DSB (DPA) – Court Ruling (Austria, 2023)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Austria's data protection authority confirmed that a government controller violated a person's right to confidentiality by sharing personal information without permission. The authority found that the controller's actions were not justified. This ruling stresses the importance of protecting personal data, especially in administrative processes.
What happened
A government controller shared unredacted personal data in an email without the individual's consent.
Who was affected
The person whose personal data was shared without their consent.
What the authority found
The authority ruled that the controller violated the individual's right to confidentiality under data protection rules.
Why this matters
This ruling serves as a reminder for organizations to handle personal data carefully and underscores the need for proper consent when sharing information.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
On 28.11.2019, the data subject received their regional government's administrative decision regarding the recognition of previous qualifications and their experience in becoming a mountain sports guide. On 12.02.2020, the controller attempted to challenge the decision and sent an email to further recipients besides the affected authority. They expressed their concerns and included unredacted parts of the administrative decision. On 18.12.2020. the data subject lodged a complaint with the Austrian DPA (DSB) regarding the violation of their right to confidentiality under [https://ris.bka.gv.at/eli/bgbl/i/1999/165/A1P1/NOR40139563?Abfrage=Bundesnormen&Kundmachungsorgan=&Index=&Titel=DSG&Gesetzesnummer=&VonArtikel=&BisArtikel=&VonParagraf=1&BisParagraf=&VonAnlage=&BisAnlage=&Typ=&Kundmachungsnummer=&Unterzeichnungsdatum=&FassungVom=13.07.2026&VonInkrafttretedatum=&BisInkrafttretedatum=&VonAusserkrafttretedatum=&BisAusserkrafttretedatum=&NormabschnittnummerKombination=Und&ImRisSeitVonDatum=&ImRisSeitBisDatum=&ImRisSeit=Undefined&ResultPageSize=100&Suchworte=&Position=1&SkipToDocumentPage=true&ResultFunctionToken=b2435486-6818-41ec-a0f8-4150a50eb221 §1(1) DSG]. On 09.12.2021, the DPA partly confirmed the data subject's complaint, stating that the the email contained personal data of the data subject under Article 4(1) GDPR. The controller subsequently appealed against the DPA's decision on 05.01.2022, arguing that their actions were justified by legitimate interests in safeguarding professional standards and public safety pursuant to Article 6(1)(f) GDPR. Furthermore, only parts of the administrative decision were cited, thereby adhering to the principle of data minimisation under Article 5(1)(c) GDPR. First, the court held that the data subject had neither consented to the processing of their personal data nor was the processing in their vital interest under [https://ris.bka.gv.at/eli/bgbl/i/1999/165/A1P1/NOR40139563?Abfrage=Bundesnormen&Kundmachungsorgan=&Index=&Tit
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (3)
Other cases involving DSB (DPA) in AT
Court Ruling
Details
About this data
Cite as: Cookie Fines. DSB (DPA) - Austria (2023). Retrieved from cookiefines.eu
Last updated: