Back to Feed
PolicyJul 31, 2026

DSB (Austria) - 2025-1.049.138

Austrian DPA fines digital marketing agency €25,500 for unlawful recording of applicant interviews.

Summary

The Austrian Data Protection Authority (DSB) has fined a digital marketing agency €25,500 for recording and indefinitely storing phone interviews with job applicants without a valid legal basis. The agency also failed to inform applicants that their calls were being recorded or disclose the identity of the controller.

Full text

Help DSB (Austria) - 2025-1.049.138: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 15:16, 31 July 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators243 edits Tag: Decisions [1.0] (No difference) Latest revision as of 15:16, 31 July 2026 DSB - 2025-1.049.138 Authority: DSB (Austria) Jurisdiction: Austria Relevant Law: Article 5(1)(a) GDPR Article 13(1)(d) GDPR Article 6(1)(a) GDPR Article 6(1)(f) GDPR Article 5(1)(c) GDPR Article 5(1)(e) GDPR Article 12 GDPR Article 13 GDPR Type: Other Outcome: n/a Started: Decided: 19.01.2026 Published: 27.07.2026 Fine: 25500.0 EUR Parties: n/a National Case Number/Name: 2025-1.049.138 European Case Law Identifier: ECLI:AT:DSB:2026:2025.1.049.138 Appeal: Pending appealBundesverwaltungsgericht (Austria) Original Language(s): German Original Source: RIS (in DE) Initial Contributor: ds The DPA fined a digital marketing agency €25,500 for recording and indefinitely storing applicants’ phone interviews without a valid legal basis or telling them about the recording and the identity of the actual controller. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted and interviewed by telephone. A former employee of the controller was examined as a witness by the Austrian DPA (DSB) and provided evidence concerning the recordings. The telephone interviews generally followed a particular pattern. The employees contacted data subjects in the name of the relevant client, stated that their application appeared interesting, presented the position, asked about their qualifications and professional experience and, where appropriate, arranged an in-person interview. The calls were recorded from beginning to end and stored for an indefinite period. In some cases, data subjects were not informed that the call was being recorded. In other cases, the employee asked during the call whether recording would be acceptable. In one such call, the data subject responded, “Uh, yeah.” Moreover, a superior employee had encouraged other employees through an intranet message to record and store interviews for training purposes, including without obtaining the data subject’ consent. The controller argued that it had been unaware of the recording practice. It submitted that the employee who had instructed the others to make the recordings was neither a managing director nor an authorised signatory and had no authority to issue such instructions. According to the controller, the statement that interviews could be recorded “even without consent” resulted from personal overzealousness and legal recklessness and did not reflect the controller’s internal procedures. As legal bases for the processing, the controller stated that it relied on consent under Article 6(1)(a) GDPR and legitimate interests under Article 6(1)(f) GDPR. It claimed that data subjects had been expressly asked for consent at the beginning of the application process and that the recordings served the legitimate interest of improving employee performance. Holding The DPA relied on the CJEU’s judgment in Case C-807/21 (Deutsche Wohnen) and held that a legal entity may be liable not only for infringements committed by its representatives, managers or executives, but also for infringements committed by any person acting within the scope of its business activities and on its behalf. It acknowledged that an exception may apply where an employee acts outside that framework and exclusively for personal purposes. The DPA determined that the supervising employee had ordered the processing within the scope of their employment relationship and in the controller’s interest. It pointed out that the controller could therefore not avoid responsibility by claiming that it had been unaware of the practice or that the employee lacked formal authority to issue instructions. The DPA held that no consent had been obtained in some cases and that, where consent had been sought, it was neither timely nor valid. It stated that consent must be obtained before processing begins. However, it noted that the recordings had already been activated before the calls began, due to the fact that the recordings included the opening greetings. It held that asking for consent during the recorded call was too late. The DPA further held that one data subject’s response, “Uh, yeah,” did not constitute an unambiguous affirmative act. It also considered that a job interview, similarly to an existing employment relationship, is characterised by a structural imbalance of power. Moreover, it emphasised that the data subjects had not been informed of the true identity of the controller, because its employees presented themselves as acting for the client companies. It concluded that the data subject could therefore not have given valid consent and that processing could not be based on Article 6(1)(a) GDPR. Furthermore, the DPA examined whether the recordings could be justified by legitimate interests. It underlined that a controller relying on Article 6(1)(f) GDPR must comply with the corresponding transparency obligations. Specifically, pursuant to Article 13(1)(d) GDPR, the legitimate interests pursued must be communicated when the personal data is collected. Referring to Case C-394/23 (Mousse) the DPA held that the collection could not be based on Article 6(1)(f) GDPR where that information had not been provided in time. It found that the data subjects had either not been informed at all of the legitimate interest pursued or had been informed only after the collection of their personal data had begun. It held accordingly that the processing could not be based on Article 6(1)(f) GDPR. The DPA concluded that the recording and storage of the interviews lacked a legal basis and infringed Article 6(1) GDPR in conjunction with Article 5(1)(a) GDPR. In addition, the DPA held that the recordings were not necessary for the training purpose as less intrusive alternatives, such as simulated interviews between employees, could have achieved the same objective. It therefore found a violation of the principle of data minimisation under Article 5(1)(c) GDPR. It further found that the indefinite retention of the recordings was also unnecessary and violated the principle of storage limitation under Article 5(1)(e) GDPR. The DPA also found that the controller had failed to comply with its transparency obligations. In some cases, data subjects received no information about the processing. In others, information was provided only after the processing had begun. The data subjects were also not informed of the identity of the actual controller, because the employees presented themselves as representatives of the client companies. It therefore found an infringement of Article 5(1)(a) GDPR in conjunction with Article 12 GDPR and Article 13 GDPR. The DPA found that the controller had acted at least negligently. It imposed a fine of €25,500 for the infringements. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the German original. Please refer to the German original for more details. Text Ref. No.: 2025-1.049.138 dated January 19, 2026 (Case No.: DPA-D550.1231) [Processing Officer’s Note: Names and company names, legal forms and product names, addresses (including URLs, IP addresses, and email addresses), case numbers (and similar), statistical data, etc., as well as their initials and abbreviations, may have been abbreviated and/or altered for pseudonymization purposes. Obvious spelling, grammar, and punctuation errors have been corrected.] Pen

Entities

DSB (vendor)