BVwG - W254 2313142-1

From GDPRhub
BVwG - W254 2313142-1
Court: BVwG (Austria)
Jurisdiction: Austria
Relevant Law: Article 5 GDPR
Article 6 GDPR
Article 12 GDPR
Article 13 GDPR
Article 14 GDPR
DSG § 1
Decided: 08.01.2026
Published: 02.03.2026
Parties:
National Case Number/Name: W254 2313142-1
European Case Law Identifier: ECLI:AT:BVWG:2026:W254.2313142.1.00
Appeal from:
Appeal to: Unknown
Original Language(s): German
Original Source: RIS (in German)
Initial Contributor: n/a

A court held that an electricity network operator unlawfully continued to store and use a data subject’s email address after it falsely confirmed the email address’ deletion.

English Summary

Facts

The data subject had initially requested that a electricity network operator (the controller) delete his email address from its systems. In March 2022, the controller confirmed that the deletion had been carried out. Nevertheless, in January 2024 the controller again contacted the data subject via the same email address to send a notification regarding a reading of the electricity meter.

The data subject subsequently filed a complaint with the Austrian Data Protection Authority (DSB), arguing that the controller continued to process his personal data despite assuring him that it had been deleted. After the DSB failed to issue a decision within the six-month deadline, the data subject brought an inactivity complaint before the Federal Administrative Court on 23 February 2025, requesting that the court decide the case itself.

During the proceedings, the controller initially argued that the email might have been collected again elsewhere due to human error. However, after a further internal review, the controller acknowledged that the email address had in fact not been deleted in 2022 as previously stated and had remained stored in its system until April 2024, when it was finally deleted.

Holding

The court partially upheld the complaint.

Because the controller retained the email address and used it to send a notification to the data subject, the court found that the processing lacked any valid legal basis under Article 6(1) GDPR. As a result, the court concluded that the processing was unlawful and therefore violated the principle of lawfulness under Article 5(1)(a) GDPR. The continued retention and use of the email address after a deletion request also contravened the principles of purpose limitation and data minimisation under Article 5(1)(b) and (c) GDPR, since the data were used again despite the data subject’s request that they no longer be stored. Furthermore, the controller breached the accountability principle under Article 5(2) GDPR by initially claiming that the data had been deleted and only later admitting that the email address had in fact remained stored until 2 April 2024 due to internal procedural failures. In light of these circumstances, the court also found a violation of the data subject’s fundamental right to secrecy under § 1(1) DSG.

However, the court rejected the complaint insofar as it alleged infringements of the transparency and information obligations under Articles 12, 13, and 14 GDPR. The court reasoned that these provisions apply where personal data are newly collected or obtained, whereas in this case the controller had not collected the email address again but had merely continued to store it in its system. Since no new data collection took place, the controller could not have violated the information obligations linked to such collection.

The court also dismissed the complaint regarding the right to erasure under Article 17 GDPR as inadmissible. It held that the exercise of the right to erasure requires a prior request by the data subject directed to the controller in relation to the specific processing at issue. Because the data subject did not submit a new deletion request to the controller after the email was used again in January 2024 and instead directly lodged a complaint with the authority, the procedural requirement for invoking Article 17 GDPR had not been fulfilled. The first erasure request by the data subject was already subject to previous procedures before the DPA.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the German original. Please refer to the German original for more details.

Decision Date

January 8, 2026

Legal Norm

Federal Constitutional Law (B-VG) Art. 133 para. 4
Data Protection Act (DSG) §1
Data Protection Act (DSG) §1 para. 1
Data Protection Act (DSG) §24
General Data Protection Regulation (GDPR) Art. 12
General Data Protection Regulation (GDPR) Art. 13
General Data Protection Regulation (GDPR) Art. 14
General Data Protection Regulation (GDPR) Art. 17 para. 1
General Data Protection Regulation (GDPR) Art. 5 para. 1 lit. a
General Data Protection Regulation (GDPR) Art. 5 para. 1 lit. b
General Data Protection Regulation (GDPR) Art. 5 para. 1 lit. c
General Data Protection Regulation (GDPR) Art. 5 para. 2
General Data Protection Regulation (GDPR) Art. 6
General Data Protection Regulation (GDPR) Art. 6 para. 1
Administrative Court Procedure Act (VwGVG) §16
Administrative Court Procedure Act (VwGVG) §8

Federal Constitutional Law (B-VG) Art. 133 today: Federal Constitutional Law (B-VG) Art. 133 valid from January 1, 2019 to May 24, 2018, last amended by Federal Law Gazette I No. 138/2017; Federal Constitutional Law (B-VG) Art. 133 valid from January 1, 2019, last amended by Federal Law Gazette I No. Article 133 of the Federal Constitutional Law (B-VG) valid from May 25, 2018 to December 31, 2018, last amended by Federal Law Gazette I No. 22/2018; Article 133 of the Federal Constitutional Law (B-VG) valid from August 1, 2014 to May 24, 2018, last amended by Federal Law Gazette I No. 164/2013; Article 133 of the Federal Constitutional Law (B-VG) valid from January 1, 2014 to July 31, 2014, last amended by Federal Law Gazette I No. 51/2012; Article 133 of the Federal Constitutional Law (B-VG) valid from January 1, 2004 to December 31, 2013, last amended by Federal Law Gazette I No. 100/2003; Article 133 of the Federal Constitutional Law (B-VG) valid from January 1, 1975 to 31.12.2003, last amended by Federal Law Gazette No. 444/1974. Federal Constitutional Law Art. 133, valid from 25.12.1946 to 31.12.1974, last amended by Federal Law Gazette No. 211/1946. Federal Constitutional Law Art. 133, valid from 19.12.1945 to 24.12.1946, last amended by State Law Gazette. No. 4/1945 B-VG Art. 133 valid from January 3, 1930 to June 30, 1934

DSG Art. 1 § 1 now DSG Art. 1 § 1 valid from January 1, 2014, last amended by Federal Law Gazette I No. 51/2012 DSG Art. 1 § 1 valid from January 1, 2000 to December 31, 2013

DSG Art. 1 § 1 now DSG Art. 1 § 1 valid from January 1, 2014, last amended by Federal Law Gazette I No. 51/2012 DSG Art. 1 § 1 valid from January 1, 2000 to December 31, 2013

DSG Art. 2 § 24 now DSG Art. 2 § 24 valid from July 15, 2024, last amended by Federal Law Gazette I No. 70/2024. Data Protection Act (DSG) Art. 2 § 24, valid from May 25, 2018 to July 14, 2024, last amended by Federal Law Gazette I No. 120/2017. Data Protection Act (DSG) Art. 2 § 24, valid from January 1, 2010 to May 24, 2018, last amended by Federal Law Gazette I No. 133/2009. Data Protection Act (DSG) Art. 2 § 24, valid from January 1, 2000 to December 31, 2009.

Administrative Court Procedure Act (VwGVG) § 16, now VwGVG § 16, valid from July 1, 2021, last amended by Federal Law Gazette I No. 109/2021. VwGVG § 16, valid from January 1, 2014 to June 30, 2021

Administrative Court Procedure Act (VwGVG) § 8 (now VwGVG § 8, valid from January 1, 2014)

Judgment

W254 2313142-1/6E

IN THE NAME OF THE REPUBLIC!

I. The Federal Administrative Court, composed of Judge Dr. Tatjana Cardona as presiding judge, and lay judges Mag. Viktoria Haidinger and Mag. Thomas Gschaar as associate judges, renders the following judgment in closed session regarding the appeal XXXX concerning the Data Protection Authority's breach of its duty to decide on a data protection complaint dated August 17, 2024 (respondent: XXXX, represented by: Baker & McKenzie Attorneys at Law LLP & Co KG): Roman numeral one. The Federal Administrative Court, composed of Judge Dr. Tatjana Cardona as presiding judge, and lay judges Mag. Viktoria Haidinger and Mag. Thomas Gschaar as associate judges, renders the following judgment in non-public session regarding complaint number 40 concerning a breach of the duty to decide by the Data Protection Authority regarding a data protection complaint dated August 17, 2024 (respondent: Roman 40, represented by: Baker & McKenzie Rechtsanwälte LLP & Co KG):

A)

1. The data protection complaint is partially granted, and it is determined that the respondent violated the complainant's right to confidentiality under Section 1 Paragraph 1 of the Data Protection Act (DSG) and his rights under Article 5 Paragraph 1 Letters a, b, and c, Article 5 Paragraph 2, and Article 6 Paragraph 1 of the General Data Protection Regulation (GDPR) by continuing to use the email address on the appellant's behalf despite the alleged deletion of the email address. 1. The data protection complaint is partially upheld, and it is determined that the respondent violated the complainant's right to confidentiality under Section 1, Paragraph 1 of the Austrian Data Protection Act (DSG) and his rights under Article 5, Paragraph 1, Letters a, b, and c, Article 5, Paragraph 2, and Article 6, Paragraph 1 of the GDPR by reusing the email address on January 26, 2024, despite the alleged deletion of the email address.

2. The data protection complaint for violation of Articles 12, 13, and 14 of the GDPR is dismissed as unfounded.

B)

The appeal on points of law is inadmissible pursuant to Article 133, Paragraph 4 of the Austrian Federal Constitutional Law (B-VG).
... II. The Federal Administrative Court, composed of Judge Dr. Tatjana Cardona as presiding judge, and lay judges Mag. Viktoria Haidinger and Mag. Thomas Gschaar as associate judges, renders the following decision in a non-public session regarding the appeal of XXXX concerning the Data Protection Authority's breach of its duty to decide on a data protection complaint dated August 17, 2024 (respondent: XXXX, represented by: Baker & McKenzie Rechtsanwälte LLP & Co KG): II. The Federal Administrative Court, composed of Judge Dr. Tatjana Cardona as presiding judge, and lay judges Mag. Viktoria Haidinger and Mag. Thomas Gschaar as associate judges, renders the following decision regarding the appeal of XXXX concerning the Data Protection Authority's breach of its duty to decide on a data protection complaint dated August 17, 2024 (respondent: XXXX, represented by: Baker & McKenzie Rechtsanwälte LLP & Co KG): , represented by: Baker & McKenzie Rechtsanwälte LLP & Co KG) in a non-public session, the following decision:

A)

The data protection complaint alleging a violation of Article 17(1) GDPR is dismissed as inadmissible.

B)

The appeal on points of law is inadmissible pursuant to Article 133(4) of the Austrian Federal Constitutional Law (B-VG).

Text

Reasons for the Decision:

I. Procedural History:

1. In the data protection complaint at hand, dated August 17, 2024, the complainant alleged a violation of his fundamental right to confidentiality pursuant to Section 1(1) of the Austrian Data Protection Act (DSG) and of Articles 5, 6, 12, 13, 14, and 17 GDPR by the respondent, a network operator. 1. In the data protection complaint dated August 17, 2024, the complainant alleged a violation of his fundamental right to confidentiality under Section 1, Paragraph 1 of the Austrian Data Protection Act (DSG) and Articles 5, 6, 12, 13, 14, and 17 of the GDPR by the respondent, a network operator.

The complainant essentially argued that the respondent—despite having been repeatedly assured of the requested deletion of his email address from the system in connection with other previously initiated data protection proceedings—contacted him again by email on January 26, 2024. This disregard of his previously requested and assured deletion constituted a violation of his right to confidentiality under Section 1, Paragraph 1 of the DSG and a violation of Article 6 of the GDPR. Furthermore, the respondent allegedly violated the principles of lawfulness, fairness, transparency, purpose limitation, and data minimization as defined in Article 5 of the GDPR, or failed to demonstrate compliance with these principles. If the respondent re-entered the email address between its deletion and the sending of the email in question, the complainant was not informed of this, resulting in a violation of Articles 12, 13, and 14 of the GDPR. The complainant essentially argued that the respondent, despite having been repeatedly assured of the requested deletion of the complainant's email address from the system in connection with other previously initiated data protection proceedings, contacted him again by email on January 26, 2024. This disregard of his previously requested and assured deletion constituted a violation of his right to confidentiality under Section 1, Paragraph 1 of the German Federal Data Protection Act (BDSG) and a violation of Article 6 of the GDPR. Furthermore, the respondent violated the principles of lawfulness, fairness, transparency, purpose limitation, and data minimization as defined in Article 5 of the GDPR, or failed to demonstrate compliance with these principles. If the respondent re-entered the email address between its deletion and the sending of the email in question, the respondent was not informed of this, resulting in a violation of Articles 12, 13, and 14 of the GDPR.

In addition, the complainant requested that the initiation of an official review procedure and administrative penalty proceedings against the respondent be considered, and that the complainant participate in these proceedings as a private party with a lump sum payment of EUR 5,000.

The complainant attached the email dated January 26, 2024, to the data protection complaint; the email concerned an electricity meter reading.

2. In a statement dated October 18, 2024, the respondent replied – insofar as relevant to the proceedings – that he was legally obligated to read the meter and that customers were sent a notification in this regard. The fact that this notification was mistakenly sent to the complainant by email instead of by post could only have been due to human error, for which the respondent apologized. It was true that the respondent had deleted the complainant's email address. That it was subsequently reused could only be because it had been collected (newly) elsewhere in the meantime. The respondent could not reconstruct or otherwise verify with certainty whether and when this had occurred. After the deletion, an internal note was also made in the system indicating that the complainant did not wish to be contacted by email and therefore the email address should not be collected or used again. The respondent regretted that an error had apparently occurred in this matter. Therefore, the internal systems were examined again, the email address was deleted once more, and a note was also made to ensure that no further emails would be sent to the complainant in the future.

3. The appellant responded – insofar as relevant to the proceedings – by letter dated December 3, 2024, stating that he contested the respondent's obligation to read the electricity meter for further reasons. Regarding the deletion of his email address, the respondent had lost credibility in light of the prior proceedings, although it was legally irrelevant whether the email address was deleted and re-entered or never deleted at all.

4. On February 23, 2025, the appellant filed the present complaint for failure to act with the respondent authority, citing the expiration of the six-month decision period. He requested that the Federal Administrative Court decide the matter itself, impose a penalty on the respondent, and order the respondent authority to bear the costs of the complaint for failure to act, as well as reimburse the appellant for these costs.


4. 5. On March 6, 2025, the respondent submitted supporting documentation, stating that after a thorough review of the procedures, it had determined that, despite internal instructions, it had apparently not permanently deleted the appellant's email address from its system by April 2, 2024. Only on that date was the deletion actually and definitively carried out.

6. By letter dated April 18, 2025, received by the Federal Administrative Court on April 23, 2025, the respondent authority submitted the complaint of failure to act, along with the administrative act.
... II. The Federal Administrative Court considered:

1. Findings:

By letter dated February 28, 2022, the appellant requested the respondent to delete his email address from its system and, in this context, filed a data protection complaint – not at issue here – on February 27, 2023. The respondent stated by letter dated March 28, 2022, that it had deleted the appellant's email address.

On January 26, 2024, the respondent contacted the appellant again via his email address XXXX@gmx.at. The appellant then filed the data protection complaint now at issue with the Data Protection Authority on August 17, 2024, again requesting the deletion of his email address. This request was not preceded by any related request for deletion addressed to the respondent. On January 26, 2024, the respondent contacted the complainant again via his email address 40@gmx.at. The complainant then submitted the present data protection complaint to the Data Protection Authority on August 17, 2024, again requesting the deletion of his email address. This request was not preceded by any related request for deletion addressed to the respondent.

Due to faulty internal procedures, the respondent did not actually delete the complainant's email address from its system on March 28, 2022, but only on April 2, 2024.










... 2. Evaluation of Evidence:

The findings are based on the undisputed submissions of the parties. The respondent ultimately stated in a letter dated March 6, 2025, and provided supporting documentation, that faulty internal processes had resulted in the appellant's email address not being deleted from their system until April 2, 2024, despite prior notification to the contrary.

3. Legal Assessment:

Regarding A)

3.1. Legal Basis:

Section 1 of the Data Protection Act (DSG) – Fundamental Right to Data Protection

(1) Everyone has the right to the confidentiality of their personal data, particularly with regard to respect for their private and family life, insofar as there is a legitimate interest in such confidentiality. Such an interest is precluded if data is not subject to a claim for confidentiality due to its general availability or because it cannot be traced back to the data subject.

(2) Unless the processing of personal data is necessary to protect the vital interests of the data subject or is carried out with their consent, restrictions on the right to confidentiality are only permissible to safeguard overriding legitimate interests of another party. In the case of interventions by a public authority, such restrictions are only permissible on the basis of laws that are necessary for the reasons stated in Article 8(2) of the European Convention for the Protection of Human Rights and Fundamental Freedoms (ECHR), Federal Law Gazette No. 210/1958. Such laws may only permit the processing of data that is particularly sensitive by its nature to safeguard important public interests and must simultaneously establish appropriate safeguards for the protection of the data subjects' confidentiality interests. Even in the case of permissible restrictions, the interference with the fundamental right may only be carried out in the least intrusive manner necessary to achieve the objective. (2) Insofar as the use of personal data is not in the vital interest of the data subject or with their consent, restrictions on the right to confidentiality are only permissible to protect overriding legitimate interests of another party, and in the case of interference by a public authority, only on the basis of laws that are necessary for the reasons stated in Article 8, paragraph 2, of the European Convention for the Protection of Human Rights and Fundamental Freedoms (ECHR), Federal Law Gazette No. 210 of 1958. Such laws may only provide for the use of data that are particularly worthy of protection by their nature to protect important public interests and must at the same time establish appropriate safeguards for the protection of the data subjects' confidentiality interests. Even in the case of permissible restrictions, the interference with the fundamental right may only be carried out in the least intrusive manner necessary to achieve the objective.


``` (3) Everyone has the right, insofar as personal data concerning them is intended for automated processing or for processing in manually maintained files (i.e., without automated processing), in accordance with statutory provisions:

1. the right to information about who processes which data concerning them, where the data originates, and for what purpose it is used, including, in particular, to whom it is transmitted;

2. the right to rectification of inaccurate data and the right to erasure of unlawfully processed data.

(4) Restrictions on the rights under paragraph 3 are only permissible under the conditions specified in paragraph 2.

(4) Restrictions on the rights under paragraph 3 are only permissible under the conditions specified in paragraph 2.












... Article 5 GDPR – Principles for the Processing of Personal Data

(1) Personal data must be

a) processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”);

b) collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be deemed incompatible with the original purposes in accordance with Article 89(1) (“purpose limitation”);

c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimization”);

d) accurate and, where necessary, kept up to date; All reasonable steps must be taken to ensure that personal data which are inaccurate with regard to the purposes for which they are processed are erased or rectified without delay (“accuracy”);

e) are stored in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed; personal data may be stored for longer periods insofar as, subject to the implementation of appropriate technical and organisational measures required by this Regulation to safeguard the rights and freedoms of the data subject, the personal data are processed solely for archiving purposes in the public interest or for scientific or historical research purposes or statistical purposes in accordance with Article 89(1) (“storage limitation”);

f) are processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures (“integrity and confidentiality”);

(2) The controller is responsible for compliance with paragraph 1 and must be able to demonstrate such compliance (“accountability”).

Article 6 GDPR – Lawfulness of processing

(1) Processing shall be lawful only if at least one of the following conditions is met:

a) The data subject has given consent to the processing of his or her personal data for one or more specific purposes;

b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

c) processing is necessary for compliance with a legal obligation to which the controller is subject;

d) processing is necessary in order to protect the vital interests of the data subject or of another natural person;

e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

Paragraph 1(f) shall not apply to processing carried out by public authorities in the performance of their tasks.

(2) Member States may maintain or introduce more specific provisions to adapt the application of the provisions of this Regulation with regard to processing for the purposes of paragraph 1(c) and (e), by specifying more precisely the specific requirements for processing and other measures to ensure lawful and fair processing, including for other specific processing situations referred to in Chapter IX.

(3) The legal basis for processing referred to in paragraph 1(c) and (e) shall be determined by:

(a) Union law or

(b) the law of the Member State to which the controller is subject.

(2) Member States may maintain or introduce more specific provisions to adapt the application of the provisions of this Regulation with regard to processing for the purposes of paragraph 1(c) and (e), by specifying more precisely the specific requirements for processing and other measures to ensure lawful and fair processing, including for other specific processing situations referred to in Chapter IX. The purpose of the processing must be specified in this legal basis or, with regard to processing pursuant to paragraph 1(e), must be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This legal basis may contain specific provisions to adapt the application of the rules of this Regulation, including provisions on the general conditions governing the lawfulness of processing by the controller, the types of data processed, the data subjects, the entities to which and for what purposes the personal data may be disclosed, the purpose limitation, the storage period, and the processing operations and procedures that may be used, including measures to ensure lawful and fair processing, such as those for other specific processing situations referred to in Chapter IX. Union or Member State law must pursue an objective in the public interest and be proportionate to the legitimate aim pursued. The purpose of the processing must be specified in this legal basis or, with regard to processing pursuant to paragraph 1(e), be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This legal basis may contain specific provisions to adapt the application of the rules of this Regulation, including provisions on the general conditions governing the lawfulness of processing by the controller, the types of data processed, the data subjects, the entities to which and the purposes for which personal data may be disclosed, the purpose limitation, the storage period, and the processing operations and procedures that may be used, including measures to ensure lawful and fair processing, such as those for other specific processing situations referred to in Chapter IX. Union or Member State law must pursue an objective in the public interest and be proportionate to the legitimate aim pursued.

This legal basis may contain specific provisions to adapt the application of the rules of this Regulation, including provisions on the general conditions governing the lawfulness of processing by the controller, the types of data processed, the data subjects, the entities to which and the purposes for which personal data may be disclosed, the purpose limitation, the storage period, and the processing operations and procedures that may be used, including measures to ensure lawful and fair processing, such as those for other specific processing situations referred to in Chapter IX. Union or Member State law must pursue an objective in the public interest and be proportionate to the legitimate aim pursued.


This legal basis may include provisions on the application of the law of Union or Member States law. (4) Where processing for a purpose other than that for which the personal data were collected is not based on the data subject’s consent or on Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard the objectives referred to in Article 23(1), the controller, in order to determine whether processing for a different purpose is compatible with that for which the personal data were originally collected, shall take into account, inter alia,

a) any link between the purposes for which the personal data were collected and the purposes of the intended further processing,

b) the context in which the personal data were collected, in particular with regard to the relationship between the data subjects and the controller,

c) the nature of the personal data, in particular whether special categories of personal data are processed pursuant to Article 9 or whether personal data relating to criminal convictions and offences are processed pursuant to Article 10,

d) the possible consequences of the intended further processing for the data subjects,

e) the existence of suitable Guarantees, which may include encryption or pseudonymization.

Article 12 GDPR – Transparent information, communication, and modalities for exercising the rights of the data subject

(1) The controller shall take appropriate measures to provide the data subject with all information referred to in Articles 13 and 14 and all communications referred to in Articles 15 to 22 and Article 34 relating to processing in a concise, transparent, intelligible, and easily accessible form, using clear and plain language, in particular for information addressed specifically to children. The information shall be provided in writing or by other means, including, where appropriate, electronically. If requested by the data subject, the information may be given orally, provided that the data subject’s identity has been verified by other means.

(1) (2) The controller shall facilitate the exercise of the data subject’s rights under Articles 15 to 22. In the cases referred to in Article 11(2), the controller may refuse to act on the data subject’s request to exercise their rights under Articles 15 to 22 only if they can credibly demonstrate that they are unable to identify the data subject.

(3) The controller shall provide the data subject with information on the measures taken in response to a request under Articles 15 to 22 without undue delay and in any event within one month of receipt of the request. This period may be extended by a further two months where necessary, taking into account the complexity and number of requests. The controller shall inform the data subject of any extension of this period, together with the reasons for the delay, within one month of receipt of the request. Where the data subject makes the request electronically, the information shall be provided electronically where possible, unless the data subject requests otherwise.

(4) If the controller does not act on a request from the data subject, the controller shall inform the data subject without delay, and at the latest within one month of receipt of the request, of the reasons for not acting and of the possibility of lodging a complaint with a supervisory authority or seeking a judicial remedy.

(5) Information pursuant to Articles 13 and 14 and all communications and actions pursuant to Articles 15 to 22 and Article 34 shall be provided free of charge. In the case of manifestly unfounded or excessive requests from a data subject, particularly in the case of frequent repetition, the controller may either

a) charge a reasonable fee, taking into account the administrative costs of providing the information or communication or taking the action requested, or

b) refuse to act on the request.

The controller shall bear the burden of proof that the request is manifestly unfounded or excessive.

(6) If the controller has reasonable doubts about the identity of the natural person making the request pursuant to Articles 15 to 21, he may, without prejudice to Article 11, request additional information necessary to confirm the identity of the data subject.

(7) The information to be provided to data subjects pursuant to Articles 13 and 14 may be provided in combination with standardized pictorial symbols to give a clear, easily recognizable, and readily understandable overview of the intended processing. Where the pictorial symbols are presented electronically, they must be machine-readable.

(8) The Commission is empowered to adopt delegated acts pursuant to Article 92 to determine the information to be presented by pictorial symbols and the procedures for providing standardized pictorial symbols.

Article 13 GDPR – Information to be provided when personal data are collected from the data subject

(1) Where personal data are collected from the data subject, the controller shall, at the time when personal data are collected, provide the data subject with the following information:

a) the name and contact details of the controller and, where applicable, of the controller’s representative;

b) where applicable, the contact details of the data protection officer;

c) the purposes for which the personal data are to be processed and the legal basis for the processing;

d) where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party;

e) where applicable, the recipients or categories of recipients of the personal data and

f) where applicable, the controller’s intention to transfer personal data to a third country or international organisation, and the existence or absence of an adequacy decision by the Commission or, in the case of transfers pursuant to Article 46 or Article 47 or Article 49(1), second subparagraph, reference to the appropriate or suitable safeguards and how a copy of them can be obtained or where they are available.

(2) In addition to the information referred to in paragraph 1, the controller shall, at the time the personal data are collected, provide the data subject with the following additional information necessary to ensure fair and transparent processing:

a) the period for which the personal data will be stored, or, if that is not possible, the criteria used to determine that period;

b) the existence of the right to request from the controller access to the personal data concerning the data subject, as well as the right to rectification or erasure of personal data or restriction of processing, or to object to such processing, and the right to data portability;

c) where processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;

d) the right to lodge a complaint with a supervisory authority;

(e) whether the provision of personal data is required by law or contract, or is necessary for entering into a contract, whether the data subject is obliged to provide the personal data, and the possible consequences of failure to provide such data;

(f) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

(3) Where the controller intends to further process the personal data for a purpose other than that for which the personal data were collected, the controller shall, before such further processing, provide the data subject with information on that other purpose and any other relevant information referred to in paragraph 2.

(4) Paragraphs 1, 2, and 3 shall not apply where and to the extent that the data subject already possesses the information.


(f) Article 14 GDPR – Information to be provided where personal data have not been obtained from the data subject

(1) Where personal data are not obtained from the data subject, the controller shall provide the data subject with the following information:

a) the name and contact details of the controller and, where applicable, of the controller’s representative;

b) the contact details of the data protection officer;

c) the purposes for which the personal data are to be processed and the legal basis for the processing;

d) the categories of personal data concerned;

e) where applicable, the recipients or categories of recipients of the personal data;

(f) where applicable, the controller’s intention to transfer personal data to a recipient in a third country or an international organisation, and the existence or absence of an adequacy decision by the Commission or, in the case of transfers pursuant to Article 46 or Article 47 or Article 49(1), second subparagraph, reference to the appropriate or suitable safeguards and the means of obtaining a copy of them or where they have been made available.

(2) In addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following information necessary to ensure fair and transparent processing of personal data:

(a) the period for which the personal data will be stored, or, if that is not possible, the criteria used to determine that period;

(b) where processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party;

c) the existence of the right to obtain from the controller confirmation as to whether or not personal data concerning the data subject are being processed, and, where that is the case, access to the personal data and the following information: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal data have been or will be disclosed; where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period; the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; the right to lodge a complaint with a supervisory authority;

f) the source of the personal data and, where applicable, whether or not they were obtained from publicly available sources;

g) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.


(d) where processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. (3) The controller shall provide the information referred to in paragraphs 1 and 2

a) taking into account the specific circumstances of the processing of the personal data, within a reasonable period after obtaining the personal data, but not later than one month,

b) if the personal data are to be used for communication with the data subject, at the latest at the time of the first communication to the data subject, or

c) if disclosure to another recipient is intended, at the latest at the time of the first disclosure.

(4) Where the controller intends to further process the personal data for a purpose other than that for which the personal data were obtained, the controller shall, before such further processing, provide the data subject with information on that other purpose and any other relevant information referred to in paragraph 2.

(5) Paragraphs 1 to 4 shall not apply where and to the extent that

a) the data subject already has the information,

b) providing that information proves impossible or would involve a disproportionate effort; This applies in particular to processing for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes, subject to the conditions and safeguards referred to in Article 89(1), or where the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing. In such cases, the controller shall take appropriate measures to safeguard the rights and freedoms and legitimate interests of the data subject, including making the information available to the public;

(c) the obtaining or disclosure is expressly regulated by Union or Member State law to which the controller is subject and which provides for appropriate measures to safeguard the legitimate interests of the data subject; or

(d) the personal data are subject to professional secrecy under Union or Member State law, including a statutory duty of confidentiality, and must therefore be treated confidentially.


(c) the processing is subject to professional secrecy under Union or Member State law, including a statutory duty of confidentiality. Article 17 GDPR – Right to Erasure (“Right to be Forgotten”)

(1) The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay, and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:

a) The personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed.

b) The data subject withdraws consent on which the processing is based according to point (a) of Article 6(1) or point (a) of Article 9(2), and where there is no other legal ground for the processing.

c) The data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2).

d) The personal data have been unlawfully processed.

e) The erasure of the personal data is necessary for compliance with a legal obligation under Union or Member State law to which the controller is subject.

f) The personal data were collected in relation to the offer of information society services referred to in Article 8(1).

(2) Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase them, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copies or replications of, those personal data.

(3) Paragraphs 1 and 2 shall not apply to the extent that processing is necessary

a) for exercising the right of freedom of expression and information;

b) for compliance with a legal obligation to which the controller is subject under Union or Member State law, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

c) for reasons of public interest in the area of public health, in accordance with Article 9(2)(h) and (i) and Article 9(3);

d) for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with Article 89(1), insofar as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or

e) for the establishment, exercise, or defense of legal claims.

Section 24 of the Data Protection Act (DSG) – Complaint to the Data Protection Authority

(1) Every data subject has the right to lodge a complaint with the Data Protection Authority if they believe that the processing of their personal data infringes the GDPR or Section 1 or Article 2, Chapter 1. This does not apply insofar as a right to lodge a complaint with the Parliamentary Data Protection Committee exists pursuant to Section 35f, paragraph 1.

(1) Every data subject has the right to lodge a complaint with the Data Protection Authority if they believe that the processing of their personal data infringes the GDPR or Section 1 or Article 2, Chapter 1. This does not apply insofar as a right to lodge a complaint with the Parliamentary Data Protection Committee exists pursuant to Section 35f, paragraph 1. (2) The complaint must contain:

1. the designation of the right allegedly violated,

2. where reasonable, the designation of the legal entity or body to which the alleged violation is attributed (respondent),

3. the facts from which the violation is derived,

4. the grounds on which the claim of unlawfulness is based,

5. the request to establish the alleged violation, and

6. the information necessary to assess whether the complaint was filed in a timely manner.

(3) Where appropriate, the underlying application and any response from the respondent must be attached to a complaint. The Data Protection Authority shall provide further assistance to the data subject upon request in the event of a complaint.


``` (4) The right to have a complaint addressed expires if the complainant does not submit it within one year of becoming aware of the event giving rise to the complaint, but no later than three years after the event allegedly occurred. Complaints submitted after this deadline must be rejected.

(5) If a complaint is found to be justified, it must be granted. If a violation is attributable to a controller in the private sector, that controller must be ordered to comply with the complainant's requests for access, rectification, erasure, restriction of processing, or data portability to the extent necessary to remedy the established violation. If the complaint is found to be unjustified, it must be dismissed.

(6) A respondent may remedy the alleged violation retroactively until the conclusion of the proceedings before the Data Protection Authority by complying with the complainant's requests. If the Data Protection Authority considers the complaint moot in this respect, it must hear the complainant on this point. At the same time, the complainant must be informed that the data protection authority will terminate the proceedings informally if he does not provide reasons within a reasonable period of time as to why he still considers the originally alleged infringement of rights to be at least partially unremedied. If such a statement by the complainant fundamentally alters the nature of the case (Section 13(8) of the General Administrative Procedure Act), the original complaint is to be considered withdrawn and a new complaint filed simultaneously. In this case as well, the original complaint proceedings must be terminated informally and the complainant notified accordingly. Late submissions are not to be considered. (6) A respondent may subsequently remedy the alleged infringement of rights until the conclusion of the proceedings before the data protection authority by complying with the complainant's requests. If the data protection authority considers the complaint moot in this respect, it must hear the complainant on this point. At the same time, the complainant must be informed that the data protection authority will terminate the proceedings informally if he does not provide reasons within a reasonable period of time as to why he still considers the originally alleged infringement to be at least partially unremedied. If such a statement by the complainant fundamentally alters the nature of the case (Section 13, paragraph 8, of the General Administrative Procedure Act), the original complaint shall be deemed withdrawn and a new complaint filed simultaneously. In this case as well, the original complaint proceedings shall be terminated informally, and the complainant shall be notified accordingly. Late submissions shall not be considered.

(7) The complainant shall be informed by the Data Protection Authority of the status and outcome of the investigation within three months of the complaint being filed.

(8) Any data subject may appeal to the Federal Administrative Court if the Data Protection Authority fails to address the complaint or fails to inform the data subject of the status or outcome of the complaint within three months.

(9) The Data Protection Authority may, where necessary, appoint experts to the proceedings.


(7) Data Protection Authority shall inform the complainant of the status and outcome of the complaint within three months. (10) The following are not included in the decision period pursuant to Section 73 of the General Administrative Procedure Act (AVG):

1. the time during which the proceedings are suspended pending a final decision on a preliminary issue;

2. the time during proceedings pursuant to Articles 56, 60, and 63 of the GDPR.

Section 8 of the Administrative Court Procedure Act (VwGVG) – Time Limit for Filing a Complaint for Inaction

(1) A complaint for breach of the obligation to decide pursuant to Article 130(1)(3) of the Federal Constitutional Law (B-VG) (complaint for inaction) may only be filed if the authority has not decided the matter within six months, or, if a shorter or longer decision period is provided for by law, within that period. The time limit begins when the application for a decision on the merits is received by the authority to which it was to be submitted. The appeal shall be dismissed if the delay is not due to the overriding fault of the authority. (1) An appeal for breach of the duty to decide pursuant to Article 130, paragraph 1, point 3, of the Austrian Federal Constitutional Law (appeal for failure to act) may only be lodged if the authority has not decided the matter within six months, or, if a shorter or longer decision period is provided for by law, within that period. The time limit begins when the application for a decision on the merits is received by the authority to which it was to be submitted. The appeal shall be dismissed if the delay is not due to the overriding fault of the authority.

(2) The following shall not be included in the time limit:

1. the time during which the proceedings are suspended pending a final decision on a preliminary issue;

2. the time of proceedings before the Administrative Court, the Constitutional Court, or the Court of Justice of the European Union.


Section 16 of the Administrative Court Procedure Act (VwGVG) – Issuance of a Decision

(1) In proceedings concerning complaints regarding a violation of the duty to decide pursuant to Article 130, paragraph 1, item 3 of the Federal Constitutional Law (B-VG), the authority may issue the decision within a period of up to three months. If the decision is issued, or if it was issued before the commencement of the proceedings, the proceedings must be discontinued.

(2) If the authority fails to issue the decision, it must submit the complaint to the Administrative Court, attaching the files of the administrative proceedings. At the same time, the authority must notify the parties of the submission of the complaint to the Administrative Court; this notification must include the instruction that all written submissions must be filed directly with the Administrative Court from the date the complaint is submitted.

(1) In proceedings concerning complaints regarding a violation of the duty to decide pursuant to Article 130, paragraph 1, item 3 of the Federal Constitutional Law (B-VG), the authority may issue the decision within a period of up to three months. If the decision is issued, or if it was issued before the commencement of the proceedings, the proceedings must be discontinued.

(2) If the authority fails to issue the decision, it must submit the complaint to the Administrative Court, attaching the files of the administrative proceedings. At the same time, the authority must send the parties a notification of the submission of the complaint to the Administrative Court; this notification must include the instruction that all written submissions must be filed directly with the Administrative Court from the date the complaint is submitted.


(1) In proceedings concerning complaints regarding a violation of the duty to decide pursuant to Article 130, paragraph 1, item 3 of the Federal Constitutional Law (B-VG). 3.2. Failure of the Respondent Authority:

The data protection complaint in question was filed with the respondent authority on August 17, 2024, and the six-month decision period pursuant to Section 73 Paragraph 1 of the General Administrative Procedure Act (AVG) expired on February 17, 2025. Since no decision had been issued by then, and it is not apparent that the delay was not due to the authority's predominant fault, the complaint for failure to act, filed on February 23, 2025, is admissible. As the authority also failed to issue the decision within three months as required by Section 16 of the Administrative Court Procedure Act (VwGVG), jurisdiction for the decision was transferred to the Federal Administrative Court. Since no decision had been issued by that date and it is not apparent that the delay was not due to the authority's overriding fault, the complaint of default filed on February 23, 2025, is admissible. As the authority also failed to issue the decision within three months as required by Section 16 of the Administrative Court Procedure Act (VwGVG), jurisdiction for the decision was transferred to the Federal Administrative Court.

3.3. On the merits:

3.3.1. Regarding the (un)lawfulness of the processing pursuant to Article 6 GDPR:

The complainant alleged that the respondent was processing his email address unlawfully and thus infringing Article 6 GDPR.

























































] Specifically, the complainant has undoubtedly and indisputably not given consent to the processing of his email address (Art. 6 para. 1 lit. a). The processing of the email address is also not necessary for the performance of a contract, especially since the respondent himself stated that he could also contact the complainant by post regarding this matter (lit. b). The respondent has not claimed, nor is it otherwise apparent, that the processing would be necessary for compliance with a legal obligation, for the protection of the vital interests of the complainant or a third party, for the performance of a task carried out in the public interest or in the exercise of official authority, or finally for the purposes of the legitimate interests pursued by the respondent or a third party (lit. c, d, e and f). Specifically, the complainant has undoubtedly and indisputably not given consent to the processing of his email address (Art. 6 para. 1 lit. a). The processing of the email address is also not necessary for the performance of a contract, especially since the respondent himself stated that he could also contact the complainant by post regarding this matter (paragraph b). The respondent did not claim, nor is it otherwise apparent, that the processing would be necessary for compliance with a legal obligation, for the protection of the vital interests of the complainant or third parties, for the performance of a task carried out in the public interest or in the exercise of official authority, or finally for the purposes of the legitimate interests pursued by the respondent or a third party (paragraphs c, d, e and f).

A review of the conditions for a data protection complaint under Article 6(1) GDPR thus reveals that the complainant is correct in his assertion – a fact which the respondent at least implicitly acknowledged in his communication of March 6, 2025.

The data protection complaint is therefore to be upheld in this respect.

3.3.2. On the principles for the processing of personal data pursuant to Article 5 GDPR: 3.3.2. Regarding the principles for the processing of personal data pursuant to Article 5 GDPR:

In his data protection complaint, the complainant alleged a violation of the principles of lawfulness, fairness, transparency, purpose limitation, and data minimization, as well as the related accountability under Article 5(1)(a), (b), and (c), and (2) GDPR.

As already explained in section II.3.3.1 above, the data processing in question was unlawful, thus constituting a violation of Article 5(1)(a) GDPR. Therefore, the data processing in question was unlawful, and thus already constitutes a violation of Article 5(1)(a) GDPR.

Even if the complainant's email address was originally collected for legitimate purposes, this legitimacy was lost when it was not deleted despite a corresponding request. Consequently, the current use of the email address cannot be considered a compatible, purposeful (further) processing and therefore violates the purpose limitation principle of Article 5(1)(b) GDPR.

Even if the complainant's email address was originally collected for legitimate purposes, this legitimacy was lost when it was not deleted despite a corresponding request. Therefore, the current use of the email address cannot be considered a compatible, purposeful (further) processing and therefore violates the purpose limitation principle of Article 5(1)(b) GDPR. Accordingly, this renewed use of the email address was not compatible with the principle of data reduction to the unavoidable and thus data minimization pursuant to Article 5(1)(c) GDPR.
































