BVwG - W108 2285546-1/22E
| BVwG - W108 2285546-1/22E | |
|---|---|
| Court: | BVwG (Austria) |
| Jurisdiction: | Austria |
| Relevant Law: | Article 4(7) GDPR Article 6(1)(f) GDPR Article 9(1) GDPR Article 9(2)(a) GDPR Article 22 GDPR Article 33 GDPR Article 57 GDPR Article 58 GDPR Article 83(1) GDPR Article 83(5)(a) GDPR § 30 DSG |
| Decided: | 25.10.2024 |
| Published: | 25.10.2025 |
| Parties: | Datenschutzbehörde (DPA) A political party (Controller) Recipients of emails (data subjects) |
| National Case Number/Name: | W108 2285546-1/22E |
| European Case Law Identifier: | |
| Appeal from: | DSB (Austria) D550.688 2023-0.615.432 |
| Appeal to: | Not appealed |
| Original Language(s): | German |
| Original Source: | RIS (in German) |
| Initial Contributor: | avalang |
A court partially upheld a fine against a controller for violating Article 9(1) GDPR by disclosing recipients’ political opinions through an open email distribution list.
English Summary
Facts
The controller was a political party, the data subjects were recipients of two campaign emails.
On 22 November 2021, a staff member of the controller sent two emails with attached “open letters” as part of a political campaign, using an open distribution list in the “To” field instead of using blind copy (BCC). Each email exposed around 400 email addresses, including at least 100 personalised addresses showing first and last names. The controller had collected the email addresses from publicly accessible sources and relied on legitimate interest under Article 6(1)(f) GDPR for the processing, instead of asking for consent.
On 4 December 2021, the controller notified the DPA of the personal data breach.
On 22 April 2022, in separate supervisory proceedings, the DPA found that the controller had unlawfully disclosed political opinions through the open distribution list. Subsequently, it initiated administrative fine proceedings. On 14 December 2023, the DPA imposed a fine of €50,700 under Article 83(5)(a) GDPR for infringements of Article 5(1)(a) and (c) GDPR and Article 9(1) GDPR.
The controller appealed to the court. It argued that the email addresses did not reveal political opinions, that § 30 DSG required attribution to a natural person in a leadership position, and that the fine was disproportionate.
Holding
The court partly upheld the appeal and amended part of the decision.
First, the court held that the combination of the personalised email addresses and the political content attributed a political opinion to at least part of the recipients. By making the distribution list visible to all recipients, the controller disclosed special categories of personal data within the meaning of Article 9(1) GDPR and no exception under Article 9(2) GDPR applied. Legitimate interests under Article 6(1)(f) GDPR can not justify the processing of special categories of data.
Second, the court confirmed a violation of Article 5(1)(a) GDPR (lawfulness) and Article 5(1)(c) GDPR (data minimisation). The controller could have used BCC as a milder, equally successful option. Using an open list was not necessary for the campaign’s purpose.
Third, regarding attribution and fault, the court followed the CJEU’s interpretation of Article 83 GDPR in Case C-807/21. It held that a fine against a legal person does not require prior identification of a specific natural person under national law. The conduct of the employee was attributable to the controller.
Finally, the court reassessed proportionality under Article 83 GDPR. It took into account the seriousness of the infringement, the number of affected data subjects, the financial situation of the controller and mitigating factors, including cooperation and the absence of prior infringements. It reduced the fine from the previous €50,700 to €28,000.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the German original. Please refer to the German original for more details.
Postal address: Erdbergstraße 192 – 196 1030 Vienna Tel: +43 1 601 49 – 0 Fax: +43 1 711 23-889 15 41 Email: einlaufstelle@bvwg.gv.at www.bvwg.gv.at Date of decision October 25, 2024 File number W108 2285546-1/22E IN THE NAME OF THE REPUBLIC! The Federal Administrative Court, presided over by Judge Mag. BRAUCHART, and with lay judge Dr. FELLNER-RESCH and the expert lay judge Mag. KUNZ as assessor, on the appeal XXXX, represented by SUMMEREDER PICHLER WÄCHTER Rechtsanwälte GmbH, against the penalty order of the Data Protection Authority of December 14, 2023, file no. D550.688 2023-0.615.432, after oral hearing, the following judgment is rendered: A) I. The appeal is partially granted pursuant to Section 50 Paragraph 1 of the Administrative Court Procedure Act (VwGVG), and the contested penalty order is amended to the effect that a) its operative provisions read: “XXXX, in its role as controller pursuant to Article 4 No. 7 GDPR, unlawfully processed special categories of personal data within the federal territory of Austria on November 22, 2021, at 5:05 p.m. and at 5:18 p.m. (hereinafter referred to as the “period of the offense”).” Within the meaning of Article 4 No. 1 in conjunction with Article 9 Paragraph 1 GDPR (special categories of personal data) processed by sending two different emails during the relevant period from Ms. XXXX (in her role as "Office Manager" of the XXXX Federal Office XXXX) with the sender address "XXXX" using an open email distribution list, each containing 400 email addresses, including at least 100 personalized email addresses. In addition to the email addresses, the political opinions and ideological convictions of the data subjects were also disclosed to the recipients of at least 100 email addresses within the distribution list due to the content of the emails. ... and - 2 - b) the imposed penalty is reduced to EUR 28,000.00. II. Pursuant to Section 64 Paragraph 1 of the Administrative Penalties Act (VStG), the appellant is required to pay a contribution to the costs of the proceedings before the respondent authority in the amount of EUR 2,800.00, which is 10% of the now imposed penalty. III. Pursuant to Section 52 Paragraph 8 of the Administrative Court Procedure Act (VwGVG), the appellant shall not bear any costs of the administrative court proceedings. B) The appeal on points of law is inadmissible pursuant to Article 133 Paragraph 4 of the Federal Constitutional Law (B-VG). Grounds for the decision: I. Procedural history and facts: 1. On November 23, 2021, a submission was received by the Data Protection Authority (DSB, respondent authority before the Federal Administrative Court) stating that the appellant, a political party, had issued a I sent an email which contained the email addresses of all recipients, visible to everyone, including email addresses with the first and last names of some recipients. The email also included two open letters, suggesting that all the listed email addresses, institutions, and named individuals were part of the complainant's campaign. 2. The respondent authority subsequently initiated an official review procedure (“data protection review”) pursuant to Articles 57 in conjunction with 58 in conjunction with Article 22 General Data Protection Regulation (GDPR) under reference number D213.1503 and, by letter dated November 30, 2021, requested the complainant to submit a statement. The email was also accompanied by two open letters, suggesting that all the listed email addresses, institutions, and named individuals were part of the complainant's campaign. 2. The respondent authority subsequently initiated an official review procedure (“data protection review”) pursuant to Articles 57 in conjunction with 58 in conjunction with Article 22 General Data Protection Regulation (GDPR) under reference number D213.1503 and, by letter dated November 30, 2021, requested the complainant to submit a statement. 3. On December 4, 2021, the complainant reported the following breach of the protection of personal data pursuant to Article 33 GDPR: As a result of sending an email to a large group of recipients on November 22, 2021, a breach of confidentiality occurred. An employee of the complainant erroneously and contrary to instructions, used an open email distribution list visible to all recipients to send the email. As a result of this action - 3 - the categories of personal data "first and last name", "email address", "employer of the data subject", and "management or employer position of the data subject" were disclosed. The complainant's employee sent the email to a total of 975 recipient addresses. Of these, approximately 100 addresses contained the name of a recipient and are therefore classified as personal data due to the identifiability of the address holder. The complainant became aware of the breach of personal data protection through an official review initiated by the respondent authority. The respondent authority first contacted the complainant on December 2, 2021. The complainant considers the risk to the rights and freedoms of natural persons arising from the breach of confidentiality to be minor. While identification of the data subjects is possible through the disclosure of three parameters (name, email address, employer), this information is largely also visible on the websites of the companies or departments of the data subjects and is therefore publicly accessible. The complainant assesses the criteria of the type, sensitivity, and scope of the data as having low sensitivity. 44 of the approximately 100 email addresses that contained personal data are publicly accessible on the internet. The disclosed categories of personal data primarily consist of names and email addresses, while no special categories of personal data, no data relating to criminal offenses, no location data, and no credit-related data are involved. The severity of the conceivable consequences is low. Neither sensitive data is involved, nor can the disclosed personal data be misused. Exposure of the data subjects through the disclosure of protected information from their privacy is ruled out, as is defamation or other violations of the right to privacy, because the disclosed personal data has exclusively official relevance, and no adverse opinion of the other recipients can be derived from it. The individuals concerned are employers active in the healthcare sector or their employees in management positions who are contact persons for a political campaign of the complainant. Through the disclosure, those individuals whose email addresses were not publicly accessible on the internet have partially and slightly lost control over this data in such a way that other addressed recipients could now contact them by email, possibly with knowledge of their disclosed position within the company. Furthermore, no restriction of the rights and freedoms of the individuals concerned is to be expected. Neither sensitive data is affected nor is it to be assumed that other recipients - 4 - will now misuse the disclosed data. The disclosure of the email address is not to be expected to result in any exposure, discrimination, or similar harm. The complainant has commissioned an external data protection officer to evaluate the data processing procedures within the party. This should be done to conduct a review of all data processing activities in order to identify and mitigate potential risks early on. Furthermore, the complainant has implemented a CMS system. This will be used in the future for sending emails addressed to multiple recipients. The complainant's employees involved in political campaigns are trained in the principles of data protection. The complainant does not expect that the recipients of the disclosure will use the received email addresses to contact other recipients without their consent. The recipients all belong to the same market. Therefore, it is not expected that one recipient will conduct marketing activities against another. Recalling the sent email addresses is technically impossible. Sending another email to the same recipients with a note not to use these email addresses for marketing purposes or similar could, at best, have the opposite effect and create the very idea. The complainant therefore decided not to send any further emails to the same recipients in order to avoid increasing the adverse effects. Because no other possible adverse effects were conceivable, the complainant did not consider or take any further measures. 4. On January 7, 2022, the complainant submitted a statement explaining that as the data controller within the meaning of Article 4(7) GDPR, the complainant had collected and stored the email addresses in question from party members and used them on November 22, 2021, for the purpose of a political campaign to send the letter dated November 22, 2021. Due to the negligence of an employee, these email addresses were disclosed in breach of confidentiality, which the complainant reported to the respondent authority on December 4, 2021, pursuant to Article 33 of the GDPR. The complainant processed the first and last name, email address, and employment details (employer, industry, position) based on a legitimate interest within the meaning of Article 6(1)(f) of the GDPR (promotion of political interests). As can be seen from the letter of November 22, 2021, the complainant pursued the purpose of influencing the government's decision-making process, specifically targeting the addressed members of the Federal Government, state governors, and state health ministers. In order to lend the announcement of an impending strike to the Federal Ministry and other decision-makers the necessary political weight, the complainant was compelled to inform other decision-makers in the health sector as well as the press. For this purpose, the complainant was also entitled to process the aforementioned personal data of these decision-makers at the political level, in the health sector, and in the press, provided that this did not conflict with overriding interests of the data subjects. The balancing of interests favors the complainant, since only data from the professional sphere was involved and most of the processed personal data is publicly available. No overriding confidentiality interests exist. The processing of the aforementioned categories of personal data only affects, at most in the abstract, the control of the data subjects over their data, but poses no further risks to their rights and freedoms: For example, there is no risk of exposure of the most private sphere of life, nor are there any economic disadvantages, such as those that arise from the processing of credit-related data. 5. By decision of the respondent authority dated April 22, 2022, file number D213.1503 2022-0.016.020, the authority decided on the ex officio review procedure as follows: "The controller violates the GDPR by unlawfully disclosing personal data in the form of personalized email addresses, insofar as a specific or identifiable personal reference can be derived from the email addresses, or insofar as they are not generic email addresses, through the sending of the emails of November 22, 2021, at 5:05 p.m. and 5:18 p.m. in an open email distribution list, and thereby unlawfully publishing the political opinions of the data subjects due to the lack of a legal basis for processing pursuant to Article 9(2) GDPR, by making them visible to other recipients. The controller is hereby ordered to cease and desist from this processing." With immediate effect, the processing of the aforementioned personalized email addresses without the consent of the data subjects within the meaning of Article 9(2)(a) GDPR is prohibited in the future. This decision became legally binding due to the lack of an appeal. 6. Subsequently, the respondent authority initiated administrative penalty proceedings against the appellant and XXXX (hereinafter: Dr. N.C.) as the appellant's chairman. By letter dated August 16, 2022, it requested the Federal Ministry of the Interior, Department III/3, to provide the appellant's statutes, filed pursuant to Section 1(4) of the Political Parties Act, by way of administrative assistance. 7. By letter dated August 19, 2022, the Federal Ministry of the Interior transmitted the appellant's statutes. - 6 - 8. The respondent authority informed the complainant by letter dated August 23, 2022, that it was suspected, as the data controller, of having unlawfully processed personal data of data subjects on November 22, 2021, at 5:05 p.m. and at 5:18 p.m. (hereinafter referred to as the “period of the offense”) in XXXX, by sending two different emails from Ms. XXXX (hereinafter: Mag. B.H.) with the sender address “XXXX” in her role as “Office Manager” of the complainant (Federal Office XXXX) to an open email distribution list, each containing approximately 400 email addresses, to [specifically named] recipients, thereby constituting administrative offenses under Art. 5 para. 1 lit. a and c as well as Art. 9 para. 1 in conjunction with Art. 83 para. Articles 1 and 5(a) of the GDPR, and requested justification. 9. On September 19, 2022, the complainant submitted a statement in which it was explained that the complainant had arranged for comprehensive instruction from Mag. B.H. and her immediate superiors to ensure the prevention of such incidents in the future. Measures had been implemented within the complainant's administration to ensure the necessary due diligence in the future and guarantee control by immediate superiors when sending emails. All email addresses related to the incident had been deleted from the complainant's IT and email systems. The statement included confirmation of the complainant's financial status for the year 2021 at the time of the incident. 10. At the request of the respondent authority, the appellant submitted a statement of current assets of EUR 123,353.57 on September 29, 2022, and a statement of total income for 2022 from membership fees and donations amounting to EUR 851,120.89 on October 24, 2022. 11. By decision of the respondent authority dated October 27, 2022, file number D550.688 2022-0.770.555, the proceedings were suspended pursuant to Section 24 of the Administrative Penalties Act (VStG) in conjunction with Section 38 of the General Administrative Procedure Act (AVG) pending a final and binding decision by the Court of Justice of the European Union (CJEU) in Case C-807/21. ... 12. By decision of the respondent authority dated December 5, 2023, file number D550.688 2023-0.804.939, the decision of the respondent authority dated October 27, 2022, was set aside following the publication of the judgment of the CJEU in the aforementioned preliminary ruling case, and the proceedings were continued. - 7 - 13. On December 14, 2023, the respondent authority issued a notification of the discontinuation of the administrative penalty proceedings against Dr. N.C. as chairperson of the accused appellant. 14. In the now contested penalty order of the same date, the respondent authority stated that the appellant had committed the following offense and thereby committed the following administrative offence: “XXXX, in her role as data controller pursuant to Article 4(7) GDPR, unlawfully processed special categories of personal data within the meaning of Article 4(1) in conjunction with Article 9(1) GDPR (special categories of personal data) by sending two different emails from Ms. XXXX (in her role as “Office Manager” of the XXXX Federal Office XXXX) with the sender address “XXXX” using an open email distribution list, each containing 400 email addresses, within the federal territory of Austria on November 22, 2021, at 5:05 p.m. and 5:18 p.m. (hereinafter referred to as the “period of the offense”). were sent. In addition to the email addresses, the political opinions and ideological convictions of the data subjects were also disclosed to the recipients on the distribution list due to the content of the emails. As a result, XXXX processed special categories of personal data contrary to the legally mandated prohibition under Article 9(1) GDPR and without an exception or legal basis under Article 9(2) GDPR. [The sentence is incomplete in the original text.] The complainant has therefore, as a result, processed a special category of sensitive personal data pursuant to Art. 4(1) in conjunction with Art. 9(1) GDPR (here, specifically, political opinions and philosophical beliefs) contrary to the prohibition of processing under Art. 9(1) GDPR and without an exception under Art. 9(2) GDPR, as well as the principle of processing personal data lawfully, fairly and in a transparent manner in relation to the data subject pursuant to Art. 5(1)(a) GDPR “lawfulness, fairness and transparency”) and the principle of processing of personal data that is adequate, relevant and limited to what is necessary for the purposes of the processing pursuant to Art. 5(1)(c) GDPR (“data minimization”). An administrative offense pursuant to Article 5(1)(a) and (c) and Article 9(1) in conjunction with Article 83(1) and (5)(a) GDPR has been committed. For this administrative offense, a fine of EUR 50,700.00 is imposed pursuant to Article 83(5)(a) GDPR. Furthermore, the appellant is required to pay a contribution of EUR 5,070.00 towards the costs of the proceedings pursuant to Section 64 of the Administrative Penal Code. The total amount payable (fine/costs/out-of-pocket expenses) is therefore EUR 55,770.00. The respondent authority made the following findings of fact: "1.2. Regarding the sending of the emails in question, including attachments On November 22, 2021, an employee of XXXX (Ms. XXXX in her role as "Office Manager" of the Federal Office XXXX) sent two different emails at 5:05 p.m. and 5:18 p.m. using an open email distribution list, each containing approximately 400 email addresses. These included personalized and some private email addresses (e.g., "@gmail.com"). "Open Letters" were attached to each email and referenced. XXXX alone made the decision regarding the form and sending of the aforementioned emails. The email distribution list was a distribution list of XXXX." The email addresses were collected by party members and used for the purpose of a political campaign within the context of the emails in question. The content of the political campaign, or rather both emails, consisted of two attached PDF files, titled "XXXX" and "XXXX". The PDF file titled "XXXX" contained the following (formatting not reproduced verbatim): The PDF file titled "Open Letter XXXX" contained the following (formatting not reproduced verbatim): 1.3. Income and Assets of the Accused XXXX generated a total of EUR 851,120.89 in income from membership fees and donations. Furthermore, in 2022, XXXX received - 9 - party funding in the amount of EUR 1,200,000 and has assets totaling EUR 123,353.57 (as of September 29, 2022). Legally, the respondent authority found that the complainant had unlawfully processed sensitive data by sending the emails in question on November 22, 2021, the complainant processed personal data by disclosing, among other things, the personalized email addresses of the data subjects to all persons and institutions listed on the distribution list, thereby disclosing the names and, in some cases, the workplace/employer of the data subjects to multiple recipients. This alone constituted an infringement of the fundamental right to privacy of the data subjects under Section 1, Paragraph 1 of the GDPR.1 GDPR. In this specific case, in addition to these data categories or information, the political opinions and ideological convictions of the data subjects were also disclosed to the recipients listed in the distribution list. The content of the emails in question, in conjunction with the purpose of the processing (conducting a “political campaign”), attributed a political opinion and ideological conviction to the data subjects and, consequently, disclosed them to all recipients through the distribution of the emails to an open distribution list. The processing of special categories of personal data pursuant to Article 9(1) GDPR is generally prohibited. Exceptions to the prohibition on processing are set out in Article 9(2) GDPR. The complainant based the processing solely on legitimate interests pursuant to Article 6(1)(f) GDPR, which do not constitute an exception for the processing of sensitive data pursuant to Article 9(1) GDPR. In this specific case, there was also no consent from the data subjects within the meaning of Art. 4 No. 11 in conjunction with Art. 7 in conjunction with Art. 9 para. 2 lit. a GDPR, and the complainant did not claim such consent. The remaining exceptions in Art. 9 para. 2 GDPR are also not applicable to the specific processing. Finally, with regard to the principle of data minimization pursuant to Art. 5 para. 1 lit. c GDPR, it can be pointed out that in the specific case, the necessity of the processing in question cannot be seen. The complainant could have conducted her political campaign without using an open distribution list. Transmission via "blind carbon copy" (BCC) would have achieved the desired result just as well. Therefore, the processing also occurred in disregard of the principle of data minimization, as it was not appropriate and relevant to the purpose and was limited to what is necessary for the purposes of the processing. Thus, the objective elements of a violation of the principles for processing under Article 5(1)(a) and (c) GDPR and the prohibition of processing under Article 9(1) GDPR were fulfilled. - 10 - Regarding the appellant's criminal liability as a legal entity under Article 83 GDPR, it should be noted that the Administrative Court, in its ruling of May 12, 2020, Ro 2019/04/0229, addressed for the first time the applicability of the conditions for criminal liability under Section 30 Data Protection Act (DSG) in proceedings under Article 83 GDPR and, in this context, established that a legal entity cannot act on its own and therefore its criminal liability under Section 30 DSG is a consequence of the factual, unlawful, and culpable conduct of a natural person (managing director) within the meaning of Section 30(1) DSG. However, the CJEU ultimately ruled in its judgment of December 5, 2023, that the directly applicable provisions of Article 58(2)(i) and Article 83(1) to (6) GDPR must be interpreted as precluding a national regulation under which a fine for an infringement referred to in Article 83(4) to (6) GDPR against a legal person in its capacity as controller can only be imposed if that infringement has previously been attributed to an identified natural person. Consequently, the provisions of Section 30(1) and (2) of the GDPR are not applicable, as they would, in light of the CJEU's judgment, contrary to Article 83(1) to (6) GDPR by establishing (additional) substantive requirements for imposing a fine on a legal person. ``` The subjective element of the offense is also fulfilled, as culpability in the form of intent (Art. 83 para. 2 lit. b GDPR) exists. In the course of the investigation, no indications emerged to suggest that the complainant was not at fault for the violation of the applicable administrative regulations. In light of the case law of the CJEU regarding the unlawfulness of her conduct, the complainant could not have been unaware, regardless of whether she was aware that she was violating the provisions of the GDPR. The complainant's assertion that there was culpability in the form of negligence on the part of an employee is a mere pretext. Taking into account the purpose of the processing or the planned political campaign and in conjunction with the specific content of the email messages, the respondent authority concludes that the complainant made a conscious and deliberate decision to send the emails in question, including attachments, to an open distribution list. In essence, these messages in summary, the complainant claims to have found “countless like-minded individuals” in the health and care sector who wish to oppose the mandated vaccination, and this is apparently to be illustrated to the recipients of the message through the open distribution list containing numerous (partly private, partly work-related) email addresses. In conjunction with the specific wording of the message (for example, "We, healthcare workers..."; "We stand up against the discrimination of us, healthcare workers"; "We have found countless like-minded individuals in our profession, or more precisely, we have networked"; "WE ARE MANY"; "All of us are prepared to stop working and go on strike..."; "Finally, we would like to inform you that we have received notification from numerous healthcare professionals that they will stop working with immediate effect in the event of mandatory vaccination," etc.), the authority in question concludes that the complainant acted intentionally. The concluding part of the message also makes it clear that the complainant intended to convey to the recipients that she was signing the message on behalf of numerous healthcare and nursing staff from all federal states. This was to be illustrated by the open distribution list and the personalized email addresses it contained. Objectively speaking, this was intended to create the impression that the individuals listed on the distribution list were opposed to the mandatory vaccination and were prepared to stop working. Based on this, the respondent authority concluded that there was intent to commit the offense, and therefore the subjective element of the offense was fulfilled. Regarding sentencing, the respondent authority stated that it had applied the EDPB Guidelines on the calculation of administrative fines under the GDPR (see EDPB Guidelines 04/2022 on the calculation of administrative fines under the GDPR, Version 2.1 of 24 May 2023 – hereinafter also referred to as the “Fines Guidelines”). The complainant generated income from membership fees and donations totaling EUR 851,120.89 and also received party funding in the amount of EUR 1,200,000.00. Applying the Fines Guidelines, the complainant is classified in the second-lowest category (“Undertakings with a turnover of €2m up to €10m”) with regard to its income and the imposition of an effective, dissuasive, and proportionate fine. This classification ensures, in particular, the proportionality of the fine. In light of the facts deemed proven and taking into account the nature, severity, and duration of the infringement (Art. 83 para. 1 lit. a GDPR), the intentionality or negligence of the infringement (Art. 83 para. 2 lit. b GDPR), and the categories of personal data affected by the infringement (Art. 83 para. 2 lit. g GDPR), the authority concerned determined the severity of the infringement to be a high degree of severity. No aggravating circumstance was considered in determining the penalty; the intensity of the impairment or the interference with the fundamental right of the data subject to confidentiality had already been taken into account when determining the degree of severity. The following factors were taken into account as mitigating circumstances in determining the sentence: the complainant had no prior relevant GDPR violations at the respondent authority, the complainant cooperated in the investigation proceedings before the respondent authority and thereby contributed to establishing the truth, in particular by not denying the alleged facts and by showing remorse after being served with the request for justification, and the fact that the complainant promptly informed the respective employees and, moreover, deleted the email addresses and the distribution list in order to prevent such mailings in the future. The complainant also took into account the following mitigating factors: The complainant had no prior relevant GDPR violations at the respondent authority, the complainant cooperated in the investigation proceedings before the respondent authority and thereby contributed to establishing the truth, in particular by not denying the alleged facts and by showing remorse after being served with the request for justification, as well as the fact that the complainant promptly informed the respective employees and, moreover, deleted the email addresses and the distribution list in order to prevent such mailings in the future. The complainant cooperated in the investigation proceedings before the respondent authority and thereby contributed to establishing the truth, in particular by not denying the alleged facts and showing remorse after being served with the respondent authority. The complainant also cooperated in the investigation proceedings before the respondent authority and thereby contributed to establishing the truth, in particular by not denying the alleged facts and by showing remorse after being served with the respondent authority. The complainant also took into account the fact that the complainant had no prior relevant GDPR violations at the respondent authority and thereby made a contribution to establishing the truth, in particular by not denying the alleged facts and by showing remorse after being served with the respondent authority. The complainant cooperated in the investigation proceedings before the respondent authority and The imposition of the fine was not necessary in the sense of specific deterrence, but rather in the sense of general deterrence, in order to raise awareness among those responsible, in particular other political parties, regarding the legally compliant sending of emails using a distribution list and the associated obligations under the GDPR, especially when this involves the processing of sensitive data of data subjects. The resulting fine of EUR 50,700.00 therefore appears proportionate to the offense and the degree of culpability, in light of the actual harm committed, and measured against the available penalty range under Article 83(5) GDPR (here up to EUR 20,000,000.00), and is at the very lower end of the available penalty range (0.25% of the penalty range). 15. The appellant filed a timely appeal against this penalty order with the Federal Administrative Court pursuant to Article 130(1)(1) of the Federal Constitutional Law (appeal by a party), arguing the following: The penalty order issued by the respondent authority is challenged on the grounds of illegality of content and violation of essential procedural rules. The appellant had not violated any provisions of the GDPR, or at least, the appellant was not responsible for any potential violation due to lack of fault. The appellant had lawfully processed the approximately 400 email addresses of data subjects at issue in the proceedings. The conclusion that these email addresses constitute special categories of personal data pursuant to Article 9 of the GDPR is incorrect. For the recipients of the letter the list of recipients (distribution list) does not indicate which political - 13 - conviction a particular person belongs to, since it includes, on the one hand, political officeholders, on the other hand, the press and public, as well as certain individuals close to the petition. Without further indications, it is impossible for an individual recipient to infer the political orientation or worldview of other recipients. Members of various parties were among the recipients of the letter, and there is also a discrepancy between the number of recipients and the number of signatories of the petition. A complete link to the effect that all persons on the distribution list are members/supporters/signatories of the petition and thus of the complainant cannot be established for these reasons alone. Even assuming that special category personal data was processed, the complainant cannot be held responsible for the violation. The employee, Ms. B.H., who sent this letter to the distribution list, had only been hired a few weeks prior as an assistant to the complainant and the state organization XXXX. At the time of sending the letter, she was unaware that its transmission to the distribution list, which contained personal data, might, through its connection to the other content of the letter, indirectly reveal the political opinions and ideological convictions of the individuals named therein. She would not have sent the letter to the distribution list without further consideration, but would have paid particular attention to this circumstance before sending it and clarified beforehand whether any further necessary steps were required. In any case, the letter was sent due to excusable misconduct by an employee – who had previously been explicitly instructed during her onboarding to comply with data protection measures within the company, namely both in handling the personal data of colleagues and in handling other personal data of other persons (e.g., members, supporters, donors, etc.). The complainant considers compliance with data protection regulations extremely important as a political party, which is why all employees are sensitized to data protection during the hiring process and subsequently through regular training, and are obligated to comply with corresponding measures. The complainant was unaware that the employee would send this letter to all recipients on the distribution list simultaneously, and, given the comprehensive onboarding and the obligation of all employees to comply with data protection regulations, was not required to assume this. 14 - The complainant was therefore, within the meaning of the case law of the CJEU, uncertain about any potential unlawfulness on the part of an employee attributable to it. An excusable error by an employee cannot and should not lead to holding the complainant accountable as the responsible party for the first breach of data protection regulations – which is still being contested – especially not to the extent alleged. Furthermore, the respondent authority ignores the fact that the CJEU's decision in case C-807/21 was only issued on December 5, 2023, while the incident in question occurred on November 22, 2021 (more than two years earlier). Accordingly, the provision of Section 30 of the Data Protection Act (DSG), which remains valid and thus still in force, is applicable and must be taken into account (at least with regard to the question of culpability). Mag. B.H., however, neither held a (management) position as defined in Section 30 Paragraph 1 of the Data Protection Act (DSG) nor could the appellant be accused of a lack of supervision or control of a management position. For this reason alone, punishment is precluded due to the lack of (attributable) fault on the part of the appellant. Should the Federal Administrative Court share the view of the respondent authority that the employee's conduct is attributable to the appellant insofar as the appellant is also at fault, then at most the appellant could be considered negligent – and not intentional – which would, of course, have a significant impact on sentencing. The respondent authority itself states in the penalty order that punishment does not appear necessary for special preventive reasons, especially given that the appellant has no prior administrative offense record. The mitigating circumstances significantly outweigh the aggravating circumstances, and the infringement of the legally protected interest (only an indirect connection to the political stance) is comparatively extremely minor. In this specific case, a warning would therefore have sufficed. In any event, the amount of the imposed fine is excessive. Previous penal practice indicates fines in the range of approximately EUR 10,000.00. The respondent authority failed to interview the persons relevant to the present case, despite a request to do so. Had the authority in question – in accordance with its duty to ascertain the material truth – interviewed the employees involved, Ms. B.H., Ms. XXXX (hereinafter: G.S.), and the then-chairman, Dr. N.C., it would have concluded that, firstly, individual recipients of the letters could not be attributed to a specific political conviction or – 15 – worldview – namely, that of the complainant, and furthermore, that the complainant, lacking knowledge of the mailing to the entire distribution list and due to the training and obligation of all employees to comply with data protection regulations, could not be held liable for any (organizational) negligence. ... The respondent authority, with the issued penalty order, violates the complainant's right to equality before the law pursuant to Art. 7 para. 1 of the Federal Constitutional Law (B-VG) and Art. 2 of the Federal Constitutional Court Act (StGG) by attributing an unequal content to the applicable law and grossly misinterpreting the substantive legal provisions, as well as by arbitrarily serious procedural defects and by ignoring the parties' submissions. However, even if the Federal Administrative Court were to share the respondent authority's view and conclude that the affected persons' rights to confidentiality and data protection had been violated, the respondent authority, with its action (namely, the imposition of the administrative penalty), disproportionately infringes upon the fundamental political rights of the complainant and her members/supporters/signatories. The complainant's activities as a political party may not be subject to any restrictions pursuant to Section 1 of the Political Parties Act. This includes the sending of any letters conveying the collective opinion of like-minded individuals (here: approximately 9,000 signatories of the petition) to persons who hold a different political stance/opinion. 16. By letter dated January 22, 2024, the respondent authority submitted the complaint, along with the relevant files of the administrative penalty proceedings (including the administrative files relating to the official review procedure [D213.1503]), to the Federal Administrative Court for a decision and issued a statement defending the contested decision and arguing that the alleged training measures and agreements in the employment contract were irrelevant due to the non-application of Section 30 Paragraph 2 of the Data Protection Act. The appellant misunderstands the legal situation regarding the applicability of Section 30 of the Data Protection Act (DSG). Decisions of the CJEU have retrospective effect, create objective law, and extend beyond the initial legal dispute to the effect that all courts and administrative authorities of the Member States must comply with the interpretation made by the CJEU. The CJEU has made it unequivocally clear that no action, and not even knowledge of the infringement, on the part of the governing body of a legal person is required (see CJEU of 5 December 2023, C-807/21, paragraph 77). This is not altered by the appellant's argument that, due to the mentioned measures, she was "uncertain about any potential illegality on the part of an employee attributable to her". Whether the culpability was in the form of intent or negligence is not decisive for the appellant's criminal liability or the fulfillment of the subjective element of the offense. The argument regarding the alleged violation of the freedom to form and operate political parties is limited to general statements and fails to provide a detailed explanation as to how the sending of the two emails in question via an open distribution list was necessary for the exercise of the freedom “freedom of operation” as a political party. The complaint is also internally contradictory in this respect. On the one hand, the complainant argues that no intent can be attributed to her because the sending via an open distribution list occurred due to the misconduct of an employee (thus admitting that sending via a distribution list was not necessary), and on the other hand, it is necessary and must be possible for the complainant, as a political party, to send such messages via an open distribution list for the purpose of conducting a political campaign in order to exercise her rights as a political party. ... Regarding the alleged procedural errors, it should be noted that the appellant, during the investigation in the administrative penalty proceedings, only submitted a brief justification and limited herself to the bare essentials. Neither during the administrative penalty proceedings nor during the official review proceedings did the appellant request the examination of the aforementioned persons. Regardless, the alleged procedural errors are not relevant. Even if the corresponding findings had been made, the issue of proof raised by the appellant would not have led to a different outcome (dismissal or warning). The question of whether the sending of the emails in question constituted the disclosure of sensitive data arises from the email messages themselves and is, moreover, a legal question. The argument/argument that there was no organizational negligence and that the employee's conduct could therefore not be attributed to the complainant is irrelevant for the reasons stated above. Regarding the argument that the fine is "excessive" and that the respondent authority imposed a fine of EUR 10,000 (against a natural person) in a more specifically cited "much worse case" (DSB-D550.185), it should be noted that a reference to other penalty rulings (regardless of the fact that the cited case is not comparable) is irrelevant, since a supervisory authority, when imposing a fine pursuant to Article 83(1) GDPR, must ensure that the fine is effective, proportionate, and dissuasive in each individual case. The respondent authority carried out such an individual assessment and also applied the Fines Guidelines of the EDPB. 17. The Federal Administrative Court forwarded the respondent authority's statement submitted with the case file to the appellant for her information and response. 18. On February 19, 2024, the appellant submitted a statement in which she reiterated her arguments from the party appeal and stated that the respondent authority again failed to recognize that the provision of Section 30 of the Data Protection Act (DSG), which remains in force and is therefore applicable, must be taken into account accordingly (at least with regard to the question of culpability). However, even the decision of the CJEU in Case C-807/21 cited by the respondent authority is being misinterpreted by it. Because, according to this decision, only a culpable violation leads to the imposition of a fine. This is the case if the responsible party (here: the appellant) could not have been unaware of the unlawfulness of their conduct. In this context, the respondent authority continues to fail to provide justifications as to why data protection training measures and contractual obligations to comply with data protection regulations are insufficient to conclude the lack of awareness regarding any potential unlawfulness on the part of an employee attributable to the appellant. 