Austria has renewed a licence for a surveillance system built on advertising data. Nobody in government will say under what legal authority, and the data protection regulator was never asked.
A procurement notice on Austria’s public tender portal records the extension of a licence agreement between the Interior Ministry and the US vendor Penlink, worth roughly 1.85 million euros over two years. The package covers Penlink products including Webloc. Der Standard reported the deal first; netzpolitik.org followed with the ministry’s response, which was that no public information can be given about specific software solutions, and that anything the ministry uses, it uses within its legal powers.
The first half of that answer is a choice rather than a constraint. The second half cannot be verified, because the first half prevents anyone from checking it.
What makes this worth more than a paragraph of outrage is what Webloc actually is, and why the standard categories used in Austrian surveillance debate do not fit it.
What Webloc does
Webloc was built by the Israeli firm Cobwebs Technologies, acquired by Spire Capital in 2023 and merged into Penlink. It is sold as an add-on to Tangles, Cobwebs’ web and social media intelligence platform, and it is not a wiretap, not an interception system, and not spyware in the conventional sense. It never touches the target’s device.
Instead it ingests the exhaust of the mobile advertising industry. Every time a phone opens an app that shows ads, an auction runs in under a second and the user’s data is broadcast to a large number of bidding parties. Separately, tracking SDKs embedded in apps collect and sell data directly. Both streams carry a Mobile Advertising ID, a persistent identifier tied to a specific handset, alongside GPS coordinates, Wi-Fi access point names, IP address, device model, operating system, language, and in many cases the ad targeting segments used to classify the person behind the phone.
Citizen Lab’s April 2026 analysis, based on leaked contract documents from El Salvador, technical specifications from Vietnam, US Navy procurement records and Penlink material from 2025, describes a system with access to a continuously updated stream from up to 500 million devices worldwide, refreshed every four to twenty-four hours, with three years of history available for query.
The interface is what matters. An analyst can draw a polygon on a map and retrieve every device observed inside it during a time window. They can intersect two polygons to find devices present in both, which surfaces people who travelled between two places. They can set alerts for new devices entering a monitored area. They can run a heat map on a single identifier to infer home address and workplace, which the vendor documentation treats as the expected workflow rather than an edge case. One example screen in the leaked material tracks a person moving from Germany through Austria into Hungary. Another resolves a single device to a specific building, rendered in Street View.
Note what this means structurally. Even when the target is one person, the query runs against everyone. A geofence around an address returns the neighbours. A geofence around a mosque, a clinic, a union hall or a newsroom returns whoever was there. The distinction between targeted and mass surveillance, which does most of the load-bearing work in Austrian legal argument about the SNG and the Constitutional Court proceedings on messenger surveillance, does not survive contact with this architecture. The Vienna-based tracking researcher Wolfie Christl put it plainly: even used against individuals, the system collects and analyses data on millions of uninvolved people every day.
Two legal questions, neither answered
There are two separate lawfulness problems here and they are routinely collapsed into one.
The first concerns the supply chain. Location data harvested from consumer apps under a consent banner about advertising, then sold onward through data brokers to a surveillance vendor, then sold to a state intelligence service, is being processed for a purpose no user ever agreed to. Christl’s position is that consent is effectively the only conceivable GDPR basis for such a transfer, and that no party in the chain holds valid consent for state surveillance. Germany’s consumer protection ministry took a comparable line in 2024, arguing that transferring personal data as a commodity in itself is incompatible with data protection law. The claim in Penlink’s older documentation that collection is GDPR compliant and consent-based rests on the same fiction the entire ad-tech sector rests on.
The second concerns the buyer. Even assuming the data existed lawfully, the Interior Ministry would need a domestic legal basis to acquire and query it. Purchasing commercially available data is a well-known route around the warrant requirement precisely because it does not look like a search. Nothing is intercepted, no device is compromised, no court is asked. In the United States, seventy-two members of Congress called in March 2026 for an investigation into warrantless location data purchases by ICE and other agencies, and an internal DHS review in 2023 already found that several DHS components had broken federal law through such purchases.
Austria has answered neither question. The ministry’s response to netzpolitik.org gestured at extremist and terrorist offences and indicated the Directorate for State Protection and Intelligence Service as the responsible body, which tells us the intended use case without telling us the authority for it.
The oversight gap is the actual scandal
The Austrian data protection authority told netzpolitik.org that it has no closer knowledge of the ministry’s planned use of the software and was not consulted. Under the GDPR, prior consultation with the supervisory authority is required where a data protection impact assessment identifies a high residual risk.
Work through the possibilities. Either the ministry conducted an impact assessment on a system that queries commercial location data covering hundreds of millions of people and concluded there was no high risk, or it did not conduct one. Both are difficult to defend. The regulator has kept the door open, noting it can examine compliance at any time through a complaint or an own-initiative review. It has not said it will.
Meanwhile the transparency record is instructive. Citizen Lab sent ninety-six freedom of information requests across fourteen European countries and six EU bodies. Austrian ministries, alongside Dutch and Romanian ones, declined to say whether they use Webloc. Europol confirmed holding relevant information and refused to release it. Not a single European agency confirmed use. Austria’s participation only became known because a procurement document sat in a public tender portal. Green MP Süleyman Zorba, who had previously been told that any disclosure would endanger national security, has made the obvious point that the deployment is now documented in public award records.
Austria is, on current evidence, the second confirmed ad-based surveillance customer in the EU after Hungary, where domestic intelligence has been using Webloc since at least 2022 and bought a fresh licence round in March 2026.
Mission creep is not hypothetical
The reassurance offered in these debates is always that the tool is reserved for terrorism, extremism and organised crime. There is now a documented answer to that.
Tucson police in Arizona acquired Tangles and Webloc for sex trafficking investigations, funded from a state border security programme. An internal report obtained by journalists describes the department using the system to investigate burglary, robbery and the theft of several thousand dollars of cigarettes, running advertising ID queries across crime scene areas to locate a suspect’s workplace, his former girlfriend and the apartment the identifiers kept returning to. The same system was used to monitor protests during campaign visits by presidential and vice-presidential candidates.
That is the empirical trajectory of a capability that is fast, cheap, warrantless and sitting on an analyst’s desk. Nothing about Austrian institutional culture makes it immune, and the current absence of any published control regime makes it less protected than the American departments where at least the procurement records are litigated.
The counterintelligence problem nobody is discussing
There is a dimension to this that civil liberties framing misses, and it should concern Austrian security professionals more than it currently does.
If the Interior Ministry can buy access to a stream covering hundreds of millions of devices, so can anyone else with a budget and a front company. The data does not become available only to lawful buyers. It is a commercial product moving through an opaque broker layer, and the same bidstream that produces Webloc produces competitor systems from other vendors, some of them in jurisdictions with no meaningful export control on this category.
Vienna hosts the IAEA, UNODC, the OSCE, OPEC and a large diplomatic corps. It is one of the densest concentrations of intelligence-relevant personnel in Europe. Every one of those people carries a phone running apps with embedded tracking SDKs. A geofence around the Vienna International Centre, a ministry, an embassy or a safe house is a commercially purchasable product. Pattern of life on a named official requires only linking one identifier, and advertising IDs are routinely matched to names, addresses and phone numbers by the same industry that insists they are anonymous. The US Federal Trade Commission has stated directly that these identifiers provide no anonymity in the marketplace.
A state that normalises the purchase of this data for its own investigations has a weaker position from which to argue that the market should not exist. That is a counterintelligence cost, not just a privacy cost, and it is being incurred without public debate.
What should happen next
Three things are reasonable to demand, and none of them require accepting or rejecting the underlying capability.
Publish the legal basis. Not the operational detail, not the target selection, just the statutory provision under which commercially sourced location data may be acquired and queried, and which oversight body approves individual queries.
Have the data protection authority open an own-initiative review. The question of whether the underlying processing is lawful is squarely within its mandate and does not depend on the ministry’s cooperation.
Treat ad-based tracking as a defensive problem. For anyone in Austria handling sensitive material, the mitigation is unglamorous and available today: reset advertising identifiers regularly or disable them entirely, deny location permission to any app that does not require it for its core function, and remove ad-supported apps from devices used for sensitive travel. This is not a substitute for regulation. It is what can be done while regulation does not exist.
Sources
- Wolfie Christl, Astrid Perry, Luis Fernando Garcia, Siena Anstis and Ron Deibert, “Uncovering Webloc: An Analysis of Penlink’s Ad-based Geolocation Surveillance Tech,” Citizen Lab Report No. 191, University of Toronto, 9 April 2026
- Sebastian Meineck, netzpolitik.org, 30 June 2026
- Der Standard, reporting on the Interior Ministry procurement record
- VSquare, Szabolcs Panyi, on Hungarian intelligence use of Webloc, April 2026
- Austrian federal procurement portal, tender award documentation
