DSB: Retailer must grant full access and delete data after third-party fraud order
A retailer (controller) sent a notebook to the address of a data subject after having received an order to that address.
Status Not cited by any decision here yet
Original title: DSB (Austria) - DSB-D124.2016/23
Holding
According to the DPA, the data subject cannot claim a violation of their access right because of incomplete access to their data when the data is already deleted, in accordance with their request. The data subject runs the risk of impairing their access right in case of incomplete access to their personal data when the data subject requests access to their personal data and the deletion thereof at the same time. Since the data subject requested the deletion before the involvement of the DPA, the controller did not violate the principle of lawfulness and transparency, and did not violate the data subject’s access right. As far as the processing of personal data in the context of the credit check was concerned, the DPA held that the processing can be based on legitimate interest as provided for by Article 6(1)(f) GDPR. The controller had the legitimate interest of confirming the creditworthiness of the data subject to evaluate the risk of a payment default despite the fact that the order was not placed by the data subject themselves. At the time of processing, there was no reason for the controller to doubt the identity of the person placing the order because the data subject’s data disclosed by the third person who placed the order was correct and the credit check using the data provided resulted in a match. There is no obligation for the controller to additionally verify the identity of the customer before every order. Such a practice would not be compatible with the principles of lawfulness, data minimisation and proportionality under the GDPR. When balancing the legitimate interest of the controller with the rights of the data subject, the economic interest of the controller prevailed. It was the third person, not the controller, who violated the data subject’s right to secrecy as provided for by national law. The DPA held that in order for the controller to rely on Article 6(1)(f) GDPR as legal basis, the controller must inform the data subject about their legitimate interest at the time of obtaining the data in accordance with Article 13 or 14 GDPR, if applicable. However, since the controller did not collect the data from the data subject, Article 13 GDPR is not applicable. Neither was the controller obliged to inform the data subject under Article 14 GDPR. From the controller’s point of view, the person placing the order was the data subject and no other person was involved. There was no reason for the controller to doubt that the order was placed by the data subject. Moreover, since the e-mail address and phone number used to place the order did not belong to the data subject, the provision of information proves impossible under Article 14(5)(b) GDPR, resulting in an exemption from the right to information.
From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓
However, the data subject has never placed the order and did not hold an account with the retailer. An unknown third person has placed the order, using the data subject’s address, correct first and last name and date of birth. The e-mail address and phone number used by the third person did not belong to the data subject. After having received the order, and believing that the order was placed by the data subject, the controller carried out a credit check of the data subject with a credit information agency. After receiving the notebook and learning about the false order, the data subject requested within one e-mail both access to their personal data held by the controller and the deletion of their personal data. The controller gave access to some of the data subject's personal data. Afterwards, the data subject filed a complaint with the DPA, claiming the data received upon their access request was incomplete because the data relating to the credit check were not included, amongst others. Moreover, the data subject claimed that the controller did not have a legal basis for disclosing their personal data to the credit rating agency. After the complaint was lodged, the controller replied to the access request and subsequently deleted the data. At the time of the procedure before the DPA, the controller did not process personal data of the data subject anymore.
Full text 4 findings
Machine translation of the decision, via GDPRhub — not the official text. Read the original
Text Ref. No.: 2026-0.068.850 dated January 27, 2026 (Case No.: DPA-D124.2016/23) [Processing Officer’s Note: Names and company names, legal forms and product names, addresses (including URLs, IP addresses, and email addresses), case numbers (and similar), statistical data, etc., as well as their initials and abbreviations, may have been abbreviated and/or altered for pseudonymization purposes. Obvious spelling, grammar, and punctuation errors have been corrected.] DECISION RULING The Data Protection Authority rules on the data protection complaint filed by Attorney Dr. Ludwig A*** (complainant), represented by B*** A*** C*** E*** Attorneys at Law, dated September 1, September 2023 against m***.at GmbH (respondent) regarding an alleged violation of the right of access pursuant to Art. 15 of the GDPR and the right to confidentiality pursuant to § 1 of the DSG, as follows:The Data Protection Authority makes a decision on the data protection complaint filed by Attorney Dr. Ludwig A*** (complainant), with representation provided by B*** A*** C*** E*** Attorneys at Law, dated September 1, September 2023 against m***.at GmbH (respondent) regarding an alleged violation of the right of access under article 15 of the GDPR and the right to confidentiality under Section 1 of the DSG as follows: The complaint is dismissed as unfounded. Legal basis: Art. 5, Art. 6(1)(f), Art. 15, Art. 51(1), Art. 57(1)(f), and Art. 77(1) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR), OJ No. L 119 of May 4, 2016, p. 1; Sections 1, 18(1), and 24(1) and (5) of the Data Protection Act (DSG), Federal Law Gazette I No. 165/1999, as amended.Legal basis: Article 5, Article 6(1)(f), Article 15, Article 51(1), Article 57(1)(f), and Article 77(1) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR), Official Journal No. L 119 of May 4, 2016, page 1; Section 1, Paragraph 18(1), and Paragraph 24(1) and (5) of the Data Protection Act (DSG), Federal Law Gazette, Part I, No. 165 of 1999, as amended. STATEMENT OF REASONS A. Arguments of the Parties and Course of Proceedings A.1. On September 1, 2023, the complainant filed a complaint, supplemented by letters dated September 7, 2023, and September 25, September 2023, filed a complaint against the respondent party regarding an alleged violation of the rights to access under Art. 15 of the GDPR, erasure under Art. 17 of the GDPR, and confidentiality pursuant to § 1 of the DSG.A.1. On September 1, 2023, supplemented by letters dated September 7, 2023, and September 25, September 2023, filed a complaint against the respondent regarding an alleged violation of the rights to access under Article 15 of the GDPR, erasure under Article 17 of the GDPR, and confidentiality pursuant to Paragraph 1 of the DSG. In summary, the complainant argued that she had received a shipment containing a H*** notebook from the respondent, even though she had neither created a customer account nor placed an order with the respondent. The shipment was expressly addressed to her home address; however, the mobile phone number provided was incorrect. After contacting the respondent, the respondent informed her on July 18, July 2023 that the complainant had apparently fallen victim to a fraudster, as an online order had been placed using her data and, following an address and credit check, the order had been approved. This apparent misuse of her personal data had alarmed the complainant, as it was no trivial matter that someone had evidently created a customer account and placed orders under her name and using her data. Shortly after the complaint in question was filed, the respondent contacted the complainant, who subsequently reached out to the respondent’s data protection officer. On September 7, 2023, she received a response indicating that an email address apparently existed in the complainant’s name, but that she had never created it. Her personal information (first and last name, date of birth, address) was correct. However, the phone number was not that of the complainant. It appears that there were two IP addresses from which orders were placed or attempted, and a credit check was conducted, the results of which were not communicated to the complainant. The complainant considers her right to access and erasure to have been violated, as on July 20, July 2023, the complainant sent a letter to the respondent containing a request for information pursuant to Article 15 of the GDPR and a request for erasure pursuant to Article 17 of the GDPR.The complainant considers her right to access and erasure to have been violated, as she sent a letter to the respondent on July 20, 2023, containing a request for access pursuant to article 15 of the GDPR and a request for erasure pursuant to article 17 of the GDPR. On September 7, 2023, she received an email in response to her request for access. This response was delayed and did not include all the information required to be disclosed under Article 15(1) of the GDPR. Specifically, the information regarding the processing purpose, the recipients (or categories of recipients), the retention period, and the data subject rights was incomplete. Furthermore, a copy or the content of the credit report apparently conducted on July 10, 2023, was not attached. On September 7, 2023, she received an email in response to her request for information. This response was delayed and did not include all the information required to be disclosed pursuant to Article 15, paragraph 1, of the GDPR. Specifically, it was incomplete with regard to information on the processing purpose, the recipients (or categories thereof), the retention period, and the data subject rights. Furthermore, a copy or the content of the credit check apparently conducted on July 10, 2023, had not been attached. The complainant’s data had not been subjected to erasure, which is why she considers her right to erasure to have been violated. The information provided indicates that the respondent processes the complainant’s personal data without being able to demonstrate a legitimate basis for such processing within the meaning of the GDPR. Neither had consent been granted, nor was the processing justified (already due to the lack of a contractual relationship with the complainant) on the grounds of necessity for the performance of a contract or even due to legal requirements. In any case, any interests of the respondent would take a back seat to the complainant’s own interests in confidentiality. Attached to the submissions were - the email correspondence between the parties to the proceedings (Exhibit ./A) - the complainant’s request for information dated July 20, 2023 (Exhibit ./B) - the complainant’s request for deletion dated July 20, 2023 (Exhibit ./C) - the information provided by the respondent, as well as the confirmation of erasure dated September 7, 2023 (Exhibit ./D) the respondent’s promise to carry out an erasure dated September 6, 2023 (Exhibit ./E) A.2. The respondent was requested to submit a statement by a letter from the Data Protection Authority dated December 21, 2023. A.3. The respondent submitted a statement by letter dated January 2, 2024, and explained that the complainant had received all available data from the respondent. This data is also available to the Data Protection Authority, as the complainant submitted it as part of the complaint in question. The complainant’s personal data has been anonymized since September 7, 2023. Transaction data, such as orders and returns, is still available and can only be linked to customer number *0*1*5*4*. However, this customer number can no longer be linked to any specific individual, as the original data has been overwritten and therefore no longer exists. The respondent does not process any name, address, date of birth, or email address of the complainant in connection with this incident. In general, retention periods range from 2 to 7 years, depending on the importance of the data. However, order, return, and payment data are always stored for 7 years. In this specific case, no data concerning the complainant relating to this incident has been available since September 7, 2023. Prior to the complainant’s complaint, a “legitimate interest” in the processing of the data had in any case existed, and reference is made to Recital 47. A.4. The complainant responded to this in a statement dated January 17, 2024, and, in particular, withdrew the complaint regarding the alleged violation of the right to erasure under Article 17 of the GDPR.A.4. The complainant responded to this in a statement dated January 17, 2024, and specifically withdrew the complaint regarding the alleged violation of the right to erasure under article 17 of the GDPR. With regard to the alleged violation of the right of access under Article 15 of the GDPR, it should be noted that not all of the content and information required to be disclosed under Article 15(1) of the GDPR was provided. Furthermore, a copy of the personal data—in particular, the credit report apparently conducted by the respondent on “March 10, 2023”—was not included. In the event that this has since been deleted, the respondent is requested to comment on this matter.With regard to the alleged violation of the right of access under article 15 of the GDPR, it should be noted that not all of the content and information required to be disclosed under article 15(1) of the GDPR had been provided. Furthermore, a copy of the personal data—in particular, the credit report apparently conducted by the respondent on “March 10, 2023”—was not included. In the event that this has since been deleted, the respondent is requested to comment on this matter. With regard to the complaint concerning the violation of the right to confidentiality, it should be noted that it has only now become apparent to the complainant that the respondent is basing the processing of the complainant’s personal data on a “legitimate interest.” However, this is not comprehensible. First, the respondent should be advised that, when justifying the processing of personal data on the basis of this ground, both the ground itself and the legitimate interests pursued thereby must be disclosed as part of the duty to provide information pursuant to Art. 12 et seq. GDPR. No such information is found in the respondent’s privacy policy, in the current response, or elsewhere. Furthermore, the admissibility of relying on this legal basis for online store orders is generally questionable; in any case, it is ruled out in the context of unlawful orders placed by third parties who are not lawfully permitted to have access to the complainant’s personal data.However, this is not comprehensible. First, the respondent should be advised that, when justifying the processing of personal data on the basis of this ground, both the ground itself and the legitimate interests pursued thereby must be disclosed in accordance with the duty to provide information under article 12 et seq. GDPR. No such information is found in the respondent’s privacy policy, in its current statement, or anywhere else. Furthermore, the admissibility of invoking this legal basis for online store orders is generally questionable; in any case, it is ruled out in the context of unlawful orders placed by third parties who are not lawfully permitted to have access to the complainant’s personal data. A.5. In its response dated October 18, 2024, the respondent stated, in summary, that according to the records at issue in the proceedings, no credit check could have been performed on March 10, March 2023, as alleged by the complainant, no credit report could have been issued because this person was not entered into the system until July 10, 2023, as is clearly evident from the information provided on September 7, September 2023. The credit report and data regarding the complainant had since been deleted—as previously explained—which is why only the records could be cited. The processing purposes include fulfilling orders for the delivery of goods to customers. Recipients of the data are generally limited to partners necessary for order fulfillment. A data processing agreement is in place with all of these partners. This includes delivery services as well as suppliers who ship directly to the customer. Data storage lasts for three to a maximum of seven years, depending on whether an order is placed. A “legitimate interest” exists in this regard because address data is required to fulfill an order (delivery of goods), and assessing the individual’s creditworthiness is relevant for purchases on account. A.6. The complainant responded to this in its submission dated November 15, 2024, as part of the hearing of the parties, and argued, in summary, that not all of the information required to be disclosed under Article 15(1) of the GDPR had yet been provided. Specifically, information was missing regarding the processing purposes (Article 15(1)(a)), the recipients (Article 15(1)(c)), and the retention period (Article 15(1)(g)). Furthermore, a copy of the personal data had not been included. It is true, however, that the accuracy of the date of the credit report—March 10, 2023—was apparently compromised in the submission dated January 17, 2024; the credit report appears to be dated July 10, 2023.A.6. The complainant responded to this in its submission of November 15, 2024, as part of the hearing of the parties, and argued, in summary, that not all of the information required to be disclosed under article 15, paragraph 1, of the GDPR had yet been provided. Specifically, information regarding the processing purposes (article 15(1)(a)), the recipients (article 15(1)(c)), and the retention period (article 15(1)(g)) was missing. Furthermore, a copy of the personal data had not been included. It is true, however, that the accuracy of the date of the credit report, listed as March 10, 2023, in the submission dated January 17, 2024, was apparently incorrect—the credit report appears to be dated July 10, 2023. With regard to the alleged violation of the right to confidentiality, reference is therefore made to the arguments presented thus far, particularly in the submission dated January 17, January 2024, and it is further emphasized that a credit report on the complainant was obtained and processed even though no contractual relationship existed and no other justification pursuant to Article 6(1) of the GDPR could be present.With regard to the alleged violation of the right to confidentiality, reference is therefore made to the arguments presented to date, in particular in the submission dated January 17, January 2024, and it is further emphasized that a credit report concerning the complainant was obtained and processed even though no contractual relationship existed and no other grounds for justification pursuant to article 6(1) of the GDPR could exist. B. Subject Matter of the Complaint Based on the complainant’s arguments, the subject matter of the complaint is the question of whether the respondent 1) thereby violated the complainant’s right to confidentiality under § 1 of the DSG by conducting a credit check with D*** GmbH using the complainant’s data provided by an unknown third party in the course of an online order, and thereby violated the complainant’s right to confidentiality under Paragraph 1, of the DSG by conducting a credit check with D*** GmbH using the complainant’s data provided by an unknown third party in the course of an online order, and 2) thereby violated her right to access under Article 15 of the GDPR by providing incomplete information regarding her personal data after simultaneously receiving a request for access and a request for erasure, and subsequently erasing the data as requested.thereby violated her right of access under article 15 of the GDPR by providing incomplete information regarding her personal data after receiving a simultaneous request for access and erasure, and subsequently deleting the data as requested. However, the subject matter of the complaint is not the question of whether the respondent violated the complainant’s right to erasure, as the complainant withdrew the complaint in this regard in a submission dated January 17, 2024. C. Findings of Fact C.1. The complainant is an attorney in V***dorf with an office located at . C.2. The respondent operates an online store as a limited liability company headquartered in W*** under company registration number *7*7*5i. C.3. On July 10, 2023, an unknown third party placed an online order on the respondent’s website using the complainant’s personal data, specifically the complainant’s first and last name, private residential address, and date of birth. The email address and phone number provided, however, did not belong to the complainant. C.4. On July 10, 2023, the respondent conducted a search in the “Identity and Creditworthiness Database” of D*** GmbH using the complainant’s data provided by the person placing the order and received a positive match. C.5. The complainant first became aware of the order when the goods ordered in her name were delivered to her private residence and subsequently contacted the respondent to clarify the matter. On July 17, 2023, she requested the erasure of her data, initially asking the respondent to explain where it had obtained her data. In a letter dated July 20, 2023, the complainant finally requested information regarding their personal data pursuant to Article 15 of the GDPR and simultaneously requested its erasure. The corresponding requests were as follows (screenshot, excerpt; formatting not reproduced exactly): In a letter dated July 20, 2023, the complainant finally requested information regarding her personal data pursuant to Article 15 of the GDPR and, at the same time, requested its erasure. The relevant requests were as follows (screenshot, excerpt; formatting not reproduced exactly): [Editor’s note: The legal brief from the complainant’s representatives—reproduced here in the original as a scan of a paper document, along with the attached requests for access and erasure—could not be converted into a text document with reasonable effort and was removed for pseudonymization purposes.] Figure 1 [Editor’s note: as above] Figure 2 [Editor’s note: as above] Figure 3 [Editor’s note: as above] Figure 4 [Editor’s note: same as last time] Figure 5 C.6. On September 1, 2023, the complainant filed the subject complaint with the Data Protection Authority. C.7. The respondent responded outside the scope of the present proceedings in letters dated September 6, 2023, and September 7, September 2023 to the complainant’s requests for access and erasure as follows (screenshot, excerpt, formatting not reproduced exactly): [Processing Officer’s Note: The email reproduced in the original at this point as a facsimile in PNG format has been converted to a text document and is reproduced here in pseudonymized form.] “From: Data Protection Date: September 6, 2023, at 5:27:14 p.m. CEST To: "Dr. Ludwig A*** - b*** a*** c*** e***" CC: ludwig.a***@***provider.at, data protection@m***.at, service@m***.at Subject: Re: Customer Number *0*1*5*4*, Order Number *02*11*R, Order Date July 9, 2023 URGENT Dear Dr. A***, I have no idea which parts of your explanation are correct and which are not; in any case, I hereby confirm the erasure of your account and the blocking of your name so that nothing can ever be ordered under that name again. Sincerely, Karl T*** Data protection officer” Figure 6 [Editor’s note: The email, which appears in the original as a facsimile in PNG format at this point, has been converted to a text document and is reproduced here in pseudonymized form.] “From: Karl T*** on behalf of data protection Sent: Thursday, September 7, 2023, 1:55 PM To: Herta J*** - b*** a*** c*** e*** Subject: Reply: Dr. Ludwig A*** - m***.at GmbH Tag: For tracking Status: Closed Dear Dr. A***, We received your request for information on July 20, 2023.
We received your request for information pursuant to Article 15 of the GDPR on July 20, 2023. You have sufficiently verified your identity in the request. We received your request for information pursuant to Article 15 of the GDPR on July 20, 2023. You have sufficiently verified your identity in it.
We are hereby responding to your request within the extended two-month deadline.
We have stored the following personal data about you. However, this data has already been forwarded to the relevant department for erasure and will be erased following my final approval. Customer number: *0*1*5*4* created on July 10, 2023 Name: A*** LUDWIG Date of birth: **.**.196* Email address: dr.ludwig.a***@x*mail***.com Address: **** ****BURG, ****HANG **5/3* Phone: 0***/*7*7*9 Source of your data: Online store Order history: July 10, 2023 at 5:06 PM not delivered (Order number *5*1*A) From IP address: *5.**8.5*9.*4 Article: July 10, 2023 at 5:05 PM not delivered (Order number *88*0*1B) From IP address: *5.**8.5*9.*4 Article: July 9, 2023, at 4:17 PM—not shipped (Order number 7*6*33*C) From IP address: *1.2*5.**.13* Article: July 9, 2023, at 4:11 PM – Shipped (Order number *02*11*R) From IP address: *1.2*5.**.13* Article: Returns: Order number *02*11*R on August 1, 2023 Figure 7 Credit check: Conducted by D*** on July 10, 2023, at 10:29 a.m. and resulted in a match with a good rating. Karl T*** Data protection officer I hope this is sufficient for a potential criminal complaint, as I cannot provide you with any further data. Sincerely,” Figure 8 C.8. The respondent deleted the data stored regarding the complainant on September 7, 2023, as requested, after the complainant provided the information at the same time. Assessment of the Evidence: The findings under C.1. regarding the complainant are based on the complainant’s submissions, as well as an ex officio investigation by the Data Protection Authority on the website of the *** Bar Association and an ex officio investigation on https://www.b*a*c*e*.at/ (last accessed on January 13, 2026). The finding under C.2. is based on an ex officio search at https://www.m***.at/impressum/ conducted on January 16, 2026, and is supported by the consistent and undisputed submissions of the parties to the proceedings. The findings regarding C.3. and C.4. are based on the consistent submissions of the parties to the proceedings in this regard, in particular the email correspondence (Exhibit ./A) and the information provided by the respondent on September 7, 2023 (Exhibit ./D). The findings regarding C.5. and C.7. are based on the consistent submissions of the complainant dated September 1, 7, and 25, 2023, as well as those of the respondent in its statement dated January 2, January 2024 to the Data Protection Authority, the complainant’s statement of January 17, 2024, and the documents attached to the complaint, particularly the submitted correspondence between the parties to the proceedings. The erasure of the complainant’s personal data, as established under C.8., is based on the respondent’s submissions—which ultimately remained uncontested by the complainant—as well as on the documents submitted by the complainant. D. From a legal perspective, the following follows: Pursuant to Art. 77(1) of the GDPR and § 24(1) of the DSG, every data subject has the right to lodge a complaint with the Data Protection Authority if they believe that the processing of their personal data violates the GDPR or § 1 of the first main section of the DSG. Pursuant to article 77, paragraph one, GDPR or Section 24(1) of the DSG, every data subject has the right to lodge a complaint with the Data Protection Authority if they believe that the processing of their personal data violates the GDPR or Section 1 of Paragraph 1 of Part I of the DSG. In general, it should be noted that both the Data Protection Authority and the Federal Administrative Court (BVwG) have consistently held in their case law that in cases based on an application—such as, in particular, the complaint procedure pursuant to Article 77 of the GDPR in conjunction with Section 24(1) of the DSG—the content of the application (in this case: the complaint) constitutes and delimits the subject matter of the administrative proceedings (in this case: the subject matter of the complaint) (see, for example, the BVwG decision of May 17, 2022, W214 2233132-1).As a general rule, it should be noted that both the Data Protection Authority and the BVwG have consistently held in their case law that in cases based on an application—such as, in particular, the complaint procedure pursuant to Article 77 of the GDPR in conjunction with paragraph 24(1) DSG—the content of the application (in this case: the complaint) constitutes and delimits the subject matter of the administrative proceedings (in this case: the subject matter of the complaint); see, for example, the BVwG decision of May 17, 2022, W214 2233132-1). D.1. Regarding the Alleged Violation of the Right of Access D.1.1. General Pursuant to Art. 15(1) of the GDPR, the data subject has the right to request confirmation from the controller as to whether personal data concerning him or her is being processed; if so, he or she has the right to access such personal data […]. Pursuant to Article 15(3) of the GDPR, the controller shall provide a copy of the personal data undergoing processing.Pursuant to Article 15, paragraph 1, of the GDPR, the data subject has the right to obtain from the controller confirmation as to whether personal data concerning him or her are being processed; if so, he or she has the right to access such personal data […]. Pursuant to Article 15(3) of the GDPR, the controller shall provide a copy of the personal data undergoing processing. According to Haidinger, the immediate legal consequence of a request for access is the controller’s obligation to provide the information. Based on the wording in Article 15(1) (“are being processed”), it must be concluded that the substantive obligation to provide information is triggered when the controller is currently processing data, but not when the controller has processed the data subject’s data in the past and such data has since been deleted. The scope of the information provided is therefore determined by the time the request is made (Haidinger in Knyrim [ed.], DatKomm, [Oct. 1, 2018], Art. 15 GDPR, paras. 26 and 27).According to Haidinger, the immediate legal consequence of a request for access is the controller’s obligation to provide the information. Based on the wording of Article 15, paragraph 1 (“are being processed”), it can be concluded that the substantive obligation to provide information is triggered when the controller is currently performing data processing, but not when the controller has performed data processing of the data subject in the past and that data has since been deleted. The scope of the information provided is therefore determined by the time the request is made (Haidinger in Knyrim [ed.], DatKomm, [Oct. 1, 2018], article 15, GDPR, paras. 26 and 27). According to Recital 63, a data subject should have the right of access to the personal data concerning him or her that has been collected and should be able to exercise this right easily and at reasonable intervals in order to be aware of the processing and to be able to verify its lawfulness. Furthermore, the right of access is necessary to enable the data subject to exercise their rights to rectification, erasure, and restriction of processing; it is also necessary for the right to object to processing (see Ehmann in Ehmann/Selmayr [eds.], General Data Protection Regulation 2 [2018], Art. 15, para. 1). Furthermore, the right of access is necessary to enable the data subject to exercise their rights to rectification, erasure, and restriction of processing; as well as the right to object to processing (see Ehmann in Ehmann/Selmayr [eds.], General Data Protection Regulation 2 [2018], article 15, para. 1). If the controller does not perform any processing of personal data (the “negative certification” scenario, also known as a negative response), the remaining parts of the provision are no longer relevant in the specific case. A negative response may be considered if either no data regarding the data subject is being processed at all, or if existing (originally) personal data has been irreversibly anonymized (see Ehmann in Ehmann/Selmayr [eds.], General Data Protection Regulation 2 [2018], Art. 15, paras. 4 and 13). If the controller does not perform any processing of personal data (the “negative attestation” scenario, also known as a negative response), the remaining parts of the provision are no longer relevant in the specific case. A negative disclosure may be considered if either no data regarding the data subject is being processed at all, or if existing (originally) personal data has been irreversibly anonymized (see Ehmann in Ehmann/Selmayr [eds.], General Data Protection Regulation 2 [2018], article 15, paras. 4 and 13). In accordance with Article 5(1)(a) of the GDPR, personal data must be processed lawfully, fairly, and in a manner that is transparent to the data subject (“lawfulness, fairness, transparency”).In accordance with Article 5, paragraph 1, subparagraph (a) of the GDPR, personal data must be processed lawfully, fairly, and in a manner that is transparent to the data subject (“lawfulness, fairness, and transparency”). According to Selmayr, the principle of fairness in processing is about ensuring “fair” processing, as the English version (“fairly”) makes clear. This principle serves as a guiding standard for taking into account the protective purpose of the GDPR (Art. 1(2)) when applying its provisions and prohibits the controller or processor from exercising their rights in an impermissible manner to the detriment of the data subject. In particular, the principle requires that, when applying the law in specific processing situations, the “reasonable expectations” of the data subject must be taken into account (Heberlein in Ehmann/Selmayr [eds.], General Data Protection Regulation 2 [2018], Art. 5, para. 9). According to Selmayr, the principle of fairness in processing is about ensuring “fair” processing, as the English version (“fairly”) makes clear. This principle serves as a guiding standard for taking into account the protective purpose of the GDPR (article 1, paragraph 2) when applying its provisions and prohibits the controller or processor from exercising their rights in an impermissible manner to the detriment of the data subject. In particular, the principle requires that, when applying the law in specific processing situations, the “reasonable expectations” of the data subject must be taken into account (Heberlein in Ehmann/Selmayr [eds.], General Data Protection Regulation 2 [2018], article 5, margin note 9). D.1.2. On the Merits In the present case, the respondent—as the data controller under data protection law—was, in any event, processing the complainant’s personal data in connection with an online order at the time the request for access was received, as established. Information regarding the complainant’s processed personal data was provided in the respondent’s response dated September 7, 2023, to the complainant’s access request dated July 20, 2023. Based on the complainant’s request for erasure, filed on July 20, 2023, at the same time as the request for information, July 2023, which was submitted concurrently with the request for information, the respondent subsequently deleted the complainant’s personal data outside the scope of the ongoing investigation before the Data Protection Authority and immediately after the information was provided on September 7, 2023. In this regard, it should be noted that while the right to access under Art. 15 GDPR and the right to erasure under Art. 17 of the GDPR do indeed coexist, the simultaneous assertion of requests for access and erasure inherently carries the risk that, as a result of the erasure request being carried out, no further personal data of the applicant will remain.In this regard, it should be noted that while the right to access under Article 15 of the GDPR and the right to erasure under Article 17 of the GDPR do indeed coexist; however, the simultaneous assertion of requests for access and erasure inherently carries the risk that, as a result of fulfilling the erasure request, no further personal data pertaining to the applicant will remain. In particular, as a person knowledgeable in legal matters (see C.1.), the complainant should have recognized that the simultaneous assertion of requests for access and erasure gives rise to a foreseeable conflict of objectives and that, based on their “reasonable expectations,” could or must have anticipated that the respondent would delete the complainant’s personal data after the information was provided on September 7, 2023 (see, in particular, the passage contained in the information provided “We have stored the following personal data about you. However, this data has already been transferred to the relevant department for erasure and will be erased once I give my final approval.”) and subsequently—in the context of the present proceedings—states that it no longer possesses any data.In particular, as a person knowledgeable in legal matters (see C.1.), the complainant should have recognized that the simultaneous assertion of requests for access and erasure gave rise to a foreseeable conflict of interest and, according to its “reasonable expectations,” could or should have anticipated that the respondent would delete their personal data after the information was provided on September 7, 2023—see in particular the passage contained in the information provided “We have stored the following personal data about you. However, this data has already been transferred to the relevant department for erasure and will be erased upon my final approval.”) and subsequently—in the context of the present proceedings—states that it no longer possesses any data. Since the complainant explicitly submitted a request for the erasure of their personal data at the same time as a request for access, they themselves have thwarted the fulfillment of their right to access, so that they cannot subsequently invoke any incompleteness of the information provided. The risk of incomplete information resulting from the simultaneous assertion of these claims therefore lies with the complainant in the present case and cannot be attributed to the respondent. The respondent’s course of action—first providing the information upon receipt of the complainant’s request for information and erasure, and then immediately thereafter erasing the relevant data as requested— with the deletion having taken place, in particular, even before a request for a statement was issued by the Data Protection Authority, is consistent with the principle of fairness. The respondent has therefore complied in accordance with the law with its obligation to provide information—which arose directly from the request for information—and the associated obligation of transparency under Article 5(1)(a) of the GDPR.The respondent’s approach—first providing the information requested by the complainant upon receipt of the request for access and erasure, and then immediately deleting the relevant data as requested, notably with the erasure taking place even before the Data Protection Authority issued a request for comments, is consistent with the principle of fairness in processing. The respondent has thus complied with its obligation to provide information—which arose directly from the request for access—and the associated obligation of transparency under article 5(1)(a) of the GDPR in a manner consistent with the law. Consequently, there has been no violation of the complainant’s right of access (Art. 15 in conjunction with Art. 5(1)(a) of the GDPR).Consequently, there has been no violation of the complainant’s right of access (Article 15 in conjunction with Article 5(1)(a) of the GDPR). The decision was rendered in accordance with the ruling. D.2. Regarding the Alleged Violation of the Right to Confidentiality D.2.1 General Remarks on the Right to Confidentiality The fundamental right to data protection enshrined in § 1 of the DSG, pursuant to the first paragraph of which everyone, in particular with regard to respect for their private and family life, has a right to the confidentiality of personal data concerning them, provided there is a legitimate interest in such protection, includes the protection of the data subject against the collection of their data and the disclosure of data collected about them. However, the fundamental right to data protection is not absolute; rather, it may be restricted by certain permissible interventions. The fundamental right to data protection enshrined in Section 1 of the DSG, according to the first paragraph of which every person, in particular with regard to respect for his or her private and family life, has a right to the confidentiality of personal data concerning him or her, provided there is a legitimate interest in such protection, includes the protection of the data subject against the collection of his or her data and the disclosure of data collected about him or her. However, the fundamental right to data protection is not absolute; rather, it may be restricted by certain permissible interventions. Pursuant to § 1(2) of the DSG, restrictions on the right to confidentiality—insofar as the use of personal data is not in the vital interest of the data subject or does not occur with his or her consent— permitted only to safeguard the overriding legitimate interests of another party; in the case of interventions by a government authority, these may occur only on the basis of laws that are necessary for the reasons set forth in Article 8(2) of the ECHR.Pursuant to Section 1, paragraph 2, of the DSG, restrictions on the right to confidentiality—provided that the use of personal data is not in the vital interest of the data subject or does not occur with the data subject’s consent—are permitted only to safeguard the overriding legitimate interests of another person; in the case of interventions by a government authority, these may only be based on laws that are necessary for the reasons set forth in article 8, paragraph 2, of the ECHR. According to Article 4(7) of the GDPR, the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data is the controller. The key criterion here is the decision-making authority.According to Article 4(7) of the GDPR, the controller is the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data. The key criterion here is the decision-making authority. “Processing” means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, retrieval, use, etc. (see Art. 4(2) of the GDPR).“Processing” means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, retrieval, use, etc. See Article 4, paragraph 2, of the GDPR) is understood as processing. However, the GDPR—and in particular the principles enshrined therein—must in any case be taken into account when interpreting the right to confidentiality (see the decision of July 4, 2019, Ref. No.: DPA-D123.652/0001-DPA/2019, RIS).However, the GDPR—and in particular the principles enshrined therein—must in any case be taken into account when interpreting the right to confidentiality; see the decision of July 4, 2019, Ref. No.: DPA-D123.652/0001-DPA/2019, RIS). According to the established case law of the CJEU, any processing of personal data must comply with the principles for data processing set forth in Article 5(1) of the GDPR and must meet the conditions for the lawfulness of processing listed in Article 6 of that Regulation (see, inter alia, judgments of October 6, 2020, La Quadrature du Net et al., C‑511/18, C‑512/18, and C‑520/18, EU:C:2020:791, para. 208; of June 22, 2021, Latvijas Republikas Saeima [Traffic Points], C‑439/19, EU:C:2021:504, para. 96, as well as of October 20, 2022, Digi, C‑77/21, EU:C:2022:805, paras. 49 and 56, and C-60/22, EU:C:2023:373, paras. 56 and 57, dated May 4, 2023). According to the established case law of the CJEU, any processing of personal data must comply with the principles for data processing set forth in article 5(1) of the GDPR and meet the conditions for the lawfulness of processing set forth in article 6 of that Regulation; see, inter alia, judgements of October 6, 2020, La Quadrature du Net et al., C‑511/18, C‑512/18, and C‑520/18, EU:C:2020:791, para. 208; of June 22, 2021, Latvijas Republikas Saeima [Traffic Points], C‑439/19, EU:C:2021:504, para. 96, and of October 20, 2022, Digi, C‑77/21, EU:C:2022:805, paras. 49 and 56, and C-60/22, EU:C:2023:373, paras. 56 and 57, dated May 4, 2023). Consequently, the principles set forth in Article 5 of the GDPR constitute a duty or obligation for the controller, to which the controller is bound, and—according to the CJEU—also impose on the controller the burden of proof regarding compliance (see Article 5(2) of the GDPR and the CJEU judgement in Case C-60/22, paras. 53 and 54).In conclusion, the principles set forth in article 5 of the GDPR constitute a duty or obligation for the controller, to which the controller is bound, and—according to the CJEU—also impose on the controller the burden of proof regarding compliance; see article 5(2), GDPR and the CJEU judgement in Case C-60/22, paras. 53 and 54). It is undisputed that the preliminary investigation revealed that the respondent, as the controller under data protection law pursuant to Article 4(7) of the GDPR, made the decision regarding the purposes and means of the processing. It was therefore the entity that exercised control over the processing of the complainant’s personal data and also had the authority to decide for what purpose and by what means the data processing was to take place.It is undisputed that the investigation revealed that the respondent, as the data controller under Article 4(7) of the GDPR, made the decision on the purposes and means of processing. It was therefore the entity that exercised control over the processing of the complainant’s personal data and also had the authority to determine the purposes and means of such processing. It is also undisputed that the data in question constituted personal data of the complainant within the meaning of Article 4(7) of the GDPR. The retrieval of creditworthiness data from a credit reporting agency—in this case, D*** GmbH—undoubtedly constitutes the processing of the complainant’s personal data.It is also undisputed that this involved the complainant’s personal data within the meaning of article 4(7) of the GDPR. The retrieval of credit information from a credit reporting agency—in this case, D*** GmbH—undoubtedly constitutes the processing of the complainant’s personal data. D.2.2. On the Merits Based on the findings, a previously unknown third party placed an online order with the respondent by misusing the complainant’s personal data. In this context, the respondent, using the data provided by the person placing the order, submitted a request to a credit reporting agency, which resulted in a positive match. The complainant considers this action to be a violation of their right to privacy, as they did not place an online order themselves and did not give consent to the processing of their data. With regard to the lawfulness of the processing, the respondent relies on “the protection of legitimate interests,” which indicates data processing based on Article 6(1)(f) of the GDPR.According to the findings, a previously unknown third party placed an online order with the respondent by misusing the complainant’s personal data. In this context, the respondent, using the data provided by the person placing the order, submitted a request to a credit reporting agency, which resulted in a positive match. The complainant considers this action to be a violation of their right to privacy, as they did not place an online order themselves and did not give consent to the processing of their data. The respondent party bases the lawfulness of the processing on “the protection of legitimate interests,” which indicates data processing pursuant to article 6(1)(f) of the GDPR. It must therefore be examined whether the respondent’s data processing was attributable to it, lacked sufficient justification, and was thus unlawful. The legal basis of “legitimate interests” is relevant. On the Lawfulness of Processing Under Article 6(1)(f) of the GDPROn the Lawfulness of Processing Under Article 6(1)(f) of the GDPR An assessment of the respondent’s legitimate interests must be conducted, taking into account the respondent’s interests as well as the potential consequences for the complainant (as the data subject) in the context of a balancing of interests. Data processing on the legal basis of “legitimate interests” is permissible under three cumulative conditions: i) the controller or the third party(ies) is pursuing a legitimate interest; ii) the processing of personal data is necessary to fulfill the legitimate interest; and iii) the fundamental rights and freedoms of the data subject do not override the legitimate interest being pursued (see, with regard to the comparable legal situation under Directive 95/46/EC, the judgement of the CJEU of December 11, 2019, C-708/18 [TK], para. 40, with further references).Data processing on the legal basis of “legitimate interests” is permissible under three cumulative conditions: i) the controller or the third party(ies) is pursuing a legitimate interest; ii) the processing of personal data is necessary to pursue that legitimate interest; and iii) the fundamental rights and freedoms of the data subject do not override the legitimate interest pursued; see, with regard to the comparable legal situation under Directive 95/46/EC, the judgement of the CJEU of December 11, 2019, C-708/18 [TK], para. 40, with further references). a) On the balancing of interests The complainant has a legitimate interest in the protection of their right to confidentiality pursuant to § 1(1) of the DSG. The complainant has a legitimate interest in the protection of their right to confidentiality pursuant to Paragraph 1, Section 1, of the DSG. With regard to i) the pursuit of a legitimate interest, the respondent has argued that the data processing serves to protect against payment defaults in the case of purchases on account by obtaining a credit report. The respondent has a legitimate interest in verifying the creditworthiness of potential customers and evaluating the risk of non-payment. The credit check enables the respondent to make informed decisions to protect itself against financial losses. The measure serves to prevent payment defaults in purchases on account and to avoid potential economic losses that could result from unpaid receivables. The processing of credit-related data—in this case, the respondent’s retrieval of the complainant’s personal data from the credit bureau D*** GmbH—can be based on Article 6(1)(f) of the GDPR, since minimizing credit risk or safeguarding against payment defaults in the case of a purchase on account by obtaining a credit report can be considered a legitimate interest, and this is the position that the Data Protection Authority represents in its rulings.The processing of credit-related data—in this case, the respondent’s retrieval of the complainant’s personal data from the credit reporting agency D*** GmbH—may be based on article 6, paragraph 1, (f) of the GDPR, since minimizing credit risk or protecting against payment defaults in the case of a purchase on account by obtaining a credit report can be considered a legitimate interest, and this is consistently represented in the Data Protection Authority’s case law. The respondent party thus pursues legitimate interests through the data processing in question. Regarding ii) the necessity of the processing, it should first be noted that this is generally only met to the extent that the processing is appropriate and relevant to the purpose and limited to what is necessary for the purposes of the processing (Art. 5(1)(c) GDPR).Regarding (ii) the necessity of the processing, it should first be noted that this is generally only satisfied to the extent that the processing is appropriate and relevant to the purpose and limited to what is necessary for the purposes of the processing (article 5(1)(c) of the GDPR). Necessity must be assessed from an ex ante perspective, which allows for a certain degree of discretion (see Kastelitz/Hötzendorfer/Tschohl in Knyrim (eds.), DatKomm, Art. 9 GDPR, para. 44).Necessity must be assessed from an ex ante perspective, which allows for a certain degree of discretion (see Kastelitz/Hötzendorfer/Tschohl in Knyrim (ed.), DatKomm, article 9, GDPR, para. 44). Checking creditworthiness using the information provided by the applicant is necessary for a quick and efficient assessment of a potential customer’s creditworthiness in order to take timely action and protect against potential financial risks. This approach is also in line with standard industry practice. Finally, in the opinion of the Data Protection Authority, there were no equivalent, alternative, and less intrusive measures available. At the time the complainant’s personal data was processed, the respondent had no objective grounds that would have justified doubting the identity of the person placing the order. The data provided or used by the unknown person was correct and resulted in a match during the credit check with D*** GmbH, which further confirmed the plausibility of the identity. Nor were there any other grounds to cast doubt on the identity of the person placing the order. In particular, the respondent cannot be accused of inadequate technical or organizational measures. There is no general obligation on controllers to conduct additional identity checks for every online order. In the view of the Data Protection Authority, such an obligation could not be reconciled with either the principle of lawfulness or those of data minimisation or proportionality. Finally, in the opinion of the Data Protection Authority, based on the interests mentioned and explained above, there is no iii) preponderance of the fundamental rights and freedoms of the complainant as the data subject: The complainant’s interest in the confidentiality of their personal data does not, in the context of this proceeding, outweigh the economic interests of the respondent. In this case, therefore, a balancing of the complainant’s rights and freedoms favors the respondent. The respondent has, in principle, chosen a means that is appropriate and proportionate to the legitimate purpose and has thus limited the interference with the complainant’s rights to the necessary minimum. In conclusion, from the perspective of the Data Protection Authority, it should be noted that the identity theft and the violation of the right to confidentiality in the present case are attributable to the unknown third party, but not to the respondent. This constitutes unlawful conduct by a third party that lies outside the respondent’s sphere of influence, and it should be particularly emphasized that the respondent deleted the complainant’s data after becoming aware of the incident and providing the requested information. b) Regarding the information obligations under Article 13 of the GDPR and Article 14 of the GDPRb) Regarding the information obligations under Article 13 of the GDPR and Article 14 of the GDPR In its submission dated January 17, 2024, the complainant further states that the respondent was required to explain the legitimate interests it was pursuing in a manner comprehensible to the complainant at the time of data collection, pursuant to Art. 13 GDPR and Article 14 GDPR, which is why the respondent cannot rely on Article 6(1)(f) GDPR.In a submission dated January 17, 2024, the complainant further states that the respondent was required to explain the legitimate interests it was pursuing in a manner comprehensible to the complainant at the time of data collection, in accordance with Article 13 of the GDPR and Article 14 of the GDPR, which is why the respondent cannot rely on Article 6(1)(f) of the GDPR. In this context, the recent judgement of the CJEU dated January 9, 2025, Case C-394/23, in which the Court stated in paragraph 52, in essence, that in the context of “legitimate interest,” it must be examined whether the controller had informed the data subject of a legitimate interest at the time of collecting the data in question in accordance with Article 13( 1(d) of the GDPR. This provision requires that data subjects be informed directly of the legitimate interest being pursued at the time the data is collected; otherwise, such collection cannot be justified on the basis of Article 6(1)(f) of the GDPR.In this context, the recent judgement of the CJEU of January 9, 2025, Case C-394/23, in which the Court stated in paragraph 52, in essence, that in the context of “legitimate interest,” it must be examined whether the controller informed the data subject, at the time of collecting the data in question, in accordance with article 13(1), (d) of the GDPR. This provision requires that data subjects be informed directly of the legitimate interest pursued at the time the data is collected; otherwise, such collection cannot be justified on the basis of article 6(1)(f) of the GDPR. In this regard, it should be noted that the information obligations under Article 13 and Article 14 of the GDPR logically presuppose that the controller knows whom it must inform and has the appropriate means of contact.In this regard, it should be noted that the information obligations under articles 13 and 14 of the GDPR logically presuppose that the controller knows whom it must inform and has the appropriate means of contact. aa) Regarding the obligation to provide information under Article 13 of the GDPRRegarding the obligation to provide information under Article 13 of the GDPR A prerequisite for the application of Article 13 of the GDPR (“Obligation to provide information when personal data is collected from the data subject”) is that the controller has collected the personal data directly from the data subject (“direct collection”). As can be seen from the findings in C.3., the respondent did not collect the data from the complainant, but rather from a previously unknown third party who had unlawfully assumed the complainant’s identity. Therefore, the respondent did not have an obligation to provide information under Article 13 of the GDPR on its merits.A prerequisite for the application of Article 13 of the GDPR (“Obligation to provide information when collecting personal data from the data subject”) is that the controller has collected the personal data directly from the data subject (“direct collection”). As can be seen from the findings in section C.3., the respondent did not collect the data from the complainant, but rather from a previously unknown third party who had unlawfully assumed the complainant’s identity. Therefore, the respondent was not subject to an obligation to provide information under Article 13 of the GDPR on its very basis. bb) Regarding the obligation to provide information under Article 14 of the GDPRRegarding the obligation to provide information under Article 14 of the GDPR In the present case, the complainant’s personal data was collected not from the complainant but in the context of identity theft related to an online order; consequently, the respondent was, in principle, obligated to provide information pursuant to Article 14 of the GDPR.In the present case, the complainant’s personal data was not collected from the complainant in the context of an identity theft incident related to an online order; consequently, the respondent was, in principle, obligated to provide information pursuant to article 14 of the GDPR. However, pursuant to Article 14(5)(b) of the GDPR, the obligation to provide information does not apply if providing such information proves impossible or would involve a disproportionate effort. However, pursuant to article 14(5)(b) of the GDPR, the obligation to provide information does not apply if providing such information proves impossible or would involve a disproportionate effort. At the time the personal data was collected, from the respondent’s perspective, there was no data subject other than the person placing the order. The complainant, as the true identity holder, is unknown to the respondent, and there is no reliable way to distinguish her from the person placing the order. In particular, the respondent did not have an email address or phone number associated with the complainant. The duty to provide information is therefore objectively impossible to fulfill. No general obligation to actively verify identity in order to fulfill the duty to provide information can be inferred from the GDPR. Such an obligation would effectively force the controller to verify identity without any specific cause, which would violate the general principles of data processing. The respondent’s duty to provide information under Article 14 of the GDPR does not apply in the present case pursuant to Article 14(5)(b) of the GDPR, because the respondent was unable to determine the identity of the complainant as the actual data subject, and providing the information was therefore objectively impossible. The respondent’s obligation to provide information under article 14, GDPR does not apply in the present case pursuant to article 14, paragraph 5, subparagraph b, GDPR, because the identity of the complainant as the actual data subject could not be ascertained by the respondent, and providing such information was therefore objectively impossible. In Conclusion In summary, it must therefore be noted that even if data processing can be based on Article 6(1)(f) of the GDPR, a duty to provide information under Articles 13 and 14 of the GDPR exists only if the requirements of Article 13 GDPR and Article 14 GDPR are met. In summary, it must therefore be noted that even if data processing can be based on Article 6(1)(f) of the GDPR, an obligation to provide information under Articles 13 and 14, GDPR only applies if the requirements of Article 13 and Article 14 of the GDPR are met. In the case of identity theft, Article 13 of the GDPR does not apply, as the data was not collected from the data subject. Although Article 14 of the GDPR applies in principle, the obligation to provide information is waived pursuant to Article 14(5)(b) of the GDPR because the identity of the actual data subject cannot be determined by the controller and providing the information would therefore be objectively impossible.In the event of identity theft, article 13 of the GDPR does not apply, as the data was not collected from the data subject. Although article 14 of the GDPR applies in principle, the obligation to provide information is waived pursuant to article 14, paragraph 5, letter b of the GDPR because the controller cannot determine the identity of the actual data subject, and providing the information would therefore be objectively impossible. The decision was therefore rendered in accordance with the ruling.
How it connects
References
All 37
- Art. 5(1)(a)
- Art. 5(1)(c)
- Art. 5(2)
- Art. 6(1)
- Art. 6(1)(f)
- Art. 13(1)
- Art. 14(5)(b)
- Art. 15(1)
- Art. 15(1)(a)
- Art. 15(1)(c)
- Art. 15(1)(g)
- Art. 15(3)
- Art. 17(1)
- Art. 51(1)
- Art. 57(1)(f)
- Art. 77(1)
- Art. 1
- Art. 4
- Art. 5
- Art. 6
- Art. 9
- Art. 12
- Art. 13
- Art. 14
- Art. 15
- Art. 17
- Art. 77
- CJEU - C-439/19 - Latvijas Republikas Saeima (Penalty points)
- CJEU - C-511/18 - La Quadrature du Net and Others
- UZ v Bundesrepublik Deutschland
- Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság
- TK v Asociaţia de Proprietari bloc M5A-ScaraA