VwGH Ro 2025/04/0007-7
The controller was an address publisher and direct advertising company that operated a data application to provide advertisers with personal data for targeted marketing measures.
🔥 Heavily discussed 3papers · 1news item
- The Court of Justice on the Excessiveness of Access Requests under the GDPR European Journal of Risk Regulation
- POJAM OSOBNOG PODATKA U TUMAČENJU SUDA EUROPSKE UNIJE Zbornik radova. Aktualnosti građanskog i trgovačkog zakonodavstva i pravne prakse
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Computer law & security review
- EDPB: CJEU ILVA (C-383/23) ruling consistent with Guidelines 4/2022; no change needed CJEU
- The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza
In 2019, following media reports concerning the alleged sale of personal data, particularly information about natural persons’ political party affinity, the Austrian DPA (DSB) initiated an ex officio investigation against the controller. Based on its investigation, the DPA found that the controller had unlawfully processed political party affinity data and unlawfully further processed parcel-frequency data, and had infringed its obligations concerning the DPIA and record of processing activities. It consequently imposed a fine of €18,000,000. The controller appealed to the Federal Administrative Court (BVwG), arguing that the commission of an infringement by a legal person was not, in itself, sufficient for a fine to be imposed under the GDPR. It claimed that since a legal person could not act on its own, the culpable conduct of a natural person had to be identified and attributed to it. The controller argued that the DPA had failed to establish such attribution. The court agreed and, on 26 November 2020, annulled the fine. It found that the DPA had failed to establish that natural persons acting on behalf of the controller had engaged in culpable conduct. The DPA filed an extraordinary official appeal against this judgment with the Austrian Supreme Administrative Court (VwGH). The court stayed the proceedings pending the CJEU’s preliminary ruling in Case C-807/21 (Deutsche Wohnen SE), as the questions referred in that case were also relevant to the appeal proceedings. The CJEU published its judgement on this matter on 5 December 2023. The CJEU held that a fine under Article 83(4) GDPR, Article 83(5) GDPR and Article 83(6) GDPR may be imposed on anyone who qualifies as a controller where it is established that the controller committed the relevant infringement intentionally or negligently. A controller may be sanctioned where it could not have been unaware of the infringing nature of its conduct, regardless of whether it knew that its conduct infringed the GDPR. The CJEU further clarified that, where the controller is a legal person, the application of Article 83 GDPR does not require any action or knowledge on the part of its governing body. Member States may not impose additional substantive requirements for the imposition of fines beyond those laid down in Article 83 GDPR. For the determination of the fine, the controller may also constitute an undertaking within the meaning of EU competition law, with the turnover of the relevant economic unit being taken into account. Following the CJEU judgment, the Supreme Administrative Court annulled the Federal Administrative Court’s judgment on 1 February 2024. The Federal Administrative Court issued a new judgment on 27 December 2024, largely upholding the infringements but reducing the fine to €16,000,000. The controller appealed this decision before the Supreme Administrative Court. Holding — The court found that the controller gathered information concerning the political party affinity of the Austrian population based on anonymous surveys conducted by commissioned polling institutes. These surveys included specific questions concerning interest in election advertising, together with sociodemographic information such as age, level of education and income, place of residence and interest in advertising from political parties. Marketing groups were subsequently formed based on the sociodemographic data and place of residence. For each group, calculations were made to determine the likelihood that an individual with particular sociodemographic characteristics and religious affiliation would be interested in advertising from the political parties concerned. By assigning an identifiable individual to a particular marketing group, the controller linked that person to the probability values calculated for the group and the resulting political party affinity. The court held that the controller did not obtain consent from the data subjects to whom these probability scores were assigned. In total, political party affinity was attributed to approximately 2,200,000 individuals. The court reiterated that political party affinity scores attributed to identifiable individuals constituted personal data revealing political opinions within the meaning of Article 9(1) GDPR. It therefore upheld the finding that the controller had infringed Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. In assessing the controller’s culpability, the court relied heavily on the CJEU’s judgment in Deutsche Wohnen SE. It held that the fact that the controller believed it had complied with the GDPR because it had established a quality-assured organisation was not decisive. It pointed out that under GDPR, a legal person’s fault does not require knowledge or awareness on the part of the management body. The establishment of a data protection compliance system, like the obtaining of legal advice, did not in itself exculpate the controller. It stated that the decisive question was whether the controller could have been aware of the unlawfulness of the processing of political party affinity data during the relevant period. The court ruled that the controller had incorrectly assessed that political party affinity scores did not constitute personal data and that it had consequently failed to examine whether they constituted special categories of personal data under Article 9 GDPR. The court rejected the controller’s argument that political party affinity was processed only in relation to groups rather than in relation to specific identifiable individuals. It also rejected the argument that marketing classifications used for political advertising posed no risk to data subjects. The court concluded that given the controller’s resources and its ability to examine the applicable legal position, that legal assessment amounted to gross negligence concerning the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. Furthermore, the court ruled that the controller’s incorrect assessment that political party affinity scores did not constitute personal data or special categories of personal data also led it to conclude in its Data Protection Impact Assessment (DPIA) that the processing did not pose a high risk and that the scope of Article 35(3)(a) GDPR was therefore not applicable. The court held that the DPIA-related infringement was therefore absorbed from the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. It found no separate element of wrongdoing. The court additionally ruled that the same incorrect legal assessment resulted in the controller’s failure to include political party affinity as a separate category of personal data in its record of processing activities under Article 30(1)(c) GDPR. The court similarly found that these documentation failures did not contain a separate element of wrongdoing beyond that already covered by the infringement of Article 5(1)(a) GDPR and Article 9(1) GDPR. The court therefore discontinued the proceedings concerning the separate DPIA and record-of-processing infringements. It further held that, where a controller commits multiple GDPR infringements, a single aggregate fine must be imposed under Article 83(3) GDPR, the total amount of which may not exceed the amount applicable to the most serious infringement. The court reassessed the penalty and reduced it to €13,000,000, because the DPIA and record of processing infringements were no longer to be taken into account in determining the fine.
How it connects
References
- Art. 14
- Art. 83(5)(a)
- Art. 83(3)
- Art. 9
- Art. 6(1)
- Art. 30(1)(c)
- Art. 83(4)(a)
- Art. 9(2)
- Art. 5
- Art. 9(1)
- Art. 35(3)(b)
- Art. 35(7)(c)
- Art. 83
- Art. 35
- Art. 30
- Art. 58
- Art. 58(2)
- Art. 40
- Art. 42
- Art. 58(2)(i)
- Art. 83(4)
- Art. 83(2)(b)
- Art. 83(2)
- Art. 5(1)(a)
- Art. 30(1)
- Art. 10
- Art. 35(1)
- Art. 5(2)
- Art. 29
- Art. 30(1)(a)
- Art. 83(1)
- Art. 83(2)(d)
- Art. 25
- Art. 32
- Art. 47
- Art. 83(5)
- Art. 83(6)
- Art. 35(3)(a)
- Art. 4(7)
- Art. 6(4)
- Art. 36
- Art. 9(2)(a)
- Art. 9(2)(g)
- Art. 83(2)(f)
- Art. 83(2)(k)
- Art. 83(2)(j)
- Art. 4(1)
- Art. 4
- Art. 83(2)(e)
- FSV Inzage. Interne adviezen, juridische analyses die zijn bedoeld om intern te delen, notities die persoonlijke gedachten van medewerkers kunnen persoonsgegevens bevatten
- BVwG - W258 2227269-1/39E
- BVwG - W258 2227269-1/39E
Cited by
- Coordinated Enforcement Action,
- EDPB: CJEU ILVA (C-383/23) ruling consistent with Guidelines 4/2022; no change needed
- BAG - 8 AZR 169/25
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- VwGH - VwGH Ro 2025/04/0007-7
- OLG München - 36 U 1054/25 e
- BVwG - W254 2321912-1
- BVwG - W254 2321912-1
- FSV Inzage. Interne adviezen, juridische analyses die zijn bedoeld om intern te delen, notities die persoonlijke gedachten van medewerkers kunnen persoonsgegevens bevatten
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- EDPB Annual Report 2024
- Richtsnoeren 01/2022 over de rechten van betrokkenen Recht van inzage
- Richtsnoeren 01/2022 over de rechten van betrokkenen Recht van inzage
- Richtsnoeren 01/2022 over de rechten van betrokkenen Recht van inzage
- Richtsnoeren 01/2022 over de rechten van betrokkenen Recht van inzage
- Richtsnoeren 10/2020 met betrekking tot de beperkingen krachtens artikel 23 AVG
- Guidelines 10/2020 on restrictions under Article 23 GDPR
- BVwG - W258 2227269-1/39E
- BVwG - W258 2227269-1/39E
- BVwG - W258 2227269-1/39E
- BVwG - W258 2227269-1/39E
- BVwG - W258 2227269-1/39E
- BVwG - W258 2227269-1/39E
- Richtsnoeren 02/2021 inzake virtuele spraakassistenten
- Deutsche Wohnen SE v Staatsanwaltschaft Berlin
- Peter Nowak v Data Protection Commissioner
- The Court of Justice on the Excessiveness of Access Requests under the GDPR
- POJAM OSOBNOG PODATKA U TUMAČENJU SUDA EUROPSKE UNIJE
- OLG München - 36 U 1054/25 e
- BAG - 8 AZR 169/25
- BVwG - W254 2321912-1
- Coordinated Enforcement Action,
- Gerechtshof Arnhem-Leeuwarden, 24-02-2026 (200.356.273/01)
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- EDPB Annual Report 2024
- FSV Inzage. Interne adviezen, juridische analyses die zijn bedoeld om intern te delen, notities die persoonlijke gedachten van medewerkers kunnen persoonsgegevens bevatten
- BVwG - W258 2227269-1/39E
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how
- UZ v Bundesrepublik Deutschland
- PHR - 22/01253
- Richtsnoeren 01/2022 over de rechten van betrokkenen Recht van inzage
- Guidelines 10/2020 on restrictions under Article 23 GDPR
- Richtsnoeren 02/2021 inzake virtuele spraakassistenten
- Richtsnoeren 10/2020 met betrekking tot de beperkingen krachtens artikel 23 AVG
- Peter Nowak v Data Protection Commissioner
- Deutsche Wohnen SE v Staatsanwaltschaft Berlin
Related across sources
Full text 88 paragraphs
at IN THE NAME OF THE REPUBLIC! The Administrative Court, through its presiding judge, Senate President Dr. Lukasser, as well as Court Councilor Dr. Mayr, Court Councilor Mag. Hainz-Sator, Court Councilor Mag. Brandl, and Court Councilor Dr. Funk-Leisch as judges, with the assistance of the Clerk Mag. Vonier, has ruled on the appeal filed by Ö Aktiengesellschaft, with representation provided by Schönherr Rechtsanwälte GmbH in Vienna, against the decision of the Federal Administrative Court dated December 27, 2024, W258 2227269-1/39E, concerning a data protection matter (authority sued before the Administrative Court: Data Protection Authority; other party: Federal Minister of Justice), I. )] a) and b) of the contested decision, insofar as the Federal Administrative Court confirmed the Data Protection Authority’s penalty order in its point II. a) subject to the conditions specified in detail and identified the violated legal provisions regarding point II.
a. of the Data Protection Authority’s penalty order, is dismissed. II. Correctly held: 1. )] a) and b) of the contested decision, insofar as the Federal Administrative Court confirmed the penalty decision of the Data Protection Authority in its Point I, subject to the conditions specified in detail, and identified the legal provisions violated in that regard, is dismissed as unfounded. 2. at “Ö, as the controller within the meaning of Art. 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data , on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation; GDPR), OJ No. L 119 of May 4, 2016, p. 1, is responsible for the following at its registered office: I. 2 million natural persons, and, b) calculated through June 30, 2018, for and sold to S with respect to all data mentioned in (a), and through February 21, 2019, to W and Ö with respect to all data mentioned in (a), limited to natural persons with addresses in N.
The controller thereby violated the following legal provisions: Art. 5(1)(a) in conjunction with Art. 9(1) in conjunction with Art. 83(5)(a) of the GDPR. II. , the number of packages the individual received during a specific period—and subsequently anonymized the data in order to create an extrapolation model for marketing purposes. The controller thereby violated the following legal provisions: Art. 5(1)(a), 2nd and 3rd cases, in conjunction with Art. 83(5)(a) GDPR, Art. 5 (1)(b) in conjunction with Art. 6(4) in conjunction with Art. 83(5)(a) of the GDPR. at “relocation frequency”—or the “relocation affinity” used to calculate it—the processing is discontinued pursuant to § 45 (1)(1), second case, of the Administrative Offenses Act (VStG). b) With regard to the allegation of unlawful processing through the storage and sale of personal data in the following categories: - Donation Affinity - Bioaffinity - Relationship - Annual income - Type of employment - Qualifications - Consumer-oriented base - Night owls - Investment affinity - Life stage the proceedings are discontinued pursuant to para 45(1)(1) (first case) of the VStG.
III
With regard to the allegation against the defendant of having thereby violated her obligation to conduct a data protection impact assessment concerning the “DAM Target Group Addresses” application by failing to data protection impact assessment was not conducted during the period from March to June 2018, but at a later date, in any case after May 25, 2018, the proceedings are discontinued pursuant to § 45(1)(1) (first case) of the VStG IV. With regard to the allegation that the data protection impact assessment for the “DAM – Target Group Addresses” application was flawed as of May 25, 2018, because it denied the processing of special categories of personal data. data was denied, even though “party affiliation” was calculated and processed, and yet the conclusion was that a high risk did not exist in any case, the proceedings are discontinued pursuant to Para 45(1)(2) of the VStG. V.
at as well as b) the extensive processing of sensitive data is denied, the proceedings are discontinued pursuant to para 45(1)(2) VStG. VI. With regard to the allegation that the controller failed, as of May 25, 2018, failed to create a complete record of processing activities for the “DAM Target Group Addresses” application by failing to include in it a sufficient description of the category of data “Marketing,” namely ‘MARKETING, such as partial payers, loyalty cardholders, bargain hunters, animal lovers, sports, Sinus Milieu, neurotypes, travel, organic, night owls, recreational grillers, Paket Score, DIY enthusiasts, online shoppers, brand, Style High Fashion, Life Stage, Party Affinity, Income, Purchasing Power, Agriculture, Number of Children, Baby, Toddler, Child, School-Age Child, Teenager, Marital Status,” the proceedings are discontinued pursuant to para 45(1)(2) VStG. VII. With regard to the allegation that the defendant (wrongfully) failed to conduct a consultation pursuant to Art.
36 of the GDPR, the proceedings are discontinued pursuant to § 45(1)(1) (first case) of the VStG. VIII. With regard to the allegation that the defendant failed to fulfill her obligations under Article 14 of the GDPR by not informing data subjects to the required extent about which data—not collected directly from the data subject—was collected by whom and in what manner, and subsequently transferred to third parties—for example, sold or otherwise made available—the proceedings are discontinued pursuant to § 45(1)(1) (first case) of the VStG. The administrative fine is set at €13,000,000 (in words: thirteen million euros) pursuant to Article 83(5)(a) in conjunction with Article 83(3) of the GDPR. The The contribution toward the costs of the proceedings is set at €100,000 (in words: one hundred thousand euros) pursuant to § 64(1) VStG. 40 within 14 days, subject to enforcement otherwise. at Reasons for the Decision: I.
1. ” She operates a data application called “DAM Target Group Addresses” to provide advertising clients with personal data for targeted marketing measures in exchange for payment. 3 To the extent relevant here, the following information about natural persons was used and disclosed to third parties: title, first and last name, address, date of birth, and certain marketing information such as party affiliation, package preferences, and relocation tendencies, among others. ” 5 In connection with this activity, the appellant has been collecting, since 2017, information on the party affiliations of the entire Austrian population based on anonymous surveys conducted by commissioned opinion research institutes, in which specific questions regarding interest in election campaigning were asked. In this context, sociodemographic data such as age, formal education, and income levels, as well as place of residence and any interest in election campaigning by political parties, were collected.
at the probability that a specific person with certain sociodemographic characteristics and religious affiliation would be interested in advertising from the aforementioned political parties. By classifying a specific individual into a particular marketing group, these individuals were assigned the probability values calculated for the respective marketing group and the resulting party affinity. 6 The appellant did not obtain consent from the data subjects to whom probability values were assigned for the processing of party affiliation data. 2 million different individuals were assigned a party affiliation. As of February 22, 2019, the appellant no longer processed party affiliations for address trading or marketing purposes and deleted them on that date with respect to those individuals who had not submitted a request for information to the appellant. 2. In the data application “DAM Target Group Addresses,” from August 2017 through February 2019, package affinities for individuals had the purpose of marketing using statistical methods based on the parcel frequency in a specific region and sociodemographic data.
This affected at least several hundred thousand data subjects. The parcel affinities were deleted by May 13, 2019. The appellant did not obtain consent from the data subjects for the further processing of the delivery data required to determine the package affinities, to calculate the package frequency, and subsequently to create the extrapolation model for the package affinities. 3. In the DAM Target Group Addresses data application, the petitioner also determined moving affinities from January 2017 through February 2019 and assigned them to individual persons for marketing purposes. 4. Based on media reports, the respondent authority initiated an ex officio investigation against the appellant on January 8, 2019. With a request for justification dated February 20, 2019, the respondent authority initiated administrative penalty proceedings regarding the violations of the GDPR alleged against the appellant.
5. In a penalty notice dated October 23, 2019, the respondent authority charged the appellant with the following as the controller within the Within the meaning of Art. 4(7) of the GDPR, what is responsible for the following: “I. The unlawful processing of special categories of personal data within the meaning of Art. 9 of the GDPR (‘party affiliations’) in the course of exercise of the business activity ‘address publishers and direct marketing companies’; this was done by failing to obtain the consent of the data subjects and the data processing cannot otherwise be based on any of the grounds exhaustively listed in Article 9 of the GDPR. II. at - Night owls - Investment affinity - Life stage the proceedings are dismissed pursuant to para 45(1)(1) (first case) of the Administrative Offenses Act (VStG). III. With regard to the allegation against the defendant of having thereby violated her obligation to conduct a data protection impact assessment concerning the use of “DAM Target Group Addresses” by failing to data protection impact assessment was not conducted during the period from March to June 2018, but at a later date, in any case after May 25, 2018, the proceedings are discontinued pursuant to § 45(1)(1) (first case) VStG IV.
The data protection impact assessment for the “DAM Target Group Addresses” application was flawed because it denied the processing of special categories of personal data, even though “party affiliation” was calculated and processed, and yet the existence of a high risk was denied in any case. V. The inaccuracy of the record of processing activities “DAM Target Group Addresses,” since, according to this record, a) the processing of data requiring special protection, including political opinion, as well as b) extensive processing of sensitive data is denied. VI. The inadequacy of the record of processing activities “DAM Target Group Addresses,” since it does not list all categories of data actually processed and was therefore not prepared in sufficient detail. VII. With regard to the allegation that the defendant (wrongfully) failed to conduct a consultation pursuant to Art. 36 of the GDPR, the proceedings are discontinued pursuant to § 45(1)(1) (first case) of the VStG.
VIII
With regard to the allegation that the defendant failed to fulfill her obligations under Article 14 of the GDPR by not informing data subjects to the required extent about which data not collected directly from the data subject was collected by whom and in what manner, and subsequently subsequently transferred to third parties—for example, sold or otherwise made available—the proceedings are discontinued pursuant to § 45(1)(1) (first case) of the VStG. : Art. 5(1)(a), Art. 9 in conjunction with Art. a): Art. 5(1)(a) and (b), Art. 6(1) and (4) in conjunction with Art. : Art. 35 in conjunction with Art. 83(4)(a) of the GDPR Re V. : Art. 30 in conjunction with Art. ” 11 An administrative fine in the amount of €18,000,000 was imposed on the appellant pursuant to para 83(5)(a) of the GDPR. The contribution toward the costs of the criminal proceedings was set at €1,800,000 pursuant to para 64(2) of the Administrative Offenses Act (VStG).
6. Regarding the background of the appeal proceedings, reference is also made to the rulings of the Administrative Court dated December 14, 2021, Ro 2021/04/0007, and February 1, 2024, Ra 2020/04/0187. 1. a. )) and the costs of the proceedings pursuant to para 64(2) VStG to €1,600,000 [Point A) IV. )]. ) For her product ‘DAM Target Group Addresses,’ with respect to the individuals contained in her DAM database, she compiled at least a list of the packages received, including the time of receipt, from the recipients parcel delivery division (“Key Figures”) and used this to calculate the parcel frequency for each individual—that is, the number of parcels the individual received during a specific period—and subsequently anonymized the data to create an extrapolation model for marketing purposes. 1, IV, and V and VI. of the penalty notice: “I. ‘Art. 5(1)(a) in conjunction with Art. 9(1) in conjunction with Art.
): ‘Art. 5(1)(a), second and third cases, in conjunction with Art. 83(5)(a) of the GDPR; Art. 5 (1)(b) en relación con el Art. 6(4) en relación con el Art. : ‘Art. 35(3)(b) en relación con el Art. 35(7)(c) en relación con el Art. 83(4)(a) del GDPR’ V. ” 15 The Administrative Court declared the appeal admissible pursuant to Article 133(4) of the Federal Constitutional Law (B-VG). ) (confirmation of the penalty order subject to the conditions specified in subparagraph a), and adjustment of the violated legal provisions under subparagraph b)) are set forth below. 2. The Administrative Court made the following findings of fact (beyond points I. 1. through I. 3. ), which are essential for the appeal proceedings: 18 Regarding the subjective element of the offense with respect to party affiliations, the Administrative Court—insofar as relevant here—found that the appellant had launched the “Fit for the GDPR” project to prepare for compliance with the GDPR.
Among other things, project goals had been defined, a steering committee had met regularly since December 2017, and progress had been monitored using a traffic-light system. An external consultant had been engaged to assist with the organizational design of the data protection structure. From an organizational standpoint, so-called “data protection managers” were appointed in the individual departments, who were entrusted with assessing the admissibility of processing activities under data protection law. The data protection officer was to be involved in the review of data applications in the respective departments. at 19 L H was responsible as Data Protection Manager for the “DAM Target Group Addresses” division. From 2017 to 2020, E W served as the appellant’s data protection officer. The Administrative Court made detailed findings regarding the data protection manager and the data protection officer, covering their resumes, their knowledge of data protection law, and their duties at the appellant.
20 L H had reviewed the “DAM Target Group Addresses” data application even before the introduction of the GDPR, around 2010 or 2011, and deemed it permissible. It had also been entered into the data processing register. However, party affiliation had not yet been processed at that time. It had reviewed the data application—and thus also the “Sinus-Geo-Milieus” and party affiliation— in the course of preparing for the GDPR and again in light of a high-profile public debate in Germany. To the extent that the processing of party affiliation was deemed permissible by the Austrian Direct Marketing Association and A GmbH, this was essentially justified on the basis of § 151 GewO 1994. The permissibility was not justified on the grounds that the affinities did not constitute personal data. 21 L H conducted legal research in the Federal Legal Database (RIS) . ” She misinterpreted this decision in that she assumed that the Data Protection Authority had regarded marketing classifications or statistical values attributed to individual persons were not considered personal data.
She inferred from the alleged classification of the “Sinus-Geo-Milieus” as non-personal data that party affiliation was also non-personal. at including attorneys, but did not receive a satisfactory answer. No further discussions with attorneys took place. 23 Ultimately, she also discussed the issue of personal data within her team. One of her employees expressed concerns in February 2018 that party affiliations might constitute personal data and could be problematic. L H discussed these concerns during the weekly meeting with the team leaders of the “DAM” division and its head, but the opinion did not gain majority support. The individuals involved assumed that the concerns were unfounded because the affiliations did not constitute personal data. Additionally, representation was made that their processing was covered by the Trade Regulation Act. 24 L H concluded that “Sinus-Geo-Milieus” constituted statistical data that was not personal in nature, even if it had been attributed to specific individuals.
Based on the similarities with the “Sinus-Geo-Milieus,” it subsequently assumed that the party affiliations also did not constitute personal data. 25 It discussed this conclusion with the data protection officer of the appellant. The data protection officer also shared the view that statistical data—despite being linked to a specific individual—did not constitute personal data, and therefore considered the data application “DAM Target Group Addresses” and the party affiliation as unproblematic under data protection law. 3. 435/0005-DPA/2017). at With regard to decisions, it can be inferred that marketing classifications or probability values attributed to individual persons constitute personal data. 27 In Austrian legal literature, Jahnel also assumes in *Handbuch Data Protection Law (2010), margin note 3/72, that estimates of a person’s probable membership in a specific target group, determined using statistical extrapolations, should be classified as personal data.
4. With regard to the data protection impact assessment (DPIA) for the data application “DAM Target Group Addresses,” the Administrative Court found, with respect to the objective facts of the case, that Annex 2B-1 of the DPIA for the application “DAM Target Group Addresses,” titled “Privacy Impact Assessment/DSFA (pursuant to Art. ” 39 Regarding the subjective element of the offense concerning the DPIA for the data use “DAM Target Group Addresses,” the Administrative Court found that, since the data protection manager had been of the opinion that the marketing classification “party affiliation” did not constitute personal data, she did not examine whether party affiliation could constitute special categories of data. Accordingly, she had ruled out the existence of special categories of data and, consequently, the existence of a high risk in the DPIA. The data protection officer, too, had assumed that party affiliations did not constitute personal data, which is why she had followed the assessment of the data protection manager and did not advise otherwise.
5. ]” 41 A more detailed breakdown of the “marketing” data category is found neither in the main document nor in any annexes to the VVZ. The Appellant processed, among other things, the following data types in connection with the aforementioned “data”: Marketing, such as installment payers, loyalty cards, bargain hunters, animal lovers, sports, Sinus Milieu, neurotypes, travel, organic, night owls, backyard grillers, Paket Score, DIYers, online shoppers, brand, high fashion, life stage, party affiliation, income, purchasing power, agriculture, number of children, baby, toddler, child, school-age child, teenagers, marital status. at 42 In the appellant’s data processing notice regarding the use of “DAM Target Group Addresses,” the “Risks” section states the following: “Is there extensive processing of sensitive data? )? | No” 43 Regarding the subjective element of the offense concerning the data usage declaration “DAM Target Group Addresses,” the Administrative Court found that the data protection officer had made the decision that extensive processing of sensitive data and the processing of data requiring special protection, including political opinion, should be ruled out because she had been of the opinion that the marketing classification “party affiliation” did not constitute personal data and therefore did not fall under special categories of personal data.
The VVZ should have included an appendix providing a detailed breakdown of the types of data processed. However, due to an oversight, the appendix was attached to the DSFA only as Appendix 2D “Processed Data,” but not to the VVZ. This appendix contains a detailed breakdown of the types of data used, such as the individual affinities. 6. In recalculating the administrative fine, the Administrative Court determined that the appellant’s revenue for the 2018 fiscal year amounted to €1,804,099,563 for the 2018 fiscal year and €2,033,836,266 for the 2023 fiscal year. 8 million. 6 million. 7. In its legal assessment, the Administrative Court addressed point I of the penalty order (unlawful processing of party affiliation) regarding the objective elements of the offense—insofar as relevant here—that the appellant, contrary to the processing prohibition under Art. 2 million natural persons, and - calculated until June 30, 2018, and sold to [S] with respect to all data, and until February 22, 2019, to [W] and [O] with respect to natural persons with addresses in [N], and thus processed.
46 In a brief dated November 11, 2024, the appellant announced that it accepted the legal opinion of the highest courts and no longer maintained its argument that party affiliations did not constitute personal data or data regarding political opinions. 47 There is no exception to the prohibition on processing, especially since the appellant did not obtain the explicit consent of the data subjects within the meaning of Art. 9(2)(a) of the GDPR, and processing on the basis of the law of a Member State within the meaning of Art. 9(2)(g) of the GDPR in conjunction with § 151 of the 1994 Trade Regulation Act (GewO) is ruled out, because the processing of special categories of personal data pursuant to § 151(4) of the 1994 Trade Regulation Act (GewO) is likewise only permissible if the data subject has given explicit consent to the processing of such data for third-party marketing purposes, and also none of the other grounds for permissibility under Article 9(2) of the GDPR apply.
Nor does § 151(6) of the GewO 1994 constitute a suitable legal basis for the processing. 48 The appellant thus violated the legality requirement of Article 5 (1)(a), first case, of the GDPR in conjunction with the prohibition on processing special categories of personal data under Article 9(1) of the GDPR. The punishability of this violation is based on Article 83(5)(a) of the GDPR. 8. The appellant is alleged to have acted negligently. From an organizational perspective, it must be acknowledged that the appellant devoted considerable resources to preparing for the applicability of the GDPR. The division of responsibilities resulting from the “Fit for the GDPR” project—between the initial assessment of data use in the respective departments on the one hand, and the mandatory involvement of the data protection officers on the other—appears at first glance to have been appropriate. 50 In this specific case, however, there was a significant risk of fundamental legal misinterpretations due to a lack of general legal knowledge and “confirmation bias,” which was not adequately addressed from an organizational standpoint—at least during the transition period to the GDPR taken into account.
51 Although the involvement of the data protection officers could have prevented or at least reduced the aforementioned problems, sole review by the data protection officer would inevitably push a large enterprise such as the appellant, when all of the appellant’s data applications had to be reviewed in preparation for the GDPR. In such a case, it could not be assumed that there was sufficient time to adequately address the respective data applications. This is the basis for the criticism leveled against the appellant; contrary to its opinion, there was thus no effective Surveillance and Control system in place that could have excluded the attribution of fault to the appellant. 52 With regard to the specific data processing operations, the data protection manager and the data protection officer had assumed that statistical values did not constitute personal data, even if they were attributed to specific individuals.
at of the Data Protection Commission, the Data Protection Authority, and the CJEU (reference to CJEU Dec. 20, 2017, C-434/16, Nowak) is untenable (reference to Administrative Court, Dec. 14, 2021, Ro 2021/04/0007, para. , according to which, in light of [the Nowak case law] the classification of party affiliation as information “about” the persons concerned “cannot be seriously called into question,” and OGH April 15, 2021, 6 Ob 35/21x, para. 30, according to which “the desired interpretive result—namely, that a (high) receptivity to party advertising attributed to the plaintiff himself […] is not “personal data,” and that the interpretation is “unquestionable”). This applies even if there had not yet been any explicit supreme court case law on party affiliations. 53 The data protection manager is to be criticized for having been strikingly careless in forming her opinion, especially since she interpreted a relevant data protection decision in a manner that is conceptually impossible and, despite the imminent massive consequences associated with it—namely, the impending processing of special categories of personal data pertaining to numerous individuals—the data protection officer failed to take any further steps to investigate the matter.
54 The data protection officer is to be criticized for having—in blatant ignorance of existing case law and despite a new legal situation—relied on her existing (erroneous) opinion that statistical data does not constitute personal data even when attributed to specific individuals, and failed to conduct her own relevant research. 55 This reprehensible misjudgment led to the appellant to fail to further examine the party affiliation to determine whether it constituted a special category of data within the meaning of Art. 9(1) GDPR and whether, and under what conditions, its processing could have been permissible. The fact that an objective and careful examination might, under certain circumstances (albeit incorrectly), have revealed that the party affiliations did not constitute special categories of data cannot remedy the error, especially since no such examination was in fact conducted.
at 56 It must be assumed that there was grossly negligent conduct. The appellant conduct must be attributed to the appellant; an action or knowledge on the part of a member of the appellant’s management body is not required for this (reference to CJEU, Dec. 5, 2023, C-807/21, Deutsche Wohnen SE). 57 Insofar as the appellant refers to decisions, proceedings, or an isolated dissenting opinion in the literature, it must be held against her that—regardless of their actual content—these were only issued or published after the appellant had assessed the data processing , which is why they cannot justify its misjudgment during the relevant period. The appellant —even if one were to accept its arguments—could at most have had doubts regarding the classification of party affiliation under data protection law. In such a case, however, she would have been required to address the issue on a sound legal basis, for example by obtaining an external, legally sound expert opinion on the matter, which she failed to do.
9. Regarding the flaws in the DPIA, the Administrative Court stated that the appellant had, among other things, processed individuals’ party affiliations. Such extensive processing of data within the meaning of Art. 35 (3)(b) of the GDPR entails, in any case, a high risk, which must be identified in a proper DPIA. 59 The assessment made by the appellant in the DPIA regarding the “DAM target group addresses”—which also included the processing of political affiliation—that “no high risk” existed was therefore incorrect. The DPIA was therefore flawed or was not properly conducted. Consequently, the objective elements of a violation of Article 35(3)(b) of the GDPR in conjunction with Article 35(7)(c) of the GDPR have been met. The punishability of this violation is based on Article 83 (4)(a) of the GDPR. at the appellant must also be held liable for the consequential error resulting from this careless conduct as negligent conduct.
61 Insofar as the appellant argues that the element of wrongdoing has already been addressed by Point I of the ruling and the act described therein, it must be countered that the requirements for the lawfulness of data processing and the provisions governing the obligations of a controller pursue different objectives. Furthermore, a data protection impact assessment (DPIA) must be conducted prior to the commencement of processing activities, whereas unlawfulness can only become apparent after processing has commenced. The two violations are therefore necessarily separate in time. In this respect, the violation resulting from a flawed DPIA is not, as claimed by the appellant, already subsumed by the unlawful processing within the meaning of Point I of the ruling. 10. ),” even though it had processed party affiliations and thereby personal data from which political opinion could be inferred.
63 63 These statements by the appellant in its VVZ regarding the use of “DAM target group addresses” are therefore objectively incorrect. The explicit denial of the processing of sensitive or particularly vulnerable data regarding political opinion makes it difficult—and may even render it impossible—to verify the lawfulness of the present processing on the basis of this directory. Thus, the objective elements of a violation of Article 30(1)(c) of the GDPR are fulfilled. The punishability of this violation is based on Article 83(4)(a) of the GDPR. Since the inaccuracy of the information in the VVZ is based on the incorrect classification of party affiliation as non- personal data—which must be deemed negligent—the appellant must be held responsible for the consequential error resulting from this careless conduct as negligent behavior. at Nor is this violation remedied by the act described in Point I of the ruling.
11. The VVZ is further deficient because, with regard to the use of data “DAM target group addresses” regarding the categories of personal data processed, it was “only” stated that “address data, identification data, contact data, marketing data, and personal master data” were processed. Thus, the objective elements of a violation of Article 30(1)(c) of the GDPR. 65 The appellant had prepared a detailed list of the categories of data that have been processed in order to attach it to the VVZ and the DSFA as an appendix. The appellant inadvertently failed to assign this appendix to the VVZ, sending it only to the DSFA instead. She must be held responsible for this oversight as negligent conduct, although in this case it can barely be considered punishable. 12. Regarding the determination of the penalty, the Administrative Court—insofar as relevant here—stated that it must be assumed that the processing operations were interrelated, because all of the acts alleged against the appellant, involved processing the political affiliations of data subjects and preparing an incorrect DSFA and an incorrect VVZ with respect to this data processing, as well as , and having prepared an inadequate data processing plan regarding the data processing for the “DAM Target Group Addresses,” were driven by the same intent and aimed at the same purpose, namely the creation and maintenance of the “DAM Target Group Addresses” marketing database.
67 In determining the administrative fine, the Administrative Court noted regarding the party affiliations that, since the data, according to its calculations, was subsequently sold only to two political parties for the purpose of Individuals, it could be assumed that the calculation, assignment, and disclosure caused only minor non-pecuniary harm to the data subjects. at a large portion of the people living in Austria people living in Austria were systematically classified according to their presumed political interests over a prolonged period, a violation of a high degree of severity must be assumed. 68 With regard to the inadequacy of the Data Protection Impact Assessment (DPIA) and the inadequacy of the Data Processing Agreement (DPA), a violation of a minor degree of severity must be assumed in each case. With regard to the inadequacy of the VVZ, it should be assumed that the violation is of an extremely minor severity.
69 The following should be considered as mitigating factors: the comprehensive cooperation of the petitioner with the Data Protection Authority and the Administrative Court (Art. 83(2)(f) GDPR), the erasure of data regarding party affiliations, the cessation of the transfer of “package frequency” data between the business units, and the reduction of the damage by the appellant through settlements with data subjects (Art. 83 (2)(c) of the GDPR), as well as the lengthy duration of the proceedings—five years and ten months (Art. 83(2)(k) of the GDPR)—which cannot be attributed to the appellant, especially since it was necessitated by a second set of proceedings and a stay of the appeal proceedings pending the decision of the CJEU in Case C-807/21, Deutsche Wohnen SE. 70 An aggravating factor is the economic benefit the appellant derived from the unlawful processing through the sale of party affiliations as well as from the creation of extrapolation models for package affiliations, which were subsequently marketed (Art.
83 (2)(k) of the GDPR). 71 There were no relevant prior violations by the appellant, especially since, although two administrative fines had been imposed on the appellant, they had been directed against other legal interests. There are special preventive grounds for penalizing the appellant, particularly since it would in principle be free to resume the activities, provided it has not issued any cease-and-desist declarations. at refrain from imposing a penalty or substantially reduce the administrative fine. Contrary to the appellant’s view, any adherence to old rules of conduct and any intent to comply with new rules of conduct should not be considered a mitigating factor, especially since the appellant has not, in fact, complied with the approved rules of conduct (Art. 83(2)(j) GDPR). 72 The extent to which the appellant’s expenses incurred in the course of preparations for the GDPR should be considered a mitigating factor is not clear, especially since they did not prevent the commission of the acts at issue here.
Insofar as the appellant argues as a mitigating factor that it endeavored to conduct a risk assessment in the DSFA, it must be pointed out, on the one hand, that the risk assessment was in fact incorrect and, on the other hand, a measure cannot be considered a mitigating factor if the appellant was legally obligated to implement it in the first place. 73 There is no legal basis for the appellant’s requested calculation of the administrative fine based on offense-related revenue, particularly since Art. 83 (4) and (5) of the GDPR refer to the total annual revenue generated worldwide in the preceding fiscal year. With regard to the—by the appellant—cited sound technical and organizational measures, no mitigating factor can be assumed because, with respect to the assessment of party affiliation, there was also organizational negligence involved. The appellant’s “confession” should not be considered a mitigating factor, because the mere admission of facts without acknowledging the subjective elements of the criminal conduct does not have a mitigating effect, and the appellant did not view her conduct as negligent in the first place.
5 million, the penalty of €18 million imposed by the prosecuting authority appears to be at the very lower end of the range. at range in order to be just barely effective, proportionate, and appropriate. 75 Given that, compared to the decision by the defendant authority, the Administrative Court, with regard to the most serious offense— namely, the processing of party affiliation—assumes a smaller number of data subjects, that the mitigation of harm through the conclusion of settlements and the offering of cease-and-desist declarations was more pronounced, and that the proceedings regarding the processing of the “moving frequency” or “moving affinities” had been discontinued, and with regard to the period of the offense concerning the processing of “package frequency,” the period of the offense had been narrowed, special preventive reasons were reduced by the offer and conclusion of cease-and-desist agreements with the affected parties—thereby making it more difficult to repeat the conduct in this business area— the mitigating factor of the long duration of the proceedings was added, and the aggravating factor of a relevant prior conviction , the administrative fine of €16,000,000 and the costs of the proceedings must nevertheless be reduced accordingly, taking § 64 VStG into account in an overall assessment.
The reduction in the number of affected individuals should not have been given greater weight because, in the final analysis, the appellant nevertheless systematically classified a large portion of the people living in Austria according to their presumed political interests over a prolonged period of time. 13. The Administrative Court justified the admissibility of the appeal on the grounds of the lack of case law from the Administrative Court regarding the principle of cumulation under Art. 83(3) of the GDPR, namely as to which criteria should be used to distinguish whether identical or interrelated processing operations within the meaning of Article 83(3) of the GDPR exist. 77 3. ) of this decision. The respondent authority filed a response to the appeal and moved for the dismissal, or in the alternative, the rejection of the appeal, as well as for the award of costs for legal representation.
at 78 4. In support of its admissibility, the appeal essentially argues, in summary, that there is no case law from the Administrative Court regarding the question of what requirements a data protection compliance system must meet. Provided that an adequate compliance system, as established by the appellant, was in place, the failure of the compliance system in an individual case does not constitute a criminal offense, because there is no fault. Furthermore, the Administrative Court deviated from the case law of the Administrative Court of Appeal by finding fault on the part of the appellant, even though the appellant had established an adequate data protection compliance system. 79 Furthermore, with regard to the case law of the CJEU, there is a lack of case law from the Administrative Court of Appeal on how, within the scope of Article 83 of the GDPR, to assess whether a controller, through no fault of its own, was unaware of the unlawfulness of its conduct, whether a A data protection impact assessment (DPIA) under Article 35 of the GDPR and a record of processing activities under Article 30 of the GDPR must be maintained in accordance with the controller’s legal assessment, or whether these documents must be objectively accurate, as the The administrative fine should be assessed within the scope of Article 83 of the GDPR, and whether, within the scope of Article 83 of the GDPR—regardless of the amount of the fine—procedural costs should be ordered pursuant to § 64(2) of the Administrative Offenses Act (VStG).
