Austria
How to File a Data Protection Complaint (Beschwerde) with Austria's DSB

Anyone who believes a company, association or public authority in Austria is mishandling their personal data has a formal way to raise it: a Beschwerde (complaint) to the Datenschutzbehörde (DSB), Austria's national data protection authority. The right itself comes from EU law, Art. 77 DSGVO, but the procedure you actually follow, including what the complaint must contain and how long you have to bring it, is set out in Austrian national law at § 24 DSG.
This page walks through who can file a Beschwerde, what it must say, the deadlines that apply, and what happens after the DSB receives it, including the backstop route to Austria's Bundesverwaltungsgericht (BVwG) if the DSB does not act.
Information last verified on 22 July 2026. This page provides general legal information about Austrian law and does not constitute legal advice in an individual case.
Who Can File a Beschwerde, and About What
§ 24 Abs 1 DSG gives every betroffene Person (data subject) the right to complain to the Datenschutzbehörde where they believe that processing of their personal data violates the DSGVO, or violates § 1 of the DSG or Artikel 2, 1. Hauptstück, DSG. Those two national provisions cover Austria's own constitutional-level data protection rules and the DSG's general processing conditions, alongside the GDPR itself.
There is one narrow carve out. § 24 Abs 1 does not apply where a right of complaint before the Parlamentarisches Datenschutzkomitee already exists for the processing in question, which covers certain parliamentary matters under § 35f Abs 1 DSG. For essentially every everyday case, a data subject in Austria, whether the target is a private company, an association, or a public authority, brings the complaint to the DSB.
The DSB itself is established by § 18 DSG as Austria's national supervisory authority under Art. 51 DSGVO, and § 19 DSG guarantees its independence from instruction. It is a single national authority for the whole country; there is no separate regional data protection authority the way there is in some other EU member states.
It is worth knowing, before you file, that the remedy the DSB can order differs depending on who you are complaining about. Against a private sector controller, the DSB can order the controller to comply with your request, for example to grant access or delete data, under § 24 Abs 5 DSG. Against a public authority or a body governed by public law, Austria has taken the option under the GDPR to exempt public bodies from administrative fines entirely, a divergence covered in more detail on GDPR in Austria. The Beschwerde procedure itself, however, works the same way regardless of who the respondent is.
What the Beschwerde Must Contain
§ 24 Abs 2 DSG sets out six specific pieces of content a Beschwerde must include. A complaint that leaves these out risks being sent back for correction, or in the worst case, not being properly processed, so it is worth treating this as a checklist rather than a suggestion.
- The designation of the right you consider violated.
- Where reasonably possible, the identification of the legal entity or body you believe committed the violation (the respondent).
- The facts from which you derive the violation.
- The grounds on which your claim of unlawfulness rests.
- The request that the DSB establish that the alleged violation occurred.
- The information needed for the DSB to assess whether your complaint was lodged on time.
That last point matters more than it looks. Because § 24 Abs 4 DSG imposes a strict deadline (covered next), the DSB needs enough detail from you to work out when you first learned of the problem and when the underlying event happened. Leaving out dates, or being vague about when you found out, can complicate that assessment.
A Beschwerde does not need to be filed by a lawyer, and § 24 DSG does not attach a fee to the six content requirements above. It is a written submission to an administrative authority, not a court filing, so it does not carry the procedural formalities of a lawsuit.
Deadlines: One Year From Knowledge, Three Years at the Outside
§ 24 Abs 4 DSG sets a firm, two part time limit. Your claim to have a complaint handled by the DSB lapses if you do not lodge it within one year after you gained knowledge of the event you are complaining about, and in any case no later than three years after the event you allege took place. A complaint filed late must be rejected outright.
| Trigger | Deadline |
|---|---|
| From the date you learn of the event | One year |
| From the date the event itself occurred | Three years (absolute outer limit) |
The practical effect is that the clock can start running well before you notice a problem. If a controller mishandled your data in a way you only discovered much later, the one year period runs from discovery, not from the original event, but the three year period is an absolute ceiling regardless of when you found out. Someone who learns of a two year old violation still has roughly a year to act, but someone who learns of it after three years and one month has already lost the right to have the DSB handle a Beschwerde about it.
This is why the timing details in § 24 Abs 2's sixth requirement matter: the DSB needs to be able to check both dates against your complaint before it can proceed.
How the DSB Handles a Complaint, and the BVwG Backstop
Once a Beschwerde is lodged, § 24 Abs 7 DSG obliges the DSB to inform the complainant of the status and the outcome of its investigation within three months of the complaint being filed. That three month clock is a genuine commitment, not a guideline, and it gives every complainant a concrete point at which they should expect to hear something.
If the DSB does not meet that commitment, either by failing to deal with the complaint at all or by failing to inform the complainant within the three month window, § 24 Abs 8 DSG lets the data subject bring the matter directly to the Bundesverwaltungsgericht (BVwG), Austria's federal administrative court. This is a genuine backstop: a complainant is never left waiting indefinitely on a DSB that has gone silent. A BVwG ruling can itself be appealed further, on a point of law, to the Verwaltungsgerichtshof (VwGH).
Two further wrinkles are worth knowing before you file. First, under § 24 Abs 6 DSG, the respondent can still cure the alleged violation before the proceeding closes, for instance by finally producing the records that were previously refused. Where that happens, the DSB can treat the matter as resolved rather than issuing a formal finding. Second, where a complaint against a private sector controller is upheld, § 24 Abs 5 DSG lets the DSB order that controller to comply, whether that means granting access, correcting a record, or deleting data as originally requested.
The Right of Access as a Common Trigger for a Beschwerde
In practice, one of the most frequent reasons people end up filing a Beschwerde is a simple access request that went nowhere. Art. 15 DSGVO gives every data subject the right to ask a controller whether it is processing their personal data and, if so, to get access to it along with a defined set of information about that processing.
The controller's clock for responding is set by Art. 12 Abs 3 DSGVO: the request must be actioned without undue delay and in any event within one month of receipt. Where the request is complex or the controller is handling a large number of them, that period can be extended by up to two further months, but the controller has to tell the requester about the extension and explain the reason for it.
A controller that simply misses this deadline, with no reply and no notice of an extension, is exactly the kind of failure § 24 DSG exists to address. Austria also mirrors an access right at constitutional level: § 1 Abs 3 DSG grants a constitutional level Anspruch auf Auskunft (right of access), alongside rights to Richtigstellung (rectification) and Löschung (erasure), reinforcing the GDPR right rather than replacing it.
One verification note: the one month response deadline and the wording of Art. 15 DSGVO are stable text that has not changed since the GDPR took effect in 2018, but if you are relying on the exact current wording for a specific case, it is worth checking the current consolidated text directly rather than a secondary summary.
A Worked Example
Suppose a data subject emails a company on 3 February asking, under Art. 15 DSGVO, for a copy of the personal data it holds about her. The one month deadline under Art. 12 Abs 3 DSGVO runs out on 3 March with no reply, no acknowledgement, and no notice of an extension.
She waits a little longer in case the company is simply slow, but by early May, three months after her original request and well past even the maximum extended period, she still has nothing. At that point she has clear grounds to file a Beschwerde with the DSB under § 24 DSG, naming the company as respondent, describing the request and the missed deadline as the facts the violation is based on, and asking the DSB to establish that her right of access was violated.
Because she learned of the problem (the missed deadline) in early March, her one year window under § 24 Abs 4 DSG runs from that date, giving her until roughly the following March to lodge the complaint, and in any case no later than three years from the original February request. Once she files, the DSB has three months to tell her the status and outcome of its handling of the case, or she can take the matter to the BVwG herself.
Practical Notes Before You File
Before lodging a Beschwerde, it is worth gathering the underlying communication (the original request, any acknowledgement, any partial or delayed reply) since § 24 Abs 2 DSG asks you to state the facts the violation is based on and the grounds for your claim. Precise dates matter, both for describing the event and for letting the DSB check the one year and three year deadlines under § 24 Abs 4 DSG.
It also helps to be clear about which right you believe was violated, whether that is the right of access under Art. 15 DSGVO, another GDPR right, or a right under § 1 or Artikel 2, 1. Hauptstück, DSG. § 24 Abs 2's first requirement is exactly this: naming the right, not just describing a general grievance.
Finally, remember that filing a Beschwerde does not prevent the other side from fixing the problem first. If the respondent finally provides the missing access, correction, or deletion before the DSB rules, § 24 Abs 6 DSG allows the case to be treated as cured. For many complainants, that outcome, actually getting the data or the correction they originally asked for, is the practical goal of the whole process.
Frequently Asked Questions
What is a Datenschutzbeschwerde in Austria?
A Datenschutzbeschwerde is a formal complaint lodged with Austria's Datenschutzbehörde (DSB) by anyone who believes that processing of their personal data violates the DSGVO or the relevant provisions of the Austrian DSG. The legal basis is Art. 77 DSGVO at EU level and § 24 DSG as the Austrian procedure.
Which authority handles a data protection complaint in Austria?
The Datenschutzbehörde (DSB) is Austria's national supervisory authority under § 18 DSG and Art. 51 DSGVO. § 19 DSG guarantees its independence, and it is the body that receives and processes a Beschwerde under § 24 DSG.
How long do I have to file a Beschwerde with the DSB?
§ 24 Abs 4 DSG sets a two part deadline: you must lodge the complaint within one year of learning of the event that gave rise to it, and no later than three years after the event allegedly took place. A late complaint must be rejected.
What information must a Beschwerde to the DSB contain?
§ 24 Abs 2 DSG lists six required elements: the right you consider violated, the respondent (where reasonably identifiable), the facts the violation is based on, the grounds supporting the claim of unlawfulness, the request that the DSB establish the violation, and the details needed to assess whether the complaint was filed on time.
How long does the DSB take to decide a complaint?
The DSB must tell you the status and outcome of your complaint within three months of when you lodged it, under § 24 Abs 7 DSG. If it fails to deal with the complaint or fails to inform you within that period, § 24 Abs 8 DSG lets you bring the matter to the Bundesverwaltungsgericht instead.
Can I complain about a public authority the same way as a private company?
Yes, the Beschwerde procedure under § 24 DSG applies to complaints against both private controllers and public bodies. The available remedy differs though: for a private sector controller the DSB can order compliance under § 24 Abs 5 DSG, while a public authority in Austria cannot be fined under the GDPR's administrative fine regime.
Can the other side fix the problem before the DSB rules?
Yes. § 24 Abs 6 DSG allows a respondent to cure the alleged violation before the proceeding concludes, for example by finally granting an access request that was refused. If that happens, the DSB can treat the complaint as resolved.
What happens if the DSB does not respond within three months?
You can bring the complaint directly to the Bundesverwaltungsgericht (BVwG) under § 24 Abs 8 DSG. A BVwG decision on a point of law can be further appealed to the Verwaltungsgerichtshof (VwGH).
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
General Data Protection Regulation (GDPR)
Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subjectIn forcecited in 14 of our articles
1. The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication under Articles 15 to 22 and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The information shall be provided in writing, or by other means, including, where appropriate, by electronic means. When requested by the data subject, the information may be provided orally, provided that the identity of the data subject is proven by other means. 2. The controller shall facilitate the exercise of data subject rights under Articles 15 to 22. In the cases referred to in Article 11(2), the controller shall not refuse to act on the request of the data subject for exercising his or her rights under Articles 15 to 22, unless the controller demonstrates that it is not in a position to identify the data subject. 3.
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 16 court opinionsMost recently applied by a court: 2026
Leading cases:
- FT v DW (Court of Justice of the European Union 2023, C-307/22)
- Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V (Court of Justice of the European Union 2024, C-757/22)
- F.F. v Österreichische Datenschutzbehörde and CRIF GmbH (Court of Justice of the European Union 2023, C-487/21)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: GDPR in Austria (DSGVO): How EU Law and the Datenschutzgesetz Work Together, How to Submit a Data Deletion Request (2026), GDPR Subject Access Requests (DSAR): How to Respond (2026)
Art. 15Right of access by the data subjectIn forcecited in 14 of our articles
1. The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information: (a) the purposes of the processing; (b) the categories of personal data concerned; (c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations; (d) where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period; (e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; (f) the right to lodge a complaint with a supervisory authority; (g) where the personal data are not collected from the data subject, any available information as to their source;
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 13 court opinionsMost recently applied by a court: 2025
Leading cases:
- CK v Magistrat der Stadt Wien (Court of Justice of the European Union 2025, C-203/22)
- F.F. v Österreichische Datenschutzbehörde and CRIF GmbH (Court of Justice of the European Union 2023, C-487/21)
- Proceedings brought by J.M (Court of Justice of the European Union 2023, C-579/21)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Austrian Data Privacy Law (Datenschutz): GDPR, the DSG and the Datenschutzbehörde, Schulden und Insolvenz in Deutschland: The Complete Debt Law Hub, SCHUFA Eintrag löschen: What You Can Actually Get Removed, and What You Cannot
Art. 77Right to lodge a complaint with a supervisory authorityIn forcecited in 6 of our articles
1. Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation. 2. The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 15 court opinionsMost recently applied by a court: 2025
Leading cases:
- Österreichische Datenschutzbehörde v F R (Court of Justice of the European Union 2025, C-416/23)
- Nemzeti Adatvédelmi és Információszabadság Hatóság v UC (Court of Justice of the European Union 2024, C-169/23)
- Österreichische Datenschutzbehörde v WK (Court of Justice of the European Union 2024, C-33/22)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Italian Privacy Law: An Overview, The Garante Privacy: Italy's Data Protection Authority and How to Complain
Search our record of EU legislation — GDPR, ePrivacy, AI Act and more, from EUR-Lex →
Sources and References
- § 24 Abs 1 DSG, right to lodge a Beschwerde with the Datenschutzbehörde(ris.bka.gv.at).gov
- § 24 Abs 2 DSG, six required content elements of a Beschwerde(ris.bka.gv.at).gov
- § 24 Abs 4 DSG, one year / three year deadline to lodge a Beschwerde(ris.bka.gv.at).gov
- § 24 Abs 5 DSG, DSB order to a private sector controller(ris.bka.gv.at).gov
- § 24 Abs 6 DSG, cure of the alleged violation before the case closes(ris.bka.gv.at).gov
- § 24 Abs 7 and 8 DSG, three month DSB information duty and the BVwG backstop(ris.bka.gv.at).gov
- § 18 DSG, the Datenschutzbehörde as national supervisory authority under Art. 51 DSGVO(ris.bka.gv.at).gov
- § 1 DSG, Austria's constitutional right to data protection including a right of access(ris.bka.gv.at).gov
- Datenschutzbehörde official guidance on lodging a Beschwerde(dsb.gv.at).gov
- Art. 77 DSGVO, right to lodge a complaint with a supervisory authority(eur-lex.europa.eu).gov
- Art. 15 DSGVO, the data subject's right of access(eur-lex.europa.eu).gov
- Art. 12 Abs 3 DSGVO, one month response deadline for an access request(eur-lex.europa.eu).gov