Chat on WhatsApp

How does DSG-A (Austrian GDPR) + DSB cookie banner enforcement differ from Germany?

Austria implements GDPR via the DSG (Datenschutzgesetz), locally called DSG-A to distinguish from older versions. Enforcement is by the DSB (Datenschutzbehörde), headquartered in Wien.

Concrete differences from a Magento perspective:

  • Cookie consent, DSB requires explicit, granular, per-purpose opt-in. No pre-ticked checkboxes. The “Alle ablehnen” (Reject all) button must be as prominent as “Alle akzeptieren”. Aligned with EDSA (European Data Protection Board) guidance but DSB has been more aggressive than some neighbours on enforcement.
  • Cookie wall ban, you cannot block content for users who refuse non-essential cookies (DSB position, similar to CNIL).
  • Data localisation, DSB prefers EU-region hosting. Adobe Commerce Cloud Frankfurt, ANEXIA (Austrian), A1 Internet (Austrian), Hetzner (Germany) all acceptable. US hosting requires DPF (Data Privacy Framework) compliance.
  • Schrems II, Austrian privacy activist Max Schrems triggered the EU-US data-transfer ruling. DSB is highly aware. We default to EU hosting + EU CDN for AT clients.
  • NIS2 directive, for critical sectors (energy, transport, finance, health) the Austrian transposition adds incident-reporting + cybersecurity requirements that affect Magento stores serving those sectors.

We ship Cookiebot / Usercentrics / Borlabs (German-native, AT-compliant) wired into Magento’s cookie API, banner copy reviewed against DSB guidance, German + Austrian-German translations.

Was this helpful?