BVwG - W176 2259543-1
| BVwG - W176 2259543-1 | |
|---|---|
| Court: | BVwG (Austria) |
| Jurisdiction: | Austria |
| Relevant Law: | Article 5(1)(b) GDPR Article 6(1) GDPR Article 15 GDPR Article 57 GDPR Article 58 GDPR |
| Decided: | 03.04.2025 |
| Published: | 04.06.2025 |
| Parties: | |
| National Case Number/Name: | W176 2259543-1 |
| European Case Law Identifier: | ECLI:AT:BVWG:2025:W176.2259543.1.00 |
| Appeal from: | |
| Appeal to: | Unknown |
| Original Language(s): | German |
| Original Source: | RIS (in German) |
| Initial Contributor: | ap |
A court upheld a decision by the DPA and stated that an address publisher violated the principle of purpose limitation by unlawfully transferring data collected for marketing purposes to a credit information agency. It also held that the data subject has no subjective right to a specific remedy, such as a ban of the processing.
English Summary
Facts
In March 2021, a data subject (represented by noyb) filed a complaint to the DPA against an address publisher and direct marketing company (referred to as the address publisher or the controller) and a credit information agency. The data subject submitted a request for information (Article 15 GDPR) to the address publisher and several credit information agencies in Austria. The address publisher was named as the source of the data; it had collected it for the purposes of exercising the trade of address publisher, however, it also transferred data as part of a contractual agreement with the credit information agency. This agency processed data (name, date of birth and (partially historical) addresses) for the purpose of assessing the data subject’s creditworthiness. The credit information agency has an additional business license for address publishing and direct marketing.
In the complaint the data subject argued that this processing violated the principle of purpose limitation (Article 5(1)(b) GDPR in conjunction with Article 6(4) GDPR). The data subject had not provided data to the controller and was not informed of the changes in the purpose of data processing. Furthermore, the way in which the credit score was calculated was unclear to the data subject. The address publisher argued that its business license allowed it to process personal data and disclose it to third parties.
In its decision, the DPA stated the controller had violated the principle of purpose limitation because it collected data for marketing purposes, but transferred data to the credit information agency for the purposes of credit rating. The DPA also stated that the data subject had no subjective right for the DPA to impose a processing ban.
The data subject appealed the second point of the decision, arguing that a processing ban is the only way to effectively prevent future unlawful data processing. The controller appealed the first point of the decision, arguing that it amended the agreement with the credit information agency when the GDPR came into force, and that the DPA based its decision on the previous version.
Holding
The Court first dismissed the appeal by the address publisher. The purpose limitation principle (Article 5(1)(b) GDPR) applies to both the initial collection and the further processing of personal data. The Court considered the further processing for credit assessment purposes incompatible with the original purpose of address publishing and direct marketing (Article 6(4) GDPR). The Court found no connection between the original purpose and the further processing, and stated that the latter clearly deviated from the legitimate expectations of the data subject.
The Court dismissed the companies’ argument that their amended agreement respected the principle of purpose limitation. Clauses in the agreement allowed the transfer of data beyond marketing purposes. This meant the companies wrongly considered the data processing as legal, and the agreement was not sufficiently changed to comply with the GDPR. The Court considered the address publisher had violated the principle of purpose limitation, since it could not ensure that the credit information agency would only use the data for marketing purposes.
The Court did not see the need to analyse whether the processing complied with Article 6(1) GDPR. CJEU case law[1] states that processing must comply with both Article 5 and Article 6. It is a cumulative requirement, and therefore Court considered the processing unlawful in any case.
Finally, the Court dismissed the appeal by the data subject. The Court upheld the reasoning of the DPA in not applying a data processing ban on the address publisher. The DPA has a range of powers under Article 57 GDPR and Article 58 GDPR and may be obliged to take specific measures if the protection under EU law cannot be guaranteed under any other means.[2] However, the ban on processing is a burdensome measure for processors, and the DPA must consider if the ban is appropriate, necessary or proportionate. Furthermore, the Court agreed with the DPA’s reasoning that the data subject did not have the subjective right to a specific remedy.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the German original. Please refer to the German original for more details.
Decision Date
April 3, 2025
Standard
AVG §39 Para. 2
B-VG Art. 133 Para. 4
DSG §24
GDPR Art. 4
GDPR Art. 5
GDPR Art. 51
GDPR Art. 57
GDPR Art. 58
GDPR Art. 6
GDPR Art. 77
GewO 1994 §151
GewO 1994 §152
VwGVG §17
AVG § 39 today AVG § 39 valid from August 15, 2018, last amended by Federal Law Gazette I No. 57/2018 AVG § 39 valid from April 20, 2002 to August 14, 2018, last amended by Federal Law Gazette I No. 65/2002 AVG § 39 valid from January 1, 1999 to April 19, 2002, last amended by Federal Law Gazette I No. 158/1998, AVG § 39, valid from February 1, 1991 to December 31, 1998
B-VG Art. 133 today. B-VG Art. 133 valid from January 1, 2019 to May 24, 2018, last amended by Federal Law Gazette I No. 138/2017. B-VG Art. 133 valid from January 1, 2019, last amended by Federal Law Gazette I No. 22/2018. B-VG Art. 133 valid from May 25, 2018 to December 31, 2018, last amended by Federal Law Gazette I No. 22/2018. B-VG Art. 133 valid from August 1, 2014 to May 24, 2018 last amended by BGBl. I No. 164/2013 B-VG Art. 133 valid from January 1, 2014 to July 31, 2014 last amended by BGBl. I No. 51/2012 B-VG Art. 133 valid from January 1, 2004 to December 31, 2013 last amended by BGBl. I No. 100/2003 B-VG Art. 133 valid from January 1, 1975 to December 31, 2003 last amended by BGBl. No. 444/1974 B-VG Art. 133 valid from December 25, 1946 to December 31, 1974 last amended by BGBl. No. 211/1946 B-VG Art. 133 valid from 19.12.1945 to 24.12.1946 last amended by StGBl. No. 4/1945 B-VG Art. 133 valid from January 3, 1930 to June 30, 1934
DSG Art. 2 § 24 valid from July 15, 2024, last amended by Federal Law Gazette I No. 70/2024 DSG Art. 2 § 24 valid from May 25, 2018 to July 14, 2024, last amended by Federal Law Gazette I No. 120/2017 DSG Art. 2 § 24 valid from January 1, 2010 to May 24, 2018, last amended by Federal Law Gazette I No. 133/2009 DSG Art. 2 § 24 valid from January 1, 2000 to December 31, 2009
GewO 1994 Section 151 (currently GewO 1994 Section 151) valid from May 25, 2018, last amended by Federal Law Gazette I No. 32/2018. GewO 1994 Section 151 valid from February 27, 2008, to May 24, 2018, last amended by Federal Law Gazette I No. 42/2008. GewO 1994 Section 151 valid from August 1, 2002, to February 26, 2008, last amended by Federal Law Gazette I No. 111/2002. GewO 1994 Section 151 valid from March 19, 1994, to July 31, 2002.
GewO 1994 Section 152 (currently GewO 1994 Section 152) Valid from August 1, 2002, last amended by Federal Law Gazette I No. 111/2002, Trade Regulation Act 1994, Section 152, valid from March 19, 1994, to July 31, 2002
VwGVG Section 17, now VwGVG Section 17, valid from January 1, 2014
Saying
W176 2259543-1/15E
W176 2259545-1/11E
IN THE NAME OF THE REPUBLIC!
The Federal Administrative Court, with Judge Mag. NEWALD as presiding judge and the expert lay judges Mag. BOGENDORFER and RAUB as assessors, has decided on the complaints of (1.) XXXX , represented by noyb - European Center for Digital Rights, against point 2) and (2.) XXXX , represented by Attorney Mag. Gernot SCHAAR, against point 1 of the decision of the Data Protection Authority dated 22.07.2022, Ref. No. D124.3817, 2021-0.584.299,The Federal Administrative Court, with Judge Mag. NEWALD as presiding judge and the expert lay judges Mag. BOGENDORFER and RAUB as assessors, has decided on the complaints of (1.) roman 40 , represented by noyb - European Center for Digital Rights, against point 2) and (2.) roman 40 , represented by Attorney Mag. Gernot SCHAAR, against point 1 of the decision of the Data Protection Authority dated July 22, 2022, Ref. No. D124.3817, 2021-0.584.299,
A1) Decided:
The proceedings are joined for a joint decision pursuant to Section 17 of the Administrative Court Act (VwGVG) in conjunction with Section 39 (2) of the Administrative Court Act (AVG). The proceedings are joined for a joint decision pursuant to Section 17 of the Administrative Court Act (VwGVG) in conjunction with Section 39 (2) of the Administrative Court Act (AVG).
A2) Correctly ruled:
I. The appeal of the first appellant is dismissed as unfounded. Roman one. The appeal of the first appellant is dismissed as unfounded.
II. The appeal of the second appellant is dismissed as unfounded. Roman II. The appeal of the second appellant is dismissed as unfounded.
B) The appeal is inadmissible pursuant to Article 133(4) of the Federal Constitutional Act.
B) The appeal is inadmissible pursuant to Article 133(4) of the Federal Constitutional Act.
Text
Reasons for the decision:
I. Course of proceedings: Roman one. Course of proceedings:
I.1. By written submission dated March 15, 2021, XXXX (hereinafter: the first complainant) filed a data protection complaint against XXXX (hereinafter: the second complainant). According to the complaint, the first complainant submitted a request for information pursuant to Article 15 GDPR to XXXX and other credit reporting agencies operating in Austria. XXXX processes several personal data belonging to the first complainant. The second complainant was named exclusively as the source of the data. The first complainant never provided any data to any of these companies himself and was not informed of any changes in the purpose of the data after his data had been collected. It should be noted in particular that the second appellant does not hold a trade license pursuant to Section 152 of the German Trade Regulation Act (GewO). Although the second appellant (as far as can be seen) only has the name, date of birth, and (partially historical) addresses of the first appellant and transmitted this data to XXXX, XXXX calculated numerically different credit scores – in a manner incomprehensible to the first appellant – and transmitted them to specific recipients identified (in an attachment). The transmission of the first appellant's personal data by the second appellant, which collected it for the purpose of "exercising the business of address publishing pursuant to Section 151 of the German Trade Regulation Act," to XXXX, which used the data to assess the first appellant's creditworthiness, violates the purpose limitation principle pursuant to Article 5 (1) (b) in conjunction with Article 6 (4) GDPR. This purpose of the data processing by the second appellant is incompatible with the second appellant's original purpose as a data provider. Furthermore, no justification exists, neither for the data processing by the second appellant nor for that by XXXX. Furthermore, the first appellant filed an application for a data processing ban against the second appellant pursuant to Art. 58 (2) GDPR, prohibiting the second appellant from collecting personal data from address publishers within the meaning of Section 151 of the Trade Regulation Act (GewO) and processing this data for credit assessment purposes within the meaning of Section 152 of the Trade Regulation Act (GewO). römisch eins.1. By written submission of March 15, 2021, römisch 40 (hereinafter: the first appellant) filed a data protection complaint against römisch 40 (hereinafter: the second appellant). According to the complaint, the first complainant submitted a request for information pursuant to Article 15 of the GDPR to roman 40 and other credit agencies operating in Austria. roman 40 processes several personal data belonging to the first complainant. The second complainant was named exclusively as the source of the data. The first complainant never provided any data to any of these companies and was not informed of any changes in purpose after his data was collected. It should be noted, in particular, that the second complainant does not hold a trade license pursuant to Section 152 of the Trade Regulation Act (GewO). Although the second complainant (as far as can be seen) only possesses the name, date of birth, and (partially historical) addresses of the first complainant and transmitted this data to roman 40, roman 40 calculated numerically different credit scores – in a manner incomprehensible to the first complainant – and transmitted them to specific recipients identified (in an attachment). The transmission of the first appellant's personal data by the second appellant, which the data were collected for the purpose of "carrying out the business of address publishing pursuant to Section 151 of the Trade Regulation Act," to roman 40, which uses the data to assess the first appellant's creditworthiness, violates the purpose limitation principle pursuant to Article 5, paragraph 1, letter b, in conjunction with Article 6, paragraph 4, GDPR. This purpose of the data processing by the second appellant is incompatible with the second appellant's original purpose as a data provider. Furthermore, there is no justification for the data processing by the second appellant or by roman 40. Furthermore, the first appellant filed a motion to impose a data processing ban on the second appellant pursuant to Article 58(2) GDPR, prohibiting the second appellant from collecting personal data from address publishers within the meaning of Section 151 of the Trade Regulation Act (GewO) and processing this data for credit assessment purposes within the meaning of Section 152 of the Trade Regulation Act (GewO).
I.2. In a written submission dated July 10, 2021, the second appellant argued that the justification for the data processing arises from the valid trade license pursuant to Section 151 of the Trade Regulation Act (GewO) for address publishers and direct marketing companies. This entitles the second appellant to process, collect, record, organize, store, retrieve, and use the personal data, as well as to disclose it to third parties by transmission and forwarding. Based on the valid trade license, the second appellant can transmit personal data to XXXX. Only the name, date of birth, and address of the first complainant were transmitted. There was no violation of the principle of purpose limitation or the legality of data processing. It is not the subject of the proceedings whether XXXX uses the first complainant's data to assess creditworthiness. The data transfer to XXXX was based on its trade license as an address publisher and direct marketing company; the second complainant was entitled to do so based on its own trade license as an "address publisher and direct marketing company." It is irrelevant that XXXX also holds other trade licenses; the data transfer was always only carried out within the scope of XXXX's activities as an address publisher and direct marketing company. Roman one.2. In a written submission dated July 10, 2021, the second complainant stated that the justification for the data processing arises from the valid trade license pursuant to Section 151 of the Trade Regulation Act (GewO) for address publishers and direct marketing companies. This authorizes the processing, collection, recording, organization, storage, retrieval, and use of personal data, as well as its disclosure to third parties by transmission and forwarding. Based on its valid business license, the second appellant may transmit personal data to roman 40. Only the name, date of birth, and address of the first appellant were transmitted. There was no violation of the principle of purpose limitation or the lawfulness of data processing. It is not relevant to these proceedings whether roman 40 uses the first appellant's data to assess creditworthiness. The data was transmitted to roman 40 on the basis of its business license as an address publisher and direct marketing company; the second appellant was authorized to do so on the basis of its own business license as an "address publisher and direct marketing company." It is irrelevant that roman 40 also holds other business licenses; the data was always transmitted only within the scope of roman 40's activities as an address publisher and direct marketing company.
I.3. In a written submission dated August 10, 2021, the first appellant argued that a controller is obligated to ensure that data is processed separately according to the processing purposes and is not further processed for purposes other than those intended. An address publisher such as the second appellant is not permitted to pass on data for credit assessment purposes, and a credit reporting agency such as XXXX is not permitted to collect data from an address publisher for credit assessment purposes or (further) process data received from an address publisher for credit assessment purposes. It can be inferred from the address delivery agreement concluded between the second appellant and XXXX that the second appellant did not transmit personal data (such as that of the first appellant) to XXXX for (third-party) marketing purposes. The second appellant and XXXX even excluded in the agreement that XXXX would process the data for these purposes. 3. In a written submission dated August 10, 2021, the first appellant argued that a controller is obligated to ensure that data is processed separately according to the processing purposes and is not further processed for purposes other than those intended. An address publisher such as the second appellant is not permitted to pass on data for credit assessment purposes, and a credit agency such as roman 40 is not permitted to collect data from an address publisher for credit assessment purposes or (further) process data received from an address publisher for credit assessment purposes. The address delivery agreement concluded between the second appellant and roman 40 indicates that the second appellant did not transmit personal data (such as that of the first appellant) to roman 40 for marketing purposes (of third parties). The second appellant and roman 40 even exclude in the agreement that roman 40 may process the data for these purposes.
I.4. By the decision of July 22, 2022, mentioned in the ruling, the authority concerned upheld the appeal of the first appellant and found in point 1 of the ruling that the second appellant had violated the principle of purpose limitation pursuant to Art. 5 (1) (b) GDPR and had therefore unlawfully processed the first appellant's data contrary to Art. 6 (1) in conjunction with (4) GDPR by transmitting at least his name, address, and date of birth, which it had originally collected for the purposes of address publishing and direct marketing, to XXXX, which subsequently processed this data for credit assessment purposes pursuant to Section 152 of the Trade Regulation Act 1994. In point 2 of the ruling, the authority rejected the first appellant's application for a data processing ban against the second appellant. Roman one.4. By the decision dated July 22, 2022, referred to in the ruling, the authority in question upheld the first appellant's appeal and found in point 1 of the ruling that the second appellant had violated the principle of purpose limitation pursuant to Article 5, paragraph 1, letter b, GDPR and had therefore unlawfully processed the first appellant's data in violation of Article 6, paragraph 1, in conjunction with paragraph 4, GDPR by transmitting at least the first appellant's name, address, and date of birth, which it had originally collected for address publishing and direct marketing purposes, to roman 40, which subsequently processed this data for credit assessment purposes pursuant to Section 152 of the Trade Regulation Act 1994. In point 2 of the ruling, the authority rejected the first appellant's application for a data processing ban against the second appellant.
With regard to point 1 of the decision, the authority in question essentially stated that the second appellant had violated the principle of purpose limitation pursuant to Art. 5 (1) (b) GDPR because the requirements of Art. 6 (4) GDPR were not met. The violation lay in the fact that the second appellant had transmitted data that it had collected for marketing purposes to XXXX, and it had been expressly agreed that XXXX would (also) process this data for creditworthiness purposes. A strict purpose limitation, according to which XXXX may also process the transmitted data only for the purposes of address publishing and direct marketing, could not be inferred from the agreement between the second appellant and XXXX. This omission must be attributed to the second appellant pursuant to Art. 5 (2) GDPR. In substance, Art. 5 (1) (b) GDPR had been violated; This has direct implications for Art. 6 (1) (f) GDPR. Regarding point 1 of the decision, the authority in question essentially stated that the second appellant had violated the principle of purpose limitation pursuant to Article 5 (1) (b) GDPR because the requirements of Article 6 (4) GDPR were not met. The violation lay in the fact that the second appellant had transmitted data it had collected for marketing purposes to roman 40, and it had been expressly agreed that roman 40 would (also) process this data for credit assessment purposes. A strict purpose limitation, according to which roman 40 may also process the transmitted data only for the purposes of address publishing and direct marketing, could not be inferred from the agreement between the second appellant and roman 40. This omission must be attributed to the second appellant pursuant to Article 5 (2) GDPR. In substance, Article 5, paragraph 1, letter b, GDPR had been violated; this had direct implications for Article 6, paragraph 1, letter f, GDPR.
Regarding point 2 of the decision, the authority, referring to the wording of Article 58, paragraph 2, letter f, GDPR, stated that a data subject does not have a subjective right to have the supervisory authority impose a processing ban.Regarding point 2 of the decision, the authority, referring to the wording of Article 58, paragraph 2, letter f, GDPR, stated that a data subject does not have a subjective right to have the supervisory authority impose a processing ban.
I.5. The first appellant filed a timely appeal against point 2 of the decision, essentially arguing that the mere finding of the unlawfulness of the historical data transfer by the second appellant to XXXX did not provide him with legal protection against possible future data transfers. Even if the second complainant and XXXX were to delete all personal data concerning him from their databases, there is a risk that the second complainant would again collect data from him in the future without informing him and transmit it to XXXX, which would then use it to carry out credit assessments – again without informing him. In supervisory authority proceedings, according to Art. 77 GDPR, a subjective right to the imposition of a processing ban pursuant to Art. 58 (2) (f) GDPR must in principle be affirmed. The first complainant is entitled to a subjective right to the imposition of a processing ban because the discretion of the authority concerned is reduced to zero in this regard. A processing ban is the only means of effectively preventing unlawful data processing by the second complainant. There is currently an imminent danger of a repetition of the data protection violations committed.Roman one.5. The first appellant filed a timely appeal against point 2 of the decision, essentially arguing that the mere finding of the unlawfulness of the historical data transfer by the second appellant to roman 40 did not provide him with legal protection against possible future data transfers. Even if the second appellant and roman 40 were to delete all personal data concerning him from their databases, there was a risk that the second appellant would again collect data from him in the future without informing him and transmit it to roman 40, which would then use it to conduct credit assessments—again without informing him. In supervisory proceedings, according to Article 77 GDPR, a subjective right to impose a processing ban pursuant to Article 58, paragraph 2, letter f, GDPR must be affirmed. The first appellant is entitled to a processing ban, as the discretion of the authority concerned is reduced to zero in this regard. A processing ban is the only means of effectively preventing unlawful data processing by the second appellant. There is currently an imminent risk of a repetition of the data protection violations committed.
I.6. The second appellant, in turn, filed a timely appeal against point 1 of the decision, essentially stating the following: The first appellant's data, which it had transmitted to XXXX, was presumably also used for another purpose. However, use for another purpose was not contractually permitted. Originally, the transmitted data could have been used for specific creditworthiness and identity questions within the framework of an individual query. However, this was amended and clarified in the addenda to the effect that use outside of XXXX's marketing purposes was not permitted. The original contract was therefore amended on May 25, 2018. The authority in question only relied on the original agreement and ignored the fact that the addendum clarified that the use of the data transmitted by the second complainant to XXXX was limited to marketing purposes and to improve accessibility and deliverability.Any further processing of the data by XXXX would likely be justified as a "secondary activity" under Section 32 of the German Trade Code (GewO). These data were never suitable for determining creditworthiness. Furthermore, there was a connection between the original purpose and the new purpose, and no special categories of data were affected, meaning that a change of purpose by the second appellant was permissible under Article 6 (4) GDPR even without the consent of the first appellant and without separate legal regulations. 6. The second appellant, in turn, filed a timely appeal against point 1 of the decision, essentially stating the following: The first appellant's data, which she had transmitted to roman 40, had presumably also been used for another purpose. However, use for another purpose was not contractually permitted. Originally, the transmitted data could have been used for specific creditworthiness and identity questions within the framework of an individual query. However, this was amended or clarified in the addenda to the effect that use outside of roman 40's marketing purposes was not permitted. Thus, the original contract was amended on May 25, 2018. The authority in question only relied on the original agreement and ignored the fact that the addenda clarified that the use of the data transmitted by the second complainant to roman 40 was limited to marketing purposes and to improve accessibility and deliverability. Any further processing of the data by roman 40 would likely be justified as a "secondary activity" under Section 32 of the German Trade Regulation Act (GewO). These data were never suitable for determining creditworthiness. Furthermore, there was a connection between the original purpose and the new purpose, and no special categories of data were affected, meaning that a change of purpose was permissible by the second complainant under Article 6, Paragraph 4, GDPR, even without the consent of the first complainant and without separate legal regulations.
The second complainant also never received the first complainant's statement of August 10, 2021, which is why her rights as a party were violated.
The purpose limitation of Article 5 (2) GDPR is not a subjective right, which is why it could not be disputed in the present case. The purpose limitation of Article 5 (2) GDPR is not a subjective right, which is why it could not be disputed in the present case.
I.7. By letter dated August 29, 2022, the respondent authority submitted the appeals against the decisions, including the relevant administrative files, to the Federal Administrative Court, commenting on both appeals.
I.8. In a written submission dated March 9, 2023, the second appellant submitted two anonymized statements from the Federal Ministry of Labor and Economics dated November 29, 2022, and January 17, 2023. These statements stated that address publishers are authorized to engage in secondary activities in addition to their main activity, in particular the transmission of address data to credit agencies for the purposes of credit assessment. The second appellant's data transmission to XXXX, which is itself an address publisher, is in any case permissible. Roman one.8. In a written submission dated March 9, 2023, the second appellant submitted two anonymized statements from the Federal Ministry of Labor and Economics dated November 29, 2022, and January 17, 2023. This means that address publishers are authorized to engage in secondary activities in addition to their main activity, in particular the transmission of address data to credit agencies for the purposes of credit assessment. The second appellant's transmission of data to roman 40, which is itself an address publisher, is in any case permissible.
I.9. By order of the Business Allocation Committee of November 29, 2023, the case was removed from the previously competent court division and assigned to Court Division W176.
I.10. By letter dated June 4, 2024, the Federal Administrative Court gave the complaining parties the opportunity to comment on the appeals against the decisions filed by the other complaining party and the relevant statements of the authority being challenged.
I.11. While no comments were received from the second appellant, the first appellant made the following statements in written submissions dated June 14 and 17, 2025: Regarding his appeal regarding the processing prohibition, he referred in summary to the Advocate General's statements in ECJ case No. C-768/21 of April 11, 2024, according to which data subjects are entitled to a subjective right to a specific remedial measure if the supervisory authority's scope for action is reduced to zero. Regarding the second appellant's appeal against the decision, he noted that the latter itself has since admitted that XXXX used its data for credit assessment and thus not for advertising purposes, and that it also transmitted the data to XXXX specifically for the credit assessment, so that there had in any case been a change of purpose. The processing for credit assessment purposes is undoubtedly incompatible within the meaning of Article 6 (4) GDPR with the direct marketing purposes of third parties for which the second complainant originally collected its data. Furthermore, according to supreme court case law, violations of Articles 5 and 6 GDPR can of course be asserted as subjective rights in appeal proceedings. Finally, it was suggested that the present proceedings and the proceedings pending before the Federal Administrative Court under cases W605 2270910-1 and W605 2271598-1 concerning the appeals filed by the first complainant and XXXX against the decision of the respondent authority dated March 24, 2023, case number D124.3816 2023-0.193.268 (concerning the processing of the first complainant's data by XXXX), be joined for decision by the same Senate. Roman one.11. While no comments were received from the second appellant, the first appellant, in written submissions dated June 14 and 17, 2025, made the following statements: Regarding his appeal regarding the processing prohibition, he referred in summary to the Advocate General's statements in ECJ Case C-768/21 of April 11, 2024, according to which data subjects are entitled to a subjective right to a specific remedial measure if the supervisory authority's scope for action is reduced to zero. Regarding the second appellant's appeal against the decision, he noted that the latter itself has since admitted that roman 40 used its data for credit assessment and thus not for advertising purposes, and that it also transmitted the data to roman 40 specifically for the credit assessment, so that there had in any case been a change of purpose. The processing for credit assessment purposes is undoubtedly incompatible within the meaning of Article 6, Paragraph 4, GDPR with the direct marketing purposes of third parties for which the second appellant originally collected its data. Furthermore, according to supreme court jurisprudence, violations of Articles 5 and 6 GDPR can of course be asserted as subjective rights in appeal proceedings. Finally, it was suggested that the present proceedings and the proceedings pending before the Federal Administrative Court under Case Nos. W605 2270910-1 and W605 2271598-1 concerning the appeals filed by the first appellant and the roman 40 against the decision of the respondent authority dated March 24, 2023, Case No. D124.3816 2023-0.193.268 (concerning the processing of the first appellant's data by the roman 40) be joined for decision by the same Senate.
II. The Federal Administrative Court considered: Roman II. The Federal Administrative Court considered:
1. Findings:
The procedural course of action described under I. forms the basis for the findings; in particular, it is further established: The procedural course of action described under Roman 1. forms the basis for the findings; in particular, it is further established:
1.1. The second appellant has been authorized to carry out the business of address publishing and direct marketing company pursuant to Section 151 of the Trade Regulation Act (GewO) since February 2, 2018.
XXXX has (also) operated the business of "address publishing and direct marketing company" pursuant to Section 151 of the Trade Regulation Act (GewO) since January 16, 2013. Furthermore, it has since then also held a business license as a credit information agency pursuant to Section 152 of the German Trade Regulation Act (GewO) and is authorized to provide services in automatic data processing and information technology within the meaning of Section 153 of the German Trade Regulation Act (GewO). Since January 16, 2013, Römische 40 has (also) operated the business of "address publishing and direct marketing company" pursuant to Section 151 of the German Trade Regulation Act (GewO). Furthermore, it has since then also held a business license as a credit information agency pursuant to Section 152 of the German Trade Regulation Act (GewO) and is authorized to provide services in automatic data processing and information technology within the meaning of Section 153 of the German Trade Regulation Act (GewO).
1.2. XXXX operates as an information agency for credit and creditworthiness-related circumstances of data subjects, including fraud prevention, and operates a related identity and creditworthiness database, the so-called "XXXX database." 1.2. Römische 40 operates as an information agency for credit and creditworthiness-related circumstances of data subjects, including fraud prevention, and operates a related identity and creditworthiness database, the so-called "Roman 40 database."
1.3. In December 2012, XXXX and the second complainant (then: XXXX) concluded an agreement regarding the delivery and use of address data. The agreement became effective on January 1, 2013, and contains the following excerpts (emphasis added by the Federal Administrative Court):
"Preamble
1. The [second appellant] is authorized, based on its trade license for address publishers and direct marketing companies, to collect, process, use, transfer, and transmit personal data within the framework of the law.
..
3. [XXXX] is also authorized, based on its own trade license for address publishers and direct marketing companies and a data registration in Austria, to collect, process, use, transfer, and transmit personal data within the framework of the law.
....
1 Subject of the Agreement 1.3. In December 2012, roman 40 and the second appellant (then: roman 40) concluded an agreement regarding the delivery and use of address data. The agreement became effective on January 1, 2013, and contains the following excerpts (emphasis added by the Federal Administrative Court):
"Preamble
1. The [second appellant] is authorized, on the basis of its trade license for address publishers and direct marketing companies, to collect, process, use, provide, and transmit personal data within the framework of the law.
..
3. [Roman 40] is also authorized, on the basis of its own trade license for address publishers and direct marketing companies and a data registration in Austria, to collect, process, use, provide, and transmit personal data within the framework of the law.
...
1 Subject of the Agreement
1. [The second appellant] shall provide [XXXX] with the following types of data for the duration of the agreement:
● Name and First name
● Address
● Telephone number…
….
2. [The XXXX ] has a limited right of use with regard to this address data transmitted by [the second appellant] for its own purposes for data comparison, address identification, address searches, address corrections, and address supplementation on its own systems and its own internet applications, whether in-house or out-house. The use of this data for other activities, as well as the transmission or transfer of this address data to third parties, whether for a fee or free of charge, is prohibited. [The XXXX ] is entitled to transmit addresses as the result of individual queries within the framework of a specific creditworthiness or identity check. If such a transmission occurs, [the second appellant] ensures that the recipient of the transmission may neither pass these addresses on to third parties nor use them for marketing purposes. 2. [The Roman 40 ] has a limited right of use with regard to this data transmitted by [the [The second appellant] grants the address data transmitted by [the second appellant] a limited right of use for its own purposes for data comparison, address identification, address searches, address correction, and address supplementation on its own systems and its own internet applications, whether in-house or out-house. The use of this data for other activities, as well as the transmission or transfer of this address data to third parties, whether for a fee or free of charge, is prohibited. [The Roman 40] is entitled to transmit addresses as the result of individual queries within the framework of a specific creditworthiness or identity check. If such a transmission occurs, [the second appellant] ensures that the recipient of the transmission may neither pass these addresses on to third parties nor use them for marketing purposes.
...“
1.4. Following the entry into force of the GDPR on May 25, 2018, XXXX and the second appellant concluded an addendum to this contract with the following content (emphasis added by the Federal Administrative Court): 1.4. Following the entry into force of the GDPR on May 25, 2018, Römische 40 and the second appellant concluded an addendum to this contract with the following content (emphasis added by the Federal Administrative Court):
" 1 Introduction
The contracting parties are currently working together on the basis of the "Agreement on the Delivery and Use of Address Data" dated December 2012. This agreement is hereinafter referred to as the "Main Agreement," [...]
In light of the GDPR's validity since May 25, 2018, the contracting parties agree as follows:
It is a common understanding that there is no contract processing relationship between XXXX and [the second appellant], but rather that both contracting parties are to be qualified as independent data controllers.
2 Subject Matter of the Contract
2.1. Subject Matter of the Processing under the Main Contract
Provision of limited use of certain data characteristics of certain individuals for a specific period of time from its "A-Plus Consumer" database by [the second appellant] for the following purposes:
1. Marketing purposes of XXXX for its own marketing measures and marketing measures that [the second appellant] carries out or prepares for third parties. 1. Marketing purposes of roman 40 for its own marketing activities and marketing activities that [the second appellant] carries out or prepares for third parties.
2. Reference and validation purposes, i.e., the purpose of determining improved accessibility and deliverability, for the purpose of correcting and/or supplementing the data records of XXXX or its customers, including the use of the data to improve analyzed data sets of [the second appellant]. 2. Reference and validation purposes, i.e., the purpose of determining improved accessibility and deliverability, for the purpose of correcting and/or supplementing the data records of roman 40 or its customers, including the use of the data to improve analyzed data sets of [the second appellant].
3. Other purposes for which [the second appellant] and/or XXXX are authorized to process the data under statutory provisions. 3. Other purposes for which [the second appellant] and/or roman 40 are authorized to process the data under statutory provisions.
[The second appellant] does not carry out any activities of its own for XXXX and is only obligated to maintain and update its Aplus database, including uploading and transmitting updates.
1.5. By email dated January 11, 2021, the first appellant sent a request for information to XXXX pursuant to Article 15 GDPR. 1.5. By email dated January 11, 2021, the first appellant sent a request for information to roman 40 pursuant to Article 15 GDPR.
1.6. XXXX responded to this request for information by email dated February 12, 2021, and enclosed a letter dated February 11, 2021, with its reply. Accordingly, XXXX has stored the following data of the first complainant:
The information provided by XXXX indicates that it has stored the first complainant's name (before the change in connection with his marriage), his date of birth, and his (partially historical) address(es). XXXX cited the second complainant as the source of this data. The information provided by roman 40 indicates that it stored the first appellant's name (before the change in connection with his marriage), his date of birth, and his (partially historical) address(es). roman 40 stated the second appellant as the source of this data.
The second appellant thus determined and stored the first appellant's name, date of birth, and address(es) and transmitted this data to XXXX. The second appellant thus determined and stored the first appellant's name, date of birth, and address(es) and transmitted this data to roman 40.
Regarding the general information and processing purposes, XXXX stated the following:
The data of the first complainant thus obtained were recorded by XXXX in its identity and creditworthiness database ("XXXX database"), stored for forwarding, and also transmitted to third parties (customers) together with a rating score calculated by XXXX ("credit score").
The data of the first complainant thus obtained were recorded by roman 40 in its identity and creditworthiness database ("roman 40 database"), stored for forwarding, and also transmitted to third parties (customers) together with a rating score calculated by roman 40 ("credit score").
1.7. The first appellant was not individually informed that the second appellant was processing his personal data, nor that this data had been transmitted to XXXX.
1.7. The first appellant was not individually informed that the second appellant was processing his personal data, nor that this data had been transmitted to roman 40.
1.8. The first appellant is not and has not had a contractual relationship with either the second appellant or XXXX. The first appellant has not personally provided his data to either the second appellant or XXXX.
2. Assessment of Evidence:
2.1. The findings under point 1.1. regarding the business licenses of the second appellant and XXXX are derived from current officially obtained extracts from the Austrian Business Information System (as of February 9, 2025, and February 13, 2025).
2.2. The findings under point 1.1. regarding the business licenses of the second appellant and Römische 40 are derived from current officially obtained extracts from the Austrian Business Information System (as of February 9, 2025, and February 13, 2025).
2.2. The findings under point 1.2. regarding the activities of XXXX, including the operation of an identity and creditworthiness database, are derived from the information provided by XXXX in the parallel proceedings. W605 2270910-1 and W605 2271598-1, the authenticity and accuracy of which (in particular also regarding the processing register of XXXX) were never in doubt during the proceedings. 2.2. The finding under 1.2. regarding the activities of roman 40, including the operation of an identity and creditworthiness database, arises from the documents submitted by the company itself in the parallel proceedings, numbers W605 2270910-1 and W605 2271598-1, the authenticity and accuracy of which (in particular also regarding the processing register of roman 40) were never in doubt during the proceedings.
2.3. The finding under points 1.3. and 1.4. concerning the agreements concluded between the second appellant and XXXX are derived from the documents submitted by the second appellant herself, the authenticity and accuracy of which have never been in doubt at any time during the proceedings. 2.3. The findings under points 1.3 and 1.4 regarding the agreements concluded between the second appellant and Römische 40 are derived from the documents submitted by the second appellant herself, the authenticity and accuracy of which have never been in doubt at any time during the proceedings.
2.4. The findings under point 1.6 regarding the processing of the aforementioned data of the first appellant by the second appellant and XXXX are based on the undisputed information provided by the second appellant on February 11, 2021, submitted by the first appellant in the context of the data protection complaint of March 15, 2021. 2.4. The findings under point 1.6 regarding the processing of the aforementioned data of the first appellant by the second appellant and roman 40 are based on the undisputed information provided by the second appellant on February 11, 2021, submitted by the first appellant in the context of the data protection complaint of March 15, 2021.
2.5. The fact that no contractual relationships existed and/or exist between the parties to the proceedings, including between the first appellant and the two respondents to his data protection complaint – the second appellant and XXXX – and that he did not himself provide his personal data in question, is undisputedly evident from the consistent submissions of both parties to the proceedings in this regard throughout the entire proceedings. This is not disputed by the second appellant. The fact that no contractual relationships existed and/or exist between the parties to the proceedings, including between the first appellant and the two respondents to his data protection complaint – the second appellant and roman 40 – and that he himself did not provide his personal data in question, is undisputedly evident from the consistent, consistent arguments of both parties throughout the proceedings. This is not disputed by the second appellant.
3. Legal Assessment:
3.1. Pursuant to Section 6 of the Federal Administrative Court Act (BVwGG), the Federal Administrative Court shall decide by a single judge, unless federal or state law provides for decisions by panels.
3.1. Pursuant to Section 6 of the Federal Administrative Court Act (BVwGG), the Federal Administrative Court shall decide by a single judge, unless federal or state law provides for decisions by panels. According to Section 27 of the Data Protection Act (DSG), the Senate therefore has jurisdiction in this case.
According to Section 28 (1) of the Administrative Court Act (VwGVG), the administrative court must resolve the case by judgment, unless the appeal is to be dismissed or the proceedings are to be discontinued. According to Section 31 (1) of the Administrative Court Act (VwGVG), decisions and orders are to be made by resolution, unless a judgment is to be made. According to Section 28 (1) of the Administrative Court Act (VwGVG), the administrative court must resolve the case by judgment, unless the appeal is to be dismissed or the proceedings are to be discontinued. According to Section 31 (1) of the Administrative Court Act (VwGVG), decisions and orders are to be made by resolution, unless a judgment is to be made.
According to Section 28, Paragraph 2 of the Administrative Court Act (VwGVG), the administrative court must decide on the merits of appeals pursuant to Article 130, Paragraph 1, Item 1 of the Federal Constitutional Court Act (B-VG) if (1) the relevant facts are established or (2) the determination of the relevant facts by the administrative court itself is in the interest of expeditiousness or involves significant cost savings. According to Section 28, Paragraph 2 of the Administrative Court Act (VwGVG), the administrative court must decide on the merits of appeals pursuant to Article 130, Paragraph 1, Item 1 of the Federal Constitutional Court Act (B-VG) if (1) the relevant facts are established or (2) the determination of the relevant facts by the administrative court itself is in the interest of expeditiousness or involves significant cost savings.
3.2. Regarding ruling point A1)
Section 39, paragraph 1 of the Administrative Procedures Act (AVG) reads as follows:
"Section 39. (1) The administrative regulations shall be authoritative for the conduct of the investigation.
(2) To the extent that the administrative regulations do not contain any instructions in this regard, the authority shall proceed ex officio and determine the course of the investigation in compliance with the provisions contained in this part. In particular, it may, ex officio or upon request, conduct an oral hearing and join several administrative cases for joint hearing and decision or separate them again. In all such procedural instructions, the authority shall be guided by considerations of the greatest possible expediency, speed, simplicity, and cost savings."
Pursuant to Section 17 of the Administrative Court Act (VwGVG) in conjunction with Section 39 (2) of the Administrative Court Act (AVG), the Administrative Court may, taking into account the greatest possible expediency, speed, simplicity, and cost savings, join several legal cases within its jurisdiction for a joint decision, provided this is possible within the scope of the allocation of cases (cf. VwGH 03.02.2022, Ra 2019/17/0115; 17.11.2015, Ra 2015/03/0058; Kolonovits/Muzak/Stöger, Verwaltungsverfahrensrecht10 Rz 276/1 and 798). Pursuant to Section 17 of the Administrative Court Act (VwGVG) in conjunction with Section 39 (2) of the Administrative Court Act (AVG), the Administrative Court may, taking into account the greatest possible expediency, speed, simplicity, and cost savings, join several legal cases within its jurisdiction for a joint decision, provided this is possible within the scope of the allocation of cases (cf. VwGH). February 3, 2022, Ra 2019/17/0115; November 17, 2015, Ra 2015/03/0058; Kolonovits/Muzak/Stöger, Administrative Procedure Law 10 (paragraphs 276/1 and 798).
The decision of the administrative court to join several administrative cases for joint hearing and decision or to separate them again constitutes a procedural decision within the meaning of Section 31 Paragraph 2 of the Administrative Court Act (VwGVG) that cannot be appealed separately and does not require a statement of reasons (cf. VwGH 17.07.2017, Ra 2017/11/0156 with reference to the comments under point 5 of the E of 30.06.2015, Ra 2015/03/0022). The decision of the administrative court to join several administrative cases for joint hearing and decision or to separate them again constitutes a procedural decision within the meaning of Section 31 Paragraph 2 of the Administrative Court Act (VwGVG) that cannot be appealed separately and does not require a statement of reasons (cf. VwGH 17.07.2017, Ra 2017/11/0156 with reference to the comments under point 5 of the E of June 30, 2015, Ra 2015/03/0022).
The parties to the proceedings are the complainant and the respondent in the administrative proceedings before the authority concerned, and they have filed an appeal against the same decision. Since both parties to the proceedings explicitly stated in their respective submissions before the Federal Administrative Court that they agreed to join the proceedings, the joinder of the proceedings in question, which were also assigned to the same judicial division of the Federal Administrative Court due to their annexation, was necessary in view of the expediency, speed, simplicity, and cost savings of the proceedings.
A joinder of the present proceedings with those pending before the Federal Administrative Court under cases W605 2270910-1 and W605 2271598-1 for decision by the same Senate, as suggested by the first appellant, is not legally possible in light of the principle of fixed allocation of cases (Article 135 para. 2, Article 87 para. 3 of the Federal Constitutional Act) (cf. Constitutional Court, November 28, 2024, E 1806/2024, 1841/2024). A joinder of the present proceedings with those under cases W605 2270910-1 and W605 2271598-1 is also not legally possible. W605 2270910-1 and W605 2271598-1 are pending before the Federal Administrative Court, for decision by the same Senate, as suggested by the first appellant, is not legally possible in light of the principle of fixed allocation of cases (Article 135, paragraph 2, and Article 87, paragraph 3, Federal Constitutional Law) (cf. Constitutional Court, November 28, 2024, E 1806/2024, 1841/2024).
3.3. On Decision Point A2)
3.3.1. The relevant provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR) are excerpted, including the heading, as follows:
Article 4 GDPR reads in part:
Definitions
1. "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
2. “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
…
7. “Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are specified by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
8. “Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
9. "Recipient" means a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be considered recipients; the processing of those data by those public authorities shall be in compliance with applicable data protection rules in accordance with the purposes of the processing;
10. "Third party" means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons authorised to process personal data under the direct authority of the controller or processor;
…
12. “Personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed;
21. “Supervisory authority” means an independent public authority established by a Member State pursuant to Article 51;
…”
Article 5 of the GDPR reads in part: Article 5 of the GDPR reads in part:
“Principles governing the processing of personal data
(1) Personal data must:
a) be processed lawfully, fairly, and in a transparent manner in relation to the data subject (“lawfulness, fairness, transparency”);
b) are collected for specified, explicit and legitimate purposes and must not be further processed in a manner incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered incompatible with the original purposes in accordance with Article 89(1) ('purpose limitation');
...
(2) The controller shall be responsible for compliance with paragraph 1 and shall be able to demonstrate compliance ('accountability').
[...]."
Article 6 of the GDPR reads in part: Article 6 of the GDPR reads in part:
"Lawfulness of processing
...
(3) Processing shall only be lawful if at least one of the following conditions is met:
a) Union law; or
b) Member State law to which the controller is subject.
The purpose of the processing must be specified in that legal basis or, with regard to the processing referred to in point (e) of paragraph 1, necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. That legal basis may contain specific provisions to adapt the application of the provisions of this Regulation, including provisions on the general conditions governing the lawfulness of processing by the controller, the types of data processed, the data subjects concerned, the entities to which the personal data may be disclosed and for what purposes, the purpose limitation, the storage period, and the processing operations and procedures to be applied, including measures to ensure lawful and fair processing. processing, such as those for other specific processing situations pursuant to Chapter IX. Union or Member State law must pursue an objective in the public interest and be proportionate to the legitimate purpose pursued. The purpose of the processing must be specified in that legal basis or, as regards the processing referred to in point (e) of paragraph 1, it must be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. That legal basis may contain specific provisions to adapt the application of the rules of this Regulation, including provisions on the general conditions governing the lawfulness of processing by the controller, the types of data processed, the data subjects concerned, the entities to which and for which purposes the personal data may be disclosed, the purpose limitation, the storage period and the processing operations and procedures that may be used, including measures to ensure lawful and fair processing, such as those for other specific processing situations pursuant to Chapter IX. Union or Member State law must pursue an objective in the public interest and be proportionate to the legitimate purpose pursued.
(4) Where processing for a purpose other than that for which the personal data were collected is not based on the data subject's consent or on a Union or Member State law which, in a democratic society, constitutes a necessary and proportionate measure to safeguard the objectives referred to in Article 23(1), the controller shall, in order to determine whether processing for another purpose is compatible with that for which the personal data were initially collected, take into account, inter alia,
a) any link between the purposes for which the personal data were collected and the purposes of the intended further processing;
b) the context in which the personal data were collected, in particular as regards the relationship between the data subjects and the controller;
c) the nature of the personal data, in particular whether special categories of personal data pursuant to Article 9 are being processed or whether personal data relating to criminal convictions and offenses are being processed; are processed pursuant to Article 10,
d) the possible consequences of the intended further processing for the data subjects,
e) the existence of appropriate safeguards, which may include encryption or pseudonymization."
Article 51 GDPR reads: Article 51, GDPR reads:
"Supervisory authority
(1) Each Member State shall provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation, in order to protect the fundamental rights and freedoms of natural persons with regard to processing and to facilitate the free flow of personal data within the Union (hereinafter "supervisory authority").
(2) Each supervisory authority shall contribute to the consistent application of this Regulation throughout the Union. To that end, the supervisory authorities shall cooperate with each other and with the Commission in accordance with Chapter VII.
(2) Each supervisory authority shall contribute to the consistent application of this Regulation throughout the Union. To that end, the supervisory authorities shall cooperate with each other and with the Commission in accordance with Chapter VII. …“
Article 57 of the GDPR reads in part: Article 57 of the GDPR reads in part:
“Tasks
(1) Without prejudice to other tasks set out in this Regulation, each supervisory authority shall, within its territory,
a) monitor and enforce the application of this Regulation;
…
h) conduct investigations into the application of this Regulation, including on the basis of information from another supervisory authority or public authority;
…“
Article 58 of the GDPR reads: Article 58 of the GDPR reads:
“Powers
(1) Each supervisory authority shall have all of the following investigative powers, allowing it to:
a) order the controller, the processor and, where applicable, the representative of the controller or processor, to provide all information necessary for the performance of its tasks;
b) conduct investigations in the form of data protection audits carry out,
c) conduct a review of the certifications issued pursuant to Article 42(7);
d) draw the controller's or processor's attention to an alleged infringement of this Regulation;
e) obtain from the controller and processor access to all personal data and information necessary to perform their tasks;
f) obtain access to the premises, including all data processing facilities and equipment, of the controller and processor in accordance with Union or Member State procedural law.
(2) Each supervisory authority shall have all of the following remedial powers, allowing it to:
a) warn a controller or processor that intended processing operations are likely to infringe this Regulation;
b) warn a controller or processor when processing operations infringe this Regulation; has,
c) to order the controller or processor to comply with requests from the data subject to exercise their rights under this Regulation,
d) to order the controller or processor to bring processing operations into compliance with this Regulation, where appropriate, in a specified manner and within a specified period,
e) to order the controller to communicate a personal data breach to the data subject accordingly,
f) to impose a temporary or definitive restriction of processing, including a prohibition,
g) to order the rectification or erasure of personal data or the restriction of processing in accordance with Articles 16, 17 and 18 and to inform recipients to whom those personal data have been disclosed pursuant to Article 17(2) and Article 19 of such measures,
h) to withdraw a certification or to order the certification body to withdraw a certification issued pursuant to Articles 42 and 43 revoke a certification granted or instruct the certification body not to issue a certification if the conditions for certification are not or no longer met;
i) impose a fine in accordance with Article 83, in addition to or instead of the measures referred to in this paragraph, depending on the circumstances of the case;
j) order the suspension of the transfer of data to a recipient in a third country or to an international organization.
[…]
(4) The exercise of the powers conferred on the supervisory authority pursuant to this Article shall be subject to appropriate safeguards, including effective judicial remedies and due process, in accordance with Union and Member State law in accordance with the Charter.
Article 77 GDPR reads:
"Right to lodge a complaint with a supervisory authority
(1) Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a Supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement, if the data subject considers that the processing of personal data concerning them infringes this Regulation.
(2) The supervisory authority with which the complaint has been lodged shall inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy pursuant to Article 78.
The relevant provisions of the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act - DSG), as amended by Federal Law Gazette I No. 24/2018, read in extracts, including the heading, as follows:
Section 24 of the Data Protection Act reads in extracts: Paragraph 24, DSG reads Excerpt:
"Complaint to the Data Protection Authority
Section 24. (1) Every data subject has the right to lodge a complaint with the Data Protection Authority if they believe that the processing of personal data concerning them violates the GDPR or Section 1 or Article 2, Chapter 1."
Section 24. (1) Every data subject has the right to lodge a complaint with the Data Protection Authority if they believe that the processing of personal data concerning them violates the GDPR or Section 1 or Article 2, Chapter 1." The relevant sections 151 and 152 of the Trade Regulation Act 1994 (GewO 1994), Federal Law Gazette I No. 111/2002, read together with the heading: The relevant sections 151 and 152 of the Trade Regulation Act 1994 (GewO 1994), Federal Law Gazette Part One, No. 111 of 2002, read together with the heading:
"Address publishers and direct marketing companies
Section 151 (1) The use of personal data for third-party marketing purposes by traders authorized to carry out the business of address publishers and direct marketing companies is subject to the provisions of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), OJ L 199 of 4.5.2016 S 1, (hereinafter: GDPR), as well as the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act - DSG), Federal Law Gazette I No. 165/1999, as amended by Federal Law Gazette I No. 120/2017, shall apply, unless otherwise stipulated below. Paragraph 151, (1) The use of personal data for third-party marketing purposes by traders authorized to carry out the business of address publishers and direct marketing companies shall be subject to the provisions of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), OJ No. L 199 of 4.5.2016 S 1, (hereinafter: GDPR), as well as the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act - DSG), Federal Law Gazette Roman 1st No. 165 of 1999,, as amended by Federal Law Gazette Roman 1st No. 120 of 2017,, shall apply unless otherwise stipulated below.
(2) The activity as an intermediary between owners and users of customer and prospective customer file systems (list broking) is reserved for the traders referred to in paragraph 1. (2) The activity as an intermediary between owners and users of customer and prospective customer file systems (list broking) is reserved for the traders referred to in paragraph 1.
(3) The traders referred to in paragraph 1 are entitled to obtain personal data for their activities pursuant to paragraphs 1 and 2 from publicly available information, by interviewing the data subjects, from customer and prospective customer file systems of third parties, or from the marketing file systems of other address publishers and direct marketing companies, insofar as this is necessary in compliance with the principle of proportionality for (3) The traders referred to in paragraph 1 are entitled to obtain personal data for their activities pursuant to paragraph 1 and 2, to obtain personal data from publicly available information, by interviewing the data subjects, from customer and prospective customer file systems of third parties, or from marketing file systems of other address publishers and direct marketing companies, insofar as this is necessary and permissible in accordance with paragraphs 4 and 5, in compliance with the principle of proportionality, for
1. the preparation and implementation of third-party marketing campaigns, including the design and dispatch of advertising materials, or
2. list broking
and is permissible in accordance with paragraphs 4 and 5.
(4) To the extent that special categories of personal data pursuant to Art. 9 (1) GDPR are affected, these may be processed by the traders referred to in paragraph 1, provided that the data subject has given their express consent to the processing of these data for third-party marketing purposes. The acquisition and further processing of special categories of personal data from customer and prospective customer file systems of third parties based on such consent is only permissible to the extent of paragraph 5 and only to the extent that the owner of the file system has declared its absence of objections to the trader in writing in accordance with paragraph 1. that the data subjects have expressly consented to the processing of their data for third-party marketing purposes. Criminally relevant data within the meaning of Article 10 GDPR may only be processed for marketing purposes by traders pursuant to paragraph 1 in accordance with Section 4 paragraph 3 DSG or if explicit consent has been given. (4) Insofar as special categories of personal data pursuant to Article 9 paragraph 1 GDPR are affected, these may be processed by the traders named in paragraph 1, provided that the data subject has expressly consented to the processing of this data for third-party marketing purposes. The identification and further processing of special categories of personal data from third-party customer and prospective customer file systems on the basis of such consent is only permissible to the extent of paragraph 5 and only to the extent that the owner of the file system has declared in writing to the trader pursuant to paragraph 1 that the data subjects have expressly consented to the processing of their data for third-party marketing purposes. Criminally relevant data within the meaning of Article 10 GDPR may only be processed for marketing purposes by traders pursuant to paragraph 1 in accordance with paragraph 4 paragraph 3. DSG or if there is express consent.(5) Unless the data subjects have given their consent pursuant to Article 4(11) GDPR to the transmission of their data for third-party marketing purposes, the traders referred to in paragraph 1 may only obtain the following data from a third-party customer and prospect filing system:
1. Name,
2. Gender,
3. Title,
4. Academic degree,
5. Address,
6. Date of birth,
7. Professional, industry, or business title, and
8. Affiliation of the data subject to this customer and prospect filing system. The prerequisite for this – unless the stricter provisions of paragraph 4 apply – is that the owner of the filing system has declared to the trader in writing, without objection, in accordance with paragraph 1, that the data subjects have been appropriately informed of the possibility of prohibiting the transmission of their data for third-party marketing purposes, and that no prohibition has been issued. The prerequisite for this is – unless the stricter provisions of paragraph 4 apply – that the owner of the filing system has declared to the trader in writing, without objection, in accordance with paragraph 1, that the data subjects have been appropriately informed of the possibility of prohibiting the transmission of their data for third-party marketing purposes, and that no prohibition has been issued.
(6) Business operators pursuant to paragraph 1 may use marketing information and classifications collected for marketing purposes that are attributed to specific individuals based on marketing analysis procedures only for marketing purposes and, in particular, may only transmit them to third parties if the latter unequivocally declare that they will use these analysis results exclusively for marketing purposes. (6) Business operators pursuant to paragraph 1 may use marketing information and classifications collected for marketing purposes that are attributed to specific individuals based on marketing analysis procedures only for marketing purposes and, in particular, may only transmit them to third parties if the latter unequivocally declare that they will use these analysis results exclusively for marketing purposes.
(7) Business operators pursuant to paragraph 1 must design mailings in the course of marketing campaigns which they carry out using personal data provided by them or transmitted by them in such a way that, through appropriate labelling of the sent advertising material, the identity of the persons responsible for the filing systems with whose data the advertising mailing was addressed (source filing systems) can be traced; insofar as business operators pursuant to paragraph 1 only participate in advertising mailings by making data available or transmitting data, they must ensure that the identity of the persons responsible for the source filing systems used can be traced by providing appropriate information to the persons responsible for the advertising mailing. For traders as per paragraph 1, if they themselves carried out the mailing using data they provided or mediated, Art. 15 GDPR applies – without prejudice to their possible obligations to provide information as controllers – with the proviso that, based on a request for information made within three months of the advertising mailing, they are only obliged to provide information about the controllers of the original filing systems based on the information about the advertising mailing provided by the data subject; if they only participated in the mailing by making data available or mediating it, they must, if possible, contribute to locating the controllers of the original filing systems. If traders fail to properly comply with the labelling requirement pursuant to paragraph 1, it is sufficient to submit a timely request for information to the advertiser to safeguard the right to information vis-à-vis the trader pursuant to paragraph 1.(7) Traders pursuant to paragraph 1 must design mailings carried out as part of marketing campaigns using personal data provided or transmitted by them in such a way that the identity of the controllers of the file systems with whose data the advertising mailing was addressed (source file systems) can be traced through appropriate labelling of the sent advertising material; insofar as traders pursuant to paragraph 1 only participate in advertising mailings by making data available or transmitting data, they must ensure that the identity of the controllers of the source file systems used can be traced by providing appropriate information to those responsible for the advertising mailing. For traders as per paragraph 1, if they themselves carried out the mailing using data provided by them or mediated by them, Article 15 of the GDPR applies - without prejudice to their possible obligation to provide information as controllers - with the proviso that, on the basis of a request for information made within three months of the advertising mailing, they are only obliged to provide information about the controllers of the original filing systems on the basis of the information about the advertising mailing provided by the data subject; if they only participated in the mailing by making data available or mediating it, they must, if possible, contribute to locating the controllers of the original filing systems. If traders fail to properly comply with the labeling obligation pursuant to paragraph 1, submitting a timely request for information to the advertiser shall be sufficient to safeguard the right to information vis-à-vis the trader pursuant to paragraph 1.
(8) If the data subject submits a request to a trader pursuant to paragraph 1 for the erasure of data that the trader has stored about them for the purposes of marketing campaigns, the trader must comply with the data subject's request promptly and, in any event, within one month and free of charge (Article 12 (3) GDPR). This period may be extended by a further two months if necessary, taking into account the complexity and number of requests. If the data subject – after being informed of the possible consequences of physically deleting their data – does not insist on the physical deletion of their data, the deletion must take the form of blocking the use of this data for marketing purposes. (8) If the data subject requests the deletion of data stored about them for marketing purposes pursuant to paragraph 1, the business operator must comply with the data subject's request promptly, and in any event within one month, free of charge (Article 12, paragraph 3, GDPR). This period may be extended by a further two months if necessary, taking into account the complexity and number of requests. If the data subject – after being informed of the possible consequences of physically deleting their data – does not insist on the physical deletion of their data, the deletion must take the form of blocking the use of this data for marketing purposes.
(9) The Advertising and Marketing Communications Association of the Austrian Chamber of Commerce shall maintain a list in which persons who wish to exclude themselves from the delivery of advertising material may be registered free of charge. The list shall be updated at least monthly and made available to the traders pursuant to paragraph 1. Traders pursuant to paragraph 1 may not send or distribute addressed advertising material to the persons listed in this list, nor may they disclose their data. The data contained in the list may be used exclusively for the purpose of preventing the sending of advertising material. (9) The Advertising and Marketing Communications Association of the Austrian Chamber of Commerce shall maintain a list in which persons who wish to exclude themselves from the delivery of advertising material may be registered free of charge. The list shall be updated at least monthly and made available to the traders pursuant to paragraph 1. Traders pursuant to paragraph 1 may not send or distribute addressed advertising material to the persons listed in this list, nor may they disclose their data. The data contained in the list may be used exclusively for the purpose of preventing the sending of advertising material.
(10) Owners of customer and prospective customer filing systems may only transmit personal data from these filing systems to traders pursuant to paragraph 1 for third-party marketing purposes and, in particular, may only make them available for list broking if they have appropriately informed the data subjects that they can prohibit the processing of these data for third-party marketing purposes and if no prohibition has been issued; special categories of personal data and data relevant to criminal law may be transmitted to traders pursuant to paragraph 1 and made available for list broking under the conditions set out in paragraph 4. The possibility of prohibition must be expressly indicated in writing if data is collected in writing from the data subject. The prohibition of transmission has no influence on a contractual relationship between the data subject and the owner of the customer and prospective customer file system. (10) Owners of customer and prospective customer file systems may only transmit personal data from these file systems to traders as per paragraph 1 for third-party marketing purposes and, in particular, only make them available for list broking if they have informed the data subjects in an appropriate manner that they can prohibit the processing of this data for third-party marketing purposes and if no prohibition has been issued; special categories of personal data and data relevant to criminal law may be transmitted to traders as per paragraph 1 and made available for list broking under the conditions set out in paragraph 4. The possibility of prohibition must be expressly pointed out in writing if data is collected in writing from the data subject. The prohibition of transmission has no influence on a contractual relationship between the data subject and the owner of the customer and prospective customer file system.
