BVwG - W171 2302513-1
| BVwG - W171 2302513-1 | |
|---|---|
| Court: | BVwG (Austria) |
| Jurisdiction: | Austria |
| Relevant Law: | Article 5(2) GDPR Article 13 GDPR Article 15 GDPR Article 44 GDPR Article 45 GDPR Article 46(2)(c) GDPR |
| Decided: | 18.05.2026 |
| Published: | 09.06.2026 |
| Parties: | |
| National Case Number/Name: | W171 2302513-1 |
| European Case Law Identifier: | ECLI:AT:BVWG:2026:W171.2302513.1.00 |
| Appeal from: | DSB (Austria) |
| Appeal to: | Not appealed |
| Original Language(s): | German |
| Original Source: | RIS (in German) |
| Initial Contributor: | ds |
A court held that although a media company had used Standard Contractual Clauses and implemented additional measures for the transfer of a data subject’s personal data to the USA, it did not ensure a level of data protection equivalent to the EU.
English Summary
Facts
The controller was an Austrian magazine publisher based in Vienna. Its business consisted in publishing and distributing weekly, monthly and other periodicals. The data subject was a long-standing customer of the controller. They held multiple subscriptions.
On 7 March 2022, the data subject received an informational email with regard to one of their subscriptions. The email contained links allowing users to unsubscribe from further emails or manage their email settings. The unsubscribe link led to a website operated by the controller’s marketing software provider. The provider was a company specializing in mass email marketing solutions. Its parent company was headquartered in USA, while its subsidiary was based in Germany.
The data subject complained to the controller and requested information regarding the receipt of this email. Additionally, they contended that the transfer of their data to the United States was unlawful.
On 25 April 2022, the data subject lodged a complaint with the Austrian DPA. They argued that the controller had failed to properly respond to their access request, had not provided the required information under the GDPR and had apparently transferred personal data to the United States without a valid legal basis.
The controller alleged that the failure to respond happened because of an internal error. It argued that it had subsequently provided the data subject with the information required under Article 13 GDPR, Article 14 GDPR and Article 15 GDPR. The controller further submitted that for the sending of informational emails, it used a marketing software provider, acting as a processor, which offered services for the mass sending of emails. According to the controller, only the data subject’s first name, surname and email address were shared for this purpose. It acknowledged that a transfer to third countries could not be ruled out, but argued that any such transfer was covered by Standard Contractual Clauses (SCCs) and additional technical, contractual and organisational measures. It also referred to amendments it made after the Schrems II to its data processing activities to comply with this decision and to the later migration of existing customer data to European data centres.
The DPA partly upheld the complaint. It found that the controller had infringed Article 44 GDPR because it had not complied with the requirements for transferring the data subject’s personal data to the USA. The DPA also found a violation of Article 13 GDPR, because the controller had failed to provide the data subject with the required information at the time of data collection. However, the DPA rejected the complaint concerning Article 15 GDPR since the controller had subsequently provided the requested information.
The controller appealed the DPA’s decision before the Austrian Federal Administrative Court. It further argued that the SCCs with the provider and the additional implemented safeguards ensured a level of data protection equivalent to that of the GDPR. It also alleged that there was a reference to this contractual relationship in its privacy policy.
Holding
Regarding the transfer to third countries, the court agreed with the DPA that the processing involved a transfer of personal data to the USA by disclosing the data subject’s first name, surname and email address to the marketing software provider. It pointed out that the provider had used these data at least once for the sending of the email at issue.
The Court then assessed the transfer under Chapter V GDPR which governs transfers of personal data to third countries or to international organizations. It noted that, at the relevant time, there was no adequacy decision under Article 45 GDPR for transfers to the United States. It found that the previous EU – US Privacy Shield was already declared invalid by the CJEU ruling in Case C-311/18 (Schrems II) and the later EU-US Data Privacy Framework was not relevant to the case, because it was adopted after the processing at issue.
It relied heavily on Schrems II. It stated that Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR may constitute appropriate safeguards. Furthermore, it pointed out that the CJEU in this case held that due to the contractual nature of SCCs they cannot bind third-country public authorities. The court therefore determined that SCCs may need to be supplemented by additional safeguards, depending on the situation of the third country concerned. The court concluded that the transfer must ensure a level of protection essentially equivalent to that guaranteed within the EU.
The court accepted that the controller and the provider had used the European Commission’s Standard Contractual Clauses and had implemented certain technical, contractual and organisational measures, including encryption, terms of use and storage-management systems. However, it held that although these additional measures increased the level of data protection, they were not sufficient to remedy the core concerns identified by the CJEU in Schrems II, namely the potential access of US authorities to personal data and the lack of effective judicial redress. The court therefore upheld the DPA’s decision that the safeguards implemented by the controller were insufficient. It therefore ruled that the transfer infringed Article 44 GDPR.
Regarding the information obligations, the court also upheld the DPA’s finding of a violation of Article 13 GDPR. It noted that the controller did not actively provide the required information to the data subject at the time of data collection. It also pointed out that it was not enough to argue that a privacy policy existed online.
In addition, the court concluded that the controller had violated the accountability principle under Article 5(2) GDPR since it was not able to prove that the required information had been provided to the data subject in accordance with Article 13 GDPR.
The court dismissed the controller’s appeal and upheld the DPA’s findings.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the German original. Please refer to the German original for more details.
Decision Date May 18, 2026 Legal Norm Federal Constitutional Law (B-VG) Art. 133 para. 4 GDPR Art. 12 GDPR Art. 13 GDPR Art. 14 GDPR Art. 4 no. 1 GDPR Art. 4 no. 7 GDPR Art. 44 GDPR Art. 45 GDPR Art. 46 GDPR Art. 5 Federal Constitutional Law (B-VG) Art. 133 currently in force; Federal Constitutional Law (B-VG) Art. 133 valid from January 1, 2019 to May 24, 2018, last amended by Federal Law Gazette I No. 138/2017; Federal Constitutional Law (B-VG) Art. 133 valid from January 1, 2019, last amended by Federal Law Gazette I No. 22/2018; Federal Constitutional Law (B-VG) Art. 133 valid from May 25, 2018 to December 31, 2018, last amended by Federal Law Gazette I No. 22/2018 B-VG Art. 133 valid from 01.08.2014 to 24.05.2018, last amended by BGBl. I No. 164/2013; B-VG Art. 133 valid from 01.01.2014 to 31.07.2014, last amended by BGBl. I No. 51/2012; B-VG Art. 133 valid from 01.01.2004 to 31.12.2013, last amended by BGBl. I No. 100/2003; B-VG Art. 133 valid from 01.01.1975 to 31.12.2003, last amended by BGBl. No. 444/1974; B-VG Art. 133 valid from 25.12.1946 to December 31, 1974, last amended by Federal Law Gazette No. 211/1946. Federal Constitutional Law Art. 133, valid from December 19, 1945, to December 24, 1946, last amended by State Law Gazette No. 4/1945. Federal Constitutional Law Art. 133, valid from January 3, 1930, to June 30, 1934. Judgment W171 2302513–1/17E IN THE NAME OF THE REPUBLIC! The Federal Administrative Court, composed of Judge Gregor Morawetz, MBA, presiding, and lay judges Huberta Maitz-Strassnig and [name missing], has rendered the following judgment: Jakob KALINA, on the appeal of XXXX, represented by Attorney-at-Law Katharina Raabe-Stuppnig, Wickenburggasse 23/11, 1080 Vienna, against the decision of the Data Protection Authority of October 2, 2024, file number XXXX, after conducting an oral hearing, has ruled as follows: The Federal Administrative Court, composed of Judge Gregor Morawetz, MBA, presiding, and lay judges Huberta Maitz-Strassnig and Jakob Kalina, has ruled as follows on the appeal of [Company Name], represented by Attorney-at-Law Katharina Raabe-Stuppnig, Wickenburggasse 23/11, 1080 Vienna, against the decision of the Data Protection Authority of October 2, 2024, file number 40, after conducting an oral hearing: A) The appeal is dismissed as unfounded. ... B) The appeal is inadmissible pursuant to Article 133, paragraph 4 of the Austrian Federal Constitutional Law (B-VG). Text Reasons for the Decision: I. Procedural History: 1. By initiating proceedings on April 25, 2022, amended on May 9, 2022, XXXX (hereinafter referred to as "intervening party") contacted the Data Protection Authority (hereinafter referred to as "respondent authority" or "DPA") and argued that the complainant had violated its right of access, as a request for information dated March 7, 2022, had not been answered. Specifically, the intervening party claimed that its right to information and its right of access had been violated. Furthermore, the complainant had apparently transferred data to the USA. The intervening party stated that it had never consented to data processing by the complainant. 1. In a preliminary submission dated April 25, 2022, amended on May 9, 2022, Roman 40 (hereinafter referred to as "participating party") contacted the Data Protection Authority (hereinafter referred to as "respondent authority" or "DPO") and argued that the complainant had violated its right of access by failing to respond to a request for information dated March 7, 2022. Specifically, the participating party claimed that its right to information and its right of access had been violated. Furthermore, the complainant had apparently transferred data to the USA. The participating party stated that it had never consented to any data processing by the complainant. 2. In a statement dated June 27, 2022, the complainant, represented by legal counsel, summarized that it had subsequently provided all information required under Articles 13, 14, and 15 of the GDPR. Internal errors had led to the request from the co-defendant not being forwarded. 2. In a statement dated June 27, 2022, the complainant, represented by legal counsel, summarized that it had subsequently provided all information required under Articles 13, 14, and 15 of the GDPR. Internal errors had led to the request from the co-defendant not being forwarded. The co-defendant is an existing customer of the complainant and holds various newspaper and news subscriptions. The email that prompted this data protection complaint was an informational email intended to inform the co-defendant about the scope of one of its subscriptions. A link in the email allowed users to opt out of receiving such informational emails. The co-defendant is an existing customer of the complainant and holds various newspaper and news subscriptions. The complainant uses a software service provider that offers solutions for sending large volumes of emails to send such informational emails and other email communications. Only the surname, first name, and email address are shared with XXXX. No processing for any other purposes takes place. Due to XXXX's international focus, potential data transfers to third countries cannot be ruled out; however, these transfers are carried out in compliance with the standard contractual clauses for data transfers to third countries issued by the EU Commission, as well as the GDPR in general. The complainant uses a software service provider that offers solutions for sending large volumes of emails to send such informational emails and other email communications. Only the surname, first name, and email address are shared with XXXX. No processing for any other purposes takes place. Due to the international nature of Roman 40, the possibility of data transfers to third countries cannot be ruled out. However, such transfers would be carried out in compliance with the standard contractual clauses for data transfers to third countries issued by the European Commission, as well as the GDPR in general. Following the CJEU ruling on "Schrems II," the complainant made various adjustments to its internal data processing to comply with European data protection requirements. Furthermore, plans are underway to establish European data centers to further prevent data transfers to third countries. Finally, Roman 40 is itself obligated to inform customers of any requests from US authorities; however, no such requests have been received to date. Following the CJEU ruling on "Schrems II," the complainant made various adjustments to its internal data processing to comply with European data protection requirements. Furthermore, plans are underway to establish European data centers to further prevent data transfers to third countries. Finally, Roman 40 is itself obligated to inform customers of any requests from US authorities; however, no such requests have been received to date. The risk of infringement on the rights and freedoms of the affected party was therefore assessed as low. At the same time, the complainant submitted the information provided to the affected party, along with various attachments demonstrating lawful data processing. 3. In a statement dated July 14, 2022, the affected party argued that the information had not been provided within the statutory time limit. Furthermore, its data had been transferred to various companies without its consent, and there was no legal basis for these transfers. It also contested the lawfulness of the data transfer to the USA and asserted that the complainant was also unlawfully processing personal behavioral data. 4. By letter dated August 3, 2022, the complainant was requested to provide supplementary information and answer various questions. In her subsequent statement of September 8, 2022, the complainant essentially reiterated the points she had already raised in her statement of June 27, 2022. She stated that it could not be ruled out that data of the co-involved party (name, email address) had been transferred to a third country following the sending of the email. XXXX had implemented extensive measures to ensure compliance with the level of data protection under EU law. This applied in particular to technical, contractual, and organizational measures. The data was stored in encrypted form by XXXX. Regarding XXXX's corporate structure, the complainant stated that she had concluded a contract with XXXX, which is based in Germany. 4. By letter dated August 3, 2022, the complainant was requested to provide a supplementary statement and answer various questions. In its subsequent statement of September 8, 2022, the complainant essentially reiterated the points it had already raised in its statement of June 27, 2022. It could not be ruled out that data belonging to the co-respondent (name, email address) had been transferred to a third country following the sending of the email. Roman 40 had implemented extensive measures to ensure compliance with the level of data protection required by EU law. This applied in particular to technical, contractual, and organizational measures. The data was stored in encrypted form by Roman 40. Regarding the corporate structure of Roman 40, the complainant stated that it had concluded a contract with Roman 40, which is based in Germany. 5. In its statement of October 17, 2022, the co-respondent argued that the so-called "SCCs" (Standard Contractual Clauses) on which the complainant relied were insufficient to guarantee the protection of personal data. The fact that the data would be migrated to European data centers in a timely manner is irrelevant to the present case. The argument that no American authorities had conducted inquiries and that the purpose of the data processing was "manageable" is also irrelevant. Overall, the complainant's submissions amount to mere pretexts. 6. By letter dated March 28, 2023, the complainant stated that a data transfer to European data centers had taken place and that the personal data of the co-respondent was now stored and processed exclusively in Europe. 7. By the decision dated October 2, 2024, which is the subject of these proceedings, the respondent authority partially upheld the data protection complaint of the co-respondent and found that the complainant (respondent in the administrative proceedings) had violated Article 44 GDPR by failing to comply with the requirements of Article 44 GDPR when transferring the co-respondent's personal data, and that the complainant had thereby violated the co-respondent's right to information by not providing the information required under Article 13 GDPR at the time of data collection and thus failing to comply with its information obligation under Article 13 GDPR. The complaint regarding the right of access was dismissed. 7. In its decision of October 2, 2024, the respondent authority partially upheld the data protection complaint of the co-respondent and found that the complainant (respondent in the administrative proceedings) had violated Article 44 of the GDPR by failing to comply with the requirements of Article 44 of the GDPR when transferring the co-respondent's personal data, and that the complainant had thereby violated the co-respondent's right to information by not providing the information required under Article 13 of the GDPR at the time of data collection, thus failing to comply with its information obligation under Article 13 of the GDPR. The complaint regarding the right of access was dismissed. With regard to point 1 of the decision, the respondent authority reasoned that the complainant, as the data controller, was generally obligated to demonstrate that the data processing complied with EU data protection regulations. Since the complainant has not provided any corresponding evidence to the contrary, it must be assumed that a data transfer to the USA (a third country) has taken place. There is neither a (valid) adequacy decision by the European Commission for data transfers to the USA, nor are there any contractual, technical, or organizational measures that could prevent unlawful data processing in the sense of "appropriate measures." Furthermore, there is no exception to these principles in this case. Regarding point 2 of the ruling, the respondent authority stated that it is the controller's responsibility to actively provide the information pursuant to Article 13 GDPR. Unlike the right of access pursuant to Article 15 GDPR, which requires a request and can be remedied retrospectively in the event of a breach, the fact that the information was provided retrospectively in the present proceedings does not preclude a finding of a breach of the right to information pursuant to Article 13 GDPR. Article 13 GDPR does not preclude this. Regarding point 2 of the ruling, the respondent authority stated that it is the controller's responsibility to actively provide the information pursuant to Article 13 GDPR. Unlike the right of access pursuant to Article 15 GDPR, which requires a request and can be remedied retrospectively in the event of a breach, the fact that the information was subsequently provided in the present proceedings does not preclude a finding of a breach of the right to information pursuant to Article 13 GDPR. Regarding point 3 of the ruling, the respondent authority stated that the breach of rights had been subsequently remedied with respect to Article 15 GDPR, and therefore the complaint was to be dismissed on this point. Regarding point 3 of the ruling, the respondent authority stated that the breach of rights had been subsequently remedied with respect to Article 15 GDPR, and therefore the complaint was to be dismissed on this point. 8. By way of an appeal against the decision dated November 12, 2024, the appellant contacted the Federal Administrative Court and summarized the points that had also been raised in the administrative proceedings. The appellant further stated that a contract with XXXX had been in place since May 2021 and that this connection was also mentioned in its data protection policy. Although the appellant was named as a data exporter and XXXX as a data importer in an annex document of an XXXX Processing Agreement, the designation "data exporter" was much more appropriate for XXXX. 8. By way of an appeal against the decision dated November 12, 2024, the appellant contacted the Federal Administrative Court and summarized the points that had also been raised in the administrative proceedings. The appellant further stated that a contract with Roman 40 had been in place since May 2021 and that this connection was also mentioned in its data protection policy. Although the appellant is named as the data exporter and the appellant as the data importer in an annex document to a Roman 40 Processing Agreement, the designation "data exporter" is much more appropriate for the appellant. 9. On January 15, 2026, an oral hearing was held before the Federal Administrative Court in the presence of the presiding panel, informed representatives of the appellant, the appellant's legal counsel, and the intervening party. The respondent authority was excused from the hearing. During this hearing, the subject matter of the proceedings and the relevant legal situation were discussed in detail. 10. By submission of the file dated January 30, 2026, the appellant submitted various documents to support its position. II. The Federal Administrative Court considered the following: 1. Findings: 1.1. The complainant is an Austrian magazine publisher based in Vienna. The company's business purpose is the publication and distribution of weekly, monthly, and other magazines. 1.2. The co-respondent has been a customer of the complainant for several years and has, or had, a subscription under two specified customer numbers for the delivery of XXXX magazine, the subscription to the journal XXXX, and any other magazines. The subscription agreement for XXXX (print and e-magazine) has been in effect since December 27, 2017, and the subscription agreement for XXXX since April 30, 2021; both remain in force. 1.2. The co-respondent has been a customer of the complainant for several years and has, or had, a subscription under two specified customer numbers for the delivery of the Roman 40 magazine, the subscription to the journal Roman 40, and any other magazines. The subscription agreement for Roman 40 (print and e-magazine) has been in effect since December 27, 2017, and the subscription agreement for Roman 40 since April 30, 2021; both remain valid. The subscription agreement for the XXXX magazine in question was concluded by telephone. The subscription includes a physical copy of the magazine, as well as access to an e-paper (i.e., an electronic edition) and XXXX, a platform providing additional content. No recordings of the telephone call during which the subscription agreement was concluded exist. Access to the e-paper and XXXX requires additional registration, during which users receive various data protection information. The data protection declaration applicable to the subscription agreement in question differs from the one currently used for new contracts. The subscription agreement for Roman 40 was concluded by telephone. The subscription includes a physical copy of the magazine, as well as access to an e-paper (i.e., an electronic edition) and "Röm 40," a platform providing additional content. No recordings exist of the telephone call during which the subscription agreement was concluded. Access to the e-paper and "Röm 40" requires additional registration, during which users receive various data protection information. The data protection declaration used for the subscription agreement in question differs from the one currently used for new contracts. The party involved in this case did not register for the digital content of the subscription. During the telephone contract conclusion, the party involved did not receive any data protection information as defined in Articles 13 and 14 of the GDPR, nor any related information in the form of general terms and conditions. Articles 13 and 14 of the GDPR and no related information in the form of general terms and conditions. On May 1, 2021, the data was transferred to the marketing software service provider now the subject of these proceedings. The affected party was not actively informed of this change and the resulting updated data protection information. 1.3. On March 7, 2022, the affected party received an informational email as part of its subscription with the subject line "Your XXXX sample is waiting for you" and was informed about the usage options of its subscription. A link provided access to the presented format. 1.3. On March 7, 2022, the affected party received an informational email as part of its subscription with the subject line "Your Roman numeral 40 sample is waiting for you" and was informed about the usage options of its subscription. A link provided access to the presented format. At the bottom of the email were the following links: "help@abo. XXXX .at", "Unsubscribe from all emails", and "Manage settings". Clicking the "Unsubscribe from all emails" link led to a website operated by XXXX. 1.4. XXXX is a marketing company that offers software solutions for sending large volumes of emails – such as commercial informational emails or newsletters – and handles this distribution. The parent company XXXX is headquartered in Cambridge, USA, and the subsidiary XXXX is headquartered in Berlin. XXXX is subject to US law. 1.4. Roman 40 is a marketing company that, among other things, offers software solutions for sending large volumes of emails—such as commercial informational emails or newsletters—and handles this distribution. The parent company Roman 40 is headquartered in Cambridge, USA, and the subsidiary Roman 40 is headquartered in Berlin. Roman 40 is subject to US law. 1.5. By email dated March 7, 2022, the party involved complained about the delivery of the informational email and simultaneously requested information pursuant to the GDPR as well as answers to various questions. Furthermore, the party involved stated that data transfer to the USA was inadmissible. 1.5. The complainant submitted the information requested by the co-defendant during the administrative proceedings. 1.6. The complainant disclosed the co-defendant's personal data – first and last name and email address – to both XXXX and XXXX. XXXX used this data at least on March 7, 2022, in connection with sending the informational/promotional email underlying these proceedings. The complainant also disclosed the co-defendant's personal data – first and last name and email address – to both Roman 40 and Roman 40. Roman 40 used this data at least on March 7, 2022, in connection with sending the informational/promotional email underlying these proceedings. The complainant and XXXX signed a “XXXX Data Processing Agreement” which designates the complainant as the data exporter and XXXX as the data importer and refers to the Standard Contractual Clauses pursuant to European Commission Implementing Decision ((EU) 2021/914 of 4 June 2021). The complainant and Roman 40 signed a “Roman 40 Data Processing Agreement” which designates the complainant as the data exporter and Roman 40 as the data importer and refers to the Standard Contractual Clauses pursuant to European Commission Implementing Decision ((EU) 2021/914 of 4 June 2021). `` The complainant and XXXX signed a “Roman 40 Data Processing Agreement” which designates the complainant as the data exporter and XXXX as the data importer and refers to the Standard Contractual Clauses pursuant to European Commission Implementing Decision ((EU) 2021/914 of 4 June 2021. XXXX uses the German-based company XXXX as a subcontractor for contractual marketing purposes, which are used by customers such as the complainant. The complainant uses the German-based company XXXX as a subcontractor for contractual marketing purposes, which are used by customers such as the complainant. 1.7. XXXX, as the complainant's contractual partner, implemented various technical (encryption), contractual (terms of service), and organizational (storage management system) measures that constitute "appropriate safeguards" within the meaning of Article 46 GDPR. 1.7. XXXX, as the complainant's contractual partner, implemented various technical (encryption), contractual (terms of service), and organizational (storage management system) measures that constitute "appropriate safeguards" within the meaning of Article 46 GDPR. Neither at the time of the conclusion of the contract in question nor at the time of sending the advertising email in question by XXXX was there an adequacy decision by the European Commission pursuant to Article 45 GDPR in force regarding the transfer of personal data to the USA. Neither at the time of the conclusion of the contract in question nor at the time of sending the advertising email in question by Roman 40 was there an adequacy decision by the European Commission pursuant to Article 45 GDPR in force regarding the transfer of personal data to the USA. 1.8. The migration of the data of the complainant's existing customers to European data centers took place on March 23 and 24, 2023. 2. Evaluation of Evidence: 2.1. The findings concerning the appellant (point II.1.1) are based, firstly, on the contents of the respondent authority's file, which reveals its business purpose, and secondly, on a judicial review of the appellant's legal notice on its website. 2.1. The findings concerning the appellant (point II.1.1) are based, firstly, on the contents of the respondent authority's file, which reveals its business purpose, and secondly, on a judicial review of the appellant's legal notice on its website. 2.2. The findings concerning the co-respondent (point II.1.2) are based on its statements in the data protection complaint submitted to the Federal Administrative Court and on the appellant's undisputed statements in this regard. The appellant submitted screenshots of its internal processing programs in both the administrative and administrative court proceedings, from which the customer status of the co-defendant is unequivocally evident. 2.2. The findings regarding the co-defendant (point 2.1.2.) are based on its statements in the data protection complaint submitted to the Federal Administrative Court and on the appellant's undisputed statements in this regard. The appellant submitted screenshots of its internal processing programs in both the administrative and administrative court proceedings, from which the customer status of the co-defendant is unequivocally evident. The fact that the magazine subscription contract in question was concluded by telephone, but no records of this exist, and that additional registration is required for the online products, which the other party never carried out, is particularly evident from the oral hearing of January 15, 2026. The other party stated that it had never carried out such a registration, and the complainant was unable to produce any records of the telephone call or of any possible registration by the other party. Likewise, the complainant was unable to prove that the other party received information within the meaning of Articles 13 and 14 of the GDPR. The complainant failed to demonstrate, either before the respondent authority or before the court hearing the case, that the other party had received this information – in particular regarding the transfer of personal data to third countries. Nor was the complainant able to prove that the other party received information within the meaning of Articles 13 and 14 of the GDPR. The appellant failed to demonstrate, either before the respondent authority or the court hearing the case, that the co-respondent had received this information – particularly regarding the transfer of personal data to third countries. While the appellant submitted various documents related to the co-respondent's subscription agreements in her written submission of January 30, 2026, these documents are of no relevance to the present proceedings. The document designated by the appellant as Exhibit ./24 does contain a reference to the digital subscription, but this letter pertains to a subscription concluded prior to the one at issue. The appellant states in her submissions that there was a subscription from April 1, 2016, to April 15, 2021, and another from April 30, 2021, to April 29, 2022. However, given that the contract was concluded over the phone and no record of it exists, it cannot be assumed that the other party received all the necessary information required under the GDPR with regard to the subsequent subscription. The submission of the terms and conditions that were in effect when the later subscription was concluded and which referred to the complainant's privacy policy is of no help, as it could not be proven that these became part of the contract. Similarly, the screenshot of the login screen for the online account is also unhelpful, as it could not be proven that the other party used this account. Furthermore, the complainant itself states that invoices no longer mentioned the e-paper, as it was included in the print subscription and therefore no longer explicitly listed. No corresponding information could be provided to the other party regarding the software service provider XXXX, which was used from May 2021 onwards, and the associated updated privacy policy. In her written submission of January 30, 2026, the complainant did submit various documents relating to the subscription agreements of the co-defendant; however, these documents are of no relevance to the present proceedings. While the document designated by the complainant as Exhibit ./24 does contain a reference to the digital subscription, this letter pertains to a subscription concluded prior to the one at hand. The complainant states in her file submission that there was a subscription from April 1, 2016, to April 15, 2021, and another from April 30, 2021, to April 29, 2022. However, given that the contract was concluded by telephone, for which no record exists, it cannot be assumed that the co-defendant received all the information required under the GDPR with regard to the later subscription. The submission of the terms and conditions that were in effect when the subsequent subscription was concluded and which referred to the complainant's privacy policy is of no help, as it could not be proven that these became part of the contract. Similarly, the screenshot of the login screen for the online account is also unhelpful, as it could not be proven that the other party used this account. Furthermore, the complainant herself states that the e-paper was no longer mentioned on invoices, as it was included in the print subscription and therefore no longer explicitly listed. No corresponding information regarding the software service provider Roman 40, used from May 2021 onwards – and the associated updated privacy policy – could be provided to the other party. Likewise, the transition from the former software service provider to the relevant company XXXX is evident from the appellant's undisputed statements. Similarly, the transition from the former software service provider to the relevant company Roman numeral 40 is evident from the appellant's undisputed statements. 2.3. The findings regarding the informational email to the co-respondent party dated March 7, 2022, are based on the data protection complaint submitted to the Federal Administrative Court, in which a screenshot of the email was provided. The fact that some of the text passages contained links to other websites is evident from the parties' undisputed submissions. The finding that the hyperlink in the text "Unsubscribe from all emails" leads to a website operated by XXXX is based, firstly, on the undisputed submissions of the co-respondent party and, secondly, on the submission of a screenshot in the data protection complaint. The cursor is positioned on the text linked by a hyperlink, and the computer program used displays a preview of the URL to be accessed. This URL contains the domain XXXX, clearly establishing the connection to XXXX. 2.3. The findings regarding the informational email to the co-defendant dated March 7, 2022, are based on the data protection complaint submitted to the Federal Administrative Court, in which a screenshot of the email was provided. The fact that some of the text passages contained links to other websites is evident from the undisputed submissions of the parties. The finding that the hyperlink in the text "Unsubscribe from all emails" leads to a website operated by Roman 40 is based, firstly, on the undisputed submissions of the co-defendant and, secondly, on the screenshot submitted as part of the data protection complaint. The cursor is positioned on the text linked by a hyperlink, and the computer program used displays a preview of the URL to be accessed. This contains the domain name 40, from which the connection to 40 is clearly evident. 2.4. The findings under II.1.4. are based on the appellant's corresponding submissions and a judicial review of the legal notice of XXXX. The registered office of XXXX and the findings regarding the company structure, insofar as XXXX is concerned, are based on the undisputed act of the respondent authority. 2.4. The findings under II.1.4. are based on the appellant's corresponding submissions and a judicial review of the legal notice of 40. The registered office of 40 and the findings regarding the company structure, insofar as 40 is concerned, are based on the undisputed act of the respondent authority. 2.5. The finding that the co-party filed a data protection complaint and that the complainant subsequently provided the requested information to the co-party during the administrative proceedings is evident from the administrative act, which is undisputed in this respect. 2.6. The fact that the complainant processed the personal data "first and last name" and "email address" and forwarded it to XXXX is based on the complainant's corresponding submissions in the administrative proceedings and the complaint filed. That XXXX processed this data at least on March 7, 2025, is evident from the date of the email underlying the proceedings, which was sent on that very day. Since XXXX was contractually responsible for sending the email, the data was clearly used for sending on that day as well. The fact that the complainant processed the personal data "first and last name" and "email address" and forwarded it to Roman 40 is based on the complainant's corresponding submissions in the administrative proceedings and the complaint filed. That Roman 40 processed this data at least on March 7, 2025, is evident from the date of the email underlying the proceedings, which was sent on that very day. Since Roman 40 was contractually responsible for sending the email, the data was clearly used for this purpose on that day as well. The finding that the complainant transmitted personal data of the co-participating party to XXXX so that the latter could subsequently send informational or promotional emails is based primarily on the documents submitted by the complainant. Among other things, the complainant submitted an "XXXX Data Processing Agreement" signed by representatives of XXXX and the complainant. Annex 3, "List of Sub-Processors," contains a table listing XXXX as a sub-processor whose purpose is "Services & Support." XXXX is explicitly described as a "data importer," and the complainant is explicitly described as a "data exporter." The court therefore concludes that the data processing agreement was concluded directly between the complainant and XXXX, and that XXXX acted, at most, as a data processor for XXXX. The finding that the complainant transmitted personal data of the co-participating party to Roman 40 so that the latter could subsequently send informational or promotional emails is based primarily on the documents submitted by the complainant. Among other things, the complainant submitted a "Roman 40 Data Processing Agreement" signed by representatives of Roman 40 and the complainant. Annex 3, "List of Sub-Processors," contains a table listing Roman 40 as a sub-processor whose purpose is "Services & Support." Roman 40 is explicitly described as a "data importer," and the complainant is explicitly described as a "data exporter." The court therefore concludes that the data processing agreement was concluded directly between the complainant and Roman 40, and that Roman 40 acted, at most, as a data processor for Roman 40. This view is further reinforced by the complainant's submissions in its supplementary statement of September 8, 2022, in which it argued that, due to XXXX's global reach, it could not be ruled out that data had been transferred to the USA. This view is further reinforced by the appellant's submissions in its supplementary statement of September 8, 2022, in which it argued that, due to the global scope of Roman 40, it could not be ruled out that data had been transferred to the USA. In this regard, it should also be noted that the appellant submitted, among other things, information from XXXX concerning "XXXX's new EU data center." This information indicates that the personal data of new customers would be processed in a new EU data center from July 2021 onwards, and that data migration for existing customers was planned from 2022. In the opinion of the court, this implies that the data of European customers was not (exclusively) processed in the EU until 2022 and was evidently processed in a third country. In its supplementary statement of March 28, 2023, the appellant stated that this planned data migration was to take place on March 23/24. March 2023. In this regard, it should also be noted that the appellant submitted, among other things, information from Roman 40 concerning "Roman 40's new EU data center." This information indicates that the personal data of new customers would be processed in a new EU data center from July 2021 onwards, and that data migration for existing customers was planned for 2022. In the opinion of the court, this implies that the data of European customers was not (exclusively) processed in the EU until 2022 and was evidently processed in a third country. In a supplementary statement dated March 28, 2023, the appellant stated that this planned data migration took place on March 23/24, 2023. This information indicates that the personal data migration of new customers would be processed in a new EU data center from July 2021 onwards, and that data migration for existing customers was planned for 2022 onwards. The finding that the complainant and XXXX concluded a data processing agreement that refers to the European Commission's standard data protection clauses ((EU) 2021/914 of 4 June 2021) is based on the documents submitted and signed by the complainant. During the oral hearing of 15 January 2026, the complainant's legal representative stated that while the documents showed that the data processing agreement had been concluded with XXXX, the personal data had in fact only been transferred to Germany. Data protection law relates to actual data processing and circumstances, not to contractual definitions or roles. During the oral hearing on January 15, 2026, the complainant's legal representative stated that while the documents showed that a data processing agreement had been concluded with Roman 40, the personal data had in fact only been transferred to Germany. Data protection law relates to actual data processing and circumstances, not to contractual definitions or roles. However, the adjudicating panel cannot accept this argument. The contractual arrangement undoubtedly indicates a data transfer to the USA – the appellant failed to fully clarify how the actual division of roles between the appellant and XXXX in the course of the collaboration deviated from the contractual arrangement. As already explained, the role of the German company XXXX was defined solely as "Service & Support," which is why it must be assumed that the personal data was also transferred to the USA for the purpose of fulfilling the contract. However, the adjudicating panel cannot accept this argument. The contractual arrangement undoubtedly indicates a data transfer to the USA – the appellant failed to fully clarify how the actual division of roles between the appellant and XXXX in the course of the collaboration deviated from the contractual arrangement. As already explained, the role of the German company XXXX was defined solely as "Service & Support," which is why it must be assumed that the personal data was also transferred to the USA for the purpose of fulfilling the contract. Furthermore, the arguments presented during the administrative and judicial proceedings also suggest that personal data was transferred to the USA. Firstly, the appellant stated in its submission of September 8, 2022, and in its present appeal, that it "could not be ruled out" that data had been transferred to the USA. Secondly, it was repeatedly emphasized that after the data migration to European data centers, no data would be processed in the USA. 2.7. The findings regarding the measures implemented by the appellant and XXXX to guarantee adequate protection of personal data – technical, contractual, and organizational measures – are based on the appellant's corresponding submissions in the context of the appeal and the entire administrative proceedings, as well as the documents submitted. The findings regarding the measures implemented by the complainant and Roman 40 to guarantee adequate protection of personal data—technical, contractual, and organizational measures—are based on the complainant's submissions during the complaint and the entire administrative proceedings, as well as the documents submitted. 2.8. The findings regarding data migration are based on a corresponding statement from the complainant. 3. Legal Assessment: The present proceedings concern a data transfer to a third country within the meaning of Chapter V of the GDPR and a breach of information obligations under Article 13 of the GDPR. In summary, the complainant argues that the data transfer to the USA was lawful because the contractual arrangements for the transfer provided suitable safeguards to prevent any undermining of the European Union's level of data protection. Regarding the information obligations under Article 13 of the GDPR, the facts established by the respondent authority require further clarification. The present proceedings concern a data transfer to a third country within the meaning of Chapter V of the GDPR and a breach of information obligations within the meaning of Article 13 of the GDPR. The complainant argues, in summary, that the data transfer to the USA was lawful because the contractual arrangements for the transfer provided suitable safeguards to prevent any undermining of the level of data protection in the European Union. Regarding the information obligations within the meaning of Article 13 of the GDPR, the facts established by the respondent authority require further clarification. Regarding A) Regarding Point I of the Ruling 3.1. It is undisputed that the complainant is the "controller" within the meaning of Article 4(7) of the GDPR and that the present case also involves personal data within the meaning of Article 4(1) of the GDPR. Rather, it must be clarified whether an (un)lawful transfer of data to the USA has taken place and whether the other party involved has been infringed in its right of access pursuant to Article 13 GDPR. 3.1. The fact that the complainant is the "controller" within the meaning of Article 4, point 7, GDPR and that personal data within the meaning of Article 4, point 1, GDPR is also at issue in the present case is undisputed. Rather, it must be clarified whether an (un)lawful transfer of data to the USA has taken place and whether the other party involved has been infringed in its right of access pursuant to Article 13 GDPR. 3.2. Article 5 GDPR governs the principles for the processing of personal data and stipulates, in summary, in paragraph 1, that personal data must be processed lawfully, fairly, and transparently (lit. a); personal data must be collected for specified, explicit, and legitimate purposes and may not be further processed in a manner incompatible with those purposes (Article 5(b)); must be adequate, relevant, and limited to what is necessary for the purposes for which they are processed (Article 5(c)); must be accurate and, where necessary, kept up to date (Article 5(d)); must be kept in a form which permits identification of the data subject for no longer than is necessary for the purposes for which they are processed (Article 5(e)); and must be processed in a manner that ensures appropriate security of the personal data (Article 5(f)). According to Article 5(2) GDPR, the controller must be able to demonstrate compliance with paragraph 1. 3.2. Article 5 GDPR governs the principles for the processing of personal data and stipulates in paragraph 1, in summary, that personal data must be processed lawfully, fairly, and transparently (Article 5(a)). Personal data must be collected for specified, explicit, and legitimate purposes and may not be further processed in a manner incompatible with those purposes (Article b); must be adequate, relevant, and limited to what is necessary for the purposes for which they are processed (Article c); must be accurate and, where necessary, kept up to date (Article d); must be stored in a form which permits identification of the data subject for no longer than is necessary for the purposes for which they are processed (Article e); and must be processed in a manner that ensures appropriate security of the personal data (Article f). According to Article 5(2) of the GDPR, the controller must be able to demonstrate compliance with paragraph 1. In line with this, the CJEU held in its case law that the GDPR is addressed to "controllers" in principle, and that controllers must not only take appropriate and effective measures to protect personal data but must also be able to demonstrate that their processing activities comply with the GDPR. (cf. ECJ 05.12.2023, C-807/21 [Deutsche Wohnen] para. 38; ECJ 24.02.2022, C-175/20 [“SS” SIA] para. 77; ECJ 04.07.2023, C-252/21 [Meta/Bundeskartellamt] para. 95) Correspondingly, the ECJ held in its case law that the GDPR is addressed in principle to “controllers” and that these controllers must not only take appropriate and effective measures to protect personal data, but must also be able to demonstrate that their processing activities comply with the GDPR. cf. ECJ 05.12.2023, C-807/21 [Deutsche Wohnen] para. 38; ECJ 24.02.2022, C-175/20 [“SS” SIA] para. 77; (ECJ 04.07.2023, C-252/21 [Meta/Bundeskartellamt] para. 95) 3.3. Chapter V of the GDPR governs the transfer of personal data to third countries or international organizations. According to Article 44 of the GDPR, a transfer to a third country is generally only permissible if the controller or processor complies with the conditions of Chapter V and also complies with the other provisions of the GDPR. The level of protection guaranteed by the GDPR must not be undermined. According to Article 45 of the GDPR, a transfer within the meaning of the GDPR is only permissible if the controller or processor complies with the conditions of Chapter V and also complies with the other provisions of the GDPR. Article 44 of the GDPR allows for transfers of personal data to third countries or international organizations if the Commission has decided that the third country, a territory or one or more specific sectors within that third country, or the international organization in question ensures an adequate level of protection. Such transfers do not require any special authorization. Article 45 of the GDPR also allows for transfers of personal data to third countries or international organizations if the Commission has decided that the third country, a territory or one or more specific sectors within that third country, or the international organization in question ensures an adequate level of protection. Such transfers do not require any special authorization. If no decision pursuant to Article 45 of the GDPR exists, Article 46 of the GDPR allows for transfers of personal data to a third country or an international organization only if the controller or processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the data subjects. Article 45 of the GDPR provides that, according to Article 46 of the GDPR, a controller or processor may only transfer personal data to a third country or an international organisation if the controller or processor has provided suitable safeguards and if enforceable rights and effective legal remedies are available to the data subjects. Article 49 of the GDPR stipulates that, in the absence of an adequacy decision pursuant to Article 45 of the GDPR or appropriate safeguards pursuant to Article 46 of the GDPR, the transfer or series of transfers of personal data to a third country or an international organization is only permissible under certain specified conditions. 3.4. In accordance with Guidelines 5/2021 on the interplay between the application of Article 3 and the provisions on international transfers under Chapter V of the GDPR issued by the European Data Protection Board (Version 2.0, 14 February 2023; hereinafter referred to as the “Guidelines”), there are three cumulative criteria by which it can be determined whether a processing operation constitutes a transfer within the meaning of Chapter V of the GDPR: (i) a controller or processor (exporter) is subject to the GDPR for the processing in question, (ii) the exporter discloses personal data that are the subject of this processing to another controller, joint controller or processor (“importer”), by transfer or otherwise, (iii) the importer is located in a third country, regardless of whether that importer is subject to the GDPR for the processing in question, or the importer is an international organisation. 3.4. In accordance with Guidelines 5 of 2021 on the interplay between the application of Article 3 and the provisions on international transfers under Chapter 5 of the GDPR issued by the European Data Protection Board (Version 2.0, 14 February 2023; hereinafter referred to as the “Guidelines”), there are three cumulative criteria for determining whether a processing operation constitutes a transfer within the meaning of Chapter 5 of the GDPR: (i) a controller or processor (exporter) is subject to the GDPR for the processing in question, (ii) the exporter discloses personal data that are the subject of this processing, by transfer or otherwise, to another controller, joint controller, or processor (“importer”), (iii) the importer is located in a third country, regardless of whether the importer is subject to the GDPR for the processing in question, or the importer is an international organization. (i) a controller or processor (exporter) is subject to the GDPR for the processing in question, (ii) the exporter discloses personal data that are the subject of this processing to another controller, joint controller, or processor (“importer”), (iii) the importer is located in a third country, regardless of whether the importer is subject to the GDPR for the processing in question, or the importer is an international organization. Article 8(1) of the EU Charter of Fundamental Rights establishes an obligation to maintain the level of protection afforded by EU law (ECJ 06.10.2015, C-362/14 (Schrems I), para. 72). The relevant provisions govern the conditions under which a controller or processor (exporter) may transfer personal data to a third country. The term "transfer," which is not legally defined, must be understood in relation to the purpose of data protection within the framework of Articles 44 et seq. It therefore encompasses any transfer of personal data to an entity outside the territory of the European Union or to an international organization (Kühling/Buchner, GDPR·BDSG3, Art. 44, para. 16; Jahnel, Commentary on the General Data Protection Regulation, Art. 44 GDPR (as of 1 December 2020, rdb.at), para. 18). Article 8(1) of the EU Charter of Fundamental Rights establishes an obligation to maintain the level of protection afforded by EU law (ECJ 6 October 2015, C-362/14 (Schrems, Roman numeral I), para. 72). These provisions govern the conditions under which a controller or processor (exporter) may transfer personal data to a third country. The term "transfer," which is not legally defined, must be understood in relation to the purpose of data protection within the framework of Articles 44 et seq. It therefore encompasses any transfer of personal data to an entity outside the territory of the European Union or to an international organization (Kühling/Buchner, GDPR/BDSG3, Article 44, para. 16; Jahnel, Commentary on the General Data Protection Regulation, Article 44 GDPR (as of December 1, 2020, rdb.at), para. 18). 