BVwG - W137 2308681-1

From GDPRhub
BVwG - W137 2308681-1
Court: BVwG (Austria)
Jurisdiction: Austria
Relevant Law: Article 4(22)(c) GDPR
Article 56 GDPR
Article 60 GDPR
Article 63 GDPR
§ 24 DSG
§ 8(1) VwGVG
Decided: 05.08.2025
Published: 26.09.2025
Parties:
National Case Number/Name: W137 2308681-1
European Case Law Identifier: ECLI:AT:BVWG:2025:W137.2308681.1.00
Appeal from:
Appeal to: Unknown
Original Language(s): German
Original Source: RIS (in German)
Initial Contributor: xz

A court rejected a data subject’s complaint against the inactivity of the DPA since it deemed national procedural deadlines not to be applicable in cross-border complaint procedures

English Summary

Facts

The data subject filed a complaint on 07.05.2024 with the Austrian Data Protection Authority (DSB), alleging that an Estonian company located in Tallinn, Estonia, had failed to fully respond to a request for access under Article 15 GDPR.

By 12.02.2025, more than six months later, the DSB had not issued a decision. As a result, the data subject filed an inactivity complaint with the DSB, arguing that it had failed to act within the legally required time.

By letter dated 17.02.2025, the DSB informed the data subject that the complaint had been forwarded to the Estonian supervisory authority, which would assume responsibility as the lead supervisory authority.

By letter from the DSB dated 20.02.2025, the inactivity complaint was transmitted to the Federal Administrative Court. It stated in particular that, due to cross-border processing, the Estonian supervisory authority is allegedly the responsible authority under the procedure referred to in Article 60 GDPR, and that the decision-making period is suspended for the duration of this procedure, in accordance with national procedural law.

Holding

The Court dismissed the inactivity complaint as unfounded.

Under Austrian procedural law, specifically § 8(1) VwGVG and § 24 DSG, an inactivity complaint may not be filed until the authority has failed to issue a decision on the matter within six months. However, when calculating this six-month period, any time during which cooperation procedures are carried out under Articles 56, 60, and 63 of the GDPR is excluded.

According to Article 56(1) GDPR, when a complaint concerns cross-border processing of personal data, there is a division of responsibilities between a lead supervisory authority, usually the authority of the main or sole establishment of the controller under Article 60 GDPR, and the other supervisory authorities concerned. These authorities are required to cooperate according to the process set out in Article 60 GDPR.

In this case, the DSB correctly recognized that the complaint involved cross-border processing, as defined under Article 4(23) GDPR. Therefore, the Austrian DPA qualifies as a concerned supervisory authority under Article 4(22)(c) GDPR. The responsibility for leading the case lies with the Estonian DPA, as the lead supervisory authority.

As set out in Article 60(7) GDPR, decisions in such cases are adopted by the lead supervisory authority, even though they are based on cooperation and input from the other authorities involved. If a complaint is rejected, the formal rejection is issued by the supervisory authority where the complaint was originally lodged, in this case, the DSB.

As confirmed by national case law, the initiation of the cooperation procedure under Articles 56 and 60 GDPR is not at the discretion of the supervisory authority. It occurs automatically once a complaint involving cross-border processing is submitted. The national procedural deadline for the authority to make a decision was interrupted automatically at the moment the complaint was submitted. Therefore, the DSB is not inactive in the sense of national procedural law, as the conditions for asserting a failure to act have not been met.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the German original. Please refer to the German original for more details.

Decision Date

05.08.2025

Standard

B-VG Art. 130 Para. 1 Z3
B-VG Art. 133 Para. 4
DSG §24
GDPR Art. 4
GDPR Art. 55
GDPR Art. 56
GDPR Art. 60
GDPR Art. 77
VwGVG §8

B-VG Art. 130 today B-VG Art. 130 valid from February 1, 2019, last amended by Federal Law Gazette I No. 14/2019 B-VG Art. 130 valid from January 1, 2019 to January 31, 2019, last amended by Federal Law Gazette I No. 22/2018 B-VG Art. 130 valid from January 1, 2019 to May 24, 2018, last amended by Federal Law Gazette I No. 138/2017 B-VG Art. 130 valid from 25.05.2018 to 31.12.2018 last amended by BGBl. I No. 22/2018 B-VG Art. 130 valid from 01.01.2015 to 24.05.2018 last amended by BGBl. I No. 101/2014 B-VG Art. 130 valid from 01.01.2014 to 31.12.2014 last amended by BGBl. I No. 115/2013 B-VG Art. 130 valid from 01.01.2014 to 31.12.2013 last amended by BGBl. I No. 51/2012 B-VG Art. 130 valid from 01.01.2004 to 31.12.2013 last amended by BGBl. I No. 100/2003 B-VG Art. 130 valid from 01.01.1998 to 31.12.2003 last amended by BGBl. I No. 87/1997 B-VG Art. 130 valid from 01.01.1991 to 31.12.1997 last amended by BGBl. No. 685/1988 B-VG Art. 130 valid from 01.07.1976 to 31.12.1990 last amended by BGBl. No. 302/1975 B-VG Art. 130 valid from 18.07.1962 to 30.06.1976 last amended by BGBl. No. 215/1962 B-VG Art. 130 valid from December 25, 1946 to July 17, 1962, last amended by BGBl. No. 211/1946 B-VG Art. 130 valid from December 19, 1945 to December 24, 1946, last amended by StGBl. No. 4/1945 B-VG Art. 130 valid from January 3, 1930, to June 30, 1934

B-VG Art. 133 today B-VG Art. 133 valid from January 1, 2019, to May 24, 2018, last amended by Federal Law Gazette I No. 138/2017 B-VG Art. 133 valid from January 1, 2019, last amended by Federal Law Gazette I No. 22/2018 B-VG Art. 133 valid from May 25, 2018, to December 31, 2018, last amended by Federal Law Gazette I No. 22/2018 B-VG Art. 133 valid from August 1, 2014, to May 24, 2018, last amended by Federal Law Gazette I No. 164/2013 B-VG Art. 133 valid from 01.01.2014 to 31.07.2014 last amended by BGBl. I No. 51/2012 B-VG Art. 133 valid from 01.01.2004 to 31.12.2013 last amended by BGBl. I No. 100/2003 B-VG Art. 133 valid from 01.01.1975 to 31.12.2003 last amended by BGBl. No. 444/1974 B-VG Art. 133 valid from 25.12.1946 to 31.12.1974 last amended by BGBl. No. 211/1946 B-VG Art. 133 valid from 19.12.1945 to 24.12.1946 last amended by StGBl. No. 4/1945 B-VG Art. 133 valid from January 3, 1930 to June 30, 1934

DSG Art. 2 § 24 valid from July 15, 2024, last amended by Federal Law Gazette I No. 70/2024 DSG Art. 2 § 24 valid from May 25, 2018 to July 14, 2024, last amended by Federal Law Gazette I No. 120/2017 DSG Art. 2 § 24 valid from January 1, 2010 to May 24, 2018, last amended by Federal Law Gazette I No. 133/2009 DSG Art. 2 § 24 valid from January 1, 2000 to December 31, 2009

Section 8 of the Administrative Court Act (VwGVG) today, Section 8 of the Administrative Court Act (VwGVG) valid from January 1, 2014

Ruling

W137 2308681-1/3E

IN THE NAME OF THE REPUBLIC!

The Federal Administrative Court, with Judge Mag. Peter HAMMER as presiding judge and the expert lay judges Mag. Ursula ILLIBAUER and Mag. Martina CHLESTIL as assessors, has rightly ruled on the appeal by XXXX, represented by SUMMER SCHERTLER KAUFMANN Rechtsanwälte GmbH, for a breach of the data protection authority's duty to decide the data protection complaint of May 7, 2024: The Federal Administrative Court, with Judge Mag. Peter HAMMER as presiding judge and the expert lay judges Mag. Ursula ILLIBAUER and Mag. Martina CHLESTIL as assessors, has rightly ruled on the appeal by Römische 40, represented by SUMMER SCHERTLER KAUFMANN Rechtsanwälte GmbH, for a breach of the data protection authority's duty to decide the data protection complaint of May 7, 2024:

A)

The appeal is dismissed pursuant to Section 130 (1) (3) of the Federal Constitutional Constitution Act (B-VG) in conjunction with Section 8 VwGVG as amended. The complaint is dismissed as unfounded pursuant to Section 130, Paragraph 1, Item 3, Federal Constitutional Court Act (B-VG) in conjunction with Section 8 VwGVG as amended.

B)

The appeal is inadmissible pursuant to Article 133, Paragraph 4, Federal Constitutional Court Act (B-VG). The appeal is inadmissible pursuant to Article 133, Paragraph 4, Federal Constitutional Court Act (B-VG). 

Text

Reasons:

I. Course of proceedings: Roman one. Course of proceedings:

1. By procedural submission dated May 7, 2024, the complainant filed a data protection complaint with the Data Protection Authority (hereinafter also referred to as the respondent authority) against XXXX Tallinn, Estonia, for a violation of his right to information pursuant to Article 15 GDPR. In support of his claim, the complainant stated that he had submitted a request for information to XXXX, but that the authority had not fully complied. By procedural submission dated May 7, 2024, the complainant filed a data protection complaint with the Data Protection Authority (hereinafter also referred to as the respondent authority) against roman 40 Tallinn, Estonia, alleging a violation of his right to information under Article 15 GDPR. The complainant justified his complaint by stating that he had submitted a request for information to roman 40, but that the authority had not fully complied.

2. On February 12, 2025, the complainant filed the present complaint of default with the respondent authority, citing the filing of the data protection complaint on May 7, 2024. The respondent authority had failed to comply with its obligation to decide within six months, as it had neither processed the decision as requested, rejected the application, nor initiated proceedings pursuant to Articles 56 et seq. GDPR. On February 12, 2025, the complainant filed the present complaint of default with the respondent authority and referred to the filing of the data protection complaint on May 7, 2024. The respondent authority had failed to comply with its obligation to decide within six months, as it had neither processed the decision as requested, rejected the application, nor initiated proceedings under Articles 56 et seq. of the GDPR.

3. By letter from the Data Protection Authority dated February 20, 2025, received on March 5, 2025, the complaint of default, including the administrative act, was submitted to the Federal Administrative Court. In particular, it stated that, due to the cross-border processing, the Estonian supervisory authority was presumably the lead supervisory authority responsible for the procedure under Article 60 GDPR, and that the deadline for making a decision was suspended for the duration of these proceedings. By letter from the Data Protection Authority dated February 20, 2025, received on March 5, 2025, the complaint against default, including the administrative act, was submitted to the Federal Administrative Court. In particular, it was stated that, due to the cross-border processing, the Estonian supervisory authority was presumably the lead supervisory authority responsible for the procedure under Article 60 GDPR, and that the deadline for making a decision was suspended for the duration of these proceedings.

II. The Federal Administrative Court considered: Roman II. The Federal Administrative Court considered:

1. Findings:

The data protection complaint filed by the complainant on May 7, 2024, is directed against XXXX, based in Tallinn, Estonia, for a violation of the right to information pursuant to Art. 15 GDPR. Subsequently, on February 12, 2025, the complainant filed a complaint alleging a breach of the authority's decision-making obligation pursuant to Section 8 (1) of the Administrative Court Act (VwGVG). The data protection complaint filed by the complainant on May 7, 2024, is directed against roman 40, located at roman 40, Tallinn, Estonia, for a violation of the right to information pursuant to Article 15 of the GDPR. Subsequently, on February 12, 2025, the complainant filed a complaint alleging a breach of the authority's decision-making obligation pursuant to Section 8, Paragraph 1 of the Administrative Court Act (VwGVG).

By letter dated February 17, 2025, the competent authority forwarded the complainant's data protection complaint to the Estonian supervisory authority established pursuant to the GDPR via the IT cooperation platform "Internal Market Information System" (IMI) and informed the authority that it assumed the Estonian authority's jurisdiction as the lead supervisory authority.

2. Evaluation of Evidence:

The findings arise from the unobjectionable contents of the file, in particular from the complainant's data protection complaint of May 7, 2024, the appeal against default, and the IMI Report, No. 736441.1, dated February 17, 2025, enclosed with the administrative act.

3. Legal Assessment:

3.1. Pursuant to Section 6 of the Federal Administrative Court Act (BVwGG), the Federal Administrative Court decides by a single judge, unless federal or state law provides for decisions by senates. 3.1. Pursuant to Section 6 of the Federal Administrative Court Act (BVwGG), the Federal Administrative Court decides by a single judge, unless federal or state law provides for decisions by senates.

Pursuant to Section 27 (1) of the Data Protection Act (DSG), the Federal Administrative Court decides by a senate on appeals against decisions based on violations of the duty to provide information pursuant to
Section 24 (7) of the Data Protection Act and the data protection authority's duty to decide. According to Section 27, Paragraph 2, first sentence, of the Data Protection Act (DSG), the Senate consists of a presiding judge and one expert lay judge each from the circle of employers and one from the circle of employees. Thus, the Senate has jurisdiction over the matter. According to Section 27, Paragraph 1, of the Data Protection Act (DSG), the Federal Administrative Court decides through a Senate on appeals against decisions based on violations of the duty to provide information pursuant to
Section 24, Paragraph 7, leg.cit., and the decision-making duty of the Data Protection Authority. According to Section 27, Paragraph 2, first sentence, of the Data Protection Act (DSG), the Senate consists of a presiding judge and one expert lay judge each from the circle of employers and one from the circle of employees. Thus, the Senate has jurisdiction over the matter.

The procedure of the administrative courts, with the exception of the Federal Finance Court, is governed by the Administrative Court Act (VwGVG), Federal Law Gazette I 2013/33, as amended by Federal Law Gazette I 2013/122 (Section 1, leg.cit.). Pursuant to Section 59, Paragraph 2 of the Administrative Court Act (VwGVG), conflicting provisions already promulgated at the time this federal law enters into force remain in force. The procedure of the administrative courts, with the exception of the Federal Finance Court, is governed by the Administrative Court Act (VwGVG), Federal Law Gazette Roman One 2013/33, as amended by Federal Law Gazette Roman One 2013/122 (paragraph one, leg.cit.). Pursuant to Section 59, Paragraph 2 of the Administrative Court Act (VwGVG), conflicting provisions already promulgated at the time this federal law enters into force remain in force.

According to Section 17 of the Administrative Court Act (VwGVG), unless otherwise provided in this federal law, the provisions of the Administrative Court Act (AVG) with the exception of Sections 1 to 5 and Part IV, the provisions of the Federal Fiscal Code (BAO), Federal Law Gazette No. 194/1961, the Agricultural Procedure Act (AgrVG), Federal Law Gazette No. 173/1950, and the Civil Service Procedure Act 1984 (DVG), Federal Law Gazette No. 29/1984, and, in addition, those procedural provisions in federal or state laws that the authority applied or should have applied in the proceedings preceding the proceedings before the administrative court, shall apply mutatis mutandis to the proceedings concerning complaints pursuant to Article 130, Paragraph 1, B-VG. 1 to 5, as well as Part IV of Roman Law, the provisions of the Federal Fiscal Code (BAO), Federal Law Gazette No. 194 of 1961, the Agricultural Procedure Act (AgrVG), Federal Law Gazette No. 173 of 1950, and the Civil Service Procedure Act 1984 (DVG), Federal Law Gazette No. 29 of 1984, and, in addition, those procedural provisions in federal or state laws that the authority applied or should have applied in the proceedings preceding the proceedings before the administrative court, shall be applied mutatis mutandis.

3.2. Pursuant to Section 31 (1) of the Administrative Court Act (VwGVG), decisions and orders shall be made by resolution unless a judgment is required.

3.2. Pursuant to Section 31 (1) of the Administrative Court Act (VwGVG), decisions and orders shall be made by resolution unless a judgment is required. According to Section 28 (1) of the Administrative Court Act (VwGVG), the administrative court must resolve the case by decision unless the appeal is to be dismissed or the proceedings are to be discontinued. According to Section 28 (1) of the Administrative Court Act (VwGVG), the administrative court must resolve the case by decision unless the appeal is to be dismissed or the proceedings are to be discontinued.

Regarding A)

3.3. The relevant provisions of the GDPR

Article 4

Definitions

For the purposes of this Regulation, the following definitions apply:

1.-6. (…)

7. "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

8.-20. (…)

21. ‘supervisory authority’ means an independent public authority established by a Member State pursuant to Article 51;

22. ‘supervisory authority concerned’ means a supervisory authority that is concerned by the processing of personal data because:

a) the controller or processor is established in the territory of the Member State of that supervisory authority;

(…)

23. ‘cross-border processing’ means either:

a) processing of personal data which is carried out in the context of the activities of establishments in the Union of a controller or processor in more than one Member State, where the controller or processor is established in more than one Member State; or

(…)

24.-26. (…)

Article 55
Competence

(1) Each supervisory authority shall be competent for the performance of the tasks and the exercise of the powers conferred on it by this Regulation within the territory of its own Member State.

(…)

Article 56
Competence of the lead supervisory authority

(1) Without prejudice to Article 55, the supervisory authority of the main establishment or of the single establishment of the controller or processor shall be the competent lead supervisory authority for cross-border processing carried out by that

controller or processor, in accordance with the procedure referred to in Article 60.

(2) By way of derogation from paragraph 1, each supervisory authority shall be competent to deal with a complaint submitted to it or with a possible infringement of this Regulation if the matter is related only to an establishment in its Member State or significantly affects data subjects in its Member State only.

(3) In the cases referred to in paragraph 2 of this Article, the supervisory authority shall immediately inform the lead supervisory authority of the matter. Within three weeks of the notification, the lead supervisory authority shall decide whether or not to deal with the case in accordance with the procedure laid down in Article 60, taking into account whether or not the controller or processor has an establishment in the Member State whose supervisory authority informed it.

(4) If the lead supervisory authority decides to deal with the case, the procedure laid down in Article 60 shall apply. The supervisory authority that informed the lead supervisory authority may submit a draft decision to the lead supervisory authority. The lead supervisory authority shall take the utmost account of that draft decision when preparing the draft decision pursuant to Article 60(3).

(5) If the lead supervisory authority decides not to deal with the case itself, the supervisory authority that informed the lead supervisory authority shall deal with the case in accordance with Articles 61 and 62.

(6) The lead supervisory authority shall be the sole contact point for controllers or processors regarding issues relating to cross-border processing carried out by that controller or processor.

(…)

Article 60

Cooperation between the lead supervisory authority and the other supervisory authorities concerned

(1) The lead supervisory authority shall cooperate with the other supervisory authorities concerned in accordance with this Article, endeavouring to reach consensus. The lead supervisory authority and the supervisory authorities concerned shall exchange all relevant information.

(2) The lead supervisory authority may at any time request mutual assistance from other supervisory authorities concerned in accordance with Article 61 and carry out joint operations in accordance with Article 62, in particular to conduct investigations or to monitor the implementation of a measure with respect to a controller or processor established in another Member State.

(3) The lead supervisory authority shall without undue delay provide the other supervisory authorities concerned with the relevant information on the matter. It shall without undue delay submit a draft decision to the other supervisory authorities concerned for their opinion, taking due account of their views.

(4) If, within four weeks of being consulted pursuant to paragraph 3 of this Article, one of the other supervisory authorities concerned submits a relevant and reasoned objection to that draft decision and the lead supervisory authority does not agree with the relevant and reasoned objection or considers the objection to be irrelevant or unfounded, the lead supervisory authority shall initiate the consistency mechanism referred to in Article 63 for the matter.

(5) If the lead supervisory authority intends to join the relevant and reasoned objection, it shall submit a revised draft decision to the other supervisory authorities concerned for their opinion. The revised draft decision shall be subject to the procedure referred to in paragraph 4 within two weeks.

(6) If none of the other supervisory authorities concerned objects to the draft decision submitted by the lead supervisory authority within the time limit set out in paragraphs 4 and 5, the lead supervisory authority and the supervisory authorities concerned shall be deemed to have agreed with the draft decision and shall be bound by it.

(7) The lead supervisory authority shall adopt the decision and notify it to the main establishment or single establishment of the controller or, where applicable, the processor, and shall inform the other supervisory authorities concerned and the Board of the decision, including a summary of the relevant facts and reasons. The supervisory authority to which a complaint has been lodged shall inform the complainant of the decision.

(8) By way of derogation from paragraph 7, where a complaint is rejected or dismissed, the supervisory authority to which the complaint was lodged shall adopt the decision, notify it to the complainant, and inform the controller.

(9) Where the lead supervisory authority and the supervisory authorities concerned agree to reject or dismiss parts of the complaint and to take action on other parts of that complaint, a separate decision shall be adopted on that matter for each of those parts. The lead supervisory authority shall adopt the decision for the part concerning action with regard to the controller, notify it to the main establishment or single establishment of the controller or processor in its Member State, and inform the complainant thereof, while the supervisory authority responsible for the complainant shall adopt the decision for the part concerning the rejection or dismissal of that complaint, notify it to that complainant, and inform the controller or processor thereof.

(10) Following notification of the lead supervisory authority's decision pursuant to paragraphs 7 and 9, the controller or processor shall take the necessary measures to bring the processing activities of all its establishments in the Union into compliance with that decision. The controller or processor shall inform the lead supervisory authority of the measures taken to comply with that decision, which shall, in turn, inform the other supervisory authorities concerned.

(11) Where, in exceptional cases, a supervisory authority concerned has reason to believe that urgent action is necessary to protect the interests of data subjects, the urgency procedure provided for in Article 66 shall apply.

(12) The lead supervisory authority and the other supervisory authorities concerned shall communicate the information required under this Article to each other by electronic means using a standardized format.

(…)

Article 77

Right to lodge a complaint with a supervisory authority

(1) Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation.

(2) The supervisory authority to which the complaint was submitted shall inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy under Article 78.

3.4 The relevant provisions of the Data Protection Act

Complaint to the Data Protection Authority

Section 24. (1) Every data subject has the right to lodge a complaint with the Data Protection Authority if they believe that the processing of personal data concerning them violates the GDPR or Section 1 or Article 2, Chapter 1.

Section 24. (1) Every data subject has the right to lodge a complaint with the Data Protection Authority if they believe that the processing of personal data concerning them violates the GDPR or Section 1 or Article 2, Chapter 1.

(2) - (7) (…)

(8) Any data subject may refer the complaint to the Federal Administrative Court if the Data Protection Authority does not address the complaint or has not informed the data subject of the status or outcome of the complaint within three months.

(9) (…)

(10) The decision-making period pursuant to Section 73 of the General Data Protection Regulations (AVG) does not include:

1. the period during which the proceedings are suspended pending a final decision on a preliminary issue;

2. the period during proceedings pursuant to Articles 56, 60, and 63 GDPR;

3.5. The admissibility of a default appeal presupposes the default of the authority before the administrative court whose decision-making obligation is asserted, and thus the obligation of that authority to decide on the application submitted to it by means of an official decision. If there is no default on the part of the authority, the default appeal must be dismissed (cf. VwGH 28.03.2019, Ra 2018/14/0286; 10.12.2018, Ro 2018/12/0017). 3.5. The admissibility of a default appeal presupposes the default of the authority before the administrative court whose decision-making obligation is asserted, and thus the obligation of that authority to decide on the application submitted to it by means of an official decision. If there is no default on the part of the authority, the complaint based on default must be rejected (cf. VwGH March 28, 2019, Ra 2018/14/0286; December 10, 2018, Ro 2018/12/0017).

3.6. In the present case, it was therefore necessary to examine whether the authority concerned was in default. According to Section 8 (1) of the Administrative Court Act (VwGVG), a complaint based on default can only be filed if the authority has not decided the matter within six months, or if a shorter or longer decision period is provided for by law. The period begins on the date the application for a decision on the merits is received by the legally prescribed body. In line with this, Section 24 (10) of the Data Protection Act (DSG), which is relevant to the case, initially refers to Section 73 of the Administrative Court Act (AVG), which requires authorities to decide without unnecessary delay, but no later than six months after receipt of an application. According to Section 24 (10), this decision-making period does not include, on the one hand, the period during which the proceedings are suspended pending a final decision on a preliminary issue (item 1), and, on the other hand, the period during proceedings pursuant to Articles 56, 60, and 63 GDPR (item 2). In both cases, the decision-making period is to be suspended (cf. VwGH 14.11.2023, Ro 2020/04/0009). 3.6. In the present case, it was therefore necessary to examine whether there was a default on the part of the authority concerned. According to Section 8, paragraph 1, VwGVG, an appeal against default may only be filed if the authority has not decided the matter within six months, or if a shorter or longer decision-making period is provided for by law. The period begins on the date on which the application for a decision on the merits is received by the legally prescribed body. In line with this, the relevant paragraph 24, paragraph 10, of the Data Protection Act (DSG), first refers to paragraph 73 of the AVG, which requires authorities to decide without undue delay, but no later than six months after receipt of an application. Paragraph 24, paragraph 10 further states that this decision-making period does not include, on the one hand, the period during which the proceedings are suspended pending a final decision on a preliminary issue (paragraph 1), and, on the other hand, the period during proceedings pursuant to Articles 56, 60, and 63 GDPR (paragraph 2). In both cases, the decision-making period is to be suspended (cf. VwGH 14.11.2023, Ro 2020/04/0009).

Article 55(1) GDPR provides that each supervisory authority is, in principle, responsible for the performance of the tasks and the exercise of the powers conferred on it by the Regulation within the territory of its own Member State. The tasks assigned to it include, among others, the handling of complaints from data subjects pursuant to Article 57(f) GDPR, which presupposes that the supervisory authority is actually competent for a specific data processing operation (see ECJ, June 15, 2021, C-645/19, paras. 47 et seq.). Article 55, paragraph 1, GDPR provides that each supervisory authority is, in principle, competent for the performance of the tasks assigned to it by the Regulation and the exercise of the powers conferred on it by the Regulation within the territory of its own Member State. The tasks assigned to it include, among others, the handling of complaints from data subjects pursuant to Article 57(f) GDPR, which presupposes that the supervisory authority is actually competent for a specific data processing operation (see ECJ, June 15, 2021, C-645/19, paras. 47 et seq.).

Article 56(1) GDPR provides – without prejudice to the jurisdiction rule contained in Article 55(1) of the Regulation – for "cross-border processing" within the meaning of Article 4(23) of the Regulation, the cooperation and consistency mechanism, based on an allocation of responsibilities between a "lead supervisory authority" and the other supervisory authorities concerned. Accordingly, the supervisory authority of the main establishment or single establishment of the controller or processor, in accordance with the procedure set out in Article 60, is the competent lead supervisory authority for cross-border processing carried out by that controller or processor. This, in conjunction with Article 60, requires that, with regard to "cross-border processing," the various national supervisory authorities concerned must cooperate in accordance with the procedure laid down in those provisions in order to reach a consensus and a single decision that is binding on all supervisory authorities and with which the controller must harmonize the processing activities of all its establishments in the Union (cf. ECJ, 15 June 2021, C-645/19, paras. 50 et seq.). Article 56(1) GDPR provides for the cooperation and consistency procedure for "cross-border processing" within the meaning of Article 4(23) of the Regulation, without prejudice to the jurisdiction rule contained in Article 55(1) of the Regulation. This procedure is based on an allocation of responsibilities between a "lead supervisory authority" and the other supervisory authorities concerned. Accordingly, the supervisory authority of the main establishment or the single establishment of the controller or processor, in accordance with the procedure laid down in Article 60, is the competent lead supervisory authority for cross-border processing carried out by that controller or processor. This, in conjunction with Article 60, means that with regard to "cross-border processing," the various national supervisory authorities concerned must cooperate in accordance with the procedure laid down in those provisions to reach a consensus and a single decision that is binding on all supervisory authorities and with which the controller must harmonize the processing activities of all its establishments in the Union (see ECJ, June 15, 2021, C-645/19, paras. 50 et seq.).

In the case of cross-border processing, the competence of the "lead supervisory authority" to conduct such a cooperation and consistency procedure is the rule – as is clear in particular from Article 56 (6) GDPR – and is only derogated from in exceptional cases, as provided for in Article 56 (2) and Article 60 (11) GDPR (not applicable here). The competence to decide on a complaint regarding cross-border data processing itself ("issuing decisions"), however, is again made dependent on the outcome of the cooperation procedure. While decisions by the supervisory authorities involved are issued by the lead supervisory authority pursuant to Art. 60 (7) GDPR, the rejection of the complaint by the supervisory authorities involved pursuant to Art. 60 (8) GDPR should be made by the supervisory authority to which the complaint was submitted (cf. BVwG 11.09.2024, W256 2290824-1/14E). In the case of cross-border processing, the competence of the "lead supervisory authority" to conduct such a cooperation and consistency procedure is the rule – as is clear in particular from Article 56 (6) GDPR – and is only deviated from in exceptional cases, as provided for in Article 56 (2) and Article 60 (11) GDPR (not applicable here). The jurisdiction to decide on a complaint regarding cross-border data processing itself ("issuance of decisions"), however, is again dependent on the outcome of the cooperation procedure. While decisions of the supervisory authorities involved pursuant to Article 60, Paragraph 7, GDPR are issued by the lead supervisory authority, the decision to reject the complaint by the supervisory authorities involved pursuant to Article 60, Paragraph 8, GDPR is to be made by the supervisory authority to which the complaint was submitted (cf. BVwG 11.09.2024, W256 2290824-1/14E).

