Data processing agreement under Art. 28 GDPR (Austria)
Published byDocMuse
This document is in German
The PDF you download is in German — that is the language it has to be filed in, so it is not translated. Everything on this page is here to tell you what it says.
A data processing agreement for businesses in Austria that have a service provider process personal data for them — hosting, cloud, payroll, IT support, newsletters. It contains every minimum term of Art. 28(3) GDPR, the data secrecy duty of § 6 of the Austrian Data Protection Act (DSG), rules for sub-processors, the place of processing, and annexes for the technical and organisational measures and the sub-processors. The supervisory authority is the Austrian Datenschutzbehörde. The European Commission offers standard contractual clauses free of charge; this is our own text. In German.
What you fill in
The details the document asks for.
- Data controller
- Controller's address
- Controller's company register number (FN) and register court (if registered)
- Signing for the controller
- Processor (service provider)
- Processor's address
- Processor's company register number (FN) and register court (if registered)
- Signing for the processor
- Processor's data protection officer (if appointed)
- Main contract (title and date)
- Subject-matter, nature and purpose of the processing
- Categories of personal data
- Categories of data subjects
- Authorisation of sub-processors: general, or case by case
- Objection period under a general authorisation of sub-processors
- Where the data are processed: EU and EEA only, or third countries too
- Measures: pseudonymisation and encryption
- Measures: confidentiality and integrity
- Measures: availability, resilience and recovery
- Measures: regular testing and evaluation
- Approved sub-processors (name, address, service, location) or “none”
- City
- Date
Preview
This document is produced for you. Your answers are typed into it and the finished PDF is yours to keep.
Common questions
- When does a business in Austria need a data processing agreement, and is there a free model?
- Whenever a service provider processes personal data on its behalf — hosting, cloud services, payroll or sending newsletters, for instance (Art. 28 GDPR). The European Commission provides standard contractual clauses for this contract free of charge (Implementing Decision (EU) 2021/915), which the parties may use instead of a contract of their own. This document is our own contract text with every minimum term of Art. 28(3) GDPR.
- Does a data processing agreement in Austria have to be signed?
- It must be in writing, which may be in electronic form (Art. 28(9) GDPR). The GDPR does not say in detail what that electronic form must look like. This document is printed and signed by both sides, or signed with a qualified electronic signature such as ID Austria; either way the conclusion of the contract can be proved. In an investigation the Data Protection Authority may require the contract to be produced (Art. 58(1) GDPR).
- Which authority in Austria deals with a personal data breach at a processor?
- The Data Protection Authority (Datenschutzbehörde) in Vienna, Austria's national supervisory authority under the GDPR (§ 18 DSG); there are no regional authorities as in Germany. If the processor becomes aware of a personal data breach, it notifies the controller without undue delay (Art. 33(2) GDPR). The controller reports it to the Data Protection Authority where feasible within 72 hours, unless it is unlikely to result in a risk to the people concerned (Art. 33(1) GDPR).
How you can sign this document
- Print it and sign by hand. The signature lines in the document are left blank on purpose — sign on them in ink.
- Sign it yourself with a qualified electronic signature. If you already hold a QES — Evrotrust, B-Trust, StampIT, ZealiD or any qualified provider on the EU Trusted List, on a card, a USB token, in a mobile app or in the cloud — our signing guide explains step by step how to sign this exact file without invalidating it. Step-by-step help, and a way to check it worked
DocMuse sells documents, not legal advice. Acceptance always depends on the recipient's rules and your local law.
Related documents
- Application to block registration data from disclosure (Austria)
The application to the registration authority (Meldebehörde) to block your address from register enquiries (§ 18(2) of Austria's Registration Act, MeldeG): without a block, anyone who knows your name and a few other details can obtain your address. The block must be granted where you show a protectable interest to be credible — stalking, violence, threats or a well-founded fear of revenge, for instance — and lasts up to five years, even after you deregister. With your reasons, evidence and any children under 18. In German, ready to print and sign.
- Subject access request under Art 15 GDPR (Austria)
Your access request to a company, association or body in Austria: whether and which data about you are processed, for what purposes, where they came from, to whom they go and how long they are kept, with a free copy (Art 15 GDPR). The answer is due within one month, extendable by two months with reasons (Art 12(3) GDPR). If none comes, you can complain to Austria's data protection authority, the Datenschutzbehörde (§ 24 DSG), which provides its own form free of charge. No copy of an identity document as a condition. In German.