DSB · 2025-1.049.138
The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients.
As part of this process, applicants (data subjects) were contacted and interviewed by telephone. A former employee of the controller was examined as a witness by the Austrian DPA (DSB) and provided evidence concerning the recordings. The telephone interviews generally followed a particular pattern. The employees contacted data subjects in the name of the relevant client, stated that their application appeared interesting, presented the position, asked about their qualifications and professional experience and, where appropriate, arranged an in-person interview. The calls were recorded from beginning to end and stored for an indefinite period. In some cases, data subjects were not informed that the call was being recorded. In other cases, the employee asked during the call whether recording would be acceptable. In one such call, the data subject responded, “Uh, yeah.” Moreover, a superior employee had encouraged other employees through an intranet message to record and store interviews for training purposes, including without obtaining the data subject's consent. The controller argued that it had been unaware of the recording practice. It submitted that the employee who had instructed the others to make the recordings was neither a managing director nor an authorised signatory and had no authority to issue such instructions. According to the controller, the statement that interviews could be recorded “even without consent” resulted from personal overzealousness and legal recklessness and did not reflect the controller’s internal procedures. As legal bases for the processing, the controller stated that it relied on consent under Article 6(1)(a) GDPR and legitimate interests under Article 6(1)(f) GDPR. It claimed that data subjects had been expressly asked for consent at the beginning of the application process and that the recordings served the legitimate interest of improving employee performance. Holding — The DPA relied on the CJEU’s judgment in Case C-807/21 (Deutsche Wohnen) and held that a legal entity may be liable not only for infringements committed by its representatives, managers or executives, but also for infringements committed by any person acting within the scope of its business activities and on its behalf. It acknowledged that an exception may apply where an employee acts outside that framework and exclusively for personal purposes. The DPA determined that the supervising employee had ordered the processing within the scope of their employment relationship and in the controller’s interest. It pointed out that the controller could therefore not avoid responsibility by claiming that it had been unaware of the practice or that the employee lacked formal authority to issue instructions. The DPA held that no consent had been obtained in some cases and that, where consent had been sought, it was neither timely nor valid. It stated that consent must be obtained before processing begins. However, it noted that the recordings had already been activated before the calls began, due to the fact that the recordings included the opening greetings. It held that asking for consent during the recorded call was too late. The DPA further held that one data subject’s response, “Uh, yeah,” did not constitute an unambiguous affirmative act. It also considered that a job interview, similarly to an existing employment relationship, is characterised by a structural imbalance of power. Moreover, it emphasised that the data subjects had not been informed of the true identity of the controller, because its employees presented themselves as acting for the client companies. It concluded that the data subject could therefore not have given valid consent and that processing could not be based on Article 6(1)(a) GDPR. Furthermore, the DPA examined whether the recordings could be justified by legitimate interests. It underlined that a controller relying on Article 6(1)(f) GDPR must comply with the corresponding transparency obligations. Specifically, pursuant to Article 13(1)(d) GDPR, the legitimate interests pursued must be communicated when the personal data is collected. Referring to Case C-394/23 (Mousse) the DPA held that the collection could not be based on Article 6(1)(f) GDPR where that information had not been provided in time. It found that the data subjects had either not been informed at all of the legitimate interest pursued or had been informed only after the collection of their personal data had begun. It held accordingly that the processing could not be based on Article 6(1)(f) GDPR. The DPA concluded that the recording and storage of the interviews lacked a legal basis and infringed Article 6(1) GDPR in conjunction with Article 5(1)(a) GDPR. In addition, the DPA held that the recordings were not necessary for the training purpose as less intrusive alternatives, such as simulated interviews between employees, could have achieved the same objective. It therefore found a violation of the principle of data minimisation under Article 5(1)(c) GDPR. It further found that the indefinite retention of the recordings was also unnecessary and violated the principle of storage limitation under Article 5(1)(e) GDPR. The DPA also found that the controller had failed to comply with its transparency obligations. In some cases, data subjects received no information about the processing. In others, information was provided only after the processing had begun. The data subjects were also not informed of the identity of the actual controller, because the employees presented themselves as representatives of the client companies. It therefore found an infringement of Article 5(1)(a) GDPR in conjunction with Article 12 GDPR and Article 13 GDPR. The DPA found that the controller had acted at least negligently. It imposed a fine of €25,500 for the infringements.
How it connects
Related across sources
Full text 12 findings
The following facts relevant to the decision have been established based on the evidentiary proceedings conducted:
The defendant is a limited liability company with its registered office at K***platz *5/*4/a, in **** Z***bach (hereinafter “scene of the offense”) and operates an advertising agency. The defendant’s line of business is “digital marketing.” In the 2024 fiscal year, the defendant classified itself as “small” for the purposes of its annual financial statements and employed an average of seven employees during that fiscal year. In the 2024 fiscal year, the defendant had retained earnings of EUR 1,459,067.97 and liabilities totaling EUR 109,810.32.
Employees of the defendant were tasked with pre-screening potential applicants for clients. As part of this process, potential applicants were called and interviewed. The phone calls last an average of five minutes and follow this pattern: Contact is made on behalf of “Company XY,” and the applicant is informed that their application has been deemed interesting and that the company would like to schedule an interview. During the subsequent conversation, the employee first introduces the enterprise and explains the advertised position. Potentially problematic aspects of the job are also addressed, such as shift work or weekend work. The employee then gets to know the applicant better, asks about their professional experience to date, and, if appropriate, schedules an in-person job interview.
From August 1, 2025, through at least November 27, 2025 (hereinafter the “Relevant Period”), the interviews with the applicants (hereinafter the “Data Subjects”) —sometimes with, sometimes without a notice regarding the recording—from start to finish and stored for an indefinite period. In this regard, employees were actively encouraged by a supervisor via an intranet announcement to record and store job interviews for training purposes, even without obtaining the consent of the data subjects. Conversations without any notice that they were being recorded took place as follows, for example (verbatim transcript of the audio recording of the conversation provided by the Data Protection Authority): “Applicant: Hello? Employee: Hello, this is Karin from Tiefkühlkost U***. You applied to us for the sales driver position. Applicant: Oh, right, hello. Employee: Yes, exactly. Do you have five minutes? Applicant: Yes, sure, yes. Employee: Perfect, great, thank you! First of all, thank you very much for your application. I’ve taken a look at all your information, and I think you’d be a great fit for us. Applicant: Okay. Employee: We offer additional financial benefits, a wide range of career advancement opportunities, and above-average pay.” Applicant: Okay. Yes. Employee: The most important question for this job is whether you have a Class B driver’s license. Applicant: Yes, I do. Employee: Perfect, great. So, what are you doing right now? Are you in this field as well? Applicant: I’m unemployed. So I’m not really doing anything at the moment. Employee: Sorry, I didn’t catch that. Applicant: Sorry, it might be my internet connection here—I’m currently looking for work. Employee: Yeah, okay, that’s perfectly fine. Applicant: Exactly. Employee: Why exactly do you want to work for us, at Tiefkühlkost U***? Applicant: Because I like it, and I wanted to try something new in my life—and this is exactly what was suggested to me. And yes, I’d like to check it out and see what’s new in my life. Employee: Okay. Let me briefly explain what your work routine will be like. So, you’ll drive to the distribution center, load your van with the merchandise, drive to the customers, and deliver what they’ve ordered—and you’ll also have the opportunity to sell products. Does that sound like something you’d be comfortable with? Applicant: All right, sure. Employee: Do you have any sales experience? Applicant: Yes, I do. I’m actually a trained chef, so I’m good with people. Employee: Yes, very good. Applicant: Exactly, yes. Employee: What was your last job? Applicant: I know this is something completely different, but I worked at G***stahl, here in L***dorf, as a blacksmith. Employee: At G***stahl as what? Applicant: Exactly, as a blacksmith. Hammer smith. Employee: As a blacksmith? Applicant: Yes, exactly. Employee: Oh, okay, cool. How long were you there? Applicant: Oh, I was there for two years. Recruiter: Two years—okay, great. Good. Applicant: But I’d also like to find a job that I can keep long-term. Recruiter: Yeah. That would be ideal for us anyway. Great. Let’s see what we can do. So, you’re Ulrich P***—did I get that right? Applicant: P***. Yeah, that’s right. Employee: Ulrich P***118@gmail.com? Applicant: Exactly, yeah. Employee: That fits perfectly—I’ll write all that down. Then we’ll set up the interview right away. Applicant: Yeah, sure. Employee: Great. So… I’m just checking the calendar. Applicant: Yeah, no problem. Employee: Good. How about this Thursday, August 21… Applicant: Yeah, I’m free then, yes. Staff Member: Shall we do it at 4:00 p.m.? Applicant: Yeah, that works. Staff Member: Perfect. Applicant: And where exactly would I need to go? Staff Member: It’s on-site. Applicant: Yeah. Staff Member: Yeah, give me a second—I’ll look it up for you right away. It’s in D***bergtal, but I’ll check the exact address for you in a moment… because I handle calls for different locations, that’s why. Applicant: Ah, okay, got it—I know my way around there. Employee: All right, here it is: Im Gewerbepark *34, **** D***bergbach. Applicant: Exactly, yes. Employee: Exactly. Applicant: All right. Employee: And everything else will be discussed with branch management. Exactly. Great, then I’ll just jot everything down, and thank you very much for the conversation. Applicant: Thank you, likewise. Employee: Yeah, thank you. Applicant: Thanks. Employee: Great. Thanks, bye.” Conversations that included a notice that the call was being recorded went as follows, for example (verbatim transcript of the audio recording of the conversation provided by the Data Protection Authority): “Employee: Hi there. This is Mike from K*** Office. You applied to us for the position of junior technical project developer. Applicant: Yes. Employee: Right, I was wondering if you have a moment to talk. Applicant: Sure, sure, I have time. Employee: Great. Could I ask you something real quick? Um… we’re currently conducting internal training, and to help our HR department run more smoothly, uh… we’d like to record this conversation—just for our internal use, of course, not for anyone else. Would that be okay with you? Applicant: Uh, yeah. Employee: All right, thank you very much. The thing is—and first of all, thank you for applying with us. Um, here’s the situation: we’re looking for a junior technical project developer, and so you can get a better idea of what that entails, I’d like to explain it to you in a bit more detail. Essentially, we’re looking for someone to manage and coordinate external service providers—that is, architects, specialist planners, and government agencies. We also need someone who can actively participate in contract negotiations and coordination with the planners and contractors—someone who can really put themselves in their shoes. Then, of course, there’s the creation of technical concepts, presentations, and decision-making documents for our investors and/or internal stakeholders, as well as surveillance of project implementation—from obtaining building permits all the way through to completion, actually. Exactly. Now I wanted to ask you—does that sound like a good fit for you so far? Applicant: Yes. Yes, I… it sounds good; I’d like to, um, of course, take advantage of this opportunity. Employee: Okay. Then I have a few questions for you. I’m going to ask you a few questions, and you’ll just answer them briefly and to the point—and if I want to know a little more, I’ll follow up anyway. Okay? Applicant: Okay. Employee: Great, perfect. What did you study, or rather, what’s your educational background? Applicant: Well, mostly—I studied architecture. Employee: Okay. Bachelor’s or master’s? Applicant: Um, both. Employee: Ah, okay. So what was your master’s in? What was your focus there? Applicant: Well, my master’s was… uh… it was more about structural engineering. I studied at […] and, yeah, overall it was about, well, structural engineering and a bit of interior design. Employee: Hmm. Okay. Um, so here’s the thing, um… What kind of experience do you actually have in project development? What did you do there? Applicant: Well, I think this might be interesting for you… I used to work in Russia. I basically worked up to level five. Employee: So, okay, you worked on levels one through five. Hmm. Applicant: Yes. That’s right. It was very similar to what happens in Germany—everything in the construction phase. I did that and was involved in it there, and here in Berlin. I’m currently working at M***, and at the start of my career at M***, I—I think I worked on phases one through five. Employee: So phases one through five. Meaning LP phases one through five? Hmm. Applicant: Yes. So at the beginning, phases three through five—and that involved […] making coffee or… Employee: Hmm. Yeah, I see. I see. Hmm. Did you actually… let me just follow up on that… did you actually, uh… Experience in real estate, or—let me put it this way—experience related to development in project coordination? Applicant: Not exactly. But I did have some experience about ten years ago; I worked with architects on an interior design project. Staff Member: Okay. Applicant: It was very… um… Yes. Employee: Okay, I see. Hmm. Okay. Um. Yes. Okay. Um. If I may just follow up briefly. I’m afraid I have to turn you down. We’re actually looking for someone with a bit more experience in real estate and development-related project coordination. Um. I hope you have a nice day anyway. Applicant: Thanks. Employee: Sure, have a nice day, bye. Applicant: Bye.”
The findings are based on the following assessment of the evidence:
The findings regarding the legal form of the defendant in Section 1.1 result from an ex officio query of the Commercial Register under FN *9*36*u and a review of the defendant’s 2024 annual financial statements, as well as an official query of the Austrian Business Information System (GISA) under GISA number *5*6*88*0.
The findings regarding Section 1.2 are based on the questioning of a former employee of the defendant, which took place on October 30, 2025 (see pages 3 and 5 of the transcript of the examination of witness Michael T*** dated October 30, 2025; Ref. No. D550.1231; 2025-0.853.318). The transcript was attached to the request for a statement of defense dated November 25, 2025 (Ref. No.: D550.1231; 2025-0.853.318) and was not disputed by the defendant on these points.
The fact that the telephone job interviews referred to in section 1.3 were recorded was acknowledged by the accused in her written defense dated December 18, 2025. The Data Protection Authority determines the start of the period in question based on the witness examination that took place on October 30, 2025 (see page 6 of the transcript of the examination of witness Michael T*** dated October 30, 2025; Ref. No. D550.1231; 2025-0.853.318). The end of the period of the offense is based on the fact that the request for justification dated November 25, 2025 (Ref. No.: D550.1231; 2025-0.853.318) was acknowledged by the accused on November 27, 2025, and that, as part of her defense submitted on December 18, 2025, she stated that she had ceased recording and conducting storage of the job interviews after receiving the letter from the Data Protection Authority. The findings regarding the order to record, as well as the reference to it, are based on the witness examination that took place on October 30, 2025 (see pages 3 and 5 of the transcript of the examination of witness Michael T*** dated October 30,October 2025; Ref. No. D550.1231; 2025-0.853.318) as well as the defendant’s statement of December 18,December 2025, in which she acknowledged that she had been granted the option to record job interviews for the purpose of personal improvement and explained that the employee’s statement—which was not further questioned and was made out of legal negligence—regarding the recording of any “record conversations even without consent” was clearly based on personal overzealousness, although she demonstrably pursued the goal of supporting colleagues in their professional development and improving their work processes. The transcripts of the conversations recorded via audio are based on one audio file submitted by the witness and one submitted by the defendant. The finding that the recordings were stored for an indefinite period is based, on the one hand, on the witness examination (see page 5 of the transcript of the examination of witness Michael T*** dated October 30, 2025; Ref. No. D550.1231; 2025-0.853.318) and, on the other hand, from the fact that the defendant submitted an audio recording dating from a period when the former employee was still employed by the defendant. Several months had passed between the termination of the employment relationship and the submission of the audio recording, and the defendant could not possibly have known at the time of the termination of the employment relationship on August 25, 2025, that the present proceedings would be initiated, since she only became aware of this circumstance on November 27, 2025, upon service of the request for an explanation dated November 25, 2025 (Ref. No.: D550.1231; 2025-0.853.318) on November 27, 2025. Against this background, the defendant’s assertion in her defense of December 18, 2025—that the recordings are stored for only a few days—can be regarded as a mere defensive claim.
Legally, this leads to the following conclusions:
Regarding the objective elements of the offense Regarding Point I (Roman numeral one) In this case, as established, employees of the defendant recorded and stored the content of job interviews at the scene of the offense during the relevant time period, thereby processing personal data of the data subjects pursuant to Art. 4(1) of the GDPR (including, among others, the following categories: name, contact information, work experience, education). As established, employees of the defendant recorded and stored the content of job interviews at the scene of the offense during the relevant time period, thereby processing the personal data of the data subjects in accordance with Article 4(1) of the GDPR (including, among others, the following categories: name, contact information, work experience, education) is processed. Insofar as the defendant argues that she was unaware of the practice of recording job interviews, and further asserts that although the employee who ordered the recordings was her superior in the organizational hierarchy, she was neither the managing director nor an authorized signatory and, moreover, had no authority to issue instructions—thereby suggesting that responsibility had been transferred—this account is based on an incorrect legal assessment. Nor does the defendant’s argument—that the statement made by the employee to the defendant, namely that interviews could be recorded “even without consent,” was merely an expression of personal overzealousness and legal recklessness and cannot be attributed to internal procedures or structures—exonerate the defendant. This is because, under Article 83 of the GDPR, the enterprise is liable for data protection violations committed by its employees, unless they acted in excess of their authority and exclusively for their own purposes. Such an act exceeding the scope of authority has neither been demonstrated nor is it apparent in the present case, so the defendant cannot absolve herself of liability. A case where an individual employee would be held liable would arise, for example, if the employer’s data records were used for private purposes (see the ruling of the Federal Administrative Court [BVwG] dated March 26, 2024; W137 2241630-1). This can be ruled out even upon a cursory examination of the data processing at issue in these proceedings. The supervising employee ordered the data processing within the scope of her employment relationship in the interest of the accused. This is because, under article 83 of the GDPR, the enterprise is liable for data protection violations committed by its employees, unless they acted beyond the scope of their authority and exclusively for their own purposes. Such an act exceeding the scope of authority has neither been demonstrated nor is it apparent in the present case, so the defendant cannot absolve herself of liability. A case of liability on the part of an individual employee would, for example, exist if the employer’s data records were used to pursue private purposes; see, for example, the ruling of the Federal Administrative Court (BVwG) dated March 26, 2024; W137 2241630-1). This can be ruled out even upon a cursory examination of the data processing at issue in these proceedings. The supervising employee ordered the data processing within the scope of her employment relationship in the interest of the accused. With regard to legal entities, this means that they are liable not only for violations committed by their representatives, managers, or executives, but also for violations committed by any other person acting within the scope of the business activities and on behalf of these legal entities (see CJEU decision of Dec. 5, 2023, in Case C-807/21). With regard to legal entities, this means that they are liable not only for violations committed by their representatives, managers, or executives, but also for violations committed by any other person acting within the scope of the business activities and on behalf of these legal entities (see CJEU, December 5, 2023, in Case C-807/21). The defendant is therefore the controller pursuant to Article 4(7) of the GDPR. The defendant is therefore the controller pursuant to Article 4(7) of the GDPR. According to the established case law of the CJEU, in order for data processing to be lawful within the meaning of the GDPR, comply with all the principles set forth in Article 5(1) of the GDPR and, in addition, must be based on at least one of the grounds or legal bases specified in Article 6(1) of the GDPR (see, for example, the CJEU judgment of May 4, 2023, C-60/22, paras. 56 and 57, and CJEU, Dec. 21, 2023, C-667/21, para. 78).According to the established case law of the CJEU, in order for data processing to be lawful within the meaning of the GDPR, it must comply with all the principles set forth in Article 5(1) of the GDPR and, in addition, must be based on at least one of the grounds or legal bases set forth in Article 6(1) GDPR (see, e.g., CJEU judgment of May 4, 2023, C-60/22, paras. 56 and 57, and CJEU judgment of December 21, 2023, C-667/21, para. 78). With regard to the legal basis, the defendant invoked both consent within the meaning of Article 6(1)(a) of the GDPR and legitimate interests under Article 6(1)(f) of the GDPR. The defendant did not invoke the remaining legal bases under Article 6(1) of the GDPR, and these are not relevant in the present case even after an ex officio review (see also the Administrative Court decision of February 8, 2022, Ro 2021/04/0033, regarding the examination of grounds for justification).With regard to the legal basis, the defendant invoked both consent within the meaning of Article 6(1)(a) of the GDPR and legitimate interests under Article 6(1)(f) of the GDPR. The remaining legal bases under Article 6(1) GDPR were not raised by the defendant and, even after an ex officio review, are not relevant in the present case; see also, regarding the examination of the grounds for justification, the Administrative Court (VwGH) decision of February 8, 2022, Ro 2021/04/0033). First, it must be determined whether the data processing—in those cases where a notice was provided or, in the defendant’s view, consent was obtained—is based on consent; for depending on whether consent actually exists, the defendant may only, in cases where consent is in fact absent that the data controller may subsequently rely on legitimate interests pursuant to Art. 6(1)(f) of the GDPR (see also the decision dated July 30, 2020, Ref. No.: D213.983; 2020-0.465.771). However, this does not apply in cases where consent was initially deemed to exist but subsequently proves to be invalid.First, it must be determined whether the data processing—in those cases where a notice was provided or, in the opinion of the accused, consent was obtained—is based on consent, because, depending on whether consent actually exists, the accused may only subsequently rely on legitimate interests pursuant to article 6, paragraph 1, letter f, of the GDPR; see also the decision of July 30, 2020, Ref. No.: D213.983; 2020-0.465.771). However, this does not apply in cases where consent was initially given but subsequently proves to be invalid. a) Processing Based on Consent Article 4(11) of the GDPR defines consent as “any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.”Article 4(11) of the GDPR defines consent as “any freely given, specific, informed, and unambiguous indication of the data subject’s wishes, by a statement or by a clear affirmative action, indicating that the data subject consents to the processing of personal data relating to him or her.” The data subject’s consent must be obtained prior to the controller’s commencement of processing the personal data (see Kastelitz in Knyrim, DatKomm Art. 7 GDPR, para. 16).The data subject’s consent must be obtained prior to the start of the processing of personal data by the controller (see Kastelitz in Knyrim, DatKomm article 7, GDPR, para. 16). Given that the audio recordings were started before the conversation began—which is evident from the greeting at the start of the recordings—it is effectively impossible to obtain consent under data protection law before processing begins. Although the defendant claims to have expressly sought the consent of the data subjects at the beginning of the application process, she overlooks the fact that the processing began at the start of the data collection—that is, when the recording was activated—and that obtaining consent at the time in question would have been too late. Even if the defendant assumes that consent was given in a timely manner, it would not have been validly given. Valid consent requires an unambiguous affirmative act, which is not present here. An “Um, yes,” which was uttered during a job interview more as a cautious clarification, does not meet these requirements. Furthermore, the job interview—similar to an existing employment relationship—is characterized by a structural power imbalance, meaning that the required voluntariness is regularly lacking (see EDPB Guidelines 5/2020, para. 13 et seq.). Even if the defendant assumes that consent was given in a timely manner, it would not have been validly given. Valid consent requires an unambiguous affirmative act, which is not present here. An “Um, yes,” which was uttered during a job interview more as a cautious clarification, does not meet these requirements. Furthermore, the job interview—similar to an existing employment relationship—is characterized by a structural power imbalance, so that the required voluntariness is regularly lacking (see the EDPB’s Guidelines 5 of 2020, para. 13 et seq.). Furthermore, the validity of consent depends, among other things, on whether the data subjects have previously received information about all circumstances related to the processing of the data in question, enabling them to give consent with full knowledge of the facts (see CJEU decision of September 4, 2025, C-413/23p, para. 106). This is certainly not the case if the data subject cannot even identify the controller, especially since the employees’ calls were made in such a way that they posed as representatives of “Company XY.” Thus, no information regarding the true controller was provided (see point II for further details in this regard).Furthermore, the validity of consent depends, among other things, on whether the data subject has previously received information about all circumstances related to the processing of the data in question, enabling them to give consent with full knowledge of the facts (see CJEU, September 4, 2025, C-413/23p, para. 106). This is certainly not the case when the data subject cannot identify the controller at all, especially since the employees’ calls were made in such a way that they presented themselves as representing “Company XY.” Thus, no information regarding the true controller was provided (see point 2 for further details in this regard). Consequently, the justification under Article 6(1)(a) of the GDPR is ruled out, and the next step is to examine whether the processing of personal data is covered by legitimate interests pursuant to Article 6(1)(f) of the GDPR.Consequently, the justification under Article 6, paragraph 1, subparagraph a, of the GDPR is ruled out, and the next step is to examine whether the processing of personal data is covered by legitimate interests pursuant to Article 6, paragraph 1, subparagraph f, of the GDPR. Processing Based on Legitimate Interests Article 6(1)(f) of the GDPR permits the processing of personal data in “relationships of equal standing” between private parties if it is necessary to safeguard the legitimate interests of a controller or a third party (see Article 4(10) of the GDPR). However, these legitimate interests do not, in and of themselves, constitute sufficient grounds for the lawfulness of the processing if the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, prevail.Article 6(1)(f) of the GDPR permits the processing of personal data in “relationships of equal standing” between private individuals if it is necessary to safeguard the legitimate interests of a controller or a third party (see Article 4(10) of the GDPR). However, these legitimate interests do not, in and of themselves, constitute sufficient grounds for the lawfulness of the processing if the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, prevail. The CJEU has established a “test framework” for the predecessor provision (Art. 7(f) of the Data Protection Directive), which is largely consistent in substance, according to which the processing of personal data is permissible under three cumulative conditions, a framework that is also applied by the Data Protection Authority, the Administrative Court, and the Supreme Court in their case law (see CJEU, Dec. 11, 2019, Case C-708/18, para. 36 with further references; see also, most recently, CJEU, Nov. 9, 2025, C-394/23, para. 64): With regard to the predecessor provision, which was largely consistent in substance (article 7(f) of the Data Protection Directive), , a “test framework” under which the processing of personal data is permissible if three cumulative conditions are met; this framework is also applied by the Data Protection Authority, the Administrative Court, and the Supreme Court in their case law; see CJEU, Dec. 11, 2019, Case C-708/18, para. 36 with further references; see also, most recently, CJEU, November 9, 2025, Case C-394/23, para. 64): (i) The existence and communication of a legitimate interest; (ii) The necessity of the processing; and (iii) The rights and freedoms of others are not overridden. Regarding point (i): Existence and Communication of the Legitimate Interest In the absence of a definition of the term “legitimate interest” in the GDPR, a broad spectrum of interests may, in principle, be considered legitimate (see CJEU, Nov. 9, 2025, C-394/23, para. 46); Recitals 47 et seq. contain some examples. Article 9(2) of the GDPR also lists legitimate interests in certain contexts, which, by extension, may also justify the processing of non-sensitive data. Of particular note is Article 9(2)(f) of the GDPR cited above (“processing is necessary for the establishment, exercise, or defense of legal claims or for proceedings before Courts in the course of their judicial functions”) (see Kastelitz/Hötzendorfer/Tschohl in Knyrim, DatKomm Art. 6 GDPR, para. 54).In the absence of a definition of the term “legitimate interest” in the GDPR, a broad spectrum of interests may, in principle, be considered legitimate; see CJEU, Nov. 9, 2025, C-394/23, para. 46); Recitals 47 et seq. contain several examples. Article 9(2) of the GDPR also lists legitimate interests in certain contexts, which, by extension, may also justify the processing of non-sensitive data. Of particular note is article 9(2)(f), paragraph 3, loc. cit. (“processing is necessary for the establishment, exercise, or defense of legal claims, or for actions by Courts in the course of their judicial activities”) (see Kastelitz/Hötzendorfer/Tschohl in Knyrim, DatKomm article 6, GDPR, para. 54). Furthermore, it should be noted that controllers must comply with corresponding transparency obligations when processing personal data on the basis of legitimate interests (see European Data Protection Board, Guidelines 1/2024 on the processing of personal data based on Article 6(1)(f) of the GDPR, Version 1.0, para. 64 et seq., available at “https://www.edpb.europa.eu/system/files/202410/edpb_guidelines_202401_legitimateinterest_en.pdf”). Specifically, pursuant to Article 13(1)(d) of the GDPR, the controller is required to inform a data subject, at the time personal data is collected from the data subject, of the legitimate interests being pursued (see Section II for further details in this regard), if such processing is based on Article 6(1)(f) of the GDPR (see CJEU, Nov. 9, 2025, C-394/23, para. 46); otherwise, the collection of personal data cannot be based on Article 6(1)(f) of the GDPR (see CJEU, Nov. 9, 2025, C-394/23, para. 52; see also Federal Administrative Court decision of June 11, 2025, Case No.: W211 2308914-1/9E).Furthermore, it should be noted that controllers must comply with corresponding transparency obligations when processing personal data on the basis of legitimate interests; see European Data Protection Board, Guidelines 1 of 2024, on the processing of personal data based on Article 6(1)(f) of the GDPR, Version 1.0, para. 64 et seq., available at “https://www.edpb.europa.eu/system/files/202410/edpb_guidelines_202401_legitimateinterest_en.pdf”). Specifically, pursuant to Article 13(1)(d) of the GDPR, the controller is required to inform a data subject, at the time personal data is collected from the data subject, of the legitimate interests being pursued (see point 2 for further details in this regard), if such processing is based on Article 6(1)(f) of the GDPR; see CJEU, Nov. 9, 2025, C-394/23, para. 46); otherwise, the collection of personal data cannot be based on Article 6(1)(f) of the GDPR—see CJEU, Nov. 9, 2025, C-394/23, para. 52; see also Federal Administrative Court decision of June 11, 2025, Ref. No.: W211 2308914-1/9E). The defendant states that the processing serves to improve the employees. The improvement of employees generally constitutes a legitimate interest. However, as can be seen from the findings, the data subjects were either not informed at all about the legitimate interests, or were informed only after the collection of their personal data had begun. Although this renders further examination unnecessary—since the processing cannot be based on Art. 6(1)(f) of the GDPR—for the sake of completeness, it is set forth below that the lawfulness of the processing also fails to meet the criterion of necessity and the principle of data minimisation pursuant to Article 5(1)(c) of the GDPR.However, as can be seen from the findings, the data subjects were either not informed at all or were informed only after the collection of their personal data had begun regarding the legitimate interests. Although this renders further examination unnecessary—since the processing cannot be based on Article 6, paragraph 1, (f) of the GDPR—for the sake of completeness, it is set forth below that the lawfulness of the processing also fails to meet the criterion of necessity and the principle of data minimisation pursuant to article 5(1)(c) of the GDPR. Regarding Point ii) Necessity When assessing what is “necessary,” it must be examined whether the legitimate interests pursued by the data processing cannot be achieved just as effectively in practice by other means that are less restrictive of the data subject’s fundamental rights and freedoms. Thus, with regard to the necessity of processing, the CJEU has already held on several occasions that exceptions and restrictions relating to the protection of personal data must be limited to what is absolutely necessary (see the CJEU judgement of May 4, 2017, C-13/16, as well as those of November 9, 2010, C-92/09 and C-93/09). The criterion of necessity is closely linked to the principle of data minimisation under Article 5(1)(c) of the GDPR (see CJEU judgment of December 11, 2019, C-708/18, para. 48).When assessing what is “necessary,” it must be examined whether the legitimate interests pursued by the data processing cannot be achieved just as effectively in practice by other means that are less restrictive of the data subject’s fundamental rights and freedoms. In this regard, the CJEU has already held on several occasions with respect to the necessity of processing that the exceptions and restrictions relating to the protection of personal data must be limited to what is absolutely necessary (see the CJEU judgement of May 4, 2017, C-13/16, as well as those of November 9, 2010, C-92/09 and C-93/09). The criterion of necessity is closely linked to the principle of data minimisation under article 5(1)(c) of the GDPR (see the CJEU judgment of December 11, 2019, C-708/18, para. 48). In any case, the processing in question, as carried out, was not necessary to achieve the purpose; rather, there are less intrusive alternatives for the purposes pursued, such as simulated conversations with colleagues. Furthermore, a storage period that is not clearly defined in terms of duration is by no means necessary and violates the principle of storage limitation pursuant to para 5(1)(e) of the GDPR.In any case, the processing in question was not necessary in the form in which it was carried out to achieve the intended purpose; rather, there are less intrusive alternatives for the purposes pursued, such as simulated conversations with colleagues. Furthermore, a retention period without a clearly defined time limit is by no means necessary and violates the principle of storage limitation pursuant to article 5(1)(e) of the GDPR. Consequently, the legal basis invoked by the defendant under Article 6(1)(f) of the GDPR is also not applicable.Consequently, the legal basis cited by the defendant under article 6(1)(f) of the GDPR is also not applicable. In conclusion, the processing operations (1 and 2) were therefore unlawful. Thus, the objective elements of a violation of the principles of processing pursuant to Article 5(1)(a), (c), and (e) in conjunction with Article 6(1) of the GDPR are fulfilled. Consequently, the processing operations (1 and 2) were therefore unlawful. Thus, the objective elements of a violation of the principles of processing pursuant to Article 5(1)(a), (c), and (e) in conjunction with Article 6(1) of the GDPR are fulfilled. Regarding Point II Regarding Point II Article 5(1)(a) of the GDPR provides that personal data must be processed lawfully, fairly, and in a manner that is transparent to the data subject (“principle of lawfulness, fairness, and transparency”). In the GDPR, the principle of transparency is specified in Articles 13 and 14 GDPR regarding the obligation to provide information, as well as in Article 12 GDPR regarding the relevant procedures. Article 5, paragraph 1, subparagraph (a) of the GDPR stipulates that personal data must be processed lawfully, fairly, and in a manner that is transparent to the data subject (“principle of lawfulness, fairness, and transparency”). In the GDPR, the principle of transparency is specified in articles 13 and 14 regarding the obligation to provide information, as well as in article 12 regarding the relevant procedures. The substance of the principle of transparency can thus be derived from these provisions as well as from Recitals 39 and 58: Data subjects must be able to recognize that personal data is being processed, what data is being processed, for what purposes it is being processed, by whom it is being processed (identity of the controller), and to whom it may be disclosed. In addition, data subjects should be informed about risks, regulations, safeguards, and rights related to the processing, as well as how to exercise these rights. This information must be accurate, easily accessible, and understandable, and must be written in clear and plain language. The importance of transparency in processing—and thus the obligation to provide information—lies particularly in its role as a necessary prerequisite for the exercise of data subject rights: If the data subject is not aware that his or her data is being processed and/or does not know who is carrying out the processing, he or she cannot exercise his or her rights in this regard under Articles 15 through 21 of the GDPR (see Hötzendorfer/Tschohl/Kastelitz in Knyrim, DatKomm Art. 5 GDPR, para. 18 et seq.).The importance of transparency in processing—and thus the duty to provide information—lies in particular in its role as a necessary prerequisite for the exercise of data subject rights: If the data subject is not aware that theirdata is taking place, and/or does not know who is carrying it out, he or she cannot exercise his or her rights in this regard under articles 15 through 21 of the GDPR; see Hötzendorfer/Tschohl/Kastelitz in Knyrim, DatKomm Article 5, GDPR, margin note 18f). Given the volume of information that must be provided to a data subject, a controller may opt for “tiered access” and a combination of means to comply with the transparency requirement. As can be seen from the findings of fact, the defendant in some cases failed entirely to inform the data subjects about the data processing. In other cases—as already explained above—the information was provided only after processing had begun and, moreover, not on behalf of the controller, namely the defendant herself, but on behalf of “Company XY.” The defendant thus violated her obligations to provide information as the controller for the entire relevant period of the offense and thereby fulfilled the objective elements of the offense under Article 5(1)(a) in conjunction with Articles 12 and 13 of the GDPR.The defendant thus violated her information obligations as the controller for the entire relevant period of the offense and thereby fulfilled the objective elements of the offense under Article 5(1)(a) in conjunction with Articles 12 and 13 of the GDPR.
On the subjective element of the offense. Intent or negligence is required for criminal liability under Article 83 of the GDPR. The CJEU has already clarified that fault in the form of negligence exists if the defendant could not have been unaware of the unlawfulness of its conduct, regardless of whether it was aware that it was violating the provisions of the GDPR (see CJEU C-807/21, paras. 68 and 76). For liability under article 83 of the GDPR, intent or negligence is required. The CJEU has already clarified that negligence is established if the accused could not have been unaware of the unlawfulness of their conduct, regardless of whether they were aware that they were violating the provisions of the GDPR (see CJEU C-807/21, paras. 68 and 76). In the present case, the defendant, as the controller, decided that, for the specified purposes, 1) recording of job interviews and 2) the storage of these recordings for the purpose of improving staff performance. The responsibility and liability of a controller extend to any processing of personal data carried out by or on its behalf. In this context, the controller must not only implement appropriate and effective measures but must also be able to demonstrate that its processing activities comply with the GDPR and that the measures it has taken to ensure such compliance are effective (see CJEU C-807/21, para. 38, with reference to Recital 74). In the present case, the defendant, as the controller, decided that, for the stated purposes, 1) recording of job interviews and 2) the storage of these recordings for the purpose of improving staff performance. The responsibility and liability of a controller extend to any processing of personal data carried out by or on its behalf. In this context, the controller must not only take appropriate and effective measures but must also be able to demonstrate that its processing activities comply with the GDPR and that the measures it has taken to ensure such compliance are effective (see CJEU C-807/21, para. 38, with reference to Recital 74). First, it should be noted that, in the course of the preliminary investigation, there was no evidence to suggest that the violations in question were committed by individuals who were not acting within the scope of the business’s activities and on behalf of the legal entity. According to the judgement of the CJEU, whether and which managing director of the defendant or any other person within the organization is responsible for the violations in question is not relevant to the imposition of an administrative fine against a legal entity. Although the defendant claims that it can avoid liability by relying on relevant policies and guidelines, but the fact that the defendant provided its employees with the means to record and perform storage of data—which was effectively possible even without obtaining explicit consent—already constitutes fault amounting to at least slight negligence. Furthermore, an employee who was hierarchically superior to the employees who carried out the actions also publicly promoted this practice on the Internet. The fact that the defendant now claims that such conduct did not, in principle, comply with the prescribed work procedures does not preclude a finding of slight negligence, especially since such working methods were not ruled out in advance and the associated risk also existed with regard to the employees carrying out the work. Consequently, the subjective element of the offense is also satisfied, and fault in the form of negligence is present.
With regard to sentencing, the following should be noted: In this case, the absorption principle under Article 83(3) of the GDPR applies, and a single penalty is imposed for the established violations (Point I and Point II of the ruling) (see VwGH April 30, 2025, Ro 2021/04/0024). In the present case, the absorption principle under article 83, paragraph 3, GDPR applies, and a single aggregate fine is imposed for the identified violations (Point I and Point II of the ruling) (see VwGH April 30, 2025, Ro 2021/04/0024). Pursuant to Article 83(1) of the GDPR, the Data Protection Authority must ensure that the imposition of administrative fines for violations of the provisions of the GDPR subject to sanctions (Article 83(4), 5, and 6 of the GDPR) is effective, proportionate, and dissuasive in each individual case. More specifically, Article 83(2) of the GDPR stipulates that, when making the decision to impose an administrative fine and determining its amount in each individual case, certain criteria must be duly taken into account.Pursuant to Article 83(1) of the GDPR, the Data Protection Authority must ensure that the imposition of administrative fines for violations of the provisions of the GDPR subject to sanctions (Article 83(4), 5, and 6 of the GDPR) is effective, proportionate, and dissuasive in each individual case. Furthermore, article 83(2) of the GDPR stipulates that, when making a decision on whether to impose an administrative fine and determining its amount in each individual case, certain criteria must be duly taken into account. In determining the amount of the fine, the Data Protection Authority applied the EDPB Guidelines on the calculation of administrative fines under the GDPR (see EDPB Guidelines 04/2022 on the calculation of administrative fines under the GDPR, Version 2.1 dated May 24, 2023 —hereinafter “Fines Guidelines”) in determining the penalty.In determining the penalty, the Data Protection Authority applied the EDPB guidelines on the calculation of administrative fines under the GDPR (see EDPB Guidelines 04/2022 on the calculation of administrative fines under the GDPR, Version 2.1 dated May 24, 2023 – hereinafter referred to as the “Fines Guidelines”) were applied. In light of the Fines Guidelines, and taking into account the annual financial statements as of December 31, 2024 (annual financial statements for the year 2025 were not available at the time of the Data Protection Authority’s decision) and with a view to imposing an effective, deterrent, and proportionate administrative fine, is classified in the category “Enterprises with a turnover of EUR 2 million to EUR 10 million.” The penalty range in this specific case, pursuant to Article 83(5) of the GDPR, extends up to an amount of EUR 20,000,000 (static penalty range). The dynamic penalty range (4% of annual turnover) does not apply.The penalty range in this specific case, pursuant to article 83(5) of the GDPR, extends up to an amount of EUR 20,000,000 (static penalty range). The dynamic penalty range (4% of annual turnover) does not apply. In light of the facts assumed to be proven and taking into account the nature, gravity, and duration of the violation, as discussed in detail above (Art. 83(1)(a) GDPR [Editor’s note: obvious editorial error; Art. 83(2)(a) GDPR is intended]); the intentional or negligent nature of the violation (Art. 83(2)(b) GDPR), whereby negligence was assessed as a neutral factor; the categories of personal data affected by the violation (Art. 83(2)(g) GDPR), whereby the fact that no special categories of personal data were affected could only be assessed as neutral; the Data Protection Authority ultimately determines the severity of the violation to be moderate and sets a starting amount of EUR 3,000,000 as the basis for further calculation. In light of the facts deemed proven and taking into account the nature, gravity, and duration of the violation already discussed in detail above (Article 83(1)(a) of the GDPR [Editor’s note: obvious editorial error; article 83(2)(a) of the GDPR is intended]); whether the violation was intentional or negligent (article 83(2)(b) of the GDPR), with negligence being assessed as a neutral factor; the special categories of personal data affected by the violation (Article 83(2)(g) of the GDPR), whereby the fact that no special categories of personal data were affected could only be assessed as neutral; the Data Protection Authority ultimately determined the severity of the infringement to be moderate and set a starting amount of EUR 3,000,000 as the basis for further calculation. Consequently, the size of the company and its economic capacity, as defined in the Guidelines, were taken into account, and an adjustment was made to 1% of the starting amount, in particular to ensure the proportionality of the administrative fine pursuant to Article 83(1) of the GDPR.Consequently, the company’s size and economic capacity, as defined in the Guidelines, were taken into account, and an adjustment was made to 1% of the starting amount, in particular to ensure the proportionality of the administrative fine in accordance with article 83(1) of the GDPR. Apart from the circumstances already taken into account in determining the severity of the violation, there are no further aggravating factors affecting the calculation of the fine. This amount was ultimately reduced based on the mitigating factors listed below: - The Data Protection Authority has no record of any relevant prior violations of the GDPR by the defendant (Art. 83(2)(e) GDPR).The Data Protection Authority has no record of any relevant prior violations of the GDPR by the accused (article 83(2)(e) of the GDPR). - The defendant cooperated in the course of the present investigation and thereby contributed to establishing the facts (Art. 83(2)(f) and (k) of the GDPR).The defendant cooperated in the present investigation and thereby contributed to establishing the truth (article 83(2)(f) and (k) of the GDPR). According to the established case law of the Administrative Court (VwGH), considerations of specific and general deterrence may also be taken into account when determining the penalty (see VwGH May 15, 1990, 89/02/0093, VwGH April 22, 1997, 96/04/0253, VwGH January 29, 1991, 89/04/0061). Furthermore, under Article 83(1) of the GDPR, it must be ensured that any administrative fine imposed by the Data Protection Authority for established violations is effective, dissuasive, and proportionate. Thus, in accordance with these requirements, the administrative fine may be further increased or reduced on a case-by-case basis. According to the established case law of the Administrative Court, considerations of specific and general prevention may also be taken into account when determining the penalty; see Administrative Court, May 15, 1990, 89/02/0093; VwGH April 22, 1997, 96/04/0253; VwGH January 29, 1991, 89/04/0061). Furthermore, pursuant to Article 83(1) of the GDPR, it must be ensured that any administrative fine imposed by the Data Protection Authority for established violations is effective, dissuasive, and proportionate. Thus, in accordance with these requirements, the administrative fine may be further increased or reduced on a case-by-case basis. Although the imposition of the specific fine was not necessary in terms of specific prevention to deter the defendant from committing further offenses of the same nature—since she ceased the conduct after the administrative penalty proceedings were initiated— the imposition of the fine was nonetheless necessary for the purposes of general prevention to raise awareness among controllers regarding the identified violations, especially since complaints had already been filed with the Data Protection Authority based on similar cases. In light of this, the penalty ultimately imposed in the amount of EUR 25,500 appears appropriate in view of the actual gravity of the offense, measured against the available penalty range under Article 83(5) of the GDPR (up to EUR 20,000,000 in this case), to be proportionate to the offense and the degree of culpability, and falls at the very lower end of the available penalty range. An (even) lower fine would not satisfy the key requirements for an administrative fine set forth in Article 83(1) of the GDPR.In light of this, the penalty of EUR 25,500 ultimately imposed appears, in view of the actual value of the offense as measured against the available penalty range under article 83, paragraph 5, GDPR (up to EUR 20,000,000 in this case), to be proportionate to the offense and the degree of culpability and is at the lower end of the available penalty range. An (even) lower fine would not satisfy the key requirements for an administrative fine set forth in article 83(1) of the GDPR.