BVwG - W108 2285546-1/22E

From GDPRhub
BVwG - W108 2285546-1/22E
Court: BVwG (Austria)
Jurisdiction: Austria
Relevant Law: Article 4(7) GDPR
Article 6(1)(f) GDPR
Article 9(1) GDPR
Article 9(2)(a) GDPR
Article 22 GDPR
Article 33 GDPR
Article 57 GDPR
Article 58 GDPR
Article 83(1) GDPR
Article 83(5)(a) GDPR
§ 30 DSG
Decided: 25.10.2024
Published: 25.10.2025
Parties: Datenschutzbehörde (DPA)
A political party (Controller)
Recipients of emails (data subjects)
National Case Number/Name: W108 2285546-1/22E
European Case Law Identifier:
Appeal from: DSB (Austria)
D550.688 2023-0.615.432
Appeal to: Not appealed
Original Language(s): German
Original Source: RIS (in German)
Initial Contributor: avalang

A court partially upheld a fine against a controller for violating Article 9(1) GDPR by disclosing recipients’ political opinions through an open email distribution list.

English Summary

Facts

The controller was a political party, the data subjects were recipients of two campaign emails.

On 22 November 2021, a staff member of the controller sent two emails with attached “open letters” as part of a political campaign, using an open distribution list in the “To” field instead of using blind copy (BCC). Each email exposed around 400 email addresses, including at least 100 personalised addresses showing first and last names. The controller had collected the email addresses from publicly accessible sources and relied on legitimate interest under Article 6(1)(f) GDPR for the processing, instead of asking for consent.

On 4 December 2021, the controller notified the DPA of the personal data breach.

On 22 April 2022, in separate supervisory proceedings, the DPA found that the controller had unlawfully disclosed political opinions through the open distribution list. Subsequently, it initiated administrative fine proceedings. On 14 December 2023, the DPA imposed a fine of €50,700 under Article 83(5)(a) GDPR for infringements of Article 5(1)(a) and (c) GDPR and Article 9(1) GDPR.

The controller appealed to the court. It argued that the email addresses did not reveal political opinions, that § 30 DSG required attribution to a natural person in a leadership position, and that the fine was disproportionate.

Holding

The court partly upheld the appeal and amended part of the decision.

First, the court held that the combination of the personalised email addresses and the political content attributed a political opinion to at least part of the recipients. By making the distribution list visible to all recipients, the controller disclosed special categories of personal data within the meaning of Article 9(1) GDPR and no exception under Article 9(2) GDPR applied. Legitimate interests under Article 6(1)(f) GDPR can not justify the processing of special categories of data.

Second, the court confirmed a violation of Article 5(1)(a) GDPR (lawfulness) and Article 5(1)(c) GDPR (data minimisation). The controller could have used BCC as a milder, equally successful option. Using an open list was not necessary for the campaign’s purpose.

Third, regarding attribution and fault, the court followed the CJEU’s interpretation of Article 83 GDPR in Case C-807/21. It held that a fine against a legal person does not require prior identification of a specific natural person under national law. The conduct of the employee was attributable to the controller.

Finally, the court reassessed proportionality under Article 83 GDPR. It took into account the seriousness of the infringement, the number of affected data subjects, the financial situation of the controller and mitigating factors, including cooperation and the absence of prior infringements. It reduced the fine from the previous €50,700 to €28,000.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the German original. Please refer to the German original for more details.

Postal address:

Erdbergstraße 192 – 196

1030 Vienna

Tel: +43 1 601 49 – 0

Fax: +43 1 711 23-889 15 41

Email: einlaufstelle@bvwg.gv.at

www.bvwg.gv.at

Date of decision

October 25, 2024

File number

W108 2285546-1/22E
IN THE NAME OF THE REPUBLIC!

The Federal Administrative Court, presided over by Judge Mag. BRAUCHART,

and with lay judge Dr. FELLNER-RESCH and the expert lay judge
Mag. KUNZ as assessor, on the appeal XXXX, represented by

SUMMEREDER PICHLER WÄCHTER Rechtsanwälte GmbH, against the penalty order of the

Data Protection Authority of December 14, 2023, file no. D550.688 2023-0.615.432, after oral
hearing, the following judgment is rendered:

A)

I. The appeal is partially granted pursuant to Section 50 Paragraph 1 of the Administrative Court Procedure Act (VwGVG), and the
contested penalty order is amended to the effect that

a) its operative provisions read:

“XXXX, in its role as controller pursuant to Article 4 No. 7 GDPR, unlawfully processed special categories of personal data within the federal territory of

Austria on November 22, 2021, at
5:05 p.m. and at 5:18 p.m. (hereinafter referred to as the “period of the offense”).” Within the meaning of Article

4 No. 1 in conjunction with Article 9 Paragraph 1 GDPR (special categories of personal data)
processed by sending two different emails during the relevant period from Ms. XXXX (in her role as "Office Manager" of the XXXX Federal Office XXXX) with the sender address "XXXX" using an open email distribution list, each containing 400 email addresses, including at least 100 personalized email addresses.

In addition to the email addresses, the political opinions and ideological convictions of the data subjects were also disclosed to the recipients of at least 100 email addresses within the distribution list due to the content of the emails.
... and - 2 -

b) the imposed penalty is reduced to EUR 28,000.00.

II. Pursuant to Section 64 Paragraph 1 of the Administrative Penalties Act (VStG), the appellant is required to pay a contribution to the costs of the proceedings before the respondent authority in the amount of

EUR 2,800.00, which is 10% of the

now imposed penalty.

III. Pursuant to Section 52 Paragraph 8 of the Administrative Court Procedure Act (VwGVG), the appellant shall not bear any costs of the

administrative court proceedings.

B)

The appeal on points of law is inadmissible pursuant to Article 133 Paragraph 4 of the Federal Constitutional Law (B-VG).

Grounds for the decision:

I. Procedural history and facts:

1. On November 23, 2021, a submission was received by the Data Protection Authority (DSB, respondent authority before the

Federal Administrative Court) stating that the appellant, a

political party, had issued a I sent an email which contained the email addresses of all recipients, visible to everyone, including email addresses with the first

and last names of some recipients. The email also included two open letters,

suggesting that all the listed email addresses, institutions, and named individuals were part of the complainant's campaign.

2. The respondent authority subsequently initiated an official review procedure (“data protection review”) pursuant to Articles 57 in conjunction with 58 in conjunction with Article 22

General Data Protection Regulation (GDPR) under reference number D213.1503 and, by letter

dated November 30, 2021, requested the complainant to submit a statement.


The email was also accompanied by two open letters,

suggesting that all the listed email addresses, institutions, and named individuals were part of the complainant's campaign.

2. The respondent authority subsequently initiated an official review procedure (“data protection review”) pursuant to Articles 57 in conjunction with 58 in conjunction with Article 22

General Data Protection Regulation (GDPR) under reference number D213.1503 and, by letter

dated November 30, 2021, requested the complainant to submit a statement. 3. On December 4, 2021, the complainant reported the following breach of the protection of personal data pursuant to Article 33 GDPR: As a result of sending an

email to a large group of recipients on November 22, 2021, a
breach of confidentiality occurred. An employee of the complainant

erroneously and contrary to instructions, used an

open email distribution list visible to all recipients to send the email. As a result of this action - 3 -

the categories of personal data "first and last name", "email address",

"employer of the data subject", and "management or employer position of the data subject" were disclosed. The complainant's employee

sent the email to a total of 975 recipient addresses. Of these,
approximately 100 addresses contained the name of a recipient and are therefore classified as personal data due to the

identifiability of the address holder.

The complainant became aware of the breach of personal data protection through an official review initiated by the
respondent authority.

The respondent authority first contacted the complainant on December 2, 2021.

The complainant considers the risk to the rights and freedoms of natural persons arising from the breach of confidentiality to be minor.

While identification of the data subjects is possible through the disclosure of three parameters (name, email address, employer), this information is largely also visible on the websites of the companies or

departments of the data subjects and is therefore publicly accessible. The

complainant assesses the criteria of the type, sensitivity, and scope of the data as having
low sensitivity. 44 of the approximately 100 email addresses that contained personal data are

publicly accessible on the internet. The disclosed categories of
personal data primarily consist of names and email addresses, while no

special categories of personal data, no data relating to criminal offenses, no

location data, and no credit-related data are involved. The severity of the
conceivable consequences is low. Neither sensitive data is involved, nor can

the disclosed personal data be misused.

Exposure of the data subjects through the disclosure of protected information from their privacy is ruled out, as is defamation or other violations of the

right to privacy, because the disclosed personal data has exclusively

official relevance, and no adverse opinion of the other
recipients can be derived from it. The individuals concerned are

employers active in the healthcare sector or their employees in management positions who are

contact persons for a political campaign of the complainant. Through the
disclosure, those individuals whose email addresses were not publicly accessible on the internet

have partially and slightly lost control over this data
in such a way that other addressed recipients could now contact them by email,

possibly with knowledge of their disclosed position within the company. Furthermore,

no restriction of the rights and freedoms of the individuals concerned is to be expected.

Neither sensitive data is affected nor is it to be assumed that other recipients - 4 -

will now misuse the disclosed data. The disclosure

of the email address is not to be expected to result in any exposure, discrimination, or similar harm.

The complainant has commissioned an external data protection officer to evaluate

the data processing procedures within the party. This should be done to conduct a review of all data processing activities in order to identify and mitigate potential risks early on.

Furthermore, the complainant has implemented a CMS system.

This will be used in the future for sending emails addressed to multiple recipients.

The complainant's employees involved in political campaigns are trained in the principles of data protection.

The complainant does not expect that the recipients of the disclosure will use the received email addresses to contact other recipients without their consent.

The recipients all belong to the same market. Therefore, it is not expected that one recipient will conduct marketing activities against another.

Recalling the sent email addresses is technically impossible.

Sending another email to the same recipients with a note not to use these email addresses for marketing purposes or similar could, at best, have the opposite effect and create the very idea. The complainant therefore decided not to

send any further emails to the same recipients in order to avoid increasing the adverse
effects. Because no other possible adverse

effects were conceivable, the complainant did not consider or take any further measures.

4. On January 7, 2022, the complainant submitted a statement explaining that

as the data controller within the meaning of Article 4(7) GDPR, the complainant had

collected and stored the email addresses in question from party members and used them on
November 22, 2021, for the purpose of a political campaign to send the letter dated

November 22, 2021. Due to the negligence of an employee,

these email addresses were disclosed in breach of confidentiality, which the
complainant reported to the respondent authority on December 4, 2021, pursuant to Article 33 of the GDPR.

The complainant processed the first and last name, email address, and

employment details (employer, industry, position) based on a legitimate interest within the meaning of Article 6(1)(f) of the GDPR (promotion of political interests).

As can be seen from the letter of November 22, 2021, the complainant pursued the purpose of influencing the government's decision-making process, specifically targeting the addressed members of the Federal Government, state governors, and state health ministers.

In order to lend the announcement of an impending strike to the Federal Ministry and other decision-makers the necessary political weight, the complainant was compelled to inform other decision-makers in the health sector as well as the press. For this purpose, the complainant was also entitled to process the aforementioned personal data of these decision-makers at the political level, in the health sector, and in the press, provided that this did not conflict with overriding interests of the data subjects.

The balancing of interests favors the complainant, since only data from the professional sphere was involved and most of the processed personal data is publicly available.


No overriding confidentiality interests exist. The processing of the aforementioned
categories of personal data only affects, at most in the abstract, the control of the

data subjects over their data, but poses no further risks to

their rights and freedoms: For example, there is no risk of exposure of the
most private sphere of life, nor are there any economic disadvantages,

such as those that arise from the processing of credit-related data.


5. By decision of the respondent authority dated April 22, 2022, file number D213.1503 2022-0.016.020,
the authority decided on the ex officio review procedure as follows:

"The controller violates the GDPR by unlawfully disclosing personal data in the form of personalized email addresses, insofar as a specific or identifiable personal reference can be derived from the email addresses, or insofar as they are not generic email addresses, through the sending of the emails of November 22, 2021, at 5:05 p.m. and 5:18 p.m. in an open email distribution list, and thereby unlawfully publishing the political opinions of the data subjects due to the lack of a legal basis for processing pursuant to Article 9(2) GDPR, by making them visible to other recipients. The controller is hereby ordered to cease and desist from this processing." With immediate effect, the processing of the aforementioned personalized email addresses without the consent of the data subjects within the meaning of Article 9(2)(a) GDPR is prohibited in the future.

This decision became legally binding due to the lack of an appeal.

6. Subsequently, the respondent authority initiated administrative penalty proceedings against the appellant and XXXX (hereinafter: Dr. N.C.) as the appellant's chairman.

By letter dated August 16, 2022, it requested the Federal Ministry of the Interior,

Department III/3, to provide the appellant's statutes, filed pursuant to Section 1(4) of the Political Parties Act, by way of administrative assistance.

7. By letter dated August 19, 2022, the Federal Ministry of the Interior transmitted the appellant's statutes. - 6 -

8. The respondent authority informed the complainant by letter dated August 23, 2022,

that it was suspected, as the data controller, of having unlawfully processed personal data of data subjects on November 22, 2021, at 5:05 p.m. and at
5:18 p.m. (hereinafter referred to as the “period of the offense”) in XXXX, by sending two different emails
from Ms. XXXX (hereinafter: Mag. B.H.) with the sender address “XXXX” in her role as

“Office Manager” of the complainant (Federal Office XXXX) to an open

email distribution list, each containing approximately 400 email addresses, to [specifically named]
recipients, thereby constituting administrative offenses under Art. 5 para.

1 lit. a and c as well as Art. 9 para. 1 in conjunction with Art. 83 para. Articles 1 and 5(a) of the GDPR,

and requested justification.

9. On September 19, 2022, the complainant submitted a statement in which

it was explained that the complainant had arranged for comprehensive instruction from Mag. B.H.

and her immediate superiors to ensure the prevention of such
incidents in the future. Measures had been implemented within the complainant's administration

to ensure the necessary due diligence in the future and guarantee

control by immediate superiors when sending emails.

All email addresses related to the incident had been deleted from the complainant's IT and email systems.

The statement included confirmation of the complainant's financial status for the year 2021 at the time of the incident.

10. At the request of the respondent authority, the appellant submitted a statement of current assets of EUR 123,353.57 on

September 29, 2022, and a statement of total income for 2022 from

membership fees and donations amounting to EUR 851,120.89 on

October 24, 2022.

11. By decision of the respondent authority dated October 27, 2022, file number D550.688 2022-0.770.555,

the proceedings were suspended pursuant to Section 24 of the Administrative Penalties Act (VStG) in conjunction with Section 38 of the General Administrative Procedure Act (AVG) pending a final and binding decision

by the Court of Justice of the European Union (CJEU) in Case C-807/21.
... 12. By decision of the respondent authority dated December 5, 2023, file number D550.688 2023-0.804.939,

the decision of the respondent authority dated October 27, 2022, was set aside following the publication of the
judgment of the CJEU in the aforementioned preliminary ruling case, and the proceedings were

continued. - 7 -

13. On December 14, 2023, the respondent authority issued a notification of the discontinuation

of the administrative penalty proceedings against Dr. N.C. as chairperson of the accused
appellant.


14. In the now contested penalty order of the same date, the respondent authority stated that the appellant had committed the following offense and

thereby committed the following administrative offence:

“XXXX, in her role as data controller pursuant to Article 4(7) GDPR, unlawfully processed special categories of personal data within the meaning of Article
4(1) in conjunction with Article 9(1) GDPR (special categories of personal data)

by sending two different emails from Ms. XXXX (in her role as “Office Manager” of the XXXX Federal Office XXXX) with the sender address “XXXX” using an open email distribution list, each containing 400 email addresses, within the federal territory of Austria on November 22, 2021, at 5:05 p.m. and 5:18 p.m. (hereinafter referred to as the “period of the offense”). were sent. In addition to the email addresses, the political opinions and ideological convictions of the

data subjects were also disclosed to the recipients on the distribution list due to the content of the emails. As a result, XXXX processed special categories of personal data contrary to the legally mandated prohibition under Article 9(1) GDPR and without an exception or legal basis under Article 9(2) GDPR.


[The sentence is incomplete in the original text.] The complainant has therefore, as a result, processed a special category of
sensitive personal data pursuant to Art. 4(1) in conjunction with Art. 9(1) GDPR (here,

specifically, political opinions and philosophical beliefs) contrary to the
prohibition of processing under Art. 9(1) GDPR and without an exception under

Art. 9(2) GDPR, as well as the principle of processing

personal data lawfully, fairly and in a transparent manner in relation to the data subject pursuant to Art. 5(1)(a) GDPR

“lawfulness, fairness and transparency”) and the principle

of processing of personal data that is adequate, relevant and limited to what is necessary for the purposes of the processing

pursuant to Art. 5(1)(c) GDPR (“data minimization”).


An administrative offense pursuant to Article 5(1)(a) and (c) and Article 9(1) in conjunction with Article
83(1) and (5)(a) GDPR has been committed.

For this administrative offense, a fine of EUR 50,700.00 is imposed pursuant to Article 83(5)(a) GDPR.

Furthermore, the appellant is required to pay a contribution of EUR

5,070.00 towards the costs of the proceedings pursuant to Section 64 of the Administrative Penal Code.

The total amount payable (fine/costs/out-of-pocket expenses) is therefore EUR 55,770.00.

The respondent authority made the following findings of fact:

"1.2. Regarding the sending of the emails in question, including attachments

On November 22, 2021, an employee of XXXX (Ms. XXXX in her role as

"Office Manager" of the Federal Office XXXX) sent two
different emails at 5:05 p.m. and 5:18 p.m. using an open email distribution list, each containing approximately 400
email addresses. These included personalized and some private
email addresses (e.g., "@gmail.com").

"Open Letters" were attached to each email and referenced.

XXXX alone made the decision regarding the form and sending of the aforementioned emails.

The email distribution list was a distribution list of XXXX." The email addresses were collected by party members and used for the purpose of a political campaign within the context of the emails in question.

The content of the political campaign, or rather both emails, consisted of two attached PDF files, titled "XXXX" and "XXXX".

The PDF file titled "XXXX" contained the following (formatting not reproduced verbatim):

The PDF file titled "Open Letter XXXX" contained the following (formatting not reproduced verbatim):

1.3. Income and Assets of the Accused

XXXX generated a total of EUR 851,120.89 in income from membership fees and donations. Furthermore, in 2022, XXXX received - 9 -

party funding in the amount of EUR 1,200,000 and has assets totaling EUR 123,353.57 (as of September 29, 2022).

Legally, the respondent authority found that the complainant had unlawfully processed sensitive data

by sending the emails in question

on November 22, 2021, the complainant processed personal data by

disclosing, among other things, the personalized email addresses of the

data subjects to all persons and institutions listed on the distribution list, thereby disclosing the names and, in some cases, the workplace/employer of the
data subjects to multiple recipients. This alone constituted

an infringement of the fundamental right to privacy of the data subjects under Section 1, Paragraph 1 of the GDPR.1 GDPR. In this specific case, in addition to these data categories or information,

the political opinions and ideological convictions of the data subjects were also disclosed to the recipients listed in the distribution list. The content of the emails in question, in conjunction with the purpose of the processing (conducting

a “political campaign”), attributed a political opinion and ideological conviction to the data subjects and, consequently, disclosed them to all recipients through the distribution of the emails to an open distribution list. The processing of special categories of personal data pursuant to Article 9(1) GDPR is generally prohibited.

Exceptions to the prohibition on processing are set out in Article 9(2) GDPR. The complainant based the processing solely on legitimate interests pursuant to Article 6(1)(f) GDPR, which do not constitute an exception for the processing of sensitive data pursuant to Article 9(1) GDPR. In this specific case, there was also
no consent from the data subjects within the meaning of Art. 4 No. 11 in conjunction with Art. 7 in conjunction with Art. 9 para. 2 lit. a

GDPR, and the complainant did not claim such consent.

The remaining exceptions in Art. 9 para. 2 GDPR are also not applicable to the

specific processing. Finally, with regard to the

principle of data minimization pursuant to Art. 5 para. 1 lit. c GDPR, it can be pointed out that in the
specific case, the necessity of the processing in question cannot be seen.

The complainant could have conducted her political campaign without using

an open distribution list. Transmission via "blind carbon copy" (BCC) would have achieved the desired result just as well. Therefore, the processing also occurred in

disregard of the principle of data minimization, as it was not

appropriate and relevant to the purpose and was limited to what is necessary for the purposes of the processing. Thus, the objective elements of a violation of the

principles for processing under Article 5(1)(a) and (c) GDPR and the

prohibition of processing under Article 9(1) GDPR were fulfilled. - 10 -

Regarding the appellant's criminal liability as a legal entity under Article 83 GDPR,

it should be noted that the Administrative Court, in its ruling of May 12, 2020, Ro
2019/04/0229, addressed for the first time the applicability of the conditions for criminal liability under Section 30

Data Protection Act (DSG) in proceedings under Article 83 GDPR and, in this context, established that a legal entity cannot act on its own

and therefore its criminal liability under Section 30 DSG is a consequence of the factual,

unlawful, and culpable conduct of a natural person (managing director) within the meaning of Section 30(1) DSG. However, the CJEU ultimately ruled in its judgment of December 5, 2023,

that the directly applicable provisions of Article 58(2)(i) and

Article 83(1) to (6) GDPR must be interpreted as precluding a national regulation
under which a fine for an infringement referred to in Article 83(4) to (6) GDPR against a legal person in its capacity as controller

can only be imposed if that infringement has previously been attributed to an identified natural person. Consequently, the provisions of Section 30(1) and (2) of the GDPR are not applicable, as they would, in light of the CJEU's judgment,

contrary to Article 83(1) to (6) GDPR by establishing (additional) substantive requirements for imposing a fine on

a legal person.



``` The subjective element of the offense is also fulfilled, as culpability in the form of intent (Art. 83 para.

2 lit. b GDPR) exists. In the course of the investigation, no

indications emerged to suggest that the complainant was not at fault for the violation of the applicable administrative regulations.

In light of the case law of the CJEU regarding the

unlawfulness of her conduct, the complainant could not have been unaware, regardless of whether she was aware that she was violating the provisions of the GDPR.

The complainant's assertion that there was culpability in the form of negligence on the part of an

employee is a mere pretext. Taking into account the purpose
of the processing or the planned political campaign and in conjunction with the

specific content of the email messages, the respondent authority concludes that the complainant made a conscious

and deliberate decision to send the emails in question, including attachments, to an open distribution list. In essence, these messages

in summary, the complainant claims to have found “countless like-minded individuals” in the health and care sector who wish to oppose the mandated vaccination,

and this is apparently to be illustrated to the recipients of the message through the open distribution list containing numerous (partly

private, partly work-related) email addresses. In conjunction with the specific

wording of the message (for example, "We, healthcare workers..."; "We stand up against the discrimination of us, healthcare workers"; "We have found

countless like-minded individuals in our profession, or more precisely, we have networked"; "WE ARE MANY"; "All of us are prepared to stop working and

go on strike..."; "Finally, we would like to inform you that we have received notification from numerous

healthcare professionals that they will stop working with immediate effect in the event of mandatory vaccination," etc.), the

authority in question concludes that the complainant acted intentionally. The

concluding part of the message also makes it clear that the complainant intended to convey to the recipients that she was signing the message on behalf of numerous

healthcare and nursing staff from all federal states.


This was to be illustrated by the open distribution list and the personalized email addresses it contained. Objectively speaking, this was intended to create the impression that the individuals listed on the distribution list were opposed to the mandatory vaccination and were prepared to stop working. Based on this, the respondent authority concluded that there was intent to commit the offense, and therefore the subjective element of the offense was fulfilled.

Regarding sentencing, the respondent authority stated that it had applied the EDPB Guidelines

on the calculation of administrative fines under the GDPR (see EDPB Guidelines 04/2022 on the calculation of administrative fines under the GDPR, Version 2.1 of 24 May 2023 – hereinafter also referred to as the “Fines Guidelines”). The complainant

generated income from membership fees and donations totaling EUR

851,120.89 and also received party funding in the amount of EUR

1,200,000.00. Applying the Fines Guidelines, the complainant is classified

in the second-lowest category (“Undertakings with a turnover of €2m up to €10m”) with regard to its income and the imposition of an effective,

dissuasive, and proportionate fine. This classification

ensures, in particular, the proportionality of the fine.


In light of the facts deemed proven and taking into account the nature,
severity, and duration of the infringement (Art. 83 para. 1 lit. a GDPR), the intentionality or

negligence of the infringement (Art. 83 para. 2 lit. b GDPR), and the categories of
personal data affected by the infringement (Art. 83 para. 2 lit. g GDPR),

the authority concerned determined the severity of the infringement to be a high

degree of severity. No aggravating circumstance was considered in determining the penalty; the intensity of the impairment or the interference with the fundamental right of the

data subject to confidentiality had already been taken into account when determining the degree of severity. The following factors were taken into account as mitigating circumstances in determining the sentence:

the complainant had no prior relevant GDPR violations at the respondent authority,

the complainant cooperated in the

investigation proceedings before the respondent authority and thereby

contributed to establishing the truth, in particular by not denying the
alleged facts and by showing remorse after being served with the

request for justification, and the fact that

the complainant promptly informed the respective employees and, moreover, deleted the email addresses and the distribution list in order to prevent such

mailings in the future.


The complainant also took into account the following mitigating factors:


The complainant had no prior relevant GDPR violations at the respondent authority,

the complainant cooperated in the

investigation proceedings before the respondent authority and thereby

contributed to establishing the truth, in particular by not denying the
alleged facts and by showing remorse after being served with the request for

justification, as well as the fact that

the complainant promptly informed the respective employees and, moreover, deleted the

email addresses and the distribution list in order to prevent such

mailings in the future.



The complainant cooperated in the

investigation proceedings before the respondent authority and thereby

contributed to establishing the truth, in particular by not denying the
alleged facts and showing remorse after being served with the respondent authority.


The complainant also cooperated in the

investigation proceedings before the respondent authority and thereby

contributed to establishing the truth, in particular by not denying the
alleged facts and by showing remorse after being served with the respondent authority.


The complainant also took into account the fact that

the complainant had no prior relevant GDPR violations at the respondent authority and thereby made a contribution to establishing the truth, in particular by not denying the
alleged facts and by showing remorse after being served with the respondent authority.


The complainant cooperated in the

investigation proceedings before the respondent authority and The imposition of the fine was not necessary in the sense of specific deterrence, but rather in the sense of general deterrence, in order to raise awareness among those responsible, in particular

other political parties, regarding the legally compliant sending of emails using

a distribution list and the associated obligations under
the GDPR, especially when this involves the processing of sensitive data of data subjects.

The resulting fine of EUR 50,700.00 therefore appears proportionate to the offense and the degree of culpability,

in light of the actual harm committed, and measured against the available

penalty range under Article 83(5) GDPR (here up to EUR 20,000,000.00), and is at the very lower end of the available

penalty range (0.25% of the penalty range).

15. The appellant filed a timely appeal against this penalty order with the Federal Administrative Court pursuant to Article 130(1)(1) of the Federal Constitutional Law (appeal by a party),

arguing the following: The penalty order issued by the respondent authority is challenged on the grounds of

illegality of content and violation of essential procedural rules.

The appellant had not violated any provisions of the GDPR,

or at least, the appellant was not responsible for any potential violation due to lack of fault.

The appellant had lawfully processed the approximately
400 email addresses of data subjects at issue in the proceedings.

The conclusion that these email addresses constitute special categories of personal data pursuant to Article 9 of the GDPR is incorrect. For the recipients of the letter

the list of recipients (distribution list) does not indicate which political - 13 -

conviction a particular person belongs to, since it includes, on the one hand,

political officeholders, on the other hand, the press and public, as well as certain individuals close to the petition. Without further indications, it is impossible for

an individual recipient to infer the political
orientation or worldview of other recipients. Members of various

parties were among the recipients of the letter, and there is also a discrepancy between

the number of recipients and the number of signatories of the petition. A complete link to the effect that all persons on the distribution list are

members/supporters/signatories of the petition and thus of the complainant

cannot be established for these reasons alone.

Even assuming that special

category personal data was processed, the complainant cannot be held responsible for the violation. The employee, Ms. B.H., who sent this letter to the distribution list,
had only been hired a few weeks prior as an assistant to the complainant and the

state organization XXXX. At the time of sending the

letter, she was unaware that its transmission to the distribution list, which contained personal data, might, through its connection to the

other content of the letter, indirectly reveal the political opinions and
ideological convictions of the individuals named therein. She

would not have sent the letter to the distribution list without further consideration, but would

have paid particular attention to this circumstance before sending it and clarified beforehand whether any further necessary steps were required. In any case, the letter was sent due to

excusable misconduct by an employee – who had previously been explicitly instructed during her onboarding to comply with data protection measures within the company, namely
both in handling the personal data of colleagues and

in handling other personal data of other persons (e.g., members,

supporters, donors, etc.).

The complainant considers compliance with data protection regulations extremely important as a political party, which is why all employees are

sensitized to data protection during the hiring process and subsequently through regular training, and are obligated to comply with corresponding measures.

The complainant was unaware that the employee would send this letter to all recipients on the distribution list simultaneously,

and, given the comprehensive onboarding and the obligation of all employees to comply with data protection regulations, was not required to assume this.

14 - The complainant was therefore, within the meaning of the case law of the CJEU,

uncertain about any potential unlawfulness on the part of an employee attributable to it. An excusable error by an employee cannot and should not

lead to holding the complainant accountable as the responsible party for the first breach of data protection regulations – which is still being contested –

especially not to the extent alleged.

Furthermore, the respondent authority ignores the fact that the CJEU's decision in case
C-807/21 was only issued on December 5, 2023, while the incident in question occurred on

November 22, 2021 (more than two years earlier). Accordingly, the provision of Section 30 of the Data Protection Act (DSG), which

remains valid and thus still in force, is applicable

and must be taken into account (at least with regard to the question of culpability). Mag. B.H., however, neither

held a (management) position as defined in Section 30 Paragraph 1 of the Data Protection Act (DSG) nor could the appellant be accused of

a lack of supervision or control of a management position. For this reason alone, punishment is precluded due to the lack of (attributable) fault on the part of the

appellant.

Should the Federal Administrative Court share the view of the respondent authority that the employee's conduct is attributable to the appellant insofar as

the appellant is also at fault, then at most the appellant could be considered negligent – and not intentional – which

would, of course, have a significant impact on sentencing. The respondent authority itself states in the

penalty order that punishment does not appear necessary for special preventive reasons,
especially given that the appellant has no prior administrative offense record. The mitigating circumstances significantly outweigh the aggravating circumstances, and the infringement of the legally protected interest (only an indirect connection to the political stance) is comparatively extremely minor. In

this specific case, a warning would therefore have sufficed.

In any event, the amount of the imposed fine is excessive. Previous penal practice indicates fines in the range of approximately EUR 10,000.00.

The respondent authority failed to interview the persons relevant to the present case,

despite a request to do so. Had the authority in question – in accordance with its duty to ascertain the material truth – interviewed the employees involved, Ms. B.H., Ms. XXXX (hereinafter: G.S.), and the then-chairman, Dr. N.C., it would have concluded that, firstly,

individual recipients of the letters could not be attributed to a specific political conviction or – 15 –

worldview – namely, that of the complainant, and

furthermore, that the complainant, lacking knowledge of the mailing to the entire distribution list and due to the training and obligation of all employees to comply with data protection regulations, could not be held liable for any (organizational) negligence.
... The respondent authority, with the issued penalty order, violates the complainant's

right to equality before the law pursuant to Art. 7 para. 1 of the Federal Constitutional Law (B-VG) and Art. 2 of the Federal Constitutional Court Act (StGG) by attributing an unequal content to the applicable law

and grossly misinterpreting the substantive legal provisions, as well as by arbitrarily serious

procedural defects and by ignoring the parties' submissions.

However, even if the Federal Administrative Court were to share the respondent

authority's view and conclude that the affected persons' rights to confidentiality and data protection had been violated, the respondent

authority, with its action (namely, the imposition of the administrative penalty), disproportionately infringes upon

the fundamental political rights of the complainant and her members/supporters/signatories. The complainant's activities as a

political party may not be subject to any restrictions pursuant to Section 1 of the Political Parties Act. This includes
the sending of any letters conveying the collective opinion of

like-minded individuals (here: approximately 9,000 signatories of the petition) to persons who hold a different

political stance/opinion.

16. By letter dated January 22, 2024, the respondent authority submitted the complaint, along with the relevant files of the

administrative penalty proceedings (including the administrative files relating to the official review procedure

[D213.1503]), to the Federal Administrative Court for a
decision and issued a statement defending the contested

decision and arguing that the alleged training measures and

agreements in the employment contract were irrelevant due to the non-application of Section 30 Paragraph 2 of the Data Protection Act.

The appellant misunderstands the legal situation regarding the applicability of Section 30 of the Data Protection Act (DSG).

Decisions of the CJEU have retrospective effect, create objective law, and

extend beyond the initial legal dispute to the effect that all courts and administrative authorities of the Member States must comply with the interpretation made by the CJEU.

The CJEU has made it unequivocally clear that no action, and not even knowledge of the infringement, on the part of the governing body of a

legal person is required (see CJEU of 5 December 2023, C-807/21, paragraph 77).

This is not altered by the appellant's argument that, due to the

mentioned measures, she was "uncertain about any potential illegality on the part of an employee attributable to her". Whether the culpability was in the form of intent or

negligence is not decisive for the appellant's criminal liability or the fulfillment
of the subjective element of the offense.

The argument regarding the alleged violation of the freedom to form and operate

political parties is limited to general statements and fails to provide a detailed explanation as to how the sending of the two emails in question via an open distribution list was necessary for the exercise of the freedom

“freedom of operation” as a political party. The complaint is also internally contradictory in this respect. On the one hand, the

complainant argues that no intent can be attributed to her because the sending via an open distribution list occurred due to the

misconduct of an employee (thus admitting that sending via a distribution list was not necessary), and on the other hand, it is necessary

and must be possible for the complainant, as a political party, to send such messages via an open distribution list for the purpose of conducting a political campaign in order to exercise her rights as a

political party.
... Regarding the alleged procedural errors, it should be noted that the appellant,

during the investigation in the administrative penalty proceedings, only submitted a brief

justification and limited herself to the bare essentials. Neither during the
administrative penalty proceedings nor during the official review proceedings did the

appellant request the examination of the aforementioned persons. Regardless,

the alleged procedural errors are not relevant. Even if the

corresponding findings had been made, the issue of proof raised by the
appellant would not have led to a different outcome (dismissal or

warning). The question of whether the sending of the emails in question constituted the
disclosure of sensitive data arises from the email messages themselves and

is, moreover, a legal question. The argument/argument that there was no

organizational negligence and that the employee's conduct could therefore not be attributed to the
complainant is irrelevant for the reasons stated above.

Regarding the argument that the fine is "excessive" and that the respondent

authority imposed a fine of EUR 10,000 (against a natural person) in a more specifically cited "much worse case" (DSB-D550.185), it should be noted that a reference to other penalty rulings (regardless of the fact that the
cited case is not comparable) is irrelevant, since a supervisory authority, when

imposing a fine pursuant to Article 83(1) GDPR, must ensure that the fine is effective, proportionate, and dissuasive in each individual case. The

respondent authority carried out such an individual assessment and also applied the

Fines Guidelines of the EDPB.

17. The Federal Administrative Court forwarded the respondent authority's statement submitted with the case file to the appellant for her information and

response.

18. On February 19, 2024, the appellant submitted a statement in which she

reiterated her arguments from the party appeal and stated that the respondent

authority again failed to recognize that the provision of Section 30 of the Data Protection Act (DSG), which remains in force and is therefore applicable,

must be taken into account accordingly (at least with regard to the question of culpability). However, even the decision of the CJEU in Case C-807/21 cited by the respondent authority is being misinterpreted by it. Because, according to this decision, only a culpable violation leads to

the imposition of a fine. This is the case if the responsible party (here: the
appellant) could not have been unaware of the unlawfulness of their conduct.

In this context, the respondent authority continues to fail to provide

justifications as to why data protection training measures and
contractual obligations to comply with data protection regulations are insufficient to

conclude the lack of awareness regarding any potential unlawfulness on the part of an employee attributable to the appellant.


19. In a letter dated August 14, 2024, the appellant further argued that the

admitted error by Mag. B.H. could not automatically lead to a penalty for the

appellant, particularly if no systematic deficiencies or
organizational shortcomings could be demonstrated. The appellant took all

necessary measures to prevent such an incident, therefore

no fault can be attributed to her.

Attached to the written submission was the data protection and

confidentiality declaration signed by Mag. B.H. on November 1, 2021. - 18 -

20. The Federal Administrative Court held a public oral hearing in the present data protection

matter, in which the
appellant, her legal representatives, and the respondent authority participated.

Furthermore, two employees of the appellant, Mag. B.H. and G.S.,

as well as the former chairman of the appellant, Dr. N.C., were heard as witnesses.

The witness Mag. B.H. stated in particular that she had been employed as a

secretary by the appellant from November 2021 to January 2023. The two emails in question, dated November 22, 2021, were sent by her on the instructions of G.S.

G.S. came in and presented her with a letter addressed to the

healthcare staff. She couldn't remember now whether it was in paper form or as an email; she believed it was an email. G.S. said, "There's a letter; we'll send it to the

healthcare staff by email." Then G.S. gave her an electronic list with

approximately 800 to 1,000 email addresses to which the letter was to be sent.

G.S. and she went through the letter again to check that everything was correct in terms of spelling.

She then sent the letters to all the recipients on this list,

as instructed. She made a mistake in the process. It was
a somewhat stressful situation. Normally, one would send it in blind copy, "bcc,"

but she made a typo and sent the emails in "cc." She believes she entered herself as the recipient. From the next day onward, there were

various responses; there were also approximately 15-20 responses

from people who no longer wanted to be on the distribution list. The distribution list was subsequently discontinued. Some people explicitly

said they wanted nothing to do with the complainant and wanted to receive nothing from her.

Whether the issue of "cc" and "bcc" had been discussed prior to sending the emails, she could no longer say; that was three years ago.

Witness G.S. stated in particular that she currently held no position with the complainant

at the time of the incident, she was the complainant's deputy secretary. She had received the addresses electronically from XXXX (hereinafter: Dr. P.), the managing director

and federal finance officer, printed them out and gave them to Mag. B.H. for processing.

She showed her on the computer how to send emails with "bcc,"
Blind Copy. She no longer remembers who gave her this instruction.

Mag. B.H. was supposed to type in the addresses. It took her an extremely long time, and
at some point, Mag. B.H. came to her and said, "I've done it," and

went home. She no longer remembers how many addresses were on the list

or whether she also forwarded the email with the addresses to Mag. B.H. She is - 19 -

no longer sure what exactly was supposed to be sent, but she believes it was an open letter

to the Minister of Health or the healthcare personnel. Before sending it, she apparently didn't proofread the letter
with Mag. B.H.

The witness Dr. N.C. stated that he was a co-founder and, from February 14, 2021, to January 12, 2022, the federal party chairman of the complainant. The federal executive committee had

decided that these messages should be sent, but he had not actually carried out the sending himself.

As far as he could remember, the addresses had come from Dr.

P., who had assured him that they were all official email addresses that could

also be found on the internet. He himself had not concerned himself with the addresses; his

task had been political work. Besides, the mailing should, of course, have been done in such a way that the addresses were not visible, if only for reasons of

discretion and courtesy. It is self-evident and does not need further discussion that such things are sent via blind copy. Whether it was specifically discussed, he no longer knows today. As far as he knows, approximately two recipients complained.

The complainant then tried to rectify everything.

The respondent authority stated that the complainant had attempted, through the requested witnesses, to create the impression that there was no organizational negligence

within the complainant. However, she fundamentally overlooked the fact that this is irrelevant. The respondent authority had already explained

that criminal liability does not depend on Section 30 Paragraph 2 of the Data Protection Act. Ultimately, the culpability of the

complainant must be assessed based on the actions of Mag. B.H. Her conduct is directly attributed to the legal entity, even without organizational negligence.

The complainant does not dispute the misconduct of Mag. B.H. With regard to the subjective element of the offense, it should be noted that
intent is not a necessary element of the offense. The appellant's argument

that extraordinary mitigating circumstances exist within the meaning of Sections 19 and 20 of the Administrative Penal Code (VStG)

is also without merit, since the CJEU, in its judgment C-807/21, unequivocally

held that the substantive requirements for a fine are conclusively regulated in

Article 83(1) to (6) GDPR. Finally, attention should be drawn to the

accountability of the appellant under Article 5(2) GDPR, which

has not been fulfilled in any way here.

The complainant stated that she currently possesses no assets. The party's expenses
are covered by third parties. The complainant currently receives no party funding

because it is not represented in any parliament. In 2024, the complainant received membership fees totaling EUR

70,000.00 from approximately 2,400 individuals; these funds have been entirely spent. Party funding for the XXXX, a separate legal entity, amounted to EUR 1.2 million for the year 2024.


The complainant's legal representative referred to the previous submissions and
reiterated that the complainant had not processed any special categories

of personal data, since the recipients of the

emails – contrary to the apparent assumption of the respondent authority – were not
exclusively political supporters of the complainant, but

also included persons notorious in the courts as belonging to other political parties, as well as

journalists and other public figures. It is therefore not possible to infer a person's political orientation from their
email address, which is why a

violation of Article 9 GDPR is impossible. The respondent authority also failed to make any finding regarding a political conviction in its

penalty order. The facts established by the authority are therefore insufficient in themselves to support the cited

judgment. The annulment of the penalty order and the discontinuation of the

proceedings pursuant to Section 45 of the Administrative Penal Code are requested.

21. By letter dated October 3, 2024, the complainant submitted evidence of her

current income and assets.

22. On October 15, 2024, the respondent authority issued a statement regarding the

documents submitted by the complainant, arguing that it should be taken into account that

the complainant does not generate "turnover" in the classical sense (the sum of all income
from the sale of goods or services), but primarily income

from membership fees, donations, and statutory subsidies (party funding).

The submitted "turnover lists" were from the current and not yet completed year (reference period 2024). However, the wording of Article 83(5)

GDPR indicates that only the complainant's income

in the preceding (completed) year is relevant. The documents submitted by the complainant were therefore already irrelevant. The account balance cited also does not constitute the decisive basis for any potential sentencing by the adjudicating panel. The wording and structure of Article 83(2) GDPR indicate that the primary focus is on the established infringement and its severity, and no subjective right to the imposition of a "minimum penalty" can be inferred from the cited account balance. Regardless, the respondent authority disputes that the submitted - 21 -

transaction statements represent all of the complainant's income in the form of

membership fees, donations, and party subsidies in the previous year. With regard to statutory party subsidies, it is common knowledge that the complainant's state organization in XXXX receives EUR 1.2 million annually in party subsidies. There can be no talk of two separate entities here.

There are obvious interconnections. For example, the

appellant is represented externally by the members of the XXXX State Parliament, and the public data protection declaration of the XXXX organization states

that the appellant is the controller within the meaning of Article 4(7) GDPR for the processing of personal data.

II. The Federal Administrative Court considered the following:

1. Findings:

1.1. The statements above under point I. regarding the procedural history (administrative proceedings) are established.

1.2. The appellant is a political party active in Austria and Europe, headquartered

in XXXX. The appellant constitutes the party's federal organization; in addition, there is a state organization with its own legal personality for each Austrian federal state, with personnel and organizational interconnections. The
current federal party chairman of the complainant, XXXX, is also

state party chairman of the complainant's state organization in XXXX (XXXX), the

deputy federal party chairman, XXXX, is also XXXX member of the state parliament for
XXXX, and the federal organization's finance officer, XXXX, holds the office of

parliamentary group chairman of the XXXX parliamentary group in the XXXX state parliament and is state party chairman.

There is a unified membership; every member is a member of the federal party and is also listed as a state party member, if applicable. Active members can be

elected or

sent as delegates and thus also to the bodies of the federal party executive committee. Insofar as it is necessary for the conduct of federal elections or federal political actions decided upon by federal bodies, all

institutions, functionaries, employees, and volunteers of the party and its

sub-organizations must comply with the federal party's guidelines.

1.3. On November 22, 2021, Ms. B.H., in her role as "Office Manager" or secretary,

sent two emails with attachments (two attached PDF files; "Open Letters") to the complainant for the purpose of a political campaign at 5:05 p.m. and at
5:18 p.m.

an open email distribution list visible to all recipients, each containing approximately 400 email addresses in the "To" field.

At least 100 of these were personalized email addresses, clearly displaying the recipients' full names, including both

work and private email addresses of individuals. Specifically, the following email addresses were disclosed to the following recipients:

The content of the political campaign, or rather both emails, consisted of two attached PDF files, titled "Open Letter XXXX" and "Open Letter XXXX".

The findings of fact made by the respondent authority regarding the content of the "Open Letters" under

Point I.14, Point 1.2 of the contested penalty order, form the basis of the court's findings.

The email addresses were obtained from publicly accessible sources by the former managing director and CFO of the

appellant, Dr. P. The email recipients were primarily decision-makers at both the political

level and in the healthcare sector, healthcare institutions (hospitals, senior citizens' and nursing homes, etc.), and generally individuals working in the healthcare sector (as

employees) who are not (exclusively)

party members or political allies of the complainant.

There is no consent from all affected individuals for the data processing in question, in particular for publication.

1.4. It cannot be established that, with regard to the emails at issue in these proceedings, the email addresses were deliberately placed in the "To" field and not in the "Bcc" field

before the emails and the "Open Letters" were sent to the respective recipients.

1.5. Following the sending of the emails in question, approximately 15 to 20

individuals complained to the complainant about the email(s) they had received and stated that they wanted nothing to do with the complainant and did not want to receive anything from her.

1.6. In 2022, the complainant generated total revenue of

EUR 851,120.89 from membership fees and donations. Furthermore, in 2022, the complainant received party funding in the amount of EUR 1,200,000.00 and had total assets of EUR 123,353.57 as of September 29, 2022.

The total revenue for 2022 thus amounted to EUR 2,051,120.89.


In 2024, the appellant received membership fees totaling EUR 70,000.00 from approximately 2,400 individuals. Party funding for XXXX amounted to EUR 1,200,000.00 for the year

2024. The balance of the appellant's current account at
XXXX, IBAN XXXX, was EUR 4,304.62 as of September 27, 2024.

The total revenue for the year 2024 thus amounted to EUR 1,270,000.00.

2. Evaluation of Evidence:

The findings are based on the submitted administrative documents and the

case files, in particular the transcript of the

oral hearing before the Federal Administrative Court.

In detail:

The findings regarding point 1.2. The findings are based on publicly available information
on the complainant's website XXXX (accessed on October 14, 2024) and on the –

also publicly available – statutes/bylaws of the complainant (XXXX) and

of the complainant's state organization XXXX (XXXX).

The findings regarding point 1.3 are based on the emails dated November 22, 2021, contained in the case file, the contested penalty order issued by the respondent authority,

in conjunction with the findings from the decision regarding the official review proceedings,

as well as the complainant's own submissions and the witness statements. The

sending of the emails at issue in these proceedings by an employee of the

appellant to the listed (established) email addresses/recipients using an open distribution list, thereby disclosing them to the respective recipients,

and the content of the sent emails is evident from the two

emails themselves and was not disputed or even presented by the appellant - 24 -

The same applies with regard to the fact that personalized email

addresses were among the disclosed recipients: The disclosure of at least
100 (168 according to the Federal Administrative Court's count) personalized email

addresses, from which full names were evident, including both official and private email addresses of natural persons, in particular a specific

named employee of healthcare facilities, is objectively proven by the emails in question dated November

22, 2021, and was ultimately admitted by the
appellant herself, especially since she stated in her notification pursuant to Art.

Article 33 of the GDPR of December 4, 2021, stated that approximately 100 email addresses qualify as personal data because of the

identifiability of the address holder.

The complainant also presented, and did not dispute, the specific circumstances of the collection of the email addresses: that they were

used for the purpose of a political campaign, that they were email addresses of organizations/individuals who are not (exclusively) party members or political

like-minded individuals, and that no consent had been obtained from all data subjects

for the data processing in question, in particular for publication. The fact that the email addresses were collected from publicly accessible sources by the former managing director and CFO of the

complainant, Dr. P., is also evident
from the testimony of Dr. N.C.

Regarding the finding in point 1.4. It must be noted that – contrary to the statements

of the respondent authority in the contested penalty order – the
Federal Administrative Court has not found that it was a conscious and deliberate

decision by the appellant to insert the email addresses in the "To" field instead of the "bcc" field before sending the emails and the "Open Letters" to the respective recipients. While it became apparent during the oral proceedings

before the Federal Administrative Court that the witnesses heard were no longer able to recall

the specific circumstances of the sending of the emails in question with sufficient certainty, witness G.S., when questioned, could not definitively state

what exactly was to be sent, how many email addresses were involved, or whether she had contacted Mag. B.H. Whether the list of email addresses was also transmitted electronically or only in
printed form, and whether – as Mag. B.H. stated – she checked the letter again with Mag. B.H. for spelling accuracy before
sending it. The witness Mag. B.H. also testified that she had made a

mistake when sending the emails, that she had "typed" and sent the emails in "cc" instead of "bcc",

however, it is established that the email addresses were sent in the "To" field and not – as Mag. B.H. – 25 –

repeatedly testified – in the "cc" field, so that it must also be assumed that the witness Mag. B.H.

no longer had a concrete recollection of the actual circumstances
of sending the emails.

Nevertheless, the witness Mag. B.H. It can generally be accepted that she made a mistake when sending the emails by accidentally entering the email addresses she should have sent using the "bcc" function into the wrong field. Witness G.S. and witness Dr. N.C. also testified consistently and convincingly that the emails in question should have been sent in such a way that the addresses were not visible. Witness Dr. N.C. emphasized in particular that there was "no need to discuss further that such things are sent in blind copy." Against this background, the Federal Administrative Court assumes that in the appellant's daily work, such letters or political campaigns were generally sent to the respective recipients without an open distribution list. This is also supported by the

fact that – as the respondent authority also stated in the contested penalty order

the appellant immediately instructed the affected employees

and furthermore deleted the email addresses and the distribution list in order to prevent such mailings in the future. In the specific case, this means

that the contents of the file, in conjunction with the appellant's statements and those of the witnesses heard, do not support the conclusion that it was a

conscious and deliberate decision by the appellant to insert the email

addresses in the "To" field instead of the "Bcc" field, but rather that an error by one of her employees led to the disclosure of the

email addresses.
... If the respondent authority concludes, based on its assessment of the evidence, that the
appellant intended to demonstrate to the recipients of the

message, through the open distribution list, that she had found "countless like-minded individuals" in the health and care sector

who wished to oppose the mandated vaccination, it must be noted that this is ultimately a speculative assumption by the respondent

authority, which – despite an oral hearing and supplementary

taking of evidence by the Federal Administrative Court – could not be substantiated by any concrete evidence. Even the reference to the specific

wording of the open letters (for example, “We, the employees of the
healthcare sector…”; “We stand up against the discrimination against us, the employees of the

healthcare sector”; “We have found countless like-minded people in our profession,

more precisely, we have networked”; “WE ARE MANY”; “All of us are ready to – 26 –

stop work and go on strike…”; “Finally, we would like to inform you

that we have received notification from numerous people in the healthcare professions that they will stop working with immediate effect in the event of mandatory vaccination,” etc.) does not support the assumption of a deliberate action by the complainant,
especially since it can be read ambiguously, for example, to mean

that – as the complainant claims – she wanted to win over the recipients of the letters to her

political ideas, or that the letters were intended as a wake-up call to the
complainant to be added.

The finding regarding point 1.5 is based on the testimony of Mag. B.H. during the

oral hearing before the Federal Administrative Court. Witness Dr. N.C. testified contrary to this, stating that (only) approximately two recipients had complained, but simultaneously indicated that he had not been further involved in the matter, as it had been handled by the

management, the appellant's former legal representative, and XXXX. Therefore, the Federal Administrative Court accepts the testimony of Mag. B.H.

especially since she was directly involved as the sender of the emails

and also stated that she had collected the expressions of dissatisfaction in a folder and verbally shared them with colleagues.

The findings regarding the appellant's income and assets under point 1.6. The following conclusions are drawn from the appellant's statements

in the administrative proceedings, in the oral hearing before the

Federal Administrative Court, and from the submitted, unobjectionable documents.

3. Legal Assessment:

Regarding A)

3.1. Pursuant to Section 6 of the Federal Administrative Court Act (BVwGG), the Federal Administrative Court decides by a single judge,
unless federal or state law provides for a decision by a panel.

Pursuant to Section 27 of the Data Protection Act (DSG) as amended, the Federal Administrative Court decides in

proceedings concerning appeals against decisions, violations of the duty to provide information
pursuant to Section 24 Paragraph 7, and the duty of the data protection authority to make a decision, by a panel.

The panel consists of a presiding judge and one lay judge each from the

group of employers and from the group of employees.

The procedures of the administrative courts, with the exception of the Federal Fiscal Court, are governed by

the Administrative Court Procedure Act (VwGVG), Federal Law Gazette I 2013/33 as amended by Federal Law Gazette I 2013/122 (§ 1 of the aforementioned Act). Pursuant to § 58 para. 2 - 27 -

VwGVG, conflicting provisions that were already promulgated at the time of entry into force

this Federal Act remain in force.


The Administrative Court Procedure Act (VwGVG) Pursuant to Section 17 of the Administrative Court Procedure Act (VwGVG), unless otherwise provided in this Federal Act, the provisions of the General Administrative Procedure Act (AVG), with the exception of Sections 1 to 5 and Part IV, the provisions of the Federal Fiscal Code (BAO), Federal Law Gazette No. 194/1961, the Agricultural Procedure Act (AgrVG),

Federal Law Gazette No. 173/1950, and the Civil Service Procedure Act 1984 (DVG), Federal Law Gazette No. 29/1984, and, in all other respects, those procedural provisions in federal or state laws

apply mutatis mutandis to the proceedings concerning appeals pursuant to Article 130 Paragraph 1 of the Federal Constitutional Law (B-VG),

with the exception of Sections 1 to 5 and Part IV, the provisions of the Federal Fiscal Code (BAO), Federal Law Gazette No. 194/1961, the Agricultural Procedure Act (AgrVG),

Federal Law Gazette No. 173/1950, and the Civil Service Procedure Act 1984 (DVG),

and, in all other respects, those procedural provisions in federal or state laws which the authority applied or would have been required to apply in the proceedings preceding the proceedings before the

Administrative Court.
... Pursuant to Section 28 Paragraph 1 of the Administrative Court Procedure Act (VwGVG), the Administrative Court must decide the case by judgment

unless the appeal is to be dismissed or the proceedings discontinued.

Pursuant to Section 31 Paragraph 1 of the VwGVG, decisions and orders are issued by order,

unless a judgment is to be issued.

Pursuant to Section 28 Paragraph 2 of the VwGVG, the Administrative Court must decide on the merits of appeals pursuant to Article 130
Paragraph 1 Item 1 of the Federal Constitutional Law (B-VG) if (1) the relevant

facts are established or (2) the establishment of the relevant facts by the
Administrative Court itself is in the interest of expediency or would result in significant

cost savings.

3.2. Regarding the procedural requirements:

The appeal was filed within the prescribed time limit, and the other

procedural requirements are also met.

3.3. On the merits:

3.3.1. Legal basis:

The relevant provisions of Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) and the
Administrative Penal Code 1991 (VStG) are as follows (excerpt, including heading):

Article 4, paragraphs 1, 2 and 7 GDPR: - 28 -

“1.“Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular

by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

2. “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

7. ‘Controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for by Union or Member State law;

Article 5 GDPR:

“Principles relating to the processing of personal data

(1) Personal data shall be

a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);

b) collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes; Further processing for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes is not considered incompatible with the original purposes (“purpose limitation”) in accordance with Article 89(1);

c) adequate, relevant, and limited to what is necessary for the purposes for which they are processed (“data minimization”);

d) accurate and, where necessary, kept up to date; all reasonable steps must be taken to ensure that personal data which are inaccurate in relation to the purposes for which they are processed are erased or rectified without delay (“accuracy”);

e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed; - 29 -

Personal data may be stored for longer periods if, subject to the implementation of appropriate technical and organizational measures required by this Regulation to safeguard the rights and freedoms of the data subject, the personal data are processed solely for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with Article 89(1) (“storage limitation”);

(f) are processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical and organizational measures (“integrity and confidentiality”);

(2) The controller shall be responsible for compliance with paragraph 1 and must be able to demonstrate compliance (“accountability”).


(f) Article 6 GDPR:

"Lawfulness of processing

(1) Processing shall be lawful only if at least one of the following conditions is met:

a) The data subject has given consent to the processing of his or her personal data for one or more specific purposes;

b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

c) processing is necessary for compliance with a legal obligation to which the controller is subject;

d) processing is necessary in order to protect the vital interests of the data subject or of another natural person;

e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data override,
in particular where the data subject is a child.

Paragraph 1(f) shall not apply to processing carried out by public authorities in the performance of their tasks.

(2) Member States may maintain or introduce more specific provisions to adapt the application

of the provisions of this Regulation with regard to processing for the purposes of paragraph 1(c) and (e) by specifying more precisely the specific requirements for the processing and other measures to ensure lawful and fair processing, including for other specific processing situations referred to in Chapter IX.

(3) The legal basis for processing referred to in paragraph 1(c) and (e) shall be determined by

(a) Union law or

(b) the law of the Member State to which the controller is subject.

The purpose of the processing must be specified in that legal basis or, with regard to the

processing referred to in paragraph 1(e), be necessary for the performance of a task carried out in the public interest or in the exercise of official authority. is carried out, which has been transferred to the
controller. This legal basis may contain specific provisions
to adapt the application of the provisions of this Regulation, including provisions on the general conditions that govern the
lawfulness of processing by the controller, the types of data processed, the data subjects, the entities to which and for which purposes the personal data may be disclosed, the purpose limitation to which they are subject, how long they may be stored, and the processing operations and procedures that may be applied, including measures to ensure lawful and fair processing, such as those for other specific processing situations referred to in Chapter IX.

Union law or the law of the Member States must pursue an objective in the public interest and be proportionate to the legitimate
purpose pursued.

(4) Where processing for a purpose other than that for which the personal data were collected is not based on the data subject’s consent or on Union or Member State law which provides for such a purpose, the processing must be carried out in accordance with the applicable legal provisions. a

democratic society where processing constitutes a necessary and proportionate measure for the protection of the objectives referred to in Article 23(1), the controller shall, in order to determine whether processing for a different purpose is compatible with that for which the personal data were originally collected, take into account, inter alia,

a) any link between the purposes for which the personal data were collected and the purposes of the intended further processing,

b) the context in which the personal data were collected, in particular with regard to the relationship between the data subjects and the controller,

c) the nature of the personal data, in particular whether special categories of personal data pursuant to Article 9 are processed or whether personal data relating to criminal convictions and offences pursuant to Article 10 are processed,

d) the possible consequences of the intended further processing for the data subjects,

e) the existence of appropriate safeguards, which may include encryption or pseudonymization.


Article 9 GDPR

"Processing of special categories of personal data

(1) The processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person,

data concerning health or data concerning a natural person's sex life or sexual orientation, shall be prohibited.

(2) Paragraph 1 shall not apply in the following cases:

a) the data subject has given explicit consent to the processing of the personal data referred to in paragraph 1 for one or more specified purposes, unless, under Union or Member State law, the prohibition in paragraph 1 cannot be overridden by the data subject's consent;

b) processing is necessary for the controller or the data subject to perform their personal data.to exercise their rights arising from employment law and social security and social protection law,

and to comply with their obligations in this regard, insofar as this is permitted under Union law or the law of the Member States or a collective agreement under the law of the Member States which provides suitable safeguards for the fundamental rights and interests of the data subject,

c) processing is necessary to protect the vital interests of the data subject or of another natural person and the data subject is physically or legally incapable of giving consent,

d) processing is carried out on the basis of suitable safeguards by a politically, ideologically, religiously or trade union-oriented foundation, association or other non-profit organization in the course of its legitimate activities and provided that the processing relates exclusively to the members or former members of the organization or to persons who have regular contact with it in connection with its purpose,

and the personal data are not processed without Consent of the data subject
disclosed externally,

e) the processing relates to personal data which the data subject has manifestly made public,

f) the processing is necessary for the establishment, exercise or defence of legal claims or for the performance of judicial acts, - 32 -

g) the processing is based on Union or Member State law which is proportionate to the objective pursued, respects the essence of the right to data protection and provides for appropriate and specific measures to safeguard the fundamental rights and interests of the data subject,

necessary for reasons of substantial public interest,

h) the processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, for medical diagnosis, the provision of health or social care or treatment or for the management

of health or social care schemes and services based on Union law or the law of a Member State or pursuant to a contract with a
healthcare professional and subject to the conditions and safeguards referred to in paragraph 3,

i) processing is necessary for reasons of public interest in the area of public

health, such as protection against serious cross-border threats to health or to ensure high standards of quality and safety
in healthcare and in relation to medicinal products and medical devices, on the basis of Union or Member State law which provides for appropriate and

specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy, or

j) processing is necessary on the basis of Union or Member State law which is proportionate to the objective pursued, respects the essence of the right to data protection and provides for appropriate and specific

measures to safeguard the fundamental rights and interests of the data subject, for archiving purposes in the public interest, scientific or historical research purposes or necessary for statistical purposes in accordance with Article 89(1).

(3) The personal data referred to in paragraph 1 may be processed for the purposes referred to in paragraph 2

(h) if such data are processed by or under the responsibility of professional personnel who are subject to professional secrecy under Union law or the law of a Member State or the rules of national competent authorities, or if the processing is carried out by another person who is also subject to a duty of confidentiality under Union law or the law of a Member State or the rules of national competent authorities.

(4) Member States may introduce or maintain additional conditions, including restrictions, with regard to the processing of genetic, biometric, or health data.


(2) Section 64, paragraphs 1 and 2 of the Administrative Penal Code:

"Costs of Criminal Proceedings

(1) Every penalty order must state that the convicted person is required to contribute to the costs of the criminal proceedings.

(2) This contribution is to be calculated at 10% of the imposed penalty for the proceedings at first instance, but at least €10; in the case of custodial sentences, one day of imprisonment is to be credited as €100 for the calculation of the costs. The cost contribution accrues to the local authority, which is responsible for covering the expenses of the administration."

3.3.2. Applied to the present case, this means the following:

3.3.2.1. Regarding the fulfillment of the objective elements of the offense:

Based on the facts it established, the respondent authority initially assumed

that the material scope of application of Article 2(1) GDPR was applicable, since
the email addresses disclosed in the present case through the use of the open email distribution list

constitute personal data within the meaning of Article 4(1) GDPR,

that the sending of the emails in question via the open distribution list undoubtedly constituted processing within the meaning of Article 4(2) GDPR, and that the complainant was to be classified as

the controller of this data processing within the meaning of Article 4(7) GDPR.

The complainant did not contest the respondent authority's legal assessment in this regard, and the Federal Administrative Court also finds

no reason to believe that the respondent authority's statements in this respect are incorrect.


It should also be noted that even if the email addresses used originate from public sources, this does not mean that the data protection regime does not apply. The data protection for already published data does not fundamentally differ from the scope of protection for other personal data. This means that not all data that is published or publicly accessible may be used by a controller for any purpose they choose (see:

2 Thiele/Wagner, Commentary on the Austrian Data Protection Act, Section 1 [as of February 1, 2022, rdb.at], para. 115 et seq. with further references).

If lawfully published data is not merely reproduced, but rather a

new element is linked to this data, such as the creation of

informational added value for the creation of a "doctor rating platform" or the
use of the data for the potential acquisition of properties in the context of business

as a real estate trustee, or – as in this case – the use of the data for a political

campaign, this linking constitutes processing pursuant to Article 4(2) GDPR, which requires a legal basis within the meaning of Articles 5 and 6 or 9 GDPR.
... Regarding the lawfulness of the processing (sending the emails in question), the
responsible authority stated in the contested penalty order that the appellant

by sending the emails, processed a special category of personal (sensitive)

data pursuant to Art. 4(1) in conjunction with Art. 9(1) GDPR (specifically, political opinions and - 34 -

philosophical convictions) contrary to the prohibition on processing under Art. 9(1) and

without an exception under Art. 9(2) GDPR, as well as the principle
of processing personal data lawfully, fairly and

in a transparent manner in relation to the data subject pursuant to Art. 5(1)(a) GDPR (“lawfulness, fairness and transparency”) and the

principle of processing personal data that is adequate, relevant and limited to what is necessary for the purposes of the processing

pursuant to Art. 5(1) GDPR. Article 1(c) GDPR (“data minimization”) has been violated.

The complainant argues, in summary, that the legal assessment of the respondent

authority, the email addresses in question were lawfully processed by the data subjects, and that the conclusion that these email addresses constitute special categories of personal data pursuant to Article 9

GDPR is incorrect. The recipients of the letter cannot discern from the list of recipients (distribution list) the political convictions of a particular person, as the list includes, on the one hand, political officeholders,

the press and public, and certain individuals close to the petition. Without further indications, it is impossible for an individual recipient to infer the political orientation or worldview of other recipients.

However, the following must be pointed out to the complainant:

According to Article 9(1) GDPR, the processing of personal data revealing (among other things) political opinions or philosophical beliefs is prohibited.

Article 9(2) GDPR provides for exceptions to this prohibition.

According to the case law of the Administrative Court, for Article 9(1) GDPR to apply, it is sufficient if, with regard to the data categories of racial and ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership, the sensitive information is only indirectly evident. Thus, indirect indications of these characteristics are also subject to special protection,

whereby recognizability by an average, objective third party is sufficient (see VwGH

17.05.2024, Ra 2023/04/0005-6, para. 30 with reference to VwGH 14.12.2021, Ro
2021/04/0007, para. 46, with further references).

According to the case law of the CJEU, the purpose of Article 9(1) GDPR is to guarantee
enhanced protection against data processing which, due to the particular sensitivity of the data being processed, may constitute a particularly serious

interference with the fundamental rights to respect for private life and to the protection of personal data guaranteed by Articles 7 and 8 of the Charter (see CJEU

21 December 2023, C-667/21, Krankenversicherung Nordrhein, para. 41).

In its judgment of 1 August 2022,

C-184/20, Vyriausioji tarnybinės etikos komisija, the CJEU, regarding the interpretation of the term “special categories of personal data”

and the “emerging” aspect of Article 9(1) GDPR, stated the following:

“122 [...] Article 9(1) of the GDPR provides that, inter alia, the processing

of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of data concerning health or data relating to a natural person’s sex life or sexual orientation, is prohibited.

123 As the Advocate General essentially stated in point 85 of his Opinion, the use of the verb ‘emerging’ in these provisions indicates that a
processing is covered which relates not only to data that is sensitive in nature,
but also to data from which sensitive information can be indirectly derived through a process of deduction or

comparison [...].

[...]

125 The objective of Directive 95/46 and the GDPR, mentioned in paragraph 61 of this judgment, also supports a broad interpretation of the terms ‘special categories of personal data’
and ‘sensitive data’. This objective is to ensure a high level of protection of the

fundamental rights and freedoms of natural persons – in particular their right to privacy –
when personal data relating to them is processed [...].

[...]

127 Consequently, these provisions cannot be interpreted as exempting the
processing of personal data that may indirectly reveal sensitive information about a natural person from the enhanced safeguards provided for in these provisions, since otherwise the practical effectiveness

of those safeguards and the protection of fundamental rights they are intended to achieve would be undermined. and fundamental freedoms
of natural persons would be infringed.”

The Supreme Court, whose reasoning the Administrative Court adopted in its ruling

Ro 2021/04/0007, also stated with regard to “party affiliations” that Article 9 GDPR is intended, in particular, to protect data subjects from being exposed to the risk of particularly serious discrimination

through data processing, and that it therefore appears necessary to include not only data revealing the actual political views of the data subject within the scope of protection of Article 9(1) GDPR, but also data concerning presumed political preferences

of the individual, since the processing of such data also carries the risk of particularly negative consequences for the data subject (see Supreme Court 15 April 2021, 6 Ob 35/21x, para. 34). Therefore, for the purposes of protection under Article 9(1) GDPR, it is irrelevant whether the attribution is intended or whether it is (substantively) accurate with regard to the data subject (see also, in this sense,

Weichert in Kühling/Buchner, GDPR BDSG [2024] Article 9 GDPR, para. 24).


In light of these considerations, it becomes clear that the disclosure of a
part of the identified email addresses to all recipients, namely at least

with regard to those at least 100 personalized email addresses from which official or

private email addresses of natural persons as recipients, in particular a
specific named employee of healthcare facilities,

emerge or are evident, constitutes processing (prohibited under Article 9(1) GDPR) of

personal data revealing the (alleged) political opinion, especially since the content of the emails in question,

in conjunction with the purpose (conducting a political campaign) and the

method of processing (use of an open distribution list), suggested to the recipients of the emails (and the recipients or third parties could objectively

understand this) that these individuals were supporters of the complainant, whose
political Shared views, with reference here to the wording of the letters sent:

(“We healthcare workers…”; “We stand against the discrimination of

us healthcare workers”; “We have found countless like-minded people in our profession, or rather, we have networked”; “WE ARE MANY”; “All

among us are prepared to stop working and go on strike…”;

“Finally, we would like to inform you that we have received notification from numerous people in the healthcare professions that they will stop working with immediate effect in the event of mandatory vaccination,” etc.) which gives the impression

that the affected individuals listed in the distribution list have joined the complainant, oppose mandatory vaccination, and are

prepared to stop working. The attribution of a (supposed) political

conviction is also supported by the fact that, according to Ms. B.H., following the sending of the emails in question, approximately 15-20 people complained to the

complainant and explicitly stated that they wanted nothing to do with the
complainant and did not want to receive anything from her. Thus, the

potential danger posed by the email addresses sent by the complainant in an open distribution list,

at least with regard to the at least 100 personalized email addresses, lies in the discrimination or persecution of the data subjects based on the presumed

political conviction, and not merely, as stated in the notification pursuant to Article 33 GDPR by the
complainant dated December 4, 2021, in unsolicited

contact.



The email addresses sent by the complainant in an open distribution list, at least with regard to the at least 100 personalized email addresses, lie in the discrimination or persecution of the data subjects based on the presumed

political conviction, and not merely, as stated in the notification pursuant to Article 33 GDPR by the
complainant dated December 4, 2021, in unsolicited

contact. The complainant thus assigned a political opinion to the data subjects by using an open

email distribution list and disclosed it to all recipients.

Even if it is conceded that not all email addresses used by the complainant (e.g., those pertaining to an entire

healthcare facility) allow conclusions to be drawn about the political convictions of the staff, residents, etc. there, this does not alter the fact that,

with regard to a significant portion of the email addresses disclosed to a larger

group of people, such processing has occurred – as just explained – and the objective elements of a violation of Article 5(1)(a) and (c) GDPR

as well as Article 9(1) GDPR are therefore met. The partial presence of (sensitive)

data under Article 9(1) GDPR in relation to the disclosed email addresses will be taken into account in the
determination of the penalty, although this circumstance is not

decisive (see section 3.3.2.3 below).

The political convictions in question, attributed to and disclosed by the data subjects in at least 100 cases, are therefore to be subsumed under the special

category of personal data under Article 9(1) GDPR and thus fall under the special protection of this provision (see also

Mangelberger/Scheichenbauer, The Limits of Ideological Conviction in the GDPR, in jusIT 5/2021, 202 [207 f]). Therefore, their processing would only be permissible if an exception under Article 9(2) GDPR existed (see in this regard CJEU

21 December 2023, C-667/21, Krankenversicherung Nordrhein, para. 42). The complainant does not claim that such an exception existed, nor is it otherwise apparent. In particular, as established, there is no consent from all

data subjects for the data processing in question, especially the

publication within the meaning of Article 9(2)(a) GDPR, and the
justification under Article 9(2)(d) GDPR – which the

appellant has not invoked – is also not applicable, especially since the
processing – as established – does not relate (exclusively) to members or former

members of the organization or to persons who maintain regular contact with it in connection with its - 38 -

purpose of activity, and the

personal data were disclosed externally without the consent of the data subjects.

With regard to the principle of data minimization under Article 5(1)(c) GDPR, the
Federal Administrative Court also cannot find that the processing in question is

necessary in this specific case with regard to the use of an

open distribution list. As the respondent authority correctly states in the contested penalty order, the appellant's political campaign could have been conducted without the use of an open distribution list, and sending the emails via the "bcc" field would have achieved the desired result just as effectively. The appellant's opposing argument regarding the alleged violation of the freedom to form and operate political parties is limited—as the respondent authority also correctly states in its response to the party's appeal—to general statements and fails to demonstrate in a comprehensible way how the appellant's exercise of its freedom to operate as a political party required the sending of the emails in question via an open distribution list. This argument also contradicts

the appellant's claim that the email was sent with an open distribution list due to
employee misconduct, and the

testimony of witnesses during the oral hearing before the Federal Administrative Court,

that "such things are normally sent in bcc".

As a result, the form of processing (use/transmission/disclosure) of email addresses that is the subject of the complaint cannot be based on the GDPR and the GDPR, as it is not covered by any legal basis and was not legitimized by the existence of an exception under Article 9(2) GDPR. The data processing under review here did not comply with the requirements and obligations arising from the GDPR and does not meet the lawfulness requirements set out in the GDPR, as it did not comply with the principle of lawfulness, fairness, and transparency pursuant to Article 5(1)(a) GDPR and was not limited to what is necessary in accordance with the principle of data minimization set out in Article 5(1)(c) GDPR. The infringement of the data protection rights of the affected persons is disproportionate and unjustified, since, in the required balancing of interests,

their interests with regard to their (sensitive) data outweigh the infringement. - 39 -

