Back to all lessons
Awareness Lessons
3 weeks ago

Austrian Court Rules Unredacted Personal Data in Public Legal Decisions Violates Privacy Law

The Austrian Federal Administrative Court found that a government website published a disciplinary decision containing highly sensitive personal details — including mental health status and religious function — without redacting information unnecessary for legal transparency. This constitutes a fundamental failure in data minimisation, a core principle of GDPR, where only the minimum necessary personal data should be disclosed publicly. The case highlights that digital publication of official documents carries the same (and often amplified) privacy obligations as physical publication due to wider reach and permanence. Organisations handling legal or administrative records must treat publication workflows as data processing activities subject to full privacy review. Failure to embed privacy checks into document publication processes exposes public bodies to legal liability and causes real harm to individuals.

Tactical Insight

Immediate actions

  • Conduct an urgent audit of all publicly accessible legal and administrative decisions to identify unredacted sensitive personal data.
  • Establish an emergency redaction process to remove or anonymise unnecessary personal identifiers (health, religion, workplace details) from already-published documents.

Process & Policy improvements

  • Implement a mandatory pre-publication privacy review checklist aligned with GDPR data minimisation and purpose limitation principles for all official documents.
  • Define clear redaction standards specifying which categories of personal data (e.g., health, religion, financial) must always be removed before public disclosure.
  • Train legal and administrative staff on privacy-by-design principles, ensuring they understand that digital publication amplifies privacy risks compared to traditional formats.

Long-term governance measures

  • Integrate a Data Protection Impact Assessment (DPIA) into the document publication workflow for any records containing special category data under GDPR Article 9.
  • Appoint or empower the Data Protection Officer (DPO) to approve publication of sensitive administrative decisions before they go live.
  • Implement automated content scanning tools to flag special category data in documents prior to upload to public-facing systems.