BVwG - W298 2322178-1
| BVwG - W298 2322178-1 | |
|---|---|
| Court: | BVwG (Austria) |
| Jurisdiction: | Austria |
| Relevant Law: | Article 14 GDPR Article 15 GDPR Article 16 GDPR Article 17 GDPR Article 18 GDPR Article 21 GDPR Article 22 GDPR |
| Decided: | 29.04.2026 |
| Published: | 15.05.2026 |
| Parties: | |
| National Case Number/Name: | W298 2322178-1 |
| European Case Law Identifier: | ECLI:AT:BVWG:2026:W298.2322178.1.00 |
| Appeal from: | |
| Appeal to: | |
| Original Language(s): | German |
| Original Source: | RIS (in German) |
| Initial Contributor: | av |
A court held that a credit information agency did not violate a data subject’s right of access since the data subject limited the scope of their request. According to the court, the data subject also failed to exercise their rights under Article 16-22 GDPR before filing a complaint with the DPA.
English Summary
Facts
A data subject made an access request to a credit information agency (the controller) in 2023. He later filed a complaint with the Austrian DPA and alleged that the controller had violated his right of access under Article 15 GDPR by providing him partially flawed and inconsistent information. In particular, the data subject claimed that no information regarding the logic involved in the calculation of credit scores were disclosed by the controller. The data subject also stated that his right to information, rectification, erasure, restriction of processing, objection and the right not to be subjected to automated decision-making under Articles 14 and 16–22 GDPR had been violated.
While the controller provided further access in course of the procedure, it argued that it provided all information required under Article 15 GDPR.
After the DPA initially ordered the data subject to provide more information regarding his complaint, the DPA found no infringement of the GDPR. In particular, the DPA held that the data subject limited its access request to partial information and that he failed to exercise his rights under Article 16–22 GDPR before failing the respective complaint.
The data subject subsequently appealed the decision to the Austrian Federal Administrative Court.
Holding
The court dismissed the data subject’s appeal. First, the court interpreted the access request narrowly and found that the controller had not violated Article 15 GDPR. It stated that the data subject had limited his access request to concern certain information only and held that the controller had provided him all such information.
Second, the court could not find any infringement of Article 14 GDPR: it held that the data subject had failed to elaborate why he considered his right to information had been violated. Furthermore, the court stated that Articles 16–22 GDPR had not been infringed, as the data subject had not exercised his rights under these provisions by sending the controller a corresponding request on rectification, erasure, restriction of processing, objection or the right not to be subject to automated decision-making. In particular, the data subject failed to comply with the DPA’s order to further specify his complaint.
Comment
Some of the court's reasons to dismiss the appeal are quite bizarre. For example, requiring the data subject to exercise their right not to be subject to automated decision making under Article 22 GDPR. The CJEU already clarified that Article 22(1) GDPR “lays down a prohibition in principle, the infringement of which does not need to be invoked individually by such a person.” (see CJEU C-643/12 §52).
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the German original. Please refer to the German original for more details.
Office Vienna
Erdbergstraße 192–196, 1030 Vienna
Tel: +43 1 601 49 – 0
Fax: +43 1 711 23 – 889 15 41
www.bvwg.gv.at
Date of Decision
April 29, 2026
File Number
W298 2322178-1/6E
IN THE NAME OF THE REPUBLIC!
The Federal Administrative Court, composed of Judge Mag. Mathias Veigl as presiding judge
and lay judges Mag. Gerda Ferch-Fischer and Mag. Florian Schultes as associate judges, has ruled on the appeal of XXXX
, represented by noyb – European Center for Digital Rights, Goldschlagstraße
172/4/3/2, 1140 Vienna, against the decision of the Data Protection Authority dated May 13, 2025, file number:
XXXX (intervening party: XXXX), concerning a violation of the right to information, as follows:
A) The appeal is dismissed with the proviso that the contested decision
is amended to read as follows:
I. The appeal concerning an alleged violation of the right to confidentiality and
concerning an alleged violation of the right to information is dismissed as unfounded.
... II. The complaint regarding an alleged violation of the right to information
pursuant to Article 14 GDPR, the right to rectification pursuant to Article 16 GDPR, the right to erasure
pursuant to Article 17 GDPR, the right to restriction of processing pursuant to Article 18 GDPR, the right to object pursuant to Article 21 GDPR, and the right not to be subject to a
automated decision pursuant to Article 22 GDPR is
dismissed. - 2 -
B) The appeal on points of law is inadmissible pursuant to Article 133(4) of the Austrian Federal Constitutional Law (B-VG).
Grounds for the decision:
I. Procedural history:
1. The complainant filed a data protection complaint on [date] 2023
against [company name] (hereinafter referred to as the “party involved”). The complainant was not
informed about the origin of his data, its use, or to whom it was transmitted, even though he explicitly requested this information in his request to the
involved party. The information provided only explains in general terms why the
involved party has an overriding interest in his "highly sensitive" personal data.
A "scoring value" of XXXX is stored for the complainant. Since the
"scoring value" can range between 250 and 700, it appears that negative entries for the complainant must be incorrectly recorded.
Without disclosure of this harmful data, and invoking trade secrets, his data subject rights are being severely violated.
Furthermore, the complainant was forced by the
involved party to submit his identification, which is not permissible according to established case law.
2. The respondent authority issued the complainant with a letter dated XXXX 2023
order to remedy the deficiency.
3. In a submission dated May 10, 2023, the complainant stated that he had submitted a request for information to the co-respondent on XXXX 2023
(presumably XXXX 2023). He claimed that his
right to obtain information without difficulty under Article 15 GDPR had been violated, as the co-respondent would have refused to provide the information if he had not submitted a copy of an
identification document. He stated that he had finally received
deficient information from the co-respondent in a submission dated XXXX 2023. It refuses to provide any
information about the complainant's personal data (apart from
company register entries, which are public anyway) and only cites a score of -3 -
XXXX, which was transmitted to 2 customers. Regarding the calculation of the
"score," the co-dealer refers to a trade secret. The co-dealer's
privacy policy lacks any mention of implemented
security measures; these are described in detail in the privacy policies of other credit reporting agencies.
4. The complainant filed a complaint for failure to act on March 21, 2025.
5. In its statement of [date] 2025, the co-dealer stated that
identity card or passport data is used exclusively to identify a
data subject requesting their own data. After identification,
the data is deleted immediately. The self-disclosure was sent directly to
the complainant after identification. The complainant received a self-disclosure in a timely manner, which also showed which data was being processed by the
participating party, who the recipients were, and where the
data originated. It is therefore incomprehensible for the complainant to claim not to have received this information. No information was withheld at any time. By letter dated XXXX 2025, a new self-disclosure was sent to the
complainant, which contained the explanations regarding the "scoring value" on page 10. All personal data stored by both participating parties concerning the
complainant is evident from the last disclosure issued on XXXX 2025. Accordingly, the information provided by the participating party about the complainant is based solely on this
data, and the exercise of all his rights under the GDPR is therefore possible. The
participating party was also not required to include the technical and organizational measures in its privacy policy.
6. In his statement of April 30, 2025, the complainant argued that the statement
of the participating party was by no means satisfactory. While the information provided by the participating party was now more detailed, it was partly incorrect and inconsistent.
In any case, section "2.1. Contact Details" was incorrect, as none of the telephone numbers
were current or had ever been correct. While sources for the assessment were now listed in "Chapter 3: Personal Matches," it was not explained how the "scoring values" were generated.
It was also not explained why the sources listed in the privacy statement had reported data to
XXXX. The complainant had not explicitly given any of these sources permission to do so. Furthermore, the co-involved party is now simply delegating its secret
scoring procedure one level further down. It is by no means clear why and - 4 -
with which data "scoring values" are generated. Without disclosure of the
calculation method, the complainant cannot assess whether these
scorings could be appropriate in any way or whether, like the aforementioned
telephone numbers, they are not based on incorrect data.
7. By decision of June 20, 2025, the complainant's data protection complaint was dismissed as unfounded
due to an alleged violation of the right to confidentiality, the right to information,
the right of access, the right to rectification, the right to erasure, the right to
restriction of processing, the right to object, the right not to be subject to an automated decision, and due to an alleged
violation of the principles governing the processing of personal data. The respondent authority essentially reasoned that the
appellant had been correctly requested to provide proof of identity.
The appellant had expressly limited his request for information to a subset of the
right of access under Article 15(1) GDPR and requested information regarding which personal data the co-respondent processed about him,
where this data originated, and to which recipients it had been disclosed. In the
present case, a broader right of access could not be derived from the specific request for information submitted on [date] 2023. The co-party
provided the complainant with information about the (master) data (payment history data, name, date of birth, addresses, business functions) it processed about the complainant by letters dated XXXX 2023 and XXXX 2025.
Therefore, no deficiency can be identified in this regard, nor is any alleged by the
complainant. The complainant fails to recognize that the
requested disclosure of the calculation method for the reported "scoring value," in order to understand the
significance of the disclosed data in connection with the scores, would have to be asserted within the framework of a request pursuant to Article 15(1)(h) GDPR. The
complainant did not submit a corresponding request for information pursuant to Article 15(1)(h) GDPR to the co-party. The complainant's request for information, addressed to the co-party, dated [date] 2023, did not contain a corresponding request for information about the purposes of the data processing or the legal basis for the data processing pursuant to Article 15(1)(a) GDPR. The co-party
also provided corresponding information about the processing purposes and legal bases in responses dated [date] 2023 and [date] 2025. In addition to the specific data processed, it also provided categories (such as "payment experience data",
"name", "date of birth", "address", or "telephone number"), even though the complainant's request for information had not been directed at this. By letter
dated [date] 2025, the co-party sent the complainant a subsequent [information/information].Updated information on 25 specific recipients of the complainant's personal data, as well as information on the transmitted data, was provided.
Given that the co-party, in particular regarding the origin of the complainant's data, named several public sources and also several companies by name, and provided further information on the transmitted data,
and that the complainant had not submitted any substantiated arguments regarding the alleged inadequacy of the information provided pursuant to Article 15(1)(g) GDPR,
the information provided in this respect is to be considered complete. The release of further
documents containing the complainant's personal data is to be denied in principle,
as it is not necessary to ensure the contextualization of the processed
personal data or its comprehensibility. The co-party has sufficiently complied with its obligation to provide information pursuant to Article 14(2)(b) GDPR. The rights under Articles 15 to 22 GDPR are
rights requiring an application. This means that the data subject must first submit a corresponding request to the controller in order to assert these
rights.
However, since the complainant in the present case never submitted a request to the
party involved to assert his rights to rectification under Article 16 GDPR, to erasure under Article 17 GDPR, to restriction of processing under Article 18 GDPR, to object under Article 21 GDPR, or not to be subject to a decision based solely on automated processing under Article 22 GDPR, he could not have been infringed in his rights in this regard.
8. The appellant filed an appeal against the decision of the respondent authority and
submitted a request to amend the following parts of the contested decision
within the framework of a preliminary decision on the appeal. The information provided by the
joint party to the proceedings stated that the appellant had received numerous previously undisclosed details of information for the first time. The amended information provided by the
joint party to the proceedings dated XXXX 2025 showed that its original information was also (or rather,
particularly) grossly incomplete in these points (“master data, recipients, and origin”). Some parts of the information provided remained incomplete.
In particular, the purpose of the processing was not properly disclosed, contrary to Article 15(1)(a) GDPR. The co-party involved merely referred to Sections 151–153 of the Trade Regulation Act (GewO) regarding the
purpose of processing, without specifying which data would be processed for which of these purposes. It is hardly conceivable that the co-party involved processes all of the complainant's data for all three
trade licenses. The information provided pursuant to Article 15(1)(h) GDPR
regarding the existence of automated decision-making, including profiling pursuant to Article 22(1) and (4), and – at least in these cases – meaningful
information about the logic involved, as well as the scope and intended
effects of such processing for the data subject, was also incomplete. The co-party involved should have provided the complainant with an explanation of the
procedure and principles applied in the respective credit assessments
to arrive at the calculated credit profile. The procedure and the principles specifically applied should have been
described in such a way that the complainant could have understood
which of his personal data were used in the context of the automated
decision-making process in question, and how. According to the clear case law of the
Administrative Court, a breach of the duty to provide information
by the co-participating party is not subject to subsequent rectification. This
assessment by the respondent authority is already incorrect with regard to the right to erasure under Article 17
GDPR, since controllers are obligated to erase inaccurate data even without a corresponding request. However, such an assessment is particularly flawed
in connection with Article 22 GDPR, which constitutes a prohibition and by no means requires a request. Numerous credit ratings were conducted on the complainant.
If the score provided by the co-involved party were indeed not at all
relevant to the business decisions of XXXX customers, one would have to assume
that they are spending money on largely irrelevant information. Moreover,
XXXX customers would even be admitting to basing business decisions (exclusively) on scores obtained from
XXXX. The reference by the respondent authority to the
general possibility of basing the activities of credit reporting agencies on Article 6(1)(f) GDPR is misguided. Regarding the data collection and further processing
of the data allegedly collected from address publishers, a violation of the complainant's right to
confidentiality and a breach of Article 6(1)(f) GDPR would have had to be established. The processing of personal data must also be necessary based on
legitimate interests. In particular, with regard to the telephone numbers in question, which have not been confirmed for over 20 years and were also withheld from the complainant in the initial information provided, it is incomprehensible, and the co-party does not claim, how these numbers could be necessary for the processing purposes at hand. - 7 -
9. In its statement of November 28, 2025, the co-party essentially stated that it had provided the complainant with all the information requested by him pursuant to Article 15 GDPR. He had received all the information about the processing by the co-party pursuant to Article 14 GDPR. The co-party could not be accused of any infringement of Article
22 GDPR, as it does not make any automated decisions. All processing activities by the co-defendant were always lawful, as they could be based on
Article 6(1)(f) GDPR and the appellant was also informed of the legitimate interest pursued.
By the co-defendant, the Federal Administrative Court considered the following:
1. Findings:
1.1. The co-defendant is a company that, among other things, operates the business of
"credit reporting agency" pursuant to Section 152 of the Trade Regulation Act (GewO). The payment experience data processed in its database is obtained by the appellant from its
contractual partners (e.g., debt collection agencies). The credit reporting agency operated by the appellant
serves its clients to assess the default risk of (potential) contractual partners.
... 1.2. The complainant sent an email dated XXXX 2023 requesting information to the
intervening party with the following content:
“Dear Sir or Madam,
I request information about what data you have stored about me, where it
originated from, and to whom it has been forwarded. Please also inform me which
data and information requests required my written consent (loan applications, etc.).
Thank you very much! […]”
The intervening party replied on XXXX 2023 that a legible copy of the complainant's identification document was necessary to process the request.
By email dated XXXX 2023, the complainant sent the intervening party a
copy of his identification document as proof of identity. - 8 -
1.3. The party involved informed the complainant by letter dated XXXX 2023
which personal data it had stored about him. The co-defendant
responded to the complainant's request for information in part as follows:
…
…
…
3. Categories of Data Processed
For the purposes mentioned in point 1, we process the following categories of
personal data:
Identity data (in particular first and last name(s), date of birth and death, gender,
title, academic degree, status (calculated from date of birth and death),
citizenship), timestamp from the identity verification (date, time of use by our
service providers)
Data and documents relating to personal documents (insofar as provided by the data subject)
Contact details (in particular address, company headquarters, telephone number, fax, email, website)
Building data (data relating to a building assigned to an address)
Company-related data (in particular company register data, VAT ID, LEI, OeNB numbers,
business purpose, company size/number of employees, vehicle fleet, balance sheet data,
NACE code, business functions) including powers of representation and organization,
Date of entry/exit or change of function in the company,
Length of stay for foreign nationals, crisis-specific subsidies,
Shareholding and liability amount, information on previous employment and
secondary employment, real estate ownership (private or company-owned) - 9 -
Business-related data (data on business licenses, other business register data,
Description of activity, industry)
Association register data
Land register data
Data on court publications (insolvency data and data on court
auctions)
Blocking notice according to the Robinson List, bank account details (IBAN and BIC or BLZ;
exclusively for fraud prevention purposes), payment history data (data on
compliance with payment deadlines and undisputed, unpaid after the due date
and repeatedly demanded receivables, including lease collections, rent payments and
evictions) including balance and duration of their imprisonment and reminders
Media monitoring and research data (on entrepreneurs) ID and data contained therein
incl.ID photo [exclusively for the purpose of identification and authentication upon
request from data subjects]
Photograph (exclusively for the purpose of identification and authentication upon request from
data subjects) Payment data (exclusively for processing online payments) Creditworthiness data (including aggregated creditworthiness criteria and score)
Hardware and software data (including browser used, device identifier), geolocation
data (calculated based on addresses) and photographs from Google Maps for the analysis of
potential abusive activity (insofar as collected from the customer with the consent of the
data subject and then transmitted to XXXX)
Indications of abusive or other potentially abusive behavior such as
attempts to deceive identity, address, or creditworthiness in connection with contracts
for telecommunications services or contracts with credit institutions or
financial service providers (loan or investment agreements, current accounts) or in the (Internet) Commerce
Assessment regarding deliverability of addresses
Data collected during queries by XXXX customers in the XXXX database ("query data,"
including any order data contained therein)
Log data relating to the database (including confirmation of address data) Risk assessment
Source of the data and classification of the source, as well as details of the corresponding
Data collection - 10 -
Data on the ordering behavior of the data subject (application counter, application repetitions)
Financing volume
Information provided by you within the framework of the Synesgy ESG platform regarding
ecological and social sustainability, as well as the related certification results
Information on the protection of the data subjects' identities, insofar as this is necessary within the framework of the
identity assessment
…“
1.4. The complainant filed a data protection complaint on XXXX 2023
due to what he considered to be insufficient information.
1.5. The co-defendant granted the Complainant submitted on XXXX 2025 a
further supplementary information with the following content:
"Dear Mr.XXXX!
We are informing you below which personal data we have stored about you as of today's
reference date. To facilitate the interpretation of this data,
please refer to the key at the end of this letter.
1. Payment History
Currently, we have no payment history data stored about you.
2. Master Data - Addresses
This section contains the known addresses, address updates, and the
Verification Score.
2.1 Master Data - Address Book
The following table contains the master data stored about you.
2.1 Master Data - Contact Details
The following tables contain the contact details stored for your client.
Your telephone numbers - 11 -
2.2 Master Data - Regularly Calculated Scores
The Verification Score indicates, on a scale from A to D, how well a person is rated in the XXXX
database." is confirmed. A is the best possible value and means that the data is highly
likely to be correct.
2.3 Master Data – Updates
The following table contains information on the first and last updates of the data listed in
the "Master Data Addresses" section, sorted by address ID.
3. Recipients or Categories of Recipients
In general, companies that have previously entered into a written contractual relationship with XXXX
and, among other things, acknowledge the data protection regulations/laws,
can conduct queries in our identity and creditworthiness database. These include
primarily companies in the credit industry, debt collection agencies,
or other companies.
Personal Matches
Specifically, we have stored the following queries about your client that resulted in
unique identification in our identity and creditworthiness database
“Personal Matches”:
The decision regarding the establishment of a business relationship and its
terms and conditions is made exclusively by the client of XXXX within the framework of private autonomy.
4. Entrepreneurial Functions and Powers of Representation
Source: Commercial Register, Austrian Business Information System (“Business Register”), if applicable
Register of Beneficial Owners. - 12 -
To obtain a complete extract of data on the companies associated with your client,
you can request a company information report. Please submit a
application including a copy of the identification document of an authorized signatory of the company to
auskunft@XXXX.com.
5. Storage Period and Criteria for Deletion
The data storage period is determined as follows:
The data remains in our identity and creditworthiness database as long as it is factually correct,
no legal grounds for deletion exist under the GDPR or other regulations,
and the storage corresponds to the purpose of the processing, and it is still necessary for those purposes.
... 6. Correspondence in the Processing of Your Applications
We store messages and information that we exchange with you via email or letter in order to refer to them at a later date
and to provide you with information about them.
Since you are already aware of the content of this communication, it will not be shown separately in the
self-disclosure form. Furthermore, this information will under no circumstances be processed in our identity or creditworthiness database.
If you would like detailed information about data processing in accordance with the GDPR,
you can find further information here:
https://www.XXXX.at/datenschutz-in-bewegung-XXXX-informiert/datenschutzerklaerung-
data subject rights.
7. Automated Decision-Making and Profiling
XXXX generates recommendations regarding a person's ability or willingness to pay based on
statistical calculations. Factors such as previous payment defaults (like debt collection entries and insolvencies), the person's age, and place of residence are taken into account.
It is important to know, however, that these recommendations have no direct impact on whether a business transaction takes place between you and the company requesting your personal data.
This decision rests with the company itself.
8. General Information and Processing Purposes
Information on the Origin and Use of Data - 13 -
The data used by XXXX comes from public sources such as
court publications (edict files), balance sheets, the commercial register, or trade and
association registers. XXXX verifies the accuracy of this information, for example, the correct
spelling of names, and corrects it if necessary.
XXXX obtains important creditworthiness information, such as payment history, from over 80
debt collection service providers (collection agencies and lawyers) throughout Austria.
This information is transmitted directly to XXXX by these service providers or the creditors themselves. Debtors are informed in advance, in a debt collection letter, that
their data will be passed on to XXXX.
The data is stored for the purpose of conducting business in accordance with:
• Section 151 Address publishers and direct marketing companies
• Section 152 Credit reporting agencies and
• Section 153 Services in automatic data processing and information technology according to the 1994 Trade Regulation Act (GewO).
Access to the data is granted only to those companies that
• have entered into a contractual relationship with XXXX and
• assume a credit risk in the course of their business activities (e.g., delivery on open account).
The decision regarding the establishment of a business relationship rests solely with the
company, which may consider additional evaluation criteria besides the data transmitted by XXXX.
9. Rights of Data Subjects
Data subjects may assert their right to erasure at any time by sending an email to auskunftXXXX.com.
... In principle, according to current data protection regulations, there is no
right to unjustified erasure. A claim for erasure of data from the database
of XXXX generally only exists if
• the data was processed unlawfully,
• there is no longer a purpose for processing, or - 14 -
• a legitimate reason for objection could be demonstrated.
Further information can be found on our website at:
https://www.XXXX.at/datenschutz-in-bewegung-XXXX-informiert/datenschutzerklaerung-
auskunftei-und-adressverlag
Questionnaire on Ecological and Social Sustainability (“ESG Rating”)
If you have completed the questionnaire on ecological and social sustainability (“ESG Rating”)
and wish to exercise your right to information about the data processed therein,
you can do so via the following link: https://XXXX.com/at.
Sincerely,
XXXX
Information Team
KEY
In addition to the self-disclosure, you will find further explanations and descriptions for each section of the self-disclosure here.
Section "Payment History"
The list of payment history is solely for data protection purposes.
This means that this information does not represent a list of potential claims or balances.
If you require information on potential outstanding amounts, you can find it under "Source of Information." There, the outstanding amounts are assigned to the respective companies and provide an overview of all possible receivables.
In detail, the individual column headings mean the following:
Section "Master Data"
Explanation of the Master Data - Address Data section:
Deliverability assesses the accuracy and probability of delivery of a document to the specified address.
Address data is marked as premium data if it has been verified by an address publisher.
` ...
`
`
`
`
`
`
`
`
`
Section “Recipients and Recipient Categories”
This overview explains each line in this section:
How creditworthiness values are assessed depends on the requesting company.
For example, one company might have concerns about the calculated creditworthiness of the person in question due to its risk management, while another company might not.
have no such concerns.
Please also note that creditworthiness values are not transmitted with every data transfer to a requesting company. Some requesting companies, for example, only receive information about the identity of the person in question. We would also like to refer you to the section “Automated Decision-Making and Profiling” for more information.
For more information, please see the section “Automated Decision-Making and Profiling.” Please note the legal limitations of the right to information under data protection law:
We thank you for your understanding that no information will be provided about the detailed parameters or
the algorithm underlying the calculation. According to Article 15 Paragraph 4 GDPR
and Section 4 Paragraph 6 of the Austrian Data Protection Act (DSG), the right to information under data protection law does not extend to
information that constitutes a trade or business secret.
Section “Entrepreneurial Functions and Powers of Representation”
This section lists the official functions (powers of representation and shareholdings)
that you hold or have held in companies. The sources for this information are the
Commercial Register and the Trade Register of the Republic of Austria, as well as, where applicable, the Register of Beneficial Owners. - 16 -
1.6. The respondent authority, in a request for rectification dated
XXXX 2023, instructed the complainant to provide specific details regarding which elements of Article 15(1) GDPR were missing from the information provided. Furthermore, the complainant was asked to
provide more detailed information as to why he considered his right to information under Articles 13 and 14 GDPR to have been violated. The respondent authority also requested
the complainant to provide details regarding the timeline of events, for example, when
an alleged infringement was supposed to have occurred or when the complainant submitted corresponding requests (access, erasure, objection, rectification, etc.).
Regarding an alleged violation of the right to rectification of data (Article 16 GDPR),
erasure of data (Article 17 GDPR), restriction of processing (Article 18 GDPR),
objection (Art. 21 GDPR) and the right not to be subject to a decision
based solely on automated processing (Art. 22 GDPR), the
complainant should submit the underlying request and any response from the
joint party. The complainant was advised that in order to
assert their data subject rights, it is necessary to first submit a corresponding
request (e.g., request for access, erasure, rectification, objection)
to the controller. Only if the controller does not respond to the request within a period
of one month, or refuses to comply with the request before this period, would a (promising) complaint regarding a violation of their
data subject rights be possible.
1.7. The complainant did not submit a request to the joint party for
recognition, erasure, restriction of processing, objection, or
any Request for information as to whether he has been subject to an automated decision
or whether his right to be subject to an automated decision pursuant to Article 15(1)(h) GDPR has been violated. He also did not submit a
request for information on the purposes of processing pursuant to Article 15(1)(a) GDPR. The
complainant, in his amended data protection complaint of May 10, 2023,
also failed to provide any further details as to why he considered his right to information under Articles 13 and
14 GDPR to have been violated.
1.8. The respondent authority addressed the following points in its decision:
• whether the party involved violated the complainant's right to information in
concerning the principle of facilitation by requiring proof of the complainant's identity before providing
information; - 17 -
• whether the co-party violated the complainant's right to access
by failing to fully respond to the access request of XXXX 2023;
• whether the co-party violated the complainant's right to information under Articles 13
and 14 GDPR by failing to disclose the respondent's legitimate interests in the privacy policy;
• whether the co-party violated the complainant's right to rectification
under Article 16 GDPR;
• whether the co-party violated the complainant's right to erasure under Article 17
GDPR;
• whether the co-party violated the complainant's right to restriction of processing under Article 18 GDPR;
• whether the co-party violated the complainant's right to object under Article 21
GDPR;
• whether the co-party has infringed the complainant's right not to be subject to a
decision based solely on automated processing
within the meaning of Article 22 GDPR;
• whether the co-party, in processing the complainant's personal data, has violated the principles of processing pursuant to Article 5(1)(d) and
(f) GDPR, as well as Articles 25 and 32 GDPR; 10. whether the
respondent has infringed the complainant's right to confidentiality
by unlawfully processing the complainant's data.
1.9. In his appeal against the decision, the complainant argued that the
co-party "does not name any specific data sources," "does not provide a complete list of
recipients," and "fails to provide numerous master data points that were obviously available."
Furthermore, the complainant argues that there is insufficient information regarding the
purpose of the processing, the existence of automated decision-making,
including profiling, and meaningful information about the logic involved, as well as the - 18 -
scope and intended effects of such processing for the
data subject.
The complainant also alleges a breach of the information obligation under Article 14
GDPR by the co-processing party and a violation of Article 6(1)(f) GDPR,
specifically in conjunction with Articles 13 and 14 GDPR.
In addition, the complainant considers his right to erasure and his right
not to be subject to a decision based solely on automated processing, including profiling, to have been violated.
2. Evaluation of Evidence:
The findings are based on the administrative act, in particular on the
appellant's request for information dated XXXX 2023 and his
data protection complaint dated XXXX 2023.
The content of the information provided by the co-party was contained in the letters dated XXXX
2023 and XXXX 2025.
The content of the complaint is contained in the data protection complaint filed by the appellant
as well as in the respondent authority's order to remedy deficiencies dated XXXX 2023.
That the appellant did not
comply with the respondent authority's order to remedy deficiencies and did not submit the corresponding applications to the co-party is evident from the contested decision and the case file.
3. Legal Assessment:
Regarding A) I. Dismissal of the Appeal:
3.1. Key Provisions
The key provisions of Regulation (EU) 2016/679 of the European
Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the
processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) are as follows:
"Article 5
Principles relating to processing of personal data - 19 -
(1) Personal data must be
a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);
b) collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes; a) Further processing for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes is not considered incompatible with the original purposes (“purpose limitation”) in accordance with
Article 89(1);
c) adequate, relevant, and limited to what is necessary for the purposes for which they are processed (“data minimization”);
d) accurate and, where necessary, kept up to date; all
appropriate measures must be taken to ensure that personal data which are inaccurate in relation to the purposes for which they are processed are erased or rectified without delay (“accuracy”);
e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed;
Personal data may be stored for longer periods if the personal
data are processed, subject to the implementation of appropriate technical and organizational
measures required by this Regulation to safeguard the rights and freedoms of the
data subject, solely for archiving purposes in the public interest or for scientific or historical research purposes or for statistical purposes in accordance with Article 89(1) (“storage limitation”);
(f) are processed in a manner that ensures appropriate security of the personal
data, including protection against unauthorized or
unlawful processing and accidental loss, destruction,
or damage, by means of appropriate technical and organizational
measures (“integrity and confidentiality”);
(2) The controller shall be responsible for compliance with paragraph 1 and must be able to demonstrate compliance (“accountability”).
(2) The controller shall be responsible for compliance with paragraph 1 and shall be able to demonstrate compliance (“accountability”). .... Article 6 - 20 -
Lawfulness of processing
(1) Processing shall be lawful only if at least one of the following
conditions is met:
(a) The data subject has given consent to the processing of his or her personal data forone or more specific purposes;
b) processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract;
c) processing is necessary for compliance with a legal obligation to which the controller is subject;
d) processing is necessary in order to protect the vital interests of the data subject or of another natural person;
e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Point (f) of paragraph 1 shall not apply to processing carried out by public authorities in the performance of their tasks.
(2) Member States may maintain or introduce more specific provisions to adapt the application
of the provisions of this Regulation with regard to processing for the purposes of paragraph 1
points c and e, by specifying more precisely the specific requirements for the processing and other measures to ensure lawful and fair processing, including for other
specific processing situations referred to in Chapter IX INSURANCE.
(3) The legal basis for processing pursuant to paragraph 1 points c and e shall be
established by - 21 -
a) Union law or
b) the law of the Member States to which the controller is subject.
The purpose of the processing must be specified in that legal basis or, with regard to the
processing referred to in paragraph 1 point e, be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This legal basis may contain specific provisions
for adapting the application of the provisions of this Regulation, including provisions on the general conditions governing the
lawfulness of processing by the controller, the types of data
processed, the data subjects, the entities to which and for which purposes the personal data may be disclosed, the purpose limitation to which they are
subject to, how long they may be stored, and the processing operations and
procedures that may be applied, including measures to ensure lawful and fair processing, such as those for other
specific processing situations as defined in Chapter IX INSURANCE. Union law or
the law of the Member States must pursue an objective in the public interest
and be proportionate to the legitimate aim pursued.
[…]
“Article 12
Transparent information, communication and modalities for exercising the rights of the
data subject
(1) The controller shall take appropriate measures to provide the data subject with all
information referred to in Articles 13 and 14 and all communications referred to in Articles 15 to
22 and Article 34 relating to processing in a concise, transparent, intelligible and easily accessible form, using clear and plain language,
in particular for information addressed specifically to children.
The information shall be provided in writing or by other means, including, where appropriate, electronically. If requested by the data subject, the information may be given orally
provided that the identity of the data subject has been verified by other means.
(2) The controller shall facilitate the exercise of the data subject’s rights referred to in Articles 15 to 22. In the cases referred to in Article 11(2), the controller may only refuse to comply with the data subject’s request for - 22 -
to exercise their rights under Articles 15 to 22 if they credibly demonstrate that they are unable to identify the data subject.
(3) The controller shall provide the data subject with information on the measures taken in response to a request
pursuant to Articles 15 to 22 without undue delay and in any event within one month of receipt of the request. This period may be extended by a further two months where necessary, taking into account the complexity and number of requests. The controller shall inform the data subject of any extension of this period, together with the reasons for the delay, within one month of receipt of the request. Where the data subject makes the request electronically, the information shall be provided electronically where possible, unless the data subject requests otherwise.
[…]”
“Article 13
Information to be provided where personal data are collected from the data subject
(1) Where personal data are collected from the data subject, the controller shall inform the data subject of the following: the
controller shall provide the data subject with the following information at the time these data are collected:
[…]
c) the purposes for which the personal data are to be processed, as well as the
legal basis for the processing;
[…] (2) In addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following additional information at the time these data are collected:
information necessary to ensure fair and transparent processing:
[…]
f) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
[…]
(3) [...]
(4) Paragraphs 1, 2 and 3 shall not apply where and to the extent that the data subject
already has the information.
“Article 15
Right of access by the data subject
(1) The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:
a) the purposes of the processing;
b) the categories of personal data concerned;
c) the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
d) where possible, the envisaged period for which the personal data will be stored,
or, if not possible, the criteria used to determine that period;
e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning him or her or to object to such processing;
f) the Existence of a right to lodge a complaint with a supervisory authority;
(g) where the personal data are not collected from the data subject, all
available information about the source of the data;
(h) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
(2) Where personal data are transferred to a third country or to an international
organization, the data subject shall have the right to be informed of the appropriate safeguards referred to in Article 46 relating to the transfer.
(3) The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on
administrative costs. If the data subject submits the application electronically,
the information must be provided in a commonly used electronic format unless the data subject specifies otherwise.
(4) The right to receive a copy pursuant to paragraph 1b must not adversely affect the rights and freedoms of other
persons.
3.2. On the scope of the appeal and the Administrative Court's power of review:
The "matter" of the appeal proceedings is only that which formed the content of the
decision issued by the respondent authority. The outermost scope of the Administrative Court's
power of review is therefore the "matter" of the contested decision (see, for example, VwGH 18.10.2022, Ra 2022/01/0276, para. 19, with further references).
As can be seen from the course of proceedings and the findings, the respondent authority
only partially ruled on the complaint regarding the alleged violation of the right to
access, because it assumed that the complainant had not made a
global request for access to personal data under data protection law.
The CJEU, in case C-487/21, Austrian Data Protection Authority and XXXX, of XXXX 2023,
held that the right of access to personal data under Article 15 GDPR is not a divisible
right in the sense of separate claims.
Conversely, however, as the respondent authority correctly
explained, a data subject is free to exercise a right of access partially or in a limited manner.
In interpreting the application, the respondent authority concluded
that the application, which was addressed to the co-respondent, was not to be understood as meaning that the appellant wanted to be informed of all information pursuant to Article 15
GDPR. - 25 -
According to the case law of the Administrative Court, in an administrative procedure requiring an application, the applicant primarily determines the subject matter
of the procedure; their application defines what is the subject of the (authorization) procedure (cf.
Austrian Administrative Court (VwGH) 12.09.2016, Ro 2016/04/0014, with further references). The subject matter of the proceedings in the application-based proceedings before the Data Protection Authority (DSB) could only encompass those rights of access
that the data subject actually claimed to have been violated when submitting their application (cf.
Austrian Administrative Court (VwGH) 02.04.2024, Ro 2021/04/0008).
Therefore, a ruling on the request for information as to whether the appellant has been subjected to
automated decision-making or whether their right to be subject to automated decision-making pursuant to Art. 15
para. 1 lit. h GDPR has been violated, as well as on the request for information on the
processing purposes pursuant to Art. 15 para. 1 lit. a GDPR, is explicitly not covered by the ruling, the reasoning, and the findings.
A ruling on the request for information as to whether the appellant has been subjected to an automated decision or whether their right to be subject to an automated decision pursuant to Art. 15 para. 1 lit. h GDPR has been violated.
The decision does not explicitly cover the request for information on the processing purposes pursuant to Art. 15 para. 1 lit. a GDPR.
... If the appellant now argues that the decision is unlawful in its content,
it must be noted that, according to the cited case law of the Administrative Court, the Federal Administrative Court is not permitted to rule on circumstances that were not the subject of the decision.
Should the appellant believe that the appeal was not (fully) addressed by the respondent authority, the remedy of an appeal against the decision is not available. Instead, any alleged defect in a (partial) decision would have to be challenged by means of an appeal for failure to act.
3.3. On the interpretation of the request for information:
The findings show that the appellant submitted a limited request for information and did not rely on Article 15 GDPR without restriction.
On [date] 2023, the complainant submitted a request for information to the co-party
and asked for information about which of his data was stored by the co-party
where it originated and to whom it had been forwarded.
He also requested information about which of these data and disclosures had been subject to his written consent (loan applications, etc.).
The complainant thus did not submit a request to the co-party for information
pursuant to Article 15(1)(h) GDPR regarding the existence of automated
decision-making, including profiling, pursuant to Article 22(1) and (4) and — - 26 -
at least in these cases — meaningful information about the logic involved and the significance and the envisaged consequences of such processing for the
data subject.
... In his appeal against the decision, the appellant stated that a restriction to
specific components of the information was not intended and that the other party involved had not understood it that way either (see appeal against the decision, p. 5). It must be countered that
just because the co-party addressed all the points mentioned in Article 15 GDPR in its two requests for information, the complainant's request for information of XXXX 2023 cannot (objectively) be interpreted as
requesting access to all information pursuant to Article 15 GDPR, especially since he did not explicitly invoke Article 15 GDPR. If it is not argued that if the data subject
for example, specifically requests "information about the data concerning him/her processed,"
the controller should assume that the data subject is exercising his/her right under Article 15 paragraphs 1 and 2 GDPR in full, it must be countered that the
complainant did not generally request "information about data concerning him/her,"
but explicitly requested information in his/her request about which data concerning him/her is stored by the co-party, and from where it was obtained. These originate from and to whom they were forwarded
—a reference to Article 15 GDPR is also missing. Furthermore, he should be informed for which of these data and information requests his written consent was obtained
(loan applications, etc.).
While it is true that when determining the legal status and content of a request, it should not be assumed in cases of doubt that a party has submitted a request that is inherently pointless or
inadmissible. However, it is impermissible to interpret a request contrary to the express wishes of the
party in a way that cannot be directly derived from the wording of the request, even if the request, as it was formulated,
is hopeless or even inadmissible from the outset (see Austrian Administrative Court [VwGH] 27.09.2011, 2010/12/0142;
20.11.2007, 2007/16/0145). Given the expressed wishes of a party – especially one represented by legal counsel – the authority is prohibited from interpreting the application in a way that does not correspond to its wording, i.e., from relating it to a different legal basis
(see Austrian Administrative Court [VwGH] 03.10.2013, 2012/06/0156).
Regarding the question of whether the data subject wishes to obtain access to all information processed about them
or only parts thereof, the EDPB
guidelines cited by the complainant indicate that if, for example, the data subject specifically requests "information about the data processed concerning them," the controller should assume that the data subject is exercising their right under Article 15, paragraphs 1 and 2 of the GDPR in full. Such a request should therefore not be interpreted as meaning that the data subject only wishes to receive the categories
of personal data being processed and that they are waiving the information listed in Article 15(1)(a) to (h). Accordingly, if the data subject merely clarifies their request not to provide any information,
specifies the data sources or origin of the personal data, or the expected storage period, it would be
the case that the data subject merely specifies that they do not wish to provide any information,
names the data sources or origin of the personal data, or the expected storage period. In such a case, the controller may limit its response to the
specific information requested (see Guidelines 01/2022 on the
rights of the data subject – Right of access, Version 2.0 m8 51). This was the case
in the present case, as the complainant clarified his request for access
to the effect that he should be informed of the data stored about him,
as well as where this data originated and to whom it was disclosed.
Therefore, as correctly assumed by the respondent authority,
the complainant did not make a general request that could be understood as seeking information
regarding Article 15(1)(a) to (h) GDPR. The fact that the
intervening party addressed all points does not alter this.
In his appeal against the decision, the appellant argued that the improved
information provided by the co-respondent on [date] 2025 was incomplete, particularly with regard to "master data,"
"recipient," and "origin."
3.3.1. Regarding the completeness of the information provided:
3.3.1.1. Regarding the information on "master data":
In his request for information dated [date] 2023, the appellant asked for information about
what data concerning him was stored by the co-respondent. The co-respondent provided the appellant with information by letters dated [date] 2023 and [date] 2025.
In the information provided by the co-defendant on XXXX 2025,
point 2 contained information on the "master data" stored for the appellant. In
the appeal against the decision, the appellant ultimately argued that the co-defendant
party had failed to include numerous "master data" items, which were clearly available, in the
initial information. The revised information showed that the originally provided
information had been grossly incomplete. - 28 -
In his appeal against the decision, the appellant did not specify which
"master data" the co-defendant had not yet disclosed or
why he assumed that the co-defendant stored further data about him and
had not disclosed it.
If the complainant's aim is to object to the fact that the
participating party should have already provided the "master data" given in the information provided ... The
Administrative Court, in its ruling VwGH06.03.2024, Ro 2021/04/0027, paragraphs 27 to 37, specifically referring to VwGH 19.10.2022, Ro 2022/04/0001, denied the right
of the data subject to obtain a declaration of an alleged infringement of the right to
access under Article 15 GDPR if the respondent, pursuant to Section 24
paragraph 6 of the Data Protection Act (DSG), provides the requested information in full by the conclusion of the proceedings before the Data Protection Authority
and thereby subsequently remedies the alleged infringement.
In his appeal against the decision, the appellant stated that even if one were to consider this
information as subsequently rectified within the meaning of Section 26 Paragraph 6 of the Data Protection Act (DSG), since the
jointly involved party had supplemented the information after more than two years, some components of the information were still incomplete. Subsequently,
he addressed in his appeal any potential deficiencies in the information regarding the
purpose of processing and the "logic involved." It can therefore be assumed that the
appellant now considers the information provided to him regarding the "master data" to be
complete, since he did not specify why the information provided on XXXX 2025
remains incomplete. The jointly involved party provided the
appellant with information about the categories of personal data being processed in accordance with Article
15 Paragraph 1 Letter b GDPR.
3.3.1.2. Regarding information about recipients or categories of recipients (Art. 15 para. 1 lit. c GDPR):
In his request for information to the co-defendant, the complainant requests from
XXXX 2023 information as to whom the data stored by him has been forwarded. In the original disclosure dated XXXX 2023, the co-party listed three recipients who had made inquiries regarding the complainant's identity and creditworthiness within the last six months. By letter dated XXXX 2025,
the co-party provided the complainant with subsequent or updated information on 25 specific recipients of the complainant's personal data, as well as information on the transmitted data (date of the inquiry,
name or company of the recipient, company registration number, address, data requested,
value transmitted, transmitted "Identity Protection" category). The complainant
objected to the information provided by the co-respondent regarding the
recipients or categories of recipients pursuant to Article 15(1)(c) GDPR, arguing that the
improved information provided by the co-respondent on [date] 2025 showed that its original
information was also (or especially) grossly incomplete in these points (“master data, recipients and origin”).
The complainant did not explain why it
assumed that the information regarding the recipients was still incomplete, but merely stated that the improved information provided by the co-respondent on [date] 2025
showed that its original information was also (or especially) grossly incomplete in these points (“master data, recipients and origin”). As already explained, there is no right to a
declaration of lateness. The complainant
did not explain why the information about recipients or categories of recipients should
still be incomplete. The co-respondent thus provided the complainant with sufficient information pursuant to Article 15(1)(c) GDPR, and the complainant did not claim otherwise.
3.3.1.3. Regarding information about the origin of the personal data pursuant to Article 15(1)(g) GDPR:
In his request for information to the co-respondent dated XXXX 2023, the complainant requested information about the origin of the data stored about him.
By letter dated XXXX 2025, the co-respondent provided the complainant with
information regarding the sources and additionally listed the following data sources by name: XXXX.
The complainant did not provide any grounds in his appeal against the decision as to why the information
regarding the origin of the data is (still) incomplete. A right to a declaration of delay does not exist in this case either.
Therefore, taking into account his application submitted on XXXX 2023,
the complainant was fully provided with the requested information regarding the origin, recipients, and which data (“master data”) is stored about him, which is why the appeal regarding the alleged incompleteness of the information provided was to be dismissed. - 30 -
3.3.2. Regarding the alleged violation of the complainant's right to confidentiality and
a violation of Article 6(1)(f) GDPR:
The complainant argued that the party involved claims a legitimate interest within the meaning of Article 6(1)(f) GDPR. However, such a situation does not exist when collecting
address data from address publishers like XXXX or XXXX. The co-involved
party should therefore have identified a violation of the complainant's right to confidentiality and a breach of
Article 6(1)(f) GDPR with regard to the data collection and further processing of the data. The alternative reference to the
general possibility of basing the activities of credit reporting agencies on Article 6(1)(f) GDPR is, in contrast, flawed. Furthermore, invoking a
legitimate interest pursuant to Article 6(1)(f) GDPR as a legal basis for
data processing is already precluded if no information about the legitimate
interest has been provided.
Regarding Article 6(1), subparagraph... Article 1(f) of the GDPR has ruled that this
provision must be interpreted as meaning that processing can only be considered necessary for the purposes of the
legitimate interests pursued by the controller or by a third party within the meaning of that
provision if such processing is limited to what is strictly necessary for the purposes of those legitimate interests and if, after weighing the competing interests and taking into account all relevant circumstances, it is clear that the interests or fundamental rights and freedoms of the data subjects do not override the legitimate interests of the controller or by a third party (see, to that effect,
judgments of 4 May 2017, Rīgassatiksme, C-13/16, EU:C:2017:336, paragraph 30, and of 4 July 2023,
Meta Platforms et al. [General Terms of Use of a Social Network], C-252/21,
EU:C:2023:537, para. 126).
The processing of personal data is lawful, in particular, if it is necessary for the
performance of a task carried out in the public interest and the task is described with sufficient clarity and precision by law; it is not necessarily
required that the law itself describe the data processing. (Austrian Administrative Court, 21 December 2023,
Ro 2021/04/0010).
In this context, the ECJ (C-26/22 and C-64/22, paragraphs 83 to 86) also assumes the
existence of a socio-economic interest of the credit sector in the processing of creditworthiness data, in particular insolvency data. It refers, on the one hand, to Article 8 of Directive 2008/48/EC,
which, in light of recital 28 of that Directive, establishes the obligation of the lender, with regard to consumer credit agreements, to assess the creditworthiness of the consumer before concluding the
credit agreement, using sufficient information,
where necessary also using information from public and private databases (this corresponds to Section 7(1) of the German Consumer Credit Act (VKrG), which implements Article 8 of Directive 2008/48/EC on consumer credit agreements).
... On the other hand, with regard to residential mortgage credit agreements for
consumers, the lender must, pursuant to Article 18(1) and Article 21(1) of Directive 2014/17 in conjunction with recitals 55 and 59 of that Directive, carry out a thorough assessment of the consumer's creditworthiness
, whereby consulting credit databases to which the
lender has access is a useful element in this assessment (this corresponds to Section 9(1) and (2) of the Mortgage and Real Estate Credit Act (HIKrG) at the national level, which implements Article
18(1) of Directive 2014/17/EU). Moreover, the obligation to assess the creditworthiness of consumers, as provided for in Directives 2008/48/EC and
2014/17/EU, is intended not only to protect the credit applicant but also, as emphasized in recital 26 of Directive 2008/48/EC, to ensure the smooth functioning of the entire credit system (see also Austrian Administrative Court [VwGH] 01.02.2024, Ro
2020/04/0031).
The analysis by a credit reporting agency, such as the party involved, can, insofar as it enables an
objective and reliable assessment of the creditworthiness of its
contractual partners' potential customers, compensate for information discrepancies and thus reduce fraud risks and other uncertainties (see ECJ C-26/22 and C-64/22, para. 93).
Therefore, there is a legitimate interest within the meaning of Article 6(1)(f) GDPR in the processing
of data. Consequently, no violation of the fundamental right to data protection could be established.
Regarding A) II. Rejection of the Complaint
3.4. Pursuant to Section 13(3) of the General Administrative Procedure Act 1991 (AVG), defects in written submissions do not authorize the authority to reject them. Rather, the authority must
provide immediate remediation of the defect ex officio and may order the
applicant to remedy the defect within a reasonable period, with the effect that the submission will be rejected if this period expires without remedy.
If the defect is remedied in a timely manner, the submission is deemed to have been correctly submitted from the outset. - 32 -
The rejection of an application pursuant to Section 13 Paragraph 3 of the General Administrative Procedure Act (AVG) is permissible if the authority has demonstrably instructed the applicant to amend the application (Austrian Administrative Court [VwGH] 14 November 1989, 89/05/0076).
Hengstschläger/Leeb, AVG § 13 para. 28 (as of 1 January 2014, rdb.at)). Under no circumstances may the authority proceed with the application without having amended it (Austrian Administrative Court [VwGH] 19 October 2006, 2006/19/0383; Hengstschläger/Leeb, AVG § 13 para. 28 (as of 1 January 2014, rdb.at)).
3.4.1. Regarding the alleged breach of the duty to provide information pursuant to Article 14 GDPR by the
participating party:
In his data protection complaint dated XXXX 2023, the complainant argued that
pursuant to Articles 13 and 14 GDPR, the legitimate interests of the data subjects must be disclosed.
This right is not sufficiently granted to the complainant as a data subject,
since it is only generally stated why the participating party appears to have overriding interests
in highly sensitive personal data concerning him. The complainant referred
to the participating party's online privacy policy.
The complainant was notified by a request for rectification dated XXXX 2023
that he was required to provide further details regarding why he considered his
right to information under Articles 13 and 14 GDPR to have been violated. In his "improved"
submission dated May 10, 2023, the complainant did not address the request for rectification
from the respondent authority and did not explain why he considered his right to information under Articles 13 and 14 GDPR to have been violated. In his
data protection complaint dated XXXX 2023, he merely stated why the privacy policy
was inadequate. Despite the request for rectification
from the respondent authority, the complainant did not address whether the information required under Article 14 GDPR
had not been provided to him at all or not at the correct time.
The respondent authority should therefore not have issued a substantive decision regarding the right to information under Articles 13 and 14 GDPR, given that the complainant also failed to comply with the order to remedy the deficiency in this respect,
and should not have dismissed the complainant's complaint regarding the breach of the information obligation under Article 14 GDPR as unfounded. Rather, the respondent authority should
have also rejected this application by the complainant pursuant to Section 13(3) of the General Administrative Procedure Act (AVG).
3.4.2. Regarding the rights to erasure pursuant to Article 17 GDPR, to rectification pursuant to Article 16
GDPR, to restriction of processing pursuant to Article 18 GDPR, to object pursuant to Article 21 GDPR, and to not be subject to a decision based solely on automated processing pursuant to Article 22 GDPR:
The data controller stated in its decision that the rights pursuant to Articles 15 to 22
GDPR are rights requiring an application. This means that the data subject must first submit a corresponding request to the controller in order to assert these rights. Since the complainant in the present case
never submitted a request to the co-party to assert his rights to rectification under
Article 16 GDPR, to erasure under Article 17 GDPR, to restriction of processing under
Article 18 GDPR, to object under Article 21 GDPR, or to not be subject to a
decision based solely on automated processing under Article 22 GDPR, he could not have been infringed in his rights in this regard by the
co-party.
The respondent authority is correct in asserting that the complainant
apparently did not submit a request under Articles 15 to 22 GDPR in his request for information dated [date] 2023.
... The complainant argued that this assessment by the respondent authority was incorrect with regard to the right to erasure under Article 17 GDPR, since controllers are obligated to erase inaccurate data even without a corresponding request. It must be countered that the co-defendant could not have known the accuracy of the stored telephone numbers. The co-defendant fully complied with the request for information submitted to it on [date], by listing which data it stores about the complainant. This list includes the telephone numbers mentioned by the complainant. The complainant should therefore have informed the co-defendant that this data was incorrect in order to initiate any necessary erasure. However, the complainant failed to do so and did not submit any other request for erasure.
... Furthermore, the complainant argued that it was particularly misguided to assume such an assessment in connection with Article 22 GDPR, which constitutes a prohibition and is by no means subject to application. The fact that the activity of XXXX (credit rating
of data subjects) is subject to the fundamental prohibition of Article 22 GDPR is also evident from the case law of the Federal Administrative Court and the publicly accessible legal opinion of the respondent authority itself. Numerous credit ratings are carried out on the complainant. - 34 -
These arguments of the complainant must be countered by the fact that, according to the case law of the Administrative Court, the rights regulated in Articles 15 to 22 GDPR are dependent on an application by the data subject. These rights therefore exist
– unlike the controller's obligation to provide information under Article 14 GDPR – not independently of a prior application by the data subject. The general provision of Article 12 GDPR also refers to a request by the data subject to exercise
their rights with regard to the rights under Articles 15 to 22 GDPR (see Austrian Administrative Court [VwGH]
26 March 2024, Ro 2021/04/0030-4 to 0031-5, para. 77 et seq.). Article 12(3) GDPR,
Recital 59 GDPR, and Article 16 GDPR also establish that the right to rectification under Article 16 GDPR is a right requiring a request.
The complainant should therefore have submitted a corresponding request for rectification or
deletion, as well as not being subject to an automated decision.
The complainant was demonstrably informed in the remedial order of
XXXX 2023 to submit a corresponding request to the controller and to send a copy of the request. The complainant did not comply with this order.
The respondent authority should therefore not have made a substantive decision on the matter,
which is why it should have rejected the data protection complaint pursuant to Section 13 Paragraph 3 of the General Data Protection Regulation (AVG).
The complainant directed his complaint against the decision in its entirety.
The respondent authority should have dismissed the complainant's complaint regarding a
violation of the right to confidentiality and an alleged violation of the
principles of processing personal data, as well as a violation of Article 15
Paragraph 1 Letters b, c, and g, based on the information already provided. Since the
complainant failed to comply with the respondent authority's order to remedy the deficiencies,
the authority would have had to reject the data protection complaint due to an alleged violation of the right to
information about the purposes of processing pursuant to Article 15(1)(a) and the right to information about the
existence of automated decision-making, including profiling, pursuant to Article 15(1)(h) GDPR, as well as due to an alleged violation of the right to information pursuant to Article 14 GDPR, the right to rectification pursuant to Article 16 GDPR, the right to erasure pursuant to Article 17 GDPR, the right to restriction of processing pursuant to Article 18 GDPR, the right
to object pursuant to Article 21 GDPR, and the right not to be subject to a decision based solely on automated processing pursuant to Article 22 GDPR, which is why
the decision was rendered accordingly. - 35 -
Regarding the omission of an oral hearing:
Pursuant to Section 24 Paragraph 1 of the Administrative Court Procedure Act (VwGVG), the Administrative Court must, upon request or if it deems it necessary,
hold a public oral hearing ex officio.
Pursuant to Section 24 Paragraph 4 of the VwGVG, the Administrative Court may, notwithstanding a party's request,
dispense with a hearing if the case file indicates that an oral discussion
would not provide any further clarification of the legal issues, and dispensing with a hearing
is not contrary to Article 6 Paragraph 1 of the Convention for the Protection of Human Rights and Fundamental Freedoms
or Article 47 of the Charter of Fundamental Rights of the European Union.
In the present case, the omission of a requested oral hearing
can be based on the fact that the facts of the case are clear from the case file in conjunction with the appeal. The Federal Administrative Court therefore has jurisdiction in this case exclusively
to rule on questions of law (see ECtHR 05.09.2002, Application No. 42057/98, Speil v. Austria).
According to the jurisprudence of the Constitutional Court, an oral hearing may be dispensed with if the facts are undisputed and the legal question is not of particular complexity (VfSlg. 17.597/2005; VfSlg. 17.855/2006; most recently, for example, VfGH
18.6.2012, B 155/12).
Regarding B) Inadmissibility of the appeal:
Pursuant to Section 25a Paragraph 1 of the Administrative Court Act (VwGG), the Administrative Court must state in the operative part of its judgment or decision whether the appeal is admissible pursuant to Article 133 Paragraph 4 of the Federal Constitutional Law (B-VG). The
decision must be briefly justified.
The appeal is inadmissible pursuant to Article 133, paragraph 4 of the Austrian Federal Constitutional Law (B-VG) because the decision does not depend on the
solution of a legal question of fundamental importance. The
decision in question neither deviates from the established case law of the
Administrative Court, nor is there a lack of case law; furthermore, the
existing case law of the Administrative Court cannot be considered inconsistent.
There are also no other indications of the fundamental importance of the legal question to be
resolved.




