Provisional text
OPINION OF ADVOCATE GENERAL
NORKUS
delivered on 18 June 2026 (1)
Case C‑185/25 [Waldfelber] (i)
RS
v
TS
(Request for a preliminary ruling from the Oberster Gerichtshof (Supreme Court, Austria))
( Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘data controller’ – Natural person acting in their capacity as head of a public body – Headteacher of a school – Determination of the purposes and means of the processing of personal data – Personal data in an email sent by the headteacher from his professional email address – Article 15(1)(g) – Right of the data subject to have access to ‘any available information’ as to the source of the personal data – Personal data consisting of an opinion about the data subject – Opinion based on a discussion with a third party – Right of the data subject to have access to information about the identity of the third party – Article 82 – Right to compensation and liability – Damage allegedly caused by a breach of the right of access – Exclusion of liability of the headteacher – Validity of the exclusion )
I. Introduction
1. The present case concerns a situation that is not uncommon in the workplace. A natural person, acting as an employee or agent of a private or public legal entity, asks a third party, in a face-to-face conversation, to give his or her opinion of an individual selected to fill a position within that entity. Following that discussion, the employee or agent sends an email from his or her professional email address to the person responsible for proposing the candidate, requesting that another individual be proposed instead.
2. The individual designated to fill the position becomes aware of the email and seeks to find out the identity of the third party. Can that individual obtain that information on the basis of the Regulation (EU) 2016/679, (2) and more specifically, Article 15(1)(g) thereof?
3. Pursuant to that provision, the data subject (that is to say, the identified or identifiable natural person whose personal data (3) has been processed) (4) has the right to obtain ‘any available information as to [the] source’ of his or her personal data from the ‘controller’, where those personal data are not collected from the data subject him or herself. In casu, the alleged ‘controller’ (TS, the defendant in the main proceedings) is the headteacher of a primary school in Austria. In that capacity, he organises continuing training programmes for the teachers of his school. Such programmes are run by the Pädagogische Hochschule (‘the University for Educational Sciences’), with the help of ‘programme coordinators’ (‘Prozessbegleiter’).
4. The data subject (RS, the applicant in the main proceedings) is one such programme coordinator. TS, having been informed that an upcoming training programme for the teachers of his school would be coordinated by RS, enquired about the latter’s reputation from a third party. On the basis of the information provided to him, TS sent an email to the University for Educational Sciences from his professional address, in which he requested that a different programme coordinator be appointed in his place. RS, relying on Article 15(1)(g) of the GDPR, wishes to know the identity of the third party who spoke negatively about him.
5. Within that context, the Oberster Gerichtshof (Supreme Court, Austria) seeks clarification as to the scope of that provision. It also wonders, as a preliminary point, whether a person such as TS can be regarded as a ‘controller’, within the meaning of Article 4(7) of the GDPR. Finally, it would like to know whether the adverse consequences resulting from an infringement of the obligation to provide information laid down in Article 15(1) of the GDPR can constitute ‘damage caused by processing which infringes [that] regulation’, within the meaning of Article 82(2) of the GDPR, and lead to the obligation of the controller to pay compensation. It also asks whether, in such a situation, Article 82 of the GDPR precludes national legislation which excludes persons acting as the ‘executive officers’ of certain legal public entities (such as in casu, TS) from being held liable for such damage.
II. Legal framework
A. European Union law
6. Recital 63 of the GDPR states:
‘A data subject should have the right of access to personal data which have been collected concerning him or her, and to exercise that right easily and at reasonable intervals, in order to be aware of, and verify, the lawfulness of the processing … Every data subject should therefore have the right to know and obtain communication in particular with regard to the purposes for which the personal data are processed, where possible the period for which the personal data are processed, the recipients of the personal data, the logic involved in any automatic personal data processing and, at least when based on profiling, the consequences of such processing …That right should not adversely affect the rights or freedoms of others, including trade secrets or intellectual property and in particular the copyright protecting the software. However, the result of those considerations should not be a refusal to provide all information to the data subject …’
7. Article 4(7) of that regulation defines a ‘controller’ as a ‘natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law’.
8. Article 15(1)(g) of the GDPR grants the data subject ‘the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and … where the personal data are not collected from the data subject, any available information as to their source’.
9. Article 82(1) of the GDPR grants ‘any person who has suffered material or non-material damage as a result of an infringement of this Regulation … the right to receive compensation from the controller or processor for the damage suffered’. Pursuant to paragraph 2 of that article, ‘any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation’. It further specifies that ‘a processor shall be liable for the damage caused by processing only where it has not complied with obligations of this Regulation specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller’.
B. Austrian law
10. Chapter I (entitled ‘Third[-]Party Liability’) of the Bundesgesetz über die Haftung der Gebietskörperschaften und der sonstigen Körperschaften und Anstalten des öffentlichen Rechts für in Vollziehung der Gesetze zugefügte Schäden (Amtshaftungsgesetz) (Federal law on the liability of local authorities and other public-law entities for damage caused in the enforcement of laws (‘Law on public liability’)) of 18 December 1948 (BGBl. 20/1949), in its version applicable to the dispute in the main proceedings, contains Paragraph 1(1), which reads as follows:
‘The Federation, the [Länder], municipalities, other bodies of public law and the institutions of social insurance – hereinafter named legal entities – are liable under the provisions of Civil Law for any damage to any person or any property caused by unlawful acts of persons at fault when implementing the law on behalf of such legal entities; such executive officers implementing the law on are not liable vis a vis the persons injured. [Compensation for the damage] shall be paid only in terms of money.’
11. According to Paragraph 9(5) of that law (which comes under Chapter II, entitled ‘Proceedings’), ‘[compensation for] damage caused by an executive officer of a legal entity named in [Paragraph] 1 of this Federal [Law] in the course of implementation of the law cannot be claimed by the injured party in standard legal proceedings’.
III. Facts, national procedure and the questions referred
12. TS, the defendant in the main proceedings, is the headteacher of a primary school in Austria. In that capacity, he organises continuing training programmes for the teachers of the school, who are subject to a legal obligation to attend them.
13. The University for Educational Sciences provides the training programmes in question. In particular, it supplies schools with organisational staff (programme coordinators) who are specifically selected to facilitate the delivery of those programmes.
14. After being informed that RS, the applicant in the main proceedings, had been proposed by the University for Educational Sciences as the coordinator of an upcoming training programme for the teachers at his school, TS enquired about RS’s reputation in a face-to-face conversation with a teacher (‘the third party’).
15. A few days after the conversation with the third party, TS sent an email via his professional email address – which he uses exclusively for official purposes – using a school computer and a specifically designated server to an employee at the University for Educational Sciences in which he asked that a different programme coordinator be assigned (‘the email at issue’). He based his request on the information that he had obtained from the third party regarding RS, according to which RS takes issue with the public school system and is in constant dispute with the relevant education authority.
16. TS did not create a file note or make any other record of the conversation with the third party. He did not disseminate the information obtained during that conversation in any other way. Apart from the email at issue itself, there is no other written record of the personal data concerning RS contained therein.
17. When RS became aware of the content of the email at issue, he complained to TS. He requested that he be provided with certain information, concerning, inter alia, the identity of the third party, pursuant to Article 15(1) of the GDPR, and that he be sent a copy of the personal data concerning him which TS had processed in that email.
18. On the same day, TS informed RS by email that he had never possessed any personal data concerning him nor had he passed such data on to anyone else. TS stated that he had merely expressed his concerns about RS being selected as a programme coordinator for the training programme which the teachers of his school were meant to attend.
19. RS subsequently initiated legal proceedings, seeking an order requiring TS to provide him with certain information, concerning, inter alia, the identity of the third party, pursuant to Article 15(1)(g) of the GDPR, as well as a copy of the personal data concerning him. He also asked that TS be ordered to pay him EUR 800 in compensation for non-material damage due to the alleged infringement of his right to information, provided for in Article 15 of the GDPR. TS objected to that action on the grounds that only the legal entity which governs the school on behalf of whom he had acted could be held liable and that he had neither processed nor stored RS’s personal data.
20. The court hearing the case at first instance dismissed RS’s claim. That decision was later confirmed by the relevant appeal court. Both courts considered, in essence, that TS had acted as an executive officer of the legal entity which governs the school and that the means of processing personal data (specific server, professional email address) had been prescribed to him. In the light of those elements, they found that it would be contrary to the Law on public liability to qualify TS as a ‘controller’ within the meaning of the GDPR. The court hearing the case on appeal further considered that, in any event, there was no obligation to keep a written record of the name of the third party and, therefore, no obligation to disclose information about the identity of that party.
21. RS lodged an appeal on a point of law against the decision rendered by the appeal court before the Oberster Gerichtshof (Supreme Court), which is the referring court.
22. Harbouring doubts as to the correct interpretation of Article 4(7), Article 15(1)(g) and Article 82 of the GDPR, the referring court decided to stay the proceedings and to refer the following questions to the Court of Justice for a preliminary ruling:
‘(1) Is Article 4(7) of [the GDPR] to be interpreted as meaning that natural persons, who, in the exercise of their duties, process personal data by means of the tools made available and prescribed to them, not in their own personal interest but as the head of an organisation (an institution or other entity without legal personality), but which is backed by a legal entity, are “controllers” who can be held liable in court?
(2)(a) Is Article 15(1)(g) of the GDPR to be interpreted as meaning that, in a case in which the processed data consists of a factual statement about or an evaluative assessment of the data subject in an email, “any available information as to their source” refers only to the author of the email, or does it also include the group of persons with whom the author has discussed the data subject?
(2)(b) In the event that names of the parties to the conversation that have not been stored constitute “available information as to [the] source” for purposes of Article 15(1)(g) of the GDPR: when weighing up the interests of the data subject against the interests of such a party to the conversation, is the fact that it was not foreseeable for the party that their statements would be made the subject of data processing relevant?
(3) Is Article 82(2) of the GDPR to be interpreted as meaning that negative consequences for the data subject resulting from an infringement of that [r]egulation, which occurred after the processing of the personal data and which is solely an infringement of the obligation to provide information pursuant to Article 15(1) of the GDPR, constitute damage caused by “processing which infringes this Regulation” and leads to the obligation of the controller to pay compensation?
(4) If Question 1 or 3 is answered in the affirmative: does Article 82 of the GDPR preclude national provisions according to which a claim for the compensation for damage caused to an injured party by [an executive officer] of a legal entity in the sovereign execution of the law cannot be asserted against the [executive officer] itself?’
23. The request for a preliminary ruling, dated 18 February 2025, was lodged at the Registry of the Court of Justice on 7 March 2025. The applicant in the main proceedings, the Austrian and Italian Governments and the Commission submitted written observations. No hearing was held.
IV. Assessment
24. The GDPR was adopted with the objective of establishing ‘a strong … data protection framework in the Union’, (5) by ‘the strengthening and setting out in detail of the rights of data subjects and the obligations of those who process … personal data’ (6) and ensuring, in particular, that natural persons have a ‘high level of protection’ (7) and ‘control of their own personal data’. (8) To that end, Articles 12 to 15 of the GDPR entitle data subjects to receive certain information concerning, inter alia, the processing (9) of their personal data, as well as the categories of personal data and recipients concerned. As I have explained in the introduction, under Article 15(1)(g) thereof, where the personal data are not collected from the data subject, he or she is also entitled to receive ‘any available information as to [the] source’ of those data. The obligation to provide that information falls directly on the ‘controller’. (10)
25. At the same time, recital 4 of the GDPR states that the right to the protection of personal data, which is enshrined in Article 8 of the Charter of Fundamental Rights of the European Union (‘the Charter’), ‘is not an absolute right’ and ‘must be considered in relation to its function in society and be balanced against other fundamental rights’, including the right to freedom of thought and expression.
26. It follows that there are limits to the various rights which data subjects derive from the GDPR and which seek to give practical effect to the right to protection of personal data, including the right to information laid down in Article 15(1) thereof.
27. The present case concerns the limits of the latter right precisely and, more specifically, the extent to which a data subject (here, RS, the applicant in the main proceedings) is entitled to access information from the controller regarding the ‘source’ of the personal data concerning him or her, under Article 15(1)(g) of the GDPR. Where those data were produced by the controller following an oral conversation with a third party (as is the case in the main proceedings), is the data subject entitled to disclosure of the identity of the third party?
28. I will address that issue, which corresponds, in essence, to the second question referred for a preliminary ruling by the Oberster Gerichtshof (Supreme Court), in Section B below. Before I do so, I will first clarify, in response to the first question, whether a natural person who (like TS) processes personal data not in his or her own personal interest, but in the exercise of his or her duties, as the head of an organisation (in casu, a school), and by means of the tools made available and prescribed to him or her by such an organisation, qualifies as a ‘controller’, within the meaning of Article 4(7) of the GDPR (Section A).
29. Lastly, I will turn to the third and fourth questions, which concern the right of data subjects to compensation, as laid down in Article 82 of the GDPR. More specifically, the third question pertains to whether the adverse consequences resulting from a breach of the obligation to provide information under Article 15(1) of the GDPR may constitute ‘damage caused by processing which infringes [that] Regulation’, within the meaning of Article 82(2) of that regulation (Section C). The fourth question invites the Court to examine whether that article precludes national rules which provide that persons acting as ‘executive officers’ – that is to say, on behalf of – certain public legal entities cannot be held liable for damage caused to data subjects in their capacity as controllers or processors (Section D).
A. The concept of ‘controller’ (Article 4(7) of the GDPR) (Question 1)
30. Article 4(7) of the GDPR describes two situations in which a ‘natural or legal person, public authority, agency or another body’ may qualify as a ‘controller’. Indeed, pursuant to the second sentence of that provision, ‘the controller or the specific criteria for its nomination may be provided for by Union or Member State law’ (the first situation). (11) The second situation is where, following an assessment of the relevant facts, the person in question is deemed ‘alone or jointly with others, [to determine] the purposes and means of the processing’. The Court has indicated that, in order to fulfil that criterion, a natural or legal person must actually ‘[exert] influence over the processing of personal data’. (12) It follows that a natural or legal person, public authority, agency or another body which is in fact in a position to determine the purposes and means of the processing will be regarded as a ‘controller’, irrespective of whether he, she or it was formally appointed as such (by law or in a contract or otherwise). (13)
31. The first question of the referring court concerns that second situation. Indeed, that court states that Austrian law expressly designates headteachers of primary schools as ‘controllers’ in relation to the personal data of pupils, only. The main proceedings do not relate to the processing of such data. As I have already explained, they concern the processing, by the headteacher of a primary school (TS), of the personal data of a person (RS) who was selected to coordinate a training programme for the teachers of the school in question.
32. The Oberster Gerichtshof (Supreme Court) identifies the following circumstances as being relevant to the issue of whether TS qualifies as a ‘controller’, within the meaning of Article 4(7) of the GDPR: TS was acting in the exercise of his duties; he processed the personal data not in his own personal interest but in that of the school and he did so by means of the tools made available and prescribed to him (using his professional email address, a school computer and a specifically designated server).
33. RS challenges the accuracy of the facts presented by the referring court. He claims that the means employed by TS in collecting the personal data at issue (the oral conversation with the third party) have not been prescribed to him, that TS may have acted for his own purposes when collecting those data from the third party and when sending the email at issue (which contained the personal data) and that such set of processing operations was, at any rate, neither ‘normal’ nor necessary for the performance of TS’s duties as headteacher. According to RS, TS has therefore exceeded the margin of discretion granted to him and acted outside the scope of his duties under Austrian law.
34. I recall that, in preliminary ruling proceedings, the Court does not have the task of establishing the alleged facts but solely that of interpreting the relevant provisions of EU law. According to the case-law of the Court, questions on the interpretation of EU law are referred by a national court in the factual and legislative context which that court is responsible for defining, the accuracy of which is not a matter for the Court to determine. (14)
35. It follows that, notwithstanding RS’s arguments, which I have summarised in point 33 above, I shall limit myself, for the purposes of providing an answer to the first question, to the factual elements presented by the referring court as outlined in point 32 above.
36. Against that background, I take the view that a natural person who (like TS) processes personal data not in his or her own personal interest, but in the exercise of his or her duties as the head of an organisation (in casu, a school), and by means of the tools made available and prescribed to him or her by such an organisation, does not qualify as a ‘controller’, within the meaning of Article 4(7) of the GDPR. The Austrian and Italian Governments, as well as the Commission, also defend that position.
37. In that regard, I recall that the Court has held that Article 4(7) of the GDPR defines the concept of ‘controller’ broadly. The objective of that broad definition consists, in accordance with the objective pursued by that regulation, in ensuring effective protection of the fundamental rights and freedoms of natural persons and, in particular, a high level of protection of the right of every person to the protection of personal data concerning him or her. (15)
38. At the same time, the Court has emphasised that the controller must ‘[exert] influence over the processing of such data, for his, her or its own purposes’. (16) As such, it is clear that a natural or legal person, public authority, agency or another body who processes personal data on behalf of another, rather than for his, her or its own purposes, does not qualify as a ‘controller’, within the meaning of Article 4(7) of the GDPR.
39. That is confirmed by recital 74 of that regulation, which provides that the responsibility and liability of the controller is the same for ‘any processing of personal data carried out by the controller or on the controller’s behalf’, (17) as well as by the Court’s case-law on Article 29 thereof, which states that ‘any person acting under the authority of the controller … who has access to personal data, shall not process those data except on instructions by the controller …’. The Court has concluded from that provision that a controller may not be exempted from liability on the sole ground that that damage was caused by the wrongful conduct of a person acting under his, her or its authority. (18)
40. Furthermore, and as noted by the referring court in its request for a preliminary ruling, the Court’s case-law contains various examples in which the personal data at issue were processed by a natural person on behalf of a legal entity and where that entity (rather than the natural person) was nevertheless considered to be the ‘controller’. (19) In particular, the Court has ruled that legal persons (such as companies) are liable not only for infringements of the GDPR committed by their representatives, directors or managers, but also for those committed by any other person acting in the course of the business of those legal persons and on their behalf. (20) In my view, the same naturally applies to any ‘public authority, agency or other body’, to use the terms employed in Article 4(7) of the GDPR.
41. Those findings are consistent with the EDPB Guidelines 07/2020, which provide, in essence, that, even where a specific person is appointed by a legal entity (company or public body) as responsible for the implementation of the processing activity, the legal entity remains ultimately responsible, in its capacity as controller, in case of infringement of the rules. (21)
42. In my view, it follows from those considerations that the headteacher of a school who (like TS) processes personal data not in his or her own personal interest (that is to say, not for his or her own purposes) but as the head of such a public body, must be regarded as acting on behalf of the latter. In such a situation, the headteacher does not qualify as a ‘controller’, within the meaning of Article 4(7) of the GDPR. Rather, the school is the ‘controller’. (22)
43. That conclusion is not affected by the fact that the school itself does not have legal personality. Indeed, the Court has already stated that an entity may be considered a ‘controller’, within the meaning of that provision, even if that entity lacks legal personality. (23)
44. A different outcome would only be justified, in my view, if the referring court were to conclude, as part of its appreciation of the facts presented to it, that, in processing RS’s personal data, TS acted either outside the scope of his duties, that is to say, exclusively for his own purposes (in which case, he would be the sole ‘controller’), or for his own purposes as well as those of the school (as a joint controller). (24) If either of those situations were established in the main proceedings, I consider that TS would have to be regarded as determining not only the purposes, but also the means of the processing. Indeed, in so far as he used his professional email address, as well as the school computer and the independent server put at his disposal for his own purposes, the use of those means would be ‘unauthorised’, which could then not be regarded as being prescribed to him. However, it is for the referring court to make such a determination.
45. On the basis of the foregoing considerations, I propose that the Court answer the first question in the negative. In the light of that answer, I consider that it is not necessary for the Court to answer the second to fourth questions, which concern the obligations under Article 15(1)(g) and Article 82 of the GDPR to which a natural person such as TS would be subject if he or she were a ‘controller’, within the meaning of Article 4(7) of that regulation. (25) I believe that to be so, regardless of the fact that those questions are not explicitly formulated as being conditional upon the answer to the first question. (26)
46. Nevertheless, should the Court take a different view and, for the sake of completeness, I will now turn to the substantive issues raised by the second to fourth questions.
B. The scope of the right to information as to the source of personal data (Article 15(1)(g) of the GDPR) (Question 2)
47. The second question is composed of two parts. By the first part, the referring court asks whether, where the personal data which have been processed consist of a factual statement about or an evaluative assessment of the data subject in an email, Article 15(1)(g) of the GDPR must be interpreted as meaning that ‘any available information as to [the] source’ of the data refers only to the identity of the author of the email or whether it also refers to that of the persons with whom the author has (orally) discussed the data subject and on whose opinion such a factual statement or evaluative assessment is based.
48. To contextualise that question, I recall that, in the main proceedings, RS claims that he should be entitled, on the basis of Article 15(1)(g) of the GDPR, to find out from TS (who he considers to be a ‘controller’, within the meaning of Article 4(7) of that regulation) the identity of the third party (with whom TS discussed RS’s reputation), since that third party must be deemed the ‘source’ of the personal data – the opinion regarding RS – contained in the email at issue.
49. The second part concerns whether, should the Court find that the identity of such a third party amounts to ‘available information as to [the] source’ within the meaning of Article 15(1)(g) of the GDPR, it is relevant to the weighing up of the interests of the data subject and of such a person, that the latter could not have foreseen that his or her statements would be subject to processing.
1. The first part of Question 2
50. To begin with, I recall that the Court has held that the use of the expression ‘any information’ in the definition of the concept of ‘personal data’ in Article 4(1) of the GDPR reflects the aim of the EU legislature to assign a wide scope to that concept, which potentially encompasses all kinds of information, not only objective but also subjective, in the form of opinions and assessments, provided that it ‘relates’ to the data subject. (27)
51. As the referring court correctly assumes, it follows that an opinion (‘evaluative assessment’) concerning a data subject (here, RS) contained in an email (here, the email sent by TS to the University for Educational Sciences) amounts to ‘personal data’, within the meaning of Article 4(1) of the GDPR.
52. With regard to the ‘source’, within the meaning of Article 15(1)(g) of the GDPR, of such an opinion or of a factual statement about the data subject in an email, I note that neither that provision nor any other provision of that regulation defines that concept. In the absence of such a definition, it is necessary, in accordance with settled case-law, to consider not only the usual meaning of the term ‘source’ in everyday language, but also the context in which that provision occurs and the objectives pursued by the rules of which it is part. (28)
53. The ‘source’ of something is defined, in its ordinary meaning, as ‘the person, place or thing which you get it from’. (29) Accordingly, for the information that must be disclosed under Article 15(1)(g) of the GDPR, one must look at the origin of that personal data. Moreover, since Article 15(1)(g) of the GDPR only applies ‘where the personal data are not collected from the data subject’, it is clear that the ‘source’ cannot, under that provision, be the data subject him or herself.
54. As to the context of Article 15(1)(g) of the GDPR, I note that the term ‘source’ also appears in Article 14(2)(f) of that regulation, which provides for the right to obtain from the controller information regarding ‘which source the personal data originate’ from, (30) where they have not been obtained from the data subject him or herself. That confirms, in my view, that the term ‘source’ in Article 15(1)(g) of the GDPR means the origin of the personal data.
55. Finally, with regard to the objectives of the GDPR, it is important to recall that Article 15 of the GDPR ‘complements the framework of transparency organised by that regulation by granting the data subject a right of access to his or her personal data and a right to information regarding the processing of those data’. (31)
56. Paragraph 1(a) to (h) of that article seeks to give effect to the latter right. By providing that the data subject is entitled to information regarding the processing of his or her personal data, that provision enables him or her to assess the correctness of the personal data and the lawfulness of the processing, as well as effectively exercise the related rights provided in that regulation, inter alia the rights to rectification, erasure (‘the right to be forgotten’), restriction of processing and objection (32) – all of which seek to reinforce the data subject’s ‘control’ over his or her personal data. (33)
57. I consider that it is with regard to that particular function that the scope of the right to information as to the ‘source’ of the personal data in Article 15(1)(g) of the GDPR must be determined. (34) As such, one must consider whether the information sought under that provision is necessary for the data subject to ensure the correctness of his or her personal data or the lawfulness of the processing of those data, or for the data subject effectively to exercise his or her rights under that regulation. (35)
58. In my view, that is the case where, for example, the data subject relies on Article 15(1)(g) of the GDPR in order to ascertain the ‘source’ of inaccurate data concerning him or her so as to prevent those data from being further circulated between different controllers (36) (that is to say, prevent further ‘processing’), or where the disclosure of available information concerning the ‘source’ of the relevant personal data enables the data subject to identify that a prior processing operation, or set of operations, falling within the material scope of the GDPR, has been carried out in respect of the same data – with regard to which he or she is entitled to exercise his or her rights under that regulation.
59. Having made those clarifications, I note that the Commission and the Italian Government take the view that, where the relevant personal data consist of an opinion (‘evaluative assessment’) or a factual statement concerning the data subject contained in an email, the ‘source’ of such an opinion is the author of the email (here, TS). They argue that, in such a situation, Article 15(1)(g) of the GDPR must be interpreted as meaning that ‘any available information as to [the] source’ of the data does not include the identity of the persons with whom the author has (orally) discussed the data subject prior to forming his or her opinion or writing the factual statement about that subject.
60. I agree. However, in my view, such a conclusion can only be reached on the condition that the opinion (‘evaluative assessment’) or factual statement concerning the data subject in the email in question can indeed be attributed to the author of that email. In that regard, I agree with the Commission that the fact that the author alludes, in the email, to the views of other persons regarding the data subject is irrelevant, so long as the personal data in question (that is to say, the opinion or factual statement) can still be attributed to the author him or herself and does not amount to a mere citation of those views. Indeed, in the latter case, I consider that the ‘source’ of the personal data (the opinion) would be the third party or parties whose views are being cited and not the author of the email.
61. In casu, it is for the referring court to determine, in the light of the facts before it, whether the opinion (‘evaluative assessment’) concerning RS contained in the email at issue is actually attributable to TS or whether, conversely, it merely consists of the views previously expressed to TS by a third party (namely, the other teacher with whom TS discussed RS), which TS simply reproduced or cited in the email, as RS appears to contend. (37) Should that court determine that the opinion about RS in the email at issue is attributable to TS, then I consider – in agreement with the Commission and the Italian Government – that RS’s right to information as to the ‘source’ of that opinion, in Article 15(1)(g) of the GDPR, could not extend to receiving information concerning such a third party, as only TS could be considered as the ‘source’ of the opinion in question.
62. Nevertheless, the referring court wonders whether it follows from the fact that Article 15(1)(g) of the GDPR refers not only to the ‘source’ of the relevant personal data, but also to ‘any available information as to [that] source’, that, even where the ‘source’ of an opinion or factual statement concerning the data subject in an email is the author of the email, the data subject is entitled to receive information about the elements or individuals that contributed to the formation of such an opinion or to the author formulating such a factual statement (such as the identity of a third party with whom the author had an oral conversation).
63. In that regard, first, I share the Italian Government and the Commission’s view that such an interpretation of Article 15(1)(g) of the GDPR would be too extensive, given the myriad of elements that may come into play, particularly when forming an opinion. To take an example, let us consider the facts of the case which gave rise to the judgment in Nowak . (38) Part of the personal data at issue was the examiner’s subjective comments on an examination sheet. In such a situation, could ‘any available information as to the source’ of the personal data, within the meaning of Article 15(1)(g) of the GDPR, encompass any information concerning persons with whom the examiner may have interacted while assessing the examination sheets – ranging, for example, from a colleague who gave advice on assessing the candidates’ answers to a neighbour making a particularly irritating noise, thereby exasperating the examiner to such an extent that he marked more harshly than he otherwise would have? In my view, it could not.
64. Second, and with reference to the specific function of the right to information as to the source of the personal data in Article 15(1)(g) of the GDPR which I have outlined in point 57 above, I fail to see how obtaining information about the identity of a third party who is not the ‘source’ of the relevant personal data (here, an opinion or a factual statement about the data subject in an email), but who merely contributed to the formation of such an opinion or to the author of the email formulating such a statement following an oral conversation with him or her, would enable the data subject to ensure the correctness of his or her personal data or the lawfulness of the processing of those data, or to exercise his or her rights under the GDPR.
