BVwG - W176 2250812-1

From GDPRhub
BVwG - W176 2250812-1
Court: BVwG (Austria)
Jurisdiction: Austria
Relevant Law: Article 6 GDPR
Article 15 GDPR
Article 15(1)(h) GDPR
Article 15(1)(a) GDPR
Article 20 GDPR
Article 22 GDPR
Article 99 GDPR
Decided: 21.08.2025
Published: 03.10.2025
Parties:
National Case Number/Name: W176 2250812-1
European Case Law Identifier: ECLI:AT:BVWG:2025:W176.2250812.1.00
Appeal from:
Appeal to: Not appealed
Original Language(s): German
Original Source: RIS (in German)
Initial Contributor: xz

A court dismissed a complaint regarding an alleged failure to provide access to the logic involved in a credit assessment in 2010. The court held that Article 15(1)(h) GDPR could not be applied retroactively to individual decision making that occurred before the GDPR became applicable.

English Summary

Facts

A data subject was employed by the controller for several years. In 2010 the controller and the data subject signed also a loan agreement. Before concluding the loan agreement, the controller carried out a credit check which resulted in a classification of the data subject’s creditworthiness, nevertheless, a further processing of data of the data subject for the purposes of automated decision-making including profiling did not take place. The controller terminated the employment on 2018.

On 2020, the data subject filed a complaint against the controller for allegedly failing to provide complete information and to comply with the request of the data subject for the transfer of the data under Article 15 and 20 GDPR. At a later stage in the proceedings, the data subject withdrew the complaint relating to the exercise of rights under Article 20 GDPR.

Although the controller provided several sets of documents between 2018 and 2020, the data subject claimed these were incomplete according to Article 15 GDPR, that the controller’s responses were insufficient and the legal basis for data processing was not clearly explained. The data subject also claimed that its loan-related information was only partially provided and the automated processing of its personal data for credit analysis constituted profiling under Article 4(4) and 22 GDPR.

The controller stated that it had provided extensive data in paper and electronic form in a comprehensive and structured manner, that some data were unavailable or withheld to protect third-party rights and that information on the systematic analysis of credit risk was a trade secret.

On 19 October 2021, the DPA partially upheld the data subject’s complaint, finding that the controller had violated the data subject’s right to information, because there was no reference to the processing purposes within the meaning of Article 5(1)(b) GDPR and the legal basis was not clear , and also the controller could not rely solely on business or trade secrets to refuse disclosure, and ordered the controller to provide to the data subject complete information under Article 15(1)(a) GDPR and Article 15(1)(h) GDPR. The remainder of the complaint was dismissed.

The controller appealed this decision and the case was subsequently transferred to the Federal Administrative Court.

Holding

The Court upheld the appeal and dismissed the data subject’s complaint entirely .

Information regarding the purposes of the processing under Article 15(1)(a) GDPR

The Court emphasized that, according to Recital 63 GDPR the entire right of access under Article 15 GDPR, including the creation of the processing purposes, serves to ensure that the data subject should be able to verify the legality of the processing. A legal basis for the processing is therefore not to be provided in any case, it must be provided when necessary to assess lawfulness.

The Court found that the controller had sufficiently stated both the legal bases and the purposes of data processing, by providing several different documents, including references to Article 6(1) GDPR. The information given was enough for the data subject to understand why the data was being processed and to evaluate its lawfulness. Therefore, the Court disagreed with the data protection authority’s initial claim that it was unclear which data were processed for which purposes.

It was evident from data subject’s initial response that the personal data processed up to that point related to data subject’s employment and was handled by the controller in its role as employer. As such, the controller did not violate data subject’s right of access under Article 15(1)(a) GDPR. The purposes and legal grounds were sufficiently explained, giving the data subject the ability to understand and potentially challenge the processing.

Regarding the credit agreement concluded in 2010, the Court agreed that relevant information had already been provided by the controller. Nothing in the proceedings suggested that the data subject was unable to assess the lawfulness of this data processing after receiving the information. The Court clarified that a controller is not obliged to cite a specific article or paragraph of law for each data processing activity, especially when dealing with complex, long-term relationships involving a large volume of data. Also with regard to the data processed by the controller after termination of the employment relationship, the data subject was provided with explicit mention of the legal bases of the data processing.

In a summary, it therefore follows that full information was provided to the data subject with regard to Article 15(1)(a) GDPR in total and thus the controller corresponded to all the requests for information.

Information regarding the existence of automated decision-making under Article 15(1)(h) GDPR

Regarding automated decision-making under Article 15(1)(h) GDPR and the alleged lack of information, the Court ruled that data subject’s request was inadmissible. The credit scoring took place in 2010, which was before the GDPR came into force in 2018 and further processing of data of the controller for the purposes of automated decision-making, including profiling, did not take place. So based on Article 99 GDPR, the GDPR's provisions on automated decision-making did not apply. Although the data subject could have relied on older Austrian data protection law to request information about the data on credit rating scoring and the logic behind automated decision, the requests explicitly based on the GDPR. The Court held that such a request cannot be reinterpreted under older law without a specific request from the data subject to do so. As a result, it should therefore be noted that the information provided by the controller to the data subject does not constitute incomplete.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the German original. Please refer to the German original for more details.

Decision Date

August 21, 2025

Standard

B-VG Art. 133 Para. 4
DSG 2000 §26
DSG 2000 §49
GDPR Art. 12
GDPR Art. 13
GDPR Art. 15
GDPR Art. 15 Para. 1 lita
GDPR Art. 15 Para. 1 lita
GDPR Art. 22
GDPR Art. 4
GDPR Art. 5
GDPR Art. 6
GDPR Art. 99

B-VG Art. 133 today B-VG Art. 133 valid from January 1, 2019, to May 24, 2018, last amended by Federal Law Gazette I No. 138/2017 B-VG Art. 133 valid from January 1, 2019, last amended by Federal Law Gazette I No. 22/2018 B-VG Art. 133 valid from 25.05.2018 to 31.12.2018 last amended by BGBl. I No. 22/2018 B-VG Art. 133 valid from 01.08.2014 to 24.05.2018 last amended by BGBl. I No. 164/2013 B-VG Art. 133 valid from 01.01.2014 to 31.07.2014 last amended by BGBl. I No. 51/2012 B-VG Art. 133 valid from 01.01.2004 to 31.12.2013 last amended by BGBl. I No. 100/2003 B-VG Art. 133 valid from 01.01.1975 to 31.12.2003 last amended by BGBl. No. 444/1974 Federal Constitutional Law Art. 133 valid from December 25, 1946, to December 31, 1974, last amended by Federal Law Gazette No. 211/1946 Federal Constitutional Law Art. 133 valid from December 19, 1945, to December 24, 1946, last amended by Federal Law Gazette No. 4/1945 Federal Constitutional Law Art. 133 valid from January 3, 1930, to June 30, 1934

Saying

W176 2250812-1/20E

IN THE NAME OF THE REPUBLIC!

The Federal Administrative Court, with Judge Mag. NEWALD as presiding judge and the expert lay judges Mag. BOGENDORFER and RAUB as assessors, has rightly ruled on the appeal by XXXX , represented by ENGELBRECHT Rechtsanwalts GmbH, against points 1 and 2 of the (“partial”) decision of the Data Protection Authority dated 19 October 2021, Ref. No. D124.2128, 2021-0.339.952 (co-participating party: XXXX ), due to violation of the right to information:The Federal Administrative Court, with Judge Mag. NEWALD as presiding judge and the expert lay judges Mag. BOGENDORFER and RAUB as assessors, has rightly ruled on the appeal by Römische 40 , represented by ENGELBRECHT Rechtsanwalts GmbH, against points 1 and 2 of the (“partial”) decision of the Data Protection Authority dated 19 October 2021, No. D124.2128, 2021-0.339.952 (co-participating party: Roman 40), for violation of the right to information, the following is correctly decided:

A) The appeal is upheld, and the ruling of the contested decision is amended to read:

"The data protection complaint is dismissed as unfounded."

B) The appeal is inadmissible pursuant to Article 133, Paragraph 4, of the Federal Constitutional Act.

Text

Reasons for the decision:

I. Proceedings: Roman one. Procedure:

1. By letter dated February 10, 2020, amended by letters dated May 18, 2020, and May 28, 2020, XXXX (= co-participating party before the Federal Administrative Court and complainant before the Data Protection Authority, hereinafter: MP) filed a data protection complaint with the Data Protection Authority (also: the respondent authority) against his former employer, XXXX (= complainant before the Federal Administrative Court and respondent before the respondent authority, hereinafter: BF), alleging a violation of his right to information and data portability. According to the complaint, MP submitted an oral request to the BF pursuant to Articles 15 and 20 of the GDPR on July 23, 2018. The BF did not provide the information until October 23, 2018, and the information was incomplete. Furthermore, the Federal Office for Consumer Protection failed to comply with the co-participating party's request of December 21, 2019, for the transfer of the MP's data. The further provision of information by the Federal Office for Consumer Protection on January 21, 2019, was again incomplete. Furthermore, the MP learned in the summer of 2019 that further information was being processed by the Federal Office for Consumer Protection, which is why the MP submitted a new request for information pursuant to Articles 15 and 20 of the GDPR in a letter dated December 21, 2019. The Federal Office for Consumer Protection only provided information about the purposes of the processing. The last information provided by the Federal Office for Consumer Protection on January 28, 2020, in no way complies with the content requirements of Article 15 (1) of the GDPR. 1. By letter dated February 10, 2020, amended by letters dated May 18, 2020, and May 28, 2020, roman 40 (= co-participating party before the Federal Administrative Court and complainant before the Data Protection Authority, hereinafter: MP) filed a data protection complaint with the Data Protection Authority (also: the respondent authority) against his former employer, roman 40 (= complainant before the Federal Administrative Court and respondent before the respondent authority, hereinafter: BF), alleging a violation of his right to information and data portability. According to the complaint, MP submitted an oral application to BF pursuant to Articles 15 and 20 of the GDPR on July 23, 2018. BF did not provide the information until October 23, 2018, and the information was incomplete. Furthermore, the Federal Office for Consumer Protection failed to comply with the co-participating party's request of December 21, 2019, for the transfer of MP's data. The further provision of information by the Federal Office for Consumer Protection on January 21, 2019, was again incomplete. Furthermore, the MP learned in the summer of 2019 that further information was being processed by the Federal Office for Consumer Protection, which is why the MP submitted a further request for information in accordance with Article 15, GDPR, and Article 20, GDPR, in a letter dated December 21, 2019. The Federal Office for Consumer Protection merely provided information about the purposes of the processing. The last information provided by the Federal Office for Consumer Protection dated January 28, 2020, in no way complied with the content requirements of Article 15, paragraph 1, GDPR.

2. In a written submission dated October 8, 2020, the Federal Office responded to MP's submission. In summary, the court stated – as far as relevant to the proceedings – that it was incorrect that the MP's request of July 23, 2018, had not been fully complied with. On October 23, 2018, the MP received the personal data stored by the Federal Employment Agency relating to the MP, both in paper form (several hundred pages) and in electronic form. The MP received the electronic data in a structured, common, and machine-readable format. The completeness of the information was ensured by the use of appropriate software that verified the personnel management data. The MP also received additional, supplementary explanations in a precise, transparent, and understandable form. Regarding further data mentioned by the MP, the Federal Employment Agency stated that this was no longer available and that disclosing this data would restrict the rights and freedoms of other individuals. The emails concerning the services of the co-participant were not to be disclosed because this data was relevant to the termination challenge and equal treatment proceedings between the MP and the BF. The data concerning the loan application was made available to the MP via the BF on November 23, 2018. However, this data was not retrieved by the MP, which is why the BF sent these documents to the MP on January 21, 2019. Information about the systematic analysis of credit risk is a trade secret. Regarding access control and monitoring of building entrances, the MP was informed of the processing and advised to provide information about the times at which it expected access. Reference was also made to the limited retention periods in this regard. The BF has no access to the MP's health data.

3. In a written submission dated February 1, 2021, the Federal Fiscal Court submitted a supplementary statement, essentially stating that it had structured the previously submitted data set in more detail, including coding it by color, to improve its readability and clarity. Furthermore, it had compiled an index, which also served to provide a better overview of the completeness of the data and its comprehensibility. Automated decision-making or profiling did not occur.

4. In a written submission dated May 10, 2021, the Federal Fiscal Court replied – as far as relevant to the proceedings – that it had submitted only one application each in 2018 and 2019, so that the application could not be described as "excessive." In its statement of February 1, 2021, the BF merely stated in general terms that the legal basis for the disclosed processing operations was the "above-mentioned legal and contractual obligations arising from the employment relationship." This section, referred to as "above," merely lists the justifications under the GDPR without addressing specific processing operations. The BF also failed to state what constitutes the legitimate interest in the processing. Furthermore, the BF failed to explain the information provided. The mere transmission of hundreds of pages of unstructured and undocumented information made it simply impossible for the MP to determine what would happen to the personal data concerning him, let alone assess whether the processing was lawful. In its supplementary statement, the BF stated that internal application documents were no longer stored centrally via the MP and that the application documents were still stored with the respective managers. Contradictorily, it also stated that the internal application documents were not available. Under data protection law, managers are considered to be part of the employer (data protection controller), which is why the BF should have collected the application documents and provided information. During the time the MP worked for the BF, the person involved both wrote emails from his email address and received emails to his email address. None of these emails are included in the information. The information also does not contain any emails from other people that are not addressed to the person involved but whose content concerns him. If any disclosure would result in an infringement of the rights and freedoms of others, this could be counteracted by anonymization. The MP also requested information regarding his credit. However, the information was only partially provided. The automated processing of personal data, which consists in using this data to analyze the financial situation, constitutes profiling.

5. By written submission dated October 13, 2021, the MP withdrew its data protection complaint with regard to Article 20 GDPR.

6.1. By the contested ("partial") decision dated October 19, 2021, the respondent authority partially upheld the MP's data protection complaint and found that the Federal Office of Data Protection had violated the MP's right to information by failing to provide complete information (point 1 of the decision). The Federal Office of Data Protection instructed the MP to provide complete information within four weeks, failing which the MP would be liable to execution (point 2 of the decision). The remaining data protection complaint was dismissed (point 3 of the decision). In the contested ("partial") decision of October 19, 2021, the respondent authority partially upheld the MP's data protection complaint and found that the Federal Data Protection Authority had violated the MP's right to information by failing to provide complete information (point 1 of the decision). The Federal Data Protection Authority ordered the MP to provide complete information to the MP within four weeks, failing which the decision would be enforced (point 2 of the decision). The remaining data protection complaint was dismissed (point 3 of the decision).

In the grounds for the decision, the respondent authority initially defined the subject matter of the complaint as the question of whether the Federal Data Protection Authority had violated the MP's right to information by providing the MP with incomplete information. The question of whether the MP's right to data portability had been violated was not relevant to the proceedings, as the complaint had been withdrawn to this extent. Furthermore, the question of whether the Federal Office of Public Safety violated the MP's right to information by failing to provide a complete copy of the personal data it processed via the MP is not the subject of this (“partial”) decision.

In summary, the respondent authority stated that, in the course of the proceedings, the Federal Office of Public Safety provided the MP with a bundle of various documents comprising several hundred pages, both in paper form and on a USB stick. It should be noted that the MP had worked for the Federal Office of Public Safety for several years, which explains the large volume of documents. Furthermore, the “provision of information” was a process spanning several years, during which the Federal Office of Public Safety endeavored to accommodate the MP's numerous requests. The Federal Office of Public Safety structured the submitted bundle of data content-wise and color-coded it. Furthermore, it compiled a reading list. The extent to which the MP's right to information was allegedly violated in this regard is unclear.

Furthermore, pursuant to Article 15 (1) (a) GDPR, the processing purposes within the meaning of Article 5 (1) (b) GDPR must be disclosed. However, the BF did not provide the MP with proper information in this sense, which is why it was required to provide information in this regard. However, inadequate information regarding Article 15 (1) (b) GDPR (categories of data processed) cannot be identified. Furthermore, pursuant to Article 15 (1) (a) GDPR, the processing purposes within the meaning of Article 5 (1) (b) GDPR must be disclosed. However, the BF did not provide the MP with proper information in this sense, which is why it was required to provide information in this regard. However, inadequate information regarding Article 15 (1) (b) GDPR (categories of data processed) cannot be identified.

With regard to the requested information on the loan agreement, the information cannot be refused with a blanket reference to business and trade secrets. Pursuant to Article 15 (1) (h) GDPR, the individual information can also be provided to the MP in this way, without affecting business and trade secrets through the (complete) disclosure of the algorithm or the analysis structure. With regard to the requested information on the loan agreement, the information cannot be refused with a blanket reference to business and trade secrets. Pursuant to Article 15 (1) (h) GDPR, the individual information can also be provided to the MP in this way, without affecting business and trade secrets through the (complete) disclosure of the algorithm or the analysis structure.

6.2. By decision No. D124.2128, 2021-0.721.807, dated the same day, the respondent authority suspended the proceedings regarding the question of whether there has been a violation of Article 15 (3) GDPR, pursuant to Section 38 of the General Administrative Court Act (AVG), pending the decision by the European Court of Justice regarding the preliminary ruling case C-487/21. 6.2. By decision No. D124.2128, 2021-0.721.807, dated the same day, the respondent authority suspended the proceedings regarding the question of whether there has been a violation of Article 15 (3) GDPR, pursuant to Section 38 of the General Administrative Court Act (AVG), pending the decision by the European Court of Justice regarding the preliminary ruling case C-487/21.

7. By timely submission of a written statement dated November 17, 2021, the BF withdrew the objection referred to in point 6.1. The applicant lodged an appeal against the (partial) decision presented here and essentially stated the following:

The disclosure of the legal basis for processing within the meaning of Article 6 (1) or Article 9 (2) GDPR was not mentioned as part of the information pursuant to Article 15 GDPR, which is why there is no obligation to do so. Furthermore, the applicant had already been informed of the legal basis for data processing in a cover letter included in the documents submitted with the letter dated October 23, 2018. The disclosure of the legal basis for processing within the meaning of Article 6 (1) or Article 9 (2) GDPR was not mentioned as part of the information pursuant to Article 15 GDPR, which is why there is no obligation to do so. Furthermore, the applicant had already been informed of the legal basis for data processing in a cover letter included in the documents submitted with the letter dated October 23, 2018.

The view that a specific article or paragraph on which the legality of the data processing is based must be cited for each data application mentioned would exceed the controller's duty to provide information, especially since the average data subject would not gain any added information from simply citing a paragraph. In a letter dated November 23, 2018, the MP was also provided with a complete copy of the data collected and processed in connection with the loan granting in 2010.

The MP's credit rating was also provided to it, and only information on the systematic analysis of credit risk was not disclosed. This complied with Article 15 (1) (h) GDPR, even though this provision is not applicable in the present case at all: The loan agreement between the MP and the BF was concluded in April 2010, and the MP's creditworthiness was also assessed in the course of concluding the loan agreement, which, however, did not involve an automated credit check. Even if the assessment of the MP were to be subsumed under the term "profiling" within the meaning of Article 4(4) GDPR by today's standards – contrary to the BF's legal opinion – it should be noted that this assessment was carried out and completed in 2010, and since then, no automated decision-making regarding the credit assessment of the MP has taken place. The credit assessment from 2010 is no longer relevant today and can no longer affect the MP. Furthermore, Article 15 (1) (h) GDPR was fully complied with. Only the algorithm used to assess borrowers was not disclosed. The credit assessment of the MP was also communicated to the BF, and only information about the systematic analysis of the credit risk was not disclosed. This complied with Article 15, paragraph 1, letter h, GDPR, even though this provision was not applicable in the present case at all: The loan agreement between MP and BF was concluded in April 2010, and MP's creditworthiness was assessed in the course of concluding the loan agreement, although this did not involve an automated credit check. Even if, according to today's standards – contrary to BF's legal opinion – the assessment of MP were to be subsumed under the term "profiling" within the meaning of Article 4, paragraph 4, GDPR, it should be noted that this assessment was carried out and completed in 2010, and no automated decision-making regarding MP's creditworthiness has taken place since then. The creditworthiness assessment from 2010 is no longer relevant today and can no longer affect MP. Furthermore, Article 15, paragraph 1, letter h, GDPR was fully complied with. Only the algorithm used to evaluate borrowers was not disclosed.

8. By letter dated January 13, 2022, the respondent authority submitted the relevant administrative act to the Federal Administrative Court for a decision.

9. By letter dated May 15, 2023, the MP submitted a (143-page) statement on the appeal against the decision, explaining why it had filed the data protection complaint. The relevant statements are essentially irrelevant to the present proceedings.

10. By written submission dated March 26, 2024, the respondent authority responded to the appeal against the decision, stating that it continues to assume that complete information pursuant to Art. 15 (1) (a) GDPR had not been provided to the MP. This also follows from the fact that the information dated October 23, 2018, did not contain any information on the question of which data had been processed for which purposes, with reference to the Federal Administrative Court's decision of September 2, 2022, Ref. No. W214 2230686-1.10. In a written submission dated March 26, 2024, the respondent authority responded to the complaint by stating that it continued to assume that no complete information had been provided to the MP in accordance with Article 15, paragraph 1, letter a, GDPR. This also follows from the fact that the information dated 23 October 2018 did not contain any information on the question of which data had been processed for which purposes, whereby reference was made to the decision of the Federal Administrative Court dated 02 September 2022, Ref. No. W214 2230686-1.

11. By letter dated March 27, 2024, the MP submitted a further statement, essentially repeating parts of its statement of May 15, 2023.

12. By written submission dated May 15, 2024, the BF responded to the statement of the respondent authority set out under point 10, essentially explaining why, contrary to the authority's opinion, the legal basis for the processing and the purposes of the processing had been stated. Furthermore, it is argued that Article 15 (1) (h) GDPR is not applicable to the credit assessment in question, which was carried out in 2010, because the data processing in question was carried out before the GDPR came into force.12. In a written submission dated May 15, 2024, the Federal Administrative Court responded to the statement of the respondent authority set out under point 10, essentially explaining why, contrary to the authority's opinion, the legal basis for the processing and the processing purposes had been stated. Furthermore, it is argued that Article 15, paragraph 1, letter h, GDPR is not applicable to the credit assessment in question, which was carried out in 2010, because the data processing in question was carried out before the GDPR came into force.

13. In a letter dated July 22, 2024, the MP's legal representative announced that the power of attorney relationship with the MP had been terminated.

II. The Federal Administrative Court considered: Roman II. The Federal Administrative Court considered:

1. Findings:

The procedural course described under I. forms the basis for the findings; in particular, it is further established: The procedure described under Roman one. The procedural process described forms the basis for the findings; in particular, the following is also established:

1.1. The MP was employed by the employer-employee association (BF) until the employer-employee association terminated her employment relationship on July 23, 2018. The MP then initiated proceedings against the employer-employee association (BF) with the Equal Treatment Commission and filed a lawsuit against the termination before the Vienna Labor and Social Court (file no. 36 Cga 78/18f).

1.2. On the day of termination, the MP submitted an oral request based on Art. 15 GDPR for information about the personal data relating to the MP that the employer-employee association processed, as well as a request for data portability (including a copy of the processed data) pursuant to Art. 20 GDPR. On October 23, 2018, the MP received the first information from the employer-employee association. 1.2. On the day of termination, the MP submitted an oral request based on Article 15 of the GDPR for information about the personal data processed by the BF relating to the MP, as well as a request for data portability (including a copy of the processed data) pursuant to Article 20 of the GDPR. On October 23, 2018, the MP received the first information from the BF.

1.3. The MP then requested information again on October 25, 2018, whereupon it received another response from the BF in a letter dated January 21, 2019, which, among other things, referred to the personal handover of the data relating to the loan agreement (see 1.6.).

1.4. On December 21, 2019, the MP submitted another request for information, which the BF granted in a letter dated January 28, 2020.

1.5. In the further proceedings, the BF submitted a bundle of various documents containing several hundred pages of MP's personal data, which it had processed during the course of the employment relationship, both in paper form and on a USB stick.

1.6. BF and MP entered into a loan agreement in 2010. Prior to conclusion, the BF conducted a credit check on April 27 and 28, 2010, which resulted in MP's credit rating of "3." The relevant data processing was completed on April 28, 2010; no further processing of MP's data for the purposes of automated decision-making, including profiling, took place.

2. Evaluation of Evidence:

The findings regarding the relevant facts are derived from the administrative act, the complaint, and the court file.

The fact that the BF and the MP concluded a loan agreement in 2010, and that the BF conducted a credit check prior to the conclusion on April 27 and 28, 2010, which resulted in a credit rating of "3" for the MP, and that the related data processing was completed on April 28, 2010, and that no further processing of the MP's data for the purposes of automated decision-making, including profiling, took place, is evident from several documents in the bundle referred to in 1.5. and is consistent with the BF's allegations in this regard. Neither the MP nor the authority concerned has argued otherwise.

3. Legal Assessment:

Since the subject matter of the complaint is a decision by the Data Protection Authority, the Senate has jurisdiction pursuant to Section 27 of the Data Protection Act.

Regarding Decision Point A):

3.1. The relevant provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation; GDPR), OJ L 119 of 4 May 2016, p. 1, read in extracts: 3.1. The relevant provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation; GDPR), OJ L 119 of 4 May 2016, Session 1, read in part:

"Article 4

Definitions

For the purposes of this Regulation, the following definitions shall apply:

1. "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); A natural person is considered identifiable if he or she can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physiological, genetic, mental, economic, cultural or social identity of that natural person;

2. “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

[…]

7. “Controller” means the natural or legal person, public authority, agency or other body which alone or jointly with others decides on the purposes and means of the processing of personal data; Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

[…]

11. “Consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
[…]

Article 5

Principles governing the processing of personal data

(1) Personal data must:

a) be processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”);

b) be collected for specified, explicit and legitimate purposes and must not be further processed in a manner incompatible with those purposes; Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered incompatible with the original purposes pursuant to Article 89(1) (“purpose limitation”);

c) be adequate, relevant and limited to what is necessary for the purposes of the processing (“data minimization”);

d) be accurate and, where necessary, kept up to date; every reasonable step shall be taken to ensure that personal data which are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (“accuracy”);

e) be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed; personal data may be stored for a longer period provided that the personal data are processed solely for archiving purposes in the public interest or for scientific and historical research purposes or statistical purposes in accordance with Article 89(1), subject to the implementation of appropriate technical and organizational measures required by this Regulation to protect the rights and freedoms of the data subject (“storage limitation”);

f) are processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organizational measures (“integrity and confidentiality”);

(2) The controller shall be responsible for compliance with paragraph 1 and must be able to demonstrate compliance with it (“accountability”).

Article 6

Lawfulness of Processing

(1) Processing shall be lawful only if at least one of the following conditions is met:

a) the data subject has given consent to the processing of personal data relating to him or her for one or more specific purposes;

b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

c) processing is necessary for compliance with a legal obligation to which the controller is subject;

d) processing is necessary to protect the vital interests of the data subject or of another natural person;

e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

f) processing is necessary to protect the legitimate interests of the controller or of a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

Point (f) of the first subparagraph shall not apply to processing carried out by public authorities in the performance of their tasks.

(2) Member States may maintain or introduce more specific provisions to adapt the application of the rules of this Regulation with regard to processing for the purpose of complying with points (c) and (e) of paragraph 1 by specifying more precisely specific processing requirements and other measures to ensure lawful and fair processing, including for other specific processing situations as referred to in Chapter IX INSURANCE. (2) Member States may maintain or introduce more specific provisions to adapt the application of the rules of this Regulation with regard to processing for the purpose of complying with points (c) and (e) of paragraph 1 by specifying more precisely specific processing requirements and other measures to ensure lawful and fair processing, including for other specific processing situations as referred to in Chapter IX INSURANCE.

(3) The legal basis for the processing operations referred to in points (c) and (e) of paragraph 1 shall be:

(a) Union law; or

(b) Member State law to which the controller is subject.

The purpose of the processing must be specified in that legal basis or, as regards the processing referred to in point (e) of paragraph 1, it must be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. That legal basis may contain specific provisions adapting the application of the rules of this Regulation, inter alia, provisions on the general conditions governing the lawfulness of processing by the controller, the types of data processed, the data subjects concerned, the entities to which and for which purposes the personal data may be disclosed, the purpose limitation, the storage period and the processing operations and procedures that may be used, including measures to ensure lawful and fair processing, such as those for other specific processing situations referred to in Chapter IX INSURANCE. Union or Member State law must pursue an objective in the public interest and be proportionate to the legitimate purpose pursued. The purpose of the processing must be specified in that legal basis or, as regards the processing referred to in point (e) of paragraph 1, must be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. That legal basis may contain specific provisions adapting the application of the rules of this Regulation, inter alia, provisions on the general conditions governing the lawfulness of processing by the controller, the types of data processed, the data subjects concerned, the entities to which and for which purposes the personal data may be disclosed, the purpose limitation, the storage period and the processing operations and procedures that may be used, including measures to ensure lawful and fair processing, such as those for other specific processing situations referred to in Chapter IX of the Insurance Regulation. Union or Member State law must pursue an objective in the public interest and be proportionate to the legitimate purpose pursued.

[…]

Article 12

Transparent information, communication, and modalities for exercising the data subject's rights

(1) The controller shall take appropriate measures to provide the data subject with all information referred to in Articles 13 and 14 and all communications referred to in Articles 15 to 22 and Article 34 relating to processing in a concise, transparent, intelligible, and easily accessible form, using clear and plain language; this shall apply in particular to information specifically addressed to children. The information shall be provided in writing or by other means, including, where appropriate, electronically. If requested by the data subject, the information may be provided orally, provided that the data subject's identity has been verified by other means.

(2) The controller shall facilitate the exercise of the data subject's rights under Articles 15 to 22. In the cases referred to in Article 11(2), the controller may refuse to act on the data subject's request to exercise their rights under Articles 15 to 22 only if the controller demonstrates that the controller is unable to identify the data subject.

(3) The controller shall provide the data subject with information on the action taken on the request pursuant to Articles 15 to 22 without undue delay and in any event within one month of receipt of the request. This period may be extended by a further two months if necessary, taking into account the complexity and number of requests. The controller shall inform the data subject of any extension within one month of receipt of the request, together with the reasons for the delay. Where the data subject submits the request electronically, the information shall be provided electronically, if possible, unless the data subject indicates otherwise.

(4) If the controller does not act on the data subject's request, it shall inform the data subject without delay, and at the latest within one month of receipt of the request, of the reasons for its failure to act and of the possibility of lodging a complaint with a supervisory authority or seeking judicial redress.

(5) Information pursuant to Articles 13 and 14, as well as all notifications and measures pursuant to Articles 15 to 22 and Article 34, shall be provided free of charge. In the case of manifestly unfounded or excessive requests from a data subject, in particular in the case of repetitive requests, the controller may either:

a) charge a reasonable fee, taking into account the administrative costs of providing the information or notification or of implementing the requested measure; or

b) refuse to act on the request. The controller shall provide evidence of the manifestly unfounded or excessive nature of the request.

(6) - (8) [...]

Article 13

Information obligation when personal data are collected from the data subject

(1) Where personal data are collected from the data subject, the controller shall, at the time of collection, inform the data subject of the following:

[…]

c) the purposes for which the personal data are to be processed and the legal basis for the processing;

[…]
(2) In addition to the information referred to in paragraph 1, the controller shall, at the time of collection, provide the data subject with the following further information necessary to ensure fair and transparent processing:

[…]

f) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject.

[…]

(3) […]

(4) Paragraphs 1, 2, and 3 shall not apply if and to the extent that the data subject already has the information.

Article 15

Right of access of the data subject

(1) The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed; where that is the case, access to those personal data and the following information:

a) the purposes of the processing;

b) the categories of personal data concerned;

c) the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations;

d) where possible, the envisaged period for which the personal data will be stored, or, where not possible, the criteria used to determine that period;

(e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning him or her or to object to such processing;

(f) the existence of the right to lodge a complaint with a supervisory authority;

(g) where the personal data are not collected from the data subject, any available information as to their source;

(h) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject.

(...)

(3) The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. If the data subject makes the request electronically, the information shall be provided in a commonly used electronic format, unless the data subject indicates otherwise.

Article 22

Automated individual decision-making, including profiling

(1) The data subject shall have the right not to be subjected to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

(2) Paragraph 1 shall not apply if the decision

a) is necessary for entering into, or the performance of, a contract between the data subject and the controller,

b) is authorized by Union or Member State law to which the controller is subject, and that law lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, or

c) is based on the data subject's explicit consent.

(3) In the cases referred to in points (a) and (c) of paragraph 2, the controller shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.

(4) Decisions pursuant to paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1), unless points (a) or (g) of Article 9(2) apply and suitable measures to protect the data subject's rights and freedoms and legitimate interests have been taken.

Article 99

Entry into force and application

(1) This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.

(2) It shall apply from 25 May 2018.

Recital 63 of the GDPR states:

"A data subject should have the right of access to the personal data concerning him or her that have been collected and be able to exercise this right easily and at reasonable intervals, in order to be aware of the processing and to verify its lawfulness. This includes the right of data subjects to access their own health-related data, such as data in their medical records containing information such as diagnoses, test results, findings of treating physicians, and details of treatments or interventions. Every data subject should therefore have the right to know and be informed, in particular, of the purposes for which the personal data are processed and, where possible, the length of time they will be stored, the recipients of the personal data, the logic used for automated processing of personal data, and the possible consequences of such processing, at least where the processing is based on profiling. Where possible, the controller should be able to provide remote access to a secure system that would allow the data subject direct access to their personal data. This right should respect the rights and freedoms of others, such as This should not affect trade secrets or intellectual property rights, and in particular software copyright. However, this must not result in the data subject being denied any information. If the controller processes a large amount of information about the data subject, it should be able to require the data subject to specify which information or processing operations their request for information relates to before providing the information.

3.2. Applied to the present case, this means the following:

It is undisputed that the Federal Office for Migration and Refugees provided the MP with written information on October 23, 2018, and January 28, 2020; in addition, further information was provided by personally handing over the data relating to the loan agreement and transmitting the package referred to in finding 1.5. However, in the contested decision, the competent authority considers the information provided by the MP to be incomplete, on the one hand, with regard to the naming of the processing purposes (Art. 15 (1) (a) GDPR) and, on the other hand, with regard to the provision of meaningful information on the logic involved, as well as the scope and intended effects of automated decision-making, including profiling, for the data subject pursuant to Art. 15 (1) (h) GDPR. It is undisputed that the BF provided the MP with written information on October 23, 2018, and January 28, 2020; in addition, further information was provided by personally handing over the data relating to the loan agreement and transmitting the package referred to in finding 1.5. However, in the contested decision, the competent authority considers the information provided by the MP to be incomplete, both with regard to the naming of the processing purposes (Article 15, paragraph 1, letter a, GDPR) and with regard to the provision of meaningful information about the logic involved, as well as the scope and intended effects of automated decision-making, including profiling, for the data subject pursuant to Article 15, paragraph 1, letter h, GDPR.

3.2.1. Regarding the information about the processing purposes of the personal data pursuant to Article 15, paragraph 1, letter a, GDPR:

It must first be examined whether the Federal Office for Data Protection violated the MP's right to information by providing it with incomplete information regarding the purposes for which it processed (or has processed) data relating to the MP.

3.2.1.1. The ECJ has held that Article 15 (1) GDPR is intended to ensure transparency regarding the manner in which personal data is processed for the data subject. The information specified in Article 15 (1) GDPR aims to ensure that the data subject is aware of the processing and can verify its lawfulness. The right of access provided for in Art. 15 GDPR must enable the data subject to verify whether the data concerning him or her are correct and whether they are being processed lawfully, and thus, where appropriate, to exercise his or her rights to rectification, erasure and restriction of processing under Art. 16 to 18 GDPR, as well as his or her right to object to the processing of his or her personal data under Art. 21 GDPR or, in the event of damage, his or her right to lodge a legal remedy under Art. 79 and 82 GDPR (cf. VwGH 06.03.2024, Ro 2021/04/0030; 03.08.2023, Ro 2020/04/0015, each with reference to ECJ 22.06.2023, C-579/21 and 04.05.2023, C-487/21).3.2.1.1. The ECJ has stated that Article 15, paragraph 1, GDPR is intended to ensure transparency towards the data subject regarding the way in which personal data is processed. The information referred to in Article 15, paragraph 1, GDPR aims to ensure that the data subject is aware of the processing and can verify its lawfulness. The right of access provided for in Article 15, GDPR must enable the data subject to verify whether the data concerning them is accurate and processed lawfully and thus, where appropriate, to exercise their rights to rectification, erasure and restriction of processing under Articles 16 to 18 GDPR, as well as their right to object to the processing of their personal data under Article 21 GDPR or, in the event of damage, their right to appeal under Articles 79 and 82 GDPR (cf. VwGH 6 March 2024, Ro 2021/04/0030); 03.08.2023, Ro 2020/04/0015, each with reference to ECJ 22.06.2023, C-579/21 and 04.05.2023, C-487/21).

The legal basis for processing (Article 6 (1), in the case of sensitive data in conjunction with Article 9 (2)) is not explicitly included in the content of the information provision according to Article 15 (1). However, Recital 63 states that the right to information is intended to enable the legality of the processing to be verified. Therefore, the legal basis for the processing must also be disclosed, unless it is already clear from the purpose of the processing.
(Jahnel, Commentary on the General Data Protection Regulation, Article 15 GDPR, para. 22 | as of December 1, 2020, rdb.at). According to Article 15, paragraph 1, the legal basis for the processing (Article 6, paragraph 1, in the case of sensitive data in conjunction with Article 9, paragraph 2) is not explicitly included in the content of the information. However, Recital 63 states that the right to information is intended to enable the legality of the processing to be verified. Therefore, the legal basis for the processing must also be disclosed, unless it is already clear from the purpose of the processing.
(Jahnel, Commentary on the General Data Protection Regulation, Article 15, GDPR, para. 22 | as of December 1, 2020, rdb.at).

The purposes of the processing must be disclosed within the meaning of Article 5 (1) (b) (see Article 5, para. 20 et seq.). Although the information does not have to be as detailed as a processing register within the meaning of Article 30, it may be necessary to assign the purposes to the specific data, or possibly data categories, in order to fulfill the request for information if otherwise a legality check by the data subject would not be possible.
(Haidinger in Knyrim, DatKomm Article 15 GDPR para. 37 | as of July 1, 2024, rdb.at). The purposes of the processing must be disclosed within the meaning of Article 5 (1) (b) (see Article 5, para. 20 et seq.). Although the information does not have to be as detailed as a processing register within the meaning of Article 30, it may be necessary to assign the purposes to the specific data, or possibly data categories, in order to fulfill the request for information if otherwise a legality check by the data subject would not be possible
(Haidinger in Knyrim, DatKomm Article 15, GDPR para. 37 | as of July 1, 2024, rdb.at).

3.2.1.2. As can be seen from the literature cited above, with reference to Recital 63 of the GDPR and the case law of the ECJ, the entire right to information – including information about the purposes of processing – serves to enable the data subject to verify the lawfulness of the processing. Therefore, a legal basis for processing does not necessarily have to be disclosed, but may be covered by the right to information if it is necessary to verify the lawfulness of the data processing.

The authority concerned also argues in a similar way in its decision and its reply of 26 March 2024 regarding the appeal against the decision, where it refers, for example, to Heberlein in Ehmann/Selmayr GDPR Art. 5, para. 14, according to which vague or overly broad descriptions of the purposes also contradict the transparency requirement of Art. 5 (1) (a) GDPR, and it mentions the decision of the Federal Administrative Court of 10 December 2018, W211 2188383-1/9E, according to which, for example, the purpose specification “marketing purposes” does not meet the requirements of Art. 15 (1) (a) GDPR.The authority concerned also argues in a similar way in its decision and its reply of 26 March 2024 regarding the appeal against the decision, where it refers, for example, to Heberlein in Ehmann/Selmayr GDPR Art. 5, para. 14, according to which vague or An overly broad definition of the purposes also contradicts the transparency requirement of Article 5, paragraph 1, letter a, GDPR, and it mentions the decision of the Federal Administrative Court of December 10, 2018, W211 2188383-1/9E, according to which, for example, the specification of the purpose "marketing purposes" does not meet the requirements of Article 15, paragraph 1, letter a, GDPR.

In Ehmann/Selmayr GDPR Article 13, para. 47, Knyrim also considers a blanket reference to Article 6 (para. 1) GDPR to be insufficient.

