Background
On 6 February 2026, I received an unsolicited professional email at my work email address inviting me to attend a conference on conversational AI and customer experience in Munich.
The message was sent by a marketing representative of an event-organising company.
The issue was not the conference invitation itself. My concern was that I did not know how the sender had obtained my work email address or whether that address had subsequently been disclosed to other parties.
The email address concerned was a professional address associated with my employment. I therefore wanted to establish the provenance of the data and understand how it had entered the sender’s marketing or contact systems.
My Request for Information
I contacted the sender and requested information concerning the processing of my personal data.
In particular, I asked for:
the source from which my work email address had been acquired; and
information concerning any other parties with whom my personal data had been shared.
My request expressly referred to my rights under the GDPR and explained that I was concerned about how my work email address had been obtained and used.
The original correspondence submitted as evidence shows both the conference invitation and my subsequent request for information.
Why the Source of the Address Mattered
The purpose of my request was not simply to stop receiving marketing emails.
Where personal data have not been collected directly from the data subject, understanding their provenance can be important for determining how the processing began and whether the information may have circulated through additional organisations or databases.
In this case, I specifically wanted to know how this particular work email address had reached the sender.
I therefore did not merely unsubscribe from the communications. I exercised my data-protection rights in order to establish the origin and possible onward disclosure of the address.
No Substantive Response
I did not receive an answer providing the requested information concerning the source of the email address or possible recipients.
After more than one month had passed, I brought the matter before the Austrian Data Protection Authority (Datenschutzbehörde – DSB).
My complaint stated that the sender had contacted my work email address on 6 February 2026 and that my subsequent questions concerning where the address had been found and whether it had been forwarded remained unanswered.
I therefore alleged an infringement of my right of access.
Complaint to the Austrian Data Protection Authority
On 14 March 2026, I submitted a data-protection complaint to the Austrian DSB.
The complaint identified the issue as an alleged violation of the right of access and stated that no response had been provided within one month of my request.
I requested that the DSB establish that my right of access had been infringed.
The email correspondence was submitted as supporting evidence.
Clarification of the Respondent
A further submission was made on 30 March 2026 in connection with DSB reference D124.0812/26.
In that submission, the respondent was identified as the event-organising company rather than only the individual marketing employee who had sent the original message.
The substance of the complaint remained the same: I had received an unsolicited email at my work address and had not received an answer explaining where that address had been obtained or whether it had been disclosed further.
The submission again recorded that no response had been received within one month and asked the DSB to establish an infringement of the right of access.
Data-Protection Question Raised by the Case
The case raises a straightforward but important question:
When an organisation uses a person’s professional email address for direct contact, what information must it provide when the person asks where that particular address came from and whether the data were disclosed to others?
For me, the central issue was transparency.
Receiving an unsolicited professional invitation does not by itself establish unlawful processing. Nor does the fact that I did not know the sender establish that the sender necessarily obtained the address unlawfully.
The purpose of exercising the right of access was precisely to obtain the information necessary to understand the processing before drawing conclusions about it.
Where that information is not provided, however, the data subject may be unable to determine how their personal data entered the organisation’s systems or where those data may subsequently have gone.
Current Status
The matter was submitted to the Austrian Data Protection Authority under reference:
D124.0812/26
The complaint asks the authority to determine whether the failure to provide the requested information constituted an infringement of my right of access.
The proceedings are pending.
Note
This case description documents my experience and the questions submitted to the competent data-protection authority. It does not imply that the respondent committed an unlawful act beyond any infringement that may ultimately be established by the authority or a competent court.