Regulatory Watch  /  Austria  /  Enforcement
Low impactEnforcementPublished

Austrian DSB rules credit bureau KSV 1870 may not collect data via access requests and civil registries

The Austrian Data Protection Authority found KSV 1870's practice of storing information obtained through GDPR access requests and civil‑registry comparisons illegal, violating purpose‑limitation under Article 5(1)(b) GDPR. The DSB ordered the deletion of the unlawfully processed data.

Why it matters: The ruling restricts credit bureaus from using access‑request data for credit scoring, reinforcing GDPR purpose‑limitation and deletion obligations.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Credit agency prohibited from collecting data via access requests and civil registries
noyb · primary source · Feb 6, 2023
Credit agency prohibited from collecting data via access requests and civil registries
noyb · Feb 6, 2023
Details
JurisdictionAustria
RegulatorAustrian Data Protection Authority (DSB)
LawGeneral Data Protection Regulation
StatusPublished
PublishedFebruary 6, 2023
Effectivenot stated
OrganisationsKSV 1870
Topicspurpose limitation, deletion, access, privacy
Datapersonal