Back to all lessons
Awareness Lessons
4 weeks ago

Austrian Court Rules Credit Agency Violated GDPR Purpose Limitation

A credit information agency unlawfully repurposed personal data originally collected for marketing to conduct identity checks in credit assessments, breaching GDPR's purpose limitation principle under Article 5(1)(b). This case highlights that data collected for one specific purpose cannot simply be reused for an unrelated purpose without a new, valid legal basis. Organizations must define and document the intended purpose of data collection before processing begins, as post-hoc repurposing exposes them to significant legal liability. The ruling serves as a reminder that even seemingly benign secondary uses of data — such as identity verification — can constitute a serious GDPR violation if the original consent or legal basis did not anticipate that use.

Tactical Insight

Immediate actions

  • Audit all existing personal data sets to verify that current processing activities align with the original stated purpose of collection.
  • Suspend any data processing workflows where the legal basis or original purpose cannot be clearly documented.

Policy & governance improvements

  • Establish a formal Data Purpose Register that records the lawful basis, retention period, and permitted uses for every category of personal data collected.
  • Implement a mandatory Privacy Impact Assessment (PIA) process before repurposing any existing data set for a new business function.
  • Train staff responsible for data governance on GDPR purpose limitation and the distinction between compatible and incompatible secondary uses.

Detection & monitoring measures

  • Deploy data lineage tracking tools to monitor how personal data flows across systems and detect unauthorized secondary processing.
  • Schedule periodic internal audits or third-party DPA reviews to verify ongoing compliance with stated data purposes.