Regulatory Watch  /  Austria  /  Enforcement
Low impactEnforcementFiled

noyb files GDPR complaint against Austrian credit data broker KSV 1870

On 08.02.2021, the privacy NGO noyb lodged a GDPR complaint with the Austrian data protection authority alleging that KSV 1870 stores identification data from access requests in its commercial database, violating purpose‑limitation. The complaint cites Article 15 GDPR and Article 5(1)(b) GDPR as well as § 152 of the Austrian Trade Regulation Act.

Why it matters: The complaint highlights a potential misuse of data subjects' access‑request information, raising enforcement concerns for credit reference agencies.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Right of access as a data protection boomerang?
noyb · primary source · Feb 8, 2021
Right of access as a data protection boomerang?
noyb · Feb 8, 2021
Details
JurisdictionAustria
RegulatorAustrian Data Protection Authority
LawGeneral Data Protection Regulation
StatusFiled
PublishedFebruary 8, 2021
Effectivenot stated
OrganisationsKSV 1870
Topicspurpose limitation, privacy, data brokers, access, profiling, automated decision making
Datapersonal, financial