65. Third, as already stated in points 25 and 26 above, recital 4 of the GDPR makes clear that the right to the protection of personal data is, at any rate, ‘not an absolute right’ and ‘must be considered in relation to its function in society and be balanced against other fundamental rights’, including the right to freedom of thought and expression. The same holds true in respect of the various rights which data subjects derive from the GDPR and which seek to give practical effect to the right to the protection of personal data, such as the right of access to personal data provided for in Article 15 of the GDPR, (39) which the Court has found should not adversely affect the rights or freedoms of others. (40) It goes without saying that a similar balancing exercise must also be undertaken in relation to the right to information as to the source of the personal data under Article 15(1)(g) of the GDPR.
66. Against that background, it is clear to me that disclosing the identity of a third party who is not him or herself the ‘source’ of the relevant personal data (here, an opinion or factual statement concerning the data subject in an email), but who merely contributed to the formation of such an opinion or to the author of the email formulating such a statement following an oral conversation with him or her, would unduly place the balance in favour of the data subject by adversely affecting numerous rights or freedoms of the third party, in particular his or her right to freedom of thought and expression (41) or to privacy and respect for communications. (42)
67. It follows from those considerations that, where the ‘source’ of an opinion (‘evaluative assessment’) or factual statement concerning the data subject in an email is the author of the email him or herself, the data subject is not entitled, under Article 15(1)(g) of the GDPR, to receive information about the elements or persons (such as the identity of a third party with whom the author had an oral conversation) that contributed to the formation of such an opinion or to the author formulating such a factual statement.
68. By way of final remark, I recall that Article 15(1)(g) of the GDPR confers on data subjects a right to ‘any available information as to the source’ of the personal data concerning them, not a right to have any information as to the source of the personal data and the sources of that source. If, contrary to my suggestion, the Court were to adopt the interpretation of that provision outlined in point 62 above, the consequence would be that, where the source of the personal data is, for example, a file or record, the data subject would be entitled under Article 15(1)(g) of the GDPR not only to ‘any available information’ as to that file or record, but also to any prior file or record on which it is based. The scope of that provision would, in other words, become unlimited.
2. The second part of Question 2
69. The second part of the second question concerns the situation where a third party, rather than the author of the email, must be regarded as the ‘source’ of the personal data in question – here, an opinion or a factual statement concerning the data subject contained in an email. As I explained in point 60 above, that situation would arise only where the opinion or statement in the email is not attributable to the author of the email because it merely consists of a reproduction or citation of views previously expressed by the third party.
70. In my view, in such a situation, it is clear that the balancing exercise referred to in point 65 above would likewise apply. In other words, disclosure of the identity of the ‘source’ of the relevant personal data under Article 15(1)(g) of the GDPR would not be automatic. The rights and freedoms of the person who is considered the ‘source’ must also be taken into account and weighed up against the right of the data subject to obtain information as to the source of the personal data, under that provision.
71. In that regard, the fact that the third party in question could not have foreseen that his or her statements would be subject to processing constitutes a relevant factor. Indeed, it suggests that the third party engaged in what he or she assumed to be a confidential or private conversation, the contents of which, and the fact of his or her participation therein, he or she did not expect to be shared with the data subject by virtue of the provisions of the GDPR. In my view, in such a situation, particular emphasis would need to be placed on the importance of respecting the third party’s right to freedom of thought and expression (43) and to privacy and respect for communications. (44)
72. Furthermore, I fail to see how, even where the opinion or statement concerning the data subject in an email consists merely of a reproduction or citation of views previously expressed orally by the third party, obtaining information as to the identity of that party (the ‘source’), in application of Article 15(1)(g) of the GDPR, could contribute to fulfilling the objective served by that provision, which is, as I have recalled in point 57 above, to enable the data subject to ensure, inter alia, the correctness of his or her personal data. Indeed, opinions are, by nature, inherently subjective. This means that, unlike factual statements, their accuracy or correctness is difficult to verify. (45)
C. The right to compensation under Article 82 of the GDPR for breach of Article 15(1) of the GDPR (Question 3)
73. By the third question, the referring court enquires as to whether the adverse consequences suffered by a data subject as a result of a controller’s breach of the obligation to provide the information laid down in Article 15(1) of the GDPR (in casu, the obligation under point (g) thereof to provide information as to the ‘source’ of the personal data collected) constitute ‘damage caused by processing which infringes [that] [r]egulation’, within the meaning of Article 82(2) of the GDPR, thereby giving rise to the controller’s liability and a corresponding obligation for him or her to compensate the data subject.
74. As that court explains, it asks, in essence, the Court of Justice to clarify whether a breach of that obligation may give rise to a claim for compensation of the data subject under Article 82 of the GDPR, taken as a whole. In more concrete terms, should TS be regarded as a ‘controller’, within the meaning of Article 4(7) of that regulation and as having acted in breach of Article 15(1)(g) thereof, would RS be entitled to compensation under Article 82 of the GDPR? I thus propose that the Court reformulate the third question so as to include the interpretation of that provision in its entirety, instead of only referring to paragraph 2 thereof. (46)
75. Turning now to the interpretation of Article 82 of the GDPR I understand that the referring court’s doubts regarding the interpretation of that provision arise from the fact that the obligation to provide information laid down in Article 15(1) of that regulation only comes into existence after the relevant processing of personal data took place, (47) as well as where no processing has in fact occurred at all, (48) whereas Article 82(2) of the GDPR refers to ‘damage caused by processing …’. (49) In the light of that wording, it could be assumed, as that court appears to do, that the right to compensation provided for in Article 82 of that regulation arises only in respect of damage caused by processing contrary to the GDPR, and not in respect of damage resulting from an infringement of an obligation provided in that instrument which, like the obligation to provide information laid down in Article 15(1) thereof, takes place after or irrespective of such processing.
76. However, in my view, it is clear that the right to compensation provided for in the former provision extends to damage caused by a breach of that obligation.
77. First, with regard to the legislative history of Article 82 of the GDPR, I recall that the corresponding provision of its predecessor, Article 23 of Directive 95/46, referred to a ‘damage as a result of an unlawful processing operation or of any act incompatible with the national provisions adopted pursuant to [Directive 95/46]’. It is clear that, when adopting the GDPR, the EU legislature had no intention of reducing the level of protection granted to data subjects, in comparison to that afforded to them under Directive 95/46, quite the contrary. (50)
78. In that regard, I further note that, during the legislative process leading to the adopting of the GDPR, the Council suggested limiting the right to compensation of data subjects to damages which are the ‘result of a processing operation which is not in compliance with [the GDPR]’. (51) That limitation does not however appear in the final version of Article 82 of that regulation.
79. Second, Article 82 of the GDPR serves a dual function. On the one hand, it provides the data subject with a right to compensation and establishes, as a matter of principle, the corresponding liability of the controller or processor for the damage suffered (Article 82(1)). On the other hand, it sets out the specific conditions in which the controller or processor or both may be held liable (or exempted from liability) for that damage, as well as how liability should be allocated between them when several parties were involved in the data processing in question (Article 82(2) to (5)).
80. It follows that the purpose of Article 82(2) of the GDPR is not to determine the scope of the right to compensation of data subjects as such. Rather, it is to specify the rules on liability – the principle of which is established in paragraph 1 of that article. (52)
81. The scope of the right to compensation must, for its part, be determined in the light of the wording of Article 82(1) of the GDPR, which does not contain the same restriction as paragraph 2 of that article, as it states in more general terms that ‘any person who has suffered material or non-material damage as a result of an infringement of [that] [r]egulation shall have the right to receive compensation from the controller or processor for the damage suffered’. (53) No mention is made of ‘processing’.
82. In the light of those elements, I consider that the reference to ‘damage caused by processing’ in Article 82(2) of the GDPR cannot be interpreted as restricting the scope of the right to compensation provided for in Article 82(1) of that regulation to such damage alone. A similar conclusion was reached by Advocate General Szpunar in the Opinion in Brillen Rottler, (54) in which he described paragraph 2 of Article 82 of the GDPR as a ‘complementary provision’ and not as a limitation of paragraph 1 of that article.
83. Furthermore, in the recently issued judgment in that case, (55) the Court expressly ruled that, since Article 82(1) of the GDPR does not contain a reference to ‘processing’, ‘the right to compensation cannot be limited to damage resulting from the processing of personal data’. (56)
84. In that judgment, the Court also recalled that Article 82(1) of the GDPR is contained in Chapter VIII of that regulation, which governs remedies, the rules for liability and penalties to protect those rights, and that it must be read in the light of recital 141 of the GDPR, which provides that every data subject should have the right to an effective judicial remedy in accordance with Article 47 of the Charter ‘if [he or she] considers that his or her rights under [that] regulation are infringed’. (57) The Court added that that encompasses a data subject’s right of access to his or her personal data under Article 15(1) of the GDPR. That right, along with the other rights granted to data subjects by Article 15 of that regulation, including the right to obtain the information listed in points (a) to (h) of paragraph 1, must thus be protected by Article 82 of the GDPR, which must therefore be interpreted as applying to damage resulting from infringements of those rights.
85. Third, it is clear to me that limiting the data subject’s right to receive compensation under that provision to damage caused by unlawful data processing would also be incompatible with the objectives pursued by that regulation as a whole, which, as I have stated in point 24 above, are to ensure a ‘high level of protection’ and ‘strengthen … the rights of data subjects and the obligations of those who process and determine the processing of personal data’. In the judgment in Brillen Rottler, (58) the Court stated, in essence, that Article 82 of the GDPR seeks to ensure the implementation of those objectives.
86. As the Commission correctly pointed out, if the data subject’s right to receive compensation under that provision were limited to damage caused by unlawful data processing, this would affect not only the protection of the rights provided for in Article 15 thereof, but also nearly all of the rights of data subjects under Chapter III of the GDPR, (59) which would become largely symbolic. (60) Indeed, each of those rights comes with a corresponding obligation on controllers, to which they become subject only after (61) the (alleged) data processing in question has taken place. (62)
87. For those reasons, I consider that the adverse consequences suffered by a data subject as a result of an infringement of the obligation to provide information under Article 15(1) of the GDPR may be regarded as constituting ‘damage’, within the meaning of Article 82 thereof, thereby leading to an obligation for the controller to pay compensation to the data subject under that provision.
D. Whether Article 82 of the GDPR precludes national rules which provide for the exclusion of liability of the controller (Question 4)
88. I shall now turn to the fourth question by which the referring court asks, in the event that the first or third questions are answered in the affirmative, whether Article 82 of the GDPR precludes national rules providing that persons acting as ‘executive officers’ – that is to say, on behalf of – certain public legal entities cannot be held liable for the damage which they cause to data subjects, in their capacity as controllers or processors.
89. That question is raised in relation to certain specific features of Austrian law, namely those set out in Paragraph 1 of the Law on public liability, which provides that persons acting as ‘executive officers’ of the Federation, the Länder, municipalities, other bodies of public law and the institutions of social insurance are, in the execution of the law, not liable for the damage which they cause to any person due to their unlawful conduct. Consequently, a claim for compensation for damage cannot be brought against such persons under Article 82 of the GDPR. (63)
90. In casu, I understand that TS, in his capacity as headteacher of a primary school in Austria, must be regarded as acting as an ‘executive officer’ of the relevant Land (since, under Austrian law, schools do not have legal personality and, therefore, cannot be sued). It follows from Paragraph 1 of the Law on public liability that, even if TS satisfied all the conditions necessary to qualify as a ‘controller’ within the meaning of Article 4(7) of the GDPR with regard to the processing of personal data at issue in the main proceedings (which, as explained, I do not believe to be the case), RS could not bring a claim for compensation against him under Article 82 of that regulation in respect of the damage allegedly caused by TS’s breach of Article 15(1)(g) thereof. The referring court wonders whether such a national provision is contrary to Article 82 of the GDPR.
91. I think not. Indeed, a national provision such as Paragraph 1 of the Law on public liability does not, in itself, prevent a data subject from bringing a claim for compensation where the relevant breach of the GDPR was carried out by a person acting on behalf of a public legal entity. Rather, it merely shifts the liability for compensation onto the entity in question.
92. It appears that the main objective of such a shift of liability is to ensure the protection of the victim by providing him or her with a solvent debtor. (64) Thus, contrary to what the applicant argues, the rationale behind a national provision such as Paragraph 1 of the Law on public liability is not to restrict the legal protection for data subjects, but rather to enhance it.
93. In the light of those considerations, I fail to see how such a national provision could be regarded as incompatible with Article 82 of the GDPR.
94. I acknowledge that Article 82(2) of that regulation, which states that ‘any controller involved in processing shall be liable for the damage caused by processing which infringes the [GDPR]’, could, prima facie, be understood as requiring the direct liability of the controller.
95. However, the underlying rationale of Article 82 of the GDPR is, as the Court has consistently held, (65) to provide the data subject with full and effective compensation for damage suffered as a result of an infringement of the GDPR. (66) As I have already noted in point 84 above, that provision is contained in Chapter VIII of that regulation, which governs remedies, the rules for liability and penalties to protect those rights. It must thus be read in the light of recital 141 of the GDPR, which expressly refers to the right of data subjects to an effective judicial remedy in accordance with Article 47 of the Charter, when their rights under that regulation are infringed.
96. In my view, it therefore does not matter whether compensation is paid directly by the controller or processor or by the public legal entity that employs or is responsible for such a person. What matters is that the damage actually suffered by the data subject as a result of an infringement of the GDPR be compensated in full.
97. That conclusion is not affected by a comparison between Article 82 of the GDPR and Article 83(7) thereof, which expressly leaves it to the discretion of the Member States to determine the extent to which administrative fines may be imposed on public authorities and bodies. According to RS, the absence of any similar discretion in Article 82 of the GDPR can only be interpreted as meaning that Member States are not allowed to exempt public authorities and bodies, and thus executive officers, from claims for damages under private law.
98. That argument however overlooks the fact that Article 82 and Article 83 of the GDPR pursue different objectives. (67) The former provision has an exclusively compensatory function (in other words, it relates to the compensation of the data subject for damage suffered), whereas the latter serves a punitive purpose. (68) I consider that, because of that punitive purpose, the administrative fines must, in principle, be directly ‘tied’ to the controller or processor in question.
99. Furthermore, as explained in point 91 above, a national provision such as Paragraph 1 of the Law on public liability merely shifts the liability for compensation from a person acting on behalf of a legal entity onto the entity in question. (69) By contrast, when a Member State sets out rules on the basis of Article 83(7) of that regulation, it may exclude the imposition of administrative fines on its public authorities and bodies altogether.
100. In those circumstances, I consider that Article 82 of the GDPR does not preclude national rules pursuant to which persons acting on behalf of certain public legal entities cannot be held liable for the damage which they cause to data subjects, in their capacity as controllers or processors, provided that those rules also identify the entity against which a claim for compensation may be brought by such data subjects.
V. Conclusion
101. In the light of the foregoing considerations, I propose that the Court answer the questions referred for a preliminary ruling by the Oberster Gerichtshof (Supreme Court, Austria) as follows:
Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
must be interpreted as meaning that a natural person who, in the exercise of his or her duties, processes personal data not in his or her own personal interest but as the head of an organisation, and by means of the tools made available and prescribed to him or her by such an organisation, does not qualify as a ‘controller’, within the meaning of that provision.
1 Original language: English.
i The name of the present case is a fictitious name. It does not correspond to the real name of any party to the proceedings.
2 Regulation of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ 2016 L 119, p. 1) (‘the GDPR’).
3 See Article 4(1) of the GDPR.
4 Ibid.
5 See recital 7 of the GDPR.
6 See recital 11 of the GDPR.
7 See Article 1(2) of the GDPR and recital 10 thereof.
8 See recital 7 of the GDPR. That regulation is based on a conception of the data subject as an active individual, capable of decision-making as regards the personal data concerning him or her (see Spiecker gen. Döhmann, I., Papakonstantinou, V., Hornung, G. and De Hert, P., General Data Protection Regulation: Article-by-Article Commentary, Nomos, Baden-Baden, 2023, p. 86).
9 ‘Processing’ is defined under Article 4(2) of the GDPR as ‘any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction’.
10 See Article 15(1) of the GDPR: ‘the data subject shall have the right to obtain from the controller …’ (emphasis added).
11 In such a situation, the ‘purposes and means of the processing of personal data’ are themselves determined by European Union or Member State law.
12 See judgment of 10 July 2018, Jehovan todistajat (C‑25/17, EU:C:2018:551, paragraph 68). That judgment concerned the interpretation of the concept of ‘controller’ as it was defined under Article 2(d) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (OJ 1995 L 281, p. 31). Although that directive is no longer in force and has been replaced by the GDPR, the interpretation given by the Court with regard to that provision remains relevant within the context of the application of the GDPR, given that the definition of that concept remains identical in both instruments, save for minor formal modifications. Thus, I will refer to judgments relating to one or the other instrument without distinction.
13 See, also, in that regard, ‘Guidelines 07/2020 on the concepts of controller and processor in the GDPR’ of the European Data Protection Board (EDPB), version 2.1, adopted on 7 July 2021 (‘the EDPB Guidelines 07/2020’, available at: https://edpb.europa.eu/system/files/2021-07/eppb_guidelines_202007_controllerprocessor_final_en.pdf), p. 3 and paragraphs 21 and 25 to 27.
14 See judgment of 4 October 2024, Bezirkshauptmannschaft Landeck (Attempt to access personal data stored on a mobile telephone) (C‑548/21, EU:C:2024:830, paragraph 41 and the case-law cited).
15 See judgment of 5 December 2023, Nacionalinis visuomenės sveikatos centras (C‑683/21, EU:C:2023:949, paragraph 29).
16 Ibid., paragraph 30.
17 Emphasis added.
18 See judgment of 11 April 2024, juris (C‑741/21, EU:C:2024:288, paragraphs 47 to 49).
19 Ibid. See, also, in that regard, judgments of 22 June 2023, Pankki S (C‑579/21, EU:C:2023:501); of 5 December 2023, Deutsche Wohnen (C‑807/21, EU:C:2023:950); and of 25 January 2024, MediaMarktSaturn (C‑687/21, EU:C:2024:72), in which the ‘controllers’ were found to be companies, even though the alleged ‘processing’ had been carried out by the employees of those companies.
20 See judgment of 5 December 2023, Deutsche Wohnen (C‑807/21, EU:C:2023:950, paragraph 44).
21 See paragraphs 18 and 19 of those guidelines.
22 I agree with the Commission that, by the first question, the referring court merely enquires as to whether a person such as TS qualifies as a ‘controller’, within the meaning of Article 4(7) of the GDPR. Thus, should the Court of Justice agree with my view that that question must be answered in the negative, I do not think that it would be necessary for it to determine whether the school or the relevant Land should be considered the ‘controller’ instead of TS.
23 See, to that effect, judgment of 27 February 2025, Amt der Tiroler Landesregierung (C‑638/23, EU:C:2025:127, paragraphs 30 to 34). See, also, judgment of 11 January 2024, État belge (Data processed by an official journal) (C‑231/22, EU:C:2024:7, paragraph 36).
24 See, in that regard, judgment of 7 March 2024, IAB Europe (C‑604/22, EU:C:2024:214, paragraphs 56 to 59). For an example where an entity (religious community) and the members of that entity were actually found to be joint controllers, see judgment of 10 July 2018, Jehovan todistajat (C‑25/17, EU:C:2018:551).
25 See, in that regard, my Opinion in Lindenberg (C‑205/25, EU:C:2026:312, ‘my Opinion in Lindenberg’), in point 49 of which I state that Article 15 of the GDPR may be exercised only against the controller.
26 That is true even of the fourth question, which is asked only ‘if Question 1 or 3 is answered in the affirmative’ (emphasis added).
27 See, in that regard, judgments of 20 December 2017, Nowak (C‑434/16, EU:C:2017:994, paragraph 34), on the concept of ‘personal data’ as it was defined under Article 2(a) of Directive 95/46, and of 2 December 2025, Russmedia Digital and Inform Media Press (C‑492/23, EU:C:2025:935, paragraph 49). See, also, in that regard, ‘Guidelines 01/2022 on data subject right – Right of access’ of the EDPB, version 2.1, adopted on 28 March 2023 (‘the EDPB Guidelines 01/2022’, available at: https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-012022-data-subject-rights-right-access_en), paragraph 96.
28 See judgment of 19 March 2026, Brillen Rottler (C‑526/24, EU:C:2026:216, paragraph 24 and the case-law cited).
29 See the definition of the term ‘source’ given by the online version of the Collins Dictionary, available at: https://www.collinsdictionary.com/dictionary/english/source. According to the online Cambridge Dictionary, the term ‘source’ is usually understood to mean the place from where something comes or someone or something that supplies information (https://dictionary.cambridge.org/dictionary/english/source).
30 Emphasis added.
31 See judgment of 9 January 2025, Österreichische Datenschutzbehörde (Excessive requests) (C‑416/23, EU:C:2025:3, paragraph 46).
32 See, to that effect, judgment of 22 June 2023, Pankki S (C‑579/21, EU:C:2023:501, paragraphs 56 to 59 and the case-law cited). See also, in that regard, recital 63 of the GDPR (point 6 above).
33 See point 24 above.
34 See, by analogy, point 58 of my Opinion in Lindenberg, in which I consider that the scope of the right to obtain a copy under Article 15(3) of the GDPR remains strictly circumscribed by its function.
35 See, again, to that effect, judgment of 22 June 2023, Pankki S (C‑579/21, EU:C:2023:501, paragraphs 69 to 75), in which the Court analyses whether the disclosure of the relevant information may be necessary to ensure fair and transparent processing, thus enabling the data subject fully to assert his or her rights under that regulation.
36 See the EDPB Guidelines 01/2022, paragraph 36.
37 Indeed, RS claims that, where the information received during an oral conversation with a third party is reproduced in an email exactly as it was received (as is, in his view, the case in the main proceedings), the third party him or herself must be considered as the ‘source’ of the personal data contained in the email.
38 Judgment of 20 December 2017 (C‑434/16, EU:C:2017:994).
39 See recital 63 of the GDPR.
40 See, also, in that regard, judgment of 22 June 2023, Pankki S (C‑579/21, EU:C:2023:501, paragraph 77).
41 See Article 11 of the Charter and Article 10 of the Convention for the Protection of Human Rights and Fundamental Freedoms (ECHR).
42 As protected under Article 7 of the Charter and Article 8 ECHR.
43 See Article 11 of the Charter and Article 10 ECHR.
44 As protected under Article 7 of the Charter and Article 8 ECHR.
45 Having said that, I acknowledge that, in such a situation, obtaining information concerning the identity of the source may enable the data subject to prevent his or her personal data from being further circulated between different controllers (that is to say, to prevent further ‘processing’) (see point 58 above). However, that consideration alone is not sufficient, in my view, to justify disclosure of the identity of the source (the third party) to the data subject.
46 In that regard, I recall that, in the procedure laid down by Article 267 TFEU providing for cooperation between national courts and the Court, it is for the latter to provide the national court with an answer which will be of use to it and will enable the national court to determine the case before it. To that end, the Court should, where necessary, reformulate the questions referred to it and consider provisions of EU law which the national court has not referred to in its question. (see judgment of 30 April 2026, Lidl Italia (Unfair commercial practices concerning food), C‑301/25, EU:C:2026:357, paragraph 25).
47 The data subject is only entitled to receive from the controller the information listed under Article 15(1)(a) to (h) of the GDPR where personal data concerning him or her are being processed.
48 Under Article 15(1) of the GDPR, the data subject shall also have ‘the right to obtain from the controller confirmation as to whether or not personal data concerning him her or her are being processed’ (emphasis added).
49 Emphasis added. See, also, Article 82(4) of the GDPR and recital 146 thereof, which mentions ‘any damage which a person may suffer as a result of processing’.
50 See, also, in that regard, Opinion of Advocate General Szpunar in Brillen Rottler (C‑526/24, ‘the Opinion in Brillen Rottler’, EU:C:2025:723, points 69 to 71).
51 See, in that regard, Note from the Presidency of the Council, No 9565/15, of 11 June 2015, ‘Proposal for a Regulation of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) – Preparation of a general approach’, available at: https://data.consilium.europa.eu/doc/document/ST-9565-2015-INIT/en/pdf (p. 185).
52 See judgment of 4 October 2024, Agentsia po vpisvaniyata (C‑200/23, EU:C:2024:827, paragraph 159). See, also, in that regard, the Opinion in Brillen Rottler, in which the Advocate General explains at point 70 that Article 82(2) of the GDPR introduced the liability of the processor, which did not feature in Article 23 of Directive 95/46.
53 Emphasis added.
54 Point 73.
55 See judgment of 19 March 2026, Brillen Rottler (C‑526/24, ‘the judgment in Brillen Rottler’, EU:C:2026:216).
56 See paragraph 48. In paragraph 59 of that judgment, the Court also recalled its well-established case-law pursuant to which, in order for a right to compensation to arise, a causal link must be established between the damage suffered and an infringement of the GDPR, broadly understood. To the best of my knowledge, the more restrictive requirement of a causal link between that damage and ‘unlawful processing’ (rather than an ‘infringement of the GDPR’) appears only in the judgment of 4 October 2024, Agentsia po vpisvaniyata (C‑200/23, EU:C:2024:827, paragraph 159). It also appears in paragraph 36 of judgment of 4 May 2023, Österreichische Post (Non-material damage in connection with the processing of personal data) (C‑300/21, EU:C:2023:370); yet, paragraph 32 refers, more generally to an ‘infringement of the GDPR’.
57 Paragraph 49.
58 Paragraph 53.
59 That chapter includes, apart from the various rights to information laid down in Articles 12 to 15, the right to rectify personal data (Article 16), the right to erase such data (Article 17), the right to restrict the processing of personal data (Article 18) and the right to data portability (Article 20).
60 See, to that effect, the judgment in Brillen Rottler, paragraph 53.
61 Chapter III of the GDPR also includes the right to object ‘at any time’ to processing of personal data (Article 21 of the GDPR). Unlike the other rights listed in that chapter, it seems to me that that right must be exercised while those data are being processed, as it gives rise, in principle, to an obligation for the controller to no longer process the personal data in question.
62 The same is true of other obligations imposed on controllers by Chapter III of the GDPR, such as those provided for in Articles 26 and 30 of that regulation, the infringement of which does not constitute ‘unlawful processing’ (see, in that regard, the judgment in Brillen Rottler, paragraph 52 and the case-law cited).
63 See, in that regard, Paragraph 9(5) of the Law on public liability, whose content I have recalled in point 11 above.
64 See, in that regard, Kucsko-Stadlmayer, G., ‘Art. 23 BV-G’, in Korinek, K., Holoubek, M. et al (eds), Österreichisches Bundesverfassungsrecht, Verlag Österreich, 2013. The constitutional basis of Paragraph 1 of the Law on public liability is Article 23 of the Bundes-Verfassungsgesetz (‘B-VG’; ‘the Federal Constitutional Law’).
65 See, in that regard, judgments of 4 October 2024, Patērētāju tiesību aizsardzības centrs (C‑507/23, EU:C:2024:854, paragraph 34 and the case-law cited), and of 4 September 2025, Quirin Privatbank (C‑655/23, EU:C:2025:655, paragraph 78 and the case-law cited).
66 See also, in that regard, recital 146 of the GDPR which states that ‘data subjects should receive full and effective compensation for the damage they have suffered.’
67 See, in that regard, judgments of 11 April 2024, juris (C‑741/21, EU:C:2024:288, paragraph 56), and of 20 June 2024, PS (Incorrect address) (C‑590/22, EU:C:2024:536, paragraph 38).
68 See, in that regard, judgments of 20 June 2024, Scalable Capital (C‑182/22 and C‑189/22, EU:C:2024:531, paragraphs 2 and 23 and the case-law cited); of 20 June 2024, PS (Incorrect address) (C‑590/22, EU:C:2024:536, paragraph 41); and of 4 September 2025, Quirin Privatbank (C‑655/23, EU:C:2025:655, paragraph 70 and the case-law cited).
69 In that regard, I note that the shift of liability operated by paragraph 1 of the Law on public liability does not necessarily lead to a full exemption of liability of the ‘executive officer’ in question. Indeed, pursuant to Article 23(2) of the Federal Constitutional Law and Paragraph 3 of the Law on public liability, a public legal entity that has compensated a data subject for damage caused by one of its ‘executive officers’ may claim reimbursement from the persons who acted as its ‘executive officer’ where the latter acted with intent or gross negligence.