Law / Austria

Austria

privacy

Austria's private-sector personal data regime is the General Data Protection Regulation (GDPR) as given domestic effect by the Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999 as amended by BGBl. I Nr. 24/2018. There is no standalone Austrian biometric-privacy statute; biometric identifiers are governed entirely through GDPR Article 9's special category regime, enforced by the Datenschutzbehorde (DSB).

Austria supplied one of the two leading CJEU rulings on Article 82 private compensation, C-300/21 Osterreichische Post, itself referred by the Austrian Supreme Court.

20 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

GDPR Articles 33-34, Breach Notification in Austria

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

A controller must notify the Datenschutzbehorde without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Austria-specific derogation from this timeline or threshold was identified in the DSG.

What it asks of an app

Comprehensive regime

Datenschutzgesetz (DSG), Data Protection Act

cite Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999, as amended by BGBl. I Nr. 24/2018 stage In effect since 2018-05-25 source Austrian Federal Law Gazette (Rechtsinformationssystem, RIS), consolidated text

The General Data Protection Regulation (GDPR) applies directly in Austria, and the Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999 as amended by BGBl. I Nr. 24/2018, supplies domestic institutional and procedural provisions: the structure of the Datenschutzbehorde (DSB), criminal offenses for data misuse under Article 4 DSG, and a media privilege under Article 9 DSG that the Constitutional Court held unconstitutional and that was re-regulated alongside Austria's new Freedom of Information Act from September 2025.

Lawful bases follow GDPR Article 6 unmodified, and controller and processor duties follow GDPR Articles 24 to 28 with no Austrian derogation identified.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Austria

cite Regulation (EU) 2016/679, Arts. 44-49 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Transferring personal data of a person in Austria outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the highest Article 83(5) fine tier (up to EUR 20 million or 4 percent of global turnover). This is a real, structured condition on outbound transfer, not an absence of restriction. No Austria-specific derogation from this framework was identified.

What it asks of an app

Data subject rights

GDPR Article 22 and DSG Sections 42-45, Automated Decision-Making in Austria

cite Regulation (EU) 2016/679, Art. 22; Datenschutzgesetz (DSG) ยงยง42-45 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

General Data Protection Regulation (GDPR) Articles 12 to 23 give a person in Austria rights of access, rectification, erasure, restriction, portability and objection, plus Article 22 rights against a decision based solely on automated processing that produces legal or similarly significant effects. DSG Sections 42 to 45 give Article 22 domestic procedural effect.

The Datenschutzbehorde's September 2025 finding that KSV1870's credit scoring was prohibited automated decision-making under Article 22 was overturned by the Verwaltungsgerichtshof (Supreme Administrative Court) on 11 June 2026, which held the scoring parameters were not personal data in that instance. This narrows the DSB's Article 22 theory in the credit-scoring context but leaves the underlying statutory right and DSB enforcement authority unchanged.

What it asks of an app

Enforcement supervision

GDPR Article 82 and Datenschutzbehorde Enforcement in Austria

cite Regulation (EU) 2016/679, Arts. 82-83; Datenschutzgesetz (DSG) Art. 4 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

The Datenschutzbehorde (DSB) is Austria's supervisory authority, with General Data Protection Regulation (GDPR) Article 83 administrative fines of up to the greater of EUR 20 million or 4 percent of global turnover, plus DSG Article 4 criminal offenses for data secrecy violations.

Article 82 arms an individual with a direct private right of action for material or non-material damage, without a seriousness threshold, per the CJEU's first Article 82 ruling, C-300/21 UI v Osterreichische Post AG (4 May 2023), itself referred by the Austrian Supreme Court. Since 2 December 2024, noyb is a Qualified Entity under Austria's Qualifizierte-Einrichtungen-Gesetz, letting it bring collective Article 80(2) redress actions.

What it asks of an app

Sensitive categories

GDPR Article 9, Special Categories of Personal Data Including Biometric Data, as Applied in Austria

cite Regulation (EU) 2016/679, Art. 9, as applied in Austria stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Article 9(1) prohibits processing special categories of personal data, including biometric data processed to uniquely identify a person, unless a listed Article 9(2) exception applies, most often explicit consent. Austria adds no separate statutory biometric regime alongside General Data Protection Regulation (GDPR) Article 9. The Datenschutzbehorde found in 2021 that Clearview AI's scraped facial recognition database was unlawful under Austrian data protection law for processing biometric data without a lawful basis.

No Austria-specific guidance on voiceprint biometrics specifically was found in this research; the GDPR baseline, that a voiceprint captured through specific technical processing for identification is special category data on the same footing as a faceprint, governs by default.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.