Austria
NSA Tier B partner tied into the EU’s Europol, Schengen and Prüm data systems and the Council of Europe assistance conventions, whose own intelligence service proved so porous that Club de Berne auditors judged its shared network hackable by moderately skilled attackers
Overview
EU Member State: Austria is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page. This page covers national laws, intelligence and surveillance, and Austria’s role in international data sharing.
Austria’s privacy landscape is defined less by its domestic statute than by the alliances its intelligence services join and the routes its data takes out of the country. Austria is an NSA Tier B partner under “Focused Cooperation” and participates in the CROSSHAIR high-frequency direction-finding network as one of sixteen Third Party countries; unlike Five Eyes members, Third Party partners can be and are targeted by NSA collection. Its domestic service, the DSN (successor to the scandal-hit BVT), belongs to the Club de Berne and its Counter-Terrorism Group. Because Austria is landlocked with no submarine cable landings, effectively all of its international traffic transits neighbouring states, primarily through DE-CIX Frankfurt where Germany’s BND conducts bulk cable interception, so Austrian data routinely loses domestic legal protection the moment it crosses the border.[3][9][15]
Austria’s outward data-sharing runs through its alliances and treaties, each detailed below. It is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks (an original 2005 Prüm signatory) and to Europol, was one of seven member states that initiated the European Investigation Order, and holds a bilateral mutual legal assistance treaty with the United States. These are the channels through which the domestic protections described below are, in practice, bypassed.[22][23][24][25][26]
International Data Sharing Agreements
Despite constitutional neutrality and strong DSG protections, Austria participates in extensive intelligence and law enforcement data sharing, and its internet transit infrastructure creates additional involuntary exposure.
Mutual Legal Assistance: Layered Framework
EU Member States (26 countries): The EU Convention on Mutual Assistance in Criminal Matters (2000) and the Schengen Convention provide the primary MLA framework. Austria was one of seven initiating member states that proposed the European Investigation Order (EIO) directive in April 2010, enabling binding cross-border evidence requests across the EU.[17]
European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols apply between Austria and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[22]
Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Austria is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[23]
Bilateral MLAT with the United States: Signed February 23, 1995, entered into force August 1, 1998. Covers testimony, searches, and evidence transfers. Austria’s Tier B SIGINT relationship with the NSA operates alongside but outside this formal legal assistance framework. Beyond the US, Austria’s bilateral treaties are published in the Federal Legal Information System (RIS): the Bundesrecht database (filter to the “Staatsverträge” / state-treaties collection).[18]
Intelligence Sharing
Club de Berne and CTG: Austria’s DSN participates in the Club de Berne and its Counter-Terrorism Group. The Club de Berne keeps no public roster; it is reported to comprise the intelligence services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland, with the United Kingdom also reported as a member; the CTG comprises the same services plus the United Kingdom. The BVT scandal and Poseidon vulnerability raised concerns about the security of shared intelligence held in Austria.[9][27]
NSA Tier B: Austria’s bilateral SIGINT relationship includes the CROSSHAIR network and Königswarte listening station cooperation.[3]
Neutrality Paradox
Austria is constitutionally neutral (1955 Federal Constitutional Law on Neutrality) and not a NATO member, participating only in NATO’s Partnership for Peace. This creates a paradox: Austria cooperates with the NSA bilaterally as a Tier B partner while remaining outside NATO intelligence structures that most EU neighbours use.[8]
EU Law Enforcement Cooperation
SIS II: Real-time query and alert sharing across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[24] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange; Austria was an original 2005 Prüm signatory, and the framework now binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[25] EU-US Umbrella Agreement: Judicial redress for Austrian citizens before US courts. SWIFT/TFTP: International wire transfers subject to US Treasury subpoena. PNR: Passenger data shared for US-bound flights.
Europol
As an EU member state, Austria is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Austrian person data flowing through Europol is reachable onward.[26]
Cross-Border Police Cooperation
Bilateral police cooperation with Germany and a trilateral agreement with Switzerland and Liechtenstein (2012) covering joint patrols, information exchange, and cross-border hot pursuit. Austria’s position in the data flow chain means Liechtenstein’s internet traffic transits through Austria onward after Switzerland.[19]
The Privacy Backdoor Effect
Despite constitutional data protection and DSB GDPR enforcement, alternative pathways exist for accessing Austrian person data:
- DE-CIX Transit / BND: Austrian traffic routinely transits DE-CIX Frankfurt where BND conducts bulk cable interception. Data loses domestic legal protection upon crossing the German border
- NSA Tier B: Bilateral SIGINT sharing about Austrian persons outside GDPR-compatible frameworks
- Club de Berne / EU INTCEN: DSN intelligence shared among the Club de Berne services (27 EU states plus Norway and Switzerland, UK reported) outside any GDPR framework
- EU Framework Sharing: Austrian person data in SIS II, Prüm, or EIO channels accessible to 27 EU states and through Europol to US FBI
- MLAT/CoE Conventions: the US, the 51 parties to the 1959 Convention and the 82 parties to the Budapest Convention can request data through MLA channels
- SWIFT/PNR: Financial transactions and air travel data subject to US access
Conversely, foreign nationals whose communications transit Austrian networks are subject to DSN collection under the SNG without GDPR protection (Article 2(2) national security exemption).
Surveillance and Intelligence
Intelligence Agencies
The DSN (Direktion Staatsschutz und Nachrichtendienst) is Austria’s domestic intelligence and state protection agency, formed December 2021 under the SNG to replace the discredited BVT. The HNA (Heeresnachrichtenamt) is the military intelligence service, operating the Königswarte SIGINT station in Lower Austria. Austria has no foreign civilian intelligence service: foreign intelligence is split between the HNA (military) and DSN (security-related).[8]
BVT Scandal (2018–2021)
On February 28, 2018, police raided BVT headquarters, seizing files and hard drives, potentially exposing shared European intelligence. In February 2019, the Club de Berne dispatched its “Soteria” team to audit the BVT. The classified report (leaked to Austrian media November 11, 2019) found that moderately talented hackers could use the BVT’s network to penetrate “Poseidon,” the Club de Berne’s shared IT network. The leak itself became the biggest breach in Club de Berne history. A related Russian espionage case (retired Colonel Martin M., arrested November 2018 for ~20 years of GRU spying) further eroded partner confidence and contributed to the BVT’s dissolution.[9][10][11]
Bundestrojaner (State Spyware)
On July 9, 2025, parliament authorised DSN deployment of state spyware to intercept encrypted communications (WhatsApp, Signal) by a 105–71 vote. Deployment is permitted even against individuals not suspected of any crime (if other methods are exhausted), requires Federal Administrative Court approval, and is capped at 25–30 annual cases. Deployment expected 2027. This is Austria’s second attempt: on December 11, 2019, the Constitutional Court struck down an identical law, ruling it violated Article 8 ECHR, Section 1 DSG, and Article 9 Staatsgrundgesetz, holding that computer infiltration differs fundamentally from traditional wiretapping because it provides insight into all areas of life. Civil society organisations have promised legal challenges to the new law.[2][12]
NSA Tier B Cooperation
Austria is classified as an NSA Tier B partner under “Focused Cooperation” (disclosed via Snowden documents, published by El Mundo October 30, 2013). Austria participates in the CROSSHAIR worldwide High Frequency Direction-Finding (HFDF) network, listed among 16 Third Party countries. Unlike Five Eyes members, Third Party partners can be and are targeted by NSA collection.[3]
Internet Infrastructure and Transit Exposure
The Vienna Internet Exchange (VIX) is Austria’s primary IXP. As a landlocked country with no submarine cable landings, all international traffic transits through neighbouring states, primarily westward through Germany via DE-CIX Frankfurt.[13]
The BND has intercepted DE-CIX traffic since 2009. Austrian politician Peter Pilz accused the BND and Deutsche Telekom of tapping a telecommunications line between Luxembourg and Vienna, with evidence that lines between Amsterdam, Stockholm, Dublin, Moscow, and Vienna were likely intercepted. Austrian data also transits Swiss exchange points where the NDB conducts cable reconnaissance.[14][15]
Privacy Framework
The Datenschutzbehoerde (DSB) is Austria’s independent supervisory authority, replacing the former Datenschutzkommission on January 1, 2014. The DSB issued the first EU ruling that Google Analytics violated GDPR by transferring data to the US (January 2022), triggering parallel rulings across Europe. However, the DSB faces severe resourcing constraints: beginning July 2025, budget pressure (EUR 6.1M in 2025, EUR 5.9M in 2026) forced elimination of ~20 intern positions, restricted ex officio investigations, and curtailed public access, even as new responsibilities (Freedom of Information Act, AI Act, political advertising) were added. noyb filed a complaint with the European Commission about these deficiencies.[1][4][5]
The DSG supplements the GDPR with national provisions. Section 1 provides a constitutional fundamental right to data protection (Verfassungsbestimmung), predating the GDPR by four decades. Austria is home to noyb (None of Your Business), Max Schrems’s organisation whose litigation produced the Schrems I and Schrems II CJEU rulings that invalidated two successive EU-US data-transfer frameworks.[1] The StPO (Code of Criminal Procedure, Sections 134ff) governs lawful interception requiring judicial orders for offences over one year. The SPG (Security Police Act) authorises police metadata access. The SNG (State Protection and Intelligence Service Act, December 2021) provides the DSN’s legal basis.[6][7]
Data Retention
On June 27, 2014, the Constitutional Court struck down Austria’s data retention law as disproportionate and unconstitutional. Austria has not enacted replacement legislation. Telecom providers retain traffic data only as needed for billing/service provision. Law enforcement can still obtain real-time interception orders and access subscriber data under the StPO.[16]
Pending Legislation
- Messenger surveillance (Bundestrojaner) implementation: the messenger-surveillance law enacted in 2025 (amending the State Protection and Intelligence Service Act, Security Police Act, and Telecommunications Act) is being operationalised, with case-by-case Federal Administrative Court approval; civil-society and bar-association challenges over its constitutionality are expected, echoing the 2019 Constitutional Court strike-down of an earlier version.[12]
- DSB resourcing / structural reform (oversight): epicenter.works and noyb have filed a complaint with the European Commission over the Datenschutzbehörde’s underfunding (53 staff for 9 million people); any remedy would require budgetary or structural legislation.
- EU AI Act national implementation: Austria must designate AI market-surveillance authorities and adapt the DSG framework; implementing legislation is pending.
- Data retention: Austria has no general retention regime (struck down in 2014); quick-freeze and targeted-retention proposals continue to be debated in light of CJEU case law.
- Under-14 social media ban: in March 2026 the governing coalition (Vice-Chancellor Andreas Babler of the SPÖ) announced a compulsory minimum age of 14 for social media use, with draft legislation to be prepared by the end of June 2026. The government says it will rely on “technically modern,” privacy-respecting age-verification methods, and would designate covered platforms by how addictive their algorithms are and whether they carry content such as “sexualised violence” rather than naming services. The plan, paired with expanded media-literacy and AI education in schools, follows the EU age-verification blueprint debate and similar moves in Australia, Denmark, Greece, Spain, and France. The agreement was reached on March 27, 2026 after weeks of negotiation between the ÖVP, SPÖ and NEOS, and the ban is intended to take effect from September 2026, the start of the 2026/27 school year. The verification design is the notable part: Austria proposes a two-stage online age check built on zero-knowledge proofs, in which a platform learns only whether a user has passed a given age threshold and receives no personal data, not even the exact age. If it works as described, it is the opposite of the identity-document and facial-estimation model being built in the United Kingdom and Australia, where verification necessarily discloses identity or biometric data to a platform or its vendor. Digitalisation State Secretary Alexander Pröll said Austria would not wait for Brussels: “We do not have the time to wait years more for a European solution.”[20][21]
