complainant (controller) – Court Ruling (Austria, 2025)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
An Austrian data controller failed to fully respond to a user's request for access to their personal data. The ruling emphasizes the importance of providing complete information to users about their data. Businesses must be careful to comply with access requests to avoid complaints.
What happened
The data controller did not provide complete information when a user requested access to their data.
Who was affected
The user who requested their personal data was affected by the incomplete response.
What the authority found
The Datenschutzbehörde ruled that the controller violated the user's right to access by not providing all necessary information.
Why this matters
This case serves as a reminder for businesses to be thorough when responding to data access requests, as incomplete responses can lead to regulatory scrutiny.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
On 7 April 2021, the data subject requested access to their data under Article 15 GDPR. The controller replied on 12 April 2021 and provided further information on 27 May 2021 after the data subject made a further enquiry. As the controller's privacy policy listed significantly more data being collected, the data subject lodged a complaint with the Austrian DPA (DSB) on 13 July 2021. They argued that the data provided and its sources were incomplete. On 03 January 2022, the DPA partly upheld the complaint and ruled that the controller violated the right of access by not providing information pursuant to Article 15(1)(h) GDPR, as the calculation of the creditworthiness constitutes profiling under Article 4(4) GDPR. On 09 February 2022, the controller appealed, stating that its calculations were not based on automated processing and that providing further information would reveal trade secrets. The proceedings were stayed until the CJEU's preliminary ruling in [https://infocuria.curia.europa.eu/tabs/document/C/2022/C-0203-22-00000000RP-01-P-01/ARRET/295841-EN-1-html 'Dun & Bradstreet Austria' (C‑203/22)]. By letter of 15 May 2025, the court resumed the case. During the entire proceedings, the controller gradually provided further information on the personal data being processed and the calculation of the credit score. Hence, the following data is used to calculate the credit score: Name, age, gender, address, macroeconomic statistical parameters, payment history. The calculation itself is performed automatically using an algorithm and the same formula unless the controller's customers order a different score model. First the court ruled that the controller had an obligation to provide information under Article 15(1)(h) GDPR, as all three cumulative requirements pursuant to Article 22 GDPR were stated to be met: A credit score was calculated ('decision'), which predicts various aspects of the data subject, including their economic situation, for example. This con
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (0)
No other cases found for complainant (controller) in AT
This is the only recorded case for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. complainant (controller) - Austria (2025). Retrieved from cookiefines.eu
Last updated: