🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
AT · run data-protection-2026-08-02 v13-gdpri-1.0.0
content: ai_generated 17 sources retrieved model claude-sonnet-5 ·

Austria

AT schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 44 claims · 17 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
44Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fully GDPR-aligned omnibus regime with an operational, EDPB-networked national DPA and consistent CJEU-tested procedural framework.

Primary frameworkDatenschutzgesetz (DSG) BGBl I No 165/1999, as amended, together with Regulation (EU) 2016/679 (GDPR)
Traffic-light rationale — GreenFully GDPR-aligned omnibus regime with an operational, EDPB-networked national DPA and consistent CJEU-tested procedural framework.

Sub-modules (5)

Regulator And AuthorityGreen

The DSB, based in Vienna, is Austria's independent supervisory authority under the GDPR and DSG.

Claims: CLM-AT-a1000001

Act And InstrumentsGreen

DSG supplements GDPR with national procedural rules including a statutory complaints regime under §24 DSG.

Claims: CLM-AT-a1000002

Material ScopeAmber

GDPR Art 2 material scope applies; DSG §1's constitutional right can extend protection to processing outside EU-law material scope, subject to CJEU delimitation.

Claims: CLM-AT-a1000003

Territorial ScopeGreen

GDPR Art 3 territorial scope rules apply directly; no distinct Austrian territorial-scope regime.

Claims: CLM-AT-a1000004

Regulator Registration And FilingGreen

No general prior-notification/registration regime exists post-GDPR; DSB levies specific statutory fees for certain filings.

Claims: CLM-AT-a1000005

Category narrative56 words

Austria is an EU Member State operating under the directly-applicable GDPR, supplemented by the national Datenschutzgesetz (DSG, BGBl I No 165/1999 as amended), which establishes the Datenschutzbehörde (DSB) as sole national supervisory authority, sets the constitutional-rank fundamental right to data protection (§1 DSG), and lays down national procedural rules (complaints procedure, limitation periods) for DSB proceedings.

Sources and claims (5)
  1. ConfirmedEDPBThe Österreichische Datenschutzbehörde (DSB), headquartered at Barichgasse 40-42, Vienna, is Austria's independent data protection supervisory authority responsible for handling complaints and enforcing the GDPR and DSG.
  2. ConfirmedEUR-LexThe Datenschutzgesetz (DSG), Federal Law Gazette I No 165/1999 as amended, provides that every data subject has the right to lodge a complaint with the DSB and sets a one-year (max. three-year) limitation period under §24 DSG.
  3. ConfirmedEUR-LexThe CJEU held in Case C-33/22 that data processing carried out by a parliamentary committee of inquiry concerning national-security matters may fall outside the material scope of EU law under Article 2(2)(a) GDPR read with Article 4(2) TEU, thereby limiting DSB competence in that narrow category.
  4. ConfirmedEUR-LexGDPR Article 3 territorial-scope rules on establishment and targeting apply directly to controllers/processors in relation to Austria without a distinct national derogation.
  5. ProbableEDPBAustria does not require general prior notification or registration of processing activities with the DSB; the DSB instead applies specific statutory fees to certain filings, such as a fixed EUR 30 fee referenced in a DSB decision concerning a commercial-register-related complaint.

#

Directly-applicable GDPR core with a narrow, well-documented national research-safeguards overlay; no material derogation gaps identified.

Primary frameworkGDPR Arts 6, 7, 9; DSG §7 (research safeguards)
Traffic-light rationale — GreenDirectly-applicable GDPR core with a narrow, well-documented national research-safeguards overlay; no material derogation gaps identified.

Sub-modules (4)

Lawful BasesGreen

GDPR Art 6 lawful bases apply directly; no Austria-specific supplementary lawful basis list identified.

Claims: CLM-AT-a1000006

Special CategoriesGreen

GDPR Art 9 special-category rules apply directly; DSG §7 creates two distinct safeguard constellations for research processing of sensitive data.

Claims: CLM-AT-a1000008

Pseudonymisation And AnonymisationGreen

Austrian research-safeguards law requires anonymisation prior to dissemination of research data unless third-party dissemination interests prevail over data-subject interests.

Claims: CLM-AT-a1000009

Category narrative44 words

GDPR Articles 6, 7, and 9 apply directly and without a general Austrian derogation on lawful bases or consent standards; the DSG carries a distinct national safeguard regime for scientific/historical/statistical research processing (§7 DSG) layering additional anonymisation and dissemination conditions onto the GDPR baseline.

Sources and claims (4)
  1. ConfirmedEUR-LexGDPR Article 6 lawful bases for processing apply directly and uniformly in Austria without a general national supplementary basis regime.
  2. ConfirmedEUR-LexGDPR Article 7 consent standards (freely given, specific, informed, unambiguous, revocable) apply directly in Austria without a general derogation.
  3. ProbableEDPBArticle 7 DSG distinguishes two processing constellations for scientific research purposes involving special-category data, each subject to different national safeguards additional to GDPR Article 9.
  4. ProbableEDPBPersonal data processed for scientific, historical, or statistical research purposes in Austria cannot be disseminated without prior anonymisation unless third-party interests in dissemination prevail over the data subject's fundamental rights and freedoms.

#

Core rights are directly enforced by the DSB with a developed body of national and CJEU case law; no material national restriction identified.

Primary frameworkGDPR Arts 15-22; DSG §24 (complaints procedure)
Traffic-light rationale — GreenCore rights are directly enforced by the DSB with a developed body of national and CJEU case law; no material national restriction identified.

Sub-modules (5)

Access RightGreen

GDPR Art 15 access right applies directly; CJEU C-416/23 clarifies the 'excessive requests' fee/refusal discretion under Art 57(4) GDPR as applied by the DSB.

Claims: CLM-AT-a1000010

Rectification And ErasureAmber

DSB balances erasure requests against overriding legitimate/public interests, e.g. commercial-register transparency.

Claims: CLM-AT-a1000011

Restriction And ObjectionGreen

GDPR Arts 18/21 restriction and objection rights apply directly, including the requirement of compelling overriding legitimate grounds to continue processing after an objection.

Claims: CLM-AT-a1000012

Data PortabilityGreen

DSB practice treats delivery of data in a structured, machine-readable format directly to the complainant as satisfying Art 20 portability and can lead to amicable case closure.

Claims: CLM-AT-a1000013

Deadlines And Response WindowsGreen

The GDPR's one-month (extendable to three-month) response deadline applies; DSB enforcement treats prolonged non-response as an actionable infringement.

Claims: CLM-AT-a1000014

Category narrative48 words

GDPR Articles 15-22 apply directly in Austria; DSB enforcement decisions and CJEU references (notably Case C-416/23 on 'excessive requests' and various DSB portability/erasure/access decisions) illustrate concrete national application, including the balancing of erasure requests against public-register transparency interests and the treatment of structured-format data delivery as satisfying portability.

Sources and claims (5)
  1. ConfirmedEUR-LexThe CJEU held in Case C-416/23 that a supervisory authority faced with 'excessive' requests within Article 57(4) GDPR must show the requests were both repeated/frequent and manifestly vexatious or abusive before charging a fee or refusing to act, constraining the DSB's discretion in access-right complaints.
  2. ConfirmedEDPBIn a 2025 decision the DSB held that publicly available Austrian commercial-register data identifying a company's legal representative need not be erased where the general public interest in transparency of representative authority outweighs the data subject's Article 17 erasure interest.
  3. ConfirmedEDPBUnder GDPR Article 21(1) as applied by the DSB, a controller may continue processing following an objection only where it demonstrates compelling legitimate grounds overriding the data subject's interests, rights and freedoms.
  4. ConfirmedEDPBThe DSB treats a controller's delivery of the complainant's personal data in a structured, commonly used, machine-readable (e.g. CSV/Excel) format directly to the data subject as satisfying the Article 20 GDPR portability right, permitting the complaint to be closed as amicably settled under §24(6) DSG.
  5. ConfirmedEDPBDSB enforcement practice treats a controller's failure to respond to a data-subject portability/access request for more than a month, despite reminders, as an actionable non-compliance with GDPR response deadlines.

#

Core accountability obligations are GDPR-direct and green, but granular Austria-specific implementation detail (DPIA lists, sectoral retention rules) could not be independently confirmed this pass, warranting amber pending further primary-source verification.

Primary frameworkGDPR Arts 5, 25, 28, 30, 32-39
Traffic-light rationale — AmberCore accountability obligations are GDPR-direct and green, but granular Austria-specific implementation detail (DPIA lists, sectoral retention rules) could not be independently confirmed this pass, warranting amber pending further primary-source verification.

Sub-modules (7)

Accountability And DpiaAmber

GDPR Arts 5, 25 and 35 apply directly; an Austria-specific DPIA blacklist/whitelist was not confirmed in this research pass.

Absence provenance: not recorded. Searched: D, S, B, , D, P, I, A, , l, i, s, t, , A, u, s, t, r, i, a, , b, l, a, c, k, l, i, s, t, , w, h, i, t, e, l, i, s, t, , A, r, t, , 3, 5, (, 4, ).

Claims: CLM-AT-a1000015

Dpo RequirementsGreen

DPO appointment follows the GDPR Article 37 criteria; no Austria-specific lowered numerical threshold (unlike Germany) was identified.

Claims: CLM-AT-a1000016

Ropa RequirementsGreen

GDPR Art 30 ROPA obligations apply directly to Austrian controllers/processors above the Art 30(5) thresholds.

Claims: CLM-AT-a1000017

Joint Controller ArrangementsGreen

GDPR Arts 26/28 joint-controller and processor-contract rules apply directly.

Claims: CLM-AT-a1000018

Security MeasuresGreen

GDPR Art 32 security-of-processing obligations apply directly; no Austria-specific technical security statute overlay was confirmed.

Claims: CLM-AT-a1000019

Breach NotificationGreen

GDPR Arts 33/34 breach-notification duties apply directly, with the DSB as the national notification recipient.

Claims: CLM-AT-a1000020

Retention And DisposalAmber

GDPR Art 5(1)(e) storage-limitation principle applies; a distinct Austrian general retention/disposal statute beyond sector-specific rules was not confirmed in this pass.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , D, S, G, , g, e, n, e, r, a, l, , d, a, t, a, , r, e, t, e, n, t, i, o, n, , d, i, s, p, o, s, a, l, , s, t, a, t, u, t, e.

Category narrative61 words

GDPR Articles 5, 25, 28, 30, 32-35 and 37-39 apply directly to Austrian controllers/processors without a general national derogation elevating or lowering thresholds; Austria has not enacted a stricter national DPO-appointment trigger analogous to Germany's lower headcount-based threshold. National-specific implementation detail beyond direct GDPR application (e.g., a distinct Austrian DPIA blacklist/whitelist, sector retention statutes) was not independently confirmed in this pass.

Sources and claims (6)
  1. ConfirmedEUR-LexGDPR Articles 5 (principles), 25 (data protection by design/default) and 35 (DPIA) apply directly to Austrian controllers and processors without a general national derogation.
  2. ProbableEUR-LexDPO appointment in Austria follows the GDPR Article 37(1) criteria (public authority/body, large-scale regular systematic monitoring, or large-scale special-category processing) without an Austria-specific stricter numerical trigger comparable to Germany's national threshold.
  3. ConfirmedEUR-LexGDPR Article 30 records-of-processing obligations apply directly to Austrian controllers and processors meeting the Article 30(5) thresholds.
  4. ConfirmedEUR-LexGDPR Articles 26 (joint controllers) and 28 (processor contracts) apply directly in Austria without a general national derogation.
  5. ConfirmedEUR-LexGDPR Article 32 security-of-processing obligations (technical and organisational measures appropriate to risk) apply directly to Austrian controllers and processors.
  6. ConfirmedEDPBGDPR Articles 33 (regulator notification within 72 hours) and 34 (data-subject notification for high-risk breaches) apply directly in Austria, with the DSB as the competent notification recipient.

#

Fully harmonised EU Chapter V transfer regime with no identified Austria-specific derogation or localisation mandate.

Primary frameworkGDPR Arts 44-49 (Chapter V)
Traffic-light rationale — GreenFully harmonised EU Chapter V transfer regime with no identified Austria-specific derogation or localisation mandate.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Chapter V mechanisms (adequacy, SCCs, BCRs, Art 49 derogations) apply directly, enforced by the DSB for Austrian-established controllers/processors.

