Data & Privacy · Austria
Data protection & GDPR compliance in Austria (2026)
Austria shaded by its data & privacy status
Data protection in Austria: comprehensive law.
FrameworkEU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) directly applicable, supplemented and implemented nationally by the Austrian Federal Data Protection Act (Datenschutzgesetz — DSG, BGBl. I Nr. 165/1999 as most recently amended by BGBl. I Nr. 70/2024). Supervised by the Austrian Data Protection Authority (Datenschutzbehörde — DSB).
Austria has a comprehensive personal-data protection regime built on the directly-applicable GDPR and the national DSG, which supplements the GDPR (constitutional right to secrecy of personal data in § 1 DSG, national derogations, processing of criminal data, and rules for authorities). The independent Datenschutzbehörde (DSB) is the primary supervisory authority under Art. 51 GDPR, and since 1 January 2025 a separate Parliamentary Data Protection Committee (Parlamentarisches Datenschutzkomitee) supervises legislative bodies. The framework is reinforced by directly-applicable EU instruments including the EU Data Act (applicable from 12 September 2025), the ePrivacy rules in the Austrian Telecommunications Act (TKG 2021), and NIS2/DORA.
GDPR & data protection in Austria
In Austria, data protection is governed by the EU General Data Protection Regulation (GDPR), which applies directly and is enforced by the Austrian Data Protection Authority (Datenschutzbehörde).
- Framework
- the GDPR (Regulation (EU) 2016/679) plus the national data-protection act
- Supervisory authority
- the Austrian Data Protection Authority (Datenschutzbehörde)
- Applies to
- any organisation processing the personal data of people in Austria, wherever the organisation is based
- Maximum fine
- €20 million or 4% of global annual turnover, whichever is higher
- Breach notification
- within 72 hours of becoming aware, to the supervisory authority
- DPO
- required for large-scale monitoring or large-scale special-category processing
The GDPR is bloc-wide; Austria supplements it with a national data-protection act and its own supervisory authority.
GDPR in Austria: FAQ
Yes. As an EU/EEA member, Austria applies the GDPR (Regulation (EU) 2016/679) directly, enforced by the Austrian Data Protection Authority (Datenschutzbehörde).
The Austrian Data Protection Authority (Datenschutzbehörde).
Up to €20 million or 4% of global annual turnover, whichever is higher.
A DPO is required where you carry out large-scale monitoring or process special-category data at scale.
Personal-data breaches must be notified to the supervisory authority within 72 hours of becoming aware.
Key points
GDPR applies directly since 25 May 2018; the DSG (as amended, latest consolidated version BGBl. I Nr. 70/2024) implements national opening clauses, contains the constitutional Grundrecht auf Datenschutz (§ 1 DSG), and sets out rules on the DSB, judicial data processing, employer/employee data, video surveillance, and criminal-law data processing.
The Datenschutzbehörde (DSB), Barichgasse 40-42, 1030 Vienna, is the independent supervisory authority under Art. 51 GDPR. It handles complaints, conducts investigations, issues corrective measures and administrative fines; its 2026 budget is approximately EUR 5.9 million, with around 53 staff.
The DSB may order cessation of unlawful processing and impose GDPR fines up to EUR 20 million or 4% of worldwide annual turnover (Art. 83 GDPR), plus DSG-specific administrative fines up to EUR 50,000. Notable recent decisions include the EUR 16 million fine confirmed against Österreichische Post in December 2024 by the Federal Administrative Court.
Data subjects enjoy full GDPR rights (access, rectification, erasure, restriction, portability, objection) plus the § 1 DSG constitutional right to data secrecy, and may lodge complaints with the DSB free of charge. Following CJEU ruling C-416/23 (9 January 2025), the DSB may not arbitrarily cap the number of complaints a data subject can file.
Controllers must notify the DSB of personal-data breaches without undue delay and, where feasible, within 72 hours (Art. 33 GDPR), and inform affected data subjects where there is a high risk to their rights (Art. 34 GDPR). Failure to notify can trigger fines up to EUR 10 million or 2% of global turnover.
The DSG was amended in June and July 2024 (BGBl. I 2024/62 and 2024/70) in response to CJEU C-33/22 (16 January 2024), creating a separate Parlamentarisches Datenschutzkomitee that took over supervision of legislative bodies on 1 January 2025. The EU Data Act (Regulation (EU) 2023/2854) became directly applicable across Austria on 12 September 2025, adding data-access and data-sharing obligations.
Timeline - major decisions & events
In case 6 Ob 189/24y (announced 18 Dec 2025), the OGH ended an 11-year Schrems case, finding Meta's targeted-ad processing required specific consent and ordering Meta to disclose all of a user's personal data including sources and purposes. It set a binding GDPR precedent on consent and access rights across the EU.
noyb ↗The Austrian Data Protection Authority ruled that KSV1870's fully automated scoring used to deny consumers energy contracts constituted prohibited automated individual decision-making under Article 22 GDPR. It reinforced limits on algorithmic decisioning in Austria.
E+H Rechtsanwälte ↗Facing a 769% rise in complaints since 2017 (3,813 in 2024) but flat funding, the Austrian Data Protection Authority imposed operational restrictions from July 2025. It signaled a growing gap between enforcement demand and regulator capacity.
PPC Land ↗After awaiting the CJEU's Deutsche Wohnen ruling, the Federal Administrative Court confirmed a EUR 16 million fine against the Austrian Postal Service for GDPR violations tied to profiling. It is among the largest GDPR penalties ever issued in Austria.
CMS GDPR Enforcement Tracker ↗In the first decision on noyb's 101 post-Schrems II model complaints, the DSB held that exporting Google Analytics data to the US breached GDPR Chapter V because standard contractual clauses could not protect against US FISA 702 surveillance. It triggered a wave of similar rulings across EU regulators.
noyb ↗In Case C-311/18, originating from Austrian activist Max Schrems's complaint, the Court of Justice struck down the Privacy Shield and tightened conditions for using standard contractual clauses. It reshaped the legal basis for all EU-US data transfers, including for Austrian organisations.
Court of Justice of the EU ↗The revised Data Protection Act entered into force alongside the EU GDPR, restructuring the national framework while retaining the constitutional Section 1 right to data secrecy. It is the central national statute supplementing the GDPR today.
RIS (Federal Legal Information System) ↗Published as BGBl I No. 120/2017, the Data Protection Amendment Act 2018 exercised the GDPR's national discretionary powers and overhauled the DSG ahead of 25 May 2018. A government attempt to abolish the constitutional data-protection right failed for lack of a two-thirds majority.
Parlament Österreich ↗In Case C-362/14, brought by Max Schrems against the Irish DPA, the Court ruled Safe Harbor inadequate and affirmed national authorities' power to scrutinise transfers. It was the first of the landmark Austrian-originated cases to reshape global data-transfer rules.
Court of Justice of the EU ↗Austria's original Data Protection Act (BGBl No. 565/1978) enshrined a constitutional right to data secrecy in Section 1 and created the Data Protection Commission, one of the earliest such authorities worldwide. This constitutional anchor still underpins the modern framework.
GDPRhub ↗Austria - other topics
Data & Privacy in other countries
Last verified 7/26/2026 · Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite · State of Technology Regulation 2026 · Explore the full world map →