BVwG - W252 2249249-1

From GDPRhub
BVwG - W252 2249249-1
Court: BVwG (Austria)
Jurisdiction: Austria
Relevant Law: Article 5 GDPR
Article 6 GDPR
Article 7 GDPR
Article 9 GDPR
Article 10 GDPR
Article 11 GDPR
§ 1 DSG
Decided: 22.10.2024
Published: 10.12.2024
Parties: BF (data subject)
MP (controller)
National Case Number/Name: W252 2249249-1
European Case Law Identifier: ECLI:AT:BVWG:2024:W252.2249249.1.00
Appeal from: DSB (Austria)
unknown
Appeal to: Not appealed
Original Language(s): German
Original Source: RIS (in German)
Initial Contributor: Ava Lang

A court held that a controller did not violate Article 6 GDPR by processing heat consumption data via a smart meter, as the processing was necessary for legal obligations and legitimate interests.

English Summary

Facts

The data subject had a heating supply contract with a private energy company, the controller.

On 17 October 2019, the controller installed a smart heat meter in the data subject’s apartment. The device recorded various consumption and technical data, including energy usage, flow rates, and temperatures. It also stored historical operational data for error detection.

The controller read the meter once per year on-site. Although the device technically supported remote reading via a radio module, the controller did not use this function.

On 21 September 2020, the data subject filed a complaint with the DPA, arguing that the device unlawfully processed personal data and that the controller required a specific legal basis as a public authority. The DPA rejected the complaint on 11 October 2021. The data subject appealed to the court.

Holding

First, the court held that the controller was not a public authority. It acted as a private company under a contractual relationship and had no statutory powers to exercise authority. Therefore, Article 6(1)(f) GDPR could apply.

Second, the court held that the processing of consumption data (such as energy use, flow, and temperatures) complied with Article 6(1)(c) GDPR. National law required the collection and storage of such data for billing, energy efficiency, and system operation. This law satisfied the requirements of Article 6(3) GDPR by defining the purpose, scope, and retention periods.

Third, the court held that the processing of additional technical and historical data (such as error logs and operational records) complied with Article 6(1)(f) GDPR. The controller had a legitimate interest in ensuring the proper functioning and maintenance of the device. The processing was necessary for detecting faults and maintaining system reliability.

Finally, the court found that the data subject’s interests did not override the controller’s interests. Access to detailed historical data required specialised tools, and the data was only used in limited circumstances. The storage periods were also limited and aligned with legal requirements.

The court therefore upheld the DPA’s decision and rejected the appeal.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the German original. Please refer to the German original for more details.

The Federal Administrative Court, composed of Judge Elisabeth SCHMUT LL.M. as presiding judge and lay judges Claudia ROSENMAYR-KLEMENZ and Adriana MANDL as associate judges, has ruled on the appeal of XXXX, represented by WALLNER JORTHAN RECHTSANWALTS GmbH (a party to the proceedings before the Administrative Court XXXX GmbH, represented by CERHA HEMPEL Rechtsanwälte GmbH), against the decision of the Data Protection Authority dated October 11, 2021, file number XXXX, in a data protection matter, as follows:

A) The appeal is dismissed.

B) An appeal on points of law is not permitted.


[The appeal is dismissed.] Text

Reasons for the Decision:

I. Procedural History:

1. By submission dated September 21, 2020, the complainant (hereinafter referred to as "the complainant") filed a data protection complaint with the respondent authority, arguing, in part, that the co-respondent party (hereinafter referred to as "the party with whom he had a district heating contract) was violating his fundamental right to privacy by operating a smart small heat meter installed in his building.

2. On July 19, 2021, the complainant filed a complaint of failure to act with the respondent authority.

3. By decision dated October 11, 2021, the respondent authority dismissed the complainant's complaint regarding a violation of the right to privacy.

