Privacy
Data protection law for businesses

Make data protection workable.

Responsibilities, contracts, data breaches and data subject rights are connected. This portal helps you find the right starting point through focused topics, interactive checks, checklists, a glossary and current articles.

BRANDAUER Rechtsanwälte
Contact person

Mag. Bernhard Brandauer, Rechtsanwalt

BRANDAUER Rechtsanwälte

Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.

GDPR
European framework
AT
Austrian law
3
languages
Structure

Turn individual questions into a reliable overview.

Data protection is more than a privacy notice. Businesses need to consider roles, purposes, data flows, retention, access rights and evidence together.

01

Clarify roles

Controller, processor or joint controllers: the correct classification shapes contracts, instructions and responsibility.

02

Organise processes

Data subject requests, breaches, erasure concepts and access procedures need clear ownership and traceable documentation.

03

Record decisions

Legal bases, risk assessments and security measures should be documented in a way that remains useful inside the business.

Start with the issue in front of you. The topic pages provide deeper explanations, the checks create an initial structure and the checklists help prepare the next step.

Role check

Role check

Orientation on data protection law for businesses in Austria.

Orientation

From the GDPR to day-to-day business practice.

The GDPR and Austrian data protection law provide the legal framework. Whether a business needs a specific document, process or safeguard depends on the purpose of processing, the people affected, the service providers involved and the actual risk. The detailed guide “GDPR for businesses in Austria” on the firm website explains the main duties. This portal takes you from that overview to specific business situations and practical next steps.

FAQ

Common questions about business data protection

Where should a business begin its data protection review? +
A useful starting point is an overview of processing activities: what data is processed, for which purpose, who can access it and which providers are involved. Legal bases, information duties, erasure, security and missing records can then be reviewed in a targeted way.
How can a business identify a processor? +
The actual role matters more than the contract label. A provider is a processor where it processes personal data on documented instructions while the business determines the purposes and essential means. Mixed services require a careful review of the real process and contract.
What should happen first after a data breach? +
Secure the available information and record when the incident became known, which data and people may be affected and which measures have already been taken. The risk can then be assessed. Whether notification or communication is required depends on that assessment and the circumstances.
Which documents help with an initial legal assessment? +
A short description of the facts, relevant contracts, process documents, existing records, privacy information, provider material and any incident documentation are useful. The key is to make the purpose, roles and actual process understandable.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich