Compliance8 min read

AI and Data Protection in Austria: the DSG and the DSB

In Austria the GDPR and the national DSG both apply, overseen by the DSB. Use AI responsibly: legal basis, data minimisation and a data processing agreement.

By Alexis de ONYRI
Worried about your data? Anonymize it before AI

AI and data protection go together in Austria. The GDPR applies, plus the national Data Protection Act (DSG). The Data Protection Authority (DSB) is in charge of oversight. If you put personal data into an AI, you need a legal basis and you must keep data to a minimum. In short: AI is allowed, but only with clear rules.

GDPR and the DSG in Austria

Two layers apply in Austria at the same time. The GDPR is the European foundation. The national DSG completes it. According to the DSG, some points are spelled out in more detail.

  • The GDPR applies directly in every EU country, including Austria.
  • The DSG completes it, for example on data protection at work.
  • According to the DSG, staff owe a duty of data secrecy (§ 6 DSG).
  • In Austria, data protection even has constitutional rank under § 1 DSG (a fundamental right to data protection).
  • Both layers apply to AI use in parallel.

The Data Protection Authority (DSB)

The DSB is Austria's central supervisory authority. It watches over the GDPR and the DSG. When rules are broken, it can act.

  • The DSB is Austria's national data protection authority.
  • It reviews complaints from affected individuals.
  • It can open proceedings and impose GDPR fines.
  • It publishes decisions and guidance.
  • Companies should document their decisions and processing.

Legal basis and data minimisation

Every AI use needs a legal basis. Art. 6 GDPR lists the possible grounds. Art. 5 GDPR also requires data minimisation. According to OpenAI, business customers' inputs are not used to train its models by default. Check this in the current documentation all the same.

  • Every processing needs a legal basis under Art. 6 GDPR.
  • Art. 5 GDPR requires data minimisation: only what is needed.
  • You need a data processing agreement with the AI vendor (Art. 28).
  • Automated individual decisions are limited under Art. 22 GDPR.
  • Check whether the vendor uses your inputs for training.

What must not go into an open AI

Some data gets extra protection. Art. 9 GDPR lists these categories exhaustively. A simple name is not one of them.

  • Special categories under Art. 9 GDPR get extra protection.
  • They include health, origin, religion, biometrics and more.
  • A simple name or address does not fall under Art. 9.
  • Such sensitive data must not go into an open AI.
  • Reduce personal details before every prompt.

Practical steps for companies

Data protection for AI is easy to plan. A few fixed steps help in daily work. They also keep you ready to answer the DSB.

  1. 1Define the legal basis for each AI use.
  2. 2Sign a data processing agreement with the vendor.
  3. 3Minimise data: pseudonymise before sending.
  4. 4Document your decisions for the DSB.
  5. 5Train your team on handling AI.
Data typePut into an open AI?Recommendation
Name, phoneOnly minimisedPseudonymise before sending
Address, customer IDOnly if neededData minimisation (Art. 5)
Health, origin (Art. 9)NoNever in an open AI
API keys, passwordsNoRemove from the text
Internal strategyWith cautionCheck the legal basis
Public informationYesNo special risk

This is where a tool like ONYRI Sanitize helps. It detects sensitive data in your text and replaces it with reversible tokens before the text reaches the AI. The mapping table stays in your browser and is never sent to a server. After the reply, the real values are restored. Important and honest: this is pseudonymisation, not anonymisation. Pseudonymised data stays personal data (GDPR recital 26). ONYRI lowers your data exposure, but it replaces neither a data processing agreement nor a legal basis.

AI and data protection are not opposites in Austria. With the GDPR, the DSG and oversight by the DSB, the rules are clear. Minimise your data and document your decisions, and you use AI more safely.

Frequently asked questions

Does only the GDPR apply in Austria, or national law too?
Both. The GDPR applies directly, and the national DSG completes it. The supervisory authority in charge is the Data Protection Authority (DSB).
Am I allowed to put personal data into an AI?
Yes, but only with a legal basis under Art. 6 GDPR and as sparingly as possible. Sensitive data under Art. 9 must not go into an open AI.
What is the data secrecy duty in the DSG?
According to the DSG (§ 6), staff must keep personal data confidential. This duty adds to the general rules of the GDPR.
Does pseudonymisation make my AI use GDPR-compliant?
No. Pseudonymisation lowers the risk and supports data minimisation. But the data stays personal, and you still need a legal basis and a data processing agreement.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next