All news
Case law June 24, 2026 7 min

Austria: the Supreme Administrative Court cuts the fine from 18 to 13 million. But the part to read is where it says a compliance programme excuses nothing

A 'Fit for GDPR' system, internal opinions and outside experts did not avoid gross negligence, because the legal position was indefensible and the company had the means to know it

TL;DR for the DPO

Four useful points. 1) Liability of a legal person does not require that the top of the house knew: the controller's own fault is enough. 2) A legal opinion, internal or external, offers no protection if the position is indefensible, and having the money to be advised well becomes an argument against you. 3) A statistical probability score attached to an identifiable person is personal data even when it is an estimate. 4) The DPIA and record-of-processing charges were annulled as absorbed into the main breach, but those documents were still wrong.

What the case is about

The proceedings have been pending since 2019 and had already reached the Supreme Administrative Court twice. A company - the decision keeps it anonymous, referring to a businesswoman - collected and managed personal data of advertising recipients and made it available for a fee to customers running advertising, including election advertising. Between May 2018 and February 2019 it calculated and stored, for around 2.2 million people, so-called party affinities: statistical probability values indicating how interested a person might be in advertising by particular parties, partly sold to third parties. It also processed, for marketing purposes and without consent, parcel-frequency data derived from its delivery activity.

2.2million
million people with a party affinity calculated and stored

The Austrian authority had imposed EUR 18 million plus EUR 1.8 million as a contribution to the costs of the penalty proceedings. The Federal Administrative Court reduced this to EUR 16 million and EUR 1.6 million in costs, discontinuing the part on 'moving affinities' and narrowing the period charged for parcel frequencies, but confirming the unlawful processing of party affinities as a special category of personal data, together with the findings on the deficient impact assessment and record of processing activities.

The defence: we had a compliance programme

On appeal the company argued it had not acted culpably: it had set up a comprehensive compliance system, had the legal position checked both internally and by experts, and at the time took the view that statistically calculated probability values were not personal data.

Why the Court rejected it

Punishing a legal person requires no act or knowledge on the part of its management bodies: it is enough that the controller acted intentionally or negligently. And the test for fault is whether the controller could have been clear about the unlawfulness of its conduct - awareness of the breach is not a precondition. Classifying party affinities as non-personal was an indefensible position: already before 2018 the decision-making practice of the authorities had made clear that information attributed to an identifiable person is personal data, even where it rests on estimates. And because the company had considerable means for legal review and still misinterpreted the existing practice, gross negligence is confirmed.

It is a reversal worth remembering when a client says "we got an opinion on it". The opinion is not a shield: if the position sat outside known practice, the ability to obtain good advisers becomes the reason there is no excuse. The first-instance court had been even blunter: the internal control system had failed to prevent basic legal misinterpretations.

DPIA and record: dropped, but not because they were right

In the impact assessment and in the record of processing activities the company had denied processing special-category data. The Court sees absorption here: that data had not been entered in the documents as a consequence of the mistaken assessment that it was not personal data, and therefore not special categories either. The wrong involved in breaching documentation duties is already fully captured by punishing the unlawful processing itself, and additional punishment is inadmissible. On those counts the proceedings were discontinued.

How to read this in practice

Do not expect a separate fine under Articles 30 and 35 when the defect in the documents is the downstream consequence of a single classification error. But note the converse: the record and the DPIA were wrong all the same, and one mistaken classification propagates into every document that depends on it. When you review a record, the useful question is not "are the entries filled in" but "what classification do they rest on".

Procedural costs as a disguised penalty

Among the mitigating factors the Court gave weight to the measures taken to prevent a breach, the cease-and-desist declarations given to numerous data subjects, and the exceptionally long duration of the proceedings, around 66 months. It did not consider it necessary to count the absence of prior infringements as a further mitigating factor, because the lower court had already treated it as the absence of an aggravating one.

The newest point comes at the end: setting the contribution to the costs of the proceedings at EUR 1.3 million conflicts with EU law, because it leads to an additional penalty that cannot be justified on the merits. The Court reduced that contribution to EUR 100,000.

What to do now, in practice

1) Go looking for scores at your clients: propensity, affinity, interest scoring, computed segments. If they are attached to an identifiable person they are personal data, even when they are estimates, and if they estimate political opinions, health, religion or sexual orientation they are Article 9 data. 2) Do not file a legal opinion as if it were a guarantee: also record the authority practice you consulted and the date, because the test is whether you could have realised. 3) Run the record-of-processing check in reverse: start from the classifications (personal data yes or no, special category yes or no) and see which entries and which DPIAs depend on them. One error at the top produces ten downstream. 4) If a client receives a fine with a costs contribution proportionate to the amount, this decision is an argument for challenging it. 5) Remember that the authority's own delay works in favour of the party fined: 66 months counted as mitigation.

Official source:Verwaltungsgerichtshof - Ro 2025/04/0007 of 24 June 2026, press release of 16 July 2026

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Case law
200 €for the loss of control

Real employee data inside the test system: what loss of control is worth

Testing a new HR system with real data is not forbidden: transferring more fields than the test needs is. The German Federal Labour Court ordered an employer to pay two hundred euro because it had uploaded salary, home address, tax ID and marital status although it had agreed a list of nine fields with the works council. And it confirmed that a delayed answer to an access request is not, in itself, a damage.

Aug 21, 2026New 5 min
Case law
7i criteri di bilanciamento CEDU

You don't delete the article, you delete the name

On 5 August 2026 the CNIL clarified the boundaries of a right that is often exercised and widely misunderstood. Against a press organisation, objection and erasure remain available; access and rectification do not. And a refusal must be reasoned concretely: six generic formulas are named as inadmissible.

Aug 05, 2026New 4 min
Case law
3condizioni cumulative del test

Legitimate interest is not the fallback legal basis

In Case C-621/22 the Court of Justice held that a commercial interest can constitute a legitimate interest under Article 6(1)(f). Many people read only that line. The rest of the judgment recalls that the conditions remain three and cumulative, and that the third - the balancing against the data subject's reasonable expectations - is where the case at hand was lost. For the DPO the consequence is practical: legitimate interest exists only if it is written down somewhere.

Aug 12, 2026New 6 min