[codicts-css-switcher id=”346″]

Global Law Experts Logo
foi personal data austria

How to Respond to FOI Requests That Include Personal Data in Austria (2026), Step‑by‑step Guide for Public Bodies & Businesses

By Global Law Experts
– posted 43 minutes ago

FOI personal data Austria requests sit at the intersection of two legal regimes that frequently pull in opposite directions: the public’s right to official information and the individual’s right to have their personal data protected. Austria’s Freedom of Information Act (Informationsfreiheitsgesetz, IFG) was enacted in early 2024 and, following an implementation period, entered into force on 1 September 2025, replacing the former constitutional duty of official secrecy (Amtsgeheimnis) with a general right of access to information. Since then, public bodies and private organisations holding public-sector records have faced a marked rise in access requests that touch on third-party personal data.

In 2026, the Austrian Data Protection Authority (Datenschutzbehörde) has continued to emphasise sound procedure in how these mixed requests are handled. This practitioner guide sets out an auditable, stepwise workflow, with timelines, required documents, costs and templates, so that FOI officers and in-house counsel can produce defensible decisions under the GDPR and the Austrian Data Protection Act (Datenschutzgesetz, DSG).

1. Overview, FOI & personal data in Austria

Handling a foi personal data austria request begins with understanding the legal framework and how its component parts interact. Austria’s constitutional right of access to information now obliges federal, state and municipal bodies, and certain entities performing public functions, to disclose information on request, subject to defined exemptions. Where that information contains personal data, the data protection regime imposes an overlay of duties that cannot be ignored.

1.1 What is an FOI request in Austria?

An FOI request is a formal application, by any person, for access to information held by a body bound by the IFG. As a general rule the requester need not demonstrate a specific legal interest, and the body must respond within the statutory deadline. The right is anchored in the constitutional reform that amended Article 22a of the Federal Constitutional Law (B-VG) and is given effect by the IFG, whose text is available through the Austrian Legal Information System (RIS) and the materials published by the Austrian Parliament.

1.2 How FOI intersects with the GDPR and Austrian DSG

When an FOI request captures personal data, three instruments apply together. The GDPR (Regulation (EU) 2016/679) is the primary EU-level authority governing the processing of personal data, and disclosure to a requester is a form of processing that must have a lawful basis and respect the data minimisation principle. The Austrian Data Protection Act (DSG) supplements and, where permitted, derogates from the GDPR at national level, and contains provisions relevant to public bodies. The IFG provides the access right but expressly subordinates disclosure to the protection of personal data where an overriding interest exists.

The practical consequence is that a body cannot treat an FOI request as a mechanical duty to hand over documents. It must first screen for personal data, then assess whether disclosure is lawful under the GDPR and DSG, and only then decide whether to release, redact or refuse. Guidance from the Datenschutzbehörde and the European Data Protection Board (EDPB) on applying exemptions and balancing tests should inform every borderline decision. For a fuller treatment of the national regime, see our Austrian Data Protection Act (overview).

2. Eligibility, when FOI rules apply and what counts as personal data

Before processing a foi personal data austria request, establish two threshold questions: is your organisation bound by the FOI regime, and does the requested material contain personal data at all?

2.1 Who is subject to FOI (public bodies vs private bodies holding public records)

The IFG binds organs of the federation, the states (Länder) and municipalities, together with other bodies of self-administration and entities subject to audit by the Court of Audit (Rechnungshof). The obligation can also reach certain entities controlled by public bodies or performing public tasks, for example, state-run enterprises and municipally owned utilities. An entity that holds records generated in the course of a public function may therefore find itself answerable to an FOI request. Two recurring scenarios illustrate the point: a municipal council asked to disclose correspondence relating to a planning decision, and a public health body asked for records that inevitably contain patient or staff data. In both, the mixed FOI/GDPR analysis is unavoidable.

Note that the IFG contains thresholds and exceptions, including a proactive publication duty from which smaller municipalities are relieved, so the precise scope for any given body should be confirmed against the current IFG text.

2.2 What qualifies as personal data in FOI context

Personal data, under GDPR Article 4, means any information relating to an identified or identifiable natural person. In the FOI context this is broader than most FOI officers expect. It includes obvious identifiers such as names, addresses, email addresses and signatures, but also indirect identifiers, a job title combined with a department, a case reference tied to an individual, or metadata revealing who authored or received a document. Special category data (health, political opinions, trade-union membership) attracts heightened protection under GDPR Article 9 and the corresponding DSG provisions. When scoping a request, assume that most documents produced by or about individuals will contain personal data, and map accordingly.

3. Step‑by‑step process for handling a foi personal data austria request

This is the operational core of the guide. The workflow below converts the legal duties into a defensible, auditable sequence. Each step names the responsible role and the practical red flags to watch. The aim is a decision that can be reconstructed and justified months later if the Datenschutzbehörde or an appellate body asks how you reached it.

  1. Record & acknowledge receipt. The FOI officer or front office logs the request the moment it arrives, records the date and precise wording, and issues a written acknowledgement copied to the data protection officer (DPO) and legal. The acknowledgement should confirm the request was received, state the statutory response deadline, and time-stamp the file. This start date drives every downstream deadline, so accuracy is non-negotiable. Sample wording: “We confirm receipt of your request dated [date]. Under the Freedom of Information Act we will respond within the statutory period. If your request is unclear or voluminous we may contact you to narrow its scope.” Red flag: undated or informal requests received by email that are never entered into the case management system.
  2. Identify scope & personal data categories requested. The records custodian and FOI officer define exactly what is being asked for and run structured searches across the systems likely to hold responsive material, email archives, document management systems, case files and shared drives. Produce a search log recording which systems were searched and what was located. Simultaneously, classify the personal data found: ordinary identifiers, special category data, and third-party versus requester data. Red flag: relying on a single custodian’s memory rather than a documented, repeatable search.
  3. Legal screening: apply GDPR/DSG exceptions, the balancing test & IFG grounds. The DPO and legal counsel now assess whether the personal data can lawfully be disclosed. Disclosure to a public requester is processing that requires a lawful basis under the GDPR and must respect the DSG. The IFG permits withholding where the protection of personal data (or another protected interest) outweighs the public interest in disclosure. This calls for a documented balancing test: weigh the requester’s interest and the public interest in transparency against the affected individual’s reasonable expectation of privacy, the sensitivity of the data, and the consequences of release. Special category data under GDPR Article 9 will rarely survive the balance in favour of disclosure without a specific legal gateway. Relevant EDPB and Datenschutzbehörde guidance should be referenced in the decision memo. Red flag: treating the balancing test as a formality rather than a genuine, reasoned weighing recorded in writing.
  4. Consult third parties where required. Where the records contain identifiable third parties whose interests may be affected, legal or the DPO should consider notifying or consulting them before disclosure, giving them an opportunity to object. Consultation must itself respect confidentiality, do not reveal the requester’s identity or motive where that would compromise anyone. Set a clear internal deadline for responses so consultation does not derail the statutory timeline. Red flag: disclosing third-party correspondence without any attempt to consult the individuals concerned, then facing a complaint to the Datenschutzbehörde.
  5. Decide disclosure vs redaction vs refusal. A senior FOI decision-maker, with legal sign-off, resolves the outcome for each document. Three options exist: full disclosure; partial disclosure with redaction of personal data that cannot lawfully be released; or refusal where no meaningful disclosure is possible. Every redaction must be entered in a redaction log recording what was removed, why, and the legal basis (for example, protection of third-party personal data under the IFG read with the DSG). A refusal must be reasoned; where a request is refused in whole or in part, the requester may request a formal, appealable decision (Bescheid), so the reasoning and the applicable appeal route must be clear. Red flag: blanket refusals that fail to consider whether a redacted version could be released, a common criticism.
  6. Produce the disclosure package, metadata log & audit trail. The records team and IT assemble the final release, ensuring redactions are irreversible (flattened, not merely visually masked) and that hidden metadata revealing personal data is stripped. Version the disclosed set and preserve a master copy. Red flag: releasing PDFs where “redacted” text can be copied out, or documents whose metadata exposes authors and recipients.
  7. Notify the requester & (if required) third parties or the DPA. The FOI officer issues the response within the statutory deadline, releasing the package or serving the reasoned refusal. Where the handling of the request has itself caused an accidental personal data breach, for example an over-disclosure to the wrong recipient, the DPO assesses whether the incident meets the GDPR notification threshold and, if so, notifies the Datenschutzbehörde and any affected individuals within the applicable timelines. Red flag: discovering an over-disclosure and treating it as an internal matter rather than assessing the breach notification duty.

