Skip to content
Enforcement · DSB (Austria) ·D130.2269 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Austrian DSB: e-marketplace transfer of customer data to China and US requires valid Art.

The DPA was acting upon a complaint addressing the subject matter of third country personal data transfers.

Original title: DSB (Austria) - D130.2269

Holding

The DPA held that the complaint at hand cannot be considered an abusive exercise of rights and was legally admissible. The question arose because the DPA considered the complaint as part of a campaign against processing of transfers of personal data to the People’s Republic of China. This is because the data subject was represented by a data protection organisation that has already filed several complaints on that subject matter in the past. Additionally, the data subject has initiated the transfer of personal data to the People’s Republic of China right before the procedure before the DPA by ordering from the controller’s platform. Yet, the DPA held that the data subject based his complaint overwhelmingly on motives relating to the exercise of his individual rights. Despite doubts concerning the incompetence of the Irish DPA, the Austrian DPA declared itself competent for handling the complaint in order to ensure the data subject’s right to an effective remedy as provided for under Article 13 of the European Convention on Human Rights, Article 47 of the Charter of Fundamental Rights of the European Union in conjunction with Article 77 GDPR. As far as the transfer of personal data to a third country is concerned, the DPA held that the transfer of personal data to the two US companies was lawful under the adequacy decision. The two companies were listed in the “Data Privacy Framework List”. As far as the transfer of data to the People’s Republic of China was concerned, for lack of an adequacy decision, the controller based the transfers of personal data on standard data protection clauses pursuant to Article 46(2)(c) GDPR. When relying on standard data protection clauses, the controller must ensure an adequate level of protection of personal data for the processing of personal data in the third country. In this context, the controller cannot solely rely on the contractual relationship and the standard data protection clauses between the data importer and data exporter. The controller has to consider the access of public authorities to personal data as well. The DPA held that the controller was unable to demonstrate an adequate protection of personal data for the transfer to the People’s Republic of China. The controller only referred to the standard data protection clauses and an overview of technical and organisational measures (TOMs). The TOMs did not deal with the issue of access of public authorities. Moreover, the controller failed to provide precise information as to the question of who has control over decryption of personal data. The TOMs merely require the data importer to apply the “commercially available industry standard”. The DPA held that this reference is not precise enough to demonstrate what standard is meant by this wording and if adequate security is ensured. However, the DPA held that Article 49(1)(b) GDPR is applicable in this case. Under Article 49 GDPR, third country data transfers are allowed, in the absence of an adequacy decision or appropriate safeguards pursuant to Article 46 GDPR, only if one of the conditions in Article 49(1) GDPR is fulfilled. According to the DPA, the transfer of personal data to the People’s Republic of China was necessary for the implementation of pre-contractual measures taken at the data subject’s request pursuant to Article 49(1)(b) GDPR. The controller has to transfer the personal data of the data subject to the independent vendor located in a third country in order to fulfil his contractual obligation in the case of a purchase by the data subject. The data subject conducted the purchase on the controller’s platform voluntarily and on his own initiative. According to the DPA, Recital 111 does not prevent the application of Article 49 GDPR in this case. The DPA held that the word “occasional” in Recital 111is to be understood as including “in case of a purchase”. The transfer of personal data occurred only once and not even repeatedly or regularly. The DPA held that the data subject’s request to suspend all data flows of European users lays outside of the subject matter of the case. Moreover, in order for the DPA to impose a suspension, each individual data flow to the third country must be unlawful, which the DPA did not assume at the time being. The DPA rejected the complaint.

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Summary

The controller, established in Ireland, operates an e-marketplace platform within the Union that connects costumers with independent vendors mostly located in Asia. The use of the controller’s platform requires potential costumers to create an account with the platform. When a customer orders a product via the platform, the controller establishes the contact between the costumer and the vendor. The parties of the purchase contract, however, are the customer and the vendor, not the controller. The processing of personal data in the context of providing the controller’s platform takes place within the Union and in the United Kingdom. In case of an order, the personal data is transferred to the vendors registered on the platform who offer the requested product. A customer (data subject) created an account with the controller’s platform in 2024. He logged into his account on the platform another time in 2024 and once in 2026, shortly after the procedure before the DPA was concluded. During his log-in in 2026, the data subject placed an order via the controller’s platform. In the course of the order, the data subject’s personal data was transferred to the People’s Republic of China and to two companies within the US. The European Commission has issued an adequacy decision pursuant to Article 45 GDPR concerning data transfers to the US (so-called “Data Privacy Framework”). Both US companies are featured on the “Data Privacy Framework List”. There is no adequacy decision concerning data transfers to the People’s Republic of China. The Irish DPA has declared itself not competent for the procedure at hand.

Full text 36 findings

Machine translation of the decision, via GDPRhub — not the official text. Read the original

Paragraphs carrying a topic or an applied provision show those connections inline
§

Text Ref. No.: 2026-0.617.893 dated July 31, 2026 (Case No.: D130.2269) [Processing Agent’s Note: Names and company names, legal forms and product names, addresses (including URLs, IP addresses, and email addresses), file numbers (and similar), statistical data, etc., as well as their initials and abbreviations, may have been abbreviated and/or altered for pseudonymization purposes. Obvious spelling, grammar, and punctuation errors have been corrected.] DECISION RULING The Data Protection Authority rules on the data protection complaint filed by Bruno A*** (complainant), with the M*** Data Protection Association acting as its representative, on January 16, January 2025 against N*** Technology Limited (respondent) regarding a violation of Chapter V of the GDPR resulting from the transfer of personal data to recipients in the United States of America and the People’s Republic of China as follows:The Data Protection Authority makes a decision on the data protection complaint filed by Bruno A*** (complainant), represented by the M*** Data Protection Association, on January 16, January 2025 against N*** Technology Limited (respondent) regarding a violation of Chapter V of the GDPR resulting from the transfer of personal data to recipients in the United States of America and the People’s Republic of China as follows: - The complaint is dismissed as unfounded.

§

Legal basis: Art. 1, Art. 45, Art. 46, Art. 49(1)(b), Art. 51(1), Art. 57(1)(f), and Art. 77(1) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR), OJ No. L 119 of May 4, 2016, p. 1; Sections 18(1) and 24(1) and (5) of the Data Protection Act (DSG), Federal Law Gazette I No. 165/1999, as amended, Commission Implementing Decision (EU) 2023/1795 of July 10, 2023, on the adequacy of the level of protection for personal data under the EU-US Data Privacy Framework: Article 1, Article 45, Article 46, Article 49(1)(b), Article 51(1), Article 57(1)(f), and Article 77(1) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR), Official Journal No. L 119 of May 4, 2016, page 1; Paragraphs 18(1), 24(1), and 24(5) of the Data Protection Act (DSG), Federal Law Gazette, Part I, No. 165 of 1999, as amended, Commission Implementing Decision (EU) 2023/1795 of July 10, 2023, on the adequacy of the level of protection for personal data under the EU-U.S.

§

Data Privacy Framework STATEMENT OF REASONS I. Subject Matter of the Complaint Based on the arguments presented by the complainant (hereinafter: BF), the subject matter of the complaint is whether the respondent (hereinafter: “Respondent”) has infringed upon the Complainant’s rights under Chapter V of the GDPR by conducting transfers of personal data to the United States and the People’s Republic of China. Based on the arguments presented by the complainant (hereinafter: CP), the subject matter of the complaint is whether the respondent (hereinafter: R) violated the CP’s rights under Chapter Roman five of the GDPR by conducting transfers of personal data to the United States and the People’s Republic of China. II. Findings of Fact 1. The respondent is headquartered in Ireland and operates the “X***TRADE” platform within the European Economic Area. The platform functions as an e-commerce marketplace that connects consumers with merchants and product suppliers (primarily from Asia).

§

To use the platform, consumers must create an account on BG’s platform and accept the applicable terms of use. The contract for the purchase of individual products, however, is concluded with the respective seller who offers their products on the “X***TRADE” platform. 2. On August 19, 2024, BF created an account on BG’s platform. Another login is recorded for November 25, 2024. 3. BG performs processing of the following data pertaining to BF: email address, username and password, name, phone number, shipping address, information about page views, order data, information about the devices BF used to visit the BG website (e.g., operating system, Android ID, device brand, etc.), information about service emails (e.g., password reset code, updated terms of use), account and profile information, information about cookies set and their values, as well as information about data recipients. The processing of data subjects’ personal data for the purpose of providing the platform’s services generally takes place in the European Union and the United Kingdom.

§

In the case of orders, however, personal data is transferred to the sellers of the ordered products who are registered on the platform in order to fulfill the order or arrange delivery. 4. Apart from the logins described in Section II.2, BF accessed BG’s website only once more shortly before the conclusion of the present proceedings on July 14, 2026, to place an order. 4. Apart from the logins described in Roman numeral two.2., BF accessed BG’s website only once more, shortly before the conclusion of the proceedings in question on July 14, 2026, to place an order. 5. BF’s personal data was transferred to the following third countries: the United States and the People’s Republic of China. In the case of the United States, there is an adequacy decision by the Commission pursuant to Art. 45 GDPR (Data Privacy Framework). The recipients in the United States were K***search LLC and U*** Inc. Both enterprises appear on the so-called “Data Privacy Framework List.”

§

For the People’s Republic of China, there is no adequacy decision pursuant to Article 45 of the GDPR. 5. The personal data of BF was transferred to the following third countries: the United States and the People’s Republic of China. In the case of the United States, there is an adequacy decision by the Commission pursuant to Article 45 of the GDPR (Data Privacy Framework). The recipients in the United States were K***search LLC and U*** Inc. Both enterprises appear on the so-called “Data Privacy Framework List.” For the People’s Republic of China, there is no adequacy decision pursuant to article 45 of the GDPR. [Editor’s note: The search result reproduced here in the original as a screenshot (graphic file), which included the names of several enterprises, could not be pseudonymized with reasonable effort and has therefore been removed.] Fig. Screenshot of the ex officio query of the Data Privacy Framework List by the Data Protection Authority on July 27, 2026 (https://www.dataprivacyframework.gov/list) 6.

§

At the time of the conclusion of the proceedings in question, the Irish Data Protection Authority (DPC) expressly denied its jurisdiction as the lead supervisory authority for handling the complaint against BG. Assessment of the evidence: The findings are based on the undisputed record, in particular the information provided by BG to BF in February 2025, as well as BG’s statements in the investigative proceedings following a request by the Data Protection Authority. All documentation is included in the case file and forms the basis for the Data Protection Authority’s decision-making. III. Roman numeral three. From a legal perspective, the following conclusions follow: 1. Regarding the subject matter of the complaint Both the Data Protection Authority and the Federal Administrative Court have consistently held in their case law that in cases based on a petition—such as, in particular, the complaint proceedings pursuant to Art. 77 GDPR in conjunction with § 24(1) DSG—the content of the petition (in this case: the complaint) constitutes and delimits the subject matter of the administrative proceedings (see, for example, the Federal Administrative Court’s decision of May 17, 2022, W214 2233132-1).Both the Data Protection Authority and the Federal Administrative Court have consistently held in their case law that in cases based on an application—such as, in particular, the complaint procedure pursuant to Article 77 of the GDPR in conjunction with paragraph 24(1) DSG—the content of the application (in this case: the complaint) constitutes and delimits the subject matter of the administrative proceedings (see, for example, the Federal Administrative Court’s decision of May 17, 2022, W214 2233132-1).

§

The complainant—represented by M***, an organization specializing in data protection issues—explicitly limited the subject matter of the complaint to an alleged violation of Chapter V of the GDPR and did not raise any further grounds for complaint. Although a further complaint regarding an alleged violation of the right of access under Art. 12 in conjunction with Art. 15 of the GDPR was announced, it has not yet been filed with the DPA.The BF—represented by M***, an organization specializing in data protection issues—explicitly limited the scope of its complaint to an alleged violation of Chapter V of the GDPR and did not raise any further grounds for complaint. Although another complaint regarding an alleged violation of the right of access under Article 12, in conjunction with Article 15, of the GDPR was announced, it has not yet been filed with the DPA. Consequently, the proceedings in question concerned exclusively an alleged violation of Chapter V of the GDPR by BG.

§

Consequently, the proceedings in question concerned exclusively an alleged violation of Chapter V of the GDPR by BG. 2. On the Jurisdiction of the Data Protection Authority Upon receipt of the complaint, the Data Protection Authority first initiated proceedings under Article 56 of the GDPR to determine the lead supervisory authority, since—given that BG’s headquarters are in Ireland—it could not be ruled out that the Irish supervisory authority (DPC) might have lead authority. Upon receipt of the complaint, the Data Protection Authority first initiated proceedings pursuant to Article 56, GDPR to determine the lead supervisory authority, since, given that BG’s headquarters are in Ireland, it could not be ruled out that the Irish supervisory authority (DPC) had lead jurisdiction. In a notification dated September 3, 2025, the DPC informed the Data Protection Authority that it did not consider itself the lead supervisory authority for the case in question.

§

As of the conclusion of the proceedings in question, no decision to the contrary had been communicated by the DPC to the DPA, although the BG had pointed out on several occasions that the DPC was in the process of reconsidering its position on this matter. In order to provide the complainant with an effective remedy within the meaning of Art. 13 of the ECHR and Art. 47 of the CFR in conjunction with Article 77 of the GDPR, and in the absence of a contrary decision by the DPC regarding the question of its potential lead authority, as well as taking into account the prohibition inherent in the GDPR against “forum shopping,” the DPA affirmed its jurisdiction within the meaning of Article 55(1) of the GDPR in the present case and conducted the proceedings outside the cooperation mechanism provided for in Article 60 of the GDPR.By notice dated September 3, 2025, the DPC informed the Data Protection Authority that it did not consider itself the lead supervisory authority for the case in question.

§

Until the conclusion of the proceedings in question, no decision to the contrary had been communicated to the DPA by the DPC, although the BG had pointed out on several occasions that the DPC was in the process of reconsidering its position on this matter. In order to provide the complainant with an effective remedy within the meaning of article 13 of the ECHR and article 47 of the CFR in conjunction with article 77 of GDPR, and in the absence of a decision to the contrary by the DPC regarding the question of its potential primary jurisdiction, as well as taking into account the prohibition inherent in the GDPR against “forum shopping,” the DPA has affirmed its jurisdiction in the present case within the meaning of Article 55(1) of the GDPR and conducted the proceedings outside the cooperation mechanism provided for in Article 60 of the GDPR. 3. On the Admissibility of Data Transfers to Third Countries in General Article 1 of the GDPR identifies the free flow of personal data within the Union as an essential objective of this Regulation and expressly states in para 3 that the free flow of data within the Union may not be restricted or prohibited on grounds of the protection of natural persons.Article 1 of the GDPR identifies the free flow of personal data within the Union as an essential objective of this Regulation and also expressly states in paragraph 3 that the free flow of data within the Union may not be restricted or prohibited on grounds of the protection of natural persons.

§

Recital 101 of the GDPR further states that the flow of personal data from and to third countries is necessary for the expansion of international trade and international cooperation. However, it is also expressly stated that the level of protection for personal data guaranteed throughout the Union must not be undermined by transfers to third countries. Thus, data transfers to third countries are permitted only in compliance with the conditions set forth in the GDPR. The conditions listed above are found in Chapter V of the GDPR, which comprehensively regulates the transfer of personal data to third countries or international organisations.The conditions listed above are set forth in Chapter V of the GDPR, which comprehensively regulates the transfer of personal data to third countries or international organisations. The regulations governing international data transfers are based on the European legislator’s assumption that the level of data protection outside the EU or the EEA is lower than within the Union, which is why, to ensure adequate protection of fundamental rights, sufficient safeguards must be provided as soon as personal data leaves the territory of the EEA.

§

These safeguards are listed in Articles 45–49 of the GDPR and form a hierarchical relationship with one another. It follows that a data transfer to a third country should primarily be legitimized by an adequacy decision (Article 45 of the GDPR). If no such decision exists for the third country in question, the safeguards of Article 46 of the GDPR may be relied upon. Finally, Article 49 of the GDPR provides, as a last resort, for exceptions under which personal data may be transferred to third countries even without the safeguards of Article 46 of the GDPR (Jahnel, Commentary on the General Data Protection Regulation, Art. 44 GDPR, Marginal Note 2 (as of Dec. 1, 2020, rdb.at).The provisions governing international data transfers are based on the European legislator’s assumption that the level of data protection outside the EU or the EEA is lower than within the Union, which is why, to ensure adequate protection of fundamental rights, sufficient safeguards must be provided as soon as personal data leaves the territory of the EEA.

§

These safeguards are listed in articles 45–49 of the GDPR and form a hierarchical relationship with one another. It follows that a data transfer to a third country should primarily be legitimized by an adequacy decision (Article 45 of the GDPR). If no such decision exists for the third country in question, the safeguards of Article 46 of the GDPR may be invoked. Finally, Article 49 of the GDPR provides, as a last resort, for exceptions under which personal data may be transferred to third countries even without the safeguards of Article 46 of the GDPR (Jahnel, Commentary on the General Data Protection Regulation, Article 44, GDPR, Marginal Note 2 (as of Dec. 1, 2020, rdb.at). Consequently, it must be examined below whether the transfer of the BF’s personal data to the recipient countries (the United States and the People’s Republic of China) can be based either on an adequacy decision, on appropriate safeguards, or on exceptions for specific cases. 4.1.

§

Regarding the Transfer of the BF’s Personal Data to the U.S. As noted in Section II.5, the BF’s personal data was transferred to the U.S. The recipients were K***search LLC and U*** Inc., as operators of the “P***grid” service. As noted in Roman numeral II.5, BF’s personal data was transferred to the United States. The recipients were K***search LLC and U*** Inc., the operator of the “P***grid” service. Pursuant to Article 45(3) of the GDPR, the Commission may, by means of an implementing act, decide that a third country provides an adequate level of protection for personal data. By Implementing Decision (EU) 2023/1795 of July 10, 2023, the Commission certified that the United States provides such an adequate level of protection.Pursuant to article 45(3) of the GDPR, the Commission may, by means of an implementing act, decide that a third country provides an adequate level of protection for personal data.

