VwGH - Ra 2024/04/0375
| VwGH - Ra 2024/04/0375 | |
|---|---|
| Court: | VwGH (Austria) |
| Jurisdiction: | Austria |
| Relevant Law: | Article 4(7) GDPR Article 26(1) GDPR |
| Decided: | 14.04.2026 |
| Published: | 12.05.2026 |
| Parties: | Controller (subsidiary of parent company) Parent company DSB (data protection authority) |
| National Case Number/Name: | Ra 2024/04/0375 |
| European Case Law Identifier: | ECLI:AT:VWGH:2026:RA2024040375.L00 |
| Appeal from: | BVwG (Austria) W176 2249328-1/7E |
| Appeal to: | Unknown |
| Original Language(s): | German |
| Original Source: | RIS (in German) |
| Initial Contributor: | Ava Lang |
The Administrative Supreme Court held that the parent company of the provider of a loyalty program is not a joint controller with its subsidiary since merely establishing and financing a subsidiary does not automatically create joint controllership.
English Summary
Facts
The parent company operated a customer loyalty programme through its subsidiary, the controller, starting 2 May 2019. The controller managed the operational business and processed personal data of registered customers, including profiling activities based on customer data.
The controller designed the profiling consent forms, determined the data processing activities, prepared the privacy documentation, implemented technical and organisational measures, and established GDPR compliance processes. The parent company only financed the controller.
On 12 October 2021, the Austrian DPA fined the parent company €8,000,000. The DPA considered the parent company and the subsidiary to be joint controllers under Article 26 GDPR. It held that the consent forms used for profiling did not meet the requirements for valid consent under Article 4(11) and Article 7 GDPR. It further held that the profiling lacked a valid legal basis under Article 6(1) GDPR because the consent was invalid.
The parent company appealed. The Federal Administrative Court annulled the fine and terminated the proceedings. The DPA then appealed to the Austrian Supreme Administrative Court.
Holding
First, the court referred to the case law of the Court of Justice of the European Union on the concept of controller under Article 4(7) GDPR and joint controllership under Article 26 GDPR. The court noted that a party qualifies as a controller only if it actually influences the purposes and means of the relevant processing operations. Merely establishing and financing a subsidiary did not automatically create joint controllership, as the parent company didn't exercise actual influence over the specific processing activities. As a result, the parent company was not a joint controller under Article 26 GDPR.
Second, the court also rejected the DPA’s reliance on CJEU judgments such as Jehovan todistajat, Fashion ID and others, as those cases involved direct influence over concrete processing operations, which was absent here.
Finally, the court rejected the DPA’s appeal.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the German original. Please refer to the German original for more details.
Subject The Administrative Court, composed of Presiding Judge Dr. Kleiser, Judges Mag. Hainz-Sator and Dr. Funk-Leisch, and Clerk Dr. Zeitfogel, has decided on the appeal filed by the Data Protection Authority against the decision of the Federal Administrative Court of May 28, 2024, W176 2249328-1/7E, concerning a data protection matter (intervening party: R AG, represented by WOLF THEISS Rechtsanwälte GmbH & Co KG in Vienna; further party: Federal Minister of Justice), as follows: Ruling The appeal is dismissed. The Federal Government shall reimburse the intervening party for expenses in the amount of €1,106.40 within 14 days, failing which enforcement proceedings will be initiated. Reasons 1. By penalty order of the Data Protection Authority dated 12 October 2021, R AG (jointly involved party) was found to be the (joint) data controller within the meaning of Art. 4(7) and Art. 26 GDPR, as the form used from 2 May 2019 onwards to obtain declarations of consent for the processing of personal data from persons registered at [B Club] for the purpose of profiling, which did not comply with the data protection requirements for effective consent pursuant to Art. 4(11) in conjunction with Art. 5(1)(a) and Art. 7 GDPR. As a result, the co-party committed administrative offenses pursuant to Art. 5 para. 1 lit. a in conjunction with Art. 7 para. 2 in conjunction with Art. 83 para. 5 lit. a GDPR (Point I.).1. By penalty order of the Data Protection Authority of 12 October 2021, R AG (co-party) was charged as the (joint) controller under data protection law within the meaning of Article 4, point 7 and Article 26 GDPR, with the forms used from 2 May 2019 onwards to obtain declarations of consent for the processing of personal data from persons registered at [B Club] for the purpose of profiling not complying with the data protection requirements for effective consent pursuant to Article 4, point 11, in conjunction with Article 5, paragraph 1, letter a and Article 7 GDPR. As a result, the respondent committed administrative offenses under Article 5(1)(a) in conjunction with Article 7(2) in conjunction with Article 83(5)(a) of the GDPR (Judgment Roman numeral I). 2. Furthermore, the respondent was accused of the fact that, as a consequence of the invalid consents, the processing of personal data of persons registered at [B Club] for profiling purposes from May 2, 2019, until at least January 31, 2021, could not have been based on either a valid declaration of consent or on any of the other legal bases exhaustively defined in Article 6(1) of the GDPR. As a result, the co-defendant committed administrative offenses pursuant to Art. 5 para. 1 lit. a in conjunction with Art. 6 para. 1 in conjunction with Art. 83 para. 5 lit. a GDPR. The criminal, unlawful, and culpable conduct of the board members of the co-defendant named in the penalty order is attributed to the co-defendant as the accused legal entity and (joint) controller under data protection law within the meaning of Article 4(7) and Article 26 GDPR. Furthermore, the co-defendant was accused of ensuring that, as a consequence of the legally invalid consents, the processing of personal data of persons registered at [B Club] for profiling purposes from May 2, 2019, until at least January 31, 2021, could not have been based on a legally valid declaration of consent or on any of the other grounds for processing exhaustively defined in Article 6(1) GDPR. The co-respondent thereby committed administrative offenses pursuant to Article 5(1)(a) in conjunction with Article 6(1) in conjunction with Article 83(5)(a) of the GDPR. The unlawful and culpable conduct of the co-respondent's board members named in the penalty order is attributed to the co-respondent as the accused legal entity and (joint) data controller within the meaning of Article 4(7) and Article 26 of the GDPR. 3. A fine of €8,000,000 was imposed on the co-respondent pursuant to Section 30(1) and (2) of the Data Protection Act (DSG) in conjunction with Article 83(5)(a) of the GDPR. Furthermore, a contribution to the costs of the criminal proceedings in the amount of €800,000 was imposed. A fine of €8,000,000 was imposed on the co-defendant pursuant to Section 30, paragraphs 1 and 2, of the Data Protection Act (DSG) in conjunction with Article 83, paragraph 5, letter a, of the GDPR. Furthermore, a contribution to the costs of the criminal proceedings in the amount of €800,000 was imposed. 4 2.1. The Administrative Court upheld the co-defendant's appeal against this penalty order in the decision challenged in the appeal proceedings, set aside the contested penalty order, and discontinued the administrative penalty proceedings. The Administrative Court declared the appeal inadmissible. 5 2.2. In its account of the administrative proceedings, the Administrative Court noted that the respondent authority had initiated administrative penalty proceedings against U GmbH, the designated data controller of the [B Club], as part of an ex officio review procedure, and concluded these proceedings with a penalty order dated July 26, 2021. The Administrative Court determined that the co-respondent was the sole shareholder of U GmbH through R Dienstleistungs-GmbH. The business purpose of U GmbH was the operation of a customer loyalty program, in particular through discounts and support services. This program was the [B Club]. The managing directors of U GmbH were appointed by its parent company, R Dienstleistungs-GmbH. There were no personnel overlaps in the management bodies of the co-respondent and R Dienstleistungs-GmbH. The business purpose of the co-participant includes, among other things, holding and managing investments in trading companies, tourism companies, and companies in the advertising and retail services sector. 6. During the concept phase from 2017 until U GmbH commenced operations in May 2019, the management board [of the co-participant] defined the strategic direction of the customer loyalty program, according to which a proprietary multi-partner system was to be created. Following the end of the concept phase, the management of U GmbH carried out the concrete implementation and design of the customer loyalty program. The co-participant and its management board members were not involved in this process. The implementation phase encompassed, in particular, the concrete design of data processing activities within the framework of the customer loyalty program, the drafting of contracts with customers and the general terms and conditions, the declaration of consent for profiling, as well as the preparation of the necessary documents and the establishment of processes to comply with data protection regulations (for example, privacy policy, record of processing activities, technical and organizational measures pursuant to Art. 43 GDPR). U GmbH used external and internal consultants for this purpose. The internal consultants included the group data protection officer of the co-participating company, who has been in office since 2018 and is employed by R Dienstleistungs-GmbH. During the concept phase from 2017 until U GmbH began operations in May 2019, the management board [of the co-participating company] defined the strategic direction of the customer loyalty program, according to which a proprietary multi-partner system was to be created. Following the completion of the concept phase, the management of U GmbH was responsible for the concrete implementation and design of the customer loyalty program. The co-participant and its board members were not involved in this process. The implementation phase encompassed, in particular, the specific design of the data processing activities within the framework of the customer loyalty program, the drafting of the contracts with customers and the general terms and conditions, the declaration of consent for profiling, as well as the preparation of the necessary documentation and the establishment of processes to comply with data protection regulations (for example, the privacy policy, the record of processing activities, and technical and organizational measures pursuant to Article 43 of the GDPR). U GmbH utilized external and internal consultants for this purpose. Among the internal consultants was the co-participant's group data protection officer, who has been in office since 2018 and is employed by R Dienstleistungs-GmbH. 7. On May 2, 2019, U GmbH commenced the operational business of the customer loyalty program and the associated data processing activities. This included creating profiles from the various data sets collected from customers participating in the loyalty program. 8. 2.3. In its legal reasoning, the Administrative Court stated, insofar as relevant here, that the principles, prohibitions, and obligations stipulated in the GDPR are directed in particular at "controllers." According to Recital 74 of the GDPR, their responsibility and liability extend to any processing of personal data carried out by them or on their behalf. Within this framework, they must not only take appropriate and effective measures but also be able to demonstrate that their processing activities comply with the GDPR and that the measures they have taken to achieve this compliance are also effective. The controller is the addressee of claims from the data subject and is considered the contact point for measures taken by the supervisory authority. 9. The role of the data controller is defined by three characteristics: (1) any natural or legal person, public authority, agency or other body (personal aspect), (2) who, alone or jointly with others (pluralistic control), (3) decides on the purposes and means of processing personal data (decision-making function). 10. From the fact that the respondent made the strategic decision to establish its own multi-partner customer loyalty program and, for this purpose, founded U GmbH via R Dienstleistungs GmbH, and provided U GmbH – again with the assistance of R Dienstleistungs GmbH – with the financial and human resources necessary to operate the [B Club] customer loyalty program, the respondent authority derived joint data protection responsibility between the respondent and U GmbH. ``` 11. The appeal disputes this, in particular, on the grounds that there was no joint decision on the purposes and means of data processing. The co-respondent was not involved in the implementation of the customer loyalty program. 12. The Administrative Court's legal opinion is correct. A cooperative collaboration between two actors, as required by the case law of the Court of Justice of the European Union (CJEU), is not apparent in the present case. 13. Insofar as the respondent authority argues in this context that the present case is similar to that of the CJEU judgment of 10 July 2018, C-25/17, Jehovan todistajat, it must be pointed out that this case differs from the present one. In the Jehovah's Deaths case, a door-to-door preaching activity, during which the data was collected, was organized and coordinated by a religious community. The other party involved, however, had not been involved in the relevant processes since the conclusion of the planning phase. No deliberate influence on specific data processing purposes and means could be identified. 14. The same applies to the judgments of the CJEU of 29 July 2019, C-40/17, Fashion ID, concerning the integration of a social plug-in by the operators of a website, and of 5 June 2018, C-210/16, Wirtschaftsakademie Schleswig-Holstein GmbH, cited by the respondent authority. These cases also show no parallels to the present situation. Moreover, the CJEU, in its judgment of 7 March 2024, C-604/22, IAB Europe, emphasized that for joint controllership to exist, a person must have actually exerted influence on determining the purposes and methods of processing or further processing data. 15. Against this background, the co-respondent cannot be considered a controller for the data processing on which the allegation is based. Its activities were limited to the establishment of U GmbH and the strategic decision during the concept phase to establish its own multi-partner customer loyalty program. Insofar as the respondent authority states that the co-respondent "did not carry out or initiate any management or control activities with regard to U GmbH" from the commencement of operations, it demonstrates precisely the absence of a deliberate and conscious collaboration between the parties to make the essential decisions regarding the purposes and means of data processing. However, this is a prerequisite for establishing joint responsibility. 16. 3. The present official appeal is directed against this decision. The Administrative Court initiated the preliminary proceedings. The co-respondent filed a response to the appeal, requesting that the appeal be returned to the lower court or, alternatively, dismissed, and that the costs of the written submissions be awarded. 17. 4. Pursuant to Article 133(4) of the Federal Constitutional Law, an appeal against a decision of the Administrative Court is admissible if it depends on the resolution of a legal question of fundamental importance, in particular because the decision deviates from the case law of the Administrative Court, such case law is lacking, or the legal question to be resolved is not answered uniformly in the existing case law of the Administrative Court. According to Article 133, paragraph 4, of the Austrian Federal Constitutional Law (B-VG), an appeal against a decision of the Administrative Court is admissible if it depends on the resolution of a legal question of fundamental importance, in particular because the decision deviates from the case law of the Administrative Court of Cassation, such case law is lacking, or the legal question to be resolved is not answered uniformly in the existing case law of the Administrative Court of Cassation. 18. According to Section 34, paragraph 1, of the Administrative Court Act (VwGG), appeals that are not admissible due to the absence of the prerequisites of Article 133, paragraph 4, of the Austrian Federal Constitutional Law (B-VG) are to be dismissed by decision without further proceedings. According to Section 34, paragraph 1, of the Administrative Court Act (VwGG), appeals that are not admissible due to the absence of the prerequisites of Article 133, paragraph 4, of the Austrian Federal Constitutional Law (B-VG) are to be dismissed by decision without further proceedings. 18. 19. Pursuant to Section 34 Paragraph 1a of the Administrative Court Act (VwGG), the Administrative Court is not bound by the ruling of the Administrative Court pursuant to Section 25a Paragraph 1 of the VwGG when assessing the admissibility of an appeal on points of law pursuant to Article 133 Paragraph 4 of the Federal Constitutional Law (B-VG). The Administrative Court must review the admissibility of an extraordinary appeal on points of law pursuant to Article 133 Paragraph 4 of the B-VG within the framework of the grounds presented in the appeal on points of law (Section 28 Paragraph 3 of the VwGG). Pursuant to Section 34 Paragraph 1a of the VwGG, the Administrative Court is not bound by the ruling of the Administrative Court pursuant to Section 25a Paragraph 1 of the VwGG when assessing the admissibility of an appeal on points of law pursuant to Article 133 Paragraph 4 of the B-VG. The Administrative Court must review the admissibility of an extraordinary appeal pursuant to Article 133, paragraph 4, of the Austrian Federal Constitutional Law (B-VG) within the framework of the grounds presented in the appeal (Section 28, paragraph 3, of the Administrative Court Act (VwGG)). 20 5.1. In support of its admissibility, the appeal argues that there is a lack of case law from the Administrative Court on the question of whether the establishment, financing, and promotion of a customer loyalty program for group-owned retail companies constitutes sufficient influence on data processing and establishes liability, even if a company was no longer operationally involved during the implementation phase. Furthermore, the Administrative Court's ruling is inconsistent with the recent case law of the Court of Justice of the European Union (CJEU) (reference to CJEU 5 December 2023, C-683/21, Nacionalinis visuomenės sveikatos centras). Had the Administrative Court taken into account the cited case law of the CJEU, it would have concluded that the co-respondent was responsible for the data processing relevant here from a data protection perspective. 21 5.2. Regarding the definition of the controller under Article 4(7) GDPR – in the context of Article 26 GDPR – the CJEU has held that any natural or legal person who, for their own benefit, influences the processing of personal data and thus participates in the decision on the purposes and means of that processing may be regarded as a controller of that processing (CJEU 2 December 2025, C-492/23, Russmedia Digital SRL, para. 58; 7 March 2024, C-604/22, IAB Europe, para. 57; 5 December 2023, C-683/21, Nacionalinis visuomenės sveikatos centras, para. 30; 10 July 2018, C-25/17).5.2. The CJEU, in defining the controller under Article 4(7) GDPR – in the context of Article 26 GDPR – has held that any natural or legal person who, acting in their own interest, influences the processing of personal data and thus participates in the decision on the purposes and means of that processing may be regarded as a controller of that processing (CJEU 2 December 2025, C-492/23, Russmedia Digital SRL, para. 58; 7 March 2024, C-604/22, IAB Europe, para. 57; 5 December 2023, C-683/21, Nacionalinis visuomenės sveikatos centras, para. 30; 10 July 2018, C-25/17). CJEU 2 December 2025, C-492/23, Russmedia Digital SRL, para. 58; 7 March 2024, C-604/22, IAB Europe, para. 57; 5 December 2023, C-683/21, Nacionalinis visuomenės sveikatos centras, para. 30; 10 July 2018, C-25/17. 22. In its judgment of 29 July 2019, C-40/17, Fashion ID, paragraph 74, the CJEU, in assessing the position of the controller within the meaning of Article 2(d) of Directive 95/46, held that, without prejudice to any civil liability provided for in this respect under national law, a natural or legal person cannot be regarded as responsible within the meaning of that provision for upstream or downstream operations in the processing chain for which it does not determine the purposes or means (see also VwGH 27 March 2025, Ro 2022/04/0023, paragraph 22). Responsibility is limited to data processing operations for which the data subject actually determines the purposes and means (see ECJ 29.7.2019, C-40/17, Fashion ID, para. 85; see also Austrian Administrative Court [VwGH] 27.6.2023, Ro 2023/04/0013-0015, para. 22). In its judgment of 29 July 2019, C-40/17, Fashion ID, in paragraph 74, the ECJ, in assessing the position of the controller within the meaning of Article 2(d) of Directive 95/46, stated that, without prejudice to any civil liability provided for in this respect under national law, a natural or legal person cannot be considered responsible within the meaning of that provision for upstream or downstream operations in the processing chain for which they do not determine either the purposes or the means (see also [reference to relevant case law]). (VwGH 27.3.2025, Ro 2022/04/0023, para. 22). Responsibility is limited to data processing operations for which the data subject actually decides on the purposes and means (cf. ECJ 29.7.2019, C-40/17, Fashion ID, para. 85; cf. VwGH 27.6.2023, Ro 2023/04/0013-0015, para. 22). 23. Participation in the decision on these purposes and means can take various forms and may result from a joint decision by two or more bodies or from concurring decisions that complement each other in such a way that each of them has a concrete effect on the determination of the purposes and means of processing (see ECJ 7 March 2024, C-604/22, IAB Europe, paragraph 59; 5 December 2023, C-683/21, Nacionalinis visuomenės sveikatos centras, paragraph 43). Participation in the decision on these purposes and means can take various forms and may result from a joint decision by two or more bodies or from concurring decisions that complement each other in such a way that each of them has a concrete effect on the determination of the purposes and means of processing (see ECJ 7 March 2024, C-604/22). IAB Europe, para. 59; 5 December 2023, C-683/21, Nacionalinis visuomenės sveikatos centras, para. 43). 24. In order to determine whether the co-respondent can be considered a controller within the meaning of Article 4(7) – or joint controllers pursuant to Article 26(1) GDPR – it is necessary, according to the case law of the Administrative Court, which refers to the case law of the Court of Justice of the European Union, to examine whether, taking into account the specific circumstances of the present case, it has exerted influence on the processing of personal data in question out of its own interest and – possibly jointly with others – has determined the purposes and means of the processing in question. It is therefore necessary to clarify which natural or legal person made the decision regarding both the purpose – the “why” – and the means – “how” – of the data processing (see VwGH 27.3.2025, Ro 2022/04/0023, para. 31). In order to determine whether the co-respondent can be considered a controller within the meaning of Article 4(7) – or joint controllers pursuant to Article 26(1) GDPR – the case law of the Administrative Court, which refers to the case law of the CJEU, requires an examination of whether, taking into account the specific circumstances of the present case, it exerted influence on the processing of personal data in question out of self-interest and – possibly jointly with others – determined the purposes and means of the processing in question. It is therefore necessary to clarify which natural or legal person made the decision regarding both the purpose – the “why” – and the means – “how” – of the data processing (see VwGH 27.3.2025, Ro 2022/04/0023, para. 31). Contrary to the appellant's assertions, the criteria for assessing joint controllership under Article 26 GDPR based on the influence of the persons involved on the data processing have been clarified by the cited case law of the CJEU and the case law of the Administrative Court referring to it. Contrary to the appellant's assertions, the criteria for assessing joint controllership under Article 26 GDPR based on the influence of the persons involved on the data processing have been clarified by the cited case law of the CJEU and the case law of the Administrative Court referring to it. 26 5.3. Insofar as the appellant argues that the Administrative Court's decision contradicts the judgment of the CJEU of 5 December 2023, C-683/21, Nacionalinis visuomenės sveikatos centras, it must be pointed out that, according to the Administrative Court's findings, the co-respondent in the present appeal – unlike in the original case leading to the CJEU's judgment of 5 December 2023 – did not commission U GmbH to develop a specific IT application for carrying out the data processing. The appellant does not claim otherwise. 27 5.4. A legal assessment made in an individual case can only justify the admissibility of an appeal if this is necessary for reasons of legal certainty due to a gross misjudgment of the case-specific circumstances by the Administrative Court (see, e.g., VwGH 18.12.2025, Ro 2025/04/0027, para. 17; 1.8.2025, Ra 2023/04/0058, para. 21, with further references). 5.4. A legal assessment made in an individual case can only justify the admissibility of an appeal if this is necessary for reasons of legal certainty due to a gross misjudgment of the case-specific circumstances by the Administrative Court (see, e.g., VwGH 18.12.2025, Ro 2025/04/0027, para. 17). 1.8.2025, Ra 2023/04/0058, para. 21, with further references). 28. The Administrative Court explained the responsibility of the co-respondent, whose activities were limited to the founding of U GmbH and the strategic decision during the concept phase to establish a separate multi-partner customer loyalty program. Insofar as the respondent authority stated that the co-respondent had "not undertaken or initiated any management or control activities with regard to [U GmbH]" since the commencement of operations, this demonstrated precisely the lack of a deliberate and conscious collaboration between the parties to make the essential decisions regarding the purposes and means of data processing. This, however, is a prerequisite for establishing joint responsibility. 29. The appeal does not contest the findings of fact made by the Administrative Court that are essential to the decision. The appellant's submissions do not demonstrate that the Administrative Court made a gross error in its assessment that the co-respondent had no influence on the purposes and means of the data processing carried out by U GmbH after the conclusion of the strategic concept phase and should not be considered a joint controller under Article 26 GDPR. The appeal does not contest the findings of fact made by the Administrative Court that are essential to the decision. Nor does the appellant's submissions demonstrate that the Administrative Court made a gross error in its assessment that the co-respondent had no influence on the purposes and means of the data processing carried out by U GmbH after the conclusion of the strategic concept phase and should not be considered a joint controller under Article 26 GDPR. The appeal does not contest the findings of fact made by the Administrative Court that are essential to the decision. 30. 6. Since the questions of EU law to be clarified in the present case have already been clarified by the established case law of the CJEU cited above, a referral to the CJEU under Article 267 TFEU was not necessary (see, regarding the obligation of supreme courts to state reasons, CJEU 24 March 2026, C-767/23, Remling). Since the questions of EU law to be clarified in the present case have already been clarified by the established case law of the CJEU cited above, a referral to the CJEU under Article 267 TFEU was not necessary (see, regarding the obligation of supreme courts to state reasons, CJEU 24 March 2026, C-767/23, Remling). 31. 7. The appeal does not raise any legal questions of fundamental importance within the meaning of Article 133, paragraph 4, of the Austrian Federal Constitutional Law (B-VG). The appeal was therefore to be dismissed pursuant to Section 34, paragraphs 1 and 3, of the Austrian Administrative Court Act (VwGG). 7. The appeal does not raise any legal questions of fundamental importance within the meaning of Article 133, paragraph 4, of the Austrian Federal Constitutional Law (B-VG). The appeal was therefore to be dismissed pursuant to Section 34, paragraphs 1 and 3, of the Austrian Administrative Court Act (VwGG). 32. The decision on costs is based on Sections 47 et seq., in particular Section 51, of the Administrative Court Act (VwGG) in conjunction with the Administrative Court's Expenditure Reimbursement Ordinance 2014. Vienna, April 14, 2026




