Background of the incident
In March 2022, due to a configuration error, personal data of 33,000 citizens of the city of Baden was made publicly accessible for four days. The data included names, dates of birth, addresses, and phone numbers, but no critical information such as credit card details. The city argued that the data was available in public registers, which was intended to mitigate the severity of the incident.
Court judgment and legal aspects
The Higher Regional Court upheld the judgment of the Regional Court of Wiener Neustadt and emphasized that, even without concrete proof of misuse, non-material damage, such as psychological stress, is sufficient for damages. This decision follows the case law of the Court of Justice of Justice of the European Union (CJEU), according to which the violation of the right to data protection is eligible for compensation independently of direct damage.ECJ, Judgment of July 4, 2023, Case C-300/21).
Responsibilities of public institutions
The ruling shows that public institutions have a special responsibility to protect personal data. In this case, the city tried to shift the responsibility onto the IT service provider, which was rejected by the court. The city had launched the Baden-Card online before the IT security measures were fully implemented, which led to the security vulnerability. Such violations are subject to the GDPR, and public institutions cannot rely on external service providers to avoid their own liability.
Reactions and precedent
This ruling strengthens the position of citizens in cases of data protection violations and could lead to a wave of claims for damages. The ECJ's decision regarding non-material damage caused by data protection violations gives affected citizens a broader entitlement to compensation. This jurisprudence is expected to impact future rulings across Europe and raise awareness of personal data protection. For public institutions, this means increased responsibility, particularly in the selection and monitoring of IT service providers.
Preventive measures and recommendations
To prevent similar incidents, public authorities should:
- Security controls and auditsRegular review of IT systems and security protocols.
- Employee trainingPrivacy policy awareness training.
- Consistent implementation of the GDPREnsuring that all technical and organizational measures are completed before commissioning new systems.
Frequently Asked Questions
- What rights do data subjects have after a data breach?
Data subjects have the right to information, rectification, erasure, and damages, even without direct proof of misuse. - Can other affected parties claim damages?
Yes, the limitation period is three years, and other citizens can still assert claims. - How can public institutions protect their data better?
Through the implementation of secure IT systems, regular audits, and compliance with GDPR regulations.
Conclusion
The ruling against the city of Baden has far-reaching consequences for data protection in Austria. Since the statute of limitations for such claims for damages is three years, it is expected that the city of Baden will face further demands from affected citizens. This ruling emphasizes the need for public institutions to raise their data protection standards in order to avoid legal consequences.
Affected individuals can contact us at the telephone number 01 3912345 or by email pfefferkorn@atb.law at Matija Pfefferkorn and Roman Taudes report to check your claims and, if necessary, assert claims for damages.