Law note · Austria
Datenschutzgesetz (DSG), Data Protection Act
The General Data Protection Regulation (GDPR) applies directly in Austria, and the Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999 as amended by BGBl. I Nr. 24/2018, supplies domestic institutional and procedural provisions: the structure of the Datenschutzbehorde (DSB), criminal offenses for data misuse under Article 4 DSG, and a media privilege under Article 9 DSG that the Constitutional Court held unconstitutional and that was re-regulated alongside Austria's new Freedom of Information Act from September 2025.
Lawful bases follow GDPR Article 6 unmodified, and controller and processor duties follow GDPR Articles 24 to 28 with no Austrian derogation identified.
What it asks of an app
- Establish and document a lawful basis under General Data Protection Regulation (GDPR) Article 6 before processing any personal data of a person in Austria.
- Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, following GDPR Articles 24 to 28.
When LexLint raises it
Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics
Primary source: Austrian Federal Law Gazette (Rechtsinformationssystem, RIS), consolidated text