[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4BT5Tp4LVgCSvilydKnna3H-fcqKWfTuNCvlf6oRjrY":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"bc72b528-0de9-4357-981c-33e7c1ccb56f","DSB (Austria) - DSB-D550.1284","dsb-austria-dsb-d550-1284-0f5d09","Created page with \"{{DPAdecisionBOX |Jurisdiction=Austria |DPA-BG-Color= |DPAlogo=LogoAT.png |DPA_Abbrevation=DSB |DPA_With_Country=DSB (Austria) |Case_Number_Name=DSB-D550.1284 |ECLI=ECLI:AT:DSB:2026:2026.0.074.279 |Original_Source_Name_1=RIS |Original_Source_Link_1=https:\u002F\u002Fwww.ris.bka.gv.at\u002FDokument.wxe?ResultFunctionToken=31c6ed0b-c0fd-4d81-852d-c5848e962afc&Position=1&SkipToDocumentPage=True&Abfrage=Dsk&Entscheidungsart=Undefined&Organ=Undefined&SucheNachRechtssatz=True&SucheNachTe...\" New page {{DPAdecisionBOX |Jurisdiction=Austria |DPA-BG-Color= |DPAlogo=LogoAT.png |DPA_Abbrevation=DSB |DPA_With_Country=DSB (Austria) |Case_Number_Name=DSB-D550.1284 |ECLI=ECLI:AT:DSB:2026:2026.0.074.279 |Original_Source_Name_1=RIS |Original_Source_Link_1=https:\u002F\u002Fwww.ris.bka.gv.at\u002FDokument.wxe?ResultFunctionToken=31c6ed0b-c0fd-4d81-852d-c5848e962afc&Position=1&SkipToDocumentPage=True&Abfrage=Dsk&Entscheidungsart=Undefined&Organ=Undefined&SucheNachRechtssatz=True&SucheNachText=True&GZ=&VonDatum=01.01.1990&BisDatum=&Norm=&ImRisSeitVonDatum=&ImRisSeitBisDatum=&ImRisSeit=EinerWoche&ResultPageSize=100&Suchworte=DSGVO&Dokumentnummer=DSBT_20260127_2026_0_074_279_00 |Original_Source_Language_1=German |Original_Source_Language__Code_1=DE |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Type=Complaint |Outcome= |Date_Started= |Date_Decided= |Date_Published= |Year= |Fine=1000.0 |Currency=EUR |GDPR_Article_1=Article 5(1)(a) GDPR |GDPR_Article_Link_1=Article 5 GDPR#1a |GDPR_Article_2=Article 5(1)(b) GDPR |GDPR_Article_Link_2=Article 5 GDPR#1b |GDPR_Article_3=Article 4(7) GDPR |GDPR_Article_Link_3=Article 4 GDPR#7 |GDPR_Article_4=Article 6(1)(f) GDPR |GDPR_Article_Link_4=Article 6 GDPR#1f |GDPR_Article_5=Article 83(5)(a) GDPR |GDPR_Article_Link_5=Article 83 GDPR#5a |GDPR_Article_6= |GDPR_Article_Link_6= |GDPR_Article_7= |GDPR_Article_Link_7= |EU_Law_Name_1= |EU_Law_Link_1= |EU_Law_Name_2= |EU_Law_Link_2= |National_Law_Name_1= |National_Law_Link_1= |National_Law_Name_2= |National_Law_Link_2= |Party_Name_1= |Party_Link_1= |Party_Name_2= |Party_Link_2= |Appeal_To_Body= |Appeal_To_Case_Number_Name= |Appeal_To_Status= |Appeal_To_Link= |Initial_Contributor=lh | }} The DPA held that an employee who shared a customer’s phone number with a third person for a personal favour, overstepping company rules, acted as separate controller. Further, the DPA fined the controller € 1,000 for the unlawful data transmission. == English Summary == === Facts === An employee (controller) of a company shared the telephone number of a costumer (data subject) with a third person. The third person who was a personal acquaintance of the controller, asked the controller to share the telephone number of the data subject, who was the third person’s ex-partner, in order to gift her a present. In reality, the third person used the information to repeatedly call the data subject. The controller’s employer had rules in place to avoid such data transmissions. Those company rules were overstepped by the controller by providing the third person with the telephone number of the data subject without asking for the password connected to the data subject’s account held with the company. The controller stated that he acted out of benevolence to do the third person a favour, believing that the third person intended to make the data subject a gift. === Holding === The DPA held that the employee acted as controller pursuant to [[Article 4 GDPR|Article 4(7) GDPR]] because he acted on his own initiative and not on behalf of the company. The controller could not rely on any legal basis for his processing of personal data. “Benevolence” is not a legitimate interest as provided for by [[Article 6 GDPR|Article 6(1)(f) GDPR]]. Neither can the controller rely on a legitimate interest of the third person, as “overwhelming a person with phone calls” is not a legitimate interest. The DPA held that in order to determine the legitimate interest of a third person, what matters is the actual interest, not the interest the controller believes the third person to have. The DPA held that the controller has to act with intent or negligence for the DPA to issue a fine. The controller intentionally shared the personal data without requesting the credentials to the data subject’s account and misused his competences as an employee. The DPA issued a fine of €1,000. In the DPA’s publication of the decision, it is pointed out that the fine was reduced to €700 upon appeal of the controller with the Federal Administrative Court (Bundesverwaltungsgericht). == Comment == ''Share your comments here!'' == Further Resources == ''Share blogs or news articles here!'' == English Machine Translation of the Decision == The decision below is a machine translation of the German original. Please refer to the German original for more details. Text Ref. No.: 2026-0.074.279 dated January 27, 2026 (Case No.: DPA-D550.1284) [Note from the processor: Names and company names, legal forms and product names, addresses (including URLs, IP addresses, and email addresses), case numbers (and the like), statistical data, etc., as well as their initials and abbreviations, may be abbreviated and\u002For altered for pseudonymization purposes. Obvious spelling, grammar, and punctuation errors have been corrected.] Penalty Notice Defendant: Aydin B***, born on **.**.1994 As the controller within the meaning of Art. 4(7) of Regulation (EU) 2016\u002F679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\u002F46\u002FEC (General Data Protection Regulation, hereinafter: “GDPR”), OJ No. L 119 of May 4, 2016, p. 1, as amended, committed the following administrative offense by engaging in the acts described below: As the controller within the meaning of article 4, paragraph 7, of Regulation (EU) 2016\u002F679 on the protection of natural persons with regard to the processing of personal data, on the free movement of such data, and repealing Directive 95\u002F46\u002FEC (General Data Protection Regulation, hereinafter “GDPR”), Official Journal No. L 119 of May 4, 2016, page 1, as amended, committed the following administrative offense by engaging in the acts described below: On December 3, 2025 (hereinafter “date of the offense”), as an employee of V*** GmbH (hereinafter “V***”), headquartered at 1*** Vienna, K***-Gasse 1*7\u002FF\u002F*8 (hereinafter “scene of the offense”), by using it without an official assignment and contrary to all official instructions in such a way that you accessed the customer data of Ms. Manuela O*** (hereinafter “data subject”) and disclosed the data subject’s (new) phone number to a third party —with whom you were personally acquainted—(hereinafter “Third Party”), to whom you disclosed the data subject’s (new) phone number out of goodwill and based on a long-standing relationship of trust during a telephone conversation. The data subject subsequently received numerous calls from the Third Party. The processing of the Data Subject’s personal data and its disclosure to an unauthorized person took place without a legal basis pursuant to Article 5(1)(a) in conjunction with Article 6(1) of the GDPR and without a legitimate purpose pursuant to Article 5(1)(b) of the GDPR.The processing of the data subject’s personal data and its disclosure to an unauthorized person took place without a legal basis pursuant to Article 5(1)(a) in conjunction with Article 6(1) of the GDPR and without a legitimate purpose pursuant to Article 5(1)(b) of the GDPR. Administrative offense pursuant to: Art. 5(1)(a) and (b) and Art. 6(1) in conjunction with Art. 83(3) and (5)(a) of the GDPR, OJ L 2016\u002F119, p. 1, as amended; Article 5, paragraph 1, subparagraphs (a) and (b), and Article 6, paragraph 1, in conjunction with Article 83, paragraph 3 and paragraph 5, subparagraph (a), of the GDPR, Official Journal L 2016\u002F119, p. 1, as amended The following penalty is imposed for this administrative offense: [Processing Officer’s Note: For the amended and final penalty determination, see the section “Appeal to the BVwG\u002FVwGH\u002FVfGH”] Fine of Euro if this is uncollectible, a substitute custodial sentence of pursuant to €1,000 60 hours Art. 83(5)(a) GDPR in conjunction with § 16 of the Administrative Penalties Act of 1991 (VStG) Article 83, paragraph 5, subparagraph (a), GDPR in conjunction with Section 16 of the Administrative Penalties Act of 1991 (VStG) Furthermore, pursuant to § 64 of the Administrative Penalties Act of 1991 (VStG), you are required to pay: Furthermore, pursuant to § 64 of the Administrative Penalties Act of 1991 (VStG), you are required to pay: 100 euros as a contribution toward the costs of the penalty proceedings, which amounts to 10% of the fine, but at least 10 euros; The total amount due (fine\u002Fcosts\u002Fout-of-pocket expenses) is therefore 1,100 euros Payment deadline: If no complaint is filed, this penalty notice is immediately enforceable. In this case, the total amount must be paid into the account [omitted here] within two weeks after the decision becomes final. Please indicate the reference number and the date of settlement as the payment description. If payment is not made within this period, the total amount may be subject to collection proceedings. In this case, a flat-rate fee of five euros must be paid. If payment is still not made, the outstanding amount will be enforced, and if it proves uncollectible, a substitute prison sentence corresponding to this amount will be served. Reasons: 1. The following facts relevant to the decision have been established based on the evidentiary proceedings conducted: 1.1. The defendant is an employee of V*** GmbH (hereinafter “V***”), headquartered at 1*** Vienna, K***-Gasse 1*7\u002FF\u002F*8 (hereinafter “scene of the offense”). Manuela O*** (hereinafter “the affected party”) has been a customer of V*** since November 26, 2025. On December 2, 2025, her phone number was changed because the affected party was being harassed by her ex-partner (hereinafter “third party”). On December 2, 2025, the accused was contacted by the third party, who is known to her family. The purpose of the call was to inquire whether there was a possibility of extending the contract for the Affected Party—under which the third party’s phone number is also registered. In this context, he also asked about available devices. The defendant replied that she would not be back at work until December 3, 2025. 1.3. The third party then messaged the defendant on December 3, 2025 (hereinafter “the time of the offense”) at 8:30 a.m. and asked whether she was already at work. This was followed by a telephone conversation between the defendant and the third party. The third party stated that he wanted to give the affected party a gift and intended to renew the contract for this purpose. However, the third party was not a customer himself and did not have the customer password. Because they knew each other personally, the defendant was persuaded to use the “Master Switch”—which did not require the customer password—to access the data subject’s customer account. During the conversation, the third party had the data subject confirm her new phone number. 1.4. The affected party subsequently received numerous calls from the third party. 1.5. After V*** became aware of the situation, the accused was briefed in a detailed conversation, assigned to an internal data protection training course, and issued a written warning. 1.6. The accused has a monthly net income of approximately EUR 2,300 and debts totaling approximately EUR 209,000. 1.7. The accused maintained her conduct and stated that she was experiencing unimaginable remorse as well as personal disappointment, since her good Art had been exploited under false pretenses. The findings are based on the following assessment of the evidence: 2.1. The findings regarding points 1.2 through 1.5 are indisputably derived from the administrative record pertaining to the security breach proceedings, file no. D082.3549. Furthermore, the accused fully admitted to the allegation in her written defense dated January 26, 2026. 2.2. The findings regarding the accused’s income and financial situation in point 1.6 are based, as far as the Data Protection Authority is concerned, on the information provided by the accused in her written defense dated January 26, 2026. 2.3. The findings in Section 1.7 are also based on the accused’s written defense of January 26, 2026. 3. Legally, this leads to the following conclusions: 3.1. Regarding the objective elements of the offense In this case, the accused, as the controller within the meaning of Art. 4(7) of the GDPR—especially since she acted on her own initiative and not in the course of her official duties—accessed, as established, the personal (customer) data stored by V*** regarding the data subject via the master switch and disclosed the data subject’s new phone number to a third party over the phone. Specifically, the defendant, as the controller within the meaning of Article 4(7), GDPR—especially since she acted on her own initiative and not in the course of her official duties—as established, accessed the personal data (customer) stored by V*** regarding the data subject via the master switch at the scene of the crime and at the time of the offense pursuant to article 4, (1) of the GDPR, and disclosed the data subject’s new telephone number to a third party by telephone. Both the “access” to and the “disclosure” of the personal data constitute a single sequence of operations and are therefore to be classified as a single processing operation within the meaning of Article 4(2) of the GDPR.Both the “access” to and the “disclosure” of the personal data constitute a single sequence of operations and are therefore to be classified as a single processing operation within the meaning of Article 4(2) of the GDPR. According to the established case law of the CJEU, in order for data processing to be lawful within the meaning of the GDPR, it must comply with all the principles set forth in Article 5(1) of the GDPR and, in addition, must be based on at least one of the grounds or legal bases specified in Article 6(1) (see, e.g., CJEU, May 4, 2023, C-60\u002F22, paras. 56 and 57, and CJEU, December 21, 2023, C-667\u002F21, para. 78).According to the established case law of the CJEU, in order for data processing to be lawful within the meaning of the GDPR, it must comply with all the principles set forth in article 5(1) of the of the GDPR and, furthermore, be based on at least one of the grounds or legal bases set forth in Article 6(1) (see, e.g., CJEU, May 4, 2023, C-60\u002F22, paragraphs 56 and 57, and the CJEU decision of December 21, 2023, C-667\u002F21, paragraph 78). In the present case, the defendant did not specify which of the grounds set forth in Article 6(1) of the GDPR specifically supports the processing in question. In this regard, the defendant merely stated that she had carried out the processing out of sheer good faith. Therefore, only the existence of a legitimate interest pursuant to Article 6(1)(f) of the GDPR could be considered. In the present case, the defendant did not specify which of the grounds set forth in Article 6(1) of the GDPR specifically supported the processing in question. In this regard, the defendant stated only that she had carried out the processing out of sheer good faith. Therefore, the only possible basis would be a legitimate interest pursuant to article 6(1)(f) of the GDPR. Article 6(1)(f) of the GDPR permits the processing of personal data in “relationships between private individuals on an equal footing” if such processing is necessary to safeguard the legitimate interests of a controller or a third party and those interests override the interests or fundamental rights and freedoms of the data subject. Article 6, paragraph 1, subparagraph f, of the GDPR permits the processing of personal data in “relationships between equals” among private individuals if such processing is necessary to safeguard the legitimate interests of a controller or a third party and those interests outweigh the interests or fundamental rights and freedoms of the data subject. Merely acting in “good faith,” using access to personal data available in a work context to disclose data contained therein to a third party, the Data Protection Authority does not, in any case, consider that a legitimate interest approved by the legal system—which would justify the processing—can be derived. Furthermore, no legitimate interest of any kind on the part of a third party can be constructed upon which the accused could rely, especially since such an interest cannot be inferred from the act of requesting a phone number for the purpose of bombarding the data subject with calls. This is true regardless of what the defendant assumed to be the third party’s purported legitimate interest, since a controller may rely only on a legitimate interest that actually exists. Consequently, there are no grounds justifying the processing, and thus the existence of a legitimate purpose pursuant to Article 5(1)(b) of the GDPR must also be ruled out.Consequently, there are no facts justifying the processing, and thus the existence of a legitimate purpose pursuant to article 5(1)(b) of the GDPR must also be ruled out. The objective elements of the offense are thus fulfilled. 3.2. On the subjective elements of the offense The CJEU has held that only violations of provisions of the GDPR committed by the controller through fault—i.e., intentionally or negligently—can lead to the imposition of an administrative fine (see CJEU, Dec. 5, 2023, C-807\u002F21, para. 68) and that such fault already exists if the accused could not have been unaware of the unlawfulness of his conduct, regardless of whether he was aware that he was violating the provisions of the GDPR (see CJEU C-807\u002F21, para. 76). The accused is under a corresponding duty to inquire in any case where he was unclear about the legal situation (VwGH, June 25, 2013, 2013\u002F09\u002F0022). The CJEU has held that only violations of provisions of the GDPR committed by the controller through fault—that is, intentionally or negligently—can lead to the imposition of an administrative fine (see CJEU, Dec. 5, 2023, C-807\u002F21, para. 68) and that such fault already exists if the accused could not have been unaware of the unlawfulness of his conduct, regardless of whether they were aware that they were violating the provisions of the GDPR (see CJEU C-807\u002F21, para. 76). In any event, the defendant has a corresponding duty to inquire if they were unclear about the legal situation (Administrative Court, June 25, 2013, 2013\u002F09\u002F0022). In any case, the defendant should have recognized that the processing carried out could not be in accordance with the principles of data processing. It follows from the very wording of the principles set forth in Article 5(1)(b) of the GDPR that the processing of personal data must not be carried out for purposes incompatible with those for which it was collected. Furthermore, this can also be inferred from the fact that the defendant deliberately disregarded V***’s guidelines—which require that the customer password be entered when accessing customer data—and misused the master switch. Furthermore, the defendant also stated that she had a bad feeling immediately after disclosing the phone number. In any case, the defendant should have recognized that the processing carried out could not be in accordance with the principles of data processing. It follows directly from the wording of the principles set forth in Article 5, paragraph 1, subparagraph (b) of the GDPR that the processing of personal data must not be carried out for purposes other than those for which it was collected. Furthermore, this can also be inferred from the fact that the defendant deliberately disregarded V***’s guidelines—which require that the customer password be entered when accessing customer data—and misused the master switch. Furthermore, the defendant also stated that she had an uneasy feeling immediately after disclosing the phone number. This also fulfills the subjective element of the offense in the form of intent. 4. With regard to the determination of the penalty, the following should be noted: Pursuant to Article 83(5)(a) of the GDPR, the penalty range in this specific case extends up to an amount of EUR 20,000,000.The penalty range in this specific case, pursuant to article 83(5)(a) of the GDPR, extends up to an amount of EUR 20,000,000. With regard to the facts of this case, the following aggravating factors were taken into account in determining the penalty: ● Nature and severity of the violation: The defendant abused her official access privileges to disclose the data subjects’ personal data to a third party (Art. 83(2)(a) GDPR).Nature and severity of the violation: the defendant abused her official access privileges to disclose personal data of the data subjects to a third party (Article 83(2)(a) of the GDPR). ● The violation was committed intentionally (Art. 83(2)(b) GDPR). The violation was committed intentionally (Article 83(2)(b) GDPR). With regard to the facts of this case, the following mitigating factors were taken into account in determining the penalty: ● To date, the Data Protection Authority had no record of relevant prior violations by the defendant based on breaches of the GDPR or the DSG (Article 83(2)(e) of the GDPR).To date, the Data Protection Authority had no record of relevant prior violations by the defendant related to breaches of the GDPR or the DSG (article 83(2)(e) of the GDPR). ● The accused cooperated in the course of the present preliminary investigation and contributed to the determination of the facts. Furthermore, the accused admitted to the violation (confession) and expressed remorse (Art. 83(2)(k) GDPR).The accused cooperated in the present investigation and contributed to the determination of the facts. Furthermore, the defendant admitted to the violation (confession) and expressed remorse (article 83(2)(k) of the GDPR). With regard to the defendant’s income, the Data Protection Authority assumed an average monthly net income of approximately EUR 2,300. The defendant’s debts were also taken into account in determining the penalty; however, they do not in and of themselves constitute grounds for a reduced penalty. One of the fundamental objectives of the GDPR, pursuant to Article 1(2) of the GDPR, is the protection of the fundamental rights and freedoms of natural persons, and in particular their right to the protection of personal data under Article 8 of the EU CFR. As outlined above, the defendant violated the fundamental rights of the data subjects. The imposition of this specific fine is therefore necessary, at any rate, as a general deterrent to raise awareness among controllers who have access to data in connection with the unauthorized access to and disclosure of data to third parties, particularly with regard to the fact that such processing is not covered by the legal basis under Article 6(1)(f) of the GDPR.One of the main objectives of the GDPR, pursuant to Article 1(2) of the GDPR, is the protection of the fundamental rights and freedoms of natural persons, and in particular their right to the protection of personal data under Article 8 of the CFR. The defendant has violated the fundamental rights of the data subjects, as explained above. The imposition of this specific fine is therefore necessary, at least in the sense of general prevention, to raise awareness among controllers who have access to data in connection with the unauthorized access to and disclosure of data to third parties, particularly with regard to the fact that such processing is not covered by the legal basis under article 6(1)(f) of the GDPR. The Data Protection Authority assumes that the accused will refrain from carrying out such processing in the future, particularly since she has already faced consequences from her employer. Therefore, in the opinion of the Data Protection Authority, there are no reasons for specific prevention. The specific penalty imposed in the amount of EUR 1,000 therefore appears, in view of the actual gravity of the offense—measured against the available penalty range under Article 83(5) of the GDPR (up to EUR 20,000.000) and taking into account the relevant criteria for determining the penalty under Article 83(2) of the GDPR, to be proportionate to the offense and the degree of culpability; as this is a first-time violation, it falls at the very lower end of the available penalty range.The specific fine imposed in the amount of EUR 1,000 therefore appears appropriate in light of the actual value of the violation, measured against the available penalty range under article 83, paragraph 5, GDPR (up to EUR 20,000,000 in this case), as well as taking into account the relevant criteria for determining the penalty under article 83(2) GDPR, to be proportionate to the offense and the degree of culpability and, given that this was a first-time violation, falls at the lower end of the available penalty range. If a fine is imposed on a natural person, a substitute custodial sentence must also be imposed pursuant to para 16 of the Administrative Offenses Act (VStG) in the event that the fine cannot be collected. The substitute prison sentence may not exceed the maximum term of imprisonment prescribed for the administrative offense and, if no term of imprisonment is prescribed and nothing else is specified, two weeks.If a fine is imposed on a natural person, pursuant to Section 16, paragraph 1, of the VStG, a substitute custodial sentence must be set at the same time in the event that the fine cannot be collected. The substitute imprisonment shall not exceed the maximum term of imprisonment prescribed for the administrative offense or, if no term of imprisonment is prescribed and nothing else is specified, two weeks. Consequently, the penalty actually imposed in the present case is effective, proportionate, and dissuasive within the meaning of Article 83(1) of the GDPR. A (further) lower amount would not (any longer) meet these criteria for an administrative fine.Consequently, the specific penalty imposed in this case is effective, proportionate, and dissuasive within the meaning of article 83(1) of the GDPR. A (further) lower amount would no longer meet these criteria for an administrative fine.","An employee in Austria acted as an independent controller when they shared a customer's phone number with a third party for personal reasons, violating company rules and GDPR. The Austrian Data Protection Authority (DSB) fined the employee €1,000 for unlawful data transmission, as 'benevolence' or a third party's interest in harassing someone does not constitute a legitimate basis for processing personal data.","Austrian DPA fines employee €1,000 for sharing customer data without consent.","Help DSB (Austria) - DSB-D550.1284: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 08:46, 18 August 2026 view source Lh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators3 edits Tag: Decisions [1.0] (No difference) Latest revision as of 08:46, 18 August 2026 DSB - DSB-D550.1284 Authority: DSB (Austria) Jurisdiction: Austria Relevant Law: Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 4(7) GDPR Article 6(1)(f) GDPR Article 83(5)(a) GDPR Type: Complaint Outcome: n\u002Fa Started: Decided: Published: Fine: 1000.0 EUR Parties: n\u002Fa National Case Number\u002FName: DSB-D550.1284 European Case Law Identifier: ECLI:AT:DSB:2026:2026.0.074.279 Appeal: n\u002Fa Original Language(s): German Original Source: RIS (in DE) Initial Contributor: lh The DPA held that an employee who shared a customer’s phone number with a third person for a personal favour, overstepping company rules, acted as separate controller. Further, the DPA fined the controller € 1,000 for the unlawful data transmission. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts An employee (controller) of a company shared the telephone number of a costumer (data subject) with a third person. The third person who was a personal acquaintance of the controller, asked the controller to share the telephone number of the data subject, who was the third person’s ex-partner, in order to gift her a present. In reality, the third person used the information to repeatedly call the data subject. The controller’s employer had rules in place to avoid such data transmissions. Those company rules were overstepped by the controller by providing the third person with the telephone number of the data subject without asking for the password connected to the data subject’s account held with the company. The controller stated that he acted out of benevolence to do the third person a favour, believing that the third person intended to make the data subject a gift. Holding The DPA held that the employee acted as controller pursuant to Article 4(7) GDPR because he acted on his own initiative and not on behalf of the company. The controller could not rely on any legal basis for his processing of personal data. “Benevolence” is not a legitimate interest as provided for by Article 6(1)(f) GDPR. Neither can the controller rely on a legitimate interest of the third person, as “overwhelming a person with phone calls” is not a legitimate interest. The DPA held that in order to determine the legitimate interest of a third person, what matters is the actual interest, not the interest the controller believes the third person to have. The DPA held that the controller has to act with intent or negligence for the DPA to issue a fine. The controller intentionally shared the personal data without requesting the credentials to the data subject’s account and misused his competences as an employee. The DPA issued a fine of €1,000. In the DPA’s publication of the decision, it is pointed out that the fine was reduced to €700 upon appeal of the controller with the Federal Administrative Court (Bundesverwaltungsgericht). Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the German original. Please refer to the German original for more details. Text Ref. No.: 2026-0.074.279 dated January 27, 2026 (Case No.: DPA-D550.1284) [Note from the processor: Names and company names, legal forms and product names, addresses (including URLs, IP addresses, and email addresses), case numbers (and the like), statistical data, etc., as well as their initials and abbreviations, may be abbreviated and\u002For altered for pseudonymization purposes. Obvious spelling, grammar, and punctuation errors have been corrected.] Penalty Notice Defendant: Aydin B***, born on **.**.1994 As the controller within the meaning of Art. 4(7) of Regulation (EU) 2016\u002F679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\u002F46\u002FEC (General Data Protection Regulation, hereinafter: “GDPR”), OJ No. L 119 of May 4, 2016, p. 1, as amended, committed the following administrative offense by engaging in the acts described below: As the controller within the meaning of article 4, paragraph 7, of Regulation (EU) 2016\u002F679 on the protection of natural persons with regard to the processing of personal data, on the free movement of such data, and repealing Directive 95\u002F46\u002FEC (General Data Protection Regulation, hereinafter “GDPR”), Official Journal No. L 119 of May 4, 2016, page 1, as amended, committed the following administrative offense by engaging in the acts described below: On December 3, 2025 (hereinafter “date of the offense”), as an employee of V*** GmbH (hereinafter “V***”), headquartered at 1*** Vienna, K***-Gasse 1*7\u002FF\u002F*8 (hereinafter “scene of the offense”), by using it without an official assignment and contrary to all official instructions in such a way that you accessed the customer data of Ms. Manuela O*** (hereinafter “data subject”) and disclosed the data subject’s (new) phone number to a third party —with whom you were personally acquainted—(hereinafter “Third Party”), to whom you disclosed the data subject’s (new) phone number out of goodwill and based on a long-standing relationship of trust during a telephone conversation. The data subject subsequently received numerous calls from the Third Party. The processing of the Data Subject’s personal data and its disclosure to an unauthorized person took place without a legal basis pursuant to Article 5(1)(a) in conjunction with Article 6(1) of the GDPR and without a legitimate purpose pursuant to Article 5(1)(b) of the GDPR.The processing of the data subject’s personal data and its disclosure to an unauthorized person took place without a legal basis pursuant to Article 5(1)(a) in conjunction with Article 6(1) of the GDPR and without a legitimate purpose pursuant to Article 5(1)(b) of the GDPR. Administrative offense pursuant to: Art. 5(1)(a) and (b) and Art. 6(1) in conjunction with Art. 83(3) and (5)(a) of the GDPR, OJ L 2016\u002F119, p. 1, as amended; Article 5, paragraph 1, subparagraphs (a) and (b), and Article 6, paragraph 1, in conjunction with Article 83, paragraph 3 and paragraph 5, subparagraph (a), of the GDPR, Official Journal L 2016\u002F119, p. 1, as amended The following penalty is imposed for this administrative offense: [Processing Officer’s Note: For the amended and final penalty determination, see the section “Appeal to the BVwG\u002FVwGH\u002FVfGH”] Fine of Euro if this is uncollectible, a substitute custodial sentence of pursuant to €1,000 60 hours Art. 83(5)(a) GDPR in conjunction with § 16 of the Administrative Penalties Act of 1991 (VStG) Article 83, paragraph 5, subparagraph (a), GDPR in conjunction with Section 16 of the Administrative Penalties Act of 1991 (VStG) Furthermore, pursuant to § 64 of the Administrative Penalties Act of 1991 (VStG), you are required to pay: Furthermore, pursuant to § 64 of the Administrative Penalties Act of 1991 (VStG), you are required to pay: 100 euros as a contribution toward the costs of the penalty proceedings, which amounts to 10% of the fine, but at least 10 euros; The total amount due (fine\u002Fcosts\u002Fout-of-pocket expenses) is therefore 1,100 euros Payment deadline: If no complaint is filed, this penalty notice is immediately enforceable. In this case, the total amount must be paid into the account [omitted here] within two weeks after the decision becomes final. Please indicate the reference number and the date of settlement as the payment description. If payment is not made within this period, the total amount may be subject to collection proceedings. In this case, a flat-rate fee of five euros mus","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=DSB_(Austria)_-_DSB-D550.1284&diff=52709&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F1\u002F1f\u002FLogoAT.png","2026-08-18T08:46:22+00:00","2026-08-18T10:00:16.310753+00:00",7,[18],{"name":19,"type":20},"V*** GmbH","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37,39],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":21,"icon":23,"name":24,"slug":25},{"category":40},{"id":41,"icon":23,"name":42,"slug":43},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]