[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fIOJjxQKIhfcCx1BTaBU1I_7IuGthnsWSoK59CToJOsE":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"2caed4ce-c315-43fc-ae2f-69788e1ff344","DSB (Austria) - 2026-0.483.002","dsb-austria-2026-0-483-002-605e58","Created page with \"{{DPAdecisionBOX |Jurisdiction=Austria |DPA-BG-Color= |DPAlogo=LogoAT.png |DPA_Abbrevation=DSB |DPA_With_Country=DSB (Austria) |Case_Number_Name=2026-0.483.002 |ECLI=ECLI:AT:DSB:2026:2026.0.483.002 |Original_Source_Name_1=RIS |Original_Source_Link_1=https:\u002F\u002Fwww.ris.bka.gv.at\u002FDokument.wxe?ResultFunctionToken=9b92bd78-b53e-46c4-9e75-fffb8fa4e3ef&Position=1&SkipToDocumentPage=True&Abfrage=Dsk&Entscheidungsart=Undefined&Organ=Undefined&SucheNachRechtssatz=True&SucheNachT...\" New page {{DPAdecisionBOX |Jurisdiction=Austria |DPA-BG-Color= |DPAlogo=LogoAT.png |DPA_Abbrevation=DSB |DPA_With_Country=DSB (Austria) |Case_Number_Name=2026-0.483.002 |ECLI=ECLI:AT:DSB:2026:2026.0.483.002 |Original_Source_Name_1=RIS |Original_Source_Link_1=https:\u002F\u002Fwww.ris.bka.gv.at\u002FDokument.wxe?ResultFunctionToken=9b92bd78-b53e-46c4-9e75-fffb8fa4e3ef&Position=1&SkipToDocumentPage=True&Abfrage=Dsk&Entscheidungsart=Undefined&Organ=Undefined&SucheNachRechtssatz=True&SucheNachText=True&GZ=&VonDatum=01.01.1990&BisDatum=&Norm=&ImRisSeitVonDatum=&ImRisSeitBisDatum=&ImRisSeit=ZweiWochen&ResultPageSize=100&Suchworte=DSGVO&Dokumentnummer=DSBT_20260609_2026_0_483_002_00 |Original_Source_Language_1=German |Original_Source_Language__Code_1=DE |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Type=Investigation |Outcome=Violation Found |Date_Started=22.12.2025 |Date_Decided=09.06.2026 |Date_Published=18.09.2026 |Year=2026 |Fine=1200.0 |Currency=EUR |GDPR_Article_1=Article 4(2) GDPR |GDPR_Article_Link_1=Article 4 GDPR#2 |GDPR_Article_2=Article 4(7) GDPR |GDPR_Article_Link_2=Article 4 GDPR#7 |GDPR_Article_3=Article 4(15) GDPR |GDPR_Article_Link_3=Article 4 GDPR#15 |GDPR_Article_4=Article 5(1)(a) GDPR |GDPR_Article_Link_4=Article 5 GDPR#1a |GDPR_Article_5=Article 5(1)(b) GDPR |GDPR_Article_Link_5=Article 5 GDPR#1b |GDPR_Article_6=Article 6(1) GDPR |GDPR_Article_Link_6=Article 6 GDPR#1 |GDPR_Article_7=Article 9(2) GDPR |GDPR_Article_Link_7=Article 9 GDPR#2 |GDPR_Article_8=Article 83(2)(a) GDPR |GDPR_Article_Link_8=Article 83 GDPR#2a |GDPR_Article_9=Article 83(2)(b) GDPR |GDPR_Article_Link_9=Article 83 GDPR#2b |GDPR_Article_10=Article 83(2)(e) GDPR |GDPR_Article_Link_10=Article 83 GDPR#2e |GDPR_Article_11=Article 83(2)(f) GDPR |GDPR_Article_Link_11=Article 83 GDPR#2f |GDPR_Article_12=Article 83(2)(g) GDPR |GDPR_Article_Link_12=Article 83 GDPR#2g |GDPR_Article_13=Article 83(2)(k) GDPR |GDPR_Article_Link_13=Article 83 GDPR#2k |GDPR_Article_14=Article 83(3) GDPR |GDPR_Article_Link_14=Article 83 GDPR#3 |GDPR_Article_15=Article 83(5)(a) GDPR |GDPR_Article_Link_15=Article 83 GDPR#5a |GDPR_Article_16= |GDPR_Article_Link_16= |GDPR_Article_17= |GDPR_Article_Link_17= |EU_Law_Name_1= |EU_Law_Link_1= |EU_Law_Name_2= |EU_Law_Link_2= |National_Law_Name_1= |National_Law_Link_1= |National_Law_Name_2= |National_Law_Link_2= |Party_Name_1=Albin D. (controller) |Party_Link_1= |Party_Name_2=Relief organization (employer) |Party_Link_2= |Party_Name_3=Maria O. (data subject) |Party_Link_3= |Party_Name_4=Berta V. (data subject) |Party_Link_4= |Party_Name_5= |Party_Link_5= |Party_Name_6= |Party_Link_6= |Appeal_To_Body= |Appeal_To_Case_Number_Name= |Appeal_To_Status=Unknown |Appeal_To_Link= |Initial_Contributor=Ava Lang | }} The DPA fined a medical services employee €1,200 for photographing two patients and sharing the images with unauthorised third parties because they contained health data under [[Article 9 GDPR|Article 9(1) GDPR]]. == English Summary == === Facts === The employee, acting as a controller, was working for a rescue and aid organisation that operated a care facility for people with special needs. Between 1 December and 19 December 2025, he used his private smartphone to photograph two patients in wheelchairs. Their physical impairments and their use of care or health services were visible in the pictures, meaning that the images revealed information about their health. The images were shared to third parties through a chat application. The controller made the decision to take and disclose the photographs himself, acted outside his work duties and did not pursue any purpose connected with caring for the patients or operating the facility. The organisation informed the DPA of the incident. === Holding === First, the DPA held that taking the pictures constituted the collection or recording of personal data, while sharing them through a chat application constituted disclosure by transmission or another form of making the data available under [[Article 4 GDPR|Article 4(2) GDPR]], which qualifies both as processing data. Second, the DPA held that the employee, rather than the organisation, was the controller under [[Article 4 GDPR|Article 4(7) GDPR]] as he determined the purposes and means of the processing, used his private smartphone and acted outside the scope of his duties for his own purposes. The organisation was therefore not the controller for this processing. Third, the DPA held that the photographs contained health data under [[Article 4 GDPR|Article 4(15) GDPR]]. The patients appeared as persons receiving care in a specialised facility, and the photographs revealed their physical impairments and use of care or health services. The processing therefore concerned a special category of personal data. Fourth, the DPA considered that lawful processing had to comply with the principles in [[Article 5 GDPR|Article 5(1) GDPR]] and have a legal basis under [[Article 6 GDPR|Article 6(1) GDPR]]. Because the photographs contained health data, the processing also required an applicable exception under [[Article 9 GDPR|Article 9(2) GDPR]]. It found that it had no legitimate purpose, no legal basis and no applicable exception. The DPA therefore held that the processing was unlawful and that the data subject had violated Articles 5(1) and (b), 6(1) and 9(1) GDPR and ultimately imposed a €1,200 fine under [[Article 83 GDPR|Article 83(5)(a) GDPR]]. == Comment == ''Share your comments here!'' == Further Resources == ''Share blogs or news articles here!'' == English Machine Translation of the Decision == The decision below is a machine translation of the German original. Please refer to the German original for more details. Text Ref. No.: 2026-0.483.002 dated June 9, 2026 (Case No.: DPA-D550.1317) [Processing Officer’s Note: Names and company names, legal forms and product names, addresses (including URLs, IP addresses, and email addresses), case numbers (and the like), statistical data, etc., as well as their initials and abbreviations, may have been abbreviated and\u002For altered for pseudonymization purposes. Obvious spelling, grammar, and punctuation errors have been corrected. The service pseudonymized as J***chat is a very large online platform (VLOP) pursuant to Art. 33 of Regulation (EU) 2022\u002F2065 (Digital Services Act—DSA).]The service pseudonymized as J***chat is a Very Large Online Platform (VLOP) pursuant to article 33 of Regulation (EU) 2022\u002F2065 (Digital Services Act—DSA).] Penalty Notice Defendant: Albin D***, born on **.**.2005 As the controller within the meaning of Article 4(7) of Regulation (EU) 2016\u002F679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\u002F46\u002FEC (General Data Protection Regulation, hereinafter “GDPR”), OJ No. L 119 of May 4, 2016, p. 1, as amended, committed the following administrative offense by engaging in the conduct described below: As the controller within the meaning of article 4, paragraph 7, of Regulation (EU) 2016\u002F679 on the protection of natural persons with regard to the processing of personal data, on the free movement of such data, and repealing Directive 95\u002F46\u002FEC (General Data Protection Regulation, hereinafter “GDPR”), Official Journal No. L 119 of May 4, 2016, page 1, as amended, committed the following administrative offense: During a period that cannot be precisely determined, but in any case between December 1, 2025, and December 19, 2025 (hereinafter: “period of the offense”), used a device in your possession (including a camera function) to take photographs of two data subjects (Maria O*** and Berta V***) at the W*** nursing home, G*** Street **4, **** H***stadt, and disclosed these photographs to unauthorized third parties via the J***chat application. The photographs depict the data subjects as patients in a care facility for people with special needs. Both individuals are shown in wheelchairs in the photographs. The photographs in question reveal the data subjects’ physical limitations as well as their use of health care services, thereby disclosing information about their state of health. By taking the photographs and disclosing them to third parties via the J***chat app, you processed special categories of personal data—namely, data concerning health pursuant to Art. 4(15) of the GDPR—without having a legitimate purpose pursuant to Art. 5(1)(b) of the GDPR, nor a legal basis under Article 6(1) in conjunction with Article 9(2) and Article 5(1)(a) of the GDPR.By taking the photographs and disclosing them to third parties via the J***chat application, you have processed special categories of personal data—namely data concerning health pursuant to article 4, paragraph 15, GDPR, without having a legitimate purpose pursuant to Article 5(1)(b) of the GDPR or a legal basis pursuant to Article 6(1) in conjunction with Article 9(2) and Article 5(1)(a) of the GDPR. Administrative offense under: Art. 5(1)(a) and (b) as well as Art. 6(1) in conjunction with Art. 9(2) and Art. 83(5)(a) of the GDPR (OJ L 2016\u002F119, p. 1, as amended: Article 5, paragraph 1, subparagraphs (a) and (b), and Article 6, paragraph 1, in conjunction with Article 9, paragraph 2, and Article 83, paragraph 5, subparagraph (a), of the GDPR, Official Journal L 2016\u002F119, p. 1, as amended For this administrative offense, the following penalty is imposed pursuant to Article 83 of the GDPR: For this administrative offense, the following penalty is imposed pursuant to Article 83 of the GDPR: A fine of Euro if this is uncollectible, a substitute custodial sentence of in accordance with €1,200 66 hours Article 83(5)(a) of the GDPR in conjunction with Section 16 of the Administrative Penalties Act of 1991 (VStG)Article 83, paragraph 5, subparagraph (a), GDPR in conjunction with Section 16 of the Administrative Penalties Act of 1991 (VStG) Furthermore, pursuant to § 64 of the Administrative Penalties Act of 1991 (VStG), you are required to pay: Furthermore, pursuant to § 64 of the Administrative Penalties Act of 1991 (VStG), you are required to pay: 120 euros as a contribution toward the costs of the penalty proceedings, which amounts to 10% of the fine, but at least 10 euros The total amount due (fine\u002Fcosts\u002Fout-of-pocket expenses) is therefore 1,320,- euros Payment deadline: If no complaint is filed, this penalty notice is immediately enforceable. In this case, the total amount must be paid into the account [omitted here] within two weeks of the decision becoming final. Please indicate the case number and the date of resolution as the payment reference. If payment is not made within this period, the total amount may be subject to a collection notice. In this case, a flat-rate fee of five euros must be paid. If payment is still not made, the outstanding amount will be enforced, and if it cannot be collected, a substitute custodial sentence corresponding to this amount will be carried out. Reasoning: 1. The following facts have been established: 1.1. Regarding the course of the proceedings: The *** Rescue & Relief Organization, Lower Austria Regional Association (hereinafter “***RHW”), informed the Data Protection Authority (hereinafter “DPA”) in a report dated December 22, 2025, of misconduct by a civil service worker with personnel number *3*8*9i (this is the (former) employee number of the accused). Specifically, the DPA was informed that the accused used his personal smartphone to take photographs of two female patients at a care facility for people with special needs and subsequently distributed them via the “J***chat” app. The incriminating photographs were reported to the ***RHW on December 19, 2025. The photographs were submitted to the DPA as evidence. Consequently, the DPA initiated the administrative penalty proceedings in question and, in a letter dated May 13, 2026, requested that the accused provide a justification. In his written explanation dated June 4, 2026, the accused stated that he regretted the incident and had no malicious intent. He explained that at the time, he had not considered the possible consequences of his behavior. He further stated that, as a civilian service worker, he had always enjoyed helping sick people. He acknowledged the mistake he had made and apologized for it. 1.2. The defendant was employed as a civilian service worker at ***RHW in Lower Austria (emergency medical services) and, between December 1, 2025, and December 19, 2025, used a device in his possession (a personal smartphone with a camera) between December 1, 2025, and December 19, 2025, at the W*** nursing home, G*** Street **4, **** H***stadt. 1.3. At the time the photographs were taken, the data subjects were patients at a care facility for people with special needs. Both data subjects can be seen in wheelchairs in the photographs. The photographs clearly show the data subjects’ physical limitations as well as their use of care and health services. 1.4. The accused subsequently made the decision on his own to disclose the photographs he had taken to third parties via the J***chat app. The taking and disclosure of the photographs occurred without official instructions and outside the context of his official duties. Thus, no purpose related to the care of the data subjects or the operation of the facility was pursued. The actions were intended to humiliate the data subjects. 1.5. The photographs specifically appeared as follows (Note: Formatting not reproduced exactly): [Editor’s note: Two digital photographs reproduced here in their original graphic format have been removed for pseudonymization purposes. They depict the content described above in section 1.3.] 1.6. Upon commencing his civilian service, the accused was made aware of the need to maintain data confidentiality and was contractually obligated to do so. Furthermore, immediately upon commencing his civilian service, he successfully completed the mandatory data protection training required by ***RHW Lower Austria as part of his training as a paramedic and was also instructed on the rights and obligations of a civilian service worker. 1.7. No consent was obtained from the data subjects or from any other authorized persons regarding the creation or disclosure of the photographs. The accused’s actions were also carried out without the knowledge of the data subjects. 1.8. After this incident was reported to the ***RHW by other users of the J***chat app, the accused was ultimately dismissed early from civilian service by the Civilian Service Agency at the request of the ***RHW, pursuant to a decision dated January 20, 2026 (Ref. No.: *3*8*9i\u002F**\u002FZD\u002F*1*7). 1.9. At the time of the decision, the defendant was employed as a retail salesperson in the telecommunications sector, earning a monthly net income of EUR 1,829; he has no dependents and no assets. 2. The findings are based on the following assessment of the evidence: 2.1. The findings regarding the course of the proceedings are derived entirely from the case file of the administrative penalty proceedings in question, as well as from the administrative act pertaining to the security breach report filed by ***RHW (Ref. No.: D084.0011\u002F26). The essential facts of the case were set forth in the report submitted by ***RHW on December 22, 2025. At the request of the DPA, this report was supplemented by a submission dated March 6, 2026, in which the incriminating photographs were submitted as evidence, along with the decision from the Civil Service Agency. 2.2. The findings regarding the information discernible from the photographs (in particular, the physical limitations) are based on the photographs submitted by ***RHW. 2.3. The other findings are also based primarily on the statements made by ***RHW during the security breach proceedings and were presented to the accused in summary form. The accused did not dispute the facts relevant to the decision in response to the request for justification. The accused admitted to the acts in question and apologized. 2.4. The findings regarding income and financial circumstances are based on the information provided by the accused in his written statement of defense. 3. Legally, this implies the following: 3.1. By taking the photographs and disclosing them to third parties via the J***chat application, the defendant processed personal (image) data of the data subjects. Taking the photographs constitutes the collection or recording of personal data; sharing them via J***chat constitutes disclosure through transfers or another form of making the data available within the meaning of Art. 4(2) of the GDPR.By taking the photographs and disclosing them to third parties via the J***chat application, the defendant processed personal (image) data of the data subjects. The taking of the photographs constitutes the collection or recording of personal data; the sharing via J***chat constitutes disclosure through transfers or another form of provision within the meaning of article 4(2) of the GDPR. In this context, the accused is to be classified as the controller within the meaning of Article 4(7) of the GDPR, and not the ***RHW, since he independently made the decision on the taking of the photographs, their use, and their disclosure to third parties, and thus solely determined the purposes and means of the processing in question. In doing so, he acted outside the context of his official duties, used his personal smartphone for the processing, and pursued his own interests (the humiliation of the data subjects).The accused is therefore to be classified as the controller within the meaning of Article 4(7) of the GDPR, and not the ***RHW, since he independently made the decision on the taking of the photographs, their use, and their disclosure to third parties, and thus solely determined the purposes and means of the processing in question. In doing so, he acted outside the scope of his official duties, used his personal smartphone for the processing, and pursued his own interests (the humiliation of the data subjects). 3.3. The data processed by the accused constitutes special categories of personal data (sensitive data). In the photographs, the data subjects are recognizable as patients in a care facility for people with special needs. In addition, physical limitations as well as the use of care or health services are evident. The photographs therefore reveal information about the data subjects’ state of health, meaning that data concerning health was processed in accordance with Art. 4(15) of the GDPR.The data processed by the defendant constitutes special categories of personal data (sensitive data). In the photographs, the data subjects are recognizable as patients in a care facility for people with special needs. In addition, physical limitations as well as the use of care and health services are evident. The photographs therefore reveal information about the health status of the data subjects, meaning that data concerning health was processed in accordance with article 4(15) of the GDPR. According to the established case law of the CJEU, for data processing to be lawful within the meaning of the GDPR, it must comply with all the principles set forth in Article 5(1) of the GDPR and, furthermore, be based on at least one of the grounds or legal bases specified in Article 6(1) of the GDPR (see, e.g., CJEU, May 4, 2023, C-60\u002F22, paras. 56 and 57, and CJEU, Dec. 21, 2023, C-667\u002F21, para. 78). When processing sensitive data, an exception under Article 9(2) of the GDPR must also apply. According to the established case law of the CJEU, in order for data processing to be lawful within the meaning of the GDPR, it must comply with all the principles set forth in Article 5(1) GDPR and, in addition, must be based on at least one of the grounds or legal bases set forth in article 6(1) of the GDPR (see, e.g., CJEU, May 4, 2023, C-60\u002F22, paragraphs 56 and 57, and CJEU, Dec. 21, 2023, C-667\u002F21, paragraph 78). When processing sensitive data, an exception under article 9(2) of the GDPR must also apply. 3.5. Neither a legitimate purpose under Article 5(1)(b) of the GDPR nor a legal basis under Article 6(1) of the GDPR, nor an exception under Article 9(2) of the GDPR. In response to the request for justification, the defendant also failed to cite any legal basis. Nor did the accused provide a detailed justification for the purpose of the processing. Viewed objectively, no purpose other than the humiliation of the data subjects can be discerned; consequently, a legitimate purpose for the processing cannot be assumed under any circumstances.Neither a legitimate purpose under Article 5(1)(b) of the GDPR nor a legal basis under Article 6(1) GDPR, nor was there an exception under article 9(2) of the GDPR. In response to the request for justification, the defendant also failed to cite any legal basis. Nor did the defendant provide a detailed justification for the purpose of the processing. Viewed objectively, no purpose other than the humiliation of the data subjects can be discerned; consequently, a legitimate purpose for the processing cannot be assumed under any circumstances. 3.6. The processing in question was therefore not lawful. The objective elements of the administrative offense under Art. 5(1)(a) and (b) and Art. 6(1) in conjunction with Art. 9(2) and Art. 83(5)(a) of the GDPR are thus fulfilled.The processing in question was therefore not lawful. The objective elements of the administrative offense under Article 5(1)(a) and (b) and Article 6(1), in conjunction with Article 9(2) and Article 83(5)(a) of the GDPR, are thus fulfilled. 3.7. With regard to the subjective elements of the offense, it should be noted that, according to the facts of the case deemed proven, the accused was thoroughly instructed regarding his confidentiality obligations upon commencing his civilian service. The accused was therefore aware that no photographs and\u002For video recordings of the persons under his care were permitted at the assignment site. Nevertheless, he consciously made the decision to take the photographs in violation of these guidelines and to disclose them to unauthorized third parties via J***chat. The defendant therefore acted with at least conditional intent, as he had to seriously consider the occurrence of the facts relevant under data protection law as a possibility and accepted that risk (dolus eventualis). 3.8. Thus, with regard to the subjective element of the offense, there is culpability in the form of intent pursuant to Article 83(2)(b) of the GDPR. Thus, with regard to the subjective element of the offense, there is culpability in the form of intent pursuant to Article 83(2)(b) of the GDPR. 4. Regarding the determination of the penalty: 4.1. The determination of the penalty is a discretionary decision to be made by the authority on a case-by-case basis, taking into account the criteria specified by the legislature. The CJEU has clarified in this regard that the requirements concerning administrative fines under Article 83 of the GDPR are governed exclusively by para 1 through 6 of that provision and leave no discretion to the Member States (see CJEU, Dec. 5, 2023, C-807\u002F21, para. 65). Against this background, the DPA based its decision on the amount of the fine on the following considerations: The determination of the fine is a discretionary decision to be made by the authority on a case-by-case basis, taking into account the criteria specified by the legislature. The CJEU has clarified in this regard that the provisions regarding administrative fines under article 83 of the GDPR are governed exclusively by paragraphs 1 through 6 of that provision and leave no discretion to the Member States (see CJEU, Dec. 5, 2023, C-807\u002F21, para. 65). Against this background, the DPA based its decision on the amount of the fine on the following considerations: 4.2. In the present case, the severity of the violations is assessed on the basis of the criteria set forth in Article 83(2)(a), (b), and (g) of the GDPR, using a scale of “minor,” “moderate,” and “serious,” and is ultimately classified as “serious.”In the present case, the severity of the violations is assessed on the basis of the criteria set forth in paragraph 83(2)(a), (b), and (g) of the GDPR, using a scale of “minor,” “moderate,” and “severe,” and is ultimately classified as severe. An aggravating factor in this regard was that ● several violations of key provisions of the GDPR were identified, which must not be disregarded within the scope of Article 83(3) of the GDPR, even if only a single administrative fine is imposed due to the absorption principle,several violations of key provisions of the GDPR were identified, which must not be disregarded within the scope of article 83(3) of the GDPR, even if only a single administrative fine is imposed due to the absorption principle, ● there was culpability in the form of intent, ● special categories of personal data, namely data concerning health, were affected by the violations, ● the photographs were taken without the knowledge of the data subjects while they were in a particularly vulnerable situation and were disclosed to unauthorized third parties, ● the purpose of the processing was to humiliate the data subjects. 4.3. Apart from the circumstances already taken into account in determining the severity of the violation, there are no further aggravating factors affecting the determination of the administrative fine. However, the administrative fine to be imposed based on the severity of the violation was reduced due to the following mitigating factors: ● The DPA has no record of any relevant prior violations of the GDPR by the accused (Art. 83(2)(e) GDPR).The DPA has no record of any relevant prior violations of the GDPR by the defendant (article 83(2)(e) of the GDPR). ● The defendant cooperated during the investigation in question and thereby contributed to establishing the facts by admitting to the alleged acts, acknowledging his misconduct, and expressing regret for it (Art. 83(2)(f) and (k) of the GDPR). These circumstances led to a significant reduction in the administrative fine. The accused cooperated in the present investigation and thereby contributed to establishing the truth by admitting to the alleged acts, acknowledging his misconduct, and expressing regret for it (Article 83, paragraph 2, subparagraphs (f) and (k) of the GDPR). These circumstances led to a significant reduction in the administrative fine. 4.4. Pursuant to Article 83(1) of the GDPR, every administrative fine must be effective and dissuasive. Thus, general and specific deterrence considerations play a particularly important role in determining the penalty. In the present case, the imposition of the administrative fine was necessary for reasons of general deterrence to deter other individuals entrusted with the care of patients from committing similar violations. Pursuant to Article 83(1) of the GDPR, every administrative fine must be effective and dissuasive. Consequently, general and specific deterrence considerations play a particularly significant role in determining the amount of the fine. In the present case, the imposition of the administrative fine was necessary for general preventive reasons to deter other individuals entrusted with the care of patients from committing similar violations. 4.5. The specific administrative fine imposed in the amount of EUR 1,200 therefore appears proportionate to the accused’s income and financial circumstances, the actual harm caused by the offense, the penalty range under Art. 83(5) of the GDPR, and taking into account the relevant criteria for determining the penalty under Article 83(1) and (2) of the GDPR, to be proportionate to the offense and the degree of culpability. Given that this is the first such violation and the defendant’s cooperative behavior during the proceedings, the administrative fine falls within the lowest range of the available penalty framework. An amount that is (even) lower would not satisfy the requirements of Article 83(1) of the GDPR.The specific administrative fine imposed in the amount of EUR 1,200 therefore appears proportionate to the nature of the offense and the degree of culpability, taking into account the accused’s income and financial circumstances, the actual harm caused, the penalty range under article 83, paragraph 5 GDPR, and taking into account the relevant criteria for determining the penalty under article 83(1) and (2) of the GDPR, to be proportionate to the offense and the degree of culpability. Due to the fact that this is the first relevant violation and the defendant’s cooperative behavior during the proceedings, the administrative fine falls