Austrian Data Privacy Law (Datenschutz): GDPR, the DSG and the Datenschutzbehörde

Austria's data privacy law operates on two layers stacked together. The General Data Protection Regulation, referred to in German as the DSGVO, is European Union law that applies directly in Austria the same way it applies across the rest of the EU. Sitting alongside it is Austria's own statute, the Datenschutzgesetz (DSG), which fills the gaps the DSGVO leaves open to national law, establishes the country's data protection regulator, and layers on rules that exist only in Austria.
This hub is the entry point for the site's Austrian data privacy section, sometimes searched simply as Datenschutz. It orients the framework: how the DSGVO and the DSG relate to each other, the constitutional right to data protection that predates the GDPR by nearly two decades, the Datenschutzbehörde as the country's single supervisory authority, and Austria's sharpest divergence from the ordinary EU fine regime. For the wider legal system this section sits inside, including the courts and how Austrian statutes are cited, see the Austria overview.
The framework below matters to a wide range of readers, not only privacy specialists. An employer processing staff records, a small business running a website with an inquiry form, a resident who wants to know what a company or public office holds on them, and a public authority weighing its own exposure under the fine regime are all governed by the same DSGVO plus DSG structure described here.
Information last verified on 22 July 2026. This page provides general legal information about Austrian law and does not constitute legal advice in an individual case.
The DSGVO and the Austrian DSG: How the Two Layers Fit Together
§ 64 DSG states plainly that the Act serves to carry out and implement Regulation (EU) 2016/679, the DSGVO, along with the related EU Law Enforcement Directive. In practical terms, the DSGVO supplies the core substance: the definitions of personal data and processing, the lawful bases for processing, and the general rights of data subjects such as access, rectification, and erasure.
The DSG then does the jobs the DSGVO leaves to national law. It fills the DSGVO's opening clauses, the specific points where the regulation lets member states set their own rules.
It establishes the Datenschutzbehörde as Austria's supervisory authority. It adds a constitutional data protection right that predates the DSGVO entirely. And it creates national penalties, including the public body fine exemption covered below.
A researcher who reads only the DSGVO gets an accurate but incomplete picture of the law that actually governs an Austrian controller. For the complete picture of how the two levels interact, including the DSGVO's Article 83 fine regime and the DSG's own national sanctions, see GDPR in Austria.
A Constitutional Right to Data Protection: § 1 DSG
The most distinctive feature of Austrian data protection law predates the GDPR by nearly two decades. § 1 DSG is a Verfassungsbestimmung, a constitutional provision, granting every person a right to Geheimhaltung, meaning confidentiality, of their personal data wherever a legitimate interest in that confidentiality exists. § 1 Abs 3 DSG extends that same constitutional status to the rights of access, correction, and deletion.
Because this right sits at constitutional level, it has direct effect against private parties as well as public authorities, not merely against the state. Most EU member states protect data privacy through ordinary statute and the GDPR alone. Unlike Germany, where the constitutional basis for data protection rests on judicially developed personality rights rather than an explicit statutory Verfassungsbestimmung of this kind, Austria's constitutional layer is written directly into the DSG and sits above the DSGVO as an independent, domestic legal foundation.
The Datenschutzbehörde: Austria's Data Protection Regulator
§ 18 DSG establishes the Datenschutzbehörde, known as the DSB, as Austria's national supervisory authority under Article 51 DSGVO. The DSB is led by a Leiter, with a deputy who takes over in the Leiter's absence, and § 19 DSG guarantees its independence from political direction.
The DSB receives complaints, investigates suspected breaches, and where warranted imposes administrative fines. A narrow exception exists for certain parliamentary data processing, which falls instead to a separate Parlamentarisches Datenschutzkomitee, but for the overwhelming majority of complaints and enforcement matters, the DSB is the relevant authority for the whole country. There is no separate regional data protection authority the way there is in some other EU member states.
The DSB's reach extends past ordinary office records. § 62 Abs 1 DSG's list of national administrative offences includes unlawful Bildverarbeitung, meaning unlawful video or image processing, which is the direct link between this section and the site's separate coverage of Austrian recording and CCTV rules. The same regulator that handles a Beschwerde over a mishandled access request is also the authority for a complaint about an unlawfully operated camera system.
GDPR Fines in Austria: The Public Body Exception at a Glance
This is the sharpest divergence between Austrian data protection law and the general GDPR fine regime. § 30 Abs 1 DSG confirms that the DSB can impose administrative fines, Geldbußen, on companies and other juristische Personen for breaches of the DSGVO or the DSG, the ordinary regime capped under Article 83 DSGVO at up to 20 million euro or four percent of annual worldwide turnover.
§ 30 Abs 5 DSG then removes an entire category of actor from that regime. No Geldbuße can be imposed against a Behörde, an öffentliche Stelle, or a Körperschaft des öffentlichen Rechts, meaning a body governed by public law carrying out a statutory function. Austria used the opt out available under Article 83(7) DSGVO to exempt public authorities from the fine regime entirely rather than only partially, so the DSB's remedy against a public body is a corrective order, not a monetary penalty.
Austria also layers two further national sanctions on top of the GDPR's own regime: § 62 DSG, an administrative offence with fines up to 50,000 euro, and § 63 DSG, a judicial crime tried by a court rather than decided by the DSB, carrying up to one year in prison or up to 720 Tagessätze. For the full three tier breakdown, including a worked comparison between a fineable company and a non fineable public authority, see GDPR in Austria.
Filing a Data Protection Complaint at a Glance
Article 77 DSGVO gives every data subject the right to lodge a complaint with a supervisory authority if they believe processing of their personal data breaches the regulation. § 24 DSG is the Austrian procedural rule that implements that right: a complaint goes to the DSB, must identify the right believed to have been violated among six required elements, and must generally be filed within one year of the complainant learning of the event and no later than three years after the event occurred.
