VwGH - VwGH Ro 2025/04/0007-7
Austrian court reduces fine for processing political affinity data without consent.
Summary
The Austrian Supreme Administrative Court has reduced a fine against an address publisher to €13,000,000 for grossly negligently processing political party affinity data of 2.2 million people without explicit consent. The court's decision was influenced by a preliminary ruling from the CJEU, which clarified that controllers can be sanctioned if they could not have been unaware of the infringing nature of their conduct, even without direct knowledge of the GDPR violation. The court found the company's incorrect assessment of political party affinity scores as non-personal data to be gross negligence.
Full text
Help VwGH - VwGH Ro 2025/04/0007-7: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 11:12, 27 July 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators229 edits Tag: Decisions [1.0] Revision as of 12:24, 28 July 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators229 editsmTag: Visual editNewer edit → Line 108: Line 108: }}}} The Supreme Administrative Court reduced a fine against an address publisher and direct advertising company to €13,000,000. It upheld the finding that the company had grossly negligently processed political party affinity data of 2.2 million people without explicit consent.The Supreme Administrative Court reduced a fine against an address publisher and direct advertising company to €13,000,000. It upheld the finding that the company had grossly negligently processed political party affinity data of 2,200,000 people without explicit consent. == English Summary ==== English Summary == Line 121: Line 121: The DPA filed an extraordinary official appeal against this judgment with the Austrian Supreme Administrative Court (VwGH). The court stayed the proceedings pending the CJEU’s preliminary ruling in Case C-807/21 (Deutsche Wohnen SE), as the questions referred in that case were also relevant to the appeal proceedings. The CJEU published its judgement on this matter on 5 December 2023. The DPA filed an extraordinary official appeal against this judgment with the Austrian Supreme Administrative Court (VwGH). The court stayed the proceedings pending the CJEU’s preliminary ruling in Case C-807/21 (Deutsche Wohnen SE), as the questions referred in that case were also relevant to the appeal proceedings. The CJEU published its judgement on this matter on 5 December 2023. The CJEU held that a fine under [[Article 83 GDPR|Article 83(4) GDPR]], [[Article 83 GDPR|Article 83(5) GDPR]] and Article 83 (6) GDPR may be imposed on anyone who qualifies as a controller where it is established that the controller committed the relevant infringement intentionally or negligently. A controller may be sanctioned where it could not have been unaware of the infringing nature of its conduct, regardless of whether it knew that its conduct infringed the GDPR. The CJEU further clarified that, where the controller is a legal person, the application of [[Article 83 GDPR|Article 83 GDPR]] does not require any action or knowledge on the part of its governing body. Member States may not impose additional substantive requirements for the imposition of fines beyond those laid down in [[Article 83 GDPR|Article 83 GDPR]]. For the determination of the fine, the controller may also constitute an undertaking within the meaning of EU competition law, with the turnover of the relevant economic unit being taken into account.The CJEU held that a fine under [[Article 83 GDPR|Article 83(4) GDPR]], [[Article 83 GDPR|Article 83(5) GDPR]] and Article 83 (6) GDPR may be imposed on anyone who qualifies as a controller where it is established that the controller committed the relevant infringement intentionally or negligently. A controller may be sanctioned where it could not have been unaware of the infringing nature of its conduct, regardless of whether it knew that its conduct infringed the GDPR. The CJEU further clarified that, where the controller is a legal person, the application of [[Article 83 GDPR]] does not require any action or knowledge on the part of its governing body. Member States may not impose additional substantive requirements for the imposition of fines beyond those laid down in [[Article 83 GDPR]]. For the determination of the fine, the controller may also constitute an undertaking within the meaning of EU competition law, with the turnover of the relevant economic unit being taken into account. Following the CJEU judgment, the Supreme Administrative Court annulled the Federal Administrative Court’s judgment on 1 February 2024. The Federal Administrative Court issued a new judgment on 27 December 2024, largely upholding the infringements but reducing the fine to €16,000,000. The controller appealed this decision before the Supreme Administrative Court.Following the CJEU judgment, the Supreme Administrative Court annulled the Federal Administrative Court’s judgment on 1 February 2024. The Federal Administrative Court issued a new judgment on 27 December 2024, largely upholding the infringements but reducing the fine to €16,000,000. The controller appealed this decision before the Supreme Administrative Court. Line 133: Line 133: In assessing the controller’s culpability, the court relied heavily on the CJEU’s judgment in Deutsche Wohnen SE. It held that the fact that the controller believed it had complied with the GDPR because it had established a quality-assured organisation was not decisive. It pointed out that under GDPR, a legal person’s fault does not require knowledge or awareness on the part of the management body. The establishment of a data protection compliance system, like the obtaining of legal advice, did not in itself exculpate the controller. It stated that the decisive question was whether the controller could have been aware of the unlawfulness of the processing of political party affinity data during the relevant period.In assessing the controller’s culpability, the court relied heavily on the CJEU’s judgment in Deutsche Wohnen SE. It held that the fact that the controller believed it had complied with the GDPR because it had established a quality-assured organisation was not decisive. It pointed out that under GDPR, a legal person’s fault does not require knowledge or awareness on the part of the management body. The establishment of a data protection compliance system, like the obtaining of legal advice, did not in itself exculpate the controller. It stated that the decisive question was whether the controller could have been aware of the unlawfulness of the processing of political party affinity data during the relevant period. The court ruled that the controller had incorrectly assessed that political party affinity scores did not constitute personal data and that it had consequently failed to examine whether they constituted special categories of personal data under [[Article 9 GDPR|Article 9 GDPR]]. The court rejected the controller’s argument that political party affinity was processed only in relation to groups rather than in relation to specific identifiable individuals. It also rejected the argument that marketing classifications used for political advertising posed no risk to data subjects. The court concluded that given the controller’s resources and its ability to examine the applicable legal position, that legal assessment amounted to gross negligence concerning the infringement of [[Article 5 GDPR|Article 5(1)(a) GDPR]] in conjunction with [[Article 9 GDPR|Article 9(1) GDPR]].The court ruled that the controller had incorrectly assessed that political party affinity scores did not constitute personal data and that it had consequently failed to examine whether they constituted special categories of personal data under [[Article 9 GDPR]]. The court rejected the controller’s argument that political party affinity was processed only in relation to groups rather than in relation to specific identifiable individuals. It also rejected the argument that marketing classifications used for political advertising posed no risk to data subjects. The court concluded that given the controller’s resources and its ability to examine the applicable legal position, that legal assessment amounted to gross negligence concerning the infringement of [[Article 5 GDPR|Article 5(1)(a) GDPR]] in conjunction with [[Article 9 GDPR|Article 9(1) GDPR]]. Furthermore, the court ruled that the controller’s incorrect assessment that political party affinity scores did not constitute p