§

By Implementing Decision (EU) 2023/1795 of July 10, 2023, the Commission certified that the United States provides such an adequate level of protection. However, it should be noted that this adequacy decision applies only partially and covers only those data importers that appear on the so-called “Data Privacy Framework List.” As also noted in Section II.5, both data recipients appear on the aforementioned “Data Privacy Framework List,” which is why they fall within the scope of the adequacy decision.As also noted in section II.5, both data recipients appear on the aforementioned “Data Privacy Framework List,” which is why they fall within the scope of the adequacy decision. Furthermore, it was established that BF opened its account with BG on August 19, 2024, and thus, without a doubt, only after the aforementioned adequacy decision had been issued, from which it follows that the associated transfer of its data to the recipients in the United States was also covered by the adequacy decision for the United States in terms of timing, and no other indications have emerged that would specifically suggest the inapplicability of the adequacy decision, wherefore the complaint on this point was to be dismissed as ruled.

§

In addition, it should be noted that an adequacy decision by the European Commission—insofar as it determines that the third country in question ensures an adequate level of protection and, as a result, authorizes the transfer of personal data—is binding on all Member States pursuant to Art. Para 288(4) TFEU—and is therefore also binding on all their institutions. As long as the adequacy decision has not been declared invalid by the Court of Justice of the European Union, the data protection supervisory authorities may not take any measures contrary to this decision (such as legal acts that bindingly determine that the third country to which the decision relates does not ensure an adequate level of protection), although this neither removes nor limits the powers granted to the data protection supervisory authorities, and they may, in complete independence, assess whether the requirements set forth in the GDPR are met during transfers of personal data (see CJEU, July 16, 2020, C‑311/18, paras. 117 et seq.).In addition, it should be noted that an adequacy decision by the European Commission—insofar as it finds that the third country in question ensures an adequate level of protection and consequently authorizes the transfer of personal data—is binding on all Member States pursuant to article 288, paragraph 4, of the TFEU in its entirety and is therefore also binding on all their institutions.

§

As long as the adequacy decision has not been declared invalid by the Court of Justice of the European Union, the data protection supervisory authorities may not take any measures contrary to this decision (such as legal acts that bindingly determine that the third country to which the decision relates does not ensure an adequate level of protection), although this neither removes nor limits the powers granted to the data protection supervisory authorities, and they may, with complete independence, assess whether the requirements set forth in the GDPR are met during transfers of personal data (see CJEU, July 16, 2020, C‑311/18, paras. 117 et seq.). 4.2. Regarding the Transfer of BF’s Personal Data to the People’s Republic of China 4.2.1 On the (Preliminary) Issue of Dismissing the Complaint on the Grounds of Abuse of Rights The complaint in question was part of a larger wave of complaints filed by the BF’s representation throughout Europe against Chinese enterprises or against enterprises believed to be transferring personal data to China (see: https://m***.at/***/de/***-surrender-europeans-data-authoritarian-china, accessed on July 28, 2026).

§

The campaign’s intent can thus be assumed to be to take action against such enterprises or, more generally, against the practice of transferring personal data to the People’s Republic of China.The complaint in question was part of a larger wave of complaints filed by the BF representation throughout Europe against Chinese enterprises or against enterprises believed to be transferring personal data to China; see: https://m***.at/***/de/***-surrender-europeans-data-authoritarian-china, accessed on July 28, 2026). The intent of the campaign can thus be assumed to be to take action against such enterprises or, more generally, against the practice of transferring personal data to the People’s Republic of China. Although such a motivation, on its own and in all cases, does not in itself indicate an abuse of legal rights in the complaint, it should nevertheless be noted, as stated in Section II.4, it must be noted that the complainant herself triggered the transfer of her data to the People’s Republic of China shortly before the conclusion of the proceedings in question by placing an order on the defendant’s platform shortly before the end of the proceedings, thereby creating a factual element favorable to her.Although such motivation, on its own and in all cases, does not in itself indicate an abuse of process in the complaint, it must nevertheless be noted, as stated in Roman numeral II.4, it must be noted that BF itself triggered the transfer of its data to the People’s Republic of China only shortly before the conclusion of the proceedings at issue by placing an order on BG’s platform shortly before the proceedings ended, thereby creating a factual element favorable to itself.

§

The Data Protection Authority was therefore required to examine whether, in this case, the complaint should have been dismissed on the grounds of irrelevant motives (see the decision of the Federal Administrative Court [BVwG] of September 3, 2025, W292 2248134-1). Although the case at hand exhibits some aspects of the “activism” described in the aforementioned ruling, which ultimately and rightly led to the Data Protection Authority’s refusal to consider the complaint, after weighing all arguments and evaluating the evidence, it could not be established that the complainant had filed his complaint predominantly or exclusively for irrelevant motives and thus in abuse of the law.The Data Protection Authority was therefore required to examine whether, in this instance, a decision to dismiss the complaint on the grounds of irrelevant motives should have been made (see the ruling of the Federal Administrative Court [BVwG] of September 3, 2025, W292 2248134-1).

§

Although the present case exhibits some aspects of the “activism” described in the aforementioned ruling, which ultimately and rightly led to the Data Protection Authority’s refusal to process the complaint, after weighing all the arguments and evaluating the evidence, it could not be established that the complainant had filed his complaint predominantly or exclusively for irrelevant motives and thus in abuse of the law. Consequently, the complaint was found to be barely admissible, which is why the Data Protection Authority was obligated to accept it for consideration and render a decision. 4.2.2. On the Lawfulness of the Transfer of the Complainant’s Personal Data to the People’s Republic of China Unlike in the case of the transfer to the United States described above, the situation regarding the transfer of the BF’s personal data to the People’s Republic of China must be assessed separately, since, as noted in Section II.5, there is no adequacy decision by the European Commission for that country.Unlike in the case of the transfer to the United States described above, the situation regarding the transfer of BF’s personal data to the People’s Republic of China must be assessed separately, since, as noted in Roman numeral II.5, there is no adequacy decision by the European Commission for that country.

§

BG primarily bases data transfers to the People’s Republic (as well as to other third countries) on SCCs within the meaning of Article 46(2)(c) of the GDPR and thus on appropriate safeguards (see Section III.3 above).The BG primarily bases the data transfer to the People’s Republic (as well as to other third countries) on SCCs within the meaning of article 46(2)(c) of the GDPR and thus on appropriate safeguards (see Roman numeral III.3 above). However, according to the case law of the CJEU, the appropriate safeguards must be such that they ensure a level of protection for individuals whose personal data is transferred to a third country on the basis of standard data protection clauses that is, in substance, equivalent to the level of protection guaranteed in the Union (see CJEU, July 16, 2020, C-311/18, para. 96). The Court further stated that a controller who bases its data transfer to a third country on SCCs within the meaning of Article 46(2)(c) of the GDPR must, when assessing whether an adequate level of protection exists in the third country, must take into account not only the contractual arrangements between the data importer and the data exporter, but also the possibility of access to personal data by public authorities and, more generally, the relevant elements of that country’s legal system (ibid., para. 105).However, according to the case law of the CJEU, the appropriate safeguards must be such that they ensure, for individuals whose personal data is transferred to a third country on the basis of standard data protection clauses, a level of protection that is essentially equivalent to that guaranteed in the Union (see CJEU, July 16, 2020, C-311/18, para. 96).

§

The Court further stated that a controller who bases its data transfer to a third country on SCCs within the meaning of Article 46(2)(c) of the GDPR must, when assessing whether an adequate level of protection exists in the third country, must take into account not only the contractual arrangements between the data importer and the data exporter, but also the possibility of access by public authorities to personal data as well as, more generally, the relevant elements of that country’s legal system (ibid., para. 105). In its brief initiating the proceedings, the BF was able to demonstrate in a coherent and comprehensible manner that, in the case of the People’s Republic of China, there must be serious doubts as to whether an adequate level of protection exists in that country when applying the standard set forth above. In contrast, despite having multiple opportunities to comment on this matter, the BG merely referred to the aforementioned SCCs and provided a brief overview of the technical and organizational measures (TOMs), which, however, do not establish a level of security exceeding what would be expected in any case.

§

The issue of access by public authorities—or how to proceed in the event of unauthorized requests from public authorities—is not addressed in the TOMs, nor are there more specific provisions regarding encryption or so-called “key management” (i.e., who has control over the decryption of data). The data importer is merely required to apply a commercially available industry standard that is not further defined (Note: Translation by the DPA, English original: “commercially available industry standard”), although this imprecise description makes it virtually impossible to determine which standards are (or must be) applied and how secure they are.In its brief initiating the proceedings, the BF was able to demonstrate conclusively and comprehensibly that, in the case of the People’s Republic of China, there must be serious doubts as to whether an adequate level of protection exists in that country when applying the standard outlined above.

§

In contrast, despite having multiple opportunities to comment on this matter, the BG merely referred to the aforementioned SCCs and submitted a brief overview of the technical and organizational measures (TOMs), which, however, do not establish a level of security exceeding what would be expected in any case. The issue of access by public authorities—or how to proceed in the event of unauthorized requests from public authorities—is not addressed in the TOMs, nor are there more specific provisions regarding encryption or so-called “key management” (i.e., who has control over the decryption of data). The data importer is merely required to apply a commercially available industry standard—Note: Translation by the DPA, (English original: “commercially available industry standard”), although due to this imprecise description, it is virtually impossible to determine which standards are (or must be) applied and how secure they are.

§

In light of the above remarks, it is therefore highly doubtful whether, in the case of the data transfer at issue, justification based on SCCs under Art. 46(2)(c) is possible, as it is questionable whether this alone can ensure an adequate level of protection in the recipient country.In light of the above, it is therefore highly doubtful whether, in the case of the data transfer at issue in these proceedings, justification is possible by means of SCCs under article 46(2)(c), paragraph 2, since it is questionable whether this alone can ensure an adequate level of protection in the recipient country. However, this does not necessarily mean that a decision must be made on granting the complaint in the present proceedings, since, as explained in Section III.3, the Federal Court still has the option of applying exceptions in certain cases pursuant to Art. 9 of the GDPR [Editor’s note: obvious editorial error; presumably Article 49 of the GDPR is intended.]However, this does not necessarily mean that a decision must be made on upholding the complaint in the present proceedings, since, as explained in section Roman numeral three.3, the Federal Court still has the option of granting exceptions for certain cases pursuant to article 9 of the GDPR [Editor’s note: obvious editorial error; presumably article 49 of the GDPR] remains open.

§

The provisions under Article 49 of the GDPR constitute exceptions (see, for example, the German or Spanish [“excepciones”] language versions) or derogations (see, for example, the English [“derogations”] or French [“dérogations”] language versions) from the general principle that personal data may only be transferred to third countries if an adequate level of protection exists in that third country or if appropriate safeguards have been provided, and if data subjects are granted enforceable and effective rights so that they can continue to exercise their fundamental rights and safeguards (Guidelines 2/2018 on the exceptions under article 49 of Regulation 2016/679, page 4).The provisions under Article 49 of the GDPR constitute exceptions (see, for example, the German or Spanish [“excepciones”] language versions) or derogations (see, for example, the English [“derogations”] or French [“dérogations”] language versions) from the general principle that personal data may only be transferred to third countries if an adequate level of protection exists in that third country or if appropriate safeguards have been put in place, and if data subjects are granted enforceable and effective rights so that they can continue to exercise their fundamental rights and safeguards (Guidelines 2 of 2018, on the exceptions under article 49 of Regulation 2016/679, page 4).

§

The CJEU also confirms this in its judgement cited above, stating—following the annulment of a previous adequacy decision for the United States—that this does not create a legal vacuum, since Article 49 of the GDPR clearly stipulates under what conditions personal data may be transferred to third countries if neither an adequacy decision nor appropriate safeguards exist (ibid., para. 202).The CJEU also confirms this in its judgement cited above, stating—following the annulment of a previous adequacy decision regarding the United States—that this does not create a legal vacuum, since article 49, of the GDPR clearly sets forth the conditions under which personal data may be transferred to third countries if neither an adequacy decision nor appropriate safeguards are in place (ibid., para. 202). Thus, even in the absence of appropriate safeguards within the meaning of Article 46(2)(c) of the GDPR, a transfer of personal data to a third country is possible if the conditions of Article 49 are met.Thus, even in the absence of appropriate safeguards within the meaning of Article 46(2)(c) of the GDPR, the transfer of personal data to a third country is possible if the conditions of Article 49 are met.

§

Article 49(1)(b) of the GDPR permits the transfer of data if it is necessary for the performance of a contract between the data subject and the controller or for the implementation of precontractual measures at the request of the data subject. This is precisely the situation at hand. As noted in Section II, BF created an account on BG’s platform and, shortly before the conclusion of the proceedings, placed an order that triggered a data transfer to a third country (the People’s Republic of China). The essence of the contract between BG and BF consists of providing access to a platform on which independent merchants can offer and sell their goods to consumers. Should such a purchase actually take place, it is inherent in the nature of the transaction that the buyer’s personal data must be transferred to the seller so that BG can fulfill its obligations to BF under the platform’s terms of use.

§

Likewise, the process can be regarded as a pre-contractual measure at the request of the data subject, since, as already mentioned, BF actively initiated the purchase without being compelled to do so, and facilitating the transaction through the transfer of the necessary data can be characterized as a pre-contractual measure. Ultimately, it is impossible to place an order with a merchant from a third country if the corresponding data transfer to that third country is not permitted.Article 49(1)(b) of the GDPR permits the transfer of data if it is necessary for the performance of a contract between the data subject and the controller or for the implementation of precontractual measures at the request of the data subject. This is precisely the situation at hand. As noted in Roman numeral 2, the BF created an account on the BG platform and, shortly before the conclusion of the proceedings, placed an order that triggered a data transfer to a third country (the People’s Republic of China).

§

The essence of the contract between BG and BF consists of providing access to a platform on which independent merchants can offer and sell their goods to consumers. Should such a purchase actually take place, it is inherent in the nature of the transaction that the buyer’s personal data must be transferred to the seller so that BG can fulfill its obligations under the platform’s terms of use toward BF. Likewise, the process can be regarded as a pre-contractual measure at the request of the data subject, since, as already mentioned, the BF actively initiated the purchase without being compelled to do so, and facilitating the transaction through the transfer of the necessary data can be characterized as a pre-contractual measure. Ultimately, it is impossible to place an order with a merchant from a third country if the associated data transfer to that third country is not permitted. Insofar as BF argues in its complaint that this exception does not apply because it must be interpreted restrictively and the transfers may occur only occasionally, the following counterargument must be made: The requirement of merely occasional transfer is not found in the text of the law, but only in Recital 101, which, however, does not provide a definition of the term “occasional” in terms of a maximum number.

§

Thus, “occasionally” can certainly also be understood to mean “in the event of an order,” which, in BF’s case, triggered exactly a single transfer. Consequently, in the present case, there is not even a repeated or regular transfer. In conclusion, it must be noted that the transfer of BF’s personal data in the present case can be based on the exception provided for in Art. 49(1)(b) of the GDPR, since it occurred only once in this specific instance in connection with an order and was also necessary for the performance of a contract or for pre-contractual measures at the BF’s request.In conclusion, it must therefore be noted that the transfer of BF’s personal data in the present case can be based on the exception provided for in article 49, paragraph 1, (b) of the GDPR, since in the present case it occurred only once in connection with an order and was also necessary for the performance of a contract or precontractual measures at the BF’s request.

§

Alternatively, reference should be made to the case law of German civil courts, according to which—particularly in the case of online platforms designed for the permanent networking of Users—even repeated transfers to third countries may be based on the exception provided for in Art. 49(1)(b) of the GDPR, provided that this is necessary for the underlying performance of the contract (see Regional Court of Trier, Sept. 29, 2025, 2 O 94/24, with further references; Regional Court of Passau, February 16, 2024, 1 O 616/23; Regional Court of Traunstein, July 8, 2024, 9 O 173/24).Alternatively, it should be noted that, according to the established case law of German civil courts, particularly in the case of online platforms designed for the permanent networking of Users, even repeated transfers to third countries may be based on the exception provided in article 49, paragraph 1, (b) of the GDPR, provided that this is necessary for the underlying performance of the contract; see Regional Court of Trier, Sept. 29, 2025, 2 O 94/24, with further references; Regional Court of Passau, February 16, 2024, 1 O 616/23; Regional Court of Traunstein, July 8, 2024, 9 O 173/24).

§

Although these considerations were made with reference to social media platforms, they can be applied to the case at hand, since BF entered into its user agreement with BG precisely for the purpose of purchasing goods from sellers registered on BG’s trading platform. In this respect, it is inherent in the user agreement between BF and BG—given its content and purpose—that, in the event of an order for goods placed by BF, BG transmits the data necessary to process the order to the respective sellers in the third country. The complaint was therefore dismissed as ruled. Insofar as BF requests that the DPA order BG to suspend the data flow from all European Users and require BG to bring its data processing into compliance with Chapter V of the GDPR, it should be noted that, on the one hand, this would go beyond the scope of the present proceedings (see also the remarks on the subject matter of the complaint) and, on the other hand, would first require a finding that the data transfers are unlawful in each individual case.

§

However, such a finding cannot be made across the board at this time. Nevertheless, in light of the above remarks regarding the SCCs used, the BG will have to regularly review its data transfers to third countries and the instruments under Articles 45 through 49 of the GDPR used for this purpose, and adjust them as necessary, since the competent supervisory authority may at any time investigate BG’s data transfers to third countries as part of an ex officio review procedure and, if necessary, exercise its powers.Insofar as the BF requests that the DPA order BG to suspend the data flow from all European Users and require BG to bring its data processing into compliance with Chapter V of the GDPR, it should be noted that, on the one hand, this would go beyond the scope of the present proceedings (see also the remarks on the subject matter of the complaint) and, on the other hand, it would first require a determination that the data transfers are unlawful in each individual case.

§

However, such a determination cannot be made on a blanket basis at this time. Nevertheless, in light of the remarks made above regarding the SCCs used, the BG must regularly review its data transfers to third countries and the instruments relied upon under articles 45 through 49 of the GDPR on a regular basis and adjust them as necessary, since the competent supervisory authority may at any time investigate the BG’s data transfers to third countries as part of an ex officio review procedure and, if necessary, exercise its powers.

How it connects

36 of 36 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-487/21 Österreichische Datenschutzbehörde v CRIF C-487/21 (Österreichische Datenschutzbehörde) CJEU Oct 26, 2023 Right of Access Right to Restriction Personal Data
Guidelines 07/2022 certification as a tool for transfers Guidelines on certification and identifying certification criteria Guidelines ·EDPB Feb 24, 2023 Certification International Transfer Processing Agreement
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision