BF (data subject) – Court Ruling (Austria, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A court ruled that the Austrian migration authority lawfully processed a person's data when they rejected their application for international protection. This case is significant because it clarifies how immigration laws can affect data handling.
What happened
The Austrian migration authority rejected a person's application for international protection and entered their return alert into the Schengen Information System.
Who was affected
The individual who applied for international protection in Austria and had their data entered into the Schengen Information System.
What the authority found
The court held that the migration authority lawfully processed the person's data according to EU immigration law, which requires such entries.
Why this matters
This ruling shows that immigration authorities can legally process personal data under specific laws. Businesses should understand how legal obligations can impact data management.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
The data subject applied for international protection in Austria on 22 September 2022. The controller (Austrian migration authority) rejected the application on 19 October 2022, issued a return decision without an entry ban, and entered the data subject's return alert into the Schengen Information System (SIS) on 21 November 2022. On 17 July 2025, the data subject asked the controller to delete the SIS alert. The controller refused the request. On 31 August 2025, the data subject lodged a complaint with the Austrian DPA seeking deletion of the SIS alert. On 31 October 2025, the DPA rejected the complaint because the return decision remained valid, the data subject had not proved departure from the Schengen area. The data subject appealed to the court, arguing that they had voluntarily left Austria, were lawfully residing in Portugal, and were in the process of obtaining a residence permit there. First, the court held that the controller had lawfully processed the data under Article 6(1)(c) GDPR and Article 6(1)(e) GDPR because EU immigration law required Member States to enter return decisions into the SIS. Second, the court held that none of the deletion grounds under the immigration law appled, as the return decision had not been withdrawn or annulled, the data subject had not demonstrated departure from the territory of the Schengen Member States, and Portugal had neither granted a residence permit nor notified Austria of an intended or completed grant. Third, the court found that Article 17(3)(b) GDPR did not require a deletion as the processing remained necessary to comply with a legal obligation and to perform a task in the public interest. The court also noted that the processing of biometric data contained in the SIS alert was permitted under Article 9(2)(g) GDPR because Union law authorised the processing for an important public interest and included appropriate safeguards. The court therefore concluded that the controller had no obligation to erase the
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (1)
Other cases involving BF (data subject) in AT
Details
About this data
Cite as: Cookie Fines. BF (data subject) - Austria (2026). Retrieved from cookiefines.eu
Last updated: