Law / Austria

Austria

European Union law applies in Austria Austria is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Austria, described on this page below, applies here too.

18 of 21 named instruments researched to a stage, across all six areas of law we track: 15 in force, 2 enacted but not yet in force and 1 proposed. As of 14 September 2026.

When they take effect17 of 18 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 8 instruments (8 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 4 instruments (4 in force) 2023: 1 instrument (1 in force) 2024: 0 instruments 2025: 0 instruments 2026: 2 instruments (2 enacted but not yet in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 4
  4. Cybersecurity law 4
  5. Age gating law 1
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (228 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Austria and is not restated here as Austrian law; its Article 5, 50, and 53 duties are covered in the eu document.

Austria's own AI-specific instrument is a 2023 amendment to Section 207a of the Strafgesetzbuch (StGB), which criminalizes bildliches sexualbezogenes Kindesmissbrauchsmaterial (image-based sexual abuse material involving minors) and extends to a realistic depiction that, through alteration of an existing image or without using one at all, creates the impression of such abuse, reaching a wholly AI-generated or deepfake image on the same footing as a real photograph.

Austria has not enacted a standalone AI Act implementing statute.

The Servicestelle für Kunstliche Intelligenz (KI-Servicestelle), established within RTR-GmbH's telecommunications division by Section 194a of the Telekommunikationsgesetz 2021 (TKG 2021) and Section 17(8) of the KommAustria-Gesetz, provides public advisory and coordination services on the AI Act's regulatory framework and does not itself impose a duty on a developer or deployer; formal designation of Austria's AI Act Article 70 market-surveillance and notifying authorities is not carried out by that provision.

The Digital Services Act (DSA)-Begleitgesetz, BGBl. I Nr. 182/2023, separately designated KommAustria as Austria's Digital Services Coordinator for the EU Digital Services Act's own algorithmic-transparency duties on very large platforms, a different EU instrument from the AI Act. No Austria-specific case law construing an AI-transparency or output-labeling duty was located in the sources checked.

AI prohibited practices

StGB Section 207a(4)(4), Computer-Generated and Altered Child Sexual Abuse Material

StGB Sec. 207a(4)(4), BGBl. Nr. 60/1974 as amended by BGBl. I Nr. 135/2023Austrian Federal Law Gazette (Rechtsinformationssystem, RIS), consolidated text of the Strafgesetzbuch

In force since 1 December 2023. Binds public and private bodies.

What this law does

Section 207a(4) defines image-based sexual abuse material and sexual depictions of minors to include, at Z 4, any pictorial representation whose viewing creates the impression, whether through alteration of an image or without using one at all, that it is a representation of the kind described in Z 1 to 3: a realistic depiction of a sexual act involving a person under 14, or of an event that appears to be such an act, or the same acts involving a minor between 14 and 18.

This reaches a wholly AI-generated or synthetically altered image with no underlying real depiction, on the same footing as a real photograph, provided the image is realistic. Producing such an image, or offering, procuring, supplying, showing, or otherwise making it accessible to another, is an offense under Section 207a(1). Knowingly accessing one online is a separate offense under Section 207a(3a). Merely possessing or procuring one is punishable under Section 207a(3).

What it requires

Privacy law6 instruments, 6 in force

Research summary (75 words)

Austria's private-sector personal data regime is the General Data Protection Regulation (GDPR) as given domestic effect by the Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999 as amended by BGBl. I Nr. 24/2018. There is no standalone Austrian biometric-privacy statute; biometric identifiers are governed entirely through GDPR Article 9's special category regime, enforced by the Datenschutzbehorde (DSB).

Austria supplied one of the two leading CJEU rulings on Article 82 private compensation, C-300/21 Osterreichische Post, itself referred by the Austrian Supreme Court.

Breach notification

GDPR Articles 33-34, Breach Notification in Austria

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the Datenschutzbehorde without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Austria-specific derogation from this timeline or threshold was identified in the DSG.

What it requires

Comprehensive regime

Datenschutzgesetz (DSG), Data Protection Act

Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999, as amended by BGBl. I Nr. 24/2018Austrian Federal Law Gazette (Rechtsinformationssystem, RIS), consolidated text

In force since 25 May 2018. Binds public and private bodies.

What this law does

The General Data Protection Regulation (GDPR) applies directly in Austria, and the Datenschutzgesetz (DSG), BGBl. I Nr. 165/1999 as amended by BGBl. I Nr. 24/2018, supplies domestic institutional and procedural provisions: the structure of the Datenschutzbehorde (DSB), criminal offenses for data misuse under DSG Section 63, and a media privilege under Article 9 DSG that the Constitutional Court held unconstitutional and that was re-regulated alongside Austria's new Freedom of Information Act from September 2025.

Lawful bases follow GDPR Article 6 unmodified, and controller and processor duties follow GDPR Articles 24 to 28 with no Austrian derogation identified.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Austria

Regulation (EU) 2016/679, Arts. 44-49Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Transferring personal data of a person in Austria outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the highest Article 83(5) fine tier (up to EUR 20 million or 4 percent of global turnover). This is a real, structured condition on outbound transfer, not an absence of restriction. No Austria-specific derogation from this framework was identified.

What it requires

Data subject rights

GDPR Article 22 and DSG Sections 42-45, Automated Decision-Making in Austria

Regulation (EU) 2016/679, Art. 22; Datenschutzgesetz (DSG) §§42-45Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12 to 23 give a person in Austria rights of access, rectification, erasure, restriction, portability and objection, plus Article 22 rights against a decision based solely on automated processing that produces legal or similarly significant effects. DSG Sections 42 to 45 give Article 22 domestic procedural effect.

The Datenschutzbehorde's September 2025 finding that KSV1870's credit scoring was prohibited automated decision-making under Article 22 was overturned by the Verwaltungsgerichtshof (Supreme Administrative Court) on 11 June 2026, which held the scoring parameters were not personal data in that instance. This narrows the DSB's Article 22 theory in the credit-scoring context but leaves the underlying statutory right and DSB enforcement authority unchanged.

What it requires

Enforcement supervision

GDPR Article 82 and Datenschutzbehörde Enforcement in Austria

Regulation (EU) 2016/679, Arts. 82-83; Datenschutzgesetz (DSG) Art. 4Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

The Datenschutzbehorde (DSB) is Austria's supervisory authority, with General Data Protection Regulation (GDPR) Article 83 administrative fines of up to the greater of EUR 20 million or 4 percent of global turnover, plus DSG Section 63 criminal offenses for data secrecy violations.

Article 82 arms an individual with a direct private right of action for material or non-material damage, without a seriousness threshold, per the CJEU's first Article 82 ruling, C-300/21 UI v Osterreichische Post AG (4 May 2023), itself referred by the Austrian Supreme Court. Since 2 December 2024, noyb is a Qualified Entity under Austria's Qualifizierte-Einrichtungen-Gesetz, letting it bring collective Article 80(2) redress actions.

What it requires

Sensitive categories

GDPR Article 9, Special Categories of Personal Data Including Biometric Data, as Applied in Austria

Regulation (EU) 2016/679, Art. 9, as applied in AustriaOfficial Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Article 9(1) prohibits processing special categories of personal data, including biometric data processed to uniquely identify a person, unless a listed Article 9(2) exception applies, most often explicit consent. Austria adds no separate statutory biometric regime alongside General Data Protection Regulation (GDPR) Article 9. The Datenschutzbehorde found in 2021 that Clearview AI's scraped facial recognition database was unlawful under Austrian data protection law for processing biometric data without a lawful basis.

No Austria-specific guidance on voiceprint biometrics is identified; the GDPR baseline, that a voiceprint captured through specific technical processing for identification is special category data on the same footing as a faceprint, governs by default.

What it requires

Scraping law4 instruments, 4 in force

Research summary (206 words)

Austria has no scraping-specific statute; the applicable regime is assembled from general criminal, copyright, and unfair-competition law.

The Strafgesetzbuch (StGB) criminalizes overcoming a computer system's specific security measure to access protected data or cause harm (Section 118a), damaging or suppressing data (Section 126a), disrupting a system's functioning (Section 126b), and creating or trading tools built for those offenses (Section 126c), so a public, unauthenticated page carries no comparable statutory bar because these offenses turn on defeating a technical protection measure, not on mere access.

The Urheberrechtsgesetz (UrhG) gives a database's producer a sui generis right against extracting or re-utilizing a substantial part of a database that required substantial investment (Sections 76c to 76e), and creates a text-and-data-mining exception, unconditional for research organizations and cultural-heritage institutions and defeasible only by an express, machine-readable reservation for any other use (Section 42h).

The general unfair-commercial-practices clause of the Bundesgesetz gegen den unlauteren Wettbewerb (UWG), Section 1, reaches conduct in trade that damages a competitor, giving Austria a general_law_applies posture rather than a scraping-specific unfair-competition doctrine.

No reported Austrian judgment applying any of these provisions to a web-scraping fact pattern, and no Austria-specific authority on robots.txt's legal weight or on browsewrap versus clickwrap enforceability, was located in the sources checked.

Computer misuse

StGB Sections 118a and 126a to 126c, Computer-Misuse Offenses

StGB Sec. 118a, 126a-126c, BGBl. Nr. 60/1974 as amendedAustrian Federal Law Gazette (Rechtsinformationssystem, RIS), consolidated text of the Strafgesetzbuch

In force since 1 October 2002. Binds public and private bodies.

What this law does

Section 118a punishes anyone who gains access to a computer system, or part of one, by overcoming a specific security measure, with intent either to obtain personal data whose secrecy is protected or to cause harm through the accessed data or system; prosecution requires the victim's authorization. Section 126a punishes altering, deleting, rendering unusable, or suppressing data over which the offender lacks sole authority, where this damages another.

Section 126b punishes seriously disrupting a computer system's functioning by entering or transmitting data. Section 126c punishes creating, acquiring, distributing, or possessing a program, device, password, or access code built or adapted for committing these offenses, with intent that it be so used. None of the four turns on whether the targeted content was publicly viewable; each turns on overcoming a technical or legal barrier to access, or on the tool's built purpose.

What it requires

Copyright and text and data mining (TDM)

UrhG Section 42h, Text-and-Data-Mining Exception

UrhG Sec. 42h, BGBl. Nr. 111/1936 as amended by BGBl. I Nr. 244/2021Urheberrechtsgesetz (UrhG), JUSLINE Osterreich consolidated text

In force since 1 January 2022. Binds public and private bodies.

What this law does

Section 42h(1) to (5) lets a research organization, a cultural-heritage institution, or an individual researcher acting for one, reproduce a lawfully accessed work to mine text and data for scientific or artistic research, and store the reproduction as long as the research purpose justifies it; this exception cannot be contracted away and applies even where a for-profit undertaking participates in a public-private partnership with the research or heritage institution.

Section 42h(6) creates a separate, general exception letting any person reproduce a lawfully accessed work for their own text-and-data-mining, for any purpose, unless the rightsholder has expressly prohibited the reproduction through an adequately signaled reservation, in particular a machine-readable one for works made available online.

The dossier for this visit listed a distinct 'Section 42i' covering the general opt-out exception; no such section exists in the consolidated UrhG text read for this visit, and the general exception is Section 42h(6) itself.

What it requires

Database right

UrhG Sections 76c to 76e, Sui Generis Database Right

UrhG Sec. 76c-76e, BGBl. Nr. 111/1936Urheberrechtsgesetz (UrhG), JUSLINE Osterreich consolidated text

In force since 1 January 1998. Binds public and private bodies.

What this law does

A database whose compilation, verification, or presentation required a substantial investment is protected as such under Section 76c, independent of any copyright in its contents.

Section 76d gives the database's producer the exclusive right to reproduce, distribute, broadcast, publicly communicate, and make available the whole database or a substantial part of it, and treats the repeated and systematic extraction or re-utilization of insubstantial parts the same way where this conflicts with the database's normal exploitation or unreasonably prejudices the producer's legitimate interests.

Section 76e voids any contractual term by which a lawful user agrees not to extract or re-utilize insubstantial parts, to the extent that doing so neither conflicts with normal exploitation nor unreasonably prejudices the producer. The right lasts fifteen years from completion, or from publication if the database is published within that period.

What it requires

Unfair competition

UWG Section 1, General Unfair Commercial Practices Clause

UWG Sec. 1, BGBl. Nr. 448/1984Austrian Federal Law Gazette (Rechtsinformationssystem, RIS), consolidated text of the UWG

In force since 20 July 2022. Binds private bodies.

What this law does

Section 1 of the Bundesgesetz gegen den unlauteren Wettbewerb (UWG) lets an injured party seek an injunction, and damages where the defendant is at fault, against anyone who, in the course of trade, applies an unfair commercial practice or other unfair conduct capable of more than trivially affecting competition to the disadvantage of undertakings, or a commercial practice contrary to professional diligence that is likely to materially distort the economic behavior of the average consumer it reaches.

Austria has no scraping-specific unfair-competition or misappropriation doctrine; this general clause is the only unfair-competition authority identified, and no reported Austrian judgment applying it to unauthorized data extraction or web scraping was located in the sources checked.

What it requires

Cybersecurity law4 instruments, 2 in force, 2 enacted but not yet in force

Research summary (724 words)

Austria's NIS2 transposition is enacted but not yet in force, after an earlier attempt lapsed. A ministerial draft, the Netz- und Informationssystemsicherheitsgesetz 2024 (326/ME, XXVII. GP), completed public consultation on 1 May 2024 and was submitted to the Bundeskanzleramt on 3 May 2024, but did not advance to a government bill before that legislative period ended, so Austria missed Directive (EU) 2022/2555's own 17 October 2024 transposition deadline.

A new government bill (308 d.B., XXVIII. GP) became the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), BGBl. I Nr. 94/2025, promulgated 23 December 2025.

Under its own Section 51, the Act's substantive provisions (Sections 2 to 45, 46(1), and 47 to 50, together with Annexes 1 and 2) enter into force nine months after promulgation, on the next following first of a month, which is 1 October 2026; on that same date Sections 2 to 31 of the predecessor Netz- und Informationssystemsicherheitsgesetz (NISG), BGBl. I Nr. 111/2018 (Austria's transposition of the original NIS Directive, Directive (EU) 2016/1148), and its implementing ordinances (the NISV, BGBl. II Nr. 215/2019, and the QuaSteV, BGBl. II Nr. 226/2019) cease to apply.

So as of this review the predecessor NISG remains Austria's operative cybersecurity regime, and Austria's cybersecurity law today sits in a transitional shape: the predecessor NISG's currently in-force security and reporting duties are recorded alongside NISG 2026's enacted-but-not-yet-binding duties, the same footing this topic already records for the Cyber Resilience Act's own not-yet-binding requirements.

The predecessor NISG binds an operator of essential services in the energy, transport, banking, financial-market-infrastructure, health, drinking-water and digital-infrastructure sectors (Section 17, security measures; Section 19, reporting) and a digital service provider, defined narrowly as an online marketplace, online search engine or cloud-computing service with a micro- or small-enterprise exemption (Section 21, both duties combined), on a lighter, non-fixed-clock notification duty than NIS2's own.

NISG 2026 replaces the Bundesminister für Inneres's direct oversight with a new monocratic Bundesamt für Cybersicherheit (Section 3a), binds an essential entity or an important entity drawn from the sector lists of Annexes 1 and 2 at the medium (at least 50 employees, or turnover and balance-sheet total each over EUR 10 million) or large (at least 250 employees, or turnover over EUR 50 million and balance-sheet total over EUR 43 million) enterprise threshold, and its territoriality provision, Section 28(2)(2), names an online marketplace, an online search engine and a social-networking-platform provider expressly among the digital providers it reaches.

Its risk-management duty (Section 32) restates NIS2 Article 21's ten-category all-hazards list, and its reporting duty (Section 34) restates NIS2 Article 23's clock: a 24-hour early warning, a 72-hour notification, an interim report on request, and a final report within one month.

A covered entity must register with the Bundesamt für Cybersicherheit within three months of commencement (by 1 January 2027) and self-declare its risk-management measures within twelve months of registration; an essential entity additionally faces a shortened two-month proof window once the Bundesamt first requests it, which it may not do before two years after commencement.

Fines run to EUR 10,000,000 or 2 percent of worldwide turnover for an essential entity and EUR 7,000,000 or 1.4 percent for an important entity, both administrative offences rather than crimes, with no double sanction where the same conduct already drew a General Data Protection Regulation (GDPR) fine; a public-sector body faces no fine at all, only a published notice of non-compliance.

No Austrian instrument reviewed here imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.

Austria has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is GDPR Article 32's security-of-processing obligation, and personal-data breach notification under GDPR Articles 33 and 34 and the Datenschutzgesetz, both of which sit in the privacy topic rather than here.

Only the digital-provider slice of each regime's covered-entity class is flagged on this jurisdiction's rows; the wider sector classes both Acts also reach (energy, transport, banking, health, water, public administration and the rest) are recorded here as law the lint does not yet reach rather than flagged on an unrelated activity.

Austria's computer-misuse offences under the Strafgesetzbuch (Sections 118a and 126a to 126c) bind the person who accesses a system without authorisation rather than the system's operator, and sit in the scraping topic rather than here.

Sector security regimes

Netz- und Informationssystemsicherheitsgesetz (NISG), Security Measures for Operators of Essential Services and Digital Service Providers

NISG, BGBl. I Nr. 111/2018, §§ 17 und 21Bundesgesetzblatt, authentic PDF text, BGBl. I Nr. 111/2018

In force since 28 December 2018. Binds public and private bodies.

What this law does

Section 17 requires an operator of essential services, designated under Section 16 in the energy, transport, banking, financial-market-infrastructure, health, drinking-water or digital-infrastructure sector, to take technical and organisational security measures for the network and information systems it uses to provide the essential service, appropriate and proportionate to the state of the art and to the risk that can be identified with reasonable effort, and to prove compliance to the Bundesminister für Inneres at least every three years.

Section 21 places the equivalent duty on a digital service provider, defined by Section 3(12) and (13) as an online marketplace, online search engine or cloud-computing service with a main establishment or a designated representative in Austria and excluding a micro or small enterprise, covering at minimum the security of its systems and facilities, incident handling, business-continuity management, monitoring and testing, and compliance with international standards.

This is Austria's transposition of the original NIS Directive (Directive (EU) 2016/1148); the successor Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) repeals Sections 2 to 31 of this Act, this provision included, on 1 October 2026, documented on this jurisdiction's companion rows.

What it requires

Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management Measures

NISG 2026, BGBl. I Nr. 94/2025, §§ 24, 25, 28 und 32Bundesgesetzblatt, authentic PDF text, BGBl. I Nr. 94/2025

In force in 8 days, effective 1 October 2026. Binds public and private bodies.

What this law does

Section 32 requires a wesentliche Einrichtung (essential entity) or wichtige Einrichtung (important entity), as Section 24 defines them against the Annex 1 and Annex 2 sector lists and the medium- or large-enterprise thresholds Section 25 sets, to implement appropriate and proportionate technical, operational and organisational risk-management measures to reduce the risks to the security of the network and information systems it uses for its operations or to provide its services, and to prevent or minimise the impact of cybersecurity incidents on the users of its services and on other services.

The measures must follow an all-hazards approach and cover at least ten categories: risk analysis and information-system security concepts; cybersecurity-incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the security practices of direct suppliers and service providers; security in the acquisition, development and maintenance of network and information systems, including vulnerability management and disclosure; policies and procedures to assess the effectiveness of risk-management measures; basic cyber-hygiene practices and cybersecurity training; policies on the use of cryptography and, where appropriate, encryption; personnel security, access-control concepts and asset management; and multi-factor or continuous authentication, secure voice, video and text communication and, where appropriate, secure emergency communication systems, transposing NIS2 Article 21.

Section 28, the territoriality provision, names an online marketplace, an online search engine and a platform for social-networking services expressly among the digital providers it reaches, alongside cloud-computing, data-centre, content-delivery-network, managed-service and managed-security-service providers.

Section 31 places implementation and oversight of these measures on the entity's management body (Leitungsorgan), which must attend cybersecurity training designed for it and ensure staff receive regular training.

What it requires

Vulnerability and incident reporting

Netz- und Informationssystemsicherheitsgesetz (NISG), Incident Notification Obligations

NISG, BGBl. I Nr. 111/2018, §§ 19 und 21Bundesgesetzblatt, authentic PDF text, BGBl. I Nr. 111/2018

In force since 28 December 2018. Binds public and private bodies.

What this law does

Section 19 requires an operator of essential services to notify a security incident affecting an essential service it provides, without delay (unverzüglich), to its competent Computer Notfallteam (CERT), which forwards the notification to the Bundesminister für Inneres; the notification must contain every relevant detail known at the time, with later developments reported in follow-up and final notifications.

Section 21(2) places the equivalent duty on a digital service provider, limited to a case where the provider has access to the information needed to assess the incident's impact. Neither provision fixes a numeric notification clock: both require the report without undue delay rather than on NIS2's own 24-hour and 72-hour deadlines.

This is Austria's transposition of the original NIS Directive (Directive (EU) 2016/1148); the successor Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) repeals Sections 2 to 31 of this Act, this provision included, on 1 October 2026, and replaces this notification duty with NIS2's own fixed clock, documented on this jurisdiction's companion rows.

What it requires

Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting Obligations

NISG 2026, BGBl. I Nr. 94/2025, §§ 34 und 35Bundesgesetzblatt, authentic PDF text, BGBl. I Nr. 94/2025

In force in 8 days, effective 1 October 2026. Binds public and private bodies.

What this law does

Section 34 requires a wesentliche Einrichtung (essential entity) or wichtige Einrichtung (important entity) to notify its competent sector-specific CSIRT, or, absent one, the national CSIRT, of every significant cybersecurity incident (defined by Section 35) without delay: an early warning within 24 hours of becoming aware of the incident, stating whether it is suspected to result from unlawful and culpable acts or to have cross-border effects, followed by a fuller notification within 72 hours updating that assessment with an initial evaluation of the incident's severity and impact and any indicators of compromise.

It also requires an interim report on the CSIRT's or the Cybersicherheitsbehörde's request, and a final report no later than one month after the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once it is resolved, transposing NIS2 Article 23.

Section 35 treats a cybersecurity incident as significant where it has caused or can cause severe operational disruption or severe financial loss to the entity, or has affected or can affect another natural or legal person through considerable material or non-material damage, judged against criteria including the dependency of other Annex 1 or Annex 2 sectors on the affected service, the entity's market share, and the incident's possible geographic and cross-border reach.

What it requires

Age gating law1 instrument, 1 proposed

Research summary (169 words)

Austria has no age-verification or age-gating statute currently in force. Youth media protection is a matter for the nine Bundeslander under Austria's federal constitution, so any general content-based access restriction for minors sits in Land-level Jugendschutzgesetze rather than a single federal act, and those Land laws are outside the scope of this national document.

At the federal level, the government sent a draft law to public consultation and to the European Commission for technical-regulation notification on 27 July 2026, which would require platforms that use specified addictive design features, including stranger-heavy recommendation feeds, infinite scroll or autoplay, continuous-use reward systems, or re-engagement push notifications, to bar users under 14 from creating or keeping an account, subject to a child-appropriate area exception; messaging services such as WhatsApp are excluded.

Verification would run on a zero-knowledge, double-blind model that discloses only a yes-or-no age predicate to the platform, with the state's ID Austria digital-identity system offered as one, non-mandatory, verification path. The bill was not yet enacted as of this review.

Social media and minors

Draft Law on a Minimum Age for Social Media Platforms

Gesetzesentwurf Mindestalter Soziale Medien, Begutachtung 27 Juli 2026Bundeskanzleramt Osterreich, official government announcement of the draft law's public consultation and EU notification

Proposed: draft date not recorded. A published draft that has not reached a legislature, dated 27 July 2026, as of 12 September 2026. Binds private bodies.

What this law does

Not yet in force, as proposed. A platform that uses at least one of a defined set of addictive design features, a recommendation feed weighted toward strangers' content, infinite scroll or autoplay, a continuous-use reward system, or a push notification meant to draw a user back, would have to prevent a user under 14 from opening or keeping an account, while remaining free to offer a separate child-appropriate area.

Age verification would run once at account creation, using a zero-knowledge-proof, double-blind design under which the age-attestation provider learns nothing about where or when its attestation is used, the platform receives only a true-or-false answer on whether the 14-year threshold is met, and no name, birth date, or other identifying data passes to the platform. ID Austria, the state digital-identity system, would be one available verification method among others, not a mandatory one. Very large platforms would face a fine of up to 6 percent of worldwide annual turnover for a violation.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (165 words)

Austria transposed the EU Digital Single Market Copyright Directive's press-publisher neighbouring right through Section 76f of the Urheberrechtsgesetz (UrhG), inserted by BGBl. I Nr. 244/2021, giving a press publication's producer an exclusive online reproduction and making-available right that lasts two years from publication.

The same 2021 amendment inserted Section 42h(6), a general text-and-data-mining exception open to any person for any purpose, including an aggregator's indexing, unless the rightsholder has expressly reserved their rights in a machine-readable manner.

Austria has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code, Canada's Online News Act, or the US JCPA; disputes over the Section 76f right are handled through the ordinary courts under the UrhG's general enforcement provisions rather than a dedicated bargaining or arbitration process.

No Austria-specific hot-news or misappropriation doctrine distinct from the general unfair-competition clause of the UWG was located, and no reported Austrian judgment construing Section 76f or the linking and framing question for news aggregation was identified in the sources checked.

Press publishers' right

UrhG Section 76f, Press-Publisher Neighbouring Right

UrhG Sec. 76f, BGBl. Nr. 111/1936 as amended by BGBl. I Nr. 244/2021Urheberrechtsgesetz (UrhG), JUSLINE Osterreich consolidated text

In force since 1 January 2022. Binds private bodies.

What this law does

A service provider that produces a press publication, in analogue or digital form, on its own initiative and under its own editorial responsibility and oversight, holds the exclusive right to reproduce the whole publication or parts of it, and to make it available to the public online, within an information-society service.

A press publication is a collection of predominantly journalistic literary works, published under a common title as a periodically appearing or regularly updated title such as a newspaper, magazine, or journal, and intended to inform the public about news or other topics; scientific and academic periodicals are expressly excluded. The right lasts two years from the press publication's own publication, and cannot be exercised to the detriment of an underlying author's or performer's own rights.

Note and primary source

Text and data mining (TDM) opt-out

UrhG Section 42h(6), Text-and-Data-Mining Opt-Out for Aggregation

UrhG Sec. 42h(6), BGBl. Nr. 111/1936 as amended by BGBl. I Nr. 244/2021Urheberrechtsgesetz (UrhG), JUSLINE Osterreich consolidated text

In force since 1 January 2022. Binds public and private bodies.

What this law does

Section 42h(6) UrhG lets any person, for any purpose, reproduce a work they have lawfully accessed in order to mine text and data in digital form automatically, including for indexing and aggregation. This general exception does not apply where the rightsholder has expressly prohibited the reproduction and signaled that prohibition adequately, in particular through machine-readable means for a work made available online.

This is Austria's transposition of the Digital Single Market (DSM) Directive's general, opt-out-based text-and-data-mining exception, distinct from the narrower, non-waivable scientific-research exception in Section 42h(1) to (5). No dedicated 'Section 42i' exists in the consolidated UrhG; an earlier dossier entry citing that section number for this exception was checked against the primary text and corrected here.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.