Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
A controller must notify the Datenschutzbehorde without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Austria-specific derogation from this timeline or threshold was identified in the DSG.
What it asks of an app →
Comprehensive regime
cite Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999, as amended by BGBl. I Nr. 24/2018
stage In effect
since 2018-05-25
source Austrian Federal Law Gazette (Rechtsinformationssystem, RIS), consolidated text
The General Data Protection Regulation (GDPR) applies directly in Austria, and the Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999 as amended by BGBl. I Nr. 24/2018, supplies domestic institutional and procedural provisions: the structure of the Datenschutzbehorde (DSB), criminal offenses for data misuse under Article 4 DSG, and a media privilege under Article 9 DSG that the Constitutional Court held unconstitutional and that was re-regulated alongside Austria's new Freedom of Information Act from September 2025.
Lawful bases follow GDPR Article 6 unmodified, and controller and processor duties follow GDPR Articles 24 to 28 with no Austrian derogation identified.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Transferring personal data of a person in Austria outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the highest Article 83(5) fine tier (up to EUR 20 million or 4 percent of global turnover). This is a real, structured condition on outbound transfer, not an absence of restriction. No Austria-specific derogation from this framework was identified.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Art. 22; Datenschutzgesetz (DSG) ยงยง42-45
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Articles 12 to 23 give a person in Austria rights of access, rectification, erasure, restriction, portability and objection, plus Article 22 rights against a decision based solely on automated processing that produces legal or similarly significant effects. DSG Sections 42 to 45 give Article 22 domestic procedural effect.
The Datenschutzbehorde's September 2025 finding that KSV1870's credit scoring was prohibited automated decision-making under Article 22 was overturned by the Verwaltungsgerichtshof (Supreme Administrative Court) on 11 June 2026, which held the scoring parameters were not personal data in that instance. This narrows the DSB's Article 22 theory in the credit-scoring context but leaves the underlying statutory right and DSB enforcement authority unchanged.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83; Datenschutzgesetz (DSG) Art. 4
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
The Datenschutzbehorde (DSB) is Austria's supervisory authority, with General Data Protection Regulation (GDPR) Article 83 administrative fines of up to the greater of EUR 20 million or 4 percent of global turnover, plus DSG Article 4 criminal offenses for data secrecy violations.
Article 82 arms an individual with a direct private right of action for material or non-material damage, without a seriousness threshold, per the CJEU's first Article 82 ruling, C-300/21 UI v Osterreichische Post AG (4 May 2023), itself referred by the Austrian Supreme Court. Since 2 December 2024, noyb is a Qualified Entity under Austria's Qualifizierte-Einrichtungen-Gesetz, letting it bring collective Article 80(2) redress actions.
What it asks of an app →
Sensitive categories
cite Regulation (EU) 2016/679, Art. 9, as applied in Austria
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Article 9(1) prohibits processing special categories of personal data, including biometric data processed to uniquely identify a person, unless a listed Article 9(2) exception applies, most often explicit consent. Austria adds no separate statutory biometric regime alongside General Data Protection Regulation (GDPR) Article 9. The Datenschutzbehorde found in 2021 that Clearview AI's scraped facial recognition database was unlawful under Austrian data protection law for processing biometric data without a lawful basis.
No Austria-specific guidance on voiceprint biometrics specifically was found in this research; the GDPR baseline, that a voiceprint captured through specific technical processing for identification is special category data on the same footing as a faceprint, governs by default.
What it asks of an app →