Austrian Federal Minister of Finance (BMF) – Violation Found (Austria, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Austria's data protection authority approved a data-sharing agreement between the Austrian Finance Ministry and a U.S. oversight board. This agreement ensures personal data is transferred with proper safeguards, even without a specific EU-U.S. data privacy deal. Website operators should note the importance of having strong data protection measures when sharing data internationally.
What happened
The Austrian DPA approved a data-sharing agreement between the Austrian Finance Ministry and the U.S. Public Company Accounting Oversight Board.
Who was affected
The agreement affects individuals whose personal audit documents are shared between Austrian and U.S. authorities.
What the authority found
The Austrian DPA found that the data-sharing agreement included adequate safeguards for transferring personal data to a third country.
Why this matters
This approval highlights the need for strong data protection measures when transferring personal data internationally, especially after the annulment of the Privacy Shield. It serves as a reminder for companies to ensure their international data transfers comply with GDPR requirements.
GDPR Articles Cited
The Austrian Auditor Oversight Authority (APAB) informed the Austrian DPA by letter dated March 3, 2022 about the planned conclusion of an administrative agreement between the Federal Minister of Finance (BMF) and the US Public Company Accounting Oversight Board (PCAOB) regarding the transmission of personal audit documents by the APAB. The DPA solicited an opinion from the European Data Protection Board (EDPB) per Article 64(2) GDPR on the safeguards for the transfer of personal data to a third country which, in the absence of an adequacy decision, Article 46(1) GDPR required. The EDPB approved by majority vote. The EDPB had previously approved a similar transfer to the PCAOB by French authorities. The DPA pointed out that the previous adequacy decision for personal data transfers to recipients in the US, the so-called "Privacy Shield," had been annulled by the European Court of Justice, adding that it had not applied to data transfers between authorities anyway. In any case, suitable guarantees were required by Article 46(1) GDPR. Per Article 46(3)(b) GDPR, those guarantees could be provided for by provisions inserted into administrative arrangements between public authorities or bodies subject to the approval of the competent supervisory authority. As the administrative agreement submitted by the BMF was essentially identical to a previous EDPB-approved arrangement between French authorities and the PCAOB and because the EDPB through a majority vote issued a positive opinion on the current transfer, the DPA concluded that safeguards were adequate and approved the transfer.
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (0)
No other enforcement actions found for Austrian Federal Minister of Finance (BMF) in AT
This is the only recorded action for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Austrian Federal Minister of Finance (BMF) - Austria (2022). Retrieved from cookiefines.eu
Last updated: