{
 "jurisdiction_id": "LU",
 "jurisdiction": "Luxembourg",
 "url": "https://dataprotection.gi/jurisdictions/luxembourg/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 27,
  "sub_modules": 57,
  "source_register": 12
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/luxembourg/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Core regulator, founding statute and territorial scope are well-evidenced from primary EDPB/EUR-Lex sources; registration/filing sub-module lacks a distinct LU-specific finding.",
   "claims": [
    {
     "statement": "The Commission Nationale pour la Protection des Données (CNPD), based at 15 Boulevard du Jazz, 4370 Belvaux, Luxembourg, is the country's independent GDPR supervisory authority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/about-edpb/about-edpb/members_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Luxembourg's GDPR-implementing act is the Loi du 1er août 2018 portant organisation de la Commission nationale pour la protection des données et du régime général sur la protection des données, published in Mémorial A No. 686 of 16 August 2018.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex (National Implementing Measure record)",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=NIM:262136",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 3 extends Luxembourg's data-protection regime extraterritorially via the establishment criterion (Art 3(1)) and the targeting criterion (Art 3(2)).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/files/file1/edpb_guidelines_3_2018_territorial_scope_after_public_consultation_en_1.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The general data-protection regime organised by the Loi du 1er août 2018 applies alongside the directly-applicable GDPR to processing falling within GDPR's material scope, with the national act supplying Luxembourg's institutional and procedural framework (CNPD organisation, sanctions, cooperation).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex (National Implementing Measure record)",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=NIM:262136",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/luxembourg/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Lawful bases, consent and special categories are solidly evidenced from EDPB primary guidance; pseudonymisation/anonymisation sub-module has no LU-specific finding.",
   "claims": [
    {
     "statement": "Data controllers must rely on one of the GDPR Article 6 lawful bases (consent, contract, legal obligation, vital interests, public interest/official authority, or legitimate interests) to process personal data lawfully.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where consent is used as the lawful basis, GDPR requires it to be freely given, informed, specific and unambiguous, with individuals able to freely withdraw consent without negative consequences.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Processing of special categories of data (racial/ethnic origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic data, biometric data for identification, health data, sex life/orientation) is prohibited by default under GDPR Article 9 absent a specific exception.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/luxembourg/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Strong enforcement-based evidence for access/rectification/erasure/objection; portability and deadlines sub-modules unevidenced.",
   "claims": [
    {
     "statement": "In its 16 July 2021 decision, the CNPD found Amazon Europe Core in violation of, among other provisions, GDPR Article 15 (right of access), as part of a €746 million fine.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/luxembourg-president-administrative-tribunal-suspends",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The same CNPD decision against Amazon Europe Core also found violations of GDPR Articles 16 (rectification) and 17 (erasure).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/luxembourg-president-administrative-tribunal-suspends",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CNPD's Amazon decision further found a violation of GDPR Article 21 (right to object), the provision underpinning objections to profiling-based targeted advertising.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/luxembourg-president-administrative-tribunal-suspends",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/luxembourg/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "DPO and accountability sub-modules well evidenced; ROPA, joint-controller, GDPR-breach-notification and retention sub-modules unevidenced in this pass.",
   "claims": [
    {
     "statement": "The CNPD's Amazon Europe Core decision found that the company's processing of personal data for behavioural advertising lacked a valid legal basis under GDPR Article 6(1), reflecting the accountability principle that controllers must be able to demonstrate a lawful basis for each processing purpose.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/luxembourg-president-administrative-tribunal-suspends",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In Decision No. 23FR/2021 of 29 June 2021, the CNPD held that direct reporting lines or the ability to bypass intermediate management levels can be proportionate measures to guarantee a Data Protection Officer's autonomy under GDPR Articles 38-39.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CNIL",
     "source_url": "https://www.cnil.fr/sites/cnil/files/atoms/files/cnil-gdpr_practical_guide_data-protection-officers.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Luxembourg's Law of 5 May 2026 transposing the NIS2 Directive introduces risk-based cybersecurity obligations, incident-notification requirements and governance/accountability measures for essential and important entities, with the Institut Luxembourgeois de Régulation (ILR) — not the CNPD — designated as the supervising authority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/luxembourg-official-journal-publishes-nis2",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/luxembourg/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "General Chapter V applicability evidenced generically; LU-specific transfer-mechanism detail (SCC uptake, TIA practice, localisation) unevidenced.",
   "claims": [
    {
     "statement": "As an EU Member State, Luxembourg's cross-border transfer regime for personal data is governed directly by GDPR Chapter V (Articles 44-49) as directly-applicable EU law, with the Loi du 1er août 2018 supplying the national institutional and enforcement framework (CNPD) rather than a separate transfer statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex (National Implementing Measure record)",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=NIM:262136",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/luxembourg/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial and telecoms overlays well evidenced; health, employment, credit-scoring, education and (binding) insurance overlays unevidenced.",
   "claims": [
    {
     "statement": "The Law of 5 April 1993 on the financial sector, as amended, imposes professional-secrecy obligations on the CSSF and governs its cooperation and information-exchange with EU and third-country authorities, forming a sectoral confidentiality overlay for Luxembourg's banks, investment firms and other supervised entities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CSSF",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_on_financial_sector.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ePrivacy Directive (2002/58/EC, as amended) remains the operative EU instrument governing confidentiality of electronic communications and cookie-related tracking, layered on top of the GDPR, pending adoption of a replacement ePrivacy Regulation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/data-protection/our-work/subjects/eprivacy-directive_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Luxembourg's Law of 5 May 2026 transposing NIS2 also amended the law of 17 December 2021 on electronic communications networks and services, linking cybersecurity obligations to the electronic-communications sector.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/luxembourg-official-journal-publishes-nis2",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Luxembourg's draft AI Act implementing bill (No. 8476) proposes designating the Commissariat aux Assurances (Insurance Commission) as the market-surveillance authority for AI systems placed on the market, commissioned, or used by entities under its insurance-sector supervision.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://legacy.dataguidance.com/news/luxembourg-parliament-introduces-bill-implementing-ai",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/luxembourg/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookies/dark-patterns/cross-context advertising well evidenced; opt-out signals, clean rooms and direct marketing unevidenced.",
   "claims": [
    {
     "statement": "CNPD guidelines on cookies and other trackers clarify consent requirements for essential and non-essential cookies, including analytical cookies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/luxembourg-cnpd-publishes-guidelines-cookies",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CNPD cookie guidance addresses dark-pattern designs in consent banners, treating manipulative interface choices that pressure users toward accepting non-essential cookies as a compliance risk under the cookie-consent framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/luxembourg-cnpd-publishes-guidelines-cookies",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CNPD's €746 million decision against Amazon Europe Core centred on the company's targeted (cross-context) advertising practices, which the authority found lacked a valid GDPR Article 6(1) legal basis.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CNIL",
     "source_url": "https://www.cnil.fr/fr/lautorite-luxembourgeoise-de-protection-des-donnees-prononce-lencontre-damazon-europe-core-une",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/luxembourg/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "AI Act competent-authority designation and Art 22 baseline evidenced but the designation is still at bill stage; biometric/genetic/profiling/surveillance carve-out sub-modules unevidenced.",
   "claims": [
    {
     "statement": "Luxembourg's draft AI Act implementing bill (No. 8476), introduced 23 December 2024, proposes designating the CNPD as the market-surveillance authority and notified body for high-risk AI systems used by law-enforcement, immigration, or asylum authorities, and amends the Act organising the CNPD and the general data-protection regime accordingly.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://legacy.dataguidance.com/news/luxembourg-parliament-introduces-bill-implementing-ai",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 22's restrictions on solely automated decision-making with legal or similarly significant effects apply directly in Luxembourg as EU law, enforced by the CNPD under the Loi du 1er août 2018's institutional framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex (National Implementing Measure record)",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=NIM:262136",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/luxembourg/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Age-of-consent/parental-consent baseline evidenced via GDPR Art 8 generic guidance; no confirmed LU-specific derogation and other sub-modules unevidenced.",
   "claims": [
    {
     "statement": "Under GDPR Article 8, children aged 16 and above can consent to information-society-service processing on their own behalf, while for children below 16 the controller must obtain consent from a parent or legal guardian, subject to Member States' ability to lower this threshold to as low as 13 by national law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/luxembourg/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Landmark enforcement action, its collective-complaint origin, and a within-180-day legislative development are all well evidenced; funding/capacity and private-right-of-action detail are gaps.",
   "claims": [
    {
     "statement": "The CNPD exercises GDPR Chapter VI investigative and corrective powers and can impose administrative fines up to GDPR maxima, as illustrated by its €746 million fine against Amazon Europe Core on 16 July 2021, an amount described as unprecedented in scale and marking a turning point in GDPR enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CNIL",
     "source_url": "https://www.cnil.fr/fr/lautorite-luxembourgeoise-de-protection-des-donnees-prononce-lencontre-damazon-europe-core-une",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Amazon Europe Core case originated from a collective complaint lodged with the French CNIL by the advocacy group La Quadrature du Net, which was handled by the CNPD as lead supervisory authority under the GDPR's cooperation procedures because Amazon Europe Core is established in Luxembourg.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CNIL",
     "source_url": "https://www.cnil.fr/fr/lautorite-luxembourgeoise-de-protection-des-donnees-prononce-lencontre-damazon-europe-core-une",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 5 May 2026, Luxembourg's Official Journal published the Law of 5 May 2026 transposing the NIS2 Directive, which entered into force on 10 May 2026 and designates the Institut Luxembourgeois de Régulation (ILR) — not the CNPD — as the competent cybersecurity supervisory authority, with self-registration required for essential/important entities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/luxembourg-official-journal-publishes-nis2",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}