DSB (Austria) - 2025-0.891.622
| DSB - 2025-0.891.622 | |
|---|---|
| Authority: | DSB (Austria) |
| Jurisdiction: | Austria |
| Relevant Law: | Article 2(1) GDPR Article 3(2)(a) GDPR Article 4(1) GDPR Article 4(11) GDPR Article 5(1)(a) GDPR Article 7(1) GDPR Article 12(1) GDPR Article 17 GDPR Article 19 GDPR Article 25(1) GDPR Article 58(2) GDPR Article 58(6) GDPR Article 77(1) GDPR Article 80(2) GDPR § 1 DSG § 24 DSG |
| Type: | Complaint |
| Outcome: | Partly Upheld |
| Started: | 11.08.2021 |
| Decided: | 07.11.2025 |
| Published: | 02.04.2026 |
| Fine: | n/a |
| Parties: | n/a |
| National Case Number/Name: | 2025-0.891.622 |
| European Case Law Identifier: | ECLI:AT:DSB:2025:2025.0.891.622 |
| Appeal: | Unknown |
| Original Language(s): | German |
| Original Source: | RIS (in DE) |
| Initial Contributor: | Ava Lang |
The DPA ordered the operator of a live-streaming website to change their cookie banner due to its deceptive design. The DPA considered the “accept” option to be visually more prominent, unlawfully nudging users towards consent.
English Summary
Facts
The data subject visited a live-streaming website operated by a controller based in the United States on 21 January 2021. During this visit, the website set and read cookies containing unique identifiers and transmitted these values, together with the IP address, to third parties.
The cookie banner presented an “Accept” button more prominently than other options. The data subject later filed a complaint on 11 August 2021, requesting deletion of personal data, notification of recipients, and ceasing the unlawful processing. On 30 December 2022, the data subject additionally requested a formal finding of a violation of the right to confidentiality.
The controller stated that it had changed the cookie banner, deleted the remaining identifier, and informed third-party recipients of the deletion. It also confirmed that it no longer stored the relevant cookie data or IP address.
The data subject was represented by noyb during the proceedings in this case.
Holding
First, the DPA confirmed that cookie identifiers combined with IP addresses constituted personal data under Article 4(1) GDPR.
Second, the DPA held that there was no violation of Article 17 GDPR or Article 19 GDPR because the controller had already deleted the data and informed recipients. It noted that data subjects do not have a right to a declaration that deletion occurred too late.
Third, the DPA rejected the request to order cessation of processing under Article 58(2) GDPR because the controller no longer processed the data of the data subject. It also clarified that complaints must relate to the data subject’s own data and cannot be used as a general action against processing practices.
Fourth, the DPA rejected the request for a declaration of a past violation of the right to confidentiality as time-barred under § 24(4) DSG, since it was filed more than one year after the data subject became aware of the processing.
Finally, the DPA exercised its corrective powers under Article 58(2)(d) GDPR on its own initiative. It held that the cookie banner did not meet the requirements for valid consent under Article 4(11) GDPR and Article 7 GDPR and violated the fairness principle under Article 5(1)(a) GDPR. The authority found that the “accept” option was visually more prominent, which nudged users towards consent.
The DPA ordered the controller to redesign the cookie banner within two weeks to ensure equal visual presentation of “accept” and “decline” options, including equal colour, size, contrast, and placement.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the German original. Please refer to the German original for more details.
Text
File No.: 2025-0.891.622 dated November 7, 2025 (Case No.: DSB-D130.1438)
[Note from Editor: Names and companies, legal forms and product names, addresses (including URLs, IP and email addresses), file numbers (and the like), statistical data, etc., as well as their initials and abbreviations may be abbreviated and/or altered for pseudonymization purposes.] Obvious spelling, grammar, and punctuation errors have been corrected.
DECISION
RULING
The Data Protection Authority decides on the data protection complaint filed by Franziska A*** (complainant), represented by the O*** Data Protection Association, U***platz *5*/*4, 1**** Vienna, ZVR: *6*2*7*33, on August 11, 2021, against N*** Online, Inc., headquartered in the USA (respondent), concerning A) the right to erasure and the obligation to notify in connection with erasure, B) the request for an order against the respondent to cease unlawful processing, and C) the request of December 30, 2022, to establish an alleged violation of the right to confidentiality, as follows:
1) The complaint is dismissed with regard to points A) and B).
2) The complaint is rejected with regard to point C).
3) The respondent is ordered ex officio, within two weeks, failing which enforcement proceedings will be initiated, to amend the request for consent (the cookie banner, see Statement of Facts C.6.) on the website https://www.n***.online in such a way that valid consent is obtained when visiting the website. To this end, the respondent must at least amend the cookie banner so that the data subject is offered an equivalent choice between "Accept" and "Reject" on the first level of the cookie banner. It must be ensured that both options are designed equally with regard to visual presentation, including color, size, contrast, placement, and emphasis. It is impermissible to give precedence to one of the options through an excessively conspicuous design, such as a preferred color scheme, a larger font size, or a more prominent placement.
To this end, the respondent must at least modify the cookie banner so that the data subject is offered an equivalent choice between "Accept" and "Reject" on the first level of the cookie banner. Legal basis: Article 2(1), Article 3(2)(a), Article 4(11), Article 5(1)(a), Article 7, Article 12(1), Article 17, Article 19, Article 57(1)(f), Article 58(2)(d) and Article 77(1) of Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR), OJ No. L 119 of 4.5.2016, p. 1; Sections 18(1) and 24(1), (2)(5), (4) and (5) of the Data Protection Act (DSG), Federal Law Gazette I No. 165/1999 as amended. Legal basis: Article 2(1), Article 3(2)(a), Article 4(11), Article 5(1)(a), Article 7, Article 12(1), Article 17, Article 19, Article 57(1)(f), Article 58(2)(d), and Article 77(1) of Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR), Official Journal No. L 119 of 4 May 2016, Session 1. Sections 18, paragraph one, and 24, paragraphs one, 2, number 5, 4, and 5, of the Data Protection Act (DSG), Federal Law Gazette Part One, No. 165 of 1999, as amended.
REASONING
A. Submissions of the Parties and Procedural History
A.1. In submissions dated August 11, 2021, December 30, 2022, and September 8, 2025, the complainant (hereinafter: bP) argued, in essence, that it had visited the website of the respondent (hereinafter: BG) at https://www.n***.online and that impermissible cookies had been set. It was requested that BG be ordered to cease all relevant processing activities and delete all relevant personal data. Furthermore, it was requested that a violation of the right to confidentiality be established. The changes made to the cookie banner in the interim are welcome. However, the GDPR requirements for consent declarations are still not fully met. The present complaint was initially filed against N*** UK Limited and later directed against the current BG. Several attachments were included with the submissions.
A.2. In submissions dated August 22, 2025, and October 30, 2025, the BG essentially stated that it was responsible for the website https://www.n***.online and that changes had been made to the cookie banner. The design complies with the GDPR requirements. An internal investigation of the IP address and cookie values of the third-party provider (bP) was conducted. The BG was unable to find any data from the bP except for a device_id. The device_id has been deleted. Furthermore, the BG sent letters to third-party providers who own the cookies in question, informing them of the deletion request.
B. Subject of the Complaint
B.1. Article 58 GDPR does not contain an explicit legal basis for an independent determination of the potential unlawfulness of a data processing operation relevant under data protection law (see Austrian Administrative Court [VwGH] of 1 September 2022, Ra 2022/04/0066). Therefore, the mere determination of a violation of a data protection right pursuant to (Article 58(6) GDPR in conjunction with) Section 24(2)(5) in conjunction with Section 1 of the Austrian Data Protection Act (DSG)) requires an application from the data subject. B.1. Article 58 GDPR does not contain an explicit legal basis for an independent determination of the potential unlawfulness of a data processing operation relevant under data protection law (see Austrian Administrative Court [VwGH] of 1 September 2022, Ra 2022/04/0066). Accordingly, the mere finding of a violation of a data protection right pursuant to Article 58(6) GDPR in conjunction with Section 24(2)(5) in conjunction with Section 1 of the Austrian Data Protection Act (DSG) requires a request from the data subject.
For the subject matter of the complaint in the present case, this means the following:
B.2. The complainant did not submit a request within the meaning of Section 24(2)(5) DSG in its submission of August 11, 2025. No reference to Section 24(2)(5) DSG—or to the DSG in general—was initially apparent in the subsequent statements either. recognizable.
Only with its submission of December 30, 2022, did the applicant submit a supplementary request to establish that the company violated the provisions of Section 24, Paragraph 2, Item 5 of the Data Protection Act (DSG) in conjunction with Section 1 of the DSG, which are exhaustively numbered for each type of violation – ultimately amounting to a violation of the right to confidentiality. Therefore, a determination of a past legal violation must be made.
However, it must first be examined whether the The application for the right to confidentiality submitted on December 30, 2022, is not already precluded.
B.3. The subject of the complaint is also the request by the data controller to order the supervisory authority to A) delete the data controller's personal data and notify the recipients of the deletion, and B) cease the "relevant processing activities."
By "relevant processing activities," the data controller refers to the data processing on January 21, 2021, during which cookies were set or read.
B.4. In the present case, it must also be examined beforehand whether the territorial scope of the GDPR is applicable and whether the data protection authority is therefore competent to handle the complaint.
C. Findings of the Facts
C.1. Cookies allow the collection of information generated by a website and stored via an internet user's browser. A cookie is a small file or piece of text information (usually less than one kilobyte) that a website places on a user's computer or mobile device's hard drive via their browser.
A cookie allows the website to "remember" the user's actions or preferences. Most web browsers support cookies, but users can configure their browsers to reject them. They can also delete cookies at any time.
Websites use cookies to identify users, remember their customers' preferences, and allow users to complete tasks without having to re-enter information when they navigate to another page or revisit the website later.
Cookies can also be used to gather information based on online behavior for targeted advertising and marketing. For example, companies use software to track user behavior and create personalized profiles that allow them to show users ads tailored to their previous searches.
Evaluation of Evidence C.1: The statements regarding the functioning of cookies are taken from the Advocate General's Opinion in Case C-673/17, paragraphs 36 et seq., with further references. Since this is a general technical description of the possible functions of cookies, independent of any specific case, these statements were to be included at the factual level – and not in the legal assessment.
C.2. The BG operates the website https://www.n***.online. It decides under which conditions which cookies are set or read when the aforementioned website is accessed.
“N***” is a live streaming platform where users worldwide can stream and watch video games, music, art, talk shows, and other content in real time. Viewers can interact with streamers and subscribe to channels. The service is not restricted to people from specific regions. When accessing the “N***” platform from an Austrian user location, the information on the user interface is provided in German.
Evidence Assessment C.2: The findings are based on the statement of the Austrian Federal Government (BG) dated August 22, 2025, and an official search conducted by the Data Protection Authority on the website https://www.n***.online, last accessed on November 5, 2025.
C.3: The Austrian Federal Government (bP) visited the website https://www.n***.online at least on January 21, 2021.
``` The cookie banner looked like this on January 21, 2021 (formatting not reproduced exactly):
[Editor's note: the original cookie banner shown here as a graphic file has been removed for pseudonymization reasons.] The pseudonymized text content is reproduced here, along with a description of other elements.
“We value your privacy.
N*** and our partners use technologies such as cookies on our site to personalize content, deliver interest-based (“personalized”) advertising, and analyze user activity. See our Privacy Policy to read more. By continuing to use the site, you consent to the use of these technologies. N*** also engages in third-party personalized ad activities to support our services and provide more relevant ad experiences. By clicking “Accept,” you consent to this activity. To learn more or to decline consent for this activity, click “Manage Preferences.”
[To the left of the text is a graphic cookie symbol; to the right are two buttons: “Manage Preferences” and “Accept,” with “Accept” displayed in a bolder color.]
Evaluation of Evidence C.3: The findings are based on the submission of the applicant dated August 11, 2021, and are undisputed. The screenshot is based on the attachment "Exhibit 2.png" submitted by bP.
C.4. As a result of visiting the website https://www.n***.online on January 21, 2021, cookies containing a unique, randomly generated value (random number) were placed on and read from bP's device. These cookie values were subsequently transmitted to third-party providers.
The content of attachments "Exhibit 5.har" and "Exhibit 6.csv" forms the basis for the findings of fact.
Evaluation of Evidence C.4.: The findings are based on bP's submission of August 11, 2021, and on the attached attachments "Exhibit 5.har" and "Exhibit 6.csv". A .har file is an archive format for HTTP transactions.
C.5. The BG is currently not storing any cookie data that was set and read on the user's device as a result of the visit to https://www.n***.online on January 21, 2021. Furthermore, the BG is not currently storing the IP address of the user's device, which was stored in its log files—at least temporarily—as a result of the same visit.
The BG has also informed the recipients of the data transfer (specifically, the providers of the services it has implemented on its website) about the deletion.
Evidence Assessment C.5: The findings are based on the BG's statement of August 22, 2025. Following an explicit request from the Data Protection Authority, the BG stated that it had conducted a search of its internal systems. The search was carried out using the user's name and the IP address provided in the complaint. The BG also explained that the recipients of the data transfer were informed about the deletion. There is no evidence to doubt the BG's submissions, especially since the BG has been quite cooperative during the investigation and has adjusted the cookie banner – albeit perhaps not to the complete satisfaction of all parties. The bP has also ceased to dispute the BG's submissions in this regard.
C.6. The BG has adjusted the cookie banner on the website https://www.n***.online. Currently, the BG's cookie banner looks like this (formatting not reproduced verbatim):
[Editor's note: The original cookie banner, shown here as a graphic file, has been removed for pseudonymization purposes. Only the pseudonymized text content of the actual banner (not the website content also shown) is reproduced here, along with a description of other elements.] [The underlined text passages contain hyperlinks in the original.]
"Cookies and Advertising Options
N*** uses personal data collected through our services, such as page visits via cookies and other device identifiers, to generate personalized content, store preferences, analyze usage to improve products, and measure the effectiveness of campaigns to acquire new users. If you agree, we also allow other N*** services and up to 14 trusted third-party partners to receive data from our services or to store and access cookies on your device to deliver personalized advertising, measure its effectiveness, and gain audience insights. We also personalize the ads we show you on N*** using cookies and personal data we may receive from third-party partners. Ads you see on other websites may also be personalized based on your use of N***. For more information, please see our Cookie Statement and Privacy Policy. By clicking "Accept," you consent to these activities." Click "Decline" to object, or "Customize" to make more detailed selections and learn more. You can change these settings at any time.
[To the left of the text is a graphical cookie icon; to the right are three buttons: "Accept," "Custom," and "Decline." "Accept" is graphically highlighted as a white button against two light purple buttons.]
Enlarged view:
[Editor's note: The cookie banner (without website content) originally displayed here as an image file has been removed because it is redundant.]
If "Accept" is selected, cookies will be placed on and read from the user's device. These cookies contain a unique, randomly generated value (random number).
[Editor's note: The cookie banner shown here in the original image file (without website content) has been removed because it is redundant.]
If "Accept" is selected, cookies will be placed on and read from the user's device. These cookies contain a unique, randomly generated value (random number).
[Editor's note: The original cookie banner shown here has been removed because it is redundant.] Evaluation of Evidence C.6: The findings regarding the cookie banner are based on an official search conducted by the Data Protection Authority at https://www.n***.online, last accessed on November 5, 2025, as well as on the statement of the BG dated August 22, 2025, and the submitted list of cookies. The publicly available tool of the European Data Protection Board (EDPB website auditing tool) was also used for the cookie search.
Legal Assessment
D.1. Territorial Scope
First, it must be examined whether the territorial scope of the GDPR is applicable.
Article 3(2) GDPR reads: “This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union where the processing is related to (a) offering goods or services to data subjects in the Union, irrespective of whether payment is to be made by those data subjects, or (b) monitoring their behavior, insofar as that behavior takes place in the Union.” Article 3(2) GDPR reads: “This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union where the processing is related to (a) offering goods or services to data subjects in the Union, irrespective of whether payment is to be made by those data subjects, or (b) monitoring their behavior, insofar as that behavior takes place in the Union.”
This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union where the processing is related to (a) offering goods or services to data subjects in the Union, irrespective of whether payment is to be made by those data subjects, or (b) monitoring their behavior, insofar as that behavior takes place in the Union. Even though the concept of "directing an activity" differs from "offering goods or services," the EDPB considers this case law in Pammer v Reederei Karl Schlüter GmbH & Co and Hotel Alpenhof v Heller (Joined Cases C-585/08 and C-144/09) helpful in assessing whether goods or services are being offered to a data subject in the Union. Taking into account the specific circumstances of the case, the following factors, among others, could therefore be considered, possibly in combination:
- The EU or at least one Member State is named with reference to the goods or services offered;
- The controller or processor pays a search engine operator for an internet referencing service to facilitate access to its website by consumers in the Union, or the controller or processor has launched a marketing and advertising campaign aimed at the public in an EU country;
- The international nature of the activity in question, such as certain tourism activities;
- The provision of specific addresses or telephone numbers that can be reached from an EU country;
- The use of a top-level domain name other than that of the third country in which the controller or processor is established, e.g., ".de", or the use of neutral top-level domain names such as ".eu";
- The description of travel instructions from one or more other EU Member States to the location where the service is provided;
- The indication of an international customer base consisting of customers located in different EU Member States, in particular through invoicing by these customers;
- The use of a language or currency other than that customary in the country of the trader, in particular a language or currency of one or more EU Member States;
- The controller offers the delivery of goods to EU Member States (see EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) of 12 November 2019, pp. 20 et seq.). The controller offers the delivery of goods to EU Member States (see EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) of 12 November 2019, session 20 et seq.).
As can be seen from the findings of fact, “N***” is a live streaming platform where users worldwide can stream and watch video games, music, art, talk shows, and other content in real time. Viewers can interact with streamers and subscribe to channels. There is no restriction of the service to people from specific regions (see findings of fact C.2). It should also be noted that “N***” provides standard information in the respective national language on its general user interface, depending on the region.
The territorial scope of the GDPR is therefore established.
D.2. Material Scope
In the Google Analytics case, the data protection authority has already ruled—in accordance with the case law of the European Data Protection Supervisor (EDPS)—that cookies containing a unique, randomly generated value (random number) and set for the purpose of identifying and singling out individuals meet the definition of Article 4(1) GDPR. In particular, it can never be ruled out that the cookie values and the IP address of a person's terminal equipment may be combined with additional information at any point in the processing chain, e.g., if the data subject registers on a website with their email address or real name (see the decision of 22 April 2022, file number: 2022-0.298.191, available on the website www.dsb.gv.at; this legal opinion is confirmed, inter alia, by the ruling of the Federal Administrative Court of 12 May 2023, file number: W245 2252208-1; regarding the personal data nature of "Google Analytics cookies," see also the decision of the European Data Protection Supervisor (EDPS) against the European Parliament of 5 January 2022, file number: 2020-1013, p. 13). In the case of Google Analytics, the data protection authority has already ruled – in accordance with the jurisprudence of the European Data Protection Supervisor (EDPS) – that cookies containing a unique, randomly generated value (random number) and set for the purpose of individualizing and singling out persons meet the definition of Article 4(1) of the GDPR. In particular, it can never be ruled out that the cookie values and the IP address of a person's terminal equipment are combined with additional information at any point in the processing chain, e.g., when the data subject registers on a website with their email address or full name (see the decision of April 22, 2022, file number: 2022-0.298.191, available on the website www.dsb.gv.at). This legal opinion is confirmed, among other things, by the ruling of the Federal Administrative Court of May 12, 2023, file number: W245 2252208-1. Regarding the personal data processing of "Google Analytics cookies," see also the decision of the European Data Protection Supervisor (EDPS) v. the European Parliament of 5 January 2022, file number 2020-1013, session 13.
These considerations can be applied to the present case, as cookies with unique values were set and read on the user's device as a result of visiting the website https://www.n***.online on 21 January 2021. Subsequently, the cookie values and the user's device IP address were transmitted to third-party servers (see statement of facts C.4).
The material scope of the GDPR is therefore also applicable.
D.3. Jurisdiction of the Data Protection Authority for the Use of Cookies
Processing operations in a given case may be subject to the provisions of Directive 2002/58/EC as amended (ePrivacy Directive) or the Telecommunications Act 2021 (TKG 2021), as well as the GDPR. While the setting or reading of cookies is to be assessed according to the provisions of Article 5(3) of the ePrivacy Directive, the subsequent data processing falls within the scope of the GDPR (see EDPB Guidelines 01/2020 on the processing of personal data in connection with connected vehicles and mobility-related applications, Version 2.0, paragraphs 15 and 53). Processing operations in a given situation may be subject to the provisions of Directive 2002/58/EC as amended (ePrivacy Directive) or the Telecommunications Act 2021, as well as the GDPR. While the setting or reading of cookies is to be assessed according to the provisions of Article 5(3) of the ePrivacy Directive, the subsequent data processing falls within the scope of the GDPR (see EDPB Guidelines 01/2020 on the processing of personal data in connection with connected vehicles and mobility-related applications, Version 2.0, paragraphs 15 and 53).
This also corresponds to the legal opinion of the CJEU in the Fashion ID case. The CJEU held that, as a consequence of the implementation of a social plugin on a website (which falls within the scope of the ePrivacy Directive), the transfer of the website visitor's data to Facebook Ireland Limited and the subsequent data processing fall within the scope of the (then) Directive 95/46/EC (see the CJEU judgment of 29 July 2019, C-40/17, paragraphs 26 and especially 85). This was based on the assumption that, as a consequence of implementing a social plugin on a website (which falls within the scope of the ePrivacy Directive), the transfer of the website visitor's data to Facebook Ireland Limited and the subsequent data processing fall within the scope of the (then) Directive 95/46/EC (see the judgment of the CJEU of 29 July 2019, C-40/17, paragraphs 26 and especially 85).
The data protection authority is therefore competent for the present complaint, as data transfer has taken place as a result of setting or reading cookies (see statement of facts C.4).
Regarding point 1 of the ruling
D.4. On the right to erasure and the obligation to notify (point of complaint A)
As established, the BG does not currently store the information that can be considered personal data of the bP – i.e., the IP address and the cookie values of the bP's device. Furthermore, the recipients of the data transfer were informed of the deletion in accordance with Article 19 GDPR (see Statement of Facts C.5). As established, the BG does not currently store the information that can be considered personal data of the bP – i.e., the IP address and cookie values of the bP's device. Furthermore, the recipients of the data transfer were informed of the deletion in accordance with Article 19 GDPR (see Statement of Facts C.5).
According to the jurisprudence of the Federal Administrative Court (BVwG), there is no subjective right to a declaratory judgment that the rights of data subjects—in this case, the right to erasure—were respected too late (see the BVwG's ruling of January 31, 2020, file number W258 2226305-1 with further references).
According to the jurisprudence of the Federal Administrative Court (BVwG), there is no subjective right to a declaratory judgment that the rights of data subjects—in this case, the right to erasure—were respected too late (see the BVwG's ruling of January 31, 2020, file number W258 2226305-1 with further references). At least at the time of the decision, there can therefore be no assumption of a violation of Article 17 (in conjunction with Article 19) GDPR.
D.5. Regarding the application for an order against the BG to cease the unlawful processing (point of complaint B)
Furthermore, the applicant has requested that the BG be ordered to cease the unlawful processing.
According to Article 77(1) of the GDPR, every data subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement, if the data subject considers that the processing of personal data relating to them infringes this Regulation, without prejudice to any other administrative or judicial remedy.
[…] without prejudice to any other administrative or judicial remedy, every data subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement, if the data subject considers that the processing of personal data relating to them infringes this Regulation. The wording of Article 77(1) GDPR makes it clear that any requests made in the context of a complaint procedure—insofar as they are admissible at all—must relate to the complainant's personal data.
As already stated, the BG does not currently store the complainant's data, meaning that no remedy can be sought that relates to the complainant's personal data.
However, as already explained, the BG does not currently store the complainant's data, meaning that no remedy can be sought that relates to the complainant's personal data.
``` In view of the exhaustive nature of the remedies under Article 58(2) GDPR (see again the decision of the Austrian Administrative Court of 1 September 2022, Ra 2022/04/0066) and the wording of Article 77(1) GDPR and Section 24(1) of the Austrian Data Protection Act (DSG) (infringes and not: "has infringed" or "will be infringed"; English version of the GDPR: "infringes", French version of the GDPR: "constitue"), no order can be issued in the context of a complaint procedure that relates to data processing pro futuro (i.e., in the event that the data subject accesses the website again in the future). In view of the exhaustive nature of the remedies under Article 58(2) GDPR (see again the decision of the Austrian Administrative Court of 1 September 2022, Ra 2022/04/0066) and the wording of Article Pursuant to Article 77, paragraph one, GDPR and Section 24, paragraph one, DSG (infringes and not: “has infreded” or “will be infringed”; English language version of the GDPR: “infringes”, French language version of the GDPR: “constitue”), no order can be issued in the context of a complaint procedure that relates to data processing pro futuro (i.e. in the event that the bP accesses the website again in the future).
Therefore, it is no longer necessary to address the abstractly formulated violations by bP in connection with the cookie banner. Such violations of the GDPR must be addressed ex officio (if required).
``` Finally, insofar as the data subject argues that a competent supervisory authority can also issue an order that "goes beyond the data subject's personal data," it must be pointed out that such a "popular complaint" (i.e., a complaint that does not only concern the data subject personally) is inadmissible (see the decision of the Data Protection Authority of November 26, 2018, file number: DSB-D216.697/0011-DSB/2018).
``` From another perspective, there would be no room for the possibility provided for in Article 80(2) GDPR for Member States to establish a right of complaint for data protection organizations, independent of a mandate from a specific data subject. The Austrian legislature has not currently made use of this possibility.
Regarding point 2 of the ruling
D.6. Regarding the applicant's request of December 30, 2022, for a declaration of an alleged violation of the right to confidentiality (point of complaint C)
Pursuant to Section 24(4) of the Data Protection Act (DSG), the right to have a complaint addressed expires if the complainant does not submit it within one year of becoming aware of the event giving rise to the complaint, but no later than three years after the event allegedly occurred. Late complaints must be rejected pursuant to Section 24, Paragraph 4, last sentence, of the Data Protection Act (DSG). According to Section 24, Paragraph 4, of the DSG, the right to have a complaint processed expires if the complainant does not submit it within one year of becoming aware of the event giving rise to the complaint, but no later than three years after the event allegedly occurred. Late complaints must be rejected pursuant to Section 24, Paragraph 4, last sentence, of the DSG.
Section 24, Paragraph 4, of the DSG refers to an event giving rise to the complaint as the trigger for the commencement of the time limit. In the present case, the visit to the website https://www.n***.online on January 21, 2021 (and the associated data processing) qualifies as such an event. Section 24, Paragraph 4, of the DSG refers to an event giving rise to the complaint as the trigger for the commencement of the time limit. In the present case, the relevant event is the visit to the website https://www.n***.online on January 21, 2021 (and the associated data processing).
The submission of the supplementary request on December 30, 2022, i.e., more than one year after becoming aware of the event giving rise to the complaint (website visit), is therefore untimely, and the data subject's right to have this request addressed had already expired by the time of the supplement. Consequently, the complaint had to be dismissed on this point pursuant to Section 24, Paragraph 4 of the Data Protection Act (DSG).
Regarding point 3
D.7. General principles concerning the powers of redress
The data protection authority has remedial powers pursuant to Article 58(2)(d) GDPR, which allow it, among other things, to instruct a controller to modify or carry out processing operations in a specific manner and within a specific timeframe.
The data protection authority has remedial powers pursuant to Article 58(2)(d) GDPR, which allow it, among other things, to instruct a controller to modify or carry out processing operations in a specific manner and within a specific timeframe. Neither the GDPR nor the German Federal Data Protection Act (BDSG) nor the German General Administrative Procedure Act (AVG) stipulates that official powers may only be exercised within the framework of a data protection audit pursuant to Article 58(1)(b) GDPR.
Neither the GDPR nor the BDSG nor the AVG stipulates that official powers may only be exercised within the framework of a data protection audit pursuant to Article 58(1)(b) GDPR. Therefore, the Federal Administrative Court (BVwG) has already ruled that the data protection authority can also exercise its powers under Article 58(2) GDPR ex officio in complaint proceedings (see the ruling of 16 November 2022, file number: W274 2237056-1/8E; most recently of 31 July 2024, file number: W108 2284491-1/15E). (last decision of July 31, 2024, file number: W108 2284491-1/15E).
The Federal Administrative Court's considerations are also consistent with the case law of the European Court of Justice, according to which a supervisory authority is obliged to exercise its remedial powers in the event of identified deficiencies (see the judgment of the European Court of Justice of July 16, 2020, C-311/18, paragraph 111).
Although the present appeal was ultimately dismissed; Since the request for consent (the cookie banner) and the use of cookies—for the reasons stated below—do not comply with data protection regulations, an official order for performance was required.
In its decision of September 12, 2025, the Data Protection Authority granted BG the opportunity to comment on the cookie banner. BG presented its position in its statement of November 3, 2025.
D.8. Regarding the performance agreement
Instructions pursuant to Article 58(2)(d) GDPR may also include adjustments regarding consent requests (see Zavadil in Knyrim, DatKomm Art. 58 GDPR [as of July 1, 2024, rdb.at] Art. 58 para. 34/1 with further references).
Instructions pursuant to Article 58(2)(d) GDPR may also include adjustments regarding consent requests. To assess how the cookie banner and the interaction options are to be understood, the figure of an average, informed, attentive, and circumspect consumer must be used (see the judgment of the ECJ of 16 July 1998, C-210/96, para. 37; the decision of the Federal Administrative Court of 13 December 2022, file number W214 2234934-1; Article 29 Working Party, Guidelines on consent pursuant to Regulation 2016/67, WP259 rev.01, 17/DE, p. 16; Greve in Sydow, Commentary on Article 12, para. 11; Illibauer in Knyrim, DatKomm, Article 12, para. 39; with regard to the Data Protection Act 2000, see also Jahnel, Handbook, para. 7/22 with further references). To understand the interaction possibilities, the figure of an average, informed, attentive, and circumspect consumer must be used (see the judgment of the ECJ of 16 July 1998, C-210/96, para. 37; the decision of the Federal Administrative Court of 13 December 2022, file number W214 2234934-1; the Article 29 Working Party, Guidelines on consent pursuant to Regulation 2016/67, WP259 rev.01, 17/DE, Session 16; Greve in Sydow, Commentary on Article 12, para. 11; Illibauer in Knyrim, DatKomm Article 12, para. 39; with regard to the Data Protection Act 2000, see also Jahnel, Handbook, para. 7/22 with further references).
Furthermore, the standard for valid consent requires that no unfair practices are used. The data subject must therefore not be pressured, either directly or subtly, into giving consent. It is thus inadmissible to design the "Reject" option in such a way (e.g., color differences, different contrast ratios, or positioning) that it is less prominent compared to the "Accept" option (see the "FAQ on Cookies and Data Protection," available at www.dsb.gv.at, in particular questions 7 and 8; see also the EDPB Report of the work undertaken by the Cookie-Banner Taskforce, p. 6, available at https://edpb.europa.eu/our-work-tools/our-documents/report/report-work-undertaken-cookie-banner-taskforce_en). Furthermore, the standard for valid consent requires that no unfair practices are used. The data subject must therefore not be pressured, either directly or subtly, into giving consent. It is therefore impermissible to design the "Reject" option in such a way (e.g., through color differences, varying contrast ratios, or positioning) that it is less prominent compared to the "Accept" option. See the "FAQ on Cookies and Data Protection," available at www.dsb.gv.at, in particular questions 7 and 8; see also the EDPB Report of the work undertaken by the Cookie-Banner Taskforce, Session 6, available at https://edpb.europa.eu/our-work-tools/our-documents/report/report-work-undertaken-cookie-banner-taskforce_en.
Furthermore, Recital 75 of Regulation (EU) 2024/900 must be taken into account, according to which the decision of individuals when giving consent should not be influenced in such a way as to distort or impair their decision-making. Although this regulation refers to political targeting, the considerations can be generally applied to data protection consents, especially since the aforementioned recital explicitly refers to the GDPR.
Based on this standard, the following must be noted for the website https://www.n***.online:
In this case, a cookie banner is used to request consent for the use of cookies (and the associated processing of personal data). Specifically, the options displayed are a white button labeled "Accept" and two light purple buttons labeled "Decline" and "Custom." The background of the cookie banner is dark purple (see statement of facts C.6). The background of the cookie banner is dark purple (see section C.6 of the facts).
From the data protection authority's perspective, the "Agree" button is more prominent because its white color makes it stand out much more clearly against the dark purple background of the cookie banner than the other buttons with their light purple backgrounds. Therefore, when asked for consent, the attention of data subjects is primarily drawn to the "Agree" button due to the choice of color and the contrast.
Such a design of a consent declaration complies neither with the principle of data processing in good faith ("fairly processed") pursuant to Article 5(1)(a) GDPR nor with the principle of privacy by design pursuant to Article 25(1) GDPR. This supports the interpretation of Article 4(11) in conjunction with Article 7 GDPR advocated by the data protection authority. Such a design of a consent declaration complies neither with the principle of fair processing pursuant to Article 5(1)(a) GDPR nor with the principle of privacy by design pursuant to Article 25(1) GDPR. This supports the interpretation of Article 4(11) in conjunction with Article 7 GDPR advocated by the data protection authority.
This conclusion is further supported by the fact that the BG, as the controller, bears the burden of proof for the validity of any consent (see the judgment of the CJEU of 4 July 2023, C-252/21, paragraph 95). This burden of proof cannot be met with such a design of a consent declaration. This burden of proof cannot be met with such a design of the consent form.
D.9. Outcome and Deadline
The BG will therefore have to redesign the request for consent.
It must either use uniform colors for all buttons or ensure, through appropriate color schemes, that the selection options are objectively and equally recognizable.
A deadline of two weeks is considered appropriate by the data protection authority to carry out the technical implementation (color adjustment).
The decision was therefore rendered accordingly.