Recital 10 of the GDPR states that, among other things, the GDPR aims to ensure that the rules protecting the fundamental rights and freedoms of natural persons with regard to the processing of personal data are applied consistently and uniformly throughout the Union and that barriers to the flow of personal data within the Union are eliminated. However, this objective and the practical effectiveness of the cooperation and consistency procedure under Article 56 (1) and (60) GDPR could be jeopardized or compromised if a supervisory authority other than the lead authority adopts a decision under this procedure (see ECJ, 15 June 2021, C-645/19, paras. 64 et seq.). Recital 10 of the GDPR states that, among other things, the GDPR aims to ensure that the provisions protecting the fundamental rights and freedoms of natural persons with regard to the processing of personal data are applied uniformly and consistently throughout the Union and that barriers to the flow of personal data within the Union are removed. However, this objective and the practical effectiveness of the cooperation and consistency procedure under Article 56(1) and Article 60 GDPR could be jeopardized or compromised if a supervisory authority other than the lead authority issues a decision under this procedure (see ECJ, June 15, 2021, C-645/19, paragraphs 64 et seq.).

As stated, the complainant filed his data protection complaint with the competent authority on May 7, 2024. This complaint was directed against XXXX, located at a specified address in Estonia, for a specifically alleged violation of the right to information pursuant to Article 15 GDPR. The respondent authority therefore rightly points out in its statement on the submitted complaint of default that the present data protection complaint is related to cross-border processing of personal data within the meaning of Art. 4 (23) GDPR and that the respondent authority, as the supervisory authority concerned, should have initiated a cooperation procedure between the Estonian lead supervisory authority pursuant to Art. 56 (1) in conjunction with Art. 60 et seq. GDPR by the respondent authority. As stated, the complainant filed his data protection complaint with the respondent authority on May 7, 2024. This complaint was directed against Römische 40, located at a specified address in Estonia, due to a specifically alleged violation of the right to information pursuant to Article 15 GDPR. The respondent authority therefore rightly points out in its statement on the submitted complaint against default that the present data protection complaint is related to cross-border processing of personal data within the meaning of Article 4(23) GDPR, and that the respondent authority, as the affected supervisory authority pursuant to Article 4(22)(c) GDPR, would have (or should have) initiated a cooperation procedure between the Estonian lead supervisory authority pursuant to Article 56(1) in conjunction with Articles 60 et seq. GDPR.

As already mentioned above, in the case of cross-border processing, the jurisdiction to issue a decision disposing of the application for a decision on the merits depends on the outcome of the cooperation and consistency procedure pursuant to Article 56(1) and Article 60 GDPR. Against this background, and in order to protect the practical effectiveness of this procedure, a breach of the obligation to decide by a supervisory authority cannot be legally asserted until such a procedure has been concluded. This is also consistent with the previously outlined provision of Section 24, Paragraph 10, Item 2 of the Data Protection Act (DSG), which states that the time during proceedings under Articles 56, 60, and 63 of the GDPR cannot be included in the six-month decision-making period. As already mentioned above, in the case of cross-border processing, the jurisdiction to issue a decision executing the request for a decision on the merits depends on the outcome of the cooperation and consistency procedure pursuant to Article 56, Paragraph 1, and Article 60 of the GDPR. Against this background, and in order to protect the practical effectiveness of this procedure, a breach of the decision-making obligation by a supervisory authority cannot be legally asserted until such proceedings have been concluded. This is also consistent with the previously outlined provision of Section 24, Paragraph 10, Item 2 of the Data Protection Act (DSG), which states that the time during proceedings under Articles 56, 60, and 63 of the GDPR cannot be included in the six-month decision-making period.

To the extent that the complainant argues in his default complaint that the authority concerned has not yet initiated proceedings under Articles 56 et seq. of the GDPR in the six months since the data protection complaint was filed, the Senate considers that reference can be made to the decision of the Federal Administrative Court of September 11, 2024, Ref. No. W256 2290824-1/14E, which was cited in the authority's statement upon submission of the file and which was based on a similar situation. Accordingly, the conduct of proceedings under Articles 56 (1) and 60 GDPR is not at the discretion of the authority concerned, but rather is automatically initiated upon filing the complaint if the statutory requirements are met. A different perspective would jeopardize the objective and practical effectiveness of the cooperation and consistency procedure. To the extent that the complainant argues in his default appeal that the authority concerned has not yet initiated proceedings under Article 56 et seq. of the GDPR in the six months since the data protection complaint was filed, the Senate considers that reference can be made to the Federal Administrative Court's decision of September 11, 2024, Ref. No. W256 2290824-1/14E, which was cited in the authority's statement upon submission of the file, which was based on a similar set of facts. Accordingly, the conduct of proceedings under Article 56, paragraph 1, and 60 of the GDPR is not at the discretion of the authority concerned, but rather is automatically initiated upon filing the complaint if the statutory requirements are met. A different perspective would jeopardize the objective and practical effectiveness of the cooperation and consistency procedure.

The result is that the suspension of the six-month decision-making period pursuant to Section 24 (10) (2) DSG did not begin with the transmission of the data protection complaint to the presumably competent lead supervisory authority on February 17, 2025, but rather ex lege with the filing of the data protection complaint relating to cross-border data processing, and thus, with respect to the decision-making period asserted here, there is no default on the part of the authority concerned. The result is that the suspension of the six-month decision-making period pursuant to Section 24 (10) (2) DSG did not begin with the transmission of the data protection complaint to the presumably competent lead supervisory authority on February 17, 2025, but rather ex lege with the filing of the data protection complaint relating to cross-border data processing, and thus, with respect to the decision-making period asserted here, there is no default on the part of the authority concerned.

In addition, the Senate hearing the case points out that a suspension of the data protection complaint procedure by decision regarding a procedure for determining the lead supervisory authority pursuant to Art. 56 GDPR lacks any legal basis, in particular that of Section 38 of the General Administrative Procedures Act (AVG). The very wording of Section 24 (10) of the Data Protection Act (DSG) and its system, which clearly distinguishes between the constellations of paragraph 1 (suspension of the procedure and preliminary question) and paragraph 2 (consistency procedure under the GDPR), indicates that in the latter case, there is no preliminary question to be resolved that would require a suspension of the data protection procedure by decision. Otherwise, the circumstances of paragraph 2 would be unnecessary, and the legislature would therefore have to be allowed to regulate superfluous provisions here. This also rules out the application of the VwGH's case law on Sections 38 and 38a of the General Data Protection Regulations (AVG) to cases under Section 24 (10) (2) of the Data Protection Act (DSG) (cf. VwGH 14.11.2023, Ro 2020/04/0009). Furthermore, the Senate hearing the case would like to point out that any legal basis, in particular that of Section 38 of the AVG, is removed from the suspension of data protection complaint proceedings by decision in relation to a procedure for determining the lead supervisory authority pursuant to Article 56 of the GDPR. The very wording of Section 24, Paragraph 10, DSG, and its systematic structure, which clearly distinguishes between the constellations of Section 1 (suspension of the proceedings and preliminary question) and Section 2 (consistency procedure under the GDPR), shows that in the second case, there is no preliminary question to be resolved that would require a suspension of the data protection proceedings by decision. Otherwise, the provisions of Section 2 would not be necessary, and the legislature would therefore have to be allowed to regulate superfluous matters here. This also rules out the application of the VwGH's case law on Sections 38 and 38a, AVG, to cases under Section 24, Paragraph 10, Paragraph 2, DSG (see VwGH 14.11.2023, Ro 2020/04/0009).

3.7. The appeal against default must therefore be dismissed for lack of default within the meaning of Section 130, Paragraph 1, Item 3 of the Federal Constitutional Constitutional Court Act. 3.7. The appeal against default must therefore be dismissed for lack of default within the meaning of Section 130, Paragraph 1, Item 3 of the Federal Constitutional Constitutional Court Act.

3.8. Pursuant to Section 24, Paragraph 1 of the Administrative Court Act (VwGVG), the administrative court must hold a public oral hearing upon request or, if it deems it necessary, ex officio. 3.8. Pursuant to Section 24, Paragraph 1 of the Administrative Court Act (VwGVG), the administrative court must hold a public oral hearing upon request or, if it deems it necessary, ex officio.

The complainant has filed a request for a public hearing. In the present case, however, the omission of an oral hearing can be based on the fact that the facts of the case have been clarified from the file. The Federal Administrative Court had to rule exclusively on a legal issue (existence of default). According to the case law of the Constitutional Court, an oral hearing may be omitted if the facts are undisputed and the legal issue is not particularly complex (VfSlg. 17,597/2005; VfSlg. 17,855/2006; most recently, for example, VfGH June 18, 2012, B 155/12).

Consequently, an oral hearing could be dispensed with pursuant to Section 24 (1) of the Administrative Court Act (VwGVG).

Consequently, an oral hearing could be dispensed with pursuant to Section 24 (1) of the Administrative Court Act (VwGVG). B) (In)admissibility of an appeal on points of law:

According to Section 25a, Paragraph 1 of the Administrative Court Act (VwGG), the administrative court must state in its judgment or decision whether the appeal on points of law is admissible pursuant to Article 133, Paragraph 4 of the Federal Constitutional Court Act (B-VG). The decision must be briefly reasoned.

According to Section 25a, Paragraph 1 of the Administrative Court Act (VwGG), the administrative court must state in its judgment or decision whether the appeal on points of law is admissible pursuant to Article 133, Paragraph 4 of the Federal Constitutional Court Act (B-VG). The decision must be briefly reasoned.

The appeal on points of law is inadmissible pursuant to Article 133, Paragraph 4 of the Federal Constitutional Court Act because the decision does not depend on the resolution of a legal question of fundamental importance. The decision in question neither deviates from the previous jurisprudence of the Administrative Court, nor is there a lack of jurisprudence; furthermore, the present jurisprudence of the Administrative Court cannot be considered inconsistent. There are also no other indications of the fundamental importance of the legal issue to be resolved. The appeal is inadmissible pursuant to Article 133, Paragraph 4, of the Federal Constitutional Law (B-VG) because the decision does not depend on the resolution of a legal issue of fundamental importance. The present decision neither deviates from the previous jurisprudence of the Administrative Court, nor is there a lack of jurisprudence; furthermore, the present jurisprudence of the Administrative Court cannot be considered inconsistent. There are also no other indications of the fundamental importance of the legal issue to be resolved.