Back to Feed
PolicyOct 6, 2026

DSB (Austria) - 2026-0.483.002

Austria's DPA fines employee €1,200 for unlawful processing of patient health data.

Summary

Austria's Data Protection Authority (DSB) has fined an employee €1,200 for unlawfully processing sensitive health data. The employee took and shared photographs of patients in a specialized facility, revealing their physical impairments and care services. The DPA determined that the employee, not the organization, was the controller, and that the processing violated multiple GDPR articles, including those concerning special categories of personal data and lawful processing principles.

Full text

Help DSB (Austria) - 2026-0.483.002: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 15:51, 6 October 2026 view sourceAvalang (talk | contribs)87 edits Tag: Decisions [1.0] Latest revision as of 15:55, 6 October 2026 view source Avalang (talk | contribs)87 editsm Tag: Visual edit Line 169: Line 169: First, the DPA held that taking the pictures constituted the collection or recording of personal data, while sharing them through a chat application constituted disclosure by transmission or another form of making the data available under [[Article 4 GDPR|Article 4(2) GDPR]], which qualifies both as processing data.First, the DPA held that taking the pictures constituted the collection or recording of personal data, while sharing them through a chat application constituted disclosure by transmission or another form of making the data available under [[Article 4 GDPR|Article 4(2) GDPR]], which qualifies both as processing data. Second, the DPA held that the employee, rather than the organisation, was the controller under [[Article 4 GDPR|Article 4(7) GDPR]] as he determined the purposes and means of the processing, used his private smartphone and acted outside the scope of his duties for his own purposes. The organisation was therefore not the controller for this processing.Second, the authority held that the employee, rather than the organisation, was the controller under [[Article 4 GDPR|Article 4(7) GDPR]] as he determined the purposes and means of the processing, used his private smartphone and acted outside the scope of his duties for his own purposes. The organisation was therefore not the controller for this processing. Third, the DPA held that the photographs contained health data under [[Article 4 GDPR|Article 4(15) GDPR]]. The patients appeared as persons receiving care in a specialised facility, and the photographs revealed their physical impairments and use of care or health services. The processing therefore concerned a special category of personal data.Third, it held that the photographs contained health data under [[Article 4 GDPR|Article 4(15) GDPR]]. The patients appeared as persons receiving care in a specialised facility, and the photographs revealed their physical impairments and use of care or health services. The processing therefore concerned a special category of personal data. Fourth, the DPA considered that lawful processing had to comply with the principles in [[Article 5 GDPR|Article 5(1) GDPR]] and have a legal basis under [[Article 6 GDPR|Article 6(1) GDPR]]. Because the photographs contained health data, the processing also required an applicable exception under [[Article 9 GDPR|Article 9(2) GDPR]]. It found that it had no legitimate purpose, no legal basis and no applicable exception.Fourth, the DPA considered that lawful processing had to comply with the principles in [[Article 5 GDPR|Article 5(1) GDPR]] and have a legal basis under [[Article 6 GDPR|Article 6(1) GDPR]]. Because the photographs contained health data, the processing also required an applicable exception under [[Article 9 GDPR|Article 9(2) GDPR]]. It found that it had no legitimate purpose, no legal basis and no applicable exception. The DPA therefore held that the processing was unlawful and that the data subject had violated Articles 5(1) and (b), 6(1) and 9(1) GDPR and ultimately imposed a €1,200 fine under [[Article 83 GDPR|Article 83(5)(a) GDPR]].The DPA therefore held that the processing was unlawful and that the data subject had violated [[Article 5 GDPR|Article 5(1)]], [[Article 6 GDPR|6 (1)]] and [[Article 9 GDPR|9(1) GDPR]] and ultimately imposed a €1,200 fine under [[Article 83 GDPR|Article 83(5)(a) GDPR]]. == Comment ==== Comment == Latest revision as of 15:55, 6 October 2026 DSB - 2026-0.483.002 Authority: DSB (Austria) Jurisdiction: Austria Relevant Law: Article 4(2) GDPR Article 4(7) GDPR Article 4(15) GDPR Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 6(1) GDPR Article 9(2) GDPR Article 83(2)(a) GDPR Article 83(2)(b) GDPR Article 83(2)(e) GDPR Article 83(2)(f) GDPR Article 83(2)(g) GDPR Article 83(2)(k) GDPR Article 83(3) GDPR Article 83(5)(a) GDPR Type: Investigation Outcome: Violation Found Started: 22.12.2025 Decided: 09.06.2026 Published: 18.09.2026 Fine: 1200.0 EUR Parties: Albin D. (controller) Relief organization (employer) Maria O. (data subject) Berta V. (data subject) National Case Number/Name: 2026-0.483.002 European Case Law Identifier: ECLI:AT:DSB:2026:2026.0.483.002 Appeal: Unknown Original Language(s): German Original Source: RIS (in DE) Initial Contributor: Ava Lang The DPA fined a medical services employee €1,200 for photographing two patients and sharing the images with unauthorised third parties because they contained health data under Article 9(1) GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The employee, acting as a controller, was working for a rescue and aid organisation that operated a care facility for people with special needs. Between 1 December and 19 December 2025, he used his private smartphone to photograph two patients in wheelchairs. Their physical impairments and their use of care or health services were visible in the pictures, meaning that the images revealed information about their health. The images were shared to third parties through a chat application. The controller made the decision to take and disclose the photographs himself, acted outside his work duties and did not pursue any purpose connected with caring for the patients or operating the facility. The organisation informed the DPA of the incident. Holding First, the DPA held that taking the pictures constituted the collection or recording of personal data, while sharing them through a chat application constituted disclosure by transmission or another form of making the data available under Article 4(2) GDPR, which qualifies both as processing data. Second, the authority held that the employee, rather than the organisation, was the controller under Article 4(7) GDPR as he determined the purposes and means of the processing, used his private smartphone and acted outside the scope of his duties for his own purposes. The organisation was therefore not the controller for this processing. Third, it held that the photographs contained health data under Article 4(15) GDPR. The patients appeared as persons receiving care in a specialised facility, and the photographs revealed their physical impairments and use of care or health services. The processing therefore concerned a special category of personal data. Fourth, the DPA considered that lawful processing had to comply with the principles in Article 5(1) GDPR and have a legal basis under Article 6(1) GDPR. Because the photographs contained health data, the processing also required an applicable exception under Article 9(2) GDPR. It found that it had no legitimate purpose, no legal basis and no applicable exception. The DPA therefore held that the processing was unlawful and that the data subject had violated Article 5(1), 6 (1) and 9(1) GDPR and ultimately imposed a €1,200 fine under Article 83(5)(a) GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the German original. Please refer to the German original for more details. Text Ref. No.: 2026-0.483.002 dated June 9, 2026 (Case No.: DPA-D550.1317) [Processing Officer’s Note: Names and company names, legal forms and product names, addresses (including URLs, IP addresses, and email addresses), case numbers (and the like), statistical data, etc., as well as their initials and abbreviations, may have been abbreviated and/or altered for pseudonymization purposes. Obvious spelling, grammar, and punctuation errors have been corrected. The service pseudonymized as J***c

Entities

DSB (vendor)