BVwG - W287 2250962-1

From GDPRhub
BVwG - W287 2250962-1
Court: BVwG (Austria)
Jurisdiction: Austria
Relevant Law: Article 12(2) GDPR
Article 16 GDPR
Article 17 GDPR
Article 22 GDPR
Article 77(1) GDPR
§ 24(1) DSG
Decided: 01.08.2023
Published: 16.08.2023
Parties: DSB (DPA)
Unnamed data subject
National Case Number/Name: W287 2250962-1
European Case Law Identifier: ECLI:AT:BVWG:2023:W287.2250962.1.00
Appeal from: DSB (Austria)
redacted
Appeal to: Unknown
Original Language(s): German
Original Source: RIS (in German)
Initial Contributor: Ava Lang

A court held that a controller did not violate the right not to be subject to a decision based solely on automated processing because an automatic assignment of profile pictures did not constitute automated decision-making under Article 22 GDPR.

English Summary

Facts

The data subject's business profile appeared on an online platform operated by the controller. The profile displayed his name, address, telephone number, opening hours, profile pictures and information about peak visiting times.

In 2020, the data subject submitted a request seeking the erasure of his personal data. He argued that he had not consented to the processing and that some of the published data were inaccurate. In particular, he claimed that profile pictures had been wrongly associated with his business profile.

In 2021, the data subject lodged a complaint with the Austrian DPA against the controller. He alleged violations of his right to rectification (Article 16 GDPR), his right to erasure (Article 17 GDPR) and the right not to be subject to a decision based solely on automated processing (Article 22 GDPR). He argued that the controllers had rejected his erasure request and that the automatic assignment of profile pictures involved unlawful automated processing.

The DPA asked the data subject to provide evidence of a rectification request and of a request concerning Article 22 GDPR. The data subject replied that his statements about inaccurate data should be treated as an implicit rectification request. He also argued that Article 22 GDPR did not require a prior request to the controller.

The DPA rejected the complaint concerning Article 16 GDPR and Article 22 GDPR, as it found that the data subject had never submitted a rectification request or a request under Article 22 GDPR to the controllers, only a deletion request.

During the proceedings, the controllers removed and corrected some information. However, the data subject maintained that incorrect profile pictures and opening hours continued to appear because of automated updates.

Holding

First, the court held that the right to rectification under Article 16 GDPR generally required a prior request to the controller. The court noted that the data subject must identify which data are inaccurate and explain how they should be corrected. The data subject only requested erasure under Article 17 GDPR and merely stated that some data were inaccurate. He did not specify how the allegedly incorrect profile pictures or opening hours should be corrected.

The court also rejected the argument that Article 5(1)(d) GDPR imposed a standalone obligation on the controllers to correct the data without a rectification request. The court held that such an obligation only arose where the controller could concretely determine the correct data. In this case, the data subject had not provided sufficient information to enable a correction.

The court therefore confirmed that the absence of a rectification request constituted a missing procedural requirement for a complaint under Article 16 GDPR.

Second, the court noted that Article 22 GDPR may prohibit certain automated decisions even without a request from the data subject. However, the court held that the profile picture assignment did not amount to profiling or automated decision-making, as it did not evaluate personal aspects of the data subject within the meaning of Article 4(4) GDPR.

The court further held that the display of incorrect profile pictures was not a decision under Article 22 GDPR because the processing did not produce legal effects or similarly significant effects for the data subject. The court considered that the incorrect images could at most cause irritation or mild embarrassment. It found no evidence that the images affected the data subject’s legal position, reputation or business activities in a significant way.

The court therefore dismissed the complaint.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the German original. Please refer to the German original for more details.

Decision Date

August 1, 2023

Legal Norm

Federal Constitutional Law (B-VG) Art. 133 para. 4
Data Protection Act (DSG) § 24 para. 1
General Data Protection Regulation (GDPR) Art. 12 para. 2
General Data Protection Regulation (GDPR) Art. 16
General Data Protection Regulation (GDPR) Art. 17
General Data Protection Regulation (GDPR) Art. 22
General Data Protection Regulation (GDPR) Art. 77 para. 1

Federal Constitutional Law (B-VG) Art. 133 currently in force; Federal Constitutional Law (B-VG) Art. 133 valid from January 1, 2019 to May 24, 2018, last amended by Federal Law Gazette I No. 138/2017; Federal Constitutional Law (B-VG) Art. 133 valid from January 1, 2019, last amended by Federal Law Gazette I No. 22/2018; Federal Constitutional Law (B-VG) Art. 133 valid from May 25, 2018 to December 31, 2018, last amended by Federal Law Gazette I No. 22/2018; Federal Constitutional Law (B-VG) Art. 133 valid from Article 133 of the Federal Constitutional Law (B-VG) valid from 1 August 2014 to 24 May 2018, last amended by Federal Law Gazette I No. 164/2013; Article 133 valid from 1 January 2014 to 31 July 2014, last amended by Federal Law Gazette I No. 51/2012; Article 133 valid from 1 January 2004 to 31 December 2013, last amended by Federal Law Gazette I No. 100/2003; Article 133 valid from 1 January 1975 to 31 December 2003, last amended by Federal Law Gazette No. 444/1974; Article 133 valid from 25 December 1946 to 31 December 1974, last amended by Federal Law Gazette No. 211/1946 B-VG Art. 133 valid from 19.12.1945 to 24.12.1946 last amended by StGBl. No. 4/1945 B-VG Art. 133 valid from January 3, 1930 to June 30, 1934

Data Protection Act (DSG) Art. 2 § 24 now DSG Art. 2 § 24 valid from July 15, 2024, last amended by Federal Law Gazette I No. 70/2024; Data Protection Act (DSG) Art. 2 § 24 valid from May 25, 2018 to July 14, 2024, last amended by Federal Law Gazette I No. 120/2017; Data Protection Act (DSG) Art. 2 § 24 valid from January 1, 2010 to May 24, 2018, last amended by Federal Law Gazette I No. 133/2009; Data Protection Act (DSG) Art. 2 § 24 valid from January 1, 2000 to December 31, 2009

Judgment

,

W287 2250962-1/10E

IN THE NAME OF THE REPUBLIC!

The Federal Administrative Court, composed of Judge MMag.a Dr.in Julia Kusznier as presiding judge and lay judges Margareta Mayer-Hainz and Dr. Ulrich E. Zellenberg as associate judges, has rendered the following judgment on the appeal of XXXX against the decision of the Data Protection Authority dated December 10, 2021, file number XXXX (participating parties: XXXX and XXXX), in a data protection matter, after oral proceedings: The Federal Administrative Court, composed of Judge MMag.a Dr.in Julia Kusznier as presiding judge and lay judges Margareta Mayer-Hainz and Dr. Ulrich E. Zellenberg as associate judges, has rendered the following judgment: Ulrich E. ZELLENBERG, as assessor, on the appeal of [Name of Appellant] (Ref. No. 40) against the decision of the Data Protection Authority of December 10, 2021, Ref. No. 40 (participants: [Name of Appellant] and [Name of Appellant]), in a data protection matter, after oral proceedings, has ruled as follows:

A)

The appeal is dismissed as unfounded.

B)

The appeal on points of law is admissible pursuant to Article 133, paragraph 4, of the Austrian Federal Constitutional Law (B-VG).


Text

Reasons for the Decision:

I. Procedural History:

1. On [Date], the appellant submitted a request for the deletion of his personal data (OZ 3 AS. 12) using an application form provided by "XXXX". The personal data in question concerns data relating to his company and himself as XXXX. He has not given XXXX his consent to the processing of his data. Furthermore, some of the data provided is inaccurate. 1. On [date] 2020, the complainant submitted a request for the deletion of his personal data (OZ 3 AS. 12) using an application form provided by "[company name]". The personal data in question concerns data relating to his company and himself as [company name]. He has not given [company name] his consent to the processing of his data. Furthermore, some of the data provided is inaccurate.


[Date] 40. 2. By submission dated XXXX 2021, the complainant filed a data protection complaint (OZ 3 AS. 4) against XXXX and XXXX (hereinafter: "participating parties") with the Data Protection Authority (hereinafter: "respondent authority"), arguing in summary that his name, address, business hours, and telephone number were published in his XXXX company profile. Furthermore, "images of the location and of people" were displayed via "XXXX". He stated that he had never consented to the publication of this data. He also claimed that some of the published data was incorrect. His request for erasure had been rejected by "XXXX" support. The complainant considered his right to erasure under Article 17 GDPR, his right to rectification under Article 16 GDPR, his fundamental right to data protection under Section 1 Paragraph 1 of the German Federal Data Protection Act (BDSG), and his right not to be subject to a decision based solely on automated processing, including profiling, under Article 22 GDPR, to have been violated. The complainant attached a “request form for the deletion of personal data” to his written submission (OZ 3 AS. 12). 2. By submission dated [date omitted] 2021, the complainant filed a data protection complaint (OZ 3 AS. 4) against [company name omitted] and [company name omitted] (hereinafter: “participating parties”) with the Data Protection Authority (hereinafter: “respondent authority”) and argued, in summary, that his name, address, the opening hours of his company, and his telephone number were published in his [company name omitted] business profile. Furthermore, [company name omitted] displayed “images of the location and of people.” He stated that he had never consented to the publication of this data. The published data was also partially incorrect. The complainant’s request for deletion had been rejected by [company name omitted] support. The complainant claims a violation of his right to erasure under Article 17 GDPR, his right to rectification under Article 16 GDPR, his fundamental right to data protection under Section 1, Paragraph 1 of the Austrian Data Protection Act (DSG), and his right not to be subject to a decision based solely on automated processing, including profiling, under Article 22 GDPR. The complainant enclosed a "Request Form for the Erasure of Personal Data" with his written submission (OZ 3 AS. 12).

3. By letter dated [DATE] 2021, the Data Protection Authority (DSB) requested the complainant to remedy the deficiencies (OZ 3 AS. 16). In particular, the complainant was requested to submit the underlying request and any response from the respondent regarding the alleged violation of his right to rectification. By letter dated [date] 40.2021, the Data Protection Authority (DSB) requested the complainant to rectify the deficiencies (OZ 3 AS. 16). In particular, the complainant was requested to submit the underlying request and any response from the respondent regarding the alleged violation of the right to rectification of data.

4. By letter dated [date] 2021, the complainant responded to the request for rectification (OZ 3 AS. 19) and stated that the data controller automatically calculated "peak times," and thus at least implicitly the waiting times and visit durations at the law firm, based on data from [user name] users. The calculation underlying this "frequency attribution," the attribution itself, and the automated assignment of images constituted a violation, in particular of Article 22 of the GDPR. Furthermore, no specific form was required for a request for rectification. The notification to the company that the data was inaccurate should therefore be considered, at the very least, as an implicit request for rectification. 4. In a letter dated [date] 2021, the complainant responded to the request for rectification (OZ 3 AS. 19) and stated that the data controllers were automatically calculating peak times, and thus at least implicitly waiting times and visit durations at the law firm, based on data from users of [website name]. The calculation underlying this "frequency attribution" and the attribution itself, as well as the automated assignment of images, constituted a violation, in particular, of Article 22 of the GDPR. Furthermore, no specific form was required for a request for rectification. The notification to the company that the data was incorrect should therefore be considered, at the very least, as an implicit request for rectification.

5. In a letter dated [date] 2021, the respondent authority again requested the complainant to rectify the deficiencies (OZ 3 AS. 27). Regarding the alleged violation of Article 22 of the GDPR, the request and any response from the respondent were lacking. 5. By letter dated [date] 40.2021, the respondent authority again requested the complainant to remedy the deficiencies (OZ 3 AS. 27). Regarding the alleged violation of Article 22 GDPR, the request and any response from the respondent were lacking.

6. By letter dated [date] 2021, the complainant responded to the request to remedy the deficiencies (OZ 3 AS. 29) and argued that the legal opinion requiring a prior request to the controller was incompatible with both EU and constitutional law, as well as with statutory law. Even if a request were necessary to assert data subject rights, this would not apply to Article 22 GDPR. 6. In a letter dated [date] 2021, the complainant responded to the request for rectification (file reference 3, p. 29) and argued that the legal opinion requiring a prior request to the data controller was incompatible with both EU and constitutional law, as well as with statutory law. Even if a request were necessary to assert data subject rights, this did not apply to Article 22 of the GDPR.

7. The respondent authority rejected the data protection complaint in a partial decision dated [date] 2021 (file reference 3, p. 32) concerning the violation of the right to rectification and the right not to be subject to a decision based solely on automated processing. The complainant had not submitted a request for rectification or a request pursuant to Article 22 of the GDPR. The rights under Articles 15 to 22 of the GDPR are rights requiring a formal application. The complainant's letters could not be classified as a request for rectification under Article 16 GDPR. Therefore, there was an irremediable defect. 7. The respondent authority dismissed the data protection complaint by partial decision dated 40.2021 (OZ 3 AS. 32) concerning the violation of the right to rectification and the right not to be subject to a decision based solely on automated processing. The complainant had not submitted a request for rectification or a request pursuant to Article 22 GDPR. The rights under Articles 15 to 22 GDPR are rights requiring an application. The complainant's letters could not be classified as a request for rectification under Article 16 GDPR. Therefore, there was an irremediable defect.

8. The appellant filed a timely appeal against the decision cited in the ruling by letter dated XXXX 2022 (file no. 3, p. 38), essentially reiterating his previous arguments.

8. The appellant filed a timely appeal against the decision cited in the ruling by letter dated Roman 40 2022 (file no. 3, p. 38), essentially reiterating his previous arguments.

9. By submission of the file dated January 17, 2022 (file no. 3, p. 1), the respondent authority submitted the appeal against the partial decision to the Federal Administrative Court for a decision, attaching the case file, and contested the grounds of appeal in its entirety in its statement.

10. Pursuant to the order of the Business Allocation Committee dated January 25, 2022, the present case was removed from Division W253 and reassigned to Division W287.

11. By letter dated March 13, 2023, the Federal Administrative Court requested the appellant to comment on the current status. In particular, a review of the XXXX business directory listing (as of March 10, 2023) revealed that the stated opening hours had since been corrected and that the XXXX business directory listing no longer indicated any "peak hours."

11. By letter dated March 13, 2023, the Federal Administrative Court requested the appellant to comment on the current status. In particular, a review of the Roman numeral 40 business directory listing (as of March 10, 2023) revealed that the stated opening hours had since been corrected and that the Roman numeral 40 business directory listing no longer indicated any "peak hours."


12. In his statement of March 20, 2023, the appellant explained that the other parties had removed the indication of "peak hours" and adjusted the opening hours. However, the profile picture assigned to the appellant as XXXX was still incorrect.

13. On May 23, 2023, a public oral hearing was held before the Federal Administrative Court. In this hearing, the appellant essentially stated that the data concerning the opening hours (specifically, the opening hours on Fridays) and the image data had still not been corrected. The data was apparently being adjusted algorithmically, resulting in new image data being assigned regularly. If it were argued here that a one-off and temporary correction would eliminate the grievance, this would ultimately lead to the result that virtually inaccurate data could be processed continuously, provided that a one-off correction was made at some point during the proceedings.

II. The Federal Administrative Court considered: Roman numeral two. The Federal Administrative Court considered the following:

1. The following facts are established:

On [date] 2020, the appellant submitted a "request for the erasure of personal data" using the form provided by the other parties involved. The excerpt read as follows:

In a submission dated July 13, 2021, to the respondent authority, the appellant alleged that his right to rectification under Article 16 GDPR and his right not to be subject to a decision based solely on automated processing (Article 22 GDPR) had been violated. In a submission dated July 13, 2021, to the respondent authority, the complainant alleged that his right to rectification under Article 16 of the GDPR and his right not to be subject to a decision based solely on automated processing (Article 22 of the GDPR) had been violated.

The complainant's complaint was initially rejected by the parties involved. The opening hours listed in the XXXX business directory were subsequently corrected temporarily; however, at the time of the oral hearing before the Federal Administrative Court, these opening hours have again become incorrect due to a change made by the complainant. The peak hours information has been removed from the XXXX business directory. Therefore, the only remaining grounds for appeal are the incorrectly assigned profile pictures and the now-incorrect opening hours. The complainant's complaint was initially rejected by the parties involved. The opening hours listed in the business directory (category 40) were temporarily corrected. However, due to a change in opening hours by the appellant, these opening hours are now incorrect again at the time of the oral hearing before the Federal Administrative Court. The peak hours information has been removed from the business directory (category 40). The subject of the appeal is therefore now solely the argument concerning the incorrectly assigned profile pictures and the now incorrect opening hours.

The appellant has not submitted a request for rectification or a request under Article 22 of the GDPR.

The findings are based on the following evaluation of evidence:

The findings are based on the administrative act of the respondent authority and the court file of the Federal Administrative Court, in conjunction with the appellant's submissions, particularly those made during the oral hearing of May 23, 2023, and are not in dispute.


These findings are based on the administrative act of the respondent authority and the court file of the Federal Administrative Court, in conjunction with the appellant's submissions, particularly those made during the oral hearing of May 23, 2023, and are not in dispute.


The appellant has not submitted a request for rectification or a request under Article 22 of the GDPR. The finding that the complainant did not submit a request for rectification or a request pursuant to Article 22 GDPR to the other parties involved is evident from the correspondence between the complainant and the other parties submitted in the proceedings before the respondent authority, as well as from the complainant's statements in the complaint (p. 2: “[…] immediately after becoming aware of the issue on July 20, 2020, the complainant submitted a request for the deletion of the account or the (incorrect) data […]. The fact of the processing of inaccurate data was expressly stated in this form, and the inaccurate data itself was also identified”). Furthermore, the complainant repeatedly pointed out that Article 22 GDPR does not establish a right of the data subject requiring an application and that an independent obligation of the controller to correct inaccurate data can be derived from Article 5 GDPR. The finding that the complainant did not submit a request for rectification or a request under Article 22 GDPR to the other parties involved is evident from the correspondence between the complainant and the other parties submitted in the proceedings before the respondent authority, as well as from the complainant's statements in the complaint (p. 2: “[…] immediately after becoming aware of the issue on July 20, 2020, the complainant submitted a request for the deletion of the account or the (inaccurate) data […]. The fact of the processing of inaccurate data was expressly stated in this form, and the inaccurate data itself was also identified”). Furthermore, the complainant repeatedly pointed out that Article 22 of the GDPR does not establish a right of the data subject requiring an application and that an independent obligation of the controller to correct inaccurate data can be derived from Article 5 of the GDPR.

3. Legal Assessment:

Pursuant to Section 6 of the Federal Administrative Court Act (BVwGG), the Federal Administrative Court decides by a single judge unless federal or state law provides for a decision by a panel. Pursuant to Section 6 of the BVwGG, the Federal Administrative Court decides by a single judge unless federal or state law provides for a decision by a panel.

Pursuant to Section 27 of the Data Protection Act (DSG), the case falls under the jurisdiction of a panel.

Pursuant to Section 27 of the DSG, the case falls under the jurisdiction of a panel. A) Rejection of the Complaint

Pursuant to Article 77(1) GDPR and Section 24(1) of the German Data Protection Act (DSG), every data subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement, if the data subject considers that the processing of personal data relating to them infringes this Regulation or Section 1 or Article 2 of Chapter 1 of the DSG, without prejudice to any other administrative or judicial remedy. The main provision of the GDPR is violated.

The subject of the proceedings is the incorrectly assigned profile pictures and the inaccurate opening hours, as the "peak times" have since been deleted.

The respondent authority assumed that the rights under Articles 15 to 22 of the GDPR are rights requiring a formal application. Due to the lack of a request to the relevant parties pursuant to Article 22 of the GDPR and a request for rectification pursuant to Article 16 of the GDPR, an irremediable defect exists, which is why the respondent authority dismissed the complaint.

Regarding the right to rectification pursuant to Article 16 GDPR:

According to Article 16 GDPR, the data subject has the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.

The right to rectification is intended to enable the data subject to correct inaccurate data processed by the controller. In some cases, there is also a right to have incomplete personal data completed. This provision protects the data subject from disadvantages caused by inaccurate or incomplete data.

According to Article 12(2) GDPR, the controller shall facilitate the data subject's exercise of their rights under Articles 15 to 22.

The decisive point in time for assessing inaccuracy is when the request is made or when the controller reviews the data. Whether the data was correct at the time of collection is irrelevant. Haidinger derives from this an independent right to have the data updated (Haidinger in Knyrim, DatKomm Art. 17 GDPR, as of December 1, 2021, rdb.at, para. 28). Haidinger derives from this an independent right to updating (Haidinger in Knyrim, DatKomm Article 17, GDPR, as of December 1, 2021, rdb.at, para. 28).

In principle, the obligation of the controller to take independent action in the event of inaccurate personal data can only be derived from Article 16 GDPR in a limited way and in conjunction with the principles of Article 5(1) in conjunction with Article 5(2) GDPR. Because the GDPR does not contain an explicit rule regarding who has the burden of proving the inaccuracy of the data, the burden of assertion and proof initially rests with the applicant, i.e., the data subject. A corresponding request must therefore contain sufficient justification as to why the data is inaccurate and how it should be correctly presented. This assessment, as well as the possibility of lodging a complaint with the relevant authority against a failure to rectify, indicates that a request for rectification must, in principle, be submitted in the form of an application that provides reasons as to which data needs to be corrected and why. The data subject must first submit a request for rectification to the controller. The absence of such an application constitutes a lack of an essential prerequisite for success and thus an irremediable defect (Federal Administrative Court, 18 March 2019, W211 2208247-1 with further references). In principle, the obligation of the controller to take independent action in the event of inaccurate personal data can only be derived from Article 16 of the GDPR to a limited extent and in conjunction with the principles of Article 5(1) in conjunction with Article 5(2) of the GDPR. Because the GDPR does not contain an explicit rule regarding who bears the burden of proving the inaccuracy of data, the burden of assertion and proof initially rests with the applicant, i.e., the data subject. A corresponding request must therefore include sufficient justification as to why the data is inaccurate and how it should be correctly presented. This assessment, as well as the possibility of lodging a complaint with the competent authority regarding a failure to rectify, indicates that a request for rectification should, in principle, be submitted in the form of an application that provides reasoned explanations as to which data needs to be corrected and why. The data subject must first submit a request for rectification to the controller. The absence of such an application constitutes a lack of an essential prerequisite for success and thus an irremediable defect (Federal Administrative Court, March 18, 2019, W211 2208247-1 with further references).










... For all data subject rights that must be asserted upon request, a violation of the GDPR by the processing to which the respective right relates can only occur if, in the data subject's opinion, a corresponding request to the controller was not handled in accordance with the GDPR, i.e., for example, if no information was provided or the processing was not restricted. This applies to the right of access (Art. 15), the right to rectification, the right to restriction of processing (Art. 18), the notification obligation (Art. 19), the right to data portability (Art. 20), and the right to withdraw consent (Art. 21). Therefore, Section 24(3) of the Austrian Data Protection Act (DSG), which stipulates that a complaint must be accompanied, where applicable, by the underlying request and any response from the respondent, is also unproblematic with regard to these rights (Jahnel, Commentary on the General Data Protection Regulation, Art. 77 GDPR, para. 15). For all data subject rights that must be asserted upon request, a violation of the GDPR by the processing to which the respective right relates can only occur if, in the data subject's opinion, a corresponding request to the controller was not handled in accordance with the GDPR, for example, if no information was provided or the processing was not restricted. This applies to the right of access (Article 15), the right to rectification, the right to restriction of processing (Article 18), the notification obligation (Article 19), the right to data portability (Article 20), and the right to withdraw consent (Article 21). Therefore, Section 24, Paragraph 3 of the GDPR, which stipulates that a complaint must be accompanied, where applicable, by the underlying request and any response from the respondent, is also unproblematic with regard to these rights (Jahnel, Commentary on the General Data Protection Regulation, Article 77, GDPR, para. 15).

Article 16 GDPR exists independently alongside Article 17 GDPR. The right to rectification is not (procedurally) a lesser right than the right to erasure, but rather a different right altogether (Kamlah in Plath, GDPR/BDSG/TTDSG, 4th ed. 2023, Art. 16 para. 1). If a right to rectification and a right to erasure conflict with regard to the same data, the right to erasure takes precedence over the right to rectification (Peuker in Sydow/Marsch, GDPR BDSG Art. 16 para. 18; similarly Haidinger in Knyrim, DatKomm Art. 17 GDPR, as of 01.12.2021, rdb.at, para. 4). A right to rectification exists only if, in addition to the inaccuracy of the processed data, the accuracy of the data designated as correct by the data subject is also unequivocally established (Kamlah in Plath, GDPR/BDSG/TTDSG, 4th ed. 2023, Art. 16 para. 3 with reference to VGH Baden-Württemberg of 10.03.2020 and para. 5; on the requirement of an application, see also: Peuker in Sydow/Marsch, GDPR BDSG Art. 16 para. 24). In contrast, a right to erasure under Article 17 GDPR is essentially available to the data subject if the controller violates the principles of Article 5 or can no longer rely on a legal basis within the meaning of Articles 6 or 9 (Haidinger in Knyrim, DatKomm Art. 17 GDPR, as of December 1, 2021, rdb.at, para. 47). Article 16 GDPR exists independently alongside Article 17 GDPR. The right to rectification is not (procedurally) a lesser right than the right to erasure, but rather a different right altogether (Kamlah in Plath, GDPR/BDSG/TTDSG, 4th ed. 2023, Article 16, para. 1). If a right to rectification and a right to erasure conflict with regard to the same data, the right to erasure takes precedence over the right to rectification (Peuker in Sydow/Marsch, GDPR BDSG Article 16, para. 18; similarly Haidinger in Knyrim, DatKomm Article 17, GDPR, as of 01.12.2021, rdb.at, para. 4). A right to rectification exists only if, in addition to the inaccuracy of the processed data, the accuracy of the data designated as correct by the data subject is also unequivocally established (Kamlah in Plath, GDPR/BDSG/TTDSG, 4th ed. 2023, Article 16, para. 3, referring to the Higher Administrative Court of Baden-Württemberg of 10.03.2020 and para. 5; regarding the requirement of an application, similarly: Peuker in Sydow/Marsch, GDPR BDSG Article 16, para. 24). In contrast, a right to erasure under Article 17 GDPR is essentially available to the data subject if the controller violates the principles of Article 5 or can no longer rely on a legal basis within the meaning of Articles 6 or 9 (Haidinger in Knyrim, DatKomm Article 17 GDPR, as of December 1, 2021, rdb.at, para. 47).

Therefore, according to the prevailing opinion, which this panel endorses, the right to rectification is generally a right requiring a formal application.

This leads to the following conclusion in the specific case:

In this particular case, the complainant submitted a request for the erasure of the profile pictures incorrectly assigned to him. He did not explicitly request rectification and did not explain why the data was inaccurate or how it should be correctly formatted. In the application form for the erasure of personal data, the complainant merely stated as the reason for the removal that the data in question was "also partially inaccurate." The stated opening hours were incorrect. Furthermore, two different photos were linked to the account. One showed a person unknown to him, the other, although found on the internet, was copyrighted. The complainant did not provide any specific information regarding the correction of this incorrect data. Instead, he stated in his request that the personal data be deleted because he had not given XXXX his consent to the processing of his personal data. In this specific case, the complainant submitted a request to delete the profile pictures incorrectly assigned to him. He did not make an explicit request for correction and did not explain why the data was incorrect or what the correct information should be. In the request form for the deletion of personal data, the complainant merely stated as the reason for removal that the listed data was "also partially incorrect." The stated opening hours were incorrect. Furthermore, two different photos were linked to the account. One showed a person unknown to him, the other, although found on the internet, was copyrighted. The complainant did not provide any specific information regarding the correction of this incorrect data. Rather, he stated in his application that the personal data should be deleted because he had not given his consent to the processing of his personal data pursuant to Roman 40.

The complainant also stated in his complaint that he had not submitted a request for rectification pursuant to Article 16 GDPR. Article 77 GDPR establishes an independent right to lodge a complaint, which is not subject to any specific formal or substantive requirements. Furthermore, he had notified the controller of the inaccuracy of the processed data. Therefore, the controller is obligated to take all necessary measures to ensure that personal data which is inaccurate with regard to its processing is erased or rectified without undue delay.

The complainant also stated in his complaint that he had not submitted a request for rectification pursuant to Article 16 GDPR. Article 77 GDPR establishes an independent right to lodge a complaint, which is not subject to any specific formal or substantive requirements. Furthermore, he had notified the controller of the inaccuracy of the processed data. Therefore, the controller is obligated to take all necessary measures to ensure that personal data which is inaccurate with regard to its processing is erased or rectified without undue delay.

Contrary to the complainant's view, an obligation for the parties involved to take independent action based on Article 5(1)(d) GDPR cannot be derived from this provision:

While it is true that the controller is obligated to act even without a request from the data subject if they become aware of inaccuracies or grounds for erasure (Haidinger in Knyrim, DatKomm Art. 17 GDPR, as of December 1, 2021, rdb.at, para. 16), this presupposes that the controller is actually able to correct the data. In his deletion request, the appellant points out the inaccuracy of his assigned profile picture and opening hours, but fails to provide any details on how the correction should be made. The statement in the deletion request, that "two different photos were/are alternately linked to the account," is, in the opinion of the presiding panel, not sufficiently specific to establish an obligation for the other parties involved to make the corrections. The same applies to the assertion that the opening hours are incorrect. Rather, Haidinger is correct in asserting that the legal consequence of a data subject's failure to provide the correct data must be erasure (and not rectification) (Haidinger in Knyrim, DatKomm Art. 17 GDPR, as of December 1, 2021, rdb.at, footnote 87). While it is true that the controller is obligated to act even without a request from the data subject if they become aware of the inaccuracy or grounds for erasure (Haidinger in Knyrim, DatKomm Art. 17 GDPR, as of December 1, 2021, rdb.at, para. 16), this presupposes that the controller is actually able to correct the data. Although the complainant points out the inaccuracy of their assigned profile picture and opening hours in their erasure request, they fail to provide any indication of how the rectification should be carried out. The statement in the request for erasure, that "two different photos were/are alternately linked to the account," is, in the opinion of the adjudicating panel, not sufficiently specific to establish an obligation for the other parties involved to correct the data. The same applies to the assertion that the opening hours are incorrect. Rather, Haidinger is correct in asserting that the legal consequence of the data subject's failure to provide the correct data must be erasure (and not rectification) (Haidinger in Knyrim, DatKomm Article 17, GDPR, as of December 1, 2021, rdb.at, footnote 87).

Therefore, the appellant's argument that the other parties involved would be obligated to rectify the data anyway due to the principle of data accuracy is also not persuasive in the context of the appeal.


Furthermore, the appellant's argument that the other parties involved would be obligated to rectify the data anyway due to the principle of data accuracy is not persuasive in the context of the appeal. Since the required request for rectification was lacking and no independent obligation to rectify could be derived from Article 5(1)(d) GDPR in this specific case, the respondent authority's view is correct.

According to the case law of the Administrative Court, the absence of a prerequisite for success, which leads to the substantive resolution of an application by its rejection, does not constitute a "defect in a written submission" within the meaning of Section 13(3) of the General Administrative Procedure Act (AVG). Whether a prerequisite described in the law constitutes a defect leading to the rejection of the application or the absence of a prerequisite for success leading to the rejection of the application must be determined by interpreting the respective provisions of the substantive law. Defects that impair the prospects of success of an application, i.e., those that preclude a substantively positive resolution of the application, are therefore not remediable within the meaning of Section 13 Paragraph 3 of the General Administrative Procedure Act (AVG). Inadequacies in an application that do not affect its completeness but rather its prospects of success are thus not defects within the meaning of Section 13 Paragraph 3 of the AVG (see Austrian Administrative Court [VwGH] 26.04.2017, Ra 2016/05/0040). According to the jurisprudence of the Administrative Court, the absence of a prerequisite for success, leading to the substantive resolution of an application through its rejection, does not constitute a "defect in a written application" within the meaning of Section 13 Paragraph 3 of the AVG. Whether a prerequisite described in the law constitutes a defect leading to the rejection of the application or the absence of a prerequisite for success leading to the rejection of the application must be determined by interpreting the respective provisions of the substantive law. Defects that impair the prospects of success of an application, i.e., those that prevent a positive outcome on the merits of the application, are therefore not remediable within the meaning of Section 13, Paragraph 3 of the Austrian General Administrative Procedure Act (AVG). Inadequacies in the application that do not affect its completeness but rather its prospects of success are thus not defects within the meaning of Section 13, Paragraph 3 of the AVG (see Austrian Administrative Court [VwGH] decision of April 26, 2017, Ra 2016/05/0040).

The absence of a request for rectification to the responsible party constitutes the absence of an essential prerequisite for success and is therefore a defect that cannot be remedied.

The dismissal of the appeal for violation of the right to rectification by the respondent authority was therefore justified. Whether the appellant's right to erasure was violated is not the subject of these proceedings and must be clarified separately.

Regarding the right not to be subject to a decision based solely on automated processing (Article 22 GDPR):

Article 22 GDPR reads as follows:

"Automated individual decision-making, including profiling

(1) The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

(2) Paragraph 1 shall not apply if the decision

a) is necessary for entering into, or performing, a contract between the data subject and a controller,

b) is authorized by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, or

c) is based on the data subject’s explicit consent.

(3) In the In the cases referred to in paragraph 2(a) and (c), the controller shall implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.

(4) Decisions pursuant to paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1), unless Article 9(2)(a) or (g) applies and suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests have been taken.


(4) Decisions pursuant to paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1), unless Article 9(2)(a) or (g) applies and suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests have been taken. Contrary to the opinion of the respondent authority, legal scholars generally assume that Article 22 GDPR does not constitute a right requiring an application. Haidinger, in Knyrim, DatKomm Art. 22 GDPR, para. 15 (as of December 1, 2022, rdb.at), argues that Article 22 GDPR indirectly prohibits automated decision-making in individual cases, as it formulates a right without mentioning the requirement of an application. Similarly, Schulz, in Gola/Heckmann, Datenschutz-Grundverordnung Bundesdatenschutzgesetz, Art. 22, para. 5, assumes that "the data subject does not have to actively exercise their right, and the provision thus has at least an indirect prohibitive character" (similarly: Jahnel, Kommentar zur Datenschutz-Grundverordnung (DSGVO), Art. 22, para. 3). The “Guidelines on automated individual decision-making including profiling for the purposes of Regulation 2016/679 of 3 October 2017 (last revised on 6 February 2018)” issued by the Article 29 Working Party also state that Article 22(1) GDPR generally prohibits decision-making based solely on automated processing and that the term “right” in this context does not mean that Article 22(1) GDPR only applies if the data subject actively makes use of it (Guidelines p. 21). Contrary to the opinion of the respondent authority, legal scholars generally assume that Article 22 of the GDPR does not constitute a right requiring an application. Haidinger, in Knyrim, DatKomm Article 22, GDPR, para. 15 (as of December 1, 2022, rdb.at), argues that Article 22 of the GDPR indirectly prohibits automated decision-making in individual cases, as it formulates a right without mentioning the requirement of an application. Similarly, Schulz, in Gola/Heckmann, Datenschutz-Grundverordnung Bundesdatenschutzgesetz, Article 22, para. 5, assumes that "the data subject does not have to actively exercise their right, and the provision thus has at least an indirect prohibitive character" (similarly: Jahnel, Commentary on the General Data Protection Regulation (GDPR), Article 22, para. 3). The “Guidelines on automated individual decision-making including profiling for the purposes of Regulation 2016/679 of 3 October 2017 (last revised on 6 February 2018)” issued by the Article 29 Working Party also indicate that Article 22(1) of the GDPR generally prohibits decision-making based solely on automated processing and that the term “right” in this context does not mean that Article 22(1) of the GDPR only applies if the data subject actively makes use of it (Guidelines Session 21).

In the present case, however, there is neither automated decision-making in individual cases nor profiling within the meaning of Article 22 GDPR:

Regarding profiling according to Article 4, point 4 GDPR:

Article 4, point 4 GDPR reads:

"For the purposes of this Regulation, the term:

4. ‘Profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements;"


``` An “assessment of personality traits” occurs when a decision is not based solely on the information representing a personal data point or personality trait, but rather on its interpretation. This can result in, for example, shopping tips, route suggestions, job and university placements, assessments of willingness to pay, or life expectancy (Martini in Paal/Pauly, GDPR/BDSG3, Art. 22 GDPR para. 21a). Profiling thus involves the collection of specific personal data to evaluate personal aspects of a natural person. The complainant argued that two different profile pictures—neither depicting the complainant—were displayed in connection with his XXXX company profile when he entered his name into the XXXX search engine. In the opinion of the adjudicating panel, this process does not constitute the use of personal data to evaluate specific personal aspects relating to a natural person. The appellant failed to demonstrate such a claim during the proceedings; indeed, he himself admitted during the oral hearing that the specific processing operations in question probably did not constitute profiling in the strict sense. The panel also finds it unclear that specific aspects relating to his work performance, financial situation, health, personal preferences, interests, reliability, behavior, location, or changes of location are being analyzed or predicted. An "assessment of personality traits" occurs when a decision is not based solely on the information representing personal data or a personality trait, but rather on its interpretation. This can result in, for example, shopping tips, route suggestions, job and university placements, assessments of willingness to pay, or life expectancy (Martini in Paal/Pauly, GDPR/BDSG3, Article 22, GDPR para. 21a). Profiling, therefore, involves the collection of specific personal data to evaluate personal aspects of a natural person. The complainant argued that two different profile pictures—neither depicting the complainant himself—were displayed in connection with his company profile on the company website (R40) when he entered his name into the search engine. In the opinion of the panel, this does not constitute the use of personal data for the evaluation of specific personal aspects relating to a natural person. The complainant failed to demonstrate such use during the proceedings; indeed, he himself admitted during the oral hearing that the specific processing operations in question probably did not constitute profiling in the strict sense. The panel also finds no evidence that specific aspects relating to his work performance, financial situation, health, personal preferences, interests, reliability, behavior, location, or changes of location are being analyzed or predicted.

Regarding automated decision-making in individual cases:

Likewise, contrary to the complainant's view, there is no automated decision-making within the meaning of Article 22 GDPR. The requirement of a decision demands that the result of automated data processing be a constitutive act attributable to a natural or legal person, selecting from at least two options, with a conclusive effect in some sense (Schulz in Gola/Heckmann, Datenschutz-Grundverordnung Bundesdatenschutzgesetz, Art. 22 para. 17 with further references). The scope of Art. 22 para. 1 GDPR therefore does not generally cover every operation based on automated processing, but only decisions. These must be constitutive acts that make a choice between two alternatives and have an effect on the external world. The data subject should have the right not to be subject to a decision – which may include a measure – based solely on automated processing that produces legal effects concerning the data subject or similarly significantly affects them, such as the automatic rejection of an online loan application or online recruitment procedure without any human intervention (Feiler/Forgó, EU-DSGVO 2016). The mere calculation of a probability or the result of a search engine does not constitute a decision (Schulz in Gola/Heckmann, General Data Protection Regulation, Federal Data Protection Act, Art. 22, para. 17). If no decision is made at all based on purely automated processing, a requirement of Art. 22 is lacking (Haidinger in Knyrim, DatKomm Art. 22 GDPR, para. 18 (as of December 1, 2022, rdb.at)). Only those automated data processing operations that lead to a decision exhibiting a minimum level of complexity comparable to the profiling explicitly mentioned in Art. 22 GDPR are intended to be covered (Schulz in Gola/Heckmann, General Data Protection Regulation, Federal Data Protection Act, Art. 22, para. 19 with further references). Likewise, contrary to the complainant's view, there is no automated decision-making within the meaning of Article 22 GDPR. The requirement of a decision demands that the result of automated data processing be a constitutive act attributable to a natural or legal person, selecting from at least two options, with a conclusive effect in some sense (Schulz in Gola/Heckmann, Datenschutz-Grundverordnung Bundesdatenschutzgesetz, Article 22, para. 17 with further references). The scope of Article 22(1) GDPR thus does not generally cover every operation based on automated processing, but only decisions. These must be constitutive acts that make a choice between two alternatives and have an effect on the external world. The data subject should have the right not to be subject to a decision—which may include a measure—based solely on automated processing that produces legal effects concerning the data subject or similarly significantly affects them, such as the automatic rejection of an online loan application or online recruitment procedure without any human intervention (Feiler/Forgó, EU-DSGVO 2016). The mere calculation of a probability or the result of a search engine does not constitute a decision (Schulz in Gola/Heckmann, General Data Protection Regulation, Federal Data Protection Act, Article 22, para. 17). If no decision is made at all based on purely automated processing, a requirement of Article 22 is lacking (Haidinger in Knyrim, DatKomm Article 22, GDPR, para. 18 (as of December 1, 2022, rdb.at)). Only those automated data processing operations that lead to a decision exhibiting a minimum level of complexity comparable to the profiling explicitly mentioned in Article 22 of the GDPR are intended to be covered (Schulz in Gola/Heckmann, General Data Protection Regulation, Federal Data Protection Act, Article 22, para. 19 with further references).

The elements of Article 22 of the GDPR thus require a decision made using technical means without the direct involvement of a human being. Furthermore, the automated assessment must have legal effects on the data subject or similarly significantly affect them (Federal Administrative Court [BVwG] 12.9.2022, W214 2230686-1). The requirements of Article 22 GDPR thus presuppose a decision made using technical means without the direct involvement of a human being. Moreover, the automated assessment must have legal effects on the data subject or similarly significantly affect them (Federal Administrative Court [BVwG] 12.9.2022, W214 2230686-1).

Only in exceptional cases will the data subject be similarly significantly affected without this necessarily having legal effects. While this alternative also covers impairments to the economic or personal situation, the threshold of mere annoyance must be exceeded (Schulz in Gola/Heckmann, General Data Protection Regulation, Federal Data Protection Act [BDSG], Art. 22, para. 23). The decision must, from an objective standpoint, be likely to have a significant impact on the living conditions, behavior, or decisions of the data subject (Haidinger in Knyrim, DatKomm Art. 22 GDPR para. 26/2 (as of 1 December 2022, rdb.at); similarly: Guidelines on automated individual decision-making, including profiling, for the purposes of Regulation 2016/679 of 3 October 2017 (last revised on 6 February 2018) of the Article 29 Working Party, p.23) It is conceivable, for example, that the data subject might feel observed and restricted by the automatic recording and analysis of their behavior in such a way that this significantly impairs their personal development, although this assessment remains subject to individual case consideration (Helfrich in Sydow/Marsch, GDPR BDSG Art. 22 para. 51 and 52). The provision is intended to prevent legally significant or long-lasting decisions from being based solely on automated processing without individual assessment and evaluation by a human being. No one may become the object of an evaluation of personal data based solely on algorithms (Scholz in Simits, Hornung, Spiecker, Data Protection Law GDPR with BDSG, Art. 22 GDPR para. 3). Only in exceptional cases will the data subject be similarly significantly impaired, without this necessarily having a legal effect. While this variant also covers impairments to the economic or personal situation, the threshold of mere annoyance must be exceeded (Schulz in Gola/Heckmann, General Data Protection Regulation, Federal Data Protection Act, Article 22, para. 23). The decision must, from an objective standpoint, be capable of having a significant impact on the living conditions, behavior, or decisions of the data subject (Haidinger in Knyrim, DatKomm Article 22, GDPR para. 26/2 (as of December 1, 2022, rdb.at); similarly: Guidelines on automated individual decision-making, including profiling, for the purposes of Regulation 2016/679 of October 3, 2017 (last revised on February 6, 2018) of the Article 29 Working Party, Meeting 23). It is conceivable, for example, that the data subject might feel observed and restricted by the automatic recording and analysis of their behavior in such a way that this significantly impairs their personal development, although this assessment remains subject to individual consideration (Helfrich in Sydow/Marsch, GDPR BDSG Article 22, paragraphs 51 and 52). The provision is intended to prevent legally significant or long-lasting decisions from being based solely on automated processing without individual assessment and evaluation by a human being. No one may become the object of an evaluation of personal data based solely on algorithms (Scholz in Simits, Hornung, Spiecker, Data Protection Law GDPR with BDSG, Article 22, GDPR paragraph 3).

In the specific case, this results in the following:

The complainant argued that the decision to which he was subjected consisted, among other things, of selecting information that was partially incorrect, particularly regarding his assigned profile picture. It must be countered that the complainant is not subjected to profiling or a decision based on automated processing within the meaning of Article 22 GDPR simply by the automatic assignment of an image to his person. It is evident that the actions of the parties involved do not constitute legally relevant decisions, and in particular, no legal positions are established, modified, or revoked (see Schulz in Gola/Heckmann, Datenschutz-Grundverordnung Bundesdatenschutzgesetz, Art. 22, para. 21 et seq.), but merely the automated assignment of images to a person. Likewise, in the opinion of the deciding panel, the effects of the automatic assignment of an incorrect image in this specific case are manageable and, according to general experience, limited to amusement, at most surprise, or mild annoyance, whereas no impact on the complainant's business operations or reputation is to be expected in this case. The complainant himself was unable to cite any specific adverse or legally relevant consequences, but merely stated in general terms that the incorrect images had repeatedly caused "surprise and irritation" (data protection complaint, p. 5). He argued that images are of crucial importance in the decision of whether to contact XXXX or refrain from doing so (statement of October 7, 2021, p. 4). However, it must be countered that in this specific case, no exposure or impairment based on the specifically assigned images can be identified, nor was any such thing alleged by the complainant. Furthermore, it can be assumed, based on general experience, that contacting and engaging a lawyer does not occur based on an image from an XXXX company profile, but rather on recommendations, the respective company's own website, and an initial consultation. It is therefore incomprehensible (and was not demonstrated by the complainant) how the complainant perceives an impairment that significantly affects him in a manner similar to a decision with legal effect. The complainant argued that the decision to which he is subject consists, among other things, of the selection of information that is partly incorrect, particularly concerning his assigned profile picture. It must be countered that the complainant is not subjected to profiling or a decision based on automated processing within the meaning of Article 22 GDPR by the mere automatic assignment of an image to his person. It is evident that no legally relevant decisions are made through the actions of the parties involved, and in particular, no legal positions are established, modified, or revoked (see Schulz in Gola/Heckmann, Datenschutz-Grundverordnung Bundesdatenschutzgesetz, Article 22, para. 21 et seq.), but rather that images are merely assigned to a person using automated means. The adjudicating panel is also of the opinion that the effects of the automatic assignment of an incorrect image in this specific case are manageable and, according to general experience, limited to amusement, at most surprise, or mild annoyance, whereas no impact on the complainant's business operations or reputation is to be expected in this particular case. The complainant himself was also unable to cite any specific adverse or legally relevant effects, but merely stated in general terms that the incorrect images had already caused "surprise and irritation" on several occasions (Data Protection Complaint, Session 5). Images are of crucial importance in the decision of whether to contact someone or not (Statement of October 7, 2021, Session 4). However, it must be countered that in this specific case, no exposure or impairment based on the specifically assigned images can be identified, nor was any such thing alleged by the complainant. It can also be assumed, based on general experience, that contacting and engaging a lawyer is not based on a picture from a company profile (e.g., a company name), but rather on recommendations, the lawyer's own website, and an initial consultation. It is therefore incomprehensible (and was not demonstrated by the appellant) how the appellant perceives an impairment that significantly affects him in a manner similar to a legally binding decision.

The appeal was therefore dismissed for lack of an automated decision that could have legal effect on the data subject or similarly significantly impair him.

Whether the appellant's right to erasure was violated as a result of the incorrect photographs being assigned by the other parties involved is not the subject of these proceedings. Likewise, the Federal Administrative Court is precluded from ruling on the copyright concerns raised by the appellant regarding the processing of the photographs.

Regarding point B) Admissibility of the appeal:

Pursuant to Section 25a Paragraph 1 of the Administrative Court Act (VwGG), the Administrative Court must state in the operative part of its judgment or decision whether the appeal is admissible pursuant to Article 133 Paragraph 4 of the Federal Constitutional Law (B-VG). The statement must be briefly reasoned. Pursuant to Section 25a Paragraph 1 of the Administrative Court Act (VwGG), the Administrative Court must state in the operative part of its judgment or decision whether the appeal is admissible pursuant to Article 133 Paragraph 4 of the Federal Constitutional Law (B-VG). The statement must be briefly reasoned.

The appeal is admissible pursuant to Article 133 Paragraph 4 of the Federal Constitutional Law (B-VG) because there is no existing case law from the Administrative Court of Justice on the interpretation of Article 22 of the GDPR or on the requirement of a formal application. The appeal is admissible pursuant to Article 133 Paragraph 4 of the Federal Constitutional Law (B-VG) because there is no existing case law from the Administrative Court of Justice on the interpretation of Article 22 of the GDPR or on the requirement of a formal application.
...`` The decision therefore had to be made in accordance with the ruling.