4. The complainant filed an appeal on November 9, 2021, against this decision. In this appeal, the appellant points out specific deficiencies in the decision, including the fact that MP should be classified as a state authority or at least as a public company, meaning that any processing activity requires a legal basis. In the absence of such a basis, MP violated the appellant's fundamental rights.

5. The respondent authority submitted the appeals, along with the administrative file, by letter dated December 9, 2021, received by the Federal Administrative Court on December 14, 2021, and requested – referring to the reasoning of the contested decision – that the appeal be dismissed.

Evidence was taken by reviewing the administrative and court files, and in particular by examining witness XXXX (hereinafter referred to as "witness") at the oral hearing on September 26, 2024.

II. The Federal Administrative Court considered the following:

1. Findings:

1.1. The tenant has a valid heat supply contract with MP for space heating and hot water. This contract stipulates billing based on actual heat consumption.

1.2. A small heat meter (DIEHL Metering "SHARKY 775") has been installed in the tenant's apartment since October 17, 2019, to measure the heat consumption. This small heat meter remains in operation at the tenant's residence.

1.3. The small heat meter is read annually during an on-site appointment by MP or a meter reading company commissioned by MP to read the meter reading from the digital display. The device installed at the tenant's residence is equipped with a radio module based on the OMS-4 communication architecture and is therefore capable of remote reading. However, remote reading of the meter readings does not currently take place at the tenant's residence.

1.4. The small heat meter processes the following data:
The data recorder stores the reading on August 31. The following data is stored on December 31st: date, energy, and volume.

The periodic log stores the following data monthly: date, energy, volume, operating hours, fault hours, as well as the maximum flow rate, power, supply and return temperatures, including timestamps. The periodic log stores the last 24 monthly values. The purpose of the periodic and fixed-date logs is to bill for consumed heat energy.

The historical log 1 stores the following data daily: time, date, energy, volume, maximum flow rate, maximum return temperature, fault hours, operating day counter, and fault byte. The historical log 1 stores the last 417 daily values.

The historical log 2 stores the following data monthly: time, date, energy, volume, and maximum flow rate. The historical log 2 can store up to 95 monthly values. The BF stores the last 59 monthly values.

The historical logs can only be read with special software and technical expertise and are not visible on the meter's display.

The purpose of the historical log memory is to check for errors and ensure the proper operation of the device.

Historical log memory 3 is deactivated on the small heat meter of the building owner (BF).

2. Evaluation of Evidence:

2.1. The findings regarding the contract between the building owner (BF) and the utility company (MP) are clearly evident from the submitted heat supply contract, which is attached to the administrative file, as well as the corresponding confirmation from MP during the oral hearing (see the individual heat supply contract dated January 21, 2005; OZ 18, pp. 3-4). The contract content ("V. Heating Cost Billing") stipulates that the amount of heat consumed is billed based on consumption (see the submitted General Terms and Conditions of Supply, Section V. Heating Cost Billing).

2.2. The findings regarding the installed device and the installation date are evident from MP's installation confirmation. This document states the date of the meter exchange (October 17, 2019) and the installed model ("Sharky 775"). Furthermore, the plaintiff confirmed in his data protection complaint of September 21, 2020, that the device was indeed installed on the aforementioned date and submitted a photograph of the fully installed device, clearly showing the manufacturer ("DIEHL Metering") and the model ("Type: 775"). Therefore, there was no doubt about the actual installation or the specific model used (see the plaintiff's data protection complaint of September 21, 2020, including attachments). Moreover, the MP confirmed during the oral hearing that the device in question remains installed and is still in operation at the plaintiff's premises. While it will be replaced in the coming weeks due to the Weights and Measures Act, it is currently still in use (see OZ 18, p. 4).

2.3. The finding that the meter readings are only taken during an on-site appointment is based on the plausible and credible statement by MP, among others, in its statement that the readings are taken (only) by a meter reading company (“XXXX GmbH”). This information was confirmed by the meter reading slip submitted by MP on April 2, 2020, which clearly shows that the consumption values were recorded by hand (see MP's statement of November 20, 2020, pp. 6-7, and the attached exhibit ./7). The witness who was heard confirmed in the oral proceedings that the physical readings were taken by a meter reading company. Since this witness works as an expert at MP in the department for economic plant operations (which includes consumption allocation and billing), he is familiar with MP's procedures for recording consumption, which is why his statements were credible (OZ 18, pp. 4-5).













... The findings regarding the radio module and the technology used are based on the operating instructions included with the administrative file and the submitted image of the BF's device, which shows the inscription "OMS 4" or "OMS Radio+ 868 MHz". Although the witness stated that no remote data readout was taking place because the cabling for readout via "M-BUS" was not installed in the BF (see OZ 18, p. 7), it should not be overlooked that the specific device installed in the BF has an integrated radio module (see the inscription "Radio+") that can transmit on the 868 MHz frequency band or via the so-called OMS 4 radio telegram (see the data protection complaint of September 21, 2020, with the attached photo of the device installed in the BF). Upon closer inspection, it becomes clear that the "SHARKY 775" has three communication interfaces, one of which is already occupied by the integrated radio (optionally 868 or 434 MHz, here 868 MHz). The two remaining slots can be retrofitted with optional interfaces (e.g., the M-BUS mentioned by the witness), which is not the case with the BF (see in particular the SHARKY 775 operating instructions submitted with the appeal, "Basic Features" and "Basic Features - Calculation Unit"; as well as the photograph of the device installed in the BF, on which the installed modules are labeled). These considerations are also confirmed by the MP's statement that the device installed in the BF would enable "this functionality" (meaning remote reading), but the interfaces provided for this purpose are not being used (see OZ 11, pp. 2-3).

As a result, it was determined that the small heat meter installed in the BF is, in principle, capable of remote reading. The mere possibility, however, says nothing about actual wireless transmission. As can be seen from the explanations (especially regarding the annual reading by a meter reading company), no actual wireless transmission or remote reading takes place at the BF.

2.4. The specific data processed is derived from the clear and unobjectionable statement of the MP dated July 7, 2022. In this statement, the MP detailed and comprehensibly broke down the individual data types of the device installed at the BF and described the purposes of each data collection (see OZ 11, pp. 3 ff.). This information corresponds to the information in the submitted operating instructions for the SHARKY 775 and was credibly confirmed by the witness during the oral proceedings (see OZ 18, pp. 4 ff.).

The finding regarding historical LOG memory 2, that it stores the last 59 monthly values of the BF, is based on the fact that it has been installed at the BF for 59 months. For the sake of completeness, it should be mentioned that the maximum number of stored months is 60, since the type of small heat meters used at BF – as credibly explained by the witness in the hearing – are routinely replaced after five years due to the Weights and Measures Act.The witness credibly confirmed that the data in the historical log files can only be read using specialized software, stating, among other things, that not even the meter reading company has access to this data or possesses the necessary software (see OZ 18, p. 7).

3. Legal Assessment:
A)
The admissible appeal is unfounded.

3.1. Applicable Law:
The subject of the appeal is whether MP violated the BF's fundamental right to privacy by processing various data concerning the BF's heat energy consumption through the small heat meter installed at the BF's premises on October 17, 2019. The heat meter is still installed and active at the BF's premises.

According to the established case law of the Austrian Administrative Court (VwGH), the Administrative Court must, in principle, apply the legal situation in force at the time the decision is issued. A different approach would only be warranted if the legislator, in a transitional provision, expresses that the previously applicable law still applies to pending proceedings, or if it is necessary to determine what was lawful on a specific date or during a specific period (see Austrian Administrative Court [VwGH] 22.02.2022, Ra 2020/08/0187, para. 12).

The processing in question is neither a singular event nor a completed process that, contrary to general principles, would require an assessment of the lawfulness of the processing on a specific date. Accordingly, the present case must be assessed according to the factual and legal situation at the time of the decision (cf. regarding the applicability of the current legal situation to data protection issues in connection with ongoing processing, see VwGH 06.03.2024,
Ro 2021/04/0037, para. 19 et seq.; or VwGH 27.06.2023,
Ra 2020/04/0083, para. 19).