3.5. In its decision C-311/18 of July 16, 2020 (Schrems II), the CJEU dealt extensively with Chapter V of the GDPR and the question of under what conditions the transfer of personal data to third countries is permissible. Both the CJEU's judgment and the case at hand concern a data transfer to the USA. 3.5. In its decision C-311/18 of 16 July 2020 (Schrems Roman numeral II), the CJEU dealt extensively with Chapter V of the GDPR and the question of under what conditions the transfer of personal data to third countries is permissible. Both the CJEU's judgment and the case at hand concern a data transfer to the USA. The preliminary ruling request in case C-311/18 concerned, firstly, the interpretation of Articles 3(2), 25, 26 and 28(3) of Directive 95/46/EC in light of Article 4(2) TEU and Articles 7, 8 and 47 of the Charter of Fundamental Rights of the EU. Secondly, it concerned the interpretation and validity of Decision 2010/87/EU on standard contractual clauses (SCC Decision) and the interpretation and validity of Implementing Decision (EU) 2016/1250 on the adequacy of the protection provided by the EU-US Privacy Shield (DSS Decision). The preliminary ruling request at issue in Case C-311/18 concerned, firstly, the interpretation of Articles 3(2), 25, 26 and 28(3) of Directive 95/46/EC in light of Article 4(2) TEU and Articles 7, 8 and 47 of the Charter of Fundamental Rights of the EU. Secondly, it concerned the interpretation and validity of Decision 2010/87/EU on Standard Contractual Clauses (SCC Decision) and the interpretation and validity of Implementing Decision (EU) 2016/1250 on the adequacy of the protection provided by the EU-US Privacy Shield (DSS Decision). The judgment stemmed from a complaint filed by Mr. Schrems before the High Court of Ireland, in which he essentially argued that the Commission's SCC Decision did not provide adequate protection for personal data against access by US authorities within the meaning of Articles 7, 8 and 47 of the Charter of Fundamental Rights of the European Union (CFR). According to Mr. Schrems, EU citizens therefore did not have the same rights as US citizens. Articles 7, 8, and 47 of the Charter of Fundamental Rights of the European Union (CFR) provide for this. EU citizens, therefore, do not possess the same rights as US citizens. The judgment implies that data transfers from the EU to other EU countries are generally subject to the GDPR, even if the data may be processed abroad for purposes of public security, national defense, and state security. (Paragraph 89) Regarding the level of protection that must exist for data transfers within the meaning of Article 46(1) and (2)(c) GDPR, the CJEU stated that while Article 46 GDPR does not specify the nature of the requirements arising from the reference to "appropriate safeguards," "enforceable rights," and "effective legal remedies," the level of protection guaranteed by the GDPR must not be undermined. The level of protection in the third country need not be identical to that of Union law, but it must, in light of the national legal system, offer protection equivalent to that of the GDPR in light of the Charter of Fundamental Rights. In the assessment required in connection with such a transfer, particular consideration must be given to the contractual arrangements agreed between the controller established in the Union or its processor established there and the recipient of the transfer established in the third country concerned, as well as, with regard to any access by the authorities of that third country to the transferred personal data, the relevant elements of that country's legal system. (Paragraphs 90 et seq.) Regarding the level of protection that must be ensured in the case of a data transfer within the meaning of the Charter, The CJEU explained that Article 46(1) and (2)(c) of the GDPR must be met. While Article 46 of the GDPR does not specify the nature of the requirements arising from the reference to "appropriate safeguards," "enforceable rights," and "effective legal remedies," the level of protection guaranteed by the GDPR must not be undermined. The level of protection in the third country does not have to be identical to that of EU law, but it must, in light of the national legal system, offer protection equivalent to that of the GDPR in light of the Charter of Fundamental Rights of the European Union (CFR). In the assessment required in connection with such a transfer, particular consideration must be given to the contractual arrangements agreed between the controller or processor established in the Union and the recipient of the transfer established in the third country in question, as well as, with regard to any potential access by the authorities of that third country to the transferred personal data, the relevant elements of that country's legal system. (Paragraphs 90 et seq.) With regard to the SDK decision, the Court held that it is undisputed that standard data protection clauses cannot be effective against authorities of a third country, since these are not contracting parties. Therefore, the standard data protection clauses may or may not guarantee sufficient data protection under the national law of the third country. This is the case, for example, if the law of the third country permits its authorities to interfere with the rights of data subjects with regard to this data.The safeguards afforded to a data subject within the meaning of Article 46(1) GDPR do not necessarily have to be provided for in a Commission decision such as the SDK decision. In this respect, such a decision differs from an adequacy decision adopted pursuant to Article 45(3) GDPR, which aims – following an examination of the law of the third country in question, taking into account in particular the relevant rules in the area of national security and the access of authorities to personal data – to establish definitively that a third country, a territory, or one or more specific sectors within that third country provides an adequate level of protection, so that the access of the authorities of that country to such data is not precluded. Therefore, it cannot be inferred from Article 46 GDPR that the Commission is obliged to assess the adequacy of the level of protection of the third country before adopting standard data protection clauses. In the absence of an adequacy decision, it is therefore up to the data-exporting controller established in the EU to provide suitable safeguards. In this respect, it may be necessary to supplement standard data protection clauses with additional safeguards. (Paragraphs 122 et seq.) With regard to the SDK decision, the Court held that it is undisputed that standard data protection clauses cannot be effective against the authorities of a third country, as they are not a contracting party. Therefore, standard data protection clauses may or may not guarantee sufficient data protection with regard to the national law of the third country. This is the case, for example, if the law of the third country permits its authorities to interfere with the rights of data subjects with regard to this data. However, the safeguards to which a data subject has within the meaning of Article 46(1) GDPR do not necessarily have to be provided for in a Commission decision such as the SDK decision. In this respect, such a decision differs from an adequacy decision adopted pursuant to Article 45(3) of the GDPR, which aims—following an examination of the law of the third country concerned, taking into account in particular the relevant rules in the area of national security and the access of authorities to personal data—to establish definitively that a third country, a territory, or one or more specific sectors within that third country provide an adequate level of protection, so that the access of the authorities of that country to such data does not preclude its transfer to that country. Therefore, it cannot be inferred from Article 46 of the GDPR that the Commission is obliged to assess the adequacy of the level of protection of the third country before adopting standard data protection clauses. In the absence of an adequacy decision, it is therefore for the data-exporting controller established in the EU to provide appropriate safeguards. In this respect, it may be necessary to supplement standard data protection clauses with additional safeguards. (Paragraphs 122 et seq.) Finally, the Court examined the Commission's DSS decision in more detail, focusing in particular on the concerns raised by the referring court that the legal protection afforded to data subjects against US authorities was not equivalent to that afforded under EU law. In response to a question from the Court, the US government admitted that Presidential Policy Directive 28 (“PPD-28”), which, among other things, governs the access procedures of US authorities to data, does not grant data subjects any rights that can be enforced in court against these authorities. Similarly, Executive Order 12333, which is relevant to data processing, does not grant data subjects any rights that can be enforced in court with regard to surveillance programs of US authorities. Overall, it must be assumed that neither Section 702 of the FISA nor the Executive Order 12333 provides sufficient legal protection for data subjects. 12333 in conjunction with PPD-28 do not meet the minimum requirements under EU law based on the principle of proportionality, so that it cannot be assumed that the surveillance programs based on these provisions are limited to what is strictly necessary and are therefore incompatible with Article 52(1), second sentence, of the Charter of Fundamental Rights. The creation of an ombudsman mechanism dealing with data protection matters was unable to remedy this deficiency. (Paragraphs 150 et seq.) Finally, the Court examined the Commission's DSS decision in more detail and addressed in particular the concerns raised by the referring court that the legal protection afforded to data subjects against US authorities was not equivalent to that afforded under EU law. In response to a question from the Court, the US government admitted that Presidential Policy Directive 28 (“PPD-28”), which, inter alia, governs the modalities of US authorities' access to data, does not confer any rights on data subjects that can be enforced in court against those authorities. Executive Order 12333, which is relevant to data processing, also does not grant data subjects any legally enforceable rights with regard to US surveillance programs. Overall, it must be assumed that neither Section 702 of the FISA nor Executive Order 12333 in conjunction with PPD-28 meets the minimum requirements of proportionality under EU law. Therefore, it cannot be assumed that the surveillance programs based on these provisions are limited to what is strictly necessary and are thus incompatible with Article 52(1), second sentence, of the Charter of Fundamental Rights of the European Union (CFR). The establishment of an ombudsman mechanism dealing with data protection issues was unable to remedy this deficiency. (Paragraphs 150 et seq.) 3.6. With Implementing Decision (EU) 2023/1795 of 10 July 2023, the Commission adopted the “Data Privacy Framework” and thus a new adequacy decision within the meaning of the Charter. Article 45(3) GDPR regarding data transfers to the USA. However, this decision is irrelevant to the present proceedings, as it was adopted after the data processing at issue. 3.6. With Implementing Decision (EU) 2023/1795 of 10 July 2023, the Commission adopted the “Data Privacy Framework” and thus a new adequacy decision within the meaning of Article 45(3) GDPR regarding data transfers to the USA. However, this decision is irrelevant to the present proceedings, as it was adopted after the data processing at issue. 3.7. Pursuant to Article 46(1) GDPR, a controller may, in the event that no adequacy decision has been issued by the Commission within the meaning of Article 45(3) GDPR, Article 45(3) GDPR applies, and personal data may only be transferred to a third country if appropriate safeguards are in place and enforceable rights and effective legal remedies are available to the data subjects. Paragraphs 2 and 3 of Article 46 GDPR then provide for measures that may constitute appropriate safeguards. 