Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
Part 2: GDPR Implementation and Supplementary Provisions

Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) AT-DSG-6: Sections 12-13 - Image processing (video surveillance/CCTV)

Image processing (video surveillance) is permitted only on the conditions in DSG ss12-13, including admissibility grounds, transparency/marking and deletion obligations.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 96 controls across 61 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 4 controls

FedRAMP High · 2 controls

  • CA-8 Penetration Testing
  • IR-4 Incident Handling

FedRAMP Moderate · 2 controls

  • CA-8 Penetration Testing
  • IR-4 Incident Handling

FedRAMP Rev 5 · 2 controls

  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests

ISO/IEC 27011:2024 · 2 controls

  • 27011-7.1 Physical security perimeters
  • 27011-7.3 Equipment protection

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.2 IoT Risk Assessment
  • 27400-6.5 Security monitoring and incident response
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access
  • NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC
  • SEMD-PS-1 Critical Infrastructure Protection
  • SEMD-PS-2 Site Security Measures
  • 58.43 Animal Care Facilities

API 1164 · 1 control

  • API1164-13 Business Continuity and Recovery

BSI IT-Grundschutz · 1 control

  • BSI-17 Continuous monitoring strategy
  • CJIS-14 Physical Protection
  • CAT-D3-2 Detective controls

FISMA · 1 control

  • FISMA-3554-Agency-Responsibilities Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))
  • FDBR-Enforcement-AG-CurePeriod Enforcement by Florida Department of Legal Affairs + Penalties + 45-Day Cure (Fla. Stat. 501.72, 501.721, 501.722)
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel
  • IACS-UR-E26-Protect-RemoteAccess-Wireless-Physical-Boundary IACS UR E26 Protect Goal - Remote Access + Wireless + Physical Security + Boundary Protection
  • ICP-24 Macroprudential Surveillance and Insurance Supervision

IEC 62443 · 1 control

  • IEC62443-13 Network security monitoring

IEEE 1686 · 1 control

  • IEEE1686-Section5.2-5.3-AuditLog-Retention-Export-Monitoring IEEE 1686 Section 5.2 + 5.3 - Audit Trail Records + Retention + Export + Supervisory Monitoring and Control + Network Security Monitoring
  • IMO-MSC-FAL-Detect-AnomalyDetection-OT-IT-Monitoring-Reporting-BridgeAlarms IMO MSC-FAL Detect Function - Anomaly Detection + OT and IT System Monitoring + Bridge Alarms + Log Aggregation + Incident Reporting Channels + Crew Observation

ISMAP (Japan) · 1 control

  • ISO28001-PS-01 Facility Security
  • 27006-9.4 Surveillance and recertification

ISO/IEC 27010:2015 · 1 control

  • 27010-11.1 Physical Protection

ISO/IEC 27019:2024 · 1 control

  • ISO27019-13 Network security monitoring
  • JP-FSA-CYB-Security-Monitoring-SOC-Operations-SIEM-EDR-MDR-XDR-24x7-Detection-Alert-Triage Japan FSA Cybersecurity Security Monitoring + SOC 24x7 Operations + SIEM + EDR + MDR + XDR + Detection + Alert Triage + Threat Hunting + Incident Response Integration + Threat Intelligence Integration + UEBA

MTCS (Singapore) · 1 control

  • MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM
  • NAIC-2 Information Security Program (ISP) - Section 4

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NISTPF-5 Protect-P Access Control (PR.AC-P)

NIST SP 1800-32 · 1 control

NIST SP 800-144 · 1 control

  • NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

NIST SP 800-190 · 1 control

  • NZISM-5 Network Security, System Hardening, and Application Security
  • DSOMM-5 Information Gathering, Logging, Monitoring, and Incident Response
  • OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification
  • PSPF24-4 Physical Security

SOC 2 · 1 control

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC-CY-S1 Logical and Physical Access Controls
  • SSAE18-CC6.4 CC6.4 - Physical Access Restrictions
  • SOCI-CIRMP-PHYSICAL CIRMP hazard vector: Physical security and natural hazards

South Korea ISMS-P · 1 control

  • ISMSP-SYS-03 Security Monitoring and Log Management
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • UKGAMBLE-4 Resilience and Incident Response
  • UK-TSA-MON-01 Security Monitoring
  • US-SEC-DA-SC-03 ETF Framework

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part 2: GDPR Implementation and Supplementary Provisions

Query this from an agent

The graph holds this control, the 96 it maps to, and the evidence behind each claim, over MCP and REST.