The GDPR baseline
As an EU member state, this jurisdiction applies the General Data Protection Regulation directly: every use of personal data needs one of six legal bases, individuals hold rights to access, correct, delete and port their data, breaches are reportable within 72 hours, and fines reach EUR 20M or 4% of global turnover. Layered on top, the ePrivacy Directive's national implementation requires prior consent for cookies and similar tracking, with electronic marketing on an opt-in basis softened only by the existing-customer exception.
For advertisers that means the EU standard playbook applies here in full: consent before tracking and behavioral targeting, a compliant consent platform, documented transfer mechanics for any non-EU stack, and one eye on the Digital Omnibus negotiations, which could amend the cookie rules once a final text is adopted. The national details below are what this member state adds or emphasizes.
The national layer
The national implementing act is the Datenschutzgesetz (DSG), and day-to-day supervision belongs to the Datenschutzbehörde. Austria is home base for noyb, the NGO behind Schrems I and II, and the DSB issued one of the first decisions finding Google Analytics transfers unlawful in 2022. Expect complaint-driven enforcement with an emphasis on adtech and transfers.
Key instruments
GDPR + Datenschutzgesetz (DSG)
Austria is home base for noyb, the NGO behind Schrems I and II, and the DSB issued one of the first decisions finding Google Analytics transfers unlawful in 2022. Expect complaint-driven enforcement with an emphasis on adtech and transfers.
Marketing and advertising
GDPR legal basis required; ePrivacy consent for cookies and tracking. Treat the consent note above as the planning rule; the penalty line below is what mispricing it costs.
Cross-border transfers
GDPR Chapter V applies in full, so personal data leaves the EEA only under an adequacy decision, standard contractual clauses, binding corporate rules or a narrow derogation, with a transfer impact assessment expected where the destination has surveillance-law exposure. The mechanics are identical across the bloc, so a transfer stack built for one member state travels to all of them.
Enforcement and penalties
The GDPR's ceiling applies, with fines up to EUR 20M or 4% of global annual turnover, whichever is higher, levied by the national supervisory authority, and the EDPB can force a harder line through the dispute mechanism. Member states share the ceiling and differ in enforcement appetite.