within the lowest range of the available penalty framework. An amount that is (even) lower would not satisfy the requirements of article 83(1) of the GDPR. 4.6. When a fine is imposed on a natural person, a substitute custodial sentence must also be set pursuant to para 16 of Section 16 of the Administrative Offenses Act (VStG) in the event that the fine cannot be collected. The substitute custodial sentence may not exceed the maximum term of imprisonment prescribed for the administrative offense or, if no term of imprisonment is prescribed and nothing else is specified, two weeks. Accordingly, a substitute prison sentence was to be imposed as stated in the ruling. When a fine is imposed on a natural person, pursuant to paragraph 16 of the VStG, a substitute prison sentence must be imposed at the same time in the event that the fine cannot be collected. The substitute prison sentence may not exceed the maximum term of imprisonment prescribed for the administrative offense or, if no term of imprisonment is prescribed and nothing else is specified, two weeks. A substitute prison sentence was therefore to be imposed in accordance with the judgment.","The Austrian Data Protection Authority (DSB) fined a medical services employee €1,200 for photographing two patients and sharing the images with unauthorized third parties. The photographs contained sensitive health data, and the employee acted as the controller, determining the purposes and means of processing outside his work duties. The DPA found the processing unlawful as it lacked a legitimate purpose, legal basis, and applicable exception under GDPR.","Austrian DPA fines employee €1,200 for unauthorized sharing of patient health data.","Help DSB (Austria) - 2026-0.483.002: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 15:51, 6 October 2026 view source Avalang (talk | contribs)87 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 15:51, 6 October 2026 DSB - 2026-0.483.002 Authority: DSB (Austria) Jurisdiction: Austria Relevant Law: Article 4(2) GDPR Article 4(7) GDPR Article 4(15) GDPR Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 6(1) GDPR Article 9(2) GDPR Article 83(2)(a) GDPR Article 83(2)(b) GDPR Article 83(2)(e) GDPR Article 83(2)(f) GDPR Article 83(2)(g) GDPR Article 83(2)(k) GDPR Article 83(3) GDPR Article 83(5)(a) GDPR Type: Investigation Outcome: Violation Found Started: 22.12.2025 Decided: 09.06.2026 Published: 18.09.2026 Fine: 1200.0 EUR Parties: Albin D. (controller) Relief organization (employer) Maria O. (data subject) Berta V. (data subject) National Case Number\u002FName: 2026-0.483.002 European Case Law Identifier: ECLI:AT:DSB:2026:2026.0.483.002 Appeal: Unknown Original Language(s): German Original Source: RIS (in DE) Initial Contributor: Ava Lang The DPA fined a medical services employee €1,200 for photographing two patients and sharing the images with unauthorised third parties because they contained health data under Article 9(1) GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The employee, acting as a controller, was working for a rescue and aid organisation that operated a care facility for people with special needs. Between 1 December and 19 December 2025, he used his private smartphone to photograph two patients in wheelchairs. Their physical impairments and their use of care or health services were visible in the pictures, meaning that the images revealed information about their health. The images were shared to third parties through a chat application. The controller made the decision to take and disclose the photographs himself, acted outside his work duties and did not pursue any purpose connected with caring for the patients or operating the facility. The organisation informed the DPA of the incident. Holding First, the DPA held that taking the pictures constituted the collection or recording of personal data, while sharing them through a chat application constituted disclosure by transmission or another form of making the data available under Article 4(2) GDPR, which qualifies both as processing data. Second, the DPA held that the employee, rather than the organisation, was the controller under Article 4(7) GDPR as he determined the purposes and means of the processing, used his private smartphone and acted outside the scope of his duties for his own purposes. The organisation was therefore not the controller for this processing. Third, the DPA held that the photographs contained health data under Article 4(15) GDPR. The patients appeared as persons receiving care in a specialised facility, and the photographs revealed their physical impairments and use of care or health services. The processing therefore concerned a special category of personal data. Fourth, the DPA considered that lawful processing had to comply with the principles in Article 5(1) GDPR and have a legal basis under Article 6(1) GDPR. Because the photographs contained health data, the processing also required an applicable exception under Article 9(2) GDPR. It found that it had no legitimate purpose, no legal basis and no applicable exception. The DPA therefore held that the processing was unlawful and that the data subject had violated Articles 5(1) and (b), 6(1) and 9(1) GDPR and ultimately imposed a €1,200 fine under Article 83(5)(a) GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the German original. Please refer to the German original for more details. Text Ref. No.: 2026-0.483.002 dated June 9, 2026 (Case No.: DPA-D550.1317) [Processing Officer’s Note: Names and company names, legal forms and product names, addresses (including URLs, IP addresses, and email addresses), case numbers (and the like), statistical data, etc., as well as their initials and abbreviations, may have been abbreviated and\u002For altered for pseudonymization purposes. Obvious spelling, grammar, and punctuation errors have been corrected. The service pseudonymized as J***chat is a very large online platform (VLOP) pursuant to Art. 33 of Regulation (EU) 2022\u002F2065 (Digital Services Act—DSA).]The service pseudonymized as J***chat is a Very Large Online Platform (VLOP) pursuant to article 33 of Regulation (EU) 2022\u002F2065 (Digital Services Act—DSA).] Penalty Notice Defendant: Albin D***, born on **.**.2005 As the controller within the meaning of Article 4(7) of Regulation (EU) 2016\u002F679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\u002F46\u002FEC (General Data Protection Regulation, hereinafter “GDPR”), OJ No. L 119 of May 4, 2016, p. 1, as amended, committed the following administrative offense by engaging in the conduct described below: As the controller within the meaning of article 4, paragraph 7, of Regulation (EU) 2016\u002F679 on the protection of natural persons with regard to the processing of personal data, on the free movement of such data, and repealing Directive 95\u002F46\u002FEC (General Data Protection Regulation, hereinafter “GDPR”), Official Journal No. L 119 of May 4, 2016, page 1, as amended, committed the following administrative offense: During a period that cannot be precisely determined, but in any case between December 1, 2025, and December 19, 2025 (hereinafter: “period of the offense”), used a device in your possession (including a camera function) to take photographs of two data subjects (Maria O*** and Berta V***) at the W*** nursing home, G*** Street **4, **** H***stadt, and disclosed these photographs to unauthorized third parties via the J***chat application. The photographs depict the data subjects as patients in a care facility for people with special needs. Both individuals are shown in wheelchairs in the photographs. The photographs in question reveal the data subjects’ physical limitations as well as their use of health care services, thereby disclosing information about their state of health. By taking the photographs and disclosing them to third parties via the J***chat app, you processed special categories of personal data—namely, data concerning health pursuant to Art. 4(15) of the GDPR—without having a legitimate purpose pursuant to Art. 5(1)(b) of the GDPR, nor a legal basis under Article 6(1) in conjunction with Article 9(2) and Article 5(1)(a) of the GDPR.By taking the photographs and disclosing them to third parties via the J***chat application, you have processed special categories of personal data—namely data concerning health pursuant to article 4, paragraph 15, GDPR, without having a legitimate purpose pursuant to Article 5(1)(b) of the GDPR or a legal basis pursuant to Article 6(1) in conjunction with Article 9(2) and Article 5(1)(a) of the GDPR. Administrative offense under: Art. 5(1)(a) and (b) as well as Art. 6(1) in conjunction with Art. 9(2) and Art. 83(5)(a) of the GDPR (OJ L 2016\u002F119, p. 1, as amended: Article 5, paragraph 1, subparagraphs (a) and (b), and Article 6, paragraph 1, in conjunction with Article 9, paragraph 2, and Article 83, paragraph 5, subparagraph (a), of the GDPR, Official Journal L 2016\u002F119, p. 1, as amended For this administrative offense, the following penalty is imposed pursuant to Article 83 of the GDPR: For this administrative offense, the following penalty is imposed pursuant to Article 83 of the GDPR: A fine of Euro if this is uncollectible, a substitute custodial sentence of in accordance with €1,200 66 hours Article 83(5)(a) of the GDPR ","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=DSB_(Austria)_-_2026-0.483.002&diff=53314&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F1\u002F1f\u002FLogoAT.png","2026-10-06T15:51:29+00:00","2026-10-06T16:00:16.162521+00:00",7,[18,21],{"name":19,"type":20},"J***chat","product",{"name":22,"type":23},"DSB","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":41},{"id":24,"icon":26,"name":27,"slug":28},{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]