[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUzhK2SiGGjVt66KqK95YglZKyMH3wyYpbporowFl2aM":3},{"article":4,"iocs":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"54ab6706-02d8-462d-acba-e6f809b47cef","OGH - 6Ob148\u002F25w","ogh-6ob148-25w-72fd5f","← Older revision Revision as of 13:14, 16 September 2026 Line 105: Line 105: The controller bought personal data about a data subject (name, address, date of birth) from a company (B) that operates in the address publishing and direct marketing industry. The contract provided that this data may only be used for identity verification. The controller bought personal data about a data subject (name, address, date of birth) from a company (B) that operates in the address publishing and direct marketing industry. The contract provided that this data may only be used for identity verification. While the data subject’s data was initially collected by company B for the purpose of direct marketing, the controller used the personal data in question exclusively for existence verification. While the data subject’s data was initially collected by company B for the purpose of direct marketing, the controller used the personal data in question exclusively for identity verification. At a customer's request, the controller issued a credit assessment of the data subject. The assessment was based on the name, gender and address of the data subject because there was no available data on possible payment defaults of the data subject. At a customer's request, the controller issued a credit assessment of the data subject. The assessment was based on the name, gender and address of the data subject because there was no available data on possible payment defaults of the data subject. Line 127: Line 127: Purpose limitation Purpose limitation The court considered that processing data for an existence check in the context of credit assessments must be regarded as processing data for the purpose of credit assessments. This is true even where the data was not used for calculating the credit score itself. In this case, the controller processed the personal data for a different purpose than the marketing purpose that justified the initial collection. The court considered that processing data for an identity check in the context of credit assessments must be regarded as processing data for the purpose of credit assessments. This is true even where the data was not used for calculating the credit score itself. In this case, the controller processed the personal data for a different purpose than the marketing purpose that justified the initial collection. The further processing had significant consequences for the data subject and was not subject to appropriate safeguards pursuant to [[Article 6 GDPR|Article 6(4)(e) GDPR]], in violation of [[Article 6 GDPR|Article 6(4) GDPR]]. The further processing had significant consequences for the data subject and was not subject to appropriate safeguards pursuant to [[Article 6 GDPR|Article 6(4)(e) GDPR]], in violation of [[Article 6 GDPR|Article 6(4) GDPR]].","The Austrian Supreme Court (OGH) ruled that a company's use of personal data, initially collected for direct marketing, for identity verification and credit assessments violated GDPR's purpose limitation principle. The court found that further processing for credit assessments, even without direct score calculation, had significant consequences for the data subject and lacked appropriate safeguards, thus infringing Article 6(4) GDPR.","Austrian court rules data processing for credit assessments violated GDPR purpose limitation.","Help OGH - 6Ob148\u002F25w: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editNewer edit →VisualWikitext Revision as of 12:56, 16 September 2026 view sourceLh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators57 editsTag: Visual edit← Older edit Revision as of 13:14, 16 September 2026 view source Ls (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators422 editsTag: Visual editNewer edit → Line 105: Line 105: The controller bought personal data about a data subject (name, address, date of birth) from a company (B) that operates in the address publishing and direct marketing industry. The contract provided that this data may only be used for identity verification. The controller bought personal data about a data subject (name, address, date of birth) from a company (B) that operates in the address publishing and direct marketing industry. The contract provided that this data may only be used for identity verification. While the data subject’s data was initially collected by company B for the purpose of direct marketing, the controller used the personal data in question exclusively for existence verification. While the data subject’s data was initially collected by company B for the purpose of direct marketing, the controller used the personal data in question exclusively for identity verification. At a customer's request, the controller issued a credit assessment of the data subject. The assessment was based on the name, gender and address of the data subject because there was no available data on possible payment defaults of the data subject. At a customer's request, the controller issued a credit assessment of the data subject. The assessment was based on the name, gender and address of the data subject because there was no available data on possible payment defaults of the data subject. Line 127: Line 127: \u003Cu>Purpose limitation\u003C\u002Fu>\u003Cu>Purpose limitation\u003C\u002Fu> The court considered that processing data for an existence check in the context of credit assessments must be regarded as processing data for the purpose of credit assessments. This is true even where the data was not used for calculating the credit score itself. In this case, the controller processed the personal data for a different purpose than the marketing purpose that justified the initial collection. The court considered that processing data for an identity check in the context of credit assessments must be regarded as processing data for the purpose of credit assessments. This is true even where the data was not used for calculating the credit score itself. In this case, the controller processed the personal data for a different purpose than the marketing purpose that justified the initial collection. The further processing had significant consequences for the data subject and was not subject to appropriate safeguards pursuant to [[Article 6 GDPR|Article 6(4)(e) GDPR]], in violation of [[Article 6 GDPR|Article 6(4) GDPR]]. The further processing had significant consequences for the data subject and was not subject to appropriate safeguards pursuant to [[Article 6 GDPR|Article 6(4)(e) GDPR]], in violation of [[Article 6 GDPR|Article 6(4) GDPR]]. Revision as of 13:14, 16 September 2026 OGH - 6Ob148\u002F25w Court: OGH (Austria) Jurisdiction: Austria Relevant Law: Article 6(1)(f) GDPR Article 6(4) GDPR Article 7 CFRArticle 8 CFR Decided: 12.08.2026 Published: Parties: National Case Number\u002FName: 6Ob148\u002F25w European Case Law Identifier: ECLI:AT:OGH0002:2026:0060OB00148.25W.0812.000 Appeal from: Appeal to: Original Language(s): German Original Source: RIS (in German) Initial Contributor: lh The processing of data initially collected for marketing purpose is incompatible with a credit assessment purpose, in violation of Article 6(4) GDPR. Score calculation based on statistics, address and name of the data subject is, however, not generally unlawful. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The controller runs an address publishing business as well as a credit information agency. As part of its credit assessment activity, it (i) verifies the existence of individuals whose credit score is requested with data like their name and address and (ii) issues credit scores based on data provided by debt collection agencies and on statistics, as payment default data is available on approximately 10% of Austrians. The controller bought personal data about a data subject (name, address, date of birth) from a company (B) that operates in the address publishing and direct marketing industry. The contract provided that this data may only be used for identity verification. While the data subject’s data was initially collected by company B for the purpose of direct marketing, the controller used the personal data in question exclusively for identity verification. At a customer's request, the controller issued a credit assessment of the data subject. The assessment was based on the name, gender and address of the data subject because there was no available data on possible payment defaults of the data subject. The data subject brought an injunction against the controller. The main discussions regarded (i) a violation of the purpose limitation principle: the data was initially collected for direct marketing purposes and later used for credit assessment; (ii) the calculation of the score, which relied solely on statistical data and not on data actually concerning the payment history of the data subject. The court of first instance and second instance rejected the injunction. The court of first instance held that the controller processed the data according to the contract with company B. Moreover, the processing for the original purpose was compatible with the further processing. The court of second instance however held that the further processing was not compatible with the original purpose but that the controller could rely on national law as legal basis. As far as the method of credit assessment was concerned, both courts held that the processing fell under Article 6(1)(f) GDPR because the processing was necessary for operating a credit information agency. The data subject appealed the decision. Holding The court partly upheld the decision of the court of second instance. Pre-emptive injunctions Firstly, the court referred to the case law of the CJEU that provides for the possibility of pre-emptive injunctions under national law. The scope of the subject matter of the injunction under Austrian national law is reduced to the specific violating actions the data subject claims. Therefore, as far as the data subject requests the controller to desist from unlawfully processing their personal data in general, the injunction is inadmissible because the data subject failed to name a specific violation. Purpose limitation The court considered that processing data for an identity check in the context of credit assessments must be regarded as processing data for the purpose of credit assessments. This is true even where the data was not used for calculating the credit score itself. In this case, the controller processed the personal data for a different purpose than the marketing purpose that justified the initial collection. The further processing had significant consequences for the data subject and was not subject to appropriate safeguards pursuant to Article 6(4)(e) GDPR, in violation of Article 6(4) GDPR. Lawfulness of credit scoring calculation in absence of payment default data The court held that the assessment of a credit score on the basis of statistical data, and the address and and name of the data subject in the absence of data on possible payment defaults was not per se unlawful under Article 6(1)(f) GDPR. As there is available data on payment defaults on only 10% of Austrians, credit assessments of the m","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=OGH_-_6Ob148\u002F25w&diff=53109&oldid=53108","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F4\u002F4c\u002FCourts_logo1.png","2026-09-16T13:14:34+00:00","2026-09-16T14:00:11.014183+00:00",7,[18],{"name":19,"type":20},"GDPR","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,31,36,38],{"category":28},{"id":29,"icon":23,"name":19,"slug":30},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","gdpr",{"category":32},{"id":33,"icon":23,"name":34,"slug":35},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":37},{"id":21,"icon":23,"name":24,"slug":25},{"category":39},{"id":40,"icon":23,"name":41,"slug":42},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]