Austria
NSA Tier B partner tied into the EU’s Europol, Schengen and Prüm data systems and the Council of Europe assistance conventions, whose own intelligence service proved so porous that Club de Berne auditors judged its shared network hackable by moderately skilled attackers
Overview
EU Member State: Austria is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page. This page covers national laws, intelligence and surveillance, and Austria’s role in international data sharing.
Austria’s privacy landscape is defined less by its domestic statute than by the alliances its intelligence services join and the routes its data takes out of the country. Austria is an NSA Tier B partner under “Focused Cooperation” and participates in the CROSSHAIR high-frequency direction-finding network as one of sixteen Third Party countries; unlike Five Eyes members, Third Party partners can be and are targeted by NSA collection. Its domestic service, the DSN (successor to the scandal-hit BVT), belongs to the Club de Berne and its Counter-Terrorism Group. Because Austria is landlocked with no submarine cable landings, effectively all of its international traffic transits neighbouring states, primarily through DE-CIX Frankfurt where Germany’s BND conducts bulk cable interception, so Austrian data routinely loses domestic legal protection the moment it crosses the border.[3][9][15]
Austria’s outward data-sharing runs through its alliances and treaties, each detailed below. It is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks (an original 2005 Prüm signatory) and to Europol, was one of seven member states that initiated the European Investigation Order, and holds a bilateral mutual legal assistance treaty with the United States. These are the channels through which the domestic protections described below are, in practice, bypassed.[22][23][24][25][26]
International Data Sharing Agreements
Despite constitutional neutrality and strong DSG protections, Austria participates in extensive intelligence and law enforcement data sharing, and its internet transit infrastructure creates additional involuntary exposure.
Mutual Legal Assistance: Layered Framework
EU Member States (26 countries): The EU Convention on Mutual Assistance in Criminal Matters (2000) and the Schengen Convention provide the primary MLA framework. Austria was one of seven initiating member states that proposed the European Investigation Order (EIO) directive in April 2010, enabling binding cross-border evidence requests across the EU.[17]
European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols apply between Austria and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[22]
Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Austria is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[23]
Bilateral MLAT with the United States: Signed February 23, 1995, entered into force August 1, 1998. Covers testimony, searches, and evidence transfers. Austria’s Tier B SIGINT relationship with the NSA operates alongside but outside this formal legal assistance framework. Beyond the US, Austria’s bilateral treaties are published in the Federal Legal Information System (RIS): the Bundesrecht database (filter to the “Staatsverträge” / state-treaties collection).[18]
Intelligence Sharing
Club de Berne and CTG: Austria’s DSN participates in the Club de Berne and its Counter-Terrorism Group. The Club de Berne keeps no public roster; it is reported to comprise the intelligence services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland, with the United Kingdom also reported as a member; the CTG comprises the same services plus the United Kingdom. The BVT scandal and Poseidon vulnerability raised concerns about the security of shared intelligence held in Austria.[9][27]
NSA Tier B: Austria’s bilateral SIGINT relationship includes the CROSSHAIR network and Königswarte listening station cooperation.[3]
Neutrality Paradox
Austria is constitutionally neutral (1955 Federal Constitutional Law on Neutrality) and not a NATO member, participating only in NATO’s Partnership for Peace. This creates a paradox: Austria cooperates with the NSA bilaterally as a Tier B partner while remaining outside NATO intelligence structures that most EU neighbours use.[8]
EU Law Enforcement Cooperation
SIS II: Real-time query and alert sharing across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[24] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange; Austria was an original 2005 Prüm signatory, and the framework now binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[25] EU-US Umbrella Agreement: Judicial redress for Austrian citizens before US courts. SWIFT/TFTP: International wire transfers subject to US Treasury subpoena. PNR: Passenger data shared for US-bound flights.
Europol
As an EU member state, Austria is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Austrian person data flowing through Europol is reachable onward.[26]
Cross-Border Police Cooperation
Bilateral police cooperation with Germany and a trilateral agreement with Switzerland and Liechtenstein (2012) covering joint patrols, information exchange, and cross-border hot pursuit. Austria’s position in the data flow chain means Liechtenstein’s internet traffic transits through Austria onward after Switzerland.[19]
The Privacy Backdoor Effect
Despite constitutional data protection and DSB GDPR enforcement, alternative pathways exist for accessing Austrian person data:
- DE-CIX Transit / BND: Austrian traffic routinely transits DE-CIX Frankfurt where BND conducts bulk cable interception. Data loses domestic legal protection upon crossing the German border
- NSA Tier B: Bilateral SIGINT sharing about Austrian persons outside GDPR-compatible frameworks
- Club de Berne / EU INTCEN: DSN intelligence shared among the Club de Berne services (27 EU states plus Norway and Switzerland, UK reported) outside any GDPR framework
- EU Framework Sharing: Austrian person data in SIS II, Prüm, or EIO channels accessible to 27 EU states and through Europol to US FBI
- MLAT/CoE Conventions: the US, the 51 parties to the 1959 Convention and the 82 parties to the Budapest Convention can request data through MLA channels
- SWIFT/PNR: Financial transactions and air travel data subject to US access
Conversely, foreign nationals whose communications transit Austrian networks are subject to DSN collection under the SNG without GDPR protection (Article 2(2) national security exemption).
Surveillance and Intelligence
Intelligence Agencies
The DSN (Direktion Staatsschutz und Nachrichtendienst) is Austria’s domestic intelligence and state protection agency, formed December 2021 under the SNG to replace the discredited BVT. The HNA (Heeresnachrichtenamt) is the military intelligence service, operating the Königswarte SIGINT station in Lower Austria. Austria has no foreign civilian intelligence service: foreign intelligence is split between the HNA (military) and DSN (security-related).[8]
BVT Scandal (2018–2021)
On February 28, 2018, police raided BVT headquarters, seizing files and hard drives, potentially exposing shared European intelligence. In February 2019, the Club de Berne dispatched its “Soteria” team to audit the BVT. The classified report (leaked to Austrian media November 11, 2019) found that moderately talented hackers could use the BVT’s network to penetrate “Poseidon,” the Club de Berne’s shared IT network. The leak itself became the biggest breach in Club de Berne history. A related Russian espionage case (retired Colonel Martin M., arrested November 2018 for ~20 years of GRU spying) further eroded partner confidence and contributed to the BVT’s dissolution.[9][10][11]
Bundestrojaner (State Spyware)
On July 9, 2025, parliament authorised DSN deployment of state spyware to intercept encrypted communications (WhatsApp, Signal) by a 105–71 vote. Deployment is permitted even against individuals not suspected of any crime (if other methods are exhausted), requires Federal Administrative Court approval, and is capped at 25–30 annual cases. Deployment expected 2027. This is Austria’s second attempt: on December 11, 2019, the Constitutional Court struck down an identical law, ruling it violated Article 8 ECHR, Section 1 DSG, and Article 9 Staatsgrundgesetz, holding that computer infiltration differs fundamentally from traditional wiretapping because it provides insight into all areas of life. Civil society organisations have promised legal challenges to the new law.[2][12]
NSA Tier B Cooperation
Austria is classified as an NSA Tier B partner under “Focused Cooperation” (disclosed via Snowden documents, published by El Mundo October 30, 2013). Austria participates in the CROSSHAIR worldwide High Frequency Direction-Finding (HFDF) network, listed among 16 Third Party countries. Unlike Five Eyes members, Third Party partners can be and are targeted by NSA collection.[3]
Internet Infrastructure and Transit Exposure
The Vienna Internet Exchange (VIX) is Austria’s primary IXP. As a landlocked country with no submarine cable landings, all international traffic transits through neighbouring states, primarily westward through Germany via DE-CIX Frankfurt.[13]
The BND has intercepted DE-CIX traffic since 2009. Austrian politician Peter Pilz accused the BND and Deutsche Telekom of tapping a telecommunications line between Luxembourg and Vienna, with evidence that lines between Amsterdam, Stockholm, Dublin, Moscow, and Vienna were likely intercepted. Austrian data also transits Swiss exchange points where the NDB conducts cable reconnaissance.[14][15]
Recent Developments
Constitutional Challenge to Messenger Surveillance Heard (June 22, 2026)
The challenge civil society promised against the 2025 messenger-surveillance law has been brought, and the Constitutional Court has heard it. Sixty-seven members of the National Council, from the FPÖ and Green parliamentary groups, applied to have the power introduced in July 2025 struck down as unconstitutional. The provision at issue is § 11(1)(9) of the State Protection and Intelligence Service Act (SNG), which authorises the monitoring of electronic messages for extended threat investigation and preventive protection against constitution-endangering attacks on reasonable suspicion, including “by introducing a program into a computer system of the person concerned by technical means.” The VfGH held a public oral hearing on June 22, 2026 in case G 13-14/2026.[29]
The applicants advance three arguments, and the first is a supply-chain point rather than a purely domestic one: Austrian authorities cannot build this software themselves, so it must be bought, which means the data to be analysed can end up in the hands of foreign vendors. Second, a technically powerful instrument of this kind carries enormous potential for abuse. Third, the software cannot monitor individual messages, so the mere possibility of being continuously and secretly monitored across the whole of one’s electronic communication is said to change the population’s communication behaviour, a chilling-effect argument rather than a claim about any particular interception. On that basis the new power is said to breach the constitutional right to data protection just as its 2019 predecessor did, which the same court struck down. Counsel for the applicants, Michael Rohregger, argued that little of substance has changed since that ruling; the federal government defends the measure as necessary for the prevention of danger. The Court continued its deliberations after the hearing and a decision is not expected before the autumn, which places it ahead of the law’s expected 2027 deployment.[29]
Asylum Seekers’ Phones Also before the Constitutional Court (G 16/2026)
A second data-seizure case is running in parallel. Under the BFA-Verfahrensgesetz, public security officers may seize the data carriers of asylum applicants, mobile phones included, and analyse the data stored on them where identity or travel route cannot be established by other means. Hearing a complaint against such an order, the Federal Administrative Court referred the provisions to the VfGH as unconstitutional, arguing that the statute contains no adequate guarantees for the confidentiality interests of the person concerned and does not regulate with sufficient clarity when a phone may be seized at all. The referral expressly invokes the reasoning by which the VfGH struck down the equivalent data-carrier seizure provisions in criminal investigations in 2023. The case was listed for deliberation in the same June 2026 sitting as the messenger-surveillance challenge.[30]
Under-14 Social Media Ban: Agreement, then Draft (March–July 2026)
The governing coalition agreed a compulsory minimum age of 14 for social media on March 27, 2026, after weeks of negotiation between the ÖVP, SPÖ and NEOS, with the ban originally intended to take effect in September 2026, the start of the 2026/27 school year. The draft was due by the end of June and did not appear then. It was published on July 27; the measure itself remains pending legislation and is listed below.[20][21]
Draft published July 27, 2026. The bill went into Begutachtung (public review) and simultaneously to the European Commission for notification on July 27, 2026, with entry into force now targeted at January 1, 2027 rather than September 2026. It works by amending the Audiovisual Media Services Act (AMD-G). Rather than naming services, it defines the ban by addictive design features: recommender algorithms serving predominantly strangers’ content, endless scrolling or autoplay, reward systems for continuous use, and push notifications when the user stops. TikTok, Instagram, YouTube and Snapchat are the named examples; platforms may still offer child-appropriate areas, and messenger services such as WhatsApp are excluded. Very large platforms face fines of up to 6% of global annual turnover.
The verification design is what makes this page’s counterexample. The draft specifies a double-blind model using privacy-enhancing technologies, principally zero-knowledge proofs: the platform receives only an age predicate (“14 or older: true”), never a name or date of birth, and the issuer of the age credential cannot see where or when a proof was used. Cryptographic measures are specified to prevent uses of the same credential at different sites from being linked to each other or to a person. Release is local and deliberate, and the user must be able to see which age threshold is being sent, for what purpose, and to which platform. Verification is once per account at creation, with existing accounts checked at entry into force; anonymous use without an account may require repeated verification. ID Austria is offered as one route but is explicitly not mandatory, and because the design tracks the EU Age Verification Blueprint it is intended to carry over to the EUDI wallet. State Secretary Alexander Pröll: “The protection of our children must not come at the cost of privacy.” Set against the identity-document and facial-estimation models being built in the United Kingdom and Australia, this is the strongest form of the argument that age assurance need not mean identification, and the question worth following is whether the deployed system matches the drafted one.[28]
Data Protection Authority Activity Report 2025 (May 11, 2026)
The DSB’s report for 2025 was laid before Parliament, and the numbers show an authority absorbing a sharply rising caseload on a shrinking budget. Complaint intake rose from 3,019 in 2024 to 5,300 in 2025, while concluded individual complaints rose from 2,397 to 3,403. The DSB also received 1,364 cross-border complaints within Austria and 173 from abroad, opened 225 ex officio review procedures and 127 administrative penal procedures, and logged 1,855 security-breach notifications (2024: 1,319), of which 1,704 were national GDPR data breaches, a large share of them hacking and ransomware incidents. It was simultaneously party to 453 proceedings before the Federal Administrative Court, 126 before the Administrative Court, and seven before the Constitutional Court.[31]
Two observations from the head of the authority, Matthias Schmidl, are worth recording. The first is a new drain on capacity: a volume of complaints generated with the help of AI, which he says ties up considerable resources. The second is a warning. After the 2025 budget cuts, and with the Freedom of Information Act, the AI Act, the political-advertising transparency regulation, the proposed Digital Omnibus reform of the GDPR, and cooperation with the new parliamentary data protection committee all landing on the same desk, Schmidl states that without additional budget and staff the DSB will not be able to manage the tasks coming to it. The authority has separately put concrete proposals to the Justice Ministry for a procedural amendment to the Data Protection Act, intended to speed proceedings up and, in specific places, to lengthen limitation periods so that cases can be run properly; a first substantive discussion has taken place. Set against the constitutional right to data protection Austria has held since 1978, the constraint is not on the right but on the body that enforces it.[31][4]
Privacy Framework
The Datenschutzbehoerde (DSB) is Austria’s independent supervisory authority, replacing the former Datenschutzkommission on January 1, 2014. The DSB issued the first EU ruling that Google Analytics violated GDPR by transferring data to the US (January 2022), triggering parallel rulings across Europe. However, the DSB faces severe resourcing constraints: beginning July 2025, budget pressure (EUR 6.1M in 2025, EUR 5.9M in 2026) forced elimination of ~20 intern positions, restricted ex officio investigations, and curtailed public access, even as new responsibilities (Freedom of Information Act, AI Act, political advertising) were added. noyb filed a complaint with the European Commission about these deficiencies.[1][4][5]
The DSG supplements the GDPR with national provisions. Section 1 provides a constitutional fundamental right to data protection (Verfassungsbestimmung), predating the GDPR by four decades. Austria is home to noyb (None of Your Business), Max Schrems’s organisation whose litigation produced the Schrems I and Schrems II CJEU rulings that invalidated two successive EU-US data-transfer frameworks.[1] The StPO (Code of Criminal Procedure, Sections 134ff) governs lawful interception requiring judicial orders for offences over one year. The SPG (Security Police Act) authorises police metadata access. The SNG (State Protection and Intelligence Service Act, December 2021) provides the DSN’s legal basis.[6][7]
Data Retention
On June 27, 2014, the Constitutional Court struck down Austria’s data retention law as disproportionate and unconstitutional. Austria has not enacted replacement legislation. Telecom providers retain traffic data only as needed for billing/service provision. Law enforcement can still obtain real-time interception orders and access subscriber data under the StPO.[16]
Pending Legislation
- Messenger surveillance (Bundestrojaner) implementation: the messenger-surveillance law enacted in 2025 (amending the State Protection and Intelligence Service Act, Security Police Act, and Telecommunications Act) is being operationalised, with case-by-case Federal Administrative Court approval; the constitutional challenge is no longer merely expected: 67 FPÖ and Green members of the National Council have brought one, the VfGH heard it on June 22, 2026 in case G 13-14/2026, and a decision is not expected before the autumn (see Recent Developments above). The 2019 Constitutional Court strike-down of an earlier version is the direct precedent.[12][29]
- DSB resourcing / structural reform (oversight): epicenter.works and noyb have filed a complaint with the European Commission over the Datenschutzbehörde’s underfunding (53 staff for 9 million people); any remedy would require budgetary or structural legislation.
- EU AI Act national implementation: Austria must designate AI market-surveillance authorities and adapt the DSG framework; implementing legislation is pending.
- Data retention: Austria has no general retention regime (struck down in 2014); quick-freeze and targeted-retention proposals continue to be debated in light of CJEU case law.
- Under-14 social media ban: in March 2026 the governing coalition (Vice-Chancellor Andreas Babler of the SPÖ) announced a compulsory minimum age of 14 for social media use, with draft legislation to be prepared by the end of June 2026. The government says it will rely on “technically modern,” privacy-respecting age-verification methods, and would designate covered platforms by how addictive their algorithms are and whether they carry content such as “sexualised violence” rather than naming services. The plan, paired with expanded media-literacy and AI education in schools, follows the EU age-verification blueprint debate and similar moves in Australia, Denmark, Greece, Spain, and France. The agreement was reached on March 27, 2026 after weeks of negotiation between the ÖVP, SPÖ and NEOS, and the original target was September 2026. The draft went into Begutachtung on July 27, 2026 with entry into force now targeted at January 1, 2027; the design, including the double-blind zero-knowledge age check, is described under Recent Developments above. It is not yet law.[20][21][28]
