Political Data and Privacy: Sensitive by definition

Article P6-08

A score that guesses how you vote counts as sensitive personal data, even though you never said a word.

In brief

An inferred political-affinity score stored next to your name is sensitive personal data under European law, so a campaign needs consent or another legal exception to hold it or to work out your politics from your data. Good intentions are not an exception, and ordinary mishandling, such as leaving addresses in the open, can draw a fine. Enforcement so far is narrower than the rule: the largest penalty on record, €13,000,000, went to a company that sold affinity scores, and no decision on file rules on a party's own targeting model.

How to use this

Before building or buying an affinity score, write down the legal exception you are relying on, because consent is the usual one and good intentions are not. Treat any file that links a guessed political preference to a name as special-category data, whatever the folder is called, and check the mailing list, the supplier's copy and the retention rule first. If you are a regulator, ask whether a score was built lawfully rather than only whether it leaked. If a supplier offers you scored political data, assume that trade is the one a court has already priced.

What the story is about

A political-affinity score is a guess about how you vote, and it does not have to come from anything you said. In one Austrian case that ended on 24 June 2026, a company had polling institutes ask people anonymously about their social and demographic details, where they lived, and whether they were interested in election adverts from named parties. It grouped the population by those traits, used the survey answers and the area's past election results to work out the probability that somebody in each group liked each party, and then attached that probability, and the resulting affinity, to real people. About 2.2 million of them were scored (Verwaltungsgerichtshof, 2026). The scores were sold on, and none of those people had consented.

Store a guess like that next to a name and European law treats it as special-category data, the kind that needs consent or another legal exception before you can hold it at all (European Parliament and Council of the European Union, 2016). The penalty was a staggering €13,000,000 fine, against a recorded turnover of €2,033,836,266 for 2023 (Verwaltungsgerichtshof, 2026). Two things did not matter: that the staff meant no harm, and that no individual employee was singled out for blame.

The penalties that land are about handling. A staff member at an Austrian political party sent two campaign emails with every recipient address in the To: field instead of the BCC field (Bundesverwaltungsgericht, 2024b). About 400 addresses went out in the open, at least 100 of them with a first and last name attached. The court's reasoning was that political messages plus named recipients tell everyone on that list how at least some of those people probably vote. That disclosed special-category data with no legal exception available, and the party had also broken the GDPR's fairness and data-minimisation rules, since hiding the addresses was just as easy and less intrusive. The authority set the fine at €50,700; the court reduced it to €28,000. This party is a different organisation from the company in the affinity case, and like that company it goes unnamed: the published decisions call it only a political party, and identify the company only by an initial (Bundesverwaltungsgericht, 2024b; Verwaltungsgerichtshof, 2026).

Across the whole record, none of the decisions rules against a party's own model for working out which voters might back it (GDPRhub, 2026). The Austrian affinity case punished a commercial address publisher that sold scores.

Ask the consultants and the picture looks different. Gregor and Vahančíková (2026) interviewed 16 political consultants working in the Czech Republic, Hungary, Poland and Slovakia. The consultants described the rules as weakly, unevenly or politically enforced. The authors frame that as a condition of perceived lawlessness: the formal rules exist, but nothing the consultants see makes them bite. The same people recognised the democratic risks of microtargeting and opaque messaging, then treated those practices as a normal part of competing for votes.

That impression is hard to check against the public record, because the public record is small. Eighteen decisions touch political data across the whole life of the GDPR, and five of them are stages in one Austrian dispute. Remove that chain and thirteen distinct disputes remain, in GDPRhub, a public register of 3,963 data-protection decisions (GDPRhub, 2026).

European data law treats a political-affinity score attached to a named person as sensitive personal data. Whether a campaign may hold that score, and work out your politics from your data, depends on whether it has consent or another legal exception for doing so. Good intentions are not one of the exceptions. The enforcement record answers a narrower question (GDPRhub, 2026). The fines and decisions on file punish leaks and the commercial selling of affinity scores. Not one of them is a ruling on a party's own targeting model. The law covers the model. The enforcement has not yet reached it.

So what

Everything here comes back to the artefact: a score stored next to a name. That score is what triggers the protection, and how it is handled is what draws a penalty. Good intentions do not enter into it, and neither does the absence of one individual to blame. That leaves different work for the two groups who have to live with the rule. The people building and holding the scores have to manage files and suppliers. The people whose job is to notice when something goes wrong have to decide where to look.

For political parties

If your party holds inferred affinity data, you are holding special-category data, whatever the file is called. The exposure rarely sits in the clever part. It sits in the mailing list somebody exports, the supplier who keeps a copy, and the retention policy nobody has read since the campaign started. Those are the places a complaint will find you.

Trading in affinity scores is the one practice a court has already priced, so that is the line you do not need to test (Verwaltungsgerichtshof, 2026). The rest of the exposure sits in ordinary handling, where the To:-field fine shows the cost of one careless email.

For government

Regulators are left holding a rule that clearly covers the modelling, with almost nothing behind it. What is missing is not a new power. It is guidance, and enforcement that reaches the model rather than the mailing list.

Some things have not been measured at all. What this regime costs a campaign to follow is unmeasured, so nobody can say whether the rules are cheap or expensive (GDPRhub, 2026).

Closing that gap means asking whether a score was built lawfully, not only whether it leaked. That is the same standard a party should want applied to it, because enforcement that flatters nobody is what keeps the data worth having.

Case studies

Austria, 2019 to 2026. An address publisher built party-affinity probabilities from anonymous survey responses, socio-demographics, place of residence and regional election results, attached them to about 2.2 million people, and sold them. The regulator's first fine was €18,000,000. A court annulled it. After the Court of Justice of the European Union ruled that a company can be fined without first identifying the employee whose conduct is attributed to it, the penalty was reinstated in principle, set at €16,000,000, and then reduced by the country's highest administrative court to €13,000,000 on 24 June 2026 (Verwaltungsgerichtshof, 2026; Bundesverwaltungsgericht, 2024a). The published decisions do not name the company.

Seven years, four courts, one final number. Read it as a valuation of the artefact, not as a verdict on a party's own targeting model. What the courts priced was the score as a product that could be sold. A party that builds something similar for its own use has not been through this.

References

Bundesverwaltungsgericht (Austria) (2024a) W258 2227269-1/39E, 27 December 2024. Available at: https://ogd.ris.bka.gv.at/Dokumente/Bvwg/BVWGT_20241227_W258_2227269_1_00_01/BVWGT_20241227_W258_2227269_1_00_01.html (Accessed: 14 September 2026).

Bundesverwaltungsgericht (Austria) (2024b) W108 2285546-1/22E, 25 October 2024. Available at: https://www.ris.bka.gv.at/Dokumente/Bvwg/BVWGT_20241025_W108_2285546_1_00/BVWGT_20241025_W108_2285546_1_00.html (Accessed: 14 September 2026).

European Parliament and Council of the European Union (2016) Regulation (EU) 2016/679 (General Data Protection Regulation). Available at: https://eur-lex.europa.eu/eli/reg/2016/679/oj (Accessed: 14 September 2026).

GDPRhub (2026) Database of data protection authority and court decisions, maintained by noyb. Available at: https://gdprhub.eu/ (Accessed: 14 September 2026).

Gregor, M. and Vahančíková, T. (2026) 'Between strategy and integrity: political consultants and the ethics of data-driven campaigning in Central Europe', Journal of Contemporary European Studies, pp. 1–21. Advance online publication. Available at: https://doi.org/10.1080/14782804.2026.2700514 (Accessed: 14 September 2026).

Verwaltungsgerichtshof (Austria) (2026) Ro 2025/04/0007-7, 24 June 2026, ECLI:AT:VWGH:2026:RO2025040007.J00. Available at: https://ogd.ris.bka.gv.at/Dokumente/Vwgh/JWT_2025040007_20260624J00/JWT_2025040007_20260624J00.html (Accessed: 14 September 2026).

Explore the idea

Let’s talk

Invisible forces shape your world — until you hire Latenta®

Contact