Furthermore, it can be inferred from the transitional provisions of Section 75 of the Federal Energy Efficiency Act (EEffG) that the provisions on remote meter reading requirements and data protection (Section 55 EEffG; in particular paragraphs 4 and 6 thereof) are also intended to apply to consumption meters already installed before the Act came into force.

3.2. Regarding the MP's status as an authority:

As the respondent authority essentially already explained in the contested decision, it was necessary to clarify at the outset – particularly since the applicant and the MP had submitted various arguments on this point during the proceedings – whether the MP should be classified as a "state authority" within the meaning of Section 1(2) of the Data Protection Act (DSG) or as an "authority" within the meaning of Recital 47 of the GDPR. The applicant argued that the MP should be considered a public body and therefore a "state authority" pursuant to Section 1(2) of the DSG.

Within the scope of the GDPR, authorities that process data in the performance of their tasks cannot rely on Article 6(1)(f) of the GDPR (see Article 6(1), last sentence), "since it is the responsibility of the legislature to establish, by law, the legal basis for the processing of personal data by public authorities." The term "authority" must be interpreted narrowly and determined according to the legal system of the respective Member State. Invoking Article 6(1)(f) in the context of private sector administration is not a priori excluded (see Kastelitz/Hötzendorfer/Tschohl in Knyrim, DatKomm Art 6 GDPR, para. 51). In this respect, the authority status of Member States is also relevant within the scope of the GDPR.

According to the jurisprudence of the Austrian Administrative Court (VwGH), sovereign administration exists (only) when administrative bodies act with "imperium," that is, by employing specific state command and coercive powers. They act within the legal framework provided by public law for the exercise of official powers. For distinguishing between private sector administration and sovereign administration, the motives and purpose of the activity are irrelevant; rather, the decisive factor is which legal instruments the legislation provides for fulfilling the tasks to be performed. If the legislature has not endowed the administrative body with coercive powers, then the activity is not sovereign administration but rather private sector administration. Whether the authority in question performs a "public task" is irrelevant to the classification of an official action as sovereign administration, since not everything "public" must be carried out by the state. Furthermore, it is not decisive that the regulation falls under public law. Nor is every act by a body endowed with official powers a sovereign act. The fact that the authority in question uses public funds in connection with the task at hand also does not determine whether the action is sovereign, because the state also uses public funds in the context of private sector administration. The decisive factor is solely which legal instruments the legislator has provided, i.e., whether there is a statutory authorization for sovereign action and whether such authorization is being exercised in the specific case (see VwGH 21.12.2023,
Ro 2021/04/0010
, para. 36 et seq.; inter alia, with reference to VfGH 03.03.2001, KI-2/99; and VfSlg 3262/1957).

As the respondent authority correctly stated, MP is a privately established limited liability company (GmbH) that operates in the energy market as a district heating supplier and has concluded a private-law contract with the applicant. As MP stated, inter alia, in its statement of 21.03.2022, no sovereign powers were conferred upon it by law. The appellant did not present any specific sovereign (coercive) powers conferred upon the MP by law during the proceedings, nor did he indicate that the MP had used sovereign forms of action or applied sovereign forms of action against him, or exercised coercive powers.

The appellant's assertion that the MP was acting at least within the framework of simple public administration is equally unfounded (see, among others, the statement of August 3, 2022). The Administrative Court has already explained that the term "simple public administration" encompasses administrative action that is not of a private-sector nature but belongs to the realm of public administration, even if no sovereign act is issued in the specific case. In simple public administration, the administrative bodies do not act in the forms of decisions, direct administrative command and coercive power, or regulations, although their authority to order and enforce is present in the background. In this sense, simple sovereign administration is a potentially sovereign administration that can become an actual sovereign administration through the application of imperial powers (see Austrian Administrative Court [VwGH] 21.12.2023,
Ro 2021/04/0010
, para. 39).

As already explained, no sovereign forms of action or coercive powers (ordinance, decree, act of direct command and coercive authority) were assigned to the MP, nor are these otherwise present in the background of the MP. Therefore, the MP's activity within the framework of simple sovereign administration as preparation for or as a potentially sovereign administration is also ruled out.

The case law on public procurement cited by the BF (including ECJ 10.04.2008, C-393/06) does not alter this conclusion, as the content and objectives of the cited public procurement directives (Directive 2004/17/EC and Directive 2004/18/EC) differ significantly from the relevant data protection regulations. Therefore, the findings in those cases cannot be applied to the present case. Even if MP were to be classified as a public body, this does not automatically grant it the power to exercise sovereign powers.

Consequently, MP operates purely as a private limited company (GmbH) and has concluded a private contract with BF. It is therefore not to be classified as a "public authority" within the meaning of Section 1(2) of the Data Protection Act (DSG) or as an "authority" within the meaning of Recital 47 of the GDPR. The lawfulness of the data processing at issue in these proceedings must therefore be examined in light of the relevant provisions of the GDPR, without considering the standard of Section 1(2) of the Austrian Data Protection Act (see also the Austrian Administrative Court decision of December 21, 2023, Ro 2021/04/0010, paragraphs 32 to 51).

3.3. On the lawfulness of the processing:

According to the case law of the Court of Justice of the European Union (CJEU), all processing of personal data must comply with the principles set out in Article 5(1) GDPR, meet the requirements for lawfulness of processing listed in Article 6 GDPR, and comply with the provisions set out in Articles 7 to 11 GDPR (see CJEU decision of May 4, 2023, C-60/22, Federal Republic of Germany, paragraphs 57 et seq.).

Regarding the conditions for the lawfulness of processing, Article 6(1) GDPR contains an exhaustive and conclusive list of the cases in which the processing of personal data can be considered lawful. Therefore, processing must fall under one of the cases provided for in this provision in order to be considered lawful (see CJEU 12.09.2024, C-17/22 and C-18/22, HTB Neunte Immobilien Portfolio, para. 34).

3.3.1. The relevant legal basis in this case is the fulfillment of a legal obligation within the meaning of Article 6(1)(c) GDPR:

Article 6(1)(c) GDPR provides a legal basis for cases in which “processing is necessary for compliance with a legal obligation to which the controller is subject.” This condition is only met if the controller has a legal obligation to process specific data; therefore, the lawfulness of the processing always requires an additional legal basis according to Article 6(3) GDPR (Kastelitz/Hötzendorfer/Tschohl in Knyrim, DatKomm Art 6 GDPR para. 39).

Section 55 of the Energy Efficiency Act (EEffG) could serve as the legal basis. According to this provision, individual consumption meters must, in principle, be remotely readable (paragraph 1). Contrary to the statements of the Member of Parliament (see in particular the submissions made during the oral hearing, item 19), Section 55 EEffG is also applicable to the present case, as it refers to remotely readable devices and not to whether this function is actually used. Furthermore, the transitional provision of Section 75 Paragraph 8 of the Energy Efficiency Act (EEffG) indicates that the legislator also intended the regulation to apply to devices that, with regard to remote readability, corresponded to the latest state of the art at the time of installation (such as the device installed at the BF).According to Section 55 of the German Energy Efficiency Act (EEffG), remotely readable individual heat or cooling consumption meters must record the energy quantity or flow rate and the supply and return temperatures. Remotely readable heat cost allocators must record the respective units. The storage of additional data is permitted if it is necessary for maintaining operational functionality (paragraph 3). If a monthly value or a comparable reference date value is determined from the data pursuant to paragraph 3 for each calendar month, this value must be stored for a maximum of twenty-eight months by the entity responsible for billing, as the data controller pursuant to Article 4 of the GDPR, for the purposes of billing, customer information, energy efficiency, and maintaining secure operation. The monthly value must be transmitted from the communication interface to a downstream reading system. The determination of weekly, daily, hourly, or second-by-second values, including the necessary transmission of data at corresponding intervals, is permitted with the express consent of the end consumer (paragraph 4). The data must be deleted immediately as soon as it is no longer needed to fulfill its purpose, but no later than seven years after its creation (paragraph 7).

Section 55, paragraph 3 of the Energy Efficiency Act (EEffG) clarifies which data may be stored. Data necessary for operational functionality includes, in particular, minimum, maximum, average, total, or reference date values, in order to ensure or verify the correct functioning of the transfer station or compliance with contractually agreed parameters. Paragraph 4 establishes an obligation to store monthly values for a maximum of twenty-eight months in the individual consumption meter or via equivalent data access systems ("backend") (Official Gazette 2050, Annex to the National Council Proceedings, 27th Legislative Period, pp. 24 et seq.).

Section 55 of the Energy Efficiency Act (EEffG) thus defines the purpose of the processing (billing, customer information, energy efficiency, and maintaining secure operation by the entity responsible for billing, as well as maintaining operational functionality). Furthermore, it specifies, among other things, which types of data are to be processed and how long they may be stored (for the purpose of fulfilling the objective, a maximum of seven years), and that data security measures (including securing the communication between devices and protecting against unauthorized access) must be implemented.

It is beyond question that Section 55 of the Energy Efficiency Act (EEffG) is part of the strategy for improving energy efficiency and reducing energy consumption, and that there is a significant public interest in this (see, among other things, the objectives of Section 35, and in particular point 9 thereof; and Recital 1 of Directive (EU) 2018/2002 of 11 December 2018 amending Directive 2012/27/EU on energy efficiency). Given the high priority given to the formulated objectives (including increasing energy efficiency, establishing the Energy Union, and the principle of "energy efficiency first") at the EU and national levels, these objectives appear to be proportionate to the pursued goals.


It is beyond doubt that Section 55 of the Energy Efficiency Act (EEffG) is part of the strategy for improving energy efficiency and reducing energy consumption, and that there is a significant public interest in this (see, among other things, the objectives of Section 35, and in particular point 9 thereof; and Recital 1 of Directive (EU) 2018/2002 of 11 December 2018 amending Directive 2012/27/EU on energy efficiency). Section 55 of the Energy Efficiency Act (EEffG) is therefore a suitable legal basis within the meaning of Article 6(3) GDPR.

3.3.2. Regarding the data of the reference date and periodic storage:

The data to be stored, as specified in Section 55(3) and (4) of the Energy Efficiency Act (EEffG), corresponds to that of the small heat meter installed at the building. In particular, the data of the reference date and periodic storage, such as energy quantity, flow rate (volume), supply and return temperatures, and the maximum values, as well as their maximum storage duration, are clearly prescribed.

The purposes stated by the building authority in its statement (see also the findings regarding the processed data) correspond to those of Section 55 of the Energy Efficiency Act (EEffG), which is why there are no concerns in this regard either.

The building authority's objections regarding the radio module are unfounded, given that it is present but not used by the building authority. Furthermore, Section 55 of the Energy Efficiency Act (EEffG) mandates remote meter reading requirements, meaning that even using the integrated radio would offer no benefit to the fire department.

As a result, the processing of the aforementioned data falls under Article 6(1)(c) GDPR (in conjunction with Section 55(3) and (4) in conjunction with Article 6(3) GDPR). The processing of this data is therefore lawful.

3.3.3. Regarding the data from historical log files 1 and 2 and the error hours of the periodic log:

According to Article 6(1)(f) GDPR, processing is lawful if it is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

According to Article 6(1)(f) GDPR, processing is also lawful if three cumulative conditions are met: First, the controller or a third party must pursue a legitimate interest; second, the processing of personal data must be necessary for the purposes of that legitimate interest; and third, the interests or fundamental rights and freedoms of the data subject must not override those interests. The reasonable expectations of the data subject, as well as the scope of the processing in question and its impact on that data subject, must be taken into account. The interests and fundamental rights of the data subject prevail, in particular, when personal data is processed in situations where a data subject cannot reasonably expect such processing (see ECJ 12.09.2024, C-17/22 and C-18/22, HTB Neunte Immobilien Portfolio, pp. 49 et seq.; and, reiterating this, VwGH 01.02.2024, Ro 2020/04/0031).

Applied to the present case, this means:

Even if the data from historical log stores 1 and 2 or the error hours of the periodic storage are not explicitly mentioned in the committee report on Section 55 of the Energy Efficiency Act (EEffG) as "data necessary for operational function," the chosen wording "in particular" clearly indicates that the list there is not exhaustive. The storage of error hours or error bytes clearly serves to maintain operational function and secure operation within the meaning of Section 55(3) and (4) of the Energy Efficiency Act (EEffG). The same applies to the data in historical log files 1 and 2, as these – as has been established – can only be read using specialized software and technical expertise.

The processing of this data can, in any case, be subsumed under Article 6(1)(f) GDPR, since MP thereby ensures the legitimate interest of maintaining the operational function and proper functioning of the device it has installed, as well as enabling the detection of device errors. Storing this data is also necessary because, without this recording, any errors could not be detected and rectified, thus jeopardizing proper operation. The interests of the user do not outweigh the interests of MP in this case, as the relevant data can only be read out when necessary using specialized software and technical expertise. This minimizes the impact on the user. Furthermore, the storage period for historical log file 1 is limited to just over one year, which ensures error detection by MP while adequately safeguarding the user's interests. The theoretical storage period of 95 months for historical log memory 2 does exceed the maximum storage period specified in Section 55 Paragraph 7 of the Energy Efficiency Act (EEffG). However, the storage unit installed at the BF building has not been in operation for that long, so exceeding this period did not require further examination in this case. Furthermore, according to Section 15 Item 5 Letter a of the Weights and Measures Act, such consumption meters must be recalibrated after five years, so there is no risk of exceeding the maximum seven-year storage period.

Consequently, the storage of the data from historical log memories 1 and 2 and the error hours of the periodic log is also lawful under Article 6 Paragraph 1 Letter f of the GDPR.

3.4. The respondent authority was therefore correct in dismissing the data protection complaint, and the appeal against this decision was therefore also to be dismissed.

3.5. The appointment of an expert from the field of communications engineering (66), specifically regarding communications and transmission technology, to clarify various technical questions concerning the storage intervals of the small heat meter installed at the BF's premises, was deemed unnecessary. The operation of the small heat storage unit and its storage capabilities could be understood and clarified through the submission of the operating instructions for the device installed at the BF's premises, the written statements from the MP (OZ 11), and the testimony of an informed MP employee during the oral proceedings (see also the evaluation of evidence). The BF's general statement that the witness was an MP employee bound by instructions does not indicate which questions remained unanswered for the MP.

3.6. The decision was therefore rendered accordingly.

B) Admissibility of the appeal:
Pursuant to Section 25a Paragraph 1 of the Administrative Court Act (VwGG), the Administrative Court must state in the operative part of its judgment or decision whether the appeal is admissible pursuant to Article 133 Paragraph 4 of the Federal Constitutional Law (B-VG). This ruling requires a brief explanation.

The appeal is inadmissible because the decision does not depend on the resolution of a legal question of fundamental importance. The court was able to rely on the cited case law of the Austrian Administrative Court (VwGH) and the European Court of Justice (ECJ). In particular, the lawfulness of processing the data from the cut-off date and periodic storage was unambiguous due to the provisions of Section 55 of the Energy Efficiency Act (EEffG). Furthermore, the case-specific balancing of interests carried out with regard to the data from historical log storage 1 and 2 and the error hours of the periodic storage is irreversible.