Skip to content
Enforcement · DSB ·DSB-D124.5337 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

DSB-D124.5337

Status Not cited by any decision here yet

Austria

Full text 110 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

Text Ref. No.: 2023-0.273.912 dated October 6, 2023 (Case No.: DPA-D124.5337) [Processing Officer’s Note: Names and company names, legal forms and product names, addresses (including URLs, IP addresses, and email addresses), case numbers (and the like), statistical data, etc., as well as their initials and abbreviations, may have been shortened and/or altered for pseudonymization purposes. Obvious spelling, grammar, and punctuation errors have been corrected. DECISION RULING The Data Protection Authority makes a decision on the data protection complaint filed on November 26, with representatives of Dr. Erich A*** and the B***labor GmbH, both of whom are represented by U*** Rechtsanwalts GmbH, November 2021 against 1) M*** Verlagsgesellschaft m.b.H. (first respondent), with P*** Rechtsanwälte KG acting as its representative, and 2) the N*** Broadcasting Company (second respondent), represented by L*** Rechtsanwälte GmbH, regarding violations of 1) the right to erasure, 2) the right of access, and 3) the right to confidentiality, as follows: I. The second appellant’s complaint against the respondents regarding a violation of the right to erasure is dismissed.

§

The first complainant’s complaint against the first respondent regarding a violation of the right to access is partially granted, and it is determined that the first respondent violated the first complainant’s right to access by failing to provide information regarding the following processed personal data of the first complainant: a. specifically processed (master) data (Art. 15(1), second sentence, GDPR); specifically processed (master) data (Article 15, paragraph 1, second sentence, GDPR); b. the purposes of the data processing (Art. 15(1)(a) GDPR); the purposes of the data processing (Article 15, paragraph 1, subparagraph (a), GDPR); c. the categories of personal data being processed (Art. 15(1)(b) GDPR); the categories of personal data being processed (Article 15, paragraph 1, subparagraph (b), GDPR); d. recipients or categories of recipients (Art. 15(1)(c) GDPR); recipients or categories of recipients (Article 15, paragraph 1, subparagraph (c), GDPR); e. if possible, the planned period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period (Art. 15(1)(d) GDPR).if possible, the planned period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period (article 15(1)(d) of the GDPR).

III

§

Roman numeral three. The first respondent is ordered to provide the first complainant with the following information within a period of four weeks, subject to enforcement if not complied with: a. the specific (master) data being processed (Article 15(1), second sentence, GDPR); the specific (master) data being processed (Article 15(1), second sentence, GDPR); b. the purposes of the data processing (Art. 15(1)(a) GDPR); the purposes of the data processing (Article 15, paragraph 1, subparagraph (a) of the GDPR); c. the categories of personal data being processed (Art. 15(1)(b) GDPR); the categories of personal data being processed (Article 15(1)(b) GDPR); d. recipients or categories of recipients (Art. 15(1)(c) GDPR); recipients or categories of recipients (Article 15, paragraph 1, subparagraph (c), GDPR); e. if possible, the envisaged period for which the personal data will be stored, or, if that is not possible, the criteria used to determine that period (Art. 15(1)(d) GDPR).if possible, the planned period for which the personal data will be stored, or, if this is not possible, the criteria for determining that period (Article 15(1)(d) of the GDPR).

§

IV. Roman numeral four. The complaint filed by the Second Complainant against the First Respondent regarding a violation of the right of access is granted, and it is determined that the First Respondent violated the Second Complainant’s right of access by failing to respond to her request in this regard. V. Roman numeral five. The first respondent is ordered to comply with its obligation to respond to the second complainant within a period of four weeks, failing which enforcement measures will be taken, in accordance with Art. 12, para. 3, Article 15(1) of the GDPR in conjunction with Section 1(3)(1) of the DSG.The first respondent is ordered to comply with its obligation to respond to the second complainant within a period of four weeks, subject to enforcement if it fails to do so, pursuant to article 12, paragraph 3, article 15, paragraph 1, GDPR in conjunction with § 1(3)(1) of the DSG.

§

VI. (Roman numeral six). The complaint filed by the first complainant against the second respondent regarding a violation of the right of access is partially upheld, and it is determined that the second respondent violated the first complainant’s right of access by failing to provide information regarding the following processed personal data of the first complainant: a. specifically processed (master) data (Art. 15(1), second sentence, GDPR); specifically processed (master) data (Article 15, paragraph one, second sentence, GDPR); b. the purposes of the data processing (Art. 15(1)(a) GDPR); the purposes of the data processing (Article 15, paragraph 1, subparagraph (a), GDPR); c. the categories of personal data being processed (Art. 15(1)(b) GDPR); the categories of personal data being processed (Article 15, paragraph 1, subparagraph (b), GDPR); d. recipients or categories of recipients (Art. 15(1)(c) GDPR); recipients or categories of recipients (Article 15, paragraph 1, subparagraph (c), GDPR); e. if possible, the planned period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period (Art. 15(1)(d) GDPR).if possible, the planned period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period (Article 15, paragraph 1, subparagraph d, GDPR).

VII

§

Roman numeral seven. The second respondent is ordered to provide the first complainant with the following information within a period of four weeks: a. the specific (master) data being processed (Article 15(1), second sentence, of the GDPR); the specific (master) data being processed (Article 15(1), second sentence, of the GDPR); b. the purposes of the data processing (Article 15(1)(a) of the GDPR); the purposes of the data processing (Article 15(1)(a) of the GDPR); c. the categories of personal data being processed (Art. 15(1)(b) GDPR); the categories of personal data being processed (Article 15, paragraph 1, subparagraph (b), GDPR); d. recipients or categories of recipients (Art. 15(1)(c) GDPR);recipients or categories of recipients (Article 15, paragraph 1, subparagraph (c) GDPR); e. if possible, the planned period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period (Art. 15(1)(d) GDPR).if possible, the planned period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period (Article 15, paragraph 1, subparagraph d, GDPR).

VIII

§

Roman numeral eight. The second complainant’s complaint against the second respondent regarding a violation of the right of access is partially upheld, and it is determined that the second respondent violated the second complainant’s right of access by by failing to provide information regarding the following details of the second complainant’s processed personal data: a. Information regarding the specific (master) data processed (Section 1(3)(1) of the Data Protection Act (DSG) in conjunction with Article 15(1) of the GDPR)Information regarding the specific (master) data processed (Paragraph 1(3)(1) of the DSG in conjunction with Article 15(1) of the GDPR) Information regarding the purposes of data processing (Section 1(3)(1) of the Data Protection Act (DSG) in conjunction with Article 15(1)(a) of the GDPR)Information regarding the purposes of data processing (Section 1, paragraph 3, item 1 of the DSG in conjunction with article 15, paragraph 1, subparagraph (a) of the GDPR) Recipients or categories of recipients (Section 1(3)(1) of the DSG in conjunction with Article 15(1)(c) of the GDPR).Recipients or categories of recipients (Section 1, paragraph 3, item 1 of the DSG in conjunction with article 15, paragraph 1, subparagraph (c) of the GDPR).

§

IX. (Roman numeral nine). The second respondent is ordered to provide the second complainant with the following information within a period of four weeks: d. Information regarding the specific (master) data processed (Section 1(3)(1) of the Data Protection Act in conjunction with Article 15(1) of the GDPR)Information regarding the specific (master) data processed (Paragraph 1(3)(1) of the DSG in conjunction with Article 15(1) of the GDPR) Information regarding the purposes of data processing (Section 1(3)(1) of the Data Protection Act (DSG) in conjunction with Article 15(1)(a) of the GDPR)Information regarding the purposes of data processing (Section 1, paragraph 3, item 1, DSG in conjunction with article 15, paragraph 1, subparagraph (a), GDPR) Recipients or categories of recipients (Section 1(3)(1) of the DSG in conjunction with Article 15(1)(c) of the GDPR).Recipients or categories of recipients (Section 1, paragraph 3, item 1 of the DSG in conjunction with article 15, paragraph 1, subparagraph (c) of the GDPR).

§

X (Roman numeral ten). The second complainant’s complaint against the first respondent regarding an alleged violation of the right to confidentiality is dismissed as unfounded. Legal basis: Art. 4, Art. 12, Art. 15, Art. 17, Art. 51(1), Art. 57(1)(f), and Art. 77(1) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR), Official Journal No. L 119 of May 4, 2016, p. 1; Sections 1, 4, 18(1), and 24(1) and (5) of the Data Protection Act (DSG), Federal Law Gazette I No. 165/1999, as amended; Section 31 of the Federal Act of June 12, 1981, on the Press and Other Media (Media Act—MedienG), Federal Law Gazette No. 314/1981, as amended. Legal basis: Article 4, Article 12, Article 15, Article 17, Article 51, paragraph 1, Article 57, paragraph 1, subparagraph (f), and Article 77, paragraph 1, of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR), Official Journal No. L 119 of May 4, 2016, page 1; Sections 1, 4, 18 (1), as well as 24 (1) and (5), of the Data Protection Act (DSG), Federal Law Gazette, Part I, No. 165 of 1999, as amended; Section 31 of the Federal Act of June 12, 1981, on the Press and Other Media (Media Act – MedienG), Federal Law Gazette No. 314 of 1981, as amended.

STATEMENT OF REASONS A

§

Arguments of the Parties and Course of Proceedings 1. In a petition initiating proceedings dated November 26, 2021, the complainants, represented by U*** Rechtsanwalts GmbH, filed a complaint alleging violations by the respondents of their rights to access information and to confidentiality. The second complainant further alleged that the respondents had violated her right to erasure. The first complainant is a physician and the sole managing director of B*** Pharma GmbH, which in turn is the sole shareholder of the second complainant. The second complainant is an enterprise registered as a limited liability company with its registered office in R*** [= name of a federal state]. Its business activities involve the operation of testing facilities and the performance of diagnostic tests, particularly in connection with PCR tests. The respondents are well-known and influential media companies in Austria and are responsible for the editorial content, production, and distribution of various media.

§

They are all media companies as defined by the Media Act. Since June 2021, the respondents have been operating an “investigative consortium” against the complainants and have been presenting themselves as “whistleblowers.” Around August 1, 2021, an email account attributable to the second complainant—which was under the control of the first complainant—was compromised. Among other things, this account contained an email with information that was to be included in a backup. As a result of the compromise of the email account, a message was disclosed to the respondents through no fault of the complainants. The respondents reported on this in the online editions of their media outlets on September 1, 2021. In response to the respondents’ media coverage, the first complainant sent an access request to each of the respondents on September 10, 2021. While the first respondent did not respond to the access request at all, the second respondent provided incomplete information on October 11, 2021.

§

The information provided should have included, at a minimum, the personal data related to the reporting on the compromise of the second respondent’s email account mentioned above. The second complainant submitted an access request to each of the respondents on September 9, 2021. Only the second respondent replied to this request. The second respondent rejected the request for information, citing the media privilege. However, the respondents had already reported more than a month earlier on the compromise of an email account within the second complainant’s sphere of influence. The purpose of the press coverage was thus clearly achieved. At the time the request for information was sent to the second respondent, the second complainant’s processing of the information in connection with the aforementioned coverage therefore served exclusively the purpose of impermissible data retention. The second complainant requested that the respondents perform an erasure of the “message” on September 2, 2021.

§

Both respondents rejected the request for erasure, justifying their decision—in nearly identical terms—by invoking the blanket application of the media privilege. Furthermore, the second respondent was informed by the first respondent both of the fact that a request for deletion had been made to her and of the content of the response sent to the second complainant. The first respondent therefore also violated the second complainant’s right to confidentiality. Attached to the complaint were, among other things, an extract from the commercial register, media reports by the respondents, letters from the complainants, and any responses from the respondents. 2. The Data Protection Authority initially dismissed the complaint by decision dated December 10, 2021, Ref. No.: D124.5337; 2021-0.835.273, initially on the grounds of lack of jurisdiction due to the applicability of the media privilege under para 9(1) of the Data Protection Act (DSG).2.

§

The Data Protection Authority initially dismissed the complaint by decision dated December 10, 2021, Ref. No.: D124.5337; 2021-0.835.273, initially dismissed the complaint for lack of jurisdiction due to the applicability of the media privilege under paragraph 9(1) of the Data Protection Act (DSG). 3. By letter dated January 7, 2022, the complainants, represented by U*** Rechtsanwalts GmbH, filed a complaint with the Federal Administrative Court pursuant to Art. 130(1)(1) of the Federal Constitutional Act (B-VG).3. In a letter dated January 7, 2022, the complainants, represented by U*** Rechtsanwalts GmbH, filed a complaint with the Federal Administrative Court pursuant to article 130, paragraph 1, item 1, of the B-VG. 4. By order dated November 3, 2022, Ref. No. W214 2250949-1/10Z, the Federal Administrative Court requested that para 9(1) of the Federal Act on the Protection of Natural Persons with Respect to the Processing of Personal Data (Data Protection Act—DSG), Federal Law Gazette I No. 165/199, as amended by Federal Law Gazette I No. 24/2018, be declared unconstitutional. 4.

§

By order dated November 3, 2022, Ref. No. W214 2250949-1/10Z, the Federal Administrative Court requested that Section 9, paragraph 1, of the Federal Act on the Protection of Natural Persons with Respect to the Processing of Personal Data (Data Protection Act—DSG), Federal Law Gazette Roman I No. 165/199, as amended by Federal Law Gazette Part I No. 24 of 2018, be declared unconstitutional. 5. By decision of the Constitutional Court dated December 14, 2022, Ref. No. G 288/2022, para 9(1) of the Federal Act on the Protection of Natural Persons with Regard to the Processing of Personal Data (Data Protection Act—DSG), Federal Law Gazette I No. 165/1999, as amended by Federal Law Gazette I No. 24/2018, was repealed on the grounds of unconstitutionality. 5. By a ruling of the Constitutional Court dated December 14, 2022, Case No. G 288 of 2022, paragraph 9(1) of the DSG of the Federal Act on the Protection of Natural Persons with Regard to the Processing of Personal Data (Data Protection Act—DSG), Federal Law Gazette Part I, No. 165 of 1999, as amended by Federal Law Gazette Part I, No. 24 of 2018, was repealed on the grounds of unconstitutionality. 6.

§

By a ruling of the Federal Administrative Court dated January 17, 2023, the decision of the Data Protection Authority dated December 10, 2021, Ref. No. D124.5337; 2021-0.835.273, was set aside without replacement, and the Data Protection Authority was instructed to continue the proceedings while refraining from relying on the previously cited grounds for dismissal. 7. In a statement dated March 3, 2023, the second respondent, represented by L*** Rechtsanwälte GmbH, essentially argued as follows: The second complainant had transferred “control” of her email account to the first complainant. This email account had been compromised, resulting in the disclosure of a message. This raises the question of what (legal) act is at issue when a controller places its email account under the “control” of another controller, and on what grounds such an act would be legally permissible if that email account were compromised and, as a result, messages from that account were disclosed.

§

Above all, however, in the context of the request for information, this raises the question of why the data in question should be considered personal data of the first complainant or the second complainant. On the merits, the complaint appears to be based on the claim that the right of access was allegedly not satisfied because the second respondent did not disclose the data that formed the subject matter of its report dated September 1, 2021. Thus, the complaint boils down to the complainants objecting to the failure to disclose COVID-19 test data and the identities of the tested individuals that were the subject of the report. This data is indeed personal data, but it does not pertain to the first complainant or the second complainant; rather, it pertains to the individuals who were tested. Disclosing this data to the first complainant or the second complainant would therefore only be conceivable if they had been duly authorized by the individuals who were tested.

§

However, the complainants have at no time claimed or provided evidence of such authorization, and it is also doubtful that such authorization actually exists. For this reason alone, the complainants’ request is without merit. Upon closer examination, the traffic data associated with the message itself remains the only data that could potentially be disclosed to the complainants. However, in order for information to be disclosed, the complainants would first have to unravel the specific act by which one party granted the other “control” over his or her email account, because only then could the second respondent, as a result of that act, possibly recognize the traffic data as legally attributable to a specific individual. Regardless, an interpretation of the complainants’ arguments reveals that they are more concerned with obtaining information about the origin of the data than with obtaining the data itself.

§

Article 15(4) of the GDPR stipulates that the right to receive a copy must not infringe upon the rights and freedoms of third parties. It is therefore clear that the protection of editorial confidentiality must be assessed in light of Article 15(4) of the GDPR. In the present case, therefore, the interest of the second respondent must be balanced against the complainants’ interest in obtaining information, taking into account the public interest in safeguarding freedom of expression pursuant to Article 10 of the ECHR and Article 11 of the CFR.Article 15(4) of the GDPR provides that the right to receive a copy must not infringe upon the rights and freedoms of third parties. It is therefore clear that the protection of editorial confidentiality must be assessed in light of article 15(4) of the GDPR. In the present case, therefore, the interest of the second respondent must be balanced against the complainants’ interest in obtaining information, taking into account the public interest in safeguarding freedom of expression under article 10 of the ECHR and article 11 of the CFR.

§

For all the reasons stated above, the complainants’ request for information should not be granted. The requested information should not be provided, and the requested determination should not be made. Only the second complainant alleges a violation of her right to erasure. Pursuant to Article 17(3)(e) of the GDPR, the controller is not obligated to perform the erasure of the data if the processing is necessary for the establishment, exercise, or defense of legal claims. It is a well-known fact that media coverage can lead to proceedings under media law, in which the data from the coverage may constitute necessary evidence. The fact that the data serves as evidence is demonstrated not least by the second complainant herself. In her own complaint, she justifies her interest in a declaratory judgment with a view to her future administrative and civil legal proceedings. Notwithstanding the necessity of retaining the data for evidentiary purposes, the second complainant is not entitled to determine when the journalistic processing purpose ends.

§

It would render all journalistic research and investigative journalism impossible if a third party could determine when the journalistic purpose had been fulfilled and, consequently, when the data underlying the report should be deleted. Consequently, the second complainant’s request for deletion must be denied, both in light of Article 17(3)(a) of the GDPR and in light of Article 17(3)(e) of the GDPR. Furthermore, the DPA represents the view that the right to erasure of a legal entity as set forth in 17 of the GDPR does not apply to a legal entity on its very basis (DPA-D123.089/0002-DPA/2018), so that the second complainant’s request must also be rejected on this ground.Only the second complainant alleges a violation of her right to erasure. Pursuant to Article 17(3)(e) of the GDPR, the controller is not obligated to carry out the erasure of the data if the processing is necessary for the establishment, exercise, or defense of legal claims.

§

It is a well-known fact that media coverage can lead to proceedings under media law, in which the data from the coverage may constitute necessary evidence. The evidentiary nature of the data is demonstrated not least by the second complainant herself. For in her own complaint, she justifies her interest in a declaratory judgment with a view to her future administrative and civil legal proceedings. Notwithstanding the necessity of retaining the data for evidentiary purposes, the second complainant is not entitled to determine when the journalistic processing purpose ends. It would render all journalistic research and investigative journalism impossible if a third party could determine when the journalistic purpose had been fulfilled and, consequently, when the data underlying the report should be deleted. Consequently, the second complainant’s request for erasure must be denied, both in light of Article 17(3)(a) of the GDPR and in light of Article 17(3)(e) of the GDPR.

§

Furthermore, the DPA represents the view that the right to erasure of a legal entity as set forth in Article 17, of the GDPR does not apply to a legal entity on its merits (DPA-D123.089/0002-DPA/2018), so the second complainant’s request must also be rejected on this ground. 8. In a letter dated March 6, 2023, the first respondent, represented by P*** Rechtsanwälte KG, submitted the following summary of its arguments: It should be noted that the email from the first respondent at issue in these proceedings was deliberately made accessible by a person in light of the respondent’s status as a media company. None of the claims asserted by the first complainant are valid because the right to access information is precluded by editorial confidentiality. Even without applying Section 9(1) of the DSG, the right to access information conflicts with the fundamental right to freedom of expression and communication and is therefore excluded under Article 15(4) of the GDPR in conjunction with Article 11 of the CFR.

§

Furthermore, the first respondent had already provided the first complainant with complete information pursuant to Article 15 of the GDPR, to the extent that he was entitled to a right of access. None of the claims asserted by the first complainant are valid because the right to access is precluded by editorial confidentiality. Even without applying Section 9(1) of the DSG, the right of access conflicts with the fundamental right to freedom of expression and communication and is therefore excluded under article 15(4) of the GDPR in conjunction with article 11 of the CFR. Furthermore, the first respondent has already provided the first complainant with complete information pursuant to article 15 of the GDPR, to the extent that he has a right of access to such information. None of the claims asserted by the second respondent are valid because the fundamental right to data protection under § 1 of the DSG does not apply between private individuals, The DPA has no jurisdiction over complaints filed by legal entities, both according to the wording of the DSG and in light of fundamental rights considerations, and there are no enforceable rights to access or erasure for legal entities because Section 1(3) of the DSG is subject to an implementing provision.

§

In any case, there are rights to refuse disclosure in order to protect the constitutionally protected editorial privilege. Furthermore, there is no right to erasure in any event, because the data processing was lawful and the right to confidentiality was safeguarded, as the coordination that took place within the research consortium with the second respondent was lawful.None of the claims asserted by the second complainant are valid because the fundamental right to data protection under Section 1, of the DSG does not apply between private individuals, the DPA is not competent to hear complaints from legal entities either under the plain language of the DSG or in light of constitutional considerations, and no enforceable rights to access or erasure exist for legal entities because Section 1, Paragraph 3, of the DSG is subject to a reservation of implementation. In any case, there are rights to refuse disclosure in order to protect the constitutionally protected editorial privilege.

§

Furthermore, there is no right to erasure in any event, because the data processing was lawful and the right to confidentiality was upheld, as the coordination that took place within the framework of the research consortium with the second respondent was lawful. Attached to the response were an extract from the commercial register, a screenshot of the media report by the first respondent, and an email from the first respondent to the first complainant dated April 15, 2022. 9. In a letter dated April 6, 2023, the complainants, represented by U*** Rechtsanwälte GmbH, responded in essence as follows: An interpretation of § 24 DSG that grants only natural persons the right to file a complaint with the Data Protection Authority would violate the principle of equality and thus be unconstitutional. The fundamental right to data protection guarantees everyone the right to confidentiality of personal data concerning them, provided they have a legitimate interest therein, particularly with regard to respect for private life.

§

To enforce these data subject rights against third parties, the data subject’s rights to access, rectification, and erasure are guaranteed to everyone. An interpretation of Section 24 of the DSG that grants only natural persons the right to file a complaint with the Data Protection Authority would violate the principle of equality and thus be unconstitutional. The fundamental right to data protection guarantees everyone the right to confidentiality of personal data concerning them, provided they have a legitimate interest therein, particularly with regard to the respect for private life. To enforce these rights against third parties, the data subject rights to access, rectification, and erasure are guaranteed to everyone. The respondents dispute that an email allegedly sent by the first complainant on August 1*, 2021, via an email account belonging to the second complainant constitutes personal data of the second complainant.

§

Given that the respondents refer to the second complainant in their reporting and name her by name, all information underlying the reporting and associated with it must be attributed to the second complainant. Due to the respondents’ identifying reporting, the information underlying the reporting necessarily also relates to the second complainant. The substance of the complainants’ request for information is unrestricted and, accordingly, encompasses all information granted under Article 15(1) and (3) of the GDPR and § 1(3)(1) of the DSG. Editorial privilege does not apply against the complainants. Accordingly, it cannot constitute a ground for refusing to disclose information. This does not prevent the respondents from exercising their freedom of expression and freedom of information.The complainants’ request for information is unrestricted in scope and accordingly encompasses all information provided for under article 15, paragraph 1, and article 3, paragraph 3, subparagraph 1, of the GDPR and § 1, paragraph 3, subparagraph 1, of the DSG.

§

Editorial confidentiality does not apply against the complainants. Accordingly, it cannot constitute a ground for refusing to disclose information. The respondents’ freedom of expression and freedom of information are not thereby impeded. Attached to the statement were a letter from the first respondent dated October 28, 2021, to the first complainant; a letter from the first complainant dated September 10, 2021, to the first respondent; screenshots of the first respondent’s website, an email from the first complainant dated February 28, 2023, and a response from the second respondent dated February 28, 2023. B. Subject Matter of the Complaint The subject matter of the complaint is whether 1) the respondents violated the second complainant’s right to erasure, 2) the respondents violated the complainants’ right to information, and 3) the first respondent violated the second complainant’s right to confidentiality, by disclosing to the second respondent that the second complainant had submitted a request for deletion to the first respondent and by disclosing the content of the response to that request to the second respondent.

§

C. Findings of Fact 1. The first complainant is a physician and the sole managing director of B*** Pharma GmbH, FN *6*0*8f, Z**platz 4*, **** H***hausen, which in turn is the sole shareholder of the second complainant. The second respondent is an enterprise registered as a limited liability company with its registered office in R*** [= name of a federal state]. Its business activities involve the operation of testing facilities and the performance of diagnostic tests, particularly in connection with PCR tests. 2. The respondents are well-known and influential media companies in Austria. The first respondent is the publisher of the daily newspaper “M***” and the online media outlet “m***.at.” The second respondent is ****, an Austrian broadcasting organization, and is responsible, among other things, for **** TV channels, [Editor’s note: Details regarding the scope of the second respondent’s business operations have been removed for pseudonymization purposes] and the n***.at network. 3.

§

Around August 1*, 2021, an unsecured Excel file containing PCR test results for several thousand individuals listed by name—which had been sent from the first complainant’s personal email account—came into the possession of the respondents. This email was made available to the respondents by a third party. 4. The first respondent reported on this incident on September 1, 2021, in the online edition of its media outlet (https://www.m***.at/id/*4*7*3/thousands-of-R*** PCR-test-results***-leaked, formatting not reproduced exactly): “Thousands of R*** PCR test results with names and data leaked More than 24,000 positive PCR test results, along with patients’ personal data, were sent via email by Erich A***. He refers to it as a ‘hacker attack’ More than 24,000 positive PCR test results from R***, from January through June 2021, including patient names, places of residence, dates of birth, and details such as the respective virus mutations.

§

This highly sensitive data, which contains prominent names [Editor’s note: abbreviated here for pseudonymization purposes], is in the possession of M*** and N*** R***. It stems from a massive data breach that raises many questions. Erich A***, former managing director of the embattled company B***labor, allegedly sent this data unencrypted via email in the form of Excel spreadsheets on August 1*. When asked, A*** confirmed that he did so and explained the leak by stating that he had been the victim of a hacker attack. Because of the data breach, he said he had initiated “IT forensic investigations.” Until these are completed, he cannot provide any further details. Afterward, he will inform the relevant authorities and file a criminal complaint. Who Received the Data The recipient of the email, an IT technician, also raises questions. A cease-and-desist order and a motion for a preliminary injunction have been filed against him.

§

His former employer, the IT firm C***, accuses him of unlawfully acquiring their custom-programmed software for processing PCR test results and now using it without their consent. He does not wish to comment on the allegations “for data protection reasons.” He states that he has not yet received the lawsuit filed against him. C*** was originally a partner of B***labor when the latter received a multi-million contract for PCR testing from the state of R*** in September 2020 without a competitive bidding process. C*** provided the necessary IT solution for data processing. However, this partnership broke down in May 2021 because B***labor had failed to pay invoices totaling seven figures. The state emphasizes that “in principle, all contractual partners are required by default to protect personal and sensitive data.” Access to or disclosure of data by third parties is “not known at this time.”

§

However, the state reserves the right to take legal action and “condemns it in the strongest terms” should this have actually occurred. Authority Investigates Violation The Data Protection Authority, which was informed of the data breach by M*** and N*** R***, is launching an investigation into a potential violation of the General Data Protection Regulation (GDPR), according to its deputy director, Matthias Schmidl. Administrative criminal proceedings are also a possibility. Furthermore, Schmidl explains, all data subjects whose names appear on the list are free to file a complaint with the Data Protection Authority at no cost—in other words, practically everyone who tested positive for COVID-19 in R*** between January and June 2021. The state points to the responsibility of the contracting parties, who are responsible for implementing and complying with data protection regulations. For data protection advocate S***, however, this is not enough: “Where the government uses taxpayer money to provide testing services, it also has a responsibility to ensure that everything is handled properly.”

§

The GDPR has been European law for years, and R*** must also comply with it. State Governor Remains Silent, Prosecutor’s Office Investigates State Governor [Editor’s note: name abbreviated here for pseudonymization purposes] has rejected ten interview requests from M*** since May, when the B***labor case broke in the media. Erich A*** and the company B***labor have filed a lawsuit against M*** over reports casting doubt on the quality of their work. The case report from the Economic and Corruption Prosecutor’s Office, which investigated the “initial suspicion of serious fraud” against B***labor, is currently with the Ministry of Justice. The State Court of Auditors is investigating the award of the contract without a competitive bidding process. (***, Sept. 1, 2021)” 5. The second respondent reported on this incident in its online edition on September 1, 2021 (https://n***.at/r***/content/*4**8, formatting not reproduced exactly): “Massive Data Breach Involving Positive COVID-19 Tests” The N*** R*** and the “M***” were leaked data on more than 24,000 positive coronavirus tests from R***, along with the corresponding personal information.

§

The data apparently came into circulation because Erich A***, the former managing director of B***labor, had sent it in an email. He himself refers to it as a hacker attack. Virtually all residents of R*** who tested positive for the coronavirus between January and June 2021 are listed in a simple Excel spreadsheet. From name, address, and date of birth to the positive test result and the test date: In total, the file contains more than 24,000 test results and the corresponding patient information—in other words, highly sensitive data that should actually be particularly well protected, said data protection expert Josef S*** of datenschutz***.info. If such data were to be leaked, it could have serious consequences for those affected. An infection could also lead to “Long COVID.” Lists of positive test results could therefore deter potential future employers and even lead to rejection by private health insurance companies, S*** noted.

§

Data Breach Caused via Email A***, the former managing director of the embattled B***labor, is said to have circulated the Excel spreadsheet himself. He likely sent the data via email to someone outside the company. For data protection expert S***, this constitutes “alarming carelessness.” When asked, A*** himself did not deny sending the email. He said he sent the email on August 1* for “backup” purposes. It was indeed encrypted, he stated in a second, later statement. Further investigations revealed that there had been a “hacker attack” on his email account. “IT forensic investigations” are now being conducted in this regard. According to his own statements, A*** intends to inform the authorities once the investigation is complete. According to the commercial register, A*** has not been the managing director of B***labor since June 2021, a position he stepped down from following intense media criticism.

§

A*** did not explain why he still has access to data concerning health. State Condemns Data Breach “in the Strongest Terms” The state of R*** stated that it had only learned of the data breach through a media inquiry. The data did not originate from the state’s servers or file systems; this had since been verified, according to Health Director Michael Ü***. All of the state’s contractual partners—including the B*** laboratory—were contractually obligated to protect personal and sensitive data. The state is unaware of any disclosure to third parties, but reserves the right to take legal action and condemns such conduct “in the strongest terms,” said Ü***. However, the state cannot be entirely absolved of responsibility, said data protection expert S***: “You can’t just brush it off that easily.” Where taxpayer money is used to fund such testing programs, the government also bears the responsibility to ensure that the work is conducted properly—not only with regard to the medical aspects of the tests, but also with regard to data protection regulations.

§

The EU’s General Data Protection Regulation (GDPR) also applies in R***, according to S***. Politicians Also on the List The list of people who tested positive includes several well-known individuals and politicians. Among them is Carolina I***, the chairwoman of the Ä*** Party. For her, the data breach is a “full-blown scandal.” Data concerning health must be handled with care. Since the tests are being conducted under the slogan “R*** Tests,” the residents of R*** had come to rely on them. That trust has now been shaken, according to I***. National Council member Udo J*** (U*** Party) also appears on the list. J*** says this isn’t a problem for him—he has nothing to hide. However, he notes that the very purpose of data protection is to safeguard precisely this kind of information. He can understand that the data breach is causing an uproar. For Peter Fo*** (TU*** Party), who was also affected by the data breach, it is “puzzling how something like this is still possible in 2021,” given all the talk about data protection and official secrecy.

§

Legal action should be urgently considered here, according to Fo***. Investigation by the Data Protection Authority The investigative team also reported the data breach to the Data Protection Authority in advance. The authority will launch an investigation into the case regarding a possible violation of the General Data Protection Regulation, said Deputy Director Matthias Schmidl. Those affected—that is, virtually all residents of R*** who tested positive for the coronavirus between January and June 2021—can file a complaint with the Data Protection Authority free of charge. Opposition Expresses Outrage [Editor’s note: The remainder of the media report has been removed for pseudonymization purposes.]” 6. On September 2, 2021, the second complainant requested that the respondents perform the erasure of the “message.” 7. The first respondent disclosed to the second respondent both the receipt and the content of the response to this request for deletion.

§

The requests read as follows in each case (formatting not reproduced exactly): “As you are already aware, an email account belonging to B***Labor GmbH was compromised, resulting in a personal data breach. I have learned from media reports that your media outlet is in possession of at least one message from this email account. As the data protection officer of B***Labor GmbH, I must accordingly request that you immediately delete this message (and, if applicable, any other messages from the email account), confirm the erasure to me, and refrain from disclosing it to any third parties. If you have already disclosed this or any other message from the mailbox to third parties, please provide the names of the recipients. Alternatively, you may inform the recipients yourself and confirm this to me.” 8. The respondents—the first respondent on September 3, 2021, and the second respondent on September 7, 2021—refused to carry out the erasure, citing the media privilege under Section 9(1) of the DSG. 8.

§

The respondents—the first respondent on September 3, 2021, and the second respondent on September 7, 2021—rejected the erasure, citing the media privilege under paragraph 9(1) of the DSG. The first respondent’s reply also included the following excerpt (formatting not reproduced exactly): “But we would like to take this opportunity to ask you, as the data protection officer at B***labor, how it is possible that Erich A*** still had access to this patient data as recently as August 2021 and sent it unsecured via email to Mr. Or***? Did he also have access to other sensitive data? What legal steps will you take against Mr. A*** in this matter?” The second respondent also included the following questions in the rejection (formatting not reproduced exactly): “- How is it possible that Erich A*** still had access to this patient data as recently as August 2021 and sent it via unsecured email to Mr. Or***? - Did he also have access to other sensitive data? - What legal steps will you take against Mr. A*** in this matter? - What did the internal ‘IT forensic investigations’ reveal?”“—How is it possible that Erich A*** still had access to this patient data as late as August 2021 and sent it unsecured via email to Mr. Or***? , - Did he also have access to other sensitive data? , - What legal steps will you take against Mr. A*** in this matter?, - What did the internal “IT forensic investigations” reveal?”. 9.

§

In a letter dated September 9, 2021, the second complainant requested the following from the respondents, in part (formatting not reproduced exactly; emphasis added by the Data Protection Authority): “We refer to the letter dated September 2, 2021, in which you were requested by B***Labor GmbH to delete all messages in your possession from the compromised email account that you reported. Since you have unfortunately not complied with this request, I am now requesting, on behalf of B***Labor GmbH, information regarding which data and trade secrets of B***Labor you are processing, for what purpose, and to whom these have been or will be transmitted (see § 1(3)(1) DSG)“Since you have unfortunately not complied with this request, I am now requesting, on behalf of B***Labor GmbH, information regarding which data and trade secrets of B***Labor you are processing, for what purpose, and to whom these have been or will be transmitted—see Section 1, Paragraph 3, item 1, DSG).”

§

In a letter dated September 9, 2021, the second respondent replied in part as follows (formatting not reproduced exactly): “After reviewing the situation, the facts of the matter are as follows: Whether the email account was or is actually compromised is beyond our knowledge. Pursuant to § 9(1) of the DSG, which is based on Article 85 of the GDPR, the processing of personal data by media owners, publishers, media staff, and employees of a media company or media service as defined by the Media Act for the journalistic purposes of the media company or media service, the provisions of the DSG and the GDPR—with the exception of Chapter I (General Provisions) and Chapter VIII (Remedies, Liability, and Sanctions), do not apply. Pursuant to Section 9, paragraph 1, of the DSG, which is based on Article 85 of the GDPR, the provisions of the DSG and the GDPR—with the exception of Chapter I (General Provisions) and Chapter VIII media staff, and employees of a media company or media service as defined by the Media Act, for the journalistic purposes of the media company or media service, the provisions of the DSG and the GDPR—with the exception of Chapter I (General Provisions) and Chapter VIII (Remedies, Liability, and Sanctions), shall not apply.

§

In doing so, the Austrian legislature has struck a balance between the right to the protection of personal data, on the one hand, and the right to freedom of expression and freedom of information, on the other. It is undisputed that the N*** broadcasting company is a media company within the meaning of the Media Act. Data processing for journalistic purposes must be understood holistically and thus extends from the “initial information” through to the initial publication and beyond. The CJEU defines “journalistic purposes” as activities intended to “disseminate information, opinions, or ideas (...) to the public.” (see CJEU, Judgement of Dec. 16, 2008, C-73/07, Satamedia, loc. cit., para. 61) The Advocate General in this case had emphasized—"to further define the concept of journalistic purposes"—the role of a free press as a "public watchdog" and derived from this the duty to "convey information and ideas on all matters of public interest."

§

Editorial processing is not a determining factor in this regard; even the provision of raw data can contribute to public debate. The CJEU ultimately concurred with this view.Data processing for journalistic purposes must be understood holistically and thus extends from the “initial information” through to the initial publication and beyond. The CJEU defines “journalistic purposes” as activities intended to “disseminate information, opinions, or ideas (...) to the public.” (See CJEU, Judgement of Dec. 16, 2008, C-73/07, Satamedia, op. cit., para. 61) The Advocate General in this case had emphasized, “to further define the concept of journalistic purposes,” the role of a free press as a “public watchdog” and derived from this the obligation to “convey information and ideas on all matters of public interest.” Editorial processing is not a determining factor in this regard; even the provision of raw data can contribute to public debate.

§

The CJEU ultimately concurred with this view. The data was processed for journalistic purposes, as it was intended to disseminate information to the public. It follows from the foregoing that the DSG and the GDPR are not applicable to the facts of this case to the extent described above; therefore, there is no legal right to data erasure, in particular pursuant to Art 17 of the GDPR.It follows from the foregoing that the DSG and the GDPR do not apply to the facts of this case to the extent mentioned above; therefore, there is no legal right to data erasure, in particular pursuant to article 17 of the GDPR. Please feel free to contact me if you have any questions.” The first respondent did not respond to the second complainant’s request for information dated September 9, 2021, until the conclusion of the proceedings before the Data Protection Authority. 10. On September 10, 2021, the first complainant sent the following request to the respondents in excerpts (formatting not reproduced exactly): “Dear Sir or Madam, I hereby request, pursuant to Article 15 of the GDPR, that you provide all data relating to me that is available to you.”I hereby request, pursuant to Article 15 of the GDPR, that you provide all data relating to me that is available to you.”

§

In the attachments, the initial complainant submitted a copy of his photo ID as well as the following requests (formatting not reproduced exactly): 1) to the initial respondent [Processing officer’s note: The request for information reproduced here as a facsimile (in the form of several PDF files)—a form from the Data Protection Authority’s website—would have required significant effort to pseudonymize and was therefore removed.] 2) To the second respondent [Editor’s note: The request for information (form from the Data Protection Authority’s website), reproduced here as a facsimile (in the form of several PDF files), would have required significant effort to pseudonymize and was therefore removed.] 11. The second respondent replied to this letter on October 11, 2021, as follows (formatting not reproduced exactly; redactions were made by the second respondent): [Editor’s note: The response to the request for information reproduced here as a facsimile (in the form of several PDF files) would have required a great deal of effort to pseudonymize and has therefore been removed.

§

In terms of content, the information is limited to the first complainant’s master data and data related to a SAT reception card/key card issued for satellite reception of the second respondent’s programs.] 12. The first respondent replied to the first complainant on April 15, 2022, with the following excerpt (formatting not reproduced exactly): [Editor’s note: The information letter reproduced here as a facsimile (in the form of several PDF files) would have required a great deal of effort to pseudonymize and was therefore removed. In terms of content, the information is limited to data related to his registration for the first respondent’s online services, such as the M*** reader forum.] 13. The first respondent did not respond to the second complainant’s request dated September 9, 2021, until the conclusion of the proceedings before the Data Protection Authority. Assessment of the Evidence: The findings made are based on the parties’ consistent submissions in this regard as well as the documents submitted by them.

§

D. From a legal perspective, the following conclusions follow: D.1. On the Precedential Effect As can be seen from the course of the proceedings, the Federal Administrative Court, based on the present case, filed a motion for judicial review with the Constitutional Court, and para 9(1) of the Data Protection Act (DSG) was struck down by the Constitutional Court as unconstitutional, effective June 30, June 2024. As can be seen from the course of the proceedings, the Federal Administrative Court, based on the present proceedings, filed a motion for judicial review with the Constitutional Court, and Section 9, paragraph 1, of the DSG was struck down by the Constitutional Court as unconstitutional, effective June 30, 2024. A provision repealed by the Constitutional Court continues to apply to facts that occurred prior to its repeal (see Art. 140, para. 7, second sentence, and Art. 139, para. 6, second sentence, of the Federal Constitutional Law [B-VG]).

§

The repeal of a legal provision by the Constitutional Court thus takes effect only for the future (pro futuro effect; Constitutional Court Decision 1415/1931). Earlier facts must continue to be assessed in accordance with the previous legal situation. Administrative acts based on a provision repealed by the Constitutional Court remain unaffected (Const. Ct. Dec. 3303/1957). The same applies in cases where the Constitutional Court finds that a law or Regulation was unconstitutional or unlawful (see Constitutional Court Decision 10.834/1986, 17.020/2003). The only—objectively justified (Const. Ct. Dec. 3519/1959, 5141/1965)—exception to this principle is the principle of retroactive application:A provision annulled by the Constitutional Court continues to apply to facts that occurred prior to its annulment (see article 140, paragraph 7, second sentence, and article 139, paragraph 6, second sentence, of the Federal Constitutional Law [B-VG]).

§

The annulment of a legal provision by the Constitutional Court thus takes effect only for the future (pro futuro effect; Constitutional Court Decision No. 1415 of 1931). Earlier facts must continue to be assessed in accordance with the previous legal situation. Administrative acts based on a provision repealed by the Constitutional Court remain unaffected (Constitutional Court Decision No. 3303 of 1957). The same applies in cases where the Constitutional Court finds that a law or Regulation was unconstitutional or unlawful (see Constitutional Court Decisions 10.834 of 1986, 17.020 of 2003). The only—objectively justified (Const. Rep. No. 3519 of 1959, No. 5141 of 1965)—exception to this principle is the retroactive effect: The case in question must be assessed as if the provision deemed unconstitutional had already ceased to be part of the legal order at the time the facts of the case in question occurred (see Constitutional Court Reports 3674/1960, 7651/1975).

§

The case in question is the legal matter that gave rise to the initiation of the constitutional review proceedings (Const. Rep. 8234/1978). The case in question must be assessed as if the provision deemed unconstitutional had already ceased to be part of the body of law at the time the facts of the case in question occurred—see Constitutional Court Reports 3674 from 1960, 7651 from 1975). The case in question is the legal matter that gave rise to the initiation of the constitutional review proceedings (Constitutional Court Decision 8234 from 1978). Since the present proceedings are to be classified as the “case in question,” a decision on the merits must be rendered as if § 9(1) of the Data Protection Act (DSG) had not been part of the legal order at the time the facts of the case occurred.Since the proceedings at issue are to be classified as the triggering case, a decision on the merits must be rendered as if Section 9(1) of the Data Protection Act (DSG) had not been part of the legal framework at the time the facts occurred.

§

The subject matter of the complaint must therefore be examined—disregarding Section 9(1) of the DSG—to determine whether the respondents violated the second complainant’s right to erasure (see Point I of the ruling), whether the respondents violated the complainants’ right to access information (see Points II–IX of the ruling), and whether the first respondent violated the second complainant’s right to confidentiality (see Point X of the ruling).The subject matter of the complaint is therefore—disregarding paragraph 9(1) of the DSG—to determine whether the respondents violated the second complainant’s right to erasure (see point I of the ruling), whether the respondents violated the complainants’ right to access (see points II through IX of the ruling), and whether the first respondent violated the second complainant’s right to confidentiality (see point X of the ruling). D.2. Regarding the Second Complainant’s Standing to File a Complaint Insofar as the First Respondent implicitly objects to the Second Complainant’s lack of standing to file a complaint due to her status as a legal entity, this argument must be rebutted as follows: Pursuant to § 4(1) of the DSG, the provisions of the GDPR and the DSG apply to the fully or partially automated processing of personal data of natural persons, as well as to the non-automated processing of personal data of natural persons that is stored or intended to be stored in a filing system.

§

Pursuant to Section 4(1) of the DSG, the provisions of the GDPR and the DSG apply to the fully or partially automated processing of personal data of natural persons, as well as to the non-automated processing of personal data of natural persons that are stored or are to be stored in a filing system. According to the intent of the legislature, the provisions of the DSG under ordinary law—including the right to file a complaint under § 24 DSG—are therefore limited to the protection of natural persons.According to the legislature’s intent, the provisions of ordinary law under the DSG—including the right to file a complaint under Section 24 of the DSG—are therefore limited to the protection of natural persons. However, the Data Protection Authority has already stated on multiple occasions that § 1 of the DSG also protects legal entities. An interpretation of the provisions of ordinary law—in particular §§ 4 and 24 of the DSG—to the effect that only natural persons are granted the right to file a complaint with the Data Protection Authority, but not legal entities, would attribute to these provisions—in light of Section 1 of the DSG—a meaning that violates the principle of equality and is therefore unconstitutional.

§

The Data Protection Authority has, however, repeatedly stated that Section 1 of the DSG also protects legal entities. An interpretation of the provisions of ordinary law—in particular Sections 4 and 24 of the DSG—to the effect that only natural persons are granted the right to file a complaint with the Data Protection Authority, but legal entities are not, would attribute to these provisions—in light of Section 1 of the of the DSG. Indeed, it cannot be assumed that the legislature intended, without a reasonable basis, to treat legal entities in a manner that is grossly disadvantageous compared to natural persons in the context of the exercise of their constitutionally guaranteed rights (see the decision of May 25, 2020, GZ 2020-0.191.240, with further references). The CJEU has affirmed that the national legislature is permitted to establish a purely national framework for the protection of personal data of legal entities (judgement of December 10, 2020, C-620/19, para. 47), meaning that the aforementioned case law of the Data Protection Authority does not contradict this.

§

In conclusion, this means that legal entities—to the extent of the rights granted to them under § 1 DSG—have standing to file a complaint, contrary to the respondents’ view. Accordingly, the second complainant also has standing to file a complaint in this case in connection with an alleged violation of the right to erasure under § 1(3)(2) DSG in conjunction with Art. 17 of the GDPR, an alleged violation of the right of access under Para 1(3)(1) of the DSG in conjunction with Art 15 of the GDPR, and an alleged violation of the right to confidentiality under Para 1 of the DSG.In conclusion, this means that legal entities—to the extent of the rights granted to them under Section 1 of the DSG—have standing to file a complaint, contrary to the respondents’ view. Accordingly, the second complainant also has standing to file a complaint in this case in connection with an alleged violation of the right to erasure pursuant to Section 1, paragraph 3, item 2, of the DSG in conjunction with article 17, GDPR, an alleged violation of the right of access pursuant to Section 1, paragraph 3, subparagraph 1 of the DSG in conjunction with article 15 of the GDPR, and an alleged violation of the right to confidentiality pursuant to Section 1, paragraph 1 of the DSG.

§

Regarding Point I; Regarding Roman numeral I D.3. General Remarks on the Right to Erasure In the absence of an implementing provision in the DSG, Art. 17 of the GDPR must be consulted for the interpretation of Section 1, para. 3, item 2 of the DSG, taking into account Section 4 of the DSG. In the absence of an implementing provision in the DSG, article 17 of the GDPR must be applied to interpret Section 1, paragraph 3, item 2 of the DSG, taking Section 4 of the DSG into account. Under Article 17(1) of the GDPR, every data subject generally has the right to request the erasure of their personal data by a controller. To exercise such a right, which requires a request, a request must first be submitted to the controller. Although the GDPR does not specify a particular form or wording for this request, it must at least be clear to the controller that the request is based on a specific right under the GDPR, as the receipt of the request triggers obligations on the part of the controller.Under Article 17(1) of the GDPR, every data subject is, in principle, entitled to request the erasure of their personal data from a controller.

§

To exercise such a right, which requires a formal request, a request must first be submitted to the controller. Although the GDPR does not specify a particular form or wording for this request, it must at least be apparent to the controller that the request is based on a specific right under the GDPR, since the receipt of the request triggers obligations on the part of the controller. When assessing whether a request is recognizable to the controller as one based on a specific right under the GDPR, the request must be examined based on its content, applying the same standard that applies to unilateral declarations of intent under private law. Accordingly, the wording and meaning of the declaration must be considered from an objective perspective—namely, as the recipient could have understood it based on its wording and purpose upon objective examination (see BVwG, May 3, 2018, W256 2190554-1, regarding the request for information under § 26 DSG 2000 and concerning the interpretation with reference to the case law of the OGH, e.g., OGH September 15, 1999, 9 ObA 148/99a).Accordingly, the wording and meaning of the statement must be considered from an objective perspective—namely, as the recipient could have understood it based on its wording and purpose when viewed objectively—see BVwG May 3, 2018, W256 2190554-1, regarding the request for information under Section 26 of the Data Protection Act 2000 (DSG 2000) and concerning the interpretation with reference to the case law of the Supreme Court, e.g., Supreme Court, September 15, 1999, 9 ObA 148/99a).

§

D.3.1. On the Merits As established, the second complainant requested erasure from each of the respondents in a letter dated September 2, 2021 (see Section C.6.). While it is undisputed that these were requests for erasure and were recognized as such by the respondents, however, from an objective recipient’s perspective, it must be assumed that the second appellant “amended her request” after the respondents rejected the erasure. Thus, while the second appellant regrets in each instance that her request for erasure was not granted, she now demanded that the respondents provide information regarding which data and trade secrets were or are being processed, for what purpose, and to whom they were or are being transferred (see Section C.9.). It could not therefore be assumed that the request for erasure remained in effect. Rather, these were replaced by requests for information (regarding the requests for information, see immediately below under Point D.4.).

§

This can also be justified by the fact that requests for information and requests for erasure are contradictory in nature and therefore, from a logical standpoint, cannot be meaningfully pursued simultaneously. Since the request for erasure was thus no longer valid at the time the complaint was filed, a violation of the right to erasure is ruled out. The second complainant’s complaint against the respondents was therefore to be dismissed on this point, as ruled, due to the lack of valid requests for erasure. Even if—contrary to the Data Protection Authority’s view—it were not to be assumed that the request had been amended, the complaint regarding an alleged violation of the right to erasure would have to be dismissed for the following reasons: Thus, the right to erasure pursuant to Article 17(3)(a) of the GDPR does not apply to the extent that the processing is necessary for the exercise of the right to freedom of expression and information.Thus, the right to erasure under Article 17(3)(a) of the GDPR does not apply to the extent that the processing is necessary for the exercise of the right to freedom of expression and information.

§

This addresses a conflict between fundamental rights that is both typical and fundamental in data protection, which is occasionally expressed as concern over censorship or unjustified control. The balancing of interests must take into account, on the part of the data subject, the fundamental rights guaranteed by Articles 7 and 8 of the CFR and Article 8 of the ECHR—namely, the right to respect for private and family life and the right to the protection of personal data—while, on the part of the controller or third parties, the fundamental right to freedom of expression or freedom of information under Para 1 of Art. 11 of the EU CFR and Art 10(1) of the ECHR (see Peuker in Sydow [ed.], General Data Protection Regulation, Handkommentar, Art. 17, para. 59).This addresses a conflict between fundamental rights that is both typical and fundamental in data protection, which is occasionally expressed as concern about censorship or unjustified control.

§

The balancing of interests must take into account, on the part of the data subject, his or her fundamental rights to respect for private and family life and to the protection of personal data, as guaranteed by articles 7 and 8 of the EU CFR and article 8, ECHR, to respect for private and family life and to the protection of personal data; on the part of the controller or third parties, the fundamental right to freedom of expression and to freedom of information pursuant to article 11, paragraph 1, of the CFR and article 10, paragraph 1, ECHR; see Peuker in Sydow [ed.], General Data Protection Regulation, Commentary, article 17, para. 59). As can be seen from the findings (see sections C.3–C.5), the “email messages,” which are the original targets of the requests for deletion, constitute the core element of the respondent’s media coverage. An erasure of this message would therefore destroy the core content of the media coverage.

§

Furthermore, in the present case, the circumstances described in Article 17(3)(e) of the GDPR may also apply, namely processing that may be necessary for the establishment, exercise, or defense of legal claims.Furthermore, in the present case, the circumstances described in Article 17(3)(e) of the GDPR could also apply, namely processing that may be necessary for the establishment, exercise, or defense of legal claims. In this regard, it should be noted that the “defense of legal claims”—contrary to what the wording might suggest—also refers to “defense against legal claims.” This provision applies, in any case, when the assertion, exercise, or defense of (or against) legal claims is already taking place or is certain to occur. The mere abstract possibility of legal disputes is not sufficient (see Herbst in Kühling/Buchner, GDPR Commentary, Art. 17, para. 83). In this regard, it should be noted that the “defense of legal claims”—without contradicting the wording—also refers to “defense against legal claims.”

§

This provision applies, in any case, when the assertion, exercise, or defense of (or against) legal claims is already taking place or is certain to occur. The mere abstract possibility of legal disputes is not sufficient (see Herbst in Kühling/Buchner, GDPR Commentary, article 17, para. 83). Pursuant to § 32 of the Media Act (MedienG), the criminal liability for a media content offense arising from the content of an accessible periodic electronic medium is subject to a statute of limitations of three years, beginning at the time the dissemination of the content commences. Pursuant to Section 32 of the Media Act (MedienG), the criminal liability for a media content offense arising from the content of an accessible periodic electronic medium is subject to a statute of limitations of three years, beginning at the time when the dissemination of the content commences. The respondents are thus not referring generally to a potential future proceeding, but are identifying specific claims that could be asserted against them within a specific time period.

§

Furthermore, the proceeding before the Data Protection Authority serves as an indication that this data is still needed to resolve legal claims. Regarding Issues II through IX; Regarding Issues Roman numeral two through Roman numeral nine D.4. General Remarks on the Right of Access Pursuant to Art. 15(para 2) 1 of the GDPR, the data subject has the right to request confirmation from the controller as to whether personal data concerning him or her is being processed and, if so, the data subject has the right to access such personal data and is entitled to the information specified in subparagraphs (a) through (h) of the provision cited. Pursuant to Article 15, paragraph 1, GDPR, the data subject has the right to request confirmation from the controller as to whether personal data concerning him or her is being processed and, if so, the data subject has the right to access such personal data and to receive the information specified in subparagraphs (a) through (h) of the cited provision.

§

The right of access under Article 15 of the GDPR serves as a tool that enables a data subject to become aware of the processing carried out by a controller and to verify the lawfulness of the processing (see Recital 63, first sentence, of the GDPR). In other words, the right of access allows the data subject to gain insight into the “whether and how” of the processing (see Paal in Paal/Pauly [eds.], General Data Protection Regulation: Commentary, Art. 15, para. 3).The right of access under Article 15 of the GDPR serves as a tool that enables a data subject to become aware of the processing carried out by a controller and to verify the lawfulness of the processing (see Recital 63, first sentence, of the GDPR). In other words, the right of access enables the data subject to gain insight into “whether and how” processing is taking place (see Paal in Paal/Pauly [eds.], General Data Protection Regulation: Commentary, article 15, margin note 3).

§

The second appellant—as a legal entity—bases her claim for access on para 1(3)(1) of the Data Protection Act (DSG). This grants the data subject the right to information regarding who is processing which data about him or her, where this data comes from, for what purposes it is used, and to whom it is disclosed.The second complainant—as a legal entity—bases its claim for access on Section 1, paragraph 3, item 1 of the DSG. This grants the data subject the right to information regarding who is processing which data about them, where such data originates, for what purposes it is used, and to whom it is disclosed. In the absence of an implementing provision in the DSG, Art. 15 of the GDPR must be consulted for interpretation, taking into account Section 4 of the DSG. Since a legal entity must not, in principle, be treated less favorably than a natural person, its right to access—taking into account the specific characteristics of a legal entity—must not be less than that of a natural person under the principle of equal treatment.In the absence of an implementing provision in the DSG, Section 4 of the DSG must be taken into account when interpreting article 15 of the GDPR.

§

Since a legal entity must not, in principle, be treated less favorably than a natural person, its right to access information—taking into account the specific characteristics of a legal entity—must not be less than that of a natural person under the principle of equal treatment. It should be noted at the outset that the letters referred to in sections C.9 and C.10 are undoubtedly requests for access to information, which have unquestionably come within the control of the respondents—and thus have been received by them (see, for example, regarding the application of the “receipt theory,” the DPA’s decision of February 22, 2019, Ref. No.: DSB-D124.098/0002-DSB/2019, available in the RIS). First, it should be noted that the letters mentioned under Section C.9 and Section C.10. are undoubtedly requests for information which have indisputably come within the control of the respondents—and have consequently been received by them—see, for example, the DPA’s decision of February 22, February 2019, Ref.

§

No.: DPA-D124.098/0002-DPA/2019, available on RIS). Since it is undisputed in the present case that the respondents, as controllers within the meaning of Art. 4(7) of the Data Protection Act, process the complainants’ personal data within the meaning of Art. 4(1) of the GDPR, cit., thereby establishing a right of access pursuant to Art. 15 GDPR and § 1(3) DSG, the respondents are generally required to provide the complainants with information regarding the processed personal data concerning them to the extent specified in Art. 15 GDPR and § 1(3), provided that no other exception to the right of access applies.Since it is undisputed in the present case that the respondents process the complainants’ personal data within the meaning of Article 4(1) of the GDPR, each acting as a controller within the meaning of Article 4(7) of the GDPR, , thereby establishing a right to access pursuant to Article 15 of the GDPR or paragraph 1(3) of the DSG, they are generally required to provide the complainants with information regarding the processed personal data concerning them within the scope of Article 15, GDPR or Section 1, Paragraph 3, insofar as no other exception to the right of access applies.

§

At the core of their complaint in this regard—assuming that there are no grounds for refusing access—the complainants each allege that the information provided was incomplete or that no information was provided at all in connection with the media coverage on September 1, September 2021, pursuant to Article 15(1) and Article 15(3) of the GDPR and Section 1(3)(1) of the DSG, respectively.At the heart of their complaint in this regard, the complainants—assuming that there are no grounds for refusing access—each allege that the information provided in connection with the media coverage on September 1 was incomplete or, in some cases, not provided at all. September 2021, pursuant to Article 15(1) and Article 15(3) of the GDPR and Paragraph 1(3)(1) of the DSG, respectively. It must therefore first be examined to what extent the grounds for refusing access cited by the respondents are valid: In this regard, the respondents unanimously argued that the right to access is precluded by editorial privilege pursuant to Article 15(4) of the GDPR in conjunction with Article 11 of the CFR and Section 31 of the Media Act (MedienG).In this regard, the respondents each argued in unison that the right to access is precluded by editorial privilege under article 15(4) of the GDPR in conjunction with article 11 of the CFR and paragraph 31 of the Media Act (MedienG).

§

In contrast, the respondents contended that Article 15(4) of the GDPR refers only to Article 15(3) of the GDPR and not to Article 15(1) of the GDPR, and that editorial privilege under Section 31 of the Media Act did not apply against the complainants. In contrast, the complainants argued that Article 15(4) of the GDPR refers only to Article 15(3) of the GDPR and not to Article 15(1), GDPR, and that the editorial privilege under Section 31 of the Media Act does not apply against the complainants. First, it is therefore noted that the legislator of the GDPR—contrary to the latter view—has indeed granted leeway for balancing interests even within the scope of Article 15(1) of the GDPR:It is therefore first noted that the legislator of the GDPR—contrary to the view mentioned last—has indeed granted leeway for balancing interests even within the scope of article 15(1) of the GDPR: Thus, access under Article 15 of the GDPR is initially limited to one’s own data—that is, to data that, according to the wording of Article 15(1) of the GDPR, constitutes “personal data relating to [the data subject].”

§

Therefore, in principle, there is still no right to access the personal data of third parties, unless there are specific reasons for doing so in individual cases (see, for example, the decision of the Data Protection Authority dated April 18, 2019, Ref. No.: DPA-D122.913/0001-DPA/2019).Thus, pursuant to Article 15 of the GDPR, access is initially limited to one’s own data—that is, to data that, according to the wording of Article 15(1) of the GDPR, constitutes “personal data relating to [the data subject].” Consequently, there is, in principle, still no right to access the personal data of third parties, unless there are specific reasons for doing so in individual cases; see, for example, the decision of the Data Protection Authority dated April 18, 2019, Ref. No.: DPA-D122.913/0001-DPA/2019). Furthermore, it is inherent in the GDPR that complaint proceedings involve case-by-case decisions in which, where necessary, conflicting fundamental rights must be weighed against one another.

§

In any case, it cannot be said that the regulator has already conducted a balancing of interests; rather, such a balancing must be carried out in the specific individual case (see the decision of the DPA dated June 1, 2022, Ref. No.: D124.0442/22; 2022-0.277.100). A systematic interpretation of the GDPR reveals that the regulator has provided for possibilities of deviation through enabling clauses and that the data subject rights granted do not apply without restriction due to the provision of Article 1(2) of the GDPR.Furthermore, it is inherent in the GDPR that complaint proceedings are case-by-case decisions in which, where applicable, conflicting fundamental rights must be weighed against one another. In any case, it cannot be said that the legislator has already conducted a balancing of interests; rather, such a balancing must be carried out in the specific individual case (see decision of the DPA dated June 1, 2022, Ref.

§

No.: D124.0442/22; 2022-0.277.100). A systematic interpretation of the GDPR reveals that the regulator has provided for the possibility of derogations through enabling clauses and that the data subject rights granted do not apply without restriction due to the provision in article 1, paragraph 2, of the GDPR. Furthermore, the Data Protection Authority refers to the following ruling by the Federal Administrative Court (BVwG) dated November 9, 2021, regarding case no. W176 2244155-1/5E: According to Recital 63 of the GDPR, the exception under Article 15(4) of the GDPR is intended to protect trade secrets and intellectual property rights, in particular copyright in software. However, it must be assumed that, in principle, all rights and freedoms recognized by Union law or the laws of the Member States will be relevant. If the controller were required to disclose an email that also mentions other individuals whose interests are deemed to take precedence, such documents would not be covered by the right of access (Haidinger in Knyrim, DatKomm Art. 15 GDPR [as of Oct. 1, October 2018, rdb.at] para. 49).

§

According to Recital 63 of the GDPR, the exception under Article 15(4) of the GDPR is intended to protect trade secrets and intellectual property rights, in particular copyright in software. However, it must be assumed that, in principle, all rights and freedoms recognized by Union law or the laws of the Member States will be relevant. If the controller were required to disclose an email that also mentions other individuals whose interests take precedence, such documents would not be covered by the right of access (Haidinger in Knyrim, DatKomm article 15, GDPR [as of Oct. 1, 2018, rdb.at] para. 49). Art. 15(4) of the DSVG stipulates that the right to receive a copy “in accordance with paragraph 3” must not infringe upon the rights and freedoms of others. At first glance, this explicit reference to the right to a copy in para 3 appears to contradict the framework developed thus far, because, according to the wording, it refers only to the right to a copy and not to the substantive right of access under Article 15(1).

§

However, this contradiction is resolved if one views the right to a copy as a more specific provision regarding the manner in which information about the data subject’s personal data is to be provided under Article 15(1) of the GDPR. In that case, the obligation to balance interests applies to the provision of information in its entirety (Jahnel, Commentary on the GDPR, Art. 15, para. 42).Article 15(4) of the GDPR stipulates that the right to receive a copy “in accordance with paragraph 3” must not infringe upon the rights and freedoms of others. At first glance, this explicit reference to the right to a copy in paragraph 3 appears to contradict the framework developed thus far, because, according to the wording, it refers only to the right to a copy and not to the right of access to the content of the data pursuant to article 15(1). However, this contradiction is resolved if one views the right to a copy as a more specific provision regarding the manner in which information about the data subject’s personal data is to be provided under article 15(1) of the GDPR.

§

In that case, the obligation to balance interests applies to the provision of information in its entirety (Jahnel, Commentary on the GDPR, article 15, Marginal Note 42). Consequently, a refusal to provide the information contained in Article 15 of the GDPR would be justified if the confidentiality interests of the respondents or third parties outweigh the complainant’s interest in obtaining the information.Consequently, a refusal to provide the information contained in article 15 of the GDPR would be justified if the respondents’ or third parties’ interests in confidentiality outweigh the complainant’s interest in obtaining the information. However, the balancing of interests must be conducted separately for each type of data required under Article 15(1)(a) through (h) of the GDPR in order to enable review by the Data Protection Authority or a Court. A blanket exclusion of all access—as suggested by the respondents—is not provided for in this context.However, the balancing of interests must be conducted separately for each type of data required under article 15(1)(a) through (h) of the GDPR to enable review by the Data Protection Authority or a Court.

§

A blanket exclusion of all information—in the sense of the view indicated by the respondents—is not provided for here. Consequently, the information provided by the respondents must therefore be examined in detail according to the aforementioned criteria. Regarding Point II (Roman numeral 2) Regarding the disclosure of information to the first respondent 1) To the first complainant a) Information regarding the specific (master) data processed (Art. 15(1) GDPR)a) Information regarding the specific (master) data processed (Article 15, paragraph one, GDPR) The core of the right of access, pursuant to Art. 15(1), first sentence, of the GDPR, is that the controller must provide the data subject with confirmation as to whether personal data concerning him or her is being processed and—if so—subsequently provide the data subject with the additional information specified in para 1(a) through (h) (second stage).The core of the right of access, pursuant to Article 15, paragraph 1, first sentence of the GDPR, is that the controller must provide the data subject with confirmation as to whether personal data concerning the data subject is being processed and—if so—must subsequently provide the data subject with the additional information specified in paragraph 1, subparagraphs (a) through (h) of the cited provision (second stage).

§

As noted, the first respondent provided the first complainant with information exclusively regarding his master data in connection with his user profile with the first respondent. As can also be inferred from the findings (see points C.4. and C.5.), the first respondent also processes data pertaining to the first complainant in connection with the media coverage of September 1, 2021 (specifically: at least his name, his email address, and his former job title). It is not apparent to the Data Protection Authority to what extent the disclosure of the master data—which is largely publicly accessible anyway—is countered by conflicting interests on the part of the first respondent, nor was this raised by the first respondent, so that the disclosure can be deemed deficient in this regard and constitutes a violation of the right under Article 15(1), second sentence, of the GDPR. To what extent the disclosure of the master data—most of which is publicly accessible anyway —master data—are counterbalanced by conflicting interests on the part of the first respondent is not apparent to the Data Protection Authority, nor was it raised by the first respondent; consequently, the information provided can be deemed deficient in this regard, and there is a violation of the right under article 15, paragraph 1, second sentence of the GDPR. b) Information regarding the purposes of data processing (Article 15(1)(a) GDPR)b) Information regarding the purposes of data processing (Article 15, paragraph 1, subparagraph (a), GDPR) Information must be provided regarding the purposes of the processing within the meaning of Art. 5(1)(b) of the GDPR.

§

Although the legal basis for the processing within the meaning of Art. 6(1) of the GDPR or Art. 9(2) of the aforementioned regulation is not explicitly mentioned as part of the information to be provided; however, since the lawfulness of processing generally cannot be assessed without this information—which is the very purpose of the right of access (see Recital 63, para. 1 of the GDPR), the legal basis is implicitly covered by the right of access (see Haidinger in Knyrim [ed.], DatKomm, Art. 15 GDPR, para. 37; and Jahnel in Jahnel [ed.], Commentary on the General Data Protection Regulation, Art. 15 GDPR, para. 22).The purposes of the processing within the meaning of Article 5(1)(b) of the GDPR must be disclosed. Although the legal basis for the processing within the meaning of Article 6(1), paragraph 1. cit. or Article 9(2), leg. cit., is not expressly mentioned as part of the information to be provided; however, since the lawfulness of processing generally cannot be assessed without this information—which is the very purpose of the right of access—see Recital 63, para. 1 of the GDPR), the legal basis is implicitly covered by the right of access (see Haidinger in Knyrim [ed.], DatKomm, Article 15, GDPR, para. 37; as well as Jahnel in Jahnel [ed.], Commentary on the General Data Protection Regulation, Article 15, GDPR, para. 22).

§

With regard to the purposes, the first respondent again refers exclusively to the user profile (see Section C.10.). However, since the first respondent did not mention the media coverage from September 1, 2021, in the information it provided and, moreover, did not cite any exception, that would explain why the purpose of processing the data in the context of media coverage—which is in any case publicly known—should not be disclosed, the first respondent has, in conclusion, only partially fulfilled its obligation to provide information under Article 15(1)(a) of the GDPR. Since the first respondent, in the context of her response to the request for information, did not mention the media coverage from September 1, September 2021 in its response to the request for information and, moreover, did not cite any exception—which would explain why the purpose of processing the data in the context of media coverage, which was already publicly known, would not need to be disclosed—the respondent has, in conclusion, only partially fulfilled its obligation to provide information under Article 15, paragraph 1, (a) of the GDPR. c) Information on the categories of personal data being processed (Art. 15(1)(b) GDPR)c) Information on the categories of personal data being processed (Article 15, paragraph 1, subparagraph (b), GDPR) The controller must also specify the categories of data being processed.

§

Since Article 15(1), first sentence, of the GDPR already requires disclosure of the specific data being processed, the added value of the additional information under para 1(b) lies lies in the fact that, through additional information regarding the grouping or categorization by data type, the data subject can quickly gain an overview of the categories of data (see Jahnel in Jahnel [ed.], Commentary on the General Data Protection Regulation, Art. 15 GDPR, para. 23; see also Haidinger in Knyrim [ed.], DatKomm, Art. 15 GDPR, para. 38).The controller must also specify the categories of data being processed. Since article 15(1), first sentence, of the GDPR already requires disclosure of the specific data being processed, the added value of the additional information under paragraph 1(b) lies cit., is that the data subject can quickly gain an overview of the categories of data through additional information regarding the grouping or aggregation by type of data; see Jahnel in Jahnel [ed.], Commentary on the General Data Protection Regulation, Article 15, GDPR, margin note 23; see also Haidinger in Knyrim [ed.], DatKomm, article 15, GDPR, margin note 38).

§

Since the first respondent also disclosed, on this point, only categories of data related to the user profile (see section C.10.) and, as noted in section a) regarding the media coverage of September 1, September 2021, there is no justifying exception to the obligation to provide information in this case either; therefore, the information provided must also be deemed deficient on this point. d) Recipients or categories of recipients (Art. 15(1)(c) GDPR)d) Recipients or categories of recipients (Article 15, paragraph 1, subparagraph (c), GDPR) The CJEU has already held that the right of access to information regarding the recipients or categories of recipients serves as a means to carry out the necessary verifications and, in particular, to verify whether the recipients are authorized to engage in data processing (see the CJEU judgement of May 7, May 2009, C-553/07 [Rijkeboer], para. 49).The CJEU has already held that the right to obtain information about the recipients or categories of recipients serves as a tool to carry out the necessary verifications and, in particular, to verify whether the recipients are authorized to engage in data processing; see the judgement of the CJEU of May 7, May 2009, C-553/07 [Rijkeboer], para. 49).

§

Pursuant to Article 15(1)(c) of the GDPR, the controller must inform a data subject of the recipients or categories of recipients to whom the personal data have been or will be disclosed. Pursuant to Article 15(1)(c) of the GDPR, the controller must inform a data subject of the recipients or categories of recipients to whom the personal data have been or will be disclosed. As can be seen from the findings, the first respondent informed the first complainant that the data is processed by its IT service providers and by enterprises within the M*** Group (see Point C.10.). However, no information was provided regarding the public disclosure inherent in the online edition of September 1, 2021 (see Point C.4.). Thus, it should at least have been disclosed that the data became available to the general public as a result of the article. No conflicting interest worthy of protection can be identified.

§

It could not be determined during the investigation whether any further transfers took place. The information provided therefore appears to be insufficient on this point as well. e) Planned storage period (Art. 15(1)(d) GDPR)e) Planned storage period (Article 15, paragraph 1, subparagraph (d), GDPR) The controller must, if possible, provide information on the intended duration for which the personal data will be stored or, if this is not possible, the criteria for determining that duration. According to the findings, the first respondent did not inform the first complainant—neither in connection with the user profile nor in connection with the media coverage—of the period for which the personal data will be stored or the criteria for determining that period. No conflicting legitimate interest that would justify withholding information regarding the storage period can be identified. Consequently, the respondent has failed to comply with its obligation to provide information under Article 15(1)(d) of the GDPR.

§

Consequently, the respondent has failed to comply with its obligation to provide information under Article 15(1)(d) of the GDPR. f) Information regarding the data subject rights and the right to lodge a complaint with a supervisory authority (Article 15(1)(e) and (f) of the GDPR)f) Information regarding data subject rights and the right to lodge a complaint with a supervisory authority (article 15(1)(e) and (f) of the GDPR) Information regarding the data subject’s rights and the right to lodge a complaint with a supervisory authority must be provided unsolicited when the data subject exercises the right of access. This information is limited to an abstract reference to these rights (see Haidinger in Knyrim [ed.], DatKomm, Art. 15 GDPR, para. 47; and Jahnel in Jahnel [ed.], Commentary on the General Data Protection Regulation, Art. 15 GDPR, para. 30).Information regarding the data subject’s rights, as well as the right to lodge a complaint with a supervisory authority, must be provided without being requested when the data subject exercises the right of access.

§

This information is limited to an abstract reference to these rights; see Haidinger in Knyrim [ed.], DatKomm, Article 15, GDPR, para. 47; as well as Jahnel in Jahnel [ed.], Commentary on the General Data Protection Regulation, Article 15, GDPR, para. 30). As established, the first respondent informed the first complainant of his data subject rights as well as his right to lodge a complaint with the Data Protection Authority; therefore, no deficiency in the information provided can be identified on this point. Information regarding the origin of the personal data, if such data was not collected from the data subject (Art. 15, para. 1, subparagraph g, GDPR)g) Information regarding the origin of the personal data, if such data was not collected from the data subject (Article 15, paragraph one, subparagraph g, GDPR) Pursuant to Article 15(1)(g) of the GDPR, if the personal data was not collected from the data subject, the data subject has the right to access all available information regarding the origin of the data.Pursuant to Article 15(1)(g) of the GDPR, if the personal data was not collected from the data subject, the data subject has the right to access all available information regarding the origin of the data.

§

Based on the foregoing, a refusal to provide information regarding the origin of the data would be justified if the confidentiality interests of the first respondent or third parties (specifically: the first respondent’s source of information) outweigh the first complainant’s interest in obtaining such information. Pursuant to § 31(1) of the Media Act (MedienG), media owners, publishers, media employees, and employees of a media company or media service have the right to refuse, as witnesses in criminal proceedings or in any other proceedings before a Court or an administrative authority, to answer questions concerning the identity of the author, contributor, or source of contributions and documents, or concerning information disclosed to them in connection with their work. According to para (2) of that section, the right set forth in para (1) may not be circumvented, in particular by requiring the entitled person to surrender documents, printed works, image or sound recordings, or data storage media, illustrations, and other representations containing such content, or by having them seized.

§

In accordance with Paragraph 31(1) of the Media Act (MedienG), media owners, publishers, media employees, and employees of a media company or media service have the right refuse, as witnesses in criminal proceedings or in any other proceedings before a Court or administrative authority, to answer questions concerning the identity of the author, contributor, or source of contributions and documents, or concerning information disclosed to them in connection with their work. Pursuant to paragraph 2 thereof, the right set forth in paragraph 1 may not be circumvented, in particular by requiring the entitled party to surrender documents, printed works, image or sound recordings, data storage media, illustrations, or other representations containing such content, or by seizing them. Since the first respondent is undisputedly a media company and disclosing the origin of the data would circumvent the protection of editorial confidentiality established in § 31 of the Media Act (MedienG), the first respondent was correct in refusing to provide information on this point.Since the first respondent is undisputedly a media company and disclosing the origin of the data would circumvent the protection of editorial confidentiality as stipulated in Section 31 of the Media Act (MedienG), the first respondent was correct to refuse to provide the information on this point. h) Existence of automated decision-making, including profiling (Article 15(1)(h) of the GDPR)h) Existence of automated decision-making, including profiling (Article 15(1)(h) of the GDPR) The first respondent did not provide any information on this matter; however, there is no evidence in the present proceedings that automated decision-making is taking place, which is why there was no information to provide in this regard. i) Provision of a copy pursuant to Article 15(3) GDPRi) Provision of a copy pursuant to Article 15, paragraph 3, GDPR Pursuant to Article 15(3) of the GDPR, the controller shall provide the data subject with a copy of the personal data that is the subject of the processing.Pursuant to Article 15(3) of the GDPR, the controller shall provide the data subject with a copy of the personal data undergoing processing.

§

With regard to the alleged failure to provide a copy within the meaning of Art. 15(3) of the GDPR regarding the “email message” underlying the media reports—which was leaked to the first respondent by a third party—reference may be made to the balancing of interests set forth in point (g). Thus, even the provision of a copy pursuant to Article 15(3) would amount to a circumvention of the cited editorial privilege. With regard to the alleged failure to provide a copy within the meaning of Article 15(3) of the GDPR regarding the “email message” underlying the media coverage—which was leaked to the first respondent by a third party—reference may be made to the balancing of interests set forth in point g). Thus, even the provision of a copy pursuant to article 15(3) would amount to a circumvention of the aforementioned editorial confidentiality. Overall, the decision was therefore to be rendered in accordance with the ruling.

§

Regarding Point III of the Ruling Regarding the Mandate Pursuant to Article 58(2)(c) of the GDPR, the first respondent was therefore ultimately ordered to comply with the first complainant’s request for access to his personal data—in accordance with Point II of the ruling.Pursuant to Article 58(2)(c) of the GDPR, the first respondent was therefore ultimately required to comply with the first complainant’s request for access to his personal data—in accordance with Point II of the ruling. A period of four weeks appears reasonable to comply with this order. The decision was therefore rendered in accordance with the ruling. Regarding Ruling Point IV 2) To the Second Respondent As can be seen from the findings, the first respondent provided neither substantive information nor any other response—in particular, no explanation of the reasons for the failure to comply—but, despite the successful service of the request for access, simply remained inactive (see Point C.9.).

§

Consequently, by failing to respond in this instance, the first respondent violated its obligation under Article 12(3) and (4) of the GDPR and thereby infringed upon the second complainant’s right to access information pursuant to § 1(3)(1) of the Data Protection Act (DSG) in conjunction with Article 15(1) of the GDPR. Consequently, by failing to respond as described above, the first respondent violated its obligations under Article 12, paragraphs 3 and 4, GDPR and thereby violated the second complainant’s right of access pursuant to Section 1, paragraph 3, item 1, of the Data Protection Act (DSG) in conjunction with article 15, paragraph 1, of the GDPR. The complaint was therefore upheld. Regarding Point V of the Ruling Regarding the Mandate Pursuant to para 58(2)(c) of the GDPR, the first respondent was therefore ultimately ordered to comply with the second complainant’s request for access to her personal data or to disclose why the provision of such information is not possible in specific instances (e.g., due to existing exceptions).

§

Pursuant to Article 58, paragraph 2, Subparagraph (c), GDPR, the first respondent was therefore ultimately ordered to comply with the second complainant’s request for access to her personal data or to explain why providing access to specific items of data might not be possible (e.g., due to existing exceptions). A period of four weeks appears reasonable to fulfill this obligation. It was therefore decided in accordance with the ruling. Regarding Point V of the Ruling (Roman numeral six) Regarding the Second Respondent’s Response to the Request for Information 1) To the First Complainant As determined, in its response dated October 11, October 2021, the second respondent provided the first complainant exclusively with information regarding his master data in connection with his N***-DIGITAL-SAT card and in connection with the processing of his data pursuant to the request for information.

§

With regard to the processing activities related to the aforementioned points, the information provided—in accordance with the findings—fully complied with the requirements set forth in Article 15(1)(a) through (h) and (3) of the GDPR from the perspective of the Data Protection Authority. The initial complainant did not object to the information provided in connection with his N***-DIGITAL-SAT card and the request for information he had submitted. Rather, he considers the information to be incomplete—as already discussed at the outset—because he did not receive any information regarding the personal data related to the report of the compromise of the second complainant’s email account.With regard to the processing activities related to the aforementioned points, the information provided—in accordance with the findings—fully complied with the requirements of article 15, paragraph 1, subparagraphs (a) through (h), and paragraph 3 of the GDPR, from the perspective of the Data Protection Authority.

§

The first complainant did not object to the information provided in connection with his N***-DIGITAL-SAT card and the request for information he had submitted. Rather, he considers the information to be incomplete—as already discussed at the outset—because he did not receive any information regarding the personal data related to the media reports on the compromise of the second complainant’s email account. The detailed review cited above, which included a balancing of interests regarding the first respondent, may also be applied—in light of the media coverage on September 1, September 2021, also be applied to the information to be provided by the second respondent to the first complainant regarding the media coverage, given the similar balance of interests. Specifically, with regard to the media coverage of September 1, 2021, the second respondent should therefore also have provided the following information to the first complainant: - Information regarding the specific (master) data processed (Art. 15(1) GDPR)Information regarding the specific (master) data processed (Article 15, paragraph 1, GDPR) - Information regarding the purposes of data processing (Art. 15(1)(a) GDPR)Information regarding the purposes of data processing (Article 15, paragraph 1, subparagraph (a) of the GDPR) - Information regarding the categories of personal data being processed (Art. 15(1)(b) GDPR)Information regarding the categories of personal data being processed (Article 15, paragraph 1, subparagraph (b), GDPR) - Recipients or categories of recipients (Art. 15(1)(c) GDPR)Recipients or categories of recipients (Article 15(1)(c) GDPR) - Intended duration of storage (Article 15(1)(d) GDPR).Intended duration of storage (Article 15, paragraph 1, subparagraph (d), GDPR).

§

With regard to the provision of information on the origin of the personal data pursuant to Art. 15(1)(h) GDPR and Art. 15(3) GDPR, reference is made to point II, subpoint 1) g), and the second respondent was justified in refusing to provide the information on this point.With regard to the provision of information about the origin of the personal data pursuant to Article 15(1)(h) of the GDPR and Article 15(3) of the GDPR, reference may be made to the discussion under Roman numeral II, point 1) g), and the second respondent was justified in refusing to provide the information on this point. The complaint was therefore found to be justified on the aforementioned points, and a violation of the right of access to the extent cited was established in accordance with the ruling. Regarding Ruling Point VII Regarding Ruling Point VII Regarding the Mandate Pursuant to Article 58(2)(c) of the GDPR, the second respondent was therefore ultimately ordered to comply with the first complainant’s request for access to his personal data—in accordance with Ruling Point VI.Pursuant to Article 58(2)(c) of the GDPR, the second respondent was therefore ultimately directed to comply with the first complainant’s request for access to his personal data—in accordance with Point VI of the ruling.

§

A period of four weeks appears reasonable to comply with this order. The decision was therefore rendered in accordance with the ruling. Regarding Ruling Point VIII (Roman numeral eight) 2) To the Second Respondent Since the interests involved with regard to the disclosure of data by the second respondent to the second complainant are similar to those involved in the disclosure of data by the second respondent to the first complainant, disclosure of data to the extent specified (see D.4.1., “Regarding Point VI of the Ruling” Regarding the disclosure of information by the second respondent 1) To the first complainant). Since, with regard to the disclosure of information by the second respondent to the second complainant, the interests involved are similar to those in the case of the disclosure of information by the second respondent to the first complainant, information should, in principle, also be provided in this context to the extent specified (see D.4.1., “Regarding Ruling Point VI” on the disclosure of information by the second respondent 1) to the first complainant).

§

However, since the second complainant requested information from the second respondent exclusively within the meaning of § 1(3)(1) of the Data Protection Act (DSG) regarding “which data and trade secrets are processed for what purpose and to whom they have been or will be transmitted,” and since the request for information defines the scope of review in the complaint proceedings, the following analysis focused exclusively on the completeness of the information provided on those points.However, since the second complainant requested from the second respondent exclusively information within the meaning of paragraph 1(3)(1) of the Data Protection Act (DSG) regarding “which data and trade secrets are being processed for what purpose and to whom they have been or will be disclosed,” and since the request for information defines the scope of review for the appeal proceedings, the following analysis must focus exclusively on the completeness of the information provided on those specific points.

§

The second respondent would therefore have been required to provide the following information: - Information regarding the specific (master) data processed (Section 1(3) in conjunction with Article 15(1) of the GDPR)Information regarding the specific (master) data processed (Section 1(3) in conjunction with Article 15(1) of the GDPR) - Information regarding the purposes of data processing (Section 1(3) in conjunction with Article 15(1)(a) of the GDPR)Information regarding the purposes of data processing (Section 1, paragraph 3, in conjunction with article 15, paragraph 1, subparagraph (a) of the GDPR) - Recipients or categories of recipients (Section 1, Para 3, in conjunction with Article 15, Para 1(c) of the GDPR).Recipients or categories of recipients (Section 1, paragraph 3, in conjunction with article 15, paragraph 1, subparagraph (c), of the GDPR). The complaint was therefore found to be justified on the points mentioned, and a violation of the right of access to the extent specified was to be established in accordance with the ruling.

§

Regarding Point IX of the Ruling Regarding the Mandate Pursuant to Article 58(2)(c) of the GDPR, the second respondent was therefore ultimately ordered to comply with the second complainant’s request for access to her personal data—in accordance with Point VIII of the ruling.Pursuant to Article 58(2)(c) of the GDPR, the second respondent was therefore ultimately required to comply with the second complainant’s request for access to her personal data—in accordance with Ruling Point VIII. A period of four weeks appears reasonable to comply with this order. It was therefore made in accordance with the ruling. Regarding Point X (Roman numeral ten) D.5. Regarding the Alleged Violation of the Right to Confidentiality In this matter, the second complainant seeks a finding that the first respondent violated her right to confidentiality, by disclosing to the second respondent the receipt and content of the response to the request for erasure submitted by the second appellant to the first respondent.

§

D.5.1. General Remarks on the Right to Confidentiality Pursuant to § 1(1) of the Data Protection Act (DSG), every person has the right to confidentiality regarding personal data concerning them, provided there is a legitimate interest therein. The existence of such an interest is precluded if data are not subject to a right to confidentiality due to their inability to be traced back to the data subject. The GDPR, and in particular the principles enshrined therein, must be consulted when interpreting the right to confidentiality (see the decision of the DPA dated October 31, 2018, Ref. No. DPA-D123.076/0003-DPA/2018). Pursuant to Section 1, paragraph 1, of the Data Protection Act (DSG), every person has the right to confidentiality regarding personal data concerning them, provided there is a legitimate interest therein. The existence of such an interest is excluded if data cannot be subject to a right to confidentiality due to the inability to trace them back to the data subject.

§

The GDPR, and in particular the principles enshrined therein, must be used to interpret the right to confidentiality; see the DPA’s decision of October 31, 2018, Ref. No. DPA-D123.076/0003-DPA/2018). Restrictions on the right to confidentiality are permissible under Section 1(2) of the DSG if personal data is used in the vital interest of the data subject, if the data subject has given their consent (or, in the terminology of the GDPR: consent), if there is a qualified legal basis for the use, or if the use is justified by the overriding legitimate interests of a third party.Restrictions on the right to confidentiality are permissible under Section 1, paragraph 2, of the DSG if personal data is used in the vital interest of the data subject, if the data subject has given his or her consent (or, in the terminology of the GDPR: consent) has been given, if there is a qualified legal basis for the use, or if the use is justified by the overriding legitimate interests of a third party.

§

D.5.2. On the Lawfulness of the Processing In the present case—as also implicitly argued by the first respondent—data processing based on overriding legitimate interests within the meaning of § 1(2) of the DSG or Art. 6(1)(f) of the GDPR may serve as a justification.In the present case—as also implicitly argued by the first respondent—data processing based on overriding legitimate interests within the meaning of Section 1(2) of the DSG or article 6(1)(f) of the GDPR may serve as a basis for justification. To this end, the legitimate interests of the second complainant must be assessed and weighed against the legitimate interests of the first respondent (and, where applicable, third parties). In the context of this balancing of interests, it must be taken into account that two cumulative conditions must be met for the first respondent to rely on this legal basis: on the one hand, the processing must be necessary to safeguard the legitimate interests of the controller or a third party; and, on the other hand, the fundamental rights and freedoms of the data subject (in this case, the second complainant) that require the protection of personal data must not override those interests (see the judgement of the CJEU of November 24, 2011, C-468/10 and C-469/10 [ASNEF and FECEMD], para. 38; see also the judgement of the CJEU of May 4, 2017, C-13/16 [Rīgas satiksme] para. 28).

§

In the context of this balancing of interests, it must be taken into account that two cumulative conditions must be met for the first respondent to rely on this legal basis: on the one hand, the processing must be necessary to safeguard the legitimate interests of the controller or a third party; and, second, the fundamental rights and freedoms of the data subject (in this case, the second appellant), which require the protection of personal data, must not override those interests; see the judgement of the CJEU of November 24, 2011, C-468/10 and C-469/10 [ASNEF and FECEMD], para. 38; see also the judgement of the CJEU of May 4, 2017, C-13/16 [Rīgas satiksme] para. 28). Furthermore, when balancing interests, it must be considered whether a data subject, at the time the personal data is collected and in light of the circumstances under which it is collected, can reasonably foresee that processing for this purpose may take place.

§

The balancing must be conducted from an objective perspective and not from the subjective perspective of individual data subjects; thus, individual sensitivities are not to be taken into account (see Kastelitz/Hötzendorfer/Tschohl, loc. cit., para. 51).Furthermore, when balancing interests, consideration must be given to whether a data subject, at the time the personal data is collected and in light of the circumstances under which it is collected, can reasonably foresee that processing for this purpose may take place. The balancing of interests must be conducted from an objective perspective and not from the subjective perspective of individual data subjects; thus, individual sensitivities must not be taken into account (see Kastelitz/Hötzendorfer/Tschohl, loc. cit., para. 51). D.5.3. On the Merits The first respondent argued in this context that the processing was carried out in its capacity as a media company due to the necessary coordination with the second respondent within the framework of the research consortium.

§

In a democratic society, the media play a central role in the public interest as a “public watchdog” (see, e.g., ECtHR, Nov. 8, 2016 [GK], Magyar Helsinki Bizottság case, Application No. 18.030/11; Constitutional Court, March 4, 2021, E 4037/2020), which is why coordination within the framework of a reporting consortium must also be recognized as a legitimate interest—as a consequence of the freedom of expression under Art. 10 of the ECHR and Art. 11 of the CFR. In a democratic society, the media play a central role in the public interest as a “public watchdog”—see, e.g., ECtHR, Nov. 8, 2016 [Grand Chamber], Magyar Helsinki Bizottság case, Application No. 18.030/11; Constitutional Court (VfGH) decision of March 4, 2021, E 4037 from 2020), which is why coordination within a research consortium must also be recognized as a legitimate interest—as a consequence of the freedom of expression under article 10 of the ECHR and article 11 of the CFR.

§

Article 11 of the EU CFR establishes two interrelated areas of protection: on the one hand, the (active) freedom of expression of the speaker and, on the other hand, the (passive) freedom of information of the recipient. The interaction of these two elements ensures an exchange of information and opinion in the sense of a comprehensive freedom of communication. Article 11 of the EU CFR establishes two interrelated areas of protection: on the one hand, the speaker’s (active) freedom of expression and, on the other hand, the recipient’s (passive) freedom of information. The interaction of these two elements ensures an exchange of information and opinion in the sense of a comprehensive freedom of communication. It must therefore be examined whether the legitimate interests of the first respondent—namely, the exchange of information between the respondents—outweigh the second complainant’s interest in the protection of her personal data.

§

First, it should be noted that on September 2, 2021, the second complainant received identical requests from both respondents (see point C.6.) for the erasure of the message that formed the basis for the respondents’ reporting on September 1, September 2021 (see points C.4. and C.5.) (see point C.6.). In view of the response necessitated by the requests—and given the identical nature of the requests and the existing investigative partnership—a uniform approach or decision regarding the erasure of the message underlying the reporting was required. Moreover, the second complainant could have anticipated such a course of action, as she was well aware that the respondents operated a joint research initiative—a fact she had even mentioned herself in her motion to initiate proceedings dated November 26, November 2021 (see point A.1.). Likewise, it is not apparent to the Data Protection Authority to what extent less intrusive means would exist to achieve the intended purpose of exchanging information within the investigative consortium existing among the respondents; therefore, this constitutes the least intrusive means available.

§

The Data Protection Authority therefore concludes, based on an overall assessment, that—given the balancing of interests conducted—there is no violation of the right to confidentiality, since the interests of the first respondent (freedom of expression) outweigh the interests of the first complainant (fundamental right to confidentiality). The decision was therefore rendered in accordance with the ruling.

How it connects

107 of 110 paragraphs apply legislation or carry a topic — see them in the full text ↓