Back to Feed
PolicyOct 2, 2026

DSB (Austria) - 2025-0.626.844

Austria's DPA rules GDPR applies to US-based video streaming service for EU users.

Summary

Austria's Data Protection Authority (DSB) ruled that the GDPR applies to a US-based video streaming service that offers services within the EU. The DSB found the service violated transparency principles by providing personal data in machine-readable formats (OPML, JSON) and failing to provide comprehensive information on data processing, storage, and transfers. The DPA emphasized that data access must be in an intelligible format and that general privacy statements are insufficient to meet GDPR requirements.

Full text

Help DSB (Austria) - 2025-0.626.844: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 08:25, 2 October 2026 view sourceLh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators104 edits Tag: Decisions [1.0] Latest revision as of 08:26, 2 October 2026 view source Lh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators104 editsmTag: Visual edit Line 93: Line 93: === Facts ====== Facts === The data subject requested access to their personal data from a video streaming service (controller) established in the US. The controller provided access to certain personal data in “opml” and “json” format. The controller’s reply did not include information on personal data from tracking, cookies, web profile, purposes of processing, recipients, storage periods, data subjects’ rights, right to lodge a complaint with the supervisory authority, sources of personal data and data transfers to third countries.The data subject requested access to their personal data from a video streaming service (controller) established in the US. The controller provided access to certain personal data in “opml” and “json” format. The controller’s reply did not include information on personal data from tracking, cookies, web profile, purposes of processing, recipients, storage periods, data subjects’ rights, right to lodge a complaint with the supervisory authority, sources of personal data and data transfers to third countries. For further information, the controller referred the data subject to general information on their privacy statement and to different online tools provided by the controller on a portal. There was no single tool where the data subject could download all requested data. The controller indicated that the data subject shall contact customer service in case they cannot access all the requested personal data on the tools. For further information, the controller referred the data subject to general information on their privacy statement and to different online tools provided by the controller on a portal. There was no single tool where the data subject could download all requested data. The controller indicated that the data subject shall contact customer service in case they cannot access all the requested personal data on the tools. The data subject lodged a complaint with the DPA, claiming a violation of their access right. The data subject lodged a complaint with the DPA, claiming a violation of their access right. Line 101: Line 104: === Holding ====== Holding === The DPA held that the GDPR was applicable pursuant to [[Article 3 GDPR|Article 3(2)(a) GDPR]] because the controller, despite being established outside the EU, offered their services within the EU. The DPA held that the GDPR was applicable pursuant to [[Article 3 GDPR|Article 3(2)(a) GDPR]] because the controller, despite being established outside the EU, offered their services within the EU. By providing the personal data in “opml” and “json” format, the controller violated the principle of transparency provided for in [[Article 12 GDPR|Article 12(1) GDPR]]. This is because these formats are used for machine processing and are not easily accessible and intelligible for the data subject. The right to access does not only encompass the mere access to the data, but also the preparation thereof in an intelligible and accessible format that data subjects who are not specialised in IT can understand. By providing the personal data in “opml” and “json” format, the controller violated the principle of transparency provided for in [[Article 12 GDPR|Article 12(1) GDPR]]. This is because these formats are used for machine processing and are not easily accessible and intelligible for the data subject. The right to access does not only encompass the mere access to the data, but also the preparation thereof in an intelligible and accessible format that data subjects who are not specialised in IT can understand. In order for the controller to comply with [[Article 12 GDPR|Article 12 GDPR]] and [[Article 15 GDPR|Article 15 GDPR]], the controller must give full access to the data. A portal where the data subject must rely on several tools in order to receive access to their personal data, and to request from customer service any information that is not provided via the tools, does not fulfil this criterium. The data subject cannot be expected to identify any missing information since the data subject does not know what personal data the controller processes. It is the purpose of the access right to provide the data subject with the knowledge about the data that the controller processes about them. The controller did not comply with [[Article 15 GDPR|Article 15 GDPR]] by referring the data subject to the privacy statement. The privacy statement includes ex ante information in order to fulfil the obligations of [[Article 13 GDPR|Article 13 GDPR]] and [[Article 14 GDPR|Article 14 GDPR]]. The general information on the processing of the controller is not necessarily applicable to the individual case of the data subject. The controller cannot fulfil its obligation to give access by providing general information.In order for the controller to comply with [[Article 12 GDPR]] and [[Article 15 GDPR]], the controller must give full access to the data. A portal where the data subject must rely on several tools in order to receive access to their personal data, and to request from customer service any information that is not provided via the tools, does not fulfil this criterium. The data subject cannot be expected to identify any missing information since the data subject does not know what personal data the controller processes. It is the purpose of the access right to provide the data subject with the knowledge about the data that the controller processes about them. The controller did not comply with [[Article 15 GDPR]] by referring the data subject to the privacy statement. The privacy statement includes ex ante information in order to fulfil the obligations of [[Article 13 GDPR]] and [[Article 14 GDPR]]. The general information on the processing of the controller is not necessarily applicable to the individual case of the data subject. The controller cannot fulfil its obligation to give access by providing general information. As far as the purposes of processing are concerned, the DPA held that the controller must provide information on the specific purposes of processing for the specific case of the data subject in order to comply with [[Article 15 GDPR|Article 15(1)(a) GDPR]]. The data subject must be able to identify which categories of personal data about them are processed for what purpose. The same is true for the storage period. Therefore, the DPA found a violation of [[Article 15 GDPR|Article 15(1)(a) GDPR]] and [[Article 15 GDPR|Article 15(1)(d) GDPR]]. As far as the purposes of processing are concerned, the DPA held that the controller must provide information on the specific purposes of processing for the specific case of the data subject in order to comply with [[Article 15 GDPR|Article 15(1)(a) GDPR]]. The data subject must be able to identify which categories of personal data about them are processed for what purpose. The same is true for the storage period. Therefore, the DPA found a violation of [[Article 15 GDPR|Article 15(1)(a) GDPR]] and [[Article 15 GDPR|Article 15(1)(d) GDPR]]. As far as the sources of data, the recipients, and appropriate safeguards for data transfers to third countries are concerned, the DPA held that the referral to the general information in the privacy statement did not suffice either. The privacy statement merely included general remarks such as the possible categories of data, the fact that the data can be collected from specific sources and that a certain legal framework in the light of data transfers to third countries is followed. Therefore, the contr

Entities

DSB (vendor)video streaming service (product)