Austrian Supreme Court Rules Purpose Limitation Violation Under GDPR in Credit Assessment Case
The Austrian Supreme Court found that repurposing personal data collected for direct marketing to perform identity verification in credit assessments violates GDPR's purpose limitation principle under Article 5(1)(b) and Article 6(4). The controller failed to conduct a proper compatibility assessment before using the data for a fundamentally different purpose, exposing the organization to significant legal liability. This ruling underscores that purchasing data for one lawful purpose does not grant unlimited rights to use it for other processes — even seemingly related ones. Organizations must treat each distinct processing purpose as requiring its own legal basis and compatibility evaluation.
Tactical Insight
Immediate actions
- Audit all existing datasets to document the original purpose of collection and map any secondary uses that may constitute incompatible repurposing.
- Halt any processing activities where personal data acquired for marketing is being used for creditworthiness, identity verification, or fraud checks without a separate legal basis.
Governance & compliance controls
- Establish a formal Data Processing Impact and Compatibility Assessment process that must be completed before any new or secondary use of personal data is approved.
- Maintain a Records of Processing Activities (RoPA) register that explicitly documents the lawful basis and purpose for each distinct processing activity, as required under GDPR Article 30.
- Implement contractual and technical controls when purchasing third-party data to restrict its use strictly to the agreed and documented purpose.
Long-term improvements
- Train data governance, marketing, and risk teams on purpose limitation principles to ensure business units do not repurpose datasets without legal review.
- Integrate a mandatory privacy-by-design checkpoint in product and process development workflows to catch unlawful purpose expansion before deployment.
- Engage Data Protection Officers (DPOs) proactively in credit assessment and identity verification pipeline design to validate GDPR compliance upstream.