Published on 5 August 2026
13 million euros in penalties – that's how expensive it can get when a company monetises its customers' personal data without asking those affected for permission. That's exactly what happened to Austrian Post AG (Österreichische Post). After a seven-year legal battle, the verdict is now final: the company must pay because it commercially exploited the estimated political leanings of roughly 2.2 million people without their explicit consent and passed this information on to third parties. Austria's Supreme Administrative Court (VwGH) has upheld this ruling (case reference Ro 2025/04/0007) with legally binding effect.
For you as a website operator or the managing director of a small or medium-sized business, this case is relevant for one simple reason: it demonstrates in no uncertain terms how expensive mishandling personal data can become – and that even large, established companies with their own legal departments can fall foul of the General Data Protection Regulation (GDPR). The principles at stake here apply to every company that processes customer data. That includes you.
Between May 2018 and February 2019, Austrian Post estimated the so-called "political affinity" of around 2.2 million Austrians. Put simply: based on existing data, the company calculated probabilities as to which party a person might feel close to – and then used these assessments commercially and passed them on to third parties.
The crucial point: the individuals concerned were not explicitly asked for their consent. But that is precisely what the GDPR requires when it comes to particularly sensitive data – and political opinion is explicitly part of this specially protected category.
The Supreme Administrative Court confirmed the GDPR violations and, in the course of proceedings, reduced the penalty to 13 million euros. The proceedings dragged on for seven years – an indication of how protracted and laborious such disputes can be once a data protection breach has been established.
To understand why this case is so serious, it's worth taking a closer look at two central concepts.
Profiling refers to the automated processing of personal data in order to evaluate or predict certain characteristics of a person – such as their buying behaviour, their interests or, in this case, their political leanings. From existing information, Post deduced which party a person might prefer. That is a textbook example of profiling.
The GDPR distinguishes between "normal" personal data (such as name and address) and particularly sensitive data. These specially protected categories include, among others, information about health, ethnic origin, religious beliefs – and political opinion. Stricter rules apply to this data. As a general rule, it may only be processed if the person concerned has given their explicit consent or if another narrowly defined statutory exemption applies.
The decisive point in the Post case: it makes no difference that the political affinity was merely estimated. Even a calculated probability regarding a person's political leanings falls under this specially protected category. Anyone who generates, uses and passes on such data without explicit consent is in breach of the GDPR.
In this specific case, around 2.2 million Austrians are affected, whose estimated political leanings were processed without consent. That is the immediate dimension of the case.
For you as an entrepreneur, however, the overarching message is more important: Affected in the broader sense is every company that processes personal data and derives profiles or target groups from it. This includes, for example:
The GDPR applies across the EU. What applies to Austrian Post applies in exactly the same way to a company in Germany. The case comes from Austria, but the legal basis is the same European regulation that is binding for you too.
Even if you don't process political data, the fundamental question is: are you processing personal data in a way for which you don't have a sufficient legal basis? Work through the following points to find out:
Use this case as an occasion to critically review your own data processing. The following steps will help you significantly reduce your risk:
The Post case makes several things unmistakably clear.
First: Data protection violations don't simply fade away in the day-to-day. The processing that was challenged took place between May 2018 and February 2019 – the legally binding verdict came years later. Anyone who is careless with data today can still be held accountable long afterwards. The proceedings dragged on for seven years.
Second: The size of the penalty shows that authorities and courts take GDPR violations seriously. 13 million euros is not a symbolic amount, but a signal. The GDPR provides for fines of up to 20 million euros or 4 percent of global annual turnover – whichever is higher. Even for smaller companies, fines can be painfully high and, in the worst case, threaten their very existence.
Third: Particularly sensitive data – such as political opinion – enjoys stricter protection. Anyone who processes, derives or estimates such data is moving into legally particularly delicate territory. And as the case shows: even a mere probability estimate is enough to fall within the scope of these strict rules.
Fourth: Sharing data with third parties without consent is one of the biggest risks. If you share, sell or combine customer data with external service providers for marketing purposes, you should carefully examine each of these practices.
The Austrian Post case is a lesson in data protection. A large company exploited and passed on the political affinity of 2.2 million people without explicit consent – and, after a seven-year legal battle, is paying 13 million euros for it. The message for small and medium-sized businesses is unambiguous: it's not about the size of the company, but about compliance with the rules.
So check now whether your own data processing rests on solid foundations. For every data category, ask yourself: do I have a clear legal basis? For sensitive data: is there explicit, demonstrable consent? And for every instance of sharing with third parties: am I even allowed to do this? Anyone who answers these questions honestly and closes any gaps not only protects their customers' data, but also their own company from expensive and drawn-out proceedings.
Data protection is not a one-off project, but an ongoing task. The Post case shows that carelessness can come back to haunt you – even years later. Better to invest in clean processes today than to risk a fine tomorrow.