Austria

NSA Tier B partner tied into the EU’s Europol, Schengen and Prüm data systems and the Council of Europe assistance conventions, whose own intelligence service proved so porous that Club de Berne auditors judged its shared network hackable by moderately skilled attackers

← Back to Privacy Law Directory

Overview

EU Member State: Austria is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page. This page covers national laws, intelligence and surveillance, and Austria’s role in international data sharing.

Austria’s privacy landscape is defined less by its domestic statute than by the alliances its intelligence services join and the routes its data takes out of the country. Austria is an NSA Tier B partner under “Focused Cooperation” and participates in the CROSSHAIR high-frequency direction-finding network as one of sixteen Third Party countries; unlike Five Eyes members, Third Party partners can be and are targeted by NSA collection. Its domestic service, the DSN (successor to the scandal-hit BVT), belongs to the Club de Berne and its Counter-Terrorism Group. Because Austria is landlocked with no submarine cable landings, effectively all of its international traffic transits neighbouring states, primarily through DE-CIX Frankfurt where Germany’s BND conducts bulk cable interception, so Austrian data routinely loses domestic legal protection the moment it crosses the border.[3][9][15]

Austria’s outward data-sharing runs through its alliances and treaties, each detailed below. It is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks (an original 2005 Prüm signatory) and to Europol, was one of seven member states that initiated the European Investigation Order, and holds a bilateral mutual legal assistance treaty with the United States. These are the channels through which the domestic protections described below are, in practice, bypassed.[22][23][24][25][26]

International Data Sharing Agreements

Despite constitutional neutrality and strong DSG protections, Austria participates in extensive intelligence and law enforcement data sharing, and its internet transit infrastructure creates additional involuntary exposure.

Mutual Legal Assistance: Layered Framework

EU Member States (26 countries): The EU Convention on Mutual Assistance in Criminal Matters (2000) and the Schengen Convention provide the primary MLA framework. Austria was one of seven initiating member states that proposed the European Investigation Order (EIO) directive in April 2010, enabling binding cross-border evidence requests across the EU.[17]

European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols apply between Austria and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[22]

Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Austria is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[23]

Bilateral MLAT with the United States: Signed February 23, 1995, entered into force August 1, 1998. Covers testimony, searches, and evidence transfers. Austria’s Tier B SIGINT relationship with the NSA operates alongside but outside this formal legal assistance framework. Beyond the US, Austria’s bilateral treaties are published in the Federal Legal Information System (RIS): the Bundesrecht database (filter to the “Staatsverträge” / state-treaties collection).[18]

Intelligence Sharing

Club de Berne and CTG: Austria’s DSN participates in the Club de Berne and its Counter-Terrorism Group. The Club de Berne keeps no public roster; it is reported to comprise the intelligence services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland, with the United Kingdom also reported as a member; the CTG comprises the same services plus the United Kingdom. The BVT scandal and Poseidon vulnerability raised concerns about the security of shared intelligence held in Austria.[9][27]

NSA Tier B: Austria’s bilateral SIGINT relationship includes the CROSSHAIR network and Königswarte listening station cooperation.[3]

Neutrality Paradox

Austria is constitutionally neutral (1955 Federal Constitutional Law on Neutrality) and not a NATO member, participating only in NATO’s Partnership for Peace. This creates a paradox: Austria cooperates with the NSA bilaterally as a Tier B partner while remaining outside NATO intelligence structures that most EU neighbours use.[8]

EU Law Enforcement Cooperation

SIS II: Real-time query and alert sharing across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[24] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange; Austria was an original 2005 Prüm signatory, and the framework now binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[25] EU-US Umbrella Agreement: Judicial redress for Austrian citizens before US courts. SWIFT/TFTP: International wire transfers subject to US Treasury subpoena. PNR: Passenger data shared for US-bound flights.

Europol

As an EU member state, Austria is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Austrian person data flowing through Europol is reachable onward.[26]

Cross-Border Police Cooperation

Bilateral police cooperation with Germany and a trilateral agreement with Switzerland and Liechtenstein (2012) covering joint patrols, information exchange, and cross-border hot pursuit. Austria’s position in the data flow chain means Liechtenstein’s internet traffic transits through Austria onward after Switzerland.[19]

The Privacy Backdoor Effect

Despite constitutional data protection and DSB GDPR enforcement, alternative pathways exist for accessing Austrian person data:

Conversely, foreign nationals whose communications transit Austrian networks are subject to DSN collection under the SNG without GDPR protection (Article 2(2) national security exemption).

Surveillance and Intelligence

Intelligence Agencies

The DSN (Direktion Staatsschutz und Nachrichtendienst) is Austria’s domestic intelligence and state protection agency, formed December 2021 under the SNG to replace the discredited BVT. The HNA (Heeresnachrichtenamt) is the military intelligence service, operating the Königswarte SIGINT station in Lower Austria. Austria has no foreign civilian intelligence service: foreign intelligence is split between the HNA (military) and DSN (security-related).[8]

BVT Scandal (2018–2021)

On February 28, 2018, police raided BVT headquarters, seizing files and hard drives, potentially exposing shared European intelligence. In February 2019, the Club de Berne dispatched its “Soteria” team to audit the BVT. The classified report (leaked to Austrian media November 11, 2019) found that moderately talented hackers could use the BVT’s network to penetrate “Poseidon,” the Club de Berne’s shared IT network. The leak itself became the biggest breach in Club de Berne history. A related Russian espionage case (retired Colonel Martin M., arrested November 2018 for ~20 years of GRU spying) further eroded partner confidence and contributed to the BVT’s dissolution.[9][10][11]

Bundestrojaner (State Spyware)

On July 9, 2025, parliament authorised DSN deployment of state spyware to intercept encrypted communications (WhatsApp, Signal) by a 105–71 vote. Deployment is permitted even against individuals not suspected of any crime (if other methods are exhausted), requires Federal Administrative Court approval, and is capped at 25–30 annual cases. Deployment expected 2027. This is Austria’s second attempt: on December 11, 2019, the Constitutional Court struck down an identical law, ruling it violated Article 8 ECHR, Section 1 DSG, and Article 9 Staatsgrundgesetz, holding that computer infiltration differs fundamentally from traditional wiretapping because it provides insight into all areas of life. Civil society organisations have promised legal challenges to the new law.[2][12]

NSA Tier B Cooperation

Austria is classified as an NSA Tier B partner under “Focused Cooperation” (disclosed via Snowden documents, published by El Mundo October 30, 2013). Austria participates in the CROSSHAIR worldwide High Frequency Direction-Finding (HFDF) network, listed among 16 Third Party countries. Unlike Five Eyes members, Third Party partners can be and are targeted by NSA collection.[3]

Internet Infrastructure and Transit Exposure

The Vienna Internet Exchange (VIX) is Austria’s primary IXP. As a landlocked country with no submarine cable landings, all international traffic transits through neighbouring states, primarily westward through Germany via DE-CIX Frankfurt.[13]

The BND has intercepted DE-CIX traffic since 2009. Austrian politician Peter Pilz accused the BND and Deutsche Telekom of tapping a telecommunications line between Luxembourg and Vienna, with evidence that lines between Amsterdam, Stockholm, Dublin, Moscow, and Vienna were likely intercepted. Austrian data also transits Swiss exchange points where the NDB conducts cable reconnaissance.[14][15]

Recent Developments

Constitutional Challenge to Messenger Surveillance Heard (June 22, 2026)

The challenge civil society promised against the 2025 messenger-surveillance law has been brought, and the Constitutional Court has heard it. Sixty-seven members of the National Council, from the FPÖ and Green parliamentary groups, applied to have the power introduced in July 2025 struck down as unconstitutional. The provision at issue is § 11(1)(9) of the State Protection and Intelligence Service Act (SNG), which authorises the monitoring of electronic messages for extended threat investigation and preventive protection against constitution-endangering attacks on reasonable suspicion, including “by introducing a program into a computer system of the person concerned by technical means.” The VfGH held a public oral hearing on June 22, 2026 in case G 13-14/2026.[29]

The applicants advance three arguments, and the first is a supply-chain point rather than a purely domestic one: Austrian authorities cannot build this software themselves, so it must be bought, which means the data to be analysed can end up in the hands of foreign vendors. Second, a technically powerful instrument of this kind carries enormous potential for abuse. Third, the software cannot monitor individual messages, so the mere possibility of being continuously and secretly monitored across the whole of one’s electronic communication is said to change the population’s communication behaviour, a chilling-effect argument rather than a claim about any particular interception. On that basis the new power is said to breach the constitutional right to data protection just as its 2019 predecessor did, which the same court struck down. Counsel for the applicants, Michael Rohregger, argued that little of substance has changed since that ruling; the federal government defends the measure as necessary for the prevention of danger. The Court continued its deliberations after the hearing and a decision is not expected before the autumn, which places it ahead of the law’s expected 2027 deployment.[29]

Asylum Seekers’ Phones Also before the Constitutional Court (G 16/2026)

A second data-seizure case is running in parallel. Under the BFA-Verfahrensgesetz, public security officers may seize the data carriers of asylum applicants, mobile phones included, and analyse the data stored on them where identity or travel route cannot be established by other means. Hearing a complaint against such an order, the Federal Administrative Court referred the provisions to the VfGH as unconstitutional, arguing that the statute contains no adequate guarantees for the confidentiality interests of the person concerned and does not regulate with sufficient clarity when a phone may be seized at all. The referral expressly invokes the reasoning by which the VfGH struck down the equivalent data-carrier seizure provisions in criminal investigations in 2023. The case was listed for deliberation in the same June 2026 sitting as the messenger-surveillance challenge.[30]

Under-14 Social Media Ban: Agreement, then Draft (March–July 2026)

The governing coalition agreed a compulsory minimum age of 14 for social media on March 27, 2026, after weeks of negotiation between the ÖVP, SPÖ and NEOS, with the ban originally intended to take effect in September 2026, the start of the 2026/27 school year. The draft was due by the end of June and did not appear then. It was published on July 27; the measure itself remains pending legislation and is listed below.[20][21]

Draft published July 27, 2026. The bill went into Begutachtung (public review) and simultaneously to the European Commission for notification on July 27, 2026, with entry into force now targeted at January 1, 2027 rather than September 2026. It works by amending the Audiovisual Media Services Act (AMD-G). Rather than naming services, it defines the ban by addictive design features: recommender algorithms serving predominantly strangers’ content, endless scrolling or autoplay, reward systems for continuous use, and push notifications when the user stops. TikTok, Instagram, YouTube and Snapchat are the named examples; platforms may still offer child-appropriate areas, and messenger services such as WhatsApp are excluded. Very large platforms face fines of up to 6% of global annual turnover.

The verification design is what makes this page’s counterexample. The draft specifies a double-blind model using privacy-enhancing technologies, principally zero-knowledge proofs: the platform receives only an age predicate (“14 or older: true”), never a name or date of birth, and the issuer of the age credential cannot see where or when a proof was used. Cryptographic measures are specified to prevent uses of the same credential at different sites from being linked to each other or to a person. Release is local and deliberate, and the user must be able to see which age threshold is being sent, for what purpose, and to which platform. Verification is once per account at creation, with existing accounts checked at entry into force; anonymous use without an account may require repeated verification. ID Austria is offered as one route but is explicitly not mandatory, and because the design tracks the EU Age Verification Blueprint it is intended to carry over to the EUDI wallet. State Secretary Alexander Pröll: “The protection of our children must not come at the cost of privacy.” Set against the identity-document and facial-estimation models being built in the United Kingdom and Australia, this is the strongest form of the argument that age assurance need not mean identification, and the question worth following is whether the deployed system matches the drafted one.[28]

Data Protection Authority Activity Report 2025 (May 11, 2026)

The DSB’s report for 2025 was laid before Parliament, and the numbers show an authority absorbing a sharply rising caseload on a shrinking budget. Complaint intake rose from 3,019 in 2024 to 5,300 in 2025, while concluded individual complaints rose from 2,397 to 3,403. The DSB also received 1,364 cross-border complaints within Austria and 173 from abroad, opened 225 ex officio review procedures and 127 administrative penal procedures, and logged 1,855 security-breach notifications (2024: 1,319), of which 1,704 were national GDPR data breaches, a large share of them hacking and ransomware incidents. It was simultaneously party to 453 proceedings before the Federal Administrative Court, 126 before the Administrative Court, and seven before the Constitutional Court.[31]

Two observations from the head of the authority, Matthias Schmidl, are worth recording. The first is a new drain on capacity: a volume of complaints generated with the help of AI, which he says ties up considerable resources. The second is a warning. After the 2025 budget cuts, and with the Freedom of Information Act, the AI Act, the political-advertising transparency regulation, the proposed Digital Omnibus reform of the GDPR, and cooperation with the new parliamentary data protection committee all landing on the same desk, Schmidl states that without additional budget and staff the DSB will not be able to manage the tasks coming to it. The authority has separately put concrete proposals to the Justice Ministry for a procedural amendment to the Data Protection Act, intended to speed proceedings up and, in specific places, to lengthen limitation periods so that cases can be run properly; a first substantive discussion has taken place. Set against the constitutional right to data protection Austria has held since 1978, the constraint is not on the right but on the body that enforces it.[31][4]

Privacy Framework

The Datenschutzbehoerde (DSB) is Austria’s independent supervisory authority, replacing the former Datenschutzkommission on January 1, 2014. The DSB issued the first EU ruling that Google Analytics violated GDPR by transferring data to the US (January 2022), triggering parallel rulings across Europe. However, the DSB faces severe resourcing constraints: beginning July 2025, budget pressure (EUR 6.1M in 2025, EUR 5.9M in 2026) forced elimination of ~20 intern positions, restricted ex officio investigations, and curtailed public access, even as new responsibilities (Freedom of Information Act, AI Act, political advertising) were added. noyb filed a complaint with the European Commission about these deficiencies.[1][4][5]

The DSG supplements the GDPR with national provisions. Section 1 provides a constitutional fundamental right to data protection (Verfassungsbestimmung), predating the GDPR by four decades. Austria is home to noyb (None of Your Business), Max Schrems’s organisation whose litigation produced the Schrems I and Schrems II CJEU rulings that invalidated two successive EU-US data-transfer frameworks.[1] The StPO (Code of Criminal Procedure, Sections 134ff) governs lawful interception requiring judicial orders for offences over one year. The SPG (Security Police Act) authorises police metadata access. The SNG (State Protection and Intelligence Service Act, December 2021) provides the DSN’s legal basis.[6][7]

Data Retention

On June 27, 2014, the Constitutional Court struck down Austria’s data retention law as disproportionate and unconstitutional. Austria has not enacted replacement legislation. Telecom providers retain traffic data only as needed for billing/service provision. Law enforcement can still obtain real-time interception orders and access subscriber data under the StPO.[16]

Pending Legislation

Sources

[1] GDPRhub: Data Protection in Austria – DSB structure, DSG Section 1 constitutional status, noyb
[2] Statewatch: Austria Legalises State Spyware (July 2025) – Bundestrojaner passage, 105-71 vote, 2027 deployment
[3] Electrospaces: NSA’s Foreign Partnerships – Austria Tier B, CROSSHAIR, Third Party classification
[4] noyb: Google Analytics Illegal (January 2022) – First EU DPA ruling, 101 model complaints
[5] PPC.land: Austrian DPA Cuts Operations (2025) – EUR 6.1M budget, ~20 intern positions eliminated
[6] FRA: Surveillance in Austria – StPO 134ff, SPG 53(3a-3b), SNG Section 11(1)
[7] DSN Official Site – December 2021 establishment, SNG legal basis
[8] Wikipedia: Heeresnachrichtenamt – HNA, Königswarte SIGINT, no foreign civilian intelligence
[9] Electrospaces: Leaked Report Reveals BVT Security Risks – Club de Berne Soteria audit, Poseidon vulnerability
[10] Matthias Monroy: Club de Berne Criticises Austria – Biggest leak in CdB history
[11] Wikipedia: Austria and Russian Intelligence – Colonel Martin M., ~20 years GRU espionage
[12] epicenter.works: Bundestrojaner Unconstitutional (December 2019) – Article 8 ECHR, Section 1 DSG violations
[14] The Local: Germany Spied on Austrian Internet Traffic (May 2015) – BND interception, Luxembourg-Vienna line tapping
[17] Wikipedia: European Investigation Order – Austria among 7 initiating states (2010)
[18] US DOJ: MLATs of the United States (April 2022) – Austria MLAT signed Feb 23, 1995, in force Aug 1, 1998
[19] DLA Piper: Data Protection – Austria – Cross-border cooperation
[20] Al Jazeera: Austria Plans Social Media Ban for Children Under 14 (March 27, 2026) – Coalition (VC Andreas Babler) compulsory minimum age 14 for social media; draft legislation by end of June 2026; privacy-respecting age verification; platforms designated by algorithmic addictiveness and harmful content rather than by name; paired with media-literacy and AI education
[21] Bundeskanzleramt Österreich: Bundesregierung setzt Mindestalter für Social Media fest (March 27, 2026) – Federal government child-protection package agreed March 27, 2026 after negotiations between ÖVP, SPÖ and NEOS; minimum age 14 for social media, named examples Instagram, TikTok, Snapchat; draft law to be ready by end of June 2026, then sent for review (Begutachtung); verification via a “Zero-Knowledge-Proof approach” described as low-barrier, secure, protected, inclusive and broad, supplementing European minimum standards; State Secretary for Digitalisation Alexander Pröll: “Wir haben nicht die Zeit, noch Jahre auf eine europäische Lösung zu warten”
[22] Council of Europe Treaty Office: European Convention on Mutual Assistance in Criminal Matters (ETS No. 30) – Chart of signatures and ratifications; 51 parties as of July 2026 (all 46 Council of Europe member states plus Chile, Israel, Mongolia, the Republic of Korea and Russia), Austria among them
[23] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026 (45 Council of Europe member states plus 37 non-member states), Austria among them
[24] European Commission: Schengen Area – The 29 states of the Schengen Area (all EU members except Ireland and Cyprus, plus the non-EU associates Iceland, Liechtenstein, Norway and Switzerland; Bulgaria and Romania became full members January 1, 2025), Austria among them
[25] Wikipedia: Prüm Convention – The Prüm framework for automated DNA, fingerprint and vehicle-data exchange; binds all 27 EU member states plus the non-EU Schengen associates Iceland, Liechtenstein, Norway and Switzerland (31 in all); Austria was an original 2005 signatory; Prüm II (2024) adds facial images and police records
[26] Europol: Operational Agreements – Europol is constituted by the 27 EU member states (Austria among them) and maintains operational cooperation agreements permitting exchange of personal data with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, the United States) plus Denmark under a separate agreement, and with Eurojust, Frontex and Interpol
[27] about:intel: The Club de Berne – The voluntary intelligence-sharing forum (no public membership roster) reported to comprise the intelligence services of the 27 EU member states plus Norway and Switzerland, with the United Kingdom also reported; its Counter Terrorism Group (CTG) comprises the same services plus the UK; Austria’s DSN is a participant
[28] Bundeskanzleramt Österreich: Gesetzesentwurf für Social-Media-Verbot unter 14 geht in Begutachtung (July 27, 2026) – draft sent to public review and to the European Commission for notification on July 27, 2026; scope defined by addictive features (recommender algorithms dominated by strangers’ content, endless scrolling or autoplay, reward systems for continuous use, push notifications on non-use), with TikTok, Instagram, YouTube and Snapchat as examples, child-appropriate areas still permitted and messenger services such as WhatsApp excluded; implemented by amending the Audiovisual Media Services Act (AMD-G); fines to 6% of global annual turnover for very large platforms; double-blind age verification using privacy-enhancing technologies and zero-knowledge proofs, so the platform receives only an age predicate and the credential issuer cannot see where or when a proof is used, with cryptographic unlinkability across sites, local and informed release by the user, one-time verification at account creation, existing accounts checked at entry into force, and possible repeated verification for anonymous use without an account; ID Austria offered but not mandatory; design follows the EU Age Verification Blueprint so as to be reusable with the EUDI wallet
[29] Verfassungsgerichtshof: Mündliche Verhandlung des VfGH zur Überwachung von Messenger-Diensten (May 27, 2026) – public oral hearing on Monday June 22, 2026 in case G 13-14/2026; application by 67 members of the FPÖ and Green parliamentary groups to strike down as unconstitutional the messenger-surveillance power introduced in July 2025; the contested provision is § 11(1)(9) SNG, authorising surveillance of electronic messages for extended threat investigation and preventive protection against constitution-endangering attacks on reasonable suspicion, including by introducing a program into the target’s computer system by technical means; grounds advanced: the software must be purchased because Austrian authorities cannot develop it, so data can reach foreign providers; enormous potential for abuse; the software cannot monitor individual messages, so the possibility of continuous secret monitoring of all electronic communication affects the population’s communication behaviour; said to breach the fundamental right to data protection as the 2019-annulled “Bundestrojaner” predecessor did
[30] Verfassungsgerichtshof: VfGH berät über Kopftuchverbot, Messenger-Überwachung und Öffentlichkeit in U-Ausschüssen (June 11, 2026) – session preview confirming that the Court would continue its deliberations on the messenger-surveillance case after the June 22 hearing; also lists G 16/2026, a Federal Administrative Court referral challenging the provisions of the BFA-Verfahrensgesetz under which public security officers may seize and analyse asylum applicants’ data carriers where identity or travel route cannot be established by other means, on the ground that the statute lacks adequate guarantees for the confidentiality interests of the person concerned and does not sufficiently regulate when a phone may be seized, invoking the reasoning of the Court’s 2023 annulment of the equivalent seizure provisions in criminal investigations
[31] Parlament Österreich, Parlamentskorrespondenz Nr. 415: Datenschutzbehörde für verfahrensrechtliche Novelle des Datenschutzgesetzes (May 11, 2026) – on the DSB activity report for 2025 (III-334 d.B.): complaint intake up from 3,019 (2024) to 5,300 (2025), individual complaints concluded up from 2,397 to 3,403, 1,364 cross-border complaints in Austria and 173 from abroad, 225 ex officio review procedures, 127 administrative penal procedures, 1,855 security-breach notifications (2024: 1,319) of which 1,704 national GDPR data breaches with many ransomware attacks, and 453 proceedings before the Federal Administrative Court, 126 before the Administrative Court and seven before the Constitutional Court; DSB head Matthias Schmidl reports 2025 budget cuts, a volume of AI-generated complaints tying up considerable resources, and new tasks from the Freedom of Information Act, the AI Act, the political-advertising transparency regulation, the proposed Digital Omnibus GDPR reform and cooperation with the new parliamentary data protection committee, stating that without additional budget and staff the authority will not be able to manage them; the DSB has put concrete proposals for a procedural amendment of the Data Protection Act to the Justice Ministry, to speed proceedings and lengthen certain limitation periods, with a first substantive discussion held
← Back to Privacy Law Directory