Skip to the content
Global Data RulesData governance rules, country by country

Austria

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Austria — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Active

You can store Austrian personal data outside Austria. We found no Austrian industry that has to keep data in the country. Data can leave once the right paperwork is in place under European rules. What Austria adds is secrecy. There is a constitutional right to have your data kept secret. Staff must be bound to secrecy. There is an extra fine of up to 50,000 euros (about 58,000 US dollars). And there is a crime carrying up to one year in prison.

Data governance in Austria

The eight things that decide how you handle data about people in Austria. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. A company with no office in Austria is still covered if it offers goods or services to people in Austria. The same applies if it watches what they do online. There is no size or revenue floor to fall below. If you have no office anywhere in the European Union, you must name a representative inside the Union, in writing. Austria does not add a second, Austria-only representative on top of that.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, with paperwork. We looked for an Austrian rule forcing data to stay in Austria and found none. We checked banking, payments, insurance, securities, health, telecoms, government and mapping. Austrian health data is the closest thing to a wall, but it is a technical one, not a border. Findings move only inside a closed, encrypted Austrian health network, between registered care providers. Checked on 18 August 2026.

What to do: Get the paperwork for one of the routes below signed before any data leaves Austria.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

You send data to countries on an approved list. Sending data outside Europe is fine if the destination is on the European Commission's approved list. If it is not, you sign the European standard contract, or use approved group-wide rules. You also write down a short risk assessment first. You do not need permission from the Austrian regulator. In its own words, apart from a few special cases, international data traffic needs no approval.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Austrian Data Protection Authority, and it is working. It has had a permanent head, Matthias Schmidl, since 1 January 2024. It has a deputy and five departments. It issues decisions. On 24 June 2026 Austria's highest administrative court confirmed a 13 million euro fine (about 15 million US dollars). That was for building profiles of people's political opinions, covering around 2.2 million people. The court held that the fine is measured against the whole group's turnover, not one product line.

What it costs if you get it wrong:
Percentage of global turnover · Order to stop

How long you must keep it — and when to delete it

There is a maximum and a minimum, and they pull against each other. The maximum is European. Keep personal data no longer than you need it, then delete it. The minimum is Austrian tax and company law. It makes you keep books, invoices and business records for years after the year they relate to. Where the two clash, the duty to keep wins for as long as it runs. The data must then be deleted.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Let people delete their data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

Count at least two deadlines, sometimes four. For a personal data breach you tell the Austrian Data Protection Authority without delay, and if possible within 72 hours. If you are late, you must explain in writing why. If you run an essential service, you also report significant incidents to Austria's network security authority. Banks and insurers report separately under European financial rules. Telecom operators have their own duty.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. A child can consent at fourteen in Austria, not sixteen. Misusing data you only learned about through your job is a crime, punishable by up to a year in prison. There is a second, separate Austrian fine of up to 50,000 euros (about 58,000 US dollars). It covers breaking data secrecy or running a camera unlawfully. Austrian public bodies cannot be fined at all, but you still can. And the law tells the regulator to warn first, which is not the same as forgiveness.

What you have to do here:
Get a parent's consent for children · Extra vendor secrecy terms
What it costs if you get it wrong:
Criminal liability · Fixed maximum fine

What's changing next

Three things to watch. Austria's Constitutional Court is deciding whether the state may put software on a phone to read messages. It heard the case on 22 June 2026 and has not ruled. Austria has still not written the new European cybersecurity rules into national law, so that expansion is still ahead of you. And from 12 January 2027, cloud providers across Europe may no longer charge you to move your data out.

What you have to do here:
Make switching cloud provider possible

What to do: Diarise 12 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Health and social care

Health data rules

Official name: Gesundheitstelematikgesetz 2012 (GTelG 2012), with the eHealth-Verordnung 2025 and the ELGA-Verordnung 2015 · Act of parliament

In forceYes, with paperwork

Austria's health data rules build a technical wall, not a border. Electronic health record findings are stored across many care providers rather than in one place. They move only in encrypted form, inside dedicated secure health networks. Only a registered provider may read them, and only during an active treatment relationship. Every access is logged. We found no rule requiring the data to physically stay in Austria, checked 18 August 2026.

In force since 1 January 2013Enforced from 9 December 2015

Enforced by ELGA GmbH

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Not fully verified — see “What we're not sure about” below.
Government

Cyber security rules

Official name: Netz- und Informationssystemsicherheitsgesetz (NISG) · Implements Directive (EU) 2016/1148; RIS Gesetzesnummer 20010536, with the NIS-Verordnung (20010722) · Act of parliament

In forceYes, with paperwork

Austria's cybersecurity law still implements the 2016 European directive, not the 2022 replacement. As at 18 August 2026 the government's own network security portal says the existing rules still need adapting for the newer directive. The deadline to write that into national law was 17 October 2024. So what the law covers today is much narrower than most European planning assumes.

In force since 29 December 2018

Enforced by Austrian Network and Information Security Authority

Not fully verified — see “What we're not sure about” below.
Government

General data protection law

Official name: Informationsfreiheitsgesetz (IFG) · BGBl. I Nr. 5/2024 · Act of parliament

In forceYes, with paperwork

Austria abolished official secrecy on 1 September 2025. Public bodies must publish information of general interest and answer information requests. The Data Protection Authority advises them on where personal data must be held back. If you contract with an Austrian public body, assume documents you send may have to be disclosed.

In force since 1 September 2025

Enforced by Austrian Data Protection Authority

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Bundesgesetz zum Schutz natürlicher Personen bei der Verarbeitung personenbezogener Daten (Datenschutzgesetz – DSG) · BGBl. I Nr. 165/1999, last amended by BGBl. I Nr. 50/2025 (Informationsfreiheits-Anpassungsgesetz) · Act of parliament

In forceYes, with paperwork

Austria's own data protection law, sitting on top of the European rules. Its first section is a constitutional right to have your personal data kept secret. It adds a staff secrecy duty and its own surveillance-camera rules. It sets the age of children's consent at fourteen. It adds a separate 50,000 euro fine and a crime carrying up to a year in prison.

In force since 1 January 2000Enforced from 25 May 2018

Enforced by Austrian Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Telecoms

Breach reporting rules (Telecoms)

Official name: Staatsschutz- und Nachrichtendienst-Gesetz (SNG), § 11 Abs. 1 Z 9 — Überwachung von Nachrichten mittels Messenger-Diensten · Introduced July 2025; under constitutional challenge as case G 13-14/2026 · Act of parliament

In forceYes, with paperwork

Austria's state security service may read encrypted messages by installing software on a target's device. Sixty-seven members of parliament challenged that power as a breach of the constitutional right to data protection. The Constitutional Court heard the case on 22 June 2026 and has not yet ruled. It struck down the earlier version of this power in 2019. So the rule applies today, but it may not survive.

Enforced by Constitutional Court of Austria

Applies across the European Union2 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Verordnung (EU) 2016/679 (Datenschutz-Grundverordnung, DSGVO) · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

The European baseline that governs Austria. It sets the conditions for data leaving Europe. It does not require data to stay. Fines are the higher of a cash cap or a share of worldwide group turnover. Austria's highest administrative court confirmed on 24 June 2026 that group turnover, not product turnover, is the measure.

In force since 25 May 2018

Enforced by Austrian Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Cloud and outsourcing rules

Official name: Datenverordnung — Verordnung (EU) 2023/2854 (Data Act) · Regulation (EU) 2023/2854 · Directly binding regulation

Partly in forceYes, with paperwork

Applies in Austria since 12 September 2025. The date that matters is 12 January 2027. From then, European cloud providers may no longer charge anything to move your data out. It also limits handing non-personal data held in Europe to non-European governments. It does not require data to be stored anywhere in particular.

In force since 12 September 2025In force now, but not enforced until 12 January 2027

That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by Austrian Regulatory Authority for Broadcasting and Telecommunications

On the books, but not enforceable1 rule

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

Breach reporting rules

Official name: DSG § 30 Abs. 1 und 2 — Allgemeine Bedingungen für die Verhängung von Geldbußen · BGBl. I Nr. 165/1999 as amended, § 30(1)-(2) · Act of parliament

UnenforceableYes, with paperwork

Still printed in Austrian law: a company can only be fined if the breach is traced to someone in a leadership position. That filter once got an 18 million euro fine against a large Austrian company overturned. European case law has since held that a company is directly liable. In June 2026 Austria's highest administrative court confirmed a 13 million euro fine measured on group turnover. Do not treat this filter as a defence. It no longer protects you.

