , via a cookie banner or privacy policy). A further examination of the facts of the case, specifically whether the data controller's lawfulness of the processing pursuant to Article 6 GDPR was violated, is unnecessary in this case because the data processing already violated the principles of data processing and was therefore unlawful for the period in question. A further examination of the facts of the case, Whether the data controller's rights under Article 6 of the GDPR were violated is irrelevant in this case because the data processing already violated the principles of data processing and was therefore unlawful for the period in question.
The data protection authority refrains from issuing a service agreement pursuant to Article 58(2) of the GDPR in this specific case due to the fact that the website was converted shortly thereafter and that the website is no longer accessible (and therefore no data processing is taking place). The decision was therefore rendered accordingly.