OGH - 6Ob148/25w
Austrian court rules data collected for marketing cannot be used for credit identity checks.
Summary
The Austrian Supreme Court (OGH) ruled that personal data collected for marketing purposes cannot be used for identity checks in credit assessments. The court found this processing incompatible with the original purpose and lacking a legal basis under Article 6(4) GDPR, as there was no direct link or relationship between the controller and data subject, and no safeguards were in place. This decision highlights the importance of purpose limitation and data subject rights under GDPR.
Full text
Help OGH - 6Ob148/25w: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 14:06, 10 September 2026 view sourceLh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators44 editsTag: Visual edit← Older edit Latest revision as of 07:19, 14 September 2026 view source Lh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators44 editsTag: Visual edit (One intermediate revision by the same user not shown)Line 129: Line 129: 2.Further processing2.Further processing The court held that the controller processed the data for a further purpose than the initial collection of the data, which was the purpose of marketing. National law provides for a legal basis to collect data for the purpose of marketing. However, the court held, that processing personal data in order to conduct an identity check for a credit assessment does not fall under the purpose of marketing. Processing data for an identity check in the context of credit assessments must be regarded as processing data for the purpose of credit assessments. This is true even where the data was not used for calculating the credit score itself. The court held that the controller processed the data for a further purpose than the initial collection of the data, which was the purpose of marketing. National law provides for a legal basis to collect data for the purpose of marketing. However, the court held, that processing personal data in order to conduct an identity check for a credit assessment where the data was initially collected for marketing purposes does not fall under the legal basis provided for by national law. Processing data for an identity check in the context of credit assessments must be regarded as processing data for the purpose of credit assessments. This is true even where the data was not used for calculating the credit score itself. Therefore, the controller processed the personal data for a different purpose. The national provisions that allow for the processing of personal data for the purpose of marketing does not constitute a legal basis pursuant to [[Article 6 GDPR|Article 6(4) GDPR]]. Therefore, the controller processed the personal data for a different purpose. The court held that the purpose of the initial collection of data (marketing) was incompatible with the further processing (credit assessment). There is no direct link between the purposes pursuant to [[Article 6 GDPR|Article 6(4)(a) GDPR]]. Neither was there any relationship between the controller and the data subject within the meaning of [[Article 6 GDPR|Article 6(4)(b) GDPR]]. On the other hand, the credit score can have significant consequences for the data subject in the form of rejections of granting of credits or entering into contracts. No safeguards pursuant to [[Article 6 GDPR|Article 6(4)(e) GDPR]] were in place.The court held that the purpose of the initial collection of data (marketing) was incompatible with the further processing (credit assessment). There is no direct link between the purposes pursuant to [[Article 6 GDPR|Article 6(4)(a) GDPR]]. Neither was there any relationship between the controller and the data subject within the meaning of [[Article 6 GDPR|Article 6(4)(b) GDPR]]. On the other hand, the credit score can have significant consequences for the data subject in the form of rejections of granting of credits or entering into contracts. No safeguards pursuant to [[Article 6 GDPR|Article 6(4)(e) GDPR]] were in place. Latest revision as of 07:19, 14 September 2026 OGH - 6Ob148/25w Court: OGH (Austria) Jurisdiction: Austria Relevant Law: Article 6(1)(f) GDPR Article 6(4) GDPR Article 7 CFRArticle 8 CFR Decided: 12.08.2026 Published: Parties: National Case Number/Name: 6Ob148/25w European Case Law Identifier: ECLI:AT:OGH0002:2026:0060OB00148.25W.0812.000 Appeal from: Appeal to: Original Language(s): German Original Source: RIS (in German) Initial Contributor: lh The court held that the further processing of personal data initially collected for the purpose of marketing is incompatible under Article 6(4) GDPR with the processing for the purpose of an identity check in the context of credit assessments. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The controller runs an address publishing business as well as a credit information agency. They bought personal data about a data subject (name, address, date of birth) from a company that operates in the address publishing and direct marketing industry. The data subject’s data was collected by the company for the purpose of direct marketing. The controller uses the personal data in question exclusively for identity checks in the context of credit assessments: When a customer of the controller asks for a credit assessment of a person, the controller verifies with their data base whether a person with that name and address exists. That personal data is not included in the credit assessment itself. The credit assessment is calculated with the personal data provided by the customer who requests the service of credit assessment from the controller, as well as data acquired from debt collection agencies. The contractual agreement between the controller and the company that sold the data subject’s data says that the controller may use the data that is subject to the contract only for identity checks and no other purposes. A supplementary agreement specific data may be used for marketing purposes. The controller made a credit assessment of the data subject. In that credit assessment, the controller relied on general data such as the name, gender and address of the data subject because there was no available data on possible payment defaults of the data subject. However, the score was not solely based on age and address. The controller indicated to the customers who request the data subject’s credit assessment that the assessment is based not on payment default data. There is payment default data available on approximately 10% of Austrians. The data subject brought an injunction against the controller with respect to the change of purpose of processing because the data in question was initially collected for direct marketing purposes and not for the purpose of credit assessment. Moreover, the injunction concerned the credit assessment that relied solely on statistical data and not on data concerning the payment history of the data subject. The court of first instance and second instance rejected the injunction. The court of first instance held that the controller processed the data according to the contract with the company they bought the data from. Moreover, the processing for the original purpose was compatible with the further processing. The court of second instance concluded that the further processing was not compatible with the original purpose but that the controller could rely on national law as legal basis. As far as the method of credit assessment was concerned, both courts held that the processing fell under Article 6(1)(f) GDPR because the processing was necessary for operating a credit information agency. Holding The court partly upheld the decision of the court of second instance. 1.Pre-emptive injunctions Firstly, the court referred to the case law of the CJEU that provides for the possibility of pre-emptive injunctions under national law. The scope of the subject matter of the injunction under Austrian national law is reduced to the specific violating actions the data subject claims. Therefore, as far as the data subject requests the controller to desist from unlawfully processing their personal data in general, the injunction is inadmissible because the data subject failed to name a specific violation. 2.Further processing The court held that the controller processed the data for a further purpose than the initial coll