Law / Austria

GDPR Articles 12-21 and DSG Section 4, Data Subject Rights in Austria

Regulation (EU) 2016/679, Arts. 12-21; Datenschutzgesetz (DSG) § 4

In force since .

A data subject rights rule binding public and private bodies.

As of .

What it requires

  • Honor a person's request to access, rectify, erase, restrict, port, or object to processing of their personal data in Austria within one month of receipt.
  • You need not, as a rule, give a person in Austria access to their personal data under General Data Protection Regulation (GDPR) Article 15 where disclosing it would endanger a business or trade secret of yours or of a third party, under DSG Section 4(6).
  • If economic or technical reasons mean you can correct or erase a person's automated personal data in Austria only at set times, restrict its processing until then, with the effect of GDPR Article 18(2), under DSG Section 4(2).

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Under General Data Protection Regulation (GDPR) Articles 12 to 21, a person in Austria can ask a controller for access to their personal data and for its rectification, erasure, restriction or portability, or object to its processing, and the controller must answer within one month, a period it may extend by two further months for complex or numerous requests.

Section 4 of the Datenschutzgesetz adds two rules for these requests: access may, as a rule, be refused where disclosure would endanger a business or trade secret of the controller or of a third party (§ 4(6)), and where automated data can be corrected or erased only at set times for economic or technical reasons, their processing is restricted until then, with the effect of GDPR Article 18(2) (§ 4(2)).

When LexLint raises it

When your app profile says your app crawls the web, trains models, generates content with AI, deploys a chatbot or sends automated outreach.

Back to the example  ·  Lint your app