DSB (Austria) - 2025-0.950.759
| DSB - 2025-0.950.759 | |
|---|---|
| Authority: | DSB (Austria) |
| Jurisdiction: | Austria |
| Relevant Law: | Article 5(1)(c) GDPR Article 5(1)(b) GDPR Article 6(1)(f) GDPR Article 6(1)(b) GDPR Article 16 GDPR Article 17 GDPR Article 25 GDPR Article 8 ECHR |
| Type: | Complaint |
| Outcome: | Partly Upheld |
| Started: | 16.05.2025 |
| Decided: | 24.11.2025 |
| Published: | 01.06.2026 |
| Fine: | n/a |
| Parties: | n/a |
| National Case Number/Name: | 2025-0.950.759 |
| European Case Law Identifier: | ECLI:AT:DSB:2025:2025.0.950.759 |
| Appeal: | n/a |
| Original Language(s): | German |
| Original Source: | RIS (in DE) |
| Initial Contributor: | ds |
The DPA held that an online store unlawfully required customers to select their gender identity. According to the DPA, this was not necessary for the proper performance of a contract with its customers or for its legitimate interest to personally address them.
English Summary
Facts
On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders either as guests or through an optional customer account.
During the registration process, the data subject's personal data was collected, including a gender-specific title. The only options provided for the title were "Mr." and "Ms.", with no option to select no title. The data subject selected “Ms.” during the registration process. The data subject then informed the controller about this situation and requested that it should refrain from using gender-specific forms of address regarding them.
The controller initially assured the data subject that it would inform the relevant department. Later, the controller communicated that implementing the requested adjustment was currently not technically feasible, but that a solution was being worked on.
On 14 May 2025, the data subject received a newsletter from the controller in which a gender specific salutation (specifically "Ms.") was used.
On 16 May 2025, the data subject lodged a complaint with the Austrian DPA against the controller. The data subject argued that the controller had infringed their rights regarding the principles of data processing under Article 5 GDPR, the rights to rectification under Article 16 GDPR, to erasure under Article 17 GDPR and to data protection by design and by default under Article 25 GDPR.
Τhe controller stated in its privacy notice that it was necessary to process customers’ personal data for registration purposes under Article 6(1)(b) GDPR. Moreover, the controller also claimed reliance on Article 6(1)(f) GDPR.
During the proceedings before the DPA, the controller restructured its IT system. On 8 September 2025, the controller announced that it had implemented gender-neutral forms of address in its online shop and requested for the complaint to be dismissed.
Holding
The DPA first noted that, during the proceedings, the controller had implemented the requested changes by removing gender-specific forms of address from the registration process. Since the data subject did not contest this, the DPA considered the alleged infringements of the rights to rectification and erasure to have been remedied and ended that part of the proceedings. However, it continued to examine whether the past processing had violated Article 5 GDPR and Article 25 GDPR.
Regarding the processing of salutation data for the personalisation of business communications, the DPA relied on the CJEU judgment in Case C-394/23 (Mousse). In this case, the CJEU had ruled that the processing of salutation data for the personalization of business communications is neither necessary for the performance of a contract pursuant to Article 6(1)(b) GDPR nor consistent with the principle of data minimization pursuant to Article 5(1)(c) GDPR, because such processing is not required for the stated purposes.
The DPA concluded that using gender-specific salutations for contract fulfilment, order processing, internal correspondence, contests, newsletters, user account registration, and delivery of goods was not strictly necessary, even under a broad interpretation. It backed this conclusion by the fact that the controller had already stopped using gender-specific salutations in direct communications, newsletters, contests, contact forms, delivery notifications, invoices, and order confirmations. The DPA therefore held that neither Article 6(1)(b) GDPR nor Article 6(1)(f) GDPR could serve as a legal basis for processing gender-specific salutations during the registration process, since the processing was not necessary. In relation to Article 6(1)(f) GDPR , the DPA accepted that the controller could in principle have a legitimate economic interest in personally addressing customers, but found that the necessity requirement was not met.
The DPA found that the processing operation violated the principles of purpose limitation and data minimisation under Article 5(1)(b) GDPR and Article 5(1)(c) GDPR due to the lack of necessity of the gender-specific salutation and the availability of less intrusive alternatives.
The DPA also referred to the Austrian Constitutional Court’s (Verfassungsgerichtshof) decision GZ G 77/2018, according to which a restriction to only two gender categories is incompatible with Article 8 ECHR.
Regarding data protection by design and by default, the DPA held that Article 25 GDPR imposes obligations on the controller, but does not grant the data subject a subjective right to demand a specific privacy-friendly technical setting. It pointed out that while privacy-unfriendly default settings might lead to a violation of confidentiality or of the data protection principles, the data subject could not require the controller to implement specific privacy-friendly settings.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the German original. Please refer to the German original for more details.
Text
File No.: 2025-0.950.759 dated November 24, 2025 (Case No.: DSB-D124.1244/25)
[Note from Editor: Names and companies, legal forms and product names, addresses (including URLs, IP and email addresses), file numbers (and the like), statistical data, etc., as well as their initials and abbreviations may be abbreviated and/or altered for pseudonymization purposes.] Obvious spelling, grammar, and punctuation errors have been corrected.
DECISION
RULING
The Data Protection Authority decides on the data protection complaint filed by Viktor A*** (complainant) on May 16, 2025, against N*** Aktiengesellschaft (respondent), represented by L*** Rechtsanwälte GmbH, concerning a violation of the principles of data processing of personal data pursuant to Article 5 GDPR and a violation of the right to data protection by design and by default pursuant to Article 25 GDPR, as follows: The Data Protection Authority decides on the data protection complaint filed by Viktor A*** (complainant) on May 16, 2025, against N*** Aktiengesellschaft (respondent), represented by L*** Rechtsanwälte GmbH, concerning a violation of the principles of data processing of personal data pursuant to Article 5 GDPR and a violation of the right to data protection by design and by default pursuant to Article 25 GDPR, as follows:
1. The complaint is partially granted and it The complaint is partially upheld, and it is determined that the BG violated the principles of data processing of personal data pursuant to Article 5 of the GDPR by linking a gender-specific form of address to the online shop's account during the registration process.
2. The complaint is otherwise dismissed.
Legal basis: Articles 4, 5, 6, 25, 51(1), 57(1)(f), and 77(1) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR), OJ No. L 119 of 4.5.2016, p. 1. Sections 18(1) and 24(1) and (5) of the Data Protection Act (DSG), Federal Law Gazette I No. 165/1999 as amended. Legal basis: Articles 4, 5, 6, 25, 51(1), 57(1), letter f, and 77(1) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR), Official Journal No. L 119 of 4 May 2016, Session 1; Sections 18(1) and 24(1) and (5) of the Data Protection Act (DSG), Federal Law Gazette Part One, No. 165 of 1999, as amended.
] JUSTIFICATION
A. Submissions of the Parties and Procedural History
Note from the Data Protection Authority regarding the procedural history: The procedural history is not a legally mandatory element, but rather optional. Therefore, it is generally not necessary to separately state the parties' submissions in the statement of reasons for the decision (see Hengstschläger/Leeb, AVG § 60 para. 22 (as of March 1, 2023, rdb.at)).
```
```
````
````````````````)` The proceedings were initiated following a data protection complaint filed on May 16, 2025, by Viktor A*** (complainant – hereinafter: bP) against N*** Aktiengesellschaft (respondent – hereinafter: BG), which was represented by legal counsel. During the investigation, both parties were given the opportunity to comment on each other's submissions.
B. Subject Matter of the Complaint
The subject matter of the complaint is whether BG violated the principles of data processing pursuant to Article 5 GDPR when processing the personal data of the data subject and whether it also infringed bP's right to data protection by design and by default pursuant to Article 25 GDPR by processing the date of the gender-specific title along with bP's data during the registration process. The subject of the complaint is whether BG, in processing the personal data of the data subject, violated the principles of processing pursuant to Article 5 of the GDPR and whether it also infringed the data subject's right to data protection by design and by default pursuant to Article 25 of the GDPR by processing the date of the gender-specific title along with the data of the data subject during the registration process.
C. Findings of Fact
1. BG is a legal entity in the form of a public limited company with the company registration number < FN *4 *1 *99z > and the VAT identification number < ATU 1 *77 *8 * >, and its business address < M***platz *6/*0, **** B***stadt >. BG's business purpose is the retail sale of goods of all kinds. BG is a legal entity in the form of a public limited company with the company registration number < FN *4 *1 *99z > and the VAT identification number < ATU 1 *77 *8 * >, and the business address < M***platz *6/*0, **** B***stadt >. BG's business purpose is the retail sale of goods of all kinds.
Screenshot of the company registration extract for BG, obtained by the authorities on November 19, 2025 (formatting not shown exactly):
[Editor's note: The original company registration extract shown here as a facsimile (graphic file) cannot be pseudonymized with reasonable effort and has therefore been removed.] It contains the data established above.]
Evaluation of evidence: These findings are based on the initial submission of May 16, 2025, by bP, the statement of June 24, 2025, by BG, and the ex officio extract from the commercial register concerning BG dated November 19, 2025. The extract from the commercial register is attached to the case file.
2. BG operates an online shop called <N*** Online Shop>, through which goods can be ordered both as a guest and via an optional customer account.
The data provided by bP during the registration process is used for the following purposes, among others: providing the online account, making the customer profile accessible, enabling use of the online shop, delivery, payment processing, handling inquiries related to the account and/or placed orders, informing about changes to the Terms and Conditions or Privacy Policy, internal statistical market research, advertising and market research, sending the newsletter, sending product recommendations, and sending other information.
In addition to first and last name, the billing and shipping addresses, as well as payment information, are required to process online orders.
Screenshot of the privacy policy dated November 20, 2025 (formatting not reproduced exactly):
[Editor's note: The privacy policy, originally displayed here as a screenshot in a graphic format, has been converted to text and is reproduced here in a pseudonymized form, graphically approximating the original.]
"5. Data processing for the performance of a contract (e.g., N*** Online Shop)
pursuant to Article 6(1)(b) GDPR
5.1. Collection of and handling of personal data within the N***
customer account
We offer our customers the option of using certain services via a personal customer account. Before using the account for the first time, you must register. After submitting your registration, you will receive a so-called double opt-in email in which you must confirm your email address. The double opt-in is a two-step process designed to prevent misuse on behalf of third parties, as only the account holder can confirm the account." Verification of your email address is required. Only then will your registration be complete and you can log in to your new N*** account. We need the following information from you:
First name, last name,
Email address
For processing orders in the online shop, we also need the following information from you:
Billing address (company name and address supplement, if applicable, street, house number, postal code, city)
Delivery address (first name, last name, company name and address supplement, if applicable, street, house number, postal code, city, mobile phone number)
Payment details (credit card details, bank account details)
Your customer account will also automatically be assigned a customer number. In addition, you can voluntarily add the following information to your customer account:
Mobile phone number
Date of birth
Postal code, Location
“My Products” (displays favorite products and products already purchased)
N*** uses the data that the user submits to N*** during registration and when placing orders in the N*** Online Shop for the following purposes:
Provision of the online account
Making the customer profile accessible on our website
Use of the N*** Online Shop at shop.n*** at
Delivery of shipments
Payment processing
Questions related to the customer account and/or orders placed by the user
Information about changes to the Terms and Conditions or Privacy Policy
Internal statistical market research
Advertising and market research for offers personally tailored to the user, provided the user has consented to this
Sending the newsletter, if expressly requested
Sending of Product recommendations for similar offers from our own company, unless expressly requested
Sending of information, if expressly requested
2.1. bP registered in the BG online shop on September 18, 2023, and has a customer account with membership number < *5*4*3*90 >. During the registration process, personal data was collected from bP, including the date of the gender-specific salutation. Only two salutation options were available: < Mr > and < Ms >. The option to select no salutation did not exist. bP selected < Ms > during the registration process.
The user profile of bP is displayed graphically as follows (formatting not shown exactly):
[Editor's note: The screenshot reproduced here as a facsimile (graphic file) cannot be pseudonymized with reasonable effort and has therefore been removed. It contains the pseudonym "Golden D***" chosen by bP and the chosen salutation "Ms." with the only alternative option "Mr."]
2.2. On September 18, 2023, bP informed BG of this situation and, in a supplementary email dated October 9, 2023, requested that they refrain from using gender-specific forms of address when referring to them.
[Note by editor: The screenshot shown here cannot be pseudonymized with reasonable effort and has therefore been removed.] Screenshot of the email from September 18, 2023, to BG (formatting not shown exactly):
[Editor's note: The email exchange, originally displayed here as facsimiles in PNG format, has been converted to text and is reproduced here in pseudonymized and slightly shortened form (omitting non-essential elements such as graphics, company logos, etc.).]
"From: "Golden D***"
Sent: 09/18/2023 5:00 PM
To: "N*** Customer Service"
cc:
Subject: [*5*6*7*88*3*2*1] Problem with online order
CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe. If you are unsure or have already opened a link or attachment, please contact your local IT helpdesk. CAUTION: This email Originating from outside the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe. If you are unsure or have already opened a link or attachment, please contact your local IT helpdesk.
Good day.
I was just about to place an order online, but unfortunately, I noticed that the required registration process only allows me to select "Mr." or "Ms."
How can I order something without a salutation?
Best regards,
Golden D***"
Screenshot of the email from October 9, 2023, from bP to BG (formatting not shown exactly):
"Request for correction dated October 9, 2023
Golden D*** Mon, Oct 9, 2023, 3:00 PM
to N***
Good day, Roger C***,
Thank you for your message. I have now registered with my email address, using an incorrect salutation (membership number *5*4*3*90). I hereby request that you change the salutation stored for me to a gender-neutral one. Furthermore, I request that you refrain from using gender-specific salutations for me in the future, both generally (e.g., in the online portal) and in connection with the provision of services (e.g., order 7*3*3*222*1).
Sincerely,
Golden D***
2.3. The BG subsequently assured the bP that it would inform the responsible department and further stated that implementing such an adjustment is currently not technically possible, but that a solution is being worked on.
Screenshot of the email from BG to bP dated October 9, 2023 (formatting not shown exactly):
"OSD-*4*5*9 N*** Online Shop Feedback External
N*** Online Shop Mon, Oct 9, 2023, 3:00 PM**
to hello@goldend***.org
Dear Customer,
Dear Customer,
Thank you for your patience and please accept our apologies for the delayed response. We always strive to answer our customer inquiries as quickly as possible; however, due to a high volume of requests, there are currently somewhat longer waiting times.
We have had your request reviewed by our specialist department.
Unfortunately, it is not currently possible to offer additional gender options in our online shop.
Of course, we have already forwarded your suggestion for improvement to the relevant departments so that it can be incorporated into any future optimizations. Unfortunately, a short-term implementation is not possible." Not possible. We kindly ask for your understanding!
Your satisfaction as a customer is of utmost importance to us – please continue to share your suggestions, wishes, and criticisms with us. This helps us to continuously optimize our service.
We wish you a pleasant day.
Sincerely,
Roger C***
Your N*** Customer Service
N*** AG
M***platz *6/*0 A-**** B***stadt
Commercial Register: LG I***burg, FN *4*1*99z
Screenshot of the email from June 21, 2024, from BG to bP (formatting not shown exactly):
"OSD-*4*5*9 Customer Feedback External Inbox x
N*** Customer Service Fri, June 21, 2024, 11:**
to hello@goldend***.org
Hello Golden D***,
Thank you for your message.
Our IT department is currently working on a solution. However, due to the complexity of the issue, this is a rather lengthy process and involves intervention in our systems.
Our colleagues are working to ensure that we can address all our customers in the salutation as soon as possible.
We therefore ask for your patience and remain
Sincerely,
Josefa W***
Your N*** Customer Service
N*** AG
M***platz *6/*0 A-**** B***stadt
Commercial Register: LG I***burg, FN *4*1*99z
[Contact details shortened here]
2.4. The bP received a newsletter from the BG on May 14, 2025, which used a gender-specific salutation (specifically, < Ms. >).
Newsletter from May 14, 2025, which was sent by The BG sent the email to bP (formatting not shown exactly as shown):
[Editor's note: The newsletter header shown here as a screenshot (graphic file) cannot be pseudonymized with reasonable effort and has therefore been removed. It contains the salutation "Dear Ms. Golden D***!"]
Evaluation of evidence: These findings are based on bP's initial submission of May 16, 2025, BG's statement of June 24, 2025, and the ex officio commercial register extract concerning BG dated November 17, 2025. The commercial register extract is attached to the case file. The finding that BG requests a gender-specific salutation during the registration process for its online shop is based, firstly, on the screenshots submitted by bP as part of its initial submission of May 16. 2025, and secondly, from the statement issued by BG on June 24, 2025, in which BG itself acknowledges that it already uses gender-neutral forms of address—where technically and economically feasible—but not yet in the registration process for its online shop. The findings regarding the purposes of processing and the data required for placing an order are based on BG's statement of June 24, 2025, and an official search conducted on November 20, 2025, on BG's website at the URL https://shop.n***.at/***/datenschutz***.
3. During the ongoing proceedings before the Data Protection Authority, BG restructured its IT system. In a statement dated September 8, 2025, it announced that the system conversion to gender-neutral registration in the online shop is now complete.
Screenshot of the statement dated September 8, 2025 (formatting not included). (1:1 representation.):
[Editor's note: The original document, shown here as a facsimile in PNG format, has been converted to text and is reproduced here in pseudonymized form.]
Ref:
D124.1244/25
2025-0.504.889
Vienna, September 8, 2025
Via email: dsb@dsb.gv.at
Subject: Supplementary statement regarding the data protection complaint from Viktor A***
Dear Ms. H***,
We are writing in reference to your request for a statement dated June 26, 2025, which was served on our client, N*** Aktiengesellschaft ("N***"), on July 1, 2025. We are pleased to submit the following statement on behalf of our client within the prescribed time limit:
The time-consuming and costly system conversion to gender-neutral registration in Our client's online shop is now closed.
Evidence: Screenshots from the N*** website (Exhibit ./1).
Gender-neutral language has now been implemented in this final section and is thus fully implemented.
We therefore request
that the complainant's complaint be dismissed.
Screenshot of the current user account without gender-specific language (formatting not reproduced exactly):
[Editor's note: The screenshot reproduced here as a facsimile (graphic file) cannot be pseudonymized with reasonable effort and has therefore been removed. It no longer contains a field for entering gender-specific data.]
Evidence assessment: These findings are based on the statement of the Federal Social Court (BSG) dated September 8, 2025, which was not contested by the client during the hearing on September 15, 2025.
[Note by editor: The screenshot shown here cannot be pseudonymized with reasonable effort and has therefore been removed.] D. From a legal perspective, this means:
D.1. General
Pursuant to Article 77(1) GDPR and Section 24(1) of the Austrian Data Protection Act (DSG), every data subject has the right to lodge a complaint with the data protection authority if they believe that the processing of their personal data infringes the GDPR or Section 1 of Chapter 1 of the DSG.
Pursuant to Article 4(1) GDPR, the term “personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. According to Article 4(1) of the GDPR, the term “personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction (see Article 4(2) GDPR).
Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction (see Article 4(2) GDPR). The controller, as defined in Article 4, point 7 of the GDPR, is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. The decisive criterion is therefore the power to decide on the purpose and means of the processing. The role of the controller thus arises primarily from the fact that a specific entity has decided to process personal data for its own purposes. It is undisputed that the BG is the controller.
The controller, as defined in Article 4, point 7 of the GDPR, is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. The decisive criterion is therefore the power to decide on the purpose and means of the processing. The role of the controller thus arises primarily from the fact that a specific entity has decided to process personal data for its own purposes. It is undisputed that the BG is the controller. In the present case, the scope of application of the General Data Protection Regulation (GDPR) is opened because the BG, as the data controller pursuant to Art. 4(7) GDPR, indisputably linked the personal data of the bP pursuant to Art. 4(1) GDPR during the registration process at its online shop with a gender-specific salutation (specifically with the salutation options < Mr > or < Ms >) specified in the bP customer data record (cf. in a similar case ECJ of 11 July 2024 in C-394/23, para. 22). The linking process constitutes a processing operation. In the present case, the scope of the General Data Protection Regulation (GDPR) is applicable because the BG, as the data controller pursuant to Article 4, point 7, GDPR, indisputably linked the personal data of the bP pursuant to Article 4, point 1, GDPR during the registration process at its online shop with a gender-specific salutation (specifically with the salutation options < Mr > or < Ms >) specified in the bP's customer data record (compare in this regard, in a similar case, ECJ judgment of 11 July 2024, case C-394/23, paragraph 22). The linking process constitutes a processing operation.
According to the established case law of the CJEU, in order to be lawful within the meaning of the GDPR, data processing must at all times comply with all the principles set out in Article 5(1) GDPR and, moreover, be able to be based on at least one legal basis under Article 6(1) GDPR (see the judgment of 11 December 2019, C-708/17, and the judgment of 4 May 2023, C-60/22, paragraphs 56 and 57). The burden of proof lies with the controller pursuant to Article 5(2) GDPR (ibid., paragraphs 53 and 54). According to the established case law of the CJEU, in order to be lawful within the meaning of the GDPR, data processing must at all times comply with all the principles set out in Article 5(1) GDPR and, moreover, be able to be based on at least one of the grounds listed in Article 6(1) GDPR (see the judgment of 11 December 2019, C-708/17, and the judgment of 4 May 2023, C-60/22, paragraphs 56 and 57). The burden of proof lies with the controller pursuant to Article 5(2) GDPR (ibid., paragraphs 53 and 54).
D.2. Subject of the Examination
It should be noted at the outset that, according to the established case law of the Austrian Administrative Court (VwGH), declarations by parties (including submissions) in proceedings are to be interpreted exclusively according to their objective meaning (see VwGH 06.11.2006, 2006/09/0094; 05.09.2008, 2005/12/0068; 03.10.2013, 2012/06/0185). October 3, 2013 (2012/06/0185).
The decisive factor is how the declaration (cf. VwGH 28 July 2000, 94/09/0308; 28 January 2003, 2001/14/0229; 30 June 2004, 2004/04/0014) must be objectively understood, taking into account the specific legal provision, the purpose of the proceedings, and the case file (VwGH 24 January 1994, 93/10/0192; 6 November 2001, 97/18/0160; 19 January 2011, 2009/08/0058; cf. also VfSlg 17.082/2003) (cf. Hengstschläger/Leeb, AVG § 13 para. 38) (As of January 1, 2014, rdb.at). The decisive factor is how the declaration compares VwGH July 28, 2000, 94/09/0308; January 28, 2003, 2001/14/0229; June 30, 2004, 2004/04/0014) must be understood objectively, taking into account the specific legal provision, the purpose of the proceedings, and the case file (Austrian Administrative Court [VwGH] January 24, 1994, 93/10/0192; November 6, 2001, 97/18/0160; January 19, 2011, 2009/08/0058; see also Austrian Constitutional Court [VfSlg] 17.082/2003; see also Hengstschläger/Leeb, AVG Section 13, para. 38 (as of January 1, 2014, rdb.at)).
The subject of these proceedings is the submission of bP dated May 16, 2025, which alleges that its rights to the principles governing the processing of its personal data pursuant to Article 5 GDPR, its right to rectification pursuant to Article 16 GDPR, its right to erasure pursuant to Article 17 GDPR, and its right to data protection by design and by default pursuant to Article 25 GDPR have been violated.
The subject of these proceedings is the submission of bP dated May 16, 2025, which alleges that its rights to the processing of its personal data pursuant to Article 5 GDPR, its right to rectification pursuant to Article 16 GDPR, its right to erasure pursuant to Article 17 GDPR, and its right to data protection by design and by default pursuant to Article 25 GDPR have been violated. The Data Protection Authority notes that, with the provision of Section 24 Paragraph 6 of the Data Protection Act (DSG), the Austrian legislature has created the possibility for data controllers to subsequently remedy alleged infringements of data protection rights (i.e., the right to rectification or erasure) until the conclusion of the proceedings before the Data Protection Authority by complying with the requests of the data subject.
The rights to rectification or erasure each establish an entitlement to a specific performance. If one of these services is the subject of the request by the data subject, the request can be granted and the service in question can be performed or arranged. Accordingly, Section 24 Paragraph 6 of the Data Protection Act (DSG) provides that the data controller can subsequently remedy the alleged infringement of rights until the conclusion of the proceedings before the data protection authority by complying with the data subject's requests. However, in the context of an infringement of the right to confidentiality or the principles of data processing, the question of remedying the infringement must be assessed differently. A breach resulting from unlawful processing cannot be retrospectively remedied by an action (here: rectification or erasure of the data in question) and thus differs from the rights guaranteed under data protection law, which can be satisfied by a specific action (see the decision of the Austrian Administrative Court of 19 October 2022, file number Ro 2022/04/0001, and the ruling of the Austrian Federal Administrative Court of 25 October 2024, file number W101 2256689-1). The substantive considerations regarding past infringements can be transferred from the right to confidentiality to a breach in Article 5 GDPR. The rights to rectification or erasure each create an entitlement to a specific action. If one of these actions is the subject of the request by the data controller, the request can be granted and the action in question can be carried out or initiated. Accordingly, Section 24, paragraph 6, of the Austrian Data Protection Act (DSG) stipulates that the data controller must... An alleged infringement of rights can be remedied retrospectively until the conclusion of the proceedings before the data protection authority by granting the applicant's requests. However, in the context of an infringement of the right to confidentiality or the principles of data processing, the question of remedying the infringement must be assessed differently. An infringement caused by unlawful processing cannot be retrospectively remedied by an action (here: rectification or erasure of the data in question) and thus differs from the rights guaranteed under data protection law, which can be satisfied by a specific action (see the decision of the Austrian Administrative Court of 19 October 2022, file number Ro 2022/04/0001, and the ruling of the Austrian Federal Administrative Court of 25 October 2024, file number W101 2256689-1). The substantive considerations regarding past infringements can be transferred from the right to confidentiality to infringements under Article 5 of the GDPR.
In the present proceedings, the BG (Berufsgenossenschaft, the German statutory accident insurance institution) complied with the rights of the affected party (bP) and, during its hearing on September 15, 2025, did not object to the BG's compliance. The proceedings were therefore terminated informally – without the issuance of a formal decision – on November 7, 2025, under file number D124.1244/25, 2025-0.903.123.
The BG granted the affected party's rights during its hearing on September 15, 2025, and the bP did not object during the hearing. Since the complaint proceedings regarding the asserted data subject rights have now been discontinued – as explained above – the scope of this review is limited to the remaining grounds for complaint. These grounds are, firstly, the alleged violation of the principles governing the processing of personal data pursuant to Article 5 GDPR, and secondly, the right to data protection by design and by default pursuant to Article 25 GDPR, arising from the data processing operation carried out during the registration process, namely linking the user account with a gender-specific form of address.
Since the complaint proceedings regarding the asserted data subject rights have now been discontinued – as explained above – the scope of this review is limited to the remaining grounds for complaint. These grounds are, firstly, the alleged violation of the principles governing the processing of personal data pursuant to Article 5 GDPR, and secondly, the right to data protection by design and by default pursuant to Article 25 GDPR, arising from the data processing operation carried out during the registration process, namely linking the user account with a gender-specific form of address. D.3. On the Matter
D.3.1. Ruling Point I (Principles of Data Processing pursuant to Art. 5 GDPR) D.3.1. Ruling Point I (Principles of Data Processing pursuant to Article 5 GDPR)
The general principles for the processing of personal data laid down in Art. 5 GDPR are fundamental conditions for all data processing. These principles, which are directly applicable as legal rules, are mandatory legal requirements for the processing of personal data – as follows from the comprehensive term "processing" defined in Article 4(2) GDPR – and must be followed in every handling and at every stage related to personal data, throughout the entire data processing cycle from collection and storage through use and transmission to erasure or destruction of the data, regardless of the methodology, procedure, or technology used for processing the data (see Heberlein in Ehmann/Selmayr Commentary on the GDPR, 3rd edition, Article 5 GDPR, para. 1). The general principles for the processing of personal data laid down in Article 5 GDPR are fundamental conditions for all data processing. These principles, which have direct legal force, are mandatory legal requirements for the processing of personal data—as is evident from the comprehensive definition of "processing" in Article 4, paragraph 2 of the GDPR—and must be observed in every handling and at every stage related to personal data, throughout the entire data processing cycle from collection and storage through use and transmission to erasure or destruction of the data, regardless of the methodology, procedure, or technology used for processing (see Heberlein in Ehmann/Selmayr Commentary on the GDPR, 3rd edition, Article 5, GDPR, para. 1).
According to the established case law of the Data Protection Authority, the Federal Administrative Court, and the CJEU, these principles constitute legally binding regulations that are specifically effective and must be taken into account when assessing the lawfulness of data processing.
According to the established case law of the Data Protection Authority, the Federal Administrative Court, and the CJEU, these principles constitute legally binding regulations that are specifically effective and must be considered when reviewing the lawfulness of data processing.
``` All processing of personal data must, firstly, comply with the principles for data processing set out in Article 5 of the GDPR and, secondly, comply with the principles regarding the lawfulness of processing set out in Article 6 of the GDPR (see CJEU of 22 June 2021, Case C-439/19, paragraph 96; CJEU of 4 May 2023, Case C-60/22, paragraphs 56 and 57; and BVwG of 2 April 2024, Case W176 2266382-1). All processing of personal data must, firstly, comply with the principles for data processing set out in Article 5 of the GDPR and, secondly, comply with the principles regarding the lawfulness of processing set out in Article 6 of the GDPR (see CJEU of 22 June 2021, Case C-439/19). (See paragraph 96, ECJ judgment of 4 May 2023, C-60/22, paragraphs 56 and 57, and BVwG judgment of 2 April 2024, W176 2266382-1).
The Data Protection Authority acknowledges that a comprehensive system change was implemented during the ongoing investigation, which now allows for gender-neutral registration in the BG online shop by eliminating gender-specific forms of address (see BG's statement of 8 September 2025). Conversely, until its system was updated, the BG continued to link the bP's data record with a gender-specific salutation. The data protection authority acknowledges that a comprehensive system change was implemented during the ongoing investigation, which now allows for gender-neutral registration in the BG's online shop by eliminating the gender-specific salutation (see the BG's statement of September 8, 2025). Conversely, until its system was updated, the BG continued to link the bP's data record with a gender-specific salutation.
The data protection authority acknowledges that a comprehensive system change was implemented during the ongoing investigation, which now allows for gender-neutral registration in the BG's online shop by eliminating the gender-specific salutation. In case C-394/23 (“Mousse”) of 9 January 2025, the CJEU ruled that the processing of salutation data for the personalization of business communications is neither necessary for the performance of a contract pursuant to Article 6(1)(b) GDPR nor compatible with the principle of data minimization pursuant to Article 5(1)(c) GDPR, because such processing is not required for the stated purposes.
