DSB (Austria) - 2026-0.483.002
Austrian DPA fines employee €1,200 for unauthorized sharing of patient health data.
Summary
The Austrian Data Protection Authority (DSB) fined a medical services employee €1,200 for photographing two patients and sharing the images with unauthorized third parties. The photographs contained sensitive health data, and the employee acted as the controller, determining the purposes and means of processing outside his work duties. The DPA found the processing unlawful as it lacked a legitimate purpose, legal basis, and applicable exception under GDPR.
Full text
Help DSB (Austria) - 2026-0.483.002: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 15:51, 6 October 2026 view source Avalang (talk | contribs)87 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 15:51, 6 October 2026 DSB - 2026-0.483.002 Authority: DSB (Austria) Jurisdiction: Austria Relevant Law: Article 4(2) GDPR Article 4(7) GDPR Article 4(15) GDPR Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 6(1) GDPR Article 9(2) GDPR Article 83(2)(a) GDPR Article 83(2)(b) GDPR Article 83(2)(e) GDPR Article 83(2)(f) GDPR Article 83(2)(g) GDPR Article 83(2)(k) GDPR Article 83(3) GDPR Article 83(5)(a) GDPR Type: Investigation Outcome: Violation Found Started: 22.12.2025 Decided: 09.06.2026 Published: 18.09.2026 Fine: 1200.0 EUR Parties: Albin D. (controller) Relief organization (employer) Maria O. (data subject) Berta V. (data subject) National Case Number/Name: 2026-0.483.002 European Case Law Identifier: ECLI:AT:DSB:2026:2026.0.483.002 Appeal: Unknown Original Language(s): German Original Source: RIS (in DE) Initial Contributor: Ava Lang The DPA fined a medical services employee €1,200 for photographing two patients and sharing the images with unauthorised third parties because they contained health data under Article 9(1) GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The employee, acting as a controller, was working for a rescue and aid organisation that operated a care facility for people with special needs. Between 1 December and 19 December 2025, he used his private smartphone to photograph two patients in wheelchairs. Their physical impairments and their use of care or health services were visible in the pictures, meaning that the images revealed information about their health. The images were shared to third parties through a chat application. The controller made the decision to take and disclose the photographs himself, acted outside his work duties and did not pursue any purpose connected with caring for the patients or operating the facility. The organisation informed the DPA of the incident. Holding First, the DPA held that taking the pictures constituted the collection or recording of personal data, while sharing them through a chat application constituted disclosure by transmission or another form of making the data available under Article 4(2) GDPR, which qualifies both as processing data. Second, the DPA held that the employee, rather than the organisation, was the controller under Article 4(7) GDPR as he determined the purposes and means of the processing, used his private smartphone and acted outside the scope of his duties for his own purposes. The organisation was therefore not the controller for this processing. Third, the DPA held that the photographs contained health data under Article 4(15) GDPR. The patients appeared as persons receiving care in a specialised facility, and the photographs revealed their physical impairments and use of care or health services. The processing therefore concerned a special category of personal data. Fourth, the DPA considered that lawful processing had to comply with the principles in Article 5(1) GDPR and have a legal basis under Article 6(1) GDPR. Because the photographs contained health data, the processing also required an applicable exception under Article 9(2) GDPR. It found that it had no legitimate purpose, no legal basis and no applicable exception. The DPA therefore held that the processing was unlawful and that the data subject had violated Articles 5(1) and (b), 6(1) and 9(1) GDPR and ultimately imposed a €1,200 fine under Article 83(5)(a) GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the German original. Please refer to the German original for more details. Text Ref. No.: 2026-0.483.002 dated June 9, 2026 (Case No.: DPA-D550.1317) [Processing Officer’s Note: Names and company names, legal forms and product names, addresses (including URLs, IP addresses, and email addresses), case numbers (and the like), statistical data, etc., as well as their initials and abbreviations, may have been abbreviated and/or altered for pseudonymization purposes. Obvious spelling, grammar, and punctuation errors have been corrected. The service pseudonymized as J***chat is a very large online platform (VLOP) pursuant to Art. 33 of Regulation (EU) 2022/2065 (Digital Services Act—DSA).]The service pseudonymized as J***chat is a Very Large Online Platform (VLOP) pursuant to article 33 of Regulation (EU) 2022/2065 (Digital Services Act—DSA).] Penalty Notice Defendant: Albin D***, born on **.**.2005 As the controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter “GDPR”), OJ No. L 119 of May 4, 2016, p. 1, as amended, committed the following administrative offense by engaging in the conduct described below: As the controller within the meaning of article 4, paragraph 7, of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data, on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter “GDPR”), Official Journal No. L 119 of May 4, 2016, page 1, as amended, committed the following administrative offense: During a period that cannot be precisely determined, but in any case between December 1, 2025, and December 19, 2025 (hereinafter: “period of the offense”), used a device in your possession (including a camera function) to take photographs of two data subjects (Maria O*** and Berta V***) at the W*** nursing home, G*** Street **4, **** H***stadt, and disclosed these photographs to unauthorized third parties via the J***chat application. The photographs depict the data subjects as patients in a care facility for people with special needs. Both individuals are shown in wheelchairs in the photographs. The photographs in question reveal the data subjects’ physical limitations as well as their use of health care services, thereby disclosing information about their state of health. By taking the photographs and disclosing them to third parties via the J***chat app, you processed special categories of personal data—namely, data concerning health pursuant to Art. 4(15) of the GDPR—without having a legitimate purpose pursuant to Art. 5(1)(b) of the GDPR, nor a legal basis under Article 6(1) in conjunction with Article 9(2) and Article 5(1)(a) of the GDPR.By taking the photographs and disclosing them to third parties via the J***chat application, you have processed special categories of personal data—namely data concerning health pursuant to article 4, paragraph 15, GDPR, without having a legitimate purpose pursuant to Article 5(1)(b) of the GDPR or a legal basis pursuant to Article 6(1) in conjunction with Article 9(2) and Article 5(1)(a) of the GDPR. Administrative offense under: Art. 5(1)(a) and (b) as well as Art. 6(1) in conjunction with Art. 9(2) and Art. 83(5)(a) of the GDPR (OJ L 2016/119, p. 1, as amended: Article 5, paragraph 1, subparagraphs (a) and (b), and Article 6, paragraph 1, in conjunction with Article 9, paragraph 2, and Article 83, paragraph 5, subparagraph (a), of the GDPR, Official Journal L 2016/119, p. 1, as amended For this administrative offense, the following penalty is imposed pursuant to Article 83 of the GDPR: For this administrative offense, the following penalty is imposed pursuant to Article 83 of the GDPR: A fine of Euro if this is uncollectible, a substitute custodial sentence of in accordance with €1,200 66 hours Article 83(5)(a) of the GDPR