REGULATORY WATCH BRIEF Moderate 43 🔨 Court Ruling decided

Austrian Supreme Court rules CRIF’s use of address‑publisher data for credit scoring violates GDPR purpose limitation

The decision clarifies GDPR purpose‑limitation obligations for credit scoring, paving the way for a consumer class action in Austria.

ImpactModerate 43
Type🔨 Court Ruling
Statusdecided case outcome
JurisdictionEU-AT

What happened

The Austrian Supreme Court (OGH) held that credit reference agencies may not collect personal data from address publishers that process the data for marketing purposes, confirming a GDPR purpose‑limitation breach. The ruling supports noyb’s planned class action against CRIF and AZ Direct.

Why it matters for trust and compliance

  • Its status is decided. The case has an outcome that others may cite.
  • The decision clarifies GDPR purpose‑limitation obligations for credit scoring, paving the way for a consumer class action in Austria.
  • It relates to GDPR. The regulations library explains what that law requires.

Who is affected

financial services technology controller processor data broker CRIF AZ Direct noyb Robert Haupt

Recommended actions

  1. Check that privacy notices describe the practices this addresses.
  2. Revisit retention schedules and data minimisation for the data involved.
  3. Inventory where this data is shared or sold and whether opt-outs are honoured.
  4. Inventory AI or automated decision systems in scope and their assessments.