3.7. Pursuant to Article 46(1) GDPR, if no adequacy decision by the Commission pursuant to Article 45(3) GDPR exists, a controller may only transfer personal data to a third country if appropriate safeguards are in place and enforceable rights and effective legal remedies are available to the data subjects. Paragraphs 2 and 3 of Article 46 GDPR then provide for measures that may constitute appropriate safeguards. Article 46(2) and (3) GDPR then provide for measures that may constitute appropriate safeguards. Article 46(2)(c) of the GDPR stipulates that standard contractual clauses adopted by the Commission in accordance with the examination procedure under Article 93(2) of the GDPR can constitute appropriate safeguards. In the aforementioned judgment of the CJEU of 16 July 2020 (Schrems II), the Court stated that standard contractual clauses as an instrument for international data transfers to third countries are, in principle, not objectionable. However, it also pointed out that standard contractual clauses are contractual in nature and therefore cannot bind third parties, or in particular public authorities. (See paragraph 126) Rather, what matters is an overall assessment of the appropriate safeguards and whether, under certain circumstances, additional safeguards exist alongside the standard data protection clauses. It must be assumed that the standard data protection clauses adopted by the Commission pursuant to Article 46(2)(c) GDPR are intended only to provide controllers established in the Union, or their processors established there, with contractual safeguards that apply uniformly in all third countries, i.e., irrespective of the level of protection guaranteed in each of those countries. Since these standard data protection clauses, by their very nature, cannot offer safeguards that go beyond the contractual obligation to ensure compliance with the level of protection required by Union law, it may be necessary, depending on the situation in a particular third country, for the controller to take additional measures to ensure compliance with that level of protection. (cf. paragraph 133) In the above-mentioned judgment of the ECJ of 16 July 2020 (Schrems Roman numeral II), the Court stated that standard data protection clauses as an instrument for international data transfers to third countries are in principle not objectionable, but it also pointed out that standard data protection clauses are contractual in nature and therefore cannot bind third parties or, in particular, authorities.(See paragraph 126) Rather, it depends on an overall assessment of the appropriate safeguards and whether, under certain circumstances, additional safeguards exist alongside the standard data protection clauses. It must be assumed that the standard data protection clauses adopted by the Commission pursuant to Article 46(2)(c) GDPR are intended only to provide contractual safeguards to controllers established in the Union or their processors established there, which apply uniformly in all third countries, i.e., regardless of the level of protection guaranteed in each of those countries. Since these standard data protection clauses, by their very nature, cannot provide safeguards that go beyond the contractual obligation to ensure compliance with the level of protection required under Union law, it may be necessary, depending on the situation in a particular third country, for the controller to take additional measures to ensure compliance with that level of protection. (See paragraph 133) For the case at hand, this means the following: 3.8. As established, the complainant and XXXX, a marketing and sales company based in the USA, entered into a contract for the sending of informational and promotional emails. For the purpose of sending these emails, XXXX transmitted the names and email addresses of the complainant's customers. The central issue in these proceedings is therefore whether the data was lawfully transferred to the USA as a third country. 3.8. As established, the complainant and XXXX, a marketing and sales company based in the USA, entered into a contract for the sending of informational and promotional emails. For the purpose of sending these emails, XXXX transmitted the names and email addresses of the complainant's customers. The central issue in these proceedings is therefore whether the data was lawfully transferred to the USA as a third country. ... As stated at the outset, Articles 44 et seq. of the GDPR govern the transfer of personal data to third countries or international organizations and establish the framework conditions under which such transfers are permissible. The party involved in these proceedings received the promotional email underlying these proceedings on March 7, 2022, which establishes that the data was processed by the email service of XXXX at least on that day. The party involved in these proceedings received the promotional email underlying these proceedings on March 7, 2022, which establishes that the data was processed by the email service of [Company Name] at least on that day. The judgment of the CJEU in case C-311/18, discussed in detail above, which declared the Commission's adequacy decision regarding the EU-US Privacy Shield pursuant to Article 45 GDPR invalid, was issued on July 16, 2020, almost two years before the data processing at issue in these proceedings. Since the subsequently negotiated EU-US Data Privacy Framework did not enter into force until July 10, 2023, there was no adequacy decision by the European Commission regarding data transfers to the USA at the time of the relevant data processing. The respondent authority's position on this point is therefore correct. The judgment of the CJEU in case C-311/18, discussed in detail above, which declared the Commission's adequacy decision regarding the EU-US Privacy Shield pursuant to Article 45 GDPR invalid, was issued on July 16, 2020, almost two years before the data processing at issue in these proceedings. Article 45 of the GDPR, which was declared invalid, was enacted on July 16, 2020, almost two years before the data processing at issue in these proceedings. Since the subsequently negotiated EU-US Data Privacy Framework did not enter into force until July 10, 2023, there was no adequacy decision by the European Commission regarding data transfers to the USA at the time of the relevant data processing. The respondent authority's position on this point is therefore correct. 3.9. During the proceedings, the complainant repeatedly argued that the data processing by XXXX was accompanied by extensive measures to ensure a level of data protection equivalent to that of the GDPR. In particular, she emphasized the use of the European Commission's Standard Contractual Clauses as well as additional technical, contractual, and organizational measures such as encryption, terms of use, and storage management systems. 3.9. The complainant repeatedly argued during the proceedings that data processing by Römische 40 was accompanied by extensive measures to ensure a level of data protection equivalent to that of the GDPR. In particular, she emphasized the use of the European Commission's Standard Contractual Clauses and additional technical, contractual, and organizational measures such as encryption, terms of use, and storage management systems. Ultimately, however, the respondent authority is correct in its assessment, which rightly refers to the European Data Protection Board's findings that while the additional measures outlined do raise the fundamental level of data protection, they cannot eliminate the concerns raised by the CJEU in its Schrems II ruling. The CJEU summarized that, despite the EU-US Privacy Shield, data subjects are sometimes unable to seek judicial redress from third-party data transfers. As a result, the level of data protection is not equivalent to that of the European Union. Although the complainant was able to demonstrate that both she and XXXX had implemented several measures to ensure a high level of data protection, these measures, as the respondent authority correctly recognized, cannot remedy the shortcomings of the EU-US Privacy Shield. Despite the data protection measures, US authorities have the same possibilities and rights as under the Privacy Shield, and therefore, data protection comparable to the GDPR is not guaranteed. Ultimately, however, the respondent authority is also correct in its assessment, which rightly refers to the European Data Protection Board's statements that while the additional measures outlined do raise the fundamental level of data protection, they cannot eliminate the concerns raised by the CJEU in its Schrems II decision. In summary, the CJEU stated that, despite the EU-US Privacy Shield, data subjects are sometimes unable to seek judicial redress. As a result, the level of data protection is not equivalent to that of the European Union. Although the appellant was able to demonstrate that both it and Rome 40 had implemented several measures to ensure a high level of data protection, these measures, as the respondent authority correctly recognized, cannot remedy the deficiencies of the Privacy Shield. Despite the data protection measures, US authorities would have the same opportunities and rights as under the Privacy Shield, and therefore, data protection comparable to the GDPR is not guaranteed. Even with regard to the data migration to European data centers at the end of March 2023, the court cannot discern how this constitutes a measure capable of addressing the concerns raised by the CJEU. With regard to a potential exception under Article 49 GDPR, no specific arguments were presented, and in the court's view, no such exception arises from the case file. With regard to a potential exception under Article 49 GDPR, no specific arguments were presented, and in the court's view, no such exception arises from the case file. Regarding Point II of the Decision 3.10 In Point II of the Decision, the respondent authority upheld the data protection complaint of the co-litigant and found that the complainant had violated the co-litigant's right to information by failing to provide the information required under Article 13 GDPR at the time of data collection and thus failing to comply with its information obligation under Article 13 GDPR. 3.11 As already explained in Point I of the Decision, Article 5 GDPR governs the principles for the processing of personal data. In addition to the principles described in more detail above in paragraph 1 of the aforementioned Article 5 GDPR, the following principles also apply: Article 5(2) GDPR stipulates that the controller is responsible for compliance with the principles set out in paragraph 1 and must be able to demonstrate such compliance within the framework of accountability. 3.11. As already explained in point 1, Article 5 GDPR governs the principles for the processing of personal data. In addition to the principles of paragraph 1 described above, Article 5(2) GDPR stipulates that the controller is responsible for compliance with the principles set out in paragraph 1 and must be able to demonstrate such compliance within the framework of accountability. According to Article 13 GDPR, controllers who collect data from data subjects must provide them with certain information.The right to information under Article 13 GDPR differs from the right to information under Article 15 GDPR in that the latter is an active obligation of the controller, whereas information under Article 15 GDPR only needs to be provided upon request by the data subject. Information under Article 13 GDPR therefore does not require a request. (cf. Austrian Administrative Court [VwGH] 06.03.2024, Ro 2021/04/0030, RS 13 and 18) According to Article 13 GDPR, controllers who collect data from data subjects must provide them with certain information. The right to information under Article 13 GDPR differs from the right to information under Article 15 GDPR in that the former is an active obligation of the controller, whereas information under Article 15 GDPR only needs to be provided upon request by the data subject. Information pursuant to Article 13 of the GDPR therefore does not require a formal request. (See Austrian Administrative Court [VwGH] decision of March 6, 2024, Ro 2021/04/0030, paragraphs 13 and 18.) According to Article 13(1) of the GDPR, the following information must be provided, but is not limited to, but includes in particular, the contact details of the controller (lit. a), the contact details of the data protection officer (lit. b), the purposes of the processing including the legal basis (lit. c), any legitimate interests in the data processing (lit. d), the recipients or categories of recipients of the personal data (lit. e), and, where applicable, the intention to transfer the personal data to a third country or an international organization. According to Article 13, paragraph 1, of the GDPR, the following information must be provided, but is not limited to, but includes in particular, the contact details of the controller (paragraph a), the contact details of the data protection officer (paragraph b), the purposes of the processing including the legal basis (paragraph c), any legitimate interests in the data processing (paragraph d), the recipients or categories of recipients of the personal data (paragraph e), and, where applicable, the intention to transfer the personal data to a third country or an international organization. Article 13 of the GDPR is thus to be regarded as a stricter form of self-responsibility for controllers. Data subjects must be informed at the time of data collection, whereby "collection" is to be considered the beginning of data processing. This includes both data provided by the data subject and data generated by the controller. (cf. Illibauer in Knyrim, DatKomm Art. 13 GDPR para. 1 f, 20 f (as of 1 July 2024, rdb.at)) Article 13 of the GDPR is thus to be regarded as stricter self-responsibility for controllers. Data subjects must be informed at the time of data collection, whereby "collection" is to be regarded as the beginning of data processing. This includes both data provided by the data subject and data generated by the controller. (See Illibauer in Knyrim, DatKomm, Article 13, GDPR, paragraphs 1 et seq., 20 et seq. (as of July 1, 2024, rdb.at)) Article 12 of the GDPR establishes the transparent information, communication, and modalities for the exercise of data subject rights and stipulates in paragraph 1, in particular, that the controller shall take all appropriate measures to provide the data subject with all information pursuant to Articles 13 and 14 and all communications pursuant to Articles 15 to 22 and Article 34 of the GDPR relating to processing in a concise, transparent, intelligible, and easily accessible form, using clear and plain language. "Easily accessible" refers to the external presentation of the information. (cf. Jahnel, Commentary on the General Data Protection Regulation, Art. 13 GDPR, para. 11 (as of December 1, 2020, rdb.at)) Article 12 of the GDPR establishes the transparent information, communication, and modalities for the exercise of the rights of data subjects and stipulates in paragraph one, in particular, that the controller shall take all appropriate measures to provide the data subject with all information pursuant to Articles 13 and 14 and all communications pursuant to Articles 15 to 22 and Article 34 of the GDPR relating to processing in a concise, transparent, intelligible, and easily accessible form, using clear and plain language. "Easily accessible" refers to the external presentation of the information. (See Jahnel, Commentary on the General Data Protection Regulation, Article 13, GDPR, para. 11 (as of December 1, 2020, rdb.at)) With regard to Article 14 GDPR, the Austrian Administrative Court (VwGH) stated that the controller's obligation to provide information under Article 14 GDPR exists independently of any prior request from the data subject. Accordingly, there is no requirement for the data subject to first assert a claim for performance that must then be fulfilled. Therefore, there is no legal violation in the failure to fulfill such a claim that could be (subsequently) remedied. Rather, the legal violation lies in the failure to provide the (unsolicited) information, which cannot be retrospectively remedied by subsequent information provided in response to a request from the data subject within the meaning of Article 15 GDPR. (cf. Austrian Administrative Court [VwGH] 06.03.2024, Ro 2021/04/0030, RS 14) With regard to Article 14 of the GDPR, the Austrian Administrative Court stated that the controller's obligation to provide information under Article 14 of the GDPR exists independently of any prior request from the data subject. Accordingly, there is no requirement for the data subject to first assert a request for performance, which must then be complied with. Consequently, there is no legal infringement in the failure to comply with such a request that could be (subsequently) remedied. Rather, the legal infringement lies in the failure to provide the (unsolicited) information, which cannot be retrospectively remedied by subsequent information provided in response to a request from the data subject within the meaning of Article 15 of the GDPR. (See Austrian Administrative Court [VwGH] 06.03.2024, Ro 2021/04/0030, RS 14) The obligation to provide information is a prerequisite for data subjects whose personal data is being processed to exercise their rights to access, rectification, or erasure (etc.) (see the statement by the European Court of Justice in its judgment of 1 October 2015, C-201/14, [Smaranda Bara et al.], which is applicable to the GDPR in this respect). However, to fulfill this function, it is also necessary that this information be easily accessible to the data subject. This cannot be guaranteed in a case where the personal data was not collected from the data subject, the data subject has no other connection with the controller, and therefore has no need to be aware of the processing of their personal data by the controller, simply by making a privacy policy available on a website. In light of the objective also expressed by the CJEU, Article 14(1) GDPR cannot be interpreted to mean that the availability of the information specified therein on a website is sufficient without the data subject having been actively and explicitly notified of this form of provision, even if the data subject was not aware of the fact that their data was being processed by the controller. (cf. Austrian Administrative Court [VwGH] 06.03.2024, Ro 2021/04/0030, RS 19) This also applies to Article 13 GDPR. The obligation to provide the information is a prerequisite for the data subject whose personal data is being processed to exercise their rights of access, rectification, or erasure (etc.). (Compare the CJEU's statement of 1 October 2015, C-201/14, [Smaranda Bara et al.], which is applicable to the GDPR in this respect.) To fulfill this function, it is essential that this information be easily accessible to the data subject. This cannot be guaranteed in cases where the personal data was not collected from the data subject, the data subject has no other connection with the controller, and therefore has no reason to be aware of the processing of their personal data by the controller. In such cases, the mere availability of a privacy policy on a website does not guarantee this. Given the objective also expressed by the CJEU, Article 14(1) GDPR cannot be interpreted as meaning that the availability of the information mentioned therein on a website is sufficient without the data subject having been actively and explicitly notified of this form of provision, even if the data subject had no knowledge of the fact that their data was being processed by the controller. (See Austrian Administrative Court [VwGH] 06.03.2024, Ro 2021/04/0030, RS 19). This also applies to Article 13 GDPR. In light of the objective also expressed by the CJEU, Article 14(1) GDPR cannot be interpreted as meaning that the availability of the information mentioned therein on a website without the data subject having been actively and explicitly informed of this form of provision, even if the data subject had no knowledge of the fact that their data was being processed by the controller. 3.12. For the present case, this means: As established, the magazine subscription in question was concluded by telephone on April 30, 2021. During the proceedings, the complainant failed to demonstrate, pursuant to Article 5(2) GDPR, that the other party involved had been provided with all relevant information within the meaning of Article 13 GDPR. The panel is aware that an essentially identical subscription ended immediately prior to the subscription in question, and therefore the other party involved must have been aware of certain information within the meaning of Article 13 GDPR. However, it must be noted that the complainant was unable to provide any evidence relating to the subscription in question, and that significant changes occurred immediately after the conclusion of the subscription in question, namely the engagement of the marketing software service provider involved in the proceedings, about which the other party involved was likewise not informed. As established, the magazine subscription in question was concluded by telephone on April 30, 2021. During the proceedings, the complainant failed to demonstrate, as required by Article 5(2) of the GDPR, that the other party involved had been provided with all relevant information within the meaning of Article 13 of the GDPR. The panel acknowledges that an essentially identical subscription ended immediately prior to the one in question, and that the other party must therefore have been aware of certain information within the meaning of Article 13 of the GDPR. However, it must be noted that the complainant was unable to provide any evidence relating to the subscription in question, and that significant changes occurred immediately after the conclusion of the subscription in question, namely the engagement of the marketing software service provider in question, about which the other party was likewise not informed. Although the complainant referred to the updated privacy policies and general terms and conditions (GTC), which are or were available online, she failed to sufficiently demonstrate that the other party involved had been informed of these or that they had been provided to her, nor that the GTC had actually become part of the contract. In this regard, reference should be made to the oral hearing before the court, in which the complainant was explicitly questioned about the relevant information but was unable to provide it. The complainant has therefore failed to comply with her accountability obligation under Article 5(2) GDPR. 3.13. The decision was therefore rendered accordingly. Regarding B) Inadmissibility of the appeal: The appeal is inadmissible pursuant to Article 133(4) of the Austrian Federal Constitutional Law (B-VG) because the decision does not depend on the resolution of a legal question of fundamental importance. The present decision neither deviates from the established case law of the Administrative Court nor is there a lack of relevant case law; furthermore, the existing case law of the Administrative Court cannot be considered inconsistent. There are also no other indications that the legal question to be resolved is of fundamental importance. The appeal is inadmissible pursuant to Article 133, paragraph 4, of the Austrian Federal Constitutional Law (B-VG) because the decision does not depend on the resolution of a legal question of fundamental importance. The present decision neither deviates from the established case law of the Administrative Court nor is there a lack of relevant case law; furthermore, the existing case law of the Administrative Court cannot be considered inconsistent. There are also no other indications that the legal question to be resolved is of fundamental importance. In light of the facts of the case and the associated legal questions, the court was able to draw upon extensive case law of the highest courts. No legal questions requiring clarification by the Administrative Court (VwGH) have arisen. Therefore, the appeal was ultimately inadmissible.




