Austria
Austria Data Privacy Laws: GDPR & DSG Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 13 primary sources cited on this page. How we verify our legal content

Austria's data privacy rules derive from two sources: the EU General Data Protection Regulation (Regulation 2016/679), which has applied directly since May 2018, and the national Datenschutzgesetz (DSG), last amended by the Informationsfreiheits-Anpassungsgesetz (BGBl. I Nr. 50/2025) with effect from 1 September 2025, which fills gaps through the GDPR's 69 opening clauses. The Datenschutzbehörde (DSB) supervises compliance.
Austria's Data Protection Legal Framework
Austria's approach to data privacy rests on two pillars. Regulation (EU) 2016/679 (the GDPR), which took direct effect across the EU on May 25, 2018, provides the primary regulatory framework. The Datenschutzgesetz (DSG), most recently amended in 2025 by the Informationsfreiheits-Anpassungsgesetz (BGBl. I Nr. 50/2025), fills the spaces where the GDPR allows national variation.
The current DSG replaced the Datenschutzgesetz 2000, which itself succeeded Austria's original 1978 data protection statute. That 1978 law was notable for establishing a constitutional right to data protection, a provision that still anchors the modern framework.
Under Section 68(1) DSG, the Federal Minister of Justice (Bundesministerin für Justiz) is charged with executing the DSG, alongside the Federal Chancellor and the other federal ministers within their own remits. The independent Datenschutzbehörde (DSB) handles supervision and enforcement. The Telecommunications Act 2021 (Telekommunikationsgesetz, or TKG 2021) adds another layer by governing cookies, electronic marketing, and communications privacy.
Since the DSG's 2018 overhaul, it has been revised in January 2019 (BGBl. I Nr. 14/2019), June 2024 (BGBl. I Nr. 62/2024), July 2024 (BGBl. I Nr. 70/2024) and most recently by the Informationsfreiheits-Anpassungsgesetz (BGBl. I Nr. 50/2025).
The 2025 amendment rewrote Sections 17(8), 22(3) and 23(2) with effect from 1 September 2025. It ties the confidentiality of information the DSB obtains in its supervisory work to the grounds in Section 6(1) of the Informationsfreiheitsgesetz (BGBl. I Nr. 5/2024).
The July 2024 amendment established the Parlamentarisches Datenschutzkomitee (Parliamentary Data Protection Committee), which has exercised its competences over the legislative bodies since 1 January 2025 under Section 69(10) DSG. The consolidated text on ris.bka.gv.at is current to 10 September 2026.
For a broader EU-level context, see our guide to EU data privacy laws. For Austria's recording consent rules, see Austria recording laws.
Jurisdiction scope: This article addresses data privacy law in Austria under the GDPR as directly applicable EU law, the Austrian Datenschutzgesetz (DSG), and related national instruments including the TKG 2021. It does not address sector-specific privacy rules outside data protection (e.g., banking secrecy, medical confidentiality) except where they interact with the DSG.

The Constitutional Right to Data Protection
What sets Austria apart from most EU member states is Section 1 of the DSG. This provision carries constitutional rank, meaning it can only be amended with a two-thirds parliamentary majority.
Section 1 guarantees everyone a right to secrecy of personal data, particularly with regard to private and family life, provided there is a legitimate interest. The word "everyone" is significant. Unlike the GDPR, which protects only natural persons, Austria's constitutional data protection right extends to legal persons as well, including companies, associations, and other entities.
In 2018, the government attempted to abolish this constitutional provision through the Datenschutz-Anpassungsgesetz (Data Protection Adjustment Act). The effort failed when it could not secure the required two-thirds majority in the National Council. The constitutional right to data protection has therefore remained continuously in effect since 1978, making Austria one of the earliest countries in the world to enshrine data protection at a constitutional level.
This constitutional status means that any Austrian law that interferes with the right to data protection can be challenged before the Constitutional Court (Verfassungsgerichtshof, or VfGH), adding a judicial check that exists beyond the GDPR framework. The VfGH remains active in this role. In the Austrian Postal Service case (see below) the company brought a constitutional complaint against its fine, and the VfGH declined to take it up on 9 December 2025 (E 335/2025-19). The Administrative High Court then settled the case in June 2026.

The Datenschutzbehörde (DSB): Austria's Supervisory Authority
The DSB replaced the former Datenschutzkommission on January 1, 2014, and operates as an independent authority from its headquarters in Vienna. It has jurisdiction over all public and private entities processing personal data in Austria.
Structure and Powers
The DSB handles complaints from data subjects, conducts investigations, issues administrative fines, and provides guidance on data protection compliance. It participates in the European Data Protection Board (EDPB) alongside supervisory authorities from all EU member states.
The authority's powers include ordering controllers and processors to comply with GDPR requirements, imposing temporary or definitive bans on data processing, ordering the rectification or erasure of personal data, and imposing administrative fines under Article 58(2)(i) and Article 83 GDPR in conjunction with Section 22(5) DSG, and, subsidiarily, national fines under Section 62 DSG.
Limits on Refusing Complaints: CJEU C-416/23
On January 9, 2025, the CJEU ruled against the DSB in case C-416/23. The DSB had refused, under Article 57(4) GDPR, to act on a complaint from a person who had lodged 77 similar complaints against different controllers in roughly 20 months.
The Court held three things. Requests under Article 57(4) GDPR include complaints made under Article 77(1). Requests cannot be classified as excessive on the strength of their number in a given period alone, because the authority has to demonstrate an abusive intention on the part of the person making them. And where requests genuinely are excessive, the authority may choose, by reasoned decision, either to charge a reasonable fee based on administrative costs or to refuse to act, provided the option it picks is suitable, necessary and proportionate.
The judgment therefore does not bar the DSB from turning away abusive complaints. It sets the evidential bar the authority has to clear first. The DSB now puts complainants on notice when it considers a complaint abusive, warning that it may refuse to act or charge a fee under Article 57(4) GDPR unless a further justification follows.
The Budget Crisis
Austria's data protection enforcement faces a structural problem. The DSB operates on a 2026 budget of EUR 5.9 million, down from EUR 6.1 million in 2025 and up from EUR 5.7 million in 2024. At the end of 2025 it had 58 staff in total: 43 contract staff, 6 civil servants, 5 administrative interns and 4 agency workers. Germany, by comparison, spends roughly double per capita on its data protection authorities.
The administrative interns are funded from material expenses rather than the permanent staff budget, and they turn over on a fixed cycle. That creates a revolving door which drains institutional expertise and imposes continuous training costs. The 2025 cuts fell mainly on material expenses, so from July 2025 the DSB could not refill most of its intern posts, of which it had around 20 in full and part time during that year.
The resource constraints are worsening: individual domestic complaints rose from 2,389 in 2023 to 3,019 in 2024 and 5,300 in 2025. The authority announced it would stop issuing legislative opinions except in "exceptional cases" and would only launch self-initiated investigations where submissions indicate a "sufficiently concrete suspicion of serious violation."
On September 18, 2025, epicenter.works and noyb filed a formal complaint with the European Commission, arguing that Austria violates Article 52(4) of the GDPR, which requires member states to provide adequate resources to their supervisory authorities. The Commission has the power to initiate infringement proceedings against Austria in response.
Enforcement Statistics
Complaint volume and penalty proceedings are separate counts, and they are easy to run together. In 2025 the DSB received 5,300 individual domestic complaints and closed 3,403 of them, 2,332 by decision and 1,071 by discontinuance. Separately, it opened 127 administrative penalty proceedings and closed 143, issuing 75 decisions of which 58 were fines totalling about EUR 145,000. Only 10 of those penalty decisions were appealed.
Enforcement in euro terms fell sharply. In 2024 the DSB closed 214 penalty proceedings and issued 73 decisions, 62 of them fines totalling EUR 1,684,230. Many proceedings still run past the six-month deadline in Section 73 of the Allgemeines Verwaltungsverfahrensgesetz (AVG), and some take years.
The DSB's 2025 Schwerpunktprüfung (thematic audit) covered every regional police directorate (Landespolizeidirektion), checking compliance with the GDPR and with Chapter 3 of the DSG, which implements Directive (EU) 2016/680. The EDPB's coordinated 2025 topic, erasure and retention periods, was folded into it. Those audits have been concluded and the DSB reported no objections. It has announced further thematic audits for 2026.

Lawful Bases for Processing Personal Data
All processing of personal data in Austria must satisfy two conditions: it must comply with the general data processing principles of Article 5 GDPR, and it must rest on one of the six lawful bases in Article 6 GDPR.
The Six Lawful Bases (Article 6 GDPR)
-
Consent (Art 6(1)(a)): The data subject has given freely given, specific, informed, and unambiguous consent. Consent must be as easy to withdraw as to give, and it may not be bundled with the acceptance of general terms and conditions where the processing is not necessary for the contract.
-
Contractual necessity (Art 6(1)(b)): Processing is necessary for performing a contract with the data subject or taking pre-contractual steps at their request.
-
Legal obligation (Art 6(1)(c)): Processing is necessary to comply with a legal obligation under Austrian or EU law.
-
Vital interests (Art 6(1)(d)): Processing is necessary to protect the life of the data subject or another natural person.
-
Public task (Art 6(1)(e)): Processing is necessary for a task carried out in the public interest or in the exercise of official authority.
-
Legitimate interests (Art 6(1)(f)): Processing is necessary for the legitimate interests of the controller or a third party, except where overridden by the data subject's interests or fundamental rights. Public authorities cannot rely on legitimate interests as a lawful basis when acting in their official capacity.
Special Categories of Data (Article 9 GDPR)
Processing of special categories of personal data (revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or sex life or sexual orientation data) is prohibited unless one of the Article 9(2) GDPR exceptions applies. Key exceptions include explicit consent, employment and social security law obligations, vital interests, data made public by the subject, legal claims, and scientific or historical research under Article 89.
Consent in Austrian Practice
The DSB requires that consent be genuinely free. The August 2025 ruling against DerStandard.at illustrates this: the Federal Administrative Court held that the newspaper's "Pay or Okay" model (requiring users to either consent to tracking or pay a monthly subscription of EUR 9.90) did not constitute valid consent because it lacked granularity. Users could not consent to specific types of processing separately; they could only give or withhold global consent. The court stopped short of ruling that pay-or-consent is inherently impermissible, but found that any implementation must allow category-by-category consent choices.
Data Subject Rights
The GDPR grants data subjects a comprehensive set of rights. Austria implements these without significant restriction, with the exception that requests deemed manifestly unfounded or excessive may attract a reasonable fee or be refused under Article 12(5) GDPR.
Right of Access (Article 15 GDPR)
Data subjects may request confirmation of whether their personal data is being processed and, if so, obtain a copy of that data along with information about the purposes, categories, recipients, retention periods, and the existence of automated decision-making. Controllers must respond within one month, extendable by a further two months where requests are complex or numerous.
The DSB's 2024 thematic audit covered ten telecom-sector companies and examined the Article 5 principles, security measures, third-country transfers and the position of the data protection officer. The EDPB's coordinated 2024 topic, the Article 15 right of access, was folded into the same questionnaire. The DSB reported that its suggestions were implemented, that no order was needed and that the overall result was positive. Separately, in a 2024 penalty decision the DSB fined a controller EUR 15,200 for failing to respond to its requests for comment across five complaint proceedings and for late compliance with an order to grant Article 15 access. On 10 March 2025 the Federal Administrative Court upheld that penalty in principle but reduced the fine to EUR 10,000 and added EUR 1,000 in costs (W287 2286005-1).
Right to Rectification (Article 16 GDPR)
Data subjects may demand correction of inaccurate personal data and completion of incomplete data.
Right to Erasure (Article 17 GDPR)
The right to erasure ("right to be forgotten") applies when data is no longer necessary for its original purpose, consent is withdrawn and no other lawful basis exists, an objection is upheld, or the data was unlawfully processed. Austria's DSG Section 4(2) provides one national modification: where rectification or erasure of automated data cannot be carried out immediately because it is only possible at set times for economic or technical reasons, the controller must restrict processing of that data with the effect of Article 18(2) GDPR until then. The delay is permitted. Leaving the data in normal use during it is not.
Right to Restriction (Article 18 GDPR)
Data subjects may request that processing be restricted while accuracy is contested, a lawful basis for processing is disputed, or an objection is pending.
Right to Data Portability (Article 20 GDPR)
Where processing is based on consent or contract and carried out by automated means, data subjects may receive their personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
Right to Object (Article 21 GDPR)
Data subjects may object at any time to processing based on legitimate interests or public task grounds. The controller must demonstrate compelling legitimate grounds overriding the individual's interests. Processing for direct marketing purposes must stop unconditionally on objection.
Rights Related to Automated Decision-Making (Article 22 GDPR)
Data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. Controllers must offer at minimum: the right to obtain human review, the right to express their point of view, and the right to contest the decision.
The DSB's September 2025 decision against KSV1870 shows how the authority reads this right. The DSB found that KSV1870, a major Austrian credit information agency, used fully automated scoring to inform a credit decision by energy supplier Unsere Wasserkraft, that this was prohibited automated individual decision-making under Article 22 GDPR, and that both companies had breached their transparency duties. It barred KSV1870 from running such automated checks on the complainant's data without consent and ordered both companies to explain the logic of their decision. The decision is a first-instance DSB decision, open to appeal to the Federal Administrative Court, and was reported as not final.
Austrian-Specific GDPR Derogations
Austria has exercised several of the GDPR's opening clauses to tailor data protection rules to national circumstances. These derogations represent the areas where Austrian law differs from the baseline GDPR.
Child Consent (Section 4(4) DSG)
The GDPR sets a default age of 16 for a child to consent to information society services (such as social media platforms), but allows member states to lower this to as young as 13. Austria set the threshold at 14 years old under Section 4(4) DSG. Children under 14 need parental consent before signing up for online services.
Video Surveillance (Sections 12-13 DSG)
Austria maintains specific rules for CCTV and video surveillance that go beyond the GDPR's general framework. The operative rule is Section 12(2) Z 4 DSG: image capture is permitted where overriding legitimate interests of the controller or a third party exist in the individual case and the measure is proportionate.
Section 12(3) then lists three situations in which that test is expressly ("insbesondere") taken to be met: preventive protection of people or property on private land used only by the controller, preventive protection at publicly accessible places subject to the controller's house rules where rights have already been infringed or the nature of the place carries a particular risk, and a private documentation interest not aimed at identifying uninvolved people. Those three are examples, not a closed list, so a camera outside them is not automatically unlawful.
Section 12(4) puts four things outside the rules altogether: capture of a person's most private sphere without express consent, capture for the purpose of monitoring employees, automated matching of image data and profiling without express consent, and evaluation by the special-category criteria in Article 9 GDPR.
Section 13 sets the operating duties: signage identifying the controller, security measures, logging of each processing operation outside real-time monitoring, and deletion once the purpose lapses. Retention beyond 72 hours must be proportionate and has to be separately logged and justified. Under Section 9(1) Z 2 DSG, Sections 12 and 13 do not apply to processing for journalistic purposes.
Timing of Erasure and Rectification (Section 4(2) DSG)
The DSG includes a practical modification to the GDPR's right to erasure. Under Section 4(2) DSG, immediate deletion or correction is not required when, for economic or technical reasons, it can only be carried out at certain scheduled times. This is not free breathing room. For the whole interim period the controller must restrict processing of the affected data with the effect of Article 18(2) GDPR. Section 4(4) DSG is a different provision: it carries the age-14 consent rule.
Journalistic Processing (Section 9 DSG)
Austria used to run a blanket media privilege. It no longer does. BGBl. I Nr. 62/2024 replaced Section 9(1) DSG in full with effect from 1 July 2024. The provision is now headed "Freiheit der Meinungsäußerung und Informationsfreiheit" (freedom of expression and freedom of information), and it states that the GDPR and the DSG apply to journalistic processing by media owners, publishers, media staff and contracted journalistic contributors "mit folgenden Maßgaben", meaning subject to the thirteen itemised modifications that follow.
The main ones: a data protection editorial privilege built on Section 31 of the Media Act (Z 1); permission to process Article 9 and Article 10 data for journalistic purposes, with Sections 12 and 13 DSG disapplied (Z 2); the transparency limb of Article 5(1)(a) softened where full traceability would disproportionately impair freedom of expression (Z 3); Articles 13, 14 and 21(1) disapplied outright (Z 4); a narrowed right of access that does not reach unpublished material, requires the applicant to name the publication and explain how they are affected, allows a fee of EUR 9 and excludes the right to a copy under Article 15(3) (Z 5); Articles 16, 17 and 18 disapplied in defined cases (Z 6), with a right to have the DSB review a refusal (Z 7); breach notification under Article 33 only where the breach is likely to result in a high risk (Z 9); no Chapter V obligations for third-country transfers, subject to a duty to take appropriate protective measures (Z 11); and no lead-authority or consistency mechanism under Article 56 and Chapter VII (Z 13).
What survives matters as much as what is switched off. The Article 5 principles apply, and so do the processor, confidentiality and security duties in Articles 28, 29 and 32. Section 9(1a) extends a reduced set of these rules to journalistic processing outside media undertakings, which is the provision the DSB applied to citizen journalism in a February 2025 decision. Section 9(2) is a separate carve-out for processing for scientific, artistic or literary purposes, and it does disapply most of the GDPR apart from Article 5 and Articles 28, 29 and 32.
Research Exemption
Austria amended its Research Organisational Act (Forschungsorganisationsgesetz, or FOG) to include broad waivers from GDPR requirements for scientific research under Article 89 of the GDPR. These exemptions allow researchers to process personal data with fewer restrictions, though they have drawn scrutiny for potentially exceeding the intended scope of the GDPR's research derogations.
Public Authority Fine Exemption
Under the DSG, public authorities are exempt from administrative fines. This does not mean they escape accountability entirely. As the 2024 City of Baden case demonstrated, public bodies remain liable for civil damages to affected individuals.
The Google Analytics Ruling: A Landmark Decision
In a partial decision published by noyb on January 13, 2022, the DSB issued what became the first decision in the EU holding that the standard use of Google Analytics violates the GDPR. The case originated from one of 101 model complaints filed by noyb following the CJEU's Schrems II decision in July 2020, which invalidated the EU-US Privacy Shield.
The DSB's Analysis
The DSB examined whether the supplementary measures Google had implemented were sufficient to protect transferred data from US government surveillance. The authority found all of them insufficient. Google, as a US-based electronic communication service provider, is subject to Section 702 of the Foreign Intelligence Surveillance Act (FISA) and Executive Order 12333. Under these laws, US intelligence agencies can compel Google to hand over data. Google's encryption does not prevent this access because Google itself holds the decryption keys. The DSB also rejected the argument that IP address truncation prevented re-identification.
On April 22, 2022, the DSB issued a follow-up decision reaffirming its position and specifically rejecting a "risk-based approach" to international data transfers. Organisations cannot argue that the low probability of US surveillance excuses non-compliance with Chapter V of the GDPR.
Current Status
The EU-US Data Privacy Framework (DPF), adopted in July 2023, provides a new adequacy basis for transfers to certified US organisations. Google LLC participates in the DPF. Organisations using Google Analytics in Austria should verify that Google maintains its DPF certification and review their specific implementation. The DSB's established posture on supplementary measures means that transfers outside the DPF framework continue to face the same strict analysis applied in the 2022 decisions.
Notable Enforcement Actions and Fines
Austrian Postal Service (Österreichische Post AG)
The most significant enforcement case in Austrian data protection history involves Österreichische Post AG. In October 2019, the DSB imposed a fine of EUR 18 million after discovering that the postal service had compiled data on the political affinity of individually identified persons through statistical modelling and marketed this information to political parties.
The Postal Service had used its address database to assign estimated political preferences to individual customers and sold this profiling data, along with information about customers' relocation frequency and parcel delivery volumes.
The Austrian Postal Service appealed to the Federal Administrative Court (Bundesverwaltungsgericht, or BVwG). The BVwG initially overturned the fine on a procedural ground. After the DSB appealed to the Administrative High Court (VwGH) and the VwGH awaited the CJEU's Deutsche Wohnen ruling on fault attribution, the BVwG decided again on December 27, 2024 (W258 2227269-1) and set the fine at EUR 16 million.
The case is now closed. The Postal Service took a constitutional complaint to the VfGH, which declined to hear it on December 9, 2025 (E 335/2025-19). On June 24, 2026 the VwGH decided the matter itself in Ro 2025/04/0007. It upheld the finding on party affinities, discontinued the proceedings on several other counts, and set the fine at EUR 13,000,000 under Article 83(5)(a) in conjunction with Article 83(3) GDPR, plus a EUR 100,000 contribution to the costs of the proceedings. The total payable is EUR 13,100,000, and that figure is final.
KSV1870 Automated Credit Scoring (September 2025)
In a decision reported on September 26, 2025, the DSB found that Austrian credit agency KSV1870 had unlawfully used fully automated scoring in a credit decision by energy provider Unsere Wasserkraft. The DSB treated the automated calculation and transmission of the risk indicator as prohibited automated individual decision-making under Article 22 GDPR, found transparency breaches by both companies and required them to explain the logic of their decision. The processing ban is scoped to the complainant's data rather than to KSV1870's business generally. The decision is a first-instance DSB decision and was reported as not final, with an appeal to the Federal Administrative Court expected.
DerStandard "Pay or Okay" (August 2025)
On August 18, 2025, the Federal Administrative Court ruled that the "Pay or Okay" consent model operated by Austrian newspaper DerStandard.at violated GDPR consent requirements. The court found that offering users a binary choice between paying EUR 9.90 per month or consenting to comprehensive third-party tracking did not constitute valid consent, because the model lacked granularity: users had no ability to consent to specific processing purposes separately. The case is expected to proceed to the VwGH and potentially the CJEU.
City of Baden Data Breach (September 2024)
A court awarded EUR 500 in damages to one Baden resident who sued over a March 2022 configuration error that left the registration data of more than 33,000 people accessible online for four days. The award went to the claimant who brought the case, not to everyone affected. Public authorities are exempt from administrative fines under Austrian law, but the Higher Regional Court of Vienna (Oberlandesgericht Wien), upholding the Regional Court of Wiener Neustadt, held that proof of actual misuse is not required for a damages claim under Article 82 GDPR. On that reasoning aggregate exposure could reach EUR 16.5 million if every affected person claimed.
Non-Cooperation With the DSB (2024, Reduced on Appeal)
In a 2024 penalty decision the DSB fined a controller EUR 15,200 for ignoring numerous requests for comment across five complaint proceedings, contrary to the duty to cooperate in Article 31 GDPR, and for missing the deadline in a DSB order to grant a data subject access under Article 15 GDPR.
The controller argued that the privilege against self-incrimination relieved it of any duty to answer. The Federal Administrative Court rejected that in its decision of 10 March 2025 (W287 2286005-1), holding that the privilege does not stretch to refusing all cooperation with the supervisory authority, because that would stop the authority carrying out its statutory tasks.
The court upheld the penalty in principle but exercised its own discretion on the amount, reducing the fine to EUR 10,000 in total and ordering the controller to pay EUR 1,000 towards the costs of the proceedings. The case still shows that non-cooperation under Article 31 GDPR can itself trigger a penalty, independent of the underlying data protection issue.
Breach Notification Requirements
Austria follows the GDPR's breach notification framework without significant national modifications. The requirements apply to all controllers processing personal data within Austrian jurisdiction.
Notification to the DSB (Article 33 GDPR)
Controllers must notify personal data breaches to the DSB without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Notification is not required if the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
The notification must include: the categories and approximate numbers of individuals and records affected; the name and contact details of the data protection officer or other contact point; a description of the likely consequences; and the measures taken or proposed to mitigate harm. Late notifications must include an explanation for the delay.
Notification to Data Subjects (Article 34 GDPR)
Where a breach is likely to result in a high risk to the rights and freedoms of individuals, the controller must communicate the breach to affected data subjects without undue delay. This direct notification can be avoided if the controller applied technical measures (such as encryption) rendering the data unintelligible, took subsequent measures ensuring the high risk is no longer likely to materialise, or where individual notification would involve disproportionate effort (in which case public communication is acceptable).
Record-Keeping (Article 33(5) GDPR)
All breaches, regardless of severity, must be documented internally. The documentation must include the facts of the breach, its effects, and the remedial actions taken. The DSB may request access to these records during investigations or audits.
Data Protection Officers
Austria follows the GDPR's DPO requirements without substantial national modifications. Organisations must appoint a DPO when their core activities involve regular and systematic monitoring of individuals on a large scale or large-scale processing of special categories of data. All Austrian federal ministries must appoint at least one DPO under Section 5(4) DSG, going beyond the GDPR's general criteria.
Enhanced Confidentiality Protections
Where Austria goes further than the GDPR baseline is in DPO confidentiality. Under the DSG, DPOs and persons working under them are bound by strict confidentiality regarding the identity of data subjects who contact the DPO and any circumstances that could allow identification. This obligation continues after the DPO relationship ends.
Right to Refuse Testimony
Austrian DPOs and their support staff have a statutory right to refuse testimony regarding information obtained in their DPO capacity. Documents and files held by the DPO that fall under this right cannot be lawfully seized. This protection is notably stronger than what the GDPR alone requires.
Conflict of Interest Prohibition
The DSB has enforced the Article 38(6) GDPR prohibition on DPO conflicts of interest. In a penalty decision of October 16, 2024 it fined a company EUR 5,000 for naming its managing director, who was also a shareholder, as DPO over a three-year period. The DSB reasoned that the double role left the company supervising itself.
