Back to all lessons
Awareness Lessons
3 months ago

Austrian Broadcaster Violated GDPR by Recording Calls Without Legal Basis

The Austrian Federal Administrative Court ruled that a public broadcaster unlawfully recorded service-line calls, failing to establish a valid legal basis under GDPR for the processing of personal data. The broadcaster's justification of quality assurance was rejected because less intrusive alternatives existed and the data minimization principle was not applied. This case highlights that organizations must proactively identify and document a lawful basis for every data processing activity before implementation, not after a complaint is filed. Failing to do so exposes organizations to regulatory enforcement, reputational damage, and erosion of public trust — particularly serious for public-sector entities.

Tactical Insight

Immediate actions

  • Conduct an urgent audit of all call recording and monitoring practices to verify a documented lawful basis exists under GDPR Article 6.
  • Suspend any recording activities that lack a clearly defined and documented legal justification until compliance is confirmed.

Long-term improvements

  • Implement a formal Data Protection Impact Assessment (DPIA) process for any new data processing activity, especially those involving personal communications.
  • Embed data minimization and purpose limitation principles into all system design and operational procedures by default (Privacy by Design).
  • Establish a recurring review cycle (at least annually) to reassess the legal basis and necessity of all ongoing data processing activities.

Detection & Governance measures

  • Appoint or empower a Data Protection Officer (DPO) with authority to review and veto non-compliant data processing practices before go-live.
  • Maintain a comprehensive Records of Processing Activities (RoPA) register as required by GDPR Article 30, updated whenever processing changes.