Austrian Post: €13M GDPR Fine for Political Profiling Data

Short & clear answers
Frequently asked questions about this incident
Am I affected by this ruling as a small website operator?
Yes, indirectly. The GDPR applies EU-wide to every company that processes personal data, regardless of size. The Austrian Post case shows that the same rules are binding for a small business in Germany as soon as you collect, analyse or share customer data.
What exactly should I do now to avoid a fine?
Take stock of all the data you process and clarify the legal basis for each category. Update your record of processing activities, revise your privacy policy, and stop any data sharing with third parties that lacks a solid legal basis. If in doubt, consult a data protection officer or specialised advisor.
Why was the Post's behaviour illegal in the first place?
The Post calculated the estimated political affinity of around 2.2 million people, used it commercially and shared it with third parties – without the individuals' explicit consent. Political opinion is one of the GDPR's special categories of sensitive data, which may generally only be processed with explicit consent. It makes no difference that the political affinity was merely estimated rather than directly collected.
Does it count as a violation if I only infer interests from purchase behaviour?
This can be a risk. Such inferences are profiling – the automated evaluation of personal characteristics. If you use them to build target groups or profiles, you need a legal basis and must inform the individuals transparently. If the inferred data is sensitive, explicit consent is usually required.
How high can a fine be and how long can such proceedings last?
In the Austrian Post case, a fine of 13 million euros was upheld as final. The proceedings dragged on for seven years, showing how lengthy and costly such disputes can be. Even large companies with their own legal departments can fail to comply with the GDPR rules.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.