Datenschutzgesetz (DSG), Data Protection Act
Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999, as amended by BGBl. I Nr. 24/2018
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
A comprehensive regime rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Establish and document a lawful basis under General Data Protection Regulation (GDPR) Article 6 before processing any personal data of a person in Austria.
- Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, following GDPR Articles 24 to 28.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The General Data Protection Regulation (GDPR) applies directly in Austria, and the Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999 as amended by BGBl. I Nr. 24/2018, supplies domestic institutional and procedural provisions: the structure of the Datenschutzbehorde (DSB), criminal offenses for data misuse under DSG Section 63, and a media privilege under Article 9 DSG that the Constitutional Court held unconstitutional and that was re-regulated alongside Austria's new Freedom of Information Act from September 2025.
Lawful bases follow GDPR Article 6 unmodified, and controller and processor duties follow GDPR Articles 24 to 28 with no Austrian derogation identified.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
Austrian Federal Law Gazette (Rechtsinformationssystem, RIS), consolidated text
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.