Law note · Austria
GDPR Articles 33-34, Breach Notification in Austria
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
reviewed 2026-08-24
A controller must notify the Datenschutzbehorde without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Austria-specific derogation from this timeline or threshold was identified in the DSG.
What it asks of an app
- Notify the Datenschutzbehorde without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Austria, unless the breach is unlikely to risk their rights and freedoms.
- Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
When LexLint raises it
Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics
Primary source: Official Journal text, EUR-Lex, Regulation (EU) 2016/679