Court case W292 2342582-1/13E – Court Ruling (Austria, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A court case in Austria involved a person who hired an association to check for data protection violations. This matters because it raises questions about how complaints can be filed and who can represent individuals in such cases. It shows that people need to be careful about how they seek help with data issues.
What happened
A person hired an association to search for possible data protection violations and file complaints on their behalf.
Who was affected
The individual who believed their data might be processed unlawfully was affected.
What the authority found
The court ruled on the validity of the association's actions in filing the complaint without explicit consent from the individual.
Why this matters
This case sets a precedent for how individuals can seek help with data protection issues. It encourages people to be cautious about who represents them in legal matters.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
A data subject hired an association whose business model is to automatically search for possible data protection violations and filing complaints or lawsuits on behalf of data subjects with the financial aid of litigation funders. The agreement between the data subject and the association foresees that the data subject receives 70% of possible profits coming from a favourable judicial or administrative decision and 30% of the profits go to the litigation funders. In the agreement, the association claims their offer would generate profit without any risk for their customers. The association made an access request and filed a complaint via a lawyer on behalf of the data subject. The telecommunication provider charged the data subject with a service fee the parties have not agreed upon. The access request concerned invoices of a telecommunication provider that the data subject was in a contractual relationship with and the service fee was indicated on the invoices. On the initiative of the association, not the data subject, the association made an access request, claiming the service fee let the data subject to believe that the telecommunication provider might possess documents concerning the data subject without their knowledge and might process their personal data unlawfully. The data subject already had access to the invoices through the telecommunication provider’s online portal for customers. The data subject did not, or did not remember, to explicitly mandate the association to lodge the access request. The lawyer hired by the association filed a complaint on behalf of the data subject because of a possible violation of Article 15 GDPR. The grounds of the violation were illustrated only rudimentary in the complaint. The DPA refused to act on the request on the basis of Article 57(4) GDPR because it held that the data subject lodged the complaint not for reasons of the protection of personal data. The association filed a total of more than 900 complaints wit
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (0)
No other cases found for Court case W292 2342582-1/13E in AT
This is the only recorded case for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Court case W292 2342582-1/13E - Austria (2026). Retrieved from cookiefines.eu
Last updated: