DSB (Austria) - 2025-0.811.087

From GDPRhub
DSB - 2025-0.811.087
Authority: DSB (Austria)
Jurisdiction: Austria
Relevant Law: Article 5 GDPR
Article 6 GDPR
Article 10 GDPR
Article 13 GDPR
Type: Investigation
Outcome: Violation Found
Started:
Decided: 27.10.2025
Published: 20.02.2026
Fine: 1,500 EUR
Parties: n/a
National Case Number/Name: 2025-0.811.087
European Case Law Identifier: ECLI:AT:DSB:2025:2025.0.811.087
Appeal: Unknown
Original Language(s): German
Original Source: RIS (in DE)
Initial Contributor: xz

The DPA fined a controller €1,500 for unlawfully recording a public sidewalk with a CCTV camera and for publishing images of a suspected thief on social media, thereby breaching the principles of data minimisation and transparency, as well as the rules governing the processing of criminal data.

English Summary

Facts

The Data Protection Authority (DSB) initiated an investigation against the controller, a sole proprietor operating a flower shop. The controller had installed three video surveillance cameras for the protection of property: one covering the sales area, one monitoring the checkout area, and one recording the public sidewalk in front of the shop, thereby capturing passers-by. The footage was stored for 72 hours and could be accessed directly via a mobile phone.

In addition, the controller publicly posted two photographs extracted from the surveillance system on a social media platform, identifying a man suspected of theft and seeking public assistance. The post contained criminal data relating to the individual concerned and was subsequently deleted.

Holding

The DSB held that the outdoor camera violated the principle of data minimisation and lawful processing under Article 5(1)(a), (c) and 6(1)(f) GDPR, because it captured passers-by without necessity, and the publication of the images constituted unlawful further processing of criminal data under Article 10 GDPR without legal basis and without informing the data subject under Article 13(3) GDPR that images would be publicly posted.

The DSB emphasized that the reuse of personal data, the controller must conduct a compatibility test and although protecting property can include identifying a perpetrator, the DSB found that publishing the images online was neither foreseeable nor proportionate.

The controller also failed to meet transparency requirements under Article 13 GDPR, by not providing proper identification of the video surveillance system or information about processing to the data subjects

The DSB imposed an administrative fine of €1,500, plus €150 in costs and ordered cessation of the unlawful processing.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the German original. Please refer to the German original for more details.

Text

File No.: 2025-0.811.087 dated October 27, 2025 (Case No.: DSB-D550.1224)

[Note from Editor: Names and companies, legal forms and product names, addresses (including URLs, IP and email addresses), file numbers (and the like), statistical data, etc., as well as their initials and abbreviations may be abbreviated and/or altered for pseudonymization purposes.] Obvious spelling, grammar, and punctuation errors have been corrected.

Penalty Notice

Defendant: Liane B***, born on **.**.197*

As a data controller within the meaning of Article 4, point 7 of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: "GDPR"), OJ No. L 119 of 4 May 2016, p. 1 as amended, you have committed the following offense and thereby the following administrative offence: As a data controller within the meaning of Article 4, point 7, of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: "GDPR"), OJ No. L 119 of 4.05.2016 Session 1 as amended, has committed the following offense and thereby the following administrative offence:

I. Between 1 February 2024 and 16 September 2025 (hereinafter referred to as "Period of Offense I"), at the address "C***-Gasse *7, **** A***dorf" (hereinafter referred to as "Location of Offense"), you unlawfully processed personal data of passers-by (hereinafter referred to as "Data Subjects") using video camera 3 – of the video surveillance system you operate to protect your property – by doing so during the opening hours (Monday to Friday from 7:00 a.m. to 8:00 p.m. and Saturday, Sunday & public holidays between 9:00 a.m. and 6:00 p.m.) of your flower shop named "Flowers ***". The principle of data minimization pursuant to Article 5(1)(c) GDPR included recordings of the publicly accessible sidewalk area at the crime scene. Thus, during the period of the crime (I), video camera 3 regularly recorded data subjects – contrary to the purpose inherent in the system – without a legally justifiable condition for processing within the meaning of Article 5(1)(a) and Article 6(1) GDPR.


Video camera 3 recorded data subjects regularly during the period of the crime (I), contrary to the purpose inherent in the system, without a legal basis ..., contrary to the purpose inherent in the system. II. You have also misused two photographic images from your video surveillance system, specifically images from video camera 2 and video camera 3, which show the same person (hereinafter referred to as "the Victim") wearing a white T-shirt and blue trousers – once in front of and once inside your flower shop at the scene of the crime – by publishing them on July 16, 2025, at 8:31 p.m. via your publicly accessible V***net profile "Flowers ***" with the following accompanying text and keeping them publicly available until September 4, 2025 (hereinafter referred to as "Period of Crime II"):

"ATTENTION

We are asking for your help. We are looking for this man in connection with a theft in A***dorf. On Tuesday, July 15, 2025, at 2:55 p.m., this man with a German accent entered the shop in A***dorf and stole personal property…

A report has been filed with the police." Reported.

If anyone saw anything or knows this man, please contact the police.

THANK YOU

The further processing pursuant to Article 6(4) GDPR was therefore carried out without a relevant legal basis under Article 5(1)(a) GDPR and Article 6(1) GDPR in conjunction with Article 10 GDPR. The further processing pursuant to Article 6(4) GDPR was therefore carried out without a relevant legal basis under Article 5(1)(a) GDPR and Article 6(1) GDPR in conjunction with Article 10 GDPR.

III. The action against you in connection with the request for justification dated August 7, 2025, Ref: D550.1224; The charge raised in case number 2025-0.580.509, alleging that you, in your role as data controller, violated your obligation to provide information under Article 13 of the GDPR by failing to properly mark the video surveillance system or otherwise inform data subjects about data processing by the video surveillance system during the aforementioned periods and at the aforementioned location, is discontinued pursuant to Section 45(1)(1) (first case) of the Administrative Penal Code.

Administrative offenses under:

Ad. I: Article 5(1)(a) and (c), Article 6(1)(f), and Article 83(1) and (5)(a) of the GDPR, OJ L 2016/119, p. 1, as amended. I: Article 5(1), letters a and c, and Article 6(1), letter f, and Article 83(1) and (5), letter a, GDPR OJ L 2016/119, Session 1, as amended

Ad. II: Article 5(1)(a) and Article 6(1)(f) in conjunction with Article 10 and Article 83(1) and (5), letter a, GDPR OJ L 2016/119, p. 1, as amended. II: Article 5(1)(a), and Article 6(1)(f), in conjunction with Article 10, and Article 83(1)(a), GDPR OJ L 2016/119, Session 1, as amended

The following penalty is imposed for these administrative offenses:

A fine of €

if this fine is uncollectible, a substitute custodial sentence of

pursuant to

€1,500

90 hours

Article 83(5)(a) GDPR in conjunction with Section 16 of the Administrative Penal Code 1991 (VStG)

Furthermore, pursuant to Section 64 of the Administrative Penal Code 1991 (VStG), you are required to pay: Pursuant to Section 64 of the Administrative Penal Code 1991 (VStG):

150

Euros as a contribution to the costs of the proceedings, which is 10% of the penalty, but at least 10 Euros;

The total amount payable (penalty/costs/out-of-pocket expenses) is therefore

1,650

Euros

Payment deadline:

If no appeal is filed, this penalty order is immediately enforceable. In this case, the total amount must be paid within two weeks of the order becoming legally binding to the account [abbreviated here], held by the Data Protection Authority. Please include the case number and the date of completion in the payment reference.

If payment is not received within this period, the total amount may be collected. In this case, a flat-rate administrative fee of five Euros is payable. If payment is not received, the outstanding amount will be enforced, and in the event of non-payment, the corresponding substitute custodial sentence will be served.

Justification:

1. The following facts relevant to the decision have been established based on the evidence presented:

1.1. The defendant is a sole proprietor and operates a flower shop called "Blumen ***" (hereinafter "Flower Shop") at the address "C***-Gasse *7, **** A***dorf" (hereinafter "Crime Scene"). The defendant has been practicing the trade of "florist" since August 1, 2002, and has also operated a retail business since April 15, 2005.


The flower shop is open Monday to Friday from 7:00 a.m. to 8:00 p.m., and on Saturdays, Sundays, and public holidays from 9:00 a.m. to 6:00 p.m. (hereinafter referred to as "Opening Hours"). From Monday to Friday between 9:00 a.m. and 1:00 p.m., staff of the accused or the accused herself are present; during these times, the flower shop operates on a self-service basis.

1.2. Since January 2024, the accused has been operating a video surveillance system consisting of three "Cam***link Wifi ** Camera" video cameras to protect her property from damage, theft, burglary, and other harmful behavior. Two of the cameras are located indoors (Camera 1 and Camera 2), and one camera is located outdoors (Camera 3) and within the flower shop.

The accused deactivated video camera 3 on September 16, 2025 – after the initiation of the present administrative penalty proceedings.

1.3. The accused can access the video surveillance system at any time via her mobile phone. The video surveillance system is activated during the flower shop's opening hours. Recordings are stored for 72 hours.

1.4. The recording areas of the video surveillance system inside the premises are as follows (formatting not reproduced verbatim):

[Editor's note: the digital photograph in a graphic format originally shown here has been removed for reasons of pseudonymization.]

(Figure 1; Video camera 1)

Video camera 1 covers the sales area of the flower shop. The entrance door is located on the right side of the recording area. People are recorded when they enter the flower shop. People who have not yet entered the flower shop are not recorded.

[Editor's note: The original digital image in a graphic format has been removed for pseudonymization purposes.]

(Figure 2; Video camera 2)

Video camera 2 covers the checkout area of the flower shop. The checkout area includes a card payment terminal. Customers are recorded when paying for their purchases.

1.5. The recording area of the outdoor video surveillance system was as follows during the period from February 1, 2024, to September 16, 2025 (hereinafter referred to as "Period I") (formatting not reproduced verbatim):

[Editor's note: The original digital image in a graphic format has been removed for pseudonymization purposes.]

(Figure 3; Video camera 3)

Video camera 3 covered the sidewalk in front of the flower shop. The recording area therefore regularly captured passersby (hereinafter referred to as "victims") during time period I. Video camera 3 covered the sidewalk in front of the flower shop. The recording area therefore regularly captured passersby (hereinafter referred to as "victims") during time period one.

1.6. The video surveillance system is marked on the entrance door as follows (formatting not reproduced verbatim):

[Editor's note: the digital photograph in a graphic format reproduced here in the original has been removed for pseudonymization purposes.]

(Figure 4; marking of the video surveillance system)

1.7. The accused made excerpts from the recording of the video surveillance system, specifically from video camera 2 and video camera 3, and published them on July 16, 2025, at 8:31 p.m. (in the subsequent "Beginning of the period of the offense II") in a post on the V***net profile "Flowers ***", which is attributable to her and accessible to everyone.

The published photographs each show the same person wearing a white T-shirt and blue shorts (hereinafter referred to as "the victim"), once in front of and once inside the flower shop at the crime scene.

The corresponding V***net post is structured as follows (formatting not copied verbatim):

[Editor's note: The social media post, presented here in two parts as screenshots in a graphic format, has been removed for pseudonymization reasons (it contains, among other things, two photographs of a victim with the note "Please share widely"). It contains the text reproduced in point II of the statement.][Editor's note: The social media post, presented here in two parts as screenshots in a graphic format, has been removed for pseudonymization reasons (it contains, among other things, two photographs of a victim with the note "Please share widely"). It contains the text reproduced in point II of the ruling.]

(Figure 5; V***net post)

The accused deleted the post on September 4, 2025 (hereinafter referred to as "End of Period II") – after receiving the request for justification dated August 7, 2025.

1.8. In 2024, the accused generated revenue of EUR 114.***.**. from the flower shop. [Editor's note: exact amount removed for reasons of anonymity.]

2. The findings are based on the following evaluation of evidence:

2.1. The findings regarding the accused's sole proprietorship in point 1.1. are based on an official inquiry in the commercial register under the reference number: *56*T*23W. The findings regarding the businesses are based on an official inquiry with the Austrian Business Information System (GISA) using the GISA numbers *4*00*1*1 and *7*10*6*3.

The findings regarding the opening hours are based on an official inquiry by the Data Protection Authority via the defendant's website (https://www.blumen-***.at/, last accessed on October 23, 2025) and the defendant's statements in their justification dated September 16, 2025. The finding that the defendant's staff or the defendant herself is present at certain times is based on the notice on the defendant's website: "Opening hours (We are happy to assist you personally) Monday to Friday: 9:00 a.m. to 1:00 p.m."

2.2. The findings regarding point 1.2. The number of video cameras is determined by the defendant's statement of September 16, 2025, in which she states that she has had the video surveillance system since January 2024, and by the supplementary statement of October 7, 2025, in which she indicates that the video cameras are "Cam***link Wifi ** Camera" models. The number of video cameras is also determined by comparing the available photographs, in particular the recording areas of video camera 1 and video camera 2 submitted by the defendant, the photograph taken from the position of video camera 3, and the screenshot of the V***net post included with the initial submission.










... The finding regarding the deactivation of video camera 3 is based on the defendant's statement of defense dated September 16, 2025, and the photographic documentation submitted as part of the supplementary statement dated October 7, 2025, which shows that the outdoor camera is now completely disconnected from the power supply and consequently no longer capable of recording.

2.3. The findings regarding point 1.3 are based on the defendant's statement of defense dated September 16, 2025, in which she explained that access was possible via her mobile phone and, upon inquiry, stated that she could also view live recordings. The finding regarding the period during which the video surveillance system was activated is also based on the defendant's statement of defense dated September 16, 2025. The finding regarding the storage duration is based on the defendant's statements in her supplementary statement dated October 7, 2025.

2.4. The findings regarding the recording areas in point 1.4 are based on the photographs submitted by the accused in her statement of defense on September 16, 2025.

2.5. The finding in point 1.5 is based on the screenshot attached to the initial submission of July 18, 2025.

2.6. The finding concerning the identification in point 1.6 is based on the accused's statement of defense dated September 16, 2025, in which she submitted a photograph of the identification.

2.7. The findings in point 1.7 are based on the screenshot submitted with the initial submission and on an official search conducted by the Data Protection Authority on the accused's public V***net profile on August 7, 2025. The date of deletion is established by the defendant's supplementary statement of October 7, 2025, in which she stated that she deleted the post on September 4, 2025. Furthermore, a subsequent search by the data protection authority on October 23, 2025, via the defendant's V***net profile, confirmed that the post is no longer accessible.

2.8. The finding regarding point 1.8 concerning the flower shop's revenue in 2024 is based on the defendant's supplementary statement of October 7, 2025.

3. The following legal conclusions can be drawn:

3.1. Regarding the objective elements of the offense

The (image) data of the data subjects recorded by the video surveillance system in the present case undoubtedly constitutes personal data within the meaning of Article 4(1) GDPR (see ECJ 11.12.2014, C-212/13, para. 2) and the use of the video surveillance system in question constituted automated processing of personal data within the meaning of Article 4(2) GDPR in the form of "collection" and "storage" (see section 3.1.1 for further details) as well as "disclosure" (see section 3.1.2 for further details) (see ECJ 11.12.2029, C-708/18, paras. 34 et seq.; Federal Administrative Court 25.07.2025, file no. W258 2299744-1/28E). The (image) data of the data subjects undoubtedly constitutes personal data within the meaning of Article 4(1) GDPR (see ECJ 11 December 2014, C-212/13, para. 2). Furthermore, the use of the video surveillance system in question involved automated processing of personal data within the meaning of Article 4(2) GDPR in the form of "collection" and "storage" (see section 3.1.1 for further details) as well as "disclosure" (see section 3.1.2 for further details) (see ECJ 11 December 2029, C-708/18, paras. 34 et seq.; Federal Administrative Court 25 July 2025, file no. W258 2299744-1/28E).















... In light of the facts deemed proven, the accused qualifies as a data controller pursuant to Article 4(7) GDPR, as she ultimately made the decision to carry out the specific data processing. The accused never disputed her role as data controller. As a data controller, the accused is subject to the relevant (punishable) obligations of the GDPR, which are examined in more detail below.

3.1.1. On the Lawfulness of the Video Recording (Ruling I) On the Lawfulness of Video Recording (Ruling Clause One)

According to the established case law of the CJEU, data processing, in order to be lawful within the meaning of the GDPR, must comply with all the principles set out in Article 5(1) GDPR and, moreover, be based on at least one legal basis or ground pursuant to Article 6(1) GDPR (see, for example, CJEU judgment of 4 May 2023, C-60/22, paragraphs 56 and 57, and CJEU judgment of 21 December 2023, C-667/21, paragraph 78). (Judgment of 4 May 2023, C-60/22, paragraphs 56 and 57, and CJEU judgment of 21 December 2023, C-667/21, paragraph 78).

In the present case, the existence of legitimate interests pursuant to Article 6(1)(f) GDPR is a possible legal basis. No other grounds for justification are apparent, nor have any been presented by the accused.

Article 6(1)(f) GDPR permits the processing of personal data in "equal relationships" between private parties if it is necessary for the purposes of the legitimate interests pursued by a controller or by a third party (see Article 4(10) GDPR). These legitimate interests, in themselves, do not constitute a sufficient justification for the lawfulness of the processing if the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, override them. Article 6(1)(f) of the GDPR permits the processing of personal data in "equal relationships" between private entities if it is necessary for the purposes of the legitimate interests pursued by a controller or a third party (see Article 4(10) of the GDPR). However, these legitimate interests, in themselves, do not constitute a sufficient justification for the lawfulness of the processing if the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, override them.

The CJEU has already established a “test scheme” for the largely identical predecessor provision (Article 7(f) of the Data Protection Directive) and has continuously developed it further in its case law. According to this scheme, the processing of personal data is permissible under three cumulative conditions (see CJEU judgment of 11 December 2019, Case C-708/18, paragraph 36 with further references; see also, most recently, CJEU judgment of 9 November 2025, Case C-394/23, paragraph 64). The processing of personal data is permissible under three cumulative conditions (see CJEU, 11 December 2019, Case C-708/18, paragraph 36 with further references; see also CJEU, 9 November 2025, Case C-394/23, paragraph 64):

(i) the pursuit and communication of a legitimate interest,

(ii) the necessity of the processing, and

(iii) the non-overriding rights and freedoms of others.

Regarding point i) Existence and communication of the legitimate interest

In the absence of a definition of the term "legitimate interest" by the GDPR, a wide range of interests can be considered legitimate (see CJEU, 9 November 2025, Case C-394/23, paragraph 46); Recitals 47 et seq. provide some examples. Article 9(2) GDPR also contains legitimate interests in certain circumstances, which, by analogy, can justify the processing of non-sensitive data. In the absence of a definition of "legitimate interest" in the GDPR, a broad range of interests can be considered legitimate (see CJEU, 09.11.2025, C-394/23, para. 46; Recitals 47 et seq. provide some examples). Article 9(2) GDPR also contains legitimate interests in certain circumstances, which, by analogy, can justify the processing of non-sensitive data.



In the absence of a definition of "legitimate interest" in the GDPR, a broad range of interests can be considered legitimate (see CJEU, 09.11.2025, C-394/23, para. 46; Recitals 47 et seq. provide some examples). The protection and security of property constitute legitimate interests (see the judgment of the CJEU of 11 December 2019, C-708/18, concerning Article 7(f) of Directive 95/46/EC), and the accused has, as established, informed the data subjects about the processing by means of a label, which is why the first criterion can be considered fulfilled.

The protection and security of property constitute legitimate interests (see the judgment of the CJEU of 11 December 2019, C-708/18, concerning Article 7(f) of Directive 95/46/EC), and the accused has, as established, informed the data subjects about the processing by means of a label, which is why the first criterion can be considered fulfilled. Regarding point ii) Necessity

The concept of “necessity” has an independent meaning in EU law and must be interpreted in a manner that fully respects the objectives of data protection law. When assessing what is “necessary,” it must be examined whether the legitimate interests pursued by the data processing can, in practice, be achieved just as effectively by other means that are less restrictive of the fundamental rights and freedoms of the data subject (see the judgment of the Court of Justice of the European Union of 4 May 2017, C-13/16, and of 9 November 2010, C-92/09 and C-93/09). The concept of “necessity” has an independent meaning in EU law and must be interpreted in a manner that fully respects the objectives of data protection law. When assessing what is "necessary," it must be examined whether the legitimate interests pursued by the data processing can be achieved just as effectively in practice by other means that restrict the fundamental rights and freedoms of the data subject less (see the judgment of the CJEU of 4 May 2017, C-13/16, and of 9 November 2010, C-92/09 and C-93/09).

The criterion of necessity is closely linked to the principle of data minimization (Article 5(1)(c) GDPR). Even if, for example, video surveillance appears absolutely necessary, measures must be taken to restrict the recording area, such as installing a physical shutter or pixelating irrelevant areas (see European Data Protection Board (EDPB) Guidelines 3/2019 on the processing of personal data by video devices, version 2.1, paragraphs 25-27; see also Austrian Supreme Court decision 6Ob115/17f of 21 November 2017; but see also 8 Ob 125/11g). The criterion of necessity is closely linked to the principle of data minimization (Article 5(1)(c) GDPR). Even if video surveillance appears absolutely necessary, measures must be taken to restrict the recording area, such as installing a physical shutter or pixelating irrelevant areas (see European Data Protection Board (EDPB) Guidelines 3/2019 on the processing of personal data by video devices, version 2.1, paragraphs 25-27; see also Austrian Supreme Court decision 6Ob115/17f of November 21, 2017; but see also 8 Ob 125/11g).

With regard to video cameras 1 and 2, the recording area is not objectionable, especially since it is designed in such a way that only persons inside the flower shop are recorded, and as a rule, neither staff nor the accused herself are present, particularly since it is a self-service shop for the majority of the time.



With regard to video cameras 1 and 2, the recording area is not objectionable, especially since it is designed in such a way that only persons inside the flower shop are recorded, and as a rule, neither staff nor the accused herself are present, especially since it is a self-service shop for the majority of the time. However, the recording area of video camera 3 was too broad, especially since it also captured the public sidewalk area at the crime scene. This constitutes excessive processing, as there is no apparent reason why recording people merely passing by the flower shop should be necessary for the purpose of protection.

Video camera 3 was operational from January 2024 and was deactivated on September 16, 2025. Consequently, the period of the offense ran from February 1, 2024, to September 16, 2025 (hereinafter referred to as "Period of Offense I").



Video camera 3 was operational from January 2024 and was deactivated on September 16, 2025. As a result, there is a violation of the principle of data minimization pursuant to Article 5(1)(c) GDPR, and the reliance on the legal basis of Article 6(1)(f) GDPR therefore fails with regard to video camera 3 due to the second requirement. Consequently, there is a violation of the principle of data minimization pursuant to Article 5(1)(c) GDPR, and the reliance on the legal basis of Article 6(1)(f) GDPR therefore fails with regard to video camera 3 due to the second requirement.

The objective elements of the offense are thus fulfilled.

3.1.2. Further processing of the recording by publication (Point II) Regarding the further processing of the recording by publication (Roman numeral II)

The accused, as established, further processed recordings from video cameras 2 and 3 by sharing two photographs depicting a person involved via her public V***net profile as part of a post.


The accused, as established, further processed recordings from video cameras 2 and 3 by sharing them on her public V***net profile. If processing is based on a purpose other than that for which the personal data were collected, the criteria of Article 6(4)(a) to (e) GDPR must be considered in a compatibility test, unless the data subject has given consent or a Member State law applies:

- any link between the purposes for which the personal data were collected and the purposes of the intended further processing,

- the context in which the personal data were collected, in particular with regard to the relationship between the data subjects and the controller,

- the nature of the personal data, in particular whether special categories of personal data pursuant to Article 9 GDPR are processed or whether personal data relating to criminal convictions and offences pursuant to Article 15 GDPR are processed Article 10 GDPR applies,

- the possible consequences of the intended further processing for the data subjects and

- the existence of suitable safeguards, which may include encryption or pseudonymization.

The protection of property generally includes the objective of identifying the perpetrator of a property infringement; this also establishes a connection to the public search for the perpetrator and the connection to the collection of data.

Furthermore, it must be noted that the post contains information that identifies a person as a suspected perpetrator of a crime. Such information qualifies as criminal data within the meaning of Article 10 GDPR.

While it is inherent in the nature of things that video recordings showing individuals interfering with the property of others can be used to investigate potential crimes, The publication of such recordings via the accused's V***net profile constitutes a form of public manhunt that is neither comprehensible nor foreseeable for the individual concerned.

The consequences of the intended further processing of the data should not be underestimated, especially since the publication has resulted in public shaming. A manhunt via social networks can effectively lead to the worldwide disclosure of the individual's identity, as the content is accessible to anyone with access to the respective platform. This significantly increases the risk of infringing upon the individual's fundamental rights, particularly since the servers are often located in third countries where the enforcement of rights is more difficult. Furthermore, such an online manhunt carries the risk of significantly exacerbating the individual's reputational damage.

Furthermore, there is neither consent nor a corresponding national legal basis within the meaning of Article 6(4) GDPR for the further processing for a different purpose. Instead, there is only an explicit legal basis for security authorities (see Section 24 in conjunction with Section 57 of the SPG). The further processing is therefore contrary to the original purpose.

Furthermore, there is neither consent nor a corresponding national legal basis within the meaning of Article 6(4) GDPR for the further processing for a different purpose. Instead, there is only an explicit legal basis for security authorities (see Section 24 in conjunction with Section 57 of the SPG). The further processing is therefore contrary to the original purpose. Even if, contrary to expectations, further processing were deemed appropriate, it would still be unlawful:

In principle, Section 4 Paragraph 3 Item 2 of the Data Protection Act (DSG) permits – beyond Article 10 of the GDPR – the processing of criminal data by private entities, provided there is a legitimate interest within the meaning of Article 6 Paragraph 1 Letter f of the GDPR (see the decision of the Federal Administrative Court of May 8, 2025, W274 2264017-1). As already discussed in section 3.1.1, it is therefore necessary to examine whether the admissibility requirements are met. In principle, Section 4 Paragraph 3 Item 2 of the Data Protection Act (DSG) permits – beyond Article 10 of the GDPR – the processing of criminal data by private entities, provided there is a legitimate interest within the meaning of Article 6 Paragraph 1 Letter f of the GDPR (see the decision of the Federal Administrative Court of May 8, 2025, W274 2264017-1). As already discussed in section 3.1.1, it is therefore necessary to examine whether the admissibility requirements are met.

This examination can be shortened in this case, particularly since it already fails at point i), as no information pursuant to Article 13(3) GDPR was provided to the data subject that the collected image data would be published via the publicly accessible V***net profile. Furthermore, with regard to the necessity requirement under criterion ii), the processing cannot be considered the least intrusive means of achieving the purpose, especially since forwarding the relevant video material to the police is already sufficient to identify the perpetrator. With regard to criterion iii), it should also be noted that the rights and freedoms of the data subject outweigh the interests of the data subject, especially since the consequences of the publication are already considered serious, and the data subject's right to privacy has been violated by the publication. The examination can therefore be shortened in this case, as it already fails at point i), since no information pursuant to Article 13(3) GDPR was provided to the data subject that the collected image data would be published via the publicly accessible V***net profile. Furthermore, with regard to the necessity requirement under criterion ii), the processing cannot be considered the least intrusive means of achieving the purpose, especially since forwarding the relevant video material to the police is sufficient to identify the perpetrator. With regard to criterion iii), it should also be noted that the rights and freedoms of the data subject outweigh the interests of the data controller, especially since the consequences of the publication are already considered serious, and the data subject's right to privacy has been violated by the publication.

Consequently, there is no legal basis justifying the processing, meaning that the objective elements of the offense are met.

3.2. Regarding the subjective element of the offense

The CJEU has held that only violations of the GDPR provisions committed culpably by the controller, i.e., intentionally or negligently, can lead to the imposition of a fine (see CJEU of 5 December 2023, C-807/21, para. 68), and that such culpability exists even if the accused could not have been unaware of the unlawfulness of their conduct, regardless of whether they were aware that they were violating the GDPR provisions (see CJEU C-807/21, para. 76). The accused has a corresponding duty to inquire, at least if they were unaware of the legal situation (Austrian Administrative Court [VwGH] 25 June 2013, 2013/09/0022). The CJEU has held that only violations of the GDPR provisions committed culpably by the controller, i.e., intentionally or negligently, can lead to the imposition of a fine (see CJEU of 5 December 2023, C-807/21, para. 68), and that such culpability exists even if the accused could not have been unaware of the unlawfulness of their conduct, regardless of whether they were aware that they were violating the GDPR (see CJEU C-807/21, para. 76). The accused has a corresponding duty to inquire, at least if they were unaware of the legal situation (Austrian Administrative Court [VwGH] 25 June 2013, 2013/09/0022).


In light of the facts deemed proven, the data protection authority does not, however, find that the accused committed an intentional act with regard to point I of the ruling. The accused chose to operate the video surveillance system for the established purposes, but apparently failed to adequately inform herself about the relevant administrative regulations concerning video camera 3. Simply accessing the data protection authority's website would have been sufficient to ascertain, for example, that video surveillance is only permitted to the extent absolutely necessary. Furthermore, the European Data Protection Board has also published recommendations on its website in the form of guidelines on video surveillance and the processing of personal data pursuant to Article 6(1)(f) GDPR (see Guidelines 3/2019 on the processing of personal data by video devices and Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR, Version 1.0, adopted on 8 October 2024). In light of the facts deemed proven, the Data Protection Authority, with regard to point one of the ruling, does not find any intentional wrongdoing on the part of the accused. The accused decided to operate the video surveillance system for the established purposes but apparently did not sufficiently inform herself about the relevant administrative regulations concerning video camera 3. Simply accessing the Data Protection Authority's website would have been sufficient to ascertain, for example, that video surveillance may only be carried out to the extent absolutely necessary. Furthermore, the European Data Protection Board has also published recommendations on its website in the form of guidelines on video surveillance and the processing of personal data pursuant to Article 6(1)(f) GDPR (see Guidelines 3/2019 on the processing of personal data by video devices and Guidelines 1/2024 on the processing of personal data based on Article 6(1)(f) GDPR, Version 1.0, adopted on October 8, 2024).

With regard to point II of the ruling, the accused should have recognized that the further processing of the photographs she intended to carry out was inappropriate. The clear wording of Article 6(4) GDPR also specifies the criteria under which further processing is permissible. The accused also deleted the post from her V***net profile immediately after receiving the request for justification. With regard to point II of the ruling, the accused should have recognized that the further processing of the photographs she intended to carry out was inappropriate. The clear wording of Article 6, paragraph 4, of the GDPR also specifies the criteria under which further processing is permissible. Furthermore, the accused deleted the post from her V***net profile immediately after receiving the request for justification.

Therefore, the subjective element of the offense is also fulfilled.

3.3. Regarding point III of the ruling

For the sake of completeness, it should be noted here that the request for justification dated August 7, 2025, file number D550.1224; The charge raised in case no. 2025-0.580.509, that the accused, in her role as data controller, violated her duty to provide information pursuant to Article 13 GDPR by failing to properly label the video surveillance system or otherwise inform data subjects about processing by the video surveillance system, was dismissed in point III of the ruling pursuant to Section 45 Paragraph 1 Item 1 (first case) of the Administrative Penal Code. For the sake of completeness, it should also be noted that the request for justification dated August 7, 2025, file number D550.1224, was also dismissed. The charge raised in case 2025-0.580.509, that the accused, in her role as data controller, violated her duty to provide information under Article 13 of the GDPR by failing to properly label the video surveillance system or otherwise inform data subjects about the processing of their data by the video surveillance system, was dismissed in point III of the ruling pursuant to Section 45, paragraph 1, number 1 (first case) of the Administrative Penal Code (VStG).

3. Regarding sentencing, the following should be noted:

In deviation from Section 22, paragraph 2 of the Administrative Penal Code (VStG), the absorption principle pursuant to Article 83, paragraph 3 of the GDPR applies to the established violations, and a single aggregate penalty is imposed for the established violations (point I and point II of the ruling) (see Austrian Administrative Court [VwGH] 30 April 2025, Ro 2021/04/0024). The penalty range is determined by the most serious infringement. Therefore, in this specific case, the penalty range pursuant to Article 83(5)(a) GDPR extends up to an amount of EUR 20,000,000. In deviation from Section 22(2) of the Administrative Penal Code (VStG), the absorption principle pursuant to Article 83(3) GDPR applies to the established infringements, and a single aggregate penalty is imposed for the established infringements (point one and point two) (see Austrian Administrative Court [VwGH] 30 April 2025, Ro 2021/04/0024). The penalty range is determined by the most serious infringement. Therefore, in this specific case, the penalty range pursuant to Article 83(5)(a) GDPR extends up to an amount of EUR 20,000,000.

With regard to the present case, the following aggravating factors were considered in determining the sentence:

● Nature and severity of the violation: The unlawful operation of video camera 3 violated the fundamental rights of the data subjects (right to privacy under Section 1 Paragraph 1 of the GDPR, as well as the right to respect for private and family life and the right to the protection of personal data under Articles 7 and 8 of the EU Charter of Fundamental Rights) over a prolonged period. The potential consequences of the unauthorized processing of the recordings and the intensity of the intrusion are also considered particularly serious.

● Categories of personal data: The defendant processed criminal offenses within the meaning of Article 10 of the GDPR (Article 83 Paragraph 2 Letter g of the GDPR) through the content of the post.


● With regard to the present case, the following mitigating factors were taken into account when determining the sentence:

● The accused had no prior convictions with the data protection authority for violations of the GDPR or the Austrian Data Protection Act (Art. 83 para. 2 lit. e GDPR).

● The accused cooperated in the present investigation and contributed to establishing the facts. Furthermore, the accused admitted the violation (confession) (Art. 83 para. 2 lit. k GDPR).

One of the essential objectives of the GDPR, according to Art. 1 para. 2 GDPR, is the protection of the fundamental rights and freedoms of natural persons, and in particular their right to the protection of personal data under Art. 8 of the Charter of Fundamental Rights of the European Union. As explained above, the accused violated the fundamental rights of the data subjects. The imposition of this specific fine is therefore necessary in a general deterrent sense, both to raise awareness among those responsible for the lawful processing of personal data within the context of video surveillance systems and to emphasize the inadmissibility of further processing such recordings via V***net profiles, including criminally relevant content. One of the essential objectives of the GDPR, according to Article 1, paragraph 2, is the protection of the fundamental rights and freedoms of natural persons, and in particular their right to the protection of personal data under Article 8 of the Charter of Fundamental Rights of the European Union. The accused violated the fundamental rights of the data subjects, as explained above. The imposition of this specific fine is therefore necessary in a general deterrent sense, both to raise awareness among those responsible for the lawful processing of personal data within the context of video surveillance systems and to emphasize the inadmissibility of further processing such recordings via V***net profiles, including criminally relevant content.














... The data protection authority assumes that the accused will refrain from publishing such content via her V***net profile in the future. Furthermore, the accused has ceased processing data using video camera 3, therefore there are no special preventive grounds for imposing any further measures.
...] The specific penalty imposed, amounting to EUR 1,500, therefore appears proportionate to the seriousness of the offense, measured against the available penalty range under Article 83(5) GDPR (here up to EUR 20,000,000) and taking into account the relevant sentencing criteria under Article 83(2) GDPR, and is at the lower end of the available penalty range due to the first offense.

If a fine is imposed on a natural person, Section 16 Paragraph 1 of the Administrative Penal Code (VStG) stipulates that a substitute custodial sentence must be imposed simultaneously in the event of non-payment.

As a result, the specific penalty imposed is therefore effective, proportionate, and dissuasive in this case within the meaning of Article 83 Paragraph 1 of the GDPR. A lower amount would no longer meet these criteria for a fine.