OLG Wien - 13R3/24t
A court found that a public broadcaster’s failure to notify a data subject about a data breach was not causal for a potential immaterial damage suffered by a data subject due to the data breach.
| OLG Wien - 13R3/24t | |
|---|---|
| Court: | OLG Wien (Austria) |
| Jurisdiction: | Austria |
| Relevant Law: | Article 33 GDPR Article 34 GDPR Article 82 GDPR |
| Decided: | 21.03.2025 |
| Published: | 26.11.2025 |
| Parties: | |
| National Case Number/Name: | 13R3/24t |
| European Case Law Identifier: | ECLI:AT:OLG0009:2025:01300R00003.24T.0321.000 |
| Appeal from: | |
| Appeal to: | |
| Original Language(s): | German |
| Original Source: | RIS (in German) |
| Initial Contributor: | xz |
English Summary
Facts
The data subject is an individual whose personal data (name, address, date of birth) are stored in the Austrian Central Population Register. The controller is a company responsible for collecting broadcasting fees and is legally allowed to receive population-register data to identify liable fee payers.
In May 2020, it became public that a hacker was offering large quantities of Austrian register data for sale. The controller issued a press release informing the public about the incident and clarifying that it was unclear whether the leaked data came from its systems. It also notified the Data Protection Authority (DSB) under Article 33 GDPR, but it did not individually notify potentially affected persons.
The data subject did not know in 2020 whether he was affected. In 2023, he learned that his data had indeed appeared in the leaked dataset. To understand what data the controller was processing, he submitted an Article 15 GDPR access request on 4 March 2023. The controller warned of delays due to high workload and ultimately responded only on 24 May 2023.
Believing that the controller had exceeded the legal response period, the data subject instructed a lawyer to file a complaint with the DSB. He paid the lawyer €200. He then brought a civil action claiming €200 in material damages for attorney’s fees and €200 in non-material damages arguing that he had to hire a lawyer and since DSB proceedings do not provide cost reimbursement, he considers these expenses a recoverable financial loss under Article 82 GDPR. He further claims that the defendant breached Article 34 GDPR by not notifying him of the 2020 data breach and as a result, he spent around 240 hours dealing with anger, worry, and efforts to obtain withheld information, justifying non-material harm.
The first-instance civil court rejected the material-damages claim as inadmissible, holding that administrative procedure costs are normally borne by the parties. It dismissed the non-material-damages claim because no actual emotional harm was proven.
The data subject appealed both points to the Higher Regional Court (OLG).
Holding
The Court held that the first-instance court was wrong to reject the data subject’s claim for material damages as inadmissible. Although the general rule in Austrian administrative law is that each party must bear its own administrative costs, including legal fees, Austrian Supreme Court has established some exceptions where the reimbursement of administrative-procedure legal costs constitutes reasonable “rescue expenses” for unavoidable procedural actions, incurred to avert or reduce damage caused by another party’s unlawful conduct.
For this reason, the court reversed the first-instance court's decision and the case was referred back to the first-instance court to continue proceedings without relying on the prior dismissal ground and to decide on the merits.
With respect to the claim for non-material damages, the court affirmed the first-instance court’s dismissal. The court acknowledged that the controller's press release had not fully satisfied the requirements of Article 34 GDPR, meaning that an individual notification to the data subject should arguably have been provided.
Nevertheless, the court emphasized that under CJEU case law, a mere infringement of the GDPR does not automatically entitle an individual to compensation. Instead, an actual harm and a causal connection between the harm and the violation must be proved. In the present case, the data subject had described only general annoyance and had not shown that any emotional harm specifically resulted from the controller's failure to notify him individually. The court found no evidence of distress or other concrete effects that could qualify as non-material damage under Article 82 GDPR.
For these reasons, it upheld the dismissal of the €200 non-material-damages claim.
Comment
It is interesting that the court held that a civil court can examine claims for reimbursement of administrative-procedure legal costs as material damages arising from GDPR violations, in case such costs can constitute reasonable “rescue expenses” for unavoidable procedural actions.
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the German original. Please refer to the German original for more details.
Head The Higher Regional Court of Vienna, acting as the court of appeal and reconciliation, with Senate President Mag. Häckel presiding, and Judges Mag. Wessely and Mag. Nigl, LL.M., in the case of the plaintiff A*, **, represented by Dr. Philipp Springer, attorney-at-law in Vienna, against the defendant B* GmbH, **, represented by Schönherr Rechtsanwälte GmbH in Vienna, regarding the most recent claim of EUR 400,-- plus interest (§ 29 para. 2 DSG), concerning the appeal (interest in the appeal: EUR 200,-- plus interest) and the appeal on points of law (interest in the appeal on points of law: EUR 200,-- plus interest) of the plaintiff against the decision and the judgment of the Regional Court for Civil Matters Vienna of November 22, 2023, **-18, in a non-public session. The Higher Regional Court of Vienna, acting as the court of appeal and appellate proceedings, with Senate President Mag. Häckel as presiding judge, as well as Mag. Wessely and Mag. Nigl, LL.M., in the case of the plaintiff A*, **, represented by Dr. Philipp Springer, Attorney at Law in Vienna, against the defendant B* GmbH, **, represented by Schönherr Rechtsanwälte GmbH in Vienna, regarding the sum of EUR 400,-- plus interest (Section 29, Paragraph 2, Data Protection Act), concerning the appeal (interest in appeal: EUR 200,-- plus interest) and the appeal on points of law (interest in appeal on points of law: EUR 200,-- plus interest) of the plaintiff against the decision and judgment of the Vienna Regional Court for Civil Matters of November 22, 2023, **-18, in non-public session Ruling I. denro. eins. den Decision issued: The appeal is granted and the contested decision is amended to read: "The objection of inadmissibility of the legal recourse with respect to EUR 200,-- plus interest is dismissed." The court of first instance is instructed to continue the proceedings to this extent, disregarding the grounds for dismissal invoked. The appeal on points of law is inadmissible in any event. II. Rightly ruled: Roman II. Rightly ruled: The appeal is dismissed with respect to EUR 200.00 plus interest. The plaintiff is ordered to reimburse the defendant for the costs of the appeal response, amounting to EUR 211.63 (including EUR 35.27 VAT), within 14 days. The appeal on points of law is inadmissible in any event. Text Grounds and Reasons for the Decision The plaintiff is a natural person residing in **. His name (first and last name), date of birth, and current principal residence are registered in the Central Population Register (./E). The defendant is a private company entrusted with the collection of broadcasting fees under the Broadcasting Fees Act (RGG). For this purpose, it records the name, gender, address, and date of birth of registered broadcasting subscribers in Austria. Upon request, it receives the necessary data in various formats from the different registration authorities in Austria. The defendant also processed the following personal data of the plaintiff: first name, last name, date of birth, and address (./AB). [...] In May 2020, a hacker offered the names and addresses of Austrian individuals for sale on the internet (hereinafter: data breach). On May 27, 2020, the defendant informed the public about the data breach via an APA press release (./U). In it, it stated, among other things: "As became known today, a large amount of data appears to have been stolen, and it cannot be ruled out that this data originated from within the sphere of influence of B*." (./U). On May 29, 2020, the defendant filed a notification with the data protection authority pursuant to Article 33 of the GDPR […]. In this context, national media outlets, such as "derStandard" on May 27, 2020, also reported on the incident (./S). The defendant did not notify individual data subjects at that time. In fact, the plaintiff's data (name, address, date of birth) was offered for sale by a "hacker" on the dark web. It is not possible to determine how the hacker obtained this data. Neither the defendant nor the plaintiff himself was aware until the conclusion of the oral proceedings that the plaintiff's data had actually been compromised. [...] The plaintiff first learned of the data security incident in early January 2023 from media reports and was annoyed because he believed the defendant had negligently posted data online. His annoyance was general in nature and did not affect his daily life. His annoyance did not increase as a result of his own research into alleged data protection violations by the defendant. The plaintiff also suffered no worries, anger, or other adverse effects. Rather, the plaintiff continued his life as before without any restrictions, voluntarily providing his data, such as his name, address, and bank details, to third parties via various websites, shopping online, booking trips online, ordering food online, and regularly using messaging services like WhatsApp and Signal. The plaintiff had no concerns about any of these online activities and the associated data disclosure. On March 4, 2023, the plaintiff submitted a request for information to the defendant based on Article 15 of the GDPR (./V). At that time, the defendant received a very large number of inquiries and was therefore unable to answer all of them in a timely manner. On the same day, the defendant confirmed receipt of the plaintiff's request for information by email and informed him that, due to the high volume of inquiries, there might be delays in responding to his request (./X). On April 12, 2023, the plaintiff, through his legal representative, filed a complaint with the Data Protection Authority (DPA), seeking a ruling that the defendant had violated his right under Article 15 GDPR by failing to respond to his request for information (./Y). For the services rendered in connection with filing the complaint, for which the plaintiff's representative recorded 40 minutes of work, the plaintiff was billed €200 gross on April 12, 2023 (./AC), which the plaintiff paid. The defendant sent the plaintiff a letter dated May 24, 2023, requesting information pursuant to Article 15 GDPR (./AB). It cannot be established that the information provided by the defendant therein was untrue or incomplete. On March 4, 2023, the plaintiff submitted a request for information to the defendant based on Article 15 GDPR (./V). At that time, the defendant was receiving a very large number of requests and was therefore unable to respond to all of them in a short period of time. The defendant confirmed receipt of the plaintiff's request for information by email on the same day and informed him that, due to the high volume of requests, there might be delays in responding to his request (./X). On April 12, 2023, the plaintiff, through his legal representative, filed a complaint with the Data Protection Authority (DPA), seeking a ruling that the defendant had violated his right under Article 15 of the GDPR by failing to respond to his request for information (./Y). For services rendered in connection with filing the complaint, for which the plaintiff's representative recorded 40 minutes of work, the plaintiff was billed €200 (gross) on April 12, 2023 (./AC), which the plaintiff paid. The defendant sent the plaintiff a letter dated May 24, 2023, requesting the information pursuant to Article 15 of the GDPR (./AB). It cannot be established that the information provided by the defendant in this letter was untrue or incomplete. For services rendered in connection with filing the complaint, for which the plaintiff's representative recorded 40 minutes of work, the defendant invoiced the plaintiff on April 12, 2023 (./AC), which the plaintiff paid. Furthermore, it cannot be established that the plaintiff had to expend considerable time and effort to put an end to the alleged infringements of rights by the defendant, nor that he incurred costs or other expenses due to his own research, such as for applications to authorities. [...] In his lawsuit, the plaintiff ultimately seeks payment of EUR 200 in material damages for legal fees and EUR 200 in non-material damages. He argued—insofar as relevant to the appeal proceedings—that in proceedings before the Data Protection Authority (DSB), regardless of the outcome, there is no entitlement to reimbursement of court costs, so the necessary expense of EUR 200 constitutes material, or alternatively non-material, damage within the meaning of Article 82(1) GDPR, which was unlawfully and causally caused by the defendant, as the defendant failed to respond to his request for information by April 5, 2023, at the latest. The plaintiff claims that this violated his right to information. The principle that costs of administrative proceedings cannot be claimed in civil proceedings is subject to numerous limitations, for example, regarding the costs of public procurement review proceedings. If complainants were prevented from claiming the reasonable costs of proceedings before the Data Protection Authority (DSB) in civil proceedings, victims of data breaches would be obligated to bear such damages themselves. Such an obligation to bear their own legal costs would, however, constitute a "financial loss" within the meaning of Recital 75 of the GDPR. Recital 146 emphasizes that data subjects should "receive full and effective compensation for the damage suffered." The plaintiff ultimately seeks payment of EUR 200 in material damages for legal fees and EUR 200 in non-material damages. He argued – insofar as relevant to the appeal proceedings – that in proceedings before the Data Protection Authority (DPA), regardless of the outcome, there is no entitlement to reimbursement of legal costs, and therefore the necessary expenses of EUR 200 constitute material or, alternatively, non-material damage within the meaning of Article 82(1) GDPR, which was unlawfully and causally caused by the defendant, as the defendant had not responded to his request for information by April 5, 2023, at the latest. The plaintiff's right to information had thus been violated. The principle that costs of administrative proceedings cannot be claimed in civil proceedings is subject to numerous limitations, for example, regarding the costs of public procurement