19. In a letter dated August 14, 2024, the appellant further argued that the admitted error by Mag. B.H. could not automatically lead to a penalty for the appellant, particularly if no systematic deficiencies or organizational shortcomings could be demonstrated. The appellant took all necessary measures to prevent such an incident, therefore no fault can be attributed to her. Attached to the written submission was the data protection and confidentiality declaration signed by Mag. B.H. on November 1, 2021. - 18 - 20. The Federal Administrative Court held a public oral hearing in the present data protection matter, in which the appellant, her legal representatives, and the respondent authority participated. Furthermore, two employees of the appellant, Mag. B.H. and G.S., as well as the former chairman of the appellant, Dr. N.C., were heard as witnesses. The witness Mag. B.H. stated in particular that she had been employed as a secretary by the appellant from November 2021 to January 2023. The two emails in question, dated November 22, 2021, were sent by her on the instructions of G.S. G.S. came in and presented her with a letter addressed to the healthcare staff. She couldn't remember now whether it was in paper form or as an email; she believed it was an email. G.S. said, "There's a letter; we'll send it to the healthcare staff by email." Then G.S. gave her an electronic list with approximately 800 to 1,000 email addresses to which the letter was to be sent. G.S. and she went through the letter again to check that everything was correct in terms of spelling. She then sent the letters to all the recipients on this list, as instructed. She made a mistake in the process. It was a somewhat stressful situation. Normally, one would send it in blind copy, "bcc," but she made a typo and sent the emails in "cc." She believes she entered herself as the recipient. From the next day onward, there were various responses; there were also approximately 15-20 responses from people who no longer wanted to be on the distribution list. The distribution list was subsequently discontinued. Some people explicitly said they wanted nothing to do with the complainant and wanted to receive nothing from her. Whether the issue of "cc" and "bcc" had been discussed prior to sending the emails, she could no longer say; that was three years ago. Witness G.S. stated in particular that she currently held no position with the complainant at the time of the incident, she was the complainant's deputy secretary. She had received the addresses electronically from XXXX (hereinafter: Dr. P.), the managing director and federal finance officer, printed them out and gave them to Mag. B.H. for processing. She showed her on the computer how to send emails with "bcc," Blind Copy. She no longer remembers who gave her this instruction. Mag. B.H. was supposed to type in the addresses. It took her an extremely long time, and at some point, Mag. B.H. came to her and said, "I've done it," and went home. She no longer remembers how many addresses were on the list or whether she also forwarded the email with the addresses to Mag. B.H. She is - 19 - no longer sure what exactly was supposed to be sent, but she believes it was an open letter to the Minister of Health or the healthcare personnel. Before sending it, she apparently didn't proofread the letter with Mag. B.H. The witness Dr. N.C. stated that he was a co-founder and, from February 14, 2021, to January 12, 2022, the federal party chairman of the complainant. The federal executive committee had decided that these messages should be sent, but he had not actually carried out the sending himself. As far as he could remember, the addresses had come from Dr. P., who had assured him that they were all official email addresses that could also be found on the internet. He himself had not concerned himself with the addresses; his task had been political work. Besides, the mailing should, of course, have been done in such a way that the addresses were not visible, if only for reasons of discretion and courtesy. It is self-evident and does not need further discussion that such things are sent via blind copy. Whether it was specifically discussed, he no longer knows today. As far as he knows, approximately two recipients complained. The complainant then tried to rectify everything. The respondent authority stated that the complainant had attempted, through the requested witnesses, to create the impression that there was no organizational negligence within the complainant. However, she fundamentally overlooked the fact that this is irrelevant. The respondent authority had already explained that criminal liability does not depend on Section 30 Paragraph 2 of the Data Protection Act. Ultimately, the culpability of the complainant must be assessed based on the actions of Mag. B.H. Her conduct is directly attributed to the legal entity, even without organizational negligence. The complainant does not dispute the misconduct of Mag. B.H. With regard to the subjective element of the offense, it should be noted that intent is not a necessary element of the offense. The appellant's argument that extraordinary mitigating circumstances exist within the meaning of Sections 19 and 20 of the Administrative Penal Code (VStG) is also without merit, since the CJEU, in its judgment C-807/21, unequivocally held that the substantive requirements for a fine are conclusively regulated in Article 83(1) to (6) GDPR. Finally, attention should be drawn to the accountability of the appellant under Article 5(2) GDPR, which has not been fulfilled in any way here. The complainant stated that she currently possesses no assets. The party's expenses are covered by third parties. The complainant currently receives no party funding because it is not represented in any parliament. In 2024, the complainant received membership fees totaling EUR 70,000.00 from approximately 2,400 individuals; these funds have been entirely spent. Party funding for the XXXX, a separate legal entity, amounted to EUR 1.2 million for the year 2024. The complainant's legal representative referred to the previous submissions and reiterated that the complainant had not processed any special categories of personal data, since the recipients of the emails – contrary to the apparent assumption of the respondent authority – were not exclusively political supporters of the complainant, but also included persons notorious in the courts as belonging to other political parties, as well as journalists and other public figures. It is therefore not possible to infer a person's political orientation from their email address, which is why a violation of Article 9 GDPR is impossible. The respondent authority also failed to make any finding regarding a political conviction in its penalty order. The facts established by the authority are therefore insufficient in themselves to support the cited judgment. The annulment of the penalty order and the discontinuation of the proceedings pursuant to Section 45 of the Administrative Penal Code are requested. 21. By letter dated October 3, 2024, the complainant submitted evidence of her current income and assets. 22. On October 15, 2024, the respondent authority issued a statement regarding the documents submitted by the complainant, arguing that it should be taken into account that the complainant does not generate "turnover" in the classical sense (the sum of all income from the sale of goods or services), but primarily income from membership fees, donations, and statutory subsidies (party funding). The submitted "turnover lists" were from the current and not yet completed year (reference period 2024). However, the wording of Article 83(5) GDPR indicates that only the complainant's income in the preceding (completed) year is relevant. The documents submitted by the complainant were therefore already irrelevant. The account balance cited also does not constitute the decisive basis for any potential sentencing by the adjudicating panel. The wording and structure of Article 83(2) GDPR indicate that the primary focus is on the established infringement and its severity, and no subjective right to the imposition of a "minimum penalty" can be inferred from the cited account balance. Regardless, the respondent authority disputes that the submitted - 21 - transaction statements represent all of the complainant's income in the form of membership fees, donations, and party subsidies in the previous year. With regard to statutory party subsidies, it is common knowledge that the complainant's state organization in XXXX receives EUR 1.2 million annually in party subsidies. There can be no talk of two separate entities here. There are obvious interconnections. For example, the appellant is represented externally by the members of the XXXX State Parliament, and the public data protection declaration of the XXXX organization states that the appellant is the controller within the meaning of Article 4(7) GDPR for the processing of personal data. II. The Federal Administrative Court considered the following: 1. Findings: 1.1. The statements above under point I. regarding the procedural history (administrative proceedings) are established. 1.2. The appellant is a political party active in Austria and Europe, headquartered in XXXX. The appellant constitutes the party's federal organization; in addition, there is a state organization with its own legal personality for each Austrian federal state, with personnel and organizational interconnections. The current federal party chairman of the complainant, XXXX, is also state party chairman of the complainant's state organization in XXXX (XXXX), the deputy federal party chairman, XXXX, is also XXXX member of the state parliament for XXXX, and the federal organization's finance officer, XXXX, holds the office of parliamentary group chairman of the XXXX parliamentary group in the XXXX state parliament and is state party chairman. There is a unified membership; every member is a member of the federal party and is also listed as a state party member, if applicable. Active members can be elected or sent as delegates and thus also to the bodies of the federal party executive committee. Insofar as it is necessary for the conduct of federal elections or federal political actions decided upon by federal bodies, all institutions, functionaries, employees, and volunteers of the party and its sub-organizations must comply with the federal party's guidelines. 1.3. On November 22, 2021, Ms. B.H., in her role as "Office Manager" or secretary, sent two emails with attachments (two attached PDF files; "Open Letters") to the complainant for the purpose of a political campaign at 5:05 p.m. and at 5:18 p.m. an open email distribution list visible to all recipients, each containing approximately 400 email addresses in the "To" field. At least 100 of these were personalized email addresses, clearly displaying the recipients' full names, including both work and private email addresses of individuals. Specifically, the following email addresses were disclosed to the following recipients: The content of the political campaign, or rather both emails, consisted of two attached PDF files, titled "Open Letter XXXX" and "Open Letter XXXX". The findings of fact made by the respondent authority regarding the content of the "Open Letters" under Point I.14, Point 1.2 of the contested penalty order, form the basis of the court's findings. The email addresses were obtained from publicly accessible sources by the former managing director and CFO of the appellant, Dr. P. The email recipients were primarily decision-makers at both the political level and in the healthcare sector, healthcare institutions (hospitals, senior citizens' and nursing homes, etc.), and generally individuals working in the healthcare sector (as employees) who are not (exclusively) party members or political allies of the complainant. There is no consent from all affected individuals for the data processing in question, in particular for publication. 1.4. It cannot be established that, with regard to the emails at issue in these proceedings, the email addresses were deliberately placed in the "To" field and not in the "Bcc" field before the emails and the "Open Letters" were sent to the respective recipients. 1.5. Following the sending of the emails in question, approximately 15 to 20 individuals complained to the complainant about the email(s) they had received and stated that they wanted nothing to do with the complainant and did not want to receive anything from her. 1.6. In 2022, the complainant generated total revenue of EUR 851,120.89 from membership fees and donations. Furthermore, in 2022, the complainant received party funding in the amount of EUR 1,200,000.00 and had total assets of EUR 123,353.57 as of September 29, 2022. The total revenue for 2022 thus amounted to EUR 2,051,120.89. In 2024, the appellant received membership fees totaling EUR 70,000.00 from approximately 2,400 individuals. Party funding for XXXX amounted to EUR 1,200,000.00 for the year 2024. The balance of the appellant's current account at XXXX, IBAN XXXX, was EUR 4,304.62 as of September 27, 2024. The total revenue for the year 2024 thus amounted to EUR 1,270,000.00. 2. Evaluation of Evidence: The findings are based on the submitted administrative documents and the case files, in particular the transcript of the oral hearing before the Federal Administrative Court. In detail: The findings regarding point 1.2. The findings are based on publicly available information on the complainant's website XXXX (accessed on October 14, 2024) and on the – also publicly available – statutes/bylaws of the complainant (XXXX) and of the complainant's state organization XXXX (XXXX). The findings regarding point 1.3 are based on the emails dated November 22, 2021, contained in the case file, the contested penalty order issued by the respondent authority, in conjunction with the findings from the decision regarding the official review proceedings, as well as the complainant's own submissions and the witness statements. The sending of the emails at issue in these proceedings by an employee of the appellant to the listed (established) email addresses/recipients using an open distribution list, thereby disclosing them to the respective recipients, and the content of the sent emails is evident from the two emails themselves and was not disputed or even presented by the appellant - 24 - The same applies with regard to the fact that personalized email addresses were among the disclosed recipients: The disclosure of at least 100 (168 according to the Federal Administrative Court's count) personalized email addresses, from which full names were evident, including both official and private email addresses of natural persons, in particular a specific named employee of healthcare facilities, is objectively proven by the emails in question dated November 22, 2021, and was ultimately admitted by the appellant herself, especially since she stated in her notification pursuant to Art. Article 33 of the GDPR of December 4, 2021, stated that approximately 100 email addresses qualify as personal data because of the identifiability of the address holder. The complainant also presented, and did not dispute, the specific circumstances of the collection of the email addresses: that they were used for the purpose of a political campaign, that they were email addresses of organizations/individuals who are not (exclusively) party members or political like-minded individuals, and that no consent had been obtained from all data subjects for the data processing in question, in particular for publication. The fact that the email addresses were collected from publicly accessible sources by the former managing director and CFO of the complainant, Dr. P., is also evident from the testimony of Dr. N.C. Regarding the finding in point 1.4. It must be noted that – contrary to the statements of the respondent authority in the contested penalty order – the Federal Administrative Court has not found that it was a conscious and deliberate decision by the appellant to insert the email addresses in the "To" field instead of the "bcc" field before sending the emails and the "Open Letters" to the respective recipients. While it became apparent during the oral proceedings before the Federal Administrative Court that the witnesses heard were no longer able to recall the specific circumstances of the sending of the emails in question with sufficient certainty, witness G.S., when questioned, could not definitively state what exactly was to be sent, how many email addresses were involved, or whether she had contacted Mag. B.H. Whether the list of email addresses was also transmitted electronically or only in printed form, and whether – as Mag. B.H. stated – she checked the letter again with Mag. B.H. for spelling accuracy before sending it. The witness Mag. B.H. also testified that she had made a mistake when sending the emails, that she had "typed" and sent the emails in "cc" instead of "bcc", however, it is established that the email addresses were sent in the "To" field and not – as Mag. B.H. – 25 – repeatedly testified – in the "cc" field, so that it must also be assumed that the witness Mag. B.H. no longer had a concrete recollection of the actual circumstances of sending the emails. Nevertheless, the witness Mag. B.H. It can generally be accepted that she made a mistake when sending the emails by accidentally entering the email addresses she should have sent using the "bcc" function into the wrong field. Witness G.S. and witness Dr. N.C. also testified consistently and convincingly that the emails in question should have been sent in such a way that the addresses were not visible. Witness Dr. N.C. emphasized in particular that there was "no need to discuss further that such things are sent in blind copy." Against this background, the Federal Administrative Court assumes that in the appellant's daily work, such letters or political campaigns were generally sent to the respective recipients without an open distribution list. This is also supported by the fact that – as the respondent authority also stated in the contested penalty order the appellant immediately instructed the affected employees and furthermore deleted the email addresses and the distribution list in order to prevent such mailings in the future. In the specific case, this means that the contents of the file, in conjunction with the appellant's statements and those of the witnesses heard, do not support the conclusion that it was a conscious and deliberate decision by the appellant to insert the email addresses in the "To" field instead of the "Bcc" field, but rather that an error by one of her employees led to the disclosure of the email addresses. ... If the respondent authority concludes, based on its assessment of the evidence, that the appellant intended to demonstrate to the recipients of the message, through the open distribution list, that she had found "countless like-minded individuals" in the health and care sector who wished to oppose the mandated vaccination, it must be noted that this is ultimately a speculative assumption by the respondent authority, which – despite an oral hearing and supplementary taking of evidence by the Federal Administrative Court – could not be substantiated by any concrete evidence. Even the reference to the specific wording of the open letters (for example, “We, the employees of the healthcare sector…”; “We stand up against the discrimination against us, the employees of the healthcare sector”; “We have found countless like-minded people in our profession, more precisely, we have networked”; “WE ARE MANY”; “All of us are ready to – 26 – stop work and go on strike…”; “Finally, we would like to inform you that we have received notification from numerous people in the healthcare professions that they will stop working with immediate effect in the event of mandatory vaccination,” etc.) does not support the assumption of a deliberate action by the complainant, especially since it can be read ambiguously, for example, to mean that – as the complainant claims – she wanted to win over the recipients of the letters to her political ideas, or that the letters were intended as a wake-up call to the complainant to be added. The finding regarding point 1.5 is based on the testimony of Mag. B.H. during the oral hearing before the Federal Administrative Court. Witness Dr. N.C. testified contrary to this, stating that (only) approximately two recipients had complained, but simultaneously indicated that he had not been further involved in the matter, as it had been handled by the management, the appellant's former legal representative, and XXXX. Therefore, the Federal Administrative Court accepts the testimony of Mag. B.H. especially since she was directly involved as the sender of the emails and also stated that she had collected the expressions of dissatisfaction in a folder and verbally shared them with colleagues. The findings regarding the appellant's income and assets under point 1.6. The following conclusions are drawn from the appellant's statements in the administrative proceedings, in the oral hearing before the Federal Administrative Court, and from the submitted, unobjectionable documents. 3. Legal Assessment: Regarding A) 3.1. Pursuant to Section 6 of the Federal Administrative Court Act (BVwGG), the Federal Administrative Court decides by a single judge, unless federal or state law provides for a decision by a panel. Pursuant to Section 27 of the Data Protection Act (DSG) as amended, the Federal Administrative Court decides in proceedings concerning appeals against decisions, violations of the duty to provide information pursuant to Section 24 Paragraph 7, and the duty of the data protection authority to make a decision, by a panel. The panel consists of a presiding judge and one lay judge each from the group of employers and from the group of employees. The procedures of the administrative courts, with the exception of the Federal Fiscal Court, are governed by the Administrative Court Procedure Act (VwGVG), Federal Law Gazette I 2013/33 as amended by Federal Law Gazette I 2013/122 (§ 1 of the aforementioned Act). Pursuant to § 58 para. 2 - 27 - VwGVG, conflicting provisions that were already promulgated at the time of entry into force this Federal Act remain in force. The Administrative Court Procedure Act (VwGVG) Pursuant to Section 17 of the Administrative Court Procedure Act (VwGVG), unless otherwise provided in this Federal Act, the provisions of the General Administrative Procedure Act (AVG), with the exception of Sections 1 to 5 and Part IV, the provisions of the Federal Fiscal Code (BAO), Federal Law Gazette No. 194/1961, the Agricultural Procedure Act (AgrVG), Federal Law Gazette No. 173/1950, and the Civil Service Procedure Act 1984 (DVG), Federal Law Gazette No. 29/1984, and, in all other respects, those procedural provisions in federal or state laws apply mutatis mutandis to the proceedings concerning appeals pursuant to Article 130 Paragraph 1 of the Federal Constitutional Law (B-VG), with the exception of Sections 1 to 5 and Part IV, the provisions of the Federal Fiscal Code (BAO), Federal Law Gazette No. 194/1961, the Agricultural Procedure Act (AgrVG), Federal Law Gazette No. 173/1950, and the Civil Service Procedure Act 1984 (DVG), and, in all other respects, those procedural provisions in federal or state laws which the authority applied or would have been required to apply in the proceedings preceding the proceedings before the Administrative Court. ... Pursuant to Section 28 Paragraph 1 of the Administrative Court Procedure Act (VwGVG), the Administrative Court must decide the case by judgment unless the appeal is to be dismissed or the proceedings discontinued. Pursuant to Section 31 Paragraph 1 of the VwGVG, decisions and orders are issued by order, unless a judgment is to be issued. Pursuant to Section 28 Paragraph 2 of the VwGVG, the Administrative Court must decide on the merits of appeals pursuant to Article 130 Paragraph 1 Item 1 of the Federal Constitutional Law (B-VG) if (1) the relevant facts are established or (2) the establishment of the relevant facts by the Administrative Court itself is in the interest of expediency or would result in significant cost savings. 3.2. Regarding the procedural requirements: The appeal was filed within the prescribed time limit, and the other procedural requirements are also met. 3.3. On the merits: 3.3.1. Legal basis: The relevant provisions of Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) and the Administrative Penal Code 1991 (VStG) are as follows (excerpt, including heading): Article 4, paragraphs 1, 2 and 7 GDPR: - 28 - “1.“Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; 2. “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; 7. ‘Controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for by Union or Member State law; Article 5 GDPR: “Principles relating to the processing of personal data (1) Personal data shall be a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’); b) collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes; Further processing for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes is not considered incompatible with the original purposes (“purpose limitation”) in accordance with Article 89(1); c) adequate, relevant, and limited to what is necessary for the purposes for which they are processed (“data minimization”); d) accurate and, where necessary, kept up to date; all reasonable steps must be taken to ensure that personal data which are inaccurate in relation to the purposes for which they are processed are erased or rectified without delay (“accuracy”); e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed; - 29 - Personal data may be stored for longer periods if, subject to the implementation of appropriate technical and organizational measures required by this Regulation to safeguard the rights and freedoms of the data subject, the personal data are processed solely for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with Article 89(1) (“storage limitation”); (f) are processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical and organizational measures (“integrity and confidentiality”); (2) The controller shall be responsible for compliance with paragraph 1 and must be able to demonstrate compliance (“accountability”). (f) Article 6 GDPR: "Lawfulness of processing (1) Processing shall be lawful only if at least one of the following conditions is met: a) The data subject has given consent to the processing of his or her personal data for one or more specific purposes; b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; c) processing is necessary for compliance with a legal obligation to which the controller is subject; d) processing is necessary in order to protect the vital interests of the data subject or of another natural person; e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data override, in particular where the data subject is a child. Paragraph 1(f) shall not apply to processing carried out by public authorities in the performance of their tasks. (2) Member States may maintain or introduce more specific provisions to adapt the application of the provisions of this Regulation with regard to processing for the purposes of paragraph 1(c) and (e) by specifying more precisely the specific requirements for the processing and other measures to ensure lawful and fair processing, including for other specific processing situations referred to in Chapter IX. (3) The legal basis for processing referred to in paragraph 1(c) and (e) shall be determined by (a) Union law or (b) the law of the Member State to which the controller is subject. The purpose of the processing must be specified in that legal basis or, with regard to the processing referred to in paragraph 1(e), be necessary for the performance of a task carried out in the public interest or in the exercise of official authority. is carried out, which has been transferred to the controller. This legal basis may contain specific provisions to adapt the application of the provisions of this Regulation, including provisions on the general conditions that govern the lawfulness of processing by the controller, the types of data processed, the data subjects, the entities to which and for which purposes the personal data may be disclosed, the purpose limitation to which they are subject, how long they may be stored, and the processing operations and procedures that may be applied, including measures to ensure lawful and fair processing, such as those for other specific processing situations referred to in Chapter IX. Union law or the law of the Member States must pursue an objective in the public interest and be proportionate to the legitimate purpose pursued. (4) Where processing for a purpose other than that for which the personal data were collected is not based on the data subject’s consent or on Union or Member State law which provides for such a purpose, the processing must be carried out in accordance with the applicable legal provisions. a democratic society where processing constitutes a necessary and proportionate measure for the protection of the objectives referred to in Article 23(1), the controller shall, in order to determine whether processing for a different purpose is compatible with that for which the personal data were originally collected, take into account, inter alia, a) any link between the purposes for which the personal data were collected and the purposes of the intended further processing, b) the context in which the personal data were collected, in particular with regard to the relationship between the data subjects and the controller, c) the nature of the personal data, in particular whether special categories of personal data pursuant to Article 9 are processed or whether personal data relating to criminal convictions and offences pursuant to Article 10 are processed, d) the possible consequences of the intended further processing for the data subjects, e) the existence of appropriate safeguards, which may include encryption or pseudonymization. Article 9 GDPR "Processing of special categories of personal data (1) The processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation, shall be prohibited. (2) Paragraph 1 shall not apply in the following cases: a) the data subject has given explicit consent to the processing of the personal data referred to in paragraph 1 for one or more specified purposes, unless, under Union or Member State law, the prohibition in paragraph 1 cannot be overridden by the data subject's consent; b) processing is necessary for the controller or the data subject to perform their personal data.to exercise their rights arising from employment law and social security and social protection law, and to comply with their obligations in this regard, insofar as this is permitted under Union law or the law of the Member States or a collective agreement under the law of the Member States which provides suitable safeguards for the fundamental rights and interests of the data subject, c) processing is necessary to protect the vital interests of the data subject or of another natural person and the data subject is physically or legally incapable of giving consent, d) processing is carried out on the basis of suitable safeguards by a politically, ideologically, religiously or trade union-oriented foundation, association or other non-profit organization in the course of its legitimate activities and provided that the processing relates exclusively to the members or former members of the organization or to persons who have regular contact with it in connection with its purpose, and the personal data are not processed without Consent of the data subject disclosed externally, e) the processing relates to personal data which the data subject has manifestly made public, f) the processing is necessary for the establishment, exercise or defence of legal claims or for the performance of judicial acts, - 32 - g) the processing is based on Union or Member State law which is proportionate to the objective pursued, respects the essence of the right to data protection and provides for appropriate and specific measures to safeguard the fundamental rights and interests of the data subject, necessary for reasons of substantial public interest, h) the processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, for medical diagnosis, the provision of health or social care or treatment or for the management of health or social care schemes and services based on Union law or the law of a Member State or pursuant to a contract with a healthcare professional and subject to the conditions and safeguards referred to in paragraph 3, i) processing is necessary for reasons of public interest in the area of public health, such as protection against serious cross-border threats to health or to ensure high standards of quality and safety in healthcare and in relation to medicinal products and medical devices, on the basis of Union or Member State law which provides for appropriate and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy, or j) processing is necessary on the basis of Union or Member State law which is proportionate to the objective pursued, respects the essence of the right to data protection and provides for appropriate and specific measures to safeguard the fundamental rights and interests of the data subject, for archiving purposes in the public interest, scientific or historical research purposes or necessary for statistical purposes in accordance with Article 89(1). (3) The personal data referred to in paragraph 1 may be processed for the purposes referred to in paragraph 2 (h) if such data are processed by or under the responsibility of professional personnel who are subject to professional secrecy under Union law or the law of a Member State or the rules of national competent authorities, or if the processing is carried out by another person who is also subject to a duty of confidentiality under Union law or the law of a Member State or the rules of national competent authorities. (4) Member States may introduce or maintain additional conditions, including restrictions, with regard to the processing of genetic, biometric, or health data. (2) Section 64, paragraphs 1 and 2 of the Administrative Penal Code: "Costs of Criminal Proceedings (1) Every penalty order must state that the convicted person is required to contribute to the costs of the criminal proceedings. (2) This contribution is to be calculated at 10% of the imposed penalty for the proceedings at first instance, but at least €10; in the case of custodial sentences, one day of imprisonment is to be credited as €100 for the calculation of the costs. The cost contribution accrues to the local authority, which is responsible for covering the expenses of the administration." 3.3.2. Applied to the present case, this means the following: 3.3.2.1. Regarding the fulfillment of the objective elements of the offense: Based on the facts it established, the respondent authority initially assumed that the material scope of application of Article 2(1) GDPR was applicable, since the email addresses disclosed in the present case through the use of the open email distribution list constitute personal data within the meaning of Article 4(1) GDPR, that the sending of the emails in question via the open distribution list undoubtedly constituted processing within the meaning of Article 4(2) GDPR, and that the complainant was to be classified as the controller of this data processing within the meaning of Article 4(7) GDPR. The complainant did not contest the respondent authority's legal assessment in this regard, and the Federal Administrative Court also finds no reason to believe that the respondent authority's statements in this respect are incorrect. It should also be noted that even if the email addresses used originate from public sources, this does not mean that the data protection regime does not apply. The data protection for already published data does not fundamentally differ from the scope of protection for other personal data. This means that not all data that is published or publicly accessible may be used by a controller for any purpose they choose (see: 2 Thiele/Wagner, Commentary on the Austrian Data Protection Act, Section 1 [as of February 1, 2022, rdb.at], para. 115 et seq. with further references). If lawfully published data is not merely reproduced, but rather a new element is linked to this data, such as the creation of informational added value for the creation of a "doctor rating platform" or the use of the data for the potential acquisition of properties in the context of business as a real estate trustee, or – as in this case – the use of the data for a political campaign, this linking constitutes processing pursuant to Article 4(2) GDPR, which requires a legal basis within the meaning of Articles 5 and 6 or 9 GDPR. ... Regarding the lawfulness of the processing (sending the emails in question), the responsible authority stated in the contested penalty order that the appellant by sending the emails, processed a special category of personal (sensitive) data pursuant to Art. 4(1) in conjunction with Art. 9(1) GDPR (specifically, political opinions and - 34 - philosophical convictions) contrary to the prohibition on processing under Art. 9(1) and without an exception under Art. 9(2) GDPR, as well as the principle of processing personal data lawfully, fairly and in a transparent manner in relation to the data subject pursuant to Art. 5(1)(a) GDPR (“lawfulness, fairness and transparency”) and the principle of processing personal data that is adequate, relevant and limited to what is necessary for the purposes of the processing pursuant to Art. 5(1) GDPR. Article 1(c) GDPR (“data minimization”) has been violated. The complainant argues, in summary, that the legal assessment of the respondent authority, the email addresses in question were lawfully processed by the data subjects, and that the conclusion that these email addresses constitute special categories of personal data pursuant to Article 9 GDPR is incorrect. The recipients of the letter cannot discern from the list of recipients (distribution list) the political convictions of a particular person, as the list includes, on the one hand, political officeholders, the press and public, and certain individuals close to the petition. Without further indications, it is impossible for an individual recipient to infer the political orientation or worldview of other recipients. However, the following must be pointed out to the complainant: According to Article 9(1) GDPR, the processing of personal data revealing (among other things) political opinions or philosophical beliefs is prohibited. Article 9(2) GDPR provides for exceptions to this prohibition. According to the case law of the Administrative Court, for Article 9(1) GDPR to apply, it is sufficient if, with regard to the data categories of racial and ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership, the sensitive information is only indirectly evident. Thus, indirect indications of these characteristics are also subject to special protection, whereby recognizability by an average, objective third party is sufficient (see VwGH 17.05.2024, Ra 2023/04/0005-6, para. 30 with reference to VwGH 14.12.2021, Ro 2021/04/0007, para. 46, with further references). According to the case law of the CJEU, the purpose of Article 9(1) GDPR is to guarantee enhanced protection against data processing which, due to the particular sensitivity of the data being processed, may constitute a particularly serious interference with the fundamental rights to respect for private life and to the protection of personal data guaranteed by Articles 7 and 8 of the Charter (see CJEU 21 December 2023, C-667/21, Krankenversicherung Nordrhein, para. 41). In its judgment of 1 August 2022, C-184/20, Vyriausioji tarnybinės etikos komisija, the CJEU, regarding the interpretation of the term “special categories of personal data” and the “emerging” aspect of Article 9(1) GDPR, stated the following: “122 [...] Article 9(1) of the GDPR provides that, inter alia, the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of data concerning health or data relating to a natural person’s sex life or sexual orientation, is prohibited. 123 As the Advocate General essentially stated in point 85 of his Opinion, the use of the verb ‘emerging’ in these provisions indicates that a processing is covered which relates not only to data that is sensitive in nature, but also to data from which sensitive information can be indirectly derived through a process of deduction or comparison [...]. [...] 125 The objective of Directive 95/46 and the GDPR, mentioned in paragraph 61 of this judgment, also supports a broad interpretation of the terms ‘special categories of personal data’ and ‘sensitive data’. This objective is to ensure a high level of protection of the fundamental rights and freedoms of natural persons – in particular their right to privacy – when personal data relating to them is processed [...]. [...] 127 Consequently, these provisions cannot be interpreted as exempting the processing of personal data that may indirectly reveal sensitive information about a natural person from the enhanced safeguards provided for in these provisions, since otherwise the practical effectiveness of those safeguards and the protection of fundamental rights they are intended to achieve would be undermined. and fundamental freedoms of natural persons would be infringed.” The Supreme Court, whose reasoning the Administrative Court adopted in its ruling Ro 2021/04/0007, also stated with regard to “party affiliations” that Article 9 GDPR is intended, in particular, to protect data subjects from being exposed to the risk of particularly serious discrimination through data processing, and that it therefore appears necessary to include not only data revealing the actual political views of the data subject within the scope of protection of Article 9(1) GDPR, but also data concerning presumed political preferences of the individual, since the processing of such data also carries the risk of particularly negative consequences for the data subject (see Supreme Court 15 April 2021, 6 Ob 35/21x, para. 34). Therefore, for the purposes of protection under Article 9(1) GDPR, it is irrelevant whether the attribution is intended or whether it is (substantively) accurate with regard to the data subject (see also, in this sense, Weichert in Kühling/Buchner, GDPR BDSG [2024] Article 9 GDPR, para. 24). In light of these considerations, it becomes clear that the disclosure of a part of the identified email addresses to all recipients, namely at least with regard to those at least 100 personalized email addresses from which official or private email addresses of natural persons as recipients, in particular a specific named employee of healthcare facilities, emerge or are evident, constitutes processing (prohibited under Article 9(1) GDPR) of personal data revealing the (alleged) political opinion, especially since the content of the emails in question, in conjunction with the purpose (conducting a political campaign) and the method of processing (use of an open distribution list), suggested to the recipients of the emails (and the recipients or third parties could objectively understand this) that these individuals were supporters of the complainant, whose political Shared views, with reference here to the wording of the letters sent: (“We healthcare workers…”; “We stand against the discrimination of us healthcare workers”; “We have found countless like-minded people in our profession, or rather, we have networked”; “WE ARE MANY”; “All among us are prepared to stop working and go on strike…”; “Finally, we would like to inform you that we have received notification from numerous people in the healthcare professions that they will stop working with immediate effect in the event of mandatory vaccination,” etc.) which gives the impression that the affected individuals listed in the distribution list have joined the complainant, oppose mandatory vaccination, and are prepared to stop working. The attribution of a (supposed) political conviction is also supported by the fact that, according to Ms. B.H., following the sending of the emails in question, approximately 15-20 people complained to the complainant and explicitly stated that they wanted nothing to do with the complainant and did not want to receive anything from her. Thus, the potential danger posed by the email addresses sent by the complainant in an open distribution list, at least with regard to the at least 100 personalized email addresses, lies in the discrimination or persecution of the data subjects based on the presumed political conviction, and not merely, as stated in the notification pursuant to Article 33 GDPR by the complainant dated December 4, 2021, in unsolicited contact. The email addresses sent by the complainant in an open distribution list, at least with regard to the at least 100 personalized email addresses, lie in the discrimination or persecution of the data subjects based on the presumed political conviction, and not merely, as stated in the notification pursuant to Article 33 GDPR by the complainant dated December 4, 2021, in unsolicited contact. The complainant thus assigned a political opinion to the data subjects by using an open email distribution list and disclosed it to all recipients. Even if it is conceded that not all email addresses used by the complainant (e.g., those pertaining to an entire healthcare facility) allow conclusions to be drawn about the political convictions of the staff, residents, etc. there, this does not alter the fact that, with regard to a significant portion of the email addresses disclosed to a larger group of people, such processing has occurred – as just explained – and the objective elements of a violation of Article 5(1)(a) and (c) GDPR as well as Article 9(1) GDPR are therefore met. The partial presence of (sensitive) data under Article 9(1) GDPR in relation to the disclosed email addresses will be taken into account in the determination of the penalty, although this circumstance is not decisive (see section 3.3.2.3 below). The political convictions in question, attributed to and disclosed by the data subjects in at least 100 cases, are therefore to be subsumed under the special category of personal data under Article 9(1) GDPR and thus fall under the special protection of this provision (see also Mangelberger/Scheichenbauer, The Limits of Ideological Conviction in the GDPR, in jusIT 5/2021, 202 [207 f]). Therefore, their processing would only be permissible if an exception under Article 9(2) GDPR existed (see in this regard CJEU 21 December 2023, C-667/21, Krankenversicherung Nordrhein, para. 42). The complainant does not claim that such an exception existed, nor is it otherwise apparent. In particular, as established, there is no consent from all data subjects for the data processing in question, especially the publication within the meaning of Article 9(2)(a) GDPR, and the justification under Article 9(2)(d) GDPR – which the appellant has not invoked – is also not applicable, especially since the processing – as established – does not relate (exclusively) to members or former members of the organization or to persons who maintain regular contact with it in connection with its - 38 - purpose of activity, and the personal data were disclosed externally without the consent of the data subjects. With regard to the principle of data minimization under Article 5(1)(c) GDPR, the Federal Administrative Court also cannot find that the processing in question is necessary in this specific case with regard to the use of an open distribution list. As the respondent authority correctly states in the contested penalty order, the appellant's political campaign could have been conducted without the use of an open distribution list, and sending the emails via the "bcc" field would have achieved the desired result just as effectively. The appellant's opposing argument regarding the alleged violation of the freedom to form and operate political parties is limited—as the respondent authority also correctly states in its response to the party's appeal—to general statements and fails to demonstrate in a comprehensible way how the appellant's exercise of its freedom to operate as a political party required the sending of the emails in question via an open distribution list. This argument also contradicts the appellant's claim that the email was sent with an open distribution list due to employee misconduct, and the testimony of witnesses during the oral hearing before the Federal Administrative Court, that "such things are normally sent in bcc". As a result, the form of processing (use/transmission/disclosure) of email addresses that is the subject of the complaint cannot be based on the GDPR and the GDPR, as it is not covered by any legal basis and was not legitimized by the existence of an exception under Article 9(2) GDPR. The data processing under review here did not comply with the requirements and obligations arising from the GDPR and does not meet the lawfulness requirements set out in the GDPR, as it did not comply with the principle of lawfulness, fairness, and transparency pursuant to Article 5(1)(a) GDPR and was not limited to what is necessary in accordance with the principle of data minimization set out in Article 5(1)(c) GDPR. The infringement of the data protection rights of the affected persons is disproportionate and unjustified, since, in the required balancing of interests, their interests with regard to their (sensitive) data outweigh the infringement. - 39 - Therefore, the objective elements of a violation of Article 5(1)(a) and (c) GDPR as well as Article 9(1) GDPR have been fulfilled. The criminal liability for this infringement is based, as the respondent authority correctly stated in its decision, on Article 83(1) and (5)(a) GDPR. Due to the established facts regarding the only partial presence of (sensitive) data under Article 9(1) GDPR with respect to the disclosed email addresses, the command of the penalty order had to be amended accordingly. 3.3.2.2. Regarding the fulfillment of the subjective element of the offense: The respondent authority stated in the contested penalty order that the subjective element of the offense was also fulfilled, as culpability in the form of intent (Art. 83 para. 2 lit. b GDPR) existed. The appellant argues, in summary, that punishment is precluded due to the lack of (attributable) culpability on the part of the appellant, since the employee Mag. B.H. neither holds a (management) position pursuant to Section 30 para. 1 GDPR nor can the appellant be accused of inadequate supervision or control of a management position. The admitted error by Mag. B.H. cannot automatically lead to a penalty for the appellant, especially if no systematic deficiencies or organizational shortcomings can be demonstrated. It should first be noted that the requirement of fault for the imposition of a fine under Article 83 GDPR must be interpreted autonomously within the framework of EU law and in particular assessed in light of the case law of the CJEU. Due to the case law of the CJEU (Judgment of 5 December 2023, C-807/21), according to which the directly applicable provisions of Article 58(2)(i) and Article 83(1) to (6) GDPR must be interpreted as precluding a national regulation under which a fine for an infringement referred to in Article 83(4) to (6) GDPR may be imposed on a legal person in its capacity as controller only if that infringement has previously been attributed to an identified natural person, the provisions of Section 30(1) and (2) GDPR (as well as the provision of Section 5 of the Administrative Penal Code [VStG]) are no longer applicable, since, in light of the aforementioned CJEU judgment, they violate Article 83(1) to (6) GDPR by imposing (additional) substantive requirements for the imposition of a fine. a fine against a legal person (see also VwGH - 40 - 01.02.2024, Ra 2020/04/0187-20, para. 28, according to which the “requirement derived from national law [the VStG] that, for the imposition of a fine under the GDPR against a legal person, all necessary elements for the punishment of the natural person must be included in the operative part of the penalty order, should have remained unapplied […]”). Referring to further case law, the CJEU also expressly clarified that the application of Article 83 GDPR to legal persons does not require any action and not even knowledge on the part of the governing body of that legal person (cf. CJEU of 05.12.2023, C-807/21, para. 77). Against this background, the appellant's argument that punishment is precluded due to a lack of (attributable) fault on the part of the appellant is unfounded, since – as the respondent authority correctly argues – due to the inapplicability of Section 30 of the Data Protection Act (DSG), it is irrelevant whether Mag. B.H. holds (or held) a (management) position within the meaning of Section 30(1) DSG at the appellant's company, or whether the appellant can be accused of inadequate supervision or control of a management position, i.e., organizational negligence. According to the case law of the CJEU, only violations of provisions of the GDPR committed culpably by the controller can lead to the imposition of a fine. However, culpability exists even if the accused could not have been unaware of the unlawfulness of their conduct, regardless of whether they were aware that they were infringing the provisions of the GDPR (see ECJ C-807/21, paragraphs 68, 76 and 77; ECJ C-683/21, paragraphs 81 and 82 with further references). Contrary to the submissions of the respondent authority, it cannot be assumed (and as already explained above) that the complainant made a conscious and intentional decision to send the emails in question, including attachments, to an open distribution list. Therefore, intentional conduct with regard to the infringement of the provisions of Article 5(1)(a) and (c) GDPR, as well as Article 9(1) GDPR, cannot be assumed in the present case. However, in accordance with the case law of the ECJ, there is clearly fault in the form of negligence. In the present case, the emails in question were sent by an employee of the applicant via an open email distribution list due to an error and failure to exercise due diligence, especially since these emails should have been sent by the employee via a closed email distribution list, so that, as explained above, a political opinion was attributed to the data subjects and disclosed to all recipients. The applicant even states in this regard that misconduct by one of its employees - 41 - occurred, thus ultimately not denying fault in the form of negligence. Given the explicit disclosure of email addresses using an open email distribution list, the complainant (or the employee acting on her behalf, who should have inserted the email addresses into the "bcc" field) could not have been unaware, according to the CJEU's case law on the unlawfulness of her conduct, on unlawful, disproportionate, excessive disclosure of email addresses, regardless of whether she was aware that she was violating the provisions of the GDPR. This constitutes negligence on the part of the complainant, which is also evident from the complainant's notification pursuant to Article 33 GDPR of December 4, 2021. Therefore, the subjective element of an infringement of Article 5(1)(a) and (c) GDPR and Article 9(1) GDPR has been fulfilled in the present case. 3.3.2.3. Regarding the determination of penalties: Article 83(1), (2) and (5)(a) GDPR, including its heading, reads: General conditions for the imposition of administrative fines (1) Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for infringements of this Regulation in accordance with paragraphs 4, 5 and 6 is effective, proportionate and dissuasive in each individual case. (2) Administrative fines shall be imposed in addition to, or instead of, the measures referred to in Article 58(2)(a) to (h) and (j), depending on the circumstances of the individual case. When deciding on the imposition of a fine and its amount, due consideration shall be given in each individual case to the following: a) the nature, seriousness and duration of the infringement, taking into account the nature, scope or purpose of the processing concerned, as well as the number of data subjects affected by the processing and the extent of the damage suffered by them; b) whether the infringement was committed intentionally or negligently; c) any measures taken by the controller or processor to mitigate the damage suffered by the data subjects; d) the degree of responsibility of the controller or processor, taking into account the technical and organizational measures they have implemented pursuant to Articles 25 and 32; e) any relevant previous infringements by the controller or processor; - 42 - f) the extent of cooperation with the supervisory authority to remedy the infringement and to mitigate its possible adverse effects; g) Categories of personal data affected by the breach; h) The manner in which the breach became known to the supervisory authority, in particular whether and, if so, to what extent, the controller or processor notified the breach; i) Compliance with measures previously ordered against the controller or processor concerned in relation to the same subject matter pursuant to Article 58(2), where such measures have been ordered; j) Compliance with approved codes of conduct under Article 40 or approved certification mechanisms under Article 42; and k) Any other aggravating or mitigating circumstances in the specific case, such as financial benefits gained or losses avoided, directly or indirectly, as a result of the breach. (5) In the event of infringements of the following provisions, fines of up to EUR 20,000,000 or, in the case of an undertaking, up to 4% of its total worldwide annual turnover of the preceding financial year, whichever is higher, shall be imposed in accordance with paragraph 2: (a) the principles governing processing, including the conditions for consent, in accordance with Articles 5, 6, 7 and 9; The determination of the penalty shall be made on a case-by-case basis, taking due account of the assessment criteria laid down in Article 83(2) GDPR. (b) The contested penalty order imposed a fine of EUR 50,700.00 on the appellant and ordered the appellant to pay a contribution to the costs of the criminal proceedings amounting to 10% of the fine, i.e., EUR 5,070.00. In 2022, the appellant generated total revenue of EUR 851,120.89 from membership fees and donations. In addition, the appellant received party funding of EUR 1,200,000.00 in 2022. In 2024, the appellant received membership fees totaling EUR 70,000.00 from approximately 2,400 individuals. Party funding for the state organization XXXX of the complainant amounts to EUR 1,200,000.00 for the year 2024. - 43 - First, it should be noted that – contrary to the appellant's submissions in the oral hearing before the Federal Administrative Court – the income/assets of the appellant's state organizations (in particular, state organization XXXX) must also be taken into account when calculating turnover: Regarding the concept of "undertaking" within the meaning of this provision, the CJEU held in Case C-807/21 (Deutsche Wohnen SE) that the reference in Recital 150 of the GDPR to the concept of "undertaking" within the meaning of Articles 101 and 102 TFEU, in this specific context of calculating fines imposed for infringements referred to in Article 83 paragraphs 4 to 6 GDPR, is to be understood as follows (see paragraphs 55 et seq.). For the purposes of applying the competition rules laid down in Articles 101 and 102 TFEU, this concept of an undertaking encompasses any entity engaged in an economic activity, irrespective of its legal form and the nature of its financing. It thus refers to an economic entity, even if, from a legal perspective, it consists of several natural or legal persons. This economic entity comprises a single organization of personal, tangible, and intangible resources, which pursues a specific economic objective on a permanent basis (with reference to the judgment of 6 October 2021, Sumal, C-882/19, EU:C:2021:800, paragraph 41 and the case law cited therein). The criteria for assessing whether an economic unit exists include: economic, legal, and organizational links between the parent and subsidiary (e.g., the level of shareholding, personnel or organizational links, instructions, and the existence of internal agreements). The CJEU has ruled that, in the specific case where a parent company holds 100% or almost 100% of the capital of its subsidiary, which has infringed EU competition rules, this parent company can exert a decisive influence on the behavior of that subsidiary, and there is a rebuttable presumption that this parent company actually does exert such influence on the behavior of its subsidiary (see, in particular, the judgments of the CJEU of 20 January 2011, C-90/09 P; and of 10 September 2009, C-97/08 P). The Court of Justice of the European Union (CJEU) has held that, firstly, that parent company can exert a decisive influence on the behavior of that subsidiary, and secondly, that there is a rebuttable presumption that the parent company does indeed exert such influence on the behavior of its subsidiary (see, in particular, CJEU judgments of 20 January 2011, C-90/09 P; and of 10 September 2009, C-97/08 P). In the present case, the applicant is a political party active in Austria and Europe. The applicant constitutes the federal organization of the party. In addition, there is a state organization with its own legal personality for each Austrian federal state, with a unified membership structure: every member is a member of the federal party and, where applicable, is also listed as a state party member - 44 - Active members can be elected or sent as delegates and thus also to the bodies of the federal party executive committee. Insofar as it is necessary for the conduct of nationwide elections or the federal political actions decided upon by federal bodies, all institutions, functionaries, employees, and volunteers of the party and its sub-organizations must comply with the guidelines of the federal party. Moreover, as established, there are close personnel links between the applicant and its state organization XXXX, so that, within the meaning of the case law of the ECJ, the applicant and its state organization XXXX constitute an “economic unit.” ... Moreover, the application of domestic law leads to the same result, especially since Section 2, Paragraph 1 of the Political Parties Act 2012 (PartG) (according to which a "political party" is any party within the meaning of Section 1 PartG, whereby this term is to be understood comprehensively and encompasses all territorial and non-territorial entities, regardless of whether an entity has legal personality) is based on a uniform understanding of the term "party" (e.g., encompassing territorial organizations). Against this background, it must be noted that the annual turnover or revenue of the entire economic unit must be used to determine the penalty range pursuant to Article 83(5) GDPR. Regarding the question of which event the preceding financial year is linked to, the turnover of which determines the upper limit of the possible fine, it should be noted that, according to the case law of the CJEU in competition law concerning the almost identically worded Article 23 of Regulation No. 1/2003, the reference period is the financial year preceding the imposition of the sanction (CJEU, Judgment of 26 January 2017 - C-637/13 P - Badezimmerkartell Laufen Austria, para. 49; CJEU, Judgment of 4 September 2014 - C-408/12 P - YKK et al., para. 90). Since Article 83 GDPR is modeled on the competition law provision, the amount of annual turnover in the last completed financial year before the issuance of the penalty notice/penalty