The DSB must inform the complainant of the status and outcome of its inquiry within three months of the complaint being lodged. If it fails to engage with the complaint, or fails to respond within that window, the complainant can bring the matter before the Bundesverwaltungsgericht. For the full step by step process, including what a complaint must contain, the exact deadlines, and what happens after the DSB decides, see how to file a data protection complaint in Austria.
The Right of Access Under the GDPR
Because it is directly applicable EU law rather than a DSG rule, the right to obtain confirmation of whether one's personal data is being processed, and to access that data, sits in Article 15 DSGVO. Article 12 Abs 3 DSGVO sets the response clock: a controller must act on the request without undue delay and in any event within one month of receipt, with a possible extension of up to two further months for complex or numerous requests.
§ 1 Abs 3 DSG mirrors that same access right at constitutional level in Austria, reinforcing rather than replacing the EU rule. A controller that misses this deadline with no reply and no notice of an extension is one of the most common reasons a complaint ends up in front of the DSB, a scenario worked through in full on the complaint page linked above.
Where This Section Goes Next
The two spoke pages linked throughout this hub cover the framework and the complaint process in the depth a ministry summary does not: GDPR in Austria works through the DSGVO and DSG relationship, the constitutional right, and the public body fine exception with a worked comparison, and how to file a data protection complaint in Austria walks through a Beschwerde from the required content list to the Bundesverwaltungsgericht backstop, including a worked example on a missed access request deadline. For the broader Austrian legal system this section sits inside, see the Austria overview.
Frequently Asked Questions
Is Austrian data privacy law the same as the GDPR?
Not exactly. The GDPR (DSGVO) is EU law and applies directly in Austria, but Austria's own Datenschutzgesetz (DSG) sits alongside it, filling gaps the regulation leaves to national law, establishing the Datenschutzbehörde, and adding rules that exist only in Austria, including a constitutional data protection right and national penalties beyond the GDPR fine regime.
What is the Datenschutzbehörde and what does it do?
The Datenschutzbehörde (DSB) is Austria's national data protection authority, established by § 18 DSG as the country's single supervisory authority under Article 51 DSGVO. It receives complaints, investigates suspected breaches, and imposes administrative fines where warranted.
What makes Austrian data protection law different from a purely GDPR approach?
Three things stand out. Austria has a constitutional Grundrecht auf Datenschutz in § 1 DSG that predates the GDPR, the Datenschutzbehörde supervises and enforces the rules, and the DSG adds national provisions the GDPR leaves to member states. The GDPR in Austria guide sets out each of these in full.
Where do the Datenschutzbehörde and the courts each come in?
The Datenschutzbehörde handles the administrative side: it receives complaints, investigates, and can order or fine private controllers. Separate national offences under §§ 62 and 63 DSG are pursued by the administrative authorities and the criminal courts. The two spoke pages cover the complaint route and the penalty tiers in detail.
Does Austria have a constitutional right to data protection?
Yes. § 1 DSG is a Verfassungsbestimmung, a constitutional provision, granting every person a right to Geheimhaltung of their personal data along with constitutional level rights of access, correction, and deletion. It predates the GDPR and has direct effect against private parties, not only the state.
Are there criminal penalties for misusing personal data in Austria?
Yes. § 63 DSG creates a judicial crime, decided by a court rather than the DSB, for intentionally misusing personal data to enrich oneself or harm someone else. It carries up to one year in prison or up to 720 Tagessätze, separate from the DSB's own administrative fines.
Where can I read the full detail on GDPR fines and complaints in Austria?
This hub orients the framework. The GDPR in Austria page works through the DSGVO and DSG relationship, the constitutional right, and the public body fine exemption in full depth, and the data protection complaint page walks through filing a Beschwerde with the DSB step by step.
Sources and References
- § 64 DSG, the Act serves to carry out and implement Regulation (EU) 2016/679 (the DSGVO) and the related EU Law Enforcement Directive(ris.bka.gv.at).gov
- § 1 Abs 1 DSG, constitutional right (Verfassungsbestimmung) to Geheimhaltung of personal data where a legitimate interest exists(ris.bka.gv.at).gov
- § 1 Abs 3 DSG, constitutional right of access, rectification and deletion(ris.bka.gv.at).gov
- § 18 Abs 1 DSG, the Datenschutzbehörde is established as the national supervisory authority under Art. 51 DSGVO(ris.bka.gv.at).gov
- § 19 DSG, the independence of the Datenschutzbehörde(ris.bka.gv.at).gov
- § 24 Abs 1 DSG, the right to complain to the Datenschutzbehörde(ris.bka.gv.at).gov
- § 24 Abs 4 DSG, a complaint expires one year after the complainant learns of the event and at most three years after the event(ris.bka.gv.at).gov
- § 30 Abs 1 DSG, the Datenschutzbehörde may impose administrative fines on companies and other juristische Personen(ris.bka.gv.at).gov
- § 30 Abs 5 DSG, no Geldbuße can be imposed against Behörden, öffentliche Stellen, or Körperschaften des öffentlichen Rechts(ris.bka.gv.at).gov
- § 62 Abs 1 DSG, national administrative offence with a fine of up to 50,000 euro, including unlawful Bildverarbeitung(ris.bka.gv.at).gov
- § 63 DSG, judicial crime of misusing personal data with intent to enrich or to harm, up to one year imprisonment or 720 Tagessätze(ris.bka.gv.at).gov
- Art. 15(1) DSGVO, the data subject's right of access to their personal data(eur-lex.europa.eu).gov