[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fmTAtp60B7zRsTnM6LgVwYJUornomzOYVDK56hoW3QGs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"bb08308c-83a7-4a90-a149-eaac6b3b9c65","austrian-court-rules-unauthorized-gps-tracking-of-employees-unlocks-liability-for-damages","89dc2597-8533-45b2-a109-f0c5b2c211b9","Austrian Court Rules Unauthorized GPS Tracking of Employees Unlocks Liability for Damages","An Austrian employer deployed GPS tracking in company vehicles without obtaining employee consent or establishing a formal company agreement, violating both labor law and data protection principles. The tracking extended into employees' leisure time, compounding the privacy violation and demonstrating a failure to respect the boundaries of lawful monitoring. The Austrian Supreme Court's ruling underscores that deploying surveillance technologies without a proper legal basis exposes organizations to significant legal and financial liability. This case matters because employee monitoring is a sensitive intersection of operational need and fundamental privacy rights — both of which require careful, documented governance to balance lawfully.","**Immediate actions:**\n- Audit all existing employee monitoring technologies (GPS, software tracking, CCTV) to confirm a documented legal basis exists for each.\n- Suspend any monitoring activity that lacks explicit employee consent or a valid company\u002Fworks council agreement until compliance is established.\n\n**Policy & compliance improvements:**\n- Draft and implement a formal Employee Monitoring Policy that defines the scope, purpose, retention period, and legal basis for all monitoring tools.\n- Engage works councils or employee representatives before deploying any new monitoring technology, as required under labor law in many jurisdictions.\n- Ensure GPS or location tracking is automatically disabled or anonymized outside of defined working hours to prevent incidental leisure-time surveillance.\n\n**Training & governance measures:**\n- Train HR, legal, and IT teams on GDPR Article 6 lawful bases and national labor law requirements before procuring monitoring solutions.\n- Establish a clear internal escalation process so employees can raise monitoring concerns and receive a documented, timely response.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(a) – Lawfulness, fairness and transparency","GDPR Article 6 – Lawful basis for processing","GDPR Article 9 – Processing of special categories of data","GDPR Article 88 – Processing in the context of employment","NIST SP 800-53 AC-1 – Access Control Policy and Procedures","NIST SP 800-53 PT-1 – Personally Identifiable Information Processing and Transparency Policy","CIS Control 3 – Data Protection","ISO\u002FIEC 29151 – Code of practice for PII protection","ITIL Service Design – Compliance and legal requirements consideration","Austrian Data Protection Act (DSG) § 11 – Employee data processing requirements","published","2026-06-24T10:20:34.007773+00:00","2026-06-24T10:20:33.892+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=OGH_-_9ObA120\u002F19s&diff=51986&oldid=38658","ogh-9oba120-19s-f1ea31","OGH - 9ObA120\u002F19s",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]