[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBQeJqKJdhPRM7gG_UNGad0CdPZy1AiLFNH-WzQ2HTLQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"c084af45-991a-42ed-9370-c9d9faff4c99","austrian-court-rules-unredacted-personal-data-in-public-legal-decisions-violates-privacy-law","efccec4d-3a49-4672-9b50-d47bf873d708","Austrian Court Rules Unredacted Personal Data in Public Legal Decisions Violates Privacy Law","The Austrian Federal Administrative Court found that a government website published a disciplinary decision containing highly sensitive personal details — including mental health status and religious function — without redacting information unnecessary for legal transparency. This constitutes a fundamental failure in data minimisation, a core principle of GDPR, where only the minimum necessary personal data should be disclosed publicly. The case highlights that digital publication of official documents carries the same (and often amplified) privacy obligations as physical publication due to wider reach and permanence. Organisations handling legal or administrative records must treat publication workflows as data processing activities subject to full privacy review. Failure to embed privacy checks into document publication processes exposes public bodies to legal liability and causes real harm to individuals.","**Immediate actions:**\n- Conduct an urgent audit of all publicly accessible legal and administrative decisions to identify unredacted sensitive personal data.\n- Establish an emergency redaction process to remove or anonymise unnecessary personal identifiers (health, religion, workplace details) from already-published documents.\n\n**Process & Policy improvements:**\n- Implement a mandatory pre-publication privacy review checklist aligned with GDPR data minimisation and purpose limitation principles for all official documents.\n- Define clear redaction standards specifying which categories of personal data (e.g., health, religion, financial) must always be removed before public disclosure.\n- Train legal and administrative staff on privacy-by-design principles, ensuring they understand that digital publication amplifies privacy risks compared to traditional formats.\n\n**Long-term governance measures:**\n- Integrate a Data Protection Impact Assessment (DPIA) into the document publication workflow for any records containing special category data under GDPR Article 9.\n- Appoint or empower the Data Protection Officer (DPO) to approve publication of sensitive administrative decisions before they go live.\n- Implement automated content scanning tools to flag special category data in documents prior to upload to public-facing systems.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(c) – Data Minimisation","GDPR Article 9 – Processing of Special Categories of Personal Data","GDPR Article 25 – Data Protection by Design and by Default","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","NIST SP 800-53 AC-3 – Access Enforcement","NIST SP 800-53 SI-12 – Information Management and Retention","CIS Control 3 – Data Protection","CIS Control 14 – Security Awareness and Skills Training","ISO\u002FIEC 27001 Annex A.8.2 – Information Classification","ITIL Service Design – Information Security Management","published","2026-09-23T08:22:19.168054+00:00","2026-09-23T08:22:19.08+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=BVwG_-_W298_2314952-1&diff=53163&oldid=53158","bvwg-w298-2314952-1-fdd40c","BVwG - W298 2314952-1",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]