Regulatory Watch  /  Austria  /  Data protection authority action
Moderate impactData protection authority actionDecided

Austrian DPA rules CRIF's processing of Austrian citizens' personal data illegal

The Austrian Data Protection Authority found that CRIF GmbH illegally processed addresses, dates of birth, names and other personal data of millions of Austrians obtained from AZ Direkt without consent or legal basis, ordering the deletion of the records. The decision results from a test case filed by privacy NGO noyb.

Why it matters: The ruling marks a significant GDPR enforcement action against a credit bureau for unlawful mass profiling.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Majority of credit bureau "CRIF" database illegal
noyb · primary source · Mar 27, 2023
Majority of credit bureau "CRIF" database illegal
noyb · Mar 27, 2023
Details
JurisdictionAustria
RegulatorAustrian Data Protection Authority
LawGeneral Data Protection Regulation
StatusDecided
PublishedMarch 27, 2023
Effectivenot stated
OrganisationsCRIF GmbH, AZ Direkt, noyb, Bertelsmann Group
Topicsconsent, purpose limitation, profiling, automated decision making, data minimization, deletion
Datapersonal