As can be seen from the files, in its initial disclosure of information dated October 23, 2018, the BF already named several legal bases pursuant to Art. 6 (1) GDPR (namely letters a to c and f) when providing information about the purposes of the processing, as well as the domestic legal obligations to which it refers with regard to Art. 6 (1) letter c leg.cit., namely various labor law provisions such as the Salaried Employees Act, the Labor Constitution Act or the General Social Security Act - albeit without citing specific paragraphs in each case; and states that it has collected employee data and time records relevant to accounting. In addition, the BF stated that it had collected the data to protect the legitimate interests of the BF in accordance with Art. 6 (1) (letter f) GDPR and that it had processed the data within the scope of the MP's consent in accordance with Art. 6 (1) (letter a). GDPR. As can be seen from the files, in its initial disclosure of information dated October 23, 2018, the Federal Office for Migration and Refugees (BF) already cited several legal bases pursuant to Article 6, paragraph 1, GDPR (namely, letters a to c and f) as part of the disclosure of the processing purposes, as well as the domestic legal obligations to which it refers with regard to Article 6, paragraph 1, letter c, leg.cit., namely various labor law provisions such as the Employees Act, the Labor Constitution Act, or the General Social Security Act – albeit without citing specific paragraphs in each case; and stated that it had collected employee data and time records relevant to accounting. Furthermore, the Federal Office stated that it had collected the data to protect the legitimate interests of the Federal Office for Migration and Refugees (BF) pursuant to Article 6, paragraph 1, letter f, GDPR and that it was processing the data within the scope of the MP's consent pursuant to Article 6, paragraph 1, letter a, GDPR.

Furthermore, the purposes and legal bases for the personal data of the MP contained in the bundle were stated in the letter dated February 1, 2021 (primarily from the legal areas of labor, social, and tax law). The BF cited, for example, the collection of employee data for the maintenance of a payroll account relevant for salary accounting and the correct accounting of the MP's remuneration entitlements. Furthermore, it was stated that data processing is necessary to calculate vacation, sick leave, or other absences, and that there is an obligation to maintain working time records in accordance with Section 26 of the Working Hours Act and Section 25 of the Working Rest Act. Furthermore, the purposes and legal bases for the personal data of the MP contained in the bundle were stated in the letter dated February 1, 2021 (primarily from the legal areas of labor, social, and tax law). In this context, the Federal Employment Agency (BF) argued, for example, that employee data was collected for the purpose of maintaining a payroll account relevant for salary calculation and for the correct accounting of MP's remuneration entitlements. Furthermore, it was argued that data processing was necessary for calculating vacation, sick leave, or other absences, and that there was an obligation to maintain working time records pursuant to Section 26 of the Working Hours Act and Section 25 of the Working Rest Act.

In the opinion of the Senate, by simply stating these purposes and legal bases for data processing, the Federal Employment Agency (BF) enabled MP to verify the legality of the processing and, if necessary, to assert its data subject rights against the Federal Employment Agency as the controller. As established, MP is a former employee of the Federal Employment Agency (BF) who first submitted a request for information on the day her employment relationship was terminated by the Federal Employment Agency. It is clear from the initial information provided by the BF that – with regard to the personal data relating to the MP that had been processed up to that point – it had collected these data within the framework of her employment relationship and, as her employer, processed them in accordance with the employment, social and tax law provisions specified by her. The European Data Board, established pursuant to Art. 68 GDPR, also states in its "Guideline 07/2020" on the concept of controllers and processors under the General Data Protection Regulation that certain processing activities can be considered inherently linked to the role of an organization, such as that of an employer vis-à-vis employees (see Guidelines 07/2020 on the concepts of controller and processor in the GDPR, Version 2.0, adopted on 7 July 2021, p. 3, p. 12, marginal no. 27, p. 50). In the opinion of the Senate hearing the case, by simply stating these purposes and legal bases for data processing, the BF enabled the MP to verify the legality of the processing and, if necessary, to assert her data subject rights against the BF as the controller. As established, the MP is a former employee of the BF who first submitted a request for information on the day her employment relationship was terminated by the BF. From the initial information provided by the Federal Data Protection Authority (BF), it is clear that – with regard to the personal data previously processed relating to the MP – it collected this data within the scope of her employment relationship and, as her employer, processed it in accordance with the labor, social, and tax law provisions specified by her. The European Data Board, established pursuant to Article 68 of the GDPR, also states in its "Guideline 07/2020" on the concept of controllers and processors under the General Data Protection Regulation that certain processing activities can be considered inherently linked to the role of an organization, such as that of an employer vis-à-vis employees (see Guidelines 07/2020 on the concepts of controller and processor in the GDPR, Version 2.0, adopted on 7 July 2021, Session 3, Session 12, para. 27, Session 50).

To the extent that the authority concerned, with reference to the Federal Administrative Court's decision of September 2, 2022, Ref. No. W214 2230686-1, argues that the information provided by the Federal Administrative Court does not indicate which data was processed for which purposes, it should be noted that the cited decision is based on facts that are not comparable to the present case, since the latter involved a controller who apparently did not collect various types of data (at least in part) from the data subject himself and subsequently collected them for entirely different purposes (such as contract fulfillment or marketing), while the Federal Administrative Court, as the employer, collected the MP's data from the MP himself and processed it in accordance with the relevant provisions mentioned above. Moreover, the question of the legality of the data processing operations carried out is not the subject of the proceedings to be decided here.

Furthermore, the respondent authority correctly noted in its decision that the "provision of information" was a process lasting several years, in which the BF endeavored to accommodate the numerous requests from the MP.

Regarding the data relating to the loan agreement concluded between the BF and the MP in 2010, information was also sent by email on November 23, 2018, as well as by post as an attachment to the letter dated January 21, 2019. In her statement of May 10, 2021, MP, who was represented by a lawyer at the time, considers this information to be incomplete only with regard to the credit check carried out (see section 3.2.2 below), but not with regard to the information on the processing purposes pursuant to Art. 15 (1) (a) GDPR. Furthermore, it has not otherwise emerged in the proceedings that MP, after having provided the information, would not have been able to verify the legality of the processing of her data about her as a borrower by BF as the financial institution granting the loan. Regarding the data on the loan agreement concluded between BF and MP in 2010, information was also sent by email on November 23, 2018, as well as by post as an attachment to the letter dated January 21, 2019. In her statement of May 10, 2021, MP, who was represented by a lawyer at the time, considers this to be incomplete only with regard to the credit check carried out (see section 3.2.2 below), but not with regard to the information on the purposes of processing pursuant to Article 15, paragraph one, letter a, GDPR. It has also not otherwise emerged in the proceedings that MP, after the information had been provided, would not have been able to verify the legality of the processing of her data about her as a borrower by BF, as the financial institution granting her the loan.

Therefore, the Federal Administrative Court cannot be countered when it argues that a controller is not required to cite a specific article or paragraph on which the lawfulness of the data processing is based for each data application mentioned, as this would exceed the controller's duty to provide information (appeal to the decision, pp. 10-11), especially when, as in this case, a large amount of data from a multi-year employment relationship was involved.

Therefore, the Federal Administrative Court cannot be countered when it argues that a controller is not required to cite a specific article or paragraph on which the lawfulness of the data processing is based for each data application mentioned, as this would exceed the controller's duty to provide information (appeal to the decision, pp. 10-11), especially when, as in this case, a large amount of data from a multi-year employment relationship was involved.

With regard to the MP's data processed by the BF after the termination of the employment relationship, the BF also responded to the MP's request for information dated December 21, 2019, on January 28, 2020, explicitly stating the legal basis for the data processing.

In summary, it can therefore be seen that the Federal Office of Data Protection provided the MP with complete information in accordance with Article 15 (1) (a) GDPR until the conclusion of the proceedings before the competent authority, thereby complying with the MP's requests for information of July 23, 2018, October 25, 2018, and December 21, 2019. In summary, it can therefore be seen that the Federal Office of Data Protection provided the MP with complete information in accordance with Article 15 (1) (a) GDPR until the conclusion of the proceedings before the competent authority, thereby complying with the MP's requests for information of July 23, 2018, October 25, 2018, and December 21, 2019.

3.2.2. Regarding automated decision-making pursuant to Article 15 (1) (h) GDPR: 3.2.2. Regarding automated decision-making pursuant to Article 15, paragraph 1, letter h, GDPR:

As stated, BF and MP entered into a loan agreement in 2010, and prior to its conclusion, BF conducted a credit check on April 27 and 28, 2010, which resulted in MP's credit rating of "3."

The authority concerned considered the information provided by the BF to the MP (in total) to be incomplete because, contrary to Article 15 (1) (h) GDPR, no meaningful information about the logic involved, as well as the scope and the intended effects of the automated decision-making, including profiling, had been provided to the MP as the data subject in accordance with Article 22 (1) and (4) GDPR, and the provision of this information was also ordered in the service contract in point 2 of the decision.The authority concerned considered the information provided by the BF to the MP (in total) to be incomplete because, contrary to Article 15 (1) (h) GDPR, no meaningful information about the logic involved, as well as the scope and the intended effects of the automated decision-making, including profiling, had been provided to the MP as the data subject in accordance with Article 22 (1) and (4) GDPR, and the provision of this information was also ordered in the service contract in point 2. of the decision.

3.2.2.1. It must therefore first be examined whether the BF violated the MP's right to information by not providing the aforementioned information in accordance with Article 15 (1) (h) GDPR.3.2.2.1. It must therefore first be examined whether the BF violated the MP's right to information by not providing the aforementioned information in accordance with Article 15 (1) (h) GDPR.

3.2.2.1.1. Pursuant to Article 15 (1) (h) GDPR, the data subject has the right to obtain confirmation from the controller as to whether personal data concerning him or her are being processed; If this is the case, they have the right to access these personal data and to the following information: the existence of automated decision-making, including profiling, pursuant to Article 22(1) and (4) of the GDPR and, at least in these cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject. The controller must therefore inform the data subject of an automated decision-making process and of profiling measures in accordance with Article 15(1)(h) GDPR. In the case of automated decision-making and in more serious cases of profiling, this obligation to provide information also includes information about the logic involved, the methods and criteria, as well as the significance and consequences of the data processing (Bäcker in Kühling/Buchner General Data Protection Regulation3, Article 15 GDPR, paragraph 27). 3.2.2.1.1. Pursuant to Article 15, paragraph 1, letter h, GDPR, the data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning them are being processed; where this is the case, they have the right to access those personal data and to the following information: the existence of automated decision-making, including profiling, pursuant to Article 22, paragraphs 1 and 4, GDPR, and—at least in these cases—meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject. The controller must therefore inform the data subject of an automated decision-making process and of profiling measures in accordance with Article 15, paragraph 1, letter h, GDPR. In the case of automated decision-making and in more serious cases of profiling, this obligation to provide information also includes information about the logic involved, the methods and criteria, as well as the significance and consequences of the data processing (Bäcker in Kühling/Buchner General Data Protection Regulation 3, Article 15, GDPR, paragraph 27).

According to Art. 4(4) GDPR, "profiling" is any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements. This therefore consists of any form of automated processing of personal data evaluating personal aspects relating to a natural person, in particular to analyze or predict aspects relating to (for example) their economic situation. Classic examples are credit scoring procedures. The provision only applies to decisions that produce "legal effects" concerning the data subject or similarly "significantly affect" them. Such a decision must have the potential to significantly influence a person's circumstances, behavior, or choices (Hladjik in Ehmann/Selmayr, General Data Protection Regulation 2, Art. 22 GDPR, paras. 7 and 9). A typical profiling tool is scoring procedures used by the private sector, for example, in credit granting. The determined score is assigned to the person who has a certain profile in a decision-making process with corresponding consequences, e.g. in the decision whether to grant a loan. Decisions based on such a score are therefore generally subject to this regulation. With regard to credit scoring, this regulation is not only applicable if the score determines a credit decision, but also if the score plays a significant role in the decision and thus becomes its essential basis. However, there is no violation of the regulation if, in the event of impending rejection due to a poor score, the clerk calls in one or more people at an early stage who, due to their appropriate decision-making powers and scope, are authorized and professionally able to review and evaluate the content of the automated specification. The authority to correct the automated decision should be documented. However, it is also crucial here that, in the required individual assessment of the overall circumstances with regard to willingness and ability to pay, other factors besides the score are taken into account in the new decision (Scholz in Simitis/Hornung/Spiecker Data Protection Law GDPR with BDSG, Art. 22 GDPR paras. 24, 29, 30). According to Article 4, paragraph 4, GDPR, "profiling" is any form of automated processing of personal data consisting of the use of these personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, whereabouts, or movements. This therefore consists of any form of automated processing of personal data evaluating personal aspects relating to a natural person, in particular to analyze or predict aspects relating to (for example) their economic situation. Classic examples are credit scoring procedures. The regulation only applies to decisions that have "legal effects" on the data subject or similarly "significantly affect" them. Such a decision must have the potential to significantly influence a person's circumstances, behavior, or choices (Hladjik in Ehmann/Selmayr, General Data Protection Regulation 2, Article 22, GDPR paras. 7 and 9). A typical instrument of profiling is scoring procedures used by the private sector, for example, in credit granting. The person who meets a certain profile is assigned the determined score in a decision-making process with corresponding consequences, e.g., in the decision whether to grant a loan. Decisions based on such a score are therefore generally subject to this regulation. With regard to credit scoring, this regulation is applicable not only when the score determines a credit decision, but also when the score plays a significant role in the decision and thus becomes its essential basis. However, there is no violation of the regulation if, in the event of imminent rejection due to a poor score, the clerk promptly consults one or more people who, due to their decision-making authority and discretion, are authorized and professionally capable of reviewing and evaluating the content of the automated decision. The authority to correct the automated decision should be documented. However, it is also crucial here that, in the required individual assessment of the overall circumstances with regard to the willingness and ability to pay, other factors besides the score are taken into account in the new decision (Scholz in Simitis/Hornung/Spiecker Data Protection Law GDPR with BDSG, Article 22, GDPR paras. 24, 29, 30).

These higher requirements regarding the lawfulness of automated decision-making, as well as the additional information obligations of the controller and the associated additional information rights of the data subject, are explained by the purpose pursued by Article 22 of the GDPR, which is to protect individuals from the specific risks to their rights and freedoms associated with the automated processing of personal data – including profiling (ECJ, December 7, 2023, C-634/21, para. 57). These higher requirements regarding the lawfulness of automated decision-making, as well as the additional information obligations of the controller and the associated additional information rights of the data subject, are explained by the purpose pursued by Article 22 of the GDPR, which is to protect individuals from the specific risks to their rights and freedoms associated with the automated processing of personal data – including profiling (ECJ, December 7, 2023, C-634/21, para. 57).

The logic involved encompasses the design, structure, and process of data processing. Meaningful information about the logic must explain the automated individual decision to the data subject in such a way that they can exercise their rights under Art. 22 GDPR. In practice, especially when granting credit, most questions in this context only arise when the data subject requests information after the scoring process has been completed. The controller must proactively explain the "logic involved," i.e., the design and structure of the scoring process, to the data subject. This includes information about which collected data (factors) are used in calculating the probability value (score) and with what weighting, as well as how the scores influence each other. The specific score may be subject to a right to information under Art. 15 (1) (h) (Dix in Simitis/Hornung/Spiecker Data Protection Law GDPR with BDSG, Art. 13 GDPR paras. 16, 17 in conjunction with Art. 15 GDPR para. 25). The logic involved encompasses the design, structure, and process of data processing. Meaningful information about the logic must explain the automated individual decision to the data subject in such a way that they can exercise their rights under Article 22 of the GDPR. In practice, especially in credit granting, most questions in this context only arise when the data subject requests information after the scoring process has been completed. The controller must proactively explain the "logic involved," i.e., the design and structure of the scoring process, to the data subject. This includes information about which collected data (factors) are used in calculating the probability value (score) and with what weighting, and how the scores influence each other. The specific score may be subject to a right to information under Article 15, paragraph 1, letter h (Dix in Simitis/Hornung/Spiecker Data Protection Law GDPR with BDSG, Article 13, GDPR margin numbers 16 and 17 in conjunction with Article 15, GDPR margin number 25).

3.2.2.1.2. As can be seen from the findings, the relevant data processing was completed on April 28, 2010, and no further processing of the MP's data for the purposes of automated decision-making, including profiling, took place. The BF therefore argues that Article 15 (1) (h) GDPR does not apply to the relevant data processing. 3.2.2.1.2. As can be seen from the findings, the relevant data processing was completed on April 28, 2010, and no further processing of the MP's data for the purposes of automated decision-making, including profiling, took place. The BF therefore argues that Article 15 (1) (h) GDPR does not apply to the relevant data processing.

Since the GDPR entered into force on the twentieth day after its publication in the Official Journal of the European Union, in accordance with Article 99 (1) GDPR, and pursuant to paragraph 2 leg.cit. Since the GDPR entered into force on the twentieth day after its publication in the Official Journal of the European Union, in accordance with Article 99, paragraph 1, GDPR, and applies from May 25, 2018, in accordance with paragraph 2, leg.cit., the BF is correct in this argument.

3.2.2.2. However, since at least the MP's (first-time) written request for information dated October 25, 2018, explicitly refers to "the personal data relating to the loan application as an employee" without mentioning Art. 15 (1) (h) GDPR (or any other standard), it must be examined whether the BF should not have provided the MP with the credit scoring data on another legal basis – in particular, under the Data Protection Act. With regard to any additional personal data related to the loan application, it should be noted that the authority concerned did not consider this information to be incomplete in the contested decision, which is why (due to the lack of an appeal by the MP against the decision) it has become legally binding in this regard and such data processing is not the subject of the appeal here. 3.2.2.2. However, since at least the MP's (first) written request for information dated October 25, 2018, explicitly refers to "the personal data relating to the loan application as an employee" without mentioning Article 15, paragraph 1, letter h, GDPR (or any other standard), it must be examined whether the BF should not have disclosed the credit scoring data to the MP on a different legal basis – in particular under the Data Protection Act (DSG). Regarding any additional personal data related to the loan application, it should be noted that the authority concerned did not consider this information to be incomplete in the contested decision, which is why (due to the lack of an appeal by the MP against the decision) this decision has become final and binding, and such data processing is not the subject of the appeal here.

3.2.2.2.1. According to the case law of the Administrative Court, in an administrative procedure requiring an application, it is primarily the applicant who determines the subject matter of the procedure; their application determines what is the subject of the (approval) procedure (cf. VwGH 12.09.2016, Ro 2016/04/0014, with further references). The subject matter of the procedure in the application-based procedure before the Data Protection Authority could only include those rights to information that the data subject had actually raised as being violated when submitting their application. Before the GDPR entered into force, the controller could not have violated obligations enshrined therein – which were expanded compared to the legal situation applicable until then. The data subject's application, which defined the subject matter of the case before the DPO, could therefore only cover the controllers' information obligations that already applied before the GDPR entered into force. This consideration does not create a gap in legal protection because the data subject was free to submit an application to the DPO concerning the extended information rights (cf. VwGH April 2, 2024, Ro 2021/04/0008). 3.2.2.2.1. According to the case law of the Administrative Court, in an administrative procedure requiring an application, it is primarily the applicant who determines the subject matter of the procedure; their application determines what is the subject of the (approval) procedure (cf. VwGH September 12, 2016, Ro 2016/04/0014, with further references). The subject matter of the procedure in the application-based procedure before the DPO could only include those information rights that the data subject had actually identified as having been violated when submitting their application. Before the GDPR entered into force, the controller could not have violated obligations enshrined therein – which were expanded compared to the legal situation applicable until then. The data subject's request, which defined the subject matter before the DPO, could therefore only cover the controller's information obligations that already existed before the GDPR entered into force. This consideration does not create a gap in legal protection because the data subject was free to submit a request to the DPO concerning the expanded information rights (cf. Administrative Court of Justice (VwGH) April 2, 2024, Ro 2021/04/0008).

In a case where it is necessary to agree on what is legal at a specific point in time before the GDPR and the DSG entered into force, the legal situation applicable at that time applies (cf. Administrative Court of Justice (VwGH) January 25, 2023, Ra 2019/04/0052; March 18, 2022, Ro 2020/04/0027). In a case where it is necessary to agree on what is legal at a specific point in time before the GDPR and the DSG came into force, the legal situation applicable at that time shall apply (cf. VwGH 25.01.2023, Ra 2019/04/0052; 18.03.2022, Ro 2020/04/0027).

If the Federal Administrative Court (BVwG) wrongfully assessed the relevant facts not according to the procedure prior to the entry into force of the GDPR and the DSG at the time of the appeal, but rather according to the legal situation applicable at the time of the decision, this does not in itself result in the unlawfulness of the contested decision if the decision is covered by the legal situation under the DSG 2000 (cf. VwGH 25.01.2023, Ra 2019/04/0052; 23.02.2021, Ra 2019/04/0054). If the Federal Administrative Court (BVwG) wrongfully assessed the relevant facts not according to the procedure prior to the entry into force of the GDPR and the DSG at the time of the appeal, but rather according to the legal situation applicable at the time of the decision, this does not in itself result in the unlawfulness of the contested decision if the decision is covered by the legal situation under the DSG 2000. (cf. VwGH 25.01.2023, Ra 2019/04/0052; 23.02.2021, Ra 2019/04/0054).

The Data Protection Act 2000 (DSG 2000), Federal Law Gazette.I No. 165/1999, in the version in force during the data processing in question (credit check of April 27 and 28, 2010), Federal Law Gazette I No. 133/2009, read as follows, as far as relevant to the proceedings: The Data Protection Act 2000 (DSG 2000), Federal Law Gazette Part One, No. 165 of 1999, in the version in force during the data processing in question (credit check of April 27 and 28, 2010), Federal Law Gazette Part One, No. 133 of 2009, read as far as relevant to the proceedings:

"Right to Information

Section 26. Paragraph 26,

(1) […]

(2)

Information shall not be provided if this is necessary for the protection of the person requesting the information for special reasons. or to the extent that overriding legitimate interests of the client or a third party, in particular overriding public interests, conflict with the provision of information. Overriding public interests may arise from the necessity of

1. protecting the constitutional institutions of the Republic of Austria, or

2. ensuring the operational readiness of the Federal Armed Forces, or

3. safeguarding the interests of comprehensive national defense, or

4. protecting important foreign policy, economic, or financial interests of the Republic of Austria or the European Union, or

5. preventing, hindering, or prosecuting criminal offenses.

The admissibility of refusing to provide information for the reasons listed in points 1 to 5 is subject to review by the Data Protection Commission pursuant to Section 30, Paragraph 3, and the special complaint procedure before the Data Protection Commission pursuant to Section 31, Paragraph 4. The admissibility of refusing to provide information for the reasons listed in points 1 to 5 is subject to review by the Data Protection Commission pursuant to Section 30, Paragraph 3, and the special complaint procedure before the Data Protection Commission pursuant to Section 31, Paragraph 4,

(3) The requester of information must cooperate in the information procedure via interview to the extent reasonable to avoid unjustified and disproportionate expenditure on the part of the client.

(4) The information must be provided within eight weeks of receipt of the request, or a written justification must be given as to why it is not being provided or is not being provided in full. The requester may also be waived if the requester has not cooperated in the procedure in accordance with Paragraph 3 or has not reimbursed the costs. (4) The information must be provided within eight weeks of receipt of the request, or a written justification must be given as to why it is not being provided or is not being provided in full. The requester may also be waived if the requester has not cooperated in the procedure in accordance with Paragraph 3 or has not reimbursed the costs.

(5) In those areas of enforcement entrusted with the performance of the tasks referred to in Paragraph 2, Items 1 to 5, the public interest that requires a refusal to provide information, the following procedure shall be followed: (5) In those areas of enforcement entrusted with the performance of the tasks specified in paragraph 2, numbers 1 to 5, the following procedure shall be followed, insofar as this is necessary to protect the public interest that requires a refusal to provide information:

In all cases in which no information is provided – including because no data is actually used – instead of a substantive justification, an indication shall be given that no data about the requester subject to the obligation to provide information is being used. The admissibility of this procedure is subject to review by the Data Protection Commission pursuant to Section 30 (3) and the special complaint procedure before the Data Protection Commission pursuant to Section 31 (4). In all cases in which no information is provided – including because no data is actually used – instead of a substantive justification, an indication shall be given that no data about the requester subject to the obligation to provide information is being used. The admissibility of this procedure is subject to review by the Data Protection Commission pursuant to Section 30, Paragraph 3 and the special complaint procedure before the Data Protection Commission pursuant to Paragraph 31, Paragraph 4.

(6) The information shall be provided free of charge if it concerns the current data set of a data application and if the requester has not yet submitted a request for information to the client regarding the same area of responsibility in the current year. In all other cases, a flat-rate reimbursement of costs of EUR 18.89 may be charged, which may be deviated from due to higher costs actually incurred. Any reimbursement of costs paid shall be refunded, regardless of any claims for damages, if data has been used unlawfully or if the information has otherwise led to a correction.

(7) From the time of knowledge of a request for information, the client may not destroy data concerning the requester within a period of four months, and in the event of a complaint being filed with the Data Protection Commission pursuant to Paragraph 31, until the final conclusion of the procedure. This period shall not apply if a request for deletion by the requester pursuant to Paragraph 27, Paragraph 1, Item 2 or Paragraph 28 is to be complied with. (7) From the time of knowledge of a request for information, the contracting authority may not destroy data concerning the information requester within a period of four months and, in the case of a complaint pursuant to Section 31, to the Data Protection Commission until the final conclusion of the procedure. This period shall not apply if a request for deletion by the information requester is to be complied with pursuant to Section 27, Paragraph 1, Item 2, or Section 28.

(8) To the extent that a data application is legally accessible to a person or group of persons with regard to the data processed relating to them, that person has the right to information in accordance with the provisions providing for the right of access. The procedure for access (including the refusal of access) is governed by the more detailed provisions of the law providing for the right of access. Components of information referred to in Paragraph 1 which are not covered by the right of access may nevertheless be claimed under this Federal Act. (8) To the extent that a data application is legally accessible to a person or group of persons with regard to the data relating to them If the processed data is accessible by law, the person concerned has the right to information in accordance with the provisions providing for the right of access. The procedure for access (including the refusal of access) is subject to the more detailed provisions of the law providing for the right of access. Elements of information listed in paragraph 1 that are not covered by the right of access may nevertheless be asserted under this Federal Act.

(9)-(10) […]

[…]

Automated Individual Decisions

Section 49. Paragraph 49

(1) No person may be subjected to a decision that has legal consequences for him or her or that significantly affects him or her and that is made solely on the basis of automated processing of data for the purpose of evaluating individual aspects of his or her person, such as his or her professional performance, creditworthiness, reliability, or conduct.

(2) By way of derogation from paragraph 1, a person may be subjected to a decision generated exclusively by automated means if (2) By way of derogation from paragraph One, a person may be subjected to a decision generated exclusively by automated means if:

1. this is expressly provided for by law, or

2. the decision is made in the context of the conclusion or performance of a contract and the data subject's request to conclude or fulfill the contract has been granted, or

3. the protection of the data subject's legitimate interests is guaranteed by appropriate measures – for example, the opportunity to assert their point of view.

(3) In the case of automated individual decisions, the logical process of automated decision-making must be explained to the data subject upon request in a generally understandable form. Section 26, paragraphs 2 to 10 apply mutatis mutandis. (3) In the case of automated individual decisions, the logical process of automated decision-making must be explained to the data subject upon request in a generally understandable form. Section 26, paragraphs 2 to 10 apply mutatis mutandis.

Article 15 (1) GDPR stipulates an expanded right to information compared to Section 26 DSG 2000 (Haidinger in Knyrim, DatKomm Article 15 GDPR, paragraph 9 | as of July 1, 2024, rdb.at; Jahnel, Commentary on the General Data Protection Regulation Article 15 GDPR, paragraph 1 | as of December 1, 2020, rdb.at). This also applies to the information to be provided pursuant to Article 15 (1) (h) GDPR compared to the information to be provided pursuant to Section 49 (3) in conjunction with Section 26 DSG 2000. Article 15, paragraph one, GDPR stipulates an expanded right to information compared to Paragraph 26 DSG 2000 (Haidinger in Knyrim, DatKomm Article 15, GDPR, paragraph 9 | as of July 1, 2024, rdb.at; Jahnel, Commentary on General Data Protection Regulation Article 15, GDPR, margin number 1 (as of December 1, 2020, rdb.at), this also applies to the information to be provided pursuant to Article 15, paragraph 1, letter h, GDPR, compared to the information to be provided pursuant to paragraph 49, paragraph 3, in conjunction with paragraph 26, DSG 2000.

To assess whether a request for information that is recognizable to the recipient as a data protection-related request under Section 26 DSG 2000 exists, the request must be examined for its content, applying the same standard that also applies to unilateral declarations of intent under private law. Accordingly, the wording and understanding of the declaration must be considered from an objective perspective, namely, as the recipient could understand it based on its wording and purpose upon objective consideration (cf. BVwG, November 19, 2024, W176 2286887-1; March 4, 2022, W245). 2247035-1; 03.05.2018, W256 2190554-1, with reference to the case law of the Supreme Court of July 10, 1996, 9 ObA 2139/96s; September 15, 1999, 9 ObA 148/99a, and many more. To assess whether a request for information under data protection law pursuant to Section 26 of the Data Protection Act 2000 exists, the request must be examined for its content, applying the same standard that also applies to unilateral declarations of intent under private law. Accordingly, the wording and understanding of the declaration must be considered from an objective perspective, namely, as the recipient could understand it based on its wording and purpose when viewed objectively (cf. BVwG November 19, 2024, W176). 2286887-1; 04.03.2022, W245 2247035-1; 03.05.2018, W256 2190554-1, with reference to the case law of the Supreme Court of 10.07.1996, 9 ObA 2139/96s; 15.09.1999, 9 ObA 148/99a and many more).

While determining the legal merits and content of a submission, in cases of doubt, it cannot be assumed that a party has filed a motion that is inherently pointless or inadmissible, it is nevertheless inadmissible to give the party's request an interpretation that cannot be directly deduced from its wording, contrary to the party's declared intention, even if the request, as filed, is inherently hopeless or even inadmissible (cf. Administrative Court of Justice, September 27, 2011, 2010/12/0142; November 20, 2007, 2007/16/0145). Given the declared will of a party—especially one represented by a legally pro-legal party—the authority is prohibited from giving the application an interpretation that is inconsistent with its wording, i.e., from referring it to a different legal basis (cf. VwGH 3 October 2013, 2012/06/0156). While it may not be assumed in cases of doubt that a party has submitted a motion that is inherently meaningless or inadmissible, when determining the legal quality and content of a submission, it is nevertheless inadmissible to give the party's request an interpretation that cannot be directly deduced from its wording, contrary to the party's declared will, even if the request, as it was submitted, is inherently hopeless or even inadmissible (cf. VwGH 27 September 2011, 2010/12/0142). November 20, 2007, 2007/16/0145). Given the declared will of a party—especially one represented by a legal representative—the authority is prohibited from interpreting the application in a way that is inconsistent with its wording, i.e., from referring it to a different legal basis (cf. Administrative Court of Justice October 3, 2013, 2012/06/0156).

3.2.2.2.2. Against this background, it must be examined whether the MP's request for information regarding the credit scoring data should have been granted in accordance with Section 49 (3) in conjunction with Section 26 of the Data Protection Act 2000. 3.2.2.2.2. Against this background, it must be examined whether MP's request for information regarding credit scoring data should have been granted in accordance with Section 49, Paragraph 3, in conjunction with Section 26, DSG 2000.

Section 49, Paragraph 3 DSG merely requires the submission of an application, and, as explained, on October 25, 2018, MP requested information in writing, without citing a legal basis, about "the personal data relating to the loan application as an employee." Section 49, Paragraph 3 DSG merely requires the submission of an application, and, as explained, on October 25, 2018, MP requested information in writing, without citing a legal basis, about "the personal data relating to the loan application as an employee."

In its statement of May 10, 2021, the MP, who was already represented by a lawyer at the time, stated through its legal counsel that the automated processing of personal data, which consists in using this data to analyze the economic situation, constitutes profiling and that the data subject, as part of the request for information in the case of profiling, must be informed "of the decisions taken, as well as the details of the logic used, the scope and the intended effects of such processing." Footnotes refer to "Article 4 No. 4 of Regulation 2016/679," thus the definition of profiling in the GDPR, and to commentary literature on the data subject's right to information in the case of profiling under Article 15 (1) (h) GDPR, and the text of the latter provision is also reproduced in part in the passage quoted in italics in the previous paragraph. However, in its statement of May 10, 2021, the MP, who was already represented by a lawyer at that time, stated through its legal counsel that the automated processing of personal data, which consists in using this data to analyze the economic situation, constitutes profiling, and that the data subject must be informed, as part of the request for information in the case of profiling, "of the decisions taken, as well as the details of the logic used, the scope, and the intended effects of such processing." Footnotes refer to "Article 4 No. 4 of Regulation 2016/679," the definition of profiling in the GDPR, and to commentary literature on the data subject's right to information in the case of profiling under Article 15, paragraph 1, letter h, GDPR. The text of the latter provision is also reproduced in part in the passage quoted in italics in the previous paragraph.

Article 15, paragraph 1, GDPR establishes an expanded right to information compared to Section 26 of the Data Protection Act 2000; because, as explained, according to Section 49, paragraph 3 in conjunction with Section 26 of the Data Protection Act 2000, in the case of automated individual decisions, the data subject must, upon request, merely be provided with the logical sequence of the automated decision-making process in a generally understandable form. Article 15, paragraph 1, GDPR establishes an expanded right to information compared to Section 26 of the Data Protection Act 2000; According to Section 49, Paragraph 3, in conjunction with Section 26, of the Data Protection Act 2000, as explained above, in the case of automated individual decisions, the data subject must, upon request, be provided with a generally understandable explanation of the logical process of automated decision-making.

However, after clarification on May 10, 2021, the MP's request – expressly based on Article 15, Paragraph 1, Letter h, GDPR – was for information about which decisions are made and information about the logic used, the scope, and the intended effects of such processing. However, after clarification on May 10, 2021, the MP's request – expressly based on Article 15, Paragraph 1, Letter h, GDPR – was for information about which decisions are made and information about the logic used, the scope, and the intended effects of such processing.

In light of the cited case law on the interpretation of party statements, this cannot be considered a request pursuant to Section 49, Paragraph 3 in conjunction with Section 26 of the Data Protection Act 2000, since this would not only require the explicitly stated legal basis to be "replaced," as it were, but also—contrary to the party's declared will—would require an interpretation to be given to its request that cannot be directly deduced from the wording of the request. In light of the cited case law on the interpretation of party statements, this cannot be considered a request pursuant to Section 49, Paragraph 3, in conjunction with Section 26 of the Data Protection Act 2000, since this would not only require the explicitly stated legal basis to be "replaced," as it were, but also—contrary to the party's declared will—would require an interpretation to be given to its request that cannot be directly deduced from the wording of the request.

The submission also does not contain any unclear content, whereby the authority (at most the court) would have had to establish the true intention of the intervener by obtaining a corresponding declaration, thus requesting him to provide more details or to consult him on the content (cf. e.g. VwGH 20.05.2025, Ra 2025/08/0049; 13.08.2024, Ra 2022/02/0217), but the clearly and precisely formulated request on the basis of Art. 15 Para. 1 lit. h GDPR proves to be simply inadmissible, since the GDPR, which only came into force on 25 May 2018, is not applicable to the creditworthiness assessment of the MP carried out by the BF on 27 and 28 April 2010 (and an application pursuant to Section 49 Para. 3 in conjunction with Section 26 DSG 2000 is not is present). Nor does the submission contain any unclear content, which would have allowed the authority (or the court) to establish the true intention of the intervener by obtaining a corresponding declaration, thus requesting him to provide more precise information or to consult him on the content, see, for example, VwGH 20.05.2025, Ra 2025/08/0049; 13.08.2024, Ra 2022/02/0217), but the clearly formulated request based on Article 15, paragraph 1, letter h, GDPR proves to be simply inadmissible, since the GDPR, which only entered into force on 25 May 2018, does not apply to the creditworthiness assessment of MP carried out by the BF on 27 and 28 April 2010 (and an application pursuant to Section 49, paragraph 3, in conjunction with Section 26, DSG 2000 has not been submitted).

In conclusion, it can therefore be concluded that the information provided by the Federal Data Protection Authority (BF) to the MP (in total) is not incomplete, even with regard to Article 15 (1) (h) GDPR.

3.2.3. Conclusion

Since no incomplete information was provided in any respect, the violation of law identified by the competent authority in point 1 of the contested decision neither exists nor is there scope for issuing a performance order to remedy it in point 2 or – given that the data protection complaint consequently proves to be unfounded in its entirety – for dismissing the complaint merely "in all other respects," as the authority did in point 3.

The ruling of the contested decision therefore had to be reformulated in its entirety, and the data protection complaint (in its entirety) dismissed as unfounded.

3.3. Pursuant to Section 24 (1) of the Administrative Court Act (VwGVG), the administrative court must hold a public oral hearing upon request or, if it deems it necessary, ex officio. Pursuant to Section 24 (4) of the Administrative Court Act (VwGVG), the administrative court may – unless otherwise provided by federal or state law – dispense with a hearing notwithstanding a party's request if the records indicate that the oral discussion is unlikely to further clarify the legal matter, and if neither Article 6 (1) of the ECHR nor Article 47 of the Charter of Fundamental Rights preclude dispensing with the hearing.

3.3. Pursuant to Section 24 (1) of the Administrative Court Act (VwGVG), the administrative court must hold a public oral hearing upon request or, if it deems it necessary, ex officio. According to paragraph 24, paragraph 4, VwGVG (Administrative Court Act), unless otherwise provided by federal or state law, the administrative court may, notwithstanding a party's request, dispense with a hearing if the files show that the oral discussion is not likely to provide further clarification of the legal case and if neither Article 6, paragraph 1, ECHR nor Article 47, CFR preclude dispensing with the hearing.

The facts relevant to the decision, particularly regarding the provision of information, arise from the administrative act and are no longer disputed for the Federal Administrative Court. Therefore, an oral hearing can no longer add value to the determination of the facts. The legal issue to be resolved is not so complex that an oral discussion would be necessary.

Therefore, an oral hearing could be dispensed with. Article 6(1) of the ECHR and Article 47 of the Charter of Fundamental Rights of the European Union do not preclude the waiver of a hearing. Article 6(1) of the ECHR and Article 47 of the Charter of Fundamental Rights of the European Union do not preclude the waiver of a hearing.

3.4. Regarding Decision B) – Inadmissibility of an appeal on points of law:

According to Section 25a, Paragraph 1 of the Administrative Court Act (VwGG), the administrative court must state in its judgment or decision whether the appeal on points of law is admissible pursuant to Article 133, Paragraph 4 of the Federal Constitutional Court Act (B-VG). The decision must be briefly reasoned. According to Section 25a, Paragraph 1 of the Administrative Court Act (VwGG), the administrative court must state in its judgment or decision whether the appeal on points of law is admissible pursuant to Article 133, Paragraph 4 of the Federal Constitutional Court Act (B-VG). The decision must be briefly reasoned.

The appeal on points of law is inadmissible pursuant to Article 133, Paragraph 4 of the Federal Constitutional Court Act because the decision does not depend on the resolution of a legal issue of fundamental importance. The present decision neither deviates from the previous jurisprudence of the Administrative Court, nor is there a lack of jurisprudence; furthermore, the present jurisprudence of the Administrative Court cannot be considered inconsistent (see in particular the case law cited under A). There are also no other indications of the fundamental importance of the legal issue to be resolved. Specific legal issues of fundamental importance were neither raised in the present appeal nor emerged in the proceedings before the Federal Administrative Court. The appeal is inadmissible pursuant to Article 133, Paragraph 4, of the Federal Constitutional Court Act (B-VG) because the decision does not depend on the resolution of a legal issue of fundamental importance. The present decision neither deviates from the previous jurisprudence of the Administrative Court, nor is there a lack of case law; furthermore, the present case law of the Administrative Court cannot be considered inconsistent (see in particular the case law cited under A). There are also no other indications of the fundamental importance of the legal issue to be resolved. Specific legal issues of fundamental importance were neither raised in the present appeal nor emerged in the proceedings before the Federal Administrative Court.

Although some of the jurisprudence of the Administrative Court cited above in the legal assessment was issued in relation to earlier legal situations, the court considers it to be applicable without change to the provisions of the current legal situation, which are largely identical in content.

With regard to point 3.2.2, it should also be noted that, according to the consistent case law of the Administrative Court, a justifiably case-specific interpretation of party statements does not generally justify the admissibility of an appeal on points of law, because the interpretation of a party statement depends on the specific circumstances of the statement and, for this reason, has no significance beyond the specific case. The interpretation of a declaration in an individual case would only be considered reviewable if it had been made in an unjustifiable manner that compromises legal certainty (cf. VwGH 16.01.2025, Ra 2024/04/0438; 11.12.2023, Ra 2021/04/0095), for which there is no evidence in this case. With regard to point 3.2.2., it should also be noted that, according to the consistent case law of the Administrative Court, a justifiable case-specific interpretation of party declarations does not generally justify the admissibility of an appeal on points of law, because the interpretation of a party declaration depends on the respective circumstances of the declaration and, for this reason, has no significance beyond the specific individual case. The interpretation of a declaration in an individual case would only be considered revisable if it had been made in an unacceptable manner that compromised legal certainty (see Administrative Court of Justice (VwGH) January 16, 2025, Ra 2024/04/0438; December 11, 2023, Ra 2021/04/0095), for which there is no evidence in this case.

The decision was therefore to be made in accordance with the judgment as a whole.