Austrian Federal Minister of Finance (BMF) – Violation Found (Austria, 2022)

Violation Found
Datenschutzbehörde16 May 2022Austria
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Austria's data protection authority approved a data-sharing agreement between the Austrian Finance Ministry and a U.S. oversight board. This agreement ensures personal data is transferred with proper safeguards, even without a specific EU-U.S. data privacy deal. Website operators should note the importance of having strong data protection measures when sharing data internationally.

What happened

The Austrian DPA approved a data-sharing agreement between the Austrian Finance Ministry and the U.S. Public Company Accounting Oversight Board.

Who was affected

The agreement affects individuals whose personal audit documents are shared between Austrian and U.S. authorities.

What the authority found

The Austrian DPA found that the data-sharing agreement included adequate safeguards for transferring personal data to a third country.

Why this matters

This approval highlights the need for strong data protection measures when transferring personal data internationally, especially after the annulment of the Privacy Shield. It serves as a reminder for companies to ensure their international data transfers comply with GDPR requirements.

Full Legal Summary
Detailed

The Austrian Auditor Oversight Authority (APAB) informed the Austrian DPA by letter dated March 3, 2022 about the planned conclusion of an administrative agreement between the Federal Minister of Finance (BMF) and the US Public Company Accounting Oversight Board (PCAOB) regarding the transmission of personal audit documents by the APAB. The DPA solicited an opinion from the European Data Protection Board (EDPB) per Article 64(2) GDPR on the safeguards for the transfer of personal data to a third country which, in the absence of an adequacy decision, Article 46(1) GDPR required. The EDPB approved by majority vote. The EDPB had previously approved a similar transfer to the PCAOB by French authorities. The DPA pointed out that the previous adequacy decision for personal data transfers to recipients in the US, the so-called "Privacy Shield," had been annulled by the European Court of Justice, adding that it had not applied to data transfers between authorities anyway. In any case, suitable guarantees were required by Article 46(1) GDPR. Per Article 46(3)(b) GDPR, those guarantees could be provided for by provisions inserted into administrative arrangements between public authorities or bodies subject to the approval of the competent supervisory authority. As the administrative agreement submitted by the BMF was essentially identical to a previous EDPB-approved arrangement between French authorities and the PCAOB and because the EDPB through a majority vote issued a positive opinion on the current transfer, the DPA concluded that safeguards were adequate and approved the transfer.

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Related Enforcement Actions (0)

No other enforcement actions found for Austrian Federal Minister of Finance (BMF) in AT

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

16 May 2022

Authority

Datenschutzbehörde

GDPRhub ID

gdprhub-5101

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Austrian Federal Minister of Finance (BMF) - Austria (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: