Status: Pending before the Austrian Data Protection Authority
Year: 2026
Relevant GDPR provisions: Articles 12, 14 and 15 GDPR
Main issue: Source, legal basis and onward disclosure of a private telephone number
- Background
This case concerns the processing of my private telephone number within the business-contact and data-enrichment ecosystem.
The number is particularly significant because, unlike a professional email address that may sometimes be derived from a company’s naming convention, my private telephone number is not information that I knowingly made publicly available for commercial contact-data purposes.
The case began when I learned that a business-contact data platform held a profile concerning me containing professional information as well as my private telephone number.
According to information communicated to me by that platform, the profile had been created on 13 August 2025. I became aware of the relevant provenance information on 20 February 2026.
Most importantly, the platform identified another company as the source from which it had allegedly obtained my work email address and private telephone number.
This created a straightforward but important question:
Where had that company obtained my private telephone number in the first place?
- Attempt to establish the origin of the data
After receiving this information, I contacted the company that had been identified as the apparent source.
I initially attempted to obtain clarification through the company’s website and by contacting a person professionally associated with the company through LinkedIn.
My request was specific.
I explained that the business-contact platform had informed me that it had obtained my private telephone number from the company and asked whether this information was correct.
I requested, in particular:
confirmation whether the company processed my private telephone number;
the exact source from which the number had been obtained;
identification of any third-party provider, partner, database or organisation that had supplied it;
the legal basis under Article 6 GDPR for processing the number; and
information concerning the recipients to whom the number had been disclosed.
I also expressly stated that I was not requesting deletion at that stage. My objective was transparency concerning the origin and disclosure of the personal data.
This distinction was important.
Deleting the number before understanding its provenance would not answer the central question of the case: how a private telephone number had entered this data chain and how it had subsequently reached another organisation.
- No substantive response
According to my complaint to the Austrian Data Protection Authority, no answer to those initial attempts had been received by 22 March 2026.
At that point, the provenance of the telephone number remained unexplained.
The information available to me therefore suggested a data chain of approximately the following form:
Unknown original source → Company A → business-contact/data platform
The last part of that chain had been indicated to me.
The first—and arguably most important—part remained unknown.
- Formal request under Articles 14 and 15 GDPR
To remove any possible ambiguity concerning the nature of my request, on 25 May 2026 I sent a formal exercise-of-rights request under Articles 14 and 15 GDPR to the company’s dedicated privacy contact address.
The request sought confirmation of whether personal data concerning me were being processed and requested information including:
- a copy of the personal data being processed;
- the categories of personal data;
- the purposes of processing;
- the legal basis under Article 6 GDPR;
- the source of the personal data, including whether they had been obtained directly from me, inferred, enriched or obtained through third parties;
- recipients or categories of recipients;
- retention information;
- information concerning international transfers; and
- information concerning profiling or automated decision-making, where applicable.
The request placed particular emphasis on my private telephone number and asked how it had been obtained, on what legal basis it was processed and whether it had been shared with third parties or business partners.
I also specifically asked whether any of my personal data had been obtained through data-enrichment services, business-intelligence platforms or third-party contact databases.
- Expiry of the GDPR response period
The one-month period for responding subsequently expired.
By 28 June 2026, according to my supplementary submission to the Austrian Data Protection Authority, I had received neither a substantive answer nor an acknowledgement of receipt of the formal request.
Consequently, several fundamental questions remained unanswered:
How was my private telephone number obtained?
What was the legal basis for processing it?
Was it disclosed to other organisations and, if so, to whom?
These were precisely the questions identified as remaining unresolved in my submission to the authority.
- Complaint before the Austrian Data Protection Authority
The matter was therefore pursued before the Austrian Data Protection Authority (Datenschutzbehörde — DSB).
An earlier submission had been framed in the electronic form under data portability, although the factual substance already concerned the failure to provide information about the origin and processing of my personal data. The subsequent submission expressly pursued the matter as a violation of the right of access.
The later filing refers to the existing proceeding under reference D135.515 and expressly states that the Article 15 request had not been answered.
I therefore requested that the DSB establish a violation of my right of access.
- Why the source matters
This case illustrates a broader problem concerning modern business-contact databases.
When personal information moves between data providers, enrichment platforms, business-intelligence services and their customers, the individual concerned may see only the end of the chain.
Suppose Company B tells an individual:
We obtained your telephone number from Company A.
That is useful information.
But if Company A does not explain where it obtained the number, the actual origin of the personal data remains unresolved.
This becomes particularly important where the information is not merely a professional title, employer name or predictable corporate email address, but a private telephone number.
The question is therefore not simply which organisation currently stores the data.
It is also:
How did the data enter the commercial information ecosystem in the first place?
- Article 14 and the provenance problem
Article 14 GDPR is particularly relevant where personal data have not been obtained directly from the data subject.
In this case, I sought to determine whether the telephone number had been:
- collected from a publicly accessible source;
- obtained from another organisation;
- supplied by a commercial data provider;
- obtained through a business-intelligence or enrichment service;
- inferred or enriched from other information; or
- acquired through some other mechanism.
My formal request expressly raised these possibilities rather than assuming which one had occurred.
That distinction remains important: I do not presently know the original source of the telephone number.
Establishing that source is precisely the purpose of the access request and the subsequent proceedings.
- A chain of accountability
The case also raises an interesting transparency problem when personal data pass through several organisations.
A simplified example is:
Original source → Company A → Company B → customers/users of Company B
From the perspective of the data subject, knowing only one link does not necessarily explain the processing.
If Company B identifies Company A, but Company A provides no information about the source from which it obtained the data, the individual may still be unable to understand:
- where the information originated;
- whether it was accurate;
- why it was collected;
- what legal basis was relied upon;
- how long it had been circulating; and
- which organisations had received it.
This is one reason why the right of access is important not merely as a mechanism for obtaining a database export, but as a means of reconstructing the provenance and movement of personal data.
- What this case does not establish
There are important limits to what can presently be concluded.
The documents do not establish the original source from which the private telephone number was obtained.
They also do not, by themselves, establish that the original collection or any subsequent disclosure was unlawful.
Nor does the fact that another organisation identified the company as its source automatically establish every detail of the underlying data transfer.
These are matters that require evidence and clarification.
What is documented is narrower:
another business-contact platform identified a company as the apparent source of my private telephone number;
I asked that company to explain the source and processing of the number;
I subsequently submitted a formal Articles 14 and 15 GDPR request;
the statutory response period expired without a response according to my DSB submission; and
the matter was consequently pursued before the Austrian Data Protection Authority.
That distinction between documented fact and unresolved inference is essential to this case.
- Current status
The case is pending in connection with proceedings before the Austrian Data Protection Authority.
The principal unresolved issue remains remarkably simple:
Where did my private telephone number originally come from, and how did it enter a commercial business-contact data chain?
Until the relevant controller provides the information it holds concerning the provenance, processing and disclosure of the number—or the competent authority establishes the relevant facts—that question remains open.
- Why I am documenting this case
I am publishing this case because it demonstrates a practical difficulty that individuals can encounter when exercising GDPR rights in interconnected data ecosystems.
Finding one’s personal information in a database is only the beginning.
The much harder questions can be:
Who supplied it?
Where did that organisation obtain it?
Which organisations subsequently received it?
What legal basis was relied upon at each stage?
And, ultimately:
Can the data subject reconstruct the path that their own personal information has travelled?
For a private telephone number that I did not knowingly make available for this purpose, those are not abstract questions.
They are the central subject of this case.
Note
This case report describes my own experience and the information available to me from correspondence and documents submitted in connection with my GDPR requests and proceedings before the Austrian Data Protection Authority.
It does not allege wrongdoing beyond matters established by the competent authorities. Where the origin, legal basis, transfer or other circumstances of processing remain unresolved, they are expressly presented here as open questions rather than established facts.