BF (data subject) – Court Ruling (Austria, 2026)

Court Ruling
Datenschutzbehörde28 April 2026Austria
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A court ruled that the Austrian migration authority lawfully processed a person's data when they rejected their application for international protection. This case is significant because it clarifies how immigration laws can affect data handling.

What happened

The Austrian migration authority rejected a person's application for international protection and entered their return alert into the Schengen Information System.

Who was affected

The individual who applied for international protection in Austria and had their data entered into the Schengen Information System.

What the authority found

The court held that the migration authority lawfully processed the person's data according to EU immigration law, which requires such entries.

Why this matters

This ruling shows that immigration authorities can legally process personal data under specific laws. Businesses should understand how legal obligations can impact data management.

GDPR Articles Cited

AI-verified

Art. 9(GDPR)
Art. 6(1)(c) GDPR
Art. 6(1)(e) GDPR
Art. 6(3) GDPR
Art. 17(1) GDPR
Art. 17(3)(b) GDPR
View original scraped data
Art. 6(1)(c) GDPR
Art. 6(1)(e) GDPR
Art. 6(3) GDPR
Art. 9(GDPR)
Art. 17(1) GDPR
Art. 17(3)(b) GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Regulation (EU) 2018/1860
Decision AuthorityBVwG
Reviewed AuthorityDSB (Austria)
Source verified 30 June 2026
articles corrected
authority corrected
Full Legal Summary
Detailed

The data subject applied for international protection in Austria on 22 September 2022. The controller (Austrian migration authority) rejected the application on 19 October 2022, issued a return decision without an entry ban, and entered the data subject's return alert into the Schengen Information System (SIS) on 21 November 2022. On 17 July 2025, the data subject asked the controller to delete the SIS alert. The controller refused the request. On 31 August 2025, the data subject lodged a complaint with the Austrian DPA seeking deletion of the SIS alert. On 31 October 2025, the DPA rejected the complaint because the return decision remained valid, the data subject had not proved departure from the Schengen area. The data subject appealed to the court, arguing that they had voluntarily left Austria, were lawfully residing in Portugal, and were in the process of obtaining a residence permit there. First, the court held that the controller had lawfully processed the data under Article 6(1)(c) GDPR and Article 6(1)(e) GDPR because EU immigration law required Member States to enter return decisions into the SIS. Second, the court held that none of the deletion grounds under the immigration law appled, as the return decision had not been withdrawn or annulled, the data subject had not demonstrated departure from the territory of the Schengen Member States, and Portugal had neither granted a residence permit nor notified Austria of an intended or completed grant. Third, the court found that Article 17(3)(b) GDPR did not require a deletion as the processing remained necessary to comply with a legal obligation and to perform a task in the public interest. The court also noted that the processing of biometric data contained in the SIS alert was permitted under Article 9(2)(g) GDPR because Union law authorised the processing for an important public interest and included appropriate safeguards. The court therefore concluded that the controller had no obligation to erase the

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Details

Ruling Date

28 April 2026

Authority

Datenschutzbehörde

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. BF (data subject) - Austria (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: