Skip to content
World Watch/Austria/Data & Privacy

Data & Privacy · Austria

Data protection & GDPR compliance in Austria (2026)

Comprehensive lawCountry index 90 · A+

Austria shaded by its data & privacy status

Data protection in Austria: comprehensive law.

FrameworkEU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) directly applicable, supplemented and implemented nationally by the Austrian Federal Data Protection Act (Datenschutzgesetz — DSG, BGBl. I Nr. 165/1999 as most recently amended by BGBl. I Nr. 70/2024). Supervised by the Austrian Data Protection Authority (Datenschutzbehörde — DSB).

Austria has a comprehensive personal-data protection regime built on the directly-applicable GDPR and the national DSG, which supplements the GDPR (constitutional right to secrecy of personal data in § 1 DSG, national derogations, processing of criminal data, and rules for authorities). The independent Datenschutzbehörde (DSB) is the primary supervisory authority under Art. 51 GDPR, and since 1 January 2025 a separate Parliamentary Data Protection Committee (Parlamentarisches Datenschutzkomitee) supervises legislative bodies. The framework is reinforced by directly-applicable EU instruments including the EU Data Act (applicable from 12 September 2025), the ePrivacy rules in the Austrian Telecommunications Act (TKG 2021), and NIS2/DORA.

GDPR & data protection in Austria

In Austria, data protection is governed by the EU General Data Protection Regulation (GDPR), which applies directly and is enforced by the Austrian Data Protection Authority (Datenschutzbehörde).

Framework
the GDPR (Regulation (EU) 2016/679) plus the national data-protection act
Supervisory authority
the Austrian Data Protection Authority (Datenschutzbehörde)
Applies to
any organisation processing the personal data of people in Austria, wherever the organisation is based
Maximum fine
€20 million or 4% of global annual turnover, whichever is higher
Breach notification
within 72 hours of becoming aware, to the supervisory authority
DPO
required for large-scale monitoring or large-scale special-category processing

The GDPR is bloc-wide; Austria supplements it with a national data-protection act and its own supervisory authority.

GDPR in Austria: FAQ

Does the GDPR apply in Austria?

Yes. As an EU/EEA member, Austria applies the GDPR (Regulation (EU) 2016/679) directly, enforced by the Austrian Data Protection Authority (Datenschutzbehörde).

Who enforces data protection law in Austria?

The Austrian Data Protection Authority (Datenschutzbehörde).

What are the GDPR fines in Austria?

Up to €20 million or 4% of global annual turnover, whichever is higher.

Do you need a Data Protection Officer in Austria?

A DPO is required where you carry out large-scale monitoring or process special-category data at scale.

How quickly must a data breach be reported in Austria?

Personal-data breaches must be notified to the supervisory authority within 72 hours of becoming aware.

Key points

Primary legal framework

GDPR applies directly since 25 May 2018; the DSG (as amended, latest consolidated version BGBl. I Nr. 70/2024) implements national opening clauses, contains the constitutional Grundrecht auf Datenschutz (§ 1 DSG), and sets out rules on the DSB, judicial data processing, employer/employee data, video surveillance, and criminal-law data processing.

Supervisory authority

The Datenschutzbehörde (DSB), Barichgasse 40-42, 1030 Vienna, is the independent supervisory authority under Art. 51 GDPR. It handles complaints, conducts investigations, issues corrective measures and administrative fines; its 2026 budget is approximately EUR 5.9 million, with around 53 staff.

Enforcement and fines

The DSB may order cessation of unlawful processing and impose GDPR fines up to EUR 20 million or 4% of worldwide annual turnover (Art. 83 GDPR), plus DSG-specific administrative fines up to EUR 50,000. Notable recent decisions include the EUR 16 million fine confirmed against Österreichische Post in December 2024 by the Federal Administrative Court.

Data subject rights and complaints

Data subjects enjoy full GDPR rights (access, rectification, erasure, restriction, portability, objection) plus the § 1 DSG constitutional right to data secrecy, and may lodge complaints with the DSB free of charge. Following CJEU ruling C-416/23 (9 January 2025), the DSB may not arbitrarily cap the number of complaints a data subject can file.

Breach notification

Controllers must notify the DSB of personal-data breaches without undue delay and, where feasible, within 72 hours (Art. 33 GDPR), and inform affected data subjects where there is a high risk to their rights (Art. 34 GDPR). Failure to notify can trigger fines up to EUR 10 million or 2% of global turnover.

Recent 2024–2025 developments

The DSG was amended in June and July 2024 (BGBl. I 2024/62 and 2024/70) in response to CJEU C-33/22 (16 January 2024), creating a separate Parlamentarisches Datenschutzkomitee that took over supervision of legislative bodies on 1 January 2025. The EU Data Act (Regulation (EU) 2023/2854) became directly applicable across Austria on 12 September 2025, adding data-access and data-sharing obligations.

Timeline - major decisions & events

Nov 26, 2025decision
Austrian Supreme Court rules Meta's personalized-ad model unlawful, orders full data access

In case 6 Ob 189/24y (announced 18 Dec 2025), the OGH ended an 11-year Schrems case, finding Meta's targeted-ad processing required specific consent and ordering Meta to disclose all of a user's personal data including sources and purposes. It set a binding GDPR precedent on consent and access rights across the EU.

noyb
Sep 25, 2025decision
DSB finds credit agency KSV1870's automated scoring unlawful

The Austrian Data Protection Authority ruled that KSV1870's fully automated scoring used to deny consumers energy contracts constituted prohibited automated individual decision-making under Article 22 GDPR. It reinforced limits on algorithmic decisioning in Austria.

E+H Rechtsanwälte
Jul 1, 2025guidance
DSB cuts operations amid budget constraints

Facing a 769% rise in complaints since 2017 (3,813 in 2024) but flat funding, the Austrian Data Protection Authority imposed operational restrictions from July 2025. It signaled a growing gap between enforcement demand and regulator capacity.

PPC Land
Dec 27, 2024enforcement
BVwG imposes EUR 16 million fine on Österreichische Post

After awaiting the CJEU's Deutsche Wohnen ruling, the Federal Administrative Court confirmed a EUR 16 million fine against the Austrian Postal Service for GDPR violations tied to profiling. It is among the largest GDPR penalties ever issued in Austria.

CMS GDPR Enforcement Tracker
Jan 13, 2022decision
DSB rules Google Analytics transfers to the US unlawful

In the first decision on noyb's 101 post-Schrems II model complaints, the DSB held that exporting Google Analytics data to the US breached GDPR Chapter V because standard contractual clauses could not protect against US FISA 702 surveillance. It triggered a wave of similar rulings across EU regulators.

noyb
Jul 16, 2020decisionofficial
CJEU 'Schrems II' invalidates the EU-US Privacy Shield

In Case C-311/18, originating from Austrian activist Max Schrems's complaint, the Court of Justice struck down the Privacy Shield and tightened conditions for using standard contractual clauses. It reshaped the legal basis for all EU-US data transfers, including for Austrian organisations.

Court of Justice of the EU
May 25, 2018lawofficial
New Datenschutzgesetz (DSG) and GDPR take effect in Austria

The revised Data Protection Act entered into force alongside the EU GDPR, restructuring the national framework while retaining the constitutional Section 1 right to data secrecy. It is the central national statute supplementing the GDPR today.

RIS (Federal Legal Information System)
Jul 31, 2017lawofficial
Datenschutz-Anpassungsgesetz 2018 adopted to implement GDPR opening clauses

Published as BGBl I No. 120/2017, the Data Protection Amendment Act 2018 exercised the GDPR's national discretionary powers and overhauled the DSG ahead of 25 May 2018. A government attempt to abolish the constitutional data-protection right failed for lack of a two-thirds majority.

Parlament Österreich
Oct 6, 2015decisionofficial
CJEU 'Schrems I' invalidates the US Safe Harbor framework

In Case C-362/14, brought by Max Schrems against the Irish DPA, the Court ruled Safe Harbor inadequate and affirmed national authorities' power to scrutinise transfers. It was the first of the landmark Austrian-originated cases to reshape global data-transfer rules.

Court of Justice of the EU
Oct 18, 1978law
First Datenschutzgesetz (DSG 1978) establishes a constitutional right to data protection

Austria's original Data Protection Act (BGBl No. 565/1978) enshrined a constitutional right to data secrecy in Section 1 and created the Data Protection Commission, one of the earliest such authorities worldwide. This constitutional anchor still underpins the modern framework.

GDPRhub

Austria - other topics

Data & Privacy in other countries

Last verified 7/26/2026 · Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite · State of Technology Regulation 2026 · Explore the full world map →