Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
Austria's Data Protection Act (Datenschutzgesetz, DSG) as amended in 2018 supplements the EU GDPR with national provisions. The Datenschutzbehörde (DSB - Austrian Data Protection Authority) oversees enforcement. The DSG retains a constitutional right to data protection (Section 1 DSG has constitutional rank). Notable provisions include the age of digital consent (14 years), broad research derogations, specific rules for image processing (Bildaufnahme), and administrative and criminal penalties. Austria's data protection has constitutional status since 2000.
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) is a compliance framework from Austria with 5 domains and 14 controls that map to 274 other frameworks. The largest domains are Part 2: GDPR Implementation and Supplementary Provisions (5 controls), Part 3: Data Protection Authority (3 controls), Part 4: Remedies and Penalties (3 controls). Every control below carries what it requires and what an assessor expects to see.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit ris.bka.gv.atFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Part 1: Constitutional Provision - Fundamental Right to Data Protection
| Code | Title |
|---|---|
| AT-DSG-1 | Section 1 - Fundamental right to data protection |
Part 2: GDPR Implementation and Supplementary Provisions
| Code | Title |
|---|---|
| AT-DSG-2 | Section 2 - Scope and application |
| AT-DSG-3 | Section 4(4) - Age of consent for children |
| AT-DSG-4 | Section 6 - Data secrecy (Datengeheimnis) |
| AT-DSG-5 | Section 9 - Media and journalistic exemption |
| AT-DSG-6 | Sections 12-13 - Image processing (video surveillance/CCTV) |
Part 3: Data Protection Authority
| Code | Title |
|---|---|
| AT-DSG-7 | Section 18 - Establishment of the Data Protection Authority |
| AT-DSG-8 | Section 22 - Functions and powers of the DPA |
| AT-DSG-9 | Section 24 - Complaint procedures |
Part 4: Remedies and Penalties
| Code | Title |
|---|---|
| AT-DSG-10 | Section 29 - Liability and right to compensation / civil jurisdiction |
| AT-DSG-11 | Sections 42-45 - Data subject rights (law enforcement) |
| AT-DSG-12 | Section 62 - Administrative penalties |
Part 5: Implementation of the Law Enforcement Directive
Your Compliance Coverage
If you comply with Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018), you already cover:
TEFCA - Trusted Exchange Framework and Common Agreement
64%
9 controls mapped
Compare →FTC GLBA Safeguards Rule (16 CFR Part 314)
64%
9 controls mapped
Compare →Florida Digital Bill of Rights (FDBR)
64%
9 controls mapped
Compare →+ 271 more: Vietnam Law on Cybersecurity (No. 24/2018/QH14) (57%), UK GDPR (UK General Data Protection Regulation) (57%)
See all 274 mapped frameworks ↓Maps to 274 other frameworks
What is Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) and who does it apply to?
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) is a compliance framework from Austria with 5 domains and 14 controls. Austria's Data Protection Act (Datenschutzgesetz, DSG) as amended in 2018 supplements the EU GDPR with national provisions. The Datenschutzbehörde (DSB - Austrian Data Protection Authority) oversees enforcement. The DSG retains a constitutional right to data protection (Section 1 DSG has constitutional rank). Notable provisions include the age of digital consent (14 years), broad research derogations, specific rules for image processing (Bildaufnahme), and administrative and criminal penalties. Austria's data protection has constitutional status since 2000. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) actually require?
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) has 14 controls organised across 5 domains. The largest domains are Part 2: GDPR Implementation and Supplementary Provisions (5 controls), Part 3: Data Protection Authority (3 controls), Part 4: Remedies and Penalties (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) do I already cover?
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) maps to 274 other compliance frameworks. The top mapping partners are TEFCA - Trusted Exchange Framework and Common Agreement (64% coverage), FTC GLBA Safeguards Rule (16 CFR Part 314) (64% coverage), Florida Digital Bill of Rights (FDBR) (64% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)?
Start your Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 14 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required