PrivacyForgeSign In
Back to Blog

Buying Marketing Lists Under GDPR: The CRIF Ruling

Austria’s Supreme Court says marketing data cannot be reused for credit scoring. Apply the same test to the lists your store buys — and the data it passes on.

PFMariyan ValevSep 3, 2026 · 15 min read
RegulationRegulation

Key Takeaways

  • On 12 August 2026 Austria's Supreme Court held that a credit-reference agency could not lawfully reuse address data collected for marketing — decisions 6Ob147/25y and 6Ob148/25w, with 6Ob151/25m reported alongside them. What failed was the change of purpose, not the original collection.
  • The court ran the Article 6(4)(a) compatibility test and found no "relevant link" between third-party marketing purposes and creditworthiness assessment, adding that people do not reasonably expect such a reuse.
  • The UK soft opt-in cannot be bought with a list. PECR regulation 22(3)(a) covers only details "that person has obtained… in the course of the sale" — the sender's own sale, never the seller's.
  • A bought list starts an Article 14 clock of one month, and Article 14(2)(f) makes you name where the data came from — at the latest when you first make contact.
  • The ruling points both ways. The test that stopped a bureau reusing marketing data is the test you fail when customer data collected for fulfilment is passed into a partner's marketing.

Introduction

Say a supplier offers your store a list: opted-in contacts in your category, priced per thousand, clean enough to import before the autumn campaign. Before it lands in your email platform, there is a question worth more than the list costs — and most of the guidance online answers only half of it.

On 12 August 2026 Austria's Supreme Court decided three cases against a credit-reference agency that had obtained address data from a direct-marketing publisher and used it to assess creditworthiness. The collection had been lawful. The reuse was not. That distinction is purpose limitation, and it governs the data leaving your store just as strictly as the data arriving.

This article is informational content, not legal advice. For organisation-specific guidance, consult a qualified legal professional.

What Austria's Supreme Court Actually Decided

The Oberster Gerichtshof (OGH) decided cases 6Ob147/25y and 6Ob148/25w on 12 August 2026; heise online reports a third, 6Ob151/25m, among the same set. The published decision text restates the principle plainly: "Nach dem Grundsatz der Zweckbindung (Art 5 Abs 1 lit b DSGVO) dürfen personenbezogene Daten (nur) für festgelegte, eindeutige und legitime Zwecke erhoben werden und nicht in einer mit diesen Zwecken nicht zu vereinbarenden Weise weiterverarbeitet werden." — under purpose limitation, data may only be collected for specified, explicit and legitimate purposes, and not further processed incompatibly with them.

What makes the case useful to a merchant is that nobody argued the address data had been gathered unlawfully. The court noted that § 151 GewO 1994, Austria's trade law, lets address publishers obtain and use certain personal data for marketing "unabhängig von einer Einwilligung der betroffenen Personen" — without the consent of the people concerned, within limits. The starting point was lawful. The destination was the problem.

The civil proceedings were brought by the Viennese lawyer Robert Haupt, independently of the privacy organisation noyb, whose parallel complaint — filed in March 2021 — had already succeeded before Austria's data protection authority and the Federal Administrative Court. Marco Blocher, data protection lawyer at noyb, put the principle this way: "Marketing and credit assessments are entirely different purposes with completely different implications for data subjects. Nevertheless, address brokers have been selling the data of millions of data subjects to credit reference agencies for years—without facing any consequences." noyb now plans a class action seeking roughly €500 per person.

The compatibility test the court applied

Article 6(4) GDPR is the machinery, and the OGH used it explicitly. Where data collected for one purpose is further processed for another without fresh consent, the controller must assess compatibility against five factors: the link between the purposes, the context of collection, the nature of the data, the consequences for the person, and any safeguards.

The finding on the first factor is the quotable one: "Eine relevante Nahebeziehung (Art 6 Abs 4 lit a DSGVO) zwischen Marketingzwecken Dritter iSd § 151 GewO 1994 und Bonitätsbeurteilungszwecken iSd § 152 GewO 1994 liegt nicht vor." There is no relevant link between third parties' marketing purposes and creditworthiness-assessment purposes. The court then reached the expectation limb: a person whose data was collected for marketing "erwartet auch vernünftigerweise nicht… dass die zu diesem Zweck erhobenen Daten für Bonitätsbeurteilungszwecke (weiter-)verarbeitet werden" — does not reasonably expect it to be further processed for credit assessment. For that proposition the court cited Recital 50, which asks the assessor to weigh "the context in which the personal data have been collected, in particular the reasonable expectations of data subjects based on their relationship with the controller as to their further use", together with the CJEU's judgment in Digi (C-77/21).

What the court did not decide

The OGH did not outlaw credit scoring built on thin data. On the claimants' request for a per-se ban on scoring without payment-experience data, it held that no breach of Article 5(1)(a) with Article 6(1)(f) could be derived from that alone; heise reports the court describing such an assessment as still "erforderlich" — necessary — within the GDPR's meaning. In a statement reported by ORF, the agency said the decisions concern a 2020 practice and that it stopped processing that publisher's address data for payment-default assessment in October 2023.

Reported honestly, this is a split result. The transferable half is the purpose-limitation half — and that half is now backed by a supreme court applying Article 6(4) to a commercial data transfer.

Does Buying a Marketing List Break GDPR?

Not automatically — but a bought list must clear three hurdles, and most clear none. You need a lawful basis, a purpose compatible with the one the data was collected for, and a way to satisfy Article 14. Sellers price the file. They rarely price the evidence you need to use it.

The first hurdle is the one every incumbent guide covers: consent, or legitimate interests under Article 6(1)(f). Recital 47 does say "the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest" — a sentence list vendors quote often and completely. It sits inside a recital that demands "careful assessment" and a balancing test, and it says may.

The second hurdle is what the CRIF ruling is about, and almost nobody applies it to marketing lists: whether the purpose you have in mind is compatible with the purpose the data was collected for. If a list was assembled for a competition entry, a shipping quote, or one company's newsletter, your campaign is a different purpose, and Article 6(4) is a test to pass rather than a formality to note. Whether the vendor's consent was valid in the first place is a separate problem, covered in our guide to third-party marketing vendor liability — purpose limitation applies even when that consent is impeccable.

Why the UK soft opt-in cannot travel with a list

The soft opt-in is tied to the sender by the text of the rule, and no contract moves it. UK PECR regulation 22(2) bars unsolicited marketing email unless "the recipient of the electronic mail has previously notified the sender that he consents". The exemption in regulation 22(3) then applies only where:

"(a) that person has obtained the contact details of the recipient of that electronic mail in the course of the sale or negotiations for the sale of a product or service to that recipient; (b) the direct marketing is in respect of that person's similar products and services only; and (c) the recipient has been given a simple means of refusing… at the time that the details were initially collected, and… at the time of each subsequent communication."

Read "that person" twice. The sale must be yours, and the products marketed must be yours. A list bought from a company that made the sale gives you neither limb, however genuine its own relationship with those people was. PECR now also carries a separate charity soft opt-in at regulation 22(3A), which does nothing for a commercial store.

The Duty Bought Lists Fail First: Article 14

When you did not collect the data from the person, Article 14 makes you tell them — and the deadline is one month. Article 14(3)(a) requires the information "within a reasonable period after obtaining the personal data, but at the latest within one month"; 14(3)(b) brings it forward to "the time of the first communication" where you use the data to contact them; 14(3)(c) to the first disclosure where you pass it on.

The disclosure itself is the awkward part. Article 14(2)(f) requires you to state "from which source the personal data originate, and if applicable, whether it came from publicly accessible sources". A campaign that opens by naming the broker it bought you from has a predictable unsubscribe rate — which is the honest cost of the tactic, and a reasonable input to the decision.

The escape hatch is narrower than it is usually assumed to be. Article 14(5)(b) disapplies the duty where the information "proves impossible or would involve a disproportionate effort, in particular for processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes". Those named examples are the context; "emailing the spreadsheet we bought is inconvenient" is not impossibility.

Two further duties attach the moment the list is in your systems. Under Article 21(2) the person can object to direct marketing "at any time", and under 21(3) processing must then stop — no balancing, no exceptions — while Article 21(4) requires that right to be presented "at the latest at the time of the first communication", "clearly and separately from any other information". And when someone asks where you got their details, Article 15(1)(g) entitles them to "any available information as to their source". If your answer is a vendor name you never recorded, you have an access-request problem as well as a marketing one.

The Mirror Case: When Your Customer Data Becomes Someone Else's List

This is the half the CRIF ruling actually decides, and the half no merchant guide covers. The agency was the buyer. The publisher that supplied the data was doing something many businesses do quietly: passing on personal data it had lawfully collected, for a purpose the people concerned had never been told about.

Run the OGH's test against your own outbound flows. For each place customer data leaves your store, ask what purpose it was collected for and what purpose it now serves:

FlowCollected forNow used forCompatible?
Order data to a fulfilment partnerDelivering the orderDelivering the orderYes — same purpose
Email addresses to an enrichment vendorOrder confirmationAppending demographics for targetingNeeds an Article 6(4) assessment
Customer list to an affiliate or partner brandYour own saleAnother controller's marketingAlmost certainly not, without consent
Checkout data to a scoring providerPayment riskPayment riskSame purpose — but see credit checks at checkout for the controller duties that stay with you

The middle two rows are where stores get caught, and the reason is rarely malice — the flow was set up by a growth team and never written down. Article 5(2) puts the burden on you: the controller "shall be responsible for, and be able to demonstrate compliance". A partnership agreed on a call and implemented with a CSV export leaves nothing to demonstrate. The fix is unglamorous and durable: every recipient of personal data, and every source of it, belongs in your record of processing activities with its purpose and lawful basis written next to it.

How to Test a List Before You Use It

Run this before the import, not after the first complaint. Steps 2 and 3 are the ones the CRIF decisions add to the usual checklist.

  1. Get the collection notice, not the assurance. Ask for the exact privacy notice and consent wording shown when the data was collected, with the dates each version was live. A vendor who cannot produce versioned text cannot support the claim it is selling.
  2. Name both purposes out loud. Write down the purpose stated at collection and the purpose you intend. If you cannot describe a link between them in one sentence, Article 6(4)(a) is already against you — that is the finding the OGH made.
  3. Apply the expectation test to a real person. Would someone who filled in that original form reasonably expect an email from your store? Recital 50 makes this part of the compatibility assessment, and the OGH treated the answer as confirming its finding. "They ticked a box saying 'partners'" is not an expectation.
  4. Draft the Article 14 notice before you buy. Write the sentence that names the source. If you would not send it, the acquisition is not one you can defend.
  5. Record the source — vendor, date, purpose, lawful basis — on the day the data arrives, not when a regulator or a customer asks.
  6. Wire the objection route first. Article 21(2) objections must be honoured immediately, and Article 21(4) requires the right to be flagged in the first message. Build the suppression list before the send.

Our recommendation, plainly: for most EU and UK eCommerce stores, buying a prospect list is not worth it. Doing it properly — versioned notices, an Article 6(4) assessment, an Article 14 mailing that announces the purchase — usually costs more than a cold list is worth, and deliverability is worse than owned-audience growth anyway. The exception worth considering is a business-to-business list where you can evidence the original purpose and your product genuinely matches it. Everything else is renting a risk.

Common Mistakes

Treating "they opted in" as the whole answer. This is the worst one, because it sounds like diligence. Consent runs to a named controller and a purpose. A valid opt-in to a comparison site's newsletter is not an opt-in to your promotional email, and the CRIF decisions are a court saying so about a transfer where the original collection was lawful.

Reading Recital 47's direct-marketing sentence as permission. It says direct marketing "may be regarded as" a legitimate interest, inside a recital that requires careful assessment and asks what the person reasonably expected. Quoting the clause without the balancing test is how a legitimate-interests assessment becomes a legitimate-interests assertion.

Assuming the soft opt-in transfers. Regulation 22(3) says "that person" twice. It is a rule about your own sale to your own customer, and it is the most commonly misapplied provision in list-buying.

Deleting the provenance. Merging a bought list into your main audience and dropping the source column destroys your ability to answer Article 15(1)(g), to segment the suppression, or to prove which contacts came from where when something goes wrong. Keep the source field; it costs one column.

How PrivacyForge Helps

The hard part of purpose limitation is not the rule. It is that the answer lives across a data map, a consent log and a marketing platform that were never designed to be read together.

PrivacyForge keeps the record of processing activities where sources and recipients sit alongside each flow's purpose and lawful basis, so an Article 6(4) assessment starts from something written down rather than a reconstruction. Consent and preference records are stored with their capture context — what an Article 15(1)(g) source question and an Article 21(2) objection both need. And compliance scoring surfaces flows that carry a recipient but no documented purpose, usually the partner integration nobody remembers approving. For a broader grounding, see our complete guide to GDPR compliance.

Frequently Asked Questions

Buying a list is not banned outright, but using it lawfully is hard. You need your own lawful basis under Article 6, a purpose compatible with the one the data was originally collected for under Articles 5(1)(b) and 6(4), and an Article 14 notice to every person on the list within one month. Most commercial lists cannot evidence the first two.

Can I email a purchased list if the seller says everyone opted in?

Not on that assurance alone. Consent under GDPR runs to a named controller and a specific purpose, so an opt-in given to the seller does not extend to your store unless you were identified at the time. In the UK, PECR regulation 22(3) makes it worse for bought lists: the soft opt-in applies only where you obtained the details in your own sale.

What is purpose limitation under GDPR?

Purpose limitation is Article 5(1)(b): personal data must be "collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes". Where you want to use data for a new purpose without fresh consent, Article 6(4) sets the compatibility test — the link between purposes, the collection context, the nature of the data, the consequences, and any safeguards.

Do I have to tell people that I bought their data?

Yes. Article 14 applies whenever personal data was not obtained from the person, and Article 14(2)(f) requires you to state "from which source the personal data originate". The deadline is one month at the latest, or the time of your first communication if that comes sooner. The disproportionate-effort exemption in Article 14(5)(b) is aimed at archiving, research and statistics, not at inconvenient marketing mailings.

Can I share or sell my customers' data with a marketing partner?

Only if the new purpose is compatible with the one you collected for, or you have consent covering it. The Austrian Supreme Court's decisions of 12 August 2026 found no relevant link between marketing purposes and credit assessment, and held that people do not reasonably expect such a reuse. Passing customer data collected for fulfilment into a partner's marketing raises the same question.

What did Austria's Supreme Court decide in the CRIF case?

On 12 August 2026, in decisions 6Ob147/25y and 6Ob148/25w, the OGH held that a credit-reference agency breached purpose limitation by using address data that a direct-marketing publisher had collected for marketing. It granted an injunction over the claimants' data. It did not ban credit scoring without payment-experience data, and the agency says the practice concerned ended in October 2023.

Conclusion

The lesson of the CRIF decisions is not "do not buy lists" — it is that lawful collection buys nothing for the next purpose. A court has now worked through the Article 6(4) catalogue on a commercial data transfer, found no relevant link between marketing and scoring, and confirmed that finding by asking what the person reasonably expected. That reasoning does not stop at credit bureaus. It reaches every list an online store imports and every export it sends to a partner.

The practical move is small and pays for itself: write down, for each flow of personal data into and out of your store, the purpose it was collected for and the purpose it now serves. Where those two do not match, you have found either an Article 6(4) assessment to run or a flow to switch off. Start with your record of processing activities — everything above is a question it should already answer.

Sources