The Austrian Data Protection Authority found KSV 1870's practice of storing information obtained through GDPR access requests and civil‑registry comparisons illegal, violating purpose‑limitation under Article 5(1)(b) GDPR. The DSB ordered the deletion of the unlawfully processed data.
Why it matters: The ruling restricts credit bureaus from using access‑request data for credit scoring, reinforcing GDPR purpose‑limitation and deletion obligations.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.