Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
Evidence request list. 14 controls, 14 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Part 1: Constitutional Provision - Fundamental Right to Data Protection
Everyone has a constitutional right to secrecy of their personal data, in particular regarding private and family life, insofar as a legitimate interest exists (DSG s1).
- Recognition of the constitutional right to data secrecy
- Policies upholding s1 protections
- Right to data secrecy not respected
- No basis for interference with the right
Part 2: GDPR Implementation and Supplementary Provisions
The DSG supplements and gives effect to the GDPR in Austria, defining the national scope and implementing provisions (DSG s2, s4).
- Determination that the DSG/GDPR applies to the processing
- Mapping of national implementing provisions
- Scope not assessed
- National derogations not applied
A child's consent to information society services is valid from the age of 14 in Austria (DSG s4(4)).
- Age-verification/consent controls for under-14s
- Parental consent where required
- Children under 14 consented without parental authorisation
- No age gate
Controllers, processors and their employees are bound to maintain data secrecy, only transmitting personal data on lawful instruction, with the obligation persisting after the employment relationship ends (DSG s6).
- Data-secrecy undertakings by personnel
- Instruction-based transmission controls
- Confidentiality obligations in contracts surviving termination
- No data-secrecy undertakings
- Personnel transmit data without lawful instruction
Processing of personal data by media undertakings for journalistic purposes is subject to the media privilege, exempting much of the GDPR/DSG (DSG s9).
- Determination of journalistic-purpose exemption
- Safeguards applied within the media privilege
- Media privilege claimed without journalistic purpose
- No safeguards for journalistic processing
Image processing (video surveillance) is permitted only on the conditions in DSG ss12-13, including admissibility grounds, transparency/marking and deletion obligations.
- Lawful basis for CCTV per s12
- Signage/transparency of surveillance per s13
- Retention and deletion of footage
- CCTV without lawful basis
- No signage
- Footage retained indefinitely
Part 3: Data Protection Authority
The Datenschutzbehörde (DSB) is established as Austria's independent supervisory authority (DSG s18).
- Recognition of the DSB as supervisory authority
- Cooperation arrangements with the DSB
- DSB authority not recognised
- No process to engage the DSB
The DSB exercises investigative, corrective, authorisation and advisory powers under DSG s22 and the GDPR.
- Process to respond to DSB investigations/orders
- Records of interactions with the DSB
- DSB orders not actioned
- No cooperation with investigations
Data subjects may lodge a complaint with the DSB; controllers must cooperate with the resulting procedure (DSG s24).
- Process to handle DSB complaint proceedings
- Records of complaints and responses
- Complaints to the DSB not handled
- No cooperation in complaint procedures
Part 4: Remedies and Penalties
Data subjects have a right to compensation for damage from unlawful processing, enforced through the civil courts (DSG s29; jurisdiction s28).
- Process for handling compensation claims
- Records of civil proceedings and outcomes
- Compensation claims not addressed
- No process for civil liability
Data subject rights (information, access, rectification, erasure, restriction) in the law-enforcement context are implemented per DSG ss42-45.
- Procedures for access/rectification/erasure requests
- Records of requests and responses
- Lawful restrictions where applicable
- Requests not actioned
- No records of rights handling
Administrative penalties apply for breaches of the DSG and GDPR as set out in DSG s62.
- Compliance monitoring against penalty provisions
- Remediation of identified breaches
- Repeated breaches
- No monitoring of penalty exposure
Part 5: Implementation of the Law Enforcement Directive
Part 3 of the DSG (ss36 onward) implements the Law Enforcement Directive (EU) 2016/680 for processing by competent authorities for law-enforcement purposes.
- Determination of law-enforcement processing scope
- Application of the LE-specific regime
- LE processing treated under GDPR only
- Scope of competent-authority processing undefined
Processing for law-enforcement purposes is lawful only where necessary for a competent authority's task and based on law (DSG s38), with the safeguards of ss42-61.
- Lawful basis and necessity for LE processing
- Safeguards (logging, DPIA, security) per ss50-54
- LE processing without lawful basis
- Safeguards not applied
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) framework page.