Claims: CLM-AT-a1000021

Adequacy ReceivedGreen

Not applicable as a distinct concept: Austria as an EU Member State does not itself 'receive' adequacy from third countries; it operates under bloc-wide EU mutual-recognition/free-movement rules internal to the EEA.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , a, d, e, q, u, a, c, y, , r, e, c, e, i, v, e, d, , f, r, o, m, , t, h, i, r, d, , c, o, u, n, t, r, y.

Adequacy GrantedGreen

Adequacy decisions under Article 45 GDPR are adopted at European Commission level and apply automatically and uniformly across Austria as an EU Member State; Austria does not issue separate national adequacy findings.

Claims: CLM-AT-a1000022

Sccs And BcrsGreen

SCCs and BCRs under Article 46 GDPR apply directly; the DSB participates in EDPB cooperation on BCR approvals for Austrian-anchor applicants.

Claims: CLM-AT-a1000023

Transfer Impact AssessmentGreen

Post-Schrems II transfer impact assessment expectations (EDPB Recommendations 01/2020) apply EU-wide, including to Austrian exporters.

Claims: CLM-AT-a1000024

Data LocalisationGreen

No general Austrian data-localisation mandate beyond EU-wide GDPR transfer rules was identified.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , d, a, t, a, , l, o, c, a, l, i, s, a, t, i, o, n, , m, a, n, d, a, t, e, , s, t, a, t, u, t, e.

Category narrative55 words

As an EU Member State, Austria applies the GDPR Chapter V transfer regime uniformly: European Commission adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, and Article 49 derogations are directly applicable, with the DSB as competent enforcement authority; Austria does not operate a separate national adequacy-decision or data-localisation regime distinct from the EU bloc-wide framework.

Sources and claims (4)
  1. ConfirmedEUR-LexGDPR Chapter V transfer mechanisms (adequacy decisions, SCCs, BCRs, and Article 49 derogations) apply directly and uniformly to Austrian-established controllers and processors, with the DSB as competent enforcement authority.
  2. ConfirmedEUR-LexEuropean Commission adequacy decisions under GDPR Article 45 apply automatically across all EU Member States including Austria without need for separate national implementation.
  3. ConfirmedEUR-LexStandard Contractual Clauses and Binding Corporate Rules under GDPR Article 46 are directly available transfer mechanisms for Austrian controllers/processors, with BCR approvals proceeding through EDPB cooperation involving the DSB where Austria is a concerned authority.
  4. ProbableEUR-LexFollowing the CJEU's Schrems II judgment, EDPB Recommendations 01/2020 on supplementary measures establish an EU-wide expectation—including for Austrian data exporters—that transfer impact assessments be conducted before relying on SCCs to third countries lacking adequacy.

#

Two of seven sub-modules (telecoms/ePrivacy, employment) are evidenced; five require further primary-source escalation.

Primary frameworkTKG 2021 (Telecommunications Act); Arbeitsverfassungsgesetz (ArbVG); GlBG; GDPR/DSG
Traffic-light rationale — AmberTwo of seven sub-modules (telecoms/ePrivacy, employment) are evidenced; five require further primary-source escalation.

Sub-modules (7)

Financial Sector OverlayRed

Not independently confirmed in this pass.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , B, a, n, k, w, e, s, e, n, g, e, s, e, t, z, , b, a, n, k, i, n, g, , s, e, c, r, e, c, y, , G, D, P, R, , i, n, t, e, r, p, l, a, y, , D, S, B.

Health Sector OverlayRed

Not independently confirmed in this pass.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , h, e, a, l, t, h, , d, a, t, a, , G, D, P, R, , s, e, c, t, o, r, a, l, , o, v, e, r, l, a, y, , G, e, s, u, n, d, h, e, i, t, s, t, e, l, e, m, a, t, i, k, g, e, s, e, t, z.

Telecoms And EprivacyGreen

Austria implements ePrivacy Directive obligations, including electronic-marketing consent, via the Telecommunications Act 2021 (TKG 2021) alongside GDPR and the E-Commerce Act.

Claims: CLM-AT-a1000025

Employment DataGreen

Austrian employment data processing sits at the intersection of GDPR/DSG with the ArbVG (works-council co-determination for employee-monitoring systems) and the GlBG (equal treatment).

Claims: CLM-AT-a1000026

Credit And ScoringRed

Not independently confirmed in this pass.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , c, r, e, d, i, t, , s, c, o, r, i, n, g, , G, D, P, R, , s, e, c, t, o, r, a, l, , r, u, l, e, s, , D, S, B.

EducationRed

Not independently confirmed in this pass.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , e, d, u, c, a, t, i, o, n, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , o, v, e, r, l, a, y, , D, S, B.

InsuranceRed

Not independently confirmed in this pass.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , i, n, s, u, r, a, n, c, e, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , o, v, e, r, l, a, y, , V, A, G, , D, S, B.

Category narrative51 words

Austrian sector-specific overlays interacting with GDPR/DSG were only partly confirmed in this research pass. Telecoms/ePrivacy (TKG 2021) and employment (ArbVG works-council co-determination, GlBG) overlays are documented; financial-sector banking-secrecy interplay (Bankwesengesetz), health-sector overlay, credit-scoring, education-sector, and insurance-sector specific DP rules were not independently confirmed and are flagged with absent_field_provenance rather than fabricated.

Sources and claims (2)
  1. ProbableDataGuidanceIn addition to the ePrivacy Directive and GDPR, Austria applies the Telecommunications Act 2021 (TKG 2021) and the E-Commerce Act to govern electronic communications marketing including SMS/MMS marketing.
  2. ProbableDataGuidanceAustrian employee data protection compliance is governed by the interaction of GDPR/DSG with the Labour Constitutional Act (Arbeitsverfassungsgesetz, ArbVG) and the Equal Treatment Act (GlBG), with works-council consent frequently required for employee-monitoring measures.

#

Cookie/tracker and direct-marketing sub-modules are evidenced; opt-out-signal, clean-room, and cross-context-advertising sub-modules do not map cleanly onto the EU consent-based model and were not independently confirmed as distinct Austrian constructs.

Primary frameworkTKG 2021 (implementing ePrivacy Directive Art 5(3)); GDPR
Traffic-light rationale — AmberCookie/tracker and direct-marketing sub-modules are evidenced; opt-out-signal, clean-room, and cross-context-advertising sub-modules do not map cleanly onto the EU consent-based model and were not independently confirmed as distinct Austrian constructs.

Sub-modules (6)

Cookies And TrackersGreen

Cookie/tracker consent in Austria is governed by TKG 2021 provisions implementing ePrivacy Directive Article 5(3), applied alongside GDPR consent standards.

Claims: CLM-AT-a1000027

Dark PatternsAmber

EDPB Guidelines on dark patterns in social media interfaces apply EU-wide, including to Austrian controllers, though no Austria-specific dark-pattern statute was identified.

Claims: CLM-AT-a1000028

Opt Out SignalsRed

No Austria-specific Global Privacy Control/DAA opt-out-signal recognition statute was identified; this is not a native construct of the EU consent-based model.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , G, l, o, b, a, l, , P, r, i, v, a, c, y, , C, o, n, t, r, o, l, , o, p, t, -, o, u, t, , s, i, g, n, a, l, , r, e, c, o, g, n, i, t, i, o, n, , l, a, w.

Clean Rooms And DcrRed

No Austria-specific clean-room/data-collaboration-room regulation was identified.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , d, a, t, a, , c, l, e, a, n, , r, o, o, m, , r, e, g, u, l, a, t, i, o, n, , D, S, B, , g, u, i, d, a, n, c, e.

Cross Context AdvertisingAmber

The CPRA 'sale'/'share' cross-context-advertising construct is a US-state concept without a direct Austrian/EU equivalent; Austria instead relies on GDPR consent and legitimate-interest balancing for behavioural advertising.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , c, r, o, s, s, -, c, o, n, t, e, x, t, , a, d, v, e, r, t, i, s, i, n, g, , e, q, u, i, v, a, l, e, n, t, , c, o, n, s, t, r, u, c, t.

Direct MarketingGreen

Direct electronic marketing requires prior opt-in consent under TKG 2021/E-Commerce Act, subject to a narrow existing-customer soft opt-in exception.

Claims: CLM-AT-a1000029

Category narrative52 words

Austria's cookie/tracker and direct-marketing consent regime derives from the ePrivacy Directive as implemented via TKG 2021, layered with GDPR consent standards; US-style constructs (Global Privacy Control opt-out signals, CPRA-style cross-context advertising, clean rooms) are not native to the Austrian/EU framework and are addressed instead through consent-based ePrivacy/GDPR mechanisms and EDPB dark-pattern guidance.

Sources and claims (3)
  1. ProbableDataGuidanceStorage of and access to information on end-user devices (cookies and similar trackers) in Austria requires consent under TKG 2021 provisions implementing Article 5(3) of the ePrivacy Directive, applied alongside GDPR consent standards where personal data is processed.
  2. UncertainEDPBEDPB guidance on dark patterns in social media platform interfaces applies to Austrian-established controllers as part of the GDPR consent-validity and fair-processing framework, absent a distinct Austrian statutory dark-pattern prohibition.
  3. ProbableDataGuidanceDirect electronic marketing communications (including SMS/MMS) in Austria require prior consent under the TKG 2021 and E-Commerce Act, mirroring the ePrivacy Directive's Article 13 soft opt-in exception for existing customer relationships.

#

Profiling/ADM and state-surveillance carve-out sub-modules are GDPR/CJEU-evidenced (green); AI-risk-assessment sub-module is evidenced but time-sensitive/in-transition (amber); biometric and genetic sub-modules lack confirmed Austria-specific overlay (red-leaning amber).

Primary frameworkGDPR Art 22; EU AI Act (Regulation (EU) 2024/1689)
Traffic-light rationale — AmberProfiling/ADM and state-surveillance carve-out sub-modules are GDPR/CJEU-evidenced (green); AI-risk-assessment sub-module is evidenced but time-sensitive/in-transition (amber); biometric and genetic sub-modules lack confirmed Austria-specific overlay (red-leaning amber).

Sub-modules (6)

Profiling RestrictionsGreen

GDPR Art 22 restrictions on solely automated decision-making, including profiling with legal/similarly significant effects, apply directly in Austria.

Claims: CLM-AT-a1000030

Automated Decision Making TransparencyGreen

GDPR Arts 13-15/22 transparency and explanation rights for ADM apply directly.

Claims: CLM-AT-a1000031

Ai Risk AssessmentsAmber

Austria is subject to the EU AI Act's competent-authority designation deadline (2 Aug 2025) and Annex III high-risk obligations (applicable from 2 Aug 2026); designation and enforcement-readiness remain in progress bloc-wide as of mid-2026.

Claims: CLM-AT-a1000032, CLM-AT-a1000033

Biometric RegimeAmber

GDPR Art 9 special-category rules govern biometric data for unique identification; a distinct Austrian biometric/facial-recognition statute was not independently confirmed.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , f, a, c, i, a, l, , r, e, c, o, g, n, i, t, i, o, n, , b, i, o, m, e, t, r, i, c, , d, a, t, a, , s, t, a, t, u, t, e.

Genetic DataAmber

GDPR Art 9 governs genetic data as a special category; a distinct Austrian Gene Technology Act overlay was not independently confirmed in this pass.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , G, e, n, t, e, c, h, n, i, k, g, e, s, e, t, z, , g, e, n, e, t, i, c, , d, a, t, a, , G, D, P, R, , o, v, e, r, l, a, y.

State Surveillance CarveoutsGreen

CJEU Case C-33/22 delineates the national-security exemption from GDPR/DSB competence for certain parliamentary-inquiry processing.

Claims: CLM-AT-a1000034

Category narrative82 words

GDPR Article 22 profiling/ADM restrictions apply directly in Austria. The EU AI Act layers additional risk-based obligations, with Member States (including Austria) required to designate national competent authorities by 2 August 2025 and high-risk obligations under Annex III applying from 2 August 2026; the European Commission has noted that competent-authority designations across Member States remain in progress. Austria-specific biometric and genetic-data overlay statutes beyond GDPR Article 9 were not independently confirmed. The CJEU's Case C-33/22 delineates a national-security carve-out from DSB competence.

Sources and claims (5)
  1. ConfirmedEUR-LexGDPR Article 22 restricts decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect a data subject, applying directly to Austrian controllers.
  2. ConfirmedEUR-LexGDPR Articles 13-15 require controllers to provide meaningful information about the logic, significance, and envisaged consequences of automated decision-making, applying directly in Austria.
  3. ConfirmedIAPPUnder the EU AI Act, all EU Member States, including Austria, were required to designate or establish national competent authorities (market surveillance and notifying authorities) by 2 August 2025.
  4. ProbableEUR-LexAs of the European Commission's 2026 implementation report, enforcement rules for the AI Act's prohibited-practices chapter apply from 2 August 2026 and national competent authorities across Member States, including Austria, are still in the process of being designated.
  5. ConfirmedEUR-LexThe CJEU held that activities of a committee of inquiry set up by a Member State parliament concerning national security may fall outside GDPR's material scope under Article 2(2)(a) read with Article 4(2) TEU, while supervisory-authority competence to assess that exemption remains subject to CJEU-defined limits under Articles 51 and 55 GDPR.

#

The EU-level Article 8 framework is confirmed, but the Austria-specific numerical age-of-consent threshold and several sub-modules were not independently verified in this pass, warranting escalation to primary source (RIS/DSG text) before publication reliance.

Primary frameworkGDPR Art 8; DSG (national age-of-consent implementation — threshold unconfirmed this pass)
Traffic-light rationale — AmberThe EU-level Article 8 framework is confirmed, but the Austria-specific numerical age-of-consent threshold and several sub-modules were not independently verified in this pass, warranting escalation to primary source (RIS/DSG text) before publication reliance.

Sub-modules (5)

Age VerificationAmber

GDPR Art 8(2) requires reasonable efforts to verify parental consent for information-society-service processing of children's data; applies directly in Austria.

Claims: CLM-AT-a1000035

Minor Profiling BansAmber

No Austria-specific statutory ban on profiling of minors beyond general GDPR children protections and EDPB Age Assurance guidance was identified.

Claims: CLM-AT-a1000037

Education SettingsRed

Not independently confirmed in this pass.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , e, d, u, c, a, t, i, o, n, -, s, e, c, t, o, r, , c, h, i, l, d, r, e, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, p, e, c, i, f, i, c, , r, u, l, e, s.

Dependent AdultsRed

Not independently confirmed in this pass.

Absence provenance: not recorded. Searched: A, u, s, t, r, i, a, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, s, , i, n, c, a, p, a, c, i, t, a, t, e, d, , p, e, r, s, o, n, s, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, p, e, c, i, f, i, c, , r, u, l, e, s.

Category narrative74 words

GDPR Article 8 establishes the EU digital age-of-consent framework (default 16, Member States may lower to no less than 13); the precise national threshold adopted under the Austrian DSG could not be independently confirmed via primary source in this research pass and is flagged as an open question requiring escalation. EDPB Statement 1/2025 on Age Assurance applies EU-wide including Austria. Austria-specific minor-profiling-ban, education-setting, and dependent-adult statutes beyond GDPR general protections were not independently confirmed.

Sources and claims (3)
  1. ConfirmedEUR-LexGDPR Article 8(2) requires controllers to make reasonable efforts to verify that consent for processing a child's data in connection with an information society service is given or authorised by the holder of parental responsibility, taking into account available technology; this applies directly in Austria.
  2. UncertainEUR-LexGDPR Article 8(1) sets a default digital age-of-consent of 16 for information-society-service processing based on a child's own consent, with Member States permitted to lower that threshold by national law to no less than 13; the specific figure adopted under Austrian law was not independently confirmed via primary source in this research pass.
  3. ProbableEDPBEDPB Statement 1/2025 on Age Assurance emphasises that age-assurance mechanisms should not enable excess profiling of individuals, particularly children, applying as EU-wide guidance relevant to Austrian controllers absent a distinct national minor-profiling-ban statute.

#

Core enforcement powers, penalty ceilings, and a significant recent CJEU judgment are well-evidenced (green-leaning); current regulator funding/capacity and collective-redress implementing-act specifics were not independently confirmed this pass (amber).

Primary frameworkGDPR Arts 58, 77-84; DSG §24 (complaints procedure)
Traffic-light rationale — AmberCore enforcement powers, penalty ceilings, and a significant recent CJEU judgment are well-evidenced (green-leaning); current regulator funding/capacity and collective-redress implementing-act specifics were not independently confirmed this pass (amber).

Sub-modules (6)

Regulator Powers And PenaltiesGreen

GDPR Art 58 investigative/corrective powers and Art 83 fines up to EUR 20m/4% global turnover apply directly to the DSB.

Claims: CLM-AT-a1000038

Enforcement Activity IndexGreen

The DSB's highest-profile fine to date is the EUR 18 million Österreichische Post AG decision.

Claims: CLM-AT-a1000039

Regulator Funding And CapacityAmber

Early post-GDPR reporting indicated a substantial pending caseload; current (2026) staffing/funding figures were not independently confirmed this pass.

Absence provenance: not recorded. Searched: D, S, B, , c, u, r, r, e, n, t, , b, u, d, g, e, t, , h, e, a, d, c, o, u, n, t, , 2, 0, 2, 6.

Claims: CLM-AT-a1000040

Collective Redress And Class ActionsAmber

GDPR Article 80 representative-action mechanism applies; Austria-specific implementing details of the EU Representative Actions Directive were not independently confirmed this pass.

Claims: CLM-AT-a1000041

Private Right Of ActionAmber

GDPR Article 82 provides a directly enforceable compensation right; a pending CJEU reference (AG Opinion, Case C-185/25) examines Austrian public-liability channelling rules against Article 82.

Claims: CLM-AT-a1000042

Recent Developments 180DGreen

Within the last 180 days, the CJEU delivered judgment in Case C-414/24 (18 June 2026) on DSB complaint-rejection practice, and the EDPB adopted Opinion 18/2024 (5 February 2026) on an Austrian certification-body draft decision.

Claims: CLM-AT-a1000043, CLM-AT-a1000044

Category narrative116 words

The DSB exercises the full suite of GDPR Article 58 investigative and corrective powers, including Article 83 administrative fines up to EUR 20 million or 4% of global annual turnover; its highest-profile action to date is the 2019 EUR 18 million fine against Österreichische Post AG (later challenged before the Federal Administrative Court). Early post-GDPR reporting indicated a substantial pending caseload, though current staffing/funding figures were not independently confirmed. Article 82 private-right-of-action compensation claims are directly enforceable, with a pending CJEU reference (AG Opinion, Case C-185/25) addressing Austrian public-liability channelling rules. A significant recent development is the CJEU's 18 June 2026 judgment in Case C-414/24 on the DSB's complaint-rejection practice where parallel judicial proceedings are pending.

Sources and claims (7)
  1. ConfirmedEUR-LexGDPR Recital 129 and Article 58 confer on supervisory authorities including the DSB investigative, corrective, authorisation and advisory powers, including the power to impose a temporary or definitive limitation or ban on processing, alongside Article 83 fines of up to EUR 20 million or 4% of global annual turnover.
  2. ConfirmedEDPBThe DSB imposed an administrative fine of EUR 18 million on Österreichische Post AG for unlawfully processing data on customers' presumed political affinity and for further processing package-frequency and relocation-frequency data for direct-marketing purposes, with the fine subject to challenge before the Federal Administrative Court and thus not final upon issuance.
  3. UncertainIAPPEarly post-GDPR reporting indicated the DSB had at least 115 fine proceedings pending and had initiated 58 ex officio investigations shortly after its first GDPR fine, though current (2026) staffing and funding levels were not independently confirmed in this research pass.
  4. ProbableEUR-LexGDPR Article 80 permits data subjects to mandate a not-for-profit body to exercise rights and lodge complaints on their behalf, applying directly in Austria; Austria-specific implementing detail of the EU Representative Actions Directive for consumer collective redress was not independently confirmed this pass.
  5. UncertainEUR-LexAn Advocate General Opinion in a pending Austrian CJEU reference (Case C-185/25) proposes that Article 82 GDPR does not preclude national rules under which persons acting on behalf of certain Austrian public-law entities cannot be held personally liable for data-subject damage, provided those rules identify the entity against which compensation claims may be brought.
  6. ConfirmedEUR-LexOn 18 June 2026, the CJEU (First Chamber) delivered judgment in Case C-414/24, Datenschutzbehörde and Dr G S v Bundesministerin für Justiz and D GmbH, interpreting Articles 77 and 79 GDPR in relation to the DSB's rejection of complaints where parallel judicial proceedings on the same subject-matter are pending.
  7. ConfirmedEDPBOn 5 February 2026, the EDPB adopted Opinion 18/2024 on the draft decision of the Austrian supervisory authority regarding certification criteria for a certification-monitoring body (DSGVO-zt GmbH) under the Article 64 consistency mechanism.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Austria
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s), 17 source(s) in the cumulative register.