3.1 Step / responsible role / duration timeline

Step Action Responsible / Who Typical duration / SLA
1 Record & acknowledge receipt FOI officer / front office; copy to DPO & legal Acknowledge promptly (suggested internal SLA: 3 working days)
2 Scope identification & search scoping Records custodian(s) & FOI officer 1–5 working days depending on complexity
3 Legal screening (GDPR/DSG/IFG exceptions) DPO + legal counsel 3–7 working days (may require further information)
4 Third‑party consultation (if required) Legal / DPO / records 5–10 working days (notify third parties promptly)
5 Decision: disclose / redact / refuse Senior FOI decision-maker + legal sign-off Within statutory deadline (see Section 5)
6 Prepare disclosure package & redaction log Records team / IT / legal 1–7 working days (varies by volume)
7 Notify requester / issue refusal / notify DPA if breach FOI officer / DPO Within statutory response time; DPA notification per breach rules

The internal SLAs above are suggested good-practice targets, not statutory deadlines; the only binding limit is the IFG response period discussed in Section 5.

4. Required documents and records to prepare

A defensible foi personal data austria response is only as strong as the paper trail behind it. Because supervisory scrutiny frequently turns on procedural gaps, missing records, not necessarily wrong decisions, are often what turns a routine request into an enforcement finding. Maintain the following as standard for every mixed request.

Document / Record Purpose / Why kept Retention note
Acknowledgement of receipt (email/letter) Proof of request date & scope Keep for life of case + applicable retention
Scope mapping / search log Shows searches run & records located Preserve for audit / DPA queries
Redaction log (what, why, legal basis) Evidence of redaction decisions & permissible grounds Required for internal & DPA review
Decision memo (balancing test) Explains legal reasoning to disclose/refuse Signed by decision-maker
Third-party consultation records Evidence of consultation & responses Keep for audit
Final disclosure package (copies) Records exactly what was disclosed (versioned) Archive securely
Refusal decision (Bescheid) & reasoning Explains legal basis & appeal routes if withholding Keep for applicable period
DPA notification (if breach) Proof of notification to the DPA if disclosure was a breach Follow DSG/GDPR timelines
Internal SLA & case file index Internal control & training material Retain for governance

5. Timeline & deadlines, statutory limits and internal SLAs

Deadlines are where good intentions unravel. The statutory clock for a foi personal data austria request runs from receipt, and the internal SLAs in the timeline table above are designed to leave headroom before that statutory limit is reached.

5.1 Public authority response time for FOI requests with personal data

Under the IFG, a bound body must grant or refuse access without undue delay and, at the latest, within the period fixed by the Act, which runs from receipt of a sufficiently specific request. The IFG provides for a maximum period, and where access is not granted the body must, on request, issue a formal decision. Where the request captures personal data, the deadline does not stop running merely because a balancing test or third-party consultation is required, which is precisely why the legal screening and consultation steps must begin immediately, not after the scope search is complete.

Because the exact number of weeks and any permitted extension are the single most audited element of the process, confirm them against the current IFG text held in RIS before every decision.

5.2 Extensions, urgent requests and clock‑stopping events

Where a request is exceptionally voluminous or complex, the IFG permits a limited extension, which must be communicated to the requester in writing, with reasons, before the original deadline expires. A genuinely unclear request may be paused while the body seeks clarification, but the pause must be documented and the requester promptly contacted. Do not use clarification requests as a delaying tactic; unjustified extensions are a recognised procedural failing.

6. Costs & fees

Cost recovery for FOI in Austria is constrained, and any charge must have a lawful basis. Under the IFG access to information is, as a rule, provided free of charge, though general administrative fee rules (for example under the Fees Act, Gebührengesetz) may apply to certain formal steps. Track internal effort in any event, both for budgeting and to justify any cost-related decision if a request is genuinely excessive.

Cost type Typical items included Example / Guidance
Statutory fees (if any) Any government-prescribed administrative charges Check the IFG and general fee rules, core FOI access is generally free of charge
Internal processing costs Staff hours (records search, redaction, legal review), IT export costs Record hourly effort for budgeting
Third-party costs Translation, notarisation, external legal advice Seek prior approval for material costs
Voluminous disclosure handling Large dataset extraction, anonymisation or secure transfer Consider staged disclosure to manage cost and risk
Cost-recovery policy Internal policy governing excessive requests Must align with Austrian law and be applied consistently

7. What changed in 2025–2026, enforcement and reporting trends to watch

The introduction of a general access right in Austria in September 2025, followed by its first year of operation, has reshaped the risk landscape for anyone handling a foi personal data austria request. Bodies that previously relied on official secrecy now face a steady flow of requests, and the Datenschutzbehörde continues to stress sound procedure.

7.1 Austrian DPA enforcement focus & common findings

Enforcement and guidance activity of the Datenschutzbehörde has consistently emphasised procedural rigour. Recurring problem areas in mixed FOI/data-protection matters include: absent or inadequate balancing-test documentation; over-disclosure of third-party personal data through defective redaction; failure to consult affected individuals; and delayed or unassessed breach notifications following accidental disclosures. A missing decision memo or search log is far easier for a supervisory authority to establish than a contestable judgement call on the merits, so bodies with a documented, repeatable workflow tend to fare markedly better under scrutiny than those relying on ad hoc judgement. The authority’s annual reports, published via its website, remain the best source for current enforcement priorities.

7.2 Practical implications for public bodies and private holders of public records

The message for both public authorities and entities holding public-sector records is to institutionalise the process now: adopt standard templates, mandate the balancing-test memo for every mixed request, and rehearse the breach-notification decision so that an over-disclosure is caught and assessed within hours, not days. Broader government data protection expectations, illustrated by published guidance such as that of the Federal Ministry of Finance, reinforce the same governance-first posture.

8. Common pitfalls & how to avoid them

Most enforcement exposure in a foi personal data austria matter traces back to a handful of avoidable errors. Address each before the next request arrives.

  • Poor recordkeeping and missing audit trails. The most common failing is the inability to reconstruct a decision after the fact, no search log, no dated acknowledgement, no signed balancing memo. Where scrutiny is procedural, absence of documentation is itself the finding. Fix: make the required-documents table mandatory for every mixed request and audit case files quarterly.
  • Over-disclosure versus unnecessary refusals. Two opposite errors carry equal risk. Over-disclosure releases third-party personal data unlawfully; blanket refusal denies legitimate access and invites successful appeal. Fix: default to partial disclosure with reasoned redaction, and record why a redacted version was or was not possible.
  • Failing to consult third parties or ignoring sector-specific rules. Releasing correspondence, health records or procurement submissions without consulting affected individuals, or without applying sectoral confidentiality rules, is a frequent source of complaints. Fix: build a mandatory consultation checkpoint into the workflow and identify which sectoral rules (for example health or commercial confidentiality) apply before deciding.

9. Comparison: FOI disclosure vs GDPR subject access request

FOI officers often conflate an FOI request with a GDPR subject access request (SAR). They are legally distinct, and misclassifying one as the other produces the wrong outcome. The table below sets out the differences that matter in practice.

Aspect FOI disclosure GDPR subject access request (SAR)
Purpose Public access to official information Data subject access to their own personal data
Recipient Any requester (public) Identified data subject (or authorised representative)
Legal basis IFG / sectoral FOI rules; public interest in transparency GDPR Article 15 (data subject right)
Exemptions Protection of personal data, national security, commercial secrets and other IFG grounds Limited where disclosure would adversely affect the rights of others or another exemption applies
Timelines Statutory FOI period (see Section 5) One month, extendable by up to two further months under GDPR Article 12(3)
Outcome May include third-party personal data unless exempt Discloses the requester’s own personal data, subject to the rights of others

The key operational lesson: an FOI request from a member of the public who happens to seek information about themselves is not automatically a SAR, and vice versa. Where a single incoming request could be read either way, log both possibilities, apply the more protective analysis to third-party data, and confirm the requester’s intent before releasing.

10. Quick templates & checklist

Standardised templates reduce error and speed compliant handling of every foi personal data austria request. The core set comprises a refusal decision, a redaction log, and a balancing-test memo. Each should be adopted only after legal review, because the wording of a refusal and the legal basis cited in a redaction log carry appeal and enforcement consequences.

  • Redaction log template. Captures each redaction, its location, the reason and the legal basis.
  • Refusal decision sample. States the reasoned grounds and the requester’s appeal routes.
  • Balancing test memo template. Records the weighing of transparency against privacy for the file.

Conclusion & next steps

Handling a foi personal data austria request well is a matter of disciplined process, not improvisation: log promptly, screen against the GDPR and DSG, document the balancing test, consult where required, redact irreversibly, and meet the statutory deadline. With the Datenschutzbehörde focused on procedural rigour, an auditable workflow is the single best protection against enforcement. Public bodies and private holders of public-sector records that adopt the steps, tables and templates in this guide will be well placed to respond defensibly to every access request that touches personal data.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact János Böszörményi at Schönherr Rechtsanwälte GmbH (‘Schoenherr’), a member of the Global Law Experts network.

Sources

  1. Austrian Data Protection Authority (Datenschutzbehörde)
  2. Federal Ministry of Finance, Data Protection
  3. GDPR (Regulation (EU) 2016/679), EUR-Lex
  4. Austrian Legal Information System (RIS)
  5. Austrian Parliament, Federal legislation
  6. European Data Protection Board (EDPB)

FAQs

How long does a public authority have to respond to an FOI request that contains personal data in Austria?
The IFG fixes a statutory response period that runs from receipt of a sufficiently specific request, with a limited extension available for voluminous or complex cases if the requester is notified in writing with reasons before the original deadline. The presence of personal data does not pause the clock, so legal screening and any third-party consultation must start immediately. Confirm the exact period against the current IFG text in RIS.
Personal data may be withheld where its protection outweighs the public interest in disclosure, applying a documented balancing test under the IFG read with the GDPR and DSG. Special category data under GDPR Article 9 will rarely be disclosable without a specific legal gateway. Relevant EDPB and Datenschutzbehörde guidance should inform borderline decisions.
Follow the workflow in Section 3: acknowledge and log the request, scope and classify the personal data, run the legal screening and balancing test, consult affected third parties where required, decide between disclosure, redaction or refusal, prepare the package with a redaction log, and notify the requester within the statutory deadline. Keep every step documented.
If an over-disclosure or misdirected release meets the GDPR breach notification threshold, the DPO must assess and, where required, notify the Datenschutzbehörde, under GDPR Article 33, without undue delay and where feasible not later than 72 hours after becoming aware of the breach, and inform affected individuals where the breach is likely to result in a high risk to their rights. Assess every accidental disclosure against this threshold rather than treating it as an internal matter.
Not automatically. Staff correspondence engages the employees’ privacy and, potentially, sectoral or workplace confidentiality. A likely outcome after a balancing test is partial disclosure with redaction of personal identifiers, or refusal where the content is inseparable from protected personal data. Each item must be assessed on its facts and the reasoning recorded.
Retain the full set in the Section 4 table: the dated acknowledgement, search log, redaction log, signed balancing-test memo, third-party consultation records, versioned copies of what was disclosed, any refusal decision, and any DPA breach notification. This is the evidence the Datenschutzbehörde will expect to see if it reviews the file.
vc due diligence india
By Global Law Experts

posted 3 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Respond to FOI Requests That Include Personal Data in Austria (2026), Step‑by‑step Guide for Public Bodies & Businesses

Send welcome message

Custom Message