{
 "jurisdiction_id": "AT",
 "jurisdiction": "Austria",
 "url": "https://dataprotection.gi/jurisdictions/austria/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 44,
  "sub_modules": 57,
  "source_register": 17
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/austria/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Fully GDPR-aligned omnibus regime with an operational, EDPB-networked national DPA and consistent CJEU-tested procedural framework.",
   "claims": [
    {
     "statement": "The Österreichische Datenschutzbehörde (DSB), headquartered at Barichgasse 40-42, Vienna, is Austria's independent data protection supervisory authority responsible for handling complaints and enforcing the GDPR and DSG.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/contact/contact-dpas_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Datenschutzgesetz (DSG), Federal Law Gazette I No 165/1999 as amended, provides that every data subject has the right to lodge a complaint with the DSB and sets a one-year (max. three-year) limitation period under §24 DSG.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62024CJ0414",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CJEU held in Case C-33/22 that data processing carried out by a parliamentary committee of inquiry concerning national-security matters may fall outside the material scope of EU law under Article 2(2)(a) GDPR read with Article 4(2) TEU, thereby limiting DSB competence in that narrow category.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0033",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 3 territorial-scope rules on establishment and targeting apply directly to controllers/processors in relation to Austria without a distinct national derogation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Austria does not require general prior notification or registration of processing activities with the DSB; the DSB instead applies specific statutory fees to certain filings, such as a fixed EUR 30 fee referenced in a DSB decision concerning a commercial-register-related complaint.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2025-08/at-2025-decision-public.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/austria/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Directly-applicable GDPR core with a narrow, well-documented national research-safeguards overlay; no material derogation gaps identified.",
   "claims": [
    {
     "statement": "GDPR Article 6 lawful bases for processing apply directly and uniformly in Austria without a general national supplementary basis regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 7 consent standards (freely given, specific, informed, unambiguous, revocable) apply directly in Austria without a general derogation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 7 DSG distinguishes two processing constellations for scientific research purposes involving special-category data, each subject to different national safeguards additional to GDPR Article 9.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2022-01/legalstudy_on_the_appropriate_safeguards_89.1.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Personal data processed for scientific, historical, or statistical research purposes in Austria cannot be disseminated without prior anonymisation unless third-party interests in dissemination prevail over the data subject's fundamental rights and freedoms.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2022-01/legalstudy_on_the_appropriate_safeguards_89.1.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/austria/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core rights are directly enforced by the DSB with a developed body of national and CJEU case law; no material national restriction identified.",
   "claims": [
    {
     "statement": "The CJEU held in Case C-416/23 that a supervisory authority faced with 'excessive' requests within Article 57(4) GDPR must show the requests were both repeated/frequent and manifestly vexatious or abusive before charging a fee or refusing to act, constraining the DSB's discretion in access-right complaints.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX%3A62023CJ0416",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In a 2025 decision the DSB held that publicly available Austrian commercial-register data identifying a company's legal representative need not be erased where the general public interest in transparency of representative authority outweighs the data subject's Article 17 erasure interest.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2025-08/at-2025-decision-public.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under GDPR Article 21(1) as applied by the DSB, a controller may continue processing following an objection only where it demonstrates compelling legitimate grounds overriding the data subject's interests, rights and freedoms.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2025-08/at-2025-decision-public.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DSB treats a controller's delivery of the complainant's personal data in a structured, commonly used, machine-readable (e.g. CSV/Excel) format directly to the data subject as satisfying the Article 20 GDPR portability right, permitting the complaint to be closed as amicably settled under §24(6) DSG.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2025-01/decision-714.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DSB enforcement practice treats a controller's failure to respond to a data-subject portability/access request for more than a month, despite reminders, as an actionable non-compliance with GDPR response deadlines.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2025-01/decision-714.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/austria/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core accountability obligations are GDPR-direct and green, but granular Austria-specific implementation detail (DPIA lists, sectoral retention rules) could not be independently confirmed this pass, warranting amber pending further primary-source verification.",
