Skip to content
Enforcement · DSB ·2026-0.483.002 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

DSB · 2026-0.483.002

The DPA fined a medical services employee €1,200 for photographing two patients and sharing the images with unauthorised third parties because they contained health data under Article 9(1) GDPR.

Status Not cited by any decision here yet

€1,200 Fine
Austria

Full text

Machine translation of the decision, via GDPRhub — not the official text.

The DPA fined a medical services employee €1,200 for photographing two patients and sharing the images with unauthorised third parties because they contained health data under Article 9(1) GDPR. English Summary. Facts. The employee, acting as a controller, was working for a rescue and aid organisation that operated a care facility for people with special needs. Between 1 December and 19 December 2025, he used his private smartphone to photograph two patients in wheelchairs. Their physical impairments and their use of care or health services were visible in the pictures, meaning that the images revealed information about their health. The images were shared to third parties through a chat application. The controller made the decision to take and disclose the photographs himself, acted outside his work duties and did not pursue any purpose connected with caring for the patients or operating the facility. The organisation informed the DPA of the incident. Holding. First, the DPA held that

How it connects

C-667/21 ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts The CJEU (Third Chamber) ruled on a preliminary reference from the Bundesarbeitsgericht in a case where ZQ sought compensation from his employer, Medizinischer Dienst der… CJEU ·Third Chamber Dec 21, 2023 Health Data Healthcare Integrity and Confidentiality Principle
C-203/22 CK v Magistrat der Stadt Wien In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien… CJEU ·First Chamber Feb 27, 2025 Profiling Automated Decision-Making Marketing
C-21/23 ND v DR In Case C-21/23, the Court of Justice of the European Union (Grand Chamber) ruled on a preliminary reference from the German Bundesgerichtshof in proceedings between two competing… CJEU ·Grand Chamber Oct 4, 2024 Healthcare Health Data Types of Special Categories of Personal Data
W292 2292202-1 The data subject is in the military The unit he is employed at (controller) and the data subject are involved in a multitude of legal disputes concerning his employment, disciplinary proceedings, data protection… BVwG - W292 2292202-1 ·Federal Administrative Court Jun 30, 2026 Health Data Integrity and Confidentiality Principle Healthcare
C‑474/24 NADA Austria and Others C‑474/24 - NADA Austria and Others Several data subjects were subject to suspension proceedings by the Austrian Anti-Doping Legal Commission (ÖADR). Under Austrian law, the National Anti-Doping Agency (“NADA”)… CJEU Jul 24, 2026 Criminal Data Material scope (GDPR) Types of Special Categories of Personal Data