Regulatory Watch  /  Austria  /  Enforcement
Low impactEnforcementFiled

noyb files GDPR complaint against CRIF and AZ Direct over illegal data exchange

noyb lodged a GDPR complaint on 18 March 2021 against credit scoring firm CRIF GmbH and address publisher AZ Direct for exchanging personal data without a legal basis. The complaint alleges violations of the GDPR purpose‑limitation principle and Austrian law. The Austrian Data Protection Authority could impose fines of up to €20 million or 4 % of annual turnover.

Why it matters: The case highlights enforcement risk for data brokers and credit agencies that share personal data beyond permitted advertising purposes.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Illegal data exchange between address publisher and credit ranking agency
noyb · primary source · Mar 18, 2021
Illegal data exchange between address publisher and credit ranking agency
noyb · Mar 18, 2021
Details
JurisdictionAustria
RegulatorAustrian Data Protection Authority
LawGeneral Data Protection Regulation
StatusFiled
PublishedMarch 18, 2021
Effectivenot stated
DecisionMarch 18, 2021
OrganisationsCRIF GmbH, AZ Direct, noyb
Topicspurpose limitation, consent, transparency, data minimization, access, deletion, profiling
Datapersonal