Case 6 – Right of Access and an Unexplained Marketing Data Chain

Status: Proceedings before the Austrian Data Protection Authority
Initial events: April 2026
Relevant GDPR provisions: Articles 12–15 GDPR
Main issue: Personal data, an apparent opt-in and campaign interactions were attributed to me within a multi-party marketing chain that I did not knowingly initiate.

  1. How the case began

In April 2026, I received an unsolicited marketing email at my professional email address concerning data-protection, backup and recovery technology.

The message was sent from the domain of one online business publication.

However, the content of the message displayed the branding of a different marketing publisher together with the logo and products of a technology company.

The footer again identified the marketing publisher rather than the domain from which the email had been sent.

The preserved email therefore presented several different organisational identities within a single marketing communication.

From the perspective of an ordinary recipient, it was not apparent:

who had obtained my personal data, who maintained the underlying contact record, who had selected me as a recipient, and which organisation was responsible for explaining the processing.

  1. My first access request

Because the unsolicited message had been sent from the domain of the business publication, I initially directed my Article 15 GDPR request there.

On 21 April 2026, I asked where my work email address had been obtained and whether my personal data had been shared with other parties.

I did not knowingly subscribe to the relevant newsletter or create an account with either the business publication or the marketing publisher. I subsequently clarified this expressly in my submissions to the Austrian Data Protection Authority.

No substantive response to the access request was received within one month.

At that stage, the case might still have remained a relatively conventional complaint concerning an unanswered access request.

It did not.

  1. Another company revealed a campaign record concerning me

Because the unsolicited message promoted the products of a technology company, I also contacted that company.

Its privacy team subsequently provided information about a campaign record associated with my personal data.

According to the information supplied to me, the record contained several personal-data fields concerning me, including professional contact information, telephone information, company information and employment-related details.

The record was described as being connected with a campaign operated by the marketing publisher.

The information also contained detailed campaign activity.

According to the record, campaign events included:

  • Sent
  • Delivered
  • Opened
  • Clicked 1
  • Clicked 2

and the record contained the additional field:

Base Opt-In: Yes

The campaign activity was recorded on 23 April 2026.

This became the most disturbing and technically interesting aspect of the case for me.

  1. Records appeared to describe actions by me that I did not recognise

The problem was no longer simply:

“Where did you obtain my email address?”

A data record now appeared to attribute behaviour to the contact record associated with me.

It suggested not only that I was present in a marketing database, but that emails had allegedly been opened and links clicked.

It also contained:

“Base Opt-In: Yes”

I do not recognise having performed or authorised the actions represented by those records.

This distinction is fundamental.

A database may contain:

Clicked = Yes

or:

Base Opt-In = Yes

But the existence of those fields does not itself establish who actually performed the underlying action.

That is precisely why I wanted access to the evidence behind them.

  1. “Base Opt-In: Yes” is not the same as proving consent

I have been careful not to interpret the field “Base Opt-In: Yes” as proof of valid consent.

It establishes only that a record carrying that value was apparently associated with my data.
To understand what it means, much more would be necessary.

For example:

  • What event created the value?
  • When was it created?
  • Who or what generated it?
  • What form was involved?
  • What wording was displayed?
  • Was there a checkbox?
  • Was it preselected?
  • What identifier, session or IP address was associated with the action?
  • Was the value imported from another system rather than generated through direct interaction?

And most importantly:

What evidence connects the alleged opt-in to me personally?

The same applies to the reported clicks.

A campaign database saying that a contact “clicked” something is not the same thing as establishing who was sitting behind the device that generated the event.

  1. The chronology also raised questions

There was another difficulty.

The unsolicited marketing communication had already reached me before the campaign activity described in the subsequently supplied record.

My initial complaint therefore noted that the chronology did not appear straightforward from the information available to me.

This does not prove that the records are incorrect.

There could be several technical explanations: different campaign events, separate records, duplicated data, delayed synchronisation or another system architecture.

But it means that the records do not explain themselves.

That is exactly why access to the underlying provenance and event information is important.

  1. Additional technical information: an IP address

The technology company later supplied additional traceability information.

It stated that an IP address had been associated with the submission:

xx.xxx.xx.xx (Vienna)

Importantly, it also explained that this information was provided to it following a request for additional traceability and was not information it otherwise stored in its own records in connection with the matter.

That qualification suggested that at least part of the technical evidence originated elsewhere in the campaign chain.

The IP address therefore became another clue.

But an IP address is not the identity of a person.

It does not establish by itself who performed a registration, clicked a link or generated an opt-in event.

  1. My separate request to the marketing publisher

Once the campaign information became available, I sent a much more detailed GDPR request directly to the marketing publisher.

I explained that information supplied to me indicated that my personal data appeared to have entered its system through a campaign landing page, while I had not personally completed such a registration.

I requested, among other things:

  • the original event or submission record;
  • the exact campaign or landing page;
  • timestamps;
  • associated metadata;
  • the actual form through which the data were allegedly submitted;
  • evidence concerning consent;
  • the wording presented at the time;
  • checkbox status;
  • the source of the personal data;
  • recipients;
  • and available technical traceability information, including campaign and session identifiers.

That request is preserved in the correspondence.

My purpose was simple:

If a system says that I opted in and interacted with campaign material, I want to know what technical evidence exists for those assertions.

  1. The marketing publisher did not answer the request

According to my complaint to the Austrian Data Protection Authority, the marketing publisher did not provide the requested response within the applicable period.

This left me unable to verify the campaign information against the underlying records of the organisation apparently connected with the campaign.

The unresolved questions included:

Where did my personal data originally come from?

What generated the “Base Opt-In: Yes” value?

What generated the recorded clicks?

Was there a landing-page submission?

If so, what information was entered?

What technical data accompany the alleged submission?

Were additional personal data processed or transferred?

These concerns were expressly reflected in my complaint.

  1. Two access requests emerged from the same incident

The case consequently developed into two related access proceedings.

One request had been addressed to the organisation whose domain appeared as the sender of the original marketing email.

The second request had been addressed to the marketing publisher after another organisation disclosed information suggesting that the relevant personal-data record was connected with one of its campaigns.

The requests were related, but they were not identical.

The first essentially asked:

Where did you obtain my data and to whom were they disclosed?

The second asked something technically more detailed:

What submission, consent, campaign and traceability records exist that explain the data and activity attributed to me?

That distinction later became procedurally important.

  1. Identifying the controller became difficult

At the time I filed the complaints, it was not clear to me whether the newsletter domain and the marketing publisher represented:

  • two separate legal entities;
  • two separate controllers;
  • different brands operated by one entity;
  • or another commercial or technical relationship.

The marketing email itself added to this uncertainty because one domain appeared as the sender while another organisation appeared in the footer and privacy information.

In a later submission, I expressly explained to the DSB that I had not brought separate complaints in order to pursue the same matter twice.

I had done so because the publicly available information did not allow me to determine clearly which entity was the relevant controller.

This is itself an important transparency issue.

A data subject should not have to reverse-engineer a commercial marketing architecture simply to determine who is responsible for answering an Article 15 request.

  1. The Austrian DSB identified an overlap

The procedural history then took an unusual turn.

On 28 July 2026, I received a telephone call concerning the apparent overlap between the two DSB proceedings.

Most of my experience with the Austrian Data Protection Authority has otherwise involved written correspondence and formal PDF documents.

For that reason, I was surprised to receive procedural guidance by telephone concerning something as significant as restructuring proceedings and potentially withdrawing a complaint.

I was also on holiday when the call occurred.

I took notes, but I did not consider my recollection of an unexpected telephone conversation alone sufficient basis for withdrawing or materially changing a pending formal complaint.

This is not a criticism of the person who called me.

It is simply my general approach to matters with legal consequences:

I do not rely solely on the identity asserted by somebody who telephones me, and I prefer consequential procedural instructions to be confirmed in writing.

  1. What I understood from the telephone conversation

According to my notes, I understood the suggested procedure to be approximately the following:

  1. submit a short supplementary filing in one proceeding;
  2. include the marketing publisher as a second respondent so that the matter could continue against both respondents;
  3. and subsequently withdraw the overlapping second complaint.

Because withdrawal can have procedural consequences, I wrote to the responsible DSB case officer asking for confirmation that I had understood the telephone guidance correctly.

I deliberately did this before withdrawing anything.

The email also explained why I was cautious: although the complaints overlap factually, they arose from different access requests sent to different recipients on different dates.

I wanted to ensure that procedural consolidation would not accidentally eliminate the independent subject matter relating to the detailed request concerning the campaign record.

  1. Why I did not want simply to “merge and withdraw”

My concern was not opposition to consolidation.

Combining related proceedings may be entirely sensible.

My concern was preserving the actual issues.

The second request concerns something particularly important:
a record apparently attributing opt-in and interactive behaviour to me that I do not recognise as mine.

If one proceeding were simply withdrawn without preserving that issue, the most technically significant aspect of the case could potentially disappear from the procedural record.

That is why I requested written confirmation.

  1. The part of the case that concerns me most

For me, the most important aspect of Case 6 is not the unwanted advertisement itself.

It is this:

A system apparently contains records saying that a person represented by my personal data opted in, opened communications and clicked links. I do not recognise those actions as actions I performed or authorised.

That creates a very different problem from ordinary unsolicited marketing.

If somebody else performed such actions using personal data associated with me, then the data record may make it appear that I interacted with or consented to something that I did not.

If the events were instead produced by some technical or automated mechanism, that also requires explanation.

I do not presently know which explanation is correct.

And that is exactly why the underlying evidence matters.

  1. Data about a person versus actions performed by that person

This case highlights a distinction that I find increasingly important in digital systems.

A database can contain personal data about an individual.

It can also contain event data apparently describing things the individual did.

Examples include:

consent = yes

opened = yes

clicked = yes

registered = yes

These fields may subsequently be treated by downstream systems as facts about that person’s behaviour.

But if the underlying activity was performed by someone else, generated automatically, imported incorrectly or otherwise misattributed, the database can create a misleading digital history.

That is why provenance is not only about:

“Where did you get my email address?”

It can also be about:

“Why does your system say that I did something?”

  1. What the evidence establishes

The documentary record establishes several things.

An unsolicited marketing email was sent to my professional address.

The email involved multiple organisational identities and commercial roles.

I submitted an Article 15 request to the organisation corresponding to the sender domain and did not receive a response within the statutory period.

A separate technology company subsequently provided campaign-related information associated with my personal data.

That information included campaign activity and a:

“Base Opt-In: Yes”

value.

Additional traceability information included an IP address.

I then submitted a separate, detailed access request to the marketing publisher asking for the underlying submission, consent and technical records.

According to my complaint, that request was not answered within the applicable period.

  1. What the evidence does not establish

Equally importantly, these documents do not establish that:

I personally performed the recorded clicks;
I personally opted in;
the “Base Opt-In” field represents legally valid consent;
a specific identifiable third person performed the activity;
the IP address identifies the person responsible;
any organisation deliberately falsified the records;
or the apparent inconsistencies necessarily indicate misconduct.

Those remain open questions.

My own position is simple:

I do not recognise or accept the attributed activity as activity I knowingly performed merely because a database says it occurred.

I want to know what evidence exists behind the database fields.

  1. Why the “clicks” matter

The recorded clicks are particularly important because they can change the apparent story of a marketing relationship.

Without them, the record might simply suggest:

Organisation possessed contact information → marketing email sent

With them, the record may appear to suggest:

person opted in → email sent → person opened email → person clicked material

Those are very different narratives.
If the second narrative is being associated with my identity, I want to understand how it was generated.

Whoever or whatever created those events may have caused systems downstream to treat me as an engaged or consenting contact.

That possibility is one of the reasons I regard the case as more serious than a conventional spam complaint.

  1. Why I am cautious about telephone communications as well

There is a connection here to my approach to the DSB telephone call.

In both situations, the same basic principle applies:

An asserted identity or recorded event should not automatically be accepted without sufficient verification when it has meaningful consequences.

If a database says that I clicked something, I want to know what evidence supports that attribution.

If somebody telephones me and discusses withdrawal or restructuring of a formal proceeding, I prefer to have the procedural instruction confirmed in writing before acting on it.

This is not because every database is wrong or every caller is untrustworthy.

It is because traceability and authentication matter when actions are attributed to a particular person.

That principle is at the heart of this case.

  1. The broader data-provenance problem

Case 6 therefore goes beyond the source of an email address.

The potential data chain appears considerably more complicated:

unknown original data source

campaign/contact database

record associated with my identity

“Base Opt-In: Yes”

campaign activity

opened / clicked events

marketing communication and downstream data processing

At present I cannot establish how the first step occurred or who or what generated several of the later steps.

That uncertainty is exactly why the right of access matters.

  1. Questions that remain open

The questions I would like the proceedings ultimately to clarify include:

  • What was the original source of my personal data?
  • What created the “Base Opt-In: Yes” field?
  • What evidence supports that value?
  • What exact event generated the recorded opening and clicks?
  • What device, session, IP address or other technical metadata accompanied those events?
  • Was a landing-page or form submission involved?
  • What data were submitted through it?
  • Was the information entered manually, imported or transferred from another system?
  • Which organisation created the underlying campaign record?
  • Which organisation controlled the relevant processing?
  • Which organisations subsequently received the resulting data?
  • And can any of the events apparently attributed to me actually be linked reliably to an action performed by me?

These remain questions, not conclusions.

  1. Current procedural position

The Austrian Data Protection Authority identified an apparent overlap between the two complaints.

Following the telephone conversation of 28 July 2026, I requested written confirmation of my understanding of the proposed procedural approach before making any withdrawal or substantive modification.

My purpose is not to maintain duplicative proceedings.

It is to ensure that whatever procedural structure is ultimately used preserves the full subject matter of the case, including the separate access request concerning the campaign, alleged opt-in, submission records and technical traceability.

The proceedings remain ongoing.

  1. Why I am documenting this case

I am documenting Case 6 because it demonstrates something that is easy to overlook when discussing personal data.

The problem is not always simply that an organisation possesses:

your name, email address or telephone number.

Digital systems may also create and exchange behavioural assertions:

  • this person registered;
  • this person consented;
  • this person opened;
  • this person clicked;
  • this person engaged.

Once such an assertion enters a commercial data ecosystem, other systems may act on it.

For me, therefore, the central question in Case 6 is:

What happens when a digital system attributes consent or behaviour to a person who says that the attributed actions were not performed or authorised by them?

The answer cannot simply be:
“The database says so.”

The provenance of the event itself then becomes personal-data transparency.

Note

This case report documents my own experience, the correspondence and campaign information supplied to me, and submissions made in proceedings before the Austrian Data Protection Authority.

It does not allege that any identified organisation deliberately falsified records, impersonated me, or unlawfully processed my personal data. Nor does the existence of an IP address, opt-in field, opening event or click event establish the identity of the person or process that generated it.

Where attribution, provenance, consent or technical causation remains unresolved, those matters are deliberately presented as open questions requiring evidence rather than conclusions.