Skip to content

Evidence request lists

Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)

Evidence request list. 14 controls, 14 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Part 1: Constitutional Provision - Fundamental Right to Data Protection

AT-DSG-1
Section 1 - Fundamental right to data protection

Everyone has a constitutional right to secrecy of their personal data, in particular regarding private and family life, insofar as a legitimate interest exists (DSG s1).

Artefacts an auditor will ask for
  • Recognition of the constitutional right to data secrecy
  • Policies upholding s1 protections
Where this commonly fails
  • Right to data secrecy not respected
  • No basis for interference with the right

Part 2: GDPR Implementation and Supplementary Provisions

AT-DSG-2
Section 2 - Scope and application

The DSG supplements and gives effect to the GDPR in Austria, defining the national scope and implementing provisions (DSG s2, s4).

Artefacts an auditor will ask for
  • Determination that the DSG/GDPR applies to the processing
  • Mapping of national implementing provisions
Where this commonly fails
  • Scope not assessed
  • National derogations not applied
AT-DSG-3
Section 4(4) - Age of consent for children

A child's consent to information society services is valid from the age of 14 in Austria (DSG s4(4)).

Artefacts an auditor will ask for
  • Age-verification/consent controls for under-14s
  • Parental consent where required
Where this commonly fails
  • Children under 14 consented without parental authorisation
  • No age gate
AT-DSG-4
Section 6 - Data secrecy (Datengeheimnis)

Controllers, processors and their employees are bound to maintain data secrecy, only transmitting personal data on lawful instruction, with the obligation persisting after the employment relationship ends (DSG s6).

Artefacts an auditor will ask for
  • Data-secrecy undertakings by personnel
  • Instruction-based transmission controls
  • Confidentiality obligations in contracts surviving termination
Where this commonly fails
  • No data-secrecy undertakings
  • Personnel transmit data without lawful instruction
AT-DSG-5
Section 9 - Media and journalistic exemption

Processing of personal data by media undertakings for journalistic purposes is subject to the media privilege, exempting much of the GDPR/DSG (DSG s9).

Artefacts an auditor will ask for
  • Determination of journalistic-purpose exemption
  • Safeguards applied within the media privilege
Where this commonly fails
  • Media privilege claimed without journalistic purpose
  • No safeguards for journalistic processing
AT-DSG-6
Sections 12-13 - Image processing (video surveillance/CCTV)

Image processing (video surveillance) is permitted only on the conditions in DSG ss12-13, including admissibility grounds, transparency/marking and deletion obligations.

Artefacts an auditor will ask for
  • Lawful basis for CCTV per s12
  • Signage/transparency of surveillance per s13
  • Retention and deletion of footage
Where this commonly fails
  • CCTV without lawful basis
  • No signage
  • Footage retained indefinitely

Part 3: Data Protection Authority

AT-DSG-7
Section 18 - Establishment of the Data Protection Authority

The Datenschutzbehörde (DSB) is established as Austria's independent supervisory authority (DSG s18).

Artefacts an auditor will ask for
  • Recognition of the DSB as supervisory authority
  • Cooperation arrangements with the DSB
Where this commonly fails
  • DSB authority not recognised
  • No process to engage the DSB
AT-DSG-8
Section 22 - Functions and powers of the DPA

The DSB exercises investigative, corrective, authorisation and advisory powers under DSG s22 and the GDPR.

Artefacts an auditor will ask for
  • Process to respond to DSB investigations/orders
  • Records of interactions with the DSB
Where this commonly fails
  • DSB orders not actioned
  • No cooperation with investigations
AT-DSG-9
Section 24 - Complaint procedures

Data subjects may lodge a complaint with the DSB; controllers must cooperate with the resulting procedure (DSG s24).

Artefacts an auditor will ask for
  • Process to handle DSB complaint proceedings
  • Records of complaints and responses
Where this commonly fails
  • Complaints to the DSB not handled
  • No cooperation in complaint procedures

Part 4: Remedies and Penalties

AT-DSG-10
Section 29 - Liability and right to compensation / civil jurisdiction

Data subjects have a right to compensation for damage from unlawful processing, enforced through the civil courts (DSG s29; jurisdiction s28).

Artefacts an auditor will ask for
  • Process for handling compensation claims
  • Records of civil proceedings and outcomes
Where this commonly fails
  • Compensation claims not addressed
  • No process for civil liability
AT-DSG-11
Sections 42-45 - Data subject rights (law enforcement)

Data subject rights (information, access, rectification, erasure, restriction) in the law-enforcement context are implemented per DSG ss42-45.

Artefacts an auditor will ask for
  • Procedures for access/rectification/erasure requests
  • Records of requests and responses
  • Lawful restrictions where applicable
Where this commonly fails
  • Requests not actioned
  • No records of rights handling
AT-DSG-12
Section 62 - Administrative penalties

Administrative penalties apply for breaches of the DSG and GDPR as set out in DSG s62.

Artefacts an auditor will ask for
  • Compliance monitoring against penalty provisions
  • Remediation of identified breaches
Where this commonly fails
  • Repeated breaches
  • No monitoring of penalty exposure

Part 5: Implementation of the Law Enforcement Directive

AT-DSG-13
Section 36 - Scope of law enforcement processing

Part 3 of the DSG (ss36 onward) implements the Law Enforcement Directive (EU) 2016/680 for processing by competent authorities for law-enforcement purposes.

Artefacts an auditor will ask for
  • Determination of law-enforcement processing scope
  • Application of the LE-specific regime
Where this commonly fails
  • LE processing treated under GDPR only
  • Scope of competent-authority processing undefined
AT-DSG-14
Section 38 - Lawfulness of law enforcement processing

Processing for law-enforcement purposes is lawful only where necessary for a competent authority's task and based on law (DSG s38), with the safeguards of ss42-61.

Artefacts an auditor will ask for
  • Lawful basis and necessity for LE processing
  • Safeguards (logging, DPIA, security) per ss50-54
Where this commonly fails
  • LE processing without lawful basis
  • Safeguards not applied
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) framework page.