(11) The right of objection pursuant to Article 21 (2) GDPR may also be exercised with regard to the traders referred to in paragraph 1 by being entered in the list referred to in paragraph 9. (11) The right of objection pursuant to Article 21 (2) GDPR may also be exercised with regard to the traders referred to in paragraph 1 by being entered in the list referred to in paragraph 9.
Credit Information Agencies
Section 152 (1) Traders authorised to carry out the business of providing credit information on credit relationships are not authorised to provide information on private circumstances that are unrelated to creditworthiness.
Section 152 (1) Traders authorised to carry out the business of providing credit information on credit relationships are not authorised to provide information on private circumstances that are unrelated to creditworthiness. (2) The traders referred to in paragraph 1 are obligated to retain their business correspondence and business records for seven years. The seven-year period begins at the end of the calendar year in which the correspondence took place or the last entry was made in the business records. In the event of termination of the trade license, the correspondence and business records must be destroyed, even if the seven-year period has not yet expired. (2) The traders referred to in paragraph 1 are obligated to retain their business correspondence and business records for seven years. The seven-year period begins at the end of the calendar year in which the correspondence took place or the last entry was made in the business records. In the event of termination of the trade license, the correspondence and business records must be destroyed, even if the seven-year period has not yet expired.
3.3.2. On the dismissal of the second appellant’s appeal against the decision with regard to point 1. a) of the contested decision (upholding the data protection appeal concerning the alleged violation of the principle of purpose limitation pursuant to Art. 5 (1) (b) GDPR by the second appellant): 3.3.2. Regarding the dismissal of the second appellant's appeal against the decision with regard to point 1. a) of the contested decision (upholding the data protection appeal regarding the alleged violation of the principle of purpose limitation pursuant to Article 5, paragraph 1, letter b, GDPR by the second appellant):
According to the case law of the European Court of Justice, any processing of personal data must, in principle, comply with the principles set out in Article 5 GDPR with regard to the processing of personal data and one of the principles set out in Article 6 GDPR with regard to the lawfulness of the processing of data (ECJ 4 May 2023, C-60/22, Federal Republic of Germany [Electronic Court File], ECLI:EU:C:2023:373, paras. 50, 52, 57, with further references; already with regard to the predecessor provision of Article 6 of the Data Protection Directive: ECJ 20 May 2003, consolidated case law C-465/00, C-138/01 and C-139/01, Österreichischer Rundfunk and others, para. 65; 16.12.2008, C-524/06, Huber, para. 48; see also VwGH 09.05.2023, Ro 2020/04/0037). Furthermore, in the Meta Platforms Inc. case, the ECJ held that, under Article 5 GDPR, the controller bears the burden of proof that the data are collected for specified, explicit, and legitimate purposes and processed lawfully, fairly, and in a transparent manner for the data subject (ECJ 4 July 2023, C-252/21 (Meta Platforms Inc.), para. 95). According to the case law of the European Court of Justice, any processing of personal data must, in principle, comply with the principles set out in Article 5 GDPR regarding the processing of personal data and one of the principles set out in Article 6 GDPR regarding the lawfulness of data processing (ECJ 4 May 2023, C-60/22, Federal Republic of Germany [Electronic Court File], ECLI:EU:C:2023:373, paras. 50, 52, 57, with further references, already on the predecessor provision Article 6, DS-RL: ECJ 20.05.2003, joined Cases C-465/00, C-138/01 and C-139/01, Österreichischer Rundfunk et al., para. 65; 16.12.2008, C-524/06, Huber, para. 48; compare also VwGH 09.05.2023, Ro 2020/04/0037). Furthermore, in the Meta Platforms Inc. case, the ECJ held that, under Article 5 of the GDPR, the controller bears the burden of proof that the data are collected for specified, explicit, and legitimate purposes and processed lawfully, fairly, and in a transparent manner in relation to the data subject (ECJ July 4, 2023, C-252/21 (Meta Platforms Inc.), para. 95).
Article 5(1) sets out the principles for the processing of personal data that apply to the controller, compliance with which the controller must be able to demonstrate in accordance with the principle of accountability set out in Article 5(2) of this Regulation. In particular, pursuant to Article 5(1)(b), which provides for the principle of "purpose limitation," personal data must, firstly, be collected for specified, explicit, and legitimate purposes and, secondly, must not be further processed in a manner incompatible with those purposes. Article 5, paragraph 1, sets out the principles for the processing of personal data that apply to the controller, compliance with which the controller must be able to demonstrate in accordance with the principle of accountability set out in Article 5, paragraph 2 of this Regulation. In particular, according to Article 5, paragraph 1, letter b, which sets out the principle of "purpose limitation," personal data must, first, be collected for specified, explicit, and legitimate purposes and, second, not be further processed in a manner incompatible with those purposes.
It is therefore clear from the wording of this provision that it contains two requirements: one relating to the purposes for which the personal data were originally collected and one relating to the further processing of those data. First, as regards the requirement that personal data must be collected for specified, explicit and legitimate purposes, according to the case-law of the Court, this means that the purposes of the processing must be established at the latest at the time the personal data are collected, that the purposes of that processing must be clearly stated and that the purposes of that processing must, in particular, ensure the lawfulness of the processing of the data concerned within the meaning of Article 6(1) (see ECJ of 20 October 2022, C-77/21, EU: C:2022:805; paragraphs 24 to 27). It follows from the wording of that provision that it contains two requirements, one relating to the purposes of the initial collection of the personal data and one relating to the further processing of those data. First, regarding the requirement that personal data must be collected for specified, explicit, and legitimate purposes, according to the Court's case law, this means that the purposes of the processing must be established at the latest at the time the personal data are collected, that the purposes of that processing must be clearly stated, and that the purposes of that processing must, in particular, ensure the lawfulness of the processing of the data concerned within the meaning of Article 6(1) (see ECJ of 20 October 2022, C-77/21, EU: C:2022:805; paragraphs 24 to 27).
According to Article 5(1)(b), data may only be collected for "legitimate" purposes. Accordingly, the processing of the data for the purposes in question must be legally permissible; i.e. there must be a relevant legal basis for them, and processing for these purposes must not violate applicable legal norms (not only data protection law) (Herbst in Kühling/Buchner, DS-GVO/BDSG4, Commentary, Art. 5 GDPR, para. 36). Art. 5 (1) (b) GDPR does not specify the conditions under which further processing of personal data can be considered compatible with the purposes for which the data was originally collected. It follows from Art. 5 (1) (b), Art. 6 (1) (a) and Art. 6 (4) that the question of the compatibility of further processing of personal data with the purposes for which it was originally collected only arises if the purposes of this further processing do not coincide with those of the original collection. According to Article 5, paragraph 1, letter b, data may only be collected for "legitimate" purposes. Accordingly, the processing of the data for the purposes in question must be legally permissible; This means that there must be a relevant legal basis for them, and the processing for these purposes must not violate applicable legal norms (not only data protection law) (Herbst in Kühling/Buchner, DS-GVO/BDSG4, Commentary, Article 5, GDPR, para. 36). Article 5, paragraph 1, letter b, GDPR does not specify the conditions under which further processing of personal data can be considered compatible with the purposes for which the data was originally collected. It follows from Articles 5, paragraph 1, letter b, Article 6, paragraph 1, letter a, and Article 6, paragraph 4, that the question of the compatibility of the further processing of personal data with the purposes for which they were originally collected only arises if the purposes of this further processing do not coincide with those of the original collection.
As correctly stated by the competent authority in the contested decision, the second complainant had collected data from the first complainant and transmitted it to XXXX under a contractual agreement. As correctly stated by the authority concerned in the contested decision, the second appellant had collected data from the first appellant and transmitted it to roman 40 within the framework of a contractual agreement.
As can be seen from the findings, these are the name of the first complainant (before the change in connection with his marriage), his date of birth, and his (partially historical) address(es). These each constitute personal data, as Art. 4(1) GDPR defines "any information relating to an identified or identifiable person," which is undisputedly the case with the aforementioned data (cf. Hödl in Knyrim, DatKomm Art. 4 GDPR, para. 9 | as of December 1, 2018, rdb.at). As can be seen from the findings, these are the name of the first complainant (before the change in connection with his marriage), his date of birth, and his (partially historical) address(es). These each constitute personal data, as Article 4, paragraph 1, GDPR defines "any information relating to an identified or identifiable natural person" as such, which is undisputedly the case with the data mentioned (cf. Hödl in Knyrim, DatKomm Article 4, GDPR, para. 9 | as of December 1, 2018, rdb.at).
In its decision regarding the data collection by the second appellant, the authority concerned stated that the latter, within the scope of its trade license pursuant to Section 151 of the Trade Regulation Act 1994 (GewO 1994), had collected data from the first appellant as an address publishing and direct marketing company and transmitted it to XXXX. The purpose of the data processing, including with regard to further use and transmission to third parties, was therefore limited to marketing purposes pursuant to Section 151, paragraph 6 of the Trade Regulation Act 1994 (GewO 1994). However, this is merely a commercial law norm; the (further) processing of the first complainant's data by transmission to XXXX is to be assessed under Art. 6 (1) in conjunction with (4) GDPR, which does not provide for an opening clause for national legislators in this case. In its decision regarding the data collection by the second complainant, the authority concerned stated that the second complainant had collected the first complainant's data within the scope of its trade license pursuant to Section 151 of the Trade Regulation Act 1994 as an address publishing and direct marketing company and transmitted it to roman 40. The purpose of the data processing, including with regard to further use and transmission to third parties, is therefore limited to marketing purposes pursuant to Section 151, Paragraph 6 of the Trade Regulation Act 1994. However, this is merely a commercial law provision, and the (further) processing of the first complainant's data by transmission to the Roman 40 is to be assessed under Article 6, paragraph 1, in conjunction with paragraph 1, of the GDPR, which does not provide for an opening clause for national legislators.
In her complaint, the second appellant essentially counters this by arguing that the first appellant cannot invoke Article 5(2) GDPR because it does not contain any subjective right of the data subject and, secondly, that the agreement between her and XXXX, as amended on 25 May 2018, prohibits the use of the data by the latter for creditworthiness purposes and generally outside of marketing purposes and that since then there has been a clear purpose for the transmitted data to be used for marketing purposes for XXXX as an address publisher. In her complaint, the second appellant essentially counters this by arguing that the first appellant cannot invoke Article 5(2) GDPR because it does not contain any subjective right of the data subject and, secondly, that the agreement between her and roman 40, as amended on 25 May 2018, prohibits the use of the data by the latter for creditworthiness purposes and generally outside of marketing purposes. prohibits and since then, the transmitted data has been clearly earmarked for marketing purposes for roman 40 as an address publisher.
However, the first appellant countered this in his statement of June 14, 2024, stating that although section 2.1, paragraph 1, of that addendum indeed refers to "marketing purposes of XXXX," paragraphs 2 and 3, however, mention "purposes of correcting and/or supplementing XXXX's data records" and "other purposes for which XXXX is authorized to process the data by law." Since XXXX and the second appellant mistakenly considered the data processing in question to be lawful, this could be precisely the data processing that is meant, and it is therefore very doubtful whether the addendum, which entered into force on May 25, 2018, actually resulted in a relevant change. Furthermore, in its appeal against the decision in the proceedings under reference W605 2271598-1, XXXX itself emphasized that it had not processed the data for advertising purposes, but had always collected it for the purpose of credit assessment, whereas the first appellant had stated in civil court proceedings concerning the data processing at issue here that it had always provided the data for the purposes of credit assessment by a credit agency. Regarding the objection that Art. 5 (2) GDPR does not contain a subjective right of the data subject, reference was made to the case law of the Administrative Court (decision of March 6, 2024, Ro 2021/04/0030), which contradicted this. However, the first appellant replied to this in his statement of June 14, 2024, stating that in that addendum, point 2.1. in paragraph 1. it does indeed refer to “marketing purposes of roman 40”, but in paragraphs 2 and 3 “purposes of correcting and/or supplementing the data records of roman 40” and “other purposes for which roman 40 is entitled to process the data due to statutory provisions” are mentioned. Since roman 40 and the second complainant wrongly regarded the data processing in question as being in compliance with the law, this could be precisely the data processing that is meant and it is therefore very doubtful whether the addendum that came into force on May 25, 2018 actually led to a relevant change. Moreover, in its appeal against the decision to the hg. In the proceedings relating to Ref. No. W605 2271598-1, the complainant itself emphasized that the data had not been processed for advertising purposes, but had always been collected for the purpose of credit assessment, while the first complainant stated in civil court proceedings concerning the data processing operations at issue here that the data had always been provided to a credit agency for the purposes of credit assessment. Regarding the objection that Article 5, Paragraph 2, GDPR does not contain a subjective right of the data subject, reference was made to the case law of the Administrative Court (decision of March 6, 2024, Ro 2021/04/0030), which contradicted this.
The following should be stated in this regard:
First of all, the first complainant rightly argues that the Higher Administrative Court, with reference to the case law of the European Court of Justice (judgment of June 22, 2023, C-579/21, J.M.) and the prevailing legal opinion, recently ruled that Article 77(1) GDPR, according to its wording, does not refer to a violation of rights, but rather to a violation of the GDPR by data processing. This, however, does not contradict the assumption that violations of the principles of Article 5(1) GDPR can be asserted in isolation in a complaint under Article 77 GDPR, provided that this violation concerns the processing of personal data concerning the complainant (VwGH March 6, 2024, Ro 2021/04/0030, with further references). The ECJ has also upheld this in its most recent case law, stating that Article 77 GDPR is sufficiently clear, precise and unconditional and thus directly applicable (cf. ECJ 16.01.2024, C-33/22, Austrian Data Protection Authority, para. 62). First of all, the first complainant rightly argues that the Administrative Court, with reference to the case law of the European Court of Justice (judgment of 22.06.2023, C-579/21, J.M.) and the prevailing legal opinion, recently ruled that Article 77, paragraph 1, GDPR, according to its wording, does not refer to a violation of rights, but rather to a violation of the GDPR by data processing. This, however, does not contradict the assumption that violations of the principles of Article 5, paragraph 1, GDPR can be asserted in isolation in a complaint under Article 77, GDPR, provided that this violation affects the processing of data concerning the complainant. personal data (VwGH March 6, 2024, Ro 2021/04/0030, with further references). The ECJ has also upheld this in its recent case law, stating that Article 77 of the GDPR is sufficiently clear, precise, and unconditional and thus directly applicable (cf. ECJ January 16, 2024, C-33/22, Austrian Data Protection Authority, para. 62).
The authority concerned was therefore right to base its proceedings on the relevant arguments in the first complainant's data protection complaint and to address them in the contested decision.
In the matter: As already explained above, the second complainant collected the first complainant's personal data for marketing purposes and transmitted them to XXXX. There is no connection between the original purpose (marketing purposes) for which the first complainant's personal data was collected and the purpose of the further processing (credit assessment purpose). The further processing for credit assessment purposes by XXXX clearly deviates from the legitimate expectations of the data subject regarding the further use of their data. While an address publisher and direct marketing company collects personal data purely for marketing purposes, the same data is used by a credit agency to provide its contractual partners with information about the creditworthiness of their potential customers. In substance: As already explained above, the second complainant collected the personal data of the first complainant for marketing purposes and transmitted it to roman 40. There is no connection between the original purpose (marketing purposes) for which the personal data of the first complainant was collected and the purpose of the further processing (credit assessment purpose). The further processing for credit assessment purposes by roman 40 clearly deviates from the legitimate expectations of the data subject regarding the further use of their data. While an address publisher and direct marketing company collects personal data purely for marketing purposes, a credit agency uses the same data to provide its contractual partners with information about the creditworthiness of their potential customers.
While the second appellant refers to the wording of the addendum dated May 25, 2018, to its agreement with XXXX, which no longer expressly provides for the further processing of the transmitted data for credit assessment purposes, the first appellant rightly counters that further processing has now also been agreed upon for "other purposes for which [the second appellant] and/or XXXX is authorized to process the data under statutory provisions." Because of the use of the term "and/or," it can be assumed that the data transmission may also be carried out for the purposes of credit assessment, which is covered by the credit agency's business license pursuant to Section 152 of the German Trade Regulation Act (GewO), which XXXX holds. It is therefore not apparent from the aforementioned provision that the second appellant could assume that the personal data it transmitted to XXXX, a company that operates not only as an address publisher and direct marketing company but also as a credit agency, would not also be used for credit assessment purposes. While the second appellant refers to the wording of the addendum of 25 May 2018 to its agreement with roman 40, which no longer expressly provides for the further processing of the transmitted data for credit assessment purposes, the first appellant rightly counters that the further processing was now also agreed for "other purposes for which [the second appellant] and/or roman 40 is entitled to process the data under statutory provisions." Because of the use of the term "and/or," it can be assumed that the data transfer may also be carried out for the purposes of credit assessment, which is covered by the credit agency's business license pursuant to Section 152 of the German Trade Regulation Act (GewO), which roman 40 holds. It is therefore not apparent from this provision that the second appellant could assume that the personal data it transferred to roman 40, a company that operates not only as an address publisher and direct marketing company but also as a credit agency, would not also be used for credit assessment purposes.
This conclusion is not changed by the letter from the Federal Ministry of Labour and Economic Affairs dated November 29, 2022, submitted by the second appellant as an attachment to its written submission of March 9, 2023, since, on the one hand, it only makes statements on the scope of the business – i.e., a commercial law perspective – of address publishers and direct marketing companies pursuant to Section 151 of the German Trade Regulation Act (GewO), and, on the other hand, “Customer Relationship Management (CRM)”, as the name already implies, is only suitable for managing data of its own customers – including potential customers with whom no contractual relationship yet exists – whereas, as established, the first appellant has never had and never has a business relationship with the second appellant and/or XXXX, and there has been no indication that they intended to enter into a business relationship with him. The letter from the Federal Ministry of Labor and Economics dated November 29, 2022, submitted by the second appellant as an attachment to its written submission of March 9, 2023, does not change this conclusion. It does not, on the one hand, contain statements on the scope of the business – i.e., a commercial law perspective – of address publishers and direct marketing companies pursuant to Section 151 of the German Trade Regulation Act (GewO), and, on the other hand, "Customer Relationship Management (CRM)," as the name implies, is only applicable to the management of data of its own customers – including potential customers with whom no contractual relationship yet exists. However, as established, the first appellant has never had or has never had a business relationship with the second appellant and/or roman 40, and there has been no indication that they intended to enter into a business relationship with him.
It should be noted that it is also unclear to what extent the data in question of the first complainant constitutes marketing information and classifications pursuant to Section 151 (6) of the Trade Regulation Act (GewO), since these data are determined as a result of statistical evaluations and attributed to specific individuals based on marketing analysis procedures (Riesz in Ennöckl/Raschauer/WesselCRIF, GewO Section 151, para. 28 | as of January 1, 2015, rdb.at). Furthermore, the Federal Ministry of Labor and Economic Affairs itself states in its letter (on page 3) that the aforementioned activities could be carried out (only) "in compliance with the provisions of the General Data Protection Regulation," which once again highlights the necessary distinction between the scope of a trade license under the GewO and data protection regulations, which traders must also observe when carrying out their business. It should be noted that it is also unclear to what extent the data in question of the first complainant constitutes marketing information and classifications pursuant to Section 151, Paragraph 6, of the Trade Regulation Act (GewO), since these are determined as a result of statistical evaluations and attributed to specific individuals based on marketing analysis procedures (Riesz in Ennöckl/Raschauer/WesselCRIF, GewO Paragraph 151, Rz 28 | as of January 1, 2015, rdb.at). Furthermore, the Federal Ministry of Labor and Economic Affairs itself states in its letter (at its third meeting) that the aforementioned activities could be carried out (only) "in compliance with the provisions of the General Data Protection Regulation," which once again highlights the necessary distinction between the scope of a trade license under the GewO and data protection regulations, which traders must also observe when carrying out their business.
By transmitting the data obtained as an address publisher and direct marketing company, which may only be collected and transmitted for marketing purposes under statutory provisions, to XXXX without being able to assume that the latter would use the data exclusively for marketing purposes, the second appellant violated the principle of purpose limitation. By transmitting the data obtained as an address publisher and direct marketing company, which may only be collected and transmitted for marketing purposes under statutory provisions, to Roman 40 without being able to assume that the latter would use the data exclusively for marketing purposes, the second appellant violated the principle of purpose limitation.
Regarding the recourse by controllers to data purchased from address publishers to correct incorrect or inaccurate data – which does not appear at all unreasonable in light of the principle of data accuracy – it should be noted that the second appellant has not argued that the transmission of the first appellant's personal data was merely for the purpose of correcting data records that XXXX already had from him, and no other indications have emerged in this regard. Regarding the recourse by controllers to data purchased from address publishers to correct incorrect or inaccurate data – which does not appear at all unreasonable in light of the principle of data accuracy – it should be noted that the second appellant has not argued that the transmission of the first appellant's personal data was merely for the purpose of correcting data records that Roman 40 already had from him, and no other indications have emerged in this regard.
The authority concerned's finding regarding point 1.a) of the contested decision was therefore correct.
3.3.3. Regarding the dismissal of the second appellant's appeal regarding point 1.b) of the contested decision (upholding the data protection appeal regarding the alleged violation of the principle of lawfulness of data processing pursuant to Article 5(1)(a) in conjunction with Article 6(1) GDPR by the second appellant): 3.3.3. Regarding the dismissal of the second appellant's appeal against the decision with regard to point 1.b) of the contested decision (upholding the data protection appeal regarding the alleged violation of the principle of lawfulness of data processing pursuant to Article 5(1)(a) in conjunction with Article 6(1) GDPR by the second appellant):
The authority concerned essentially bases its decision on the fact that, in this case, a violation of law arises from the fact that the unlawfulness of the original collection and transmission of the personal data in question by the second appellant was established pursuant to Article 5(1)(b) and Article 6(1) in conjunction with Article 4 GDPR, which is why – with reference to Article 17(1)(d) GDPR – the subsequent unlawfulness of the data processing by the second appellant as the recipient of these same personal data had to be established. Essentially, the authority concerned bases its decision on the fact that in this case a violation of law arises from the fact that the unlawfulness of the original collection and transmission of the personal data in question by the second complainant was established pursuant to Article 5, paragraph one, letter b and Article 6, paragraph one, in conjunction with Article 4 GDPR, which is why – with reference to Article 17, paragraph one, letter d, GDPR – the subsequent inadmissibility of the data processing by the second complainant as the recipient of these same personal data had to be established.
The opinion of the respondent authority is thus consistent with the ECJ case law cited above and the prevailing opinion in the literature, according to which any processing of personal data must comply with the principles set out in Art. 5 GDPR regarding the processing of personal data and one of the principles set out in Art. 6 GDPR regarding the lawfulness of data processing, i.e., these principles must be met cumulatively. Since a violation of Article 5 GDPR was already established due to the non-compliance with the purpose limitation principle, an examination of the legality pursuant to Article 6 (1) GDPR can also be left open, since the data processing (transfer) was therefore, at least in its outcome, unlawful. The opinion of the authority concerned is thus consistent with the case law of the ECJ already cited above and the prevailing opinion in the literature, according to which any processing of personal data must comply with the principles set out in Article 5 GDPR with regard to the processing of personal data and one of the principles set out in Article 6 GDPR with regard to the lawfulness of data processing; thus, these principles must be met cumulatively. Since a violation of Article 5 GDPR was already established due to the non-compliance with the purpose limitation principle, an examination of the legality pursuant to Article 6 (1) GDPR can also be left open, since the data processing (transfer) was, at least in its outcome, unlawful.
The authority's finding regarding point 1.b) of the contested decision was therefore also correct.
3.3.4. Regarding the dismissal of the first appellant's appeal against point 2 of the contested decision (rejection of his application for a processing ban pursuant to Art. 58 (2) (f) GDPR): 3.3.4. Regarding the dismissal of the first appellant's appeal against point 2 of the contested decision (rejection of his application for a processing ban pursuant to Article 58, paragraph 2, letter f, GDPR):
With point 2 of the contested decision, the respondent authority rejected the first appellant's application to issue a data processing ban against the second appellant, according to which "personal data may not be transmitted to third parties if the second appellant knows or should know that these third parties will further process the data for credit assessment purposes in accordance with Section 152 of the Trade Regulation Act 1994." With point 2 of the contested decision, the respondent authority rejected the first appellant's application to issue a data processing ban against the second appellant, according to which "personal data may not be transmitted to third parties if the second appellant knows or should know that these third parties will further process the data for credit assessment purposes in accordance with Section 152, GewO 1994."
According to the consistent case law of the Administrative Court, if the respondent authority has rejected an application in the first instance, the appeal proceedings are solely concerned with the question of the legality of the rejection. In such a case, the administrative court has exclusive jurisdiction to decide whether the rejection issued by the respondent authority is to be regarded as lawful. This alone constitutes the subject matter of the appeal proceedings (see, for example, VwGH 23.6.2015, Ra 2015/22/0040, with further references). According to the consistent case law of the Administrative Court, if the respondent authority has rejected an application in the first instance, the appeal proceedings are solely concerned with the question of the legality of the rejection. In such a case, the administrative court has exclusive jurisdiction to decide whether the rejection issued by the respondent authority is to be regarded as lawful. This alone constitutes the subject matter of the complaint procedure (see, for example, VwGH 23.6.2015, Ra 2015/22/0040, with further references).
3.3.4.1. If the processing of personal data does not comply with the principles set out, inter alia, in Article 5 GDPR, the supervisory authorities of the Member States may act in accordance with their tasks and powers under Articles 57 and 58 GDPR. The European Court of Justice has already clarified in this regard that if a national supervisory authority considers, at the end of its investigation, that the data subject does not enjoy an adequate level of protection, it is obliged under Union law to respond appropriately to remedy the identified deficiency, regardless of its origin and nature. To this end, Article 58(2) GDPR lists the various remedial powers available to the supervisory authority. It is up to the supervisory authority to choose the appropriate means to fulfill its task, which consists in monitoring full compliance with the GDPR, with all due diligence. Article 58(2) GDPR distinguishes between remedial measures that can be ordered ex officio and those that can only be taken at the request of the data subject exercising their rights under this Regulation, such as those referred to in Article 58(2)(c) GDPR (ECJ of March 14, 2024, C-46/23, EU:C:2024:239, paras 32-35). 3.3.4.1. If the processing of personal data does not comply with the principles set out, inter alia, in Article 5 GDPR, the supervisory authorities of the Member States may act in accordance with their tasks and powers under Articles 57 and 58 GDPR. In this regard, the European Court of Justice has already clarified that if, at the end of its investigation, a national supervisory authority considers that the data subject does not benefit from an adequate level of protection, it is obliged under EU law to take appropriate action to remedy the deficiency identified, regardless of its origin and nature. To this end, Article 58(2) of the GDPR lists the various remedial powers available to the supervisory authority. It is for the supervisory authority to choose the appropriate means to fulfil, with all due diligence, its task of ensuring full compliance with the GDPR. Article 58(2) GDPR distinguishes, according to its wording, between remedial measures that can be ordered ex officio and those that can only be taken at the request of the data subject exercising their rights under this Regulation, such as those referred to in Article 58(2)(c) GDPR (ECJ of 14 March 2024, C-46/23, EU:C:2024:239, paras 32-35).
The supervisory authority may be required to take some of the measures listed in Article 58(2) GDPR, in particular if it considers that the protection required by Union law cannot be ensured by other means (ECJ of July 16, 2020, C-311/18, EU:C:2020:559, para. 113). The supervisory authority may be required to take some of the measures listed in Article 58(2) GDPR, in particular if it considers that the protection required by Union law cannot be ensured by other means (ECJ of July 16, 2020, C-311/18, EU:C:2020:559, para. 113).
3.3.4.2. Article 58(2)(f) GDPR provides for the possibility of prohibition. A prohibition prohibits processing entirely. Article 58 (2) (f) GDPR contains the prohibition, one of the most burdensome measures for data processors. Accordingly, before issuing such an order, the supervisory authority must examine less intrusive measures under other alternatives of Article 58 in order to ensure a proportionate approach. If no less intrusive remedial measures can be considered, it must be further examined within the framework of Article 58 (2) (f) GDPR whether a restriction of the measure to individual forms of processing, such as storage, is appropriate. According to Article 58 (2) (f) GDPR, restrictions can be temporary or permanent. In this case, it must be examined whether a temporary limitation on processing is sufficient before a permanent restriction is imposed. A ban on all processing should only be considered as a last resort. (Polenz in Simitis/Hornung/Spiecker, Datenschutzrecht/DSGVO mit BDSG, Article 58 paras. 39f). The data protection authority can also resort to this remedial measure directly after due diligence, e.g., to immediately stop particularly risky data processing (Selmayr in Ehmann/Selmayr, General Data Protection Regulation 2, Art. 58, para. 24). 3.3.4.2. Article 58, paragraph 2, letter f, GDPR provides for the possibility of a prohibition. The prohibition completely prohibits processing. Article 58, paragraph 2, letter f, GDPR contains one of the most burdensome measures for data processors. Accordingly, before issuing such an order, the supervisory authority must examine less intrusive measures under other alternatives of Article 58 in order to ensure a proportionate approach. If no less intrusive remedial measures are possible, it must be further examined within the framework of Article 58, paragraph 2, letter f, GDPR whether a restriction of the measure to individual forms of processing, such as storage, is appropriate. According to Article 58, paragraph 2, letter f, GDPR, restrictions can be temporary or permanent. It must be examined whether a temporary restriction on processing is sufficient before a permanent restriction is imposed. Only as a last resort should a ban on all processing be considered. (Polenz in Simitis/Hornung/Spiecker, Data Protection Law/GDPR with BDSG, Article 58, paras. 39f).The data protection authority may also resort to this remedial measure directly, for example, to immediately stop particularly risky data processing (Selmayr in Ehmann/Selmayr, General Data Protection Regulation 2, Article 58, para. 24).
3.3.4.3. In the preliminary ruling proceedings in Case C-768/21, which, among other things, had to clarify the obligations of the supervisory authority when a personal data breach has been identified, the ECJ ruled in its judgment of 24 September 2024 that Article 57(1)(a) and (f), Article 58(2) and Article 77(1) of the GDPR are to be interpreted as meaning that the supervisory authority is not obliged to take a remedial measure pursuant to Article 58(2) if such intervention is not appropriate, necessary, or proportionate to remedy the identified inadequacy and ensure full compliance with this Regulation. Furthermore, in this context, the ECJ stated that, as the Advocate General stated in his Opinion, the data subject does not have a subjective right to have the supervisory authority impose a fine on the controller (para. 41). It can therefore be assumed that a data subject has no subjective right to have the supervisory authority take a specific remedial measure against the controller. This corresponds to the legal opinion expressed by the authority concerned in its decision.3.3.4.3. In the preliminary ruling proceedings in Case C-768/21, which, among other things, sought to clarify the obligations of the supervisory authority when a personal data breach has been identified, the ECJ ruled in its judgment of September 24, 2024, that Article 57, paragraph 1, letters a and f, Article 58, paragraph 2, and Article 77, paragraph 1, GDPR are to be interpreted in such a way that the supervisory authority is not obliged to take a remedial measure under Article 58, paragraph 2, if such intervention is not appropriate, necessary, or proportionate to remedy the identified inadequacy and ensure full compliance with this Regulation. Furthermore, in this context, he stated that, as the Advocate General stated in his Opinion, the data subject has no subjective right to have the supervisory authority impose a fine on the controller (paragraph 41). It can therefore be assumed that a data subject has no subjective right to have the supervisory authority take a specific remedial measure against the controller. This corresponds to the legal opinion expressed by the authority concerned in the decision.
Since Article 58(2) GDPR does not grant the complainant, whose data protection rights have been violated, a subjective right to a (specific) remedial measure, such as an order prohibiting processing pursuant to Article 58(2)(f) GDPR, by the authority concerned, he or she is not entitled to such a right. Since Article 58(2) GDPR does not grant the complainant, whose data protection rights have been violated, a subjective right to a (specific) remedial measure, such as the imposition of a processing ban pursuant to Article 58(2)(f) GDPR, by the authority concerned, the complainant is not entitled to such a measure.
The first complainant's request in this regard was therefore rightly rejected by the authority in point 2 of the contested decision for lack of standing (see also VwGH 24.02.2022, Ra 2020/05/0231).
3.3.5. Both appeals against the decision were therefore dismissed as unfounded.
3.4. Regarding the waiver of a hearing:
A hearing may be waived pursuant to Section 24, Paragraph 4 of the Administrative Court Act (VwGVG), unless otherwise provided by federal or state law, and regardless of a party's request, if the records indicate that the oral argument is unlikely to provide further clarification of the case, and if neither Article 6, Paragraph 1 of the Convention for the Protection of Human Rights and Fundamental Freedoms nor Article 47 of the Charter of Fundamental Rights of the European Union preclude the waiver of a hearing.
A hearing may be waived pursuant to Section 24, Paragraph 4 of the Administrative Court Act (VwGVG), unless otherwise provided by federal or state law, and regardless of a party's request, if the records indicate that the oral argument is unlikely to provide further clarification of the case, and if neither Article 6, Paragraph 1 of the Convention for the Protection of Human Rights and Fundamental Freedoms nor Article 47 of the Charter of Fundamental Rights of the European Union preclude the waiver of a hearing. The relevant facts could be considered sufficiently clarified by the file. The appeal did not raise any concrete and substantiated questions of fact that still needed to be clarified, and no complex legal issue was to be resolved (VwGH of July 31, 2007, Ref. No. 2005/05/0080). Therefore, an oral hearing could be dispensed with. Article 6 (1) of the ECHR and Article 47 of the Charter of Fundamental Rights of the European Union do not preclude the waiver of a hearing. The relevant facts could be considered sufficiently clarified by the file. The appeal did not raise any concrete and substantiated questions of fact that still needed to be clarified, and no complex legal issue was to be resolved (VwGH of July 31, 2007, Ref. No. 2005/05/0080). Therefore, an oral hearing could be dispensed with. Article 6, paragraph 1, of the ECHR and Article 47 of the Charter of Fundamental Rights of the European Union do not preclude waiving the hearing.
Regarding B) Inadmissibility of the appeal:
According to Section 25a, paragraph 1 of the Administrative Court Act (VwGG), the administrative court must state in its judgment or decision whether the appeal is admissible pursuant to Article 133, paragraph 4 of the Federal Constitutional Court Act (B-VG). The decision must be briefly reasoned. According to Section 25a, paragraph 1, of the Administrative Court Act (VwGG), the administrative court must state in its judgment or decision whether the appeal is admissible pursuant to Article 133, paragraph 4 of the Federal Constitutional Court Act (B-VG). The decision must be briefly reasoned.
The appeal is inadmissible pursuant to Article 133, paragraph 4 of the Federal Constitutional Court Act because the decision does not depend on the resolution of a legal issue of fundamental importance. The decision in question neither deviates from the previous case law of the Administrative Court, nor is there a lack of case law; Furthermore, the present case law of the Administrative Court cannot be considered inconsistent. There are also no other indications of the fundamental importance of the legal issue to be resolved. The appeal is inadmissible pursuant to Article 133, Paragraph 4, of the Federal Constitutional Law (B-VG) because the decision does not depend on the resolution of a legal issue of fundamental importance. The present decision neither deviates from the previous case law of the Administrative Court, nor is there a lack of case law; furthermore, the present case law of the Administrative Court cannot be considered inconsistent. There are also no other indications of the fundamental importance of the legal issue to be resolved.
For all significant legal issues, the Federal Administrative Court may rely on established case law of the Administrative Court or on an already clear legal situation. However, a legal question of fundamental importance does not arise even if it has been resolved by a judgment of the ECJ (cf. VwGH 27.05.2024, Ra 2021/13/0056; 23.01.2019, Ro 2016/13/0012). It is also not apparent that a legal question arises in the specific case that has significance beyond the (concrete) individual case at hand. Based on this, a legal question of fundamental importance cannot be affirmed in this respect either. The Federal Administrative Court can rely on established case law of the Administrative Court or on an already clear legal situation for all significant legal questions. However, a legal question of fundamental importance does not arise even if it has been resolved by a judgment of the ECJ (cf. VwGH 27.05.2024, Ra 2021/13/0056; 23.01.2019, Ro 2016/13/0012). It is also not apparent that a legal question arises in this specific case that has significance beyond the specific case at hand (at hand). Based on this, a legal question of fundamental importance cannot be affirmed in this respect either.
It was therefore necessary to declare that the appeal on points of law is inadmissible pursuant to Article 133, paragraph 4, of the Federal Constitutional Law.
It was therefore necessary to declare that the appeal on points of law is inadmissible pursuant to Article 133, paragraph 4, of the Federal Constitutional Law.




