GDPR fine: 13 million for party affinities
By Dr. Sascha Raits, Partner
An address trading company (Adressverlag) had calculated and stored so-called party affinities for around 2.2 million people in Austria: statistical probability values indicating how likely a person was to be interested in the election advertising of particular parties. Some of these values were sold to third parties. In October 2019 the Data Protection Authority imposed a fine of 18 million euros, also on account of further charges; at the end of 2024 the Federal Administrative Court reduced it to 16 million euros. With decision Ro 2025/04/0007 of 24 June 2026 the Austrian Supreme Administrative Court has closed the proceedings: the fine is 13 million euros, the contribution to the costs of the proceedings 100,000 euros.
The decision is more than the final word in a prominent case. It answers several questions that matter to every business processing personal data on a larger scale.
Probability values are personal data
The company had classified the party affinities as mere statistics rather than personal data. That assessment already failed before the Federal Administrative Court: information attributed to an identifiable person is personal data even where it rests on estimates. The Court of Justice of the European Union had said as much in December 2017 in Nowak (C-434/16), and the Austrian Data Protection Commission and Data Protection Authority had ruled to the same effect before that.
A value that reflects a person's presumed closeness to a political party reveals political opinion. It is therefore a special category of personal data under Art. 9 GDPR. Processing such data is prohibited as a rule; no explicit consent of the data subjects had been obtained. § 151 of the Trade Regulation Act (GewO), which permits address trading companies certain processing for marketing purposes, likewise requires explicit consent for data of this kind.
Fault: a compliance structure alone does not protect
The company had prepared for the GDPR with a dedicated project and had entrusted staff with data protection. They took the view that the statistical values were not personal data. That legal position was held to be untenable and the conduct grossly negligent. The preparatory project does not remove the culpability: it had not, in fact, prevented the infringements. When it came to setting the amount of the fine, however, it did count in the company's favour — see below.
The Supreme Administrative Court makes clear that penalising a legal person does not require any act or knowledge on the part of its management bodies. It relies on the judgment of the Court of Justice in Deutsche Wohnen (C-807/21). National rules on fault, such as § 5 of the Administrative Penal Act (VStG), may not go beyond the requirements of Art. 83 GDPR. What matters is whether the controller could have been aware that its conduct was unlawful.
One overall fine instead of a sum of individual fines
Besides the processing of the party affinities, the company had been charged with a flawed data protection impact assessment (Art. 35 GDPR) and an incorrect record of processing activities (Art. 30 GDPR). Both documents rested on the same classification: the record denied any processing of sensitive data, and the impact assessment saw no high risk. The Federal Administrative Court had treated these breaches as separate offences.
The Supreme Administrative Court takes a different view. Both documentation failures are consequences of the same misjudgement, namely the classification of the party affinities. They carry no separate wrongfulness of their own and are absorbed by the principal infringement. Under the court's case law, such absorption applies where two infringements violate the same legal interest and one offence necessarily entails the other.
For the remaining infringements Art. 83(3) GDPR applies: where a controller infringes several provisions in the case of identical or linked processing operations, a single overall fine is to be imposed, and its amount may not exceed the amount for the gravest infringement. That rule takes precedence over the cumulation principle of § 22 VStG, under which each offence attracts its own penalty.
Calculation: the worldwide group turnover counts
For the range of the fine, Art. 83(4) and (5) GDPR look to the total worldwide annual turnover of the preceding financial year, the group turnover figures established in the proceedings — just under two billion euros for 2018 and a good 2.7 billion for 2023. There is no legal basis for calculating the fine on the turnover attributable to the infringement, as the company had argued; nor do the guidelines of the European Data Protection Board on the calculation of fines offer any support for that approach.
Setting the fine is a discretionary decision guided by the criteria of Art. 83(2) GDPR and § 19 VStG. On this point the Supreme Administrative Court corrected the Federal Administrative Court in the way that matters most in practice: the measures the company had taken to prevent an infringement must be taken into account in its favour when assessing the degree of responsibility under Art. 83(2)(d) GDPR. Together with the cease-and-desist undertakings given to numerous data subjects and the exceptionally long duration of the proceedings — some 66 months — this is what carries the reduction from sixteen to thirteen million euros. No additional mitigation was allowed for the absence of earlier infringements, which the Federal Administrative Court had already accounted for as the absence of an aggravating factor, or for an admission limited to the facts without acknowledging the company's own responsibility. The economic advantage the company had gained, among other things from selling the data, was treated as aggravating.
Costs of the proceedings: no hidden additional penalty
Under § 64(2) VStG the contribution to the costs of the penal proceedings amounts to ten per cent of the penalty imposed. On 13 million euros that would have been 1.3 million euros. The Supreme Administrative Court regards this as disproportionate: the GDPR sets maximum amounts for fines in Art. 83(4) to (6), whereas § 64 VStG provides no ceiling for the cost contribution. The company had argued that a cost contribution in the millions would amount to an additional penalty without objective justification; in view of these exceptional circumstances the court held the amount to be excessive and therefore disproportionate. It set the contribution at 100,000 euros.
What businesses should take from this
Scores and probability values are personal data as soon as they are attributed to a person. Anyone who infers political opinion, health, religion or other sensitive characteristics from them is processing special categories of data and needs explicit consent or another exception under Art. 9(2) GDPR.
A data protection organisation is no substitute for a sound legal assessment — but it does pay off. A project and designated staff will not avert the fine if the basic classification of the data is wrong. When setting the amount, however, the Supreme Administrative Court expressly weighed the precautions taken in the company's favour. Questions of this weight deserve a legal assessment in their own right, and the reasoning behind the classification should be documented.
The fine is measured against group turnover, not against the turnover from the processing in question. For companies within group structures that can be the relevant frame, even where only one entity is concerned.
Cooperation and remediation count as mitigating. Working with the authority, deleting the data and giving cease-and-desist undertakings to data subjects were weighed in the company's favour. An admission, however, only mitigates if it includes an acknowledgement of one's own responsibility.
Follow-on breaches arising from the same misjudgement were not penalised separately here. Anyone who misclassifies a category of data will inevitably also render the impact assessment and the record of processing defective. Whether such breaches are absorbed by the principal infringement depends on the individual case, though; it is not something to rely on.
This information is general in nature and does not replace legal advice on an individual case.