Law note · Austria

Datenschutzgesetz (DSG), Data Protection Act

cite Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999, as amended by BGBl. I Nr. 24/2018 stage In effect since 2018-05-25 reviewed 2026-08-24

The General Data Protection Regulation (GDPR) applies directly in Austria, and the Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999 as amended by BGBl. I Nr. 24/2018, supplies domestic institutional and procedural provisions: the structure of the Datenschutzbehorde (DSB), criminal offenses for data misuse under Article 4 DSG, and a media privilege under Article 9 DSG that the Constitutional Court held unconstitutional and that was re-regulated alongside Austria's new Freedom of Information Act from September 2025.

Lawful bases follow GDPR Article 6 unmodified, and controller and processor duties follow GDPR Articles 24 to 28 with no Austrian derogation identified.

What it asks of an app

  • Establish and document a lawful basis under General Data Protection Regulation (GDPR) Article 6 before processing any personal data of a person in Austria.
  • Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, following GDPR Articles 24 to 28.

When LexLint raises it

Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics

Primary source: Austrian Federal Law Gazette (Rechtsinformationssystem, RIS), consolidated text

← Back to the example  ·  Lint your app →