€13M GDPR Fine for Unlawful Processing of Political Affinity Data of 2.2M Individuals
An Austrian address publishing and direct advertising company was found to have grossly negligently processed political party affinity data for 2.2 million individuals without obtaining explicit consent, violating core GDPR principles around lawful basis and special category data. Political affinity constitutes sensitive personal data under GDPR Article 9, requiring a higher standard of consent and protection than ordinary personal data. The Austrian Supreme Administrative Court upheld the finding of a violation while reducing the fine, signaling that courts will still impose substantial penalties even when mitigating factors exist. This case underscores that organizations monetizing personal data for marketing purposes face severe regulatory risk when they fail to establish a clear, documented lawful basis — especially for sensitive categories of data.
Tactical Insight
Immediate actions
- Conduct a data audit to identify all personal data categories being processed, flagging any Article 9 special category data (e.g., political opinions, health, religion).
- Suspend or quarantine any data processing activities lacking a documented and valid lawful basis until legal review is completed.
- Engage a Data Protection Officer (DPO) or legal counsel to assess consent mechanisms and processing agreements currently in use.
Long-term improvements
- Implement a Data Protection Impact Assessment (DPIA) process for all new and existing data processing activities involving personal or sensitive data.
- Build a comprehensive Records of Processing Activities (RoPA) register as required by GDPR Article 30, ensuring lawful basis is explicitly documented for each processing purpose.
- Establish a privacy-by-design framework so that consent and data minimization requirements are evaluated before launching any new data product or marketing service.
Detection & compliance monitoring
- Deploy automated tools to continuously monitor data flows and alert when sensitive data categories are accessed or shared without a logged consent record.
- Schedule annual GDPR compliance audits, including third-party reviews of data vendor contracts and data sourcing practices.
- Train marketing, data, and product teams on GDPR obligations for special category data, ensuring awareness of the elevated consent standards under Article 9.