Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
Austria's Data Protection Act (Datenschutzgesetz, DSG) as amended in 2018 supplements the EU GDPR with national provisions. The Datenschutzbehörde (DSB — Austrian Data Protection Authority) oversees enforcement. The DSG retains a constitutional right to data protection (Section 1 DSG has constitutional rank). Notable provisions include the age of digital consent (14 years), broad research derogations, specific rules for image processing (Bildaufnahme), and administrative and criminal penalties. Austria's data protection has constitutional status since 2000.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (25)
Breach
| Code | Title |
|---|---|
| DSG-BREACH | Breach notification |
Confidentiality
| Code | Title |
|---|---|
| DSG-6 | Data secrecy obligation |
Constitutional
| Code | Title |
|---|---|
| DSG-1 | Fundamental right to data protection |
Criminal Data
| Code | Title |
|---|---|
| DSG-10 | Criminal convictions data |
DPIA
| Code | Title |
|---|---|
| DSG-DPIA | Data Protection Impact Assessment |
Data Subject Rights
| Code | Title |
|---|---|
| DSG-30 | Complaint to DSB |
Documentation
| Code | Title |
|---|---|
| DSG-ROPA | Records of processing activities |
Employment
| Code | Title |
|---|---|
| DSG-EMP | Employment data |
Enforcement
| Code | Title |
|---|---|
| DSG-24 | Powers of DSB |
Governance
| Code | Title |
|---|---|
| DSG-DPO | Data Protection Officer |
Image Processing
| Code | Title |
|---|---|
| DSG-11 | Processing image data |
| DSG-12 | Permissibility of image processing |
Journalism
| Code | Title |
|---|---|
| DSG-35 | Data processing for journalism |
Lawful Basis
| Code | Title |
|---|---|
| DSG-7 | Processing in vital interest |
Part 1: Constitutional Provision — Fundamental Right to Data Protection
| Code | Title |
|---|---|
| AT-DSG-1 | Section 1 — Fundamental Right to Data Protection |
Part 2: GDPR Implementation and Supplementary Provisions
| Code | Title |
|---|---|
| AT-DSG-2 | Section 2 — Scope and Application |
| AT-DSG-3 | Section 4(4) — Age of Consent for Children |
| AT-DSG-4 | Section 6 — Processing of Special Categories of Data |
| AT-DSG-5 | Section 9 — Media and Journalistic Exemptions |
| AT-DSG-6 | Sections 12-13 — Video Surveillance (CCTV) |
Part 3: Data Protection Authority
| Code | Title |
|---|---|
| AT-DSG-7 | Section 18 — Establishment of the Data Protection Authority |
| AT-DSG-8 | Section 22 — Functions and Powers |
| AT-DSG-9 | Section 24 — Complaint Procedures |
Part 4: Remedies and Penalties
| Code | Title |
|---|---|
| AT-DSG-10 | Section 28 — Civil Court Jurisdiction |
| AT-DSG-11 | Sections 42-45 — Data Subject Rights Implementation |
| AT-DSG-12 | Section 62 — Administrative Penalties |
Part 5: Implementation of the Law Enforcement Directive
| Code | Title |
|---|---|
| AT-DSG-13 | Section 36 — Scope of Law Enforcement Processing |
| AT-DSG-14 | Section 38 — Data Subject Rights in Law Enforcement |
Penalties
| Code | Title |
|---|---|
| DSG-40 | Administrative penalties |
Public Sector
| Code | Title |
|---|---|
| DSG-15 | Public official secrets |
Rights
| Code | Title |
|---|---|
| DSG-32 | Right to confidentiality |
Scope
| Code | Title |
|---|---|
| DSG-4 | Material scope and openings |
Special Categories
| Code | Title |
|---|---|
| DSG-9 | Processing of special categories |
Supervisory Authority
| Code | Title |
|---|---|
| DSG-5 | Data Protection Authority (DSB) |
Transparency
| Code | Title |
|---|---|
| DSG-13 | Transparency in image processing |
Your Compliance Coverage
If you comply with Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018), you already cover:
ISO/IEC 27400:2022
26%
9 controls mapped
Compare →UK Telecommunications (Security) Act 2021
26%
9 controls mapped
Compare →ASEAN Data Management Framework
26%
9 controls mapped
Compare →+ 594 more: NIS2 Directive (26%), ILO Nursing Personnel Convention C149 (1977) (26%)
See all 597 mapped frameworks ↓Maps to 597 other frameworks
Frequently Asked Questions
What is Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)?
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) is a compliance framework from Austria with 25 domains and 35 controls. Austria's Data Protection Act (Datenschutzgesetz, DSG) as amended in 2018 supplements the EU GDPR with national provisions. The Datenschutzbehörde (DSB — Austrian Data Protection Authority) oversees enforcement. The DSG retains a constitutional right to data protection (Section 1 DSG has constitutional rank). Notable provisions include the age of digital consent (14 years), broad research derogations, specific rules for image processing (Bildaufnahme), and administrative and criminal penalties. Austria's data protection has constitutional status since 2000. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) have?
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) has 35 controls organised across 25 domains. The largest domains are Part 2: GDPR Implementation and Supplementary Provisions (5 controls), Part 3: Data Protection Authority (3 controls), Part 4: Remedies and Penalties (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) map to?
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) maps to 597 other compliance frameworks. The top mapping partners are ISO/IEC 27400:2022 (26% coverage), UK Telecommunications (Security) Act 2021 (26% coverage), ASEAN Data Management Framework (26% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) compliance?
Start your Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required