Our Expert in Austria
No results available
FOI personal data Austria requests sit at the intersection of two legal regimes that frequently pull in opposite directions: the public’s right to official information and the individual’s right to have their personal data protected. Austria’s Freedom of Information Act (Informationsfreiheitsgesetz, IFG) was enacted in early 2024 and, following an implementation period, entered into force on 1 September 2025, replacing the former constitutional duty of official secrecy (Amtsgeheimnis) with a general right of access to information. Since then, public bodies and private organisations holding public-sector records have faced a marked rise in access requests that touch on third-party personal data.
In 2026, the Austrian Data Protection Authority (Datenschutzbehörde) has continued to emphasise sound procedure in how these mixed requests are handled. This practitioner guide sets out an auditable, stepwise workflow, with timelines, required documents, costs and templates, so that FOI officers and in-house counsel can produce defensible decisions under the GDPR and the Austrian Data Protection Act (Datenschutzgesetz, DSG).
Handling a foi personal data austria request begins with understanding the legal framework and how its component parts interact. Austria’s constitutional right of access to information now obliges federal, state and municipal bodies, and certain entities performing public functions, to disclose information on request, subject to defined exemptions. Where that information contains personal data, the data protection regime imposes an overlay of duties that cannot be ignored.
An FOI request is a formal application, by any person, for access to information held by a body bound by the IFG. As a general rule the requester need not demonstrate a specific legal interest, and the body must respond within the statutory deadline. The right is anchored in the constitutional reform that amended Article 22a of the Federal Constitutional Law (B-VG) and is given effect by the IFG, whose text is available through the Austrian Legal Information System (RIS) and the materials published by the Austrian Parliament.
When an FOI request captures personal data, three instruments apply together. The GDPR (Regulation (EU) 2016/679) is the primary EU-level authority governing the processing of personal data, and disclosure to a requester is a form of processing that must have a lawful basis and respect the data minimisation principle. The Austrian Data Protection Act (DSG) supplements and, where permitted, derogates from the GDPR at national level, and contains provisions relevant to public bodies. The IFG provides the access right but expressly subordinates disclosure to the protection of personal data where an overriding interest exists.
The practical consequence is that a body cannot treat an FOI request as a mechanical duty to hand over documents. It must first screen for personal data, then assess whether disclosure is lawful under the GDPR and DSG, and only then decide whether to release, redact or refuse. Guidance from the Datenschutzbehörde and the European Data Protection Board (EDPB) on applying exemptions and balancing tests should inform every borderline decision. For a fuller treatment of the national regime, see our Austrian Data Protection Act (overview).
Before processing a foi personal data austria request, establish two threshold questions: is your organisation bound by the FOI regime, and does the requested material contain personal data at all?
The IFG binds organs of the federation, the states (Länder) and municipalities, together with other bodies of self-administration and entities subject to audit by the Court of Audit (Rechnungshof). The obligation can also reach certain entities controlled by public bodies or performing public tasks, for example, state-run enterprises and municipally owned utilities. An entity that holds records generated in the course of a public function may therefore find itself answerable to an FOI request. Two recurring scenarios illustrate the point: a municipal council asked to disclose correspondence relating to a planning decision, and a public health body asked for records that inevitably contain patient or staff data. In both, the mixed FOI/GDPR analysis is unavoidable.
Note that the IFG contains thresholds and exceptions, including a proactive publication duty from which smaller municipalities are relieved, so the precise scope for any given body should be confirmed against the current IFG text.
Personal data, under GDPR Article 4, means any information relating to an identified or identifiable natural person. In the FOI context this is broader than most FOI officers expect. It includes obvious identifiers such as names, addresses, email addresses and signatures, but also indirect identifiers, a job title combined with a department, a case reference tied to an individual, or metadata revealing who authored or received a document. Special category data (health, political opinions, trade-union membership) attracts heightened protection under GDPR Article 9 and the corresponding DSG provisions. When scoping a request, assume that most documents produced by or about individuals will contain personal data, and map accordingly.
This is the operational core of the guide. The workflow below converts the legal duties into a defensible, auditable sequence. Each step names the responsible role and the practical red flags to watch. The aim is a decision that can be reconstructed and justified months later if the Datenschutzbehörde or an appellate body asks how you reached it.
| Step | Action | Responsible / Who | Typical duration / SLA |
|---|---|---|---|
| 1 | Record & acknowledge receipt | FOI officer / front office; copy to DPO & legal | Acknowledge promptly (suggested internal SLA: 3 working days) |
| 2 | Scope identification & search scoping | Records custodian(s) & FOI officer | 1–5 working days depending on complexity |
| 3 | Legal screening (GDPR/DSG/IFG exceptions) | DPO + legal counsel | 3–7 working days (may require further information) |
| 4 | Third‑party consultation (if required) | Legal / DPO / records | 5–10 working days (notify third parties promptly) |
| 5 | Decision: disclose / redact / refuse | Senior FOI decision-maker + legal sign-off | Within statutory deadline (see Section 5) |
| 6 | Prepare disclosure package & redaction log | Records team / IT / legal | 1–7 working days (varies by volume) |
| 7 | Notify requester / issue refusal / notify DPA if breach | FOI officer / DPO | Within statutory response time; DPA notification per breach rules |
The internal SLAs above are suggested good-practice targets, not statutory deadlines; the only binding limit is the IFG response period discussed in Section 5.
A defensible foi personal data austria response is only as strong as the paper trail behind it. Because supervisory scrutiny frequently turns on procedural gaps, missing records, not necessarily wrong decisions, are often what turns a routine request into an enforcement finding. Maintain the following as standard for every mixed request.
| Document / Record | Purpose / Why kept | Retention note |
|---|---|---|
| Acknowledgement of receipt (email/letter) | Proof of request date & scope | Keep for life of case + applicable retention |
| Scope mapping / search log | Shows searches run & records located | Preserve for audit / DPA queries |
| Redaction log (what, why, legal basis) | Evidence of redaction decisions & permissible grounds | Required for internal & DPA review |
| Decision memo (balancing test) | Explains legal reasoning to disclose/refuse | Signed by decision-maker |
| Third-party consultation records | Evidence of consultation & responses | Keep for audit |
| Final disclosure package (copies) | Records exactly what was disclosed (versioned) | Archive securely |
| Refusal decision (Bescheid) & reasoning | Explains legal basis & appeal routes if withholding | Keep for applicable period |
| DPA notification (if breach) | Proof of notification to the DPA if disclosure was a breach | Follow DSG/GDPR timelines |
| Internal SLA & case file index | Internal control & training material | Retain for governance |
Deadlines are where good intentions unravel. The statutory clock for a foi personal data austria request runs from receipt, and the internal SLAs in the timeline table above are designed to leave headroom before that statutory limit is reached.
Under the IFG, a bound body must grant or refuse access without undue delay and, at the latest, within the period fixed by the Act, which runs from receipt of a sufficiently specific request. The IFG provides for a maximum period, and where access is not granted the body must, on request, issue a formal decision. Where the request captures personal data, the deadline does not stop running merely because a balancing test or third-party consultation is required, which is precisely why the legal screening and consultation steps must begin immediately, not after the scope search is complete.
Because the exact number of weeks and any permitted extension are the single most audited element of the process, confirm them against the current IFG text held in RIS before every decision.
Where a request is exceptionally voluminous or complex, the IFG permits a limited extension, which must be communicated to the requester in writing, with reasons, before the original deadline expires. A genuinely unclear request may be paused while the body seeks clarification, but the pause must be documented and the requester promptly contacted. Do not use clarification requests as a delaying tactic; unjustified extensions are a recognised procedural failing.
Cost recovery for FOI in Austria is constrained, and any charge must have a lawful basis. Under the IFG access to information is, as a rule, provided free of charge, though general administrative fee rules (for example under the Fees Act, Gebührengesetz) may apply to certain formal steps. Track internal effort in any event, both for budgeting and to justify any cost-related decision if a request is genuinely excessive.
| Cost type | Typical items included | Example / Guidance |
|---|---|---|
| Statutory fees (if any) | Any government-prescribed administrative charges | Check the IFG and general fee rules, core FOI access is generally free of charge |
| Internal processing costs | Staff hours (records search, redaction, legal review), IT export costs | Record hourly effort for budgeting |
| Third-party costs | Translation, notarisation, external legal advice | Seek prior approval for material costs |
| Voluminous disclosure handling | Large dataset extraction, anonymisation or secure transfer | Consider staged disclosure to manage cost and risk |
| Cost-recovery policy | Internal policy governing excessive requests | Must align with Austrian law and be applied consistently |
The introduction of a general access right in Austria in September 2025, followed by its first year of operation, has reshaped the risk landscape for anyone handling a foi personal data austria request. Bodies that previously relied on official secrecy now face a steady flow of requests, and the Datenschutzbehörde continues to stress sound procedure.
Enforcement and guidance activity of the Datenschutzbehörde has consistently emphasised procedural rigour. Recurring problem areas in mixed FOI/data-protection matters include: absent or inadequate balancing-test documentation; over-disclosure of third-party personal data through defective redaction; failure to consult affected individuals; and delayed or unassessed breach notifications following accidental disclosures. A missing decision memo or search log is far easier for a supervisory authority to establish than a contestable judgement call on the merits, so bodies with a documented, repeatable workflow tend to fare markedly better under scrutiny than those relying on ad hoc judgement. The authority’s annual reports, published via its website, remain the best source for current enforcement priorities.
The message for both public authorities and entities holding public-sector records is to institutionalise the process now: adopt standard templates, mandate the balancing-test memo for every mixed request, and rehearse the breach-notification decision so that an over-disclosure is caught and assessed within hours, not days. Broader government data protection expectations, illustrated by published guidance such as that of the Federal Ministry of Finance, reinforce the same governance-first posture.
Most enforcement exposure in a foi personal data austria matter traces back to a handful of avoidable errors. Address each before the next request arrives.
FOI officers often conflate an FOI request with a GDPR subject access request (SAR). They are legally distinct, and misclassifying one as the other produces the wrong outcome. The table below sets out the differences that matter in practice.
| Aspect | FOI disclosure | GDPR subject access request (SAR) |
|---|---|---|
| Purpose | Public access to official information | Data subject access to their own personal data |
| Recipient | Any requester (public) | Identified data subject (or authorised representative) |
| Legal basis | IFG / sectoral FOI rules; public interest in transparency | GDPR Article 15 (data subject right) |
| Exemptions | Protection of personal data, national security, commercial secrets and other IFG grounds | Limited where disclosure would adversely affect the rights of others or another exemption applies |
| Timelines | Statutory FOI period (see Section 5) | One month, extendable by up to two further months under GDPR Article 12(3) |
| Outcome | May include third-party personal data unless exempt | Discloses the requester’s own personal data, subject to the rights of others |
The key operational lesson: an FOI request from a member of the public who happens to seek information about themselves is not automatically a SAR, and vice versa. Where a single incoming request could be read either way, log both possibilities, apply the more protective analysis to third-party data, and confirm the requester’s intent before releasing.
Standardised templates reduce error and speed compliant handling of every foi personal data austria request. The core set comprises a refusal decision, a redaction log, and a balancing-test memo. Each should be adopted only after legal review, because the wording of a refusal and the legal basis cited in a redaction log carry appeal and enforcement consequences.
Handling a foi personal data austria request well is a matter of disciplined process, not improvisation: log promptly, screen against the GDPR and DSG, document the balancing test, consult where required, redact irreversibly, and meet the statutory deadline. With the Datenschutzbehörde focused on procedural rigour, an auditable workflow is the single best protection against enforcement. Public bodies and private holders of public-sector records that adopt the steps, tables and templates in this guide will be well placed to respond defensibly to every access request that touches personal data.
This article was produced by Global Law Experts. For specialist advice on this topic, contact János Böszörményi at Schönherr Rechtsanwälte GmbH (‘Schoenherr’), a member of the Global Law Experts network.
posted 1 minute ago
posted 21 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 5 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message