Court case W292 2298015-1 – Court Ruling (Austria, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A court in Austria ruled that a bank violated GDPR by contacting a customer after they requested the deletion of their phone number. This decision emphasizes that companies must respect user requests regarding their personal data.
What happened
A bank was found to have contacted a customer after they requested the deletion of their phone number, violating GDPR rules.
Who was affected
The customer whose phone number was not deleted as requested.
What the authority found
The court held that the bank's calls were unnecessary and violated GDPR because the customer had asked for their data to be deleted.
Why this matters
This ruling highlights the obligation of companies to respect user requests about their personal data. Businesses must ensure they have clear processes for handling such requests to avoid legal issues.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The data subject was a customer of a bank (controller). The data subject withdrew their consent to the processing of their e-mail address and phone number by the controller, and requested the deletion thereof. The data was not deleted. The controller tried to call the data subject in order to discuss the necessity of processing of their phone number, and send them an e-mail about the matter. The controller contacted the data subject again on the matters of possible usage of their bank account in violation of contract, and change of terms of service. Consequently, the data subject sought the termination of the contractual relationship with the controller. Because of unpaid bills, the contract could not be terminated. In order to discuss the matter, the controller tried to contact the data subject again. Eventually, the account of the data subject with the controller was closed. The data subject requested access to their data from the controller. The controller tried to call the data subject again on that matter. The data subject lodged a complaint with the DPA. The DPA held that the controller called the data subject in violation of the GDPR because the calls were not necessary for the performance of a contract between the parties pursuant to Article 6(1)(b) GDPR. Moreover, the DPA held that the controller could not rely on Article 6(1)(f) GDPR because the data subject must not reasonably expect to be called after requesting the deletion of their phone number. The controller appealed the decision by the DPA. The court overruled the decision of the DPA. The court distinguished between before and after termination of the contract. It held that before contract termination, the processing of the data subject’s e-mail address and phone number was necessary for the performance of the contract. In particular, contact details are necessary to be able to contact the data subject per phone call or e-mail about possible security threats concerning the data subject’s bank
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (0)
No other cases found for Court case W292 2298015-1 in AT
This is the only recorded case for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Court case W292 2298015-1 - Austria (2026). Retrieved from cookiefines.eu
Last updated: