Austria
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Austria does not require personal data to be kept in Austria, and we found no Austrian industry that does. Data can leave once the right paperwork is in place under European rules. What Austria adds is a secrecy layer: a constitutional right to data secrecy, a staff secrecy duty, an extra fine of up to 50,000 euros (about $58,000), and a prison offence of up to one year.
Eight questions about Austria
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Austria's rules apply to my company?
Yes. A company with no office in Austria is still caught if it offers goods or services to people in Austria, or watches what they do online. There is no size or revenue floor to duck under. If you have no establishment anywhere in the European Union, you must name a representative inside the Union in writing. Austria does not add a second, Austria-only representative on top of that.
Reach comes from Article 3 of the General Data Protection Regulation; the written representative comes from Article 27. The Austrian Data Protection Act (Datenschutzgesetz, DSG) sits on top and adds national detail rather than a separate territorial test. One Austrian layer is genuinely broader than the European one: the constitutional right in § 1 DSG is drafted as 'Jedermann hat ... Anspruch auf Geheimhaltung der ihn betreffenden personenbezogenen Daten' — 'everyone has a claim to secrecy of the personal data concerning them' — and it is a constitutional provision (Verfassungsbestimmung), not ordinary law, so it can only be changed by a two-thirds majority.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceRechtsinformationssystem des Bundes (Federal Chancellery)Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999, consolidated version as at 18 August 2026, § 1
ris.bka.gv.at
“Jedermann hat, insbesondere auch im Hinblick auf die Achtung seines Privat- und Familienlebens, Anspruch auf Geheimhaltung der ihn betreffenden personenbezogenen Daten, soweit ein schutzwürdiges Interesse daran besteht.”
Link checked 18 August 2026
Can I store my users' data outside Austria?
Yes, with paperwork. We looked for an Austrian rule forcing data to stay in Austria and found none — not in banking, payments, insurance, securities, health, telecoms, government or mapping. Austrian health data is the closest thing to a wall, but it is a technical wall, not a geographic one: findings move only inside a closed, encrypted Austrian health network between registered care providers. Checked on 18 August 2026.
Sector by sector, as at 18 August 2026. FINANCE: the Austrian Financial Market Authority (Finanzmarktaufsicht, FMA) publishes its circulars in one place and none of them covers cloud, outsourcing location or data storage; the operative regime is the European Digital Operational Resilience Act, applying since 17 January 2025, which forces you to name the location where data is processed and to hold audit and exit rights, but imposes no localisation. HEALTH: the Health Telematics Act 2012 (Gesundheitstelematikgesetz 2012), the eHealth Regulation 2025 and the ELGA Regulation 2015 require encrypted transport inside dedicated secure health networks, storage that is decentralised across care providers, an active treatment relationship before any access, and full access logging — but the ministry's own description states no border rule. GOVERNMENT: the federal computing centre (Bundesrechenzentrum) advertises 25,000 terabytes of Austrian storage but makes no legal residency claim, and we found no binding federal cloud-location rule. TELECOMS: we found no general obligation on operators to retain traffic data for law enforcement; Austria's retention law was annulled by the Constitutional Court in 2014, but we could not open an official Austrian source for that in this run, so treat it as medium confidence. EDUCATION, GAMING, DEFENCE and MAPPING: not verified this run, listed as gaps below. Separately, Regulation (EU) 2018/1807 forbids Austria from imposing localisation on non-personal data except on public-security grounds.
Sources
- Official sourceDatenschutzbehördeInternationaler Datenverkehr — the Austrian Data Protection Authority on transfers to third countries
dsb.gv.at
“Im Unterschied zur alten Rechtslage nach der Richtlinie 95/46/EG ist der internationale Datenverkehr bis auf wenige Sonderfälle genehmigungsfrei.”
Link checked 18 August 2026
- Official sourceBundesministerium für Arbeit, Soziales, Gesundheit, Pflege und KonsumentenschutzeHealth and ELGA — legal framework: Gesundheitstelematikgesetz 2012, eHealth-Verordnung 2025, ELGA-Verordnung 2015
sozialministerium.gv.at
Link checked 18 August 2026
- Official sourceFinanzmarktaufsichtFMA-Rundschreiben — the complete published list of Austrian financial regulator circulars
fma.gv.at
Link checked 18 August 2026
- Official sourceFinanzmarktaufsichtDORA — Digital Operational Resilience Act, applicable from 17 January 2025
fma.gv.at
Link checked 18 August 2026
- Official sourceBundesrechenzentrum GmbHBundesrechenzentrum — Austria's federal computing centre
brz.gv.at
Link checked 18 August 2026
What do I need in place before data leaves Austria?
The model is an approved-destination list. Sending data outside Europe is fine if the destination is on the European Commission's approved list. If it is not, you sign the European standard contract, or use approved group-wide rules, and you write down a short risk assessment first. You do not need permission from the Austrian regulator. Its own words: apart from a few special cases, international data traffic needs no approval.
The approved list is populated and includes the United Kingdom (renewed 19 December 2025, running to 2031), Japan, South Korea, Switzerland, Canada for commercial bodies, Brazil (added 26 January 2026), and the United States only for companies self-certified under the EU-US Data Privacy Framework. The 2021 standard contractual clauses remain the operative set and are unamended; the promised extra clauses for importers already directly caught by European law are still not adopted. The Austrian regulator notes on its own site that an update to the Commission's clauses is planned. The United States route is the volatile one: it is still legally valid today, but the European Data Protection Board formally wrote to the Commission on 31 July 2026 asking it to examine whether recent changes in the United States affect the decision's validity, and an appeal against the General Court's dismissal in the Latombe case is pending. Never build on it as your only mechanism.
Sources
- Official sourceDatenschutzbehördeInternationaler Datenverkehr — mechanisms listed by the Austrian Data Protection Authority
dsb.gv.at
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the European Commission's own list of approved destinations
commission.europa.eu
Link checked 18 August 2026
Who enforces the rules in Austria, and what can they do?
The Austrian Data Protection Authority, and it is genuinely working. It has had a permanent head, Matthias Schmidl, since 1 January 2024, a deputy, and five departments. It issues decisions, and on 24 June 2026 Austria's highest administrative court confirmed a 13 million euro fine (about $15 million) for building political-opinion profiles on around 2.2 million people. The court held the fine is measured against the whole group's turnover, not one product line.
Case Ro 2025/04/0007-7, decided 24 June 2026 by the Verwaltungsgerichtshof. The authority is monocratic and independent, with no supervisory ministry above it. Two Austrian features pull in opposite directions. First, § 11 DSG instructs the authority to apply the European penalty catalogue proportionately and, especially for first-time breaches, to use a warning rather than a fine — this is why Austrian fine counts look low next to Ireland or Spain. Second, § 30(5) DSG says no fine at all may be imposed on authorities, public bodies or public-law corporations, so a large slice of Austrian processing is fine-free by statute. Austria also punches above its weight on doctrine rather than volume: the Austrian authority issued the first European decision holding a website's use of Google Analytics unlawful. Rating: active rather than aggressive — the output is decisive and now court-tested, but the volume is modest and the law itself tells the regulator to warn first.
Sources
- Official sourceDatenschutzbehördeLeitung und Organisation — head of the Austrian Data Protection Authority since 1 January 2024
dsb.gv.at
Link checked 18 August 2026
- Official sourceDatenschutzbehördeVwGH confirms unlawful processing of party affinities and sets the fine at EUR 13 million (Ro 2025/04/0007-7, 24 June 2026)
dsb.gv.at
“Der Verwaltungsgerichtshof bestätigte mit seiner Entscheidung den Kernvorwurf der Datenschutzbehörde hinsichtlich der unrechtmäßigen Verarbeitung besonderer Kategorien personenbezogener Daten”
Link checked 18 August 2026
- Official sourceRechtsinformationssystem des BundesDSG § 11 (warning by the authority) and § 30(5) (no fines on public bodies), consolidated text as at 18 August 2026
ris.bka.gv.at
“Gegen Behörden und öffentliche Stellen, wie insbesondere in Formen des öffentlichen Rechts sowie des Privatrechts eingerichtete Stellen, die im gesetzlichen Auftrag handeln, und gegen Körperschaften des öffentlichen Rechts können keine Geldbußen verhängt werden.”
Link checked 18 August 2026
How long do I have to keep the data?
There is a ceiling and a floor, and they pull against each other. The ceiling is European: keep personal data no longer than you need it, then delete it. The floor is Austrian tax and company law, which makes you keep books, invoices and business records for years after the year they relate to. Where the two clash, the keeping duty wins for as long as it runs, and the data must then be deleted.
The ceiling is the storage-limitation principle in Article 5(1)(e) of the General Data Protection Regulation, backed by the erasure right in Article 17, which expressly steps aside where processing is needed to meet a legal obligation. The Austrian floor sits in the Federal Fiscal Code (Bundesabgabenordnung) and the Commercial Code (Unternehmensgesetzbuch); the commonly applied figure is seven years from the end of the relevant financial year, with longer periods for property-related records. We could not open the official consolidated text of either statute during this run because the Austrian legal information system blocked automated access, so the seven-year figure is recorded as unconfirmed below and the confidence here is medium. Two Austrian points we did verify: the Data Protection Act itself imposes no general minimum log-retention duty on ordinary businesses, and there is no Austrian equivalent of a six-month blanket log-keeping direction. Practical rule: never build deletion automation that ignores the accounting floor, and never treat the accounting floor as a licence to keep the whole customer record.
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, Article 5(1)(e) storage limitation and Article 17(3)(b) erasure exception
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceRechtsinformationssystem des BundesDatenschutzgesetz, consolidated text as at 18 August 2026 — contains no general minimum retention or log-keeping duty
ris.bka.gv.at
Link checked 18 August 2026
What happens if there is a breach?
Count at least two clocks, sometimes four. For a personal data breach you tell the Austrian Data Protection Authority without delay and if possible within 72 hours, and if you are late you must explain in writing why. If you run an essential service you also report significant incidents to Austria's network security authority. Banks and insurers report separately under European financial rules, and telecom operators have their own duty.
The 72-hour clock and the duty to tell affected people come from Articles 33 and 34 of the General Data Protection Regulation; the Austrian regulator restates the deadline on its own site as 'unverzüglich und möglichst binnen 72 Stunden'. The second clock runs to the Austrian network and information security authority, which is the Ministry of the Interior, with reports filed through the government computer emergency teams at nis.govcert.gv.at, nis.cert.at and nis.energy-cert.at. The official Austrian network security portal does not publish the reporting deadline in hours, so we have not stated one — that is a gap, not a finding. The third clock is the Digital Operational Resilience Act for financial entities, live since 17 January 2025, which has its own initial, intermediate and final reporting stages. Where the same incident triggers several clocks, the shortest one governs your first hour, and the mismatch between them is the single most common operational failure.
Sources
- Official sourceDatenschutzbehördeIhre Pflichten als Verantwortlicher — breach notification within 72 hours
dsb.gv.at
“unverzüglich und möglichst binnen 72 Stunden”
Link checked 18 August 2026
- Official sourceNIS-Behörde, Bundesministerium für InneresAllgemeines zum NIS-Gesetz — duty to report significant incidents
nis.gv.at
“Mit dem NIS-Gesetz werden Maßnahmen festgelegt, mit denen ein hohes Sicherheitsniveau von Netz- und Informationssystemen erreicht werden soll.”
Link checked 18 August 2026
What trips people up in Austria?
Five that cost people their weekend. A child can consent at fourteen in Austria, not sixteen. Misusing data you only learned about through your job is a crime punishable by up to a year in prison. There is a second, separate Austrian fine of up to 50,000 euros (about $58,000) for breaking data secrecy or running a camera unlawfully. Austrian public bodies cannot be fined at all, but you still can. And the law tells the regulator to warn first, which is not the same as forgiveness.
(1) AGE FOURTEEN. § 4(4) DSG makes a child's consent to an online service valid once the child has completed their fourteenth year — Austria took the lowest option the European rule allows, so an age gate built for Germany's sixteen will be wrong here and one built for thirteen will also be wrong. (2) CRIMINAL LIABILITY. § 63 DSG punishes using, disclosing or publishing personal data entrusted to you through your job, with intent to enrich yourself or to harm someone's right to secrecy, with up to one year's imprisonment or a fine of up to 720 daily income units. This attaches to individuals, not the company. (3) THE SECOND FINE. § 62 DSG creates an administrative offence carrying up to 50,000 euros for, among other things, deliberately breaching the data-secrecy duty or operating image capture contrary to the rules — and attempt is punishable. It bites only where European fines do not, so it is easy to miss. (4) DATA SECRECY IS A CONTRACT DUTY. § 6 DSG requires controllers and processors to bind their staff contractually to transmit personal data only on express instruction and to keep the data secret even after the job ends. A standard European processor agreement does not do this by itself. (5) PUBLIC BODIES ARE FINE-FREE. § 30(5) DSG bars fines against authorities, public bodies acting on statutory mandate and public-law corporations — your Austrian government customer carries no fine risk, so it will not share your urgency, and the risk lands on you. (6) A SEPARATE REGULATOR FOR PARLIAMENT. Complaints about data processing by the Austrian Parliament go to a Parliamentary Data Protection Committee, not to the Data Protection Authority. (7) SURVEILLANCE CAMERAS. Austria keeps its own image-processing rules in §§ 12 and 13 DSG on top of European law, including specific security and signage duties.
Sources
- Official sourceRechtsinformationssystem des BundesDatenschutzgesetz §§ 4(4), 6, 12, 13, 24, 30, 62 and 63, consolidated text as at 18 August 2026
ris.bka.gv.at
“Bei einem Angebot von Diensten der Informationsgesellschaft, das einem Kind direkt gemacht wird, ist die Einwilligung gemäß Art. 6 Abs. 1 lit. a DSGVO zur Verarbeitung der personenbezogenen Daten des Kindes rechtmäßig, wenn das Kind das vierzehnte Lebensjahr vollendet hat.”
Link checked 18 August 2026
- Official sourceDatenschutzbehördeController duties, including the two Austrian impact-assessment regulations
dsb.gv.at
Link checked 18 August 2026
What is changing soon in Austria?
Three things to watch. Austria's Constitutional Court is deciding whether the state may plant software on a phone to read messages; it heard the case on 22 June 2026 and has not ruled. Austria has still not written the new European cybersecurity rules into national law, so that expansion is still ahead of you. And from 12 January 2027, cloud providers across Europe may no longer charge you to move your data out.
PENDING COURT CASE. Sixty-seven members of the Austrian Parliament challenged § 11(1)(9) of the State Protection and Intelligence Service Act (Staatsschutz- und Nachrichtendienst-Gesetz), introduced in July 2025, which allows monitoring of encrypted messages by installing software on a target's computer system. The case is G 13-14/2026 and the oral hearing was held on 22 June 2026. Austria's Constitutional Court struck down the predecessor surveillance software provisions in 2019, so a second annulment is a live possibility — a rule that reads as binding today could become unenforceable overnight. NIS2 STILL MISSING. As at 18 August 2026 the Austrian government's own network security portal still describes the national law as implementing the 2016 directive and says the existing framework 'requires adaptation' for the newer one. The transposition deadline was 17 October 2024. When it lands, scope widens sharply into manufacturing, food, waste, postal services and digital providers, and registration windows in other member states have been short. DORMANT SWITCHES. Three matter. The Data Protection Authority can order a company to suspend flows to a third country, which usually hurts more than a fine. The government could reintroduce telecom data retention by ordinary legislation at any time. And the Freedom of Information Act, in force since 1 September 2025, is only now being tested — Austria's Constitutional Court gave its first rulings on 14 July 2026, including on a state-owned bank, so expect a widening pool of documents that companies dealing with Austrian public bodies can no longer assume stay private.
Sources
- Official sourceVerfassungsgerichtshofOral hearing of the Constitutional Court on the monitoring of messenger services, case G 13-14/2026, 22 June 2026
vfgh.gv.at
Link checked 18 August 2026
- Official sourceNIS-Behörde, Bundesministerium für InneresNIS-2-Richtlinie — the Austrian network security authority on transposition still to come
nis.gv.at
“Mit der Umsetzung der NIS-2-Richtlinie in Österreich bedarf auch die bestehende Systematik rund um das NISG einer Anpassung.”
Link checked 18 August 2026
- Official sourceVerfassungsgerichtshofConstitutional Court 2026 news list, including the first Freedom of Information rulings of 14 July 2026 (E 3982/2025)
vfgh.gv.at
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionData Act, Regulation (EU) 2023/2854 — cloud switching charges fall to zero on 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
2 rules here
Layer 2
National rules
Added by this country on top of any bloc rules.
3 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
3 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules2 rules
Verordnung (EU) 2016/679 (Datenschutz-Grundverordnung, DSGVO)
Directly binding regulation · Regulation (EU) 2016/679
The European baseline that governs Austria. It sets the conditions for data leaving Europe rather than requiring it to stay. Fines are the higher of a cash cap or a share of worldwide group turnover — and Austria's highest administrative court confirmed on 24 June 2026 that group turnover, not product turnover, is the measure.
Enforced by Austrian Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of processing
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projectsAustria has two national regulations naming processing that always needs an assessment and processing that never does.
- Written vendor contract
- Appoint a local representativeRequired where there is no establishment anywhere in the European Union.
- Put a transfer safeguard in placePlus a written transfer risk assessment following the Schrems II judgment.
- Do not hand data to foreign authorities on demandAn order from a non-European authority is not by itself a lawful basis to hand data over.
- Delete data after a period
- Get a parent's consent for children — applies at: 14 in Austria
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $23 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $12 millionController and processor obligations
- Order to stopThe regulator can ban processing or suspend flows to a third country
- Claims by individualsIndividuals can claim compensation
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceDatenschutzbehördeVwGH Ro 2025/04/0007-7, 24 June 2026 — group-wide annual turnover is decisive for the fine
dsb.gv.at
Link checked 18 August 2026
Datenverordnung — Verordnung (EU) 2023/2854 (Data Act)
Directly binding regulation · Regulation (EU) 2023/2854
Applies in Austria since 12 September 2025. The date that matters is 12 January 2027, when European cloud providers may no longer charge anything to move your data out. It also restricts handing non-personal data held in Europe to non-European governments. It imposes no storage location requirement.
Enforced by Austrian Regulatory Authority for Broadcasting and Telecommunications
What it makes you do
- Make switching cloud provider possible — from 12 January 2027All cloud switching charges and data egress fees must fall to zero.
- Do not hand data to foreign authorities on demandRestricts non-European government access to non-personal data held in Europe.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act)
eur-lex.europa.eu
Link checked 18 August 2026
National rules3 rules
Bundesgesetz zum Schutz natürlicher Personen bei der Verarbeitung personenbezogener Daten (Datenschutzgesetz – DSG)
Act of parliament · BGBl. I Nr. 165/1999, last amended by BGBl. I Nr. 50/2025 (Informationsfreiheits-Anpassungsgesetz)
Austria's own data protection law, sitting on top of the European rules. Its first section is a constitutional right to have your personal data kept secret. It adds a staff data-secrecy duty, its own surveillance-camera rules, an age of fourteen for children's consent, a separate 50,000 euro fine and a criminal offence carrying up to a year in prison.
Enforced by Austrian Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Extra vendor secrecy termsData secrecy: staff must be contractually bound to transmit data only on express instruction, and to keep it secret after leaving.
- Get a parent's consent for children — applies at: Consent to an online service is valid once the child has completed their fourteenth year
- Appoint a data protection officerMandatory for public bodies, large-scale systematic monitoring and large-scale sensitive data; contact details must be given to the authority.
- Secure the dataExtra security and signage duties apply to image capture (surveillance cameras).
- Tell people what you do
What it costs if you get it wrong
- Fixed maximum fine: €50,000 — about $58 thousandDeliberate breach of data secrecy, unlawful access, unlawful image capture, or refusing an inspection — where no European fine applies. Attempt is punishable.
- Criminal liability: Up to 1 year imprisonment or up to 720 daily income unitsUsing, disclosing or publishing personal data learned through your job, with intent to enrich yourself or to harm someone's right to secrecy
Sources
- Official sourceRechtsinformationssystem des Bundes, BundeskanzleramtDatenschutzgesetz (DSG), consolidated federal law as at 18 August 2026
ris.bka.gv.at
“Sofern die Tat nicht einen Tatbestand nach Art. 83 DSGVO verwirklicht oder nach anderen Verwaltungsstrafbestimmungen mit strengerer Strafe bedroht ist, begeht eine Verwaltungsübertretung, die mit Geldstrafe bis zu 50 000 Euro zu ahnden ist, wer ...”
Link checked 18 August 2026
- Official sourceDatenschutzbehördeIhre Pflichten als Verantwortlicher — the authority's own summary of controller duties
dsb.gv.at
Link checked 18 August 2026
DSG § 30 Abs. 1 und 2 — Allgemeine Bedingungen für die Verhängung von Geldbußen
Act of parliament · BGBl. I Nr. 165/1999 as amended, § 30(1)-(2)
Still printed in Austrian law: a company can only be fined if the breach is traced to a person in a leadership position. That filter once got an 18 million euro fine against a large Austrian company overturned. European case law has since held that a company is directly liable, and in June 2026 Austria's highest administrative court confirmed a 13 million euro fine measured on group turnover. Read as unenforceable as a shield, not as a defence.
Enforced by Austrian Data Protection Authority
What it costs if you get it wrong
- Percentage of global turnoverEuropean fines apply directly to the company; the Austrian attribution filter no longer shields it
Sources
- Official sourceRechtsinformationssystem des BundesDSG § 30(1) and (2), still in the consolidated text as at 18 August 2026
ris.bka.gv.at
“Die Datenschutzbehörde kann Geldbußen gegen eine juristische Person verhängen, wenn Verstöße ... durch Personen begangen wurden, die entweder allein oder als Teil eines Organs der juristischen Person gehandelt haben und eine Führungsposition innerhalb der juristischen Person ... innehaben.”
Link checked 18 August 2026
- Official sourceDatenschutzbehördeVwGH confirms a EUR 13 million fine, Ro 2025/04/0007-7, 24 June 2026
dsb.gv.at
Link checked 18 August 2026
Staatsschutz- und Nachrichtendienst-Gesetz (SNG), § 11 Abs. 1 Z 9 — Überwachung von Nachrichten mittels Messenger-Diensten
Act of parliament · Introduced July 2025; under constitutional challenge as case G 13-14/2026 · Telecoms
Austria's state security service may monitor encrypted messages by installing software on a target's device. Sixty-seven members of parliament challenged the power as a breach of the constitutional right to data protection. The Constitutional Court heard the case on 22 June 2026 and has not yet ruled. It struck down the earlier version of this power in 2019, so treat the rule as in force but fragile.
Enforced by Constitutional Court of Austria
What it makes you do
- Do not hand data to foreign authorities on demandThe challengers argue the surveillance software creates a dependency on foreign vendors for access to the intercepted data.
Sources
- Official sourceVerfassungsgerichtshofMündliche Verhandlung des VfGH zur Überwachung von Messenger-Diensten, case G 13-14/2026, hearing 22 June 2026
vfgh.gv.at
Link checked 18 August 2026
Industry rules3 rules
Gesundheitstelematikgesetz 2012 (GTelG 2012), with the eHealth-Verordnung 2025 and the ELGA-Verordnung 2015
Act of parliament · Health and social care
Austria's health data regime is a technical wall rather than a border. Electronic health record findings are stored across many care providers rather than centrally, move only encrypted inside dedicated secure health networks, and may be read only by a registered provider during an active treatment relationship, with every access logged. No rule found requiring the data to physically stay in Austria, checked 18 August 2026.
Enforced by ELGA GmbH
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Secure the dataTransport only in encrypted form and only within specially established secure health networks.
- Register or notifyCare providers must be registered before they can exchange health data.
- Keep logsEvery access is logged and the patient can see who looked at what.
- Allowed because the law requires itAccess requires an active treatment or care relationship.
Sources
- Official sourceBundesministerium für Arbeit, Soziales, Gesundheit, Pflege und KonsumentenschutzeHealth — legal framework, ELGA, and secure health networks
sozialministerium.gv.at
Link checked 18 August 2026
- Official sourceELGA GmbHELGA — Austria's electronic health record
elga.gv.at
Link checked 18 August 2026
Netz- und Informationssystemsicherheitsgesetz (NISG)
Act of parliament · Implements Directive (EU) 2016/1148; RIS Gesetzesnummer 20010536, with the NIS-Verordnung (20010722) · Government
Austria's cybersecurity law still implements the 2016 European directive, not the 2022 replacement. As at 18 August 2026 the government's own network security portal says the existing framework still needs adapting for the newer directive, whose transposition deadline was 17 October 2024. Scope today is therefore much narrower than most European planning assumes.
Enforced by Austrian Network and Information Security Authority
What it makes you do
- Secure the dataAppropriate technical and organisational security measures for network and information systems.
- Report cyber incidentsSignificant incidents must be reported. The official portal does not publish the deadline in hours.
- Register or notifyApplies to operators of essential services in energy, transport, finance, health, water and digital infrastructure, to digital service providers, and to public administration.
Sources
- Official sourceNIS-Behörde, Bundesministerium für InneresRechtliches und Dokumente — the instruments the Austrian network security authority lists as applicable
nis.gv.at
Link checked 18 August 2026
- Official sourceNIS-Behörde, Bundesministerium für InneresNIS-2-Richtlinie — transposition described as still to come
nis.gv.at
“Mit der Umsetzung der NIS-2-Richtlinie in Österreich bedarf auch die bestehende Systematik rund um das NISG einer Anpassung.”
Link checked 18 August 2026
Informationsfreiheitsgesetz (IFG)
Act of parliament · BGBl. I Nr. 5/2024 · Government
Austria abolished official secrecy on 1 September 2025. Public bodies must publish information of general interest and answer information requests, and the Data Protection Authority advises them on where personal data must be held back. If you contract with an Austrian public body, assume documents you send may become disclosable.
Enforced by Austrian Data Protection Authority
What it makes you do
- Tell people what you doPublic bodies must publish information of general interest online and register it as metadata on the national open data portal.
- Let people see their dataAnyone may request information; personal data is one of the grounds for refusal, decided by weighing disclosure against confidentiality.
Sources
- Official sourceDatenschutzbehördeInformationsfreiheitsgesetz, BGBl. I Nr. 5/2024, in force since 1 September 2025
dsb.gv.at
Link checked 18 August 2026
- Official sourceVerfassungsgerichtshofFirst Constitutional Court rulings on the Freedom of Information Act, E 3982/2025, 14 July 2026
vfgh.gv.at
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The Austrian record retention floor of seven years for books, invoices and business records under the Federal Fiscal Code and the Commercial Code
The Austrian legal information system blocked automated access to those statutes during this run, and the tax ministry and business portal pages we tried returned errors. The figure is widely used but we have no government backlink for it, so it is stated as medium confidence.
That Austria has no telecom data retention obligation today, following the Constitutional Court's 2014 annulment
We could not open an official Austrian source for the 2014 judgment or for the current telecoms act in this run. Treat the absence of a retention duty as probable but unverified, and re-check before relying on it.
Whether any localisation or storage rule exists in Austrian gambling, education, defence or mapping and surveying law
Not checked this run. Effort was spent on finance, health, telecoms, government and cybersecurity. This is a genuine gap, not a finding of no rule.
The exact incident reporting deadline in hours under the Austrian network and information security law
The government's own network security portal describes the duty to report significant incidents but does not publish the deadline. We declined to state a number rather than guess.
That the attribution filter in DSG § 30(1)-(2) is unenforceable following European case law
This is our reading. The text is still printed in the consolidated law, and the June 2026 court decision confirming a fine on group turnover is consistent with it, but no Austrian source we could open says in terms that the provision is disapplied.
Whether the constitutional right to data secrecy in DSG § 1 extends to companies as well as individuals
The provision says 'Jedermann' — everyone — while the law's title refers to natural persons. Austrian case law is said to read it broadly. We could not verify this against a court source in this run.
Whether a bill transposing the 2022 European cybersecurity directive is currently before the Austrian Parliament
The parliament's website could not be searched during this run. We can evidence only that the government's network security portal still presents the older law as the operative one on 18 August 2026.
Whether the Constitutional Court has ruled on messenger surveillance since the 22 June 2026 hearing
The court's own 2026 news list shows no decision announcement up to 31 July 2026. We cannot prove a negative for the days since.
60-day cadence. Two Austrian items can move without warning: the Constitutional Court's pending ruling on messenger surveillance, which could disapply an in-force surveillance power overnight, and the overdue transposition of the 2022 European cybersecurity directive, which will widen scope sharply the moment it lands. The bloc layer adds a third: the European-United States transfer framework is under active examination.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Austria versus Argentina
- Austria versus Armenia
- Austria versus Australia
- Austria versus Azerbaijan
- Austria versus Brazil
- Austria versus Bulgaria
- Austria versus Cambodia
- Austria versus Canada
- Austria versus China
- Austria versus Croatia
- Austria versus Cyprus
- Austria versus Estonia
- Austria versus France
- Austria versus Georgia
- Austria versus Germany
- Austria versus Greece
- Austria versus Hong Kong SAR
- Austria versus Hungary
- Austria versus Iceland
- Austria versus India
- Austria versus Indonesia
- Austria versus Ireland
- Austria versus Israel
- Austria versus Italy
- Austria versus Japan
- Austria versus Latvia
- Austria versus Lithuania
- Austria versus Luxembourg
- Austria versus Malta
- Austria versus Mexico
- Austria versus Mongolia
- Austria versus Nepal
- Austria versus Netherlands
- Austria versus Poland
- Austria versus Russia
- Austria versus Saudi Arabia
- Austria versus Serbia
- Austria versus Singapore
- Austria versus Slovakia
- Austria versus Slovenia
- Austria versus South Korea
- Austria versus Spain
- Austria versus Sri Lanka
- Austria versus Sweden
- Austria versus Switzerland
- Austria versus Taiwan
- Austria versus Thailand
- Austria versus Turkey
- Austria versus Ukraine
- Austria versus United Arab Emirates
- Austria versus United Kingdom
- Austria versus United States
- Austria versus Uzbekistan