🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
AT v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing17 sources retrieved model claude-sonnet-5 · 2026-08-02

Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

Austria

AT schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 44 claims · 28 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
44Claimsbaseline..claims[]
13Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 9 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Austria's data-protection picture this cycle is defined by a structural tension between a mature legal framework and a stretched enforcement apparatus. The Datenschutzbehörde (DSB) is understood to have conducted 4,030 proceedings in 2023 - 2,389 national, 876 cross-border, and 765 initiated ex officio - yet these resulted in only 55 fines, a 1.36 percent conversion rate that noyb founder Max Schrems has publicly criticised. This enforcement-rate finding sits alongside the DSB's 2026 budget of approximately EUR 5.9 million, itself down from EUR 6.1 million in 2025, a real-terms contraction for the sole national supervisory authority under Article 51 GDPR.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fully GDPR-aligned omnibus regime with an operational, EDPB-networked national DPA and consistent CJEU-tested procedural framework.

Primary frameworkDatenschutzgesetz (DSG) BGBl I No 165/1999, as amended, together with Regulation (EU) 2016/679 (GDPR)
Traffic-light rationale — GreenFully GDPR-aligned omnibus regime with an operational, EDPB-networked national DPA and consistent CJEU-tested procedural framework.

Sub-modules (5)

Regulator And AuthorityGreen

The DSB, based in Vienna, is Austria's independent supervisory authority under the GDPR and DSG.

Claims (1):

  • The Österreichische Datenschutzbehörde (DSB), headquartered at Barichgasse 40-42, Vienna, is Austria's independent data protection supervisory authority responsible for handling complaints and enforcing the GDPR and DSG.

Act And InstrumentsGreen

DSG supplements GDPR with national procedural rules including a statutory complaints regime under §24 DSG.

Claims (1):

  • The Datenschutzgesetz (DSG), Federal Law Gazette I No 165/1999 as amended, provides that every data subject has the right to lodge a complaint with the DSB and sets a one-year (max. three-year) limitation period under §24 DSG.

Material ScopeAmber

GDPR Art 2 material scope applies; DSG §1's constitutional right can extend protection to processing outside EU-law material scope, subject to CJEU delimitation.

Claims (1):

  • The CJEU held in Case C-33/22 that data processing carried out by a parliamentary committee of inquiry concerning national-security matters may fall outside the material scope of EU law under Article 2(2)(a) GDPR read with Article 4(2) TEU, thereby limiting DSB competence in that narrow category.

Territorial ScopeGreen

GDPR Art 3 territorial scope rules apply directly; no distinct Austrian territorial-scope regime.

Claims (1):

  • GDPR Article 3 territorial-scope rules on establishment and targeting apply directly to controllers/processors in relation to Austria without a distinct national derogation.

Regulator Registration And FilingGreen

No general prior-notification/registration regime exists post-GDPR; DSB levies specific statutory fees for certain filings.

Claims (1):

  • Austria does not require general prior notification or registration of processing activities with the DSB; the DSB instead applies specific statutory fees to certain filings, such as a fixed EUR 30 fee referenced in a DSB decision concerning a commercial-register-related complaint.
Category narrative56 words

Austria is an EU Member State operating under the directly-applicable GDPR, supplemented by the national Datenschutzgesetz (DSG, BGBl I No 165/1999 as amended), which establishes the Datenschutzbehörde (DSB) as sole national supervisory authority, sets the constitutional-rank fundamental right to data protection (§1 DSG), and lays down national procedural rules (complaints procedure, limitation periods) for DSB proceedings.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ProbableEDPB — The Österreichische Datenschutzbehörde (DSB), headquartered at Barichgasse 40-42, Vienna, is Austria's independent data protection supervisory authority responsible for handling complaints and enforcing the GDPR and DSG.observed
  2. ProbableEUR-Lex — The Datenschutzgesetz (DSG), Federal Law Gazette I No 165/1999 as amended, provides that every data subject has the right to lodge a complaint with the DSB and sets a one-year (max. three-year) limitation period under §24 DSG.observed
  3. ProbableEUR-Lex — The CJEU held in Case C-33/22 that data processing carried out by a parliamentary committee of inquiry concerning national-security matters may fall outside the material scope of EU law under Article 2(2)(a) GDPR read with Article 4(2) TEU, thereby limiting DSB competence in that narrow category.observed
  4. ProbableEUR-Lex — GDPR Article 3 territorial-scope rules on establishment and targeting apply directly to controllers/processors in relation to Austria without a distinct national derogation.observed
  5. ProbableEDPB — Austria does not require general prior notification or registration of processing activities with the DSB; the DSB instead applies specific statutory fees to certain filings, such as a fixed EUR 30 fee referenced in a DSB decision concerning a commercial-register-related complaint.observed

#

Directly-applicable GDPR core with a narrow, well-documented national research-safeguards overlay; no material derogation gaps identified.

Primary frameworkGDPR Arts 6, 7, 9; DSG §7 (research safeguards)
Traffic-light rationale — GreenDirectly-applicable GDPR core with a narrow, well-documented national research-safeguards overlay; no material derogation gaps identified.

Sub-modules (4)

Lawful BasesGreen

GDPR Art 6 lawful bases apply directly; no Austria-specific supplementary lawful basis list identified.

Claims (1):

  • GDPR Article 6 lawful bases for processing apply directly and uniformly in Austria without a general national supplementary basis regime.

Special CategoriesGreen

GDPR Art 9 special-category rules apply directly; DSG §7 creates two distinct safeguard constellations for research processing of sensitive data.

Claims (1):

  • Article 7 DSG distinguishes two processing constellations for scientific research purposes involving special-category data, each subject to different national safeguards additional to GDPR Article 9.

Pseudonymisation And AnonymisationGreen

Austrian research-safeguards law requires anonymisation prior to dissemination of research data unless third-party dissemination interests prevail over data-subject interests.

Claims (1):

  • Personal data processed for scientific, historical, or statistical research purposes in Austria cannot be disseminated without prior anonymisation unless third-party interests in dissemination prevail over the data subject's fundamental rights and freedoms.
Category narrative44 words

GDPR Articles 6, 7, and 9 apply directly and without a general Austrian derogation on lawful bases or consent standards; the DSG carries a distinct national safeguard regime for scientific/historical/statistical research processing (§7 DSG) layering additional anonymisation and dissemination conditions onto the GDPR baseline.

Sources and claims (4)
  1. ProbableEUR-Lex — GDPR Article 6 lawful bases for processing apply directly and uniformly in Austria without a general national supplementary basis regime.observed
  2. ProbableEUR-Lex — GDPR Article 7 consent standards (freely given, specific, informed, unambiguous, revocable) apply directly in Austria without a general derogation.observed
  3. ProbableEDPB — Article 7 DSG distinguishes two processing constellations for scientific research purposes involving special-category data, each subject to different national safeguards additional to GDPR Article 9.observed
  4. ProbableEDPB — Personal data processed for scientific, historical, or statistical research purposes in Austria cannot be disseminated without prior anonymisation unless third-party interests in dissemination prevail over the data subject's fundamental rights and freedoms.observed

#

Core rights are directly enforced by the DSB with a developed body of national and CJEU case law; no material national restriction identified.

Primary frameworkGDPR Arts 15-22; DSG §24 (complaints procedure)
Traffic-light rationale — GreenCore rights are directly enforced by the DSB with a developed body of national and CJEU case law; no material national restriction identified.

Sub-modules (5)

Access RightGreen

GDPR Art 15 access right applies directly; CJEU C-416/23 clarifies the 'excessive requests' fee/refusal discretion under Art 57(4) GDPR as applied by the DSB.

Claims (1):

  • The CJEU held in Case C-416/23 that a supervisory authority faced with 'excessive' requests within Article 57(4) GDPR must show the requests were both repeated/frequent and manifestly vexatious or abusive before charging a fee or refusing to act, constraining the DSB's discretion in access-right complaints.

Rectification And ErasureAmber

DSB balances erasure requests against overriding legitimate/public interests, e.g. commercial-register transparency.

Claims (1):

  • In a 2025 decision the DSB held that publicly available Austrian commercial-register data identifying a company's legal representative need not be erased where the general public interest in transparency of representative authority outweighs the data subject's Article 17 erasure interest.

Restriction And ObjectionGreen

GDPR Arts 18/21 restriction and objection rights apply directly, including the requirement of compelling overriding legitimate grounds to continue processing after an objection.

Claims (1):

  • Under GDPR Article 21(1) as applied by the DSB, a controller may continue processing following an objection only where it demonstrates compelling legitimate grounds overriding the data subject's interests, rights and freedoms.

Data PortabilityGreen

DSB practice treats delivery of data in a structured, machine-readable format directly to the complainant as satisfying Art 20 portability and can lead to amicable case closure.

Claims (1):

  • The DSB treats a controller's delivery of the complainant's personal data in a structured, commonly used, machine-readable (e.g. CSV/Excel) format directly to the data subject as satisfying the Article 20 GDPR portability right, permitting the complaint to be closed as amicably settled under §24(6) DSG.

Deadlines And Response WindowsGreen

The GDPR's one-month (extendable to three-month) response deadline applies; DSB enforcement treats prolonged non-response as an actionable infringement.

Claims (1):

  • DSB enforcement practice treats a controller's failure to respond to a data-subject portability/access request for more than a month, despite reminders, as an actionable non-compliance with GDPR response deadlines.
Category narrative48 words

GDPR Articles 15-22 apply directly in Austria; DSB enforcement decisions and CJEU references (notably Case C-416/23 on 'excessive requests' and various DSB portability/erasure/access decisions) illustrate concrete national application, including the balancing of erasure requests against public-register transparency interests and the treatment of structured-format data delivery as satisfying portability.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ProbableEUR-Lex — The CJEU held in Case C-416/23 that a supervisory authority faced with 'excessive' requests within Article 57(4) GDPR must show the requests were both repeated/frequent and manifestly vexatious or abusive before charging a fee or refusing to act, constraining the DSB's discretion in access-right complaints.observed
  2. ProbableEDPB — In a 2025 decision the DSB held that publicly available Austrian commercial-register data identifying a company's legal representative need not be erased where the general public interest in transparency of representative authority outweighs the data subject's Article 17 erasure interest.observed
  3. ProbableEDPB — Under GDPR Article 21(1) as applied by the DSB, a controller may continue processing following an objection only where it demonstrates compelling legitimate grounds overriding the data subject's interests, rights and freedoms.observed
  4. ProbableEDPB — The DSB treats a controller's delivery of the complainant's personal data in a structured, commonly used, machine-readable (e.g. CSV/Excel) format directly to the data subject as satisfying the Article 20 GDPR portability right, permitting the complaint to be closed as amicably settled under §24(6) DSG.observed
  5. ProbableEDPB — DSB enforcement practice treats a controller's failure to respond to a data-subject portability/access request for more than a month, despite reminders, as an actionable non-compliance with GDPR response deadlines.observed

#

Core accountability obligations are GDPR-direct and green, but granular Austria-specific implementation detail (DPIA lists, sectoral retention rules) could not be independently confirmed this pass, warranting amber pending further primary-source verification.

Primary frameworkGDPR Arts 5, 25, 28, 30, 32-39
Traffic-light rationale — AmberCore accountability obligations are GDPR-direct and green, but granular Austria-specific implementation detail (DPIA lists, sectoral retention rules) could not be independently confirmed this pass, warranting amber pending further primary-source verification.

Sub-modules (7)

Accountability And DpiaAmber

GDPR Arts 5, 25 and 35 apply directly; an Austria-specific DPIA blacklist/whitelist was not confirmed in this research pass.

Absence provenance: unavailable. Searched: D, S, B, , D, P, I, A, , l, i, s, t, , A, u, s, t, r, i, a, , b, l, a, c, k, l, i, s, t, , w, h, i, t, e, l, i, s, t, , A, r, t, , 3, 5, (, 4, ).

Claims (1):

  • GDPR Articles 5 (principles), 25 (data protection by design/default) and 35 (DPIA) apply directly to Austrian controllers and processors without a general national derogation.

Dpo RequirementsGreen

DPO appointment follows the GDPR Article 37 criteria; no Austria-specific lowered numerical threshold (unlike Germany) was identified.

Claims (1):

  • DPO appointment in Austria follows the GDPR Article 37(1) criteria (public authority/body, large-scale regular systematic monitoring, or large-scale special-category processing) without an Austria-specific stricter numerical trigger comparable to Germany's national threshold.

Ropa RequirementsGreen

GDPR Art 30 ROPA obligations apply directly to Austrian controllers/processors above the Art 30(5) thresholds.

Claims (1):

  • GDPR Article 30 records-of-processing obligations apply directly to Austrian controllers and processors meeting the Article 30(5) thresholds.

Joint Controller ArrangementsGreen

GDPR Arts 26/28 joint-controller and processor-contract rules apply directly.

Claims (1):

  • GDPR Articles 26 (joint controllers) and 28 (processor contracts) apply directly in Austria without a general national derogation.

Security MeasuresGreen

GDPR Art 32 security-of-processing obligations apply directly; no Austria-specific technical security statute overlay was confirmed.

Claims (1):

  • GDPR Article 32 security-of-processing obligations (technical and organisational measures appropriate to risk) apply directly to Austrian controllers and processors.

Breach NotificationGreen

GDPR Arts 33/34 breach-notification duties apply directly, with the DSB as the national notification recipient.

Claims (1):

  • GDPR Articles 33 (regulator notification within 72 hours) and 34 (data-subject notification for high-risk breaches) apply directly in Austria, with the DSB as the competent notification recipient.

Retention And DisposalAmber

GDPR Art 5(1)(e) storage-limitation principle applies; a distinct Austrian general retention/disposal statute beyond sector-specific rules was not confirmed in this pass.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , D, S, G, , g, e, n, e, r, a, l, , d, a, t, a, , r, e, t, e, n, t, i, o, n, , d, i, s, p, o, s, a, l, , s, t, a, t, u, t, e.

Category narrative61 words

GDPR Articles 5, 25, 28, 30, 32-35 and 37-39 apply directly to Austrian controllers/processors without a general national derogation elevating or lowering thresholds; Austria has not enacted a stricter national DPO-appointment trigger analogous to Germany's lower headcount-based threshold. National-specific implementation detail beyond direct GDPR application (e.g., a distinct Austrian DPIA blacklist/whitelist, sector retention statutes) was not independently confirmed in this pass.

Periodic update · new data 2026-09-28

Controller/Processor Duties

The DSB's controller/processor scrutiny this cycle is understood to centre on decision D135.027, which examines cookie-banner design and transparency practices alongside Microsoft 365 Education deployments in Austrian schools, including the third-country data-flow dimensions of those deployments. This is a Probable finding sourced from a T3 enforcement-tracker publication, and it is presented here as an active regulatory examination rather than a concluded, binding decision - the underlying claim carries is_binding: false, meaning it should be read as scrutiny in progress rather than a settled finding against a named controller.

The examination's dual focus - cookie-banner transparency on the one hand, education-sector cloud deployments on the other - illustrates the DSB's current controller/processor priorities: consent-interface adequacy for commercial websites, and third-country data-flow exposure for institutional deployments of major cloud-service providers. Both threads sit within the DSB's ordinary Article 51 GDPR supervisory remit; neither has been confirmed this cycle as having produced a final sanction or corrective order.

No further controller/processor developments - security-measure enforcement actions, DPIA-adequacy findings, or processor-agreement disputes - were located for Austria this cycle beyond the D135.027 examination.

Outlook

Whether the D135.027 examination concludes with a binding corrective order, and if so what it requires of cookie-banner design or of Microsoft 365 Education deployments specifically, is the concrete item to watch. Given the DSB's broader enforcement-capacity constraints reported elsewhere this cycle, the pace at which this examination resolves is itself a signal worth tracking.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ProbableEUR-Lex — GDPR Articles 5 (principles), 25 (data protection by design/default) and 35 (DPIA) apply directly to Austrian controllers and processors without a general national derogation.observed
  2. ProbableEUR-Lex — DPO appointment in Austria follows the GDPR Article 37(1) criteria (public authority/body, large-scale regular systematic monitoring, or large-scale special-category processing) without an Austria-specific stricter numerical trigger comparable to Germany's national threshold.observed
  3. ProbableEUR-Lex — GDPR Article 30 records-of-processing obligations apply directly to Austrian controllers and processors meeting the Article 30(5) thresholds.observed
  4. ProbableEUR-Lex — GDPR Articles 26 (joint controllers) and 28 (processor contracts) apply directly in Austria without a general national derogation.observed
  5. ProbableEUR-Lex — GDPR Article 32 security-of-processing obligations (technical and organisational measures appropriate to risk) apply directly to Austrian controllers and processors.observed
  6. ProbableEDPB — GDPR Articles 33 (regulator notification within 72 hours) and 34 (data-subject notification for high-risk breaches) apply directly in Austria, with the DSB as the competent notification recipient.observed

#

Fully harmonised EU Chapter V transfer regime with no identified Austria-specific derogation or localisation mandate.

Primary frameworkGDPR Arts 44-49 (Chapter V)
Traffic-light rationale — GreenFully harmonised EU Chapter V transfer regime with no identified Austria-specific derogation or localisation mandate.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Chapter V mechanisms (adequacy, SCCs, BCRs, Art 49 derogations) apply directly, enforced by the DSB for Austrian-established controllers/processors.

Claims (1):

  • GDPR Chapter V transfer mechanisms (adequacy decisions, SCCs, BCRs, and Article 49 derogations) apply directly and uniformly to Austrian-established controllers and processors, with the DSB as competent enforcement authority.

Adequacy ReceivedGreen

Not applicable as a distinct concept: Austria as an EU Member State does not itself 'receive' adequacy from third countries; it operates under bloc-wide EU mutual-recognition/free-movement rules internal to the EEA.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , a, d, e, q, u, a, c, y, , r, e, c, e, i, v, e, d, , f, r, o, m, , t, h, i, r, d, , c, o, u, n, t, r, y.

Adequacy GrantedGreen

Adequacy decisions under Article 45 GDPR are adopted at European Commission level and apply automatically and uniformly across Austria as an EU Member State; Austria does not issue separate national adequacy findings.

Claims (1):

  • European Commission adequacy decisions under GDPR Article 45 apply automatically across all EU Member States including Austria without need for separate national implementation.

