Skip to the content
Global Data RulesData governance rules, country by country

Austria

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Active

Austria does not require personal data to be kept in Austria, and we found no Austrian industry that does. Data can leave once the right paperwork is in place under European rules. What Austria adds is a secrecy layer: a constitutional right to data secrecy, a staff secrecy duty, an extra fine of up to 50,000 euros (about $58,000), and a prison offence of up to one year.

Eight questions about Austria

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Austria's rules apply to my company?

Yes. A company with no office in Austria is still caught if it offers goods or services to people in Austria, or watches what they do online. There is no size or revenue floor to duck under. If you have no establishment anywhere in the European Union, you must name a representative inside the Union in writing. Austria does not add a second, Austria-only representative on top of that.

High confidenceBloc rulesNational rulesAppoint a local representative

Can I store my users' data outside Austria?

Yes, with paperwork. We looked for an Austrian rule forcing data to stay in Austria and found none — not in banking, payments, insurance, securities, health, telecoms, government or mapping. Austrian health data is the closest thing to a wall, but it is a technical wall, not a geographic one: findings move only inside a closed, encrypted Austrian health network between registered care providers. Checked on 18 August 2026.

Medium confidenceYes, with paperworkAllowlistFinanceHealth and social careGovernmentTelecoms

What do I need in place before data leaves Austria?

The model is an approved-destination list. Sending data outside Europe is fine if the destination is on the European Commission's approved list. If it is not, you sign the European standard contract, or use approved group-wide rules, and you write down a short risk assessment first. You do not need permission from the Austrian regulator. Its own words: apart from a few special cases, international data traffic needs no approval.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesCertification schemeApproved code of conductExplicit consentNeeded for a contractLegal claimsPut a transfer safeguard in place

Who enforces the rules in Austria, and what can they do?

The Austrian Data Protection Authority, and it is genuinely working. It has had a permanent head, Matthias Schmidl, since 1 January 2024, a deputy, and five departments. It issues decisions, and on 24 June 2026 Austria's highest administrative court confirmed a 13 million euro fine (about $15 million) for building political-opinion profiles on around 2.2 million people. The court held the fine is measured against the whole group's turnover, not one product line.

High confidenceActivePercentage of global turnoverOrder to stop

How long do I have to keep the data?

There is a ceiling and a floor, and they pull against each other. The ceiling is European: keep personal data no longer than you need it, then delete it. The floor is Austrian tax and company law, which makes you keep books, invoices and business records for years after the year they relate to. Where the two clash, the keeping duty wins for as long as it runs, and the data must then be deleted.

Medium confidenceDelete data after a periodKeep data for a minimum periodLet people delete their data

What happens if there is a breach?

Count at least two clocks, sometimes four. For a personal data breach you tell the Austrian Data Protection Authority without delay and if possible within 72 hours, and if you are late you must explain in writing why. If you run an essential service you also report significant incidents to Austria's network security authority. Banks and insurers report separately under European financial rules, and telecom operators have their own duty.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Austria?

Five that cost people their weekend. A child can consent at fourteen in Austria, not sixteen. Misusing data you only learned about through your job is a crime punishable by up to a year in prison. There is a second, separate Austrian fine of up to 50,000 euros (about $58,000) for breaking data secrecy or running a camera unlawfully. Austrian public bodies cannot be fined at all, but you still can. And the law tells the regulator to warn first, which is not the same as forgiveness.

High confidenceGet a parent's consent for childrenExtra vendor secrecy termsCriminal liabilityFixed maximum fineChildren's data

What is changing soon in Austria?

Three things to watch. Austria's Constitutional Court is deciding whether the state may plant software on a phone to read messages; it heard the case on 22 June 2026 and has not ruled. Austria has still not written the new European cybersecurity rules into national law, so that expansion is still ahead of you. And from 12 January 2027, cloud providers across Europe may no longer charge you to move your data out.

High confidenceProposedMake switching cloud provider possible

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    2 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    3 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules2 rules

Verordnung (EU) 2016/679 (Datenschutz-Grundverordnung, DSGVO)

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European baseline that governs Austria. It sets the conditions for data leaving Europe rather than requiring it to stay. Fines are the higher of a cash cap or a share of worldwide group turnover — and Austria's highest administrative court confirmed on 24 June 2026 that group turnover, not product turnover, is the measure.

In force since 25 May 2018

Enforced by Austrian Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Datenverordnung — Verordnung (EU) 2023/2854 (Data Act)

Directly binding regulation · Regulation (EU) 2023/2854

Partly in forceYes, with paperwork

Applies in Austria since 12 September 2025. The date that matters is 12 January 2027, when European cloud providers may no longer charge anything to move your data out. It also restricts handing non-personal data held in Europe to non-European governments. It imposes no storage location requirement.

In force since 12 September 2025But only enforceable from 12 January 2027

Enforced by Austrian Regulatory Authority for Broadcasting and Telecommunications

High confidence

National rules3 rules

Bundesgesetz zum Schutz natürlicher Personen bei der Verarbeitung personenbezogener Daten (Datenschutzgesetz – DSG)

Act of parliament · BGBl. I Nr. 165/1999, last amended by BGBl. I Nr. 50/2025 (Informationsfreiheits-Anpassungsgesetz)

In forceYes, with paperwork

Austria's own data protection law, sitting on top of the European rules. Its first section is a constitutional right to have your personal data kept secret. It adds a staff data-secrecy duty, its own surveillance-camera rules, an age of fourteen for children's consent, a separate 50,000 euro fine and a criminal offence carrying up to a year in prison.

In force since 1 January 2000But only enforceable from 25 May 2018

Enforced by Austrian Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

DSG § 30 Abs. 1 und 2 — Allgemeine Bedingungen für die Verhängung von Geldbußen

Act of parliament · BGBl. I Nr. 165/1999 as amended, § 30(1)-(2)

UnenforceableYes, with paperwork

Still printed in Austrian law: a company can only be fined if the breach is traced to a person in a leadership position. That filter once got an 18 million euro fine against a large Austrian company overturned. European case law has since held that a company is directly liable, and in June 2026 Austria's highest administrative court confirmed a 13 million euro fine measured on group turnover. Read as unenforceable as a shield, not as a defence.

In force since 25 May 2018

Enforced by Austrian Data Protection Authority

Medium confidence

Staatsschutz- und Nachrichtendienst-Gesetz (SNG), § 11 Abs. 1 Z 9 — Überwachung von Nachrichten mittels Messenger-Diensten

Act of parliament · Introduced July 2025; under constitutional challenge as case G 13-14/2026 · Telecoms

In forceYes, with paperwork

Austria's state security service may monitor encrypted messages by installing software on a target's device. Sixty-seven members of parliament challenged the power as a breach of the constitutional right to data protection. The Constitutional Court heard the case on 22 June 2026 and has not yet ruled. It struck down the earlier version of this power in 2019, so treat the rule as in force but fragile.

Enforced by Constitutional Court of Austria

High confidence

Industry rules3 rules

Gesundheitstelematikgesetz 2012 (GTelG 2012), with the eHealth-Verordnung 2025 and the ELGA-Verordnung 2015

Act of parliament · Health and social care

In forceYes, with paperwork

Austria's health data regime is a technical wall rather than a border. Electronic health record findings are stored across many care providers rather than centrally, move only encrypted inside dedicated secure health networks, and may be read only by a registered provider during an active treatment relationship, with every access logged. No rule found requiring the data to physically stay in Austria, checked 18 August 2026.

In force since 1 January 2013But only enforceable from 9 December 2015

Enforced by ELGA GmbH

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Medium confidence

Netz- und Informationssystemsicherheitsgesetz (NISG)

Act of parliament · Implements Directive (EU) 2016/1148; RIS Gesetzesnummer 20010536, with the NIS-Verordnung (20010722) · Government

In forceYes, with paperwork

Austria's cybersecurity law still implements the 2016 European directive, not the 2022 replacement. As at 18 August 2026 the government's own network security portal says the existing framework still needs adapting for the newer directive, whose transposition deadline was 17 October 2024. Scope today is therefore much narrower than most European planning assumes.

In force since 29 December 2018

Enforced by Austrian Network and Information Security Authority

Medium confidence

Informationsfreiheitsgesetz (IFG)

Act of parliament · BGBl. I Nr. 5/2024 · Government

In forceYes, with paperwork

Austria abolished official secrecy on 1 September 2025. Public bodies must publish information of general interest and answer information requests, and the Data Protection Authority advises them on where personal data must be held back. If you contract with an Austrian public body, assume documents you send may become disclosable.

In force since 1 September 2025

Enforced by Austrian Data Protection Authority

High confidence

Who you would hear from

  • Datenschutzbehörde

    General data protection law, and advice to public bodies under the Freedom of Information Act

    Fully staffed and deciding. Led by Matthias Schmidl since 1 January 2024, with a deputy and five departments. Its decisions are being upheld on appeal: Austria's highest administrative court confirmed a EUR 13 million fine on 24 June 2026. Note that Austrian law tells it to warn rather than fine on first breaches, and forbids it from fining public bodies at all.

  • Verfassungsgerichtshof

    Constitutional review, including the constitutional right to data secrecy and state surveillance powers

    Active. Heard the challenge to messenger surveillance on 22 June 2026 and issued the first Freedom of Information rulings on 14 July 2026.

  • Verwaltungsgerichtshof

    Final appeals against data protection fines and orders

    Decided Ro 2025/04/0007-7 on 24 June 2026, setting the fine at EUR 13 million and holding group-wide turnover to be the correct measure.

  • NIS-Behörde (Bundesministerium für Inneres)

    Cybersecurity of essential services, digital services and public administration

    Operating under the older 2016 European directive. Its own portal states that the framework still needs adapting for the 2022 directive, so its scope today is narrower than most planning assumes.

  • Finanzmarktaufsicht

    Banks, insurers, investment firms, payment and e-money institutions

    Active. Supervises operational resilience under the European financial resilience rules since 17 January 2025. Publishes no circular imposing cloud or data location requirements.

  • Rundfunk und Telekom Regulierungs-GmbH (RTR)

    Telecoms and postal regulation; also the national contact point for European data rules

  • ELGA GmbH

    Austria's electronic health record system

  • Parlamentarisches Datenschutzkomitee

    Complaints about data processing by the Austrian Parliament, which are excluded from the Data Protection Authority's remit

    Created by law and given its own complaint procedure. We could not verify from an official source that it has issued any decisions, so treat its practical activity as unconfirmed rather than absent.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The Austrian record retention floor of seven years for books, invoices and business records under the Federal Fiscal Code and the Commercial Code

    The Austrian legal information system blocked automated access to those statutes during this run, and the tax ministry and business portal pages we tried returned errors. The figure is widely used but we have no government backlink for it, so it is stated as medium confidence.

  • That Austria has no telecom data retention obligation today, following the Constitutional Court's 2014 annulment

    We could not open an official Austrian source for the 2014 judgment or for the current telecoms act in this run. Treat the absence of a retention duty as probable but unverified, and re-check before relying on it.

  • Whether any localisation or storage rule exists in Austrian gambling, education, defence or mapping and surveying law

    Not checked this run. Effort was spent on finance, health, telecoms, government and cybersecurity. This is a genuine gap, not a finding of no rule.

  • The exact incident reporting deadline in hours under the Austrian network and information security law

    The government's own network security portal describes the duty to report significant incidents but does not publish the deadline. We declined to state a number rather than guess.

  • That the attribution filter in DSG § 30(1)-(2) is unenforceable following European case law

    This is our reading. The text is still printed in the consolidated law, and the June 2026 court decision confirming a fine on group turnover is consistent with it, but no Austrian source we could open says in terms that the provision is disapplied.

  • Whether the constitutional right to data secrecy in DSG § 1 extends to companies as well as individuals

    The provision says 'Jedermann' — everyone — while the law's title refers to natural persons. Austrian case law is said to read it broadly. We could not verify this against a court source in this run.

  • Whether a bill transposing the 2022 European cybersecurity directive is currently before the Austrian Parliament

    The parliament's website could not be searched during this run. We can evidence only that the government's network security portal still presents the older law as the operative one on 18 August 2026.

  • Whether the Constitutional Court has ruled on messenger surveillance since the 22 June 2026 hearing

    The court's own 2026 news list shows no decision announcement up to 31 July 2026. We cannot prove a negative for the days since.

60-day cadence. Two Austrian items can move without warning: the Constitutional Court's pending ruling on messenger surveillance, which could disapply an in-force surveillance power overnight, and the overdue transposition of the 2022 European cybersecurity directive, which will widen scope sharply the moment it lands. The bloc layer adds a third: the European-United States transfer framework is under active examination.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.