A photo taken at a protest, an automated comparison with a database containing more than 600,000 faces, and a criminal investigation targeting an innocent person. We filed a complaint, and the DSB ruled that the police's actions were unlawful. The significance of this decision reaches far beyond this individual case.

In March 2023 a man attended a climate protest in Vienna. The police photographed him and later used facial recognition to compare his image against a central database. The match led to a criminal investigation, which later was discontinued because no criminal wrongdoing was found. The complainant only became aware of the use of facial recognition after exercising his right of access. He reached out to us, and we filed a complaint with the Data Protection Authority on his behalf.

For us, the issue was never just about this individual case. The police have deployed this technology since 2020, and concerns have been raised from the outset about whether its use is supported by a sufficient legal basis. Several political parties raised questions about this through a number of parliamentary enquiries. The Ministry of the Interior, however, remained confident in its position and ignored all concerns, until now.

A victory with far-reaching consequences

The decision of the Data Protection Authority provides a clear answer. The Ministry of the Interior’s longstanding legal position is fully rejected. The DSB followed the argumentation we brought forward in our complaint, point by point.

Section 75 SPG (Austrian Security Police Act) permits the comparison of identification data in general terms but was originally enacted to govern the management of fingerprint records and contains no explicit provisions for facial recognition. Nevertheless, the police relied on this general provision as the legal basis for their use of the technology.

In our complaint, we argued that this was insufficient on two counts. First, pursuant to Article 8(1) of Directive (EU) 2016/680 (so called Law Enforcement Directive, short LED Directive), the processing of personal data within the scope of the directive is lawful only where it is necessary for the performance of a task prescribed by law. In addition, Article 8(2) Directive (EU) 2016/680 requires national law to expressly define the objectives, the categories of personal data, and the purposes of the processing. The Court of Justice of the European Union has also emphasised in its judgement in Case C-80/23 – Ministerstvo na vatreshnite raboti that the processing of sensitive data by law enforcement authorities is permissible only where it is based on a clear, precise, and verifiable legal basis.

Second, we argued that biometric processing of this kind constitutes a special category under Article 11 of the Directive, which requires that any authorising law also provide appropriate safeguards for the rights and freedoms of the data subject, at least the right to obtain human intervention.

The police pointed to their internal organisational and technical measures as such safeguards. We argued that this is not sufficient: Article 11 requires safeguards to be established in law, not merely implemented internally by the authority carrying out the processing.

The DSB followed our argumentation on both counts.

The significance of this decision extends far beyond our case. Every use of automated facial matching by the police since 2020 that relied solely on the relevant national law lacked a valid legal basis. We demand an end to this practice and a full accounting of how it could be deployed for years without an adequate legal basis.

Where technologies create new risks, the legal framework must be commensurate with those risks, providing clear limits, independent oversight, and effective safeguards for those affected.

Two months of imprisonment caused by a software

The consequences of allowing such systems to operate unchecked are illustrated by another publicly known case. An Austrian man was wrongly identified by facial recognition software as the leader of a criminal organisation. This led to an international arrest warrant, his detention in Serbia, and nearly two months in a Serbian prison cell. It was only weeks later that it became clear that the software had made a mistake and that the man had been imprisoned unjustly. Such technical errors are therefore not simply tolerable collateral damage; they can have devastating consequences for people's lives. This is exactly why effective safeguards are necessary whenever such technology is deployed.

The road ahead

The decision can still be challenged before the Federal Administrative Court within four weeks, and the Ministry of the Interior has already announced that it will do so, rather than use this opportunity to finally establish an adequate legal framework. We expect the Ministry of the Interior to pursue the case all the way to the highest court in order to uphold its legal position. Although we would welcome political action that makes it unnecessary to fight this out through every instance, we are prepared to go that route, not least in the hope of securing a decision that strengthens fundamental rights and benefits affected communities in Austria and beyond.

Our demands:

  • An immediate halt to automated facial matching

  • Effective safeguards and independent oversight for technologies that may infringe fundamental rights, such as facial recognition

  • Consistent enforcement of the AI Act and establishment of an independent AI supervisory authority

Since you're here

… we have a small favour to ask. For articles like this, we analyse legal texts, assess official documents and read T&Cs (really!). We make sure that as many people as possible concern themselves with complicated legal and technical content and understand the enormous effects it has on their lives. We do this with the firm conviction that together we are stronger than all lobbyists, powerful decision makers and corporations. For all of this we need your support. Help us be a strong voice for civil society!

Become a supporter now!

Related stories: