DSB: Google violated Art. 15 GDPR by providing incomplete YouTube access request data
A data subject, represented by noyb, brought a complaint against Google LLC (the controller) in January 2019.
Status Not cited by any decision here yet
Original title: DSB (Austria) - 2025-0.626.844
Holding
The DPA first emphasised the importance of the right to access (Article 15 GDPR), as it enables the data subject to verify whether a controller is processing personal data lawfully. In addition, Article 12(2) GDPR places an obligation on controllers to facilitate data subjects in exercising their rights. The DPA then dismissed the controller’s argument to reject the complaint, as Google LLC was the controller at the time the case was filed with the DPA. Furthermore, the DPA stated that it would have not dismissed the case even if the data subject had not chosen an entirely accurate name for the controller; it was clear that the data subject wanted to prosecute the entity responsible for the YouTube service. The DPO was considered responsible for handling the complaint, as the Irish branch was not considered the controller for YouTube. The DPA found a violation of Article 12(1) GDPR. The download portal provided information in formats design for machine processing, meaning it was not accessible for the average data subject. In addition, the controller stated that someone of the information may have been available in other secure online tools; this meant the data subject could not access a complete copy of their data through the online portal. The DPA also found violation of Article 15 GDPR, as the controller had not given the data subject sufficient information. According to the DPA, the controller’s privacy policy can fulfil the information obligations of Article 13 and 14 GDPR, but not Article 15 GDPR. This is because it is general information and may not apply to the data subject. The controller must also provide specific information relevant for the data subject, meaning it is not enough to give general statements. This applied to the processing purposes, categories of data, storage periods, tracking, and recipients of data. For the recipients of data, the DPA noted that as a leading IT company the controller could specify the specific recipients of the personal data, and the safeguards in place for third country transfers. The DPA ordered the controller to provide the data subject with a complete copy of their data. The DPA specified that referring to its privacy policy or the different online tools the data subject could use to compile the information themselves was not enough to comply with Article 12 GDPR.
From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓
According to the data subject, the controller did not provide them with complete information following an access request for the YouTube service; instead, the controller provided limited information through a download portal, which excluded information the controller stated it would process in accordance with its privacy policy. For example, the data provided did contain information on the data processed through cookies or Facebook pixels. The DPA initiated the One-Stop Shop procedure and forwarded the case to the Irish DPA, who also believed it should be considered the lead DPA for the proceedings. However, the Irish DPA ultimately declared it was not responsible in 2022, and referred the case back to the DPA. The controller argued that the data subject had incorrectly initiated proceedings against them, as it was not the controller within the meaning of the GDPR. In addition, it argued that the data subject had received complete information and that its DPO was not responsible.
Full text
Machine translation of the decision, via GDPRhub — not the official text.
Barichgasse 40-42 A-1030 Vienna Tel.: +43-1-52152 E-mail: dsb@dsb.gv.at Reference number: D130.200 Officer: 2025-0.626.844 Attn: NOYB - European Center for Digital Rights Data Protection Complaint (Right to Information) /Google LLC via email: DECISION RULING The Data Protection Authority decides on the data protection complaint filed by , represented by NOYB - European Center for Digital Rights, dated January 18, 2019, against Google LLC (respondent), represented by Baker McKenzie Attorneys at Law for violation of the right to information as follows: 1. The complaint is upheld, and it is determined that the respondent has violated the complainant's right to information by incomplete information and the manner in which the information was provided violated his rights under Art. 15 GDPR in conjunction with Art. 12 GDPR. 2. The respondent is ordered to provide the complainant with complete information within the meaning of Art. 15 (1) and (2) GDPR regarding all personal data relating to him that are processed and to provide a copy of this personal data in an easy-to-understand and readable format within a period of four weeks, failing which he will be liable to execution. Legal basis: Article 12 (1) and (2), Article 15, Article 51 (1), Article 57 (1) (f), and Article 77 (1) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR), OJ No. L 119 of 4 May 2016, p. 1; Sections 18 (1) and 24 (1) and (5) of the Data Protection Act (DSG), Federal Law Gazette I No. 165/1999, as amended. - 2 - R E A S T I O N A. Arguments of the parties and course of proceedings Comment by the Data Protection Authority on the course of proceedings: The course of proceedings does not constitute a legally binding element, but is optional. Therefore, there is generally no need to separately state the parties' submissions in the grounds for the decision (cf. Hengstschläger/Leeb, AVG § 60 para. 22 (as of March 1, 2023, rdb.at)). Due to the excessively long duration of the proceedings and their inherent complexity, which is caused by the large number of submissions from the parties to the proceedings and letters from the authorities involved, the DPA therefore limits itself to an overview of the procedure and the parties' submissions. A.1. By filing the initial submission of January 18, 2019, the complainant (hereinafter: BF) filed a complaint with the Data Protection Authority regarding incomplete information about his personal data by the respondent (hereinafter: BG). He was provided with only some rudimentary information via a download portal, which did not even fully cover the information that the BG stated in its own data protection policy that it would process. A.2. The DPO initiated the One-Stop Shop procedure on January 31, 2019, by forwarding the complaint to the Irish Data Protection Authority (DPC) and suspending the procedure pursuant to Art. 56 in conjunction with Art. 60 GDPR. At that time, both the DPC and the DPO were of the opinion that the Irish Data Protection Authority should be considered the lead supervisory authority for this procedure. A.3. However, by letter dated November 17, 2022, the Irish Data Protection Authority ultimately declared itself not to be competent and referred the case back to the DPO, which subsequently revoked the suspension decision (see section A.2.) and continued the procedure. A.4. The Federal Complaints' Association, now represented by Baker McKenzie Attorneys at Law, submitted a statement in a letter dated February 1, 2023, and summarized, as far as relevant to the proceedings, that the complaint should be dismissed or rejected because the Federal Complaints' Association had not correctly named the Federal Complaints' Association, which - 5 - Fig. Screenshot from the file, index of files downloaded by the Federal Complaints' Association Evaluation of evidence: This finding is based on the Federal Complaints' undisputed submissions and the therefore undisputed file. C.4. In addition to other categories of personal data of data subjects, the Federal Complaints' Association explicitly also processes personal data generated from cookies or Facebook pixels, as well as the IP address. However, the information provided to the Federal Complaints' Association did not contain any information regarding these data categories. Fig.: Screenshot of the Federal Complaints' privacy policy, submitted by the Federal Complaints' Association in its initial submission. Evaluation of evidence: This finding is based on the undisputed file. - 6 – C.5. In its complaint, the Federal Complaints Court explicitly named, among others, the now-contracting company "Google LLC." The named respondent was the data protection controller for the "YouTube" service at the time of the application and at the time of the filing of the complaint. Fig. Complaint by the Federal Complaints Court dated January 18, 2019, naming Google LLC as the respondent. Fig. Screenshot of a document submitted by the Contracting Company in the ongoing proceedings (certified German translation of the amendment to the Contracting Company's terms of use). Evaluation of evidence: The finding regarding the designation of the respondent is based on the documented submissions of the Federal Complaints Court. The finding regarding the status of the Contracting Company as the controller is based on its own submissions. This shows that - 7 - Google LLC, as the BG, was the data protection controller for the YouTube service both at the time of the application (October 2, 2018) and at the time of the complaint (January 18, 2019). C.6. Regarding the following categories of personal data and the personal data about him from these categories processed by the BG, the BF was merely referred to several online tools for download and to the BG's privacy policy: Tracking, cookies, advertising profiles, processing purposes, recipients, retention periods, data subject rights, the right to lodge a complaint with the supervisory authority, the data sources, and the appropriate safeguards for third-country transfers. Personalized information for the BF regarding the above-mentioned data categories and other information was not provided until the conclusion of the present proceedings. Evaluation of evidence: This finding is based on the uncontested submission of the Federal Court of Justice of February 1, 2023, and the thus undisputed state of the case file. D. From a legal perspective, this leads to the following: D.1. On the right to information in general According to Art. 15 GDPR, a data subject has the right to request confirmation from the controller as to whether personal data concerning him or her are being processed. If this is the case, the data subject also has the right to information about this personal data and about the information listed in Art. 15 (1) (a) to (h) GDPR, and, if necessary, additionally about the information pursuant to paragraph 2 of this provision. Furthermore, according to Art. 15 (3) GDPR, the controller must provide a data subject with copies of the personal data that are subject to processing. The right to information is important for the data subject in several respects. It should first ensure that the data subject is aware of whether any data concerning him or her is being processed at all. If this is the case, the data subject should be able to learn which data is involved. This knowledge of the processing forms the basis for the data subject to verify the lawfulness of the processing. The right to information is also necessary so that the data subject can assert their rights to rectification, erasure, and blocking, as well as the right to object to processing (cf. Ehmann/Selmayr [eds], General Data Protection Regulation [Vienna 2017], Art. 15, para. 1). Art. 12 GDPR regulates the modalities for exercising data subject rights, such as the right of access. Paragraph 2 leg. cit. mentions the controller's explicit obligation to facilitate the exercise of data subjects' rights. Paragraph 1 of the GDPR mentions at this point - 8 - as does Recital 58 of the GDPR, the precise, understandable, and easily accessible form of the information provided. D.2. On the merits D.2.1. On the Respondent's Responsibility and the Competence of the Data Protection Authority As stated under point C.5., the data protection authority expressly named by the Federal Data Protection Authority in its complaint was the data protection controller for the processing of the Federal Data Protection Authority's personal data at the time of the application and at the time the complaint was lodged. A possible transfer of responsibility to another company (Google Ireland Ltd.) that may have occurred after this time is therefore irrelevant for the present proceedings, so that an examination of whether this change of responsibility actually occurred in practice or merely on paper for procedural purposes can be omitted. Regarding the Federal Complaint's allegation that the Federal Complaint did not clearly identify the respondent, it should first be noted that this allegation can be considered refuted based on the undisputed nature of the file alone (see also section C.5.). Furthermore, Section 24 (2) (2) of the Data Protection Act (DSG) requires the precise designation of the legal entity to which the infringement is attributed only "to the extent that this is reasonable." Even if the Federal Complaint had chosen an inaccurate designation in the present case, which could be considered excusable for a globally operating group with a complex structure such as the Federal Complaint, it is nevertheless clear that the Federal Complaint intended to prosecute the party responsible for the internet service "YouTube." In this context, reference is also made to the case law of the Federal Administrative Court (BVwG), according to which submissions must be understood objectively, i.e., the identifiable or inferable objective of a party's action is the benchmark for assessment, not an erroneously chosen designation or an accidental verbal form. Thus, no party may be assumed to intend to conduct proceedings that are pointless from the outset (BVwG of October 16, 2019, W258 2223924-1). The complaint was therefore not to be dismissed due to an inaccurate designation of the respondent or its lack of standing to be sued. The respondent is a company headquartered in the USA. According to Article 3 (2) (a) GDPR, the GDPR applies to the processing of personal data of data subjects located in the European Union by a controller not established in the Union if the data processing is related to the offer of goods or services to a data subject in the Union, regardless of whether a payment is required from that data subject (“market place principle”). - 9 - The term “service” is not further defined in the GDPR, but it must be interpreted broadly in light of the objectives of the GDPR. All that is required is a sufficiently recognizable intention of a controller or processor not established in the EEA to offer a service to persons located in the Union (cf. Recital 23, second sentence, GDPR). In the present case, the DPO has no doubt that the BG clearly intends to reach Austrian users with the “YouTube” service, thus opening up the territorial scope of the GDPR. Since, as stated above, the Federal Office for Consumer Protection is based in the USA and the Federal Office for Consumer Protection's branch in Ireland cannot be considered as the controller of the "YouTube" service during the relevant period under review, it can be concluded, as an interim conclusion, that the DPO is competent to handle the present complaint. D.2.2. On the inadequate provision of information D.2.2.1. On the specification of the request for information In its statement of February 1, 2023, the Federal Office for Consumer Protection complained that the Federal Office for Consumer Protection had not sufficiently specified its request. It should be countered that the Federal Office's request clearly indicates that it wishes to receive all information processed concerning it. Although a data subject may be asked to limit their request for information to certain processing activities, they are not required to do so and can insist on receiving complete information (Haidinger in Knyrim, DatKomm Art. 15 para. 11). It follows that the BG's argument cannot be followed at this point and that it must be assumed that a correctly submitted and therefore compliant request for information covers all of the data subject's personal data. Given that the BG is one of – if not the world's leading – IT groups, it should not be an insurmountable problem to locate and provide all of a data subject's personal data upon their request. D.2.2.2. On the modalities of the information provided As described in points C.3 and C.6. As determined, the Federal Office for Information Security (BG) fulfilled a small portion of the Federal Office's personal data using some files made available for download. The files were mostly in JSON or OPML formats. Regarding all other information and categories of personal data mentioned in section C.6, the Federal Office was referred to the Federal Office's privacy policy and various other online tools. - 10 - First of all, it should be noted that JSON and OPML are technically structured formats that are specifically designed for machine processing and are therefore difficult to understand for laypersons without IT knowledge (see Bizer/Müller, "Data Formats and Interoperability," 2020; Karagiannis, "Information Modeling and Design," 2019). Their sole use therefore contradicts the transparency requirement under Art. 12 (1) GDPR, since these formats are neither easily accessible nor easily understandable for the average data subject. However, Art. 12 GDPR requires easily accessible and understandable communication (see Recital 58). The obligation to provide information therefore also includes the understandable processing of the data, not just its technical provision, since a controller cannot automatically assume that a data subject has the necessary IT knowledge to understand files in the mentioned formats. With regard to the files provided in JSON and OPML formats, the information is therefore to be considered inadequate and thus unlawful. The Federal Employment Agency further pointed out that some information subject to disclosure under Art. 15 GDPR may already be found in some secure online tools. This suggests that in the "portal" for downloading personal data, as the Federal Employment Agency calls it, there is no central location from which data can be downloaded, but rather a data subject must compile the desired information from several tools. This is also supported by the note that one should contact support if one needs further information that is "not included in the tools." In its statement, the Federal Administrative Court cites the case law of the Federal Administrative Court on the general admissibility of a "portal" for downloading information pursuant to Art. 15 GDPR (W101 2132183-1/36E of September 11, 2020). As far as can be seen, however, the court only addressed the general question of the admissibility of such a portal, but not its specific design and the content of the information provided. However, these very questions are at the core of the present proceedings, so the findings made in the Federal Administrative Court's decision cannot be applied directly to the present case. Regardless of the method of transmission, all information must be complete and meet the requirements of Art. 12 GDPR. A portal where a data subject must gather personal data using multiple online tools and contact customer support if data is missing cannot be reconciled with the facilitation principle of Art. 12 (2) GDPR. This is also because, among other things, the data subject cannot be required to identify the missing information themselves and, if necessary, to request it, since they cannot yet be aware of which personal data is being processed. - 11 - The right under Art. 15 GDPR serves precisely to make them aware of such processing in the first place. In light of the above, the manner in which the information was provided in this specific case cannot therefore be considered lawful within the meaning of Art. 12 in conjunction with Art. 15 GDPR. D.2.2.3 On the content of the information provided As stated above, the BF was referred to the various parts of the BG's privacy policy regarding processing purposes, recipients, retention periods, data sources, appropriate safeguards for third-country transfers, as well as tracking and advertising. In this regard, it should first be noted in general terms that the privacy policy represents ex ante information for fulfilling the information obligations under Articles 13 and 14 GDPR. It is not personalized information for a data subject and therefore contains general information about the data processing activities of a controller, which, however, do not necessarily apply to an individual, e.g., different retention periods depending on the data category, which may not all apply to that individual. Complete information for an individual cannot therefore be achieved by simply referring to a general statement. ... Regarding the processing purposes and retention periods The Federal Administrative Court's data protection declaration lists a multitude of possible purposes regarding processing purposes, but does not address which of the Federal Administrative Court's data it processes for which purposes. According to the case law of the Federal Administrative Court, the information on the purposes pursuant to Art. 15 (1) (a) GDPR must precisely specify the specific purposes in the specific case of the applicant. It is therefore not sufficient to state the general purposes of the controller without clarifying which purposes it pursues in the case of the applicant. If the processing is carried out for multiple purposes, the controller must clarify which data categories are processed for which purposes (Federal Administrative Court of May 28, 2025, W108 2230691-1/53E). By merely referring generally and without further clarification to the purposes it pursued, the BG violated the BF's rights under Art. 15 (1) (a) GDPR. The above also applies mutatis mutandis to the planned storage period under Art. 15 (1) (d) GDPR. The BG also refers to its privacy policy, which, however, only states that "some data can be deleted at any time, others are automatically deleted," and yet others "can be stored for a longer period." At no point is the BF even remotely enabled to determine, at least approximately, which of his data will be processed, for what purpose, and for how long. - 12 - The information provided must therefore also be classified as inadequate with regard to the retention periods. Regarding data sources, recipients, and appropriate safeguards for third-country transfers The above statements can also be applied to the points of data sources, data recipients, and appropriate safeguards for third-country transfers. By simply referring to the data protection declaration, the Federal Data Protection Authority was merely informed that "its data may be collected from certain sources." Such information has no explanatory value, since every piece of data is collected from some source (even if it is only generated by the controller itself). Regarding the recipients (categories), the data protection declaration only lists possible categories of data recipients. In its decision of January 12, 2023 (C-154/21), the ECJ clarified that a controller must name the specific data recipients if they are known to it. The DPO has no doubt that the BG, as a world-leading IT group, can specify to which recipients it passes on which information about a specific person. Thus, the BF would have had to provide the specific recipients of its personal data. Finally, it should also be noted that insufficient information regarding the recipients of personal data also indicates inadequate information regarding the appropriate safeguards for third-country transfers. If a data subject does not even know where their data is being transferred to, even the reference in the data protection declaration to compliance with "certain legal framework conditions" cannot be considered lawful information within the meaning of Art. 15 (2) GDPR. The information is therefore also considered inadequate with regard to data sources, data recipients, and appropriate safeguards for third-country transfers. Conclusion The Federal Data Protection Authority (BG) responded to the applicant's request for information by providing him with a limited amount of information only in a machine-readable format and by referring him to several online tools with which he could download his personal data. In the event that anything was missing, the applicant was referred to the Federal Data Protection Authority's support team. Regarding the purposes of processing, storage duration, data sources, data recipients, cookies and tracking, as well as appropriate guarantees for third-country transfers, the applicant was referred to the Federal Data Protection Authority's privacy policy. For the reasons outlined above, however, this approach is not compatible with the GDPR, as it on the one hand violates Article 12 (1) and (2) GDPR and, on the other hand, does not allow for specific information about the information pursuant to Article 15 (1) (a) – (h). The Federal Office for Consumer Protection neither received complete information - 13 - nor did it receive the limited information provided in a comprehensible, easily accessible, and readable format. The information was therefore inadequate and thus unlawful, which is why the complaint on this point had to be upheld as per the ruling. D.3. On the performance contract The performance contract is based on Art. 58 (2) (c) GDPR and is necessary to enable the complainant to exercise his rights without hindrance. A period of four weeks appears appropriate to fulfill the performance contract. The modalities of fulfillment are the responsibility of the respondent within the framework of the provisions of Art. 12 GDPR. However, a reference to the respondent's data protection policy is not sufficient in this regard, nor is a reference to various online tools from which the complainant must compile the information himself. LEGAL REMEDIES A written appeal against this decision may be lodged with the Federal Administrative Court within four weeks of service. The appeal must be submitted to the Data Protection Authority and must contain: - the name of the contested decision (reference number, subject) - the name of the authority being challenged, - the grounds on which the allegation of illegality is based, - the request, and - the information necessary to assess whether the appeal was filed in a timely manner. The Data Protection Authority has the option, within two months, to either amend its decision by issuing a preliminary decision on the appeal or to submit the appeal and the files of the proceedings to the Federal Administrative Court. An appeal against this decision is subject to a fee. The fixed fee for a corresponding submission, including any attachments, is 50 euros. The fee must be paid to the Austrian Tax Office account, stating the intended purpose. The fee must generally be transferred electronically using the "Tax Office Payment" function. The Austrian Tax Office - Special Competences Department must be specified as the recipient or - 14 - selected. Furthermore, the tax number/tax account number, the tax type "EEE - Appeal Fee," the date of the assessment as the period, and the amount must be specified. If your financial institution's e-banking system does not have the "Tax Office Payment" function, the eps procedure in FinanzOnline can be used. Electronic transfer can only be dispensed with if no e-banking system has been used previously (even if the taxpayer has an internet connection). In this case, the payment must be made by payment order, ensuring that the correct allocation is made. Further information is available from the tax office and in the manual "Electronic Payment and Reporting for the Payment of Self-Assessed Taxes." Payment of the fee must be proven when submitting a complaint to the Data Protection Authority by means of a payment receipt attached to the complaint or a printout of the issuance of a payment order. If the fee is not paid or not paid in full, a report will be sent to the responsible tax office. A timely and admissible complaint to the Federal Administrative Court has suspensive effect. The suspensive effect may have been excluded in the decision or may be excluded by a separate decision. August 7, 2025 For the Head of the Data Protection Authority: