Austria
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Austria — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can store Austrian personal data outside Austria. We found no Austrian industry that has to keep data in the country. Data can leave once the right paperwork is in place under European rules. What Austria adds is secrecy. There is a constitutional right to have your data kept secret. Staff must be bound to secrecy. There is an extra fine of up to 50,000 euros (about 58,000 US dollars). And there is a crime carrying up to one year in prison.
Data governance in Austria
The eight things that decide how you handle data about people in Austria. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. A company with no office in Austria is still covered if it offers goods or services to people in Austria. The same applies if it watches what they do online. There is no size or revenue floor to fall below. If you have no office anywhere in the European Union, you must name a representative inside the Union, in writing. Austria does not add a second, Austria-only representative on top of that.
- What you have to do here:
- Appoint a representative
The reach comes from Article 3 of the General Data Protection Regulation. The written representative comes from Article 27. The Austrian Data Protection Act (Datenschutzgesetz, DSG) sits on top. It adds national detail rather than a separate test of who is covered. One Austrian layer is broader than the European one. The constitutional right in § 1 DSG reads 'Jedermann hat ... Anspruch auf Geheimhaltung der ihn betreffenden personenbezogenen Daten'. That means everyone has a claim to secrecy of the personal data about them. It is written into the constitution (Verfassungsbestimmung), not ordinary law. So it can only be changed by a two-thirds majority.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceRechtsinformationssystem des Bundes (Federal Chancellery)Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999, consolidated version as at 18 August 2026, § 1
ris.bka.gv.at
“Jedermann hat, insbesondere auch im Hinblick auf die Achtung seines Privat- und Familienlebens, Anspruch auf Geheimhaltung der ihn betreffenden personenbezogenen Daten, soweit ein schutzwürdiges Interesse daran besteht.”
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork. We looked for an Austrian rule forcing data to stay in Austria and found none. We checked banking, payments, insurance, securities, health, telecoms, government and mapping. Austrian health data is the closest thing to a wall, but it is a technical one, not a border. Findings move only inside a closed, encrypted Austrian health network, between registered care providers. Checked on 18 August 2026.
Industry by industry, as at 18 August 2026. FINANCE. The Austrian Financial Market Authority (Finanzmarktaufsicht, FMA) publishes its circulars in one place. None of them covers cloud, where you may outsource, or where data may sit. The rules that actually apply are the European Digital Operational Resilience Act, in force since 17 January 2025. They make you name the place where data is used, and hold audit and exit rights. They do not require data to stay in Austria. HEALTH. The Health Telematics Act 2012 (Gesundheitstelematikgesetz 2012), the eHealth Regulation 2025 and the ELGA Regulation 2015 set the rules. Data must travel encrypted, inside dedicated secure health networks. Storage is spread across care providers rather than held centrally. There must be an active treatment relationship before anyone can look. Every access is logged. The ministry's own description states no rule about crossing borders. GOVERNMENT. The federal computing centre (Bundesrechenzentrum) advertises 25,000 terabytes of Austrian storage. It makes no legal claim that data must stay in Austria. We found no binding federal rule on cloud location. TELECOMS. We found no general duty on operators to keep traffic data for law enforcement. Austria's law on keeping that data was struck down by the Constitutional Court in 2014. We could not open an official Austrian source for that, so treat it as medium confidence. EDUCATION, GAMING, DEFENCE and MAPPING. Not checked this time. They are listed as gaps below. Separately, Regulation (EU) 2018/1807 stops Austria requiring non-personal data to stay in the country, except on public-security grounds.
Sources
- Official sourceDatenschutzbehördeInternationaler Datenverkehr — the Austrian Data Protection Authority on transfers to third countries
dsb.gv.at
“Im Unterschied zur alten Rechtslage nach der Richtlinie 95/46/EG ist der internationale Datenverkehr bis auf wenige Sonderfälle genehmigungsfrei.”
Link checked 18 August 2026
- Official sourceBundesministerium für Arbeit, Soziales, Gesundheit, Pflege und KonsumentenschutzeHealth and ELGA — legal framework: Gesundheitstelematikgesetz 2012, eHealth-Verordnung 2025, ELGA-Verordnung 2015
sozialministerium.gv.at
Link checked 18 August 2026
- Official sourceFinanzmarktaufsichtFMA-Rundschreiben — the complete published list of Austrian financial regulator circulars
fma.gv.at
Link checked 18 August 2026
- Official sourceFinanzmarktaufsichtDORA — Digital Operational Resilience Act, applicable from 17 January 2025
fma.gv.at
Link checked 18 August 2026
- Official sourceBundesrechenzentrum GmbHBundesrechenzentrum — Austria's federal computing centre
brz.gv.at
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Austria.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
You send data to countries on an approved list. Sending data outside Europe is fine if the destination is on the European Commission's approved list. If it is not, you sign the European standard contract, or use approved group-wide rules. You also write down a short risk assessment first. You do not need permission from the Austrian regulator. In its own words, apart from a few special cases, international data traffic needs no approval.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims
The approved list is populated. It includes the United Kingdom, renewed on 19 December 2025 and running to 2031. It also includes Japan, South Korea, Switzerland, Canada for commercial bodies, and Brazil, added 26 January 2026. The United States is on it only in part. Your recipient must have self-certified under the data privacy arrangement between the European Union and the United States. The 2021 standard contractual clauses are still the set you use, and they have not been amended. The extra clauses promised for importers already caught directly by European law have still not been adopted. The Austrian regulator notes on its own site that an update to the Commission's clauses is planned. The United States route is the unstable one. It is still legally valid today. But the European Data Protection Board wrote formally to the Commission on 31 July 2026. It asked the Commission to examine whether recent changes in the United States affect whether the decision still stands. An appeal against the General Court's dismissal in the Latombe case is also pending. Never make it your only route.
Sources
- Official sourceDatenschutzbehördeInternationaler Datenverkehr — mechanisms listed by the Austrian Data Protection Authority
dsb.gv.at
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the European Commission's own list of approved destinations
commission.europa.eu
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Austrian Data Protection Authority, and it is working. It has had a permanent head, Matthias Schmidl, since 1 January 2024. It has a deputy and five departments. It issues decisions. On 24 June 2026 Austria's highest administrative court confirmed a 13 million euro fine (about 15 million US dollars). That was for building profiles of people's political opinions, covering around 2.2 million people. The court held that the fine is measured against the whole group's turnover, not one product line.
- What it costs if you get it wrong:
- Percentage of global turnover · Order to stop
The case is Ro 2025/04/0007-7, decided on 24 June 2026 by the Verwaltungsgerichtshof. The authority is run by one person and is independent. No ministry sits above it. Two Austrian features pull in opposite directions. First, § 11 DSG tells the authority to apply the European penalty list proportionately. For a first breach especially, it should use a warning rather than a fine. That is why Austrian fine counts look low next to Ireland or Spain. Second, § 30(5) DSG says no fine at all may be imposed on authorities, public bodies or public-law corporations. So by law, a large share of Austrian data use carries no fine risk. Austria also leads on doctrine rather than volume. Its authority issued the first European decision holding a website's use of Google Analytics unlawful. We rate it active rather than aggressive. Its output is decisive and now tested in court, but the volume is modest. And the law itself tells the regulator to warn first.
Sources
- Official sourceDatenschutzbehördeLeitung und Organisation — head of the Austrian Data Protection Authority since 1 January 2024
dsb.gv.at
Link checked 18 August 2026
- Official sourceDatenschutzbehördeVwGH confirms unlawful processing of party affinities and sets the fine at EUR 13 million (Ro 2025/04/0007-7, 24 June 2026)
dsb.gv.at
“Der Verwaltungsgerichtshof bestätigte mit seiner Entscheidung den Kernvorwurf der Datenschutzbehörde hinsichtlich der unrechtmäßigen Verarbeitung besonderer Kategorien personenbezogener Daten”
Link checked 18 August 2026
- Official sourceRechtsinformationssystem des BundesDSG § 11 (warning by the authority) and § 30(5) (no fines on public bodies), consolidated text as at 18 August 2026
ris.bka.gv.at
“Gegen Behörden und öffentliche Stellen, wie insbesondere in Formen des öffentlichen Rechts sowie des Privatrechts eingerichtete Stellen, die im gesetzlichen Auftrag handeln, und gegen Körperschaften des öffentlichen Rechts können keine Geldbußen verhängt werden.”
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a maximum and a minimum, and they pull against each other. The maximum is European. Keep personal data no longer than you need it, then delete it. The minimum is Austrian tax and company law. It makes you keep books, invoices and business records for years after the year they relate to. Where the two clash, the duty to keep wins for as long as it runs. The data must then be deleted.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Let people delete their data
The maximum is the storage-limitation rule in Article 5(1)(e) of the General Data Protection Regulation. It is backed by the erasure right in Article 17. That right expressly steps aside where you need the data to meet a legal duty. The Austrian minimum sits in the Federal Fiscal Code (Bundesabgabenordnung) and the Commercial Code (Unternehmensgesetzbuch). The figure people commonly apply is seven years from the end of the relevant financial year. Property-related records run longer. We could not open the official consolidated text of either law, because the Austrian legal information system blocks automated access. So the seven-year figure is recorded as unconfirmed below, and confidence here is medium. Two Austrian points we did verify. The Data Protection Act itself sets no general minimum for keeping logs for ordinary businesses. And there is no Austrian equivalent of a blanket six-month log-keeping order. Practical rule: never build deletion automation that ignores the accounting minimum. And never treat that minimum as permission to keep the whole customer record.
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, Article 5(1)(e) storage limitation and Article 17(3)(b) erasure exception
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceRechtsinformationssystem des BundesDatenschutzgesetz, consolidated text as at 18 August 2026 — contains no general minimum retention or log-keeping duty
ris.bka.gv.at
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
Count at least two deadlines, sometimes four. For a personal data breach you tell the Austrian Data Protection Authority without delay, and if possible within 72 hours. If you are late, you must explain in writing why. If you run an essential service, you also report significant incidents to Austria's network security authority. Banks and insurers report separately under European financial rules. Telecom operators have their own duty.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
The 72-hour deadline and the duty to tell affected people come from Articles 33 and 34 of the General Data Protection Regulation. The Austrian regulator restates the deadline on its own site as 'unverzüglich und möglichst binnen 72 Stunden'. The second deadline runs to the Austrian network and information security authority, which is the Ministry of the Interior. You file through the government computer emergency teams at nis.govcert.gv.at, nis.cert.at and nis.energy-cert.at. The official Austrian network security portal does not publish that deadline in hours. So we have not stated one. That is a gap, not a finding. The third deadline is the Digital Operational Resilience Act for financial firms, live since 17 January 2025. It has its own first, interim and final reporting stages. Where one incident starts several deadlines, the shortest one decides what you do in the first hour. The mismatch between them is the single most common operational failure.
Sources
- Official sourceDatenschutzbehördeIhre Pflichten als Verantwortlicher — breach notification within 72 hours
dsb.gv.at
“unverzüglich und möglichst binnen 72 Stunden”
Link checked 18 August 2026
- Official sourceNIS-Behörde, Bundesministerium für InneresAllgemeines zum NIS-Gesetz — duty to report significant incidents
nis.gv.at
“Mit dem NIS-Gesetz werden Maßnahmen festgelegt, mit denen ein hohes Sicherheitsniveau von Netz- und Informationssystemen erreicht werden soll.”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. A child can consent at fourteen in Austria, not sixteen. Misusing data you only learned about through your job is a crime, punishable by up to a year in prison. There is a second, separate Austrian fine of up to 50,000 euros (about 58,000 US dollars). It covers breaking data secrecy or running a camera unlawfully. Austrian public bodies cannot be fined at all, but you still can. And the law tells the regulator to warn first, which is not the same as forgiveness.
- What you have to do here:
- Get a parent's consent for children · Extra vendor secrecy terms
- What it costs if you get it wrong:
- Criminal liability · Fixed maximum fine
(1) AGE FOURTEEN. § 4(4) DSG makes a child's consent to an online service valid once the child has completed their fourteenth year. Austria took the lowest option the European rule allows. So an age gate built for Germany's sixteen will be wrong here, and one built for thirteen will also be wrong. (2) YOU CAN GO TO PRISON. § 63 DSG covers using, disclosing or publishing personal data entrusted to you through your job. It applies where you meant to enrich yourself, or to harm someone's right to secrecy. The penalty is up to one year in prison, or a fine of up to 720 daily income units. It falls on individuals, not the company. (3) THE SECOND FINE. § 62 DSG creates an offence carrying up to 50,000 euros. It covers deliberately breaking the data-secrecy duty, and running image capture against the rules, among other things. Even attempting it is punishable. It applies only where European fines do not, so it is easy to miss. (4) DATA SECRECY IS A CONTRACT DUTY. § 6 DSG makes you bind your staff by contract. They may pass personal data on only when you expressly tell them to. They must keep the data secret even after they leave the job. A standard European supplier agreement does not do this by itself. (5) PUBLIC BODIES CANNOT BE FINED. § 30(5) DSG bars fines against authorities, public bodies acting under a legal mandate, and public-law corporations. Your Austrian government customer carries no fine risk, so it will not share your urgency. The risk lands on you. (6) PARLIAMENT HAS ITS OWN REGULATOR. Complaints about how the Austrian Parliament uses data go to a Parliamentary Data Protection Committee, not to the Data Protection Authority. (7) SURVEILLANCE CAMERAS. Austria keeps its own image rules in §§ 12 and 13 DSG, on top of European law. They include specific security and signage duties.
Sources
- Official sourceRechtsinformationssystem des BundesDatenschutzgesetz §§ 4(4), 6, 12, 13, 24, 30, 62 and 63, consolidated text as at 18 August 2026
ris.bka.gv.at
“Bei einem Angebot von Diensten der Informationsgesellschaft, das einem Kind direkt gemacht wird, ist die Einwilligung gemäß Art. 6 Abs. 1 lit. a DSGVO zur Verarbeitung der personenbezogenen Daten des Kindes rechtmäßig, wenn das Kind das vierzehnte Lebensjahr vollendet hat.”
Link checked 18 August 2026
- Official sourceDatenschutzbehördeController duties, including the two Austrian impact-assessment regulations
dsb.gv.at
Link checked 18 August 2026
What's changing next
Three things to watch. Austria's Constitutional Court is deciding whether the state may put software on a phone to read messages. It heard the case on 22 June 2026 and has not ruled. Austria has still not written the new European cybersecurity rules into national law, so that expansion is still ahead of you. And from 12 January 2027, cloud providers across Europe may no longer charge you to move your data out.
- What you have to do here:
- Make switching cloud provider possible
PENDING COURT CASE. Sixty-seven members of the Austrian Parliament challenged § 11(1)(9) of the State Protection and Intelligence Service Act (Staatsschutz- und Nachrichtendienst-Gesetz), introduced in July 2025. It lets the state read encrypted messages by installing software on a target's computer system. The case is G 13-14/2026 and the hearing was held on 22 June 2026. Austria's Constitutional Court struck down the earlier version of this power in 2019. So a second annulment is a real possibility. A rule that binds today could stop binding overnight. NIS2 STILL MISSING. As at 18 August 2026 the Austrian government's own network security portal still describes the national law as implementing the 2016 directive. It says the existing rules 'require adaptation' for the newer one. The deadline to write it into national law was 17 October 2024. When it lands, it will sharply widen to manufacturing, food, waste, postal services and digital providers. Registration windows in other member states have been short. POWERS ALREADY HELD. Three matter. The Data Protection Authority can order a company to suspend data flows to a country outside Europe. That usually hurts more than a fine. The government could bring back telecom data retention by ordinary law at any time. And the Freedom of Information Act, in force since 1 September 2025, is only now being tested. Austria's Constitutional Court gave its first rulings on 14 July 2026, including one on a state-owned bank. So expect a widening pool of documents that companies dealing with Austrian public bodies can no longer assume stay private.
Sources
- Official sourceVerfassungsgerichtshofOral hearing of the Constitutional Court on the monitoring of messenger services, case G 13-14/2026, 22 June 2026
vfgh.gv.at
Link checked 18 August 2026
- Official sourceNIS-Behörde, Bundesministerium für InneresNIS-2-Richtlinie — the Austrian network security authority on transposition still to come
nis.gv.at
“Mit der Umsetzung der NIS-2-Richtlinie in Österreich bedarf auch die bestehende Systematik rund um das NISG einer Anpassung.”
Link checked 18 August 2026
- Official sourceVerfassungsgerichtshofConstitutional Court 2026 news list, including the first Freedom of Information rulings of 14 July 2026 (E 3982/2025)
vfgh.gv.at
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionData Act, Regulation (EU) 2023/2854 — cloud switching charges fall to zero on 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Diarise 12 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Health data rules
Official name: Gesundheitstelematikgesetz 2012 (GTelG 2012), with the eHealth-Verordnung 2025 and the ELGA-Verordnung 2015 · Act of parliament
Austria's health data rules build a technical wall, not a border. Electronic health record findings are stored across many care providers rather than in one place. They move only in encrypted form, inside dedicated secure health networks. Only a registered provider may read them, and only during an active treatment relationship. Every access is logged. We found no rule requiring the data to physically stay in Austria, checked 18 August 2026.
Enforced by ELGA GmbH
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Secure the dataTransport only in encrypted form, and only within specially built secure health networks.
- Register or notifyCare providers must be registered before they can exchange health data.
- Keep logsEvery access is logged, and the patient can see who looked at what.
- Allowed because the law requires itYou need an active treatment or care relationship before you can look.
Sources
- Official sourceBundesministerium für Arbeit, Soziales, Gesundheit, Pflege und KonsumentenschutzeHealth — legal framework, ELGA, and secure health networks
sozialministerium.gv.at
Link checked 18 August 2026
- Official sourceELGA GmbHELGA — Austria's electronic health record
elga.gv.at
Link checked 18 August 2026
Cyber security rules
Official name: Netz- und Informationssystemsicherheitsgesetz (NISG) · Implements Directive (EU) 2016/1148; RIS Gesetzesnummer 20010536, with the NIS-Verordnung (20010722) · Act of parliament
Austria's cybersecurity law still implements the 2016 European directive, not the 2022 replacement. As at 18 August 2026 the government's own network security portal says the existing rules still need adapting for the newer directive. The deadline to write that into national law was 17 October 2024. So what the law covers today is much narrower than most European planning assumes.
Enforced by Austrian Network and Information Security Authority
What you have to do
- Secure the dataAppropriate technical and organisational security measures for network and information systems.
- Report cyber incidentsYou must report significant incidents. The official portal does not publish the deadline in hours.
- Register or notifyApplies to operators of essential services in energy, transport, finance, health, water and digital infrastructure. It also applies to digital service providers and to public administration.
Sources
- Official sourceNIS-Behörde, Bundesministerium für InneresRechtliches und Dokumente — the instruments the Austrian network security authority lists as applicable
nis.gv.at
Link checked 18 August 2026
- Official sourceNIS-Behörde, Bundesministerium für InneresNIS-2-Richtlinie — transposition described as still to come
nis.gv.at
“Mit der Umsetzung der NIS-2-Richtlinie in Österreich bedarf auch die bestehende Systematik rund um das NISG einer Anpassung.”
Link checked 18 August 2026
General data protection law
Official name: Informationsfreiheitsgesetz (IFG) · BGBl. I Nr. 5/2024 · Act of parliament
Austria abolished official secrecy on 1 September 2025. Public bodies must publish information of general interest and answer information requests. The Data Protection Authority advises them on where personal data must be held back. If you contract with an Austrian public body, assume documents you send may have to be disclosed.
Enforced by Austrian Data Protection Authority
What you have to do
- Tell people what you doPublic bodies must publish information of general interest online. They must also register it as metadata on the national open data portal.
- Let people see their dataAnyone may request information. Personal data is one reason to refuse. The body weighs disclosure against confidentiality and decides.
Sources
- Official sourceDatenschutzbehördeInformationsfreiheitsgesetz, BGBl. I Nr. 5/2024, in force since 1 September 2025
dsb.gv.at
Link checked 18 August 2026
- Official sourceVerfassungsgerichtshofFirst Constitutional Court rulings on the Freedom of Information Act, E 3982/2025, 14 July 2026
vfgh.gv.at
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Bundesgesetz zum Schutz natürlicher Personen bei der Verarbeitung personenbezogener Daten (Datenschutzgesetz – DSG) · BGBl. I Nr. 165/1999, last amended by BGBl. I Nr. 50/2025 (Informationsfreiheits-Anpassungsgesetz) · Act of parliament
Austria's own data protection law, sitting on top of the European rules. Its first section is a constitutional right to have your personal data kept secret. It adds a staff secrecy duty and its own surveillance-camera rules. It sets the age of children's consent at fourteen. It adds a separate 50,000 euro fine and a crime carrying up to a year in prison.
Enforced by Austrian Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Extra vendor secrecy termsData secrecy: staff must be bound by contract to pass data on only when you expressly tell them to. They must keep it secret after they leave.
- Get a parent's consent for children — applies at: Consent to an online service is valid once the child has completed their fourteenth year
- Appoint a data protection officerRequired for public bodies, for large-scale systematic monitoring, and for large-scale sensitive data. You must give the authority their contact details.
- Secure the dataExtra security and signage duties apply to image capture, meaning surveillance cameras.
- Tell people what you do
What it costs if you get it wrong
- Fixed maximum fine: €50,000 — about $58 thousandDeliberate breach of data secrecy, unlawful access, unlawful image capture, or refusing an inspection — where no European fine applies. Attempt is punishable.
- Criminal liability: Up to 1 year imprisonment or up to 720 daily income unitsUsing, disclosing or publishing personal data learned through your job, with intent to enrich yourself or to harm someone's right to secrecy
Sources
- Official sourceRechtsinformationssystem des Bundes, BundeskanzleramtDatenschutzgesetz (DSG), consolidated federal law as at 18 August 2026
ris.bka.gv.at
“Sofern die Tat nicht einen Tatbestand nach Art. 83 DSGVO verwirklicht oder nach anderen Verwaltungsstrafbestimmungen mit strengerer Strafe bedroht ist, begeht eine Verwaltungsübertretung, die mit Geldstrafe bis zu 50 000 Euro zu ahnden ist, wer ...”
Link checked 18 August 2026
- Official sourceDatenschutzbehördeIhre Pflichten als Verantwortlicher — the authority's own summary of controller duties
dsb.gv.at
Link checked 18 August 2026
Breach reporting rules (Telecoms)
Official name: Staatsschutz- und Nachrichtendienst-Gesetz (SNG), § 11 Abs. 1 Z 9 — Überwachung von Nachrichten mittels Messenger-Diensten · Introduced July 2025; under constitutional challenge as case G 13-14/2026 · Act of parliament
Austria's state security service may read encrypted messages by installing software on a target's device. Sixty-seven members of parliament challenged that power as a breach of the constitutional right to data protection. The Constitutional Court heard the case on 22 June 2026 and has not yet ruled. It struck down the earlier version of this power in 2019. So the rule applies today, but it may not survive.
Enforced by Constitutional Court of Austria
What you have to do
- Do not hand data to foreign authorities on demandThe challengers argue the surveillance software makes Austria depend on foreign suppliers to reach the intercepted data.
Sources
- Official sourceVerfassungsgerichtshofMündliche Verhandlung des VfGH zur Überwachung von Messenger-Diensten, case G 13-14/2026, hearing 22 June 2026
vfgh.gv.at
Link checked 18 August 2026
Applies across the European Union2 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Verordnung (EU) 2016/679 (Datenschutz-Grundverordnung, DSGVO) · Regulation (EU) 2016/679 · Directly binding regulation
The European baseline that governs Austria. It sets the conditions for data leaving Europe. It does not require data to stay. Fines are the higher of a cash cap or a share of worldwide group turnover. Austria's highest administrative court confirmed on 24 June 2026 that group turnover, not product turnover, is the measure.
Enforced by Austrian Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of how you use data
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projectsAustria has two national regulations. One names the work that always needs an assessment. The other names the work that never does.
- Written vendor contract
- Appoint a representativeRequired where you have no office anywhere in the European Union.
- Put a transfer safeguard in placePlus a written risk assessment for the transfer, following the Schrems II judgment.
- Do not hand data to foreign authorities on demandAn order from a non-European authority is not by itself a lawful reason to hand data over.
- Delete data after a period
- Get a parent's consent for children — applies at: 14 in Austria
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $23 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $12 millionController and processor obligations
- Order to stopThe regulator can ban processing or suspend flows to a third country
- Claims by individualsIndividuals can claim compensation
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceDatenschutzbehördeVwGH Ro 2025/04/0007-7, 24 June 2026 — group-wide annual turnover is decisive for the fine
dsb.gv.at
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Datenverordnung — Verordnung (EU) 2023/2854 (Data Act) · Regulation (EU) 2023/2854 · Directly binding regulation
Applies in Austria since 12 September 2025. The date that matters is 12 January 2027. From then, European cloud providers may no longer charge anything to move your data out. It also limits handing non-personal data held in Europe to non-European governments. It does not require data to be stored anywhere in particular.
