Security is of utmost priority for Austrian Airlines AG. Of course, this applies as much to the protection of your privacy as it does to the security of your personal data.
Data protection
Our Data Protection Promise
We promise we will handle your personal data carefully and conscientiously. That’s why we are continuously reviewing the processing of your personal data and taking corresponding technical and organisational security measures. We use these to protect the personal data you entrust to us against illegal manipulation, loss and access by unauthorised persons. Of course, we are continuously revising and updating our data security measures so we can offer you this protection long term.
Privacy Notice
Last updated: September 2026
The protection of your personal data is an important concern for us, Austrian Airlines AG. In the following, we explain how we process your personal data in connection with your use of the services and products we offer through our website, app, and other means, and outline your rights in this context.
We process personal data exclusively in accordance with the law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, the EU General Data Protection Regulation ("GDPR"). In the following, we inform you how we process your personal data in the context of the use of the services and products we offer via this website or app and about your rights in this context.
1. Who is the data controller?
The controller within the meaning of the GDPR for the processing of your personal data described in this Privacy Notice is:
Austrian Airlines AG
Office Park 2
PO Box 100
1300 Vienna Airport
Austria
2. Who can I contact?
If you have any further questions about data protection in connection with our website or the services and products offered there, please contact our data protection officer using the following form:
Representative in Switzerland
Our representative in Switzerland in accordance with Art. 14 of the Swiss Federal Act on Data Protection is Swiss International Air Lines AG, P.O. Box, Data Protection, ZRHS/CJ, CH-8058 Zurich Airport, Switzerland.
3. What personal data do we collect?
Personal data is any information about an identified or identifiable natural person that you provide to us or that we collect. These are in particular:
Booking data: If you book a flight or flight-related service with us, the content data entered by you and the content data collected about you (in particular name, contact details, date of birth and payment data) as well as the information provided to you by us will be processed. In addition, we collect information about time, scope and, if applicable, place of your booking. In individual cases, your nationality and voluntary information on frequent flyer programs will also be collected. If you book transportation services, we may process information about transportation arrangements that could indirectly reveal sensitive data, for example the information about a required wheelchair. If bookings are made for minors, the contact details of the legal guardians will also be collected.
Check-in data: As part of the check-in and boarding process, we process your booking data, information about your baggage, security data (e.g. your boarding time, security check status, timestamps regarding your check-in process), data about your entry documents (passport, visa, etc.) if applicable, as well as any other contact details, such as your emergency contact.
API data: API (Advanced Passenger Information) data contains the information from your travel document (e.g. passport), such as name, date of birth, nationality, passport number, gender.
PNR data: PNR (Passenger Name Record) data is collected and processed by us when we operate certain flights. This includes, but is not limited to, your name, contact details, baggage information, API data, payment details, travel itinerary information and the history of booking changes. A detailed list of possible data elements can be found in Annex I PNR Directive (EU) 2016/681.
SSR data: Special service request information such as health data in the context of mobility aids or information about religion when providing meals on board.
Content data: When you use services on our website or in our app, such as the use of contact forms, customer service, newsletters or participation in competitions or surveys, the content data entered by you and the content data collected about you as well as the information provided to you by us will be processed.
Cookie data: Data collected by cookies we use during your visit to the website or app.
Login data: Some services on our website or in our app require registration (e.g. TravelID, e-mail newsletter). For this purpose, some information is mandatory (e.g. e-mail address), other information can be added voluntarily (e.g. gender, name). As part of the registration process, we also collect your IP address and time of registration.
Server log data: When you use our websites, data (such as the date and time of your visit, pages accessed and files requested, type and version of the web browser you use, type and operating system of the device you use and your IP address) are temporarily stored in a log file on our servers. If you access our offer via our app, the type and operating system of your mobile device and your IP address will be stored in addition to the information about your visit to the app.
Medical data: Information on the processing of personal data relating to passengers requiring medical clearance, as well as our Medical Care Form, can be found here:
We generally receive this personal data directly from you, for example when you make a booking, use our website or app, contact us, or use our services. We may also collect personal data automatically from your device or from your use of our websites, apps and other services. In addition, where necessary and permitted by applicable law, we may receive personal data from:
- other companies in the Lufthansa Group and companies (e.g. travel-service providers, payment providers) involved in providing your booked services;
- persons acting on your behalf, such as family members, legal representatives or travel agencies; and
- public authorities, courts and other parties in connection with official or legal proceedings.
If you provide us with personal data relating to another person, such as a family member or fellow traveler, please ensure that you are authorized to do so and that the person concerned has been informed about this Privacy Notice.
4. What personal data is processed, for what purposes and for how long?
4.1 Booking flights and flight-related additional services
If you book a flight and/or flight-related additional services (such as seat reservations, luggage or animal transport, lounge, etc.) with us, we process your booking data for the purpose of issuing a flight ticket or booking confirmation of the flight-related service booked. If you rebook or cancel your flight or flight-related additional service, we will process your booking data accordingly.
The legal basis for the processing is the conclusion and performance of a contract with you for the operation of a flight or flight-related services, Art. 6 para. 1 lit. b GDPR.
In the event that special personal data has to be processed when booking flight-related additional services (e.g. health data when booking transport aids or information about religion when booking meals on board), the processing is based on your explicit consent (Art. 6 para. 1 lit. a GDPR). The processing of the relevant special categories of personal data is additionally permitted under the exception in Art. 9 para. 2 lit. a GDPR.
In individual cases, we are also legally and contractually obliged to process the necessary data of passengers with disabilities or reduced mobility in order to ensure carriage (Regulation (EC) No. 1107/2006, Art. 6 para. 1 lit. b, c, Art. 9 para. 2 lit. g GDPR).
This data will be deleted if it is no longer required for the performance of the contract (including customer service and possible assertion of legal claims before the limitation period expires), unless we are legally obliged to store it, e.g. due to retention obligations under commercial or tax law.
4.2 Registration of a Travel ID
4.3 Miles & More frequent flyer programme
If you would like to collect miles with our frequent flyer programme Miles & More when booking a flight, we will pass on your booking data including your Miles & More card number to Miles & More GmbH (see also Section 5.2). The legal basis for data processing is the performance of the contract (Art. 6 para. 1 lit. b GDPR).
For more information on the processing in connection with the Miles & More frequent flyer program, please refer to the privacy policy of Miles & More.
4.4 Operate flights and flight-related services (including Check-in data and Boarding data)
In order to carry out the flights you have booked and other flight related services, we process your booking data already received as well as your check-in data. You may also receive flight-related notifications, such as gate changes or entry/baggage instructions. In case irregularities such as delays or cancellations would affect your journey, you will receive information about the situation as well as proposed corrective actions for compensation and assistance based on the Air Passengers Rights Regulation (EU 261/2004). Where necessary, in connection with the operation of your flight and in accordance with national and international legislation and agreements, we will transfer your API data or PNR data to the relevant authorities in Germany and abroad for the purposes of preventing, detecting, investigating and prosecuting terrorist offences and serious crime, and combating illegal immigration.
The legal basis for the processing is the conclusion and performance of a contract with you for the operation of a flight or the provision of flight-related services, Art. 6 para 1 lit. b GDPR. With regard to the transfer of your API and PNR data, the legal basis in individual cases is a legal obligation (Art. 6 para. 1 lit. c GDPR in conjunction with the applicable national or international legislation or agreements from which legal obligations arise for us). For example, in specific cases we are obliged to transfer your API data to the competent authorities in Austria and your PNR data in accordance with Section 2 of the Passenger Name Record Act (“PNR-G”) and to the competent authorities in France in accordance with Article L. 232-7 of the French Internal Security Code (Code de la Sécurité Interieure) in conjunction with Decree No. 2014 -1095 of 26 September 2014 and Decree No. 2018-714 of 3 August 2018, to the competent authorities in France, as well as, where applicable, to authorities in third countries on the basis of existing PNR agreements (US, Canada, UK), prior to the operation of a flight to the country in question. Third countries are countries outside the European Economic Area.
You also have the option of storing the contact details of a person who would be contacted in an emergency (emergency contact). The processing of these contact details is carried out on the basis of the consent of the data subject (Art. 6 para. 1 lit. a GDPR). In this regard, when providing the contact details, you confirm that the consent of the data subject has been obtained.
In the event that special personal data has to be processed during the performance of flight-related services (e.g. SSR data), the legal basis for the processing of this data is your consent in accordance with Art. 9 para. 2 lit. a GDPR.
This data will be stored for as long as legal claims related to a specific booking can be brought before the court. It will be deleted upon expiry of that period or upon the closing of any ongoing legal proceedings exceeding the regular storage period. If the consent you have given has been revoked, your data will be deleted unless we are legally obliged or entitled to store it, e.g. due to retention obligations under commercial or tax law.
4.5 Safety, Security and Unruly Passengers
We process personal data for safety and security purposes.
For example, we use video surveillance at specific premises for the detection and prosecution of criminal acts. In keeping with applicable aviation security requirements, we also monitor the area immediately in front of the cockpit door.
“Unruly Passengers” are passengers whose improper, aggressive or violent behavior, non-compliance with instructions, threats or other misconduct endangers or disrupts the safety or security of the flight, the crew, other passengers or third parties.
We record relevant incidents in a Passenger Disturbance Report (“PDR”). Depending on the nature and severity of the disturbance or misconduct, the PDR may include details of the incident and, where necessary, information from the passenger’s travel documents to identify the passenger. We may use this information to document, assess and prevent incidents, protect the safety and security of our flights, crew and passengers, and protect our rights.
We may disclose relevant information to the police and other authorities, and, in serious cases, refuse carriage, prohibit the passenger from traveling on our flights (flight ban) or inform the crew of previous incidents. Where necessary and permitted by applicable law, we may also exchange relevant information within the Lufthansa Group and with other airlines to document, analyse and prevent fraud and incidents involving Unruly Passengers, and disclose information relating to harm, injury or criminal acts to authorities and insurance companies.
This processing is based on our legitimate interest in ensuring safety and security (Art. 6 para. 1 lit. f GDPR).
4.6 Your inquiries/feedback
If you send us inquiries via contact form, e-mail, chat or service calls, we process your content data to answer your request and, if applicable, the IP address, date and time of the request to avoid misuse of the contact form. With your explicit consent, we may record the call with you for quality assurance and training purposes. In the event that you inform us of possible errors on the website or app, we will use the data you enter and, if applicable, the data of your device to analyze and rectify the error you have reported.
The legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our and your (legitimate) interest in this data processing arises from the aim of answering your inquiries, solving any problems that may exist and thus maintaining and promoting your satisfaction as a customer or user of our website or app. If your request is aimed at initiating or executing a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR. The legal basis for the processing of data protection requests is Art. 6 para. 1 lit. c GDPR, as this is necessary to comply with legal obligations. Regarding the recording of phone calls the legal basis is your consent, Art. 6 para. 1 lit. a GDPR.
If the processing is based on the legal basis of the overriding legitimate interest (Art. 6 para. 1 lit. f GDPR), you may object to the processing of your data (see Section 7 below). We may continue processing your personal data if we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or if the processing is necessary to establish, exercise or defend legal claims.
This data will be deleted when our communication with you has ended, i.e. when the affected matter has been conclusively clarified and there is no further legitimate interest in storing it or there are no further legal obligations to store it. Your communication with our chat bot we will retain for 30 days. If you communicate with our staff, we will retain the data for 90 days or until the affected matter has been conclusively clarified.
4.7 Marketing Notifications
We process your data to send you marketing notifications.
For example, on our website, you can receive information about our products and services even without a Travel ID. In addition to our newsletter, you can also subscribe to the Best Price Alert to be informed about the best price for your individual flight route. In addition, you can receive other marketing notifications if you wish, such as notifications about flight bookings that you have not yet completed.
Your subscription to email advertising will be effective upon your confirmation. To do this, you must click on a link that we will send you in our confirmation email when you register for the newsletter.
The legal basis for the processing of your contact data is your consent (Art. 6 para. 1 lit. a GDPR). You may withdraw your consent to receive our promotional notifications at any time.
Without separate consent to receive marketing notifications, we contact customers who have already made bookings with us individually by e-mail with information about similar offers and services from us. However, you will only receive this information if and to the extent that (a) we have received your e-mail address from you in connection with the sale of a good or service, (b) we use this e-mail address for direct marketing of our own similar goods or services, and (c) you have not objected to receiving it.
The legal basis for the processing is our legitimate interest (Art. 6 para. 1 lit. f GDPR).
You can object at any time to the processing of your personal data for the purposes of marketing and product development, in whole or in part, or revoke any consent you have given.
You can object as follows:
- In case of e-mail notifications, you can use the unsubscribe link provided for you in each of them.
- Alternatively, you can send a message (keyword: data protection) via the contact form on our website and app or in writing or by e-mail to the email address in Section 2 above.
Your data will be deleted after your objection or the revocation of any consents you may have given, or otherwise at the latest after we have ceased to use it, or will only be stored in aggregated, anonymized form. Where necessary, we will store the fact of your objection and your respective contact details to prevent you from being contacted further. In the case of objection or revocation of consent regarding marketing, we will update your marketing preferences. Please note that an objection to marketing does not automatically result in the deletion of your Booking data or Travel ID (Art. 6 para. 1 lit. b GDPR).
4.8 Further development and optimization of our services and offers
We process your data to optimize our services and products.
For example, we process your Booking data (excluding any sensitive data they may contain) as well as content data that we collect when communicating with you (see section 4.5), for the further development and optimization of our services, offers and AI tools used (such as our Chat Assistant) as well as for internal statistics. This processing is used in particular to optimize our customer service, to process your enquiries efficiently and to improve the customer experience with us and our range of services.
The legal basis for the processing is our legitimate interests in further developing and optimizing our services and offers as well as compiling internal statistics (Art. 6 para. 1 lit. f GDPR). You can object to the processing for the purposes of further development and optimization at any time (see Section 7 below.
We generally process your data for these purposes in anonymized form and delete it after two years. If, for example due to irregularities in the provision of services, it is necessary to store your data in order to comply with statutory retention obligations (e.g. in accordance with Section 132 of the Austrian Federal Fiscal Code, Section 232 of the Austrian Commercial Code), we will retain the relevant data for up to 10 years.
Personal data collected during your interactions with our Chat Assistant or customer service channels may be used, in anonymized and aggregated form only, for the purpose of further developing and improving the AI tools we deploy. No personal data that directly identifies you, and no special category data within the meaning of Article 9 GDPR (including any health or mobility information provided as part of a special service request), is used for AI model training or fine-tuning.
We may invite you to participate in customer panels, market-research activities or customer-satisfaction surveys to obtain feedback on and improve our services, products and customer experience. Participation is voluntary. We process the personal data you provide in this context, including your responses and any related contact or participation data. Processing is based on your consent (Art. 6 para. 1 lit. a GDPR), which you may withdraw at any time with effect for the future.
4.9 Cookies and similar technologies
4.10 Securing the booking process and preventing fraud
In order to secure and optimize the booking process as well as to prevent fraud and to limit the risk of payment defaults, we process especially your payment data, name and address during the booking process and, if applicable, in any compensation or repayment transactions, in order to check whether there are any risks or anomalies. In addition, in the event of order cancellation, the data accrued up to the time of the order is cancelled is stored for the (technical) optimization of the ordering process, for the detection of fraud patterns and in order to be able to answer customer inquiries about the order processes.
The legal basis for the data processing described in this section is Art. 6 para. 1 lit. b and lit. f GDPR. The legitimate interest results from the protection of your identity, the minimization of non-payment risks and the avoidance of fraud attempts.
This data is only stored for as long as necessary for the purposes stated. Where suspicious booking transactions are detected and data is processed in the fraud management system, the retention period is three years from the date on which the relevant data was recorded. Data will only be stored for a longer period where and for as long as statutory retention obligations apply or where further storage is necessary for the assertion, exercise or defense of legal claims.
4.11 Enforcement of legal claims
For the purpose of enforcing our own legal claims and defending our legal position, we process the personal data required for enforcement or defense in individual cases. This can be booking data, among other things.
The legal basis for the processing is our legitimate interest in enforcing legal claims and defending our own legal position (Art. 6 para. 1 lit. f GDPR).
The data required for this will be deleted after the conclusion of the legal dispute or after the statutory retention period has expired.
4.12 Ensuring the technical infrastructure and provision of the website and app
The processing of the server log data serves the technical provision of the website or our app and then to ensure system security and protection of the technical infrastructure in order to detect malicious access to our website or app.
The legal basis for the processing is our legitimate interest in providing the website / app with our services and protecting our technical infrastructure (Art. 6 para. 1 lit. f GDPR). The processing is absolutely necessary for the use of our website and app.
This data will be deleted 180 days after the end of your session at the latest.
5. To whom do we transfer your data?
Within the framework of the above-mentioned data processing and the respective legal bases, your data may be transferred to the following categories of recipients:
5.1 Transfer of data to processors
In some cases, we use service providers in compliance with the legal requirements by way of order processing, i.e. on the basis of a contract on our behalf, according to our instructions and under our control.
Processors are in particular
- vicarious agents, e.g. service providers for ground handling services, claim handling companies and other additional services in this context,
- customer service centers (call center, mail servicing, chat provider),
- other service providers, e.g. for the provision of the website, the sending of newsletters, the processing of feedback, the compilation of international aviation statistics,
- Cloud service providers and hosting providers (for data storage and infrastructure),
- Service providers for the operation and maintenance of IT systems,
- technical service providers that we use to provide our website and app and the respective functionalities, e.g. technically necessary cookies,
- service providers for the practical implementation of advertising and marketing, e.g. service providers for e-mail sending and analysis cookies.
In these cases, we remain responsible for data processing; the transfer and processing of personal data to or by our processors is based on the legal basis that allows us to process the data in each case. A separate legal basis is not required.
5.2 Transfer of data to Lufthansa Group Companies
Certain of your data will also be transferred to other companies of the Lufthansa Group. In this case, we can be joint controllers together with the airlines concerned for the processing of this specific data in accordance with Art. 26 GDPR.
In individual cases, the recipients are Air Dolomiti S.p.A Linee Aeree Regionali Europee (Dossobuono di Villafranca (VR), Via Paolo Bembo 70, Italy), Brussels Airlines NV/SA (Kompaslaan 26, 1831 Machelen, Belgium), Deutsche Lufthansa AG (Venloer Straße 151-153, 50672 Cologne, Germany, Germany), Edelweiss Air AG (The Circle 32, 8058 Zurich Airport, Switzerland), Eurowings GmbH (Waldstraße 249, 51147 Cologne, Germany), EW Discover GmbH (Hugo-Eckener-Ring 1, FAC Building, 60549 Frankfurt a.M., Germany), Italia Trasporto Aereo S.p.A. (Via Venti Settembre 97, Rome, 00187, Italy), Lufthansa CityLine GmbH (Munich Airport, FOC, Südallee 15, 85356 Munich, Germany), Lufthansa City Airlines GmbH (Munich Airport, FOC, Südallee 15, 85356 Munich, Germany, Germany) and Swiss International Air Lines AG (Obstgartenstrasse 25, 8302 Kloten, Switzerland) – together "Lufthansa Group Airlines".
Furthermore, we may transfer your data to other group companies, such as Miles & More GmbH (see Section 4.3 above) as well as other group companies involved in the provision of services to you.
For example, your data will be passed on to the Lufthansa Group Airlines if this is necessary for the operation of the booked flight. If you book a flight with us that is operated by another airline of the Lufthansa Group, we transmit your data to this airline in order to fulfill the contract with you (Art. 6 para. 1 lit. b GDPR). In addition, based on our legitimate interest, we share information about individuals who are subject to flight bans (Art. 6 para. 1 lit. f GDPR).
For the purpose of further developing and optimizing our services and offers (see also section 4.7 above) we may pass on your data to the Lufthansa Group Airlines. The legal basis for the disclosure is the legitimate interest of the airlines involved (Art. 6 para. 1 lit. f GDPR) to improve their own services for you and other customers for the future and to adapt their own offer to your needs.
The joint controllers have entered into an arrangement pursuant to Article 26 GDPR determining their respective responsibilities for compliance with the obligations under this Regulation. The essence of that arrangement is as follows: Deutsche Lufthansa AG acts as the primary point of contact for the exercise of data subject rights arising from jointly processed data; requests submitted to any other Lufthansa Group Airline will be forwarded to the competent entity without undue delay. The full text of the arrangement is available on request by contacting the data protection officer set out in Section 2 above. However, your rights under Section 7 of this Privacy Notice can be asserted against any group company involved.
5.3 Transfer of data to third parties
In addition, we also transfer your data to third parties, i.e. partners that provide services as independent controllers.
These partners are in particular:
- Other airlines, rail partners and providers of ground transport services that carry out part of the transport (the legal basis for the data transfer is Art. 6 para. 1 lit. b GDPR);
- payment service providers with whom we cooperate and with the help of which you can make the flight booking with us (the legal basis for the data transfer is Art. 6 para. 1 lit. b GDPR);
- communications provider that operates the in-flight entertainment portal on board and provides you with access to the Internet and entertainment content, e.g. FlyNet (the legal basis for the data transfer is Art. 6 para. 1 lit. b GDPR);
- banks and payment service providers with whom we cooperate to process relevant booking, payment, contact and technical data as necessary to secure and optimize the booking process, prevent fraud, detect suspicious activity and limit the risk of payment defaults (the legal basis for the data transfer is Art. 6 para. 1 lit. f GDPR);
- state authorities and institutions, e.g. on the basis of entry requirements or police activities and investigations (the legal basis for the data transfer is Art. 6 para. 1 lit. b or c GDPR)
- service providers engaged in the event of service disruptions, e.g. hotels (the legal basis for the data transfer is Art. 6 para. 1 lit. f GDPR).
5.4 Transfer of data to third countries
In some cases, we transfer personal data to recipients who are not in the immediate scope of the GDPR but located in third countries (see Section 4.4 above). Unless the EU Commission has decided that these countries provide an adequate level of legal protection for your personal data, we must either ensure that we implement sufficient safeguards for your personal data or that one of the legal exceptions applies.
In accordance with Art. 46 para. 2 lit. c GDPR, we regularly use EU standard contractual clauses adopted by the EU Commission with recipients in third countries that are not recognized as safe. Nevertheless, in some third countries there is a risk that your data may be demanded by national authorities from the recipients for control and monitoring purposes without the requirements being clearly regulated or appropriate legal remedies available. To the extent that such risks exist that are considered unreasonable by the jurisdiction of the European courts (for example, as in some constellations in the case of the USA), we will take additional safeguards and agreements to the extent possible. For more information on these third-country transfers, and in particular for a copy of the Standard Contractual Clauses, please refer to the contact details set out in Section 2.
In some cases, we also transfer your data on the basis of Art. 49 para. 1 GDPR. This can be, for example, your explicit consent in accordance with Art. 49 para. 1 s. 1 (a) GDPR to the transfer of data to recipients in unsafe third countries, for example if our partners use cookies or comparable technologies on our website. Before giving consent, we explicitly inform you that the transfer carries possible risks for you because an adequate level of data protection and suitable safeguards are not available in the third country. If you give your consent, you accept that the risks described above, in particular access to your data by foreign authorities, will occur without further guarantees being agreed or additional protective measures being taken. In other cases, we may transfer your personal data to authorities in third countries on the basis of Art. 49 para. 1 s. 1 (b) GDPR in order to fulfill the flight booking you have made with us.
6. What kind of automated decision-making is used?
Automated decision-making (including profiling) is a data processing operation in which a decision is made automatically without any human intervention or assessment of the content.
We do not use solely automated decision-making that produces legal effects concerning you or similarly significantly affects you, pursuant to Art. 22 para. 1 GDPR. In the event that we use such a system in the future, we will inform you in accordance with the legal obligations.
7. What rights do you have?
In relation to the processing of your personal data by us, you have the following rights:
Right of access (Art. 15 GDPR): You have the right to obtain confirmation from us as to whether or not we are processing your personal data. If personal data is processed by us, you have the right to obtain information about this data as well as about the purposes of processing, data categories, data recipients, storage period, data origin, information about your rights and the existence of automated decision-making, including profiling.
Right to rectification (Art. 16 GDPR): If your personal data is incorrect or incomplete, you have a right to rectify us.
Right to erasure (Art. 17 GDPR): You have the right to request the erasure of your personal data. This is also known as the right to be forgotten. There is no blanket right to erase all personal data. For example, we may be legally obliged to continue to process individual personal data, or the processing may be necessary to defend our interests in case of legal claims.
Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of the processing of your personal data. If processing is restricted, the data will be blocked.
Right to data portability (Art. 20 GDPR): If the processing is based on your consent or if the personal data must be processed by automated means for the performance of a contract, you have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format or to transmit this data to another controller.
Right of revocation (Art. 7 para. 3 GDPR): If you have consented to the processing on the basis of a corresponding declaration, you can revoke your consent at any time for the future. The lawfulness of the data processing carried out on the basis of consent before the revocation is not affected by this.
Right to object (Art. 21 GDPR): Insofar as we process your data to safeguard legitimate interests, you can object to this processing at any time under Data subject rights request if there are reasons arising from your particular situation that opposes data processing by us. You have the right to object at any time to the processing of your personal data for the purpose of direct marketing, without providing any reasons. The data processing will then be terminated unless the Austrian Airlines AG can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or if the processing serves to establish, exercise or defend legal claims.
To exercise your rights, please contact us or the company data protection officer using the contact details given in sections 1 and 2.
8. Right to lodge a complaint with a supervisory authority
If you have any questions, concerns or complaints regarding the processing of your personal data, we encourage you to contact our data protection officer and team first at Data subject rights request.
This does not affect your right to lodge a complaint with a competent data protection supervisory authority. The competent supervisory authority for Austrian Airlines AG is:
Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Vienna
+43 1 52 152-0
dsb@dsb.gv.at
This Privacy Notice may be amended to reflect changes in our data processing practices or legal requirements. The current version is available on our website at any time.
Information about processing your personal data
It is sometimes necessary to collect, store and process some of your personal data in the course of our business operations; this is required to implement a flight booking or create your customer profile, for example. However, you can rest assured that we are as transparent as possible in relation to the processing of your data and that you have control over your personal data at all times.
Your personal data is only processed to the extent that is absolutely essential or if we have obtained your consent to do so.
If you would like to know in detail the personal data that we process, please contact us at any time by sending us an information request.
In addition, you have further rights that you can exercise based on the General Data Protection Regulation (in short: ‘GDPR’ – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data). You can find a summary of these rights on our data protection rights page.
We use cookies to optimise your experience when you visit our websites. You can find further information about the use of cookies on our website in our Cookie Policy.
1 We will deal with your concern as quickly as possible.
The data you provide will only be used to process your enquiry. Your data will not be shared with third parties unless Austrian is obliged to do so for legal reasons.
Email communication with Lufthansa Group airlines is not encrypted. Please note this in particular when sending personal data, such as your name, contact details or travel information, and most importantly do not refer to them in the subject line.