unknown data subject – Court Ruling (Austria, 2020)

Court Ruling
Datenschutzbehörde27 May 2020Austria
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A court ruled that an electronic signature is enough for a person to access their data from a public authority. The authority had asked for a physical ID, but the court decided that the electronic signature was sufficient. This case shows that businesses must accept valid forms of identification for data requests.

What happened

The court upheld a decision that an electronic signature was sufficient for a data access request.

Who was affected

A person who requested access to their personal data from an Austrian municipality.

What the authority found

The court ruled that the municipality could not require additional identification beyond the electronic signature for processing the access request.

Why this matters

This case sets a precedent for how public authorities should handle data access requests. Businesses should be aware that they must accept valid electronic identification methods.

GDPR Articles Cited

AI-verified

Art. 15(GDPR)
Art. 4(1) GDPR
Art. 4(2) GDPR
Art. 57(GDPR)
Art. 58(GDPR)
Art. 11(2) GDPR
Art. 12(6) GDPR
View original scraped data
Art. 4(1) GDPR
Art. 4(2) GDPR
Art. 11(2) GDPR
Art. 12(6) GDPR
Art. 15(GDPR)
Art. 57(GDPR)
Art. 58(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

§ 3(2) Signatur- und Vertrauensdienstegesetz (SVG)
§ 4(1) Signatur- und Vertrauensdienstegesetz (SVG)
§ 8(1) Signatur- und Vertrauensdienstegesetz (SVG)
§ 24(5) Datenschutzgesetz (DSG)
Decision AuthorityBVwG
Reviewed AuthorityDSB (Austria)
Source verified 20 March 2026
national law identified
authority corrected
Full Legal Summary
Detailed

On 19.02.2019, the data subject sent an access request under Article 15 GDPR to a controller (an Austrian municipality). The request was signed using an electronic signature. The controller did not consider the electronic signature a sufficient form of identification and required the data subject to produce an ID card under Article 12(6) GDPR. As the data subject did not do so, the controller refused to handle the access request under Article 11(2) GDPR. The data subject filed a complaint with the DSB, which shared the data subject's view and held that the electronic signature was a sufficient form of identification for an access request. The controller filed an complaint with the BVwG against the decision of the DSB. Is an electronic signature under § 4(1) SVG and Article 3(10) eIDAS Regulation sufficient to identify a data subject regarding an access request? The BVwG upheld the decision of the DSB. It ruled that the controller had never stated the reasons for its doubts concerning the identity of the data subject. The full name, address and e-mail address of the data subject were known to the controller and also used in the correspondence with the data subject. In addition, the data subject had put a qualified electronic signature on its access request. Hence, it was unclear, why the controller should have any doubts on the data subjects identity. Moreover, the BVwG shared the view of the data subject and the DSB that an electronic signature under § 4(1) SVG and Article 3(10) eIDAS Regulation a sufficient form of identification. The provision of an ID card is not the only mean of verifying a data subject's identity. Lastly, the BVWG held that § 24 Abs. 5 DSG which would bar the DSB (and BVwG/VwGH) from ordering a public entity to comply with the data subject's requests does not apply due to the primacy of application of Article 58(2)(c) GDPR. Consequently, the BVwG ordered the controller to comply with the data subject's request under Article 15 GDPR.

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Details

Ruling Date

27 May 2020

Authority

Datenschutzbehörde

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. unknown data subject - Austria (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: