Case 3 – Right of access concerning a work email address (2026)

In February 2026, I received an unsolicited marketing email at my work email address promoting scientific products relating to cancer research.

Since my work email address was not publicly available and I had no professional activity relating to the advertised products, I asked the sender to explain how my contact details had been obtained and whether my personal data had been shared by third parties.

After receiving no reply, I submitted a complaint to the Austrian Data Protection Authority (Datenschutzbehörde – DSB), alleging a violation of my right of access under Article 15 GDPR.

Response during the proceedings

During the proceedings before the Austrian Data Protection Authority, the company provided a response to my access request.

According to its reply, the company stated that:

  • it stored only my name and work email address;
  • my personal data had not been disclosed to third parties;
  • my contact details were part of a business contact list associated with scientific inquiries;
  • the legal basis for processing was its legitimate interest under Article 6(1)(f) GDPR;
  • my contact record had subsequently been suppressed or removed in order to prevent further communications.

The company further explained that it could no longer determine the specific origin of my personal data. It stated only that the information would generally originate from website submissions, scientific conferences, or other business interactions, but that no preserved source record existed for my particular contact.

My observations

After reviewing the response, I informed the Austrian Data Protection Authority that, in my view, several elements of the requested information remained insufficiently clarified.

In particular, I considered that the response did not explain:

  • the concrete source from which my work email address had originally been obtained;
  • how my contact details had entered the relevant business contact list;
  • whether the information had originated directly from me, through a third party, at a scientific event, or by another specific means.

From my perspective, the general statement that my information originated from a business contact list relating to scientific inquiries did not allow me to understand the actual origin of my personal data or the circumstances under which they had been collected.

I also pointed out that I had no professional, scientific, or commercial activity relating to cancer cell lines and therefore did not understand the asserted association of my contact details with that particular business context.

Procedural development

The Austrian Data Protection Authority initially considered that the company had remedied the original complaint by providing a response during the proceedings.

Since I subsequently argued that the response itself remained incomplete, the Authority informed me that this constituted a different procedural matter.

Accordingly, the original complaint concerning the absence of a response was closed, while my arguments concerning the alleged incompleteness of the information provided were treated as a new complaint under the same case reference.

In my subsequent submissions, I explained that, in my view, my right of access under Article 15 GDPR and the transparency requirements of Article 14 GDPR had still not been fully satisfied.

I further noted that, according to the company’s own statements, the remaining contact data had meanwhile been removed from its systems. Since my objective had been to clarify the origin and processing of my personal data, I considered that the removal of the available records during the proceedings made any subsequent verification of their provenance and processing considerably more difficult.
[16.07.26 18:19] Anna Saranti: For that reason, I referred the Austrian Data Protection Authority to one of its earlier decisions (DSB case no. 2025-0.566.415, 21 November 2025, https://rdb.manz.at/document/ris.dsb.DSBT_20251121_2025_0_566_415_00), in which the Authority had observed that the deletion of relevant information during an ongoing access procedure may impair the effective verification of the right of access. I considered that decision relevant to the procedural questions raised in my case, while recognising that the assessment of its applicability remained a matter for the Authority itself.

I also informed the Authority that, irrespective of the eventual outcome of the proceedings, I intended to document the data protection issues raised by the case, together with the legal and practical observations arising from it, in a factual and legally compliant manner on my personal website.

Current status

On 16 July 2026, the Austrian Data Protection Authority (Datenschutzbehörde – DSB) upheld my complaint concerning the exercise of my right of access under Article 15 GDPR.

The Authority concluded that my right of access had been infringed because the controller deleted the personal data relating to my request while the proceedings before the Austrian Data Protection Authority were still ongoing.

In its decision, the Authority explained that the right of access enables individuals to understand and verify how their personal data are processed. It further held that deleting the personal data to which an access request relates while that request—or the subsequent proceedings before the Authority—is still pending may prevent the Authority from assessing whether the requested information should have been disclosed. Such deletion may therefore constitute an infringement of the right of access.

For me, the decision confirms the importance of preserving relevant personal data until an access request has been fully resolved. Otherwise, both the data subject and the supervisory authority may be deprived of the possibility to verify the lawfulness and completeness of the processing.

The purpose of documenting this case is not to criticize a particular organisation. Rather, it illustrates a procedural aspect of the GDPR that may be relevant whenever individuals exercise their right of access under Article 15 GDPR.