/ Impfservice 9 Privacy Policy

Privacy Policy

Data protection information under the GDPR

1. Data Controller

The following information under Art. 13 and 14 of the General Data Protection Regulation (GDPR) is provided by the following data controller:

  • Municipal Department 15 – Public Health Services
    Address and contact details: https://www.wien.gv.at/sozialinfo/content/de/10/InstitutionDetail.do?it_1=2097624
  • E-mail: post@ma15.wien.gv.at
  • In the pilot operation of the electronic vaccination card, Municipal Department 15 and ELGA GmbH are jointly responsible under data protection law as data controllers pursuant to sec. 27 par. 17 in conjunction with sec. 24c par. 3 of the Health Telematics Act/GTelG 2012. Once the transition to full operation of the electronic vaccination card has been completed, Municipal Department 15, as the healthcare service provider responsible for storing, updating, cancelling, retroactive input and validation, will be a joint data controller responsible for processing personal data within the meaning of Art. 26 GDPR in cooperation with the Federal Minister responsible for healthcare.

Further information on the electronic vaccination card can be found at:
https://www.elga.gv.at/e-impfpass/faq-zum-e-impfpass/ https://www.sozialministerium.at/Themen/Gesundheit/eHealth/Elektronischer-Impfpass.html
https://www.sozialministerium.at/Themen/Gesundheit/eHealth/Elektronischer-Impfpass.html

2. Purposes and Legal Basis of Processing

Please note that

  • the personal data you provide (name, date of birth, sex, residential address, contact details, details of representative, if any, social insurance number)
    and the
  • information about the vaccine administered (classification, trade name, manufacturer, authorisation number, batch number, expiry date, serialisation number, central pharmaceutical number and anatomical-therapeutic-chemical classification),
  • information about the vaccination administered (date of administration, dosage and dose, vaccination schedule used, vaccination recommendation and allocation to vaccination programmes),
  • the following information about yourself: sector-specific personal identifier – health, community code, titer test result, previous illnesses relevant to vaccination and special vaccination indications
    will be processed by the abovementioned controller for the following purposes on the basis of the legal basis listed below:

3. Purposes

  • Patient-related documentation of vaccinations administered in the vaccination centres of the City of Vienna
  • Entry of these vaccinations in the “e-Impfpass” (electronic vaccination card) eHealth application

4. Legal Basis

  • Sec. 51 of the Austrian Medical Act/Ärztegesetz 1998, Federal Law Gazette I No.169/1998 as amended, sec. 132c of the General Social Insurance Act/ASVG, Federal Law Gazette No. 189/1955 as amended, sec. 1b of the Vaccination Damage Act/Impfschadengesetz, Federal Law Gazette No. 371/1973 as amended, Art. 18, 23, 36 of the International Health Regulations (2005), Federal Law Gazette III No. 98/2008 as amended,
  • Sec. 2, 4 Imperial Sanitary Act/Reichssanitätsgesetz, Act of 30 April 1870, Imperial Law Gazette No. 68/1870 as amended,
  • Sec. 24b et seq. of the Health Telematics Act/Gesundheitstelematikgesetz 2012, Federal Law Gazette I No. 111/2012 as amended,
  • Ordinance of the Federal Minister of Social Affairs, Health, Care and Consumer Protection setting forth more detailed provisions on the “electronic vaccination card” eHealth application (eHealth Ordinance/eHealth-Verordnung), Federal Law Gazette II No. 449/2020 as amended

The abovementioned legal provisions fulfil the following justifications for data processing:

  • Art. 6 (1) (c), (e) of the GDPR and
  • Art. 9 (2) (g), (h), (i) of the GDPR
  • Declaration of consent to vaccination,
  • Treatment agreement (Art. 6 (1) (b) and Art. 9 (2) (h) of the GDPR),
  • Consent to data processing for the purpose of booking appointments via the web portal (Art. 6 (1) (a) GDPR and Art. 9 (2) (a) GDPR).

5. Origin of the Personal Data

  • The personal data you provide (name, date of birth, sex, home address, contact details, details of representative, if any, social insurance number, titer test result, pre-existing conditions relevant for the vaccination and special vaccination indications)
  • are collected directly from you.
  • Further personal data originate from the following sources:
    • Registered address: Central Register of Residents (ZMR)
    • Information about the vaccine (classification, trade name, manufacturer, authorisation number, batch number, expiry date, serialisation number, central pharmaceutical number and anatomical-therapeutic-chemical classification): Vaccination Centre
    • Information about the vaccination administered (date of administration, dosage and dose, vaccination schedule used, vaccination recommendation and allocation to vaccination programmes): Vaccination Centre
    • Sector-specific personal identifier – health: SourcePIN register authority

6. Transmission of Personal Data

The personal data processed are transmitted to the following recipients for the following purposes:

  • For settlement purposes when the contribution towards costs of the TBE vaccination is claimed under sec. 132c of the General Social Insurance Act/ASVG: Name, address, sex, social insurance number, date of birth, name, batch number, expiry date and date of vaccination Recipient: Österreichische Gesundheitskasse Wien (Austrian Health Insurance Fund Vienna)
  • For managing enquiries to arrange vaccination appointments and forwarding other queries to MA 15 on the basis of the order processing agreement: Title, salutation, first name, surname, address (street, building number, postcode, town), telephone number, e-mail, date of birth, desired vaccination(s), desired date, desired vaccination centre, free text section for queries Recipient: City of Vienna – Wiener Wohnen Kundenservice GmbH as an order processor according to the definition in Art. 4 (8) GDPR
  • For the administration of vaccination data to document immunisations in the electronic vaccination card under sec. 24b et seq. of the Health Telematics Act 2012, Federal Law Gazette I No. 111/2012 as amended, Ordinance of the Federal Minister of Social Affairs, Health, Care and Consumer Protection, containing more detailed provisions on the “electronic vaccination card” eHealth application (eHealth Ordinance – eHealth-Verordnung), Federal Law Gazette II No. 449/2020 as amended. Recipients: ELGA GmbH during pilot operations of the electronic vaccination card, the Federal Ministry of Health after completion of the pilot phase
  • Information on the vaccine (classification, trade name, manufacturer, authorisation number, batch number, expiry date, serialisation number, central pharmaceutical number and anatomical-therapeutic-chemical classification),
  • Details of the vaccination administered (date of administration, dosage and dose, vaccination schedule used, vaccination recommendation and allocation to vaccination programmes),
  • Patient details (name, date of birth, sex, residential address, contact details, details of representative, if any, social insurance number, sector-specific personal identifier – health, municipal code, titer test result, pre-existing conditions relevant to the vaccination and special vaccination indications) and
  • Details of the healthcare provider in charge of vaccination or data storage (name, role, professional address and date of storage).
  • Vaccination data is not stored directly on the device (computer, mobile device, …).

There is no transfer to third countries within the meaning of Art. 44 GDPR (countries which are not members of the European Union or the European Economic Area).

7. Notes

Due to the related legal obligation under sec. 51 of the Medical Act 1998, Federal Law Gazette I No. 169/1998 as amended, your personal data will be erased after 10 years unless they have been recorded in the central vaccination register.
Pursuant to sec. 24c par. 6 of the Health Telematics Act 2012, the vaccination data stored in the central vaccination register will be erased 10 years after the date of death and no later than 120 years after the birth of the data subject.
The provision of personal data is necessary for entering into an agreement (the vaccination-related treatment agreement) and the implementation of pre-contractual measures in the context of the treatment agreement (including, without being limited to, booking appointments). Moreover, in particular pursuant to sec. 51 of the Medical Act 1998 and sec. 24c para. 2 of the Health Telematics Act 2012, the data controller is obliged to collect personal data and store them in the central vaccination register, which is part of the “electronic vaccination card” eHealth application, under sec. 24c par. 2 of the Health Telematics Act 2012.
Failure to provide your personal data would mean that the vaccination cannot be administered.

8. Rights of Data Subjects

As a data subject, you have the right of access to information about your personal data and to rectification, erasure, restriction of processing or objection to processing.
If processing is based on consent within the meaning of Art. 6 (1) (a) or Art. 9 (2) (a) GDPR, you have the right to withdraw your consent at any time. However, we would like to point out that processing on the basis of the consent is lawful until such consent is withdrawn.
Rights of data subjects in respect of the “e-Impfpass” (electronic vaccination card):
You have right of access, i.e. the right to obtain information about your data and log data stored in the central vaccination register, either electronically via the access portal (sec. 23 of the Health Telematics Act) or in writing from the ELGA Ombudsman’s Office (sec. 17 of the Health Telematics Act); you also have the right to print out the data stored in the central vaccination register yourself or have them printed out by the ELGA Ombudsman’s Office. In case of doubt, the entitlement to exercise the abovementioned rights regarding their own data is an exclusive right of citizens aged 14 (minors with qualified legal capacity) and above.
You also have the right to request the documentation of vaccinations within the meaning of Art. 31 of the International Health Regulations (IHR) in the international vaccination card (WHO International Certificate of Vaccination and Vaccination Book) from the vaccination service provider.
If you think that your rights have not or not sufficiently been safeguarded, you have the option of lodging a complaint with the Austrian Data Protection Authority:
Barichgasse 40-42, 1030 Vienna
E-mail: dsb@dsb.gv.at

9. Data Protection Officer

If you have any questions about data protection, please contact the Data Protection Officer of the City of Vienna at datenschutzbeauftragter@wien.gv.at.
Further information
Datenschutz auf wien.at