order is therefore decisive. The timing of the court's decision is irrelevant, as is the timing of the relevant infringement (see also EDPB Guidelines 04/2022 on the calculation of administrative fines under the GDPR, version 2.1, adopted on 24 May 2023, paragraph 131). Since the penalty order was issued on 14 December 2023, the annual turnover/revenue for 2022 is/are therefore decisive for determining the penalty range. Based on - 45 - a turnover for 2022 of EUR 2,051,120.89, this results in a maximum fine of EUR 20,000,000.00 pursuant to Article 83(5) GDPR. In determining the amount of the fine within this range, the following was decisive for the Federal Administrative Court: According to Article 83(1) GDPR, each supervisory authority shall ensure that the imposition of fines is effective, proportionate, and dissuasive in each individual case. Article 83(2) GDPR lists criteria for determining the amount of the fine, which must be "duly considered" in each individual case when deciding on the imposition of a fine and its amount. Relevant factors include, in particular, the nature, severity, and duration of the infringement, the number of data subjects affected by the processing, the extent of the damage, the categories of personal data concerned, the efforts of the company to mitigate the damage, the nature and extent of its cooperation with the data protection authorities, and the degree of responsibility. The company's turnover is not mentioned in Article 83(2) GDPR as a criterion for determining the amount of the fine. However, this does not mean that the company's turnover is irrelevant when determining the amount of the fine: In its judgment of 25 November 2003, C-278/01, the CJEU held that, in exercising its power of assessment, the Court must set the lump sum or penalty payment in such a way that it is appropriate to the circumstances and proportionate both to the established infringement and to the solvency of the Member State concerned. Given that fines for infringements of the GDPR within the meaning of Article 83(1) GDPR must also be proportionate, this case law can also be applied to a case such as the present one. The Bonn Regional Court, in its judgment of November 11, 2020, 29 OWi 1/20, also states that the company's turnover is significant when determining the amount of the fine: "Firstly, for companies with high turnover, the turnover determines the maximum fine and thus establishes the framework within which the specific data protection violation must be classified and applied. The fine range provides the necessary guidance for the specific assessment. Secondly, fines against companies must be effective and dissuasive pursuant to Art. 83 para. 1 GDPR. This also depends on the sensitivity of the respective company to punishment. The larger the company, the lower its sensitivity to punishment is generally, and the higher the fine must typically be set so that it can have its specific deterrent effect. The - 46 - amount of turnover is relevant to the company size and thus to the Sensitivity a suitable indicator; the net profit and other key figures of the company's economic performance can also be taken into account. ``` The EDPB Guidelines 04/2022 also assume (referring to a binding decision on this matter, EDPB Decision 1/2021, paragraphs 411 and 412) that the size of the company must be taken into account when calculating the fine, which is why its turnover must be considered. According to the guidelines, the company's economic viability must also be considered when assessing proportionality (see the EDPB Guidelines 04/2022, paragraphs 63 et seq.). Contrary to the submissions of the respondent authority, however, the turnover in the last completed financial year before the issuance of the penalty notice/penalty order is not to be considered here (in contrast to the determination of the maximum fine), but rather the applicant's current income and asset situation at the time of the Federal Administrative Court's decision, especially since this is the only way to ensure that the fine can be paid after the issuance of the (finding of the Federal Administrative Court) also proportionate within the meaning of Art.Article 83(1) GDPR. This view is consistent, on the one hand, with the case law of the Administrative Court on Section 19(2) of the Administrative Penal Code, according to which any changes in income and asset circumstances during the appeal proceedings must be taken into account (Administrative Court 29 January 2007, 2006/03/0155), and on the other hand, with the statements of the EDPB on economic viability, according to which the company must submit detailed financial data for the last five years as well as forecasts for the current and next two years (see EDPB Guidelines 04/2022, paragraphs 140 et seq.). However, the authority in question is correct in its assessment (and this also follows from the EDPB Guidelines 04/2022) that the decisive basis for sentencing is primarily the turnover, and not the account balance reported by the complainant. In view of the nature, seriousness, and duration of the infringement, taking into account the nature, scope, or purpose of the processing in question, as well as the number of data subjects affected by the processing and the extent of the damage suffered by them (Article 83(2)(a) GDPR), it must be noted that the importance of the legally protected interest and the intensity of its impairment by the act are certainly not insignificant. In the present case, the processing involved not only a large number of people or the prohibited disclosure to a large number of persons and entities (Art. 83 para. 2 lit. a GDPR), - 47 - but also a special category of personal data (Art. 83 para. 2 lit. g GDPR), namely data revealing the political opinions or philosophical beliefs of the data subjects, such data being subject to special protection under Art. 9 GDPR and only permitted to be processed under narrow exceptions. The processing was also likely to infringe the fundamental rights of the data subjects – in particular their right to privacy within the meaning of Section 1 of the GDPR. ... On the other hand, it is also significant that the disclosed email addresses only partially constituted (sensitive) data as defined in Article 9(1) GDPR and that moreover, it can be assumed that the violation was committed (merely) negligently. The respondent authority did not consider any aggravating circumstances, and no such circumstances emerged during the proceedings before the Federal Administrative Court. The fact that the appellant has no prior convictions or relevant prior violations (Article 83(2)(e) GDPR) and cooperated extensively in the conduct of the investigation before the Data Protection Authority and also before the Federal Administrative Court, thereby contributing to the establishment of the truth (Article 83(2)(f) GDPR), is a mitigating factor. Against this background, the Federal Administrative Court, in assessing the factors of Article 83(2) GDPR and considering the acts in their entirety in the present case, concludes that the infringement – despite the quantitative reduction of the official charge due to the merely negligent commissioning of the act and the existing mitigating circumstances, which are not offset by any aggravating factors – must be classified as having a high degree of seriousness overall. This is because, apart from the fact that (in at least 100 cases) a large number of data subjects are affected, whose personal data were disclosed to a large number of persons and organizations, the fact that data from a special category of personal data, which, according to the supreme court jurisprudence, is particularly worthy of protection because data subjects are exposed to the risk of particularly serious discrimination through such data processing, is of particular weight in determining the penalty. Therefore, the act must, in any case, be classified as serious in its effects. - 48 - According to the EDPB guidelines, the initial amount for further calculation in the case of a high-severity infringement is to be set between 20% and 100% of the applicable statutory maximum penalty (EUR 20,000,000.00). In light of the above, the Federal Administrative Court considers a provisional initial penalty of EUR 7,000,000.00 (35% of the statutory maximum penalty) to be appropriate. Given that, according to Article 83(1) GDPR, the imposition of fines must be effective and dissuasive, but also proportionate (and therefore must not be existentially threatening), the calculation of the fine – as explained above – must take into account the size of the company and consider its turnover and economic viability (see again the EDPB Guidelines 04/2022 and CJEU 25.11.2003, C-278/01). Since the turnover of the company of the appellant is less than EUR 500,000,000.00, an adjustment based on the company's size must be made in accordance with the aforementioned EDPB Guidelines. Based on a current business turnover such as that of the appellant (taking into account the economic unit) of EUR 1,270,000.00, the EDPB recommends an adjustment based on an amount between 0.2% and 0.4% of the provisional initial amount. Since the appellant's business turnover is significantly closer to the upper limit of EUR 2,000,000.00 than to the lower limit of EUR 0.00, the Federal Administrative Court considers a fine of EUR 28,000.00 (0.4% of the provisional initial amount) to be appropriate to the culpability and the offense in this specific case. The appellant's current business turnover is significantly closer to the upper limit of EUR 2,000,000.00 than to the lower limit of EUR 0.00. The imposition of the fine was necessary in the interest of general deterrence, in order to raise awareness among controllers, in particular other political parties, regarding the lawful sending of emails using a distribution list and the related obligations under the GDPR, especially when this involves the processing of sensitive data of data subjects. Against this background, a mere warning (within the meaning of Recital 148 of the GDPR) was not appropriate here, moreover because the infringement was not merely minor (within the meaning of Recital 148 of the GDPR). Because based on the assessment of the criteria in Article 83(2) GDPR, it cannot be said that the infringement, under the specific circumstances of this case, did not pose a significant risk to the data protection rights of the data subjects and that the core of the data protection obligation was not compromised. This is especially relevant given the background that – as already explained – special categories of personal data within the meaning of Article 9(1) GDPR were involved. Furthermore, replacing a fine with a warning is not mandatory under EU law for minor infringements (Guidelines on the application and imposition of administrative fines pursuant to Regulation 2016/679 [WP 253]). Therefore, a warning does not appear appropriate in this specific case. ... If the appellant refers to Section 20 of the Administrative Penal Code (VStG) in her appeal and requests the application of the extraordinary mitigation of punishment, it must be noted that, according to the aforementioned case law of the CJEU on Article 83 GDPR, with regard to the VStG, only EU law applies to the substantive elements of the offense, which is why the provision of Section 20 VStG must remain inapplicable (see again CJEU of December 5, 2023, C-683/21, paragraphs 46, 48, 70). It should be noted that, in reaching its decision, the Administrative Court must not merely review the exercise of discretion by the administrative penal authority, but must exercise discretion itself and determine a new sentence (Austrian Administrative Court [VwGH] January 31, 2012, 2009/05/0123). This applies particularly in the case of a change in the verdict. In this respect, it is generally the case that, if the appeal is partially granted (Austrian Administrative Court [VwGH] 27.05.2008, 2007/05/0235), for example by reducing the period of the offense (VwGH 22.04.2010, 2007/07/0015; 21.02.2012, 2010/11/0245), if entries are removed due to intervening expungement (VwGH 27.05.2008, 2007/05/0235) or if further mitigating circumstances emerge (VwGH 22.4.1998, 97/03/0353), i.e., in cases of a qualitative or quantitative reduction of the charge, the sentence must also be reduced (Wessely in Raschauer/Wessely [eds], Commentary on the Administrative Penal Code [2023] § 19 para. 26). If the appellant argues that the previous rulings of the respondent authority indicate fines in the range of EUR 10,000.00, it must be noted that the assessment of the fine pursuant to Art. 83 para. 1 GDPR is a case-by-case decision and the fine imposed here, amounting to EUR 28,000.00, appears appropriate to the offense and the degree of culpability, in light of the offense committed, and measured against the available penalty range of Art. 83 para. 5 GDPR (here up to EUR 20,000,000.00). It should also be noted, however, that the fine now imposed is at the lower end of the available penalty range, and a (still) lower amount would no longer meet the criteria of effectiveness and suitability of deterrence set out in Article 83(1) GDPR - 50 - 3.3.2.4. Regarding the costs of the administrative penalty proceedings and the appeal proceedings: Pursuant to Section 64(1) of the Administrative Penal Code (VStG), the penalty order must state that the person penalized is required to pay a contribution to the costs of the penalty proceedings. Pursuant to Section 64(2) VStG, this contribution is to be set at 10% of the imposed penalty, but at least EUR 10, for the proceedings at first instance. Due to the penalty now imposed, the contribution to costs was reduced to EUR 2,800.00. Since the appeal was partially granted, the appellant was not required to pay any costs of the appeal proceedings (§ 52 para. 8 VwGVG). 3.3.2.5. Payment Information: The appellant must pay the total amount of EUR 30,800.00 (penalty and costs of the administrative proceedings) within two weeks to the account of the Federal Administrative Court (BVwG) with IBAN AT840100000005010167 (BIC BUNDATWW), stating the case number, free of charge to the recipient. Or pay the amount at the Federal Administrative Court, taking this decision with her. In case of default, the amount will be collected by compulsory enforcement after a reminder has been issued. ... Regarding B) Pursuant to Section 25a Paragraph 1 of the Administrative Court Act (VwGG), the Administrative Court must state in the operative part of its judgment or decision whether the appeal on points of law is admissible pursuant to Article 133 Paragraph 4 of the Federal Constitutional Law (B-VG). The statement must be briefly reasoned. The present decision does not depend on the resolution of a legal question of fundamental importance. There is neither a lack of case law from the Administrative Court of Justice nor does the present decision deviate from the case law of the Administrative Court of Justice; furthermore, the existing case law of the Administrative Court of Justice cannot be considered inconsistent. There are also no other indications of the fundamental importance of the legal questions to be resolved. The Federal Administrative Court can rely on established case law of the Administrative Court of Justice or on an already clear legal situation in all significant legal questions. It is also not apparent that in the specific case – 51 – a legal question arises that has significance beyond the (specific) individual case at hand. Based on this, a legal question of fundamental importance within the meaning of Art. 133 para. 4 B- VG cannot be affirmed (cf., for example, VwGH 25.09.2015, Ra 2015/16/0085, with further references). It was therefore necessary to declare that the appeal pursuant to Art. 133 para. 4 B-VG is inadmissible.




