Privacy
Focus area

Marketing, Cookies and Tracking

Build data-driven marketing without bypassing consent, transparency or the right to object.

BRANDAUER Rechtsanwälte
Contact person

Mag. Bernhard Brandauer, Rechtsanwalt

BRANDAUER Rechtsanwälte

Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.

Marketing is not one single data-protection operation. A strictly necessary cookie, an analytics pixel, a newsletter address and an interest profile derived from customer data require different assessments. Organisations should therefore describe their data flows first and only then choose a banner, campaign or new tool.

It is particularly important to separate access to a device, processing of personal data and advertising communication. Cookies and similar technologies are subject not only to the General Data Protection Regulation but also to Austrian telecommunications law. Email, SMS and advertising calls create additional requirements.

This page explains how controllers can structure marketing measures, collect valid consent, process withdrawals and objections, and organise evidence. It does not replace a review of the concrete data model, provider terms and tags actually deployed.

If a cookie banner, customer segmentation or campaign is already running, start with an inventory: what data is collected, when, sent to whom, retained for how long and used for which decision? Those answers are the basis for a defensible assessment.

Mag. Bernhard Brandauer, Rechtsanwalt

Three assessments

Separate technology, data processing and advertising

One measure may raise several legal questions at once. This overview prevents a cookie banner from being treated as a substitute for transparent information or a proper legal basis.

Separate technology, data processing and advertising
Assessment Typical question Evidence to keep
Device and cookies Is information stored or read from the device? Selection, purpose, timing and withdrawal of consent
Personal data Which data does the organisation process? Purpose, legal basis, recipients, retention and safeguards
Direct marketing and profiling Who sees which message and why? Data source, segment logic, objections, suppression lists and approval

The correct information depends on the service, technology and audience involved.

Marketing starts with purpose and responsibility

Under Article 4(7) GDPR, the controller is the party deciding the purposes and means of processing. This will normally be the organisation using a customer database for advertising or deciding which audiences an advertising platform should target. A marketing provider may be a processor. If the platform also determines purposes and means, the allocation of roles requires a separate assessment.

Every measure should therefore have a short data-flow record: source, identifiers, tags or interfaces, recipients, profile attributes, purpose and deletion rule. Calling something a “marketing tool” does not answer these questions. Pseudonymous identifiers may still be personal data if the organisation or a provider can reasonably link them back to a person.

The data protection governance process should include approval of new tools. Where agencies, platforms or campaign partners jointly shape a campaign, clarify who informs individuals, receives objections and handles requests.

  • Describe the purpose concretely instead of using labels such as “optimisation” or “reach measurement”.
  • Distinguish controllers, processors and possible joint controllers in writing.
  • Document data sources and recipients before activating a tag or campaign.
  • Include deletion, aggregation and exclusion of objectors in the process.

Cookies and pixels require a suitable choice

For cookies, pixels and similar technologies, first determine whether information is stored on or read from the device. Section 165(3) of the Austrian Telecommunications Act 2021 requires providers of information-society services to obtain active consent, based on clear and comprehensive information, when collecting personal data. The narrow exception covers technical transmission or access that is strictly necessary for a service expressly requested by the user.

A marketing, analytics or retargeting tag therefore cannot be justified simply because it sets “only” an identifier or sends data to a provider. The user must know the purpose before choosing. Non-essential technologies must not load on the initial page view. Refusal should be possible without unnecessary obstacles and should not be hidden behind a materially less visible choice.

Consent under telecommunications law does not automatically answer the GDPR question. If an organisation processes an IP address, online identifier, device information or usage data, it also needs a suitable legal basis under Article 6 GDPR. A banner should show purposes, providers, categories and withdrawal in an understandable way rather than merely listing technical product names.

  • Separate essential functions from analytics, personalisation and advertising technically.
  • Load non-essential tags only after the relevant choice and honour changes reliably.
  • Make refusal and later withdrawal as easy as acceptance.
  • Keep the consent time, information version and selected purposes as evidence.

Direct marketing needs a purpose, a boundary and an objection route

Postal advertising, newsletters, SMS and other contact channels are not governed by identical rules. Article 6 GDPR requires a legal basis for processing. Legitimate interests may be relevant for direct marketing where purpose, scope, reasonable expectations and impact are carefully balanced. The information must name the purpose clearly. Electronic marketing is also subject to the stricter requirements of Section 174 of the Austrian Telecommunications Act 2021.

Electronic mail for direct advertising is generally permitted only with prior consent. The exception for the controller’s own similar products or services requires, among other things, that the contact details were obtained in connection with a sale or service and that a clear, free and easy opt-out was offered when collected and in every message. The specific recipients and message content must be part of the assessment.

A person objecting to processing for direct marketing has a particularly strong right under Article 21(2) GDPR. The data must then no longer be processed for that purpose. The organisation therefore needs a reliable suppression list covering CRM, newsletters, sales lists and, where relevant, contracted advertising providers.

  • Record the contact channel, data source and legal basis before sending.
  • Accept opt-outs and objections without media breaks and distribute them to every relevant system.
  • Review lists regularly for suppression entries and unlawful sources.
  • Keep sender identity, legal information and an easy unsubscribe route in electronic messages.

Profiling requires an intelligible segmentation logic

Article 4(4) GDPR defines profiling as automated processing used to evaluate personal aspects, especially to analyse or predict interests, behaviour or economic situation. Assigning someone to a target group may already qualify. The assessment is not limited to complex artificial-intelligence models: CRM rules, scores and combined online and offline data can create a profile.

For every segment, an organisation should be able to explain which attributes are used, why they are necessary, where they came from and when they expire. Special-category data or information inferred from it cannot simply be treated as an ordinary advertising attribute. This is particularly important for political, health or other Article 9 data.

A solely automated decision producing legal effects or similarly significant effects may additionally engage Article 22 GDPR. Personalised advertising is not automatically such a decision. The threshold must not be bypassed by a formal label, however. If a score controls access, price, service or another significant opportunity, the organisation needs a deeper review, appropriate information and, where required, human intervention. For an initial assessment, profiling and automated decisions should be documented as separate review steps.

  • Document attributes, sources, exclusion criteria and segment changes.
  • Review special categories of personal data and inferred attributes separately.
  • Explain profiling and its consequences to individuals in understandable language.
  • Test models and rules regularly for outdated, unfair or unnecessary attributes.

Transparency explains the path from source to advertisement

Articles 13 and 14 GDPR require information that people can actually understand. A privacy notice should not merely name an advertising platform. It should explain which data comes from which interaction, which audiences are created, how long attributes remain and whether recipients outside the European Economic Area are involved.

When data comes from public sources, partners or enrichment providers, Article 14 GDPR must also be considered. Information should not be prepared only after a complaint. Anyone purchasing an interest list should document its origin, purpose and objection route, even if the list is used for a single campaign.

For a website visit, the privacy notice, consent dialogue and actual tag behaviour must match. A banner selecting only “marketing” while the notice lists many different purposes and providers makes an informed choice difficult. The EDPB guidance on consent provides a useful framework for clear, specific and informed choices. The governance topic shows how to connect these documents with internal responsibility.

  • Describe purposes and data categories in plain language instead of relying on product names.
  • Make direct marketing and profiling visible as separate purposes.
  • Document the origin of data and recipients for purchased or enriched lists.
  • Compare the privacy notice, consent dialogue and real network requests regularly.

Evidence makes marketing decisions reviewable

The accountability principle in Article 5(2) GDPR does not require every organisation to produce the same volume of paperwork. It must be able to show why a measure appeared lawful and how it was implemented. Depending on the measure, this includes records of processing, a legitimate-interest assessment, consent logs, provider review and the withdrawal and objection process.

A data-protection impact assessment under Article 35 GDPR should be considered where processing is likely to create a high risk, for example through large-scale systematic monitoring, sensitive data, linked sources or significant consequences of automated evaluations. That is not an automatic consequence of every analytics tool; scale, duration, systematic nature and impact matter.

A practical approach is one approval record per campaign or permanent data flow. It should contain the data-flow diagram, purpose, legal basis, notice, provider, technical activation, suppression logic, retention period and an opt-out test. Changes to tags, audiences or recipients require an updated assessment.

  • Log consent with version, selected purpose and withdrawal capability.
  • Do not reuse a legitimate-interest assessment when purpose or audience changes.
  • Include providers, sub-processors and international transfers in the approval.
  • Run samples to confirm that consent, withdrawal, suppression and deletion work.

Common errors can be prevented early

Many risks arise from small gaps between planning and operation. A tag may be classified as “essential” in a manager even though it measures reach or supports advertising. Or an objection may be stored in the newsletter system but never sent to the advertising platform.

A careful banner cannot authorise unlawful profiling in a CRM. Conversely, a good privacy notice cannot replace active choice where device access or electronic advertising requires consent. The assessment should therefore cover both the interface and the downstream systems.

  • Marketing tags load before the choice because consent mode is configured incorrectly.
  • Accept is prominent while refusal or later change is materially harder.
  • A general newsletter consent is treated as covering new purposes, recipients or profiling.
  • Profile attributes persist even though purpose, accuracy or reasonable expectations are missing.
  • Unsubscribes are recorded only in the sending tool, not in CRM, sales and platform lists.
  • The documentation describes a different data flow from the tag manager actually deployed.

A defensible review follows the real data flow

The internal review can follow a simple sequence. Describe the measure, purpose, audience and contact channel. Record source, technology, recipients and storage. Then assess legal bases and notices. Only after that should the technology be activated. Once live, test first visit, acceptance, refusal, withdrawal, objection and deletion with realistic cases.

The role check supports an initial assessment of whether the organisation is a controller, processor or joint controller. A deeper review should include contracts, tag configuration, campaign briefing, data sources and deletion and suppression periods.

If a measure is already running, changing the banner text alone is not enough. Compare the browser, consent store, tag manager, CRM, sending tool and advertising platform. This reveals whether a withdrawal or objection actually reaches the last recipient.

  • Define the campaign objective and affected group.
  • Compare the data flow and roles with the providers actually used.
  • Align legal basis, notice and consent dialogue.
  • Document tests for initial visit, acceptance, refusal, withdrawal and objection.
  • Repeat the short review after material changes with a new version.
FAQ

Frequently asked questions about marketing, cookies and tracking

May an organisation set analytics and marketing cookies without a choice? +
Non-essential cookies and comparable access generally require active, informed consent. Technically necessary access is a narrow exception. The processing of personal data must also have a suitable GDPR legal basis.
Does newsletter consent also cover profiling? +
Not automatically. Profiling is a separate processing operation with its own information and legal-basis questions. Where interests, behaviour or other attributes are inferred, the purpose, logic and consequences must be transparent and data-subject rights respected.
What must happen after an objection to direct marketing? +
The objection must be effective for the relevant direct-marketing purpose. The organisation therefore needs a reliable suppression process covering newsletters, CRM, sales and contracted platforms rather than recording the opt-out in only one system.
When should a data-protection impact assessment be considered? +
Consider one where processing is likely to create a high risk, for example through large-scale systematic monitoring, sensitive data, linked sources or significant effects of automated evaluations. An analytics tool does not automatically require an impact assessment.

Sources

BRANDaktuelle Legal News

Subscribe to legal updates

Receive new articles and legal updates from the firm through BRANDaktuelle Rechtsnews.

Subscribe to the newsletter

Make your marketing legally defensible

We review data flows, consent management, profiling and direct marketing against your actual systems. Contact us with the documents already available so that we can identify the next useful steps.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich