Austria Data Protection Authority: All What You Need to Know

The Datenschutzbehörde (DSB) is Austria's national data protection authority, established in 2014 as successor to the Datenschutzkommission. Complete 2026 reference covering role, powers, EDPB influence via former chair Andrea Jelinek, landmark decisions (Google Analytics 2022, Österreichische Post €9.5M), noyb interaction, and how to file complaints.
Alaa
By Alaa
SMTPedia documents email infrastructure end to end: SMTP standards from the RFC archive, delivera...
7 min read Updated Jul 29, 2026 41 views

The Datenschutzbehörde (DSB) is Austria’s national data protection authority. Established in 2014 as the successor to the Datenschutzkommission (which dated back to 1978), the DSB enforces GDPR, the Austrian Data Protection Act (Datenschutzgesetz, DSG), and the Austrian ePrivacy transposition in the Telecommunications Act 2021. Austria’s approach mirrors the German strict-consent doctrine, and the DSB has produced several high-impact cross-border decisions through its former head Andrea Jelinek, who served as European Data Protection Board Chair from 2018 to 2022.

Datenschutzbehörde (DSB) · Established 1 January 2014 under the amended DSG, replacing the Datenschutzkommission (1978-2013) · Led by Matthias Schmidl as acting head from April 2022, formally appointed 2023 · Based at Barichgasse 40-42, 1030 Vienna · Independent federal authority under the Austrian Constitution · Enforces GDPR, DSG 2018 (Datenschutzgesetz), Telekommunikationsgesetz 2021 (Austrian ePrivacy implementation), and E-Commerce-Gesetz 2001 · Max fine: €20M or 4% of global annual turnover.

2014
Operational since 2014 as successor to Datenschutzkommission (1978)
2018-2022
Andrea Jelinek (DSB head) chaired the European Data Protection Board
DOI
Double opt-in standard, mirroring German-speaking jurisdictional practice
€9.5M
Österreichische Post sanction: largest Austrian GDPR fine to date (2019)

Role and powers

The DSB is a monocratic authority: a single head, supported by a staff of roughly 50 employees, with unified competence over the public and private sectors. This is a notable contrast to Germany’s federal + state fragmentation. Its core mandates:

  • Enforcement. Investigations, corrective measures, and administrative fines up to €20M or 4% of global annual turnover under GDPR Article 83. Austrian public bodies are notably exempt from GDPR fines under DSG Section 30 — a rule the European Commission has criticised repeatedly.
  • Guidance. The DSB issues short-form guidance notes and FAQs rather than the extensive practical guides published by CNIL or ICO. Its decisions are the primary reference tool for practitioners.
  • Complaints (Beschwerden). The DSB handles approximately 3,000 complaints per year, with a first-response target of one month and a full-decision target of six months. Cross-border cases go through the GDPR one-stop-shop.
  • Approvals. Codes of conduct, certification schemes, and binding corporate rules for multinational transfers.

Cross-border influence via EDPB

The DSB punches above its weight in EU-wide policy through its Chair. Andrea Jelinek, DSB head from 2014 to 2022, served two three-year terms as EDPB Chair and steered the European response to Schrems II, the Google Analytics transfer decisions, and the coordinated cookie enforcement action of 2021-2022. Under Matthias Schmidl since 2022 the DSB has focused more on domestic enforcement and less on EDPB leadership, but the institutional expertise remains substantial.

Recent enforcement highlights

2019, later reduced
Österreichische Post €9.5M
Profile creation on 3M+ Austrian residents with inferred political party affinity for direct marketing sale. Reduced on appeal to €18,000, then partially annulled by the Supreme Administrative Court in 2022.
2022
Google Analytics jurisprudence
Landmark DSB decision that use of Google Analytics constitutes an unlawful data transfer to the US under Schrems II. Triggered parallel decisions across the EU and remains the anchor precedent.
Ongoing
Meta cross-border cases
Austria has been the venue for multiple noyb-led complaints against Meta, TikTok, and other US platforms, several routed to the Irish DPC as lead but with DSB influence on final decisions.

Beyond headline cases, the DSB issues roughly 30 to 50 sanction decisions per year, typically in the four- and low five-figure range against SMEs for cookie consent violations, insufficient DPAs with processors, and improper data retention. Austrian courts frequently reduce DSB fines on appeal, particularly on procedural grounds — a pattern noyb (the noyb.eu privacy NGO based in Vienna) has criticised as underenforcement.

2026 enforcement priorities

EDPB-aligned modest volume. The DSB’s 2026 priorities align with EDPB coordinated enforcement themes: transparency (CEF 2026), AI training data (the EU AI Act enforcement starting 2 August 2026), and cross-border cookie consent. The DSB has not published a national email pixel deadline analogous to CNIL or Garante, but noyb has publicly demanded the DSB follow suit. Under EU law the DSB retains full independent competence over Austrian-territory violations, and Section 30 DSG penalties for private-sector infringements continue as the primary enforcement tool for marketing email.

How to file a complaint

  • Submit a Beschwerde via the DSB’s online form at dsb.gv.at or by post to Datenschutzbehörde, Barichgasse 40-42, 1030 Wien.
  • The DSB requires prior contact with the data controller: complainants must have raised a data subject request or grievance directly, and either received an unsatisfactory response or none within one month.
  • Complaints may be filed in German or English. Supporting documents in any EU language are accepted; official decisions are issued in German with English summaries for cross-border cases.
  • Cross-border cases go through the GDPR one-stop-shop and are routed to the lead supervisory authority of the controller’s main establishment.
  • Decisions are published on dsb.gv.at (in German) and cross-listed on the EDPB register for cross-border cases. noyb.eu publishes English translations of significant Austrian decisions.

Common misconceptions

“Austria is a small market so DSB enforcement is negligible.” No. The DSB’s influence exceeds its enforcement volume through EDPB leadership and cross-border case seeding. The 2022 Google Analytics decision remains the reference precedent for EU-wide Schrems II compliance, and noyb continues to route significant complaints through Austrian jurisdiction.

“Austrian consent standards are identical to Germany.” Broadly aligned but not identical. Austria follows German double-opt-in practice but the DSB has occasionally accepted robust single-opt-in evidence that a German court would reject. The Telekommunikationsgesetz 2021 cookie consent standard is also slightly less strict than the German TDDDG.

“Austrian public bodies are subject to GDPR fines.” No. DSG Section 30 exempts public bodies from GDPR administrative fines. Corrective measures remain available (orders to stop processing, publish rectifications), but monetary penalties do not apply. The European Commission has criticised this exemption repeatedly.

“Google Analytics is now blanket-illegal in Austria.” No. The DSB’s 2022 decision addressed a specific implementation of Google Analytics without adequate additional safeguards. Google Analytics 4 with EU-hosted data servers, plus the EU-US Data Privacy Framework certification (2023), materially changed the analysis. Deployment-specific review remains required, but the blanket prohibition does not apply.

Frequently asked questions

What role does noyb play in Austrian data protection?

None Of Your Business (noyb) is a Vienna-based non-profit founded by privacy activist Max Schrems in 2018. It files complaints across the EU using DSB or other DPAs as venue, focuses on structural violations by major platforms, and has been the principal driver of Schrems I, Schrems II, and the ongoing consent-vs-contract litigation against Meta. The DSB frequently rules on noyb complaints and coordinates on cross-border cases.

Does the DSB accept complaints in English?

Yes. The DSB accepts complaints in German or English via its online form. Decisions are issued in German by default, but the DSB provides English summaries for cross-border cases and for decisions of general public interest.

How is the DSB structured?

Monocratic: a single head, currently Matthias Schmidl, appointed for a five-year renewable term. The head is supported by roughly 50 staff organised into legal, technical, and administrative units. There is no independent college or restricted formation as in France or Italy.

What is DSG Section 30 and why does it matter?

Section 30 of the Austrian Data Protection Act exempts “public bodies” from GDPR administrative fines under Article 83. Corrective measures remain available. The European Commission opened infringement proceedings against Austria over this exemption in 2019 and closed them without formal action in 2023, but the exemption remains a point of continued EU criticism.

Where can I find current DSB decisions?

DSB decisions are published at dsb.gv.at (in German) and on the RIS legal information system (ris.bka.gv.at). Cross-border decisions appear on the EDPB register. noyb.eu publishes English translations of major decisions and provides context on ongoing appeals.

Where to go next

Sending marketing email into Austria? Pre-validating recipient addresses with SMTPing before you press send catches disposables, catch-alls, and dead mailboxes that generate DSB complaints. Thirteen validation types, twenty-five free checks daily, no card required. Try SMTPing free.


About the Author

Alaa - SMTPedia author

Alaa · LinkedIn

Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. I’ve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.


About SMTPedia

SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.

We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.