Skip to content
Enforcement · DSB (Austria) ·2020-0.714.215 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Austrian DSB: Controller's use of social security number for statutory financial aid was

The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent.

Original title: DSB (Austria) - DSB-D124.1749

Holding

First, the DPA held that the use of the data subject's social security number by the controller was reasonable in order to fulfill their statutory duties under the principal of data minimisation. The social security number constitutes personal data, which essentially poses an interest of confidentiality for the data subject under § 1(1) DSG. As a government agency under § 1(2) DSG, the controller is only authorized to use this category of data if there is a sufficient legal basis. Among other things, to provide financial services and manage the respective workload, they must inevitably process data types listed in § 25(1) AMSG, which constitutes a proportionate interference with the right to data protection under § 1(1) DSG. Second, the DPA held that the social security number was merely used as an identifier and not for accessing health services. According to Recital 35 GDPR, identifiers cannot be qualified as health data per se, as a link to information about the data subject's health status is required. Therefore, no date of birth is present, so the social security number is not classified as protected data under Article 9(1) GDPR or § 1(2) DSG.

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Summary

On 17.02.2020, the data subject lodged a complaint with the Austrian DPA (DSB) regarding the unlawful disclosure of their date of birth under Article 9 GDPR, which posed a risk of accessing the data subject's health records using their social security number. On 19.03.2020, the controller stated that the complaint was unfounded, since the data subject had not mentioned anyone taking note of their social security number. Furthermore, financial transactions in contemporary business environments are fully automated, and the field containing the social security number is usually only visible in detailed transaction views. The procedure is also in accordance with the Austrian Federal Ministry of Finance et al. in order to fulfill statutory services. The social security number allows easier data management and traceability, for example when financial transactions fail, and is not used for health-related purposes.

Full text 5 findings

Machine translation of the decision, via GDPRhub — not the official text. Read the original

Paragraphs carrying a topic or an applied provision show those connections inline
§

Text Ref. No.: 2020-0.714.215 dated November 5, 2020 (Case No.: DPA-D124.1749) [Note from the processor: Names and company names, legal forms and product names, addresses (including URLs, IP addresses, and email addresses), case numbers (and the like), etc., as well as their initials and abbreviations, may have been shortened and/or altered for pseudonymization purposes. Obvious spelling, grammar, and punctuation errors have been corrected. The name of the respondent, as a public-law corporation, has not been pseudonymized, as its legally defined labor market policy responsibilities are mentioned in the text of the reasoning, and therefore it was not possible to perform a meaningful and preserving pseudonymisation of the name in this decision, which must be published pursuant to para 2 of § 23 of the Data Protection Act (DSG).] DECISION RULING The Data Protection Authority makes a decision on the data protection complaint filed by Heinrich A*** (complainant) on February 17, 2020, against AMS Austria (respondent) regarding a violation of the right to confidentiality as follows: - The complaint is dismissed as unfounded. Legal Basis Art. 4(15), Art. 9(1) and (2), Art. 51(1), Art. 57(1)(f) and (4), and Art. 77(1) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR), OJ No. L 119 of May 4, 2016, p. 1; Sections 1(1) and (2), 18(1), and 24(1) and (5) of the Data Protection Act (DSG), Federal Law Gazette I No. 165/1999, as amended; Sections 1(1) and (2), 25(1) of the Federal Act on the Public Employment Service (AMSG), Federal Law Gazette No. 313/1994, as amended; § 54 of the Unemployment Insurance Act of 1977 (AlVG), Federal Law Gazette No. 609/1977, as amended; Para 2 of section 2 of the AlVG Payment Regulation (AZV), Federal Law Gazette II No. 470/1999, as amended, and Para 2(3) and (9) of the Federal Act on the Federal Computing Center GmbH (BRZ GmbH), Federal Law Gazette No. 757/1996, as amended by Federal Law Gazette I No. 82/1997, as amended. STATEMENT OF REASONS A. Arguments of the Parties and Course of Proceedings

¶1

In a complaint filed on February 17, 2020, the complainant argued, in summary, that the respondent, in the course of fulfilling its statutory duties under the AIVG, had, on behalf of the F*** Sparkasse—which, on behalf of the respondent, processes employment insurance benefits and the transfer of resulting funds—had disclosed the complainant’s social security number to the Sparkasse without the complainant’s consent. This constituted an unlawful disclosure of special categories of data, namely health data, pursuant to Art. 9 of the GDPR. Given the nature and purpose of the social security number, in the event of its unlawful disclosure to third parties, it cannot be ruled out that these third parties could use the social security number to gain access to the data concerning the data subject’s health.

¶2

In a response dated March 19, 2020, the respondent argued that the complaint should be dismissed as unfounded. Essentially, the respondent argued that the complainant had not identified any specific individuals who had obtained knowledge of his social security number. Given that account transactions in today’s business environment are fully automated—with thousands of transfers and postings occurring automatically every day—the complainant’s assumption that bank employees are involved in the disbursement process does not appear to hold true. Furthermore, the field containing the social security number does not typically appear in general transaction views—which display only transaction amounts and the corresponding transaction times—but rather only in detailed views of transactions. Without the identification of specific bank employees who would have had access to the social security number, the complaint must therefore be dismissed, as no actual violation of the law has occurred. Furthermore, the disclosure of the Social Security number to the parties involved was necessary for the complete and proper processing of the procedure for the provision of statutory benefits (Sections 7(1) et seq., 51 AIVG in conjunction with Art. 6(I)(c) GDPR in conjunction with § 25(1)(1)(b) [sic!])), including the Federal Ministry of Finance and the Federal Accounting Agency. In this context, this covers not only the actual provision of benefits but also all necessary activities and associated processing operations that, for example, provide the necessary data foundations for subsequent control and audit procedures or have been established for those cases in which the planned standard outcome of the procedure does not occur or occurs in a significantly different manner. With regard to transfers of funds to benefit recipients, this is regularly the case; that is, the funds are not always transferred without issues, which in turn leads to a benefit return procedure, in the course of which not only the AMS requires the transmitted social security number for identifying and maintaining the data record, but, in particular, the Federal Accounting Agency also requires it for the accounting work involved in the reversal. In this context, the respondent notes that it can only fill out a payment order from the Federal Ministry of Finance and subsequently has no influence over the actual implementation processes. Finally, there is also no processing of special categories of data, specifically health data within the meaning of Art. 9 GDPR. This must be considered differently in the case of the social security number. In the present case, the social security number is processed in a manner unrelated to health.

¶3

The complainant did not respond to the opportunity to be heard granted to him on April 6, 2020.

¶4

In a letter dated August 26, 2020 (received by the Data Protection Authority on August 28, 2020), the complainant filed a complaint for delay pursuant to para 132(3) of the Federal Constitutional Act (B-VG) in conjunction with §§ 7 et seq. of the Administrative Court Act (VwGVG). B. Subject Matter of the Complaint Based on the complainant’s submissions, the subject matter of the complaint is the question of whether the respondent violated the complainant’s right to confidentiality by disclosing the complainant’s social security number to the complainant’s bank, B*** Bank AG. C. Findings of Fact The respondent is a public-law service provider responsible for implementing labor market policy. In the course of providing statutory benefits under the Unemployment Insurance Act, the respondent transmitted to the bank where the complainant—who was, at that time, a beneficiary of the respondent’s benefits—maintains his recipient account—namely, B*** Bank AG—among other things, the complainant’s social security number, which was entered in the “Transaction Info” field of the transfer form alongside information regarding the benefit payment period: [Editor’s note: The account statement or online banking screenshot reproduced here as an image file cannot be easily displayed or pseudonymized in the RIS and has therefore been removed.] The complainant did not consent to such a transfer of his Social Security number. Assessment of the Evidence The findings made are based on the submissions of the parties to the proceedings as well as the contents of the file. D. From a legal perspective, the following conclusions follow: 1 General Considerations and Applicable Legal Provisions It should be noted at the outset that, in the present case, a violation of the right to confidentiality under § 1(1) of the Data Protection Act (DSG) must be examined, and that restrictions on this right arise from para 2 of the cited provision , but not from Article 6(1) or Article 9(2) of the GDPR. However, the GDPR—and in particular the principles enshrined therein—must be taken into account when interpreting the right to confidentiality (see the decision of the DPA dated October 31, 2018, Ref. No.: DPA-D123.076/0003-DPA/2018). Pursuant to § 1(1) of the Data Protection Act (DSG), every person, particularly with regard to respect for their private and family life, has a right to confidentiality of personal data concerning them, provided there is a legitimate interest in such confidentiality. Pursuant to § 1(2) of the DSG, restrictions on the right to confidentiality—insofar as the use of personal data is not in the vital interest of the data subject or does not occur with his or her consent—are permissible only to safeguard the overriding legitimate interests of another party, and in the case of interventions by a government authority, only on the basis of laws . Such laws may provide for the use of data that, by its Art, is particularly worthy of protection only to safeguard important public interests and must simultaneously establish appropriate safeguards for the protection of the data subjects’ privacy interests. Even in the case of permissible restrictions, the interference with the fundamental right must in each instance be carried out only in the least intrusive manner necessary to achieve the objective . Pursuant to § 1(1) AMSG, the implementation of the federal government’s labor market policy is the responsibility of the “ Labor Market Service .” This is a public-law service provider with its own legal personality . Pursuant to § 54 of the AlVG in conjunction with §§ 2, 3(2) of the AlVG Payment Ordinance, the authorization of benefits under the AlVG falls under the jurisdiction of the locally competent regional office of the Labor Market Service . Pursuant to Section 2(3) of the Federal Act on the Bundesrechenzentrum GmbH, the Bundesrechenzentrum GmbH is responsible for assisting with the preparation of payments. As a service provider under para 9 of the aforementioned Act, it is bound by the instructions of the respective client when using data. Pursuant to § 25(1) of the AMSG, the Labor Market Service is authorized to process personal data to the extent that such processing is an essential prerequisite for the fulfillment of its statutory duties . The relevant types of data, pursuant to Z 1(b) of the aforementioned law, cit., include, among others, the social security number and date of birth . Pursuant to para 4 of the aforementioned law, the data processed by the Public Employment Service may be transmitted to Bundesrechenzentrum GmbH within the scope of the services to be provided by the latter. Pursuant to Article 9(1) of the GDPR, the processing of data concerning health is prohibited unless an exception listed in para 2 of the aforementioned article applies. According to Article 4(15) of the GDPR, data concerning health refers to personal data relating to the physical or mental health of a natural person, including the provision of health services, and from which information about the person’s health status can be derived. 2 On the Merits a. Regarding the Allocation of Roles Under Data Protection Law As can be seen from the findings, the respondent is, pursuant to § 1(1) AMSG, a public-law service provider responsible for implementing the federal government’s labor market policy. Despite being organized into federal, state, and regional organizations, the respondent’s subsidiary organizations do not possess separate legal personality; therefore, the status of data controller under data protection law applies only to the respondent and not to its subsidiary organizations (see Jahnel, Handbook on Data Protection, margin note 3/33). The respondent was thus to be classified as a government authority within the meaning of § 1(2) of the Data Protection Act (DSG). Furthermore, the fact that Bundesrechenzentrum GmbH was involved in the specific processing of the payment is irrelevant to the respondent’s classification as a data controller under data protection law, particularly since Bundesrechenzentrum GmbH is bound by the respondent’s instructions regarding the processing of personal data (see para 2(9) of the Federal Act on Bundesrechenzentrum GmbH). Furthermore, the respondent never disputed its status as the data controller under data protection law. b. On the Lawfulness of Data Processing It should be noted at the outset that the social security number is personal data in respect of which the complainant generally has a legitimate interest in confidentiality within the meaning of § 1(1) of the Data Protection Act (DSG): it is regularly used as an identifier in business and administrative transactions, as well as, in the present case, in the context of claiming social security benefits (see the decision of the former DSK dated August 3, 2012, Ref. No.: K121.817/0016-DSK/2012). Nor is there merely an “abstract possibility of risk,” as asserted by the respondent. In this regard, the respondent overlooks the fact that, even if account transactions were to be carried out fully automatically on a regular basis, the complainant’s personal data was in any case disclosed to B*** Bank AG—and thus to a third party. Furthermore, classifying the respondent as a “public authority” within the meaning of § 1(2) DSG requires that any interference with the fundamental right to data protection may occur only on the basis of a sufficiently specific legal basis . The complainant’s assertions that he did not give consent to the processing of his data are therefore irrelevant. As can be seen from § 25(1) of the AMSG, the respondent is authorized to process the social security number to the extent that this is an essential prerequisite for the fulfillment of its statutory duties . In this context, the respondent argues that the processing of the social security number enables, on the one hand, the proper processing of the payment and, on the other hand, is in any case necessary for subsequent control and review procedures (in particular in the event of a benefit recovery procedure). The processing of payments from unemployment insurance is undoubtedly a statutory duty of the respondent. The processing of the Social Security number for the proper and accurate allocation of benefits to the respective beneficiary does not constitute an inappropriate or excessive use of data, as there is undoubtedly a matter of social security law at issue. As an interim conclusion, it can therefore be stated that the use of the social security number in connection with a payment order for unemployment insurance benefits is, in principle, to be considered permissible. Subsequently, it must be examined whether the use of the aforementioned data was proportionate, since, pursuant to § 1(2) of the Data Protection Act (DSG), even in cases of permissible restrictions, the interference with a fundamental right may only be carried out in the least intrusive Art necessary to achieve the objective (duty of data minimization). In any case, it is understandable to the average member of the public that the respondent must necessarily process certain types of data—listed in para 25(1) AMSG — must inevitably process in order to provide certain services (such as processing an application for certain unemployment insurance benefits). It is also a matter of common sense that, given the respondent’s heavy workload, benefit recovery proceedings may well arise, in the context of which the unambiguous identification of benefit recipients—particularly for accounting purposes—is inevitably required. In any case, the use of the aforementioned data was an essential prerequisite for achieving the intended purpose and therefore constitutes a proportionate interference with the right to privacy. c. Regarding the Social Security Number as Health Data Finally, the complainant’s argument that the Social Security number constitutes health data within the meaning of Article 9(1) of the GDPR must be addressed. It should be noted that laws within the meaning of Section 1(2) of the DSG may only provide for the use of data that, by its nature, is particularly worthy of protection , only for the protection of important public interests and, at the same time, must establish appropriate safeguards for the protection of the data subjects’ privacy interests. In light of Article 9(1) of the GDPR, data concerning health undoubtedly constitutes data requiring special protection, although the term must be interpreted broadly in accordance with the case law of the CJEU (see, regarding Article 8(1) of Directive 95/46, the judgement of the CJEU of November 6, 2003, C-101/01, Lindqvist, para. 50). Pursuant to Article 4(15) of the GDPR, read in conjunction with the second sentence of Recital 35 of the GDPR, this also includes numbers, symbols, or identifiers assigned to a natural person to uniquely identify that person for health purposes. However, the Data Protection Authority represents in its established case law that data concerning health must, in any event, reveal information about the data subject’s past, present, and future physical or mental health status . Taking this consideration into account, identification numbers within the meaning of Recital 35, second sentence, of the GDPR are not to be classified as health data per se rather, there must also be a certain connection between such identification numbers and information regarding the state of health (see, for example, the DPA’s decision of April 9, 2019, DSB-D123.526/0001-DSB/2019). If the social security number is therefore used merely as an indicator—that is, in this specific case, independently of the use of a health care service—it does not constitute health data and thus does not constitute data requiring special protection within the meaning of Section 1(2) of the Data Protection Act (DSG) or Art. 9(1) of the GDPR. It was therefore necessary to make a decision in accordance with the decision.

How it connects

4 of 5 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) Jan 12, 2023 Supervisory Authorities IP Address Supervision
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data
C-446/21 Maximilian Schrems v Meta Platforms Ireland Limited In a preliminary ruling arising from proceedings between Maximilian Schrems and Meta Platforms Ireland Limited, the Court of Justice of the European Union interpreted GDPR… Fourth Chamber Oct 4, 2024 Retention Period Personal Data Marketing