Therefore, the objective elements of a violation of Article 5(1)(a) and (c) GDPR

as well as Article 9(1) GDPR have been fulfilled. The criminal liability for this infringement is based,

as the respondent authority correctly stated in its decision, on Article 83(1) and (5)(a) GDPR.

Due to the established facts regarding the only partial presence of (sensitive)

data under Article 9(1) GDPR with respect to the disclosed email addresses, the

command of the penalty order had to be amended accordingly.

3.3.2.2. Regarding the fulfillment of the subjective element of the offense:

The respondent authority stated in the contested penalty order that the subjective element of the offense was also fulfilled, as culpability in the form of intent (Art. 83 para. 2 lit. b GDPR)

existed.

The appellant argues, in summary, that punishment is precluded due to the lack of (attributable) culpability on the part of the appellant, since the employee

Mag. B.H. neither holds a (management) position pursuant to Section 30 para. 1 GDPR nor can the appellant be accused of inadequate supervision or control of a management position.

The admitted error by Mag. B.H. cannot automatically lead to a penalty for the appellant,

especially if no systematic deficiencies or organizational shortcomings can be demonstrated.

It should first be noted that the requirement of fault for the

imposition of a fine under Article 83 GDPR must be interpreted autonomously within the framework of EU law and
in particular assessed in light of the case law of the CJEU.


Due to the case law of the CJEU (Judgment of 5 December 2023, C-807/21), according to which the

directly applicable provisions of Article 58(2)(i) and Article 83(1) to (6) GDPR must be interpreted as precluding a national regulation

under which a fine for an infringement referred to in Article 83(4) to (6) GDPR

may be imposed on a legal person in its capacity as controller only if that infringement has previously been attributed to an identified natural person,

the provisions of Section 30(1) and (2) GDPR (as well as the provision of Section 5 of the Administrative Penal Code [VStG]) are no longer applicable,

since, in light of the aforementioned CJEU judgment, they violate Article 83(1) to (6) GDPR

by imposing (additional) substantive requirements for the imposition of a fine. a
fine against a legal person (see also VwGH - 40 -

01.02.2024, Ra 2020/04/0187-20, para. 28, according to which the “requirement derived from national law [the VStG]

that, for the imposition of a fine under the GDPR against a legal person, all necessary elements for the

punishment of the natural person must be included in the operative part of the penalty order, should have remained unapplied
[…]”). Referring to further case law, the CJEU also expressly clarified

that the application of Article 83 GDPR to legal persons does not require any action

and not even knowledge on the part of the governing body of that legal person (cf. CJEU of 05.12.2023, C-807/21, para. 77). Against this background, the

appellant's argument that punishment is precluded due to a lack of (attributable)

fault on the part of the appellant is unfounded, since – as the respondent
authority correctly argues – due to the inapplicability of Section 30 of the Data Protection Act (DSG), it is irrelevant

whether Mag. B.H. holds (or held) a (management) position within the meaning of Section 30(1) DSG at the

appellant's company, or whether the appellant can be accused of inadequate
supervision or control of a management position, i.e., organizational negligence.

According to the case law of the CJEU, only violations of provisions of the GDPR committed culpably by the controller can lead to the imposition of a fine.


However, culpability exists even if the accused could not have been unaware of the unlawfulness of their conduct, regardless of whether they were aware that they were infringing the provisions of the GDPR (see ECJ C-807/21, paragraphs 68, 76 and 77; ECJ C-683/21, paragraphs 81 and 82 with further references).

Contrary to the submissions of the respondent authority, it cannot be assumed (and as already explained above) that the complainant made a conscious and intentional decision to send the emails in question, including attachments, to an open distribution list. Therefore, intentional conduct with regard to the infringement of the provisions of Article 5(1)(a) and (c) GDPR, as well as Article 9(1) GDPR, cannot be assumed in the present case. However,
in accordance with the case law of the ECJ, there is clearly fault in the form of

negligence. In the present case, the emails in question were sent by an employee of the applicant via an open email distribution list due to

an error and failure to exercise due diligence, especially since these emails

should have been sent by the employee via a closed email distribution list, so that, as explained above, a political opinion was attributed to the data subjects

and disclosed to all recipients. The applicant even states

in this regard that misconduct by one of its employees - 41 -

occurred, thus ultimately not denying fault in the form of negligence.


Given the explicit disclosure of email addresses using an open

email distribution list, the complainant (or the employee acting on her behalf, who should have inserted the email addresses into the "bcc" field) could not have been unaware, according to the

CJEU's case law on the unlawfulness of her conduct, on

unlawful, disproportionate, excessive disclosure of email addresses,

regardless of whether she was aware that she was violating the provisions

of the GDPR. This constitutes negligence on the part of the complainant, which is also evident from the complainant's notification pursuant to Article 33 GDPR of December 4, 2021.

Therefore, the subjective element of an infringement of Article 5(1)(a) and (c) GDPR and

Article 9(1) GDPR has been fulfilled in the present case.


3.3.2.3. Regarding the determination of penalties:

Article 83(1), (2) and (5)(a) GDPR, including its heading, reads:

General conditions for the imposition of administrative fines

(1) Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this

Article for infringements of this Regulation in accordance with paragraphs 4, 5 and 6 is effective, proportionate and dissuasive in each individual case.

(2) Administrative fines shall be imposed in addition to, or instead of, the measures referred to in Article 58(2)(a) to (h) and (j), depending on the circumstances of the individual case. When deciding on the imposition of a fine and its amount, due consideration shall be given in each individual case to the following:

a) the nature, seriousness and duration of the infringement, taking into account the nature, scope or purpose of the processing concerned, as well as the number of data subjects affected by the processing and the extent of the damage suffered by them;

b) whether the infringement was committed intentionally or negligently;

c) any measures taken by the controller or processor to mitigate the damage suffered by the data subjects;

d) the degree of responsibility of the controller or processor, taking into account the technical and organizational measures they have implemented pursuant to Articles 25 and 32;

e) any relevant previous infringements by the controller or processor; - 42 -

f) the extent of cooperation with the supervisory authority to remedy the infringement and to mitigate its possible adverse effects;

g) Categories of personal data affected by the breach;

h) The manner in which the breach became known to the supervisory authority, in particular whether
and, if so, to what extent, the controller or processor notified the breach;

i) Compliance with measures previously ordered against the controller or processor concerned in relation to the same subject matter pursuant to Article 58(2),

where such measures have been ordered;

j) Compliance with approved codes of conduct under Article 40 or approved certification mechanisms under Article 42; and

k) Any other aggravating or mitigating circumstances in the specific case, such as financial benefits gained or losses avoided, directly or indirectly, as a result of the breach.

(5) In the event of infringements of the following provisions, fines of up to EUR 20,000,000 or, in the case of an undertaking, up to 4% of its total worldwide annual turnover of the preceding financial year,

whichever is higher, shall be imposed in accordance with paragraph 2:

(a) the principles governing processing, including the conditions for consent,
in accordance with Articles 5, 6, 7 and 9;

The determination of the penalty shall be made on a case-by-case basis, taking due account of the

assessment criteria laid down in Article 83(2) GDPR.


(b) The contested penalty order imposed a fine of EUR 50,700.00 on the appellant

and ordered the appellant to pay a contribution to the costs of the criminal proceedings amounting to 10% of the fine, i.e., EUR 5,070.00.

In 2022, the appellant generated total revenue of EUR

851,120.89 from membership fees and donations. In addition, the appellant received party funding of EUR 1,200,000.00 in 2022.

In 2024, the appellant received membership fees totaling EUR 70,000.00 from approximately 2,400 individuals. Party funding for the state organization

XXXX of the complainant amounts to EUR 1,200,000.00 for the year 2024. - 43 -

First, it should be noted that – contrary to the appellant's submissions in the

oral hearing before the Federal Administrative Court – the
income/assets of the appellant's state organizations (in particular,

state organization XXXX) must also be taken into account when calculating turnover:

Regarding the concept of "undertaking" within the meaning of this provision, the CJEU held in

Case C-807/21 (Deutsche Wohnen SE) that the reference in Recital 150 of the GDPR to the concept of "undertaking" within the meaning of Articles 101 and 102 TFEU, in this specific context of calculating fines imposed for infringements referred to in Article 83

paragraphs 4 to 6 GDPR, is to be understood as follows (see paragraphs 55 et seq.).


For the purposes of applying the competition rules laid down in Articles 101 and
102 TFEU, this concept of an undertaking encompasses any entity engaged in an economic activity, irrespective of its legal form and the nature of its financing. It thus refers to

an economic entity, even if, from a legal perspective, it consists of several natural or legal persons. This economic entity comprises

a single organization of personal, tangible, and intangible resources, which pursues a specific economic objective on a permanent basis (with reference to the judgment of
6 October 2021, Sumal, C-882/19, EU:C:2021:800, paragraph 41 and the case law cited therein).

The criteria for assessing whether an economic unit exists include:

economic, legal, and organizational links between the parent and

subsidiary (e.g., the level of shareholding, personnel or organizational links, instructions, and the existence of internal agreements). The

CJEU has ruled that, in the specific case where a parent company holds

100% or almost 100% of the capital of its subsidiary, which has infringed EU competition rules, this parent company can exert

a decisive influence on the behavior of that subsidiary, and there is

a rebuttable presumption that this parent company actually does exert such influence on the behavior of its subsidiary (see, in particular, the judgments of the CJEU of 20 January 2011, C-90/09 P; and of 10 September 2009, C-97/08 P).


The Court of Justice of the European Union (CJEU) has held that, firstly, that parent company can exert

a decisive influence on the behavior of that subsidiary, and secondly, that there is a rebuttable presumption that the parent company does indeed exert such influence on the behavior of its subsidiary (see, in particular, CJEU judgments of 20 January 2011, C-90/09 P; and of 10 September 2009, C-97/08 P). In the present case, the applicant is a political party active in Austria and
Europe. The applicant constitutes the federal organization of the

party. In addition, there is a state organization with its own legal personality for each Austrian federal state, with a unified membership structure: every member

is a member of the federal party and, where applicable, is also listed as a state party member - 44 -

Active members can be elected or sent as delegates and thus also to the bodies of the

federal party executive committee. Insofar as it is necessary for the conduct of
nationwide elections or the federal political

actions decided upon by federal bodies, all institutions, functionaries, employees, and
volunteers of the party and its sub-organizations must comply with the guidelines of the

federal party. Moreover, as established, there are close personnel links between the

applicant and its state organization XXXX,
so that, within the meaning of the case law of the ECJ, the applicant and

its state organization XXXX constitute an “economic unit.”
... Moreover, the application of domestic law leads to the same result,
especially since Section 2, Paragraph 1 of the Political Parties Act 2012 (PartG) (according to which a "political party" is any party within the meaning of Section 1 PartG, whereby this term is to be understood comprehensively and encompasses all territorial

and non-territorial entities, regardless of whether an entity has legal personality) is based on a uniform understanding of the term "party" (e.g., encompassing territorial organizations).

Against this background, it must be noted that the annual turnover or revenue of the entire economic unit must be used to determine the penalty range pursuant to Article 83(5)

GDPR.


Regarding the question of which event the preceding financial year is linked to, the turnover of which

determines the upper limit of the possible fine, it should be noted that, according to the

case law of the CJEU in competition law concerning the almost identically worded Article 23 of Regulation No. 1/2003, the reference period is the financial year preceding the imposition of the sanction (CJEU, Judgment of 26 January 2017 - C-637/13 P - Badezimmerkartell Laufen Austria,

para. 49; CJEU, Judgment of 4 September 2014 - C-408/12 P - YKK et al., para. 90). Since Article 83
GDPR is modeled on the competition law provision, the amount of

annual turnover in the last completed financial year before the issuance of the

penalty notice/penalty order is therefore decisive. The timing of the court's decision is irrelevant, as is the timing of the relevant infringement (see also EDPB Guidelines 04/2022 on the calculation of administrative fines under the GDPR, version 2.1, adopted on 24 May 2023, paragraph 131).

Since the penalty order was issued on 14 December 2023, the annual turnover/revenue for 2022 is/are therefore decisive for determining the

penalty range. Based on - 45 -

a turnover for 2022 of EUR 2,051,120.89, this results in a maximum fine of EUR 20,000,000.00 pursuant to Article 83(5) GDPR.


In determining the amount of the fine within this range, the following was decisive for the

Federal Administrative Court:

According to Article 83(1) GDPR, each supervisory authority shall ensure that the imposition of

fines is effective, proportionate, and dissuasive in each individual case. Article 83(2) GDPR lists criteria for determining the amount of the fine, which must be "duly considered" in each individual case when deciding on the
imposition of a fine and its amount. Relevant factors include, in particular, the nature, severity, and duration of the

infringement, the number of data subjects affected by the processing, the extent of the
damage, the categories of personal data concerned, the efforts of the

company to mitigate the damage, the nature and extent of its cooperation with the

data protection authorities, and the degree of responsibility.

The company's turnover is not mentioned in Article 83(2) GDPR as a criterion for

determining the amount of the fine. However, this does not mean that the company's turnover is irrelevant when determining the amount of the fine:

In its judgment of 25 November 2003, C-278/01, the CJEU held that, in exercising its

power of assessment, the Court must set the lump sum or penalty payment in such a way that it is appropriate to the circumstances and proportionate both to the

established infringement and to the solvency of the

Member State concerned. Given that fines for infringements of the GDPR within the meaning of Article 83(1) GDPR must also be proportionate,

this case law can also be applied to a case such as the present one. The

Bonn Regional Court, in its judgment of November 11, 2020, 29 OWi 1/20, also states that
the company's turnover is significant when determining the amount of the fine:

"Firstly, for companies with high turnover, the turnover determines the maximum fine

and thus establishes the framework within which the specific data protection violation

must be classified and applied. The fine range provides the

necessary guidance for the specific assessment. Secondly, fines against companies must be effective and dissuasive pursuant to Art. 83

para. 1 GDPR. This also depends on the
sensitivity of the respective company to punishment. The larger the company,

the lower its sensitivity to punishment is generally, and the higher the fine must typically be set so that it can have its specific deterrent effect. The - 46 -

amount of turnover is relevant to the company size and thus to the Sensitivity

a suitable indicator; the net profit and other key figures of the company's economic
performance can also be taken into account.


