Regulatory Watch  /  Austria  /  Interpretation
Moderate impactInterpretationPublished

Austrian DPA rejects risk‑based approach for EU‑US data transfers, deems Google IP anonymisation insufficient

The Austrian Data Protection Authority issued a decision stating that the GDPR does not permit a risk‑based approach for transfers to insecure third countries such as the United States. It also concluded that Google’s IP anonymisation does not adequately protect personal data transferred via Google Analytics.

Why it matters: The ruling clarifies that GDPR requires full safeguards for EU‑US data transfers, limiting reliance on risk‑based arguments and IP anonymisation.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
UPDATE on noyb’s 101 complaints: Austrian DPA rejects “risk based approach” for data transfers to third countries
noyb · primary source · May 2, 2022
UPDATE on noyb’s 101 complaints: Austrian DPA rejects “risk based approach” for data transfers to third countries
noyb · May 2, 2022
Details
JurisdictionAustria
RegulatorAustrian Data Protection Authority
LawGeneral Data Protection Regulation
StatusPublished
PublishedMay 2, 2022
Effectivenot stated
OrganisationsGoogle
Topicscross border transfer, data minimization, security, privacy, access
Datapersonal, device