Subject access request under Art 15 GDPR (Austria)

Austria
Deutsch
Data & Privacy
Application
Print & sign
2 pages · 0 sold

Published byDocMuse

This document is in German

The PDF you download is in German — that is the language it has to be filed in, so it is not translated. Everything on this page is here to tell you what it says.

Your access request to a company, association or body in Austria: whether and which data about you are processed, for what purposes, where they came from, to whom they go and how long they are kept, with a free copy (Art 15 GDPR). The answer is due within one month, extendable by two months with reasons (Art 12(3) GDPR). If none comes, you can complain to Austria's data protection authority, the Datenschutzbehörde (§ 24 DSG), which provides its own form free of charge. No copy of an identity document as a condition. In German.

What you fill in

The details the document asks for.

  • Applicant
  • Applicant's address
  • Data controller
  • Controller's postal address (from its privacy notice)
  • City
  • Date
  • Client number
  • How the information should be sent
  • Email
  • Date of birth

Preview

This document is produced for you. Your answers are typed into it and the finished PDF is yours to keep.

Preview coming soon

Common questions

How long does a company in Austria have to answer a subject access request?
Without undue delay, and at the latest within one month of receipt. For complex or numerous requests the period can be extended by two more months; the controller must tell you so, with reasons, within the first month (Art 12(3) GDPR). The first copy of the data is free (Art 15(3) GDPR). No form is prescribed; your letter shows what you asked for and when it arrived.
What can be done in Austria when a data access request gets no answer or an incomplete one?
You can complain to the Datenschutzbehörde in Vienna (§ 24 DSG), the one supervisory authority for the whole of Austria. It provides a form on its website; an informal complaint is also possible. Enclose your request, proof of its receipt and any answer. Do not wait too long: the complaint must be lodged within a year of learning of the breach (§ 24 Abs 4 DSG).
Must a copy of an identity document go with a data access request in Austria?
Not from the start. The controller may ask for more information about your identity only where it has reasonable doubts (Art 12(6) GDPR). The document gives your date of birth and, if you have one, your customer number, and offers to supply more. Send the request from the email address or the postal address the company already knows; that makes it easier to match.

How you can sign this document

  • Print it and sign by hand. The signature lines in the document are left blank on purpose — sign on them in ink.
  • Sign it yourself with a qualified electronic signature. If you already hold a QES — Evrotrust, B-Trust, StampIT, ZealiD or any qualified provider on the EU Trusted List, on a card, a USB token, in a mobile app or in the cloud — our signing guide explains step by step how to sign this exact file without invalidating it. Step-by-step help, and a way to check it worked

DocMuse sells documents, not legal advice. Acceptance always depends on the recipient's rules and your local law.

Related documents

  • Application to block registration data from disclosure (Austria)

    The application to the registration authority (Meldebehörde) to block your address from register enquiries (§ 18(2) of Austria's Registration Act, MeldeG): without a block, anyone who knows your name and a few other details can obtain your address. The block must be granted where you show a protectable interest to be credible — stalking, violence, threats or a well-founded fear of revenge, for instance — and lasts up to five years, even after you deregister. With your reasons, evidence and any children under 18. In German, ready to print and sign.

  • Data processing agreement under Art. 28 GDPR (Austria)

    A data processing agreement for businesses in Austria that have a service provider process personal data for them — hosting, cloud, payroll, IT support, newsletters. It contains every minimum term of Art. 28(3) GDPR, the data secrecy duty of § 6 of the Austrian Data Protection Act (DSG), rules for sub-processors, the place of processing, and annexes for the technical and organisational measures and the sub-processors. The supervisory authority is the Austrian Datenschutzbehörde. The European Commission offers standard contractual clauses free of charge; this is our own text. In German.