What happened
The Austrian Supreme Court (OGH) held that credit reference agencies may not collect personal data from address publishers that process the data for marketing purposes, confirming a GDPR purpose‑limitation breach. The ruling supports noyb’s planned class action against CRIF and AZ Direct.
Why it matters for trust and compliance
- Its status is decided. The case has an outcome that others may cite.
- The decision clarifies GDPR purpose‑limitation obligations for credit scoring, paving the way for a consumer class action in Austria.
- It relates to GDPR. The regulations library explains what that law requires.
Who is affected
financial services technology controller processor data broker CRIF AZ Direct noyb Robert Haupt
Recommended actions
- Check that privacy notices describe the practices this addresses.
- Revisit retention schedules and data minimisation for the data involved.
- Inventory where this data is shared or sold and whether opt-outs are honoured.
- Inventory AI or automated decision systems in scope and their assessments.