Case 2 – Right of access concerning a non-public work email address (2026)

In January 2026, I received an unsolicited business email at my work email address.

Unlike several previous cases involving my private email address,
this communication was sent to a work email address that, to my knowledge,
was not publicly available. Since I did not know how the address had been obtained,
I asked the sender to explain the source of my contact information.

During the initial correspondence, I was informed that my contact details would be removed.
When I sought clarification concerning the origin of the email address,
I was initially informed that, based on the information then available,
it could not be determined when or through which specific contact point the address had originally been recorded.

Because the origin of the address was unclear to me, I submitted a complaint to the Austrian
Data Protection Authority (https://dsb.gv.at/) concerning my right of access under Article 15 GDPR.

Subsequent identification of the data source

During the subsequent correspondence, the company was able to identify the source
from which my work email address had been obtained and informed me that it originated
from an external business contact data provider.

I considered this development positive and important. In particular, I was positively
surprised that the origin of the data could still be reconstructed after I had previously
been informed that my email address had been removed.

The source of the email address was therefore ultimately clarified.

The remaining dispute concerned, among other procedural questions, whether Article 15 GDPR
entitled me to obtain the identity of the individual employee involved in the processing of my personal data.

Decision of the Austrian Data Protection Authority

In August 2026, the Austrian Data Protection Authority issued its decision and dismissed my complaint as unfounded.

I fully respect and accept this decision.

The Authority concluded that the information concerning the source of my email address
had been provided within the applicable timeframe. It therefore found no outstanding
infringement of my right of access in this respect.

The decision also clarified an aspect of Article 15 GDPR that I had not previously
understood in sufficient detail.

In particular, the identity of an employee acting under the authority and instructions
of a controller is not automatically information that must be disclosed to a data subject
under Article 15 GDPR. The Authority’s reasoning, referring to the relevant case
law of the Court of Justice of the European Union, explained that disclosure
of an employee’s identity may depend, among other considerations, on whether that
information is essential for the effective exercise of the data subject’s GDPR rights
and on the rights and freedoms of the employee concerned.

In my case, the Authority found that such a necessity had not been established.

I found this part of the decision particularly informative. It provided me with a
clearer understanding of the distinction between obtaining information about what
happened to one’s personal data and obtaining the identity of an individual employee
who performed processing operations within an organisation.

The decision also provided an important lesson concerning the scope of proceedings
before the Data Protection Authority. My original request had been formulated narrowly
around the source of my email address and the identity of the employee involved.
During the subsequent proceedings, I raised additional questions concerning other elements of Article 15 GDPR.

The Authority explained that these additional matters could not simply become
part of the existing proceedings because the subject matter of the complaint
was determined by the scope of the original request. This does not mean that the
Authority decided those additional questions against me.
Rather, they were outside the subject matter that could be decided in this particular proceeding.

This distinction is valuable for future cases: when exercising the right of access,
it is important to define clearly from the beginning whether a request concerns
only particular information or whether complete access under Article 15 GDPR is being sought.

Separate question concerning Article 14 GDPR

The proceedings described above concerned my right of access under Article 15 GDPR.
After studying the decision and the GDPR provisions more closely, I identified a separate
legal question concerning Article 14 GDPR, which governs information that must,
subject to the conditions and exceptions laid down in that provision,
be provided when personal data have not been obtained directly from the data subject.

This question is distinct from the Article 15 proceedings described above. The first
business communication I received did not itself explain that my work email address
had been obtained from an external business contact data provider.
The concrete source became known to me only through the subsequent correspondence.

I therefore intend to examine separately whether the information requirements applicable
under Article 14 GDPR, including the relevant timing requirements, were fulfilled
in connection with the original processing and first communication.

If I pursue this question before the Austrian Data Protection Authority,
I will do so as a separate matter, clearly distinguishing it from the Article 15 proceedings already concluded.

No conclusion regarding an infringement of Article 14 GDPR is expressed here.
Whether the relevant information obligations were fulfilled is a separate
legal question that has not been determined in the Article 15 proceedings described on this page.

Conclusion

Although my Article 15 complaint was ultimately dismissed, I regard the proceedings as valuable.

The source of my work email address was ultimately identified, and the Authority’s decision
gave me a substantially better understanding of both the scope and the limits of the right
of access under Article 15 GDPR.

The case also taught me an important procedural lesson: different GDPR rights should
be clearly distinguished, and the precise scope of an access request and any subsequent
complaint can determine which questions an authority is able to examine.

For that reason, I fully accept the outcome of the Article 15 proceedings while separately
considering the transparency questions that may arise under Article 14 GDPR.

The purpose of documenting this case is not to accuse or criticize any particular company
or individual. It is to document my experience in exercising data protection rights and
what I learned from the resulting proceedings before the Austrian Data Protection Authority.