Faultline Faultline Kommando 161

Germany · de.indymedia · · 59m

Austria: Security authorities can be spied on using advertising data

Deutsch (original) · Auto-translated to English

Symbolbild · Leonhard Lenz / CC0 · Wikimedia Commons

New research demonstrates the risk that location data from the online advertising industry poses to Austria's security. Thanks to data brokers, journalists were able to understand several sensitive movement profiles. While the government is stonewalling, Austrian security authorities are using such data themselves.


https://cdn.netzpolitik.org/wp-upload/2026/09/Gerhard_Karner_2-scaled-e1...class="attachment-landscape-860 size-landscape-860 wp-post-image" alt="An elderly person with very short hair, frameless glasses and a suit smiles into the camera" decoding="async" loading="lazy" srcset="https://cdn.netzpolitik.org/wp-upload/2026/09/Gerhard_Karner_2-scaled-e1...2560w,https://cdn.netzpolitik.org/wp-upload/2026/09/Gerhard_Karner_2-scaled-e1...860w,https://cdn.netzpolitik.org/wp-upload/2026/09/Gerhard_Karner_2-scaled-e1...1200w,https://cdn.netzpolitik.org/wp-upload/2026/09/Gerhard_Karner_2-scaled-e1...380w,https://cdn.netzpolitik.org/wp-upload/2026/09/Gerhard_Karner_2-scaled-e1...1536w,https://cdn.netzpolitik.org/wp-upload/2026/09/Gerhard_Karner_2-scaled-e1...2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" />
Austria's Interior Minister Gerhard Karner doesn't like to talk about surveillance using advertising data. –http://creativecommons.org/licenses/by-sa/3.0/deed.de">CC-BY-SA3.0:https://commons.wikimedia.org/wiki/File:Gerhard_Karner_2.JPG">AleXXw

It is shockingly detailed information that journalists from thehttps://www.news.at/investigativ/smartphone-spionage-geheimdienst-leak">Austrian news magazinewere able to find out about employees of the Austrian security apparatus: where they live and work, which doctors they visit, which hairdresser they go to, where they shop or which cemetery they regularly visit a grave. This is possible thanks to location data that was supposedly collected only for advertising purposes, but was then offered by data brokers.


Those affected include a suspected employee of the Army Intelligence Office (HNaA), which is Austria's military foreign intelligence service, a suspected employee of the Interior Ministry's Directorate of State Security and Intelligence (DSN) and a suspected police dog handler from Burgenland. In total, the journalists evaluated movement data on presumably more than 500,000 smartphones from autumn 2024.


A new form of mass surveillance


The data comes from the US data broker Datastream Group, which has since renamed itself Datasys. For the research, netzpolitik.org and Bayerischer Rundfunk provided the News colleagues with relevant data and a specially developed analysis tool. We have been reporting under this name since summer 2024http://netzpolitik.org/databroker-files/">DatabrokerFilesabout the uncontrolled trade in location data from the online advertising industry and showed, among other things, how German security authorities, high-ranking EU personnel and also US military locations can be spied on in this way.


Tracking companies collect location data, some of which is accurate to the meter, via apps on smartphones. Supposedly they only do this for advertising purposes, but they dohttps://netzpolitik.org/2025/databroker-files-im-dschungel-der-datenhaen...winding pathsThe data also ends up on a large scale with data traders. Anyone can potentially buy it there. The database from netzpolitik.org and the BR, which now includes more than 13 billion locations, is free sample data sets from several providers. This new form of mass surveillance could potentially target anyone with ad-supported apps on their phones.


There have been warnings for some time that the availability of such comprehensive movement profiles can help to monitor, compromise, blackmail or poach people from the security apparatus. Several private companies offer the processing of advertising data for government customers, this is also referred to ashttps://netzpolitik.org/2024/databroker-files-adint-gefaehrliche-spionag...“advertising-based intelligence”, ADINT for short. So in German: advertising-based education.


Austrian authorities use advertising data themselves


What is piquant is that Austrian security authorities themselves are among the customers of such providers. Only a few months ago it became known that the Ministry of the Interior therehttps://netzpolitik.org/2026/millionendeal-mit-ueberwachungsfirma-regier...for a monitoring software called Weblocwhich is based on massively recorded cell phone tracking. This was shown by a document from a public procurement portal, which was first usedhttps://www.derstandard.at/story/3000000329055/was-macht-das-innenminist...standardhad reported.


“In my view, this type of surveillance without judicial control is a complete fundamental rights disaster,”https://www.news.at/investigativ/innenministerium-ueberwachung-smartphon...Viennese tracking researcher Wolfie Christl reported the research to News. Christl is currently conducting research togetherhttps://citizenlab.ca/research/analysis-of-penlinks-ad-based-geolocation...the Citizen Lab at the University of Torontoto the ADINT industry and had revealed with others at the beginning of the year that security authoritieshttps://netzpolitik.org/2026/vor-schicksalswahl-orban-regierung-soll-neu...Hungary and El SalvadorHave purchased licenses for Webloc. Those toohttps://netzpolitik.org/2026/us-einmigrationsbehoerde-mit-palantir-und-p...ICE deportation militiauses the monitoring tool.













We free documents.
For your basic rights.




Join now










Webloc was developed by the Israeli surveillance company Cobweb, which has since been acquired by the US company Penlink. The program is also intended to inform authorities about the age and gender of smartphone users. There is also information about which advertising target groups users are classified into, which can allow conclusions to be drawn about the target person's marital status, hobbies, psychological characteristics or political affinities.


Doubts about legality


The Austrian lawyer Philipp L. Leitner expressed doubts to News about the legality of the Austrian state's use of data. In Germany there are also concerns about the use of ADINT by security authorities, among other thingshttps://netzpolitik.org/2025/sicherheitsbehoerden-und-databroker-bundesr...the Federal Data Protection Commissioner and the Scientific Services of the Bundestag.


A basic problem: Tracking companies usually collect the data illegally. Although many users agree to the use of their data for advertising within the framework of the apps' data protection regulations, the consents are usually invalid because the users are not informed about where their data actually ends up. Data protection officers also consider trading in data collected for advertising purposes to be fundamentally incompatible with the purpose limitation principle of the General Data Protection Regulation.


Security authorities may also be allowed to use illegally collected data under certain circumstances, but there are strict limits. In Austria, provisions of the State Security and Intelligence Service Act could be considered as a legal basis, lawyer Leitner told News. However, a general authority to carry out area-wide surveillance of the population without cause cannot be derived from this.


In Germany, advertising data has already been collected according to research by netzpolitik.org and the BRhttps://netzpolitik.org/2026/daten-schwarzmarkt-deutsche-polizei-nutzt-o...used at least one state criminal investigation office. German secret services probably also use ADINT. The constitutional lawyer Peter Schantz recently called for constitutional regulationhttps://netzpolitik.org/2026/aufruestung-der-geheimdienste-innenminister...framework of the current intelligence reform.


Interior Ministry wants to protect secret services with “awareness measures”.


According to News, the public prefers not to inform the Austrian government in detail about the monitoring of advertising data. In response to a question from the Green National Council member Süleyman Zorba, Interior Minister Gerhard Karner (ÖVP) responded at the end of 2025 that detailed answers would “run counter to the security interests of the Republic of Austria”. The issue could be discussed in the Standing Subcommittee of the Internal Affairs Committee, which meets in secret.


The Interior Ministry also only briefly answers questions from news journalists. However, it emphasizes that there is no unfounded mass surveillance by ADINT. Such tools are only used “targeted” and “in specific cases” by “specialized professionals,” according to News. However, this does not change the self-created dilemma that it is our own security authorities that use taxpayers' money to purchase services that are based on allegedly illegally collected data and that threaten the security of the country and the privacy of millions of people.


The answers to News Magazine's questions about what the authorities are doing to protect their own people are correspondingly helpless. The Interior Ministry, which includes the State Security and Intelligence Directorate, says that the security authorities are aware of the danger posed by ADINT. At DSN, employees receive ongoing training in the areas of information and cyber security. “In addition, appropriate awareness measures are taken to minimize the risk of employees being identified and assigned.”

–––

The work of netzpolitik.org is financed by donations from our readers.
Become part of this unique community and support our public interest-oriented, advertising- and tracking-free journalismhttps://netzpolitik.org/spenden/?via=rss">nowwith a donation.

–––


The Ministry of Defense, which includes the foreign intelligence service HNaA, responded to the journalists by saying that it was taking into account “the security risks associated with the increasing commercial availability of location and movement data.” Therefore, organizational and technical “measures for the safe use of mobile devices and to reduce the associated data exposure” would be taken. There are no more concrete answers.


Waiting for political consequences


The problem is felt worldwide. The US Department of Defense is also facing the same dilemma. There is currently a debate there about whether ADINT data could have been used by Iran to target US troops in the Persian Gulf. After bipartisan pressure from a group led by Democratic US Senator Ron Wyden, the Pentagon has now ordered that on US military equipmenthttps://www.reuters.com/business/media-telecom/us-military-turns-off-ad-...and corresponding advertising identification numbers deactivatedbecome.


In Germany and Europe, shocked politicians' reactions to the data broker revelations from netzpolitik.org, BR and partner media have so far not had any political consequences. Also the EU Commission, which will meet in autumn 2025https://netzpolitik.org/2025/databroker-files-datenhaendler-verkaufen-me...“very worried”showed, left it at that so far,https://netzpolitik.org/2025/nach-databroker-files-rundmail-warnt-eu-ang...to your own staffto send. A law that was actually announced for 2026 and is intended to close gaps in the EU's digital consumer protection, the Digital Fairness Act, is not yet in sight.


According to our reporting, data protection authorities in Germany havehttps://netzpolitik.org/2026/wegen-handy-standortdaten-wetter-online-dro...Appsinto thehttps://netzpolitik.org/2026/nach-unseren-recherchen-datenschutzbehoerde...taken, to whom they were able to prove suspected unlawful data transfer. However, there has so far been no large-scale action against the industry.


Organizations like the Federal Association of Consumer Organizations and the Chaos Computer Club are therefore calling for a radical solution: Thishttps://netzpolitik.org/2024/databroker-files-us-senator-schaltung-pentag...Essential ban on profiling and data tradingfor commercial purposes orhttps://netzpolitik.org/2024/digital-fairness-act-eu-gesetz-soll-interne...personalized advertising.


–––

The work of netzpolitik.org is financed by donations from our readers.
Become part of this unique community and support our public interest-oriented, advertising- and tracking-free journalismhttps://netzpolitik.org/spenden/?via=rss">nowwith a donation.

https://vg03.met.vgwort.de/na/0bd63a8fced84fa7a7c742900d766882"width="1" height="1" alt>

web address: https://netzpolitik.org/2026/oesterreich-sicherheitsbehoerden-lassen-sich-mit-werbedaten-auspionieren/Author/Group: Ingo DachwitzTopics: Netactivismfeed date: Thursday, September 24, 2026 - 6:00 p.m

Read the full story at the source

Source: de.indymedia