Sccs And BcrsGreen

SCCs and BCRs under Article 46 GDPR apply directly; the DSB participates in EDPB cooperation on BCR approvals for Austrian-anchor applicants.

Claims (1):

  • Standard Contractual Clauses and Binding Corporate Rules under GDPR Article 46 are directly available transfer mechanisms for Austrian controllers/processors, with BCR approvals proceeding through EDPB cooperation involving the DSB where Austria is a concerned authority.

Transfer Impact AssessmentGreen

Post-Schrems II transfer impact assessment expectations (EDPB Recommendations 01/2020) apply EU-wide, including to Austrian exporters.

Claims (1):

  • Following the CJEU's Schrems II judgment, EDPB Recommendations 01/2020 on supplementary measures establish an EU-wide expectation—including for Austrian data exporters—that transfer impact assessments be conducted before relying on SCCs to third countries lacking adequacy.

Data LocalisationGreen

No general Austrian data-localisation mandate beyond EU-wide GDPR transfer rules was identified.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , d, a, t, a, , l, o, c, a, l, i, s, a, t, i, o, n, , m, a, n, d, a, t, e, , s, t, a, t, u, t, e.

Category narrative55 words

As an EU Member State, Austria applies the GDPR Chapter V transfer regime uniformly: European Commission adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, and Article 49 derogations are directly applicable, with the DSB as competent enforcement authority; Austria does not operate a separate national adequacy-decision or data-localisation regime distinct from the EU bloc-wide framework.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ProbableEUR-Lex — GDPR Chapter V transfer mechanisms (adequacy decisions, SCCs, BCRs, and Article 49 derogations) apply directly and uniformly to Austrian-established controllers and processors, with the DSB as competent enforcement authority.observed
  2. ProbableEUR-Lex — European Commission adequacy decisions under GDPR Article 45 apply automatically across all EU Member States including Austria without need for separate national implementation.observed
  3. ProbableEUR-Lex — Standard Contractual Clauses and Binding Corporate Rules under GDPR Article 46 are directly available transfer mechanisms for Austrian controllers/processors, with BCR approvals proceeding through EDPB cooperation involving the DSB where Austria is a concerned authority.observed
  4. ProbableEUR-Lex — Following the CJEU's Schrems II judgment, EDPB Recommendations 01/2020 on supplementary measures establish an EU-wide expectation—including for Austrian data exporters—that transfer impact assessments be conducted before relying on SCCs to third countries lacking adequacy.observed

#

Two of seven sub-modules (telecoms/ePrivacy, employment) are evidenced; five require further primary-source escalation.

Primary frameworkTKG 2021 (Telecommunications Act); Arbeitsverfassungsgesetz (ArbVG); GlBG; GDPR/DSG
Traffic-light rationale — AmberTwo of seven sub-modules (telecoms/ePrivacy, employment) are evidenced; five require further primary-source escalation.

Sub-modules (7)

Financial Sector OverlayRed

Not independently confirmed in this pass.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , B, a, n, k, w, e, s, e, n, g, e, s, e, t, z, , b, a, n, k, i, n, g, , s, e, c, r, e, c, y, , G, D, P, R, , i, n, t, e, r, p, l, a, y, , D, S, B.

Health Sector OverlayRed

Not independently confirmed in this pass.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , h, e, a, l, t, h, , d, a, t, a, , G, D, P, R, , s, e, c, t, o, r, a, l, , o, v, e, r, l, a, y, , G, e, s, u, n, d, h, e, i, t, s, t, e, l, e, m, a, t, i, k, g, e, s, e, t, z.

Telecoms And EprivacyGreen

Austria implements ePrivacy Directive obligations, including electronic-marketing consent, via the Telecommunications Act 2021 (TKG 2021) alongside GDPR and the E-Commerce Act.

Claims (1):

  • In addition to the ePrivacy Directive and GDPR, Austria applies the Telecommunications Act 2021 (TKG 2021) and the E-Commerce Act to govern electronic communications marketing including SMS/MMS marketing.

Employment DataGreen

Austrian employment data processing sits at the intersection of GDPR/DSG with the ArbVG (works-council co-determination for employee-monitoring systems) and the GlBG (equal treatment).

Claims (1):

  • Austrian employee data protection compliance is governed by the interaction of GDPR/DSG with the Labour Constitutional Act (Arbeitsverfassungsgesetz, ArbVG) and the Equal Treatment Act (GlBG), with works-council consent frequently required for employee-monitoring measures.

Credit And ScoringRed

Not independently confirmed in this pass.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , c, r, e, d, i, t, , s, c, o, r, i, n, g, , G, D, P, R, , s, e, c, t, o, r, a, l, , r, u, l, e, s, , D, S, B.

EducationRed

Not independently confirmed in this pass.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , e, d, u, c, a, t, i, o, n, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , o, v, e, r, l, a, y, , D, S, B.

InsuranceRed

Not independently confirmed in this pass.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , i, n, s, u, r, a, n, c, e, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , o, v, e, r, l, a, y, , V, A, G, , D, S, B.

Category narrative51 words

Austrian sector-specific overlays interacting with GDPR/DSG were only partly confirmed in this research pass. Telecoms/ePrivacy (TKG 2021) and employment (ArbVG works-council co-determination, GlBG) overlays are documented; financial-sector banking-secrecy interplay (Bankwesengesetz), health-sector overlay, credit-scoring, education-sector, and insurance-sector specific DP rules were not independently confirmed and are flagged with absent_field_provenance rather than fabricated.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ProbableDataGuidance — In addition to the ePrivacy Directive and GDPR, Austria applies the Telecommunications Act 2021 (TKG 2021) and the E-Commerce Act to govern electronic communications marketing including SMS/MMS marketing.observed
  2. ProbableDataGuidance — Austrian employee data protection compliance is governed by the interaction of GDPR/DSG with the Labour Constitutional Act (Arbeitsverfassungsgesetz, ArbVG) and the Equal Treatment Act (GlBG), with works-council consent frequently required for employee-monitoring measures.observed

#

Cookie/tracker and direct-marketing sub-modules are evidenced; opt-out-signal, clean-room, and cross-context-advertising sub-modules do not map cleanly onto the EU consent-based model and were not independently confirmed as distinct Austrian constructs.

Primary frameworkTKG 2021 (implementing ePrivacy Directive Art 5(3)); GDPR
Traffic-light rationale — AmberCookie/tracker and direct-marketing sub-modules are evidenced; opt-out-signal, clean-room, and cross-context-advertising sub-modules do not map cleanly onto the EU consent-based model and were not independently confirmed as distinct Austrian constructs.

Sub-modules (6)

Cookies And TrackersGreen

Cookie/tracker consent in Austria is governed by TKG 2021 provisions implementing ePrivacy Directive Article 5(3), applied alongside GDPR consent standards.

Claims (1):

  • Storage of and access to information on end-user devices (cookies and similar trackers) in Austria requires consent under TKG 2021 provisions implementing Article 5(3) of the ePrivacy Directive, applied alongside GDPR consent standards where personal data is processed.

Dark PatternsAmber

EDPB Guidelines on dark patterns in social media interfaces apply EU-wide, including to Austrian controllers, though no Austria-specific dark-pattern statute was identified.

Claims (1):

  • EDPB guidance on dark patterns in social media platform interfaces applies to Austrian-established controllers as part of the GDPR consent-validity and fair-processing framework, absent a distinct Austrian statutory dark-pattern prohibition.

Opt Out SignalsRed

No Austria-specific Global Privacy Control/DAA opt-out-signal recognition statute was identified; this is not a native construct of the EU consent-based model.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , G, l, o, b, a, l, , P, r, i, v, a, c, y, , C, o, n, t, r, o, l, , o, p, t, -, o, u, t, , s, i, g, n, a, l, , r, e, c, o, g, n, i, t, i, o, n, , l, a, w.

Clean Rooms And DcrRed

No Austria-specific clean-room/data-collaboration-room regulation was identified.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , d, a, t, a, , c, l, e, a, n, , r, o, o, m, , r, e, g, u, l, a, t, i, o, n, , D, S, B, , g, u, i, d, a, n, c, e.

Cross Context AdvertisingAmber

The CPRA 'sale'/'share' cross-context-advertising construct is a US-state concept without a direct Austrian/EU equivalent; Austria instead relies on GDPR consent and legitimate-interest balancing for behavioural advertising.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , c, r, o, s, s, -, c, o, n, t, e, x, t, , a, d, v, e, r, t, i, s, i, n, g, , e, q, u, i, v, a, l, e, n, t, , c, o, n, s, t, r, u, c, t.

Direct MarketingGreen

Direct electronic marketing requires prior opt-in consent under TKG 2021/E-Commerce Act, subject to a narrow existing-customer soft opt-in exception.

Claims (1):

  • Direct electronic marketing communications (including SMS/MMS) in Austria require prior consent under the TKG 2021 and E-Commerce Act, mirroring the ePrivacy Directive's Article 13 soft opt-in exception for existing customer relationships.
Category narrative52 words

Austria's cookie/tracker and direct-marketing consent regime derives from the ePrivacy Directive as implemented via TKG 2021, layered with GDPR consent standards; US-style constructs (Global Privacy Control opt-out signals, CPRA-style cross-context advertising, clean rooms) are not native to the Austrian/EU framework and are addressed instead through consent-based ePrivacy/GDPR mechanisms and EDPB dark-pattern guidance.

Periodic update · new data 2026-09-28

AdTech & Commercial Privacy

The DSB is understood to hold a strict interpretive position on analytics cookies: that they cannot in any case be considered technically necessary for the operation of a website, meaning opt-in consent is required for their use regardless of the specific analytics purpose claimed. This is an Uncertain-confidence finding, sourced from a single T4 vendor commentary this cycle, and it has not been independently corroborated against a DSB decision or guidance document with a specific citation.

This Austrian position stands in some tension with the European Commission's proposed Digital Omnibus. Reports suggest that if the Digital Omnibus is adopted as a directly-applicable EU Regulation, it would create an EU-level cookie-consent exemption that would override Austria's stricter national position without requiring national transposition - a structurally significant possibility given the direct-applicability mechanism involved. However, adoption of the Digital Omnibus in this form is considered unlikely before mid-2027, meaning any such override remains a multi-year prospect rather than a near-term one.

The practical consequence for Austrian-facing commercial websites and adtech operators today is that the DSB's strict opt-in position remains the operative standard; no relaxation has occurred and none is imminent this cycle.

Outlook

The Digital Omnibus's legislative progress - and specifically whether it retains the cookie-consent exemption in a form that would apply directly to Austria without transposition - is the structural item to watch over the coming one to two years, with adoption considered unlikely before mid-2027. In the interim, the DSB's strict opt-in position for analytics cookies remains the binding practical standard for Austrian-facing operators.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ProbableDataGuidance — Storage of and access to information on end-user devices (cookies and similar trackers) in Austria requires consent under TKG 2021 provisions implementing Article 5(3) of the ePrivacy Directive, applied alongside GDPR consent standards where personal data is processed.observed
  2. UncertainEDPB — EDPB guidance on dark patterns in social media platform interfaces applies to Austrian-established controllers as part of the GDPR consent-validity and fair-processing framework, absent a distinct Austrian statutory dark-pattern prohibition.observed
  3. ProbableDataGuidance — Direct electronic marketing communications (including SMS/MMS) in Austria require prior consent under the TKG 2021 and E-Commerce Act, mirroring the ePrivacy Directive's Article 13 soft opt-in exception for existing customer relationships.observed

#

Profiling/ADM and state-surveillance carve-out sub-modules are GDPR/CJEU-evidenced (green); AI-risk-assessment sub-module is evidenced but time-sensitive/in-transition (amber); biometric and genetic sub-modules lack confirmed Austria-specific overlay (red-leaning amber).

Primary frameworkGDPR Art 22; EU AI Act (Regulation (EU) 2024/1689)
Traffic-light rationale — AmberProfiling/ADM and state-surveillance carve-out sub-modules are GDPR/CJEU-evidenced (green); AI-risk-assessment sub-module is evidenced but time-sensitive/in-transition (amber); biometric and genetic sub-modules lack confirmed Austria-specific overlay (red-leaning amber).

Sub-modules (6)

Profiling RestrictionsGreen

GDPR Art 22 restrictions on solely automated decision-making, including profiling with legal/similarly significant effects, apply directly in Austria.

Claims (1):

  • GDPR Article 22 restricts decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect a data subject, applying directly to Austrian controllers.

Automated Decision Making TransparencyGreen

GDPR Arts 13-15/22 transparency and explanation rights for ADM apply directly.

Claims (1):

  • GDPR Articles 13-15 require controllers to provide meaningful information about the logic, significance, and envisaged consequences of automated decision-making, applying directly in Austria.

Ai Risk AssessmentsAmber

Austria is subject to the EU AI Act's competent-authority designation deadline (2 Aug 2025) and Annex III high-risk obligations (applicable from 2 Aug 2026); designation and enforcement-readiness remain in progress bloc-wide as of mid-2026.

Claims (2):

  • Under the EU AI Act, all EU Member States, including Austria, were required to designate or establish national competent authorities (market surveillance and notifying authorities) by 2 August 2025.
  • As of the European Commission's 2026 implementation report, enforcement rules for the AI Act's prohibited-practices chapter apply from 2 August 2026 and national competent authorities across Member States, including Austria, are still in the process of being designated.

Biometric RegimeAmber

GDPR Art 9 special-category rules govern biometric data for unique identification; a distinct Austrian biometric/facial-recognition statute was not independently confirmed.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , f, a, c, i, a, l, , r, e, c, o, g, n, i, t, i, o, n, , b, i, o, m, e, t, r, i, c, , d, a, t, a, , s, t, a, t, u, t, e.

Genetic DataAmber

GDPR Art 9 governs genetic data as a special category; a distinct Austrian Gene Technology Act overlay was not independently confirmed in this pass.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , G, e, n, t, e, c, h, n, i, k, g, e, s, e, t, z, , g, e, n, e, t, i, c, , d, a, t, a, , G, D, P, R, , o, v, e, r, l, a, y.

State Surveillance CarveoutsGreen

CJEU Case C-33/22 delineates the national-security exemption from GDPR/DSB competence for certain parliamentary-inquiry processing.

Claims (1):

  • The CJEU held that activities of a committee of inquiry set up by a Member State parliament concerning national security may fall outside GDPR's material scope under Article 2(2)(a) read with Article 4(2) TEU, while supervisory-authority competence to assess that exemption remains subject to CJEU-defined limits under Articles 51 and 55 GDPR.
Category narrative82 words

GDPR Article 22 profiling/ADM restrictions apply directly in Austria. The EU AI Act layers additional risk-based obligations, with Member States (including Austria) required to designate national competent authorities by 2 August 2025 and high-risk obligations under Annex III applying from 2 August 2026; the European Commission has noted that competent-authority designations across Member States remain in progress. Austria-specific biometric and genetic-data overlay statutes beyond GDPR Article 9 were not independently confirmed. The CJEU's Case C-33/22 delineates a national-security carve-out from DSB competence.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ProbableEUR-Lex — GDPR Article 22 restricts decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect a data subject, applying directly to Austrian controllers.observed
  2. ProbableEUR-Lex — GDPR Articles 13-15 require controllers to provide meaningful information about the logic, significance, and envisaged consequences of automated decision-making, applying directly in Austria.observed
  3. ProbableIAPP — Under the EU AI Act, all EU Member States, including Austria, were required to designate or establish national competent authorities (market surveillance and notifying authorities) by 2 August 2025.observed
  4. ProbableEUR-Lex — As of the European Commission's 2026 implementation report, enforcement rules for the AI Act's prohibited-practices chapter apply from 2 August 2026 and national competent authorities across Member States, including Austria, are still in the process of being designated.observed
  5. ProbableEUR-Lex — The CJEU held that activities of a committee of inquiry set up by a Member State parliament concerning national security may fall outside GDPR's material scope under Article 2(2)(a) read with Article 4(2) TEU, while supervisory-authority competence to assess that exemption remains subject to CJEU-defined limits under Articles 51 and 55 GDPR.observed

#

The EU-level Article 8 framework is confirmed, but the Austria-specific numerical age-of-consent threshold and several sub-modules were not independently verified in this pass, warranting escalation to primary source (RIS/DSG text) before publication reliance.

Primary frameworkGDPR Art 8; DSG (national age-of-consent implementation — threshold unconfirmed this pass)
Traffic-light rationale — AmberThe EU-level Article 8 framework is confirmed, but the Austria-specific numerical age-of-consent threshold and several sub-modules were not independently verified in this pass, warranting escalation to primary source (RIS/DSG text) before publication reliance.

Sub-modules (5)

Age VerificationAmber

GDPR Art 8(2) requires reasonable efforts to verify parental consent for information-society-service processing of children's data; applies directly in Austria.

Claims (1):

  • GDPR Article 8(2) requires controllers to make reasonable efforts to verify that consent for processing a child's data in connection with an information society service is given or authorised by the holder of parental responsibility, taking into account available technology; this applies directly in Austria.

Minor Profiling BansAmber

No Austria-specific statutory ban on profiling of minors beyond general GDPR children protections and EDPB Age Assurance guidance was identified.

Claims (1):

  • EDPB Statement 1/2025 on Age Assurance emphasises that age-assurance mechanisms should not enable excess profiling of individuals, particularly children, applying as EU-wide guidance relevant to Austrian controllers absent a distinct national minor-profiling-ban statute.

Education SettingsRed

Not independently confirmed in this pass.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , e, d, u, c, a, t, i, o, n, -, s, e, c, t, o, r, , c, h, i, l, d, r, e, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, p, e, c, i, f, i, c, , r, u, l, e, s.

Dependent AdultsRed

Not independently confirmed in this pass.

Absence provenance: unavailable. Searched: A, u, s, t, r, i, a, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, s, , i, n, c, a, p, a, c, i, t, a, t, e, d, , p, e, r, s, o, n, s, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, p, e, c, i, f, i, c, , r, u, l, e, s.

Category narrative74 words

GDPR Article 8 establishes the EU digital age-of-consent framework (default 16, Member States may lower to no less than 13); the precise national threshold adopted under the Austrian DSG could not be independently confirmed via primary source in this research pass and is flagged as an open question requiring escalation. EDPB Statement 1/2025 on Age Assurance applies EU-wide including Austria. Austria-specific minor-profiling-ban, education-setting, and dependent-adult statutes beyond GDPR general protections were not independently confirmed.

Sources and claims (3)
  1. ProbableEUR-Lex — GDPR Article 8(2) requires controllers to make reasonable efforts to verify that consent for processing a child's data in connection with an information society service is given or authorised by the holder of parental responsibility, taking into account available technology; this applies directly in Austria.observed
  2. UncertainEUR-Lex — GDPR Article 8(1) sets a default digital age-of-consent of 16 for information-society-service processing based on a child's own consent, with Member States permitted to lower that threshold by national law to no less than 13; the specific figure adopted under Austrian law was not independently confirmed via primary source in this research pass.observed
  3. ProbableEDPB — EDPB Statement 1/2025 on Age Assurance emphasises that age-assurance mechanisms should not enable excess profiling of individuals, particularly children, applying as EU-wide guidance relevant to Austrian controllers absent a distinct national minor-profiling-ban statute.observed

#

Core enforcement powers, penalty ceilings, and a significant recent CJEU judgment are well-evidenced (green-leaning); current regulator funding/capacity and collective-redress implementing-act specifics were not independently confirmed this pass (amber).

Primary frameworkGDPR Arts 58, 77-84; DSG §24 (complaints procedure)
Traffic-light rationale — AmberCore enforcement powers, penalty ceilings, and a significant recent CJEU judgment are well-evidenced (green-leaning); current regulator funding/capacity and collective-redress implementing-act specifics were not independently confirmed this pass (amber).

Sub-modules (6)

Regulator Powers And PenaltiesGreen

GDPR Art 58 investigative/corrective powers and Art 83 fines up to EUR 20m/4% global turnover apply directly to the DSB.

Claims (1):

  • GDPR Recital 129 and Article 58 confer on supervisory authorities including the DSB investigative, corrective, authorisation and advisory powers, including the power to impose a temporary or definitive limitation or ban on processing, alongside Article 83 fines of up to EUR 20 million or 4% of global annual turnover.

Enforcement Activity IndexGreen

The DSB's highest-profile fine to date is the EUR 18 million Österreichische Post AG decision.

Claims (1):

  • The DSB imposed an administrative fine of EUR 18 million on Österreichische Post AG for unlawfully processing data on customers' presumed political affinity and for further processing package-frequency and relocation-frequency data for direct-marketing purposes, with the fine subject to challenge before the Federal Administrative Court and thus not final upon issuance.

Regulator Funding And CapacityAmber

Early post-GDPR reporting indicated a substantial pending caseload; current (2026) staffing/funding figures were not independently confirmed this pass.

Absence provenance: unavailable. Searched: D, S, B, , c, u, r, r, e, n, t, , b, u, d, g, e, t, , h, e, a, d, c, o, u, n, t, , 2, 0, 2, 6.

Claims (1):

  • Early post-GDPR reporting indicated the DSB had at least 115 fine proceedings pending and had initiated 58 ex officio investigations shortly after its first GDPR fine, though current (2026) staffing and funding levels were not independently confirmed in this research pass.

Collective Redress And Class ActionsAmber

GDPR Article 80 representative-action mechanism applies; Austria-specific implementing details of the EU Representative Actions Directive were not independently confirmed this pass.

Claims (1):

  • GDPR Article 80 permits data subjects to mandate a not-for-profit body to exercise rights and lodge complaints on their behalf, applying directly in Austria; Austria-specific implementing detail of the EU Representative Actions Directive for consumer collective redress was not independently confirmed this pass.

Private Right Of ActionAmber

GDPR Article 82 provides a directly enforceable compensation right; a pending CJEU reference (AG Opinion, Case C-185/25) examines Austrian public-liability channelling rules against Article 82.

Claims (1):

  • An Advocate General Opinion in a pending Austrian CJEU reference (Case C-185/25) proposes that Article 82 GDPR does not preclude national rules under which persons acting on behalf of certain Austrian public-law entities cannot be held personally liable for data-subject damage, provided those rules identify the entity against which compensation claims may be brought.

Recent Developments 180DGreen

Within the last 180 days, the CJEU delivered judgment in Case C-414/24 (18 June 2026) on DSB complaint-rejection practice, and the EDPB adopted Opinion 18/2024 (5 February 2026) on an Austrian certification-body draft decision.

Claims (2):

  • On 18 June 2026, the CJEU (First Chamber) delivered judgment in Case C-414/24, Datenschutzbehörde and Dr G S v Bundesministerin für Justiz and D GmbH, interpreting Articles 77 and 79 GDPR in relation to the DSB's rejection of complaints where parallel judicial proceedings on the same subject-matter are pending.
  • On 5 February 2026, the EDPB adopted Opinion 18/2024 on the draft decision of the Austrian supervisory authority regarding certification criteria for a certification-monitoring body (DSGVO-zt GmbH) under the Article 64 consistency mechanism.
Category narrative116 words

The DSB exercises the full suite of GDPR Article 58 investigative and corrective powers, including Article 83 administrative fines up to EUR 20 million or 4% of global annual turnover; its highest-profile action to date is the 2019 EUR 18 million fine against Österreichische Post AG (later challenged before the Federal Administrative Court). Early post-GDPR reporting indicated a substantial pending caseload, though current staffing/funding figures were not independently confirmed. Article 82 private-right-of-action compensation claims are directly enforceable, with a pending CJEU reference (AG Opinion, Case C-185/25) addressing Austrian public-liability channelling rules. A significant recent development is the CJEU's 18 June 2026 judgment in Case C-414/24 on the DSB's complaint-rejection practice where parallel judicial proceedings are pending.

Periodic update · new data 2026-09-28

Enforcement & Redress

Austria's enforcement-and-redress picture this cycle combines a documented low conversion rate from complaint to sanction with a contracting regulatory budget. The DSB is understood to have conducted 4,030 proceedings in 2023 - comprising 2,389 national proceedings, 876 cross-border proceedings, and 765 proceedings initiated ex officio - of which only 55 resulted in fines, a 1.36 percent rate that noyb founder Max Schrems has publicly criticised. This is a Probable finding sourced from noyb, a T2 source, and it is the clearest quantitative enforcement-capacity signal available for Austria this cycle.