80 Furthermore, the Administrative Court deviated from the case law of the Administrative Court of Appeal by confirming points IV and V of the DPA’s penalty notice, even though the gravity of the alleged offenses had already been addressed in Point I of the DPA’s penalty notice, and had determined the penalty in an unreasonable manner. 81 5. By order dated December 9, 2025, E 335/2025-19, the Constitutional Court refused to hear the complaint filed by the appellant against this decision. at II. 1. The penalty decision of the respondent authority challenged by the appellant contained—insofar as the respondent authority did not discontinue the proceedings regarding individual allegations in accordance with § 45 VStG—the allegation that the appellant had committed five separate violations of the GDPR, and thus five distinct points of adjudication. The Administrative Court, too, rendered separate judgments with respect to the five administrative offenses charged.
2026, Ra 2025/02/0228, paras. 9 and 10, with further references). ) a), insofar as the Administrative Court discontinued the penalty proceedings regarding the allegation that the appellant had, in the course of carrying on the business of “address publishers and direct marketing companies,” unlawfully processed “relocation affinity,” or the “relocation frequency” used to calculate it, pursuant to para 45(1)(1), second case, of the VStG. 2. Pursuant to Art. 133(4) B-VG, an appeal is admissible against a decision of the Administrative Court if it depends on the resolution of a legal issue of fundamental importance, in particular because the decision deviates from the case law of the Administrative Court, such case law is lacking, or the legal issue to be resolved has not been consistently addressed in the Administrative Court’s previous case law. 85 Pursuant to § 34(1) VwGG, appeals that are not suitable for consideration due to the absence of the 85 Pursuant to § 34(1) VwGG, appeals that are not suitable for consideration due to the absence of the requirements of Art.
133(4) B-VG shall be dismissed by order without further proceedings. at 86 Pursuant to § 34(1a) of the Administrative Court Act (VwGG), the Administrative Court, when assessing the admissibility of an extraordinary appeal under Art. 133(4) of the Federal Constitutional Act (B-VG), is not bound by the ruling of the Administrative Court pursuant to para 25a(1) VwGG. The admissibility of an extraordinary appeal pursuant to Art. 133(4) of the Federal Constitutional Law (B-VG) must be reviewed by the Administrative Court within the scope of the grounds specifically raised in the appeal (Section 28(3) of the Administrative Court Act (VwGG)). ) a) and b) of the contested decision—insofar as the Federal Administrative Court upheld the penalty decision of the Data Protection Authority in its point II. a) concerning the package frequency, subject to the specified conditions, and cited the violated legal provisions, the appeal contains no arguments regarding admissibility.
The appeal was therefore to be dismissed on this point pursuant to § 34 (1) and (3) VwGG. 4. The jurisdiction of the Administrative Court to review the decisions of the administrative courts are limited—not only in the case of an extraordinary appeal but also in ordinary appeals—to the examination of legal issues of fundamental importance within the meaning of Art. 133, para. 4, of the Federal Constitutional Law (B-VG). , VwGH March 6, 2026, Ro 2024/04/0003, para. 16, with further references). ). ) of the contested decision based on the appellant’s arguments. It is also partially well-founded. 91 2. Art. at The processing of personal data, on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation; GDPR) reads in part as follows: “Article 83 General conditions for the imposition of administrative fines (1) Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this article for infringements of this Regulation, in accordance with paragraphs 5 and 6, is effective, proportionate, and deterrent in each individual case.
(2) Administrative fines shall be imposed, depending on the circumstances of the individual case, in addition to or in lieu of the measures referred to in article 58 paragraph 2(a) to (h) and (i). at the same subject matter, if such measures were ordered; j) compliance with approved codes of conduct under Article 40 or approved certification procedures under Article 42; and k) any other aggravating or mitigating circumstances in the respective case, such as financial gains or avoided losses. (3) If a controller or a processor, in the course of the same or related processing operations, intentionally or negligently violates several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount applicable to the most serious violation. ] (6) In the event of failure to comply with an instruction issued by the supervisory authority pursuant to article 58(2), fines of up to 20,000,000 EUR or, in the case of an undertaking, up to 4% of its total worldwide Article, administrative fines of up to 20,000,000 EUR or, in the case of an enterprise, up to 4% of its total worldwide annual turnover for the preceding fiscal year shall be imposed, whichever is higher.
at may be subject to administrative fines. (8) The exercise of its own powers by a supervisory authority pursuant to this article must be subject to appropriate procedural safeguards in accordance with Union law and the law of the Member States, including effective judicial remedies and due process. (9) If the legal system of a Member State does not provide for administrative fines, this article may be applied in such a way that the administrative fine is initiated by the competent supervisory authority and imposed by the competent national Courts, ensuring that such remedies are effective and have the same effect as administrative fines imposed by supervisory authorities . In any event, the administrative fines imposed must be effective, proportionate, and dissuasive. ” 92 § 5 of the Administrative Penalties Act of 1991, Federal Law Gazette No. 52/1991, as amended by the Federal Act amending the Introductory Act to the Administrative Procedure Acts of 2008, the General Administrative Procedure Act of 1991, the Administrative Penalty Act of 1991, and the Administrative Court Procedure Act (Federal Law Gazette I No.
57/2018), reads as follows: “Culpability § 5. (1) Unless an administrative regulation provides otherwise regarding fault, negligent conduct is sufficient for criminal liability. Negligence is presumed in cases of violation of a prohibition or failure to comply with a requirement if the occurrence of damage or danger is not an element of the offense of an para (1) second sentence does not apply if the administrative offense is punishable by a fine exceeding 50,000 euros. 1. The appeal first challenges the Administrative Court’s assessment of fault, according to which the appellant, by processing data on party affiliations, acted with gross negligence in violation of Art. 5(a) of the GDPR in conjunction with the prohibition on processing special categories of personal data under Art. ) a) of the contested decision). 2. In its judgement of December 5, 2023, C-807/21, Deutsche Wohnen SE, the CJEU held that Article 58(2)(i) and Article 83 of the GDPR preclude a national provision under which a administrative fine for an infringement referred to in Article 83(4) to (6) of the GDPR may be imposed on a legal entity in its capacity as a controller only if that infringement has previously been attributed to an identified natural person.
95 In this judgement, the CJEU states, in connection with the second question referred for a preliminary ruling that it follows from the wording of Article 83 of the GDPR that only infringements of the provisions of the GDPR that the controller commits culpably—that is, intentionally or negligently—may lead to the imposition of a administrative fine against it under that article (para. 68 of the cited CJEU judgement). Article 83 of the GDPR does not permit the imposition of an administrative fine for an infringement referred to in Article 83(4) to (6) of the GDPR unless it has been proven that this infringement was committed by the controller intentionally or negligently (para. 75 of the judgement). 96 In connection with the question of whether an infringement was committed intentionally or negligently and, as a result, is punishable by an administrative fine pursuant to Article 83 of the GDPR, the CJEU clarifies that a controller may be sanctioned for conduct falling within the scope of the GDPR if the controller could not have been unaware of the unlawfulness of its conduct, regardless of whether it was aware that it was in violation of the provisions of the GDPR (para.
76 of the judgement, see also CJEU March 25, 2021, C-591/16 P, Lundbeck v. Commission, para. 156; March 25, 2021, C-601/16 P, Arrow Group and Arrow Generics v. Commission, para. at Schenker & Co. , para. 37, with further references). If the controller is a legal entity, the application of Art. 83 GDPR does not require require any action or even knowledge on the part of the governing body of that legal entity (CJEU Dec. 5, 2023, C-807/21, Deutsche Wohnen SE, para. 77, with further references). 97 The CJEU therefore bases the controller’s liability for violations of the GDPR on whether the controller could have been aware of the unlawfulness of its conduct. Awareness of the legal violation is not a prerequisite for liability. The standard for determining a controller’s fault for violations of the GDPR has thus been clarified by the CJEU. With regard to conflicting provisions under national law, it remains clear—particularly in light of the CJEU’s statement in its judgement of December 5, 2023, C-807/21, Deutsche Wohnen SE—that Member States are not authorized to provide for substantive requirements beyond the procedural requirements to be applied by supervisory authorities, which are governed by those set forth in Art.
83(1) through (6) of the GDPR (see para. ] DS-GVO2 [2025], Art. 83, para. 46, according to which the judgement in Deutsche Wohnen SE does not imply any “particularly high requirements” regarding fault). Consequently, § 5 of the VStG must be disregarded when determining the fault of the controller, § 5 of the Administrative Offenses Act (VStG) must therefore be disregarded, because the sole determining factor—as identified in the case law of the CJEU— is whether the controller could have been aware of the unlawfulness of its conduct. 98 In establishing this standard of fault, the CJEU refers to its case law on antitrust law. at Legal advice from an attorney or a decision by a national competition authority. In this judgement, the CJEU points out that the fact that the enterprise in question legally misclassified its conduct, on which the finding of the infringement is based, cannot result in no administrative fine being imposed on it, provided that it could not have been unaware of the anti-competitive nature of that conduct (see para.
38 of the judgement). 99 In its judgement of March 25, 2021, C-601/16P, Arrow Group, para. 99, the CJEU pointed out that “legal uncertainty” cannot be assumed with regard to the existence of a competition-restricting agreement if there is settled case law on the application of competition law in areas characterized by the existence of intellectual property rights. The CJEU further focused on the enterprise’s awareness that its conduct could, at the very least, raise issues from a competition law perspective. 100 In its judgement of December 12, 2012, T-332/09, Electrabel v. European Commission, the General Court of the European Union (GC), in assessing whether negligence had occurred with respect to a violation of the First Merger Regulation, the General Court, on the one hand, noted that the applicant in question was a large undertaking that had considerable resources at its disposal to assess the legal situation and had, on numerous occasions had been confronted with the EU rules on mergers (see para.
250 of the General Court’s judgement). On the other hand, the General Court held, with regard to negligence, that in light of the precedent cases—albeit from long ago—the applicant could not rely on the absence of case law in the relevant area of law (see General Court, Dec. 12, 2012, T-332/09, Electrabel v. European Commission, para. 258; see also Illibauer in Knyrim, DatKomm Art. 83 GDPR, para. 73/1 [as of Oct. at]). 3. 1, dated May 24, 2023. These guidelines address the issue of whether the infringement was intentional or negligent pursuant to Article 83(2)(b) of the GDPR (see EDPB Guidelines 04/2022, paras. 2 – Intent or Negligence of the Infringement 55. In its earlier guidelines, the EDPB stated: In general, the concept of ‘intent’ in the context of the elements of a criminal offense includes knowledge and will, whereas ‘unintentional’ means that the violation did not occur intentionally, even if the controller or processor breached its legally required duty of care.
” Example 4—Illustration of Intent and Negligence (from WP 253): “Circumstances that indicate intentional violations exist, for example, when unlawful processing has been approved by top management controller, or if—contrary to the recommendations of the data protection officer or in disregard of existing Directives—data on employees of a competitor is collected with the intent to discredit that competitor in the marketplace. , selling data for which consent to processing has been obtained, without, however, having sought or taken into account the views of the data subjects regarding the use of their data. ” Whether the violation was intentional or negligent (Article 83(2) (b) of the GDPR) should be assessed by taking into account the objective conduct evident from the facts of the case. ” In the case of an intentional violation, the supervisory authority is likely to attach greater weight to this factor.
Depending on the circumstances of the case, the supervisory authority may also take into account the degree of negligence. 1. In light of the foregoing, the following conclusions arise with regard to the arguments of the petitioner: 103 It should be noted at the outset that the Administrative Court, in its decision of December 14, 2021, Ro 2021/04/0007, that the interpretation sought by the appellant—namely, that the (high) susceptibility to advertising directed at specific recipients attributed to a specifically identified person advertising from specific parties is not to be considered personal data—cannot be derived from Art. 4(1) of the GDPR under any circumstances. However, if the result of the interpretation of Union law—as in this case—is so obvious that there is no room for reasonable doubt, then, pursuant to the “acte-clair” doctrine, a referral to the CJEU is unnecessary (see VwGH, Dec.
14, 2021, Ro 2021/04/0007, para. 40, with further references to the case law of the CJEU). In this decision, the Administrative Court further concurred with the Supreme Court’s remarks on the “expression of political opinion” pursuant to Art. 9(1) of the GDPR (para. 46 of the decision) and held that the disclosure of party affiliation is indeed well-suited to conveying to an objective third party, with sufficient clarity, the data subject’s stance toward political parties (para. 48 of the decision). Reference is made to the grounds for the decision of the Administrative Court of December 14, 2021, Ro 2021/04/0007, pursuant to § 43(2), second sentence, of the VwGG. The appellant does not, in essence, contest this case law in the appeal; her argument is that she could not have been aware of this interpretation during the relevant period and that, for this reason, she bears no fault for the violation of the requirement of lawfulness under Art.
at prohibition on the processing of special categories of personal data under Article 9(1) of the GDPR. 105 The appellant first argues that she had established an adequate data protection compliance system. Surveillance of compliance with data protection regulations was carried out at multiple hierarchical levels and within multiple structures (line organization, data protection officer, and Legal Department, as well as a project structure [“GDPR Readiness”]). The appellant cannot be blamed for a failure of this data protection compliance system in an individual case; she did not act negligently in establishing the—as described in detail—adequate data protection compliance system—which was described in detail—had not acted culpably. 3. According to the aforementioned case law of the CJEU, liability for a violation of the GDPR depends exclusively on the question of whether the controller could have been aware of the unlawfulness of its conduct could have been aware of the unlawfulness of its conduct.
According to the case law of the CJEU, the application of Article 83 of the GDPR also does not require any action or even knowledge on the part of the management body of that legal entity. The establishment of the data protection compliance system described by the appellant data protection compliance system described by the appellant—in and of itself—does not, any more than the obtaining of a legal opinion, lead to exculpation with regard to the unlawfulness of the data processed by the appellant concerning party affiliations. The decisive factor is whether the appellant could have been aware of the unlawfulness of the data processing regarding party affiliations during the period in which the processing took place. 107 Whether—as argued in the appeal—the appellant had good reason to believe that it was complying with data protection regulations due to the establishment of a quality-assured organization (see, in this regard, VwGH June 23, 2021, Ro 2019/03/0020–0021, paras.
at of the governing body (see CJEU Dec. 5, 2023, C-807/21, Deutsche Wohnen SE, para. 77). 4. ” The decisions of the DSK and the DPA cited by the Administrative Court did not concern the personal nature of marketing classifications. Furthermore, it is clear from the decisions of the DPA that the processing of marketing classifications could have been based on § 151(6) GewO 1994, which is precisely what the appellant did. 109 Nor can the appellant be held liable for gross negligence for failing to classify party affiliations—as the result of statistical extrapolations—as special categories of personal data pursuant to Art. 9(1) of the GDPR. On the one hand, the legal situation regarding this matter was unclear during the period of processing; on the other hand, contrary to the Administrative Court’s reasoning, there is no risk of data-based discrimination. Targeted political advertising is permissible; the only risk is that Data subjects might not receive certain advertisements that are irrelevant to them.
5. Since the appellant assumed that party affiliation was not processed in relation to a specific, individually identifiable person, but only in relation to groups of persons, the question of the appellant’s fault, it is essential to determine whether this constituted a legally justifiable view at the time of processing. 111 In light of the case law of the CJEU and the General Court, the existence of case law (precedents) on which the controller could base its legal opinion is of essential importance (see CJEU, March 25, 2021, C-601/16P, Arrow Group, para. 99; General Court, Dec. 12, 2012, T-332/9, Electrabel v. European Commission, para. 258). at are not personal data, even if they are attributed to specific individuals, is untenable in light of the comparable Data Protection Directive (Directive 95/46/EC) and the existing case law of the data protection authorities (Data Protection Commission and Data Protection Authority) regarding the DSG 2000, whereby the Administrative Court relied on three specifically cited decisions.
113 The appellant challenges this assessment in the appeal only to the extent that she argues the decisions of the DPA emphasized that individuals are not evaluated through marketing classifications in any way recognizable to third parties. Whether these decisions could be interpreted as assuming a lack of personal reference in marketing classifications is, furthermore, irrelevant, because it is clear from all the decisions that the processing of marketing classifications can be based on § 151(6) GewO 1994. 114 It is true that the decisions of the Data Protection Authorities cited by the Administrative Court did not directly address the question of the personal reference of marketing classifications. 754/0002-DPA/2018, each address issues concerning the (complete) provision of information pursuant to para 26(1) and (4) Data Protection Act 2000. However, insofar as these decisions addressed the content and scope of the right of access with regard to marketing classifications, the Administrative Court must, however, be agreed with in that these decisions presupposed the existence of “personal data” within the meaning of § 4(1) of the Data Protection Act 2000.
In this regard, with respect to the question—which is central here—of whether marketing classifications constitute personal data within the meaning of Art. at relevant decisions by Data Protection Authorities that the appellant must take into account in its assessment. 115 The EDPB Guidelines also identify failures to read and comply with existing Directives and failures to review published information regarding personal data as circumstances that may indicate negligence (see EDPB Guidelines 04/2022, pp. 20–21). 116 The Administrative Court’s conclusion that the legal view that statistical values do not constitute personal data—even when attributed to specific individuals—was at the time of the processing at issue, in light of the existence of decisions by Data Protection Authorities, is, against this background, already untenable in view of the significance of existing decision-making practice—as emphasized in the case law of the CJEU and the General Court— case law, as emphasized in the case law of the CJEU and the General Court.
6. The appellant further argues in the appeal that the legal situation, particularly with regard to the classification of marketing classifications as special categories of data pursuant to Art. 9 (1) of the GDPR, and that it was unforeseeable at the time of processing. Marketing classifications are not real data, and a correlation exists only with respect to the group of individuals and not to the individual. ” The Administrative Court did not conduct a separate examination of the appellant’s fault with regard to the classification of party affiliations as special categories of data pursuant to Art. 9 (1) GDPR. 118 It must be countered that there is an unclear legal situation regarding the classification of party affiliations as special categories of data pursuant to Art. 9(1) GDPR, particularly in light of the—intended—purpose of processing this data—the likelihood that political opinions would emerge from the processed data and the protective purpose of Art.
at (1) of the GDPR (see again Administrative Court, Dec. 14, 2021, Ro 2021/04/0007, paras. 46–48). The legal view that the processing of marketing classifications for political advertising entails no risk to the data subject proves to be untenable even against this background. 119 Furthermore, the appellant does not even claim to have separately examined the question of whether party affiliations constituted special categories of data pursuant to Art. 9 (1) of the GDPR prior to the processing of this data. Nor can the appellant rely on § 151(6) of the 1994 Trade Regulation Act (GewO) as the basis for processing party affiliations, because the processing of special categories of personal data data within the meaning of Article 9(1) of the GDPR, pursuant to § 151(4) of the GewO 1994 as amended by the 2018 Act on the Adaptation of Data Protection Provisions, Federal Law Gazette I No. 32/2018, requires the explicit consent of the data subjects to the processing of this data for marketing purposes of third parties.
7. Based on this, the Administrative Court’s assessment—namely, that the appellant’s legal position, according to which party affiliations, as statistical values, do not constitute personal data, even if they be attributed to specific individuals, constitutes gross negligence in failing to recognize a violation of the legality requirement under Article 5(1)(a), first case, of the GDPR in conjunction with the prohibition on processing special categories of personal data under para 9(1) of the GDPR, constitutes gross negligence, and should not be deemed unlawful. 121 Only slight negligence can be assumed, particularly in light of the existence of substantial resources available to the petitioner to examine the legal question of whether the party affiliations are personal data, which would have made it easy for the petitioner to conduct a detailed analysis of the aforementioned decisions by the Data Protection Authorities (see, in this regard, General Court, Dec.
12, 2012, T-332/9, Electrabel v. European Commission, para. 250). 8. at fail to demonstrate defects in the findings and reasoning of the contested decision (regarding the requirement to demonstrate relevance in the case of allegations of procedural defects, see VwGH Nov. 27, 2025, Ra 2023/04/0118, para. 14, with further references). 123 5. ) a) and b), insofar as the Administrative Court confirmed the Data Protection Authority’s penalty decision in its point I. concerning party affiliations, as specified in and identified the violated legal provisions, as unfounded. 1. ) a), insofar as it dismisses as unfounded the appeal against the Data Protection Authority’s penalty decision in its points V. , concerning the incorrectness and deficiencies of the VVZ, was confirmed subject to the conditions specified in detail, and b) the violated legal provisions were identified, the appeal is admissible and also well-founded.
2. Article 30(1) of the GDPR reads, in part: “Article 30 Record of processing activities (1) Each controller and, where applicable, its representative shall maintain a record of all processing activities under its responsibility. ] (3) The record referred to in paragraphs 1 and 2 shall be kept in writing, which may also be in electronic format. at (4) The controller or the processor, as well as, where applicable, the representative of the controller or the processor, shall make the record available to the supervisory authority upon request. ]” 126 Article 35 of the GDPR reads in part: “Article 35 Data protection impact assessment (1) Where a form of processing, in particular involving the use of new technologies, is likely to result in a high risk to the rights and freedoms of natural persons due to the Art, scope, context, and purposes of the processing, the controller shall carry out, in advance, an assessment of the impact of the intended processing operations on the protection of personal data.
For the assessment of several similar processing operations involving similarly high risks, a single assessment may be conducted. at rights and legitimate interests of the data subjects and other affected parties are taken into account. 3. The appellant argues that the DSFA and the VVZ were objectively accurate and complete, respectively, based on her legal opinion; furthermore, the unlawful nature of a violation of the appellant’s obligations as the controller is also exhausted by the violation of the requirement of lawfulness under Art. 5(1)(a), first case, of the GDPR in conjunction with the prohibition on the processing of special categories of personal data under Article 9(1) of the GDPR. 128 According to the findings of the Administrative Court, the appellant included the party affiliations in the appendix to the data usage “DAM Target Group Addresses” under “Target Group Addresses pursuant to § 151 GewO” and “Marketing classifications collected pursuant to § 151(6),” and assessed the risk in this context in the DPIA as “not a high risk”.
In its legal assessment, the Administrative Court concluded that there was a violation of Art. 35 para 3 lit. b in conjunction with Art. 35(7)(c) of the GDPR, because the appellant’s assessment in its DPIA—that there was no high risk with regard to party affiliations— was incorrect due to the processing of special categories of personal data. ),” even though it had processed party affiliations and thus personal data from which political opinion could be inferred. The VVZ is therefore objectively incorrect (inaccuracy of the VVZ). at identification data, contact data, marketing data, and personal master data” were being processed. Since the appellant had not provided the detailed specification of categories of data required under Art. ) a) with respect to point VI of the DPA’s penalty decision. 4. The record of processing activities to be maintained by the controller pursuant to Art. 30(1) GDPR is intended to enable proof that the controller processes personal data in accordance with the GDPR (see Recital 82).
Violations of Art. ] DS-GVO2 [2025], Art. 30, para. 8). 132 Pursuant to Art. 35(1) of the GDPR, the controller must conduct a DPIA if a form of processing—particularly when using new technologies—is likely, given the nature, scope, circumstances, and the purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons. The GDPR assumes that this is the case—among other things—particularly in the event of extensive processing of special categories of personal data pursuant to Article 9(1) of the GDPR (Article 35(3)(b) of the GDPR). ] GDPR2 [2025], Art. 35, para. 13). ] GDPR2 [2025], Art. 35, para. 104). 134 In its judgement of May 4, 2023, C-60/22, UZ v. Federal Republic Germany, para. 69, that a controller’s breach of the obligations under Articles 26 and 30 of the GDPR regarding the conclusion of an agreement establishing joint responsibility for the processing or the maintenance of a record of processing activities does not constitute unlawful processing that would entitle the data subject to the right to erasure or to restriction of processing, because such a breach does not, in and of itself, mean that the controller has violated the principle of “accountability” within the meaning of Article 5(2) in conjunction with Article 5(1)(a) and Article 6(1) first subparagraph of the GDPR.
135 A breach of the controller’s formal obligations therefore, according to the case law of the CJEU, has no impact in and of itself on the lawfulness of the processing. 01, p. 5, the competent supervisory authority may impose administrative fines if no data protection impact assessment is conducted even though one is required for the processing (Art. 35, paras. 1, 2, and 3) or if a DPIA is not properly conducted (Art. 35, paras. 2 and 7–9). 5. at other offense, if the specific circumstances of the incident indicate that the latter takes precedence (see, for example, VwGH June 23, 2021, Ra 2019/03/0020, 0021, para. 29; March 29, 2021, Ra 2020/02/0298, para. 16, each with further references). 138 The term “apparent concurrence” expresses the fact that, in reality, there is no concurrence of criminal provisions, but rather only a single provision under which punishment may be imposed. Cases of apparent concurrence include subsidiarity, specificity, and absorption (see VwGH March 29, 2021, Ra 2020/02/0298, para.
17, with further references). 139 Absorption occurs when a value-based interpretation of the formally (through a single act or multiple acts) reveals that by classifying the act(s) under one of the offenses, the total wrongfulness of the facts under review is already fully addressed by that single offense alone. The prerequisite is that the punishment for the single offense actually covers the entire degree of wrongfulness of the offender’s conduct (see again VwGH March 29, 2021, Ra 2020/02/0298, para. 18; June 25, 2020, Ra 2020/02/0046, 0047, para. 33, each with further references). 140 The existence of a “consumption” (and thus the inclusion of the unlawfulness of one offense within the penalty provision for another offense) is ruled out if the offenses are not typically related or if one offense is not necessarily—or at least not generally—linked to the other offense (see VwGH Nov. 10, 2025, Ra 2025/02/0182, para.
27, with further references). 2026, Case No. 2024/02/0154, para. 12, with further references). 6. In the context of an appeal, the following conclusions arise: 142 Art. 35(1) in conjunction with (3) of the GDPR requires an assessment of the interference caused by the data processing and the potential risks to the protection of the fundamental rights and freedoms of the data subjects. According to Article 35 of the GDPR, this refers to forms of processing that result in a high risk to the rights and freedoms of natural persons. at . A DPIA is required under para 3(b) of Article 35 of the GDPR in the case of extensive processing of special categories of personal data data pursuant to Article 9(1) of the GDPR. 143 The incorrect legal assessment that party affiliations do not constitute personal data and thus do not fall under special categories of personal data under Article 9(1) of the GDPR , led, in the appeal proceedings, to the appellant denying that the processing of party affiliations constituted special categories of personal data in the DPIA and failing to assume the existence of a high risk associated with the processing of this type of data.
The distinct nature of the unlawful act—distinct from a resulting violation of the requirement of lawfulness under Article 5(1)(a), first case, of the GDPR in conjunction with the prohibition on processing special categories of personal data under Article 9(1) of the GDPR, the incorrect classification of party affiliations in relation to the conduct of the DPIA pursuant to Article 35(1) of the GDPR cannot be inferred from the contested decision. 144 Nor does a separate element of wrongdoing arise from the requirement to conduct the DPIA “in advance” pursuant to Article 35(1) of the GDPR. The incorrect assessment of party affiliations as non-personal data and thus also not as special categories of data under Article 9 (1) of the GDPR led the appellant to assume that this type of data did not pose a high risk and to conclude that the scope of application of Art. 35 (3)(a) of the GDPR did not apply.
Insofar as the Administrative Court accuses the appellant of a violation of Article 35(1) in conjunction with paragraph 3 of the GDPR based on the denial of the processing of special categories of personal data, the gravity of this violation by the appellant is superseded by the violation of the requirement of lawfulness under Article 5(1)(a), first case, of the GDPR in conjunction with the prohibition on the processing of special categories of personal data under Article 9(1) of the GDPR. 7. Insofar as the Administrative Court accuses the appellant of a violation of Article 30(1)(a) of the GDPR based on the denial of the processing of special categories of data, the following applies with regard to the allegation that the DPIA was flawed: The incorrect legal assessment that party affiliations do not constitute personal data and thus do not fall under special categories of personal data pursuant to Article 9(1) of the GDPR—and consequently the violation of the principles of processing under Article 5(1)(a) in conjunction with Article 9 (1) of the GDPR, resulted in the party affiliations not being included in the VVZ as separate categories of personal data .
No separate element of wrongdoing can be inferred from the incorrect classification of party affiliations with regard to compliance with the documentation requirement under Article 30(1) of the GDPR. ) a) of the contested decision. , regarding the defectiveness of the DSFA, and in its point V. regarding the defectiveness of the VVZ, and in its ruling point VI. concerning the inadequacy of the VVZ, must be set aside due to the unlawfulness of its content, and the relevant administrative penalty proceedings in accordance with § 42(4) VwGG pursuant to § 45 (1)(2) VStG. 1. Finally, the appeal challenges the determination of the penalty by the Administrative Court. 149 Pursuant to Art. 2025, Ra 2025/04/0089, para. at Precedence of Union law over the principle of cumulation set forth in § 22 VStG Administrative Court of Appeal, April 30, 2025, Ro 2021/04/0024, para. 35, with further references), the total amount of which may not exceed the amount for the most serious violation.
150 The Administrative Court took into account the violations of Art. 35 GDPR regarding the inadequacy of the DPIA and of Art. 30(1)(c) GDPR with respect to the defects in the VVZ and the inadequacy of the VVZ in its determination of the penalty. 151 The Administrative Court’s determination of the penalty is unlawful, particularly in light of the dismissal of the proceedings regarding points A), V), and a) of the contested decision, insofar as it dismissed as unfounded the complaint concerning the penalty decision of the Data Protection Authority in its points IV, V, and VI, to be unfounded, is unlawful. 152 Points A) III) and A) IV), by which the Administrative Court reduced the administrative fine to €16,000,000 and the costs of the proceedings to €1,600,000, are, for this reason alone, tainted by the unlawfulness of their content. 2. Pursuant to § 42(4) VwGG, the Administrative Court of Appeal may decide the matter itself if it is ready for a decision and if making the decision itself is in the interest of simplicity, expediency, and cost savings.
This is the case here. 154 Pursuant to Article 83(1) of the GDPR, each supervisory authority shall ensure that the imposition of administrative fines pursuant to this article for violations of the GDPR in accordance with para 4 through 6 of that article is, in each individual case, effective, proportionate, and dissuasive (see CJEU, Feb. 13, 2025, C-383/23, ILVA v. AS, paras. at can fulfill the three requirements set forth in Article 83(1) of the GDPR to be both effective and proportionate as well as deterrent (see again CJEU, February 13, 2025, C-383/23, ILVA v. AS, para. 29 with reference to CJEU Dec. 5, 2023, C-807/21, Deutsche Wohnen SE, para. 58). 156 The determination of the penalty is a discretionary decision that must be made taking into account the three requirements set forth in Article 83(1) of the GDPR , the criteria listed in Article 83(2) of the GDPR, as well as the criteria set forth in § 19 of the Administrative Offenses Act (VStG), and, in the case of within the meaning of Articles 101 and 102 TFEU, taking into account their size.
1. With regard to the determination of the penalty, the appellant first argues that the data protection compliance system it established at considerable expense should be taken into account as a mitigating factor under Article 83(2)(d) of the GDPR. 158 Under Article 83(2)(d) of the GDPR, when determining the penalty, the degree of responsibility of the controller must be taken into account, with due regard to the technical and organizational measures implemented in accordance with Articles 25 and 32. Article 25 of the GDPR sets forth requirements for the technical and organizational measures to be taken by the controller, such as pseudonymisation. Article 32 of the GDPR refers to the security of processing through technical and organizational measures. 159 In its arguments regarding the establishment of a data protection compliance system, the appellant does not demonstrate that it has taken measures pursuant to Articles 25 and 32 of the GDPR with respect to the processed personal data.
To the extent that the appellant identifies identifies deficiencies in the findings of the contested decision, it does not demonstrate that, in the proceedings before the Administrative Court, it presented specific measures pursuant to Articles 32 and 25 of the GDPR in sufficient detail to warrant their consideration. at of the data regarding party affiliations is not evident with the required clarity . 160 However, the appellant must be agreed with in that the Administrative Court failed to sufficiently highlight the measures taken by the appellant to prevent a violation of the legality requirement under Art. 5 (1)(a), first case, of the GDPR in conjunction with the prohibition on processing special categories of personal data under Art. 9(1) of the GDPR regarding party affiliations when determining the degree of responsibility of the appellant. 161 According to the findings of the Administrative Court, the appellant reviewed the lawfulness of the processing of party affiliations within the framework of the data protection structure it had established—which consisted of the data protection manager and the data protection officer—with the involvement of the relevant departmental units.
As a result, the appellant incorrectly assessed the personal nature of the party affiliations and, on that basis, did not further examine whether they constituted special categories of personal data under Art. 9 GDPR. 4. above), this circumstance must nevertheless be taken into account in favor of the appellant when determining the degree of responsibility of the controller under Article 83(2)(d) of the GDPR in the assessing the administrative fine in favor of the appellant. 2. The appeal further argues, in connection with the determination of the penalty, that that, although the Administrative Court had found that there were no prior violations by the appellant to be taken into account, it did not consider the appellant’s clean record as a mitigating factor. 163 Pursuant to Art. 83(2)(e) of the GDPR, any prior violations by the controller must be taken into account when making the decision on the amount of the administrative fine.
According to the EDPB Guidelines 04/2022, para. 94, the existence of prior infringements may be regarded as an aggravating factor in the calculation of the administrative fine. at this cannot, however, be regarded as a mitigating circumstance, because compliance with the GDPR is the rule. 164 Contrary to the arguments presented in the appeal, the Administrative Court considered the absence of prior violations by the appellant as the absence of the aggravating factor of a “relevant prior conviction” in the contested decision. According to the wording of Art. 83 (2)(e) of the GDPR, which relies on the existence of prior violations as a criterion for determining the administrative fine, as well as according to the statements in the EDPB Guidelines, it was not required to take into account the the absence of prior violations of the GDPR by the appellant as a mitigating circumstance was not warranted.
3. The appellant further objects to the Administrative Court’s consideration of special preventive grounds. 166 166 Although the appellant was prohibited from processing the data category “political affiliations” for the purposes of address trading and direct marketing without the consent of the data subjects by the Administrative Court’s ruling of November 26, 2020, and the appeal filed against this ruling was dismissed as unfounded by the Administrative Court of Appeal in its decision of December 14, 2021, Ro 2021/04/0007. However, contrary to the appellant’s arguments, this does not mean that special preventive considerations regarding the appellant’s activities in the field of address publishing and direct marketing can be entirely disregarded. In determining the penalty, the Administrative Court already took into account, in the context of special preventive considerations and to the appellant’s advantage, that the appellant had issued cease-and-desist declarations to numerous affected parties, thereby making it more difficult to resume operations in this business sector.
4. at assessment criterion for determining the administrative fine. This is particularly warranted because the activity as an address publisher is not a core activity of the appellant. 168 It must be countered that Art. 83(4) and (5) of the GDPR each base the calculation of the administrative fine on the total worldwide annual turnover achieved in the preceding fiscal year. Nor do the EDPB Guidelines 04/2022, para. , provide any points of reference comparable to those set forth in the guidelines cited by the appellant regarding the procedure for setting administrative fines imposed by the European Commission (OJ C 210, Sept. 1, 2006, pp. 2–5) that would support taking the turnover related to the offense into account. 169 The group-wide revenue of the appellant for the fiscal years 2018 and 2023, as determined by the Administrative Court in its overall assessment to establish the amount of the administrative fine, is not otherwise contested by the appellant.
5. The Administrative Court classified the processing of party affiliations as a violation of high severity. Insofar as the appeal challenges this assessment, it must be countered that this violation is already to be regarded as serious pursuant to Art. 9(1) GDPR simply by virtue of the intensity of its interference with respect to the special categories of personal data concerned. In determining the penalty, the Administrative Court also took into account, in favor of the appellant, the smaller number of data subjects compared to the penalty decision issued by the authority in question. 4. According to the case law of the ECtHR and the Constitutional Court, the proceedings before the Administrative Court must also be included in the duration of the proceedings to be assessed (see VwGH 4/30/2025, Ro 2021/04/0024, para. 39, with further references). The duration of a preliminary ruling proceeding before the CJEU is not included in the time limit (see ECtHR (Grand Chamber) June 27, 2017, Satakunnan Markkinapörssi Oy and Satamedia Oy v.
Finland, 931/13, para. 208, with further references). at 172 Based on media reports, the respondent authority initiated an ex officio investigation against the appellant on January 8, 2019. With a request for justification dated February 20, 2019, the respondent authority initiated administrative penalty proceedings regarding the alleged violations of the GDPR attributed to the appellant. The penalty order issued against the appellant is dated October 23, 2019. By decision of November 26, 2020, the Administrative Court upheld the appellant’s complaint against the penalty decision, set aside the penalty decision, and dismissed the proceedings. 173 By order of February 24, 2022, Ra 2020/04/0187-11, the Administrative Court of Appeal stayed the appeal proceedings pending against the judgment of the Administrative Court of November 26, 2020, pending a a preliminary decision by the Court of Justice of the European Union (CJEU) in Case C-807/21.
In its judgement of December 5, 2023, C-807/21, Deutsche Wohnen SE, the CJEU took a decision on the request for a preliminary ruling from the Berlin Kammergericht. 174 By decision of the Administrative Court dated February 1, 2024, Ra 2020/04/0187-20, the Administrative Court set aside the decision of the Administrative Court dated November 26, 2020, on the grounds that its content was unlawful. The Administrative Court’s decision now being challenged is dated December 27, 2024. 175 The period during which the appeal proceedings before the Administrative Court of Appeal against the decision of November 26, 2020, regarding the request for a preliminary ruling in the Deutsche Wohnen SE case were suspended is, according to the case law of the European Court of Human Rights, not to be total duration of the proceedings. 176 The duration of the proceedings, calculated from the initiation of the administrative penalty proceedings on February 20, 2019, to the present day, is 88 months.
at 6 months). The Administrative Court had already assumed a duration of proceedings of five years (see decision, p. 84) and factored this into the sentencing in favor of the appellant in determining the penalty. The additional 6 months must be taken into account by the Administrative Court as a mitigating factor for the unreasonably long duration of the proceedings when determining the penalty. 5. Taking into account the reversal of three points of the penalty decision issued by the responding authority and the dismissal of the proceedings regarding these violations in the appeal proceedings, as well as those aspects which, in light of the foregoing, must be taken into account in favor of the appellant in favor of the appellant (measures taken by the appellant, duration of proceedings), the administrative fine is to be reduced, upon an overall assessment, to €13,000,000 (thirteen million).
6. The appellant also challenges the imposition of a contribution toward the costs of the first-instance penalty proceedings pursuant to para 64 (2) VStG in the amount of 10% of the penalty imposed. In light of the judgement of the CJEU of October 14, 2021, MT, C-231/20, this is excessive and results in an additional penalty. , regarding procedural costs, CJEU Oct. 14, 2021, MT, C-231/20, paras. 56 and 57; VwGH April 26, 2022, Ra 2021/08/0006, para. 44; December 10, 2021, Ra 2020/17/0013, para. 47). at 180 If, in an individual case, there are extraordinary circumstances that were not sufficiently taken into account by the legislature when establishing the statutory penalty range or setting the standard for the contribution toward procedural costs, and where even the application of § 20 VStG does not sufficient remedy, it must be ensured when applying the legal basis for imposing fines and substitute custodial sentences under the GSpG that the fine imposed in each case and the total amount of the fines imposed is not disproportionate to the economic benefit that could be derived from the penalized acts, and that the duration of the substitute custodial sentences actually imposed corresponds to the severity of the offenses, and that the contribution to the costs of the administrative penalty proceedings is not excessive (see VwGH Dec.
10, 2021, Ra 2020/17/0013, para. 50). 181 Such “exceptional circumstances” exist in the present appeal case with respect to the contribution to the costs of the first-instance proceedings to be imposed pursuant to para 64(1) and (2) VStG: 182 Article 83(4) through (6) of the GDPR provide for maximum amounts for administrative fines to be imposed on enterprises pursuant to these provisions, based on a percentage of the enterprise’s total worldwide annual turnover for the preceding fiscal year. In the case of violations of Article 83(4) through (6) of the GDPR, exceptionally high administrative fines may thus be imposed in administrative penalty proceedings. However, Section 64(2) of the VStG does not specify a maximum limit for the imposition of procedural costs for criminal proceedings at first instance. 183 Against this background, a contribution to the costs of the proceedings amounting to 10% of the imposed administrative fine of €13,000,000 is, in the this appeal case to be excessive and thus disproportionate.
The contribution to the costs of the criminal proceedings was therefore, disregarding § 64 (2), first para, of the VStG, set by the Administrative Court pursuant to § 64 (1) VStG. at 184 8. Since the present questions of Union law have already been clarified by the above-cited, established case law of the CJEU, a referral to the CJEU pursuant to Art. 267 TFEU was not necessary. A request for a preliminary ruling by the CJEU on the legal issues raised in the appeal proceedings was not made by the Administrative Court during the appeal proceedings. 185 9. The conduct of the requested oral hearing could be waived pursuant to § 39(2)(6) VwGG because the Administrative Court, a tribunal within the meaning of the ECHR or a Court within the meaning of Art. 2026, Ro 2024/04/0029, para. 63). 186 10. Pursuant to § 42(4) VwGG, the ruling in the decision subject to appeal was therefore to be amended accordingly. 187 11. The decision regarding reimbursement of expenses is based on §§ 47 et seq. VwGG in conjunction with the VwGH Reimbursement of Expenses Ordinance 2014. Vienna, June 24, 2026