In force since 25 May 2018

Enforced by Austrian Data Protection Authority

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Datenschutzbehörde

    General data protection law, and advice to public bodies under the Freedom of Information Act

    Fully staffed and deciding cases. Led by Matthias Schmidl since 1 January 2024, with a deputy and five departments. Its decisions are being upheld on appeal. Austria's highest administrative court confirmed a 13 million euro fine on 24 June 2026. Note that Austrian law tells it to warn rather than fine on first breaches. It also forbids it from fining public bodies at all.

  • Verfassungsgerichtshof

    Constitutional review, including the constitutional right to data secrecy and state surveillance powers

    Active. It heard the challenge to messenger surveillance on 22 June 2026. It issued the first Freedom of Information rulings on 14 July 2026.

  • Verwaltungsgerichtshof

    Final appeals against data protection fines and orders

    Decided Ro 2025/04/0007-7 on 24 June 2026. It set the fine at 13 million euros and held that group-wide turnover is the correct measure.

  • NIS-Behörde (Bundesministerium für Inneres)

    Cybersecurity of essential services, digital services and public administration

    Still operating under the older 2016 European directive. Its own portal says the rules still need adapting for the 2022 directive. So what it covers today is narrower than most planning assumes.

  • Finanzmarktaufsicht

    Banks, insurers, investment firms, payment and e-money institutions

    Active. It supervises operational resilience under the European financial resilience rules since 17 January 2025. It publishes no circular requiring anything about cloud or where data sits.

  • Rundfunk und Telekom Regulierungs-GmbH (RTR)

    Telecoms and postal regulation; also the national contact point for European data rules

  • ELGA GmbH

    Austria's electronic health record system

  • Parlamentarisches Datenschutzkomitee

    Complaints about data processing by the Austrian Parliament, which are excluded from the Data Protection Authority's remit

    Created by law and given its own complaint procedure. We could not confirm from an official source that it has issued any decisions. Treat its activity as unconfirmed rather than absent.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The Austrian record retention floor of seven years for books, invoices and business records under the Federal Fiscal Code and the Commercial Code

    The Austrian legal information system blocked our access to those laws. The tax ministry and business portal pages we tried returned errors. The seven-year figure is widely used, but we have no government source for it. So it is stated as medium confidence. Confirm it with your accountant before you rely on it.

  • That Austria has no telecom data retention obligation today, following the Constitutional Court's 2014 annulment

    We could not open an official Austrian source for the 2014 judgment, or for the current telecoms law. Treat the absence of a duty to keep telecom data as likely but unconfirmed. Check it before you rely on it.

  • Whether any localisation or storage rule exists in Austrian gambling, education, defence or mapping and surveying law

    We did not check these industries. Our effort went to finance, health, telecoms, government and cybersecurity. This is a gap in our work, not a finding that no rule exists. If you work in gambling, education, defence or mapping, check before you rely on this.

  • The exact incident reporting deadline in hours under the Austrian network and information security law

    The government's own network security portal describes the duty to report significant incidents. It does not publish the deadline. We chose not to state a number rather than guess. Ask the authority for the deadline that applies to you.

  • That the attribution filter in DSG § 30(1)-(2) is unenforceable following European case law

    This is our reading, not a government statement. The text is still printed in the consolidated law. The June 2026 court decision confirming a fine on group turnover fits our reading. But no Austrian source we could open says outright that the rule no longer applies. Take advice before relying on it.

  • Whether the constitutional right to data secrecy in DSG § 1 extends to companies as well as individuals

    The rule says 'Jedermann', meaning everyone, while the law's title refers to natural persons. Austrian case law is said to read it broadly. We could not check this against a court source. Take advice if your company wants to rely on the right.

  • Whether a bill transposing the 2022 European cybersecurity directive is currently before the Austrian Parliament

    We could not search the parliament's website. All we can show is that the government's network security portal still presents the older law as the one in force on 18 August 2026. Check the parliament's site before you plan around a new law.

  • Whether the Constitutional Court has ruled on messenger surveillance since the 22 June 2026 hearing

    The court's own 2026 news list shows no decision announced up to 31 July 2026. We cannot confirm the position for the days since. Check the court's site for a ruling before you rely on this.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.