unnkown individual (controller and perpetrator) – €600 Fine (Austria, 2021)

€600Datenschutzbehörde5 August 2021Austria
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

An individual in Austria was fined for sharing a medical assessment without a valid legal reason. This is important because it shows that even if you think sharing information is justified, you must have a legal basis to do so. The case highlights the need for explicit consent when dealing with sensitive health data.

What happened

Person B shared a medical assessment of Person A with a municipality without a valid legal basis.

Who was affected

Person A, whose health information was shared with the municipality.

What the authority found

The Austrian DPA found no legal basis for sharing the health data, as it was not necessary for legal claims and lacked the person's consent.

Why this matters

This ruling underscores the importance of having a legal basis for sharing sensitive data, especially health information. It serves as a cautionary tale for individuals who might assume they can share such data without explicit consent.

GDPR Articles Cited

Art. 4(2) GDPR
Art. 4(7) GDPR
Art. 5(1)(a) GDPR
Art. 5(1)(b) GDPR
Art. 5(1)(f) GDPR
Art. 9(1) GDPR
Art. 9(2) GDPR
Art. 9(2)(f) GDPR
Art. 4(10) GDPR
Art. 4(15) GDPR
Art. 83(1) GDPR
Art. 83(2)(b) GDPR
Art. 83(5)(a) GDPR

National Law Articles

§ 1489 General Civil Code (Allgemeines Bürgerliches Gesetzbuch - ABGB)
Full Legal Summary
Detailed

Person A is employed at a municipality and has been on sick leave for several weeks in 2013 and 2014. In September 2014, the municipality concluded that Person A's sickness had been caused by another individual (Person B) who was then asked for damages. In another proceeding between Person A and Person B, the latter obtained a medical assessment concerning Person A's state of health. According to Person B's view, this document would have proved the municipality's claim wrong. The document was therefore shared with the municipality (even though no further steps had been taken following the initial claim). For this reasons, Person B is considered controller of Person A's personal data. The DPA held that there was no legal basis under Article 9(2) GDPR for sending the medical assessment, which contained health data under Article 14 GDPR#15Article 4(15) GDPR, to the municipality. In particular, the controller could not invoke Article 9(2)(f) GDPR ("necessary for the establishment, exercise or defence of legal claims") because i) the municipality had taken no further steps to claim damages from the controller since September 2014 and ii) the claim had already been time-barred under § 1489 General Civil Code (Allgemeines Bürgerliches Gesetzbuch - ABGB) since more than three years had passed since the event that allegedly caused the damage (harming behaviour towards the data subject). Consequently, the DPA held that the disclosure of the data subject's health data were not necessary "for the establishment, exercise or defence of legal claims". To lawfully disclose the data, the data subject's explicit consent would have been required. When deciding on the amount of the administrative fine, the DSB took into account the sensitive nature of the data and wilful conduct of the controller but also the controller's low income and the fact that the controller collaborated with the DSB in the course of the procedure.

Related Enforcement Actions (0)

No other enforcement actions found for unnkown individual (controller and perpetrator) in AT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

5 August 2021

Authority

Datenschutzbehörde

Fine Amount

€600

GDPRhub ID

gdprhub-4454

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. unnkown individual (controller and perpetrator) - Austria (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: