BVwG - W252 2307842-1
| BVwG - W252 2307842-1 | |
|---|---|
| Court: | BVwG (Austria) |
| Jurisdiction: | Austria |
| Relevant Law: | Article 57 GDPR |
| Decided: | 26.08.2025 |
| Published: | 29.10.2025 |
| Parties: | |
| National Case Number/Name: | W252 2307842-1 |
| European Case Law Identifier: | ECLI:AT:BVWG:2025:W252.2307842.1.00 |
| Appeal from: | DSB (Austria) |
| Appeal to: | Unknown |
| Original Language(s): | German |
| Original Source: | RIS (in German) |
| Initial Contributor: | n/a |
A court held that the refusal of the DPA to examine the 20 complaints, filed by a data subject against different controllers over several months, was lawful, as the complaints were excessive.
English Summary
Facts
A data subject filed twenty data-protection complaints between April 2021 and August 2024 against twelve different controllers, alleging violations of the GDPR rights to access, confidentiality, erasure, rectification, and restriction of processing.
These complaints were submitted as free-form email attachments rather than using the authority’s structured form, and they consistently contained accusatory, hostile, and often insulting language toward the controllers and toward the Austrian Data Protection Authority (DSB). In many of the complaints, the data subject claimed that access requests had been ignored or incompletely answered, that deletion requests were not fulfilled, or that data had been unlawfully processed or disclosed. Also, the data subject frequently used derogatory expressions combined the GDPR allegations with extensive personal attacks, and repeatedly demanded “as high penalties as possible.”
The DSB refused to process the complaints, arguing that the complaints were excessive, abusive, and not genuinely aimed at protecting GDPR rights. The data subject further appealed this refusal to the Federal Administrative Court (BVwG).
Holding
The court dismissed the complaint and held that the DSB lawfully refused to process the twenty complaints under Article 57(4) GDPR on the ground that they constituted excessive and abusive requests. The Court emphasized that, under CJEU case law, supervisory authorities may refuse to act when complaints are objectively abusive, particularly when the data subject’s dominant intent is unrelated to GDPR-protected purposes.
Although a mere quantity of complaints cannot be the sole basis for refusal, the data subject’s pattern, combined with clearly retaliatory and hostile motives, satisfied the requirement of proving misuse. The Court found that the data subject used GDPR procedures as a means of personal confrontation, not to vindicate data-protection rights, and thus his conduct fell squarely within “excessive” and “abusive” use of the system.
Furthermore, the court argued that because the data subject had a very low income, imposing administrative fees, the alternative option under Article 57(4) GDPR would not have been suitable or proportionate. Therefore, the DSB’s decision to refuse treatment was appropriate.
Comment
The court did not examine the substance of all twenty complaints individually.
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the German original. Please refer to the German original for more details.
Decision Date
August 26, 2025
Legal Norm
Federal Constitutional Law (B-VG) Art. 133 para. 4
General Data Protection Regulation (GDPR) Art. 57 para. 1 lit. f
GDPR Art. 57 para. 4
GDPR Art. 77 para. 1
Federal Constitutional Law (B-VG) Art. 133 today; Federal Constitutional Law (B-VG) Art. 133 valid from January 1, 2019 to May 24, 2018, last amended by Federal Law Gazette I No. 138/2017; Federal Constitutional Law (B-VG) Art. 133 valid from January 1, 2019, last amended by Federal Law Gazette I No. 22/2018; Federal Constitutional Law (B-VG) Art. 133 valid from May 25, 2018 to December 31, 2018, last amended by Federal Law Gazette I No. 22/2018; Federal Constitutional Law (B-VG) Art. 133 valid from August 1, 2014 to 24.05.2018, last amended by Federal Law Gazette I No. 164/2013; Federal Constitutional Law Art. 133, valid from 01.01.2014 to 31.07.2014, last amended by Federal Law Gazette I No. 51/2012; Federal Constitutional Law Art. 133, valid from 01.01.2004 to 31.12.2013, last amended by Federal Law Gazette I No. 100/2003; Federal Constitutional Law Art. 133, valid from 01.01.1975 to 31.12.2003, last amended by Federal Law Gazette No. 444/1974; Federal Constitutional Law Art. 133, valid from 25.12.1946 to 31.12.1974, last amended by Federal Law Gazette No. 211/1946. Article 133, valid from December 19, 1945, to December 24, 1946, last amended by Federal Law Gazette No. 4/1945. Article 133 of the Federal Constitutional Law, valid from January 3, 1930, to June 30, 1934.
Ruling
W252 2307842-1/4E
IN THE NAME OF THE REPUBLIC!
The Federal Administrative Court, through Judge Elisabeth Schmut, LL.M., has ruled... The Federal Administrative Court, with Judge Elisabeth Schmut LL.M. presiding and lay judges Dr. Claudia Rosenmayr-Klemenz and Adriana Mandl, MA, as associate judges, has ruled on the appeal of XXXX against the decision of the Data Protection Authority of August 30, 2024, file number XXXX, in a data protection matter, in a non-public session, as follows:
A) The appeal is dismissed.
B) An appeal on points of law is not permitted.
Text
Reasons for the Decision:
I. Procedural History: Procedural History:
1. By submission dated April 25, 2021, and 19 further submissions between November 2023 and August 2024, the complainant (hereinafter: SF) filed 20 data protection complaints against twelve different respondents for violations of the rights to information, confidentiality, erasure, rectification, and restriction of processing.
2. By the present decision dated August 30, 2024, the respondent authority rejected the processing of the 20 complaints, which had been consolidated for a joint decision, essentially on the grounds that SF's submissions were both excessive and manifestly unfounded, and therefore an abuse of process.
3. SF filed an appeal against this decision on September 25, 2024. SF argues that the respondent authority incorrectly assumed excessive procedural conduct and that the proceedings should be continued.
2. 4. The respondent authority filed the appeal by letter dated January 30, 2025, received by the Federal Administrative Court on February 18, 2025, and requested – essentially referring to the reasoning of the contested decision – that the appeal be dismissed.
Evidence was taken by reviewing the administrative and court files.
II. The Federal Administrative Court considered the following:
1. Findings:
1.1. Regarding the individual data protection complaints:
1.1.1. On April 25, 2021, the appellant filed a data protection complaint against XXXX for a violation of his right to information (XXXX). In it, he alleged, in addition to misconduct by employees of the respondent authority, the incompleteness of the information he received concerning his financial data. On April 25, 2021, the appellant filed a data protection complaint against Roman 40 for a violation of his right to information (Roman 40). In it, he alleged misconduct by employees of the respondent authority and the incompleteness of the information he received regarding his financial data.
1.1.2. On November 29, 2023, the appellant filed a data protection complaint against XXXX for a violation of his right to confidentiality and access (XXXX). In it, he raised doubts about the professional expertise of the employees there and stated that an investigation against him was "completely unjustified." He further alleged that a request for information had gone unanswered and that the investigation file wrongly contained two expert medical reports about him, or rather, that these reports had not been excluded from file inspection. 1.1.2. On November 29, 2023, the appellant filed a data protection complaint against [Company Name] (Roman 40) alleging a violation of his right to confidentiality and access to information (Roman 40). In his complaint, he raised doubts about the professional expertise of the employees there and asserted that the investigation against him was "completely unjustified." He further stated that a request for information had gone unanswered and that the investigation file had wrongly contained two expert medical reports concerning him, or rather, that these reports had not been excluded from file inspection.
1.1.3. On December 19, 2023, the appellant filed a data protection complaint against [Company Name] (XXXX) alleging a violation of his right to erasure (XXXX). In it, he raised accusations against the respondent authority (including, "XXXX had the audacity to spread false, insulting, and defamatory statements about me in a public oral hearing before the Federal Administrative Court. And this in a packed courtroom. When asked, XXXX was, of course, unable to provide any specific details.") and argued that a deletion request had not been granted. 1.1.3. On December 19, 2023, the appellant filed a data protection complaint against Roman 40 for a violation of the right to erasure (Roman 40). In his complaint, he raised accusations against the respondent authority (including, "The Roman numeral 40 had the audacity to spread false, insulting, and defamatory statements about me in a public oral hearing before the Federal Administrative Court. And this in a packed courtroom. When questioned, the Roman numeral 40 was, of course, unable to provide any specific details.") and also alleged that a deletion request had been denied.
1.1.4. On January 26, 2024, the appellant filed three data protection complaints against XXXX, XXXX, and XXXX for violations of his right to information. In each complaint, he stated that requests for information regarding the recipients of data from an investigative file had not been answered. On January 26, 2024, the plaintiff filed three data protection complaints against [Company Name], [Company Name], and [Company Name] for violations of his right to information. In each complaint, he stated that requests for information regarding the recipients of data from an investigative file had not been answered.
1.1.5. On April 11, 2024, the plaintiff filed a data protection complaint against [Company Name] for a violation of his right to information. In this complaint, in addition to alleging discrimination against a named [Company Name], he stated that he had requested information about who had claimed in [Company Name] that he had verbally abused individuals and used offensive language towards them. This complaint included the BF's request for information, which contained, among other things, the question: "Who at XXXX is so antisocial, so provocative, so stupid and idiotic as to inform me of point 1 [WHO claims that the BF made insults]??" 1.1.5. On April 11, 2024, the BF filed a data protection complaint against Roman 40 for a violation of his right to information (Roman 40). In this complaint, in addition to accusations against a specifically named Roman 40 regarding discrimination against the BF, he stated that he had requested information about who at Roman 40 had claimed that he had verbally abused people there and used offensive language towards them. This complaint included the BF's request for information, which contained, among other things, the question, "Who among the 40 is so antisocial, so provocative, so stupid and foolish as to inform me of point 1 [WHO claims that the BF made insults]??"
1.1.6. On April 15, 2024, the BF filed a data protection complaint against XXXX for a violation of his right to confidentiality and access (XXXX). In this complaint, he alleged, in addition to hostile remarks against the respondent ("The respondent doesn't care about data protection."; "XXXX has utterly disgraced itself."), a violation of his right to confidentiality and access regarding his data processed within the framework of an investigation. 1.1.6. On April 15, 2024, the BF filed a data protection complaint against 40 for a violation of his right to confidentiality and access (Roman 40). In his complaint, he alleged, in addition to leveling hostile accusations against the respondent ("The respondent doesn't care about data protection."; "The Roman numeral 40 has utterly disgraced itself."), a violation of his right to confidentiality and access to information regarding his data processed within the framework of an investigation.
1.1.7. On April 16, 2024, the appellant filed a data protection complaint against XXXX for a violation of his right to access and erasure (XXXX). In his complaint, he alleged, in addition to accusations against the respondent (that it had "made incriminating, false, and damaging statements to XXXX"), that a request for information had gone unanswered. On May 14, 2024, the appellant supplemented his data protection complaint, among other things, with a letter to the respondent in that case, in which he stated, among other things, "The infamous, demonstrably false lies of the Federal Ministry XXXX have reached an intolerable level, and these false claims will definitely have extensive legal repercussions." 1.1.7. On April 16, 2024, the appellant filed a data protection complaint against Rome 40 for a violation of the right to information and erasure (Roman 40). In this complaint, in addition to accusations against the respondent (who had "made incriminating, false, and damaging statements to Rome 40"), he stated that a request for information had not been answered. On May 14, 2024, the BF supplemented his data protection complaint, among other things, with a letter to the respondent in that complaint, in which he states, among other things, "The infamous, demonstrably false lies of the Federal Ministry (Roman 40) have reached an intolerable level and these false claims will definitely have extensive legal repercussions."
1.1.8. On April 16, 2024, the appellant filed a data protection complaint against XXXX for a violation of his right to information and erasure (XXXX). In this complaint, he essentially stated, as he had already done in his data protection complaint against XXXX on the same day, that someone at XXXX was spreading lies about him and that he wanted to use his right to information to find out who this person was. In this data protection complaint, the appellant refers to a letter to the respondent in that case dated March 15, 2024. 1.1.8. On April 16, 2024, the appellant filed a data protection complaint against Roman 40 for a violation of his right to information and erasure (Roman 40). In this complaint, he essentially stated, as he had already done in his data protection complaint against Roman 40 on the same day, that someone at Roman 40 was spreading lies about him and that he wanted to use his right to information to find out who this person was. In this data protection complaint, the complainant refers to a letter to the respondent in that case dated March 15, 2024.
1.1.9. On May 2, 2024, the complainant filed a data protection complaint against XXXX for a violation of his right to information and erasure (XXXX). In this complaint, he again referred to the letter to the respondent in that case dated March 15, 2024, stating that he wanted his telephone number deleted and that his request for information had been incompletely answered. 1.1.9. On May 2, 2024, the complainant filed a data protection complaint against Roman 40 for a violation of his right to information and erasure (Roman 40). In it, he again referred to his letter to the respondent in that case dated March 15, 2024, stating that he wanted his telephone number deleted and that his request for information had been incompletely answered.
1.1.10. On May 13, 2024, the appellant filed a data protection complaint against XXXX for a violation of his rights to access, rectification, restriction of processing, and erasure (XXXX). In this complaint, supplemented on June 11, 2024, he also stated, among other things, that the respondent's claims were "grossly false, lies, and/or sloppily investigated," and that he had never heard a "more ridiculous allegation." He added, "This is complete nonsense, insanity, and the height of stupidity." With regard to a police report, he asserted violations of his rights to access, rectification, and restriction of processing. 1.1.10. On May 13, 2024, the BF filed a data protection complaint against [Company Name] (Roman 40) alleging a violation of his rights to access, rectification, restriction of processing, and erasure (Roman 40). In a supplementary statement dated June 11, 2024, he further asserted that the respondent's claims were "grossly false, fabricated, and/or based on sloppy research," and that he had never heard a "more ridiculous allegation." He stated, "This is utter nonsense, insanity, and utterly stupid." He also claimed violations of his rights to access, rectification, and restriction of processing in relation to a police report.
On June 2, 2024, the BF filed a data protection complaint against [Company Name] (XXXX) alleging a violation of his right to erasure (XXXX). In it, he stated that a request for the deletion of his data in various files had not been answered. 1.1.11. On June 2, 2024, the appellant filed a data protection complaint against [Company Name] 40 for a violation of his right to erasure ([Company Name] 40). In it, he stated that a request for the deletion of his data in various files had not been answered.
1.1.12. On June 15, 2024, the appellant filed a data protection complaint against [Company Name] XXX for a violation of his right to information ([Company Name] XXX). In it, he stated that a request for information from a company that the appellant knew from a traffic incident, which was also the subject of a police investigation, had not been answered. 1.1.12. On June 15, 2024, the BF filed a data protection complaint against Roman 40 for a violation of his right to information (Roman 40). In this complaint, he alleged that a request for information from a company he knew from a traffic incident, which was also the subject of a police investigation, had gone unanswered.
1.1.13. On June 15, 2024, the BF filed a data protection complaint against XXXX for a violation of his right to information (XXXX). In this complaint, he alleged, in addition to accusations that he had been discriminated against by the respondent due to his disability, that a request for information regarding the origin of the "lie" that there were expert opinions on him attesting to his "delusional phenomena" had gone unanswered. 1.1.13. On June 15, 2024, the appellant filed a data protection complaint against Roman 40 for a violation of his right to information (Roman 40). In addition to alleging discrimination by the respondent on the grounds of his disability, he stated that a request for information regarding the origin of the alleged lie that there were expert opinions on him attesting to his delusional phenomena had gone unanswered.
On June 20, 2024, the appellant filed a data protection complaint against XXXX for a violation of his right to information and erasure (XXXX). He stated, among other things, that a request for information had gone unanswered, and that the attached request contained allegations of abuse of office against a judge there. On June 20, 2024, the appellant filed a data protection complaint against Roman 40 for a violation of his rights to access and erasure (Roman 40). He stated, among other things, that a request for access had not been answered, and that the attached request contained allegations of abuse of office against a judge there.
On July 22, 2024, the appellant filed a data protection complaint against XXXX for a violation of his rights to access and erasure (XXXX). He stated, among other things, that a request for access had been answered incompletely and/or that his request for erasure had not been complied with. The enclosed correspondence with the respondent in that case contains, among other things, insults from the appellant ("But I think you're a liar. Why? Only an idiot would demand identification despite having no data and create more work for himself instead of simply saying that no data is being processed at all. Are you such an idiot?? I think so! Would you do something like that?? I think so! Am I going to let myself be teased? No, certainly not. The complaint to the responsible supervisory authority regarding your incorrect data disclosure is already being prepared. You wanted that, because you're obviously bored."). 1.1.15. On July 22, 2024, the appellant filed a data protection complaint against Rome 40 for a violation of his rights to information and erasure (Roman 40). In it, he stated, among other things, that a request for information had been answered incompletely and/or his request for erasure had not been complied with. The enclosed correspondence with the respondent in that case contains, among other things, insults from the complainant ("But I think you're a liar. Why? Only an idiot would demand identification despite having no data and create more work for himself instead of simply stating that no data is being processed at all. Are you such an idiot? I think so! Would you do something like that? I think so! Am I going to let myself be teased? No, certainly not. The complaint to the responsible supervisory authority regarding your false data disclosure is already being prepared. You wanted that, because you're obviously bored.").
On August 1, 2024, the complainant filed a data protection complaint against XXXX and XXXX for a violation of the right to confidentiality (XXXX). In his complaint, he alleged, in addition to accusations of "defamation, insult, damage to credit, slander, and possibly abuse of office" against the first respondent, that his email address had been wrongfully sent to all employees of the second respondent. Furthermore, the complainant explained in detail the background of his dealings with the first respondent, by whom he felt he had been treated unfairly. 1.1.16. On August 1, 2024, the complainant filed a data protection complaint against Roman 40 and Roman 40 for a violation of his right to confidentiality (Roman 40). In his complaint, he alleged, in addition to accusations of "defamation, insult, damage to credit, slander, and possibly abuse of office" against the first respondent, that his email address had been wrongfully sent to all employees of the second respondent. Furthermore, the complainant explains in detail the background story with the initial respondent in the complaint, by whom he feels he has been treated unfairly.
1.1.17. On August 7, 2024, the complainant filed a data protection complaint against XXXX for a violation of his right to information (XXXX). He included a substantial set of attachments to his data protection complaint of May 2, 2024. The requested information is still incomplete. Among other things, the complainant submitted an email dated July 16, 2024, containing various accusations against numerous ombudsmen and ombudsmen. 1.1.17. On August 7, 2024, the complainant filed a data protection complaint against Roman 40 for a violation of his right to information (Roman 40). In his submission, he included a substantial set of attachments to his data protection complaint of May 2, 2024. The requested information was still incomplete. Among other things, the appellant submitted an email dated July 16, 2024, containing various accusations against numerous ombudspersons.
1.1.18. On August 21, 2024, the appellant filed a data protection complaint against XXXX for a violation of his right to confidentiality (XXXX). In this complaint, he alleged, in addition to numerous accusations against the respondent (defamation, perjury, "I identified and reported a total of eight serious lies in the respondent's police report"), that the respondent had disclosed his name to unauthorized persons.
1.1.18. On August 21, 2024, the appellant filed a data protection complaint against Roman 40 for a violation of his right to confidentiality (Roman 40). In this complaint, he alleged, in addition to numerous accusations against the respondent (defamation, perjury, "I identified and reported a total of eight serious lies in the respondent's police report"), that the respondent had disclosed his name to unauthorized persons.
1.2. The complainant consistently submitted their data protection complaints as email attachments in the form of continuous text. The complainant deliberately chose not to use the readily available form provided by the respondent authority, opting instead to submit their complaints via email with a self-drafted document.
1.3. The data protection complaints are typically only a few pages long and include, as attachments, prior correspondence with the respondent(s). These attachments bear light gray watermarks running diagonally from the bottom left to the top right, containing the inscription "XXXX Secret XXXX Secret XXXX Secret" or similar. In addition to brief descriptions of the alleged data protection violation, the complaints generally contain numerous accusations against the respective respondent(s) and are written in a provocative, aggressive, and sometimes insulting style. The enclosures are marked with light gray watermarks running diagonally from the bottom left to the top right, bearing the inscription "Roman numeral 40 Secret Roman numeral 40 Secret Roman numeral 40 Secret" or similar. In addition to brief descriptions of the alleged data protection violation, the data protection complaints typically contain numerous accusations against the respective defendants and are written in a provocative, aggressive, and sometimes insulting style.
1.4. The complainant's primary purpose with his data protection complaints is to harass the respondent authority and to express his displeasure with other individuals, authorities, and companies. He uses his data protection complaints to get back at these entities/individuals, to insult them, and is hostile towards them as well as the respondent authority.
1.5. The complainant has a very low income.
2. Evaluation of Evidence:
2.1. The findings regarding the data protection complaints are derived from the unobjectionable administrative act to which they are attached (see the data protection complaints of 25 April 2021, OZ 1, pp. 306 ff.; 29 November 2023, OZ 1, pp. 422 ff.; 19 December 2023, OZ 1, pp. 397 ff.; 26 January 2024, OZ 1, pp. 360 ff.; 26 January 2024, OZ 1, pp. 331 ff.; 26 January 2024, OZ 1, pp. 594 ff.; 11 April 2024, OZ 1, pp. 439 ff.; 15 April 2024, OZ 1, pp. 445 ff.; 16 April 2024, OZ 1, p. 389 ff; April 16, 2024, OZ 1, p 581 ff; May 2, 2024, OZ 1, p 562 ff; May 13, 2024, OZ 1, p. 516 ff; June 2, 2024, OZ 1, p. 458 ff; June 15, 2024, OZ 1, p. 466 ff; June 15, 2024, OZ 1, p 478 ff; June 20, 2024, OZ 1, p 199 ff; July 22, 2024, OZ 1, p. 138 ff; August 1, 2024, OZ 1, p 133 ff; August 7, 2024, OZ 1, p. 293 ff; 21.08.2024, OZ 1, p. 279 ff).
2.2. The fact that the applicant deliberately did not use the form provided by the respondent authority is evident from the fact that it is prominently and easily accessible on the respondent authority's website (https://XXXX.gv.at/eingabe-an-die-XXXX/formulare) and that, due to his numerous previous proceedings before the respondent authority, he is at least familiar with it.
2.3. The findings regarding the manner in which the complainant drafts his data protection complaints are derived from an examination of the administrative file to which the complainant's submissions are attached. The findings regarding the complainant's derogatory language are derived from his submissions: see excerpts: "Although the respondent's acting bodies are all Doctors of Law, they apparently do not know the data protection laws." OZ 1, p. 424; "WHO at XXXX is so antisocial, so provocative, so stupid and idiotic as to tell me point 1??" OZ 1, p. 442; "The respondent doesn't care about data protection." "XXXX has utterly disgraced itself with this." OZ 1, p. 447; "This is complete nonsense, insanity, and its stupidity is hard to surpass." OZ 1, p. 519; “But I believe you are a liar. Why? Only a fool would demand identification despite having no data and create more work for himself instead of simply stating that no data is being processed at all. Are you such a fool? I think so! Would you do something like that? I think so! Am I going to let you tease me? No, certainly not. The complaint to the responsible supervisory authority regarding your false data disclosure is already being prepared. You wanted that, because you're obviously bored.” (OZ 1, p. 161). 2.3. The findings regarding the manner in which the complainant drafts his data protection complaints are based on an examination of the administrative file to which the complainant's submissions are attached. The findings regarding the complainant's derogatory formulations are based on his submissions: see excerpt: “Although the acting bodies of the respondent are all Doctors of Law, they apparently do not know the data protection laws.” (OZ 1, p. 424) "WHO among the Roman numeral 40 is so antisocial, so provocative, so stupid and idiotic as to tell me point 1?" OZ 1, p. 442; "The respondent doesn't care about data protection." "The Roman numeral 40 has thus utterly disgraced itself." OZ 1, p. 447; "This is complete nonsense, insanity, and its stupidity is hard to surpass." OZ 1, p. 519; "But I believe you are a liar. Why? Only a fool would demand identification despite the absence of data and create more work for himself instead of simply stating that no data is being processed at all. Are you such a fool?? I think so! Would you do something like that?? I think so! Am I going to let you tease me? No, certainly not. The complaint to the responsible supervisory authority regarding your false data disclosure is already being prepared. You wanted this, after all, because you're obviously bored." (OZ 1, p. 161).
2.4. The purpose of the complainant's data protection complaints can be seen from a review of his submissions. These submissions share the common thread that the complainant feels unfairly treated by the respective respondents and uses the data protection complaints to exact revenge and get back at them. This is evident, among other things, from the complainant's numerous requests for the "highest possible" penalties or for "no mercy" to be shown (see, among others, OZ 1, pp. 136, 201; 460). Furthermore, the complainant's data protection complaints invariably contain accusations against the respondents or the authority in question. These range from defamation, insult, damage to credit, and slander to abuse of office (OZ 1, pp. 134, 390, 399). It is acknowledged that the complainant also raises data protection concerns; however, a review of the supporting documents provided by the complainant makes it clear what the complainant's true intentions are, namely, that they are hostile to their opponents (see, among others, "The infamous, demonstrably false lies of the Federal Ministry XXXX have thus reached an intolerable level, and these false claims will definitely have extensive legal repercussions. Furthermore, by completely unjustly portraying me as delusional, XXXX has misled XXXX with these false claims into a false conclusion in the review process, so that XXXX will not discover any administrative irregularities at XXXX." OZ 1, p. 393; "Only for the sake of completeness, I add that the Ombudsman XXXX was recently found guilty of discrimination based on my disability." OZ 1, p. 441). Since the complainant already threatens his respondents with legal action, etc., in the enclosed preliminary correspondence, his hostility and aggressiveness become clear. 2.4. The purpose of the complainant's data protection complaints can be seen from a review of his submissions. These submissions have in common that the complainant feels unfairly treated by the respective respondents and uses the data protection complaints to retaliate and get even. This is evident, among other things, from the complainant's numerous requests for the "highest possible" penalties or for "no mercy" to be shown (see, among others, OZ 1, p. 136, 201; 460). Furthermore, the complainant's data protection complaints always contain accusations against the respondents or the authority in question. These range from defamation, insult, damage to credit, and slander to abuse of office (OZ 1, pp. 134, 390, 399). It is acknowledged that the complainant also raises data protection concerns; however, in conjunction with the documents provided by the complainant, it becomes clear what the complainant is really after, namely, that he is hostile to his opponents (see, among others, "The infamous, demonstrably false lies of the Federal Ministry [reference 40] have thus reached an intolerable level, and these false claims will definitely have extensive legal repercussions. Furthermore, [reference 40], by completely unjustly portraying me as delusional, has misled [reference 40] with these false claims into a false conclusion in the review process, so that [reference 40] would not find any mismanagement within the administration." (OZ 1, p. 393) "For the sake of completeness, I add that the Ombudsman was recently found guilty of discrimination based on my disability (Roman numeral 40)." (OZ 1, p. 441). Since the complainant already threatens his opponents with legal action, etc., in the enclosed preliminary correspondence, the complainant's hostility and aggressiveness become clear.
If the appellant now argues in his appeal against the decision that the protection of his data is extremely important to him (OZ 1, p. 218), this is certainly a valid point. However, this need for protection is so overshadowed by his hostility (especially towards the respondent authority) that data protection is virtually relegated to the background. The appellant's appeal against the decision is also full of derogatory statements about the respondent authority ("because XXXX is incapable of service by email or ID Austria" OZ 1, p. 216; "The reason XXXX repeatedly claims this is due to laziness and the fact that XXXX simply doesn't want to process my complaints. It's a disgrace that XXXX doesn't respect a ruling of the Federal Administrative Court." OZ 1, p. 217; "XXXX is using my data against me to gain an advantage for itself. XXXX seems to be committing an abuse of the law itself." OZ 1, p. 218; "Basically, I feel like XXXX is making a fool of me because it didn't work without discrimination for long and is already committing further discrimination based on disability and sheer stupidity." OZ 1, p. 223; "Perhaps XXXX should learn to read" OZ 1, p. 226 et al.). The appellant's abusive intent is also evident in his announcement in his data protection complaint that he will file further complaints with the respondent authority precisely because of the refusal to process his complaints (OZ 1, p. 235). While it is certainly true that the appellant argues in his appeal against the decision that the protection of his data is extremely important to him (OZ 1, p. 218), this need for protection is so overshadowed by his hostility (especially towards the respondent authority) that data protection is virtually relegated to the background. The appellant's appeal against the decision is also full of derogatory statements about the respondent authority ("because Roman 40 is incapable of service by email or ID Austria" OZ 1, p. 216; "Why Roman 40 repeatedly claims this is due to laziness and the fact that Roman 40 simply doesn't want to process my complaints. It's a disgrace that Roman 40 doesn't respect a ruling of the Federal Administrative Court." OZ 1, p. 217; "Roman 40 is using my data against me to gain an advantage for itself. Roman 40 seems to be committing an abuse of the law itself." OZ 1, p. 218; "Basically, I feel mocked by Roman 40 because it didn't work without discrimination for long and is already committing further discrimination based on disability and sheer stupidity." OZ 1, p. 223; "Roman 40 should perhaps learn to read." OZ 1, p. 226 et seq.). The appellant's abusive intent is also evident in his announcement in his data protection complaint that he will now file further complaints with the respondent authority precisely because of the refusal to process his complaints (OZ 1, p. 235).
In summary, there is no doubt about the appellant's primary intention. The obviously litigious appellant is actively seeking confrontation and merely uses the data protection concerns as a pretext. If the appellant were truly concerned with protecting his data—as he repeatedly asserts in his appeal against the decision (OZ 1, pp. 218, 225, 227)—he would present the facts objectively and directly, rather than constantly resorting to wild accusations, sweeping attacks, and threats. This is particularly evident from the fact that the BF's submissions clearly indicate that he is perfectly capable of using a refined expression and presenting his case in an orderly manner. However, since, as already stated, his aim is not the protection of his data but revenge, he repeatedly resorts to verbal abuse and deliberately spreads insults (see excerpts: "That's complete humbug, insanity, and the height of stupidity," OZ 1, p. 519; "Are you such an idiot?" OZ 1, p. 161), categorically questions professional competence (see excerpts: "As lawyers, you should know that," OZ 1, p. 257; "Although the respondent's officers are all Doctors of Law, they apparently don't know the data protection laws," OZ 1, p. 424), and hurls accusations (see excerpts: "The infamous, demonstrable lies of the Federal Ministry XXXX [...]" OZ 1, p. 393; "Defamation, insult, damage to credit, slander, and possibly abuse of office"). (OZ 1, p. 134). The corresponding findings therefore had to be made. In summary, there is no doubt about the primary intention of the appellant. The obviously litigious appellant is actively seeking confrontation and merely uses the data protection concerns as a pretext. If the appellant were truly concerned with protecting his data – as he repeatedly asserts in his appeal against the decision (OZ 1, pp. 218, 225, 227) – he would present the facts objectively and directly, instead of constantly resorting to wild accusations, sweeping attacks, and threats. This is particularly evident from the fact that the appellant's submissions clearly demonstrate his capacity for a refined and coherent presentation of his case. Since, as already stated, his aim is not to protect his data but to seek revenge, he repeatedly resorts to verbal abuse and deliberately spreads insults (see excerpts: "That's complete humbug, insanity, and incredibly stupid," OZ 1, p. 519; "Are you such an idiot?" OZ 1, p. 161), categorically questions professional competence (see excerpts: "As lawyers, you should know that," OZ 1, p. 257; "Although the respondent's officers are all Doctors of Law, they apparently don't know the data protection laws." OZ 1, p. 424), and hurls accusations (see excerpts: "The infamous, demonstrable lies of the Federal Ministry Roman numeral 40 [...]" OZ 1, p. 393; "Defamation, insult, damage to credit, slander, and possibly a Abuse of office (OZ 1, p. 134). The corresponding findings therefore had to be made.
2.5. The findings regarding the appellant's income are based on his own statements (OZ 1, p. 135). In his appeal against the decision, the appellant once again confirmed his strained financial situation (OZ 1, p. 226).
3. Legal Assessment:
Regarding point A) of the ruling
3.1. Regarding the subject matter of the proceedings:
If, as in this case, XXXX has refused to process the data protection complaint pursuant to Article 57(4) GDPR, it has not examined the content of the data protection complaint and has not made a substantive decision on it. Rather, XXXX has refused to examine the content of the data protection complaint. The "matter" of the appeal proceedings before the Administrative Court is therefore solely the question of the legality of the refusal to process the data protection complaint. This alone constitutes the subject matter of the appeal proceedings before the Administrative Court. A substantive decision on the data protection complaint would, in fact, constitute an unlawful overstepping of the scope of the appeal proceedings. The Administrative Court is not limited to examining the specific reasoning of XXXX, but must comprehensively and conclusively assess the grounds for rejection invoked by XXXX. If necessary (and no case under Section 28 Paragraph 3 Sentence 2 of the Administrative Court Procedure Act applies), the Administrative Court must itself establish the facts relevant for examining the legality of the rejection of the data protection complaint pursuant to Article 57 Paragraph 4 GDPR (see Austrian Administrative Court [VwGH] 29 January 2025, Ra 2023/04/0002, RS8). If, as in this case, the Administrative Court has refused to process the data protection complaint pursuant to Article 57 Paragraph 4 GDPR, it has not examined the content of the data protection complaint or made a substantive decision on it. Rather, the Administrative Court has refused to examine the content of the data protection complaint. The "matter" of the appeal proceedings before the Administrative Court (VwG) is therefore solely the question of the legality of the refusal to address the merits of the data protection complaint. This alone constitutes the subject matter of the appeal proceedings before the VwG. A substantive decision on the data protection complaint would, in fact, constitute an unlawful exceeding of the scope of the appeal proceedings. The VwG is not limited to examining the specific reasoning of Article 40, but must comprehensively and conclusively assess the ground for refusal invoked by Article 40. If necessary (and no case under Section 28, Paragraph 3, Sentence 2 of the Administrative Court Procedure Act (VwGVG) applies), the VwG must itself establish the facts relevant for examining the legality of the refusal of the data protection complaint pursuant to Article 57, Paragraph 4 of the GDPR (see VwGH 29.01.2025, Ra 2023/04/0002, RS8).
Therefore, the legality of the refusal to address the complaint had to be examined.
The legality of the refusal to address the complaint had to be examined. 3.2. Regarding the refusal to process the complaint:
Pursuant to Article 57(1)(f) GDPR, each supervisory authority must address complaints from data subjects within its territory, investigate the subject matter of the complaint to a reasonable extent, and inform the complainant within a reasonable timeframe of the progress and outcome of the investigation, in particular if further investigation or coordination with another supervisory authority is necessary.
In contrast, Article 57(4) GDPR provides that, in the case of manifestly unfounded or – particularly in the case of frequent repetition – excessive requests, the supervisory authority may charge a reasonable fee based on administrative costs or refuse to act on the request. In this case, the supervisory authority bears the burden of proof for the manifestly unfounded or excessive nature of the request, whereby the term "request" also includes complaints under Article 57(1)(f) and Article 77(1) GDPR (see, in this regard, CJEU 09.01.2025, C-416/23, Austrian Data Protection Authority [Excessive Requests], paragraphs 25 et seq., 41). In this case, the supervisory authority bears the burden of proof for the manifestly unfounded or excessive nature of the request, whereby the term "request" also includes complaints under Article 57(1)(f) and Article 77(1) of the GDPR (see CJEU 09.01.2025, C-416/23, Austrian Data Protection Authority [Excessive Requests], paragraphs 25 et seq., 41).
Article 57(4) of the GDPR establishes two alternative conditions – the "manifest unfoundedness" or "excessiveness" of requests – which, in these exceptional cases, entitle the supervisory authority either to refuse to act on the complaint or to impose a reasonable fee based on administrative costs. The assessment of whether a complaint is to be regarded as “manifestly unfounded” or “excessive” within the meaning of Article 57(4) GDPR requires an objective assessment of the circumstances of each individual case (see Austrian Administrative Court [VwGH] 29 January 2025, Ra 2022/04/0049, para. 16). Article 57(4) GDPR establishes two alternative conditions – the “manifest unfoundedness” or “excessiveness” of requests – which, in these exceptional cases, entitle the supervisory authority either to refuse to act on the complaint or to impose a reasonable fee based on administrative costs. The assessment of whether a complaint is to be considered "manifestly unfounded" or "excessive" within the meaning of Article 57(4) GDPR requires an objective evaluation of the circumstances of each individual case (see Austrian Administrative Court [VwGH] 29 January 2025, Ra 2022/04/0049, para. 16).
3.2.1. In the present case, this means:
Since the term "request" also encompasses data protection complaints under Article 77(1) GDPR – such as the one at hand – the provisions regarding "manifest unfoundedness" and "excessiveness" apply to the present case.
3.3. Regarding excessiveness:
According to the case law of the CJEU, requests cannot be classified as “excessive” within the meaning of Article 57(4) GDPR solely on the basis of their number during a specific period, since the exercise of the power provided for in that provision requires the supervisory authority to demonstrate the existence of an abusive intent on the part of the requesting person. This reflects the Court's settled case law, according to which there is a general principle of law in EU law that citizens may not rely on EU legal provisions in a fraudulent or abusive manner. However, the frequency of complaints from an individual can be an indication of excessive requests if it turns out that the complaints are not objectively justified by considerations relating to the protection of the rights conferred on that individual by the GDPR (see CJEU 09.01.2025, C-416/23, Austrian Data Protection Authority [Excessive Requests], paragraphs 49, 57, 59). According to the CJEU's case law, requests cannot be classified as ‘excessive’ within the meaning of Article 57(4) GDPR solely on the basis of their number during a particular period, since the exercise of the power provided for in that provision requires the supervisory authority to demonstrate the existence of an abusive intent on the part of the requesting individual. This reflects the Court's settled case law, according to which there is a general principle of law in EU law that citizens may not rely on EU legal provisions in a fraudulent or abusive manner. However, a person's frequent complaints can be an indication of excessive requests if it turns out that the complaints are not objectively justified by considerations relating to the protection of the rights granted to that person by the GDPR (see CJEU 09.01.2025, C-416/23, Austrian Data Protection Authority [Excessive Requests], paras. 49, 57, 59).
However, the frequency of complaints from a person can be an indication of excessive requests if it turns out that the complaints are not objectively justified by considerations relating to the protection of the rights granted to that person by the GDPR (see CJEU 09.01.2025, C-416/23, Austrian Data Protection Authority [Excessive Requests], paras. 49, 57, 59). Essentially, an intent to abuse the system under Article 57(4) GDPR can be assumed if the complainant's decisive reasons for filing numerous data protection complaints do not lie in pursuing their rights under the GDPR, and the complainant would not have raised the numerous data protection complaints without these extraneous reasons.
In essence, an intent to abuse the system under Article 57(4) GDPR can be assumed if the complainant's decisive reasons for filing numerous data protection complaints do not lie in pursuing their rights under the GDPR, and the complainant would not have raised the numerous data protection complaints without these extraneous reasons. Filing a data protection complaint is therefore abusive if the complainant raises the complaint to achieve a purpose not protected by data protection regulations (such as publicity, hostility, or sensationalism), but especially if the complainant must be aware of the incorrectness of their legal position, for example, because they have already unsuccessfully filed the same – or similar – complaint (see Austrian Administrative Court [VwGH] 29.01.2025, Ra 2022/04/0049, para. 30 et seq.; and Austrian Administrative Court [VwGH] 29.01.2025, Ra 2023/04/0002). Filing a data protection complaint is therefore abusive if the complainant raises the complaint to achieve a purpose not protected by data protection regulations (such as publicity, hostility, or sensationalism), but especially if the complainant must be aware of the incorrectness of their legal position, for example, because they have already unsuccessfully filed the same – or similar – complaint (see Austrian Administrative Court [VwGH] 29.01.2025, Ra 2022/04/0049, para. 30 et seq.). The complainant must be aware of the incorrectness of their legal position, for example, because they have already unsuccessfully filed the same – or similar – complaints (see Austrian Administrative Court [VwGH] 29.01.2025, Ra 2022/04/0049, para. 30 et seq.; and VwGH 29.01.2025, Ra 2023/04/0002).
3.3.1. For the present data protection complaint, this means:
Since the respondent authority rejected the processing of 20 data protection complaints from the complainant in the present decision, among other things, on the grounds of excessiveness, an objective assessment of the circumstances of each individual case must be undertaken.
3.3.2. Regarding quantitative excessiveness:
As established, the appellant filed one individual complaint with the respondent authority on April 25, 2021, and 19 more between November 29, 2023, and August 21, 2024 (an average of one complaint every 14 days) alleging data protection violations. While the appellant's relatively high complaint frequency alone does not necessarily indicate excessiveness, this accumulation of inquiries by the appellant does suggest excessiveness, as it can impair the proper functioning of the authority and an excessive number of submissions (particularly between November 29, 2023, and August 21, 2024) unduly ties up its resources.
As established, the appellant initiated one individual complaint on April 25, 2021, and 19 more individual complaints between November 29, 2023, and August 21, 2024. The data protection complaints in question are usually only a few pages long, and the attachments are generally limited to the preceding correspondence regarding the data subject's rights with the respective respondent. The substantive processing effort for each individual data protection complaint—in contrast to the total number—is limited and does not indicate any (quantitative) excessiveness.
3.3.3. Regarding qualitative excessiveness:
Qualitative excessiveness exists particularly in cases where an excessive amount of unsubstantiated or rambling statements leads to increased processing effort. In the opinion of the adjudicating panel, the structure, organization, and comprehensibility of the content can also play a role. This follows, among other things, from the fact that the purpose of Article 57(4) GDPR is, among other things, to conserve the resources of the supervisory authorities (see Zavadil in Knyrim, DatKomm Art. 57 GDPR, para. 28). Qualitative excessiveness is particularly evident in cases where an excessive amount of unsubstantiated or rambling statements leads to increased processing effort, whereby, in the opinion of the adjudicating panel, the structure, organization, and comprehensibility of the content can also play a role. This follows, among other things, from the fact that the purpose of Article 57(4) GDPR is, among other things, to conserve the resources of the supervisory authorities (see Zavadil in Knyrim, DatKomm Art. 57 GDPR, para. 28).
The data protection complaints in question are written concisely and to the point. The complainant typically argues that he submitted a request for information which went unanswered, thus constituting a violation of his right to information (see, for example, OZ 1, pp. 199 ff., 360 ff.; 466 ff.). The complainant thus presents a concrete set of facts in a clear and understandable manner, which would allow for prompt processing. The complainant's data protection complaints are short and concise. The complainant typically argues that he submitted a request for information which went unanswered, thus constituting a violation of his right to information (see, for example, OZ 1, pp. 199 ff., 360 ff.; 466 ff.). The complainant thus presents a concrete set of facts in a clear and understandable manner, which would allow for prompt processing.
It should be noted that the complainant did not use the structured forms provided by the authority for the data protection complaint in question, but instead submitted his submissions exclusively via email, attaching the complaint and supporting documents. It is acknowledged that the use of the authority's form is not mandatory; however, it is specifically designed to facilitate structured submissions for unrepresented individuals and to enable the authority to quickly grasp the necessary elements of a data protection complaint. The complainant, however, deliberately chose not to use the authority's form. This fact is not particularly significant in this case, as the complainant was nevertheless able to formulate his request in a concrete and structured manner.
It is acknowledged that the use of the authority's form is not mandatory, but rather serves to facilitate structured submissions for individuals who are not represented and allows the authority to quickly grasp the necessary components of a data protection complaint. It should be noted, however, that the complainant always marked his enclosures with slanted watermarks (“XXXX Secret XXXX Secret XXXX Secret”), which makes them difficult to read, but by no means impossible, and therefore this circumstance is not considered a major issue.
3.3.4. Regarding the purpose of the data protection complaints:
In addition to brief descriptions of the alleged data protection violation, the data protection complaints usually contain numerous accusations against the respective defendants and are written in a provocative, aggressive, and sometimes insulting style. As noted, the complainant's primary purpose with his data protection complaints is to harass the authority in question and to express his displeasure with other persons, authorities, and companies. He uses his data protection complaints to get back at these entities/individuals and harbors a hostile attitude toward them and the authority in question. While the complainant's fundamental desire for data protection is certainly discernible, it is overshadowed by the aggressive and hostile language used in his complaints.
An objective review of the complainant's 20 data protection complaints reveals that he consistently feels unfairly treated or offended by the respective complainants and uses the data protection complaint as a form of retaliation. This is particularly evident in the fact that the complainant almost invariably demands the "highest possible penalty."
Considering the principle of European law that citizens may not invoke EU law in a fraudulent or abusive manner (see ECJ 09.01.2025, C-416/23, Austrian Data Protection Authority [Excessive Requests], para. 49), it becomes clear that a data protection complaint before the authority in question may not be used by the complainant to express their displeasure, insult individuals and authorities, or act out their hostility towards them. to insult and act out his hostility towards them.
The complainant is therefore not pursuing any purpose protected by data protection regulations. Such extraneous motives as those pursued by the complainant are explicitly cited by the courts as abusive (see Austrian Administrative Court [VwGH] 29.01.2025, Ra 2022/04/0049, para. 31 regarding "hostility"). The purpose pursued by the complainant with his data protection complaints is thus clearly abusive. The purpose pursued by the complainant with his data protection complaints is therefore clearly abusive.
3.3.5. Conclusion:
Upon objective consideration of all elements of the present case, the adjudicating panel concludes that the complainant acted excessively and pursued an abusive purpose with the data protection complaints in question. While the qualitative elements argue against excessiveness, stronger considerations point to the complainant's intent to abuse the system: In particular, the high number of complaints (especially in the period from November 29, 2023, to August 21, 2024) and the clearly abusive purpose pursued by the complainant with his data protection complaints, when all circumstances are considered together, unequivocally demonstrate the complainant's intent to abuse the system and thus the excessiveness of his data protection complaints. Data protection cannot serve as a pretext for the complainant to act out his hostility towards individuals, entities, and authorities. In an overall assessment, the data protection complaint filed by the BF was therefore abusive and excessive within the meaning of Article 57(4) GDPR, in accordance with the cited case law of the CJEU and the Austrian Administrative Court (VwGH). Upon objective consideration of all elements of the case, the panel concludes that the BF acted excessively and pursued an abusive purpose with the data protection complaints in question. While the qualitative elements argue against excessiveness, stronger factors support the BF's intent to abuse the system: In particular, the high number of complaints (especially in the period from November 29, 2023, to August 21, 2024) and the clearly abusive purpose pursued by the BF with its data protection complaints, when all circumstances are considered together, unequivocally demonstrate the BF's intent to abuse the system and thus the excessiveness of its data protection complaints. Data protection cannot serve as a pretext for the appellant to act out hostility towards individuals, entities, and authorities. Considering all the circumstances, the appellant's data protection complaint was therefore abusive and excessive within the meaning of Article 57(4) GDPR, in accordance with the cited case law of the CJEU and the Austrian Administrative Court (VwGH).
Against this background, the respondent authority's alternative argument of the manifest lack of merit in its data protection complaints did not require further consideration.
3.4. Regarding the rejection:
In the case of excessive requests, the supervisory authority may, by reasoned decision, choose whether to charge a reasonable fee based on administrative costs or to refuse to act on the request, taking into account all relevant circumstances and ensuring that the chosen option is appropriate, necessary, and proportionate (CJEU 09.01.2025, C-416/23, Austrian Data Protection Authority [Excessive Requests], para. 70).
The suitability of collecting fees will be denied, for example, if the enforceability of the fee assessment is doubtful due to the financial situation of the appellant (see Austrian Administrative Court [VwGH] 29.01.2025, Ra 2023/04/0002, para. 25).
3.4.1. In the present case, this means:
Considering that the complainant has a very low income and is in a strained financial situation, the respondent authority's decision to refuse to process the complaints appears understandable. After all, a "reasonable fee" for processing 20 data protection complaints would represent a considerable additional financial burden for the complainant, who is already experiencing financial difficulties. The respondent authority's decision to refuse to process the data protection complaint therefore appears appropriate.
If the complainant believes in his appeal against the decision that he has the right to choose in this matter, he overlooks the fact that the respondent authority (and not he) has the freedom to choose between the two options. The "appropriate fee" is not to be based on the appellant's income, as the appellant claims, but rather on the administrative costs incurred due to the excessive number of complaints (see the appellant's submissions, OZ 1, p. 226; for the legal arguments, see ECJ 09.01.2025, C-416/23, Austrian Data Protection Authority [Excessive Requests], paras. 62, 68, 70).
3.5. The respondent authority was therefore correct, pursuant to Article 57(4) GDPR, in refusing to act on the appellant's request. The appeal against this decision was therefore to be dismissed.
3.5. The respondent authority was therefore correct, pursuant to Article 57(4) GDPR, in refusing to act on the appellant's request. The appeal against this decision was therefore to be dismissed. 3.6. The examination of the numerous employees of the respondent authority requested by the appellant was unnecessary, as they are not inherently suitable to contribute to the determination of the relevant facts (in particular, the purposes pursued by the appellant) (see Austrian Administrative Court [VwGH] 17 December 2024, Ra 2023/10/0373, para. 18). Insofar as the appellant demands their examination due to their (alleged) bias, he overlooks the fact that this (potential) procedural defect is remedied by proper proceedings before the Administrative Court – as is the case here (see Austrian Administrative Court [VwGH] 22 May 2023, Ra 2023/10/0037, para. 11). The examination of the numerous employees of the respondent authority requested by the appellant could be dispensed with, as they are not inherently suitable to contribute to the determination of the relevant facts (in particular, the purposes pursued by the appellant) (see VwGH 17.12.2024, Ra 2023/10/0373, para. 18). Insofar as the appellant demands their examination with regard to their (alleged) bias, he overlooks the fact that this (potential) procedural defect is remedied by proper proceedings before the Administrative Court – as is the case here (see VwGH 22.05.2023, Ra 2023/10/0037, para. 11).
3.7. The oral hearing could be dispensed with pursuant to Section 24 Paragraph 2 Item 1 of the Administrative Court Procedure Act (VwGVG).
3.8. The decision was rendered as stated above.
Regarding point B) Inadmissibility of the appeal:
Pursuant to Section 25a Paragraph 1 of the Administrative Court Act (VwGG), the Administrative Court must state in the operative part of its judgment or decision whether the appeal is admissible pursuant to Article 133 Paragraph 4 of the Federal Constitutional Law (B-VG). This statement must be briefly reasoned.
Pursuant to Section 25a Paragraph 1 of the Administrative Court Act (VwGG), the Administrative Court must state in the operative part of its judgment or decision whether the appeal is admissible pursuant to Article 133 Paragraph 4 of the Federal Constitutional Law (B-VG). This statement must be briefly reasoned. The appeal is inadmissible pursuant to Article 133(4) of the Austrian Federal Constitutional Law (B-VG) because the decision does not depend on the resolution of a legal question of fundamental importance. The court was able to rely on the established and clear case law of the European Court of Justice (ECJ) and the Austrian Administrative Court (VwGH) regarding the refusal of the respondent authority to act on a request.