That enforcement-rate finding sits alongside the DSB's 2026 budget of approximately EUR 5.9 million, down from EUR 6.1 million in 2025 - a real-terms contraction for the sole national supervisory authority under Article 51 GDPR, which operates with approximately 70 staff. One 2026 commentary, sourced from a single uncorroborated T4 source, reports that this budget constraint has forced the DSB to stop proactive investigations entirely; this claim is presented here as reported rather than confirmed, given its single-source, lower-tier basis.

The DSB's enforcement powers themselves remain broad on paper: it may order cessation of unlawful processing and impose GDPR fines of up to EUR 20 million or 4 percent of global turnover, plus DSG-specific fines of up to EUR 50,000 for CCTV and data-secrecy violations. Separately, noyb has held status as a Qualified Entity under the EU Representative Actions Directive since December 2024, enabling it to bring EU-wide representative proceedings on behalf of data subjects - a redress channel operating independently of DSB capacity constraints. Most individual complaints reach the DSB via the Article 77 GDPR direct-complaint mechanism, which is reported to drive the majority of the authority's enforcement activity.

The ongoing Österreichische Post fine litigation illustrates both the DSB's enforcement reach and the current uncertainty in its outcomes: the Constitutional Court declined the underlying complaint on 9 December 2025, but the settled fine quantum remains disputed, with one account citing a 24 June 2026 Administrative High Court figure of EUR 13 million plus EUR 100,000 in costs, against an earlier, still-cited Federal Administrative Court figure of EUR 16 million from December 2024.

Outlook

Whether the DSB's budget trajectory stabilises, and whether the reported halt to proactive investigations is confirmed by further reporting, are the structural enforcement-capacity items to track. On the specific Österreichische Post matter, resolution of the disputed quantum figure is the concrete item outstanding. Separately, Regulation (EU) 2025/2518, introducing additional procedural rules for cross-border GDPR enforcement cooperation, is reported to become applicable around April 2027, which may affect how DSB's cross-border caseload (876 proceedings in 2023) is processed going forward.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ProbableEUR-Lex — GDPR Recital 129 and Article 58 confer on supervisory authorities including the DSB investigative, corrective, authorisation and advisory powers, including the power to impose a temporary or definitive limitation or ban on processing, alongside Article 83 fines of up to EUR 20 million or 4% of global annual turnover.observed
  2. ProbableEDPB — The DSB imposed an administrative fine of EUR 18 million on Österreichische Post AG for unlawfully processing data on customers' presumed political affinity and for further processing package-frequency and relocation-frequency data for direct-marketing purposes, with the fine subject to challenge before the Federal Administrative Court and thus not final upon issuance.observed
  3. UncertainIAPP — Early post-GDPR reporting indicated the DSB had at least 115 fine proceedings pending and had initiated 58 ex officio investigations shortly after its first GDPR fine, though current (2026) staffing and funding levels were not independently confirmed in this research pass.observed
  4. ProbableEUR-Lex — GDPR Article 80 permits data subjects to mandate a not-for-profit body to exercise rights and lodge complaints on their behalf, applying directly in Austria; Austria-specific implementing detail of the EU Representative Actions Directive for consumer collective redress was not independently confirmed this pass.observed
  5. UncertainEUR-Lex — An Advocate General Opinion in a pending Austrian CJEU reference (Case C-185/25) proposes that Article 82 GDPR does not preclude national rules under which persons acting on behalf of certain Austrian public-law entities cannot be held personally liable for data-subject damage, provided those rules identify the entity against which compensation claims may be brought.observed
  6. ProbableEUR-Lex — On 18 June 2026, the CJEU (First Chamber) delivered judgment in Case C-414/24, Datenschutzbehörde and Dr G S v Bundesministerin für Justiz and D GmbH, interpreting Articles 77 and 79 GDPR in relation to the DSB's rejection of complaints where parallel judicial proceedings on the same subject-matter are pending.observed
  7. ProbableEDPB — On 5 February 2026, the EDPB adopted Opinion 18/2024 on the draft decision of the Austrian supervisory authority regarding certification criteria for a certification-monitoring body (DSGVO-zt GmbH) under the Article 64 consistency mechanism.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct76.47
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Austria
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s) (44 category placement(s)), 28 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 8Children & Vulnerable Groupsparental consent
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy granted
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Strong T1 (CJEU/EUR-Lex, GDPR text, DSB/EDPB decisions) coverage for regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, cross_border_and_adequacy, and enforcement_and_redress. controller_processor_duties relies primarily on direct GDPR-text (T1/T2) restatement absent Austria-specific DPIA-list/retention-statute confirmation. sectoral_watch and adtech_and_commercial_privacy modules are partially populated: telecoms/ePrivacy and employment sub-modules rest on T3 (DataGuidance) secondary notes; financial, health, credit, education, and insurance sub-modules carry explicit absent_field_provenance rather than fabricated claims. algorithmic_biometric_and_surveillance_governance combines T1 CJEU/GDPR content with T1/T4 AI Act implementation-status sources; biometric/genetic sub-modules are unconfirmed. children_and_vulnerable_groups carries an explicit unresolved item: the precise Austrian national age-of-consent figure under GDPR Article 8 could not be confirmed via primary source (RIS/DSG text) in this pass and is marked Uncertain pending escalation.

Unresolved questions (6):

  • What is the exact national age-of-consent threshold (13-16) adopted under the Austrian DSG for GDPR Article 8 information-society-service consent?
  • Does Austria's Bankwesengesetz (banking secrecy) create a material overlay or conflict with GDPR/DSG obligations for financial-sector controllers?
  • Is there an Austria-specific DPIA blacklist/whitelist issued by the DSB under Article 35(4) GDPR?
  • What are current (2026) DSB staffing, budget, and case-backlog figures?
  • Has Austria enacted specific implementing legislation for the EU Representative Actions Directive relevant to GDPR collective redress, beyond the general Article 80 mechanism?
  • Has Austria formally designated its EU AI Act national competent authority/authorities, and is the DSB among them?

Escalate to primary-source review: yes