A*** GmbH (commercial register code: FN *5*1*91r) – Violation Found (Austria, 2020)

Violation Found
Datenschutzbehörde28 September 2020Austria
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

An Austrian company, A*** GmbH, sought approval to monitor compliance with certain codes of conduct. The privacy authority approved them for one code but denied them for others due to lack of consent from code holders. This case shows the importance of cooperation between companies and code holders in compliance monitoring.

What happened

A*** GmbH was partially accredited to monitor compliance with codes of conduct, but denied for others due to lack of consent from code holders.

Who was affected

A*** GmbH and the holders of the codes of conduct they sought to monitor.

What the authority found

The privacy authority accredited A*** GmbH for one code but denied accreditation for others because the code holders did not consent.

Why this matters

This ruling highlights that companies need the cooperation of code holders to monitor compliance effectively. It underscores the role of mutual agreement in the accreditation process for compliance monitoring.

National Law Articles

§ 2 Überwachungsstellenakkreditierungs-Verordnung – ÜStAkk-V
§ 69(6) Datenschutzgesetz - DSG
Full Legal Summary
Detailed

In December 2019, an Austrian company ("A*** GmbH") requested accreditation to monitor compliance with three different codes of conducts under Article 41 GDPR (redacted as "code S***", code M*** and code U***"). These codes had been approved by the DSB under Article 40(5) GDPR. Inverstigations by the DSB showed that: *The holder of the DSB-approval for code S*** explicitly wanted A*** GmbH to be accredited to monitor compliance with this code of conduct. *The holder of the DSB-approval for code U*** was explicitly against A*** GmbH beeing accredited to monitor compliance with this code of conduct *The holder of the DSB-approval for code M*** did not give a statement on whether they wanted A*** GmbH to be accredited to monitor compliance with this code of conduct. However, in August 2020, the DSB had received a request by another body wanting to be accredited to monitor compliance with code M***. *Can a body be accredited to monitor compliance with a code of conduct under Article 41 GDPR if the holder of the of the code's approval is against this accreditation ("non-consensual accreditation")? *Can a body be accredited to monitor compliance with a code of conduct under Article 41 GDPR if the holder of the of the code's approval prefers a different body to be accredited to do so? The DSB accredited A*** GmbH to monitor compliance with code S*** but rejected the request for accreditation for the monitoring of code U*** and code M***. Regarding code U*** the DSB held that the holder of the DSB-approval for this code has expressly denied its cooperation with A*** GmbH regarding the monitoring for this code under Article 41 GDPR. Regarding code M*** the DSB held that the holder of the DSB-approval for this code code has expressed its willingness to cooperate regarding the monitoring under Article 41 GDPR not towards A*** GmbH, but towards another body. As a result, there were neither *monitoring mechanisms to carry out the mandatory monitoring of compliance with the

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Related Enforcement Actions (0)

No other enforcement actions found for A*** GmbH (commercial register code: FN *5*1*91r) in AT

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

28 September 2020

Authority

Datenschutzbehörde

GDPRhub ID

gdprhub-2855

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. A*** GmbH (commercial register code: FN *5*1*91r) - Austria (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: