BVwG - W274 2302843-1

From GDPRhub
BVwG - W274 2302843-1
Court: BVwG (Austria)
Jurisdiction: Austria
Relevant Law: Article 57(4) GDPR
Decided: 30.04.2026
Published: 15.05.2026
Parties: DSB
National Case Number/Name: W274 2302843-1
European Case Law Identifier: ECLI:AT:BVWG:2026:W274.2302843.1.00
Appeal from: DSB (Austria)
Appeal to:
Original Language(s): German
Original Source: RIS (in German)
Initial Contributor: ds

A court held that 13 complaints by a military officer connected to their disciplinary proceedings were abusive since the complaints were used against individuals involved in the disciplinary proceedings rather than for data protection reasons. According to the court, the DPA rightfully rejected to handle these complaints.

English Summary

Facts

The data subject was a military officer against whom were launched disciplinary proceedings. These proceedings resulted first in the imposition of a fine against them and ultimately in their dismissal. The dismissal judgement was later annulled by the Supreme Administrative Court.

The data subject lodged 14 complaints with the DPA from 11 April 2023 to 22 August 2024.

The DPA pointed out that in the recent past, it had already decided on 19 previous complaints that the data subject had lodged with it. From these 19 cases, the data subject’s complaints were dismissed nine times. Eight complaints were upheld, and one was partially upheld. Moreover, the data subject had appealed three of these decisions.

The DPA found that all of the new 14 complaints shared a common link. They were all related to the data subject’s employment-related conflicts and the disciplinary proceedings. They were also filed against individuals connected to the data subject’s former employment. In addition, the DPA noted the repetitive language in the data subject's submissions. The data subject in their complaints regularly alleged unlawful use of their data, unlawful disclosures and violations of their data subject rights. The DPA highlighted that on some occasions the data subject had filed a complaint with it as early as the day after the rejection of one of their requests.

The DPA believed that the data subject was attempting to resolve issues with former departments and superiors through data protection complaints. It concluded that the data subject was using the complaints as a form of retaliation, rather than genuinely seeking to protect their legal rights due to an alleged data protection violation.

The DPA emphasized that data protection proceedings should not be used as a means of pressure against former superiors. Consequently, the DPA determined that the data subject's complaints were abusive and their actions excessive. Deeming this an abuse of rights, the DPA decided not to process the 14 new complaints under Article 57(4) GDPR. The reason for this was that the requests were deemed excessive because they were clearly aimed at causing annoyance or exerting pressure. The DPA issued a decision refusing to handle the 14 complaints. The data subject then appealed this decision before the Federal Administrative Court.

The data subject contended that the DPA did not adequately address the specific grounds of their complaints. They also argued that the DPA had relied on the overall number of proceedings instead of assessing the individual complaints. The data subject cited the CJEU ruling in Case C-416/23 to argue for the proper interpretation of Article 57(4) GDPR. CJEU had clarified that repeated Article 77 GDPR complaints are not excessive merely because of their number and that the DPA must prove abusive intent.

Moreover, they argued, that one of the complaints should not have been included in the DPA’s refusal decision, because it had already been submitted to the Federal Administrative Court.

Holding

The court partly upheld the appeal only in relation to one complaint, which had already been submitted to court and therefore should not have been included in the DPA’s refusal decision. Therefore, it ruled that there were 13 complaints at issue in this case, not 14.

The court did not examine the merits of the data subject’s complaints. It reviewed only whether the DPA was entitled to refuse to handle them under Article 57(4) GDPR.

The court relied heavily on CJEU Case C-416/23 to evaluate whether the complaints were excessive pursuant to Article 57(4) GDPR and recognized that the number or frequency of the requests alone is insufficient to indicate excessiveness. The DPA must establish abusive intent. However, it remarked that these factors could suggest that the data subject's primary aim was unrelated to data protection. The court also noted that hostility towards specific individuals could constitute an abusive purpose. It observed that the 13 complaints were primarily directed against the data subject’s superiors, many of whom were involved in their disciplinary proceedings. The court also highlighted the close temporal proximity between these proceedings and the filing of the complaints.

Consequently, the court determined that the complaints were closely linked to the data subject’s disciplinary disputes and mainly targeted former superiors involved in those proceedings. The court concluded that the complaints were used as a means of pressure, rather than to primarily protect data protection rights.

The court upheld the DPA's opinion that there was abusive intent in the data subject's 13 complaints and that they were excessive under Article 57(4) GDPR.

Comment

The decision is notable for its application of Article 57(4) GDPR after CJEU Case C-416/23, a preliminary ruling arising from Austrian DPA proceedings, which clarified that repeated Article 77 GDPR complaints are not excessive merely because of their number and that the DPA must prove abusive intent. However, the court nevertheless found the complaints abusive in this case, based on their context, timing, repetitive wording and connection to the data subject’s disciplinary disputes. Finally, it accepted the DPA’s choice not to charge a fee, since a fee was unlikely to deter the data subject and would probably have created further administrative burden.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the German original. Please refer to the German original for more details.

Decision Date

April 30, 2026

Legal Norm

Federal Constitutional Law (B-VG) Art. 133 para. 4
Data Protection Act (DSG) §1
Data Protection Act (DSG) §24
General Data Protection Regulation (GDPR) Art. 15
General Data Protection Regulation (GDPR) Art. 52 para. 4
General Data Protection Regulation (GDPR) Art. 57 para. 4
Administrative Court Procedure Act (VwGVG) §28 para. 1
Administrative Court Procedure Act (VwGVG) §31 para. 1

Federal Constitutional Law (B-VG) Art. 133 today; Federal Constitutional Law (B-VG) Art. 133 valid from January 1, 2019 to May 24, 2018, last amended by Federal Law Gazette I No. 138/2017; Federal Constitutional Law (B-VG) Art. 133 valid from January 1, 2019, last amended by Federal Law Gazette I No. 22/2018; Federal Constitutional Law (B-VG) Art. 133 valid from May 25, 2018 to December 31, 2018, last amended by Federal Law Gazette I No. 22/2018; Federal Constitutional Law (B-VG) Art. Article 133 valid from 01.08.2014 to 24.05.2018, last amended by Federal Law Gazette I No. 164/2013. Article 133 valid from 01.01.2014 to 31.07.2014, last amended by Federal Law Gazette I No. 51/2012. Article 133 valid from 01.01.2004 to 31.12.2013, last amended by Federal Law Gazette I No. 100/2003. Article 133 valid from 01.01.1975 to 31.12.2003, last amended by Federal Law Gazette No. 444/1974. Article 133 valid from 25.12.1946 to 31.12.1974, last amended by Federal Law Gazette. No. 211/1946 B-VG Art. 133 valid from 19.12.1945 to 24.12.1946 last amended by StGBl. No. 4/1945 B-VG Art. 133 valid from January 3, 1930 to June 30, 1934

DSG Art. 1 § 1 now DSG Art. 1 § 1 valid from January 1, 2014, last amended by Federal Law Gazette I No. 51/2012 DSG Art. 1 § 1 valid from January 1, 2000 to December 31, 2013

DSG Art. 2 § 24 now DSG Art. 2 § 24 valid from July 15, 2024, last amended by Federal Law Gazette I No. 70/2024 DSG Art. 2 § 24 valid from May 25, 2018 to July 14, 2024, last amended by Federal Law Gazette I No. 120/2017 DSG Art. 2 § Section 24, valid from January 1, 2010 to May 24, 2018, last amended by Federal Law Gazette I No. 133/2009; Data Protection Act, Art. 2, Section 24, valid from January 1, 2000 to December 31, 2009

Section 28 of the Administrative Court Procedure Act (VwGVG), now Section 28, valid from January 1, 2019, last amended by Federal Law Gazette I No. 138/2017; Section 28, valid from January 1, 2014 to December 31, 2018

Section 31 of the Administrative Court Procedure Act (VwGVG), now Section 31, valid from September 1, 2018, last amended by Federal Law Gazette I No. 57/2018; Section 31, valid from January 1, 2017 to August 31, 2018, last amended by Federal Law Gazette I No. 24/2017, Administrative Court Procedure Act (VwGVG) § 31, valid from January 1, 2014 to December 31, 2016

Judgment



W274 2302843-1/14E

IN THE NAME OF THE REPUBLIC!

The Federal Administrative Court, composed of Judge Mag. Lughofer as presiding judge, and lay judges Mag. (FH) Lachnit-Griuc and Dr. [Name missing], renders the following judgment: GOGOLA, as assessor, on the complaint of Colonel XXXX, against the decision of the Data Protection Authority, Barichgasse 40-42, 1030 Vienna, dated September 11, 2024 (date of official signature), file no. 2024-0.565.534, respondents 1. XXXX, 2. XXXX, 3. Colonel XXXX, 4. Colonel XXXX as commander, 5. Colonel XXXX, 6. XXXX (as a private individual), 7. Data Protection Office of XXXX, for violation of the rights to confidentiality, access and erasure, specifically for the refusal to process data protection complaints pursuant to Article 57(4) GDPR, in a non-public session, renders the following judgment: The Federal Administrative Court, composed of Judge Mag. LUGHOFER as presiding judge, and expert lay judges Mag. (FH) LACHNIT-GRIUC and Dr. GOGOLA, as assessor, heard the complaint of the Austrian Federal Office of Defence (Obst römisch 40) against the decision of the Data Protection Authority, Barichgasse 40-42, 1030 Vienna, dated September 11, 2024 (date of official signature), file number 2024-0.565.534, respondents: 1. Austrian Federal Office of Defence (ObstdG römisch 40), 2. Austrian Federal Office of Defence (Obst römisch 40), 3. Austrian Federal Office of Defence (ObstdG römisch 40), 4. Austrian Federal Office of Defence (Obst römisch 40) as Commander, 5. Austrian Federal Office of Defence (Obst römisch 40), 6. Austrian Federal Office of Defence (Obst römisch 40) (as a private individual), 7. Data Protection Office of Austrian Federal Office of Defence (Obst 40), regarding violations of the rights to confidentiality, access, and erasure, specifically the refusal to process the data protection complaints pursuant to Article 57, paragraph 4, GDPR, in a non-public session, as follows:

1. The complaint is partially granted, and point 2 of the contested decision is set aside without substitution.

2. The complaint is otherwise dismissed.

3. The applicant's request to establish a "violation of the right to inspect files on October 2, 2024, due to the FAILURE to provide" several files and parts thereof is dismissed.

4. The applicant's request of December 5, 2024, to order the respondent authority to "reimburse the costs incurred by him for the appeals against the default and the appeal against the decision, due to the respondent authority's unlawful and culpable conduct," is dismissed.

5. The appeal on points of law is inadmissible pursuant to Article 133, paragraph 4, of the Federal Constitutional Law.

Text

Reasons for the Decision:

1.1.1. In a data protection complaint dated April 11, 2023 (recorded under D124.0729/23) to the Data Protection Authority (hereinafter: the respondent authority), XXXX (hereinafter: complainant, BF), a career officer in the Austrian Armed Forces, alleged that XXXX (hereinafter: first respondent, BG1) had violated his right to information. He claimed that he had not been provided with any information regarding the processing of his health data.

In a separate data protection complaint dated April 11, 2023 (recorded under D124.0729/23) to the Data Protection Authority (hereinafter: the respondent authority), XXXX (hereinafter: complainant, BF), a career officer in the Austrian Armed Forces, alleged that XXXX (hereinafter: first respondent, BG1) had violated his right to information. He claimed that he had not been provided with any information regarding the processing of his health data. Enclosed were requests for information and a "clarification" regarding the information provided.

By letter dated April 13, 2023, the respondent authority requested a statement from the appellant.

In a statement dated May 2, 2023, the BG1 (Federal Office for Data Protection and Freedom of Information) summarized that the appellant had been provided with information during an inspection. Furthermore, copies of the business documents had been provided to him. Further information could not be provided due to the legitimate interests of other persons. Moreover, the complaint was identical in content to the proceedings pending before the Data Protection Authority (DSB) under case number D124.5629/22.

In a statement dated May 27, 2023, the appellant maintained his complaint. He argued that the statement had not been issued by the competent body of the BG1 and should therefore be considered invalid. The pending proceedings concerned solely the disclosure of the redacted recipients of the documents from XXXX (hereinafter referred to as XXXX). He now requested information regarding his health data. This cannot infringe upon the rights of third parties. In a statement dated May 27, 2023, the appellant maintained his complaint. The statement was not issued by the competent authority of BG1 and should therefore be considered invalid. The pending proceedings concern solely the disclosure of the redacted recipients of the documents in Roman 40 (hereinafter referred to as Roman 40). He now requests information regarding his health data. This cannot infringe upon the rights of third parties.

1.1.2. In his submission of November 11, 2023 (logged under XXXX), amended by his submission of November 28, 2023, the appellant argued, in summary, that his right to confidentiality had been violated by XXXX (second respondent, BG2) and Colonel XXXX (third respondent, BG3) because the establishment of the mailbox XXXX did not adequately protect him against unauthorized access to his personal data by third parties, and that this data had been disclosed to third parties. BG3, as a member of Directorate 1-XXXX, had demonstrably accessed the mailbox of BG2 XXXX three times without authorization on October 18, 2023. Furthermore, he had been violated in his right to information under Article 33 GDPR, as he had not been informed about the disclosed data concerning him, nor had a data breach notification been sent to the Data Protection Authority. 1.1.2. In his submission of November 11, 2023 (recorded under Roman numeral 40), amended by his submission of November 28, 2023, the appellant argued, in summary, that his right to confidentiality had been violated by Roman numeral 40 (second respondent, BG2) and Colonel G.I. Roman numeral 40 (third respondent, BG3), because the establishment of the mailbox Roman numeral 40 did not adequately protect him against unauthorized access to his personal data by third parties, and that this data had been disclosed to third parties. BG3, as a member of Directorate 1 (Roman numeral 40), had demonstrably accessed the mailbox of BG2 (Roman numeral 40) three times without authorization on October 18, 2023. Furthermore, he claimed that his right to information under Article 33 of the GDPR had been violated, as he had not been informed about the disclosed data concerning him and no data breach notification had been sent to the Data Protection Authority (DPA).

By letter dated November 28, 2023, the respondent authority requested statements from BG2 and BG3.

In its statement dated December 12, 2023, the Data Protection Office of BG1 summarized its position as follows: The storage of personal data by means of a submission to email address XXXX resulted from the applicant's decision to submit an email to BG2 at this address. BG2 determines the group of people who can access the emails stored at email address XXXX. These are the individuals at BG2 who are regularly and generally involved with matters concerning the applicant and who also represent each other in this capacity. BG3 was authorized to do so. For the reasons stated above, there was no breach of the protection of the BF's personal data and therefore neither an obligation to report to the Data Protection Authority nor an obligation to report to the BF. In a statement dated December 12, 2023, the Data Protection Office of BG1 summarized its position as follows: The storage of personal data by sending a submission to email address 40 was the result of the BF's volitional decision to submit an email to BG2 at this email address. BG2 determines the group of people who can access the emails stored under email address 40. These are the individuals who are regularly and generally involved with matters concerning the BF on behalf of BG2 and who also represent each other in this regard. BG3 was authorized to do so. For the reasons set out above, there is no breach of the protection of personal data of the BF and therefore neither an obligation to report to the DSB nor an obligation to report to the BF.

On December 23, 2023, the BF (Federal Commissioner) stated, in summary, that BG3 was not a member of BG2 at the time of access to mailbox XXXX and that he maintained his complaint.

On June 3, 2024, the respondent authority requested supplementary statements from BG2 and BG3.

On June 7, 2024, the Data Protection Office of BG1 stated that, according to the applicable organizational structure pursuant to Section 7 of the Federal Registration Act (BMG), it was responsible for handling "data protection matters" within the Federal Ministry XXXX. This includes, among other things, pursuant to Section 10, paragraphs 1 and 2 of the Federal Data Protection Act (BMG), representing the ministry in data protection matters before the relevant authority. The Data Protection Office requested an extension of the deadline, which was granted until July 24, 2024. On June 7, 2024, the Data Protection Office informed BG1 that, according to the applicable organizational structure as defined in Section 7 of the BMG, it was responsible for handling "data protection matters" within the Federal Ministry (Roman 40). This includes, among other things, pursuant to Section 10, paragraphs 1 and 2 of the BMG, representing the ministry in data protection matters before the relevant authority. The Data Protection Office requested an extension of the deadline, which was granted until July 24, 2024.















On July 17, 2024, supplemented on July 31, 2023, BG2 and BG3 issued the following joint statement: They fully upheld their statement of December 12, 2023, and referred to the arguments presented therein. Furthermore, they completely denied the arguments presented by the plaintiff in his statement of December 23, 2023. Regarding BG3, there had been a verbal agreement with the head of Department XXXX concerning the further processing of matters or submissions from the plaintiff, even during other duty assignments, according to which the head of Department XXXX could be called upon for support as capacity allowed. On July 17, 2024, supplemented on July 31, 2023, BG2 and BG3 issued the following joint statement: They fully upheld their statement of December 12, 2023, and referred to the arguments presented therein. Furthermore, the BF's submissions in his statement of December 23, 2023, are entirely denied. Regarding BG3, there was a verbal agreement with the head of Department 40 concerning the further processing of the BF's matters and submissions, even during other duty assignments, according to which the head could be called upon for support as capacity allowed.

1.1.3. In his submission of January 28, 2024 (recorded under D124.0392/24), the BF argued, in summary, that BG2 violated his right to confidentiality by unlawfully disclosing his health data to uninvolved third parties, namely Department XXXX, c/o the Disciplinary Prosecutor, XXXX, and the XXXX authority. 1.1.3. In a submission dated January 28, 2024 (recorded under D124.0392/24), the appellant argued, in summary, that BG2 had violated his right to confidentiality by unlawfully disclosing his health data to uninvolved third parties, namely Department 40, addressed to the Disciplinary Prosecutor, and the 40 Authority.

By letter dated July 11, 2024, BG2 was requested to submit a statement.

In its statement dated August 30, 2024, BG2 concluded that the complaint should be dismissed due to preclusion. In his appeal of January 28, 2024, the appellant claims to have only become aware of the disclosure of his health data to Department XXXX, XXXX, and XXXX on November 13, 2023, when an unredacted copy of file XXXX was presented during the hearing before the Federal Administrative Court (BVwG) in case W258 2253618-1, thus making it accessible to him. However, it must be pointed out that the appellant has been aware since at least December 20, 2021, when he was given a redacted copy of file XXXX (1) dated June 8, 2021, that this file contained his health data and that, in addition to Department AR, it had also been sent to other recipients, albeit with redacted information. The letter from the appellant dated December 21, 2021, to Department AR indicates that he was already convinced at that time that his health data had not been disclosed to any authorized recipients, even if the specific recipients were (still) unknown to him. In its statement of August 30, 2024, BG2 summarized its position that the appeal should be dismissed due to preclusion. In his appeal of January 28, 2024, the appellant claims to have only become aware of the disclosure of his health data to Department 40 on November 13, 2023, specifically when an unredacted copy of document 40 was presented during the hearing before the Federal Administrative Court (BVwG) in case W258 2253618-1, thus making it accessible to him as well. It should be noted that the applicant has been aware since at least December 20, 2021, when he received a redacted copy of the document dated June 8, 2021, that this document contained his health data and that, in addition to Department AR, it had also been sent to other recipients, albeit with redactions. The applicant's letter of December 21, 2021, to Department AR shows that he was already convinced at that time that his health data had not been disclosed to any authorized recipients, even if he did not (yet) know the specific recipients.

Despite being aware of this fact, he only filed a complaint on December 22, 2021, alleging a violation of his right to information. Therefore, his current complaint of January 28, 2024, must be rejected as untimely. Alternatively, it is requested that the data protection complaint of the BF dated January 28, 2024, be dismissed for lack of a violation of the protection of his personal data. At the time in question, the BF was a career officer of XXXX, against whom disciplinary proceedings were pending before XXXX. According to the XXXX internal decree on XXXX disciplinary law in effect at the time of the action in question (Official Gazette I, No. 12/2014), communications from courts and administrative authorities and other evidence relevant to the proceedings, which are received or come to light after the disciplinary complaint has been filed with the disciplinary superior, were to be submitted immediately to the (then) Disciplinary Commission for XXXX (which was replaced by XXXX on October 1, 2020). A similar regulation has been retained in the current decree on XXXX disciplinary law (Official Gazette I, No. 82/2024). In disciplinary proceedings pursuant to Section 23 of the Disciplinary Code 2014 (HDG 2014), the relevant facts must be established during the investigation, and any evidence suitable for establishing these facts and expedient to the specific circumstances of the case is admissible. While the disciplinary superior is not a party to the Senate proceedings, it is nevertheless appropriate, within the scope of their obligation under Section 68 of the HDG 2014, to inform XXXX of all circumstances known to them that relate to a previously filed disciplinary complaint and are essential for proceedings to be conducted due to suspected breach of duty. Since the disciplinary attorney must also be notified pursuant to Section 68 of the HDG 2014, it is equally appropriate to bring such circumstances to their attention as well. It should be noted in particular that, over a period of several years, further disciplinary complaints ("supplements") were filed with XXXX regarding suspected breaches of duty committed by the BF, and these concerned incidents both before and after June 8, 2021. Although he was aware of this fact, on December 22, 2021, he only filed a complaint alleging a violation of his right to information. Therefore, his current complaint of January 28, 2024, must be rejected as untimely. Alternatively, it is requested that the BF's data protection complaint of January 28, 2024, be dismissed for lack of a violation of the protection of his personal data. At the time in question, the BF was a career officer of the Roman numeral 40, against whom disciplinary proceedings were pending before the Roman numeral 40. According to the internal decree on disciplinary law under Roman 40 (Official Gazette Roman 1, No. 12/2014) in effect at the time of the action in question, communications from courts and administrative authorities, as well as other evidence relevant to the proceedings, received or discovered after the disciplinary complaint had been filed with the disciplinary superior, were to be submitted immediately to the (then) Disciplinary Commission for Roman 40 (which was replaced by Roman 40 on October 1, 2020). A similar provision has been retained in the current decree on disciplinary law under Roman 40 (Official Gazette Roman 1, No. 82/2024). In disciplinary proceedings pursuant to Section 23 of the Disciplinary Law 2014, the relevant facts must be established during the investigation, and any evidence suitable for establishing these facts and expedient in the individual case is admissible. Although the disciplinary superior is not a party to the Senate proceedings, it is nevertheless appropriate, within the scope of his obligation under Section 68 of the Disciplinary Code 2014, to inform the disciplinary authority (Römer 40) of all circumstances known to him that relate to a previously filed disciplinary complaint and are relevant to proceedings to be conducted due to suspected breach of duty. Since the disciplinary attorney must also be notified under Section 68 of the Disciplinary Code 2014, it is equally appropriate to bring such circumstances to his attention as well. In particular, it should be taken into account that further disciplinary complaints ("supplements") concerning suspected breaches of duty committed by the employee have been filed with the disciplinary authority (Römer 40) over a period of several years, and these relate to events both before and after June 8, 2021.

1.1.4. In a submission dated February 19, 2024 (recorded under D124.0759/24), the plaintiff argued, in summary, that his right to confidentiality had been violated by BG2, as his health data had been unlawfully disclosed to uninvolved agencies.

By letter dated April 30, 2024, the respondent authority requested a statement from BG2.

BG2 submitted its statement on June 12, 2024. According to the legal assessment of the decision issued by the respondent authority on 28 November 2023 in the previous proceedings D124.5629, some of the bodies that received the documents in question were (fully) subject to instructions and supervised by BG2, so that for this reason they could not be considered recipients within the meaning of Art. 4 No. 9 GDPR and disclosure within the framework of a data protection right of access pursuant to Art. 15 para. 1 lit. c GDPR was not required. With regard to the (other) entities that received the business documents or the health data of the BF processed in connection therewith as independent persons and (self-governing) organizational units, the processing was carried out within the framework of a specific, statutory investigation mandate pursuant to Article 4(9), second sentence, GDPR, so that their disclosure within the framework of a data protection right of access pursuant to Article 15(1)(c) GDPR was not required. Furthermore, preclusion applies here. The BF claims in his appeal of February 19, 2024, that he only became aware of the disclosure of his health data to these entities through the decision of the respondent authority of November 28, 2023, in proceedings D124.5629. This claim is incorrect and is already evident from the files of the preceding proceedings D124.5629. The appellant filed the complaint leading to those proceedings in December 2021 alleging a violation of the right to information and was therefore already aware of the matter. On June 12, 2024, the BG2 issued its statement. According to the legal assessment of the decision issued by the respondent authority on November 28, 2023, in the previous proceedings D124.5629, some of the bodies that received the documents in question were subject to instructions and supervised by the BG2. Therefore, they could not be considered recipients within the meaning of Article 4, point 9, GDPR, and disclosure within the framework of a data protection right of access pursuant to Article 15, paragraph 1, letter c, GDPR was not required. With regard to the (other) entities that received the business documents or the health data of the BF processed in connection therewith as independent persons and (independent) organizational units, the processing was carried out within the framework of a specific, statutory investigation mandate pursuant to Article 4, paragraph 9, sentence 2 GDPR, so that disclosure within the framework of a data protection right of access pursuant to Article 15, paragraph 1, letter c, GDPR was not required. Furthermore, preclusion applies here. The BF claims in his complaint of February 19, 2024, that he only became aware of the disclosure of his health data to these entities through the decision of the respondent authority of November 28, 2023, in proceedings D124.5629. This claim is incorrect and is already evident from the files of the preceding proceedings D124.5629. The appellant filed the complaint that led to these proceedings in December 2021, alleging a violation of his right to information, and was therefore already aware of the matter.

On June 19, 2024, the appellant commented on this. He stated that the decision of the respondent authority dated November 28, 2023, regarding case number D124.5629, did not address the data protection violation concerning confidentiality, and therefore the subsequent appeal was filed within the prescribed time limit. He otherwise maintained his appeal.

1.1.5. In his submission of February 29, 2024 (recorded under D124.0668/24), the appellant argued, in summary, that his right to confidentiality had been violated by BG2, with Colonel XXXX as commander and Colonel XXXX as officer, by the unlawful disclosure of the disciplinary ruling issued by the Federal Administrative Court on January 12, 2024, concerning him, in the lecture hall of Institute XXXX to its staff during an official meeting (staff information session). 1.1.5. In a submission dated February 29, 2024 (documented under file number D124.0668/24), the applicant argued, in summary, that his right to confidentiality had been violated by BG2, specifically by its commanding officer, OberstdG 40, and the officer in charge of the department, Obst 40. He claimed that the disciplinary ruling issued by the Federal Administrative Court (BVwG) on January 12, 2024, concerning him, had been unlawfully disclosed to the department's staff during an official meeting (staff information session) in the department's lecture hall, in front of its personnel.

By letter dated April 5, 2024, the respondent authority requested a statement from BG2.


































... On May 10, 2024, BG2 stated, in summary, that this was a public announcement pursuant to Section 7 of the Hessian Data Protection Act 2014 (HDG 2014). The ruling of the Federal Administrative Court (BVwG), file number W208 2255608-2/45, was issued in the disciplinary proceedings of the Federal Administrative Court (BF) and published in the Legal Information System (RIS). Therefore, there could be no violation of the protection of personal data within the meaning of Section 1 of the Data Protection Act (DSG).

On May 10, 2024, BG2 stated, in summary, that this was a public announcement pursuant to Section 7 of the Hessian Data Protection Act 2014 (HDG 2014). The ruling of the Federal Administrative Court (BVwG), file number W208 2255608-2/45, was issued in the disciplinary proceedings of the Federal Administrative Court (BF) and published in the Legal Information System (RIS). Therefore, there could be no violation of the protection of personal data within the meaning of Section 1 of the Data Protection Act (DSG). On May 16, 2024, the BF (Federal Court of Justice) stated that Section 7 of the HDG (Higher Education Disciplinary Code) authorizes, among other things, disciplinary authorities to issue disciplinary rulings in anonymized form. However, knowledge obtained as a witness in the proceedings before the XXXX (Higher Administrative Court) and the BVwG (Federal Administrative Court) had been unlawfully included in the disciplinary ruling of January 12, 2024.

1.1.6. In a submission dated March 12, 2024 (recorded under D124.0751/24), the appellant alleged that his right to confidentiality had been violated by Colonel XXXX, commander of XXXX (fourth respondent, BG4). BG4 allegedly took a photograph of the appellant, Lieutenant Colonel XXXX, from the mobile phone of the staff representative, Lieutenant Colonel XXXX, without his consent, from a private message sent by the appellant to the staff representative, including his personal data (face and telephone number), at the XXXX barracks in XXXX, and unlawfully transmitted this photograph to third parties. 1.1.6. In a further submission dated March 12, 2024 (recorded under D124.0751/24), the appellant alleged that his right to confidentiality had been violated by Colonel Roman 40, commander of Roman 40 (fourth respondent, BG4). BG4, without the consent of the staff representative, Lieutenant Colonel (Roman 40), took a photograph of him from a private message sent by the BF to the staff representative, including his personal data (face and telephone number), at the Roman 40 barracks in Roman 40, and unlawfully transmitted this photograph to third parties.

By letter dated April 2, 2024, the respondent authority requested a statement from BG4.

On April 14, 2024, the Data Protection Office of BG1 requested an extension of the deadline. This was granted until May 13, 2024. Furthermore, the Data Protection Office stated that, according to the applicable organizational structure pursuant to Section 7 of the Federal Data Protection Act (BMG), the responsibility for handling "data protection matters" within XXXX lies with it and includes, among other things, pursuant to Section 10, paragraphs 1 and 2 of the BMG, representing the department in data protection matters before the Data Protection Authority (DSB). This power of representation exists both with regard to proceedings in which XXXX has the legal status as controller within the meaning of Art. 4 No. 7 GDPR or Section 36 para. 2 No. 8 DSG, and in proceedings in which this legal status exceptionally belongs to other bodies within the department. Therefore, the Data Protection Office (DSBür) is exercising the tasks (rights) of BG4 in the present appeal proceedings on the basis of the division of responsibilities. The Data Protection Office of BG1 requested an extension of the deadline on April 14, 2024. This was granted until May 13, 2024. Furthermore, the Data Protection Office stated that, according to the currently valid division of responsibilities pursuant to Section 7 of the Federal Data Protection Act (BMG), the responsibility for handling "data protection matters" lies with it and includes, among other things, pursuant to Section 10, paragraphs 1 and 2 of the BMG, representing the department in data protection matters before the Data Protection Authority (DSB). This power of representation exists both with regard to proceedings in which Department 40 has the legal status as the controller within the meaning of Article 4, point 7, GDPR or Section 36, paragraph 2, point 8, DSG, and in proceedings in which this legal status exceptionally belongs to other departments within the ministry. Therefore, the Data Protection Officer (DSBür) is exercising the tasks (rights) of Department 4 (BG4) in the present complaint proceedings as well, based on the division of responsibilities.

In its statement of May 7, 2024, Department 4 (BG4) stated that there was no violation of the protection of personal data pursuant to Section 1 DSG. Pursuant to Section 11 Paragraph 2 of the Data Protection Act 2014 (HDG 2014), the Federal Office for Civil Protection (BG1) and other authorities entrusted with the enforcement of this federal law may, in order to perform their respective tasks under this federal law, process not only personal data pursuant to Section 55a Paragraph 1 of the Data Protection Act 2015 (WG 2015), but also personal data concerning administrative penalty proceedings and criminal proceedings under the Code of Criminal Procedure (StPO) of persons pursuant to Section 1 of the Data Protection Act 2014 (HDG 2014) as well as of other persons whose data are required in the context of disciplinary proceedings under this federal law, provided that the respective data are necessary for the performance of their tasks. The consent of the data subject is not required for this. He had lawfully processed the personal data of the complainant in his legal capacity as disciplinary superior within the meaning of Section 11 Paragraph 1 Item 1 Letter b of the Data Protection Act 2014 (HDG 2014) on the basis of Section 11 Paragraph 2 of the HDG 2014. In its statement of May 7, 2024, the BG4 explained that there was no violation of the protection of personal data pursuant to Paragraph 1 of the Data Protection Act (DSG). According to Section 11, Paragraph 2, of the Data Protection Act 2014 (HDG 2014), the Federal Office for Civil Protection (BG1) and other authorities entrusted with the execution of this federal law may, in addition to personal data pursuant to Section 55a, Paragraph 1, of the Data Protection Act 2015 (WG 2015), also process personal data concerning administrative penalty proceedings and criminal proceedings under the Code of Criminal Procedure (StPO) of persons pursuant to Section 1, HDG 2014, as well as of other persons whose data are required in the context of disciplinary proceedings under this federal law, in order to perform the tasks assigned to them under this federal law, provided that the respective data are necessary for the performance of their tasks. The consent of the data subject is not required for this. In his legal capacity as disciplinary superior within the meaning of Section 11, Paragraph 1, Clause 1, Letter b, HDG 2014, he lawfully processed the personal data of the BF at issue in this appeal on the basis of Section 11, Paragraph 2, HDG 2014.

The respondent authority then granted the appellant a hearing and informed him that it considered BG1 to be a data controller pursuant to Article 4(7) of the GDPR. Should he disagree, he was requested to notify the respondent authority.

On May 21, 2024, the appellant stated that XXXX, with BG4, should still be considered the data controller. There was neither a legal basis nor an instruction from XXXX for photographing a mobile phone. Therefore, XXXX should be considered the data controller and thus the respondent. The data protection regulations and relevant case law clearly state that since 2018, recognizable individuals in photographs are considered personal data. He is clearly recognizable in the photograph, and his name is also written next to it. Furthermore, staff representatives are bound to secrecy, and photography is prohibited in barracks. It is a fact that no disciplinary proceedings can be pending against him, as he is not a member of XXXX. On May 21, 2024, the appellant stated that the responsible body is still the Roman numeral 40 with the BG4. There is neither a legal basis nor a directive from the Roman numeral 40 for photographing a mobile phone. Therefore, the Roman numeral 40 should be considered the responsible body and thus the respondent. The data protection regulations and relevant case law clearly state that since 2018, recognizable individuals in photographs are considered personal data. He is clearly recognizable in the photograph, and his name is also written next to it. Furthermore, staff representatives are bound to secrecy and photography is prohibited in barracks. The fact is that no disciplinary proceedings can be pending against him, as he is not a member of the Roman numeral 40.

1.1.7. In his submission of April 9, 2024 (recorded under D124.0976/24), the appellant argued, in summary, that his right to information had been violated by Colonel XXXX, the disciplinary authority, Disciplinary Commander/Unit Commander (fifth respondent, BG5). His request of March 8, 2024, for information as to whether his personal data was being processed, had not been answered by BG5 within one month. Instead, the Data Protection Office responded by letter dated April 2, 2024, stating that his request would not be considered substantively due to its manifest lack of merit and excessive nature. 1.1.7. In a submission dated April 9, 2024 (documented under D124.0976/24), the appellant argued, in summary, that his right to information had been violated by the disciplinary authority, the Disciplinary Commander/Unit Commander (fifth respondent, BG5). His request, dated March 8, 2024, for information regarding the processing of his personal data, had not been answered by BG5 within one month. Instead, the Data Protection Office responded by letter dated April 2, 2024, stating that his request would not be considered due to its manifest lack of merit and excessive nature.

The request for information and the Data Protection Office's response were enclosed with the submission.

By letter dated May 7, 2024, the respondent authority requested a statement from BG5.

On June 17, 2024, BG5 summarized its position as follows: the disciplinary commander, in the form of the unit commander, holds the position of data controller solely with regard to the processing of personal data within the framework of those disciplinary proceedings in which he acts as the competent disciplinary authority, i.e., in disciplinary proceedings pending before him in which a disciplinary order is issued using the abbreviated procedure. In addition, the unit commander is also assigned other tasks in the area of XXXX disciplinary law, in which he acts merely as an agent of XXXX bound by instructions. The BF (presumably referring to a specific individual or group) received information from the responsible authority. On June 17, 2024, BG5 (presumably referring to a specific group or group) stated, in summary, that the disciplinary commander, in the form of the unit commander, is responsible only with regard to the processing of personal data within the framework of those disciplinary proceedings in which he acts as the competent disciplinary authority, i.e., in disciplinary proceedings pending before him in which a disciplinary order is issued in the abbreviated procedure. In addition, the unit commander is also assigned other tasks in the area of disciplinary law (Section 40), in which he acts merely as an officer bound by instructions of Section 40. The BF received information from the responsible authority.

On July 17, 2024, the BF stated, in summary, that BG5, as the disciplinary authority, is the responsible party and that his right to information has been violated. He maintains his request for information.

1.1.8. In a submission dated April 10, 2024 (documented under D124.0990/24), the plaintiff argued, in summary, that his right to erasure had been violated by Colonel XXXX, as commander of XXXX and disciplinary authority (BG4), by the latter's failure to delete a photograph containing his telephone number despite his request for deletion. He requested a declaratory judgment of the violation, the deletion of the photograph, and information on who had received the photograph so that they, too, could delete it. 1.1.8. In a submission dated April 10, 2024 (documented under D124.0990/24), the plaintiff argued, in summary, that his right to erasure had been violated by Colonel XXXX, as commander of Unit 40 and disciplinary authority (BG4), by the latter's failure to delete a photograph containing his telephone number despite his request for deletion. He requested a declaratory judgment of the violation, the deletion of the photograph, and information on who had received the photograph so that they, too, could delete it.

The submission included the request for erasure, the response from the Data Protection Office, the photograph with accompanying text, and an excerpt from the disciplinary complaint.

1.1.9. In his submission of June 9, 2024 (recorded under D124.1508/24), amended by his submission of July 3, 2024, the appellant argued, in summary, that his right to confidentiality had been violated by XXXX (BG6). BG6 had unlawfully processed his personal data in order to file a complaint against him as a private individual with the authority in question. The appellant referred to BG6's statement: "Mr. XXXX's address is publicly accessible data in the Central Register of Residents (ZMR) – this address is therefore not subject to any claim of confidentiality, see Section 1 Paragraph 1 of the Data Protection Act (DSG); furthermore, this address is known to the Data Protection Authority (DSB) due to Mr. XXXX's numerous data protection complaints against XXXX or the XXXX department and its officers." He could therefore only have obtained this data from official files, since the BF's name and citizenship were not listed in the Central Population Register (ZMR). BG6 had violated his duty of official secrecy. 1.1.9. In a submission dated June 9, 2024 (recorded under D124.1508/24), amended by a submission dated July 3, 2024, the BF argued, in summary, that his right to confidentiality had been violated by Roman 40 (BG6). BG6 had unlawfully processed his personal data in order to file a complaint against him as a private individual with the authority in question. The BF referred to the information provided by BG6: “The address of Mr. Roman 40 is publicly accessible data in the Central Population Register (ZMR) – this address is therefore not subject to any claim of confidentiality, see Section 1, Paragraph 1, Data Protection Act (DSG); furthermore, this address is known to the Data Protection Authority (DSB) due to the numerous data protection complaints filed by Mr. Roman 40 against Roman 40 or the Roman 40 office and its officers.” He could therefore only have obtained this data from official files, since the BF's name and citizenship are not listed in the ZMR. BG6 had violated its duty of official secrecy.

By letter dated July 15, 2024, the respondent authority requested a statement from BG6.

On July 24, 2024, BG6 explained that the BF's private residential address was publicly accessible data in the ZMR. Furthermore, the BF's residential address served to clearly identify him. A search for the name and place of residence XXXX on the internet would yield three results in the telephone directory. He had also been released from his duty of confidentiality by his employing authority, and the legal basis for processing under Article 6(1)(f) GDPR (protection of the interests of the BG6 when filing a data protection complaint) was met. On July 24, 2024, the BG6 explained that the BF's private residential address was publicly accessible data in the Central Population Register (ZMR). Furthermore, providing the BF's residential address served to clearly identify him. A search for the name and place of residence (Roman numeral 40) on the internet would yield three results in the telephone directory. He had also been released from his duty of confidentiality by his employing authority, and the legal basis for processing under Article 6(1)(f) GDPR (protection of the interests of the BG6 when filing a data protection complaint) was met.

1.1.10. In his submission of June 28, 2024 (recorded under D124.1626/24), the appellant argued, in summary, that his right to confidentiality had been violated by BG6. BG6, acting as a private individual, had, in his data protection complaint of May 27, 2024, to the Data Protection Authority (see file number D124.1475/24), unlawfully processed his personal data (residential address) from official files, contrary to the clear provisions of Section 46 of the Federal Data Protection Act (BDG) in conjunction with Section 1 of the Data Protection Act (DSG), and thus also as a data controller within the meaning of Article 4(7) of the GDPR. That this data protection complaint was filed as a private individual and not as an officer of XXXX or as commander of a XXXX department is evident from the complaint itself (“This data protection complaint is filed by me as a private individual […].”). As a private individual, however, BG6 is bound by official secrecy. BG6 is not permitted to process official data in a private capacity. He could not have obtained the address from the Central Population Register (ZMR), as a query based solely on the complainant's name and Austrian citizenship would yield no results. Furthermore, there is no written release from official secrecy within the meaning of Section 46, paragraphs 3 and 4 of the Federal Data Protection Act (BDG). 1.1.10. In his submission of June 28, 2024 (recorded under D124.1626/24), the complainant argued, in summary, that BG6 had violated his right to confidentiality. BG6, as a private individual, had stated in his data protection complaint of On May 27, 2024, the BG6 (see file number D124.1475/24) filed a complaint with the Data Protection Authority (DSB) alleging that, contrary to the clear provisions of Section 46 of the Federal Data Protection Act (BDG) in conjunction with Section 1 of the Data Protection Act (DSG), the BG6 unlawfully processed his personal data (residential address) from official files as a private individual and thus also as a data controller within the meaning of Article 4, Paragraph 7 of the GDPR. The fact that this data protection complaint was filed as a private individual and not as an officer of the BG6 or as commander of a unit of the BG6 is evident from the complaint itself ("This data protection complaint is filed by me as a private individual [...]."). As a private individual, however, the BG6 is bound by official secrecy. The BG6 is not permitted to process official data as a private individual. The address could not have been obtained from the Central Register of Residents (ZMR), as a query based solely on the BG6's name and Austrian citizenship would yield no results. Furthermore, there is no written release from this obligation. Official secrecy within the meaning of Section 46, Paragraphs 3 and 4 of the Federal Disciplinary Code (BDG) applies.

By letter dated July 5, 2024, the respondent authority requested a statement from BG6.

On July 14, 2024, BG6 submitted its statement, requesting that the data protection complaint of the BF be dismissed as unfounded due to the absence of a data protection violation. The BF's private residential address is publicly accessible data in the Central Population Register (ZMR). Furthermore, he had been released from official secrecy by his employing authority, and the legal basis for processing under Article 6(1)(f) GDPR was met. The BF was also (deliberately) making false statements regarding BG6's release from official secrecy; he could not know whether such a release existed or not. A search for the BF's name on the internet would reveal three individuals in a telephone directory, thus also fulfilling the legal basis for processing under Article 6(1)(f) GDPR. Regarding the Central Register of Residents (ZMR) query submitted by the applicant and his statement that he could only indicate "Austrian citizen" in such a query, reference should be made to Section 18 Paragraph 17 in conjunction with Section 16 Paragraph 18 of the Registration Act. There are therefore clearly several individuals with the same name (who are also Austrian citizens). Apparently, there is also no restriction on the disclosure of information concerning the applicant. It should also be noted that the applicant knows the applicant's address from other (i.e., non-official) reasons and files. The applicant filed a number of criminal complaints against him in the summer of 2023. As a suspect in these proceedings, the applicant has access to the files and therefore also knows the applicant's private address for this reason. The BF (Federal Court of Justice) also knew his private address from these criminal proceedings and had included it in several submissions to the authority in question. On July 14, 2024, the BG6 (Federal Court of Justice) submitted a statement requesting that the BF's data protection complaint be dismissed as unfounded due to the absence of a data protection violation. The BF's private residential address is publicly accessible data in the Central Register of Residents (ZMR). He had also been released from official secrecy by his employing authority, and the legal basis for processing under Article 6, paragraph 1, letter f, of the GDPR was met. Furthermore, the BF was (deliberately) making false statements regarding the BG6's release from official secrecy; he could not know whether such a release existed or not. A search for the BF's name on the internet would yield three individuals in a telephone directory, thus also fulfilling the legal basis for processing under Article 6, paragraph 1, letter f. Regarding the Central Register of Residents (ZMR) query submitted by the applicant and his statement that he could only indicate "Austrian citizen" in the query, reference should be made to Section 18, Paragraph 17, in conjunction with Section 16, Paragraph 18, of the Registration Act (MeldeG). There are therefore clearly several individuals with the same name (who are also Austrian citizens). Apparently, there is also no restriction on the disclosure of information concerning the applicant's personal data. It should also be noted that the applicant knows the applicant's address from other (i.e., non-official) reasons and files. The applicant filed a number of criminal complaints against him in the summer of 2023. As a suspect in these proceedings, the applicant has access to the files and therefore also knows the applicant's private address. The applicant also knows his private address from these criminal proceedings and has included it in several submissions to the relevant authority.

On July 22, 2024, the applicant stated that the applicant could not have obtained his address from the Central Register of Residents (ZMR). Only clearly identifiable individuals could be queried. If the information could not be attributed to a single registered person, no information could be provided. The fact that the internet query yielded three results confirms that his private residential address is not public data. The data protection complaint filed by BG6 regarding the document dated May 4, 2024, was submitted on May 27, 2024 (D124.1475/24). In that complaint, he himself stated that he first became aware of it on May 4, 2024. Even if the application for release from official secrecy was submitted on May 4, 2024, and the decision was issued and served on May 4, 2024, the earliest possible legal effect would not occur until June 1, 2024. BG6 falsely stated before the Data Protection Authority that the private address was disclosed in the criminal complaints. None of the criminal complaints listed the private address.

1.1.11. In a submission dated July 8, 2024 (recorded under D124.1684/24), the appellant argued, in summary, that his right to confidentiality had been violated by BG2. BG2 had repeatedly requested his private residential address and disclosed it to third parties in the records, despite his objection and written notification to that effect.

1.1.12. In a submission dated July 31, 2024 (recorded under D124.1818/24), the appellant argued, in summary, that Colonel XXXX, "as the disciplinary authority, disciplinary commander/disciplinary superior (HDG)" (BG4), had violated his right to erasure by failing to comply with his request of May 13, 2024, for the erasure of his personal data. Neither his personal data, which was more than ten years old, nor the personal data specified in Section 55a of the Military Service Act (WG) had been deleted. 1.1.12. In his submission dated July 31, 2024 (logged under D124.1818/24), the appellant argued, in summary, that the General Staff Regulations (BolbstdG) Roman 40, "as the disciplinary authority, Disciplinary Commander/Disciplinary Superior (HDG)" (BG4), had violated his right to erasure by failing to comply with his request for erasure of his personal data dated May 13, 2024. Neither his personal data, which was more than ten years old, nor the personal data specified in Section 55a of the Military Service Act (WG) had been deleted.

The submission included the appellant's request for erasure, the request for an extension of the deadline, and the Data Protection Office's rejection of the erasure request.

1.1.13. In his submission of August 19, 2024 (recorded under D124.1921/24), the appellant argued, in summary, that his right to erasure had been violated by the Data Protection Office of XXXX (seventh respondent, BG7). His request for the erasure of his personal data dated May 13, 2024, had not been granted. Neither his personal data, which was more than ten years old, nor the personal data specified in Section 55a WG had been erased. 1.1.13. In his submission of August 19, 2024 (recorded under D124.1921/24), the appellant argued, in summary, that his right to erasure had been violated by the Data Protection Office of Roman 40 (seventh respondent, BG7). His request for the erasure of his personal data dated May 13, 2024, had not been granted. Neither his personal data, which was more than ten years old, nor the personal data listed in Section 55a of the German Armed Forces Act (WG) had been deleted.

The submission of August 19, 2024, included the BF's request for deletion, the request for an extension of the deadline, and the BG7's rejection of the deletion request.

1.1.14. On August 22, 2024, the BF summarized his claim by BG2, stating that his right to confidentiality had been violated when the head of the BG2, Colonel XXXX, mentioned on August 21, 2024, while on duty in the office of Lieutenant Colonel XXXX at the XXXX Barracks, that further disciplinary proceedings were pending against him at XXXX (recorded under D124.1978/24). Lieutenant Colonel XXXX is a regular employee, not a disciplinary authority or staff representative. This constituted a violation of Section 1 of the Data Protection Act (DSG) in conjunction with Section 34 of the Hessian Disciplinary Act (HDG). 1.1.14. On August 22, 2024, the plaintiff argued that his right to confidentiality had been violated by BG2 because the head of the 40th Infantry Division (OberstdG römisch 40) had mentioned on August 21, 2024, while on duty in the 40th Infantry Division's office, that further disciplinary proceedings were pending against him at the 40th Infantry Division (recorded under D124.1978/24). The 40th Infantry Division is a regular employee, not a disciplinary authority or staff representative. Therefore, BG2 violated the provisions of Section 1 of the Data Protection Act (DSG) in conjunction with Section 34 of the Hessian Disciplinary Act (HDG).

1.2. By decision dated September 11, 2024, the respondent authority rejected the processing of the fourteen data protection complaints at issue and joined for a joint decision pursuant to Section 39(2) of the Austrian General Administrative Procedure Act (AVG), in accordance with Article 57(4) of the GDPR.

1.2.1. By decision dated September 11, 2024, the respondent authority rejected the processing of the fourteen data protection complaints at issue and joined for a joint decision pursuant to Section 39(2) of the AVG, in accordance with Article 57(4) of the GDPR. The authority proceeded on the basis of the following facts:

"The complainant was a lieutenant colonel in XXXX (XXXX School Center) located at XXXX. Disciplinary proceedings were pending against him for numerous breaches of duty, which ultimately resulted in his dismissal.

Nineteen of his complaints have already been resolved by decision of the Data Protection Authority:

The first complaint was filed on December 1, 2019, against Colonel XXXX (respondent) for a violation of the right to confidentiality and was dismissed.

The complaint was unfounded because the complainant, despite appropriate prompting, filed it against a..." The appeal was not directed at the respondent, who is not considered responsible.

The decision was issued on October 28, 2020, file number D124.1801, 2020-0.338.106.

The second appeal was filed on January 6, 2020, against Brigadier XXXX (respondent) for violation of the right to confidentiality and was dismissed.

The complaint was found to be unfounded because, firstly, the respondent did not act personally but on behalf of the XXXX command, and secondly, an impartial recipient could not draw any objective conclusion from the objective content of the message that formed the basis of the complaint that criminal proceedings were pending against the complainant (transmission of data pursuant to Article 10 GDPR).

The decision was issued on February 3, 2023, file number D124.1983, 2020-0.238.968.


The complaint was found to be unfounded because, firstly, the respondent did not act personally but on behalf of the command of Roman numeral 40, and secondly, an impartial recipient could not draw any objective conclusion from the objective content of the message that formed the basis of the complaint that criminal proceedings were pending against the complainant (transmission of data pursuant to Article 10 GDPR).

The decision was issued on February 3, 2023, file number D124.1983, 2020-0.238.968.












































































]
... The third complaint, filed on May 22, 2020, against Colonel XXXX of the General Staff Service (respondent) for an alleged violation of the right to secrecy, was dismissed.

In the present proceedings, it was not apparent how the aforementioned respondent had anything to do with the questioning of Brigadier XXXX as a suspect, especially since, in such a case, the complaint should have been directed against Brigadier XXXX. But even assuming the complaint was directed against Brigadier XXXX, it would have been unsuccessful: In the interest of a fair trial and with regard to the presumption of innocence (cf. Art. 6 paras. 1 and 2 ECHR), an accused person is free to testify or refuse to testify during questioning (cf. § 7 para. 2 second sentence of the Code of Criminal Procedure). In the present proceedings, it was not apparent how the named respondent had anything to do with the questioning of Brigadier Roman 40, especially since, in such a constellation, the complaint would have had to be directed against Brigadier Roman 40. But even assuming the complaint was directed against Brigadier Roman 40, it would have been unsuccessful: In the interest of a fair trial and with regard to the presumption of innocence (see Article 6, paragraphs 1 and 2 of the European Convention on Human Rights), an accused person is free to testify or refuse to testify during questioning (see Section 7, paragraph 2, second sentence of the Code of Criminal Procedure).

The decision was issued on June 8, 2020, file number D124.2554, 2020-0.339.030.

The fourth complaint was filed on June 23, 2020, against Mr. XXXX (respondent) regarding the alleged violation of the right to confidentiality.


The fourth complaint was filed on June 23, 2020, against Mr. Roman 40 (respondent) regarding the alleged violation of the right to confidentiality. The complaint was upheld, and it was determined that the respondent violated the complainant's right to confidentiality by unlawfully disclosing to third parties the fact that several disciplinary proceedings were pending against the complainant.

The decision was issued on February 15, 2021, file number D124.2668, 2020-0.853.348.

The fifth complaint, filed on January 6, 2020, against Brigadier XXXX (respondent) for violation of the right to confidentiality, was dismissed.


The fifth complaint, filed on January 6, 2020, against Brigadier Roman 40 (respondent) for violation of the right to confidentiality, was dismissed. The subject of the complaint was whether the respondent had violated the complainant's right to confidentiality by including the sentence: "...The pending cases of Lt. Col. XXXX are in no way comparable to the conduct of Colonel XXXX..." in an official letter he drafted to multiple recipients. The complaint was found to be unfounded because, firstly, the respondent did not act personally but on behalf of the XXXX command, and secondly, an impartial recipient could not draw any objective conclusion from the objective content of the message that was the subject of the complaint regarding pending criminal proceedings against the complainant (transmission of data pursuant to Art. 10 GDPR). The subject of the complaint was whether the respondent had violated the complainant's right to confidentiality by including the sentence: "...The pending cases of Lt. Col. Roman numeral 40 are in no way comparable to the conduct of Colonel Roman numeral 40..." in an official letter he drafted to multiple recipients. The complaint was found to be unfounded because, firstly, the respondent did not act personally but on behalf of the command of the Roman 40, and secondly, an impartial recipient could not draw any objective conclusion from the objective content of the message that formed the basis of the complaint that criminal proceedings were pending against the complainant (transmission of data pursuant to Article 10 GDPR).

The decision was issued on February 3, 2023, file number D124.1983, 2020-0.238.968.


The sixth complaint was filed on May 26, 2021, against Colonel XXXX, in his capacity as disciplinary commander/superior (respondent), regarding an alleged violation of the right to confidentiality.

The sixth complaint was filed on May 26, 2021, against Colonel Roman 40, in his capacity as disciplinary commander/superior (respondent), regarding an alleged violation of the right to confidentiality. The appeal was granted, and it was determined that the respondent violated the appellant's right to confidentiality by disclosing to the XXXX authority, the Disciplinary Commission for XXXX, the Disciplinary & Appeals Department/XXXX, and the Federal Disciplinary Prosecutor/XXXX the fact that the appellant had a disciplinary penalty that was already time-barred.

The decision was issued on December 13, 2021, file number D124.4169, 2021-0.737.265.


The appeal was granted, and it was determined that the respondent violated the appellant's right to confidentiality by disclosing to the authority (Roman 40), the Disciplinary Commission for XXXX, the Disciplinary & Appeals Department/Rome 40, and the Federal Disciplinary Prosecutor/Rome 40 the fact that the appellant had a disciplinary penalty that was already time-barred. The seventh complaint was filed on November 1, 2021, against the XXXX agency, Command XXXX (respondent), represented by the General Law Department of XXXX, for a violation of the right to confidentiality and was dismissed.

The subject of the present proceedings was the question of whether the respondent violated the complainant's right to confidentiality by storing the complainant's private email address in the ELAK (Electronic File System) during the period from autumn 2019 to summer 2021. The violation of the fundamental right to confidentiality alleged by the complainant can only be determined retrospectively. This means that a complaint concerning violations that have not yet manifested themselves or that could only potentially occur was unsuccessful due to lack of standing.

The decision was issued on June 7, 2022, file number D124.5209, 2021-0.908.528.

The eighth complaint was filed on November 24, 2021, against the XXXX office, Command XXXX (respondent), for a violation of the right to secrecy and was dismissed.

The eighth complaint was filed on November 24, 2021, against the Roman 40 office, Command Roman 40 (respondent), for a violation of the right to secrecy and was dismissed. In the proceedings before the Data Protection Authority, the respondent was required, in accordance with his duty to cooperate pursuant to Article 31 in conjunction with Article 58(1)(a) and (e) of the GDPR, to provide all information necessary for the Data Protection Authority to perform its tasks.

The decision was issued on March 25, 2022, file number D124.5322, 2022-0.046.834.


The respondent was required, in accordance with his duty to cooperate pursuant to Article 31 in conjunction with Article 58(1)(a) and (e) of the GDPR, to provide all information necessary for the Data Protection Authority to perform its tasks. The ninth complaint was filed on December 16, 2021, against Brigadier XXXX, in his capacity as disciplinary commander/superior (respondent), for a violation of the right to secrecy.

The ninth complaint was filed on December 16, 2021, against Brigadier Roman 40, in his capacity as disciplinary commander/superior (respondent), for a violation of the right to secrecy. The complaint was upheld and it was determined that the respondent violated the complainant's right to confidentiality by disclosing to the XXXX authority, the Disciplinary Commission for XXXX, the Disciplinary & Complaints Department/ XXXX, and the Federal Disciplinary Prosecutor/ XXXX the fact that the complainant had a disciplinary penalty that was already time-barred.

The decision was issued on May 20, 2022, file number D124.5599, 2022-0.254.551.

The tenth appeal was filed on December 22, 2021, supplemented on December 29, 2021, against XXXX (respondent) for an alleged violation of the right to information and was dismissed as unfounded.

The subject of the appeal was whether the respondent violated the appellant's right to information by not fully complying with his request of November 4, 2021, specifically by not disclosing all recipients or categories of recipients of his data. However, the question of the lawfulness of the data transfer was not within the scope of review of the present appeal proceedings. In this regard, particular reference can be made to the CJEU's ruling in Case C-579/21, according to which persons who process data exclusively under supervision and subject to instructions are not to be classified as recipients and, consequently, are not to be disclosed (at least not as such). Therefore, their disclosure within the framework of a data protection right of access pursuant to Article 15(1)(c) GDPR was also not required. The subject of the appeal was the question of whether the respondent infringed the complainant's right of access by not fully complying with his request of November 4, 2021, by not disclosing all recipients or categories of recipients of his data. However, the question of the lawfulness of the data transfer was not within the scope of review of the present appeal proceedings. In this case, particular reference can be made to the rulings of the CJEU in Case C-579/21, according to which persons who process data exclusively under supervision and subject to instructions are not to be classified as recipients and, consequently, are not to be disclosed (at least not as such). Therefore, disclosure of their data within the framework of a data protection right of access pursuant to Article 15(1)(c) GDPR was not required.

The decision was issued on November 28, 2023, file number D124.5629, 2023-0.201.812.


The eleventh complaint was filed on January 22, 2022, against the XXXX office, Command XXXX (respondent), represented by the Office of the Data Protection Commissioner (XXXX), for an alleged violation of the right to confidentiality.

The complaint was upheld, and it was determined that the respondent had violated the complainant's right to confidentiality by having an employee of the respondent unlawfully disclose to a third party that disciplinary proceedings had been initiated against the complainant.

The decision was issued on August 22, 2022, file number D124.0122/22, 2022-0.376.956.

The twelfth complaint was filed on January 23, 2022, against XXXX, Command (respondent), alleging a violation of the right to confidentiality.

The complaint was upheld, and it was determined that the respondent violated the complainant's right to confidentiality by adding the minutes of the first parts of the complainant's employee performance reviews from 2006, 2007, 2008, and 2009, as well as a document classified as "restricted," to the complainant's personal file, thereby disclosing this information to certain individuals (specialist personnel).









































































] The decision was issued on June 8, 2022, file number D124.0123/22, 2022-0.204.494.

The thirteenth complaint filed by Mr. XXXX (complainant) against Colonel XXXX, acting as the disciplinary authority "Disciplinary Commander/Disciplinary Superior" (respondent), was submitted on July 28, 2022, regarding an alleged violation of the right to secrecy and was dismissed as unfounded. The thirteenth complaint filed by Mr. Roman 40 (complainant) was also submitted on July 28, 2022, against Colonel Roman 40, acting as the disciplinary authority "Disciplinary Commander/Disciplinary Superior" (respondent), regarding an alleged violation of the right to secrecy and was dismissed as unfounded.











































] The subject of the complaint was whether the respondent violated the complainant's right to confidentiality by transmitting a screenshot of a WhatsApp message, which revealed the complainant's private telephone number, as Exhibit 16 to file number XXXX (2) on July 13, 2022, to the XXXX authority, the Disciplinary and Complaints Department of the Federal Ministry XXXX (Disciplinary Prosecutor), and the complainant's legal representative. In the present case, the disclosure of the telephone number was necessary for the respondent to fulfill its duties under Section 68 Paragraph 1 of the 2014 Disciplinary Act (HDG 2014) and to substantiate the evidence, as the screenshot in question referred to a message from the complainant. The respondent could rely on Sections 68 Paragraph 1 in conjunction with 11 Paragraph 2 of the Hessian Data Protection Act 2014 (HDG 2014) and thus on a fundamental ground for interference pursuant to Section 1 Paragraph 2 of the Data Protection Act (DSG) with regard to the transfer of the complainant's personal data at issue in the proceedings. The subject of the appeal was the question of whether the respondent violated the complainant's right to confidentiality by transmitting a screenshot of a WhatsApp message, on which the complainant's private telephone number was visible, as Exhibit 16 of the file under reference number 40 (2) on July 13, 2022, to the authority designated as [reference number], the Disciplinary and Complaints Department of the Federal Ministry designated as [reference number] (Disciplinary Attorney), and to the complainant's legal representative. In the present case, providing the telephone number was necessary for the respondent to fulfill its obligations under Section 68, Paragraph 1, of the Data Protection Act 2014 (HDG 2014) to substantiate its evidentiary value, as the screenshot in question referred to a message from the complainant. The respondent could rely on Section 68, Paragraph 1, in conjunction with Section 11, Paragraph 2, of the HDG 2014 with regard to the transfer of the complainant's personal data at issue in these proceedings, and thus on a legally relevant ground for interference pursuant to Section 1, Paragraph 2, of the Data Protection Act (DSG).

The decision was issued on January 16, 2023, file number D124.1039/22 2023-0.013.981.

The fourteenth appeal, filed on July 29, 2022, against the complainant himself for a violation of the right to confidentiality, was rejected.

One of the necessary prerequisites for asserting the right to lodge a complaint was that the complainant was personally affected by the processing, but was neither a controller nor a processor.

The decision was issued on September 7, 2022, file number D124.1058/22 2022-0.560.569.

The fifteenth complaint was filed on April 25, 2023, against XXXX (respondent) for a violation of the right to information.


The fifteenth complaint was filed on April 25, 2023, against Roman 40 (respondent) for a violation of the right to information. The complaint was partially upheld, and it was found that the respondent had violated the complainant's right to information by failing to provide him with information regarding the specific recipients of the personal data pursuant to Article 15(1)(c) GDPR and the origin of the data pursuant to Article 15(1)(g) GDPR, which, according to the respondent, fell under the right of access pursuant to Section 44(1) in conjunction with Section 44(5) GDPR (in the respondent's terminology: "personal data processed in connection with disciplinary matters and employee interviews"). With regard to Article 15(1)(d), (e), and (f) GDPR, the complaint was dismissed as unfounded. The complaint was partially upheld and it was found that the respondent had violated the complainant's right to information by failing to provide him with information on the personal data which, according to the respondent, would fall under the right of access pursuant to Section 44 Paragraph 5 of the GDPR (in the respondent's terminology: 'personal data which are processed in relation to disciplinary proceedings'). The complaint was partially upheld, and it was found that the respondent had violated the complainant's right to information by providing the complainant with information concerning the small personnel file that was not, on the whole, in a precise, understandable, and easily accessible form. The complaint was also partially upheld, and it was found that the respondent had violated the complainant's right to information by failing to provide information regarding the specific data recipients pursuant to Article 15(1)(c) of the GDPR and the origin of the data pursuant to Article 15(1)(g) of the GDPR, concerning the personal data that, according to the respondent, would fall under the right of access pursuant to Section 44(1) in conjunction with Section 44(5) of the GDPR (in the respondent's terminology: "personal data processed in connection with disciplinary matters and employee interviews"). With regard to Article 15, paragraph 1, letters d, e and f, of the GDPR, the complaint was dismissed as unfounded. The complaint was partially upheld, and it was found that the respondent had infringed the complainant's right of access by failing to provide information on personal data which, according to the respondent, would fall under the right of access pursuant to Section 44, paragraph 5, of the GDPR (in the respondent's terminology: 'personal data processed in relation to disciplinary proceedings'). The complaint was also partially upheld, and it was found that the respondent had infringed the complainant's right of access by providing the complainant with information concerning the small personnel file, which, as a whole, was not presented in a precise, intelligible and easily accessible form.

The decision was issued on March 22, 2024, file number D124.0853/23, 2024-0.186.782.

The sixteenth complaint was filed on June 12, 2023, against the XXXX office, Command XXXX (respondent), represented by the Office of the Data Protection Officer XXXX, for a violation of the right to confidentiality.


The sixteenth complaint was filed on June 12, 2023, against the Roman numeral 40 office, Command Roman numeral 40 (respondent), represented by the Office of the Data Protection Officer Roman numeral 40, for a violation of the right to confidentiality. The complaint was upheld, and it was determined that the respondent had violated the complainant's right to confidentiality by having an employee of the respondent unlawfully disclose to other employees, during a training group meeting between April 11 and April 18, 2023, the amount (a high five-figure sum) and the type of penalty (a fine) imposed on the complainant.

The decision was issued on February 8, 2024, file number D124.1265/23, 2024-0.054.836.


The seventeenth complaint was filed on June 28, 2023, against XXXX (respondent), represented by the Office of the Data Protection Commissioner XXXX, for an alleged violation of the right to confidentiality.

The seventeenth complaint was filed on June 28, 2023, against Roman 40 (respondent), represented by the Office of the Data Protection Commissioner Roman 40, for an alleged violation of the right to confidentiality. The complaint was upheld, and it was determined that the respondent had violated the complainant's right to confidentiality by having an employee of the respondent's Institute XXXX unlawfully disclose, during a complaint hearing on June 27, 2023, a draft of a written statement and the written record of the complainant's oral complaint to another employee.

The decision was issued on April 10, 2024, file number D124.1377/23, 2024-0.088.107.

The eighteenth complaint of July 19, 2023, against XXXX (respondent) for alleged violation of the right to confidentiality was dismissed as unfounded.

The subject of the complaint was whether the respondent had violated the complainant's right to confidentiality by unlawfully disclosing health data, data relating to criminal proceedings (or a self-report), and his private email address 1) by the commander (head) of XXXX to the Data Protection Office and thus to XXXX, and subsequently 2) by the Data Protection Office or XXXX to the Data Protection Authority in the course of the proceedings before the Data Protection Authority under file number D124.1265/23. The Data Protection Office is a (dependent) organizational unit of the respondent XXXX, which handled data protection matters. This included, among other things, representing the (entire) department before the Data Protection Authority, particularly in complaint proceedings, as was also the case in proceedings D124.1265/23. Representation in proceedings before the Data Protection Authority was based on a legal basis (see Section 7 of the Federal Data Protection Act (BMG) in conjunction with the organizational structure for the central office of XXXX), which indisputably also justified the data processing necessary for the performance of this task. Furthermore, the controller had a duty to cooperate in the complaint proceedings, according to which the Data Protection Authority was required to provide all information necessary for the performance of its tasks (see Article 31 in conjunction with Article 58(1)(a) and (e) GDPR). The purpose of administrative investigation proceedings (in particular Sections 37, 45, 46 of the General Administrative Procedure Act) was to ascertain all relevant factual elements in the specific individual case ('comprehensive fact-finding'). The processing of all (personal) information that could conceivably contribute to the proper establishment of the facts was permitted, regardless of whether the authority actually used this information in its evaluation of evidence. Based on the provisions of the General Administrative Procedure Act (AVG, Sections 37 et seq.) and a legitimate public interest (Section 1, Paragraph 2 of the Data Protection Act (DSG)), the respondent was therefore authorized to disclose the data to the Data Protection Authority. The subject of the appeal was whether the respondent had violated the appellant's right to confidentiality by unlawfully disclosing health data, data relating to criminal proceedings (or a self-report), and his private email address 1) by the commander (head) of Unit 40 to the Data Protection Office and thus to Unit 40, and subsequently 2) by the Data Protection Office or Unit 40 to the Data Protection Authority during the proceedings before the Data Protection Authority under file number D124.1265/23. The Data Protection Office is a (dependent) organizational unit of the respondent, Unit 40, which handles data protection matters. This included, among other things, representing the (entire) department before the Data Protection Authority, particularly in complaint proceedings, and was also the case in proceedings D124.1265/23. Representation in proceedings before the Data Protection Authority was based on a legal foundation (see Section 7 of the Federal Data Protection Act (BMG) in conjunction with the organizational structure for the central office, Roman numeral 40), which indisputably also justified those data processing operations necessary for the performance of this task. Furthermore, the controller had a duty to cooperate in the complaint proceedings, according to which the Data Protection Authority was required to be provided with all information necessary for the performance of its tasks (see Article 31 in conjunction with Article 58, paragraph 1, letters a and e, GDPR). The purpose of the administrative investigation procedure (in particular Sections 37, 45, and 46 of the General Administrative Procedure Act (AVG)) was to investigate all relevant factual elements in the specific individual case ('comprehensive fact-finding'). The processing of all (personal) information that could conceivably contribute to the proper establishment of the facts was permitted, regardless of whether the authority actually used it in its evaluation of evidence. Based on the provisions of the General Administrative Procedure Act (Sections 37 et seq.) and a legitimate public interest (Section 1, Paragraph 2, Data Protection Act), the respondent was therefore authorized to disclose the data to the Data Protection Authority.

The decision was issued on April 19, 2024, file number D124.1772/23 2024-0.124.566.


The nineteenth complaint was filed on September 29, 2023, against the XXXX agency, Command XXXX (respondent), represented by the Office of the Data Protection Officer XXXX, for a violation of the right to confidentiality.

The nineteenth complaint was filed on September 29, 2023, against the Roman numeral 40 agency, Command Roman 40 (respondent), represented by the Office of the Data Protection Officer Roman 40, for a violation of the right to confidentiality. The complaint was upheld, and it was found that the respondent violated the complainant's right to confidentiality by having an employee of the respondent unlawfully disclose the amount (a high five-figure sum) and the type of penalty (a fine) of the complainant's disciplinary ruling to other employees during a meeting of Institute XXXX in April 2023.

The complaint was upheld, and it was found that the respondent violated the complainant's right to confidentiality by having an employee of the respondent unlawfully disclose the amount (a high five-figure sum) and the type of penalty (a fine) of the complainant's disciplinary ruling to other employees during a meeting of Institute Roman 40 in April 2023. The decision was issued on March 19, 2024, file number D124.0242/24, 2024-0.211.115.

Since November 2023, the complainant has filed a further 15 complaints with the Data Protection Authority. Therefore, as of the date of this decision, 15 proceedings (reference date: September 4, 2024) are still pending before the Data Protection Authority.

Furthermore, since November 2023, the complainant has filed two appeals against decisions of the Data Protection Authority (as the respondent authority) and three complaints for failure to act.



Since November 2023, the complainant has also filed two appeals against decisions of the Data Protection Authority (as the respondent authority) and three complaints for failure to act. The complainant's complaints consistently concern alleged unlawful data processing related to his now-terminated employment with XXXX and are connected to the disciplinary proceedings that have since been concluded.

The complainant's complaints consistently concern alleged unlawful data processing related to his now-terminated employment with [Company Name] and are connected to the now-concluded disciplinary proceedings. The respondents identified by the appellants in these proceedings include XXXX, Federal Ministry XXXX (the first respondent in these proceedings), XXXX (the second respondent in these proceedings), Colonel XXXX (the third respondent in these proceedings), Colonel XXXX as Commander XXXX and Disciplinary Authority (the fourth respondent in these proceedings), Colonel XXXX as Disciplinary Authority, Disciplinary Commander/Unit Commander (the fifth respondent in these proceedings), XXXX (the sixth respondent in these proceedings), and DSB for XXXX (the seventh respondent in these proceedings). The respondents identified by the appellants in these proceedings include the Roman numeral 40, Federal Ministry Roman numeral 40 (the first respondent in this case), the Roman numeral 40 (the second respondent in this case), Colonel General Roman numeral 40 (the third respondent in this case), Colonel General Roman numeral 40 as Commander Roman numeral 40 and Disciplinary Authority (the fourth respondent in this case), Colonel Roman numeral 40 as Disciplinary Authority, Disciplinary Commander/Unit Commander (the fifth respondent in this case), Roman numeral 40 (the sixth respondent in this case), and DSB for Roman numeral 40 (the seventh respondent in this case).

The first respondent is the Federal Ministry XXXX, the ministry responsible for XXXX.

The second respondent, XXXX, is the school center of XXXX located at XXXX. XXXX comprises several subordinate organizational units. One of these units is the 'Institute XXXX'. One of these elements is the 'Institute Roman numeral 40'.

The third respondent, Colonel XXXX, is the designated contact person for all submissions from the appellant, appointed by XXXX.

The fourth respondent, Colonel XXXX, was the commanding officer of XXXX at the relevant time and thus its head and the appellant's superior officer.

The fifth respondent is Colonel XXXX. He was the head of Institute XXXX and the complainant's immediate superior at the relevant time. The fifth respondent is Obst (Roman numeral 40). He was the head of Institute (Roman numeral 40) and the complainant's immediate superior at the relevant time.

The sixth respondent is XXXX in his private capacity. The sixth respondent is Roman numeral 40 in his private capacity.

The seventh respondent is the Data Protection Officer for XXXX, the data protection office of the Federal Ministry XXXX. This office is responsible for all data protection matters within the Federal Ministry XXXX. The seventh respondent is the Data Protection Officer for Roman numeral 40, the data protection office of the Federal Ministry (Roman numeral 40). This office is responsible for all data protection matters within the Federal Ministry (Roman numeral 40).

In the 19 cases decided by the Data Protection Authority to date, the complainant's complaints were dismissed nine times. Eight complaints were upheld, and one was partially upheld. In one case, the complaint was dismissed because the complainant filed a complaint against himself.

The eight upheld decisions concerned complaints from 2020 to 2023, each alleging a violation of the right to confidentiality. These complaints concerned the unlawful processing of the complainant's data based on a disciplinary ruling issued against him.

In nine of the fifteen cases currently pending before the Data Protection Authority, the complainant is also alleging a violation of the right to confidentiality.



The complainant is also alleging a violation of the right to confidentiality in nine of the fifteen cases currently pending before the Data Protection Authority. The respondent authority then quoted some excerpts from the initial submissions of the BF as examples.

1.2.2. From a legal perspective, the respondent authority stated that the complaints had been consolidated pursuant to Section 39 Paragraph 2 of the General Administrative Procedure Act (AVG). According to Article 57 Paragraph 4 of the GDPR, the supervisory authority may, in the case of manifestly unfounded or – particularly in the case of frequent repetition – excessive requests, charge a reasonable fee based on administrative costs or refuse to act on the request. It is within the supervisory authority's discretion to either impose costs or refuse to process the request. The authority is only required to provide a comprehensible justification for its course of action. Excessiveness also exists if the requests are manifestly vexatious or constitute an abuse of process. 1.2.2. From a legal perspective, the respondent authority stated that the complaints had been consolidated pursuant to Section 39 Paragraph 2 of the AVG. According to Article 57 Paragraph 4 of the GDPR, The supervisory authority may, in the case of manifestly unfounded or—particularly in cases of frequent repetition—excessive requests, charge a reasonable fee based on administrative costs or refuse to act on the request. The supervisory authority has discretion to either impose fees or refuse to process the request. It is only required to provide a comprehensible justification for its course of action. Excessiveness also exists if the requests are clearly vexatious or an abuse of rights.

The specific complaints are all related to the now-terminated employment of the complainant at XXXX and the disciplinary proceedings that preceded his dismissal. The respondents are always XXXX, XXXX, and individuals holding positions at XXXX. Specifically, the complainant regularly alleges unlawful use of his data, unlawful disclosures, and violations of his data subject rights. The complainant has filed a total of 34 complaints, 15 of which were within the last ten months. Nineteen complaints have already been filed. The proceedings were terminated by the respondent authority, with the appellant having filed an appeal against the decision in three cases. Although the number of 15 appeals over a ten-month period may not initially appear significant, the appellant's submissions, which were sometimes deficient and frequently repeated, and which resulted in considerable effort for the respondent authority, suggest a "frequent repetition." This is due, in no small part, to the appellant's extensive submissions and attachments, their repetitive nature, and their failure to provide all relevant information proactively. For example, the appellant requested the deletion of the same data from three different departments and subsequently filed three appeals against three different respondents with the respondent authority. All of these specific appeals are related to the appellant's now-terminated employment with Roman 40 and the disciplinary proceedings that preceded his dismissal. The respondents are always the Roman numeral 40, the Roman numeral 40, and persons holding a position within the Roman numeral 40. Specifically, the complainant regularly alleges unlawful use of his data, unlawful disclosures, and violations of his data subject rights. The complainant has filed a total of 34 complaints, 15 of which were within the last ten months. The respondent authority has already concluded 19 proceedings, with the complainant filing appeals against decisions in three cases. Although the number of 15 complaints over a ten-month period may not initially appear significant, the complainant's sometimes inadequate and frequently repetitive submissions, which entail considerable effort for the respondent authority, suggest that there is a "frequent repetition" of the complaints. This is due, in no small part, to the fact that the complainant presents his complaints and supporting documents in a very lengthy manner, repeats himself regularly, and does not provide all relevant information proactively. The complainant requested the deletion of the same data from three different authorities and subsequently filed three complaints against three different respondents with the relevant authority.

The complainant appears to be attempting to have legal issues that have already been definitively decided by a court (disciplinary ruling) or for which there are pending criminal proceedings (e.g., regarding breaches of official secrecy) revisited by the relevant authority. Even though the parallel or successive use of legal remedies is generally permitted under the GDPR (Articles 77 and 79), the complainant's chosen approach reinforces the vexatious and abusive nature of his complaints. These complaints create the impression that a data protection connection is being sought for their submission to the relevant authority, while in reality other (civil service, criminal) issues are the driving force. It is neither the purpose of a complaint to the authority in question to clarify, for example, whether official secrecy has been violated or whether the complainant's data is admissible as evidence in disciplinary proceedings, and no legitimate interest in data protection can be identified in many of the complaint's grounds. The complainant appears to be aiming to have legal issues that have already been definitively decided by a court (disciplinary ruling) or for which there are pending criminal proceedings (e.g., regarding the question of breach of official secrecy) dealt with again by the authority in question. Even if the parallel or successive use of legal remedies is generally covered by the GDPR (Articles 77 and 79 GDPR), the complainant's chosen approach reinforces the vexatious and abusive nature of his complaints. These complaints would give the impression that a data protection connection is being sought for their submission to the authority in question, when in reality other (civil service, criminal law) issues are decisive. It is neither the purpose of a complaint to the authority in question to clarify, for example, whether official secrecy has been violated or whether the complainant's data is admissible as evidence in disciplinary proceedings, and no legitimate interest in data protection can be identified in many of the complaints.

Anyone who merely feigns reliance on an existing right is acting abusively (Section 1295 Paragraph 1 Sentence 2 of the Austrian Civil Code); the prohibition of harassment is inherent in the entire legal system – and thus also in public law. Furthermore, the investigations into those complaints in which the respondents had already been asked to comment and a decision had been reached revealed that many of the alleged violations of law could not be verified or confirmed. In nine cases, the appeal was dismissed, in one case it was rejected, in eight cases it was granted, and in one case it was partially granted. Anyone who merely feigns reliance on an existing right acts abusively (Section 1295, Paragraph 1, Sentence 2 of the Austrian Civil Code); the prohibition of harassment is inherent in the entire legal system – and thus also in public law. Furthermore, the investigations into those appeals in which the respondents had already been asked to comment and a decision had been issued revealed that many of the alleged violations of law could not be verified or confirmed. In nine cases, the appeal was dismissed, in one case it was rejected, in eight cases it was granted, and in one case it was partially granted.

The vexatious nature of the complaints is further exacerbated by the fact that the complainant filed several appeals with the Data Protection Authority (DSB) on the very day after the respondent rejected his request. This vexatious nature is further intensified by the filing of a complaint for failure to act in case XXXX. The initial complaint was filed on November 11, 2023. A request for rectification of deficiencies was then necessary for the complainant. On November 28, 2023, the respondent authority received the rectified information and requested a statement from the respondent on the same day. Nevertheless, the complainant filed another complaint for failure to act on May 16, 2024. The vexatious nature is further reinforced by the fact that a specific individual (Officer XXXX) is repeatedly named as the respondent in the majority of the complaints. This is sometimes in his official capacity as the complainant's former superior, but also in his private capacity. The vexatious nature of the complaints is further exacerbated by the fact that the complainant filed several appeals with the Data Protection Authority (DSB) on the very day after the respondent rejected his request. This vexatious nature is further intensified by the filing of a complaint for failure to act in proceedings under Roman 40. The initial complaint was filed on November 11, 2023. A request for rectification of deficiencies was then necessary for the complainant. On November 28, 2023, the respondent authority received the rectified information and requested a statement from the respondent on the same day. Nevertheless, the complainant filed another complaint for failure to act on May 16, 2024. The vexatious nature is further reinforced by the fact that a specific individual (under Roman 40 of the Federal Law on the Protection of the Constitution) is repeatedly named as the respondent in the majority of the complaints. This is sometimes in his official capacity as the complainant's former superior, but also in his private capacity.


















... Overall, the impression arises that the complainant is attempting to use data protection as a means of taking action against former departments and superiors after disciplinary and employment law proceedings have proven unsuccessful. Furthermore, the often identical wording of large portions of the initial submissions suggests that the complainant's intention lies more in the systematic filing of numerous complaints than in a genuine interest in legal protection based on an alleged data protection violation.

Consequently, the complaints in question must be classified as an abuse of the Data Protection Authority's powers.

1.3. This appeal is directed against this decision on the grounds of "illegality of content and procedural irregularities" as well as "lack of jurisdiction of the Data Protection Authority," with the requests that the contested decision be overturned without substitution, that the respondent authority be ordered to process the outstanding issues, and that a violation of the right to access files be established.


Consequently, the complaints in question must be classified as an abuse of the Data Protection Authority's activities. The main argument presented was that the contested decision lacked a legal basis. During a file inspection conducted at the respondent authority on October 2, 2024, not all case files were made available. Regarding point 2 of the decision, the administrative files lacked the notification of referral to the Federal Administrative Court. Furthermore, this appeal had already been submitted to the Federal Administrative Court as a result of the appellant's complaint for failure to act, meaning that combining it with the other data protection appeals was not permissible. Since November 2023, the appellant had only filed 13 appeals with the respondent authority instead of the stated 15, of which 12 were pending. Moreover, the respondent authority had treated related submissions as separate proceedings, only to then cite "regular repetition." According to the jurisprudence of the Federal Administrative Court and the data protection report of the respondent authority, excessive complaints are only assumed to exist with 24 per year, which is far from the case here. The decision does not explain what is deficient in his complaints. He was only asked to make improvements in one proceeding (regarding point 9), and the "same" submission in the proceeding regarding point 10 did not result in any request for improvement. His complaints were concise, while the respondents' statements were excessively long, so that any "considerable effort" could not be attributed to him. He cannot be held responsible for any potential understaffing of the respondent authority. Requests for deletion must be addressed to the respective data controller, meaning he requested the deletion of data from two (not three) different entities. Filing a complaint on the very first possible day should not be considered harassment. Merely reproducing the content of data protection complaints does not comply with the authority's legally mandated obligation to provide reasons. The fact that proceedings ready for conclusion (parties' hearings completed) are now being consolidated "after more than a year" of processing time and their further processing is being refused is also "interesting." A refusal should have been issued when the complaint was filed.

1.4. The respondent authority submitted the complaint, along with the relevant files, to the Federal Administrative Court (BVwG) for a decision on November 19, 2024, referring to the decision.

1.5. The file was received by Division W274 of the court on May 12, 2025.

1.6. By electronic submission dated December 5, 2024, the appellant supplemented the complaint, stating that the Federal Administrative Court, in its ruling W137 2297602-1, had rejected the respondent authority's refusal to process his complaints. The respondent authority was ordered to issue a decision in the matter. The Administrative Court assumed that the respondent authority was largely responsible for its inaction. According to the appellant, the authority experiences frequent staff turnover. The appellant now additionally requests that the respondent authority be ordered to reimburse him for the costs he incurred due to its unlawful and culpable conduct in filing appeals for failure to act and the appeal against the decision.

1.7. In a second supplement to the appeal of December 16, 2024, the appellant pointed out that the Federal Administrative Court, in proceedings W211 2288587-1, had found that the respondent authority had not sufficiently established the necessary facts. The appellant had already pointed out this deficiency during the administrative proceedings, so the authority cannot accuse him of submitting numerous submissions on a single matter.

1.8. In a third supplement to his complaint dated January 9, 2025, the complainant referred to the judgment of the Court of Justice of the European Union of the same date in case C-416/23. The complainant argued that the respondent authority based its decision on an arbitrary limit of two complaints per month, a limit it had set itself. Furthermore, it failed to explain why it did not prefer a reasonable fee to a rejection.

1.9. In its statement of January 28, 2026, the respondent authority, after being granted a hearing, explained that the complaints were not related to data protection law, but rather concerned the terminated employment relationship with XXXX and the preceding disciplinary proceedings. While the complainant formally alleged a data protection breach in each case, the proceedings were in fact intended to resolve conflicts in a professional context, and the complainant appeared to be hostile towards the respondents. He is evidently using the present appeal proceedings to have legal questions, which have already been decided or are due to be decided by a court, reviewed again by the respondent authority. Data protection proceedings are not a tool to be used as leverage against the competent authorities for purposes unrelated to data protection. Since the appellant has not been deterred in the past from conducting numerous costly proceedings before the Federal Administrative Court, the refusal to consider the present appeals is ultimately not objectionable, as it appears appropriate, necessary, and proportionate in relation to the imposition of a fee in order to adequately counter the appellant's intent to abuse the system. The respondent authority erroneously decided on the appeal of November 11, 2023, in the contested decision, even though it already lacked jurisdiction at the time of the decision. 1.9. In its statement of January 28, 2026, the respondent authority, after being granted a hearing, explained that the complaints were not related to data protection law, but rather concerned the terminated employment relationship with Roman 40 and the preceding disciplinary proceedings. The complainant formally alleged a data protection violation in each case, but the proceedings were in fact being used to resolve conflicts in a professional context, with the complainant appearing to be hostile towards the respondents. He was clearly using the complaints to have legal questions, which had already been decided or were due to be decided by a court, reviewed again by the respondent authority. Data protection proceedings should not be used as leverage against the competent authorities for purposes unrelated to data protection. Since the appellant has in the past not been deterred from conducting numerous costly proceedings before the Federal Administrative Court, the refusal to process the present appeals is ultimately not objectionable, as it appears appropriate, necessary, and proportionate in relation to the imposition of a fee in order to adequately counter the appellant's intent to abuse the system. The respondent authority erroneously decided on the appeal of November 11, 2023, in the contested decision, even though it already lacked jurisdiction at the time of the decision.

The appeal is partially justified:

2. The following facts are established – beyond the undisputed procedural history:

2.1. Regarding the appellant's personal details and service history:

The appellant, born on May 20, 1974, has been a career officer in the public service since September 1, 1995. Prior to that, he was a temporary-service soldier and completed his basic military service as a one-year volunteer. He holds the rank of Colonel (Oberst). Since 2008, he has been stationed at XXXX Institute XXXX, where he has served as a senior instructor since January 1, 2017. As the most senior department head, he also served as the deputy to the institute's commandant, the fifth respondent. BF, born on May 20, 1974, has been a career officer in the public service since September 1, 1995. Prior to that, he was a temporary-service soldier and completed his basic military service as a one-year volunteer. He holds the rank of Colonel (Oberst). Since 2008, he has been stationed at the Institute Roman 40, where he has served as a senior instructor since January 1, 2017. As the most senior department head, he also served as the deputy to the institute's commandant, the fifth respondent in the appeal.



His workplace has been at the Institute Roman 40 since 2008, where he has been working as a senior instructor since January 1, 2017. In 2019, due to sharply worded criticism from the appellant, disciplinary measures against him were considered. Consequently, in light of the planned transfer of the fifth respondent, he was not entrusted with the management of Institute XXXX. Instead, various supervisors were temporarily assigned to the institute's management, some of whom lacked the necessary qualifications for the position of institute director according to their job descriptions. Finally, as of July 1, 2020, the fifth respondent again became the institute's director. Finally, as of July 1, 2020, the fifth respondent was again the head of the institute.

The fourth respondent had been the commander of XXXX and thus the disciplinary superior of the BF since February 1, 2020, also based on (continuously extended) duty assignments. He reported even minor breaches of duty and any criticism from the BF that he considered inappropriate. In a communications order, he designated the third respondent as the contact person for all internal matters concerning the BF. The fourth respondent had also been the commander of Roman 40 and thus the disciplinary superior of the BF since February 1, 2020, again based on (continuously extended) duty assignments. He reported even minor breaches of duty and any criticism from the BF that he considered inappropriate. In a communications order, he designated the third respondent as the contact person for all internal matters concerning the BF.


The fourth respondent was also the commander of Roman 40 and thus the disciplinary superior of the BF since February 1, 2020, again based on (continuously extended) duty assignments. He reported even minor breaches of duty and any criticism from the BF that he considered inappropriate. In a communications order, he designated the third respondent as the contact person for all internal matters concerning the BF. The accusations leveled against the employee regarding breaches of duty were largely unfounded, none of them resulted in criminal proceedings, and only a minority of the accusations led to convictions in disciplinary proceedings.

Due to these accusations, the employee launched a counterattack against his superiors, seeking fault in their actions in a fit of anger. He subsequently made some reckless accusations against them, including allegations relevant to official conduct, and also filed data protection complaints for minor infractions, either to take revenge on his superiors or to pressure them into refraining from further disciplinary action.

The employee was suspended from duty on August 8, 2019 (see Federal Administrative Court decision of October 1, 2021, W208 2244045-1/12E) and was required to report weekly to the deputy head of XXXX. By disciplinary ruling of the XXXX authority dated March 16, 2023, the BF was found guilty of breaches of duty in 49 instances and, pursuant to Section 51 of the Disciplinary Code, was subject to a disciplinary penalty of a fine of EUR 15,355. Upon appeal against this ruling, the Federal Administrative Court (BVwG), in its rulings of January 12 and 25, 2024, found the BF guilty in a total of 25 instances and imposed the disciplinary penalty of dismissal (see, regarding this chronology, VwGH Ra 2024/09/0033-11). At the time of the contested decision, the BF had therefore been dismissed, although the dismissal order was subsequently overturned by the Administrative Court (VwGH) in its ruling of October 14, 2024. The BF had been suspended from duty since August 8, 2019 (see Federal Administrative Court (BVwG) ruling of October 1, 2021, W208 2244045-1/12E) and was required to report weekly to the deputy head of the Roman 40 authority. By disciplinary ruling of the Roman 40 authority dated March 16, 2023, the BF was found guilty of breaches of duty in 49 instances and, pursuant to Section 51 of the Hessian Disciplinary Code (HDG), was fined EUR 15,355. Upon appeal against this ruling, the Federal Administrative Court (BVwG) found the appellant guilty on a total of 25 counts in its rulings of January 12 and 25, 2024, and imposed the disciplinary penalty of dismissal (see VwGH Ra 2024/09/0033-11 for this chronology). At the time of the decision under appeal here, the appellant had therefore been dismissed, although the dismissal ruling was subsequently overturned by the VwGH in its ruling of October 14, 2024.

In 2024, the appellant filed 24 declaratory judgment applications with his employing authority, which imposed three fines for frivolous conduct on him as a result.

2.2. Regarding the convictions in the disciplinary proceedings:

The Federal Administrative Court (BVwG) found the defendant guilty on the following 25 counts in its rulings of January 12, 2024, W208 2255608-2/45E, and January 25, 2024, W208 2255608-2/48E:

"He

1.) In April 2016, knowing that, according to the directive "Initial, Advanced, and Continuing Training at Civilian Training Institutions – Implementing Regulations," dated December 3, 2010, file number S93760/60-AusbB/2010 (VBl I 178/2010), Captain XXXX's participation in XXXX training courses at XXXX during working hours required approval from the commander of XXXX Brigadier General XXXX, he advised his superior and institute director, Colonel XXXX, that..." this was not necessary and required additional services could be paid for from the institute's budget, which then happened from October 2016 to December 2018, thus intentionally violating his duty of faithful service pursuant to Section 43 Paragraph 1 BDG; 1.) In April 2016, knowing that according to the directive "Initial, Advanced, and Continuing Training at Civilian Training Institutions – Implementing Regulations," dated December 3, 2010, file number S93760/60-AusbB/2010 (Official Gazette I 178/2010), the participation of Captain (R-40) in R-40 training courses during his working hours would have required approval from the commanding officer of R-40, Brigadier General (R-40), he advised his superior and the institute director, Colonel (R-40), that this was unnecessary and that required overtime could be paid from the institute's budget. This is what happened from October 2016 to December 2018, and he thus intentionally violated his duty of faithful service pursuant to Section 43, Paragraph 1, of the Federal Civil Service Act (BDG).



Captain (R-40) 3.) As the responsible course commander for the training courses from XXXX 2018 to XXXX 2018 XXXX and from XXXX 2018 to XXXX 2018 XXXX as well as from XXXX 2018 to XXXX 2018 (Type Training XXXX), he confirmed incorrectly kept training logs, on the basis of which the additional duties presented to the non-commissioned officers Vzlt XXXX, OStv XXXX and OStv XXXX (to the same extent for all three NCOs) were specifically on 3.) as the responsible course commander for the training courses from Roman numeral 40 2018 to Roman numeral 40 2018 Roman numeral 40 and from Roman numeral 40 2018 to Roman numeral 40 2018 Roman numeral 40 as well as from Roman numeral 40 2018 to Roman numeral 40 2018 (Type Training Roman numeral 40), he confirmed incorrectly kept training logs, on the basis of which the non-commissioned officers Additional services submitted by Vzlt (Roman numeral 40), OStv (Roman numeral 40), and OStv (Roman numeral 40) (all three UO to the same extent) specifically on:

XXXX 2018 by XXXX 2:15 a.m. Roman numeral 40 2018 by Roman numeral 40 2:15 a.m.

XXXX 2018 by XXXX 1:15 a.m. Roman numeral 40 2018 by Roman numeral 40 1:15 a.m.

XXXX 2018 by XXXX 2:00 a.m. Roman numeral 40 2018 by Roman numeral 40 2:00 a.m.

XXXX 2018 by XXXX 0:25 a.m. Roman numeral 40 2018 by Roman numeral 40 0:25 a.m.

XXXX 2018 by XXXX 2:30 a.m. Roman numeral 40 2018 by Roman numeral 40 2:30 a.m.

XXXX 2018 by XXXX 2:30 a.m. Roman numeral 40 2018 by Roman numeral 40 2:30 a.m.

XXXX 2018 by XXXX 7:15 a.m. Roman numeral 40 2018 by Roman numeral 40 7:15 a.m.

XXXX 2018 by XXXX 1:30 a.m. Roman numeral 40 2018 by Roman numeral 40 1:30 a.m.

and specifically on

XXXX 2018 by XXXX 3:00 a.m. Roman numeral 40 2018 by Roman numeral 40 3:00 a.m.

XXXX 2018 by XXXX 2:30 a.m. Roman numeral 40 2018 by Roman numeral 40 2:30 a.m.

XXXX 2018 by XXXX 4:30 a.m. Roman numeral 40 2018 by Roman numeral 40 4:30 a.m.

XXXX 2018 by XXXX 4:00 a.m. Roman numeral 40 2018 by Roman numeral 40 4:00 a.m.

and specifically on

XXXX 2018 by XXXX 3:00 a.m. Roman numeral 40 2018 by Roman numeral 40 3:00 a.m.

XXXX 2018 by XXXX 3:45 a.m. Roman numeral 40 2018 by Roman numeral 40 3:45 a.m.

XXXX 2018 by XXXX 5:15 a.m. Roman numeral 40 2018 by Roman numeral 40 5:15 a.m.

were approved, even though other official activities actually took place, thus intentionally violating Section 43 Paragraph 1 and Section 45 Paragraph 1 of the Federal Disciplinary Code (BDG); were approved, even though other official activities actually took place, thus intentionally violating Section 43 Paragraph 1 and Section 45 Paragraph 1 of the Federal Disciplinary Code (BDG);

4.) As the responsible course commander for the XXXX type training course in XXXX 2018, despite knowing the training logs were inaccurate, I performed additional duties, specifically on the following dates:

XXXX 2018 from XXXX 3:00 a.m.

XXXX 2018 from XXXX 3:45 a.m.

XXXX 2018 from XXXX 5:15 a.m.

I confirmed these duties as factually correct and billed them for this training, even though other official duties were actually performed, thus intentionally violating Section 43. 1. Violated Section 43, Paragraph 1 of the Federal Disciplinary Code (BDG); confirmed as factually correct and billed for this training, even though other official duties were actually performed, thus intentionally violating Section 43, Paragraph 1 of the BDG;

5.) During his service with the Basic Training Department of XXXX from February 4, 2019, to April 30, 2019, without authorization or official necessity, on April 3, 2019, he accessed the overtime work order dated March 27, 2019, issued by Captain XXXX, who works at Institute XXXX, in the electronic personnel file (ELAK) and then sent it via email to five employees of Institute XXXX, thereby negligently violating Section 43, Paragraph 1 of the BDG; 5.) During his service assignment at the Basic Operations Department of the 40th Division from February 4, 2019, to April 30, 2019, he accessed the overtime work order dated March 27, 2019, issued by Captain 40, who was working at the 40th Division, in the electronic personnel file (ELAK) on April 3, 2019, without authorization or official necessity, and then sent it via email to five employees of the 40th Division, thereby negligently violating Section 43, Paragraph 1, of the Federal Disciplinary Code (BDG).











6.) During his service at the Basic Training Department of XXXX from February 4, 2019 to April 30, 2019, he accessed a reward application from Colonel XXXX concerning Sergeant XXXX in the ELAK (Electronic Records System) on March 13, 2019, without authorization or official necessity, thereby negligently violating Section 43 Paragraph 1 of the Federal Disciplinary Code; 6.) During his service at the Basic Training Department of the Roman numeral 40 of 0From February 4, 2019, to April 30, 2019, without authorization or official necessity, on March 13, 2019, accessed a reward application from Colonel (Roman numeral 40) concerning Sergeant Major (Roman numeral 40) in the electronic personnel file (ELAK), thereby negligently violating Section 43, Paragraph 1, of the Federal Disciplinary Code (BDG);

10.) On November 6, 2019, filed a criminal complaint with the Public Prosecutor's Office (SPO) XXXX against Major XXXX on suspicion of fraud and/or abuse of office, even though he knew that only a violation of the rules of procedure had occurred, but no intent to enrich himself or cause harm, and thus intentionally violated Section 43a of the Federal Disciplinary Code (BDG). 10.) On November 6, 2019, he filed a criminal complaint with the Public Prosecutor's Office (StäD) against Major (Röm 40) on suspicion of fraud and/or abuse of office, even though he knew that only a violation of the rules of procedure had occurred, but no intent to enrich himself or cause harm, and thus intentionally violated Section 43a of the Federal Disciplinary Code (BDG);

11.) On February 11, 2020, he recklessly reported his superior, Brigadier XXXX, on suspicion of "defamation" in connection with the latter's statement, "The pending matters concerning Lieutenant Colonel XXXX are in no way comparable to the conduct of Colonel XXXX," in a letter dated November 14, 2019, file number XXXX, as well as regarding the latter's report of March 6, 2019, concerning the order and approval of the Member of Parliament's (MDL) of Captain XXXX (see above, points 1 and 2), and thus negligently violated Section 43a of the Federal Disciplinary Code (BDG); 11.) On February 11, 2020, he recklessly reported his superior, Brigadier General 40, on suspicion of "defamation" in connection with the latter's statement, "The pending matters of Lieutenant Colonel 40 are in no way comparable to the conduct of Colonel 40," in a letter dated November 14, 2019, file number 40, as well as regarding the latter's complaint of March 6, 2019, concerning the order and approval of the MDL of Captain 40 (see above, points 1 and 2), thereby negligently violating Section 43a of the Federal Disciplinary Code (BDG).











13.) On January 20, 2020, he recklessly filed a criminal complaint with the Public Prosecutor's Office XXXX against his superior, Brigadier XXXX, on suspicion of abuse of official authority, concerning the failure to prosecute disciplinary offenses reported by him to Officers Major XXXX, Colonel XXXX, and Colonel XXXX, thereby negligently violating Section 43a of the Federal Disciplinary Code (BDG); 13.) On January 20, 2020, he recklessly filed a criminal complaint with the Public Prosecutor's Office XXXX against his superior, Brigadier General 40, on suspicion of abuse of official authority, concerning the failure to prosecute disciplinary offenses reported by him to Officers Major 40, Colonel 40, and Colonel 40, thereby negligently violating Section 43a of the Federal Disciplinary Code (BDG);










14.) On June 23, 2020, in his formal complaint, he recklessly and untruthfully accused his former superior, Brigadier XXXX, of having made “knowingly, intentionally and demonstrably false statements” to XXXX, AusbA, XXXX and XXXX regarding an employee interview that was not conducted in 2019, and that “there is a suspicion of perjury” and thus negligently violated Section 43a BDG; 14.) On June 23, 2020, in his formal complaint, he recklessly and untruely accused his former superior, Brigadier General 40, of having made "knowingly, intentionally, and demonstrably false statements" to Brigadier General 40, Training and Education Department 40, and Brigadier General 40 regarding an employee review that did not take place in 2019, and that "there is a suspicion of perjury" and thus negligently violated Section 43a of the Federal Disciplinary Code (BDG);














15.) On October 14, 2020, in his report to XXXX /Recht, the XXXX and the staff council, his superior, Colonel XXXX, and Warrant Officer XXXX, as well as on October 20, 2020, in his email to Colonel XXXX and the staff committee, he recklessly accused Colonel XXXX of violating the Security Regulations and Section 310 of the German Criminal Code because Colonel XXXX did not have a valid security clearance (meaning: authorization), which was factually incorrect and thus negligently violated Section 43a of the Federal Disciplinary Code; 15.) On October 14, 2020, in his report to [unclear] /Recht, [unclear] and the staff council, his superiors, Colonel [unclear] and Warrant Officer [unclear], and on October 20, 2020, in his email to Colonel [unclear] and the staff council, [unclear] recklessly accused Colonel [unclear] of violating the [unclear] Code of Conduct and Section 310 of the German Criminal Code because Colonel [unclear] did not have a valid security clearance (meaning: authorization), which was factually incorrect and thus constituted a negligent violation of Section 43a of the Federal Disciplinary Code;


16.) In his email of October 16, 2020, he recklessly accused his superior, Colonel XXXX, in front of third parties of having committed criminal offenses or breaches of duty with regard to the repeated communication order of October 15, 2020, file number XXXX (1), and thus negligently violated Section 43a of the Federal Disciplinary Code (BDG); 16.) In his email of October 16, 2020, he recklessly accused his superior, Colonel Roman 40, in front of third parties of having committed criminal offenses or breaches of duty with regard to the repeated communication order of October 15, 2020, file number Roman 40 (1), and thus negligently violated Section 43a of the Federal Disciplinary Code (BDG);










19.) In his email of 13 November 2020, with the wording “DA XXXX / XXXX is requested to take note of this email, in particular the manner of dealing of XXXX mdFb OberstdG XXXX, that in his area of command in addition to official protocols also ‘shadow protocols’ are kept, which are concealed from the employee and only serve the purpose of ‘slandering’ the employee,” he accuses his superior, OberstdG XXXX, of a dishonest and scheming procedure and thus intentionally violates § 43a BDG; 19.) In his email of November 13, 2020, with the wording "DA Roman 40 / Roman 40 is requested to take note of this email, specifically the practice of Roman 40 mdFb OberstdG Roman 40, that in his area of command, in addition to official protocols, 'shadow protocols' are also kept, which are concealed from the employees and serve only the purpose of 'slandering' the employees," he accused his superior, OberstdG Roman 40, of dishonest and scheming conduct and thus intentionally violated Section 43a of the Federal Disciplinary Code (BDG);

20.) In his email of November 30, 2020, he accused his superior, OberstdG XXXX, of "conduct unbecoming an officer" and thus intentionally violated Section 43a of the Federal Disciplinary Code (BDG); 20.) In his email of November 30, 2020, he accused his superior, Colonel (Grafschafter) Roman numeral 40, of "conduct unbecoming an officer" and thus intentionally violated Section 43a of the Federal Disciplinary Code (BDG);

21.) Contrary to the applicable communication order of October 6, 2020, Ref. No. XXXX (1), he not only submitted his email of November 30, 2020, to Command XXXX via XXXX, but also to the Head of Institute XXXX, Colonel XXXX, even though none of the exceptions listed in the clarification of this order of October 15, 2020, Ref. No. XXXX (1), applied and he was prohibited from doing so, thus intentionally violating Section 44 Paragraph 1 of the Federal Disciplinary Code (BDG); 21.) Contrary to the applicable communication order of October 6, 2020, reference number 40 (1), he not only submitted his email of November 30, 2020, to Command 40 via the Roman numeral 40, but also to the Head of the Institute 40, Colonel 40, even though none of the exceptions listed in the clarification of this order of October 15, 2020, reference number 40 (1), applied and he was prohibited from doing so, thus intentionally violating Section 44, Paragraph 1, of the Federal Disciplinary Code (BDG);

22.) In his email of December 10, 2020, he accused his superior, Colonel XXXX, of trying to "cover something up" and of telling "half-truths" and "lies," thus intentionally violating Section 43a of the Federal Disciplinary Code (BDG); 22.) In his email of December 10, 2020, he accused his superior, Colonel (Roman numeral 40), of trying to "cover something up" and of telling "half-truths" and "lies," thereby intentionally violating Section 43a of the Federal Disciplinary Code (BDG);

23.) He failed to destroy the copy of the attachment to the XXXX concept from October 2006 (InfdNr. 03), which was classified as SECURE, that was in his office after its purpose had been fulfilled or after a maximum of 10 years, thereby negligently violating Section 44 Paragraph 1 of the Federal Disciplinary Code (BDG) in conjunction with Paragraph 120 or Paragraph 169 of the Security Regulations of the Federal Ministry XXXX and Sport (GehSV), Ref. No. XXXX, dated January 1, 2012; 23.) The copy of the appendix to the Roman 40 concept from October 2006 (Item No. 03), which was classified as a SECURITY, and which was held in his office, was not destroyed after fulfillment of its purpose or after a maximum of 10 years, and thus negligently violated Section 44, Paragraph 1, of the Federal Disciplinary Code (BDG) in conjunction with Paragraph 120 or Paragraph 169 of the Federal Ministry of Security's Classified Information Regulation Roman 40 (GehSV), File No. Roman 40, dated January 1, 2012;













24.) contrary to the applicable communication order of 06.10.2020, file number XXXX (1), the report of 13.01.2021 was submitted to the disciplinary authority Unit Commander (Colonel XXXX ), although none of the exceptions listed in the clarification of this order of 15.10.2020, file number XXXX (1), applied and he was prohibited from doing so, thus intentionally violating Section 44 Paragraph 1 BDG; 24.) Contrary to the applicable communication order of October 6, 2020, file number 40 (1), the report of January 13, 2021, was submitted to the disciplinary authority Unit Commander (file number 40), even though none of the exceptions listed in the clarification of this order of October 15, 2020, file number 40 (1), applied and he was prohibited from doing so, thus intentionally violating Section 44, Paragraph 1, of the Federal Disciplinary Code (BDG);

26.) On July 19, 2021, he made the statement to Colonel XXXX that it was "embarrassing for a Colonel of this age not to have more knowledge of the legal matters," thus negligently violating Section 43a of the Federal Disciplinary Code (BDG); 26.) On July 19, 2021, he made the following statement to Colonel (Court) Roman numeral 40, namely that it was "embarrassing for a Colonel of this age not to possess more knowledge of the legal matters," thereby negligently violating Section 43a of the Federal Disciplinary Code (BDG);

47.) On July 19, 2021, he made the following statement to Colonel XXXX, namely that he would "no longer let Mr. XXXX 'talk him down,'" thereby implicitly referring to him as a "Dodel" (meaning: stupid person, fool), and thus intentionally violating Section 43a of the Federal Disciplinary Code (BDG); 47.) On July 19, 2021, he made the following statement to OberstdG römisch 40, in which he said he would "no longer let himself be 'talked to' by Mr. römisch 40," implicitly referring to him as a "Dodel" (meaning: stupid person, fool), and thereby intentionally violated Section 43a of the Federal Disciplinary Code (BDG);

27.) contrary to the applicable communication order of 06.10.2020, file number XXXX (1), by means of his written submissions of 20.09.2021, 06.10.2021, 07.10.2021, 14.10.2021 and 20.10.2021 not only to XXXX, but also directly to the Commander XXXX, although no exception provision within the meaning of the clarification of this order of 15.00.2020, file number XXXX (1), existed and he was prohibited from doing so, and thus intentionally violated Section 44 Paragraph 1 BDG; 27.) Contrary to the applicable communication order of October 6, 2020, file number 40 (1), he transmitted his written submissions of September 20, 2021, October 6, 2021, October 7, 2021, October 14, 2021, and October 20, 2021, not only to the 40 (file number), but also directly to the Commander of the 40 (file number), even though no exception within the meaning of the clarification of this order of October 15, 2020, file number 40 (1), existed and he was prohibited from doing so, thus intentionally violating Section 44, paragraph one, of the Federal Disciplinary Code (BDG);

28) in his submission of 23 September 2021, he repeatedly asserted that Colonel XXXX had “deliberately falsely” accused him in his statement on the disciplinary proceedings of not having ordered Captain XXXX to undertake official travel in accordance with the Travel Expenses Act (RGV), even though he knew this was not the case, and thus accused Colonel XXXX of dishonest and underhanded conduct and thereby intentionally violated Section 43a of the Federal Disciplinary Code (BDG); 28) in his submission of 23 September 2021, he repeatedly asserted that Colonel XXXX had, in hisIn his statement regarding the disciplinary proceedings, he "deliberately falsely" alleged that he had not ordered Captain (Roman 40) to undertake official travel in accordance with the RGV (German Travel Expenses Act), even though he knew this was not the case, thus accusing Colonel (Roman 40) of dishonest and underhanded conduct and therefore intentionally violating Section 43a of the BDG (German Federal Disciplinary Code).


[The following appears to be a separate, unrelated sentence fragment:] 36.) In his submission of October 22, 2021, the following formulations are used: “False testimony as a witness before the LPD XXXX ...on March 15, 2021 by Commander XXXX mdFb and Chief Staff Officer & Deputy Commander due to a lack of knowledge of the BDG” and “...the main fault for this false testimony due to a lack of knowledge of the BDG does not lie with him according to the assessment above, since Commander XXXX was present and should have intervened”: The Chief Staff Officer & Deputy Commander, Colonel XXXX, is accused of having made false witness statements, and Commander XXXX, Colonel XXXX, is accused of having tolerated this and thus negligently violating Section 43a of the BDG; 36.) In his submission of October 22, 2021, the following formulations are used: “False testimony as a witness before the LPD (Regional Police Directorate) Roman 40… on March 15, 2021, by Commander Roman 40 with the Federal Police and Chief Warrant Officer & Deputy Commander due to a lack of knowledge of the Federal Police Act” and “…the latter is not primarily responsible for this false testimony due to a lack of knowledge of the Federal Police Act, according to the assessment above, since Commander Roman 40 was present and should have intervened”: The Chief Warrant Officer & Deputy Commander (Regional Police Directorate Roman 40) is accused of having given false testimony, and the Commander Roman 40 (Regional Police Directorate Roman 40) is accused of having tolerated this and thus negligently violating Section 43a of the Federal Police Act;













40.) By using the wording in his submission of 21 December 2021: “The fact is that this violates the right to information pursuant to Art. 15 GDPR or § 44 DSG and the instruction of AR/ XXXX (1) of 17 December 2021 by OberstdG XXXX,” he recklessly accused his superior of violating an instruction that was not one, and thus negligently violated § 43a BDG; 40.) By stating in his submission of December 21, 2021: “The fact is that this violates the right to information pursuant to Article 15 GDPR and Section 44 DSG, and that the instruction of the AR/ Roman numeral 40 (1) of December 17, 2021, was not correctly implemented by the Chief of Staff Roman numeral 40,” he recklessly accused his superior of violating an instruction that was not one, and thereby negligently violated Section 43a BDG;

42.) through the further formulations in his submission of 21 December 2021: “AR/XXXX is hereby also notified that Colonel XXXX is either unable or unwilling to comply with the data protection regulations and that this repeatedly violates my rights and that, according to the prevailing opinion, this behavior also damages the reputation of XXXX with the data protection authority (public) […]” ridiculed Colonel XXXX and thus intentionally violated Section 43a of the Federal Data Protection Act; 42.) Through the further formulations in his submission of December 21, 2021: “AR/ Roman numeral 40 is hereby also notified that the Chief of Staff Roman numeral 40 is either unable or unwilling to comply with the data protection regulations, and that this repeatedly violates my rights and, according to the prevailing opinion, this behavior also damages the reputation of the Chief of Staff Roman numeral 40 with the data protection authority (the public) […]” he ridiculed the Chief of Staff Roman numeral 40 and thus intentionally violated Section 43a of the Federal Data Protection Act (BDG);

44.) through the wording used in the submission of December 23, 2021: "The following unqualified and false statement is contained on the penultimate page, last paragraph (emphasis added)" and "AR/ XXXX was already warned by me (regarding health data) not to accept data from XXXX (especially from Colonel XXXX) unfiltered/unverified and forward it to third parties; external departments/authorities. In my opinion, this makes XXXX look ridiculous in public" and "Since it must be assumed that an exceptionally intelligent XXXX, such as Colonel XXXX, is capable of counting, it must be deduced that he has deliberately passed on false facts. This is repeatedly perceived as bullying" and "AR/ XXXX is hereby notified that there has been another false report from XXXX (specifically from Colonel XXXX), which will also subsequently damage XXXX's reputation with third parties (Data Protection Officer) in accordance with..." The statements “h.o. assessment is damaging (‘demonstrating incompetence’)” and “DA XXXX / XXXX reports that due to the repeated false reports of the ‘merely seconded’ OberstdG XXXX, the reputation of ‘our’ XXXX suffers in front of external agencies/authorities (here DSB)” exceed the scope of objective criticism and thus deliberately violate § 43a BDG; 44.) through the wording used in the submission of December 23, 2021: "The following unqualified and false statement is contained on the penultimate page, last paragraph (emphasis added)" and "AR/ Roman numeral 40 has already been warned by me (regarding health data) not to accept data from Roman numeral 40 (especially from Colonel General Roman numeral 40) unfiltered/unverified and forward it to third parties; external departments/authorities. In doing so, Roman numeral 40 is making himself look ridiculous in public according to the highest assessment" and "Since it must be assumed that an above-average intelligent Roman numeral 40, such as Colonel General Roman numeral 40, is capable of counting, it must be deduced that he has deliberately passed on false facts. This is repeatedly perceived as bullying in the highest assessment" and "AR/ Roman numeral 40 is hereby notified that there is a repeated false report from Roman numeral 40 (specifically by Colonel General Roman numeral 40), which is also in The following statements, which further damage the reputation of the [unclear] (Roman 40) in the eyes of third parties (DSB) according to the higher court's assessment ('demonstrating incompetence'), and 'DA Roman 40 / Roman 40 reports that due to the repeated false reports of the 'merely seconded' Colonel Roman 40, the reputation of 'our' Roman 40 in the eyes of external agencies/authorities (here DSB) is suffering,' exceeded the bounds of objective criticism and thus intentionally violated Section 43a of the Federal Disciplinary Code (BDG);

and committed culpable breaches of duty in all points pursuant to Section 2 Paragraph 1 of the 2014 Military Disciplinary Act (HDG). He was acquitted of a further 25 charges of breaches of duty and part of a ruling, with the aforementioned findings being overturned by the Administrative Court only with regard to the severity of the sentence. and was found guilty of culpable breaches of duty in all respects pursuant to Section 2, Paragraph 1, of the 2014 Military Disciplinary Act (HDG). He was acquitted of 25 further charges of breaches of duty and of one point of the ruling, with the aforementioned findings being overturned by the Administrative Court only with regard to the severity of the sentence.

2.3. Regarding the data protection complaints in question:

The data protection complaint filed by the BF on April 11, 2023 (see 1.1.1 above) against XXXX (first respondent) for a violation of the right to information, recorded under file number D124.0729/23, reads as follows:

By email via Kdo XXXX (intermediate supervisor), I requested information pursuant to Section 44 (1) of the Data Protection Act (regarding all 7 points) concerning the processing of my health data by Dion1 in a letter dated February 7, 2023. That my health data is/was being processed by Dion1 is evident from document XXXX (1) dated April 27, 2021, as this health data was unlawfully disclosed to Dion1 by Kdo XXXX (see DSB D124.5629/22). By means of XXXX (2) dated March 3, 2023, the responsible authority at XXXX claimed that this request for information had already been fully answered by the proceedings before the DSB D124.5629/22. I pointed out this error via email on March 6, 2023, clarifying that the proceedings before the DSB only concerned the "redacted recipients" and not the further processing of my health data by Dion1, and I granted an extension of the deadline until April 6, 2023. The deadline has expired without result. By email via Kdo Roman 40 (intermediate superior authority), I requested information pursuant to Section 44 (1) of the GDPR (regarding all 7 points) concerning the processing of my health data by Dion1 in a letter dated February 7, 2023. That my health data is/was being processed by Dion1 is evident from document Roman 40 (1) dated April 27, 2021, as this health data was unlawfully disclosed by Kdo Roman 40 to Dion1 (see DSB D124.5629/22). By Roman 40 (2) dated March 3, 2023, the responsible authority in Roman 40 suggested that this request for information had already been fully answered by the proceedings before DSB D124.5629/22. I pointed out the error via email on March 6, 2023, explaining that the proceedings before the Data Protection Authority (DSB) only concern the "redacted recipients" and not the further processing of my health data by Dion1, and I granted an extension until April 6, 2023. This deadline has passed without resolution.



``` The data protection complaint filed by the appellant on November 11, 2023 (1.1.2.) against XXXX (second respondent) and Colonel XXXX (third respondent) for violation of the right to confidentiality, recorded under file number XXXX, was submitted to the Federal Administrative Court (BVwG) by the respondent authority on August 9, 2024, following a complaint for failure to act filed by the appellant on May 16, 2024. Submitted to the Federal Administrative Court.


The data protection complaint filed by the BF on January 28, 2024 (1.1.3.) against XXXX (second respondent) for a violation of the right to confidentiality, recorded under file number D124.0392/24, reads as follows:

Information on the legal violation

As commander of XXXX, Chief Warrant Officer XXXX, with file number XXXX (1) dated June 8, 2021, transferred my health data to [unclear] contrary to the clear provisions of the Official Gazette I of XXXX No. 71 "Guidelines for Data Protection in XXXX; Version 2021" in conjunction with Article 5 GDPR. Uninvolved third parties, namely XXXX c/o Disciplinary Prosecutor, XXXX and the XXXX authority, unlawfully disclosed my health data. As commander of the 40th District Court, with file number 40 (1) dated June 8, 2021, my health data was unlawfully disclosed to uninvolved third parties, namely the 40th District Court c/o Disciplinary Prosecutor, XXXX and the XXXX authority, contrary to the clear provisions of the Official Gazette No. 71 of the 40th District Court, "Guidelines for Data Protection in the 40th District Court; 2021 version," in conjunction with Article 5 of the GDPR.

Facts

Lieutenant Colonel XXXX, as commander of XXXX, submitted a statement regarding a data protection complaint on June 8, 2021, under file number XXXX (1). This is clearly evident from the subject line "... XXXX, Lieutenant Colonel, Institute XXXX; Data Protection Complaint (Confidentiality) against XXXX; Forwarding..." and the first paragraph, "...The present complaint of Lieutenant Colonel XXXX to the Data Protection Authority (Enclosure 1) is forwarded to XXXX /Legal Department for processing in accordance with Official Gazette 4/2021..." According to Official Gazette 4/2021, the forwarding to XXXX /Legal Department is correct. The fact that my health data was unlawfully disclosed here is currently being addressed in proceedings before the Federal Administrative Court under case number W258 2253618-1 (Data Protection Authority proceedings file number D124.5322). Neither the then-valid VBl 4/2021 nor the currently valid VBL 71/2021 provides for the submission of statements regarding data protection complaints to any body other than the responsible body within XXXX, then XXXX /Legal Department, now DSBürger/ XXXX, as can be inferred from point VII "Responsibilities for Data Protection Matters within the Department". Consequently, the offices listed in the distribution list of the incriminating document, besides the responsible Legal Department/ XXXX: XXXX (c/o Disciplinary Attorney), XXXX, and XXXX authority, are NOT to be involved. The violation is particularly blatant due to the involvement of the Federal Disciplinary Authority, as this authority does not even belong to the XXXX department. The distribution list for XXXX /Legal Department was familiar to me from proceedings before the Data Protection Authority. However, the other recipients, XXXX and XXXX authority, were redacted in those proceedings. I only became aware of this distribution list due to the hearing before the Federal Administrative Court (BVwG) regarding case W258 2253618-1 on November 13, 2023, and this can be seen in the minutes of the hearing regarding case W258 2253618-1/12Z of November 17, 2023, page 8 (…It is noted that a copy of the letter will be given to the parties and added to the file as an attachment…). My health data is contained in this document on page “Psychological Stress”, page 2 “Contact established with the HPD and military psychological support ensured”. It is undisputed that this clearly constitutes health data within the meaning of data protection law. Lieutenant Colonel (Lt.) 40, as commander of the 40th Infantry Division, responded to a data protection complaint with file number 40 (1) dated June 8, 2021. This is clearly evident from the subject line “…Lt. Colonel 40, Lt. Colonel, Institute of the 40th Infantry Division.” 40; Data protection complaint (confidentiality) against Roman 40; forwarding..." and the first paragraph "...The present complaint of the Lieutenant Colonel Roman 40 to the Data Protection Authority (Enclosure 1) is forwarded to Roman 40 /Law for processing in accordance with VBl. 4/2021..." According to VBl 4/2021, the forwarding to Roman 40 /Law is correct. The fact that my health data has already been unlawfully disclosed here is currently being dealt with in proceedings before the Federal Administrative Court under W258 2253618-1 (Data Protection Authority proceedings file number D124.5322). Neither the then valid VBl 4/2021 nor the currently valid VBl 71/2021 provides for the forwarding of statements on data protection complaints to bodies other than the competent authority under Roman 40, then Roman 40 /Law, now DSBürg/ Roman 40, and this is clear from point Roman 40. Seven "responsibilities for data protection matters within the department." Consequently, the offices listed in the distribution list of the incriminated document, besides the responsible office Legal/Roman 40: Roman 40 (c/o Disciplinary Attorney), Roman 40, and Roman 40 Authority, are NOT to be involved. The violation is particularly blatant due to the involvement of the Federal Disciplinary Authority, as it does NOT even belong to the department of Roman 40. I was aware of the distribution list to Roman 40/Legal from proceedings before the Data Protection Authority. However, the other recipients, Roman 40 and Roman 40 Authority, were redacted in those proceedings. I only became aware of this distribution list as a result of the hearing before the Federal Administrative Court (BVwG) under case number W258 2253618-1 on November 13, 2023, and this can be seen in the minutes of the hearing under case number W258 2253618-1/12Z of November 17, 2023, page 8 (....It is noted that a copy the letter is handed over to the parties and is attached to the file as an enclosure./2..." My health data is contained in this document on page "Psychological Stress," page 2 "Contact established with the HPD and military psychological support ensured." It is undisputed that this clearly constitutes health data within the meaning of data protection law.

The data protection complaint of the BF dated February 19, 2024 (1.1.4.) against XXXX (second respondent) for violation of the right to confidentiality, recorded under file number D124.0759/24, reads as follows:

Information on the legal violation

Senior Lieutenant XXXX, as commander of XXXX By file number XXXX (2) dated November 3, 2021, my health data was unlawfully disclosed to uninvolved third parties, namely Dion1/XXXX (for information purposes) and two other departments (these are redacted), contrary to the clear provisions of Official Gazette I of XXXX No. 71 "Guidelines for Data Protection in XXXX, Version 2021" in conjunction with Article 5 GDPR. As commander of the 40th Infantry Regiment, Colonel (General Staff) unlawfully disclosed my health data to uninvolved third parties, namely Dion1/XXXX (for information purposes) and two other departments (these are redacted), by file number 40 (2) dated November 3, 2021, contrary to the clear provisions of Official Gazette I of XXXX No. 71 "Guidelines for Data Protection in XXXX, Version 2021" in conjunction with Article 5 GDPR. Disclosed.

Facts

Lieutenant Colonel XXXX, as commander of XXXX, submitted a statement on November 3, 2021, regarding a restriction of the processing of health data, under file number XXXX (2). This is clearly evident from the subject line: "...Lieutenant Colonel XXXX; Inst XXXX; General Data Protection Regulation (GDPR), Restriction of the processing of health-related data by XXXX pursuant to Art. 18 GDPR, Application; Submission..." and the first sentence in the text field: "... XXXX hereby submits the present application (Attachment 1) of Lieutenant Colonel XXXX dated November 3, 2021, to AR/ XXXX, as the competent authority, with the following statement:..." The submission to AR/ XXXX is in accordance with the official gazettes of XXXX. Neither the previous Official Gazette I No. 4/2021 nor the currently valid Official Gazette 71/2021 provides for the submission of restrictions on the processing of Health data was forwarded to entities other than the responsible office in XXXX, then AR/XXXX, now DSBür/XXXX, as can be deduced from point VII "Responsibilities for Data Protection Matters within the Department". Consequently, the offices listed in the distribution list of the incriminating document, besides the responsible office AR/XXXX, are NOT to be involved: Dion1/XXXX (for information only) and 2 other offices (redacted). Based on the previous conduct of Colonel XXXX, it is suspected that the redacted offices are XXXX/XXXX with the disciplinary lawyer Colonel IntD XXXX, and the second office is an office outside the department of XXXX, namely the XXXX authority XXXX, Senate 42 with Brigadier XXXX. The distribution list to AR/XXXX was known to me from another proceeding before the Data Protection Authority. However, by decision of the Data Protection Authority dated November 28, 2023, under D124.5629, I was informed that Requests for information regarding the offices listed in the distribution list were denied; consequently, a complaint is now being filed against two unknown offices. My health data is located in this document on page 4, under point 7: "psychological stress" and "establishing contact on April 22, 2021, with the HPD [Note: Army Psychological Service] and ensuring military psychological support." Lieutenant Colonel (Lt. 40) has, as commander of the 40th Infantry Division, issued a statement regarding a restriction of the processing of health data with reference number 40 (2) dated November 3, 2021. This is clearly evident from the subject line: "...Lieutenant Colonel (Lt. 40); Institute (Lt. 40); General Data Protection Regulation (GDPR), Restriction of the processing of health-related data by the 40th Infantry Division pursuant to Article 18, GDPR, Application; Submission..." and the first sentence in the text field: "...Lt. 40 submits the present submission (Attachment 1) of the Lieutenant Colonel." The document in question, dated November 3, 2021, was submitted to AR/Roman 40, the competent authority, with the following statement:...“ The submission to AR/Roman 40 is correct in accordance with the official gazettes of Roman 40. Neither the previous Official Gazette Roman 1 No. 4/2021 nor the currently valid Official Gazette 71/2021 provides for the submission of restrictions on the processing of health data to any body other than the competent authority under Roman 40, formerly AR/Roman 40, now DSBür/Roman 40, and this is evident from point Roman 7, “Responsibilities for Data Protection Matters within the Department.” Consequently, the offices listed in the distribution list of the document in question, in addition to the competent authority AR/Roman 40: Dion1/Roman 40 (for information) and two other offices (redacted), are NOT to be involved. Based on the previous conduct of the Chief of Staff Roman 40, it is presumed that it The redacted entries refer to the first office (Roman 40) with the disciplinary officer, Colonel (IntD) Roman 40, and the second office is an agency outside the purview of Roman 40, namely the authority (Roman 40), Senate 42, with Brigadier General (Roman 40). The distribution list to AR/Roman 40 was known to me from another proceeding before the Data Protection Authority (DSB). However, by decision of the DSB dated November 28, 2023, reference D124.5629, my request for information regarding the agencies named in the distribution list was denied; consequently, this complaint is now being filed against two unknown agencies. My health data is contained in this document on page 4, point 7: "psychological stress" and "establishing contact on April 22, 2021, with the Army Psychological Service (HPD) and ensuring military psychological support."

The data protection complaint of the BF dated The data protection complaint filed on February 29, 2024 (1.1.5.) against XXXX (second respondent), with Colonel XXXX as commanding officer and Officer XXXX, for violation of the right to confidentiality, recorded under file number D124.0668/24, reads as follows:

Details of the legal violation

On February 27, 2024, at noon, Officer XXXX, acting on behalf of the commanding officer of XXXX, violated the confidentiality provisions of the data protection regulations (DSG, GDPR) in conjunction with Sections 26 and 34 of the Hessian Data Protection Act (HDG). On February 27, 2024, in the lecture hall of Institute XXXX, in front of the staff of Institute XXXX during an official meeting (staff information session), Colonel Roman numeral 40 unlawfully disclosed my disciplinary ruling of the Federal Administrative Court (BVwG) dated January 12, 2024. On February 27, 2024, at noon, Colonel Roman numeral 40, acting on behalf of the commander of the Roman numeral 40, unlawfully disclosed my disciplinary ruling of the Federal Administrative Court (BVwG) dated January 12, 2024, in the lecture hall of Institute XXXX, in front of the staff of Institute XXXX during an official meeting (staff information session), in violation of the confidentiality provisions of the data protection regulations (DSG, GDPR) in conjunction with Sections 26 and 34 of the HDG.

Facts

The XXXX authority XXXX imposed a disciplinary penalty of a fine on me by decision dated March 16, 2023, file number 2021-0.285.817. In these proceedings, Colonel XXXX and Colonel XXXX were summoned as witnesses. Following an appeal by the disciplinary attorney/XXXX and myself against this decision, the Federal Administrative Court (BVwG), as the second instance, imposed the disciplinary penalty of dismissal by ruling dated January 12, 2024, file number W208 2255608-2/45E. Colonel XXXX and Colonel XXXX were again summoned as witnesses at this hearing. In these proceedings, restrictions on the right to confidentiality are only permissible if there is a qualified legal basis, since the respondent XXXX is a "state authority" within the meaning of Section 1 Paragraph 2 of the Data Protection Act (DSG) (public sector entity). The established jurisprudence of the Constitutional Court regarding the quality of an intervention provision within the meaning of Section 1 Paragraph 2 of the Data Protection Act (DSG) establishes that such a provision must be sufficiently precise, i.e., foreseeable for everyone, and must also regulate the conditions under which the collection or use of personal data for the performance of specific administrative tasks is permitted (see, most recently, the rulings of December 11, 2019, G 72/2019 et al., and of December 12, 2019, G 164/2019 et al.). According to Article 6 Paragraph 1 Letter e of the GDPR, processing in this context is only permissible if it is necessary for the performance of a task carried out in the public interest. Despite bearing the burden of proof, the respondent (XXXX with its officers OberstdG XXXX and Obst XXXX) failed to invoke a corresponding legal basis in this regard. The data protection authority is also unaware of any such legal basis covering the matter at issue in this complaint (see decision D124.1265). On the contrary, numerous regulations exist that are intended to protect an employee from the disclosure of a disciplinary ruling imposed against them: For example, Section 26 of the Hessian Disciplinary Act (HDG) stipulates that, outside of disciplinary proceedings, all persons participating in or otherwise involved with these proceedings are obligated to maintain confidentiality regarding all facts concerning the proceedings that come to their knowledge in their respective functions, provided this is necessary to safeguard public or legitimate private interests. Furthermore, Section 34 of the HDG stipulates that disclosures to the public about the content of disciplinary measures and disciplinary proceedings are prohibited, unless otherwise provided by this federal law. Nevertheless, on behalf of the Chief of Staff XXXX, Colonel XXXX announced my disciplinary decision to the staff of Institute XXXX on February 27, 2024, at noon in a lecture hall of Institute XXXX, detailing the number of breaches of duty and the violations of the respective legal norms. Since the respondent (XXXX with the officers OberstdG XXXX and Obst XXXX) ultimately lacks a (sufficiently) valid legal basis, the complaint will be granted pursuant to Section 24 Paragraph 5 of the Data Protection Act (DSG), and the breach of confidentiality will be determined as follows: The complaint is granted, and it is determined that the respondent (XXXX with the officers OberstdG XXXX and Obst XXXX) violated the complainant's right to confidentiality by having an employee of the respondent (Obst XXXX) unlawfully disclose the complainant's disciplinary decision to other employees during an official institute meeting on February 27, 2024, on behalf of Commander XXXX and OberstdG XXXX. It should also be noted that this agency XXXX has already unlawfully disclosed my disciplinary proceedings and penalties on several occasions, and reference may be made to the following decisions of the Data Protection Authority (DSB): - D124.2668, D124.2664, D124.4169, D124.5599, D124.0122 and D124.1265. It is only mentioned for the sake of completeness that further data protection violations by XXXX, which have been established by means of decisions of the DSB, also exist. The authority Roman 40 imposed a disciplinary penalty of a fine on me by means of a decision dated March 16, 2023, file number 2021-0.285.817. In these proceedings, Colonel (Rc. 40) and Colonel (Rc. 40) were summoned as witnesses. Due to the appeal filed by the disciplinary attorney (Roman 40) and myself against this decision, the Federal Administrative Court (BVwG), as the second instance, imposed the disciplinary penalty of dismissal in its ruling of January 12, 2024, case number W208 2255608-2/45E. At this hearing, Colonel (Roman 40) and Colonel (Roman 40) were again summoned as witnesses. In these proceedings, restrictions on the right to confidentiality are only permissible if a qualified legal basis exists, since the respondent (Roman 40) is a "state authority" within the meaning of Section 1, Paragraph 2, of the Data Protection Act (DSG) (public sector entity). According to the established case law of the Constitutional Court regarding the quality of an intervention provision within the meaning of Section 1, Paragraph 2 of the Data Protection Act (DSG), it can be inferred that such a provision must be sufficiently precise, i.e., foreseeable for everyone, and must also regulate the conditions under which the collection or use of personal data for the performance of specific administrative tasks is permitted (see, most recently, the rulings of December 11, 2019, G 72/2019 et al., and of December 12, 2019, G 164/2019 et al.). Furthermore, according to Article 6, Paragraph 1, Letter e of the GDPR, processing in this context is only permissible if it is necessary for the performance of a task carried out in the public interest. The respondent (Rum 40 with the bodies ObstdG Roman 40 and Obst Roman 40) failed to invoke a corresponding legal basis in this context, despite the burden of proof. The Data Protection Authority is also unaware of any such legal basis covering the matter at issue in this complaint (see decision D124.1265). Rather, numerous regulations exist that are intended to protect an employee from the disclosure of a disciplinary ruling imposed against them: For example, Section 26 of the Hessian Disciplinary Act (HDG) stipulates that, outside of disciplinary proceedings, all persons participating in or otherwise involved with these proceedings are obligated to maintain confidentiality regarding all facts concerning the proceedings that come to their knowledge in their respective functions, insofar as this is necessary to safeguard public or legitimate private interests. Furthermore, Section 34 of the HDG stipulates that disclosures to the public about the content of disciplinary measures and disciplinary proceedings are prohibited, unless otherwise provided by this federal law. Nevertheless, on behalf of the Chief of Staff (Roman 40), my disciplinary decision was announced to the staff of the Institute (Roman 40) on February 27, 2024, at noon in a lecture hall of the Institute (Roman 40), detailing the number of breaches of duty and violations of the respective legal norms. Since the respondent (Roman 40 with the bodies ObstdG Roman 40 and Obst Roman 40) ultimately lacks a (sufficiently) supporting legal basis, the complaint will be granted pursuant to Section 24, Paragraph 5, DSG and the breach of confidentiality will be determined as follows: The complaint is granted and it is determined that the respondent (Roman 40 with the bodies ObstdG Roman 40 and Obst Roman 40) violated the complainant's right to confidentiality by having an employee of the respondent (Obst Roman 40) unlawfully disclose the complainant's disciplinary decision to other employees during an official institute meeting on February 27, 2024, on behalf of the Commander Roman 40 ObstdG Roman 40. It should also be noted that this office (Roman 40) has already unlawfully disclosed my disciplinary proceedings and penalties on several occasions, and reference may be made to the following decisions of the Data Protection Authority (DSB): - D124.2668, D124.2664, D124.4169, D124.5599, D124.0122, and D124.1265. It is only mentioned for the sake of completeness that further data protection violations by Roman 40, which have been established by means of decisions of the DSB, also exist.



``` The data protection complaint filed by the BF on March 12, 2024 (1.1.6.) against Lt. Col. XXXX, commander of XXXX (fourth respondent), for a violation of the right to confidentiality, recorded under file number D124.0751/24, reads as follows:

Details of the legal violation

Contrary to data protection regulations in conjunction with Section 19 Paragraph 5 of the Data Protection Ordinance, Lt. Col. XXXX sent a private message from my mobile phone to the staff representative, Lt. Col. XXXX, containing my personal data (face and telephone number), WITHOUT my consent, at the XXXX barracks in XXXX. A photograph of me was taken from the mobile phone of the staff representative, Lieutenant Colonel 40, containing my personal data (face and telephone number), and was unlawfully transmitted to third parties. This occurred without my consent. This photograph was taken at the barracks in the 40 barracks in the 40 barracks.

Facts

In April 2023, I filed a formal complaint with my office, Institute XXXX, pursuant to the Data Protection Regulations (DPA), because the nature and severity of my non-final disciplinary decision had been unlawfully disclosed at this institute, contrary to data protection regulations and Sections 26 (Duty of Confidentiality) and 34 (Disclosure to the Public).In this context, reference should be made to the decisions of the Data Protection Authority (DSB) regarding cases D124.1265/23 and D124.0242/2, in which the violation of the right to confidentiality has already been established by the Data Protection Authority. Lieutenant Colonel XXXX is a member of the staff council (employee representation) of Institute XXXX, which is responsible for me, and consequently, I also exchange information with them regarding the unlawful conduct of my superiors. This communication takes place, among other things, via the provider "Signal." On April 20, 2023, I informed Lieutenant Colonel XXXX, as a staff representative, again via "Signal" about the matter of "Disclosure of Disciplinary Proceedings." That Lieutenant Colonel XXXX is NOT permitted to disclose this personal, confidential information to the employer representative, Lieutenant Colonel XXXX, is clearly established by the Federal Act on Staff Representation in Federal Agencies (Federal Staff Representation Act – PVG). However, the fact is that Lieutenant Colonel XXXX apparently "ambushed" the staff representative, Lieutenant Colonel XXXX, and photographed his private mobile phone containing my message (see Appendix 1). This incident occurred in Lieutenant Colonel XXXX's office (witness: Lieutenant Colonel XXXX). The photograph clearly shows that it was taken from Lieutenant Colonel XXXX's mobile phone; furthermore, my personal data ("passport photo," name) is also visible in the photograph. Data protection regulations and relevant case law clearly state that since 2018, recognizable individuals in photographs are considered personal data. Consequently, this already constitutes a violation of data protection regulations, as I have NEVER given my consent for this. Since this photograph was taken in the office of Lieutenant Colonel XXXX at the XXXX barracks, reference may be made to the clear provisions of Section 19 Paragraph 5 of the ADV (General Administrative Regulations), which read as follows: "...Photography and Filming (5) Photographing or filming within the barracks area requires the permission of the barracks commander..." Furthermore, signs are posted around the barracks indicating the prohibition of photography within the barracks area. Lieutenant Colonel XXXX can be cited as a witness in this regard. Consequently, there is also a violation of Section 19 (5) ADV by Lieutenant Colonel XXXX. Lieutenant Colonel XXXX also unlawfully transmitted this photograph to third parties, including the Federal Bureau for Corruption Prevention and Combating Corruption. As evidence, reference may be made to the file of the Public Prosecutor's Office XXXX, case number 11 St 99/23 m, specifically to Exhibit ON 8.28 (file number and reference number also visible in the photograph above). Whether this photograph was also transmitted to other third parties is unclear. While not known or provable, it must be inferred from recent events that this photograph was also transmitted to the disciplinary attorney/XXXX (Colonel IntD XXXX) and to the XXXX authority (Brigadier XXXX). If Colonel XXXX now believes that he has thereby presented "evidence" in the investigation against him by the Public Prosecutor's Office XXXX on suspicion of abuse of office, suppression of documents, and data processing with intent to gain or cause harm, this opinion is legally incorrect. Whether this photograph constitutes evidence in the present case is decided by the Public Prosecutor's Office, and it is clear to any objective observer that this photograph CANNOT be used to exonerate Colonel XXXX in the proceedings of the Data Protection Authority under D124.1265/23, as this is not the subject matter. A text message from me to a staff representative can never prove or disprove whether Colonel XXXX submitted documents to the Data Protection Authority (DSB) or not, and must therefore already be considered a self-serving statement in these proceedings before the DSB. Furthermore, the Supreme Court (OGH) has ruled on the use of illegally obtained evidence that an unlawfully obtained audio recording (which also applies to photographs) may only be used in legal proceedings in exceptional cases (self-defense, necessity, pursuit of legitimate interests) after a corresponding balancing of interests (3 Ob 131/00m). It is obvious that this is not the case here. In April 2023, I filed a formal complaint with my department, Institute Roman 40, pursuant to the Data Protection Act (ADV), because the nature and amount of my non-final disciplinary decision were unlawfully disclosed at this institute, contrary to data protection regulations and Sections 26 of the Hessian Data Protection Act (HDG) ("Duty of Confidentiality") and 34 of the HDG ("Disclosure to the Public"). In this context, reference should be made to the decisions of the Data Protection Authority (DSB) regarding cases D124.1265/23 and D124.0242/2, in which the violation of the right to confidentiality has already been established by the Data Protection Authority. Lieutenant Colonel Roman 40 is a member of the staff council (employee representation) of Institute Roman 40, which is responsible for me, and consequently, I also exchange information with them regarding the unlawful conduct of my superiors. This communication takes place, among other channels, via the provider "Signal." On April 20, 2023, I informed Lieutenant Colonel Roman 40, as a staff representative, again about the matter of "Disclosure of Disciplinary Proceedings" via "Signal." That Lieutenant Colonel (R-40) is NOT permitted to disclose this personal, confidential information to the employer representative, Lieutenant Colonel (R-40), is clearly evident from the Federal Act on Staff Representation in Federal Agencies (Federal Staff Representation Act – PVG). However, the fact is that Lieutenant Colonel (R-40) apparently "ambushed" the staff representative, Lieutenant Colonel (R-40), and photographed his private mobile phone containing my message (see Appendix 1). This incident occurred in Lieutenant Colonel (R-40)'s office (witness: Lieutenant Colonel (R-40)). The photograph clearly shows that it was taken from Lieutenant Colonel (R-40)'s mobile phone; furthermore, my personal data ("passport photo," name) is also visible in the photograph. Data protection regulations and relevant case law clearly state that since 2018, recognizable individuals in photographs are considered personal data. Consequently, this already constitutes a violation of data protection regulations, as I have NEVER given my consent for this. Since this photograph was taken in the office of Lieutenant Colonel Roman 40 in the Roman 40 barracks, reference must be made to the clear provisions of Section 19, Paragraph 5 of the General Administrative Regulations (ADV), which read as follows: "...Photography and Filming (5) Photographing or filming in the barracks area requires the permission of the barracks commander..." Furthermore, signs are posted around the barracks indicating the prohibition of photography within the barracks area. Lieutenant Colonel Roman 40 is cited as a witness in this matter. Consequently, there is also a violation of Section 19, (5) ADV by Lieutenant Colonel Roman 40. Lieutenant Colonel Roman 40 also unlawfully transmitted this photograph to third parties, including the Federal Bureau for Corruption Prevention and Combating Corruption. As evidence, reference may be made to the file of the Public Prosecutor's Office Roman 40, case number 11 St 99/23 m, specifically to Appendix ON 8.28 (file number and address also visible in the photograph above). Whether this photo was also transmitted to other third parties is not known or provable at present; however, it must be inferred from recent events that this photo was also transmitted to the disciplinary prosecutor (Roman 40) and to the authority (Roman 40). If the Colonel-in-Chief (Roman 40) now believes that he has thereby presented "evidence" in the investigation against him by the Public Prosecutor's Office (Roman 40) on suspicion of abuse of office, suppression of documents, and data processing with intent to gain or cause harm, this opinion is legally incorrect. Whether this photograph constitutes evidence in the present case is a matter for the public prosecutor's office to decide. It is readily apparent to any objective observer that this photograph cannot be used to exonerate the accused in the DSB proceedings under case number D124.1265/23 regarding abuse of office or suppression of documents. This is because the case is not thematically relevant. A text message I sent to a staff representative can never prove or exonerate the accused as to whether or not the accused submitted documents to the DSB. This must be considered a self-serving statement in these proceedings before the DSB. Furthermore, the Supreme Court has ruled on the admissibility of illegally obtained evidence that an unlawfully obtained audio recording (which also applies to photographs) may only be used in legal proceedings in exceptional circumstances (self-defense, necessity, pursuit of legitimate interests) after a corresponding balancing of interests (3 Ob 131/00m). It is obvious that this is not the case here.

The data protection complaint filed by the BF on April 9, 2024 (1.1.7.) against Colonel XXXX as the disciplinary authority, disciplinary commander/unit commander (fifth respondent) for violation of the right to information, recorded under file number D124.0976/24, reads as follows:

Colonel XXXX, as the disciplinary authority and disciplinary commander/unit commander pursuant to the Hessian Data Protection Act (HDG), failed to process my request for information pursuant to Section 44 of the Data Protection Act (DSG) of March 8, 2024, within the one-month deadline. By means of a preliminary submission dated 08.3.2024, I requested information about my personal data from the disciplinary authority responsible for me, Disciplinary Commander/Unit Commander Colonel XXXX, pursuant to Section 44 of the Data Protection Act (Enclosure 1).The decree issued by XXXX on July 28, 2021, file number XXXX, published as Official Gazette I, No. 71, "Directive for Data Protection in XXXX; Version 2021" of August 23, 2021, Chapter VI, Section 1, clearly stipulates that the competent authority, in this case the disciplinary authority, specifically the Disciplinary Commander/Unit Commander Colonel XXXX, is responsible for this task. Colonel XXXX has not responded by April 9, 2024, neither substantively nor by requesting a three-month extension. Instead, the Data Protection Office/XXXX responded with a letter dated April 2, 2024, file number XXXX (1) (Appendix 2). This document informs me that my request, pursuant to Section 44 Paragraph 3 of the Data Protection Act (DSG) in conjunction with Section 42 Paragraph 6 Item 2 of the DSG, or pursuant to Article 12 Paragraph 5 Letter b of the GDPR, will not be considered due to its manifest lack of merit and excessiveness. The fact that this justification is clearly lacking can be easily demonstrated: 1.) Requests to the Disciplinary Authority, Disciplinary Commander/Unit Commander XXXX: I have been a member of Institute XXXX (formerly XXXX) since January 1, 2005, and this is my first request for information to this authority. To claim that a request is unfounded and excessive after more than 20 years is beyond bizarre. 2.) Response from the Data Protection Officer/XXXX: The Data Protection Officer/XXXX represents XXXX in matters of jurisdiction, which is NOT applicable here, vis-à-vis the Data Protection Authority (DSB), and likely provided a response for its own use. The Data Protection Authority (DSB) is aware that Ministerial Councillor XXXX, DSBür/XXXX, frequently submits lengthy and inaccurate statements to the DSB on behalf of XXXX, always attempting to invoke the argument of "unfoundedness and excessiveness." The DSB has already determined in an internal meeting that this argument is unfounded. It is also officially known that DSBür/ XXXX obviously has deficiencies/problems in the application of data protection regulations (DSG; GDPR), as their statements have not been followed in a single decision by the DSB that concerns me, and reference may be made to the following decisions of the DSB: - D124.2668 - D124.4169 - D124.5599 (Confirmed by the Federal Administrative Court) - D124.0123 - D124.0122 - D124.0853/23 - D124.1265/23 - D124.0242/24. The Data Protection Authority (DSB) is hereby requested to: 1.) Determine the violation of the right to information pursuant to the application of March 8, 2024; 2.) Arrange for the transmission of the required information by the disciplinary authority, the Disciplinary Commander/Unit Commander (Obst XXXX). The disciplinary authority, Obst 40 (Roman numeral 40), as the Disciplinary Commander/Unit Commander pursuant to the Hessian Disciplinary Act (HDG), has NOT processed my application for information pursuant to Section 44 of the Data Protection Act (DSG) of March 8, 2024, within the one-month period. With my initiating submission of March 8, 2024, I requested information about my personal data from the disciplinary authority responsible for me, the Disciplinary Commander/Unit Commander, Obst 40 (Roman numeral 40), pursuant to Section 44 of the Data Protection Act (DSG) (Enclosure 1). This request was made by the decree of Obst 40 of July 28, 2021, file number 40, published as the Official Gazette (VBl.). Article 1, No. 71, "Directive on Data Protection in the [Unit Name]; Version 2021" of August 23, 2021, Chapter 6, Point 1, clearly stipulates that the competent authority, in this case the Disciplinary Authority, specifically the Disciplinary Commander/Unit Commander [Unit Name] [Unit Name] [Unit Name] [Unit Name], is responsible for this. No response, neither substantive nor a request for a three-month extension, was received from [Unit Name] [Unit Name] by April 9, 2024. Instead, the Data Protection Office/Unit Name [Unit Name] [Unit Name] responded with a letter dated April 2, 2024, reference number [Reference Number] [Unit Name] (1) (Enclosure 2). This document informs me that my request, pursuant to Section 44 Paragraph 3 of the Data Protection Act (DSG) in conjunction with Section 42 Paragraph 6, Number 2 of the DSG, or pursuant to Article 12 Paragraph 5, Letter b of the GDPR, will not be considered on its merits due to manifest lack of merit and excessiveness. That this justification is clearly lacking can be easily demonstrated: 1.) Applications to the Disciplinary Authority, Disciplinary Commander/Unit Commander, Roman 40. I have been a member of Institute Roman 40 (formerly Roman 40) since January 1, 2005, and this is my first request for information to this authority. To be told, after more than 20 years, that a request is unfounded and excessive is beyond bizarre. 2.) Response of the DSBür/ Roman numeral 40: The DSBür/ Roman numeral 40 represents the Roman numeral 40 in matters where jurisdiction exists, which is NOT the case here, vis-à-vis the DSB and likely already provided its own response. The DSB is aware that Ministerial Councillor Roman numeral 40 (DSBür/ Roman numeral 40) frequently submits lengthy and inaccurate statements to the DSB on behalf of the Roman numeral 40, always attempting to invoke the argument of "unfoundedness and excessiveness." The DSB has already determined in an internal meeting that this argument is flawed. It is also officially known that the Data Protection Authority (DSBür/Roman 40) apparently has deficiencies/problems in the application of data protection regulations (DSG; GDPR), as its statements have not been followed in a single decision by the Data Protection Authority (DSB) concerning me, and reference may be made to the following decisions of the Data Protection Authority: - D124.2668 - D124.4169 - D124.5599 (Confirmed by the Federal Administrative Court) - D124.0123 - D124.0122 - D124.0853/23 - D124.1265/23 - D124.0242/24. The Data Protection Authority is hereby requested to: 1.) Determine the violation of the right to information pursuant to the application of March 8, 2024; 2.) Arrange for the transmission of the necessary information by the disciplinary authority, the Disciplinary Commander/Unit Commander (Obst Roman 40).

The data protection complaint filed by the BF on April 10, 2024 (1.1.8.) against Colonel XXXX, as Commander XXXX and Disciplinary Authority (fourth respondent), regarding a violation of the right to erasure, recorded under file number D124.0990/24, reads as follows:

Despite a clear request dated March 12, 2024, Colonel XXXX has neither deleted the incriminating photograph nor initiated its deletion at other agencies such as the XXXX authority, the Disciplinary Attorney/XXXX, or the legal representative XXXX, even though no valid reason exists. There is a legal basis for this. In my initial application of March 12, 2024 (see Appendix 1), I requested both the erasure and, alternatively, the restriction of the processing of my personal data (a photograph of myself with my telephone number). The Data Protection Office/XXXX informed me by letter dated April 2, 2024, that this request would not be granted because this photograph constitutes evidence in the 11th disciplinary complaint of August 28, 2023, and is included therein as Appendix 13. Consequently, Colonel XXXX, as the disciplinary authority, the disciplinary commander/disciplinary superior, processed this data lawfully on the basis of and in accordance with Section 11 Paragraph 2 of the Hessian Data Protection Act 2014 for the purposes stipulated therein. With this statement, the Data Protection Office/XXXX confirmed the data protection violation and also the violation of the right to erasure! In the 11th disciplinary complaint, the incriminating photo is indeed Appendix 13. However, upon careful reading of page 20 of the disciplinary complaint regarding incident 3/3, an objective reader will notice that the photo as Appendix 13 does NOT correspond to the text and that a different document should have been included as Appendix 13 (in other words: "incorrect appendix"). Page 20 is attached as Appendix 3, and only the essential differences are briefly highlighted here: "...Incident 3/3: On May 9, 2023, Lieutenant Colonel XXXX submitted a report to Command XXXX and also to the Staff Council (see Appendix 13)...[abbreviated]..." It is NOT lost on an objective observer that this is a written submission (email) sent to two departments, Command XXXX and the Staff Council. Therefore, this can never be a text message (the correct image is a photo of a message sent via the SIGNAL service from the mobile phone of Lieutenant Colonel XXXX). However, the incriminating document dated May 9, 2023, which constitutes the actual Appendix 13, is missing from the disciplinary complaint. Furthermore, it is NOT lost on an objective observer that a message dated May 9, 2023, is referenced here, and two bullet points from it have been reproduced. The photo is from a private communication dated April 20, 2023 (see photo under my "passport picture and name"). It is therefore NOT lost on an objective observer that the text in the written message (email) dated May 9, 2023, is NOT identical to that of the personal message (SIGNAL) from me to Lieutenant Colonel XXXX dated April 20, 2023. It is quite obvious that Colonel XXXX failed to comply with the clear provisions of Section 43 of the Federal Disciplinary Code (BDG) ("...Section 43.(1) The civil servant is obligated to perform his official duties faithfully, conscientiously, diligently, and impartially, using the means available to him and in accordance with the applicable legal order..."). Otherwise, Colonel XXXX would have noticed that he had added the WRONG ENCLOSURE. It is blatant, however, that Colonel XXXX did not point this error out to his superior at the Data Protection Officer's Office (DSBür/ XXXX XXXX), and that the latter accepted it unfiltered and without verification, communicating this to me as justification for my deletion request. This should have been obvious to a legally trained civil servant of the rank of Ministerial Councilor with the academic degree of Dr. iur., had he conscientiously reviewed the report from his subordinate, Colonel XXXX, and the disciplinary complaint. Since this "photo of a SIGNAL message to Lt. Col. XXXX" is not mentioned or referenced anywhere else in the disciplinary complaint, it is already clear that the cited Section 11 Paragraph 2 of the 2014 Disciplinary Code does not apply, and therefore the entire letter of April 2, 2024, is invalid. Therefore, the following request is made: 1.) The Data Protection Authority (DSB) should declare that my right to erasure has been violated by Lt. Col. XXXX in conjunction with the DSB's office/XXXX XXXX.2.) To arrange for the deletion of this photo from the telephone of Colonel XXXX, from the electronic file XXXX dated August 28, 2023 (Appendix 13 therein), from the recipients of this file, the XXXX authority, the disciplinary prosecutor/XXXX, and the attorney XXXX. 3.) Furthermore, to instruct Colonel XXXX in conjunction with the Data Protection Officer/XXXX to disclose to whomever else this photo has been sent and to carry out the deletion there as well, and to report this to the relevant authorities. Respectfully, XXXX (signed) ENVELOPES: Enclosure 1: Application for Deletion Enclosure 2: Response from the Data Protection Officer/XXXX Enclosure 3: Page 20 of the Disciplinary Report Enclosure 4: Enclosure 13 of the Disciplinary Report Despite a clear request dated March 12, 2024, the [Officer Name] (Reference Number 40) has neither deleted the incriminating photograph nor initiated its deletion at other agencies such as the [Officer Name] (Reference Number 40), the Disciplinary Attorney (Reference Number 40), nor at the legal representative (Reference Number 40), even though no sound legal basis exists. With my initial submission of March 12, 2024 (see Enclosure 1), I requested both the deletion and, alternatively, the restriction of the processing of the personal data concerning me (a photograph of myself with my telephone number). The Data Protection Office (DSBür/Rum 40) informed me by letter dated April 2, 2024, that this request would not be granted because this photograph constitutes evidence in the 11th disciplinary complaint dated August 28, 2023, and is listed there as Appendix 13. Consequently, the Higher Regional Court (ObstdG) (Rum 40), as the disciplinary authority, the disciplinary commander/disciplinary superior, processed this data lawfully on the basis of and in accordance with Section 11 Paragraph 2 of the Hessian Data Protection Act 2014 (HDG 2014) for the purposes stipulated therein. With this statement, the Data Protection Office (DSBür/Rum 40) confirmed the data protection violation and also the violation of the right to erasure! In the 11th disciplinary complaint, the incriminating photo is indeed Appendix 13. However, upon careful reading of page 20 of the disciplinary complaint regarding incident 3/3, an objective reader will notice that the photo listed as Appendix 13 does NOT correspond to the text and that a different document should have been included as Appendix 13 (in other words: "incorrectly placed attachment"). Page 20 is included as Appendix 3, and only the essential differences are briefly highlighted here: "...Incident 3/3: Lieutenant Colonel Roman 40 submitted a report on May 9, 2023, to Command Roman 40 and also to the Staff Council (see Appendix 13)...[abbreviated]..." It is NOT lost on an objective observer that this constitutes a written submission (email) to two departments: Command Roman 40 and the Staff Council. Therefore, this can never be a text message (correctly, a message from the mobile phone of Lieutenant Colonel Roman 40 was photographed using the SIGNAL service). However, the incriminating document from May 9, 2023, which constitutes the actual Appendix 13, is missing from the disciplinary complaint. Furthermore, it is NOT lost on an objective observer that a message from May 9, 2023, is referenced here, and two bullet points from it have been reproduced. The photo is from a private communication dated April 20, 2023 (see photo under my "passport photo and name"). It is therefore NOT lost on an objective observer that the text in the written message (email) from May 9, 2023, is NOT identical to that of the personal message (SIGNAL) from me to Lieutenant Colonel Roman 40 dated April 20, 2023. It is quite obvious that Colonel (Obersturmführer) 40 failed to comply with the clear provisions of Section 43 of the Federal Disciplinary Code (BDG) ("...Section 43.(1) The civil servant is obliged to perform his official duties faithfully, conscientiously, diligently, and impartially, using the means available to him and in accordance with the applicable legal order..."). Otherwise, Colonel (Obersturmführer) 40 would have noticed that he had added the WRONG ENCLOSURE. It is blatant, however, that Colonel (Obersturmführer) 40 did not point this error out to his superior at the Data Protection Office (DSBür/Römer 40), who then accepted it unfiltered and without verification, and communicated this to me as justification for my deletion request. This should have been obvious to a legally trained civil servant of the rank of Ministerial Councilor with the academic degree of Dr. iur., had he conscientiously reviewed the report from his subordinate, Colonel (Obersturmführer) 40, and the disciplinary complaint. Since this "photo of a SIGNAL message to Lieutenant Colonel Roman 40" is not mentioned or referenced anywhere else in the disciplinary complaint, it is already clear that the cited Section 11 Paragraph 2 of the 2014 Disciplinary Code (HDG 2014) does not apply, and thus the entire letter of April 2, 2024, is invalid. Therefore, the following request is made: 1.) The Data Protection Authority (DSB) should declare that my right to erasure has been violated by Lieutenant Colonel Roman 40 in conjunction with the DSB office. 2.) The deletion of this photo should be ordered from Lieutenant Colonel Roman 40's phone, from the electronic file (ELAK) dated August 28, 2023 (Appendix 13 therein), from the recipients of this file, the disciplinary authority (Roman 40), the disciplinary attorney (Roman 40), and the attorney (Roman 40). 3.) Furthermore, to instruct the Chief of the General Staff (Roman 40) in conjunction with the Data Protection Office (DSBür/Roman 40), to disclose to whomever else this photo has been sent, and to carry out the deletion there as well, and to report this to the relevant office. Respectfully, Roman 40 e.h. ENCLOSURES: Enclosure 1: Request for Deletion Enclosure 2: Response from the Data Protection Authority/Roman 40 Enclosure 3: Page 20 of the Disciplinary Report Enclosure 4: Enclosure 13 of the Disciplinary Report

The data protection complaint filed by the BF on June 9, 2024 (1.1.9.) against XXXX (sixth respondent) for a violation of the right to confidentiality, recorded under file number D124.1508/24, reads as follows:

Details of the Legal Violation

In the data protection complaint of May 21, 2024, at 10:33:31 PM, the private individual XXXX stated the following: I filed a data protection complaint with the Data Protection Authority (DSB) on May 21, 2024, at 10:33:31 PM (case no. D124.1382/24), alleging that, contrary to the clear provisions of Section 46 of the Federal Data Protection Act (BDG) in conjunction with Section 1 of the Data Protection Act (DSG), my personal data (home address) was unlawfully processed from official files as a private individual and thus also as a data controller within the meaning of Article 4(7) of the GDPR.

The private individual, identified as Roman numeral 40, filed the data protection complaint with the DSB on May 21, 2024, at 10:33:31 PM (case no. D124.1382/24), alleging that, contrary to the clear provisions of Section 46 of the Federal Data Protection Act (BDG) in conjunction with Section 1 of the Data Protection Act (DSG), my personal data (home address) was unlawfully processed from official files as a private individual and thus also as a data controller within the meaning of Article 4(7) of the GDPR. Facts

On May 21, 2024, at 10:33:31 PM, private individual XXXX submitted a data protection complaint to the Data Protection Authority (DPA) via electronic form. The DPA is handling this case under D124.1382/24. The fact that this data protection complaint was submitted as a private individual and not as an officer of XXXX or as the commander of a XXXX department is evident from the complaint itself, specifically the last sentence of the facts section: "This data protection complaint is being made by me as a private individual..." In this complaint, private individual XXXX provided my first name, last name, both academic degrees, and my private residential address, including postal code, city, street, house number, staircase, and apartment number (evidence: see complaint). The fact that providing a private residential address in conjunction with a name constitutes personal data is clear from data protection regulations and case law. XXXX is the commander of XXXX in his official capacity and was/is therefore both my superior officer according to the Federal Disciplinary Code (BDG) and my disciplinary authority, the disciplinary commander/disciplinary superior officer according to the Hessian Disciplinary Code (HDG). In these functions, he was authorized, in the official interest, to request and process my personal data. As a private individual, however, Mr. XXXX is also subject to the clear provisions of official secrecy according to Section 46 Paragraph 1 of the BDG. Section 46 Paragraph 1 of the BDG stipulates that the objects of the duty of confidentiality are only "facts" that have become known to the official "exclusively through his official duties." The Constitutional Court (VfGH) has interpreted the concept of "facts" broadly, insofar as it also includes, in its opinion, "files and parts of files," i.e., documents (see VfSlg7455/1974; see also VwGH 14.5.1964, JBL 1965, 331). As a further prerequisite for the duty of confidentiality, Section 46 Paragraph 1 of the Federal Disciplinary Code (BDG), identical to Article 20 Paragraph 3 of the Federal Constitutional Law (B-VG), stipulates that this duty is "necessary in the interest of maintaining public peace, order, and security, comprehensive public affairs, foreign relations, the economic interest of a public corporation, the preparation of a decision, or the overriding interest of the party." The interests mentioned here comprise, on the one hand, a group of exhaustively listed public interests, and on the other hand, the private interest of the "party." In the area of data protection, the “overriding interest of the party” is specified by a “legitimate interest” in the confidentiality of “personal data”, in particular with regard to respect for its private and family life (§1 DSG), cf. Perthold-Stoitzner, Die Auskunftspflicht der Verwaltungsorgane, 1988, 165; Wieser, Art. 20/3 B-VG, in Korinek/Houloubek (eds.), Federal Constitutional Law, para. 6. That the private individual XXXX unlawfully obtained my private residential address from official files of XXXX is evident from his data protection complaint as a private individual dated May 21, 2024, in the second paragraph from the bottom, regarding the facts of the case: "...The address of Mr. XXXX is publicly accessible data in the Central Register of Residents (ZMR) – this address is therefore not subject to any claim of confidentiality, see Section 1 para. 1 of the Data Protection Act (DSG); moreover, this address is known to the Data Protection Authority (DSB) due to the numerous data protection complaints filed by Mr. XXXX against XXXX or...""Known to the XXXX office and its personnel..." By specifically referring to the official files of XXXX and the XXXX office, the private individual has revealed their source. This private individual is NOT permitted to process this official data in their private capacity. The fact that the private individual XXXX also cites the excuse of "access to the Central Population Register" demonstrates their lack of understanding of the Central Population Register and how it functions. In addition to the name, further personal data must be provided; otherwise, NO result can be disclosed. The only additional characteristic that the private individual XXXX can cite is that I am an Austrian citizen. However, this data only yields the following registration information: "...Due to the information regarding identity, the person sought cannot be clearly identified; no information can be provided..." (Evidence: Registration office inquiry dated June 9, 2024; 6:19:18 PM, Enclosure). As proof that the private individual XXXX, contrary to the clear provisions of Section 46 of the Federal Data Protection Act (BDG) in conjunction with Section 1 of the Data Protection Act (DSG), has made use of his "official knowledge and (his) official files, including those of other agencies," he impressively reveals in the third paragraph from the bottom: "...It should also be noted that this submission is known to the Data Protection Authority (Exhibit 21 on the statement of XXXX regarding D124.0668/24 – File No. XXXX (2) dated May 10, 2024), as is the official status of Mr. XXXX (Data Protection Complaint of Mr. XXXX D124.0668/24 dated..." 29.02.2024), as well as the criminal proceedings pending against me, including the discontinuation by the public prosecutor's office and the application for continuation by Mr. XXXX (pp. 13 to 17 of the statement by XXXX on D124.0668/24 – file number XXXX (2) of 10.05.2024)…") Mr. XXXX is also not a member of the DSBür/ XXXX ! Since no written release from official secrecy pursuant to Section 46, paragraphs 3 and 4 of the Federal Data Protection Act (BDG) exists for private individual XXXX, a data protection breach must be assumed, and the Data Protection Authority should confirm this with respect to private individual XXXX and impose a fine, as this individual was acting in a private capacity and not as a civil servant or official. Private individual XXXX submitted a data protection complaint as a private individual to the Data Protection Authority (DSB) via electronic form on May 21, 2024, at 10:33:31 PM. The DSB is conducting this procedure under case number D124.1382/24. That this data protection complaint was filed as a private individual and not as an officer of Roman 40 or as the commander of a Roman 40 unit is evident from the complaint itself, specifically the last sentence in the statement of facts: "This data protection complaint is filed by me as a private individual..." In this complaint, Roman 40, as a private individual, provided my first name, last name, both academic degrees, and my private residential address, including postal code, city, street, house number, staircase, and apartment number (proof: see complaint). That naming a private residential address in relation to one's name constitutes personal data is clear from data protection regulations and case law. Roman 40 is, in his official capacity, the commander of Roman 40 and was/is therefore both my superior officer according to the Federal Data Protection Act (BDG) and my disciplinary authority, the disciplinary commander/disciplinary superior officer according to the Hessian Data Protection Act (HDG). In these capacities, he was authorized, in the official interest, to request and process my personal data. As a private individual, however, Mr. Roman 40 is also subject to the clear provisions of official secrecy pursuant to Section 46 Paragraph 1 of the Federal Disciplinary Code (BDG). Section 46 Paragraph 1 of the BDG stipulates that the objects of the duty of confidentiality are only "facts" that have become known to the official "exclusively through his official duties". The Constitutional Court (VfGH) has interpreted the concept of "facts" broadly, insofar as it also includes, in its opinion, "files and parts of files," i.e., documents (cf. VfSlg7455/1974; compare also VwGH 14.5.1964, JBL 1965,331). As a further prerequisite for the duty of confidentiality, Section 46 Paragraph 1 of the Federal Disciplinary Code (BDG), identical to Article 20 Paragraph 3 of the Federal Constitutional Law (B-VG), stipulates that this duty is "necessary in the interest of maintaining public peace, order, and security, in the comprehensive interest of foreign relations, in the economic interest of a public corporation, for the preparation of a decision, or in the overriding interest of the party." The interests mentioned here comprise, on the one hand, a group of exhaustively listed public interests, and on the other hand, the private interest of the "party." In the area of data protection, the “overriding interest of the party” is specified by a “legitimate interest” in the confidentiality of “personal data”, in particular with regard to respect for its private and family life (§1 DSG), compare Perthold-Stoitzner, Die Auskunftspflicht der Verwaltungsorgane, 1988, 165; Wieser, Article 20, paragraph 3, B-VG, in Korinek/Houloubek (eds.), Federal Constitutional Law, para. 6. That the private individual Roman 40 unlawfully obtained my private residential address from the official files of Roman 40 is evident from his data protection complaint as a private individual dated May 21, 2024, in the second paragraph from the bottom, regarding the facts of the case: "...The address of Mr. Roman 40 is publicly accessible data in the Central Register of Residents (ZMR) – this address is therefore not subject to any claim of confidentiality, see Section 1, paragraph 1, Data Protection Act (DSG); furthermore, this address is known to the Data Protection Authority (DSB) due to the numerous data protection complaints filed by Mr. Roman 40 against Roman 40 or the Roman 40 office and its bodies..." By specifically referring to the official files of Roman 40 and the Roman 40 office, the private individual has disclosed his source. The private individual is NOT permitted to process this official data in his capacity as a private individual. The fact that the individual in question, Roman numeral 40, also refers to the defense of "ZMR access" demonstrates their lack of knowledge about the Central Population Register and how it works. Besides the name, further personal data must be provided; otherwise, NO result can be given. The only additional characteristic that the individual in question can cite is that I am an Austrian citizen. However, this data only yields the following registration information: "...Due to the information regarding identity, the person sought cannot be clearly identified; no information can be provided..." (Evidence: Registration office inquiry dated June 9, 2024; 6:19:18 PM, Enclosure). As proof that the private individual, Roman 40, contrary to the clear provisions of Section 46 of the Federal Data Protection Act (BDG) in conjunction with Section 1 of the Data Protection Act (DSG), has made use of his "official knowledge and (his) official files, including those of other agencies," he impressively reveals in the third paragraph from the bottom: "...It should also be noted that this submission is known to the Data Protection Authority (Blg 21 to the statement of Roman 40 regarding D124.0668/24 – Ref. Roman 40 (2) dated May 10, 2024), as is the official status of Mr. Roman 40 (Data Protection Complaint of Mr. Roman 40 D124.0668/24)." from February 29, 2024), as well as the criminal proceedings pending against me, including the discontinuation by the public prosecutor's office and the application for continuation of proceedings by Mr. Roman 40 (Exhibits 13 to 17 of Mr. Roman 40's statement on D124.0668/24 – Ref. Roman 40 (2) of May 10, 2024)…”) Mr. Roman 40 is also not a member of the Data Protection Authority/Roman 40! Since there is also no written release from official secrecy pursuant to Section 46, paragraphs 3 and 4 of the Federal Data Protection Act (BDG) for Mr. Roman 40 as a private individual, a data protection breach must be assumed, and the Data Protection Authority should confirm this with respect to Mr. Roman 40 as a private individual and impose a fine, since he was acting in this case NOT as an official or public body, but as a private individual.

Mr. Roman 40 is also not a member of the Data Protection Authority/Roman 40! The data protection complaint filed by the BF on June 28, 2024 (1.1.10.) against XXXX (sixth respondent) for a violation of the right to confidentiality, recorded under file number D124.1626/24, reads as follows:

Information on the legal violation

In the data protection complaint filed on May 27, 2024, at 10:31:40 p.m. with the Data Protection Authority (case number D124.1475/24), the private individual XXXX, contrary to the clear provisions of Section 46 of the Federal Data Protection Act (BDG) in conjunction with Section 1 of the Data Protection Act (DSG), accessed official files as a private individual and Therefore, as a data controller within the meaning of Article 4(7), my personal data (home address) was processed unlawfully. The private individual, Roman numeral 40, filed a data protection complaint with the Data Protection Authority (DSB) on May 27, 2024, at 10:31:40 PM (case number D124.1475/24). Contrary to the clear provisions of Section 46 of the Federal Data Protection Act (BDG) in conjunction with Section 1 of the Data Protection Act (DSG), the private individual, acting as a data controller within the meaning of Article 4(7), unlawfully processed my personal data (home address) from official files.

Facts

The private individual XXXX filed a data protection complaint with the DSB on May 27, 2024, at 10:31:40 PM using an electronic form. The DSB is conducting this case under case number D124.1475/24. That this data protection complaint was filed as a private individual and not as an officer of XXXX or as the commander of a XXXX department is evident from the complaint itself, specifically the last sentence in the statement of facts: "...This data protection complaint is filed by me as a private individual..." In this complaint, the private individual XXXX provided my first name, last name, both academic degrees, and my private residential address, including postal code, city, street, house number, staircase, and apartment number (proof: see complaint). That naming a private residential address in relation to one's name constitutes personal data is clear from data protection regulations and case law. XXXX is the commander of XXXX in his official capacity and was/is therefore both my superior officer according to the Federal Data Protection Act (BDG) and my disciplinary authority, the disciplinary commander/disciplinary superior officer according to the Hessian Data Protection Act (HDG). In these capacities, he was authorized, in the official interest, to request and process my personal data.As a private individual, however, Mr. XXXX is also subject to the clear provisions of official secrecy pursuant to Section 46 Paragraph 1 of the Federal Disciplinary Code (BDG). Section 46 Paragraph 1 BDG stipulates that the objects of this duty of confidentiality are only "facts" that have come to the official's knowledge "exclusively through his official duties." The Constitutional Court (VfGH) has interpreted the term "facts" broadly, insofar as it also includes "files and parts of files," i.e., documents (see VfSlg7455/1974; see also VwGH 14.5.1964, JBL 1965,331). As a further prerequisite for the duty of confidentiality, Section 46 Paragraph 1 of the Federal Disciplinary Code (BDG) stipulates, identically to Article 20 Paragraph 3 of the Federal Constitutional Law (B-VG), that this duty is "necessary in the interest of maintaining public peace, order and security, comprehensive public affairs, foreign relations, in the economic interest of a public corporation, for the preparation of a decision, or in the overriding interest of the party." The interests mentioned here comprise, on the one hand, a group of exhaustively listed public interests, and on the other hand, the private interest of the "party." In the area of data protection, the "overriding interest of the party" is specified by a "legitimate interest" in the confidentiality of "personal data," in particular with regard to respect for its private and family life (Section 1 of the Data Protection Act (DSG)), cf. Perthold-Stoitzner, The Duty of Administrative Bodies to Provide Information, 1988, 165. Wieser, Art. 20/3 B-VG, in Korinek/Houloubek (eds.), Federal Constitutional Law, para. 6. That the private individual XXXX unlawfully obtained my private residential address from the official files of XXXX is evident from his data protection complaint as a private individual dated May 27, 2024, in the second paragraph from the bottom, regarding the facts of the case: "...The address of Mr. XXXX is publicly accessible data in the Central Register of Residents (ZMR) – this address is therefore not subject to any claim for confidentiality, see Section 1 para. 1 of the Data Protection Act (DSG); furthermore, this address is known to the Data Protection Authority (DSB) due to the numerous data protection complaints filed by Mr. XXXX against XXXX or the XXXX agency and its officers..." By specifically referring to the official files of XXXX and the XXXX agency, the private individual has disclosed his source. The private individual is NOT permitted to process this official data in his capacity as a private individual. The fact that private individual XXXX also refers to the defense of "access to the Central Population Register" demonstrates their lack of knowledge about the Central Population Register and how it works. In addition to the name, further personal data must be provided, otherwise NO result can be given. Private individual XXXX can only cite as an additional characteristic that I am an Austrian citizen. However, this data only yields the following registration information: "...Due to the information regarding identity, the person sought cannot be clearly identified; no information can be provided..." (Evidence: Registration office inquiry dated June 9, 2024; 6:19:18 PM, Enclosure). As proof that the private individual XXXX, contrary to the clear provisions of Section 46 of the Federal Data Protection Act (BDG) in conjunction with Section 1 of the Data Protection Act (DSG), has made use of his "official knowledge and (his) official files, including those of other agencies," he impressively reveals in the third paragraph from the bottom: "...It should also be noted that the GStk criticized by Mr. XXXX and the incident of attempted barracks access are known to the Data Protection Authority (Exhibit 18 to the statement of XXXX regarding D124.0668/24 – Ref. No. XXXX (2) dated May 10, 2024), as is the official status of Mr. XXXX (Data Protection Complaint of the Mr. XXXX (D124.0668/24 dated February 29, 2024)...“ Mr. XXXX hereby refers to a file from a superior authority to which he does NOT belong. Since there is also no written release from official secrecy pursuant to Section 46, Paragraphs 3 and 4 of the Federal Data Protection Act (BDG), a data protection breach must be assumed, and the Data Protection Authority should confirm this with respect to Mr. XXXX as a private individual and impose a fine, as he was acting in this case NOT as a civil servant or official, but as a private individual. Mr. XXXX, using the electronic form provided by the Data Protection Authority, filed a data protection complaint as a private individual with the Data Protection Authority on May 27, 2024, at 10:31:40 PM. The Data Protection Authority is conducting this procedure under case number D124.1475/24. That this data protection complaint was filed as a private individual and not as an officer of Roman 40 or as the commander of a Roman 40 unit is evident from the complaint itself, specifically the last sentence in the statement of facts: "...This data protection complaint is filed by me as a private individual..." In this complaint, Roman 40, as a private individual, provided my first name, last name, both academic degrees, and my private residential address, including postal code, city, street, house number, staircase, and apartment number (proof: see complaint). That naming a private residential address in relation to one's name constitutes personal data is clear from data protection regulations and case law. Roman 40 is, in his official capacity, the commander of Roman 40 and was/is therefore both my superior officer according to the Federal Data Protection Act (BDG) and my disciplinary authority, the disciplinary commander/disciplinary superior officer according to the Hessian Data Protection Act (HDG). In these capacities, he was authorized, in the official interest, to request and process my personal data. As a private individual, however, Mr. Roman 40 is also subject to the clear provisions of official secrecy pursuant to Section 46, Paragraph 1, of the Federal Disciplinary Code (BDG). Section 46, Paragraph 1, BDG stipulates that the objects of this duty of confidentiality are only "facts" that have come to the official's knowledge "exclusively through his official duties." The Constitutional Court (VfGH) has interpreted the term "facts" broadly, insofar as it also includes "files and parts of files," i.e., documents (see VfSlg 7455/1974; compare also VwGH 14.5.1964, JBL 1965, 331). As a further prerequisite for the duty of confidentiality, Section 46, Paragraph 1 of the Federal Disciplinary Code (BDG), identical to Article 20, Paragraph 3 of the Federal Constitutional Law (B-VG), stipulates that confidentiality is required "in the interest of maintaining public peace, order and security, the comprehensive protection of foreign relations, the economic interest of a public corporation, for the preparation of a decision, or in the overriding interest of the party." The interests mentioned here comprise, on the one hand, a group of exhaustively listed public interests, and on the other hand, the private interest of the "party." In the area of data protection, the "overriding interest of the party" is specified by a "legitimate interest" in the confidentiality of "personal data," in particular with regard to respect for their private and family life (Section 1 of the Data Protection Act (DSG)), cf. Perthold-Stoitzner, The Duty of Information of Administrative Bodies, 1988, 165. Wieser, Article 20, paragraph 3, B-VG, in Korinek/Houloubek (eds.), Federal Constitutional Law, para. 6. That the private individual Roman 40 unlawfully obtained my private residential address from the official files of Roman 40 is evident from his data protection complaint as a private individual dated May 27, 2024, in the second paragraph from the bottom, regarding the facts of the case: "...The address of Mr. Roman 40 is publicly accessible data in the Central Register of Residents (ZMR) – this address is therefore not subject to any claim of confidentiality, see Section 1, paragraph 1, Data Protection Act (DSG); furthermore, this address is known to the Data Protection Authority (DSB) due to the numerous data protection complaints filed by Mr. Roman 40 against Roman 40 or the Roman 40 office and its bodies..." By specifically referring to the official files of Roman 40 and the Roman 40 office, the private individual has disclosed his source. The private individual is NOT permitted to process this official data in his capacity as a private individual. The fact that the individual in question, Roman numeral 40, also refers to the defense of "ZMR access" demonstrates their lack of knowledge about the Central Population Register and how it works. In addition to the name, further personal data must be provided, otherwise NO result can be given. The only further characteristic that the individual in question can cite is that I am an Austrian citizen. However, this data only yields the following registration information: "...Due to the information regarding identity, the person sought cannot be clearly identified; no information can be provided..." (Evidence: Registration office inquiry dated June 9, 2024; 6:19:18 PM, Enclosure). As proof that the private individual, identified as Roman 40, contrary to the clear provisions of Section 46 of the Federal Data Protection Act (BDG) in conjunction with Section 1 of the Data Protection Act (DSG), has made use of his "official knowledge and (his) official files, including those of other agencies," he impressively reveals in the third paragraph from the bottom: "...It should also be noted that the GStk criticized by Mr. Roman 40 and the incident of attempted barracks access are known to the Data Protection Authority (Exhibit 18 to the statement of Roman 40 regarding D124.0668/24 – Ref. Roman 40 (2) dated May 10, 2024), as is the official status of Mr. Roman 40." 40 (Data protection complaint of Mr. Roman 40 D124.0668/24 dated February 29, 2024)...“ Mr. Roman 40 hereby refers to a file from a superior authority to which he does NOT belong. Since there is also no written release from official secrecy pursuant to Section 46, paragraphs 3 and 4 of the Federal Data Protection Act (BDG), a data protection violation must be assumed, and the data protection authority should confirm this with respect to Mr. Roman 40 as a private individual and impose a fine, as he was acting in this case NOT as a civil servant or official, but as a private individual.


Mr. Roman 40 hereby refers to a file from a superior authority to which he does NOT belong. The data protection complaint filed by the BF on July 8, 2024 (January 1, 2011) against XXXX (with the head of the Colonel XXXX) (second respondent) for violation of the right to confidentiality, recorded under file number D124.1684/24, reads as follows:

My private residential address was repeatedly requested by Colonel XXXX on behalf of XXXX, acting as an officer of XXXX, and disclosed to third parties (Lieutenant Colonel XXXX, Lieutenant Colonel XXXX, and Lieutenant Colonel XXXX) in the minutes XXXX No. 23. up to 31 disclosed, although this according toArticle 5 of the GDPR (the "Need-To-Know" principle) is/was NOT required because these logs were only physically handed to me, as well as to Lieutenant Colonel XXXX and Lieutenant Colonel XXXX, and Lieutenant Colonel XXXX, and were NOT delivered by mail. I notified XXXX in writing on July 24, 2028, that I do not consent to this inquiry and disclosure to third parties, that my consent is lacking, and that this also violates data protection regulations. This is also recorded again in the log dated August 1, 2023, as follows on page 2, penultimate paragraph: "...Lieutenant Colonel XXXX points out that the private address listed as the recipient of the logs does not comply with data protection regulations and repeatedly requests its deletion. - Response: the private address will continue to be listed until clarification by XXXX..." This matter is a continuation of the facts relating to D124.1838/23, and reference is made to the explanation therein. Since the Data Protection Authority (DSB) did not decide within the statutory time limit despite the complaint of inaction, this matter is now pending before the Federal Administrative Court (BVwG) under case number W605 2291721-1, and a decision on the merits is still pending. However, the complaint had to be filed now to avoid preclusion pursuant to Section 24 Paragraph 4 of the Data Protection Act (DSG) (first becoming aware of the complaint on August 18, 2023). Enclosed are the first pages of the protocols, on which my name and private residential address are listed. By order of the Roman 40th (with the commander Colonel General Roman 40th), my private residential address was repeatedly requested on his behalf by Colonel Roman 40th, as an officer of the Roman 40th, and disclosed to third parties (Lieutenant Colonel Roman 40th; Lieutenant Colonel Roman 40th; and Lieutenant Colonel Roman 40th) in protocols Roman 40th Nos. 23 to 31, even though this is/was NOT required according to Article 5 of the GDPR ("Need-To-Know Principle"), because these protocols were only physically handed to me, as well as Lieutenant Colonel Roman 40th and Lieutenant Colonel Roman 40th, and Lieutenant Colonel Roman 40th, and were NOT delivered by mail. I have not consented to this request and disclosure to third parties, that my consent is lacking, and that this also violates data protection regulations, by means of a written submission dated July 24, 2028, to the Roman 40th 40 reported. This is also recorded again in the minutes of August 1, 2023, as follows on page 2, penultimate paragraph: "...Lieutenant Colonel Roman 40 points out that the listed private address in the recipient's records does not comply with data protection regulations and repeatedly requests its deletion. - Response: the private address will continue to be listed until Roman 40 clarifies the matter..." This matter is a continuation of the case D124.1838/23, and reference is made to the explanation therein. However, since the Data Protection Authority (DSB) did NOT decide within the statutory time limit despite the complaint for failure to act, this matter is now pending before the Federal Administrative Court (BVwG) under case number W605 2291721-1, and a decision on the merits is still pending. The complaint had to be filed now, however, to avoid preclusion pursuant to Section 24 Paragraph 4 of the Data Protection Act (DSG) (first becoming aware of this on August 18, 2023). Enclosed are the first pages of the protocols, on which my name and private residential address are listed.

The data protection complaint of the BF dated July 31, 2024 (1.1.12.) against Colonel XXXX as the disciplinary authority, Disciplinary Commander/Superior (HDG) (Fourth Respondent) for violation of the right to erasure, recorded under file number D124.1818/24, reads as follows:

Colonel XXXX as the disciplinary authority Despite a clear request dated May 13, 2024 (Appendix 1), the disciplinary commander/superior disciplinary officer has neither deleted my personal data, which is older than 10 years according to Section 25 Paragraph 3 of the 2004 Office Regulations as amended, nor the personal data relating to Section 55a of the Military Service Act. By submitting a formal request on May 13, 2024, using the form provided by the Data Protection Authority (see Appendix 1), I requested the deletion of my personal data due to my automatic retirement from active duty (reserve duty) with XXXX pursuant to Section 10 Paragraph 1 of the 2001 Military Service Act, effective May 20, 2024 (reaching the age of 50), and explicitly referred to the legally binding decision of the Data Protection Authority regarding D124.0220/23. According to §45 para. 2 no. 1 DSG, the controller (in this case Mr. ObstdG XXXX as disciplinary authority disciplinary commander/disciplinary superior) must delete personal data immediately, either on his own initiative or upon request of the data subject. In particular, disciplinary notices No. 8 (XXXX (2), No. 9 (XXXX (2), No. 10 (XXXX (2), and No. 11 (XXXX (2)) with all collected data must be deleted. The Data Protection Officer/XXXX, acting as legal representative for Colonel XXXX, informed me by letter dated June 7, 2024, file number XXXX (1) (Enclosure 2), that the extension of the deadline pursuant to Section 42 Paragraph 4 of the Data Protection Act (DSG) or Article 12 Paragraph 3 of the General Data Protection Regulation (GDPR) for a period of two months is being invoked. By letter dated July 26, 2024, file number XXXX (3) (Enclosure 3), the Data Protection Officer/XXXX, representing Colonel XXXX, informed me as follows: "...On the basis of and in accordance with these provisions, the deletion of your personal data within the enforcement area of XXXX (including the disciplinary authorities subordinate to it under the Hessian Disciplinary Act (HDG)) is currently required." 2014) is not permissible. The fact that you are no longer XXXX is irrelevant in this regard…“ Colonel XXXX, represented by DSBür/ XXXX (Mr. MinR XXXX), is mistaken on three points here and thus clearly violates laws and the recent jurisprudence of the DSB. A) Limitation periods according to the Office Regulations On page 3 in the 1st paragraph, DSBür/ XXXX correctly states the following: “…Furthermore, throughout the entire area of responsibility of XXXX, the documentation of the proper execution (also) of the provisions of the Civil Service Law 1979 and the Army Disciplinary Law 2014 must be carried out in accordance with the provisions of the Federal Office Regulations issued on the basis of Section 12 BMG…” One would have expected a legally knowledgeable person like Mr. MinR XXXX, who explicitly refers to the Federal Office Regulations, to know and be able to apply them correctly. However, Mr. MinR XXXX obviously does not. Section 25 Paragraph 3 of the Office Regulations 2004 as amended was NOT correctly applied. Section 25 Paragraph 3 of the Office Regulations reads: "...(3) Unless the specific content of the file or legal provisions make a longer retention period appear appropriate, the end of the retention period shall be set at the end of the tenth calendar year after the last processing operation..." It is clear from this that all my personal data older than 10 years should have been deleted ex officio. Consequently, the response I received from the Data Protection Officer/ XXXX for Chief Superintendent XXXX, that NO personal data would be deleted, is UNLAWFUL and violates my right to erasure. B) Deletion of Disciplinary Notices Nos. 8-11. According to Section 280 Paragraph 2 of the Federal Data Protection Act (BDG), processing, transmission, or further processing pursuant to paragraph one is only permissible for the purpose of maintaining or functioning the administration of the public service (Z1), for the purpose of fulfilling legal obligations, or for asserting rights arising from the Regulations relating to service law, labor and social law, budgetary law, salary law, pension law, organizational law, training law, or other regulations directly related to the legal relationship (Z2), or for the purpose of exercising the public authority conferred in the regulations pursuant to Z2 (Z3). However, this is NOT the case here, as my service relationship was terminated by a declaratory decision issued by the service authority, Directorate 1 - Deployment, on January 24, 2024, file number XXXX (1). Consequently, the Military Service Act must be examined: Section 55a of the Military Service Act states: "...1) The XXXX and other authorities entrusted with the execution of this Federal Act may process personal data of XXXX and other persons who are eligible for XXXX, as well as of other persons whose data are required in the context of an administrative procedure under this Federal Act, for the performance of the tasks assigned to them under this Federal Act..." Art. Article 9a, paragraph 3 of the Austrian Federal Constitution (B-VG) establishes the general [legal status] for male citizens. In conjunction with Section 10, paragraph 1 of the Austrian Military Service Act 2001 (WG 2001), the [legal status] applies to male citizens who have reached the age of 17 but not yet the age of 50. According to Section 11, paragraph 1 of the WG 2001, the [legal status] includes the [legal status] for performing military service, the duties of [legal status], and the reporting and authorization requirements according to paragraphs 4 to 6. As an interim conclusion, it must therefore be stated that I am no longer [legal status], as I turned 50 on [date]. Consequently, there is no legal justification for storing the data, and the personal data must be deleted! C) Applicability of the decision of the Austrian Data Protection Authority (DSB) D124.0220/23. It is a fact that the legally binding decision of the DSB regarding D124.0220/23 implies that further storage is not permitted. The continued storage of data after leaving XXXX is neither appropriate nor permissible. This is stated verbatim on page 14 before the instructions on legal remedies: "...Therefore, for this reason as well, the continued storage of the appellant's data collected during the recruitment process UNTIL LEAVING from XXXX is appropriate and permissible, and the appellant's appeal was therefore to be dismissed..." That this also aligns with XXXX's legal opinion is evident from the fact that XXXX, as the respondent, did not file an appeal against the decision.Therefore, the following request is made: 1.) The Data Protection Authority (DSB) should declare that my right to erasure has been violated by Colonel XXXX, as the disciplinary authority and disciplinary commander/superior, because a) the 10-year retention period stipulated in Section 25 Paragraph 3 of the Office Regulations 2004 as amended, has not been observed, and b) according to Section 55a of the Military Service Act, further storage of my personal data is NEITHER appropriate NOR permissible. 2.) To initiate the erasure of my personal data as requested. Respectfully, XXXX (signed) ENCLOSURES: Enclosure 1: Application for Deletion Enclosure 2: Extension of Time Limit Enclosure 3: NOT Deletion Notification ObstdG Roman 40 as Disciplinary Authority Disciplinary Commander/Disciplinary Superior has, despite a clear request dated 13.05.2024 (Enclosure 1), neither deleted my personal data which, according to §25 Paragraph 3, Office Regulations 2004 as amended, is older than 10 years, nor the personal data relating to §55a WG. By submitting my application on May 13, 2024, using the form provided by the Data Protection Authority (see Appendix 1), I requested the deletion of my personal data due to my automatic retirement from active duty (reserve duty) with the 40th Infantry Regiment (Roman 40) pursuant to Section 10, Paragraph 1, of the 2001 Military Service Regulations (WG 2001) effective May 20, 2024 (reaching the age of 50). I explicitly referred to the legally binding decision of the Data Protection Authority regarding D124.0220/23. Pursuant to Section 45, Paragraph 2, Number 1, of the Data Protection Act (DSG), the data controller (in this case, Colonel (Roman 40), acting as the disciplinary authority, disciplinary commander/superior) is obligated to delete personal data immediately, either on their own initiative or upon application by the data subject. In particular, disciplinary notices No. 8 (Roman 40(2)), No. 9 (Roman 40(2)), No. 10 (Roman 40(2)), and No. 11 (Roman 40(2)) with all collected data must be deleted. The Data Protection Officer (DSBür/Roman 40), acting as legal representative for the Senior Officer (ObstdG) (Roman 40), informed me by letter dated June 7, 2024, file number (Roman 40(1)) (Enclosure 2), that the extension of the deadline pursuant to Section 42, Paragraph 4, of the Data Protection Act (DSG) or Article 12, Paragraph 3, of the General Data Protection Regulation (GDPR) for a period of two months is being invoked. By letter dated July 26, 2024, file number (Roman 40(3)) (Enclosure 3), the Data Protection Officer (DSBür/Roman 40), acting for the Senior Officer (ObstdG) (Roman 40), informed me as follows: "...On the basis of and in accordance with these provisions, the deletion of your personal data within the enforcement area of the [relevant authority] is currently not possible." Roman 40 (including the subordinate disciplinary authorities according to the HDG 2014) is not permissible. The fact that you are no longer Roman 40 is irrelevant in this regard…“ OberstdG Roman 40, represented by DSBür/ Roman 40 (Mr. MinR Roman 40), is mistaken on three points here and thus clearly violates laws and the recent jurisprudence of the DSB. A) Limitation periods according to the Office Regulations On page 3 in the 1st paragraph, DSBür/ Roman 40 correctly states the following: “…Furthermore, throughout the entire area of operation of Roman 40, the documentation of the proper execution (also) of the provisions of the Civil Service Law 1979 and the Army Disciplinary Law 2014 must be carried out in accordance with the provisions of the Federal Office Regulations issued on the basis of Section 12, BMG…” Especially from a legally knowledgeable person like Mr. MinR Roman 40, It could have been expected that, given his explicit reference to the Federal Office Regulations, he would be familiar with them and able to apply them correctly. However, Mr. MinR (Ministerial Councillor Roman 40) clearly did NOT correctly apply Section 25, Paragraph 3 of the 2004 Office Regulations as amended. Section 25, Paragraph 3 of the Office Regulations reads: "...(3) Unless the specific content of the file or legal provisions warrant longer retention, the retention period shall end at the end of the tenth calendar year following the last processing operation..." It is therefore clear that all my personal data older than 10 years should have been deleted ex officio. Consequently, the response I received from the Data Protection Officer (DSBürger/Roman 40) for the Senior Civil Servant (ObersdG Roman 40), stating that NO personal data would be deleted, is UNLAWFUL and violates my right to erasure. B) Deletion of Disciplinary Notices Nos. 8-11. According to Section 280, Paragraph 2 of the Federal Data Protection Act (BDG), processing, transmission, or further processing pursuant to Paragraph 1 is only permitted if... Permissible for the purpose of maintaining or functioning the administration of the public service (Z1), for the purpose of fulfilling legal obligations or asserting rights arising from regulations relating to service law, labor and social law, budgetary law, salary law, pension law, organizational law, training law, or other regulations directly related to the legal relationship (Z2), or for the purpose of exercising the public authority conferred upon them in the regulations pursuant to point 2 (Z3). However, this is NOT the case here, as my employment relationship was terminated by a declaratory decision issued by the service authority, Directorate 1 - Deployment, on January 24, 2024, file number Roman 40 (1). Consequently, the Military Service Act must be examined: Section 55a, Military Service Act "...1) The Roman 40 and the other authorities entrusted with the execution of this Federal Act may, in order to exercise the public authority conferred upon them under this Federal Act Tasks include processing personal data of individuals subject to Roman 40 and other persons who are eligible for Roman 40, as well as other persons whose data is required in the context of administrative proceedings under this Federal Act…“ Article 9a, paragraph 3, B-VG (Federal Constitutional Law) establishes the general Roman 40 for male citizens. In conjunction with Section 10, paragraph one, WG 2001 (Military Service Act 2001), Roman 40 applies to male citizens who have reached the age of 17 but not yet the age of 50. According to Section 11, paragraph one, WG 2001, Roman 40 encompasses the obligation to perform military service, the duties of Roman 40, and the reporting and authorization requirements according to paragraphs 4 to 6. As an interim conclusion, it must therefore be stated that I am no longer subject to Roman 40, as I turned 50 on Roman 40. Consequently, there is no legal basis for storing the personal data, and the data… to be deleted! C) Applicability of the DSB's decision D124.0220/23 The fact is that the legally binding decision of the DSB regarding D124.0220/23 implies that the continued storage of data after leaving the Roman 40 is neither appropriate nor permissible. This is stated verbatim on page 14 before the instructions on legal remedies: "...Therefore, for this reason as well, the continued storage of the complainant's data collected during the recruitment process UNTIL LEAVING from the Roman 40 is appropriate and permissible, and the complainant's appeal was therefore to be dismissed..." That this also coincides with the legal opinion of the Roman 40 is evident from the fact that the Roman 40, as the respondent, did not file an appeal against the decision. Therefore, the following request is made: 1.) The Data Protection Authority (DSB) should declare that my right to erasure has been violated by the Disciplinary Authority (Colonel's Law, Roman numeral 40) as Disciplinary Commander/Disciplinary Superior, because a) the 10-year retention period pursuant to Section 25 Paragraph 3 of the Office Regulations 20004 as amended has not been observed, and b) pursuant to Section 55a of the Military Service Act, further storage of my personal data is NEITHER appropriate NOR permissible. 2.) To initiate the erasure of my personal data as requested. Respectfully, Roman numeral 40 e.h. ENCLOSURES: Enclosure 1: Request for Deletion Enclosure 2: Extension of Time Limit Enclosure 3: Notification of Non-Deletion

The data protection complaint filed by the BF on August 19, 2024 (1.1.13.) against the Data Protection Office of XXXX (seventh respondent) for violation of the right to erasure, recorded under file number D124.1921/24, reads as follows:

Facts

Despite a clear request dated May 13, 2024 (Enclosure 1), the Data Protection Office of XXXX (Mr. Ministerial Councillor XXXX) has NOT deleted any of my data since The personal data collected and processed in 1992, which, according to Section 25 Paragraph 3 of the 2004 Office Regulations as amended, is older than 10 years, nor the personal data relating to Section 55a of the WG, have been deleted, even though the Data Protection Authority (DSB/ XXXX) acknowledged and informed me of this obligation in its reply. With my application for the initiation of proceedings dated May 13, 2024, using the DSB form (see Appendix 1), I requested the deletion of my personal data due to my automatic retirement from active duty (reserve status) at XXXX pursuant to Section 10 Paragraph 1 of the 2001 WG on May 20, 2024 (reaching the age of 50), and explicitly referred to the legally binding decision of the DSB regarding D124.0220/23. According to Section 45 Paragraph 2 Item 1 of the Data Protection Act (DSG), the controller (in this case, Mr. MinR XXXX for the Data Protection Office/XXXX) is obligated to delete personal data immediately, either on their own initiative or upon request of the data subject. The Data Protection Office/XXXX informed me by letter dated June 7, 2024, Ref. No. XXXX (1) (Enclosure 2), that the extension of the retention period pursuant to Section 42 Paragraph 4 of the Data Protection Act (DSG) and Article 12 Paragraph 3 of the General Data Protection Regulation (GDPR) for a period of two months is being invoked. By letter dated July 26, 2024, Ref. No. XXXX (3) (Enclosure 3), the Data Protection Office/XXXX informed me as follows: "...Based on and in accordance with these provisions, the deletion of your personal data within the enforcement area of XXXX (including the disciplinary authorities subordinate to it under the Hessian Data Protection Act 2014) is not currently permitted."The fact that you are no longer XXXX is irrelevant in this regard…“ DSBür/ XXXX (Mr. MinR XXXX) is mistaken on several points here and thus clearly violates laws and the recent jurisprudence of the DSB. Chronology: From 1992 to October 1995, personal data concerning me was collected and processed by XXXX in accordance with the Military Service Act. This included my periods of XXXX, compulsory military service, and my time as a temporary-service soldier. From October 1995 to January 2024, further personal data was collected and processed, as I was a civil servant of XXXX during this period. Due to the termination of my civil service employment in January 2024, my personal data was again collected and processed in accordance with the Military Service Act until my 50th birthday. DSBür/ XXXX (Mr. MinR XXXX) states correctly on page 3 in the first paragraph as follows, but then unlawfully fails to implement this: “…The provisions of Section 280a, paragraphs 2 and 3 of the Federal Disciplinary Code of 1979 (BDG 1979) and Section 8 of the Hessian Disciplinary Code of 2014 (HDG 2014) therefore apply to the deletion of the data in question. Furthermore, throughout the entire enforcement area of XXXX, the documentation of the proper enforcement (also) of the provisions of the Civil Service Law of 1979 and the Army Disciplinary Law of 2014 must be carried out in accordance with the provisions of the Federal Office Regulations issued on the basis of Section 12 of the Federal Registration Act (BMG). This also includes the documentation of the transmission of disciplinary complaints and evidence to the bodies specified in Section 68, paragraph 1 of the HDG 2014. The retention of personal data processed on the basis of Section 280 of the BDG 1979 or Section 11, paragraph 2 of the HDG 2014 within the enforcement area of XXXX must therefore be provided for in accordance with Sections 25 and 26 of the Office Regulations, insofar as Section 280a BDG 1979 and § 8 HDG 2014 do not result in longer retention periods...“ A) Limitation period according to §280 a BDG According to this provision, personal data must be retained for 15 years, consequently all data which is older than 15 years (i.e. was collected or processed before 2009) must be deleted. "...(2) Organization-related, training-related, and other personal data and special categories of personal data of data subjects directly related to the legal relationship must be retained by a controller for fifteen years from the date of the last processing, transmission, or further processing. If the personal data and special categories of personal data are required beyond this period for processing, transmission, or further processing pursuant to Section 280, they must be retained for at least fifteen years after this requirement ceases to exist. If, after the last processing, transmission, or further processing, proceedings related to the respective data are initiated or have been initiated, these personal data and special categories of personal data must be retained for at least fifteen years after the final decision concluding the proceedings becomes legally binding..." Based precisely on these provisions of Section 280a of the Federal Data Protection Act (BDG), correctly reproduced by the Data Protection Officer (DSBür/ XXXX), the Data Protection Officer (DSBür/ XXXX) (Mr. Ministerial Councillor XXXX) should have deleted all of my personal data from 1992 to 2009 and informed me of this. This fact already establishes the unlawful (see cited legal norm) and culpable (recognizance and communication of the legal norm) conduct of the Data Protection Officer/XXXX (Mr. Ministerial Councillor XXXX), and this infringes upon my right to erasure. B) Statute of limitations pursuant to Section 8 of the Hessian Disciplinary Code (HDG): The record of conduct must be destroyed after one or three years pursuant to Section 8, Paragraph 2 of the HDG. Paragraph 3 states the following regarding the files: "...(3) After the discontinuation or legally binding conclusion of disciplinary proceedings, the files relating to these proceedings must be kept under seal..." Since no further time limits are specified in this provision, reference must be made to the statute of limitations of 10 years pursuant to the office regulations (see point C). C) Limitation Periods according to the Office Regulations On page 3, in the first paragraph, DSBür/ XXXX correctly states the following: "...Furthermore, throughout the entire area of responsibility of XXXX, the documentation of the proper execution of (also) the provisions of the Civil Service Law 1979 and the Military Disciplinary Law 2014 must be carried out in accordance with the provisions of the Federal Office Regulations issued on the basis of Section 12 of the Federal Ministry of Defence..." One would have expected a legally qualified person like Mr. Ministerial Councillor XXXX, given his explicit reference to the Federal Office Regulations, to be familiar with them and able to apply them correctly. However, Mr. Ministerial Councillor XXXX has clearly NOT correctly applied Section 25 Paragraph 3 of the 2004 Office Regulations as amended. Section 25 Paragraph 3 of the Office Regulations states: "...(3) Unless the specific content of the file or legal provisions make a longer retention period appropriate, the end of the retention period shall be set at the end of the tenth calendar year after the last processing operation..." It is clear from this that all my personal data older than 10 years should have been deleted ex officio. Consequently, the response I received from the Data Protection Authority (DSB) of XXXX, stating that NO personal data would be deleted, is UNLAWFUL and violates my right to erasure. D) Applicability of the DSB's Decision D124.0220/23. The fact is that the legally binding DSB decision D124.0220/23 establishes that the continued storage of data after leaving XXXX is NOT appropriate and NOT permissible. The following text appears verbatim on page 14, before the instructions on legal remedies: "...Therefore, for this reason as well, the continued storage of the complainant's data collected during the recruitment process until his departure from XXXX is appropriate and permissible, and the complainant's appeal was therefore to be dismissed..." That this also aligns with XXXX's legal opinion is evident from the fact that XXXX, as the respondent, did not file an appeal against the decision. Therefore, the following request is made: 1.) The Data Protection Authority (DSB) should declare that my right to erasure has been violated by the DSB/ XXXX (Mr. Ministerial Councillor XXXX) because a) the 10-year retention period pursuant to Section 25 Paragraph 3 of the Office Regulations 2004 as amended has not been observed, and b) pursuant to Section 55a of the Military Service Act, further storage of my personal data is NEITHER appropriate NOR permissible. 2.) To initiate the erasure of my personal data as requested. Respectfully, XXXX e.h. ENVELOPES: Enclosure 1: Application for Deletion Enclosure 2: Extension of Time Limit Enclosure 3: NOTification of NOT deleting The Data Protection Officer (DPO/ Roman numeral 40) (Mr. Ministerial Councillor Roman numeral 40) has, despite a clear request dated May 13, 2024 (Enclosure 1), NONE of my personal data collected and processed since 1992, which, according to Section 25 Paragraph 3 of the Office Regulations 2004 as amended, are older than 10 years, nor the personal data relating to Section 55a of the Data Protection Act, even though the DPO/ Roman numeral 40 acknowledged this obligation and informed me of it in their reply. By submitting my application on May 13, 2024, using the form provided by the Data Protection Authority (see Appendix 1), I requested the deletion of my personal data due to my automatic retirement from active duty (reserve duty) as a member of staff (Roman 40) pursuant to Section 10, Paragraph 1, of the 2001 Civil Service Act (WG 2001) effective May 20, 2024 (reaching the age of 50), and explicitly referred to the legally binding decision of the Data Protection Authority regarding D124.0220/23. Pursuant to Section 45, Paragraph 2, Number 1, of the Data Protection Act (DSG), the data controller (in this case, Mr. Ministerial Councillor Roman 40 for the Data Protection Authority office/Roman 40) is obligated to delete personal data without undue delay, either on their own initiative or upon request of the data subject. The Data Protection Authority (DSBür/ Roman 40) informed me by letter dated 07.06.2024, reference number Roman 40 (1) (Annex 2), that the extension of the deadline pursuant to Section 42, Paragraph 4, DSG or Article 12, Paragraph 3, GDPR for a period of 2 months is being claimed. In a letter dated July 26, 2024, file number Roman 40 (3) (Appendix 3), the Data Protection Authority (DSBür/Römer 40) informed me as follows: "...Based on and in accordance with these provisions, the deletion of your personal data within the jurisdiction of Roman 40 (including the subordinate disciplinary authorities under the Hessian Disciplinary Code 2014) is not permitted at this time. The fact that you are no longer a member of Roman 40 is irrelevant in this regard..." The Data Protection Authority (DSBür/Römer 40) (Mr. Ministerial Councillor Roman 40) is mistaken on several points and thus clearly violates laws and the recent jurisprudence of the Data Protection Authority. Chronology: From 1992 to October 1995, my personal data within the meaning of the Military Service Act was recorded and processed by Roman 40. This included my time with Roman 40, my compulsory military service, and my time as a temporary-service soldier. From October 1995 to January 2024, further personal data was collected and processed because I was a civil servant in the Roman 40 during this period. Due to the termination of my civil service relationship in January 2024, my personal data was again collected and processed in accordance with the Military Service Act until my 50th birthday. The DSBür/ Roman 40 (Mr. MinR Roman 40) states correctly on page 3 in the first paragraph as follows, but then unlawfully fails to implement it: “…The provisions of Section 280a, paragraphs 2 and 3, of the Federal Civil Service Act 1979 and Section 8, of the Higher Education Disciplinary Act 2014, therefore apply to the deletion of the data in question. Furthermore, throughout the entire area of responsibility of Roman 40, the documentation of the proper execution of the provisions of the Federal Civil Service Act 1979 and the Army Disciplinary Act 2014 must be carried out in accordance with the provisions of the Federal Office Regulations issued on the basis of Section 12, Federal Registration Act.”This also includes the documentation of the transmission of disciplinary notices and evidence to the bodies specified in Section 68, Paragraph 1, HDG 2014. The retention of personal data processed on the basis of Section 280, BDG 1979, or Section 11, Paragraph 2, HDG 2014, within the scope of enforcement of Article 40, is therefore to be provided for in accordance with Sections 25 and 26 of the Office Regulations, unless longer retention periods result from Section 280a, BDG 1979, and Section 8, HDG 2014...“ A) Limitation period pursuant to Section 280a BDG According to this provision, personal data must be retained for 15 years; consequently, all data older than 15 years (i.e., collected or processed before 2009) must be deleted. “...(2) Organization-related, training-related, and other personal data directly related to the legal relationship, and special categories of personal data of data subjects, must be retained by a controller for fifteen years from the last processing, transmission, or further processing. If the personal data are If data and special categories of personal data are required for processing, transmission, or further processing in accordance with Section 280, they must be retained for at least fifteen years after this requirement ceases to exist. If, after the last processing, transmission, or further processing, proceedings related to the respective data are initiated or have been initiated, these personal data and special categories of personal data must be retained for at least fifteen years after the final decision concluding the proceedings becomes legally binding... Based precisely on these provisions of Section 280a of the Federal Data Protection Act (BDG), correctly reproduced by DSBür/ (Mr. MinR, Roman 40), DSBür/ should have deleted all of my personal data from 1992 to 2009 and informed me of this. This fact already establishes the unlawful (see cited legal norm) and culpable (recognizance and communication of the legal norm) conduct of the Data Protection Officer (Mr. MinR, Roman 40) and infringes my right to erasure. B) Statute of limitations pursuant to Section 8 of the Hessian Disciplinary Code (HDG): The record of conduct must be destroyed after one or three years pursuant to Section 8, Paragraph 2, HDG. Paragraph 3 states the following regarding the files: "...(3) After the discontinuation or legally binding conclusion of disciplinary proceedings, the files relating to these proceedings must be kept under seal..." Since no further time limits are specified in this provision, reference must be made to the statute of limitations of 10 years pursuant to the office regulations (see point C). C) Limitation Periods according to the Office Regulations On page 3, paragraph 1, DSBür/ (Roman 40) correctly states the following: "...Furthermore, throughout the entire area of responsibility of (Roman 40), the documentation of the proper execution of the provisions of the Civil Service Law 1979 and the Military Disciplinary Law 2014 must be carried out in accordance with the provisions of the Federal Office Regulations issued on the basis of Section 12, BMG..." One would have expected a legally qualified person like Mr. MinR (Roman 40), given his explicit reference to the Federal Office Regulations, to be familiar with and able to apply them correctly. However, Mr. MinR (Roman 40) has clearly NOT correctly applied Section 25, Paragraph 3 of the 2004 Office Regulations as amended. Section 25, paragraph 3 of the Office Regulations states: "...(3) Unless the specific content of the file or legal provisions make a longer retention period appropriate, the end of the retention period shall be set at the end of the tenth calendar year after the last processing operation..." It is clear from this that all my personal data older than 10 years should have been deleted ex officio. Consequently, the response I received from the Data Protection Authority (DSB/Rome 40) that NO personal data would be deleted is UNLAWFUL and violates my right to erasure. D) Applicability of the DSB's decision D124.0220/23. The fact is that the legally binding DSB decision D124.0220/23 establishes that the continued storage of data after leaving the office (Rome 40) is NOT appropriate and NOT permissible. The following text appears verbatim on page 14, before the instructions on legal remedies: "...Therefore, for this reason as well, the continued storage of the complainant's data collected during the recruitment process until his departure from the Roman 40 is appropriate and permissible, and the complainant's appeal was therefore to be dismissed..." That this also aligns with the legal opinion of the Roman 40 is evident from the fact that the Roman 40, as the respondent, has not filed an appeal against the decision. Therefore, the following request is made: 1.) The Data Protection Authority (DSB) should declare that my right to erasure has been violated by the DSB/Roman 40 (Mr. Ministerial Councillor Roman 40) because a) neither the 10-year period stipulated in Section 25 Paragraph 3 of the Office Regulations 20004 as amended has been observed, and b) pursuant to Section 55a of the Military Service Act, further storage of my personal data is NEITHER appropriate NOR permissible. 2.) To initiate the deletion of my personal data as requested. Respectfully, Roman numeral 40 e.h. ENCLOSURES: Enclosure 1: Request for Deletion Enclosure 2: Extension of Time Limit Enclosure 3: NOTIFICATION OF NOT TO Delete

The data protection complaint of the BF dated August 22, 2024 (1.1.14.) against XXXX (with the head of the Colonel XXXX) (second respondent) for violation of the right to confidentiality, recorded under file number D124.1978/24, reads as follows: The data protection complaint of the BF dated August 22, 2024 (1.1.14.) against Roman 40 (with the head of the Colonel Roman 40) (second respondent) for violation of the right to confidentiality, recorded under file number D124.1978/24, reads as follows:

Details of the legal violation

Colonel XXXX, as commander of XXXX and disciplinary authority, is the disciplinary commander/disciplinary superior. Contrary to the clear provisions of Section 1 of the Data Protection Act (DSG) in conjunction with Section 34 of the Hessian Disciplinary Act (HDG), the right to confidentiality was violated by mentioning on August 21, 2024, while on duty in the office of Lieutenant Colonel XXXX at XXXX Barracks, that further disciplinary proceedings were pending against me at the XXXX authority. Lieutenant Colonel XXXX, as commander of the 40th Barracks and disciplinary authority, violated the right to confidentiality by mentioning on August 21, 2024, while on duty in the office of Lieutenant Colonel XXXX at XXXX Barracks, that further disciplinary proceedings were pending against me at the 40th authority.














] Facts

By decision of the XXXX authority dated October 27, 2022, file number 2022-0.698.712 (1), disciplinary proceedings were initiated against me regarding the disciplinary allegations in the 8th disciplinary complaint, file number XXXX (2), dated July 13, 2022 (see also BVwG W136 2264651-1/2E dated February 9, 2023). Furthermore, the 9th disciplinary complaint XXXX (2) dated November 3, 2022, the 10th disciplinary complaint XXXX (2) dated April 24, 2023, and the 11th disciplinary complaint XXXX (2) dated August 28, 2023, are also evident and were pending before the XXXX. These disciplinary charges were filed by the then-competent disciplinary authority, Disciplinary Commander/Disciplinary Superior Colonel XXXX. By decision of the Federal Administrative Court (BVwG) of January 12, 2024 (Case No. W208 2255608-2/45E), I was given the disciplinary penalty of dismissal, and the aforementioned proceedings were to be discontinued by operation of law. However, on October 21, 2024, Colonel XXXX informed the rank-and-file employee (i.e., not a disciplinary authority or staff representative) Lieutenant Colonel XXXX of precisely these disciplinary proceedings, thereby contradicting the provisions of Section 1 of the Data Protection Act (DSG) in conjunction with Section 34 of the Hessian Disciplinary Act (HDG). Section 34 HDG reads: "...Disclosures to the public § 34. (1) Disclosures to the public regarding the content of disciplinary measures and disciplinary proceedings are prohibited, unless otherwise provided by this Federal Act…." Lieutenant Colonel XXXX informed me of this in a telephone call via Signal on August 22, 2024, at approximately 8:37 a.m., and subsequently confirmed this in writing. He also gave me his written consent to testify to this under oath before the Data Protection Authority (DSB) or the Federal Administrative Court (BVwG). Transcript of the written Signal communication between Lieutenant Colonel XXXX and myself: XXXX August 22, 2024; 10:07 AM: "...Hi XXXX, did I understand you correctly in our phone call that XXXX spoke again yesterday (August 21st) about the disciplinary proceedings still pending against me, in case I return to the station?..." XXXX: "...No, he said that your case will be reopened at the Federal Administrative Court regarding the points that weren't addressed..." XXXX: "...Okay, so he's clearly referring to the disciplinary proceedings! Would you also testify to this before the Data Protection Authority and the Federal Administrative Court if necessary?" XXXX: "...Yes, of course!..." XXXX: "...Thank you!..." XXXX: "...It's the truth!..." General information on compliance with data protection at XXXX: It is obvious, however, that the data protection regulations are very frequently NOT being observed by XXXX under the command of Colonel XXXX. I do not wish to conceal the fact that I always first pointed out all of XXXX's errors to XXXX and also to their legal representative, the Data Protection Authority (DSB/XXXX). Only after they failed to recognize their clear errors and deficiencies and were unwilling to rectify them, did I file a complaint with the Data Protection Authority (DSB). The Data Protection Authority (DPA) is aware that the following legally binding decisions of the DPA with favorable outcomes for me exist, which affect my rights: - D124.2668 - D124.4169 - D124.5599, confirmed by the Federal Administrative Court (BVwG) - D124.0123 (Confirmed by preliminary ruling D062.1205) - D124.0122 Decisions of the DPA in my case with favorable outcomes for me, but not yet legally binding due to appeals by the DPA/ XXXX: - D124.0853/23 - D124.1265/23 - D124.1377/23 - D124.0242/24 H.o.The decision does not include a list of the individual (multiple) facts with the number of disclosures to uninvolved third parties. That the data protection regulations at XXXX, specifically at XXXX, are hardly being observed is evident from the aforementioned decisions in which violations of my rights were established. By decision of the authority under Roman 40 dated October 27, 2022, file number 2022-0.698.712 (1), disciplinary proceedings were initiated against me regarding the disciplinary allegations in the 8th disciplinary complaint under Roman 40 (2) dated July 13, 2022 (see also BVwG W136 2264651-1/2E dated February 9, 2023). Furthermore, the 9th disciplinary complaint under Roman 40 (2) dated November 3, 2022, the 10th disciplinary complaint under Roman 40 (2) dated April 24, 2023, and the 11th disciplinary complaint under Roman 40 (2) dated [date missing] are also relevant. The disciplinary proceedings against me were evident on August 28, 2023, and were pending before the relevant authority (Roman 40). These disciplinary complaints were filed by the then-competent disciplinary authority, the Disciplinary Commander/Disciplinary Superior, Colonel (Roman 40). By decision of the Federal Administrative Court (BVwG) of January 12, 2024 (Case No. W208 2255608-2/45E), I was dismissed, and the aforementioned proceedings were to be terminated by operation of law. However, on October 21, 2024, Colonel (Roman 40) informed the rank-and-file employee (i.e., not a disciplinary authority or staff council member), Lieutenant Colonel (Roman 40), of precisely these disciplinary proceedings, thereby contradicting the provisions of Section 1 of the Data Protection Act (DSG) in conjunction with Section 34 of the Higher Education Act (HDG). Section 34 of the HDG (Federal Disciplinary Code) reads: "...Public Disclosures Paragraph 34, (1) Disclosures to the public regarding the content of disciplinary measures and disciplinary proceedings are prohibited unless otherwise provided by this Federal Law..." Lieutenant Colonel Roman 40 informed me of this in a telephone call via Signal on August 22, 2024, at approximately 8:37 a.m., and subsequently confirmed this in writing. He also gave me his written consent to testify to this under oath before the Data Protection Authority (DSB) or the Federal Administrative Court (BVwG). Transcript of the written Signal communication between Lieutenant Colonel Roman 40 and myself: Roman 40 August 22, 2024; 10:07 AM: "...Hello Roman 40, did I understand you correctly in our phone call that Roman 40 spoke again yesterday (August 21st) about the disciplinary proceedings still pending against me, in case I return to the station?..." Roman 40: "...No, he said that your proceedings at the Federal Administrative Court will be reopened regarding the points that were not addressed..." Roman 40: "...Okay, so he's clearly referring to the disciplinary proceedings! Would you also testify to this before the Data Protection Authority and the Federal Administrative Court if necessary?" Roman 40: "...Yes, of course!..." Roman 40: "...Thank you!..." Roman 40: "...It's the truth!..." General information on compliance with data protection at Roman 40: It is obvious, however, that the data protection regulations are very frequently NOT being complied with by Roman 40 in conjunction with the Commander, Colonel Roman 40. I do not wish to conceal the fact that I always pointed out all of Roman 40's errors first, and also their legal representative, the Data Protection Authority (DSBür/Römer 40). Only after they failed to recognize their clear errors and deficiencies and were unwilling to rectify them, did I file a complaint with the supervisory authority, the Data Protection Authority (DSB). The Data Protection Authority (DPA) is aware that the following legally binding decisions of the DPA with favorable outcomes for me exist, which affect my rights: - D124.2668 - D124.4169 - D124.5599, confirmed by the Federal Administrative Court (BVwG) - D124.0123 (Confirmed by preliminary ruling D062.1205) - D124.0122 Decisions of the DPA in my case with favorable outcomes for me, but not yet legally binding due to appeals by the DPA (Citizen/Roman 40): - D124.0853/23 - D124.1265/23 - D124.1377/23 - D124.0242/24 A list of the individual (multiple) issues in the decisions with the number of disclosures to uninvolved third parties is omitted. That the data protection regulations are hardly being observed, specifically those under Roman 40, is evident from the aforementioned decisions in which violations of my rights have been established.

3. Evaluation of Evidence:

The findings regarding the procedural history are derived from the administrative act.

3.1. The findings regarding the defendant's personal circumstances and official history are set out in the legally binding disciplinary ruling W208 2255608-2/71E of December 30, 2024, pp. 15-20 (this ruling was issued after the partial reversal of the aforementioned rulings of the Federal Administrative Court of January 12, 2024, W208 2255608-2/45E, and January 25, 2024, W208 2255608-2/48E, by the Administrative Court of Appeal of October 14, 2024, Ra 2024/09/0033, only with respect to the sentence imposed) and were undisputed therein. The legally binding convictions are also set out in this disciplinary ruling (pp. 23ff). 3.1. The findings regarding the defendant's personal circumstances and official history are set forth in the legally binding disciplinary ruling W208 2255608-2/71E of December 30, 2024, hearings 15-20 (this ruling was issued after the partial reversal of the aforementioned rulings of the Federal Administrative Court of January 12, 2024, W208 2255608-2/45E, and January 25, 2024, W208 2255608-2/48E, by the Administrative Court of Appeal of October 14, 2024, Ra 2024/09/0033, only with respect to the sentence imposed) and were undisputed therein. The legally binding convictions are also set forth in this disciplinary ruling (pp. 23ff).

3.2. That the service-related and disciplinary charges against the appellant were largely unfounded, did not lead to any criminal proceedings, and resulted in disciplinary convictions only in a minority of cases, is evident from the Austrian Administrative Court's (VwGH) ruling in the disciplinary proceedings under case number Ra 2024/09/0033-11, paragraph 57, and the findings of the Administrative Court reproduced therein.

3.3. That the appellant, based on the charges against him, launched a counterattack against his superiors by raising various service-related and data protection-related allegations against them, is evident, firstly, from statements made by the appellant and witnesses in the oral hearings of the disciplinary proceedings (see 3.3.1 below), and secondly, from the data protection proceedings already concluded by the respondent authority, which were initiated following a complaint by the appellant (3.3.2):

3.3.1. In a letter of apology to the former commander of the second respondent (thus predecessor of the fourth respondent), Brigadier XXXX (see W208 2255608-2/71E, p. 13), against whom he had filed a criminal complaint for suspected abuse of official authority (see verdict point 13), the appellant stated verbatim (reproduced in the minutes of the hearing of December 11, 2024, p. 44): “At the time, I didn’t know what else to do but to ‘counterattack,’ filing a criminal complaint against you, to subjectively regain the right to a fair trial.” 3.3.1. In a letter of apology to the former commander of the second respondent (and thus predecessor of the fourth respondent), Brigadier General 40 (see W208 2255608-2/71E, Session 13), against whom he had filed a criminal complaint for suspected abuse of official authority (see Conviction, Point 13), the appellant stated verbatim (reproduced in the minutes of the hearing of December 11, 2024, Session 44): “At the time, I didn’t know what else to do but to ‘counterattack,’ filing a criminal complaint against you, to subjectively regain my right to a fair trial.”


``` Regarding the finding of guilt on point 44 concerning a statement about the fourth respondent that exceeded the bounds of objective criticism, the appellant admitted in the hearing of November 15, 2023 (minutes, pp. 6 and 30): “I consider all statements to be essentially wrong. It was an emotional outburst (…)” as well as “I wrote out of anger and rage” as well as “with the knowledge I have today, I will no longer use this wording.” In the last hearing of December 11, 2024 (already after the complaints at issue here had been filed), the appellant stated that in the future, if he had cause to criticize comrades or superiors, he would “remain very, very objective, not bring it up on the same day to let his emotions out” (minutes, p. 7), or “I admit, I had a problem with Colonel XXXX” (i.e., the fourth respondent; p. 9). From these statements, it can be concluded that the appellant, apparently due to his irascible temper, immediately and angrily took available legal action against his superiors upon being accused of an error. As is well known, filing a data protection complaint requires only completing an online form, making this legal avenue a very obvious "release valve." Regarding the finding of guilt on point 44 concerning a statement about the fourth respondent that exceeded the bounds of objective criticism, the appellant admitted in the hearing of November 15, 2023 (minutes of sessions 6 and 30): "I consider all statements to be essentially erroneous. It was an emotional outburst (...)" as well as "I wrote out of anger and rage" as well as "with the knowledge I have today, I will no longer use this wording." In the last meeting of the supervisory authority on December 11, 2024 (already after the complaints at issue here had been filed), the complainant stated that in the future, if he had cause to criticize colleagues or superiors, he would "remain very, very objective, not bring it up on the same day to let his emotions out" (Minutes of Meeting 7), or "I admit, I had a problem with fruit Roman numeral 40" (i.e., the fourth respondent; Meeting 9). From these statements, it can be concluded that the complainant, apparently due to his short temper, immediately and angrily took available legal action against his superiors whenever he suspected an error. As is well known, filing a data protection complaint only requires filling out an online form, making this legal avenue a very obvious "release valve."

That the data protection complaints are to be seen as a counterattack and closely related to disciplinary disputes is also demonstrated by the testimony of the fourth respondent in the hearing of September 6, 2023 (transcript p. 14), according to which there were "two strands": one concerned data protection and various data protection complaints on the part of the respondent, and the other involved various accusations against him personally. Each submission by the respondent and each response from the witness was met with further reprimands and accusations from the respondent. The fourth respondent testified in the same hearing (transcript p. 16) that the respondent had previously filed charges against individuals who had not acted according to his wishes. He had initiated a series of declaratory judgments and questioned the fourth respondent's supervisory position. In just two months (from July 6 to September 6, 2023), the respondent had submitted 45 complaints containing various accusations. The appellant did not substantively contradict these statements in the hearing. The fact that the data protection complaints are to be seen as a counterattack and closely related to disputes concerning employment law is also demonstrated by the testimony of the fourth respondent in the hearing of September 6, 2023 (minutes of session 14), according to which there were "two strands": one concerned data protection and various data protection complaints on the part of the appellant, the other various accusations against him personally, with each submission by the appellant and each response from the witness being met with further reprimands and accusations from the appellant. The fourth respondent testified in the same hearing (minutes of session 16) that the appellant had in the past filed charges against individuals who had not acted according to his wishes. He had initiated a series of declaratory judgments and called into question the fourth respondent's supervisory position. In just two months (from July 6 to September 6, 2023), the BF (presumably a person or organization) submitted 45 complaints containing various allegations. The BF did not substantively refute these claims during the preliminary hearing.

According to the testimony of the third respondent in the same preliminary hearing (transcript p. 21), the BF's "behavior" was not attributable to specific individuals, but rather a general tendency to act this way whenever he was dissatisfied with them. It is possible that during the training of young soldiers, a regulation might not be strictly followed, and this should not be turned into a "state affair." This “defensive stance” of the fire chief towards mistakes was also emphasized by the fifth respondent (p. 29): “I see a major problem because he certainly doesn’t want to be proven to have made any mistakes, and he won’t. With a staffing level of 70% and an inadequate structure, however, mistakes are unavoidable. The lengthy proceedings have certainly left their mark on the working atmosphere. As commander, I polarize the team, and so does he due to his defensiveness.” It should be noted that the fifth respondent generally showed goodwill towards the fire chief during the proceedings (VH 06.07.2023, p. 9: “I got to know him as an extremely loyal, reliable, and sincere employee.”). The appellant himself ultimately testified that, due to the threat of criminal charges by the fourth respondent, which were subsequently not filed, he had "filed a self-report" in order to "expedite" the process (VH 14.11.2023, transcript p. 20), which also illustrates his defensive stance regarding alleged errors. The disciplinary panel of the Federal Administrative Court, after six oral hearings, also explicitly stated in its reasoning that the appellant was launching a "counterattack" against his superiors (VH 11.12.2024, transcript p. 44). According to the testimony of the third respondent in the same hearing (transcript session 21), the appellant's "behavior" was not attributable to specific individuals, but rather that he generally resorted to such behavior whenever he was dissatisfied with them. It can happen during the training of young soldiers that a regulation is not followed precisely, and this should not be turned into a "state affair." This "defensive stance" of the BF (Bayerischer Feuerwehr, Bavarian Fire Brigade) towards mistakes was also emphasized by the fifth respondent (Session 29): "I see a major problem because he certainly doesn't want to be proven to have made a mistake, and he won't. With a staffing level of 70% and an inadequate structure, however, mistakes are unavoidable. The lengthy proceedings have certainly left their mark on the working atmosphere. As commander, I am polarizing, and so is he due to his defensiveness." It should be noted that the fifth respondent generally expressed goodwill towards the BF during the proceedings (VH 06.07.2023, Session 9: "I have come to know him as an extremely loyal, reliable, and sincere employee."). The appellant himself ultimately testified that, due to the threat of criminal charges by the fourth respondent, which were subsequently not filed, he had "filed a self-report" in order to "expedite" the process (VH 14.11.2023, minutes of session 20), which also illustrates his defensive stance regarding alleged errors. The disciplinary panel of the Federal Administrative Court, which reached its decision after six oral hearings, also explicitly referred to a "counterattack" by the appellant against his superiors in its reasoning (VH 11.12.2024, minutes of session 44).

3.3.2. (Data Protection Preliminary Proceedings):

On November 24, 2021, the appellant filed a data protection complaint against the second respondent for an alleged violation of his right to confidentiality, because the latter had transmitted his health data to an unauthorized body (General Law Department/XXXX), which was subsequently disclosed to the respondent authority.

A similar set of facts formed the basis of the appellant's complaint of July 19, 2023, against the first respondent (again, disclosure of the appellant's data to the respondent authority).















On November 24, 2021, the appellant filed a data protection complaint against the second respondent for an alleged violation of his right to confidentiality, because the latter had transmitted his health data to an unauthorized body (General Law Department/ 40), which was subsequently disclosed to the respondent authority.





















``` . ... In his complaint of May 26, 2021, against the fourth respondent, the plaintiff alleged a violation of his right to confidentiality due to the disclosure of the fact that a disciplinary penalty had already expired against him.

A complaint of November 1, 2021, against the second respondent concerned a violation of the plaintiff's right to confidentiality through the storage of his private email address.

A complaint of December 22, 2021, against the first respondent concerned an alleged violation of the plaintiff's right to information because the respondent had not disclosed all recipients or categories of recipients of his data.

The complaint of January 22, 2022, against the second respondent again alleged a violation of the right to confidentiality through the disclosure that a disciplinary complaint had been filed against the plaintiff.

The complaints filed on January 23, 2022, June 12, 2023, June 28, 2023, and September 29, 2023, against the second respondent also concerned the disclosure of the employee's data (regarding the disciplinary ruling, an appeal by the employee, and employee interviews, respectively).

On July 28, 2022, the employee filed a complaint against the fourth respondent for violation of the right to confidentiality, alleging that the fourth respondent had transmitted a screenshot of a WhatsApp message, which allegedly revealed the employee's private telephone number, to third parties (the disciplinary authority, the disciplinary attorney, and the employee's legal representative).



On July 28, 2022, the employee filed a complaint against the fourth respondent for violation of the right to confidentiality by forwarding a screenshot of a WhatsApp message, which allegedly showed the employee's private telephone number, to third parties (the disciplinary authority, the disciplinary attorney, and the employee's legal representative). These preliminary proceedings (mentioned as examples) demonstrate, in conjunction with the statements made in the disciplinary proceedings, that the appellant did indeed file numerous data protection complaints against his superiors, which were closely related to his own service and disciplinary proceedings, so that, in effect, a "counterattack" can be assumed.

3.4. The findings regarding the appeal proceedings covered by the operative part of the contested decision are contained in the administrative file and are undisputed.

3.5. In particular, it is also undisputed (see the respondent authority's statement of January 28, 2026) that the appellant's appeal of November 11, 2023, recorded under file number XXXX, was submitted to the Federal Administrative Court (BVwG) on the basis of a complaint of inaction by the appellant before the contested decision was issued. In particular, it is also undisputed (see the respondent authority's statement of January 28, 2026) that the appellant's complaint of November 11, 2023, recorded under file number 40, was submitted to the Federal Administrative Court (BVwG) on the grounds of inaction by the appellant even before the contested decision was issued.

4. Legal Assessment:

The respondent authority refused to process the complaints in question pursuant to Article 57(4) GDPR.

4.1.1. Pursuant to Article 57(4) GDPR, the supervisory authority may, in the case of manifestly unfounded or – in particular in the case of frequent repetition – excessive requests, charge a reasonable fee based on the administrative costs incurred in processing the requests or refuse to act on them. In this case, the supervisory authority bears the burden of proof that the requests are manifestly unfounded or excessive. 4.1.1. Pursuant to Article 57(4) GDPR, in the case of manifestly unfounded or – in particular in the case of frequent repetition – excessive requests, the supervisory authority may charge a reasonable fee based on the administrative costs incurred in processing the requests or refuse to act on the requests. In this case, the supervisory authority bears the burden of proof that the requests are manifestly unfounded or excessive.

4.1.2. In its judgment of 9 January 2025 in case C-416/23, the Court of Justice of the European Union ruled, inter alia, on the interpretation relevant to the present case regarding the following question:

“Is Article 57(4) GDPR to be interpreted as meaning that for the existence of excessive requests, it is sufficient that a data subject has submitted a certain number of requests (complaints under Article 77(1) GDPR) to a supervisory authority within a specific period, irrespective of whether the matters are different and/or the requests (complaints) concern different controllers, or is it necessary, in addition to the frequent repetition of requests (complaints), that the data subject also has an intent to abuse the system?” The question arises whether a request (complaint) can be considered "excessive" solely on the basis of its number, regardless of whether it concerns different matters and/or different controllers, or whether, in addition to the frequent repetition of requests (complaints), the data subject must also demonstrate an intent to abuse the data.

The CJEU answered this question by stating that Article 57(4) GDPR must be interpreted as meaning that requests cannot be classified as "excessive" within the meaning of this provision solely on the basis of their number during a specific period, since the exercise of the power provided for in this provision requires the supervisory authority to demonstrate the existence of an intent to abuse the data on the part of the requesting data subject.

The CJEU answered this question by stating that Article 57(4) GDPR must be interpreted as meaning that requests cannot be classified as "excessive" within the meaning of this provision solely on the basis of their number during a specific period, since the exercise of the power provided for in this provision requires the supervisory authority to demonstrate the existence of an intent to abuse the data subject. The Court of Justice of the European Union further held that, in the case of excessive requests, a supervisory authority may, by reasoned decision, choose whether to charge a reasonable fee based on the administrative costs incurred or to refuse to act on the request, taking into account all relevant circumstances and ensuring that the chosen option is appropriate, necessary, and proportionate.

In summary, the Court of Justice of the European Union explained that the adjective "excessive" refers to something that goes beyond the ordinary or reasonable level, or exceeds what is desired or permissible. The exercise of the power provided for in Article 57(4) GDPR must remain an exception to the principle of free services provided for by supervisory authorities, as laid down in Article 57(3) GDPR. It may only be exercised in cases of abuse of rights, and the number of complaints received is not, in itself, a sufficient criterion for establishing such abuse. Article 57(4) GDPR reflects the Court of Justice's settled case law, according to which there is a general principle in EU law that citizens may not invoke EU law in a fraudulent or abusive manner. Against this background, when a supervisory authority invokes Article 57(4) GDPR, it must establish, based on all relevant circumstances of each individual case, that the data subject has an intent to abuse the law, for which the number of complaints submitted by that person alone is insufficient. However, an intent to abuse the law can be established if a person submits complaints without this being objectively necessary to protect their rights under the Regulation. An isolated consideration of the number of complaints could lead to an arbitrary infringement of the data subject's rights under the GDPR. In summary, the Court of Justice of the European Union stated that the adjective "excessive" refers to something that goes beyond the ordinary or reasonable measure, or exceeds the desired or permissible level. The exercise of the power provided for in Article 57(4) GDPR must remain an exception to the principle of free services provided for by supervisory authorities, as laid down in Article 57(3) GDPR. It may only be exercised in cases of abuse of rights, and the number of complaints submitted cannot, in itself, constitute a sufficient criterion for establishing such abuse. Article 57(4) GDPR reflects the settled case law of the Court of Justice, according to which there is a general principle in EU law that citizens may not rely on EU legal provisions in a fraudulent or abusive manner. Against this background, when a supervisory authority makes use of Article 57(4) GDPR, it must establish, based on all relevant circumstances of each individual case, that the data subject intends to abuse the system, for which the number of complaints submitted by that person alone is insufficient. However, an intent to abuse the system can be established if a person files complaints without this being objectively necessary to protect their rights under the Regulation. An isolated consideration of the number of complaints could lead to an arbitrary infringement of the data subject's rights under the GDPR.

Based on the circumstances of each individual case, the supervisory authority is responsible for demonstrating, when faced with a large number of complaints, that this number is not due to the data subject's desire to protect their rights under the GDPR, but rather to another purpose unrelated to this protection. This applies particularly if the circumstances indicate that the number of complaints is aimed at impairing the proper functioning of the authority by misusing its resources. In this respect, a person's accumulation of complaints could be an indication of excessive requests if it turns out that the complaints are not objectively justified by considerations relating to the protection of the rights granted to that person by the GDPR. This can be the case, for example, if a person submits such a large number of complaints to the supervisory authority concerning a multitude of controllers with whom they have no direct connection that this excessive use of their right to lodge complaints, in conjunction with other factors such as the content of the complaints, reveals their intention to paralyze the authority by flooding it with requests.

The CJEU also held (paragraphs 51 et seq.) that, pursuant to Article 52(4) GDPR, Member States must ensure that each supervisory authority is equipped with the human, technical, and financial resources, premises, and infrastructure it needs to effectively perform its tasks and exercise its powers. Consequently, these resources must be adapted to the use made by data subjects of their right to lodge complaints with the supervisory authorities. It is therefore incumbent upon Member States to provide supervisory authorities with adequate resources to deal with all complaints submitted to them, and, where necessary, to increase these resources to reflect the use made by data subjects of their right to lodge complaints under Article 77(1) GDPR. A supervisory authority may therefore not base its refusal to act on a complaint under Article 57(4) GDPR on the grounds that a person who submits a number of complaints significantly exceeding the average number submitted by any data subject occupies a considerable portion of the authority's resources, thereby hindering the handling of complaints submitted by other persons. The CJEU also held (paragraphs 51 et seq.) that, pursuant to Article 52(4) GDPR, Member States must ensure that each supervisory authority is equipped with the human, technical, and financial resources, premises, and infrastructure it needs to effectively perform its tasks and exercise its powers. Consequently, these resources must be adapted to the use made by data subjects of their right to lodge complaints with supervisory authorities. It is therefore for Member States to provide supervisory authorities with adequate resources to deal with all complaints submitted to them and, where necessary, to increase these resources to reflect the use made by data subjects of their right to lodge complaints under Article 77(1) GDPR. A supervisory authority may therefore not base its refusal to act on a complaint under Article 57(4) GDPR on the fact that a person who submits a number of complaints significantly exceeding the average number submitted by any data subject occupies a significant portion of the authority's resources, thereby hindering the handling of complaints submitted by other persons.

4.1.3. It also follows that a supervisory authority cannot invoke its lack of resources, even with regard to a (potential) large number of inadequate or excessive complaints from a specific complainant: The resulting consumption of the authority's resources, due to the laborious process of reading and processing these complaints, or the need to prompt the complainant to provide more specific information through requests for clarification, cannot, in principle, justify a rejection under Article 57(4) GDPR. The Austrian Administrative Court (VwGH) also held in this regard in its decision Ra 2025/04/0143 that the question of whether a complaint is excessive within the meaning of Article 57(4) GDPR does not depend on whether the specific complaint leads to an overload of the supervisory authority or not. Nevertheless, frequent redundancy, for example, can be seen as an indication of an intent to abuse the system. 4.1.3. It follows that a supervisory authority cannot invoke its lack of resources, even with regard to a (potential) large number of inadequate or excessive complaints from a specific complainant: The resulting resource expenditure of the authority, due to the laborious process of reading and processing these complaints, or the need to prompt the complainant to provide more specific information through requests for clarification, cannot, in principle, justify a rejection under Article 57(4) GDPR. Similarly, the Austrian Administrative Court (VwGH) held in its decision Ra 2025/04/0143 that the question of whether a complaint is excessive within the meaning of Article 57(4) GDPR does not depend on whether the specific complaint leads to an overload of the supervisory authority. Nevertheless, frequent redundancy, for example, can be seen as an indication of an intent to abuse the system.

This leads to the following conclusions for the case under consideration:

4.2.1. First, the appellant is correct in his appeal insofar as the respondent authority, as it itself admitted in its written submission of January 28, 2026, mistakenly included the appeal proceedings regarding point 2 (concerning the appellant's data protection complaint of November 11, 2023) in the present decision, especially since, due to the submission of the relevant complaint for failure to act to the Federal Administrative Court (BVwG) at the time of the decision (§ 16 VwGVG; Ra 2020/13/0088), it was no longer competent for the aforementioned proceedings at that time. Due to the respondent authority's lack of competence in this respect, the appeal was to be granted and this point of the decision was to be set aside without substitution. 4.2.1. The appellant is initially correct in his appeal insofar as the respondent authority, as it itself admitted in its written submission of January 28, 2026, mistakenly included the appeal proceedings regarding point 2 of the ruling (concerning the appellant's data protection complaint of November 11, 2023) in the present decision, especially since, due to the submission of the relevant complaint for failure to act to the Federal Administrative Court (Section 16, Administrative Court Procedure Act; Ra 2020/13/0088) at the time of the decision, it was no longer competent for the aforementioned proceedings. Due to the respondent authority's lack of competence in this respect, the appeal was to be granted and this point of the ruling was to be set aside without substitution.

Furthermore, the following should be noted:

4.2.2. As explained, the Court of Justice of the European Union has now issued its first comprehensive ruling on Article 57(4) GDPR. The Court's key statements regarding the decisive interpretation of manifestly unfounded or excessive requests have been summarized above. 4.2.2. As described, the Court of Justice of the European Union has now issued its first detailed ruling on Article 57(4) of the GDPR. The Court's key statements regarding the decisive interpretation of manifestly unfounded or excessive requests have been summarized above.

In its decision, the Court applies a strict interpretation, according to which only proof of an abusive intent on the part of the requesting authority justifies a supervisory authority's refusal to process requests (complaints). Excessive use of the authority by one and the same requesting authority, in conjunction with other circumstances, can only constitute an indication of an excessive nature of the requests.

4.2.3. The Court of Justice of the European Union clarified that previous inquiries or complaints alone—however numerous—do not automatically imply excessiveness in all future submissions simply because of a certain frequency. Instead, each new submission must be examined to such an extent that it can be assessed whether it, either alone or in conjunction with previous submissions, is motivated by an intent to abuse the system (see also Austrian Administrative Court decision Ra 2020/04/0084). Therefore, the specific submission itself must be examined for the presence of an intent to abuse the system, and the previous submissions from the same applicant must also be considered in the assessment.

4.2.4. Against this background, the fundamental criticism of the contested decision is that the respondent authority, although its decision was issued before the aforementioned CJEU case law, only addressed the individual data protection complaints of the appellant (BF) summarized here by way of example, and barely addressed the respective individual grounds of complaint in detail. Instead, the brief legal reasoning dealt only abstractly (number of complaints, "impressed impression," partial submission on the day of rejection of the request) and generally with the large number of proceedings summarized here. Only because the essential circumstances for assessing the applicability of Article 57(4) GDPR can be established here based on the contents of the file, in particular taking into account the BF's earlier submissions in the reasoning of the decision and the evidence from the disciplinary proceedings, was it possible to refrain from remedying this deficiency. 4.2.4. Against this background, the fundamental criticism of the contested decision is that the respondent authority, although its decision was issued before the aforementioned CJEU case law, only addressed each of the 14 data protection complaints submitted by the appellant in a representative manner and barely addressed the individual grounds for each complaint. Instead, the brief legal reasoning dealt only abstractly (number of complaints, "impressed impression," partial submission on the day of rejection) and generally with the large number of cases summarized here. Only because the essential circumstances for assessing the applicability of Article 57(4) GDPR can be established here based on the contents of the file, particularly considering the appellant's earlier submissions in the reasoning of the decision and the evidence from the disciplinary proceedings, was it possible to refrain from rectifying this deficiency.

4.2.5. It should first be noted that, according to the case law cited above, neither a high number of complaints nor redundant or deficient submissions are the primary considerations here. However, these circumstances can be an indication that the complainant is pursuing primarily data protection-related purposes with their complaints (see Ra 2023/04/0002). In its recent case law, the Austrian Administrative Court (VwGH) also cited "hostility" towards certain persons as such a purpose to be considered abusive (see Ra 2025/04/0143). According to this case law, an intent to abuse the system can be assumed if data protection complaints are filed without this being objectively necessary to protect the complainant's rights under the GDPR, but rather serve another purpose that is unrelated to this protection. It is to be assumed if the complainant's decisive reasons for filing numerous data protection complaints do not lie in the pursuit of their rights under the GDPR, and the complainant would not have raised the numerous data protection complaints without these extraneous reasons (Ra 2020/04/0084).

4.2.6. Considering the findings regarding the data protection complaints at issue here, the preliminary proceedings already decided by the respondent authority against the same respondents, and the circumstances of the complainant's employment relationship with XXXX (particularly those arising from the disciplinary proceedings), the following is decisive for the court: 4.2.6. In light of the findings regarding the data protection complaints filed by the appellant, the preliminary proceedings already decided by the respondent authority against the same respondents, and the circumstances of the appellant's employment relationship with the Federal Administrative Court (particularly those arising from the disciplinary proceedings), the following is decisive for the court:

The 13 data protection complaints filed by the authority (as a result of point 2 of the ruling, which is to be remedied) were all raised in the appellant's professional context and are directed against his superiors or departments. The period covered by the complaints spans from April 11, 2023, to August 22, 2024. It appears significant that approximately one month before the first of the complaints at issue here was filed, the disciplinary ruling was issued, in which the appellant was fined for numerous breaches of duty in the course of his service. At the beginning of 2024, this penalty was even converted into a dismissal by the Federal Administrative Court. When the last of the complaints at issue here was filed in August 2024, the appellant already had to assume his dismissal. This context alone makes it clear that the filing of a not insignificant number of complaints—13 in total—over a period of approximately one and a half years (12 of which were filed within seven months, beginning on January 28, 2024, i.e., immediately after the dismissal was announced) was directed against those persons or bodies who, from a legal perspective (disciplinary complaint or initiation of disciplinary proceedings through submissions and the presentation of evidence), were responsible for the fine imposed on the appellant and his dismissal. This applies primarily to the fourth respondent, as the appellant's disciplinary superior, and the second respondent, whom he manages and against whom most of the complaints at issue here are directed. However, the other respondents must also be considered directly involved in the disciplinary disputes because the first respondent was the highest service authority for the appellant (§ 2 para. 2 DVG), all communication regarding internal matters was to be routed through the third respondent due to the communication order issued by the fourth respondent (resulting from the disciplinary disputes), the fifth respondent was the appellant's immediate superior at Institute XXXX, and the seventh respondent (the data protection office of the first respondent) was also involved in the matter at least due to the numerous data protection complaints already filed by the appellant against his superiors prior to the present proceedings. The 13 data protection complaints at issue here (resulting from point 2 of the ruling to be remedied) were all filed in the appellant's professional context and are each directed against his superiors or departments.The period covered by the complaints spans from April 11, 2023, to August 22, 2024. It is significant that approximately one month before the first of the complaints at issue here was filed, the disciplinary ruling was issued, in which the appellant was fined for numerous breaches of duty in the course of his service. At the beginning of 2024, this penalty was even converted into a dismissal by the Federal Administrative Court. By the time the last of the complaints at issue here was filed in August 2024, the appellant already had to assume his dismissal. This context alone makes it clear that the filing of a not insignificant number of complaints—13 in total—over a period of approximately one and a half years (12 of which occurred within seven months, beginning on January 28, 2024, i.e., immediately after the dismissal) was directed against those persons or bodies who, from a legal perspective (disciplinary complaint or initiation of disciplinary proceedings through submissions and the provision of evidence), were responsible for the fine imposed on the appellant or his dismissal. This applies primarily to the fourth respondent, as the appellant's disciplinary superior, and the second respondent, whom he manages and against whom most of the complaints at issue here are directed. However, the other respondents must also be considered directly involved in the disciplinary disputes because the first respondent was the highest-ranking authority for the employee (Section 2, Paragraph 2, DVG); all communication regarding internal matters was to be routed through the third respondent due to the communication order issued by the fourth respondent (resulting from the disciplinary disputes); the fifth respondent was the employee's immediate superior at Institute Roman 40; and the seventh respondent (the data protection office of the first respondent) was also involved in the matter at least due to the numerous data protection complaints already filed by the employee against his superiors prior to the present proceedings.

4.2.7. The numerous declaratory judgment applications filed by the appellant with the employing authority in 2024, which even led to the imposition of three fines for frivolous violations, illustrate the highly charged official context in which the data protection complaints at issue here were raised. This conflict-ridden context is further underscored by the convictions handed down against the appellant in the disciplinary proceedings, a significant portion of which (namely points 15, 16, 19, 20, 22, 28, 36, 40, 42, 44, and 47) concerned disputes between the appellant and the fourth respondent (and thus his disciplinary superior).

4.2.8. An examination of each of the 13 proceedings summarized here shows that each complaint must always be viewed within the context of the BF's service-related or disciplinary disputes:

In his complaint of April 11, 2023, the BF requested information regarding the disclosure of health data by the second respondent to the first respondent, arguing that the disclosure was unjustified and had been revealed in another proceeding. The core issue, therefore, concerns what the BF considers to be unjustified data processing by the second respondent (who is directly responsible for his disciplinary proceedings).

In his complaint of January 28, 2024, the BF again objected to the disclosure of health data by the second respondent, this time to the disciplinary officer in the context of a statement in the disciplinary proceedings.


In his complaint of January 28, 2024, the BF again objected to the disclosure of health data by the second respondent, this time to the disciplinary officer in the context of a statement in the disciplinary proceedings.


His complaint of February 19, 2024, also concerns the disclosure of health data by the second respondent, specifically to various parties and in connection with the appellant's request for restriction of processing pursuant to Article 18 of the GDPR.

The connection to the disciplinary proceedings is also evident in the complaint of February 29, 2024, against the fourth and fifth respondents, who, according to the appellant, unlawfully disclosed the contents of his disciplinary ruling.

In his complaint of March 12, 2024, the appellant alleges that the fourth respondent (i.e., his disciplinary superior) unlawfully transmitted a photograph of a private message from the appellant to the staff representative. The underlying issue is that the employee (BF) discussed with the staff representative what he considered to be the unlawful conduct of his superiors in connection with the disclosure of his disciplinary findings. The complaint of April 10, 2024, concerns the deletion of the photograph in question.

The complaint of April 9, 2024, is directed against the fifth respondent, whom the employee (BF) considers his disciplinary authority, and who allegedly violated his right to information.

The complaints of June 9 and June 28, 2024, each concern the fourth respondent in his private capacity (referred to here as the sixth respondent), who filed private data protection complaints against the employee and used the employee's private address, obtained through official channels. The employee argues that the sixth respondent may only request and process this data in the employee's official interest, including in his capacity as his disciplinary authority.


The complaints of June 9 and June 28, 2024, each concern the fourth respondent in his private capacity (referred to here as the sixth respondent), who filed private data protection complaints against the employee and used the employee's private address, which he had obtained through official channels. The complaint of July 8, 2024, is directed against the second respondent and concerns the fourth respondent's inquiry into the appellant's private address and its disclosure to third parties.

The connection to the disciplinary proceedings is also evident in the complaints of July 31, 2024, and August 19, 2024, both of which, in the appellant's view, concern the unlawful failure to delete disciplinary notices (once by the fourth respondent and once by the seventh respondent).

Finally, in the complaint of August 22, 2024, the appellant again objects to the fourth respondent's unlawful mention of disciplinary proceedings pending against the appellant.


These 13 data protection complaints appear – as established and explained in the evaluation of evidence with reference to the evidence presented in the disciplinary proceedings and the preliminary data protection proceedings – in the context of a "counterattack" by the BF against his superiors, who had raised – largely unfounded – accusations against him in connection with breaches of duty. He was unwilling to let these accusations stand, outside the scope of the legally prescribed clarification process, and sought to avenge or combat them by recklessly filing legal remedies for minor infractions.

4.2.9. In conclusion, given the obvious connections to his disciplinary proceedings, both in terms of timing and content, and with regard to the respective respondents, it must be assumed that the primary aim of the complainant in filing the 13 data protection complaints at issue here was to retaliate against the respective respondents, who were more or less directly involved in his disciplinary proceedings, by initiating official proceedings as retaliation for these proceedings and the decisions made therein. This retaliation was intended to use these (data protection) proceedings as leverage to deter the respondents from taking further disciplinary action that would be detrimental to the complainant. Without these circumstances related to his employment, the complainant would most likely not have filed these data protection complaints. This assessment is based on the principle that, in a professional context, an employee generally values maintaining a conflict-free relationship with colleagues and superiors, ensuring that such relationships do not negatively impact daily work.

4.2.10. Irrelevant in this context is the likelihood of success of the complaints at issue here:

Firstly, the refusal to process a complaint pursuant to Article 57(4) GDPR means precisely (in the sense of a dismissal a limine) that, due to its excessive nature, no substantive review of the respective complaint is required. Secondly, the alternative criterion of "manifest lack of merit" indicates that excessively raised complaints need not necessarily be manifestly unfounded; thus, even (potentially) well-founded complaints can be abusive and excessive. This is also demonstrated by a recent decision of the Austrian Administrative Court (VwGH) in case Ro 2025/04/0027, which upheld the rejection by the Data Protection Authority (DSB) and the Administrative Court (VwG) in connection with an alleged violation of the right of access. The data protection complaint was based on a request for access under Article 15 GDPR that was not processed within the one-month deadline for a response. The Administrative Court did not dispute the actual failure to comply with the deadline, but found that this infringed upon the complainant's subjective rights to a relatively minor extent. Firstly, the refusal to process a complaint under Article 57(4) GDPR means precisely (in the sense of a dismissal a limine) that, due to its excessive nature, no substantive review of the complaint is required. Secondly, the alternative criterion of "manifest lack of merit" indicates that excessively raised complaints need not necessarily be manifestly unfounded; thus, even (potentially) well-founded complaints can be abusive and excessive. This is also demonstrated by a recent decision of the Austrian Administrative Court (VwGH) in case Ro 2025/04/0027, which upheld the rejection by the Data Protection Authority (DSB) and the Administrative Court (VwG) in connection with an alleged violation of the right of access. In this case, the data protection complaint was based on a request for access under Article 15 GDPR that was not processed within the one-month deadline for a response. The administrative court did not question the actual failure to comply with the deadline, but found that this affected the appellant's subjective rights to a relatively minor extent.

Similarly, the Austrian Administrative Court (VwGH) ruled in case Ra 2023/04/0002: “The mere fact that a large number of data protection complaints from one person concern a multitude of controllers with whom they have a connection, and that these controllers process the complainant's personal data, does not automatically lead to the conclusion that the complainant is genuinely concerned with protecting their rights under the GDPR and not rather with pursuing other interests and objectives. For example, if a complainant only initiates the processing of their personal data by a controller in order to subsequently assert their rights under the GDPR, such as the right of access under Article 15, against that controller, and if a relationship exists between the complainant and the controller solely for this reason, then the complainant's intent to abuse the system must be assumed with regard to any subsequent data protection complaint.” Similarly, the Austrian Administrative Court (VwGH) ruled in case Ra 2023/04/0002: "The mere fact that a large number of data protection complaints from one individual concern a multitude of controllers with whom they have a connection, and that these controllers process the complainant's personal data, does not automatically lead to the conclusion that the complainant is genuinely concerned with protecting their rights under the GDPR and not rather pursuing other interests and objectives. For example, if a complainant initiates the processing of their personal data by a controller solely to subsequently assert their rights under the GDPR, such as the right of access under Article 15, against that controller, and if a relationship exists between the complainant and the controller only for this reason, then the complainant's intent to abuse the system can be assumed with regard to any subsequent data protection complaint."

4.2.11. All 13 complaints at issue here by the BF are therefore motivated by an intent to abuse the system and must be considered excessive within the meaning of Article 57(4) GDPR. 4.2.11. All 13 complaints at issue here by the BF are therefore motivated by an intent to abuse the system and must be considered excessive within the meaning of Article 57(4) GDPR.

4.2.12. As regards the legal consequences, the aforementioned provision leaves the supervisory authority, according to the CJEU, the discretionary choice between rejecting the complaint by refusing to address its merits and imposing a fee. According to the CJEU, the supervisory authority “could” demand payment of a reasonable fee as a first step and only refuse to act on a complaint as a second step, since a fee infringes the rights of the data subjects to a lesser extent (C-416/23, paragraph 69). However, Article 57(4) GDPR does not oblige the supervisory authority to always choose the option of imposing a fee first. The authority must, however, justify that the chosen option is appropriate, necessary, and proportionate (paragraph 70). 4.2.12. As regards the legal consequence, the aforementioned provision leaves the supervisory authority, according to the CJEU, the discretionary choice between rejecting the complaint by refusing to address its merits and imposing a fee. According to the CJEU, the supervisory authority “could” demand payment of a reasonable fee as a first step and only as a second step refuse to act on a complaint, since a fee is less infringing on the rights of the data subjects (C-416/23, paragraph 69). However, Article 57(4) GDPR does not oblige the supervisory authority to always choose the option of imposing a fee first. The authority must, however, justify that the chosen option is suitable, necessary, and proportionate (para. 70).

According to the case law of the Austrian Administrative Court (VwGH) (Ra 2023/04/0002), the suitability of levying a fee will be denied, among other things, if it can be assumed that the appellant will also exploit the legal remedies against a fee assessment in order to paralyze the authorities, or if, despite the imposition of fees for excessive data protection complaints, the appellant does not refrain from filing such complaints.

While it cannot be assumed in the present case that the appellant intends to "paralyze" the respondent authority with his data protection complaints; Nevertheless, as described above, he pursued purposes unrelated to data protection (hostile intent against his superiors, filing complaints as a means of exerting pressure), and the authority's view, expressed in its written submission of January 28, 2026, that the complainant would not be deterred by a fee (also in light of his numerous costly proceedings before the Federal Administrative Court), is not objectionable given the complainant's previous careless approach to filing complaints. It should be added, in accordance with the aforementioned decision of the Administrative Court of Appeal, that the complainant would naturally also contest the amount of a fee imposed by the respondent authority, so that the authority's burden of proof would increase compared to a rejection.

4.2.13. Referring to the above assessment, the respondent authority's decision not to process the complaints in question due to excessiveness within the meaning of Article 57(4) GDPR is ultimately not objectionable. 4.2.13. Referring to the above assessment, the decision of the respondent authority not to process the complaints in question due to excessiveness within the meaning of Article 57(4) GDPR is not objectionable.

4.3.1. Finally, the argument in the complaint that the respondent authority failed to cite a legal basis in the operative part of the contested decision must be addressed. It should be noted that the legal bases are indeed located below the operative part (decision, p. 2, bottom) and are therefore to be considered cited in the operative part pursuant to Section 59(1) of the General Administrative Procedure Act (AVG). Moreover, according to the case law of the Supreme Administrative Court, it is sufficient if the legal provisions supporting the decision are clearly identifiable (see Hengstschläger/Leeb, AVG § 59 (as of March 1, 2023, rdb.at), para. 74). 4.3.1. Finally, the argument in the appeal that the respondent authority failed to cite a legal basis in the operative part of the contested decision must be addressed. It should be noted that the legal bases are indeed located below the operative part (Decision Session 2, bottom) and are therefore to be considered cited in the operative part pursuant to Section 59, Paragraph 1, of the General Administrative Procedure Act (AVG). Moreover, according to established case law of the Supreme Administrative Court, it suffices if the legal provisions supporting the decision are unequivocally identifiable (see Hengstschläger/Leeb, AVG Section 59, (as of March 1, 2023, rdb.at), para. 74).

4.3.2. Regarding the alleged failure to provide all procedural files during a file inspection on October 2, 2024, i.e., after the contested decision was issued, any procedural defect is no longer relevant to the decision itself, given the timing (after its issuance). Furthermore, according to the memorandum of the responsible employee of the respondent authority dated October 7, 2024, the appellant expressly and twice waived the right to obtain the files that had been inadvertently withheld. The appellant also admits this on page 2 of his appeal. Due to this waiver, the relevance of any potential procedural defect is not apparent, as the appellant would have been free to inspect the requested files (regarding the necessary relevance, see Hengstschläger/Leeb, AVG § 17 (as of January 1, 2014, rdb.at), para. 13). In any case, the Federal Administrative Court (BVwG) does not have separate authority to determine violations of the right to inspect files in this context, so the appellant's explicit request in the appeal to this effect had to be rejected. 4.3.2. Regarding the alleged failure to provide all case files during a file inspection on October 2, 2024, i.e., after the contested decision was issued, any potential procedural defect is no longer relevant given the timing (after the decision was issued). Furthermore, according to the file note of the responsible employee of the respondent authority dated October 7, 2024, the appellant expressly and twice waived the right to obtain the files that had been inadvertently withheld. The appellant also acknowledges this in his appeal, hearing 2. Due to this waiver, the relevance of any potential procedural defect is not apparent, as the appellant would have been free to inspect the requested files (regarding the necessary relevance, see Hengstschläger/Leeb, AVG Section 17, (as of January 1, 2014, rdb.at), para. 13). The Federal Administrative Court (BVwG) does not have separate jurisdiction to determine violations of the right to inspect files in this context, so the appellant's (BF) explicit request in the appeal to this effect had to be dismissed.

4.3.3. Finally, the BF's request of December 5, 2024, for reimbursement of his costs by the respondent authority also had to be dismissed, because the BVwG is not competent to rule on such claims for damages.

5. The BF did not request an oral hearing, and one is not necessary given that the assessment is solely based on the BF's written submissions and the evidence already fully presented in the disciplinary proceedings. Moreover, a hearing was unnecessary pursuant to Section 24 Paragraph 2 Item 1 of the Administrative Court Procedure Act (VwGVG), since the respondent authority's refusal to consider the merits of an appeal is equivalent to a rejection (of the initial application) (see also the Austrian Administrative Court decision Ra 2023/04/0002). An oral hearing was not requested by the appellant and is not necessary given that the assessment is limited to the appellant's written submissions and the evidence already fully presented in the disciplinary proceedings. Furthermore, a hearing was unnecessary pursuant to Section 24, Paragraph 2, Number 1 of the Administrative Court Procedure Act (VwGVG), as the respondent authority's refusal to consider the merits of the complaint is equivalent to a rejection (of the initiating application) (see also VwGH Ra 2023/04/0002).

6. The refusal to grant leave to appeal is based on the recent clarification of the interpretation of Article 57(4) GDPR by the Court of Justice of the European Union and the specific nature of the case at hand.