The CJEU ruled in case C-394/23 (“Mousse”) of 9 January 2025 that the processing of salutation data for the personalization of business communications is neither necessary for the performance of a contract pursuant to Article 6(1)(b) GDPR nor compatible with the principle of data minimization pursuant to Article 5(1)(c) GDPR, because such processing is not required for the stated purposes. Applying the aforementioned case law to the present case, it should be noted that the applicant could only register in the online shop by mandatorily entering the salutation "Ms." or "Mr." For the primary purpose of the contractual relationship within the BG online shop—the process of fulfilling the purchase agreement (consisting of selection, ordering, delivery, and payment) for the ordered goods—the use of a gender-specific salutation is not necessary.
In the aforementioned "Mousse" case, the CJEU ruled that the processing of personal data can be considered necessary for the performance of a contract if it is objectively essential for achieving the purpose to be accomplished. This means that the processing must be objectively essential to achieve the purpose and is therefore a necessary component of the contract (see CJEU Case C-394/23 of 9 January 2025, paragraph 33). In the aforementioned case "Mousse," the CJEU held that the processing of personal data can be considered necessary for the performance of a contract if it is objectively essential for achieving the purpose. This means that the processing must be objectively essential to achieve the purpose and is therefore a necessary component of the contract (see CJEU Case C-394/23 of 9 January 2025, paragraph 33).
``` The CJEU held in the aforementioned case "Mousse" that the processing of personal data can be considered necessary for the performance of a contract if it is objectively essential for achieving the purpose to be achieved. This means that the processing must be objectively essential to achieve the purpose and is therefore a necessary component of the contract (see CJEU Case C-394/23 of 9 January 2025, paragraph 33). For the purposes of processing contracts and orders, internal correspondence with bP, prize draws, newsletter distribution, user account creation (registration), and delivery of ordered goods, the use of gender-specific forms of address is not strictly necessary, even under a broad interpretation.
Furthermore, bP itself acknowledges and substantiates in its statement of June 24, 2025, that it had already refrained from using gender-specific forms of address in direct communication, newsletter registration, prize draw participation, use of the contact form, delivery notifications, invoices, and order confirmations at that time. Article 6(1)(b) GDPR is not a legal basis for processing gender-specific forms of address during the registration process, as it is not necessary. Furthermore, BG itself acknowledges and demonstrates in its statement of June 24, 2025, that it had already refrained from using gender-specific forms of address in direct communication, newsletter registration, participation in competitions, use of the contact form, delivery notifications, invoices, and order confirmations at that time. Article 6(1)(b) GDPR is therefore not a legal basis for processing gender-specific forms of address during the registration process, as it is not necessary.
Moreover, BG itself acknowledges and documents in its statement of June 24, 2025, that it had already refrained from using gender-specific forms of address in direct communication, newsletter registration, participation in competitions, use of the contact form, delivery notifications, invoices, and order confirmations at that time. Insofar as the BG, in its statement of June 24, 2025, invokes a legitimate interest pursuant to Article 6(1)(f) GDPR as a legal basis for processing, the following should be noted: Article 6(1)(f) permits the processing of personal data in "relations of equality" between private parties if it is necessary for the purposes of the legitimate interests pursued by a controller or by a third party (cf. Article 4(10)).
The CJEU has established a “test scheme” for the largely identical predecessor provision (Article 7(f) of the Data Protection Directive), according to which the processing of personal data is permissible under three cumulative conditions, which is also used by the data protection authority and the Supreme Court in their case law (see judgments of 4 July 2023, Meta Platforms et al. [General Terms of Use of a Social Network], C-252/21, EU:C:2023:537, paragraph 106, and of 4 October 2024, Koninklijke Nederlandse Lawn Tennisbond, C-621/22, EU:C:2024:857, paragraph 37, and most recently in Case C-394/23 of 9 January 2025, paragraph 45): The CJEU has established a “test scheme” for the largely identical predecessor provision (Article 7(f) of the GDPR) provides a “test scheme” according to which the processing of personal data is permissible under three cumulative conditions, which is also used by the Data Protection Authority and the Supreme Court in their case law (see judgments of 4 July 2023, Meta Platforms and Others [General Terms of Use of a Social Network], C-252/21, EU:C:2023:537, paragraph 106, and of 4 October 2024, Koninklijke Nederlandse Lawn Tennisbond, C-621/22, EU:C:2024:857, paragraph 37, and most recently in Case C-394/23 of 9 January 2025, paragraph 45):
i. The existence of a legitimate interest pursued by the controller or by the third party(ies) to whom the data are disclosed,
ii. the necessity of processing the personal data for the purposes of the legitimate interest, and
iii. the non-overriding fundamental rights and freedoms of the data subject.
With regard to the first requirement – the safeguarding of a “legitimate interest” – it should be noted that this term is not defined in the General Data Protection Regulation (GDPR). However, the Court of Justice of the European Union (CJEU) has already ruled that a broad range of interests is generally considered legitimate (see CJEU Case C-621/22 of 4 October 2024 or the CJEU judgment of 7 December 2023, SCHUFA Holding [Debt Discharge], C-26/22 and C-64/22, EU:C:2023:958, paragraph 76). 7 December 2023, SCHUFA Holding [Debt Discharge], C-26/22 and C-64/22, EU:C:2023:958, paragraph 76).
As is also evident from Recital 47 of the GDPR, which concerns the concept of ‘legitimate interest’, the EU legislator has not required that a controller’s interest be legally regulated in order for the processing of personal data carried out by that controller to be lawful within the meaning of Article 6(1)(f) GDPR.
As is also evident from Recital 47 of the GDPR, which concerns the concept of ‘legitimate interest’, the EU legislator has not required that a controller’s interest be legally regulated in order for the processing of personal data carried out by that controller to be lawful within the meaning of Article 6(1)(f) GDPR. The facts of the case clearly show that the BG's interest is legitimate, as it does not violate either European Union or national law (see ECJ, C-621/22, para. 40). The data protection authority therefore correctly recognizes that the BG has a legitimate (economic) interest in addressing its customers personally.
The next step in the review process is to examine the necessity of the processing. When assessing what is "necessary," it must be examined whether the legitimate interests pursued by the data processing can be achieved just as effectively in practice by other means that restrict the fundamental rights and freedoms of the data subject less.
... In this context, the data protection authority refers once again to the judgment of the CJEU of 4 October 2024 in case C-621/22, in which it states that the requirement of necessity of data processing must be examined together with the principle of ‘data minimization’, which is enshrined in Article 5(1)(c) GDPR and requires that personal data be ‘adequate, relevant and limited to what is necessary for the purposes for which they are processed’ (see judgment of 4 July 2023, Meta Platforms et al. [General Terms of Use of a Social Network], C-252/21, EU:C:2023:537, paragraph 109 and the case law cited therein). If reasonable, equally effective, but less intrusive alternatives exist, the processing cannot be considered "necessary" (see Guidelines 1/2024 on the processing of personal data based on Article 6(1)(f) GDPR, adopted on 8 October 2024). In this context, the Data Protection Authority refers again to the judgment of the CJEU of 4 October 2024 in case C-621/22, in which the Court stated that the requirement of necessity for data processing must be assessed together with the principle of "data minimization," enshrined in Article 5(1)(c) GDPR, which requires that personal data be "adequate, relevant and limited to what is necessary for the purposes for which they are processed" (see judgment of 4 July 2023, Meta Platforms et al.). [General Terms of Use of a Social Network], C-252/21, EU:C:2023:537, paragraph 109 and the case law cited therein). Accordingly, if reasonable, equally effective, but less intrusive alternatives exist, the processing cannot be considered “necessary” (see Guidelines 1/2024 on the processing of personal data based on Article 6(1)(f) GDPR, adopted on 8 October 2024).
The principles of purpose limitation and data minimization laid down in Article 5(1)(b) and (c) GDPR require the controller to limit processing to what is necessary for the processing purpose. The suitability of processing for a specific purpose or economic considerations are therefore not sufficient in themselves to justify the necessity of processing if an equally effective, less intrusive means is available to achieve the purpose (see Heberlein in Ehmann/Selmayr, Commentary on the GDPR, Art. 6 GDPR, para. 45). The principles of purpose limitation and data minimization laid down in Article 5(1)(b) and (c) of the GDPR oblige the controller to limit processing to what is necessary for the processing purpose. The suitability of processing for a specific purpose or economic considerations are therefore not sufficient in themselves to justify the necessity of processing if an equally effective, less intrusive means is available to achieve the purpose (see Heberlein in Ehmann/Selmayr, Commentary on the GDPR, Art. 6 GDPR, para. 45).
In light of the aforementioned case law, it should be noted that – contrary to the BG's assertions – processing gender-specific forms of address does not appear necessary. Firstly, because the BG itself – as explained above – admitted and demonstrated in its statement of June 24, 2025, that it had already refrained from using gender-specific forms of address in direct communication, newsletter registration, participation in competitions, use of the contact form, delivery notifications, invoices, and order confirmations at that time.
Furthermore, a comprehensive system overhaul was carried out during the ongoing proceedings before the Data Protection Authority, and the BG refrained from the processing operation (linking the user profile with a gender-specific form of address during the registration process) (see point 3 of the findings). The BG itself has thus documented that this data processing is not strictly necessary and that less intrusive alternatives exist. Furthermore, a comprehensive system overhaul was implemented during the ongoing proceedings before the Data Protection Authority, and the BG has refrained from the processing operation (linking the user profile with a gender-specific salutation during the registration process – see point 3 of the findings). The BG itself has thus documented that this data processing is not strictly necessary and that less intrusive alternatives exist.
The Data Protection Authority further notes that the Constitutional Court, in its decision of June 15, 2018, case number G 77/2018, stated that in addition to "male" and "female," a third designation corresponding to the actual gender identity must also be entered in the civil registry, and that a restriction to only two gender categories is incompatible with Article 8 of the European Convention on Human Rights. How the chosen rigid, binary, gender-specific form of address for customers was compatible with the aforementioned 2018 ruling remains unclear. The Data Protection Authority further notes that the Constitutional Court, in its decision of June 15, 2018, case number G 77/2018, stated that in addition to "male" and "female," a third designation corresponding to the actual gender identity must also be entered in the civil registry, and that a restriction to only two gender categories is incompatible with Article 8 of the ECHR. How the chosen rigid, binary, gender-specific form of address for customers was compatible with the aforementioned 2018 ruling remains unclear.
In the "Mousse" case of 9 January 2025, the CJEU also held, with regard to the assessment of the necessity of processing personal data and the extent to which customs and social conventions should be taken into account, that Article 6(1)(f) GDPR does not provide for consideration of customs and social conventions when assessing the necessity of such processing (see paragraph 56).
``` With regard to the assessment of the necessity of processing personal data and the extent to which customs and social conventions should be taken into account, the CJEU held that Article 6(1)(f) GDPR does not provide for consideration of customs and social conventions when assessing the necessity of such processing (see paragraph 56).
``` This means that even if the legitimate interest is affirmed, it must be noted that less intrusive measures exist, and therefore the balancing of interests fails to meet the second requirement of necessity.
As a result, the processing operation in question violates the principles of purpose limitation and data minimization enshrined in Article 5 of the GDPR, specifically Article 5(1)(b) and (c). Furthermore, the costs and time expenditure cited by the BG (Federal Administrative Court) are disregarded in the assessment of necessity and objective legal violations, as the focus is solely on the objective legal violation within the administrative proceedings. Therefore, as a result, the processing operation in question violates the principles of purpose limitation and data minimization enshrined in Article 5 of the GDPR, specifically Article 5(1)(b) and (c). The costs and time expenditure cited by the BG (German Social Accident Insurance) are also disregarded in the assessment of necessity and objective legal violations, as the focus is solely on the objective legal violation in the administrative proceedings.
As stated at the outset, a violation of even one of the principles enshrined in Article 5(1) is sufficient to establish unlawfulness of the processing. Furthermore, it must be noted that the requirements of Article 6(1)(b) and Article 6(1)(f) GDPR cannot be considered fulfilled due to the lack of necessity of the processing for the purposes carried out. The decision was therefore rendered accordingly. As stated at the outset, a violation of even one of the principles enshrined in Article 5(1) is sufficient to establish unlawfulness of the processing. It should also be noted that the requirements of Article 6(1)(b) and Article 6(1)(f) of the GDPR cannot be considered fulfilled due to the lack of necessity of the processing for the purposes carried out. The decision was therefore rendered accordingly.
For the sake of completeness, the Data Protection Authority notes that, in the present case, a data processing agreement pursuant to Article 58(2) of the GDPR is not required due to the system already being modified during the registration process.
D.3.2. Point II of the Decision (Right to data protection by design and by default pursuant to Article 25 of the GDPR) Point II of the ruling (Right to data protection by design and by default pursuant to Article 25 GDPR)
Regarding the alleged violation of the “right to data protection by design based on data protection-friendly or data protection-unfriendly default settings pursuant to Article 25 GDPR,” it must be noted that the GDPR does not grant a right by which a data subject could demand specific data protection-friendly default settings within the meaning of Article 25 GDPR from a controller (cf., by analogy, the decision of the Data Protection Authority of 13 September 2018 concerning Article 32 GDPR, file number DSB-D123.070/0005-DSB/2018). Regarding the alleged violation of the "right to data protection by design based on privacy-friendly or privacy-unfriendly default settings pursuant to Article 25 GDPR," it should be noted that the GDPR does not grant a right by which a data subject could demand specific privacy-friendly default settings within the meaning of Article 25 GDPR from a controller (see, by analogy, the decision of the Data Protection Authority of September 13, 2018, concerning Article 32 GDPR, file number DSB-D123.070/0005-DSB/2018).
Article 25(1) GDPR obliges the controller to implement appropriate technical and organizational measures, both at the time of determining the means of processing and at the time of the processing itself, to effectively implement the principles of Article 5 GDPR, comply with the other requirements of the GDPR, and protect the rights of the data subject. Paragraph 1 grants the controller considerable discretion in this regard, but at the same time highlights the principle of data minimization pursuant to Article 5(1)(c) GDPR as an exemplary means of designing technologies in the most data protection-friendly way possible. Apart from the term "state of the art," which is to be understood as dynamic, the provision contains no further requirements regarding the design (see Baumgartner in Selmayer/Ehmann, Commentary on the GDPR, Article 25 GDPR, paragraphs 17, 19 and 22). Article 25(1) GDPR obliges the controller to implement appropriate technical and organizational measures, both at the time of determining the means of processing and at the time of the actual processing, to effectively implement the principles of Article 5 GDPR, comply with the other requirements of the GDPR and protect the rights of the data subject. Paragraph one grants the controller considerable leeway in this regard, but at the same time highlights the principle of data minimization pursuant to Article 5, paragraph 1, letter c, GDPR as an exemplary means of designing technologies in the most privacy-friendly way possible. Apart from the term "state of the art," which is to be understood as dynamic (see Baumgartner in Selmayer/Ehmann, Commentary on the GDPR, Article 25, paragraphs 17, 19 and 22), the provision contains no further specifications regarding the design.
[Note: The last sentence appears to be a fragment and is omitted.] Article 25(2) of the GDPR obliges the controller to implement data-minimizing default settings for products, services, and applications in order to limit the collection, processing, and disclosure of personal data to the minimum necessary for the intended purpose (see Baumgartner in Selmayer/Ehmann, Commentary on the GDPR, Article 25 GDPR, para. 25).
Article 25(2) of the GDPR obliges the controller to implement data-minimizing default settings for products, services, and applications in order to limit the collection, processing, and disclosure of personal data to the minimum necessary for the intended purpose. While it is generally possible that a data subject's fundamental right to confidentiality may be violated due to data protection-unfriendly default settings pursuant to Article 25 GDPR, or that there may be a breach of the principles of data processing, the data subject would not have a right to choose a specific data protection-friendly default setting by design. As Article 25 GDPR makes clear, the obligation to implement data protection-friendly default settings by design rests with the controller (see Martini in Paal/Pauly, Commentary on the GDPR, 3rd edition, Article 25 GDPR, para. 25), which can be ensured in several ways. While it is generally possible that a data subject's fundamental right to confidentiality may be violated due to data protection-unfriendly default settings pursuant to Article 25 GDPR, or that there may be a breach of the principles of data processing, the data subject would not have a right to choose a specific data protection-friendly default setting by design. As is evident from Article 25 of the GDPR, the obligation to implement data protection-friendly default settings by design rests with the controller (see Martini in Paal/Pauly, Commentary on the GDPR, 3rd edition, Article 25 GDPR, para. 25), which can be ensured in several ways.
Even after a systematic review of the GDPR, it cannot be concluded that the legislator intended to grant a data subject a subjective right to compliance with specific data protection-friendly default settings by design. The rights of data subjects are explicitly listed in Chapter III, while Article 25 GDPR and also Article 32 GDPR are contained in Chapter IV ("Controller and Processor"). This merely means that the BG, as the controller pursuant to Article 4(7) GDPR, is subject to the obligations of Article 25 GDPR. Even after a systematic review of the GDPR, it cannot be concluded that the legislator intended to grant a data subject a subjective right to compliance with specific data protection-friendly default settings by design. The rights of data subjects are explicitly listed in Chapter 3, while Article 25 and Article 32 of the GDPR are contained in Chapter 4 ("Controller and Processor"). This simply means that the BG, as the controller pursuant to Article 4, point 7 of the GDPR, is subject to the obligations of Article 25 of the GDPR.
In this context, reference is made to the jurisprudence of the former Data Protection Commission, which, with regard to data security measures, stated that these merely establish an obligation for the controller, but not subjective legal rights for a data subject (see the DSK decision of August 2, 2005, file no. K121.038/0006-DSK/2005). The Federal Administrative Court confirmed this view and, referring to the DSK's jurisprudence, stated that the assertion of specific data protection measures is not subject to a formal agreement (see the Federal Administrative Court's rulings of July 11, 2017, file no. W214 2117640-1, and of April 20, 2017, file no. W214 2007810-1). The same applies to the right to compliance with certain data protection-friendly default settings by design pursuant to Article 25 GDPR. In this context, reference is made to the case law of the former Data Protection Commission, which, with regard to data security measures, stated that these merely establish an obligation for the controller, but not subjective legal claims of a data subject (see the DSK decision of August 2, 2005, file no. K121.038/0006-DSK/2005). The Federal Administrative Court confirmed this view and, referring to the DSK's case law, stated that the assertion of specific data protection measures is not subject to a formal agreement (see the Federal Administrative Court's rulings of July 11, 2017, file no. W214 2117640-1 and of April 20, 2017, file no. W214 2007810-1). The same applies to the right to compliance with certain data protection-friendly default settings by design pursuant to Article 25 of the GDPR.
Since the plaintiff lacked a subjective right to a specific default setting, the complaint was therefore dismissed accordingly.