`` Since the respondent only announced on March 6, 2025, that contrary to its previous statements, it had not deleted the complainant's email address by April 2, 2024, it also violated the accountability requirement under Article 5(2) GDPR.

The data protection complaint is therefore upheld in this respect.

3.3.3. Regarding the fundamental right to confidentiality under Section 1 of the GDPR: Regarding the fundamental right to confidentiality under Section 1 of the GDPR:

The complainant also alleged a violation of his fundamental right to confidentiality under Section 1 of the GDPR due to the use of his email address.

Due to the direct applicability of the GDPR, a Union law-compliant interpretation of Section 1 of the GDPR is required (Lachmayer in Knyrim, DatKomm Art 1 GDPR (as of December 1, 2018, rdb.at), para. 70), which is why the provisions of Article 6(1) of the GDPR must be taken into account. Due to the direct applicability of the GDPR, a Union law-compliant interpretation of Section 1 of the Austrian Data Protection Act (DSG) is required (Lachmayer in Knyrim, DatKomm Article 1, GDPR (as of December 1, 2018, rdb.at), para. 70), which is why the provision of Article 6, paragraph 1, GDPR must be taken into account.

It should first be noted that there is no indication, nor has the respondent claimed, that the complainant's email address is publicly available or would not allow for its traceability to the complainant, so the exclusion clause of Section 1, paragraph 1, second sentence, of the DSG does not apply.


There is no indication, nor has the respondent claimed, that the complainant's email address is publicly available or would not allow for its traceability to the complainant, so the exclusion clause of Section 1, paragraph 1, second sentence, of the DSG does not apply. A restriction of the right to confidentiality is therefore only permissible under Section 1 Paragraph 2 of the German Data Protection Act (DSG) if the processing is carried out in the vital interest of the data subject or with their consent, or if it is necessary for the purposes of the legitimate interests pursued by another party.

These grounds correspond to those in Article 6 Paragraph 1 Letters a, d, and f of the GDPR. See above under point II.3.3.1. As already explained, there was neither a vital interest nor the complainant's consent to the processing of his email address, nor was a legitimate interest of another party – in particular the respondent – asserted, nor would this otherwise be apparent, especially since the respondent itself stated in its communication of March 6, 2025, that it could also contact the complainant in another way – namely by post – and therefore did not need his email address or, literally, had "no interest" in contacting him by email against his wishes. Therefore, the complaint was to be upheld on this point. These facts correspond to those in Article 6, paragraph 1, letters a, d, and f of the GDPR. As explained above under point II.3.3.1. As already explained, there was neither a vital interest nor the complainant's consent to the processing of his email address, nor was a legitimate interest of another party – in particular the respondent – asserted, nor would such an interest otherwise be apparent, especially since the respondent itself stated in its communication of March 6, 2025, that it could also contact the complainant in another way – namely by post – and therefore did not need his email address or, literally, had "no interest" in contacting him by email against his wishes. Therefore, the complaint was to be upheld on this point.

3.3.4. Regarding the transparency and information obligations under Articles 12, 13, and 14 GDPR: 3.3.4. Regarding the transparency and information obligations under Articles 12, 13, and 14 of the GDPR:

Furthermore, in the present data protection complaint, the complainant alleged that the respondent had violated its information obligations under Articles 13 and 14 of the GDPR in connection with the collection of personal data and had therefore failed to provide him with transparent information as required by Article 12 of the GDPR.











``` ` ... This relates to the respondent's previous statement that he deleted his email address on March 28, 2022, and that the renewed contact via this same email address could only be due to its having been re-registered in the meantime, although the respondent did not know how this had happened (see the statement of October 18, 2024, para. 9). However, the respondent subsequently stated that, after reviewing the events again, he had determined that, contrary to his previous statements, he had actually only deleted the complainant's email address from his system on April 2, 2024 (see the communication of March 6, 2025). This means that the respondent never re-registered the complainant's email address, nor did he need to, as it was already stored in the system. Accordingly, in the absence of a new collection of data, the respondent could not infringe the complainant's rights to information regarding the collection of personal data under Articles 13 and 14 GDPR, nor could it act contrary to the transparency requirements of Article 12 GDPR. This is related to the respondent's previous statement that he deleted his email address on March 28, 2022, and that the renewed contact via this very email address could only be due to its having been collected in the meantime, although the respondent does not know how this occurred (see the statement of October 18, 2024, paragraph 9). Most recently, however, the respondent stated that, after a further review of the procedures, he had determined that, contrary to his previous statements, he had in fact only deleted the complainant's email address from his system on April 2, 2024 (see notification of March 6, 2025). This means that the respondent never collected, nor did he need to collect, the complainant's email address again, as it was already stored in the system. Accordingly, due to the lack of a new collection, the respondent could not infringe upon the complainant's rights to information regarding the collection of personal data under Articles 13 and 14 of the GDPR, nor could he act contrary to the transparency requirements of Article 12 of the GDPR.

The data protection complaint is therefore dismissed in this respect.

3.3.5. Regarding the right to erasure under Article 17 GDPR:

In the present data protection complaint, the complainant asserted a violation of his right to erasure under Article 17 GDPR in connection with the (renewed) use of his email address – thus personal data within the meaning of Article 4(1) GDPR – by the respondent – indisputably the controller within the meaning of Article 4(7) GDPR.

According to Article 17(1), the data subject has the right to request from the controller the immediate erasure of personal data concerning him or her where one of the grounds for erasure applies and no exception under paragraph 3 applies. The right to erasure, like most data subject rights, can therefore be exercised by submitting a request to the controller. (Jahnel, Commentary on the General Data Protection Regulation, Article 17 GDPR, para. 9 [as of December 1, 2020, rdb.at]) (Jahnel, Commentary on the General Data Protection Regulation, Article 17, GDPR, para. 9 [as of December 1, 2020, rdb.at])

However, this requires, as a matter of fact, a corresponding request addressed to the respondent. Such a request is not present in these proceedings. While the complainant had already requested the deletion of his email address by the respondent in another data protection proceeding by letter dated February 28, 2022, he had already filed a data protection complaint regarding this matter on February 27, 2023. With regard to the (renewed) use of his email address on January 26, 2024, he did not address any such request to the respondent.

A natural person who has not submitted a request before filing a complaint is not entitled to file a complaint; a request to the controller cannot be made during ongoing complaint proceedings. The fact that no application was submitted is noted by the Data Protection Authority (DPA) ex officio and leads to the rejection of the complaint (see Schweiger in Knyrim, DatKomm Art. 77 GDPR para. 18/1 [as of December 1, 2021, rdb.at]). A natural person who has not submitted an application before lodging a complaint is not entitled to lodge a complaint; an application cannot be submitted to the controller during the ongoing complaint proceedings. The fact that no application was submitted is noted by the DPA ex officio and leads to the rejection of the complaint (see Schweiger in Knyrim, DatKomm Art. 77 GDPR para. 18/1 [as of December 1, 2021, rdb.at]).

The present data protection complaint must therefore be rejected as inadmissible to that extent. Furthermore, the respondent complied with the request to delete the email address, and it was deleted from the system on April 2, 2024 (see the respondent's letter of March 6, 2025). The present data protection complaint is therefore to be dismissed as inadmissible in this respect. (See the respondent's letter of March 6, 2025.)

3.3.6. Regarding the applications for the initiation of an ex officio review procedure and administrative penalty proceedings, as well as the application to join the proceedings as a private party:

The complainant also requested that the data protection authority consider initiating an ex officio review procedure pursuant to Section 22 of the Data Protection Act. Furthermore, he requested that the data protection authority consider initiating administrative penalty proceedings (presumably pursuant to Section 62 of the Data Protection Act). Finally, in his data protection complaint, he requested, with reference to Section 29 of the Data Protection Act, to participate in administrative penalty proceedings as a private party. The complainant also requested that the data protection authority consider initiating an ex officio review procedure pursuant to Section 22 of the Data Protection Act. He further requested that the data protection authority consider initiating administrative penalty proceedings (presumably pursuant to Section 62 of the Data Protection Act). Finally, in his data protection complaint, he requested, with reference to Section 29 of the Data Protection Act, to participate in administrative penalty proceedings as a private party.


The complainant also requested that the data protection authority consider initiating an ex officio review procedure pursuant to Section 22 of the Data Protection Act. Neither the Data Protection Act (DSG) nor the General Data Protection Regulation (GDPR) establishes a subjective right to initiate such an official review procedure or such administrative penalty proceedings. Therefore, the complainant's related requests are inadmissible due to a lack of legal basis. Even if these requests are understood merely as suggestions, they do not establish an obligation for the authority to investigate, nor do they impose a duty to justify its inaction. Furthermore, Section 29 of the DSG clearly refers to civil courts for the assertion of claims for damages, meaning that the data protection authority – and subsequently the Federal Administrative Court – lacks jurisdiction to rule on such claims. Neither the DSG nor the GDPR establishes a subjective right to initiate such an official review procedure or such administrative penalty proceedings. Therefore, the complainant's related requests are inadmissible due to a lack of legal basis. Even if these requests are understood merely as suggestions, they do not establish an obligation for the authority to investigate, nor do they create an obligation to justify its inaction. Furthermore, Section 29 of the Data Protection Act (DSG) clearly refers to civil courts regarding the assertion of claims for damages, meaning that the Data Protection Authority—and subsequently the Federal Administrative Court—lacks jurisdiction to rule on such claims.

3.3.7. Regarding the request for reimbursement of the costs of the complaint for failure to act:

In the present complaint for failure to act, the complainant requested that the respondent authority be ordered to pay the costs of the complaint and that these costs be reimbursed to the complainant.

According to Section 74 of the General Administrative Procedure Act (AVG), which, pursuant to Section 17 of the Administrative Court Procedure Act (VwGVG), also applies to proceedings concerning appeals under Article 130, paragraph 1, of the Federal Constitutional Law (B-VG), each party must bear its own costs incurred in the administrative proceedings, unless otherwise provided by administrative regulations.

The appellant's request for reimbursement of the costs of the default appeal is therefore inadmissible due to a lack of legal basis.

3.4. Omission of the oral hearing:

Pursuant to Section 24, paragraph 1, of the Administrative Court Procedure Act (VwGVG), the Administrative Court must hold a public oral hearing upon request or, if it deems it necessary, ex officio. According to Section 24, Paragraph 1, of the Administrative Court Procedure Act (VwGVG), the Administrative Court must hold a public oral hearing upon request or, if it deems it necessary, ex officio.
... Pursuant to Section 24, Paragraph 4 of the Administrative Court Procedure Act (VwGVG), the Administrative Court may, notwithstanding a party's request, dispense with a hearing if the case file indicates that an oral hearing would not provide any further clarification of the case, and provided that neither Article 6, Paragraph 1 of the Convention for the Protection of Human Rights and Fundamental Freedoms nor Article 47 of the Charter of Fundamental Rights of the European Union precludes dispensing with a hearing.

According to Section 24, Paragraph 4 of the VwGVG, the Administrative Court may, notwithstanding a party's request, dispense with a hearing if the case file indicates that an oral hearing would not provide any further clarification of the case, and provided that neither Article 6, Paragraph 1 of the Convention for the Protection of Human Rights and Fundamental Freedoms nor Article 47 of the Charter of Fundamental Rights of the European Union precludes dispensing with a hearing. In the present case, the omission of an oral hearing – even one not requested – can be justified on the grounds that the facts are clear from the case file in conjunction with the appeal. The Federal Administrative Court is therefore limited to ruling on legal issues (see ECtHR 05.09.2002, Application No. 42057/98, Speil v. Austria). According to the jurisprudence of the Constitutional Court, an oral hearing may be dispensed with if the facts are undisputed and the legal question – as in this case – is not particularly complex (VfSlg. 17.597/2005; VfSlg. 17.855/2006; most recently, for example, VfGH 18.6.2012, B 155/12). In the present case, the omission of an oral hearing – even one not requested – can be based on the fact that the facts are clear from the case file in conjunction with the appeal. The Federal Administrative Court therefore has to rule exclusively on legal questions in this case (compare ECtHR 05.09.2002, Appl. No. 42057/98, Speil v. Austria). According to the jurisprudence of the Constitutional Court, an oral hearing may be dispensed with if the facts are undisputed and the legal question—as in this case—is not particularly complex (VfSlg. 17.597/2005; VfSlg. 17.855/2006; most recently, for example, VfGH 18.6.2012, B 155/12).

Regarding B) Inadmissibility of the appeal:

The appeal is inadmissible pursuant to Article 133 Paragraph 4 of the Austrian Federal Constitutional Law (B-VG) because the decision does not depend on the resolution of a legal question of fundamental importance. The present decision neither deviates from the established jurisprudence of the Administrative Court nor is there a lack of relevant case law; furthermore, the existing case law of the Administrative Court cannot be considered inconsistent. Furthermore, there are no other indications of the fundamental importance of the legal question to be resolved; rather, the underlying, undisputed facts could already be resolved based on the clear and unambiguous legal situation. The appeal is inadmissible pursuant to Article 133, paragraph 4, of the Austrian Federal Constitutional Law (B-VG) because the decision does not depend on the resolution of a legal question of fundamental importance. The present decision neither deviates from the established case law of the Administrative Court nor is there a lack of case law; furthermore, the existing case law of the Administrative Court cannot be considered inconsistent. Furthermore, there are no other indications of the fundamental importance of the legal question to be resolved; rather, the underlying, undisputed facts could already be resolved based on the clear and unambiguous legal situation.