International Data Transfers
Austria follows the GDPR's Chapter V framework for international data transfers. Transfers to countries with an EU adequacy decision may proceed without additional safeguards. Transfers within the EEA are free flow rather than adequacy, so Norway, Iceland and Liechtenstein need no decision. As of 10 September 2026 the Commission's adequacy decisions cover Andorra, Argentina, Brazil, Canada (commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom (renewed in December 2025 under both the GDPR and the Law Enforcement Directive), Uruguay and the European Patent Organisation. Brazil was added by an adequacy decision adopted on 26 January 2026, so a Brazilian recipient no longer needs SCCs and a Transfer Impact Assessment. Transfers to certified US organisations under the EU-US Data Privacy Framework (adopted July 2023) are also covered.
For transfers to countries without an adequacy decision, organisations must rely on Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs) and conduct a Transfer Impact Assessment (TIA) evaluating the legal framework of the destination country.
The DSB's Google Analytics decisions established that Austrian enforcement of transfer rules is strict. Supplementary measures must demonstrably prevent access by foreign intelligence services. A risk-based approach arguing that surveillance is statistically unlikely does not satisfy Chapter V of the GDPR, per the April 2022 DSB decision.
Penalties and Sanctions
Austria's penalty framework for data protection violations operates on three levels: GDPR administrative fines, DSG-specific administrative fines, and criminal sanctions.
GDPR Administrative Fines (Article 83 GDPR)
Less severe violations carry fines of up to EUR 10 million or 2% of global annual turnover (whichever is greater). These cover: failure to notify a breach, failure to maintain proper records, failure to designate a DPO where required, or failure to conduct a data protection impact assessment.
More severe violations carry fines of up to EUR 20 million or 4% of global annual turnover (whichever is greater). These cover: unlawful processing, failure to obtain valid consent, violation of data subject rights, unlawful international data transfers, and violations of the basic principles of Article 5 GDPR.
The Deutsche Wohnen Fault-Attribution Rule
Prior to the CJEU's Deutsche Wohnen ruling (C-807/21, December 5, 2023), Austria's position was that imposing a GDPR fine on a legal entity required attributing the infringement to a specific identified natural person. This position derived in part from the constitutional tradition reflected in DSG Section 1, under which individual culpability was seen as a prerequisite for administrative sanction.
The CJEU resolved the tension: a company may be fined under Article 83 GDPR without first identifying the responsible natural person. However, the CJEU rejected strict liability. A legal entity can only be fined if the infringement occurred intentionally or negligently at an organisational level. Negligence can be inferred from systemic failures in data protection governance, even without pinning responsibility on a named individual. Austrian courts and the DSB now apply this standard. The practical effect is that organisations can no longer avoid fines by claiming that no individual employee was personally at fault.
DSG-Specific Administrative Fines
Under the DSG, the authority may impose fines of up to EUR 50,000 for violations of national DSG provisions. These apply only where the offense does not already constitute a violation under Article 83 GDPR, preventing double punishment. Cookie and electronic marketing violations under the TKG 2021 also carry fines of up to EUR 50,000 under Section 188(4) TKG 2021, but those are imposed by the Fernmeldebehörde under Section 191 TKG 2021, not by the DSB.
Criminal Sanctions (Section 63 DSG)
Austria maintains criminal penalties for data protection violations. Under Section 63 DSG, anyone who deliberately uses personal data (entrusted through professional occupation or acquired illegally) to unlawfully enrich themselves or a third party, or to damage another person's data protection interests, faces imprisonment of up to one year or a fine of up to 720 daily rates. This provision applies specifically to intentional misuse for profit or malicious purposes.
Public Authority Liability
While public authorities are exempt from administrative fines under the DSG, they remain subject to civil liability under Article 82 GDPR. The City of Baden precedent confirmed that affected individuals can claim damages without proving actual misuse of their exposed data.
Cookies and Electronic Privacy
Section 165(3) of the TKG 2021 implements the EU ePrivacy Directive in Austrian law and governs the use of cookies and similar tracking technologies.
The law distinguishes between two categories. Technically necessary cookies (serving the sole purpose of carrying out a communication or providing a service explicitly requested by the user) do not require consent. All other cookies, including analytics and advertising trackers, require prior opt-in consent. Following the CJEU's Planet49 ruling (Case C-673/17), valid consent requires an affirmative opt-in action. Pre-checked boxes do not constitute valid consent.
Enforcement of Section 165(3) TKG 2021 does not sit with the DSB. Failing to inform users is an administrative offence under Section 188(4) Z 24 TKG 2021, punishable by a fine of up to EUR 50,000, and Section 191 TKG 2021 makes the Fernmeldebehörde the competent authority: the responsible federal minister and the Fernmeldebüro under her. The DSB's own jurisdiction runs to the GDPR consent and processing side of tracking, exercised under Article 58(2)(i) GDPR and Section 22(5) DSG.
EU Digital Omnibus: Upcoming Changes
In November 2025, the European Commission proposed the EU Digital Omnibus package. For cookies, the proposal folds cookie rules into the GDPR via a new Article 88a and creates a limited consent exemption for privacy-preserving audience measurement tools that do not track individuals across sites. The proposed changes would also require single-click accept/reject mechanisms with equal prominence and browser-level preference signals that websites must honour. Organisations would be prohibited from re-requesting declined consent for six months.
The Commission tabled the Digital Omnibus on 19 November 2025. As of 10 September 2026 it is still in the ordinary legislative procedure and has not been adopted. Until it is, the existing TKG 2021 consent requirements remain in full force in Austria.
EU AI Act Overlay
Regulation (EU) 2024/1689 (the EU AI Act) entered into force on August 1, 2024. Its provisions apply on a phased timeline that directly affects organisations operating in Austria.
Application Timeline
Prohibited AI practices (such as social scoring and most real-time biometric surveillance in public spaces) have been banned across the EU, including in Austria, since February 2, 2025, along with the AI literacy duty.
Obligations for general-purpose AI models have applied since August 2, 2025. They are routinely confused with the separate transparency obligations in Article 50, which apply from August 2, 2026. That is also the date from which fines for general-purpose AI models can be imposed and from which the right to lodge a complaint (Article 85) and the right to an explanation of an individual decision (Article 86) apply.
The high-risk dates moved. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on July 27, 2026. Requirements for the high-risk systems listed in Annex III (areas including biometrics, critical infrastructure, education, employment, migration and border control) now apply from December 2, 2027, and those for Annex I systems from August 2, 2028. The same amending regulation extends the prohibition list to non-consensual sexualised deepfakes from December 2, 2026.
Austria's Institutional Response
Austria established the KI-Servicestelle (AI Service Office) within the Rundfunk und Telekom Regulierungs-GmbH (RTR), on the basis of amendments published in BGBl I Nr. 6/2024 (KommAustria-Gesetz §20c and TKG 2021 §194a). The KI-Servicestelle functions as a public-facing information hub, advisory body, and national competence centre for AI. It publishes guidance on AI Act obligations and coordinates the KI-Beirat (AI Advisory Board).
The KI-Servicestelle is an advisory body and does not exercise sanctioning powers. Austria has not yet formally designated the market surveillance and notifying authorities required for AI Act enforcement. The KI-Maßnahmenpaket announced that the Servicestelle would eventually transition into or support a dedicated national AI enforcement authority. Designation is still pending. The DSB's Tätigkeitsbericht 2025 (chapter 8.3) records that responsibility for implementing the AI Act in Austria sits with the Federal Chancellery, and that a draft implementing act naming the market surveillance authorities and their respective remits had still not appeared when the report went to press. Under Article 74(8) of the AI Act, whichever body Austria names for the Annex III biometrics, law enforcement, migration and justice areas must be either a data protection supervisory authority or another authority meeting the same independence conditions, which puts the DSB in the frame for that role.
The DSB does have an AI Act role, but not the one often attributed to it. Austria notified the DSB to the European Commission in 2024 as a fundamental rights authority under Article 77 of the AI Act, and the DSB publishes guidance on data protection in AI systems. Its advisory and evaluation duties under Section 15 of the Informationsfreiheitsgesetz are a separate matter concerning freedom of information, and the DSB states that they do not affect its tasks and powers under the GDPR. Where AI systems involve profiling or automated individual decision-making, GDPR Articles 22 and 35 (data protection impact assessments) apply alongside the AI Act.
Intersection with GDPR
The AI Act and GDPR operate in parallel. An AI system that generates profiling outputs used in automated decisions affecting individuals falls under both regimes: the AI Act for system-level risk classification and the GDPR for data subject rights. Controllers deploying high-risk AI systems in Austria should assess both regulatory frameworks when conducting data protection impact assessments under Article 35 GDPR.
Recent Developments (2024-2026)
Parliamentary Data Protection Committee (January 2025)
In response to a January 2024 CJEU ruling, Austria's July 2024 DSG amendment (BGBl. I Nr. 70/2024) established the Parlamentarisches Datenschutzkomitee, the Parliamentary Data Protection Committee. Its provisions took effect on July 15, 2024, and under Section 69(10) DSG the committee has exercised its competences over data protection in the legislative bodies since January 1, 2025, closing a longstanding gap in independent oversight of parliamentary data processing.
CJEU Ruling on Refusing Excessive Complaints (January 2025)
The CJEU's ruling in C-416/23 held that a supervisory authority cannot classify requests as excessive under Article 57(4) GDPR on the strength of their number alone, without demonstrating an abusive intention. Where requests genuinely are excessive, the authority may still choose, by reasoned decision, between charging a reasonable fee based on administrative costs and refusing to act. The case arose from a DSB refusal to handle a complaint from someone who had lodged 77 similar complaints in roughly 20 months.
KSV1870 Automated Scoring (September 2025)
The DSB's decision on KSV1870's automated credit-scoring practices is a prominent Article 22 GDPR action against a credit agency, and it signals that the DSB is willing to target automated decision-making in financial contexts even while constrained by its budget. It is a first-instance decision that was reported as not final, so it reflects the DSB's current position rather than settled Austrian law.
DerStandard "Pay or Okay" (August 2025)
The Federal Administrative Court's ruling against DerStandard.at clarified that a pay-or-consent model requires granular consent options at a minimum. The case is expected to generate further guidance on the outer limits of consent-based tracking business models in Austria.
EU Digital Omnibus Proposal (November 2025)
The Commission's Digital Omnibus package proposes to simplify cookie consent rules and fold ePrivacy into the GDPR framework, including a new Article 88a bringing processing on terminal equipment inside the GDPR and a new Article 88b on cookie management. If adopted in its current form, it would override Austria's strict cookie consent posture for privacy-preserving audience measurement tools. The proposal is still in the legislative procedure as of 10 September 2026.
Ongoing Budget Debate (2025-2026)
The infringement complaint filed with the European Commission by epicenter.works and noyb remains pending. The 2026 DSB budget of EUR 5.9 million represents a further cut from the EUR 6.1 million allocated in 2025.
Compliance Essentials for Businesses Operating in Austria
Organisations processing personal data of Austrian residents should address these areas as priorities:
-
Legal basis documentation. Map all processing activities to one of the six Article 6 GDPR lawful bases and document the basis in the Record of Processing Activities (ROPA) required by Article 30 GDPR.
-
Consent mechanics. Ensure consent is freely given, specific, informed, and obtained through an affirmative opt-in action. Bundled consents and pre-checked boxes are invalid. Following the DerStandard ruling, pay-or-consent models must offer granular consent by processing purpose.
-
Cookie compliance. Review cookie banners under TKG 2021 requirements and monitor the EU Digital Omnibus legislative progress for forthcoming changes to analytics consent rules.
-
Data subject rights processes. Establish documented procedures to respond to access, erasure, rectification, portability, restriction, objection, and automated-decision rights requests within GDPR timeframes.
-
Automated decision-making review. Audit any AI or algorithmic systems that produce legal or similarly significant effects. Article 22(2) GDPR already limits fully automated scoring used for credit, employment or similar decisions to explicit consent, contractual necessity or authorisation by EU or member state law, with human review available on request. The KSV1870 decision is the DSB's current reading of that rule rather than settled law, because it is a first-instance decision reported as not final.
-
Cross-border transfer review. Conduct a Transfer Impact Assessment for any transfers to countries outside the EU/EEA and without an adequacy decision. Verify that US service providers are DPF-certified where reliance on the DPF is intended.
-
DPO conflict of interest. In the DSB's EUR 5,000 fine of October 2024, a company had named its managing director, who was also a shareholder, as its DPO. The DSB held that the double role turned the monitoring function into a form of self-supervision. Whether any other role conflicts, a compliance officer's for instance, has to be assessed case by case under Article 38(6) GDPR.
-
EU AI Act compliance planning. Identify any AI systems in scope for the AI Act, particularly high-risk categories. Align GDPR Article 35 data protection impact assessments with AI Act risk assessments where they overlap.
-
Breach notification readiness. Maintain documented incident response procedures capable of meeting the 72-hour notification window under Article 33 GDPR.
-
Public authority civil liability. Austrian public sector bodies should be aware that the City of Baden precedent eliminates the need for data subjects to prove actual misuse when claiming Article 82 GDPR damages.
Disclaimer
This article presents general legal information about Austria's data privacy framework under the GDPR and Datenschutzgesetz (DSG). It does not constitute legal advice. The information covers Austria and EU-level data protection law as verified on September 10, 2026. Laws, enforcement practices, and regulatory guidance change frequently. Readers should consult a lawyer licensed in Austria (or the relevant EU member state) for advice on their specific situation.
Authorities Cited
- Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
- Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999, last amended by BGBl. I Nr. 50/2025, consolidated text in force 10 September 2026. https://www.ris.bka.gv.at/GeltendeFassung.wxe?Abfrage=bundesnormen&Gesetzesnummer=10001597
- Austrian Data Protection Authority (Datenschutzbehörde, DSB) official website. https://data-protection-authority.gv.at/
- Relevant Data Protection Laws, Austrian Data Protection Authority. https://data-protection-authority.gv.at/data-protection-laws/relevant-data-protection-laws
- Rights of the Data Subject (GDPR and DSG), Austrian Data Protection Authority. https://data-protection-authority.gv.at/data-protection-in-austria/rights-of-the-data-subject
- Austrian Federal Ministry of Finance, Data Protection Overview. https://www.bmf.gv.at/en/data-protection.html
- CJEU, Case C-807/21, Deutsche Wohnen SE v Staatsanwaltschaft Berlin, judgment of December 5, 2023. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0807
- CJEU, Case C-416/23 (Österreichische Datenschutzbehörde v F R), judgment of January 9, 2025. https://noyb.eu/en/austrian-data-protection-authority-slammed-cjeu
- DSB, Decision 2021-0.586.257 (D155.027), Google Analytics, published January 13, 2022. https://noyb.eu/en/austrian-dsb-eu-us-data-transfers-google-analytics-illegal
- DSB, follow-up decision on risk-based approach, April 22, 2022. https://noyb.eu/en/update-noybs-101-complaints-austrian-dpa-rejects-risk-based-approach-data-transfers-third-countries
- VwGH, Ro 2025/04/0007, Österreichische Post AG, judgment of June 24, 2026 setting the fine at EUR 13,000,000 plus EUR 100,000 in costs. https://ogd.ris.bka.gv.at/Dokumente/Vwgh/JWT_2025040007_20260624J00/JWT_2025040007_20260624J00.html
- DSB, KSV1870 automated credit scoring decision, published by noyb on September 26, 2025. https://noyb.eu/en/noyb-win-austrian-authority-forbids-unlawful-credit-scoring-ksv1870
- BVwG (Federal Administrative Court), DerStandard.at "Pay or Okay" ruling, August 18, 2025. https://noyb.eu/en/court-decides-pay-or-okay-derstandardat-illegal
- noyb and epicenter.works, Complaint to the European Commission on DSB budget constraints, September 18, 2025. https://noyb.eu/en/budget-cuts-paralyse-austrian-dpa-ngo-complaint-eu-commission
- BVwG, W258 2227269-1, Österreichische Post AG, decision of December 27, 2024 (RIS). https://ogd.ris.bka.gv.at/Dokumente/Bvwg/BVWGT_20241227_W258_2227269_1_00_01/BVWGT_20241227_W258_2227269_1_00_01.html
- Regulation (EU) 2024/1689 (EU AI Act). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689
- KI-Servicestelle at RTR, AI Act guidance. https://www.rtr.at/rtr/service/ki-servicestelle/ai-act/AI_Act.en.html
- European Commission, EU AI Act regulatory framework. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- CJEU, Case C-673/17, Planet49, cookie consent ruling. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62017CJ0673
- Datenschutzbehörde, Tätigkeitsbericht 2025 (Vienna, March 2026). https://dsb.gv.at/sites/site0344/media/downloads/taetigkeitsbericht_2025_v4.pdf
Related Articles
Last updated: 2026-09-10. Statutes cited reflect their in-force version as of 10 September 2026.
More on Austria law
This page covers one area of law in Austria. For a complete guide to Austria's legal system, including employment, family, driving, tenancy, inheritance, criminal law and consumer rights, see our full Austria law hub.
Frequently Asked Questions
Does the GDPR apply in Austria?
The GDPR applies directly in Austria as an EU member state and has been in effect since May 25, 2018. Austria supplements the GDPR with its Datenschutzgesetz (DSG), which addresses areas where the GDPR grants member states discretion, including child consent age, video surveillance rules, modifications for journalistic processing, DPO confidentiality protections, and criminal penalties for data misuse.
What is the Datenschutzbehörde (DSB) and how do I file a complaint?
The Datenschutzbehörde (DSB) is Austria's independent data protection supervisory authority, headquartered in Vienna. Individuals can file complaints directly with the DSB when they believe their data protection rights have been violated. Complaints can be submitted through the DSB's official website at data-protection-authority.gv.at. Following the CJEU ruling in C-416/23, the DSB cannot treat complaints as excessive on their number alone: it has to demonstrate an abusive intention before it charges a fee or refuses to act under Article 57(4) GDPR.
What are the penalties for violating data privacy laws in Austria?
Austria enforces penalties on three levels. GDPR administrative fines reach up to EUR 20 million or 4% of global annual turnover for serious violations such as unlawful processing or failure to respect data subject rights. The DSG allows additional fines up to EUR 50,000 for violations of national provisions not already covered by Article 83 GDPR. Under Section 63 DSG, deliberate misuse of personal data for profit or to harm others carries criminal sanctions including up to one year of imprisonment.
Is Google Analytics legal to use in Austria?
The DSB ruled in January and April 2022 that the standard implementation of Google Analytics violated the GDPR by transferring personal data to the United States without adequate safeguards. Since the adoption of the EU-US Data Privacy Framework in July 2023, transfers to DPF-certified US organisations have a new adequacy basis. Google LLC is DPF-certified. Organisations using Google Analytics in Austria should verify that Google maintains its DPF certification and review their specific configuration. The DSB's established position that supplementary measures must demonstrably prevent foreign intelligence access remains relevant for transfers outside the DPF.
At what age can children consent to online services in Austria?
Under Section 4(4) of the DSG, children in Austria can consent to information society services starting at age 14. This is lower than the GDPR's default threshold of 16, which Austria lowered using the regulation's opening clause. For children under 14, parental or guardian consent is required.
Does Austria require identifying a natural person before fining a company for a GDPR violation?
No. Following the CJEU's ruling in Deutsche Wohnen (C-807/21, December 5, 2023), Austria's courts must impose GDPR fines on legal entities on proof of organisational culpability alone. The CJEU held that it is not necessary to attribute the infringement to an identified natural person first. However, strict liability does not apply: the organisation must have acted intentionally or negligently. Negligence can be inferred from systemic failures in data protection governance without identifying the specific employee responsible.
What is the EU AI Act and how does it affect Austrian businesses?
The EU AI Act (Regulation 2024/1689) is directly applicable in Austria. Prohibited AI practices have been banned since February 2025. Obligations for general-purpose AI models have applied since August 2, 2025, and the separate Article 50 transparency obligations apply from August 2, 2026. Requirements for Annex III high-risk systems apply from December 2, 2027 and for Annex I high-risk systems from August 2, 2028, as amended by Regulation (EU) 2026/1744. Austria established the KI-Servicestelle within the RTR as a national advisory body for AI Act compliance. The AI Act operates alongside the GDPR: AI systems involving profiling or automated individual decisions must also comply with GDPR Articles 22 and 35.
Are 'Pay or Okay' cookie consent models legal in Austria?
Austrian courts have scrutinised pay-or-consent models closely. In August 2025, the Federal Administrative Court ruled against newspaper DerStandard.at, finding that its model, which required users to either pay EUR 9.90 per month or consent to comprehensive third-party tracking, did not provide valid GDPR consent because it lacked granularity. Users must be able to consent or refuse consent to specific types of processing separately. The court did not rule the pay-or-consent approach categorically impermissible, but found that granular consent options are a minimum requirement.
What are the rules for automated credit scoring and algorithmic decisions in Austria?
Article 22 GDPR prohibits decisions based solely on automated processing that produce legal or similarly significant effects, unless one of the narrow exceptions applies. In September 2025 the DSB found that KSV1870's automated credit-scoring system, whose risk indicator was passed to an energy supplier for a service decision, breached this prohibition. That decision is first instance and was reported as not final. Controllers relying on automated scoring must either obtain explicit data subject consent, demonstrate the decision is necessary for a contract, or be authorised by EU or member state law, and must in any case offer the right to human review.
What is Austria's constitutional right to data protection?
Section 1 of the DSG carries constitutional rank, meaning it can only be amended by a two-thirds majority in parliament. It guarantees everyone, including legal persons, a right to secrecy of personal data in private and family life. This provision has existed since 1978, making Austria one of the earliest countries to constitutionalise data protection. It allows any Austrian law interfering with data protection to be challenged before the Constitutional Court (VfGH), creating a judicial check beyond the GDPR framework.
Updates
Corrected the Österreichische Post case to its final outcome (the Constitutional Court declined the complaint on 9 December 2025 and the Administrative High Court set the fine at EUR 13 million plus EUR 100,000 in costs on 24 June 2026), rewrote the journalism section around the current Section 9 DSG, which since 1 July 2024 applies the GDPR with itemised modifications instead of a blanket exemption, attributed TKG cookie enforcement to the Fernmeldebehörde and the DSG to the Ministry of Justice, removed an incorrect "two complaints per month" description of CJEU C-416/23, added the 2025 DSG amendment (BGBl. I Nr. 50/2025), rebuilt the enforcement statistics from the DSB's 2025 annual report, split the AI Act timeline correctly and added Brazil to the adequacy list. Corrected the EUR 15,200 non-cooperation penalty, which the Federal Administrative Court reduced to EUR 10,000 plus EUR 1,000 in costs on 10 March 2025, and removed the claim that it was one of the highest 2024 fines; noted that TKG 2021 cookie fines are imposed by the Fernmeldebehörde rather than the DSB; sourced the pending AI Act market surveillance designation to the DSB's Tätigkeitsbericht 2025 and Article 74(8) of the AI Act; and aligned the DSG, C-416/23 and KSV1870 source labels with the records they cite.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Major update of the statutory, enforcement, cookie and AI Act sections. Several statements in that revision were found to be inaccurate and were corrected on 10 September 2026; see the later entries in this log.
Reviewed and approved by an editor
Sources and References
- Regulation (EU) 2016/679 (GDPR)(eur-lex.europa.eu).gov
- Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999, zuletzt geändert durch BGBl. I Nr. 50/2025 - Bundesrecht konsolidiert, Fassung vom 10.09.2026(ris.bka.gv.at).gov
- Austrian Data Protection Authority (DSB) - Official Website(data-protection-authority.gv.at).gov
- Relevant Data Protection Laws - Austrian Data Protection Authority(data-protection-authority.gv.at).gov
- Rights of the Data Subject (GDPR and DSG) - Austrian Data Protection Authority(data-protection-authority.gv.at).gov
- Austrian Federal Ministry of Finance - Data Protection Overview(bmf.gv.at).gov
- CJEU C-807/21 Deutsche Wohnen - fault attribution for GDPR fines against legal entities (EUR-Lex)(eur-lex.europa.eu).gov
- CJEU C-416/23, Österreichische Datenschutzbehörde v F R (9 January 2025) - limits on refusing requests as excessive under Art. 57(4) GDPR(noyb.eu)
- DSB Decision 2021-0.586.257 (D155.027) - Google Analytics, published 13 January 2022(noyb.eu)
- DSB rejects risk-based approach for data transfers - April 2022 follow-up decision(noyb.eu)
- VwGH, Ro 2025/04/0007, Österreichische Post AG, judgment of 24 June 2026 setting the fine at EUR 13,000,000 plus EUR 100,000 in costs (RIS)(ogd.ris.bka.gv.at).gov
- DSB KSV1870 automated credit scoring decision, published by noyb on 26 September 2025(noyb.eu)
- BVwG DerStandard.at Pay or Okay ruling, August 18 2025(noyb.eu)
- noyb and epicenter.works complaint to European Commission on DSB budget, September 2025(noyb.eu)
- BVwG, W258 2227269-1, Österreichische Post AG, decision of 27 December 2024 (RIS)(ogd.ris.bka.gv.at).gov
- Regulation (EU) 2024/1689 - EU AI Act(eur-lex.europa.eu).gov
- KI-Servicestelle at RTR - AI Act guidance Austria(rtr.at)
- European Commission - EU AI Act regulatory framework(digital-strategy.ec.europa.eu).gov
- CJEU Case C-673/17 Planet49 - cookie consent ruling(eur-lex.europa.eu).gov
- Datenschutzbehörde, Tätigkeitsbericht 2025 (Vienna, March 2026) - staffing, budget, complaint and penalty statistics(dsb.gv.at).gov