That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by Austrian Regulatory Authority for Broadcasting and Telecommunications
What you have to do
- Make switching cloud provider possible — from 12 January 2027All cloud switching charges and data exit fees must fall to zero.
- Do not hand data to foreign authorities on demandLimits non-European government access to non-personal data held in Europe.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act)
eur-lex.europa.eu
Link checked 18 August 2026
On the books, but not enforceable1 rule
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
Breach reporting rules
Official name: DSG § 30 Abs. 1 und 2 — Allgemeine Bedingungen für die Verhängung von Geldbußen · BGBl. I Nr. 165/1999 as amended, § 30(1)-(2) · Act of parliament
Still printed in Austrian law: a company can only be fined if the breach is traced to someone in a leadership position. That filter once got an 18 million euro fine against a large Austrian company overturned. European case law has since held that a company is directly liable. In June 2026 Austria's highest administrative court confirmed a 13 million euro fine measured on group turnover. Do not treat this filter as a defence. It no longer protects you.
Enforced by Austrian Data Protection Authority
What it costs if you get it wrong
- Percentage of global turnoverEuropean fines apply directly to the company; the Austrian attribution filter no longer shields it
Sources
- Official sourceRechtsinformationssystem des BundesDSG § 30(1) and (2), still in the consolidated text as at 18 August 2026
ris.bka.gv.at
“Die Datenschutzbehörde kann Geldbußen gegen eine juristische Person verhängen, wenn Verstöße ... durch Personen begangen wurden, die entweder allein oder als Teil eines Organs der juristischen Person gehandelt haben und eine Führungsposition innerhalb der juristischen Person ... innehaben.”
Link checked 18 August 2026
- Official sourceDatenschutzbehördeVwGH confirms a EUR 13 million fine, Ro 2025/04/0007-7, 24 June 2026
dsb.gv.at
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The Austrian record retention floor of seven years for books, invoices and business records under the Federal Fiscal Code and the Commercial Code
The Austrian legal information system blocked our access to those laws. The tax ministry and business portal pages we tried returned errors. The seven-year figure is widely used, but we have no government source for it. So it is stated as medium confidence. Confirm it with your accountant before you rely on it.
That Austria has no telecom data retention obligation today, following the Constitutional Court's 2014 annulment
We could not open an official Austrian source for the 2014 judgment, or for the current telecoms law. Treat the absence of a duty to keep telecom data as likely but unconfirmed. Check it before you rely on it.
Whether any localisation or storage rule exists in Austrian gambling, education, defence or mapping and surveying law
We did not check these industries. Our effort went to finance, health, telecoms, government and cybersecurity. This is a gap in our work, not a finding that no rule exists. If you work in gambling, education, defence or mapping, check before you rely on this.
The exact incident reporting deadline in hours under the Austrian network and information security law
The government's own network security portal describes the duty to report significant incidents. It does not publish the deadline. We chose not to state a number rather than guess. Ask the authority for the deadline that applies to you.
That the attribution filter in DSG § 30(1)-(2) is unenforceable following European case law
This is our reading, not a government statement. The text is still printed in the consolidated law. The June 2026 court decision confirming a fine on group turnover fits our reading. But no Austrian source we could open says outright that the rule no longer applies. Take advice before relying on it.
Whether the constitutional right to data secrecy in DSG § 1 extends to companies as well as individuals
The rule says 'Jedermann', meaning everyone, while the law's title refers to natural persons. Austrian case law is said to read it broadly. We could not check this against a court source. Take advice if your company wants to rely on the right.
Whether a bill transposing the 2022 European cybersecurity directive is currently before the Austrian Parliament
We could not search the parliament's website. All we can show is that the government's network security portal still presents the older law as the one in force on 18 August 2026. Check the parliament's site before you plan around a new law.
Whether the Constitutional Court has ruled on messenger surveillance since the 22 June 2026 hearing
The court's own 2026 news list shows no decision announced up to 31 July 2026. We cannot confirm the position for the days since. Check the court's site for a ruling before you rely on this.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.