   "claims": [
    {
     "statement": "GDPR Articles 5 (principles), 25 (data protection by design/default) and 35 (DPIA) apply directly to Austrian controllers and processors without a general national derogation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DPO appointment in Austria follows the GDPR Article 37(1) criteria (public authority/body, large-scale regular systematic monitoring, or large-scale special-category processing) without an Austria-specific stricter numerical trigger comparable to Germany's national threshold.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 30 records-of-processing obligations apply directly to Austrian controllers and processors meeting the Article 30(5) thresholds.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Articles 26 (joint controllers) and 28 (processor contracts) apply directly in Austria without a general national derogation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 32 security-of-processing obligations (technical and organisational measures appropriate to risk) apply directly to Austrian controllers and processors.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Articles 33 (regulator notification within 72 hours) and 34 (data-subject notification for high-risk breaches) apply directly in Austria, with the DSB as the competent notification recipient.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/contact/contact-dpas_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/austria/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Fully harmonised EU Chapter V transfer regime with no identified Austria-specific derogation or localisation mandate.",
   "claims": [
    {
     "statement": "GDPR Chapter V transfer mechanisms (adequacy decisions, SCCs, BCRs, and Article 49 derogations) apply directly and uniformly to Austrian-established controllers and processors, with the DSB as competent enforcement authority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "European Commission adequacy decisions under GDPR Article 45 apply automatically across all EU Member States including Austria without need for separate national implementation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Standard Contractual Clauses and Binding Corporate Rules under GDPR Article 46 are directly available transfer mechanisms for Austrian controllers/processors, with BCR approvals proceeding through EDPB cooperation involving the DSB where Austria is a concerned authority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following the CJEU's Schrems II judgment, EDPB Recommendations 01/2020 on supplementary measures establish an EU-wide expectation—including for Austrian data exporters—that transfer impact assessments be conducted before relying on SCCs to third countries lacking adequacy.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/austria/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Two of seven sub-modules (telecoms/ePrivacy, employment) are evidenced; five require further primary-source escalation.",
   "claims": [
    {
     "statement": "In addition to the ePrivacy Directive and GDPR, Austria applies the Telecommunications Act 2021 (TKG 2021) and the E-Commerce Act to govern electronic communications marketing including SMS/MMS marketing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/austria-smsmms-marketing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Austrian employee data protection compliance is governed by the interaction of GDPR/DSG with the Labour Constitutional Act (Arbeitsverfassungsgesetz, ArbVG) and the Equal Treatment Act (GlBG), with works-council consent frequently required for employee-monitoring measures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/austria-employment-1",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/austria/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie/tracker and direct-marketing sub-modules are evidenced; opt-out-signal, clean-room, and cross-context-advertising sub-modules do not map cleanly onto the EU consent-based model and were not independently confirmed as distinct Austrian constructs.",
   "claims": [
    {
     "statement": "Storage of and access to information on end-user devices (cookies and similar trackers) in Austria requires consent under TKG 2021 provisions implementing Article 5(3) of the ePrivacy Directive, applied alongside GDPR consent standards where personal data is processed.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/austria-smsmms-marketing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "EDPB guidance on dark patterns in social media platform interfaces applies to Austrian-established controllers as part of the GDPR consent-validity and fair-processing framework, absent a distinct Austrian statutory dark-pattern prohibition.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/contact/contact-dpas_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Direct electronic marketing communications (including SMS/MMS) in Austria require prior consent under the TKG 2021 and E-Commerce Act, mirroring the ePrivacy Directive's Article 13 soft opt-in exception for existing customer relationships.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/austria-smsmms-marketing",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/austria/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Profiling/ADM and state-surveillance carve-out sub-modules are GDPR/CJEU-evidenced (green); AI-risk-assessment sub-module is evidenced but time-sensitive/in-transition (amber); biometric and genetic sub-modules lack confirmed Austria-specific overlay (red-leaning amber).",
   "claims": [
    {
     "statement": "GDPR Article 22 restricts decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect a data subject, applying directly to Austrian controllers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Articles 13-15 require controllers to provide meaningful information about the logic, significance, and envisaged consequences of automated decision-making, applying directly in Austria.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the EU AI Act, all EU Member States, including Austria, were required to designate or establish national competent authorities (market surveillance and notifying authorities) by 2 August 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/eu-ai-act-regulatory-directory",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of the European Commission's 2026 implementation report, enforcement rules for the AI Act's prohibited-practices chapter apply from 2 August 2026 and national competent authorities across Member States, including Austria, are still in the process of being designated.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM%3A2026%3A234%3AFIN",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CJEU held that activities of a committee of inquiry set up by a Member State parliament concerning national security may fall outside GDPR's material scope under Article 2(2)(a) read with Article 4(2) TEU, while supervisory-authority competence to assess that exemption remains subject to CJEU-defined limits under Articles 51 and 55 GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0033",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/austria/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "The EU-level Article 8 framework is confirmed, but the Austria-specific numerical age-of-consent threshold and several sub-modules were not independently verified in this pass, warranting escalation to primary source (RIS/DSG text) before publication reliance.",
   "claims": [
    {
     "statement": "GDPR Article 8(2) requires controllers to make reasonable efforts to verify that consent for processing a child's data in connection with an information society service is given or authorised by the holder of parental responsibility, taking into account available technology; this applies directly in Austria.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 8(1) sets a default digital age-of-consent of 16 for information-society-service processing based on a child's own consent, with Member States permitted to lower that threshold by national law to no less than 13; the specific figure adopted under Austrian law was not independently confirmed via primary source in this research pass.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "EDPB Statement 1/2025 on Age Assurance emphasises that age-assurance mechanisms should not enable excess profiling of individuals, particularly children, applying as EU-wide guidance relevant to Austrian controllers absent a distinct national minor-profiling-ban statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/contact/contact-dpas_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/austria/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Core enforcement powers, penalty ceilings, and a significant recent CJEU judgment are well-evidenced (green-leaning); current regulator funding/capacity and collective-redress implementing-act specifics were not independently confirmed this pass (amber).",
   "claims": [
    {
     "statement": "GDPR Recital 129 and Article 58 confer on supervisory authorities including the DSB investigative, corrective, authorisation and advisory powers, including the power to impose a temporary or definitive limitation or ban on processing, alongside Article 83 fines of up to EUR 20 million or 4% of global annual turnover.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62024CJ0414",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DSB imposed an administrative fine of EUR 18 million on Österreichische Post AG for unlawfully processing data on customers' presumed political affinity and for further processing package-frequency and relocation-frequency data for direct-marketing purposes, with the fine subject to challenge before the Federal Administrative Court and thus not final upon issuance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/administrative-criminal-proceedings-austrian-data-protection-authority_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Early post-GDPR reporting indicated the DSB had at least 115 fine proceedings pending and had initiated 58 ex officio investigations shortly after its first GDPR fine, though current (2026) staffing and funding levels were not independently confirmed in this research pass.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/austria-announces-first-gdpr-fine/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 80 permits data subjects to mandate a not-for-profit body to exercise rights and lodge complaints on their behalf, applying directly in Austria; Austria-specific implementing detail of the EU Representative Actions Directive for consumer collective redress was not independently confirmed this pass.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "An Advocate General Opinion in a pending Austrian CJEU reference (Case C-185/25) proposes that Article 82 GDPR does not preclude national rules under which persons acting on behalf of certain Austrian public-law entities cannot be held personally liable for data-subject damage, provided those rules identify the entity against which compensation claims may be brought.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62025CC0185",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 18 June 2026, the CJEU (First Chamber) delivered judgment in Case C-414/24, Datenschutzbehörde and Dr G S v Bundesministerin für Justiz and D GmbH, interpreting Articles 77 and 79 GDPR in relation to the DSB's rejection of complaints where parallel judicial proceedings on the same subject-matter are pending.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62024CJ0414",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 5 February 2026, the EDPB adopted Opinion 18/2024 on the draft decision of the Austrian supervisory authority regarding certification criteria for a certification-monitoring body (DSGVO-zt GmbH) under the Article 64 consistency mechanism.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/our-work-tools/our-documents/opinion-board-art-64/opinion-182024-draft-decision-austrian_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}