[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f05cHMEx2rPTYTNfydyhFHkewoW5ndlX02gjEgSsOK7k":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"c1dc0aaf-d029-4e9f-83e1-af7384e5e069","13m-gdpr-fine-for-processing-political-affinity-data-without-consent","98a278b5-78ea-4559-bf4c-878f5604fa4a","€13M GDPR Fine for Processing Political Affinity Data Without Consent","An Austrian address publisher processed political party affinity data for 2.2 million individuals without obtaining explicit consent, violating a core GDPR principle for handling sensitive special-category data. Compounding the violation, the organization failed to conduct a Data Protection Impact Assessment (DPIA), which is mandatory when processing data likely to result in high risk to individuals. The court found gross negligence, meaning leadership did not need direct knowledge of the violation for the fine to apply — ignorance of legal obligations is not a defense. This case underscores that organizations processing any form of sensitive personal data must have airtight legal bases, not merely assume consent or legitimate interest covers all use cases.","**Immediate actions:**\n- Audit all personal data processing activities to identify any special-category data (e.g., political opinions, health, religion) being processed without explicit consent or another valid GDPR legal basis.\n- Immediately halt processing of special-category data where no documented lawful basis exists until a formal legal review is completed.\n\n**Compliance & governance improvements:**\n- Establish a mandatory DPIA process triggered whenever new data processing activities involve high-risk or special-category data.\n- Appoint or empower a qualified Data Protection Officer (DPO) with authority to review and veto data processing activities that lack a lawful basis.\n- Maintain a living Record of Processing Activities (RoPA) under GDPR Article 30 that explicitly documents the legal basis for every data processing operation.\n\n**Training & accountability measures:**\n- Train senior management and product teams on GDPR special-category data rules, emphasizing that organizational liability applies regardless of direct executive knowledge.\n- Implement a formal privacy-by-design review gate in product and data pipeline development to catch consent and DPIA gaps before processing begins.",[12,13,14,15,16,17,18,19,20],"GDPR Article 9 — Processing of special categories of personal data","GDPR Article 35 — Data Protection Impact Assessment (DPIA)","GDPR Article 5 — Principles relating to processing of personal data","GDPR Article 30 — Records of processing activities","GDPR Article 83 — General conditions for imposing administrative fines","NIST Privacy Framework PR.PP-P4 — Privacy policies and practices","NIST SP 800-53 PT-2 — Authority to Process Personally Identifiable Information","CIS Control 3 — Data Protection","ISO\u002FIEC 27701 — Privacy Information Management System (PIMS)","published","2026-07-29T11:20:22.090889+00:00","2026-07-29T11:20:21.776+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=VwGH_-_VwGH_Ro_2025\u002F04\u002F0007-7&diff=52531&oldid=52519","vwgh-vwgh-ro-2025-04-0007-7-b78307","VwGH - VwGH Ro 2025\u002F04\u002F0007-7",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]