Data Protection & AI

Secret audio recording and data protection

BVwG confirms fine for secret recording

With a decision dated March 24, 2026, the Federal Administrative Court (BVwG) upheld a GDPR fine against a limited liability company (GmbH) for the covert audio recording of a business meeting. What the decision means for companies in Austria, which mistakes must be avoided, and what rights data subjects have – a practical overview by ATB.LAW.

secret conversation recording, lawyer Austria data protection

Table of Contents

BVwG confirms risk for companies

Anyone who records conversations without warning beforehand is treading on dangerous ground. In its decision of March 24, 2026 (W298 2323263-1), the Federal Administrative Court confirmed a fine imposed by the Data Protection Authority for the covert audio recording of a business conversation. The decision is not only relevant to the specific case; rather, it is a clear signal to all companies that record, or have recorded, telephone calls, meetings, or customer conversations.

Particularly in areas such as call centers, sales, customer service, complaint management, or internal compliance investigations, audio recordings are often used without sufficient legal structure. The GDPR sets clear boundaries here—and Austrian courts and authorities enforce these boundaries.

What was the BVwG decision about?

On April 24, 2024, a representative of a Vienna advertising agency conducted a business meeting in a doctor's office. The goal: to win the doctor over as a client. What the doctor did not know: the representative was wearing a recording device and recorded the conversation without informing her at the beginning.

The recording captured not only the content of the conversation, but also the doctor's personal data: her name, her email address, her social media accounts, and information about her education. To make matters worse, patient conversations could be heard in the background.

The data subjects filed a data protection complaint. The data protection authority upheld the complaint, found a violation of the right to confidentiality, and subsequently imposed a in the penal proceedings Fine of EUR 6,300 as well as procedural costs of EUR 630. The company filed a complaint and ultimately failed before the Federal Administrative Court.

The BVwG confirmed the penalty notice in full and additionally imposed a Fee for the appeal proceedings: 20 % of the imposed penalty, i.e., EUR 1,260.00.

Particularly relevant: The court noted that the national provisions of Section 11 of the Data Protection Act (DSG) („warning instead of penalties“), Section 5 of the Administrative Criminal Act (VStG), Section 9 of the VStG and Section 33a of the VStG due to the primacy of EU law are not to be applied (more on that in a moment).

Why is an audio recording relevant under data protection law?

A person's voice is personal data within the meaning of Art. 4 No. 1 GDPR – just like a name, email address, professional function, or other information disclosed during a conversation. Merely recording a conversation is a Processing of personal data within the meaning of Art. 4 No. 2 GDPR.

This means that for every audio recording in which individuals are identifiable or could be identifiable, the full data protection requirements of the GDPR apply. This concerns not only the recording itself, but also the subsequent storage, evaluation, sharing, and archiving of the recordings.

Depending on the conversation content, additionally special categories of data personal data may be affected – such as health data, if personal information about a person's state of health is audible in a medically related conversation. This significantly increases the legal risk.

Secret audio recording: When does it become problematic under data protection law?

A call recording becomes problematic under data protection law if one or more of the following requirements are missing:

  • No prior notice: The recorded persons do not know that a recording is taking place.
  • No viable legal basis: There is no effective consent, no contract, no legal obligation, and no documented legitimate interest (Art. 6 GDPR).
  • No clear purpose: The purpose of the recording is not defined in advance.
  • No obligation to provide information pursuant to Art. 13 GDPR: The data subjects were not informed about the processing.
  • Excessive retention: The recordings are stored longer than necessary for the purpose.
  • No access concept: It is not regulated who is allowed to access the recordings.
  • Missing documentation: The recording practice is not recorded in the processing directory.
  • Misappropriation The recording will later be used for purposes other than originally stated – such as for the enforcement of claims.

In the specific BVwG case, several of these points were present: no notice at the beginning of the conversation, no effective consent, and use of the recording to support a fee claim.

What does the decision mean for companies in Austria?

The decision affects not only advertising agencies or sales representatives with hidden recording devices. It is a benchmark for any form of conversation recording in a corporate context.

Specific risk areas:

  • Call center and customer service: Phone calls are frequently recorded for quality assurance. If there is no prior notice, the recording is unlawful.
  • Online meetings (Teams, Zoom, Google Meet): Anyone who records meetings without clearly informing all participants in advance violates the GDPR – regardless of whether a feature in the tool is enabled.
  • Complaint management: Even in sensitive situations where a conversation is to be documented, a retroactive notice is not sufficient.
  • Internal investigations and compliance inquiries: Anyone who records conversations as part of an internal investigation must also comply with data protection requirements.
  • Securing evidence: The intention to secure evidence does not, in itself, justify an unlawful recording.

Fines against legal entities: Why this is particularly relevant

A common misconception: data protection violations only affect individuals. That is not true. The GDPR allows, Fines directly against companies to impose – regardless of which natural person acted internally.

In the present case, the complainant was a limited liability company (GmbH) and the fine was directed directly against this legal entity. A lack of internal processes, insufficient training of employees, or unclear guidelines on how to handle call recordings can be attributed to a company as organizational fault.

This means that it is not enough to point out that „an individual employee“ acted. Companies must ensure that clear internal guidelines exist and are followed.

Why „Advice instead of Penalties“ does not reliably protect against GDPR fines

Austrian administrative criminal law provides for simplifications: Section 33a VStG allows for advice instead of a penalty under certain conditions, and Section 11 DSG provides for a reprimand for certain data protection violations.

However, in this decision, the BVwG made it clear that these national provisions regarding GDPR fines do not apply. The reason: the primacy of EU law. As European law, the GDPR takes precedence over Austrian administrative criminal law. Where the GDPR itself—particularly in Article 83—sets the framework for fines, national regulations that would restrict this framework cannot be applied.

In practice, this means that companies cannot rely on automatically receiving only a reprimand or advice instead of a fine in the event of a GDPR violation regarding sound recording. Preventive compliance is the only reliable protection.

When can a call recording be permissible?

There is no blanket answer – it always depends on the individual case. The GDPR provides for various legal bases under Article 6 that can legitimize recording:

  • Consent (Art. 6 (1) (a) GDPR): The data subject gives voluntary, informed, and unambiguous consent – before The recording is starting. Consent obtained during or after the recording comes too late.
  • Performance of a contract (Art. 6 para. 1 lit. b GDPR): In some industries, recording can be necessary to fulfill a contract, such as with order confirmations by telephone.
  • Legitimate interest (Art. 6 para. 1 lit. f GDPR): The company has a legitimate interest in the recording which, after careful balancing, outweighs the interests of the data subjects. This balancing test must be documented.
  • Legal obligations (Art. 6 para. 1 lit. c GDPR): In certain industries, such as the financial sector, a recording obligation can be required by law.

Regardless of the chosen legal basis, the following always applies: Transparency, purpose limitation, storage limitation, access concept, deletion concept, and documentation must be guaranteed. Permissible recording is not a matter of course – it requires a conscious legal decision and appropriate organizational measures.

Typical corporate situations at a glance

Situation Data protection risk Practical measure
Recording of support phone calls High, if no prior notice is given Introduce standardized notice at the beginning of the conversation, document the legal basis
Recording of a complaint call High, as it is often spontaneous and without consent Clear internal rule: Recording only after explicit notice and documentation
Recording of an online meeting Medium to high, depending on the tool setting Note in invitation and at the beginning, start recording only after confirmation
Internal investigation / Compliance investigation High, as the sensitivity of the data is often increased Legal review in advance, data protection impact assessment if necessary
Sales or consultation meeting High, as in the BVwG case No recording without a clear prior notice and documented basis
Quality assurance in the call center Medium to high Written legal basis, privacy policy for callers, training
Securing evidence in disputes High, if without prior consent Legal advice before recording; subsequent evidence preservation can create new risks

What companies should check now

Anyone who records conversations or has them recorded should systematically check the following questions:

  • Are phone calls, online meetings, or personal conversations recorded? If yes: in which areas and to what extent?
  • Is there a clear notice before the start of each recording? Not only during the conversation, but before it.
  • Is the legal basis pursuant to Art. 6 GDPR documented? Consent, legitimate interest, or legal obligation – each with documentation of the balancing test.
  • Is there privacy information pursuant to Art. 13 GDPR? Data subjects must be informed about the processing.
  • Is there a deletion concept? How long are recordings stored, and who decides on their deletion?
  • Who has access to the recordings? And is this access restricted and documented?
  • Are recordings passed on to third parties? If so: on what basis?
  • Are employees trained? Do all parties involved know what is allowed and what is not?
  • Is the recording practice documented in the processing directory?
  • Has it been checked whether a data protection impact assessment is required? Especially in the case of systematic or extensive recording.

What affected parties can do if a conversation was secretly recorded

Anyone who suspects or knows that a conversation was recorded without prior notice should consider the following steps:

  • Document facts: Record date, location, participants, and all known circumstances.
  • Request information: According to Art. 15 GDPR, there is the right to request information about processed personal data – including audio recordings.
  • Check deletion: If there is no legal basis, a request for erasure pursuant to Art. 17 GDPR may be considered.
  • Review privacy complaint: A complaint can be filed with the Austrian Data Protection Authority if a violation of the right to confidentiality is suspected.
  • Check claims for damages: In the event of specific material or non-material damage, a claim for compensation may exist pursuant to Art. 82 GDPR.
  • Do not communicate prematurely: Before contacting the recording company, a legal assessment is recommended in order to avoid creating unintentional disadvantages.

Importance for data protection, cybercrime, and compliance

In digital conflicts, during cyber incidents, as part of internal compliance investigations, or during incident response, there is frequently intense pressure to secure evidence. Data must be secured, conversations documented, and facts recorded.

This pressure to secure evidence is understandable. However, it does not exempt one from the obligation to comply with data protection requirements. Legally inadmissible evidence collection—such as covert recording for the purpose of subsequent use in a dispute—can create new data protection risks and jeopardize the admissibility of the evidence.

Especially in areas such as cybercrime, digital forensics, incident response, and internal investigations, a sound legal structure is therefore crucial from the very beginning. Anyone who needs to secure evidence should do so with legal backing – rather than having to justify it afterwards.

How ATB.LAW can support

Data protection law, compliance, and digital forensics intertwine in practice. ATB.LAW combines experience in these areas with procedural experience before the data protection authority and the Federal Administrative Court.

For businesses:

  • Review of existing call-recording, telephone, and meeting recording processes for GDPR compliance
  • Development of data protection-compliant recording concepts (legal bases, notice texts, data protection information pursuant to Art. 13 GDPR, deletion and access concepts)
  • Representation in proceedings before the Data Protection Authority and the Federal Administrative Court
  • Advice on GDPR fines and penalty notices
  • Support for incident response and cybercrime with data protection law context
  • Compliance consulting for management and data protection officers

For those affected:

  • Legal assessment of whether a covert recording constitutes a GDPR violation
  • Assistance with requests for information and deletion
  • Assistance with data protection complaints
  • Examination of claims for damages

If you are unsure whether your recording practice is GDPR-compliant – or if you have become aware that a conversation was recorded without your knowledge – we are available for an initial assessment. Contact us.

Conclusion: Secret audio recordings are no trivial offense

The Federal Administrative Court decision of March 24, 2026, makes it clear that covert audio recordings of business conversations are not a trivial matter. The court upheld a fine of EUR 6,300 against a GmbH – plus costs and a cost contribution to the appeal proceedings. National relaxations such as „counseling before penalties“ did not apply because EU law takes precedence.

For companies in Austria, this means: anyone recording conversations needs clear processes – before the recording, not after. A standardized notice, a documented legal basis, clear access rules, and a deletion concept are not bureaucratic exercises, but the minimum standard for legally compliant action.

Affected individuals should know: A secret audio recording is no minor matter. The GDPR gives you rights – and the data protection authority enforces them.

Frequently Asked Questions (FAQ)

Is a company allowed to secretly record a business conversation?

No. A call recording without prior notice to all recorded individuals is generally impermissible under the GDPR. If a clear notice and a viable legal basis are lacking, a data protection violation exists. The Federal Administrative Court (BVwG) confirmed this in its decision of March 24, 2026 (W298 2323263-1).

Is an audio recording without consent permitted under the GDPR?

Only in rare exceptional cases. Although the GDPR provides various legal bases (Art. 6) that do not necessarily require consent—such as legitimate interest or legal obligations—prior information must be provided in any case (Art. 13 GDPR), and the legal basis must be documented and traceable. Secret recording without any prior information is generally not permitted.

What penalty is threatened for an unlawful audio recording?

In the specific BVwG case, the fine imposed on a GmbH amounted to EUR 6,300, plus procedural costs of EUR 630 and a contribution toward the costs of the appeal proceedings of EUR 1,260. Article 83 of the GDPR provides for fines of up to EUR 20 million or up to 4 % of global annual turnover for serious violations. The specific amount depends on the circumstances of the individual case.

Can companies themselves also receive a GDPR fine?

Yes. GDPR fines can be imposed directly against legal entities—meaning LLCs, corporations, and other businesses. It is not sufficient that an individual employee acted. Missing internal processes and a lack of training can be attributed to the company as organizational fault.

Is a notice at the beginning of the phone call sufficient?

A notice at the beginning of the conversation is a necessary, but not always sufficient condition. The notice must be clear and understandable and enable the affected person to make an informed decision. In addition, there is a need for a documented legal basis, data protection information in accordance with Art. 13 GDPR, and a corresponding concept for storage, access, and deletion.

What can I do if I was secretly recorded?

You can request information about the processed data (Art. 15 GDPR), request its erasure (Art. 17 GDPR), and lodge a complaint with the Austrian Data Protection Authority. If there is specific damage, a claim for damages pursuant to Art. 82 GDPR may also be considered. A preliminary legal assessment is recommended.

When is call recording legally permissible under data protection law in Austria?

Call recording is permitted if prior clear information is provided, a viable legal basis pursuant to Art. 6 GDPR exists (e.g., consent, legitimate interest with documented balancing, or legal obligation), the purpose is clearly defined, a deletion and access concept is in place, and the data protection documentation is up to date. In some industries (e.g., financial services), there are also specific legal requirements.

Contact us

Contact us. We will evaluate your individual case and represent you before civil courts and administrative authorities. For further information and an initial assessment, are available Roman Taudes, Stefan Knotzer and their team at any time at office@atb.law or by phone at 01 39 12345 available.

More articles

EU Commission CRA Guidelines

Cyber Resilience Act: EU Commission guidelines published

Get companies out of standby mode and into the fast lane for the CRA.
Picture of Stefan Knotzer
Stefan Knotzer

When the model sings: Copyright limits of AI training after the Suno ruling

Where AI & Copyright Hit a Sour Note
Picture of Stefan Knotzer
Stefan Knotzer
Laptop is losing data

Data Breach: The Devil Never Sleeps

What Austrian companies can learn from the incident at a major US law firm
Picture of Stefan Knotzer
Stefan Knotzer