DSB: No processor access violation under Art. 15 GDPR when controller deleted data
On 07. August 2023, the data subject made a request to the processor to provide the report and the questionnaire completed by the data subject at an information event.
Status Not cited by any decision here yet
Original title: DSB (Austria) - DSB-D124.0531/24
Holding
First, the DPA held that the processor had not violated the right to access under Article 15 GDPR as there was no evidence of contractual violations between the processor and the contractor under Article 28(10) GDPR. As defined in Article 4(8) GDPR, the processor processes personal data on behalf of the controller and thereby acts as their "extended arm". The processor is in physical possession of the data and is bound by the controller's directives regarding the purposes and means of the processing. Therefore, the controller is responsible for the actions of the processor if the processor were their own, except in cases where the processor exceeds the defined scope and determines the purposes and means of processing under Article 28(10) GDPR. This concludes to the controller's responsibility to ensure that the data subjects can exercise their rights, with the processor providing support where possible. Second, the DPA held that both the email from 30. September 2023 and the email of 13. January 2024 did constitute information requests under Article 15 GDPR. The data subject simply requested the transmission of information, namely the report and the questionnaire and did not refer to personal data. Third, the DPA held that the disposal of project data during the proceedings constituted a violation of the data subject's right of access under Article 15 in conjunction with Article 5(1)(a) GDPR. The deletion of personal data that is subject to an access request that has already reached the controller violates Article 15 GDPR. This is because the deletion makes it impossible for the DPA to investigate in a possible breach of the access right. However, the deletion of the questionnaire right after the initial interview had happened before the data subject's first email on 08. August 2023 and was thus lawful. Fourth, the DPA held that a right to receive the documents containing processed personal data could not be recognised under Article 15 GDPR in conjunction with Recital 63 GDPR per se, the provision of a copy is just a modality of the access request. It depends on the individual case whether the controller must provide the documents or just a register of the personal data.
From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓
The processor responded to this request, stating that they would receive a final report and that all required documents were provided to the controller. The data subject sent a request to the controller on 30. September 2023, specifically asking for access to personal data, which remained unreplied. The questionnaire had already been deleted at that time. On 13. January 2024, the data subject sent another request to the controller, also asking about the processor's procedure. The controller answered on 23. January 2024 and stated that the questionnaire had already been disposed of and therefore could not be provided. The data subject lodged a complaint with the Austrian DPA (DSB) regarding the withholding of information about their processed data and their deletion despite the processor being aware of an information request, submitted by the data subject on 07. August 2023. During the proceedings, data relating to a project involving the data subject was deleted.
Full text 14 findings
Machine translation of the decision, via GDPRhub — not the official text. Read the original
Text Ref. No.: 2025-0.566.415, dated November 21, 2025 (Case No.: DPA-D124.0531/24) [Processing Officer’s Note: Names and company names, legal forms and product names, addresses (including URLs, IP addresses, and email addresses), case numbers (and similar), statistical data, etc., as well as their initials and abbreviations, may have been shortened and/or altered for pseudonymization purposes. Obvious spelling, grammar, and punctuation errors have been corrected. BBE = Counseling and Support Center] DECISION RULING The Data Protection Authority rules on the data protection complaint filed by Elisabeth A*** (complainant) on February 9, February 2024 against the AMS (first respondent) and against N*** Austria (second respondent) regarding a violation of the right of access as follows:
The complaint is partially upheld, and it is found that the first respondent violated the complainant’s right of access as data concerning the complainant was deleted by the second respondent—who is attributable to the first respondent in its capacity as the controller—while proceedings were pending before the Data Protection Authority.
In all other respects, the complaint against the first respondent is dismissed.
The complaint against the second respondent is dismissed as unfounded due to the respondent’s lack of status as a data controller. Legal basis: Art. 15, Art. 51(1), Art. 57(1)(f), and Art. 77(1) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR), OJ No. L 119 of May 4, 2016, p. 1; §§ 18(1) and 24(1) and (5) of the Data Protection Act (DSG), Federal Law Gazette I No. 165/1999, as amended.Legal basis: Article 15, Article 51(1), Article 57(1)(f), and Article 77(1) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR), Official Journal No. L 119 of May 4, 2016, page 1; Paragraphs 18(1) and 24(1) and (5) of the Data Protection Act (DSG), Federal Law Gazette, Part I, No. 165 of 1999, as amended. STATEMENT OF REASONS A. Arguments of the Parties and Course of Proceedings 1 In a petition initiating proceedings dated February 10, 2024, supplemented on February 25, 2024, the complainant alleged a violation of the right of access. 2 In a letter dated May 10, 2024, the first respondent submitted its position, stating in summary that there is no blanket right to receive electronic copies of documents and that the complainant had failed to demonstrate and prove that the transfer of copies of all attachments listed in the request for information was indispensable for the exercise of her rights. 3 In a letter dated July 23, 2024, the complainant argued, in summary, that the first respondent was misrepresenting the facts.
In a letter dated August 12, 2024, the first respondent submitted its response.
In its disposition dated September 13, 2024, the Data Protection Authority again requested that the first respondent submit comments regarding the email dated September 30, 2023, titled “BBE Information.”
In a letter dated September 16, 2024, the first respondent submitted its comments.
In a letter dated September 18, 2024, the Data Protection Authority again granted the complainant the right to be heard and requested that she also submit, if possible, the email header of the email dated September 30, 2024.
In a letter dated September 19, 2024, the complainant again forwarded the email to the first respondent dated September 30, 2023, along with a screenshot of the extended email information.
In a letter dated October 22, 2024, the second respondent submitted its statement.
In a letter dated February 10, 2025, the second respondent submitted further comments.
In letters dated April 28, 2025, and May 8, 2025, the first respondent submitted comments.
In a letter dated July 15, 2025, the complainant submitted her response to the first respondent’s arguments. B. Subject Matter of the Complaint The subject matter of the complaint is the question of whether the first respondent violated the complainant’s right to access information by failing to disclose the data processed by the second respondent and by deleting such data despite being aware of the access request. Furthermore, the subject matter of the complaint is the question of whether the second respondent violated the complainant’s right to access information by failing to provide her with her personal data in response to her letter dated August 7, 2023. C. Findings of Fact The first respondent is responsible for implementing the federal government’s labor market policy. As a public-law service provider, the AMS contributes to the prevention and elimination of unemployment in Austria within the framework of the federal government’s full-employment policy, on behalf of the Federal Ministry of Labor and with the significant involvement of the social partners. Assessment of the Evidence: The finding in question is based on an ex officio investigation by the Data Protection Authority on the first respondent’s website (https://www.ams.at/) (last accessed on November 20, 2025). The second respondent is an NGO dedicated to promoting employment, education, and the future of women. It is a social-profit organization dedicated to promoting [Editor’s note: Explanation of the initial term used to designate the second respondent has been removed for pseudonymisation purposes], which is oriented toward social benefit and aims to create win-win situations for everyone. It is funded exclusively through project contracts. The first respondent is also among its clients. Assessment of the Evidence: The finding regarding the second respondent is based on an ex officio investigation by the Data Protection Authority on the second respondent’s website at https://www.n***-oesterreich.at/ (last accessed on November 20, 2025). The second respondent acts as a data processor for the first respondent. Assessment of Evidence: The finding is based on the consistent statements made by both the first and second respondents regarding this matter and was not contested by the complainant. The complainant was assigned to the second respondent by the first respondent and was required to fill out a multi-page questionnaire during an informational session. Assessment of the evidence: The finding made is based on the complainant’s submissions, which are undisputed in this regard. On August 7, 2023, the complainant sent the following letter to the second respondent: [Editor’s note: The following email correspondence, originally presented as facsimiles in the form of multiple files in PNG format, has been converted to text and is reproduced here (with the omission of non-essential elements such as footers, graphic elements, logos, etc.) in pseudonymized form.] “From: Lisa A*** Sent: Monday, August 7, 2023 1*:1* To: Theresia R*** Subject: Cancellation” Dear Ms. R***, I am writing to inform you in a timely manner that I will not be able to attend the appointment scheduled for August 10 at 10:00 a.m. Furthermore, I am terminating this BBE, as I do not see any benefit for myself in the appointments held so far. Finally, I request that you forward the report to the AMS, along with the questionnaire I have completed. Sincerely, D. A***” The second respondent replied on August 8, 2023, as follows: “Sent: Tuesday, August 8, 2023, at 1*:5* p.m. From: “Theresia R***” To: “Lisa A***” Subject: RE: Rejection Dear Ms. A***, I confirm receipt of your message. You will receive a final report from us via email; we will forward all necessary documents to the AMS. Sincerely, Theresia R***” On September 30, the complainant sent the following letter to the initial respondent (formatting not reproduced exactly): “Sent: Saturday, September 30, 2023, at 0*:3* a.m. From: "Lisa A***" To: "ams data protection" Subject: BBE Data Disclosure Dear Sir or Madam, I was assigned by the AMS to BBE N*** Frauen aktiv until August 23 I requested, via email, access to my stored data as well as a copy of the questionnaire I filled out at the information session in June 23 The only response I received was: “We perform transfers of all necessary documents to the AMS.” Since you, as BBE’s client, are the controller responsible for its data processing, I request that you provide the outstanding documents and answer the following questions: The BBE’s privacy policy includes the following statement: “All personal data will be deleted 6 months after the end of the project.” How do you ensure that counselors store the CVs of assigned participants exclusively in the “Akt” file, which is deleted after 6 months, and do not reuse them for their own purposes? How do you ensure that additional personal data collected—for example, on signature lists—is deleted? Regarding the Kulturpass: What is the policy for BBE if an issued Kulturpass is not picked up from BBE? Specifically: what did the BBE do with my Kulturpass? I request prompt information and the provision of the relevant documents. Given the short timeframe until erasure, my right to information would otherwise be effectively nullified. Sincerely, D. A***” The first respondent did not provide any information to the complainant in response to the letter dated September 30, 2023. Furthermore, the complainant submitted a request for information to the first respondent in a letter dated January 13, 2024. The first respondent replied to the complainant’s request in a letter dated January 23, 2024, with the following excerpt (formatting not reproduced exactly): “Data Protection Response 2024 01/23/2024 - 1:40 PM From datenschutz wien Full view Dear Ms. A***, Regarding your request for access to data pursuant to Article 15 of the GDPR dated January 3, 2024, we hereby inform you that you will receive the data disclosure from the Regional Office responsible for you at O*** Street.Regarding your request for access to data pursuant to Article 15 of the GDPR dated January 3, 2024, we would like to inform you that you will receive the data from the regional office responsible for you at O*** Street. Regarding your other questions, N*** Austria was asked to provide the following statement: BBE N*** Austria has informed us that your survey form has already been destroyed by N*** Austria, which is why it can no longer be sent to you. We can only provide you with an excerpt from the database (attached). Regarding your inquiry about the signature list on the 5th floor, N*** Austria stated that the signature list is on the consultant’s desk in the open office area. Users sign it when they use the space. The list is kept in a folder inside a locked cabinet in the project coordination office and is destroyed 6 months after the project ends. Although you made the decision not to participate in the project after the information day, you were likely in the Open Space on that day. Since the staff do not know every single participant, you were therefore also asked to sign the list. You did not state that you were not a project participant. In fact, on that day at that time, the list was lying openly on the table. This was because a client was in the Open Space before you, and the counselor was speaking with that client. As a result, she did not notice that the signature list was lying openly on the table. However, this was an exceptional case. The Culture Passes are checked at regular intervals, and any that have not been picked up are destroyed. They may not be handed over to third parties. I hope I have been able to clear up any ambiguities. Sincerely, On behalf of the State Executive Board Mag.a Ulrike W*** “Employment of Foreign Nationals & data protection” Assessment of the Evidence: The findings are based on the parties’ submissions, which are consistent in this regard, as well as the documents submitted by them. The findings regarding the complainant’s email of September 30, 2023, to the first respondent are based on the complainant’s verifiable account. Even though the first respondent states that, due to a complete mail server technology transition on March 15, 2024, it is no longer possible to determine whether the email was received on the first respondent’s mail server, this finding is supported by the email submitted by the complainant and the email header, which substantiate the complainant’s arguments in this regard. In the information provided in January 2024, the first respondent stated the following in connection with the second respondent: “August 18, 2023, training report; the following attachments are available for this document: Name of the Doc.” The document was not attached to the response. Assessment of Evidence: The findings are based on the complainant’s submissions, which have not been contested in this regard. The information provided in January 2024 was not submitted to the Data Protection Authority by the complainant. Assessment of the evidence: The finding made is based on the case file and the documents submitted. The funding agency—in this case, the second respondent—is generally not required to provide the first respondent with all processed data, but only those data that, pursuant to the specific funding regulations, are deemed relevant by the first respondent in relation to the funding agency, namely the data defined in Section 9 of the funding agreement with the funding agency—essentially enrollment and exit data, interim and final reports, resumes, as well as the results of the “JobImpuls method” (personally identifiable data), as well as aggregated data in the so-called interim and final reports submitted to the state office (aggregated data) and, after the project’s conclusion, data still relevant for project accounting (data relating solely to the project).The implementing organization—in this case, the second respondent—is generally not required to transmit all processed data to the first respondent, but only those data that, according to the specific funding provisions agreed upon with the implementing organization, are deemed relevant by the first respondent, namely the data defined in Section 9 of the funding agreement with the implementing organization—essentially enrollment and withdrawal data, interim and final reports, resumes, and the results of the “JobImpuls method” (personally identifiable data), as well as aggregated data in the so-called interim and final reports submitted to the state office (aggregated data) and, after the project’s conclusion, data relevant to project accounting (data related solely to the project). Section 9 of the funding agreement is as follows (formatting not reproduced exactly): Section 9 of the funding agreement is as follows (formatting not reproduced exactly): [Editor’s note: The following excerpt from the grant agreement, which originally appeared as a facsimile in the form of several PNG image files, has been converted to text and is reproduced here (without graphic elements such as borders) in a pseudonymized form.] “§ 9 Reporting (1) Reports to the responsible RGS: The AMS online service “eAMS Account for Enterprises/Services for Partner Institutions,” made available by the AMS on the Internet, must be used. Feedback must be provided to the RGS regarding participation in the mandatory information day/initial consultation to ensure compliance with the reporting deadline (attended/did not attend), as well as notification of the program track the participant is entering. The report templates of the “Joblmpuls Method” must be used as standard. Details regarding reporting can be found in the Service Catalog, Appendix 3 Immediately upon entry into the BBE, the relevant notification is sent via the eAMS account to the RGS. An interim report must be submitted after 4 months, and an individual counseling report must be submitted as the final report after 6 months. If the participant refuses the “Joblmpuls Method,” the form templates for the standardized individual interim report and individual counseling report in their currently valid versions must be used; these are available in the AMS Vienna Download Center at the following link: https://www.ams.at/organisation/partner/ams-partner#wien. The individual interim reports and individual counseling reports must be discussed with the participants by the grant recipient during a personal counseling appointment and handed over to them. If the participant is unreachable by the grant recipient, the AMS will hand over the individual counseling reports. The handover of the individual interim reports and counseling reports—or the reason why they were not handed over—shall be noted in the relevant section of the individual counseling report. Likewise, resumes created during counseling sessions with participants must be submitted to the AMS via the eAMS account. If the participant does not consent to the transmission of this resume, a note shall be included in the individual counseling report stating that a resume was created but the participant did not consent to its transmission. (2) Reports to the LGS: The grant recipient must submit reports to the State Office (LGS), Workforce Services Department (Ms. Mag.a Q***, ludmilla.q***@ams.at, Ms. Mag.a T*** carla.t***@ams.at) by January 15, 2023, and July 15, 2023, as well as no later than one month after the end of the funding period. To do so, the standard “Interim or Final Report” form in its currently valid version must be used; this form is available in the AMS Vienna Download Center. In addition to the interim or final report, the LGS, Department of Workforce Services (Ms. Mag.a Q*** ludmilla.q***@ams.at, Ms. Mag.a T*** carla.t***@ams.at) on a quarterly basis no later than the 15th of the following month (i.e., by October 15, 2022; January 15, 2023; April 15, 2023, July 15, 2023, and October 15, 2023) as well as no later than one month after the end of the funding period. To do so, the “Service Statistics” form in its currently valid version must be used, which is also available in the AMS Vienna download center. For all forms provided on the AMS Vienna website, the currently valid version must be used. Outdated forms will not be accepted. For further explanation, see Appendix A.” In this specific case, the second respondent provided the first respondent with the start and end dates as well as the final report of the potential assessment regarding the complainant. Assessment of the Evidence: The findings made are based on the submissions of the first respondent dated April 28, 2025, and May 8, 2025. The questionnaire that the complainant was required to complete with the second respondent was deleted after the initial interview with the complainant and after the information from the questionnaire had been entered into the database. The data regarding the relevant project was deleted by the second respondent on June 30, 2024. Assessment of the Evidence: The findings set forth herein are based on the complainant’s submissions, which have not been contested in this regard, and on the correspondence submitted by her. D. From a legal perspective, the following conclusions follow: 1 On the allocation of roles under data protection law a) Regarding the First Respondent Pursuant to § 1(1) AMSG, the implementation of the federal government’s labor market policy is the responsibility of the “Labor Market Service,” which is a public-law service provider with its own legal personality. Pursuant to para 2 of the cited provision, the Labor Market Service is organized into a federal organization, state organizations for each federal state, and regional organizations within the federal states. Pursuant to para 3 of the cited provision, the federal organization bears the name “Arbeitsmarktservice Österreich.”Pursuant to Section 1, paragraph 1, of the AMSG, the implementation of the federal government’s labor market policy is the responsibility of the “Labor Market Service,” which is a public-law service provider with its own legal personality. According to paragraph 2 of the aforementioned law, the Labor Market Service is organized into a federal organization, state organizations for each federal state, and regional organizations within the federal states. Pursuant to paragraph 3 of the aforementioned law, the federal organization bears the name “Arbeitsmarktservice Österreich.” First, the Administrative Court examines the issue of sovereign administration in detail and concludes that employment placement and the awarding of subsidies, etc., constitute private-sector administration and do not constitute sovereign activities. The provision of para 1(2) of the Data Protection Act (DSG) regarding state authorities therefore does not apply.First, the Administrative Court (VwGH) examines the issue of sovereign administration in detail and concludes that job placement and the granting of subsidies, etc., constitute private-sector administration and do not constitute sovereign activities. The provision of Section 1(2) of the DSG regarding state authorities therefore does not apply. Pursuant to Section 24(2)(2) of the DSG, the respondent must be named by the complainant. The Data Protection Authority is not authorized to alter such an explicit designation or to substitute the party with whom the complainant wishes to engage in the proceedings for another party not designated by the complainant (see the ruling of the Federal Administrative Court dated January 19, January 2017, Ref. No. W214 2117066-1, with further references). Pursuant to paragraph 24(2)(2) of the Data Protection Act (DSG), the respondent must be designated by the complainant. The Data Protection Authority is not authorized to change such an explicit designation or to substitute the party with which the complainant wishes to engage in the proceedings for another party not designated by the complainant (see the decision of the Federal Administrative Court dated January 19, January 2017, Ref. No. W214 2117066-1, with further references). The determination of the allocation of roles under data protection law is of decisive importance for the complaint proceedings under § 24 DSG or Art. 77(1) GDPR, as it determines who is responsible for compliance with the respective data protection provisions, how the data subject can exercise their rights, and, ultimately, against whom (i.e., which controller) the data protection complaint must be directed (respondent). The determination of the allocation of roles under data protection law is of crucial importance for the complaint procedure under Section 24 of the DSG or article 77, paragraph 1, GDPR, as it makes the decision on who is responsible for compliance with the relevant data protection provisions, how the data subject can exercise their rights, and, ultimately, against whom (i.e., which controller) the data protection complaint must be directed (respondent). However, it is not always reasonable to expect a data subject—who is also not represented by a representative—to independently determine the allocation of roles and responsibilities under data protection law based on the facts of the case and to conclusively identify the respondent in the complaint. This interpretation is also supported by the wording of Section 24(2)(2) of the Data Protection Act (DSG), according to which the respondent need only be identified “to the extent that this is reasonable.”The wording of paragraph 24(2)(2) of the DSG also supports this interpretation, according to which the respondent must be identified only “to the extent that this is reasonable.” Against this background, the complainant’s stated objective must be taken into account, and, in the spirit of an interpretation favorable to the data subject, the complainant’s original submission must be interpreted such that the complaint is directed against the “AMS organization” as the first respondent, and that the complainant, as a resident of Vienna, had dealings with the Vienna Regional Office and therefore incorrectly identified it as the first respondent. b) Regarding the Second Respondent As already explained, determining the allocation of roles under data protection law for the complaint procedure pursuant to Section 24 of the Data Protection Act (DSG) and Article 77(1) of the GDPR is of crucial importance. As previously explained, determining the allocation of roles under data protection law for the complaint procedure pursuant to Section 24 of the DSG or article 77(1) of the GDPR is of crucial importance. According to Article 4(7) of the GDPR, the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data is the controller. The key criterion here is the decision-making authority. The role of the controller thus arises primarily from the fact that a specific entity has made a decision to process personal data for its own purposes. The “purpose” describes an expected result, while the “means” define the manner in which the expected result is to be achieved (see the EDPB Guidelines of September 2, September 2020 07/2020 on the Concept of the Controller and Processor, para. 15 et seq.).According to Article 4(7) of the GDPR, the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data is the controller. The key criterion here is the decision-making authority. The role of the controller thus arises primarily from the fact that a specific entity has made a decision to process personal data for its own purposes. The “purpose” describes an expected result, while the “means” define the manner in which the expected result is to be achieved; see the EDPB Guidelines dated September 2, September 2020, No. 07 of 2020, on the concept of the controller and processor, para. 15 et seq.). A processor, as defined in Article 4(8) of the GDPR, is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller. The core of the processor’s activity is to process personal data on behalf of the controller as the latter’s “extension.” Although the processor exercises physical control over the processing operation, it does not itself make the decisions regarding the purposes and means of the processing. Rather, the processor acts in accordance with the controller’s instructions and without any discretion in evaluation or decision-making. In return, the controller must accept responsibility for the processor’s actions as if the processor were part of its own enterprise. As the “master of data processing,” the controller bears sole responsibility for this, with the exception of a breach of contract (pursuant to Art. 28(10) GDPR) (see Martini in Paal/Pauly, General Data Protection Regulation, Art. 28, para. 2).A processor, as defined in article 4(8) of the GDPR, is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller. The core of the processor’s activity is to process personal data on behalf of the controller as the controller’s “extension.” Although the processor exercises physical control over the processing operation, it does not itself make the decisions regarding the purposes and means of the processing. Rather, the processor acts in accordance with the instructions of the controller and without any independent discretion or decision-making authority. In return, the controller must accept responsibility for the actions of the processor as if the latter were part of its own enterprise. As the “master of data processing,” the controller bears sole responsibility for this, with the exception of a breach of the contract (pursuant to Article 28(10) of the GDPR); see Martini in Paal/Pauly, General Data Protection Regulation, Article 28, paragraph 2). Under Article 29 of the GDPR, a service provider acting under a contract is bound by instructions. Therefore, it does not carry out the processing for the client (controller) as a third party within the meaning of Article 4(10) of the GDPR. Rather, there is an “internal relationship” between the controller placing the order and its processor. The processing carried out by the processor is therefore generally attributed to the controller. Under article 29 of the GDPR, a service provider acting under a contract is bound by the controller’s instructions. Therefore, the service provider does not carry out the processing for the client (controller) as a third party within the meaning of Article 4(10) of the GDPR. Rather, there is an “internal relationship” between the controller who places the order and its processor. The processing carried out by the processor is therefore generally attributed to the controller. Furthermore, Article 28 of the GDPR expressly provides for the legal concept of the processor: Furthermore, Article 28 of the GDPR expressly provides for the legal concept of the processor: According to Article 4(8) of the GDPR, the processor processes personal data on behalf of the controller. Recital 81 of the Regulation states that a processor carries out data processing on behalf of the controller, meaning that the processor is the “extension” of the controller.According to article 4(8) of the GDPR, the processor processes personal data on behalf of the controller. Recital 81 of the Regulation states that a processor carries out data processing on behalf of the controller, meaning that the processor is the “extension” of the controller. Based on the aforementioned provisions, the Federal Administrative Court (BVwG) has already ruled that data processing by a processor is to be regarded as part of the processing carried out by the controller itself (see the BVwG ruling of October 20, 2021, Ref. No. W211 2231475-1; see also the EDPB Guidelines 07/2020 on the terms “controller” and “processor” in the GDPR, Version 2.0, adopted on July 7, July 2021, para. 80, according to which the lawfulness of data processing by the processor derives from the activities of the controller).Based on the aforementioned provisions, the Federal Administrative Court (BVwG) has already ruled that data processing on behalf of a controller is to be regarded as part of the processing carried out by the controller itself; see the BVwG decision of October 20, 2021, Ref. No. W211 2231475-1; see also the EDPB Guidelines 07 from 2020 on the terms “controller” and “processor” in the GDPR, Version 2.0, adopted on July 7, July 2021, para. 80, according to which the lawfulness of data processing by the processor is derived from the activities of the controller). Even in the case of data processing on behalf of a controller, the controller remains the addressee of the data subject rights under data protection law and must ensure that data subjects can effectively exercise their rights. In this regard, however, the controller is supported by the processor to the extent possible. Pursuant to Article 28(3)(e) of the GDPR, it must be ensured that the data processor “in light of the nature of the processing, supports the controller, where possible, with appropriate technical and organizational measures to fulfill the controller’s obligation to respond to requests for the exercise of the data subject’s rights referred to in Chapter III.” However, this provision refers only to supporting the controller. Pursuant to article 28, paragraph 3, subparagraph e, GDPR, it must be ensured that the processor “in light of the nature of the processing, supports the controller, where feasible, with appropriate technical and organizational measures to enable the controller to fulfill its obligation to respond to requests for the exercise of the data subject’s rights referred to in Chapter III.” However, this provision refers only to the support of the controller. Likewise, it is already clear from the plain language of Article 15 of the GDPR that access requests must be addressed to the controller. The obligation to provide information under Article 15 of the GDPR therefore applies only to those who qualify as controllers (“The data subject has the right to obtain from the controller confirmation as to …”).Likewise, it is already clear from the plain language of article 15 of the GDPR that access requests must be addressed to the controller. The obligation to provide information under Article 15 of the GDPR therefore applies only to a person who qualifies as a controller (“The data subject has the right to obtain from the controller confirmation as to whether …”). There is no evidence to suggest that the second respondent breached its obligations under the data processing agreement or that it is an is a (separate) controller; nor was this asserted by the complainant. There is no evidence to suggest that the second respondent breached its obligations under the data processing agreement and that it is a (separate) controller pursuant to Article 28(10) GDPR, is an (independent) controller; nor has the complainant made such a claim. The complaint against the second respondent was therefore dismissed due to the lack of controller status. 2 Regarding the right of access under Article 15 of the GDPR Regarding the right of access under Article 15 of the GDPR a) General Pursuant to Article 15(1) of the GDPR, the data subject has the right to request confirmation from the controller as to whether personal data concerning the data subject is being processed and, if so, the data subject has the right to access such personal data and to receive the information specified in Article 15(1)(a) through (h) of the GDPR. Pursuant to Article 15, paragraph 1, GDPR, the data subject has the right to request confirmation from the controller as to whether personal data concerning him or her is being processed and, if so, the data subject has the right to access such personal data and to receive the information specified in Article 15, paragraph 1, (a) through (h) of the GDPR. The right of access under Article 15 of the GDPR serves as a tool that enables a data subject to become aware of the processing carried out by a controller and to verify the lawfulness of the processing (see Recital 63, first sentence, of the GDPR). In other words, the right of access allows the data subject to gain insight into the “whether and how” of the processing (see Paal in Paal/Pauly [eds.], Commentary on the General Data Protection Regulation, Art. 15, Margin Note 3).The right of access under Article 15 of the GDPR serves as a tool that enables a data subject to become aware of the processing carried out by a controller and to verify the lawfulness of the processing (see Recital 63, first sentence, of the GDPR). In other words, the right of access allows the data subject to gain insight into “whether and how” the data is being processed (see Paal in Paal/Pauly [eds.], Commentary on the General Data Protection Regulation, article 15, para. 3). On the Frequency and Excessiveness of Access Requests Under Article 12 of the GDPR, requests for information under Article 15 may only be refused (see Article 12(5)(b) of the GDPR) if they are “excessive”—particularly in the case of frequent repetition. The dividing line, therefore, lies in the abusive exercise of a right. Admittedly, “very frequent” is sometimes a flexible term (see Illibauer in Knyrim, DatKomm Art. 12 GDPR, para. 68 et seq.). The GDPR does not contain a provision such as the former Section 26(6) of the DSG 2000, under which access had to be granted pro-bono once a year, provided the request concerned the “current data set.”Under Article 12 of the GDPR, access requests under Article 15 may be refused (see Article 12(5)(b) of the GDPR) only if they are “excessive”—particularly in the case of frequent repetition. The dividing line, therefore, is the abusive exercise of a right. Admittedly, “very frequently” is sometimes a flexible term (see Illibauer in Knyrim, DatKomm, article 12 of the GDPR, margin note 68 et seq.). The GDPR does not contain a provision such as the former Section 26(6) of the DSG 2000, which provided that information had to be provided pro-bono once a year, provided the request concerned the “current data set.” According to Recital 63, Sentence 1, the right of access must be exercisable at “reasonable intervals,” and the assessment of whether frequent repetitions or excessive requests for access can be expected according to prevailing opinion, on how dynamic the data set is and thus how frequently changes are to be expected (see OLG Vienna
R 48/24t of June 10, 2024).According to Recital 63, sentence 1, the right of access must be exercisable at “reasonable intervals,” and the assessment of whether frequent repetitions or excessive requests for information can be assumed according to prevailing opinion, on how dynamic the data set is and, consequently, how frequently changes are to be expected (see Higher Regional Court of Vienna 14 R 48/24t dated June 10, 2024). If the right of access is exercised with disproportionate frequency or if the request for access is manifestly unfounded, the controller may, pursuant to Art. 12(5) of the GDPR, charge a reasonable fee or refuse to provide the information, in which case the controller must provide evidence that the request is unfounded or disproportionate (see Specht in Sydow [ed.], European General Data Protection Regulation. Commentary. Art. 15, para. 7). If the right of access is exercised with disproportionate frequency or if the request for access is manifestly unfounded, the controller may, pursuant to Article 12, paragraph 5, GDPR, charge a reasonable fee or refuse to provide the information, in which case the controller must demonstrate that the request is unfounded or disproportionate (see Specht in Sydow [ed.], General Data Protection Regulation. Commentary. Article 15, Marginal Note 7). c) Regarding Requests for Access In an email dated August 7, 2023, the complainant requested that the second respondent “provide the report to the AMS as well as the questionnaire completed by [her].” This email was demonstrably received by the second respondent, as she replied to it on August 8, 2023, though without forwarding the completed questionnaire. However, from the Data Protection Authority’s perspective, the complainant’s email in question only contains a “request for transmission,” but does not constitute a request under Article 15 of the GDPR.In an email dated August 7, 2023, the complainant requested that the second respondent “forward the report to the AMS as well as the questionnaire completed by [her].” This email was verifiably received by the second respondent, as she replied to it on August 8, 2023, though without transmitting the completed questionnaire. However, from the perspective of the Data Protection Authority, the complainant’s email in question only contains a “request for transmission,” but does not constitute a request under article 15 of the GDPR. When assessing whether a request recognizable to the controller as pertaining to a specific right under the GDPR exists, the request must be examined based on its content, applying the same standard that applies to unilateral declarations of intent under private law. Accordingly, the wording and meaning of the declaration must be considered from an objective perspective—namely, as the recipient could have understood it based on its wording and purpose upon objective examination (see BVwG, May 3, 2018, W256 2190554-1, regarding requests for information under § 26 DSG 2000 and concerning interpretation with reference to the case law of the Supreme Court, such as OGH 15.9.1999, 9 ObA 148/99a).When assessing whether a request exists that is recognizable to the controller as a specific right under the GDPR, the request must be examined based on its content, applying the same standard that applies to unilateral declarations of intent under private law. Accordingly, the wording and meaning of the declaration must be considered from an objective perspective—namely, as the recipient could have understood it based on its wording and purpose upon objective examination (see BVwG, May 3, 2018, W256 2190554-1, regarding the request for information under Section 26 of the Data Protection Act 2000 (DSG 2000) and concerning the interpretation with reference to the case law of the Supreme Court (OGH), such as OGH, September 15, 1999, 9 ObA 148/99a). The complainant’s email to the second respondent contains no indication, either in the subject line or in the text, that the letter in question constitutes an access request under data protection law. Rather, the complainant requests that the report be forwarded to the AMS, along with the questionnaire. Viewed from the recipient’s perspective, the letter dated August 7, 2023, therefore cannot be interpreted as a request for information under data protection law (see, in this context, regarding the previous legal situation, the DSK’s decision of October 22, 2008, K121.386/0009-DSK/2008, according to which not every request for unspecified information or for the production of documents must necessarily be regarded as a request for access under data protection law) and, from a data protection perspective, it is therefore not necessary to further examine in a complaint proceeding whether the second respondent, as a data processor, should have handled the letter differently.Viewed from the recipient’s perspective, the letter dated August 7, 2023, cannot therefore be interpreted as a request for information under data protection law; in this context, compare—with regard to the previous legal situation—the DSK’s decision of October 22, 2008, K121.386/0009-DSK/2008, according to which not every request for unspecified information or for the disclosure of documents must necessarily be regarded as a request for information under data protection law) and therefore, from a data protection perspective, there is no need to further examine in complaint proceedings whether the second respondent, as a data processor, should have handled the letter differently. As established, on September 30, 2023, the complainant sent an email with the subject line “BBE Data Access” to the first respondent, requesting information therein. This therefore constitutes a request for information within the meaning of Article 15 of the GDPR, to which the first respondent did not provide any information.As established, on September 30, 2023, the complainant sent an email with the subject line “BBE Data Disclosure” to the first respondent, requesting information. This therefore constitutes a request for information within the meaning of article 15 of the GDPR, to which the first respondent did not provide any information. Furthermore, in a letter dated January 13, 2024, the complainant submitted a request for information to the first respondent, to which the latter replied in a letter dated January 23, January 2024, stating in part that the second respondent had informed them that the questionnaire had already been destroyed, which is why it could no longer be provided. d) Regarding the Alleged Incompleteness In the submission dated February 9, February 2024, which forms the subject matter of the proceedings, the complainant objected to incomplete information and specified in this regard that the data processed by the second respondent was missing and had been deleted despite knowledge of the access request. As noted, the funding agency (the second respondent) is not generally required to transmit all processed data to the first respondent, but only that data which, in accordance with the specific funding regulations governing the relationship with the funding agency, is deemed relevant by the first respondent, namely the data defined in Section 9 of the funding agreement with the funding agency—essentially enrollment and withdrawal data, interim and final reports, a resume, as well as the results of the “JobImpuls method” (personally identifiable data) as well as aggregated data in the so-called interim and final reports submitted to the state office (aggregated data) and, after the project’s conclusion, data relevant to project accounting (data pertaining solely to the project).As noted, the funding agency (the second respondent) is generally not required to transmit all processed data to the first respondent, but only that data which, according to the specific funding provisions with the funding agency, is deemed relevant by the first respondent, namely the data defined in Section 9 of the funding agreement with the funding agency—essentially enrollment and exit data, interim and final reports, résumés, as well as the results of the “JobImpuls method” (personally identifiable data) as well as aggregated data in the so-called interim and final reports submitted to the state office (aggregated data) and, after the project’s conclusion, data relevant to project accounting (data related solely to the project). As explained above under “On the Allocation of Roles under Data Protection Law,” in the present case, the second respondent acts as a data processor for the first respondent, and the processing of personal data by the second respondent is therefore attributable to the first respondent. In this specific case, the second respondent provided the first respondent with the start and end dates as well as the final report of the potential assessment concerning the complainant. The data relating to the corresponding project was deleted by the second respondent on June 30, 2024—thus during the ongoing investigation by the Data Protection Authority. In contrast, as can be seen from the findings of fact, the survey form was deleted as early as after the initial interview between the second respondent and the complainant regarding the BBE. Since the complainant informed the second respondent via email on August 8, 2023, that she was terminating the BBE, the initial meeting must have taken place before August 8, August 2023, and it follows from this that the questionnaire had already been deleted before the complainant’s request for information dated September 30, 2023, to the first respondent. Even though the GDPR and the DSG—unlike the previous legal situation under the DSG 2000—no longer explicitly prohibit the deletion of personal data upon becoming aware of a request for information, the Data Protection Authority maintains in its consistent case law (see, for example, the Data Protection Authority’s decision of June 27, 2019, Ref. No.: DSB-D124.071/0005-DSB/2019, available in the RIS), that the practice of deleting the data in question upon receipt of a request for access and subsequently issuing a negative response may constitute a violation of the principle of fairness in processing and, consequently, a violation of the data subject’s right of access (Art. 15 in conjunction with Art. 5(1)(a) of the GDPR). The same applies to the erasure of personal data of the applicant that has not yet been disclosed and which is being processed by the controller. Even if the controller makes the representation that it is not required to disclose certain data or, within the meaning of Art. 15(3) GDPR, certain documents, erasure is precluded by the right to access while a request for access is pending or, in particular, during ongoing proceedings before the Data Protection Authority, since such erasure would prevent the Data Protection Authority from determining whether access to that data was lawfully denied.Even though the GDPR and the DSG—unlike the previous legal situation under the DSG 2000—no longer explicitly prohibit the erasure of personal data upon becoming aware of a request for access, the Data Protection Authority represents the Data Protection Authority in its consistent decision-making practice—see, for example, the Data Protection Authority’s decision of June 27, 2019, Ref. No.: DPA-D124.071/0005-DPA/2019, available on RIS), that the practice of deleting the data in question upon receipt of a request for access and subsequently issuing a negative response may constitute a violation of the principle of processing with fairness and, consequently, an infringement of the data subject’s right of access (article 15, in conjunction with article 5, paragraph 1, subparagraph (a) of the GDPR). The same applies to the erasure of the applicant’s personal data that has not yet been disclosed and which the controller is processing. Even if the controller represents the view that it is not required to disclose certain data or, within the meaning of Article 15(3) of the GDPR, certain documents, erasure is precluded by the right to access while a request for access is pending or, in particular, during ongoing proceedings before the Data Protection Authority, since such erasure would prevent the Data Protection Authority from assessing whether access to this data was lawfully denied. The erasure of data to which the specific access request—which is the subject of the complaint—relates during an ongoing investigation before the Data Protection Authority thus constitutes a violation of the law, and the complaint was accordingly granted in this regard. e) Regarding the Disclosure of Documents Following a request from the Data Protection Authority to remedy deficiencies, the complainant stated in a letter dated February 25, 2025, that the information comprised 100 pages and had been provided in paper form; she therefore would not transmit it. Specifically, the issue concerns documents that were not transmitted but were merely listed in the response under a heading. She provided a concrete example of this. The authority should therefore request a statement from the initial respondent regarding this practice. In order to comply with the requirement for transparent information within the meaning of Art. 15 of the GDPR, it may sometimes be necessary and appropriate in individual cases for the controller to also provide the data subject with individual text passages or documents. However, a general right to receive documents in which personal data is processed cannot be derived from Article 15 of the GDPR (see Recital 63 of the GDPR, the judgement of the CJEU of December 20, December 2017 in Case C-434/16, and the ruling of the Federal Administrative Court (BVwG) dated September 23, 2020, Case No. W256 2226269-1/13E).In order to comply with the requirement for transparent information within the meaning of Article 15 of the GDPR, it may sometimes be necessary and appropriate in individual cases for the controller to provide the data subject with specific text passages or documents. However, a general right to receive documents in which personal data is processed cannot be derived from Article 15 of the GDPR; see Recital 63 of the GDPR, the judgement of the CJEU of December 20, December 2017 in Case C-434/16, and the ruling of the Federal Administrative Court (BVwG) dated September 23, 2020, in Case No. W256 2226269-1/13E). In Case C-487/21, which concerned the interpretation of Article 15(3) of the GDPR, the Court of Justice of the European Union (CJEU) ruled that Article 15(3) of the GDPR cannot be interpreted in such a way as to grant the data subject an independent—and thus additional—right beyond the right provided for in Article 15(1) of the GDPR (see the CJEU judgement of May 4, 2023, in Case C-487/21, paras. 29–32). Accordingly, article 15(3) of the GDPR merely governs the form in which information is provided. In Case C-487/21, which concerned the interpretation of article 15(3) GDPR, the CJEU addressed the question of whether Article 15(3) of the GDPR could be interpreted in such a way that the data subject is granted a separate—and thus additional—right distinct from the right under Article 15(1) an independent—and thus additional—right, see the CJEU judgement of May 4, 2023, in Case C-487/21, paras. 29–32). Accordingly, article 15(3) of the GDPR merely governs the form in which information is provided. The Administrative Court represents this legal view (see the decision of August 3, 2023, in Case No. Ro 2020/04/0035-5, para. 26). Article 15(3), first sentence, of the GDPR is therefore to be understood as meaning that Article 15(3), first sentence, of the GDPR is merely a provision governing the form of the information provided—a procedural requirement intended to ensure, where necessary, that the information to be provided is conveyed in an understandable Art and, if it proves indispensable for the provision of information pursuant to para 1 and para 2, it may be necessary in individual cases to provide the data subject with a faithful and understandable reproduction of all personal data.Article 15, paragraph 3, sentence 1 of the GDPR is therefore to be understood as meaning that Article 15, paragraph 3, sentence 1 of the GDPR merely concerns a provision regarding the form of notification—a method of providing information intended to ensure, where necessary, that the information to be provided is communicated in an understandable Art, and if it proves indispensable for the provision of information in accordance with paragraphs 1 and 2, it may be necessary in individual cases to provide the requester with a faithful and understandable reproduction of all personal data. Applied to the present case, this means the following: In principle, the controller—in this case, the first respondent—must structure the procedures for providing information in such a way that, for the data subject —in this case, the complainant—can contextualize the processed personal data and understand the information in a transparent and comprehensible manner (see Judgement of the CJEU of May 4, 2023, C-487/21, para. 41; and the Opinion of Advocate General Pitruzella of December 15, 2022, in Case C-487/21, paras. 57 and 58).In principle, the controller—in the present case, the first respondent—must structure the procedures for providing information in such a way that, for the data subject —in the present case, the complainant—can contextualize the processed personal data and understand the information in a transparent and comprehensible manner (see Judgement of the CJEU of May 4, 2023, C-487/21, para. 41; and the Opinion of Advocate General Pitruzella of December 15, 2022, in Case C-487/21, paras. 57 and 58). Thus, for the purpose of contextualization, it may very well be necessary to provide a faithful and comprehensible reproduction of all personal data; and the right of access is precisely about ensuring that the data subject receives a complete overview of the data in an understandable form, i.e., in a form that enables the data subject to become acquainted with this data and to verify whether it is accurate and being processed in a manner that is lawful, so that the data subject may, under certain circumstances, exercise their other data subject rights (see the judgement of the CJEU of July 17, 2014, C‑141/12 and C‑372/12 [YS, MS, et al.] para. 59, still with reference to Directive 95/46/EC; see also the decision of the Data Protection Authority dated January 2, 2014, Ref. No. DSB-K122.027/0001-DSB/2014).Thus, for the sake of contextualization, it may well be necessary to provide a faithful and comprehensible reproduction of all personal data, and the right of access is precisely about ensuring that the data subject receives a complete overview of the data in an understandable form, i.e., in a form that enables them to become acquainted with this data and to verify whether it is accurate and being processed in a lawful manner, so that they may, under certain circumstances, exercise their other data subject rights; see the judgement of the CJEU of July 17, 2014, C‑141/12 and C‑372/12 [YS, MS et al.] para. 59, still with reference to Directive 95/46/EC; see also the decision of the Data Protection Authority dated January 2, 2014, Ref. No. DSB-K122.027/0001-DSB/2014). The first respondent’s argument that it is solely the complainant’s responsibility to demonstrate why the disclosure of the documents is necessary for the information to be comprehensible cannot therefore be accepted; rather, it is precisely the responsibility of the controller to provide comprehensible and complete information. However, in order to enable the Data Protection Authority to verify the completeness and comprehensibility of the information provided, it is necessary to submit the information at issue in the proceedings—or at least the parts of the information that are the subject of the complaint—to the Data Protection Authority, since only by having knowledge of the information provided can it be reviewed for any deficiencies. In the present case, however, the information was not transmitted to the Data Protection Authority. Pursuant to Art. 57(1)(f) GDPR, the Data Protection Authority must investigate the subject matter of the complaint to a reasonable extent. The “subject matter of the complaint” is the administrative matter defined in scope by the party’s submission when filing the application—in this case, when filing the complaint—which constitutes the “matter under consideration” pursuant to Section 59(1) of the Administrative Procedure Act (AVG). Pursuant to article 57(1)(f) of the GDPR, the Data Protection Authority must investigate the subject matter of the complaint to an appropriate extent. The “subject matter of the complaint” is the administrative matter whose scope is defined by the party’s submissions at the time of filing the application—in this case, when lodging the complaint—and which constitutes the “matter under consideration” pursuant to Paragraph 59(1) of the Administrative Procedure Act (AVG). The Federal Administrative Court has already ruled on several occasions that the subject matter of a complaint proceeding before the Data Protection Authority—because it is bound by the application—must be limited to the arguments put forward by the respective complainant, and that in determining the legal nature and content of the complaint, it is not the designation but rather the content, that is, on the objective that can be identified and inferred from it (see, for example, the Federal Administrative Court’s decision of October 15, 2021, Case No.: W211 2233114-1/9E). Based on a review of the case law of the Administrative Court, according to which the appellant must assert and specify the relevant circumstances in their favor in a conclusive manner (VwGH April 25, 2001, 99/10/0055; December 16, 2002, 2000/10/0171) and to substantiate them (see also VwGH June 8, 2000, 99/20/0092, VwGH June 7, 2000, 96/03/0340) in order to enable the authority to conduct an investigation into whether these assertions are accurate (VwGH June 8, 1993, 92/08/0212; June 27, 1997, 96/19/0256), it follows that it is the complainant’s responsibility to clearly set forth the subject matter of the complaint; and if she considers her right to access information to have been violated by the disclosure of documents merely in the form of a list with a heading, she must enable the Data Protection Authority—by providing at least the relevant portions of the information or by specifying exactly which data were disclosed—to conduct an examination and assess the completeness and comprehensibility of the information.The Federal Administrative Court has already ruled on multiple occasions that the subject matter of an appeal proceeding before the Data Protection Authority—because it is bound by the application—must be limited to the arguments raised by the respective complainant, and that in determining the legal nature and content of the complaint, what matters is not the designation but rather the content, that is, on the objective that can be discerned and inferred from it—see, for example, the Federal Administrative Court’s decision of October 15, 2021, Case No.: W211 2233114-1/9E). Based on a review of the case law of the Administrative Court, according to which the appellant must assert and specify the relevant circumstances in their favor in a conclusive manner (VwGH April 25, 2001, 99/10/0055; December 16, 2002, 2000/10/0171)—see also VwGH June 8, 2000, 99/20/0092, VwGH June 7, 2000, 96/03/0340) in order to enable the authority to conduct an investigation into whether these claims are true (VwGH June 8, 1993, 92/08/0212; June 27, 1997, 96/19/0256), it follows that it is the complainant’s responsibility to clearly set forth the subject matter of the complaint; and if the complainant considers that her right to access information has been violated by the disclosure of documents merely in the form of a list with a heading, she must enable the Data Protection Authority—by performing at least one transfer of the relevant portions of the information or by specifying exactly which data were disclosed—to conduct a review and assess the completeness and comprehensibility of the information. The assertion that the information is not being provided due to its size and that it concerns documents (which are not specified by name, subject matter, or any other precise criteria) is not sufficient to conclusively set forth and specify relevant circumstances and amounts, rather, to “exploratory evidence,” which the authority is not obligated to consider (see the decision of the Administrative Court of January 3, 2018, Ra 2017/11/0207). The reference to the fact that the information is not being provided due to its size and that it concerns (neither named nor at least specified by subject matter or otherwise more precisely identified) is not sufficient to present and specify relevant circumstances in a conclusive manner; rather, it amounts to “evidence for the sake of inquiry,” which the authority is not obligated to consider (see the decision of the Administrative Court [VwGH] dated January 3, 2018, Ra 2017/11/0207). The decision in this matter was made in accordance with the ruling.