``` The EDPB Guidelines 04/2022 also assume (referring to a binding decision on this matter, EDPB Decision 1/2021, paragraphs 411 and 412) that the

size of the company must be taken into account when calculating the fine, which is why

its turnover must be considered. According to the guidelines, the company's economic viability must also be considered when assessing proportionality (see the EDPB Guidelines 04/2022, paragraphs 63 et seq.).

Contrary to the submissions of the respondent authority, however, the turnover in the last completed

financial year before the issuance of the penalty notice/penalty order is not to be considered here (in contrast to the determination of the maximum fine),

but rather the applicant's current income and asset situation at the time of the Federal Administrative Court's decision, especially since this is the only way to ensure

that the fine can be paid

after the issuance of the (finding of the Federal Administrative Court) also proportionate within the meaning of
Art.Article 83(1) GDPR. This view is consistent, on the one hand, with the case law of the

Administrative Court on Section 19(2) of the Administrative Penal Code, according to which any changes in
income and asset circumstances during the appeal proceedings must be

taken into account (Administrative Court 29 January 2007, 2006/03/0155), and on the other hand, with the

statements of the EDPB on economic viability, according to which the company must submit
detailed financial data for the last five years as well as forecasts for the current and

next two years (see EDPB Guidelines 04/2022, paragraphs 140 et seq.). However, the

authority in question is correct in its assessment (and this also follows from the EDPB Guidelines
04/2022) that the decisive basis for sentencing is primarily the turnover, and not the account balance reported by the complainant.

In view of the nature, seriousness, and duration of the infringement, taking into account the nature, scope, or purpose of the processing in question, as well as the number of data subjects affected by the processing and the extent of the damage suffered by them (Article 83(2)(a) GDPR), it must be noted that the importance of the legally protected interest and the intensity of its impairment by the act are certainly not insignificant. In the present case, the processing involved not only
a large number of people or the prohibited disclosure to

a large number of persons and entities (Art. 83 para. 2 lit. a GDPR), - 47 -

but also a special category of personal data (Art. 83 para. 2 lit. g

GDPR), namely data revealing the political opinions or philosophical
beliefs of the data subjects, such data being subject to special

protection under Art. 9 GDPR and only permitted to be processed under narrow exceptions. The processing was also likely to infringe the fundamental rights of the

data subjects – in particular their

right to privacy within the meaning of Section 1 of the GDPR.

















































































... On the other hand, it is also significant that the disclosed email

addresses only partially constituted (sensitive) data as defined in Article 9(1) GDPR and that

moreover, it can be assumed that the violation was committed (merely) negligently.

The respondent authority did not consider any aggravating circumstances, and

no such circumstances emerged during the proceedings before the Federal Administrative Court.

The fact that the appellant has no prior convictions or relevant prior violations (Article 83(2)(e) GDPR) and cooperated extensively in the

conduct of the investigation before the Data Protection Authority and

also before the Federal Administrative Court, thereby contributing to the establishment of the truth (Article 83(2)(f) GDPR), is a mitigating factor.


Against this background, the Federal Administrative Court, in assessing the factors
of Article 83(2) GDPR and considering the acts in their entirety in the

present case, concludes that the infringement – despite the quantitative reduction of the official charge due to the merely negligent

commissioning of the act and the existing
mitigating circumstances, which are not offset by any aggravating factors – must be classified as having a high degree of seriousness overall. This is because, apart from the fact that (in

at least 100 cases) a large number of data subjects are affected,
whose personal data were disclosed to a large number of persons and

organizations, the fact that data from a special category of personal data, which, according to the
supreme court jurisprudence, is particularly worthy of protection because data subjects are

exposed to the risk of particularly serious

discrimination through such data processing, is of particular weight in determining the penalty. Therefore, the act must, in any case, be classified as serious in its
effects. - 48 -

According to the EDPB guidelines, the initial amount for further calculation in the case of a

high-severity infringement is to be set between 20% and 100% of the applicable statutory
maximum penalty (EUR 20,000,000.00).

In light of the above, the Federal Administrative Court considers a
provisional initial penalty of EUR 7,000,000.00 (35% of the statutory

maximum penalty) to be appropriate.

Given that, according to Article 83(1) GDPR, the imposition of fines must be effective and dissuasive, but also proportionate (and therefore must not be existentially threatening), the calculation of the fine – as explained above – must take into account the size of the company and consider its turnover and economic viability (see again the EDPB Guidelines

04/2022 and CJEU 25.11.2003, C-278/01). Since the turnover of the company of the

appellant is less than EUR 500,000,000.00, an adjustment based on the company's size must be made in accordance with the aforementioned EDPB Guidelines. Based on

a current business turnover such as that of the appellant (taking into account the economic unit) of EUR 1,270,000.00, the
EDPB recommends an adjustment based on an amount between 0.2% and 0.4% of the

provisional initial amount. Since the
appellant's business turnover is significantly closer to the upper limit of EUR 2,000,000.00 than to the

lower limit of EUR 0.00, the Federal Administrative Court considers a fine of EUR 28,000.00 (0.4% of the provisional initial amount) to be
appropriate to the culpability and the offense in this specific case.



The appellant's current business turnover is significantly closer to the upper limit of EUR 2,000,000.00 than to the lower limit of EUR 0.00. The imposition of the fine was necessary in the interest of general deterrence, in order to

raise awareness among controllers, in particular other political parties, regarding the
lawful sending of emails using a distribution list and the

related obligations under the GDPR, especially

when this involves the processing of sensitive data of data subjects.

Against this background, a mere warning (within the meaning of Recital

148 of the GDPR) was not appropriate here, moreover because the infringement was not merely

minor (within the meaning of Recital 148 of the GDPR). Because
based on the assessment of the criteria in Article 83(2) GDPR, it cannot be said

that the infringement, under the specific circumstances of this case, did not pose a significant risk to the data protection rights of the data subjects and that the core of the data protection obligation was not compromised. This is especially relevant given the

background that – as already explained – special categories of personal data within the meaning of Article 9(1) GDPR were involved. Furthermore, replacing a

fine with a warning is not mandatory under EU law for minor infringements (Guidelines on the application and imposition of administrative fines pursuant to Regulation 2016/679 [WP 253]). Therefore, a warning does not appear appropriate in this specific case.
... If the appellant refers to Section 20 of the Administrative Penal Code (VStG) in her appeal and requests the application of the extraordinary mitigation of punishment, it must be noted that, according to the aforementioned case law of the CJEU on Article 83 GDPR, with regard to the VStG, only EU law applies to the substantive elements of the offense, which is why the provision of Section 20 VStG must remain inapplicable (see again CJEU of

December 5, 2023, C-683/21, paragraphs 46, 48, 70).

It should be noted that, in reaching its decision, the Administrative Court must not merely review the exercise of discretion by the administrative penal authority, but must exercise discretion itself and determine a new sentence (Austrian Administrative Court [VwGH] January 31, 2012,

2009/05/0123). This applies particularly in the case of a change in the verdict. In this respect, it is generally the case that, if the appeal is partially granted (Austrian Administrative Court [VwGH] 27.05.2008, 2007/05/0235), for example by

reducing the period of the offense (VwGH 22.04.2010, 2007/07/0015; 21.02.2012,

2010/11/0245), if entries are removed due to intervening expungement (VwGH 27.05.2008, 2007/05/0235) or if further mitigating circumstances emerge (VwGH

22.4.1998, 97/03/0353), i.e., in cases of a qualitative or quantitative reduction of the

charge, the sentence must also be reduced (Wessely in Raschauer/Wessely [eds],
Commentary on the Administrative Penal Code [2023] § 19 para. 26).

If the appellant argues that the previous rulings of the respondent authority

indicate fines in the range of EUR 10,000.00, it must be noted that
the assessment of the fine pursuant to Art. 83 para. 1 GDPR is a case-by-case decision

and the fine imposed here, amounting to EUR 28,000.00, appears

appropriate to the offense and

the degree of culpability, in light of the offense committed, and measured against the available
penalty range of Art. 83 para. 5 GDPR (here up to EUR 20,000,000.00). It should also be noted, however, that the fine now imposed is

at the lower end of the available penalty range,

and a (still) lower amount would no longer meet the criteria of effectiveness and suitability of deterrence set out in Article 83(1) GDPR - 50 -




3.3.2.4. Regarding the costs of the administrative penalty proceedings and the appeal proceedings:

Pursuant to Section 64(1) of the Administrative Penal Code (VStG), the penalty order must state that the person penalized is required to pay a contribution to the costs of the penalty proceedings. Pursuant to Section 64(2) VStG, this contribution is

to be set at 10% of the imposed penalty, but at least

EUR 10, for the proceedings at first instance. Due to the penalty now imposed, the contribution to costs was reduced to EUR 2,800.00.

Since the appeal was partially granted, the appellant was not required to pay any costs of the appeal proceedings (§ 52 para. 8 VwGVG).

3.3.2.5. Payment Information:

The appellant must pay the total amount of EUR 30,800.00 (penalty and costs of the

administrative proceedings) within two weeks to the account of the
Federal Administrative Court (BVwG) with IBAN AT840100000005010167 (BIC

BUNDATWW), stating the case number, free of charge to the recipient.

Or pay the amount at the Federal Administrative Court, taking this decision with her.

In case of default, the amount will be collected by compulsory enforcement after a reminder has been issued.
... Regarding B)

Pursuant to Section 25a Paragraph 1 of the Administrative Court Act (VwGG), the Administrative Court must state in the operative part of its judgment or

decision whether the appeal on points of law is admissible pursuant to Article 133 Paragraph 4 of the Federal Constitutional Law (B-VG). The
statement must be briefly reasoned.

The present decision does not depend on the resolution of a legal question of

fundamental importance. There is neither a lack of case law from the
Administrative Court of Justice nor does the present decision deviate from the

case law of the Administrative Court of Justice; furthermore, the existing

case law of the Administrative Court of Justice cannot be considered inconsistent. There are also no other indications of the fundamental importance of the legal questions to be resolved.

The Federal Administrative Court can rely on established case law of the Administrative Court of Justice or on an already clear legal situation in all significant

legal questions. It is also not apparent that in the specific case – 51 –

a legal question arises that has significance beyond the (specific) individual case at hand.

Based on this, a legal question of fundamental importance within the meaning of Art. 133 para. 4 B-
VG cannot be affirmed (cf., for example, VwGH

25.09.2015, Ra 2015/16/0085, with further references). It was therefore necessary to declare that the appeal pursuant to

Art. 133 para. 4 B-VG is inadmissible.