GDPR in Austria (DSGVO): How EU Law and the Datenschutzgesetz Work Together

The DSGVO, the EU's General Data Protection Regulation, applies in Austria the same way it applies across the rest of the European Union. As an EU regulation it takes direct effect, with no need for Austria to copy its text into a domestic law. What Austria does have on top of it is the Datenschutzgesetz (DSG), the national statute that fills the gaps the DSGVO deliberately leaves open to member states, sets up the country's data protection regulator, and layers on rules that exist only in Austria.
That combination, EU regulation plus national implementing statute, is the correct starting point for anyone researching "DSGVO" as it applies to an Austrian business, employer, or public authority. This page works through how the two levels fit together, Austria's constitutional data protection right, the Datenschutzbehörde as the supervisory authority, and the DSG's most distinctive feature: a rule that takes public bodies out of the GDPR fine regime entirely.
Information last verified on 22 July 2026. This page provides general legal information about Austrian law and does not constitute legal advice in an individual case.
How the DSGVO and the Austrian DSG Fit Together
§ 64 DSG states plainly that the Act serves to carry out and implement Regulation (EU) 2016/679, the DSGVO, along with the related EU Law Enforcement Directive. In practical terms this means the DSGVO supplies the core substance: the definitions of personal data and processing, the lawful bases for processing, the rights of data subjects such as access, rectification, and erasure, and the general fine regime under Article 83.
The DSG then does four jobs the DSGVO leaves to national law. It fills the DSGVO's opening clauses, the specific points where the regulation lets member states set their own rules.
It establishes the Datenschutzbehörde as Austria's supervisory authority. It adds a constitutional data protection right that predates the DSGVO by nearly two decades. And it creates national penalties, including the public body fine exemption and two offences that exist only under Austrian law.
A researcher who only reads the DSGVO gets an accurate but incomplete picture of the law that actually governs an Austrian data controller. The DSG is where the country specific detail lives, and it is the DSG, not the DSGVO, that explains why an Austrian public authority is treated so differently from an Austrian company.
Austria's Constitutional Right to Data Protection
The most distinctive feature of Austrian data protection law predates the GDPR entirely. § 1 DSG is a Verfassungsbestimmung, a constitutional provision, and it grants every person a right to Geheimhaltung, meaning confidentiality, of their personal data, wherever a legitimate interest in that confidentiality exists. § 1 Abs 3 DSG extends that same constitutional status to the rights of access, correction, and deletion.
Because this right sits at constitutional level, it has direct effect against private parties as well as public authorities, not merely against the state. Most EU member states protect data privacy through ordinary statute and the GDPR itself. Austria's constitutional layer sits above and alongside the DSGVO, giving Austrian data protection law a firmer domestic legal foundation than the regulation alone would provide. This is one of the clearest ways Austrian data protection law differs from the equivalent German framework, where the constitutional basis for data protection rests on judicially developed personality rights rather than an explicit statutory Verfassungsbestimmung of this kind.
The Datenschutzbehörde: Austria's Supervisory Authority
§ 18 DSG establishes the Datenschutzbehörde, known as the DSB, as Austria's national supervisory authority under Article 51 DSGVO. The DSB is led by a Leiter, with a deputy who takes over in the Leiter's absence, and § 19 DSG guarantees its independence from political direction.
The DSB is the body that receives complaints, investigates suspected breaches, and where warranted imposes administrative fines. It also issues guidance for controllers and processors operating in Austria. A narrow exception exists for certain parliamentary data processing, which falls instead to a separate Parlamentarisches Datenschutzkomitee, but for the overwhelming majority of complaints and enforcement matters, the DSB is the relevant authority.
Filing a Complaint with the DSB
Article 77 DSGVO gives any data subject the right to lodge a complaint with a supervisory authority if they believe processing of their personal data breaches the regulation. § 24 DSG is the Austrian procedural rule that implements that right: a complaint goes to the DSB, must identify the right believed to have been violated and, where reasonably possible, the party responsible, and must be filed within one year of the complainant learning of the event and no later than three years after the event occurred.
The DSB must inform the complainant of the status and outcome of its inquiry within three months of the complaint being lodged. If it fails to engage with the complaint, or fails to respond within that window, the complainant can bring the matter before the Bundesverwaltungsgericht. For the full step by step process, including what a complaint must contain and what happens after the DSB decides, see our guide to filing a data protection complaint in Austria.
GDPR Fines and Austria's Public Body Exception
This is the sharpest divergence between Austrian data protection law and the general GDPR fine regime, and it is the detail most worth knowing before assuming a public sector body faces the same exposure as a private company.
§ 30 Abs 1 DSG confirms that the DSB can impose administrative fines, Geldbußen, on companies and other juristische Personen, meaning private legal persons, for breaches of the DSGVO or the DSG. That is the ordinary GDPR fine regime most people are familiar with, capped under Article 83 DSGVO at up to 20 million euro or four percent of annual worldwide turnover, whichever figure is higher.
§ 30 Abs 5 DSG then removes an entire category of actor from that regime. It states that no Geldbuße can be imposed against a Behörde, an öffentliche Stelle, or a Körperschaft des öffentlichen Rechts, meaning a body governed by public law that carries out a statutory function, whether organised under public or private law. Austria used the opt out available under Article 83(7) DSGVO to exempt public authorities from the fine regime entirely, rather than only partially.
Consider two organisations that suffer the same kind of serious, poorly handled data breach. A private company with 10 million euro in annual worldwide turnover could in principle face a Geldbuße calculated against the four percent of turnover ceiling, in the region of 400,000 euro, imposed directly by the DSB under § 30 Abs 1 DSG. A municipal office or other public authority that mishandles the same category of personal data in the same way cannot receive that Geldbuße at all. The DSB's remedy against the public authority is a binding order requiring it to correct the unlawful practice, not a monetary penalty.
This does not mean a public authority faces no consequences whatsoever. It means the consequence is corrective rather than financial, and it is a genuine structural feature of Austrian law that a reader comparing Austria to other jurisdictions should understand before assuming the GDPR fine regime applies uniformly to every kind of organisation.
Austria's National Sanction Tiers Beyond the GDPR
Austria layers two further, purely national sanctions on top of the GDPR's own fine regime. Both sit in the DSG rather than the DSGVO, and both are distinct from the Geldbuße discussed above.
| Sanction tier | Legal basis | Who imposes it | Maximum penalty |
|---|---|---|---|
| GDPR administrative fine (Geldbuße) | Article 83 DSGVO, via § 30 DSG | Datenschutzbehörde | Up to 20 million euro or 4% of annual worldwide turnover; not available against public bodies under § 30 Abs 5 |
| National administrative offence | § 62 DSG | Datenschutzbehörde | Up to 50,000 euro |
| National judicial crime | § 63 DSG | A court | Up to one year in prison or up to 720 Tagessätze |
§ 62 DSG applies only where the conduct does not already fall under Article 83 DSGVO, or is not already punished more severely under another provision. It covers a specific list of acts: deliberately gaining unlawful access to a data processing system, unlawfully transmitting or otherwise processing data in breach of the data secrecy obligation, obtaining personal data by deception, operating an unlawful Bildverarbeitung system (meaning unlawful video or image processing, which links directly to Austria's separate rules on CCTV and recording), and refusing the DSB's inspection powers. An attempt to commit any of these is itself punishable, and the DSB is the competent authority.
§ 63 DSG is a different order of seriousness. It is a Gerichtsdelikt, meaning a court, not the DSB, decides the case. It applies only where someone acts with intent to enrich themselves or another person, or intent to harm someone in their constitutionally protected confidentiality interest under § 1 DSG, by using, disclosing, or publishing personal data they obtained through their profession or unlawfully. The maximum penalty is one year's imprisonment or 720 Tagessätze, a day fine system where the total depends on the offender's income.
Right of Access Under the DSGVO
Because it is directly applicable EU law rather than a DSG rule, the right to obtain confirmation of whether one's personal data is being processed, and to access that data, sits in Article 15 DSGVO. Article 12 Abs 3 DSGVO sets the response clock: a controller must act on the request without undue delay and in any event within one month of receipt, with a possible extension of up to two further months for complex or numerous requests. § 1 Abs 3 DSG mirrors that same access right at constitutional level in Austria, reinforcing rather than replacing the EU rule.
Frequently Asked Questions
Does the GDPR apply in Austria the same way it applies everywhere else in the EU?
Yes. The DSGVO is an EU regulation, so it applies directly in Austria without needing to be copied into national law. The Datenschutzgesetz (DSG) sits alongside it, filling gaps the regulation leaves to member states, creating the Datenschutzbehörde, and adding national rules such as the public body fine exemption and two Austria only offences.
What is the difference between the DSGVO and the DSG?
The DSGVO is the EU wide regulation that sets the core rights and obligations, such as the right of access and the lawful bases for processing. The DSG is Austria's own statute. It implements the parts the DSGVO leaves open to national law, establishes the Datenschutzbehörde as the supervisory authority, and creates additional Austrian rules, including a constitutional data protection right and national penalties beyond the GDPR fine regime.
Can Austrian public authorities be fined for a data protection breach?
Not with a Geldbuße. § 30 Abs 5 DSG removes Behörden, öffentliche Stellen, and Körperschaften des öffentlichen Rechts from the DSB's fining power entirely. The DSB can still order a public authority to fix an unlawful practice, but it cannot impose the monetary fine that a private company would face for the same conduct.
Can private companies in Austria still be fined under the GDPR?
Yes. § 30 Abs 1 DSG lets the Datenschutzbehörde impose administrative fines on companies and other private legal persons for breaches of the DSGVO or the DSG. The public body exemption in Abs 5 applies only to public authorities, not to private businesses.
What is § 62 DSG and how is it different from a GDPR fine?
§ 62 DSG is a separate national administrative offence, not the GDPR's own fine regime under Article 83. It applies only where the conduct does not already fall under Article 83 DSGVO, and it covers specific acts such as unlawful access to a data processing system or unlawful Bildverarbeitung, meaning unlawful video or image processing. It carries fines of up to 50,000 euro, imposed by the DSB.
Is there a criminal penalty for misusing personal data in Austria?
Yes, under § 63 DSG. Unlike the DSB's administrative fines, this is a judicial offence, decided by a court, and it requires intent to enrich oneself or someone else, or intent to harm another person, using personal data obtained through one's profession or unlawfully. The penalty is up to one year in prison or up to 720 Tagessätze.
How do I complain about a data protection violation in Austria?
Article 77 DSGVO gives every affected person the right to complain to a supervisory authority, and § 24 DSG sets out how that works in Austria: the complaint goes to the Datenschutzbehörde and must be filed within one year of learning about the event, and at most three years after the event itself. See our separate guide to filing a data protection complaint in Austria for the full process.
Is Austria's data protection law the same as Germany's?
No. Both countries apply the same DSGVO, but each has its own implementing statute. Austria's DSG includes features Germany's federal data protection act does not share in the same form, most notably a constitutional data protection right under § 1 DSG and the § 30 Abs 5 exemption that removes public bodies from the DSB's fining power.
Sources and References
- § 64 DSG, the Act serves to carry out and implement Regulation (EU) 2016/679 (the DSGVO) and the related EU Law Enforcement Directive(ris.bka.gv.at).gov
- § 1 Abs 1 DSG, constitutional right (Verfassungsbestimmung) to Geheimhaltung of personal data where a legitimate interest exists(ris.bka.gv.at).gov
- § 1 Abs 3 DSG, constitutional right of access, rectification and deletion(ris.bka.gv.at).gov
- § 18 Abs 1 DSG, the Datenschutzbehörde is established as the national supervisory authority under Art. 51 DSGVO(ris.bka.gv.at).gov
- § 19 DSG, the independence of the Datenschutzbehörde(ris.bka.gv.at).gov
- § 24 Abs 1 and Abs 2 DSG, the right to complain to the Datenschutzbehörde and the required content of a complaint(ris.bka.gv.at).gov
- § 24 Abs 4 DSG, a complaint expires one year after the complainant learns of the event and at most three years after the event(ris.bka.gv.at).gov
- § 30 Abs 1 DSG, the Datenschutzbehörde may impose administrative fines on companies and other juristische Personen(ris.bka.gv.at).gov
- § 30 Abs 5 DSG, no Geldbuße can be imposed against Behörden, öffentliche Stellen, or Körperschaften des öffentlichen Rechts(ris.bka.gv.at).gov
- § 62 Abs 1 DSG, national administrative offence with a fine of up to 50,000 euro, including unlawful Bildverarbeitung(ris.bka.gv.at).gov
- § 62 Abs 5 DSG, the Datenschutzbehörde is the competent authority for the § 62 offence(ris.bka.gv.at).gov
- § 63 DSG, judicial crime of misusing personal data with intent to enrich or to harm, up to one year imprisonment or 720 Tagessätze(ris.bka.gv.at).gov
- Art. 15(1) DSGVO, the data subject's right of access to their personal data(eur-lex.europa.eu).gov
- Art. 12 Abs 3 DSGVO, a controller must respond to an access request within one month, extendable by up to two further months(eur-lex.europa.eu).gov