[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3L29gWvEscGYLfJbRvoBRULzaGW4oP9uLDXoPymUJnI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"41cc664f-f211-431e-a182-c270e6441aff","13m-gdpr-fine-for-unlawful-processing-of-political-affinity-data-of-22m-individuals","1f3dd3cd-1ab0-4cf0-8b6f-bdac13c08b8a","€13M GDPR Fine for Unlawful Processing of Political Affinity Data of 2.2M Individuals","An Austrian address publishing and direct advertising company was found to have grossly negligently processed political party affinity data for 2.2 million individuals without obtaining explicit consent, violating core GDPR principles around lawful basis and special category data. Political affinity constitutes sensitive personal data under GDPR Article 9, requiring a higher standard of consent and protection than ordinary personal data. The Austrian Supreme Administrative Court upheld the finding of a violation while reducing the fine, signaling that courts will still impose substantial penalties even when mitigating factors exist. This case underscores that organizations monetizing personal data for marketing purposes face severe regulatory risk when they fail to establish a clear, documented lawful basis — especially for sensitive categories of data.","**Immediate actions:**\n- Conduct a data audit to identify all personal data categories being processed, flagging any Article 9 special category data (e.g., political opinions, health, religion).\n- Suspend or quarantine any data processing activities lacking a documented and valid lawful basis until legal review is completed.\n- Engage a Data Protection Officer (DPO) or legal counsel to assess consent mechanisms and processing agreements currently in use.\n\n**Long-term improvements:**\n- Implement a Data Protection Impact Assessment (DPIA) process for all new and existing data processing activities involving personal or sensitive data.\n- Build a comprehensive Records of Processing Activities (RoPA) register as required by GDPR Article 30, ensuring lawful basis is explicitly documented for each processing purpose.\n- Establish a privacy-by-design framework so that consent and data minimization requirements are evaluated before launching any new data product or marketing service.\n\n**Detection & compliance monitoring:**\n- Deploy automated tools to continuously monitor data flows and alert when sensitive data categories are accessed or shared without a logged consent record.\n- Schedule annual GDPR compliance audits, including third-party reviews of data vendor contracts and data sourcing practices.\n- Train marketing, data, and product teams on GDPR obligations for special category data, ensuring awareness of the elevated consent standards under Article 9.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5 – Principles relating to processing of personal data","GDPR Article 6 – Lawfulness of processing","GDPR Article 9 – Processing of special categories of personal data","GDPR Article 13\u002F14 – Transparency and information obligations","GDPR Article 30 – Records of processing activities","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","NIST Privacy Framework PR.DS-P1 – Data processing policies","NIST SP 800-53 PT-2 – Authority to Process Personally Identifiable Information","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management System (PIMS)","ITIL Service Transition – Compliance and risk management","published","2026-07-27T12:20:41.029097+00:00","2026-07-27T12:20:40.928+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=VwGH_-_VwGH_Ro_2025\u002F04\u002F0007-7&diff=52506&oldid=0","vwgh-vwgh-ro-2025-04-0007-7-cb4a46","VwGH - VwGH Ro 2025\u002F04\u002F0007-7",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]