How does DSG-A (Austrian GDPR) + DSB cookie banner enforcement differ from Germany?

Austria implements GDPR via the DSG (Datenschutzgesetz), locally called DSG-A to distinguish from older versions. Enforcement is by the DSB (Datenschutzbehörde), headquartered in Wien.

Concrete differences from a Magento perspective:

  • Cookie consent, DSB requires explicit, granular, per-purpose opt-in. No pre-ticked checkboxes. The “Alle ablehnen” (Reject all) button must be as prominent as “Alle akzeptieren”. Aligned with EDSA (European Data Protection Board) guidance but DSB has been more aggressive than some neighbours on enforcement.
  • Cookie wall ban, you cannot block content for users who refuse non-essential cookies (DSB position, similar to CNIL).
  • Data localisation, DSB prefers EU-region hosting. Adobe Commerce Cloud Frankfurt, ANEXIA (Austrian), A1 Internet (Austrian), Hetzner (Germany) all acceptable. US hosting requires DPF (Data Privacy Framework) compliance.
  • Schrems II, Austrian privacy activist Max Schrems triggered the EU-US data-transfer ruling. DSB is highly aware. We default to EU hosting + EU CDN for AT clients.
  • NIS2 directive, for critical sectors (energy, transport, finance, health) the Austrian transposition adds incident-reporting + cybersecurity requirements that affect Magento stores serving those sectors.

We ship Cookiebot / Usercentrics / Borlabs (German-native, AT-compliant) wired into Magento’s cookie API, banner copy reviewed against DSB guidance, German + Austrian-German translations.

Kishan Savaliya
Kishan Savaliya
Adobe Certified Magento Commerce Developer
Ahmedabad [IN]working hours, replies within four hours
When do you need it

Read personally. Never shared. Or email the brief.

More on magento developer austria

Need it fixed, not just explained?

Send the brief with your store URL; the written quote comes back within 24 hours.