review proceedings. If appellants were prevented from claiming the reasonable costs of the proceedings before the DPA in civil proceedings, victims of data protection breaches would be forced to bear such damages themselves ultimately. However, such an obligation to bear the costs of representation would constitute a "financial loss" within the meaning of Recital 75 of the GDPR. Recital 146 emphasizes that data subjects should "receive full and effective compensation for the damage suffered." By failing to inform the plaintiff of the data breach to this day, the defendant violated Article 34 of the GDPR. At the time of the press release, the defendant must have known that the incident involved not only "large amounts of data," but that the registration records of all Austrians—including the plaintiff—had been stolen. The data breach posed a high risk to the personal rights and freedoms of the plaintiff and the other 8.9 million affected Austrians. Since January 12, 2023, the plaintiff has spent approximately 240 hours reflecting on the incident, experiencing negative feelings such as anger and worry. He has spent many hours researching and contacting various sources to obtain the information unlawfully withheld by the defendant through other means. The plaintiff's non-material damages necessitate a judgment ordering the defendant to pay €200 in damages. By failing to inform the plaintiff of the data breach to this day, the defendant violated Article 34 of the GDPR. The defendant must have known at the time of the press release that the incident involved not only "large quantities of data," but that the registration records of all Austrians—including the plaintiff's—had been stolen. The data breach posed a high risk to the personal rights and freedoms of the plaintiff and the other 8.9 million affected Austrians. Since January 12, 2023, the plaintiff has spent approximately 240 hours reflecting on the incident, experiencing negative feelings such as anger and worry. He has spent many hours researching and contacting various authorities to obtain the information unlawfully withheld by the defendant through other means. The plaintiff's non-material damages necessitate a judgment ordering the defendant to pay him €200 in damages. The defendant argued—insofar as relevant to the appeal proceedings—that the legal recourse for the costs of the administrative proceedings was inadmissible and requested that the claim be dismissed to that extent. Awarding the plaintiff's legal fees in the civil proceedings would amount to a prejudgment of the defendant in the (still) pending administrative proceedings. Pursuant to Section 74 Paragraph 1 of the General Administrative Procedure Act (AVG), the plaintiff must bear his own costs. The GDPR does not provide for cost reimbursement. There is no basis whatsoever for cost reimbursement. The plaintiff was informed of the potential delay in processing his request for information, including the reason for this delay, by the defendant's notification after its receipt. Any "rescue expenses" are only reimbursable if they are expedient and reasonable. Representation by a lawyer is not mandatory in proceedings before the Data Protection Authority (DSB). The complaint to the Data Protection Authority (DPA) was unnecessary. A formal request to the defendant would have sufficed. By filing a complaint instead of a formal request, the plaintiff violated the duty to mitigate damages. The defendant argued – insofar as relevant to the appeal proceedings – that the legal recourse for the costs of the administrative proceedings was inadmissible and requested that the action be dismissed to that extent. Awarding the legal fees in the civil proceedings would amount to a prejudgment of the defendant in the (still) pending administrative proceedings. Pursuant to Section 74, Paragraph 1, of the General Administrative Procedure Act (AVG), the plaintiff must bear his own costs. The GDPR does not provide for cost reimbursement. There is no basis whatsoever for cost reimbursement. The plaintiff was informed by the defendant's notification after receipt of his request for information about the potential delay in processing his request, including the reason for this delay. Any "rescue expenses" are only reimbursable if they are expedient and reasonable. There is no requirement to be represented by a lawyer in proceedings before the Data Protection Authority (DPA). A complaint to the DPA was not necessary. A formal request to the defendant would have sufficed. By filing a complaint instead of a formal request, the plaintiff violated the duty to mitigate damages. The defendant could not inform the data subjects personally because it did not know which individuals were actually affected. Given the potentially large number of data subjects, such notification would also have involved a disproportionate effort, so the defendant chose to inform them through public announcement. The defendant did not act culpably or unlawfully. The research effort cited by the plaintiff falls within his own sphere of responsibility and was not caused by the defendant. The acquisition of knowledge does not constitute damage. Since the plaintiff suffered no harm beyond emotional distress, the finding of a violation of a GDPR provision provides full and effective redress. Financial compensation is set at €0. The plaintiff failed to demonstrate a violation of the GDPR that could be the cause of the "anger" and "concern." The court found that the necessary causal link and connection to the unlawfulness were lacking. I. In the contested decision, the court of first instance dismissed the plaintiff's claim for payment of EUR 200 in legal fees for filing the complaint with the Data Protection Authority (DSB) on the grounds of inadmissibility. It made the findings set forth above in the decision, as well as further findings found on pages 2 and 5 to 7 of the judgment, to which reference is made. According to established case law, any costs incurred in administrative proceedings cannot be claimed in civil proceedings. The conditions for deviating from this principle were not met in this case, and therefore there was no basis for a claim for reimbursement of the costs incurred in filing the complaint with the DSB. In the contested decision, the court of first instance dismissed the plaintiff's claim for payment of EUR 200 in legal fees for filing the appeal with the Data Protection Authority (DSB) on the grounds of inadmissibility. It made the findings set forth above in the decision, as well as further findings found on pages 2 and 5 to 7 of the judgment, to which reference is made. According to established case law, any costs incurred in administrative proceedings cannot be claimed in civil proceedings. The conditions for deviating from this principle were not met in this case, and therefore there was no basis for a claim for reimbursement of the costs incurred in filing the appeal with the DSB. The plaintiff has filed an appeal against this decision, alleging incorrect legal assessment and requesting that the claim be granted. The defendant requests that the appeal be dismissed, or alternatively, that the claim be rejected. The dismissal order is subject to appeal without restriction – even in cases where the amount in dispute is less than EUR 2,700 (§ 517 para. 1 no. 1 of the Code of Civil Procedure). Filing an appeal against the dismissal of a partial claim does not preclude the right to challenge the substantive decision issued together with it (Kodek in Fasching/Konecny 3 III/1 § 261 Code of Civil Procedure, marginal note 67). Legal Assessment The appeal is justified. ``` The dismissal order is subject to appeal without restriction – even in cases where the amount in dispute is less than EUR 2,700 (§ 517 para. 1 no. 1 of the Code of Civil Procedure) 1. In his statement of claim, the plaintiff refers to the decision of the Higher Regional Court of Linz (OLG Linz) in case no. 2 R 149/21a and argues that the defendant's general statement after receipt of his request for information, that delays might occur, cannot be considered notification of an extension of the deadline within the meaning of Article 12(3), third sentence, GDPR. The failure to respond to the request for information on March 4, 2023, within the prescribed time limit should be considered unlawful and culpable conduct, which necessitated the initiation of administrative proceedings to remedy the unlawfulness and thus caused the costs incurred to obtain the information in the form of legal fees of EUR 200. After the deadline for providing the information expired without result on April 4, 2023, the plaintiff could have filed a civil action for performance to compel the disclosure of the information, either concurrently with or as an alternative to the proceedings before the Data Protection Authority (DSB). In this case, the plaintiff would have been liable for costs under the Code of Civil Procedure (ZPO). Similarly, before initiating such a civil action for performance, the plaintiff could have sent an extrajudicial letter of demand from his lawyer to the defendant pursuant to Section 45 of the Code of Civil Procedure and – had this been successful – claimed the associated costs in civil court. 1. In this letter, the plaintiff refers to the decision of the Higher Regional Court of Linz in case 2 R 149/21a and argues that the defendant's general statement after receipt of his request for information, that delays might occur, cannot be considered notification of an extension of time within the meaning of Article 12, paragraph 3, sentence 3 of the GDPR. The failure to respond to the request for information on March 4, 2023, within the prescribed time limit should be considered unlawful and culpable conduct, which necessitated the initiation of administrative proceedings to remedy the unlawfulness and thus caused the costs incurred to obtain the information in the form of legal fees of EUR 200. After the obligation to provide information expired without result on April 4, 2023, the plaintiff could have filed a civil action for performance seeking the disclosure of the information, either concurrently with or as an alternative to the proceedings before the Data Protection Authority (DSB). In this case, the plaintiff would have been liable for court costs in accordance with the German Code of Civil Procedure (ZPO). Similarly, prior to such a civil action, the plaintiff could have sent an extrajudicial letter of demand to the defendant through his attorney, pursuant to Section 45 of the ZPO, and – if this had been successful – claimed the associated costs in civil court. 2. Pursuant to Section 74 of the General Administrative Procedure Act (AVG), the principle of self-bearing applies to the costs of the parties involved, insofar as cost reimbursement between the parties only occurs if the administrative regulations exceptionally contain a corresponding provision (Hengstschläger/Leeb, AVG § 74, para. 4). There are no concerns regarding the constitutionality of Section 74 of the AVG (Constitutional Court [VfGH] Decision 316/2020-5). Pursuant to Section 74 of the AVG, the principle of self-bearing applies to the costs of the parties involved, insofar as cost reimbursement between the parties only occurs if the administrative regulations exceptionally contain a corresponding provision (Hengstschläger/Leeb, AVG Section 74, para. 4). There are no concerns regarding the constitutionality of Section 74 of the AVG (Constitutional Court [VfGH] Decision 316/2020-5). Neither the GDPR nor the Austrian Data Protection Act (DSG) provides for reimbursement of any procedural costs (in particular legal fees) incurred by a data subject in the context of a complaint procedure under Article 77(1) GDPR (right to lodge a complaint with a supervisory authority). However, a claim for reimbursement of costs may exist if a judicial remedy is sought under Article 79 GDPR (right to an effective judicial remedy against controllers or processors). In this case, the rules for cost reimbursement in civil proceedings are governed by the national law of the Member State (Zavadil in Knyrim, DatKomm Art 57 GDPR para. 26 and footnote 20). The disadvantage of bearing one's own costs in (data protection) administrative proceedings is offset by the advantage of the lack of risk of being obligated to cover the costs of another party (Austrian Constitutional Court decision E 316/2020-5). Reimbursement of any procedural costs (in particular, legal fees) incurred by a data subject in the context of a complaint procedure under Article 77(1) GDPR (right to lodge a complaint with a supervisory authority) is not provided for in either the GDPR or the Austrian Data Protection Act (DSG). However, a claim for reimbursement of costs may exist if a judicial remedy is sought under Article 79 GDPR (right to an effective judicial remedy against controllers or processors). In this case, the rules for cost reimbursement in civil proceedings are governed by the national law of the Member State (Zavadil in Knyrim, DatKomm Article 57 GDPR, para. 26 and footnote 20). The disadvantage of bearing one's own costs in (data protection) administrative proceedings is offset by the advantage of the absence of the risk of being obligated to cover the costs of another party (Austrian Constitutional Court decision E 316/2020-5). 3. According to established case law, reimbursement of administrative costs cannot be sought through civil proceedings (Ballon/Fucik/Lovrek in Fasching/Konecny3 § 1 JN para. 217); recourse to the ordinary courts is excluded for the independent assertion of administrative costs (RS0022786). Therefore, a specific statutory or supreme court ruling would be required as a reason for the court to rule on the costs of the administrative proceedings. The established case law that legal recourse is inadmissible if the administrative procedure does not provide for reimbursement of costs cannot be interpreted conversely to mean that in every case where there is no provision for reimbursement of costs in the administrative procedure, the costs of that procedure can be claimed in court as a substantive claim for damages. This interpretation would ultimately lead to the situation where any party prevailing in an "adversarial" administrative procedure could demand reimbursement of costs, either in the administrative procedure itself, if provided for in the substantive law, or in court if the obligation to reimburse costs is not provided for in the substantive law. This would contradict the distinction between administration and the judiciary, as well as the rule in Section 74 of the General Administrative Procedure Act (see Higher Regional Court of Vienna 13 R 135/21z). According to established case law, the reimbursement of administrative costs cannot be sought through civil proceedings (Ballon/Fucik/Lovrek in Fasching/Konecny3 Paragraph one, JN Rz 217); recourse to the ordinary courts is excluded for the independent assertion of administrative costs (RS0022786). Based on this, a specific statutory or supreme court ruling would be required as to why the court should nevertheless rule on the costs of the administrative proceedings. The fact that recourse to the courts is inadmissible if the administrative proceedings do not provide for reimbursement of costs cannot be interpreted conversely to mean that in every case where there is no entitlement to reimbursement of costs in the administrative proceedings, the costs of these proceedings can be asserted in court as a substantive claim for damages. This interpretation would ultimately lead to the situation where any party prevailing in an "adversarial" administrative proceeding could demand reimbursement of costs, either in the administrative proceedings if provided for in the substantive law, or in court if the obligation to reimburse costs is not provided for in the substantive law. This would contradict the separation of administrative and judicial functions, as well as the rule of Section 74 of the General Administrative Procedure Act (AVG; see Higher Regional Court of Vienna 13 R 135/21z). 4. Case law permits the assertion of costs of administrative proceedings as damages in civil proceedings only under certain conditions: According to older case law, this applied, for example, in the case of a breach of a private law agreement (see RS0022786 [T1]) or after a referral to civil proceedings by the administrative authority (see 6 Ob 94/20x with further references; RS0022786 [T2]). Such circumstances do not exist here. According to older case law, this applied, for example, in the case of a breach of a private law agreement (see RS0022786 [T1]) or after a referral to civil proceedings by the administrative authority (see 6 Ob 94/20x with further references; RS0022786 [T2]). Such circumstances do not exist here. However, case law recognizes a further exception: In decision 4 Ob 37/16v, the Supreme Court stated that the question of whether a party can successfully claim its costs incurred in administrative proceedings depends on whether the other party unlawfully and culpably provided false information to the administrative authority, which was the cause of the proceedings and thus resulted in the first party incurring the legal representation costs claimed as damages. These costs constitute rescue expenses, meaning expenses incurred to avert a danger (cf. 6 Ob 94/20x: a clearly unfounded charge of hit-and-run triggered legal defense costs). Rescue expenses represent positive damages, which are only reimbursable if they were appropriate, but under this condition, even if they were unsuccessful. The standard for assessing appropriateness is the course of action a "reasonable person" would have chosen in the same situation. Such expenses can include the reimbursement of legal costs. The question of any potential rescue expenses must therefore be assessed ex ante (RS0023516 [T1]). From a tort law perspective, rescue costs can only include expenses for unavoidable procedural acts (RS0023516 [T2]). However, case law recognizes a further exception: In decision 4 Ob 37/16v, the Supreme Court stated that the question of whether a party can successfully claim costs incurred in administrative proceedings depends on whether the other party unlawfully and culpably provided false information to the administrative authority, which was the cause of the proceedings and thus resulted in the first party incurring the legal representation costs claimed as damages. These costs constitute rescue costs, i.e., expenses incurred to avert a danger (compare 6 Ob 94/20x: a clearly unfounded charge of hit-and-run triggered legal defense costs). Rescue costs are positive damages that are only recoverable if they were expedient, but under this condition, even if they were unsuccessful. The standard for assessing expediency is the course of action that a "reasonable person" would have chosen in the same situation. Such an expense may include the reimbursement of legal costs. The question of any potential salvage costs must therefore be assessed from an ex ante perspective (RS0023516 [T1]). From a tort law perspective, salvage costs can only include costs for unavoidable procedural acts (RS0023516 [T2]). 5. In its decision cited by the plaintiff in case 2 R 149/21a, which was also based on an appeal filed with the Data Protection Authority by the plaintiff in that case, the Higher Regional Court of Linz argued, based on this case law, that costs from preliminary proceedings, even if these were administrative proceedings, fall under the general concept of damages in Section 1293 of the Austrian Civil Code (ABGB) in conjunction with Article 82 of the GDPR and Section 29 of the Austrian Data Protection Act (DSG) and are therefore reimbursable. In its decision cited by the plaintiff (case no. 2 R 149/21a), which also involved a complaint filed with the Data Protection Authority by the plaintiff in that case, the Higher Regional Court of Linz argued, based on this case law, that costs from preliminary proceedings, even if they are administrative proceedings, fall under the general concept of damages in Section 1293 of the Austrian Civil Code (ABGB) in conjunction with Article 82 of the GDPR and Section 29 of the Austrian Data Protection Act (DSG) and are therefore reimbursable. 6. When deciding on the admissibility of the legal recourse, the wording of the claim and, furthermore, the facts of the case (the allegations made in the claim) are of primary importance (Klauser/Kodek, JN – ZPO18 § 1 JN E 12). The decisive factor is whether, according to the content of the claim, a claim is being asserted that is subject to the jurisdiction of the civil courts (Klauser/Kodek, ibid., § 1 JN E 11). Not only the wording of the claim but also the nature of the asserted claim must be considered; for this, the asserted legal basis is of decisive importance (Klauser/Kodek, loc. cit., § 1 JN E 17). The ordinary courts are generally competent for claims for damages (Klauser/Kodek, loc. cit., § 1 JN E 48). 6. When deciding on the admissibility of the legal recourse, the wording of the claim and, furthermore, the facts of the case (the allegations in the claim) are decisive (Klauser/Kodek, JN – ZPO18, paragraph one, JN E 12). The decisive factor is whether, according to the content of the claim, a claim is being asserted that falls within the jurisdiction of the civil courts (Klauser/Kodek, loc. cit., paragraph one, JN E 11). Not only the wording of the claim but also the nature of the asserted claim must be considered; in this respect, the asserted legal basis is of decisive importance (Klauser/Kodek, loc. cit., paragraph one, JN E 17). The ordinary courts are generally competent for claims for damages (Klauser/Kodek, loc. cit., paragraph one, JN E 48). The plaintiff here seeks reimbursement of the legal fees he incurred in filing the appeal, expressly on the grounds of damages. He argues that these fees were unlawful and were caused by the defendant's failure to respond to his request for information within the prescribed time limit. 7. It follows, however, that the court of first instance should have ruled on the merits of this asserted claim for damages and examined whether the prerequisites for recoverability, as established by case law, were met. Therefore, the objection of inadmissibility of the legal recourse is unfounded. When assessing the admissibility of the legal recourse, the merits of the claim must be disregarded (see Higher Regional Court of Vienna 13 R 24/17w). This is a matter for the civil court to decide. 7. It follows, however, that the court of first instance should have ruled on the merits of this asserted claim for damages and examined whether the prerequisites for recoverability, as established by case law, were met. Therefore, the objection of inadmissibility of the legal recourse is unfounded. In assessing the admissibility of the legal recourse, the merits of the claim must be disregarded (see OLG Vienna 13 R 24/17w). The civil court must decide on this matter. 8. The appeal was therefore to be granted, the procedural objection of inadmissibility of the legal recourse dismissed, and the court of first instance instructed to continue the proceedings, disregarding the ground for dismissal. It may be necessary to consider whether the proceedings initiated by the present appeal are still pending before the Data Protection Authority (DSB). It should also be noted that the plaintiff, in his appeal, expressly cited the alternatives available to him besides filing a complaint with the DSB, namely sending a letter of demand from his attorney to the defendant or filing a claim against him pursuant to Article 79 GDPR. The court of first instance may therefore also have to examine whether an "unavoidable" procedural step exists. The appeal was therefore to be granted, the procedural objection of inadmissibility of the legal process to be dismissed, and the court of first instance instructed to continue the proceedings, disregarding the ground for dismissal. It may be necessary to consider whether the proceedings initiated by the complaint at issue are still pending before the Data Protection Authority (DPA). It should also be noted that the plaintiff, in his appeal, expressly cited the alternatives available to him besides filing a complaint with the DPA, namely sending a letter of demand from his attorney to the defendant or bringing an action against him under Article 79 of the GDPR. The court of first instance may therefore also have to examine whether an "unavoidable" procedural step exists. 9. A procedural objection by the defendant triggers an interlocutory dispute. Regardless of the outcome of the main proceedings, the prevailing party is entitled to the resulting (additional) costs, which are distinguishable from the general procedural expenses (Kellner in Kodek/Oberhammer, ZPO-ON § 261 ZPO para. 22; see also Kodek in Fasching/Konecny3 III/1 § 261 ZPO para. 62). Such distinguishable costs do not exist in the proceedings at first instance, and even in the appeal proceedings, costs for the appeal and the response to the appeal were not recorded separately (but only for the appeal on points of law and the response thereto). Therefore, a decision on costs must be omitted due to the lack of distinguishable costs. 9. A procedural objection raised by the defendant triggers an interlocutory dispute. Regardless of the outcome of the main proceedings, the prevailing party is entitled to reimbursement of the resulting (additional) costs that are distinguishable from the general procedural expenses (Kellner in Kodek/Oberhammer, ZPO-ON Section 261, ZPO para. 22; see also Kodek in Fasching/Konecny3 III/1 Section 261, ZPO para. 62). Such distinguishable costs are not present in the proceedings at first instance, and even in the appeal proceedings, costs for the appeal and the response to the appeal were not listed separately (but only for the appeal itself and the response thereto). Therefore, no decision on costs can be made due to the lack of distinguishable costs. † ... 10. It should be noted that, due to the final denial of a procedural defect, the decision is substantively amending the judgment, so that a ruling pursuant to Section 500 Paragraph 2 in conjunction with Section 526 Paragraph 3 of the Code of Civil Procedure (ZPO) regarding the value of the subject matter of the decision and the admissibility of the appeal on points of law is required (Kodek in Fasching/Konecny3 III/1 Section 261 ZPO, marginal note 72). The inadmissibility of the appeal on points of law is based here on Sections 526 Paragraph 3 of the Code of Civil Procedure (ZPO) in conjunction with Section 500 Paragraph 2 Item 2 and Section 502 Paragraph 2, since the subject matter of the decision does not exceed EUR 5,000 in total, in terms of money or monetary value. It should be noted that, due to the final denial of a procedural defect, the decision is substantively amending the judgment, so that a ruling pursuant to Section 500, Paragraph 2, in conjunction with Section 526, Paragraph 3, of the Code of Civil Procedure (ZPO) regarding the value of the subject matter of the decision and the admissibility of the appeal on points of law is required (Kodek in Fasching/Konecny3 III/1 Section 261, ZPO, marginal note 72). The inadmissibility of the appeal on points of law is based here on Section 526, Paragraph 3, of the Code of Civil Procedure (ZPO) in conjunction with Section 500, Paragraph 2, No. 2, and Section 502, Paragraph 2, since the subject matter of the decision does not exceed EUR 5,000 in total, either in money or in kind. II. In the contested judgment, the court of first instance dismissed the claim for payment of EUR 200 in non-pecuniary damages. The court made the findings set forth at the beginning of the decision, as well as further findings set forth on pages 2 and 5 to 7 of the judgment, to which reference is made. In the contested judgment, the court of first instance dismissed the plaintiff's claim for payment of EUR 200 in non-pecuniary damages. It made the findings set forth at the beginning of the decision, as well as further findings set forth on pages 2 and 5 to 7 of the judgment, to which reference is made. In legal terms, the court stated – insofar as relevant to the appeal proceedings – that no infringement of rights had occurred. While the plaintiff was annoyed by the data breach, this annoyance was of a general nature and did not affect his daily life. No negative impact or impairment resulted from it. The plaintiff failed to prove any non-pecuniary (or, if applicable, any pecuniary) damage. Since the defendant was unaware of the plaintiff's individual impact from the data security incident until the very end, the allegation of a failure to personally notify the plaintiff fails on this point. In this specific case, the defendant fulfilled its obligations under Article 34(3)(c) GDPR by issuing a public notice via press release, regardless of whether it knew the plaintiff was actually affected. From a legal perspective, the court stated – insofar as relevant to the appeal proceedings – that no legal violation had occurred. While the plaintiff was annoyed by the data breach, this annoyance was of a general nature and did not affect his daily life. No negative impact or impairment resulted from it. The plaintiff failed to prove any non-material (or, if applicable, any material) damage. Since the defendant was unaware of the plaintiff's individual impact on the data security incident until the very end, the allegation of a failure to personally notify the plaintiff fails on this point. In this specific case, the defendant fulfilled its obligations under Article 34, paragraph 3, letter c, GDPR by issuing a public notice – regardless of whether it knew the plaintiff was actually affected. The plaintiff appeals this decision on the grounds of incorrect legal assessment and requests a ruling that the plaintiff's claim is upheld. The defendant requests that the appeal be dismissed. The appeal is unfounded. 1. In his appeal, the plaintiff argues that the defendant was aware that the plaintiff (like everyone else) was potentially affected by the incident. This knowledge entails an obligation to notify everyone by means of a public notice. ...] ] The fact that the plaintiff participates in commercial transactions cannot be used as a benchmark for his non-material damage. If a data protection breach – in this case, the failure to provide incident notification that meets the requirements of Article 34(3)(c) GDPR – leads to non-material damage (here, annoyance), this constitutes damage compensable under Article 82 GDPR. The press release of May 27, 2020, does not comply with the requirements of Article 33(3)(b), (c), and (d) GDPR. The fact that the plaintiff participates in commercial transactions cannot be used as a benchmark for his non-material damage. If a data breach – in this case, the failure to provide incident notification that meets the requirements of Article 34(3)(c) GDPR – results in non-material damage (here, annoyance), this constitutes damage compensable under Article 82 GDPR. The press release of May 27, 2020, does not comply with the requirements of Article 33(3)(b), (c), and (d) GDPR. 2. An undisputed prerequisite for a claim under Article 82(1) GDPR is a causal violation of this Regulation, which the plaintiff, in the appeal proceedings, bases (only) on the violation of Article 34 GDPR. An undisputed prerequisite for a claim under Article 82(1) GDPR is a causal breach of this Regulation, which the plaintiff in the appeal proceedings bases (only) on a violation of Article 34 GDPR: 3. Article 34 GDPR grants the data subject the subjective right to be notified of the data breach if the conditions stipulated therein are met (König/Schaupp in Knyrim, DatKomm Art. 34 GDPR, para. 12). The first prerequisite for the notification obligation is a breach of the protection of personal data (König/Schaupp, loc. cit., Art. 34 GDPR, para. 11; cf. Jahnel, Commentary on the General Data Protection Regulation, Art. 33 GDPR, para. 5), which the GDPR defines in Art. 4, point 12, as "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed." "Unauthorized access to personal data that has been transmitted, stored, or otherwise processed." This definition thus refers initially to a breach of the security of the protection of personal data, not to a breach of data protection in general (König/Schaupp in Knyrim, DatKomm Art. 33 GDPR para. 21/1). The elements of such a security breach are also met if unauthorized access appears possible (Hödl in Knyrim, DatKomm Art. 4 GDPR para. 132). Not only attacks by third parties, such as those by hackers, can constitute a security breach, but also purely internal company actions. Neither fault nor the unlawfulness of the breaching action is a prerequisite. Even accidental events without any action on the part of the controller are covered (König/Schaupp, loc. cit., Art. 33 GDPR, para. 21/2). This definition thus initially refers to a breach of the security of the protection of personal data, not to a breach of data protection in general (König/Schaupp in Knyrim, DatKomm, Art. 33 GDPR, para. 21/1). The elements of such a security breach are also met if unauthorized access appears possible (Hödl in Knyrim, DatKomm, Art. 4 GDPR, para. 132). Not only attacks by third parties, such as those by a hacker, can constitute a security breach, but also purely internal company actions. Neither fault nor the unlawfulness of the breaching action is a prerequisite. Even accidental events without any action on the part of the controller are covered (König/Schaupp, loc. cit., Art. 33 GDPR, para. 21/2). ... A further requirement for the notification obligation is that the data breach is likely to result in a high risk to the rights and freedoms of natural persons (König/Schaupp, loc. cit., Art. 34 GDPR, para. 12). A "high risk" can be assumed in the case of data breaches that could result in identity theft or fraud, damage to the reputation of data subjects, or other significant economic or social disadvantages for the data subjects (cf. König/Schaupp, loc. cit., Art. 34 GDPR, para. 17). A "high risk" is assumed in the case of data breaches that could result in identity theft or fraud, damage to the reputation of affected individuals, or other significant economic or social disadvantages for the affected individuals (see König/Schaupp, Article 34 GDPR, para. 17). Although Article 34 GDPR does not explicitly state this, the notification obligation presupposes that the controller has actually become aware of the personal data breach (see König/Schaupp, Article 34 GDPR, para. 12/1). Notification should generally be sent directly to the data subjects, unless this would involve a disproportionate effort, in which case public announcement is sufficient. If there is uncertainty as to whether a person is affected, they must be notified, as the obligation to notify only ceases if it is unequivocally established that they are not affected (König/Schaupp, loc. cit., Art. 34 GDPR, para. 13). In terms of content, a public announcement must meet the requirements for the content of an individual notification. Depending on the circumstances of the individual case, suitable methods of public announcement include, for example: large-format newspaper advertisements in daily newspapers, other national or regional media, or via social networks, radio or television (e.g., in the form of a press conference), or information on a website of the controller regularly visited by the data subjects (König/Schaupp, loc. cit., Art. 34 GDPR, para. 22). The notification should generally be sent directly to the data subjects, unless this would involve a disproportionate effort, in which case a public announcement is sufficient. If there is uncertainty as to whether a person is affected, they must be notified, as the obligation to notify only ceases if it is unequivocally established that they are not affected (König/Schaupp, loc. cit., Article 34 GDPR, para. 13). In terms of content, a public announcement must meet the requirements for the content of an individual notification. Depending on the circumstances of the individual case, possible forms of public announcement include, for example: large-format newspaper advertisements in daily newspapers, other national or regional media, or via social networks, radio or television (e.g., in the form of a press conference), or information on a website of the controller regularly visited by the data subjects (König/Schaupp, loc. cit., Article 34 GDPR, para. 22). Pursuant to Article 34(2) GDPR, the notification must describe the nature of the personal data breach in clear and plain language and, in conjunction with Article 33(3) GDPR, must contain at least the following information: the name and contact details of the data protection officer or another contact point for further information (lit. b). A description of the likely consequences of the personal data breach (lit. c) and a description of the measures taken or proposed by the controller to address the personal data breach and, where appropriate, measures to mitigate its possible adverse effects (lit. d; König/Schaupp, loc. cit., Art. 34 GDPR, para. 23). In accordance with Article 34(2) GDPR, the notification must describe the nature of the personal data breach in clear and plain language and, in conjunction with Article 33(3) GDPR, must contain at least the following information: the name and contact details of the data protection officer or other contact point for further information (lit. b); a description of the likely consequences of the personal data breach (lit. c); and a description of the measures taken or proposed by the controller to address the personal data breach and, where appropriate, measures to mitigate its possible adverse effects (lit. d; König/Schaupp, loc. cit., Art. 34 GDPR, para. 23). 4. Since the defendant – as can be seen from its notification to the data protection authority pursuant to Article 33 GDPR – was aware of, or should have been aware of, the possibility of a data breach (“The initial indications communicated to us by the Federal Criminal Police Office suggested that the data set up for sale might originate, at least in part, from our data sets…”) and there was uncertainty as to whether the plaintiff was affected or not, it had a duty to notify the plaintiff. The duty to notify would only have lapsed if it had been unequivocally established that the plaintiff was not affected, which was not the case here. The press release of May 27, 2020, does not meet the requirements for notification under Article 34(2) GDPR because, for example, it does not contain contact details of a potential data protection officer or other contact point (see Jahnel, Commentary on the General Data Protection Regulation, Article 34 GDPR, para. 31). Since the defendant – as evidenced by its notification to the data protection authority pursuant to Article 33 GDPR – was aware of, or should have been aware of, the possibility of a data breach (“The initial indications communicated to us by the Federal Chancellery suggested that the data set up for sale might originate, at least in part, from our data sets…”) and it was unclear whether the plaintiff was affected or not, the defendant was obligated to notify the plaintiff. This notification obligation would only have been waived if it had been unequivocally established that the plaintiff was not affected, which was not the case here. The press release of May 27, 2020, does not meet the notification requirements of Article 34(2) GDPR because, for example, it does not contain contact details of a potential data protection officer or other contact point (see Jahnel, Commentary on the General Data Protection Regulation, Article 34 GDPR, para. 31). The defendant was aware of, or should have been aware of, the possibility of a data breach (“The initial indications communicated to us by the Federal Chancellery suggested that the data set up for sale might originate, at least in part, from our data sets…”). The obligation to notify would only have been waived if it had been unequivocally established that the plaintiff was not affected, which was not the case here. 5. If the data subject has suffered material or non-material damage as a result of the failure to notify them of the data breach, they have a claim for damages under Article 82 GDPR in conjunction with Section 29 of the German Federal Data Protection Act (BDSG) (Jahnel, loc. cit., Article 34 GDPR, para. 39). Data subjects can use notifications based on Article 33 GDPR in civil proceedings for damages under Article 82 GDPR (this can also be inferred from the purpose of the notification obligation under Article 34 GDPR; König/Schaupp, loc. cit., Article 33 GDPR, para. 55/3). 5. If the data subject has suffered material or non-material damage as a result of the failure to notify them of the data breach, they have a claim for damages under Article 82 GDPR in conjunction with Section 29 of the BDSG (Jahnel, loc. cit., Article 34 GDPR, para. 39). Data subjects may use notifications based on Article 33 GDPR in compensation proceedings under Article 82 GDPR before civil courts (this can also be inferred from the purpose of the notification obligation of Article 34 GDPR; König/Schaupp aaO Article 33 GDPR para. 55/3). 6. The judgment of the CJEU of 4 May 2023, C-300/21, clarified that a mere infringement of the GDPR provisions is not sufficient in itself to give rise to a claim for damages. The data subject affected by an infringement of the GDPR is not relieved of the burden of proof regarding the damage (CJEU C-300/21 [para. 50]). In the absence of relevant provisions of EU law, the structure of legal proceedings and the determination of the criteria for assessing the amount of damages are governed by national law, taking into account the principles of equivalence and effectiveness (CJEU C-300/21 [para. 54]). The CJEU also requires, for a claim for damages to exist, that there must be a causal link between the infringement in question and the damage suffered by the data subject (CJEU C-300/21 [para. 37]; cf. 6 Ob 94/23a).6. The CJEU's judgment of 4 May 2023, C-300/21, clarifies that the mere infringement of the GDPR provisions is not sufficient in itself to give rise to a claim for damages. The data subject affected by an infringement of the GDPR is not relieved of their burden of proof regarding the damage (CJEU C-300/21 [para. 50]). In the absence of relevant provisions of EU law, the structure of legal proceedings and the determination of the criteria for assessing the amount of damages are governed by national law, taking into account the principles of equivalence and effectiveness (CJEU C-300/21 [para. 54]). The CJEU also requires, for a claim for damages to exist, that there be a causal link between the infringement in question and the damage suffered by the data subject (CJEU C-300/21 [para. 37]; compare 6 Ob 94/23a). 7. The findings of the court of first instance do not establish any damage to the plaintiff resulting from the failure to notify the data security incident. The plaintiff's frustration—it can remain undecided whether this even constitutes damage within the meaning of Article 82 GDPR—therefore related to the data security incident itself, and not to the failure to notify. However, if there is no causal link between the infringer's conduct and the occurrence of the alleged damage, no compensation can be awarded (see RS0022664). The plaintiff's claim for damages thus fails due to the lack of causality between the breach of the notification obligation and his frustration. Therefore, it is unnecessary to address the other prerequisites for a claim for damages. 7. The findings of the court of first instance do not establish any damage to the plaintiff resulting from the failure to notify the data security incident. The plaintiff's frustration—it can remain undecided whether this even constitutes damage within the meaning of Article 82 GDPR—therefore related to the data security incident itself, and not to the failure to notify. However, if there is no causal link between the wrongdoer's conduct and the occurrence of the alleged damage, no compensation is payable (see RS0022664). The plaintiff's claim for damages thus fails due to the lack of causality between the breach of the notification obligation and his frustration. Therefore, it is unnecessary to address the other prerequisites for a claim for damages. 8. The appeal was therefore dismissed. 9. The decision regarding the costs of the response to the appeal is based on Sections 41 and 50 of the German Code of Civil Procedure (ZPO). The basis for calculation is the interest in the appeal (EUR 200). 9. The decision regarding the costs of the response to the appeal is based on Sections 41 and 50 of the Code of Civil Procedure. The basis for calculation is the interest in the appeal (EUR 200). 10. The appeal on points of law is inadmissible if the subject matter of the dispute decided by the court of appeal (the subject matter of the decision) – as in this case – does not exceed EUR 5,000 in total in money or money's worth (Section 502, Paragraph 2 of the Code of Civil Procedure). 10. The appeal on points of law is inadmissible if the subject matter of the dispute decided by the court of appeal (the subject matter of the decision) – as in this case – does not exceed EUR 5,000 in total in money or money's worth (Section 502, Paragraph 2 of the Code of Civil Procedure).




