Full GDPR incorporation with a closely-aligned national implementing act and an active, EDPB-integrated supervisory authority; no material derogations identified.
Primary frameworkGDPR (EU) 2016/679 as incorporated into the EEA Agreement, implemented via the Liechtenstein Data Protection Act (DSG) of 4 October 2018 and Data Protection Ordinance (DSV) of 11 December 2018
Traffic-light rationale — GreenFull GDPR incorporation with a closely-aligned national implementing act and an active, EDPB-integrated supervisory authority; no material derogations identified.
Sub-modules (5)
Regulator And AuthorityGreen
The DSS (Kirchstrasse 8, Vaduz) is the sole national supervisory authority, headed by Dr Marie-Louise Gächter, and is a full member of the EDPB with regard to GDPR matters (without voting rights).
Claims: CLM-LI-a1b2c3d4, CLM-LI-b2c3d4e5
Act And InstrumentsGreen
GDPR applies directly via EEA incorporation; the DSG and DSV are the domestic implementing instruments.
Claims: CLM-LI-c3d4e5f6, CLM-LI-d4e5f6a7
Material ScopeGreen
The DSG tracks GDPR material scope with no major derogations, covering legal bases, data subject rights, and transfer rules.
Claims: CLM-LI-e5f6a7b8
Territorial ScopeGreen
GDPR Article 3 territorial scope applies as incorporated into the EEA Agreement; no LI-specific narrowing was identified in the sources reviewed.
Consistent with the GDPR model, Liechtenstein does not operate a general prior-registration/notification regime for controllers; accountability is discharged through internal records (ROPA) rather than filings with the DSS.
Liechtenstein is an EEA-EFTA state that has incorporated the GDPR directly via EEA Joint Committee Decision No. 154/2018, giving the Regulation direct legal effect. The domestic implementing framework is the Data Protection Act (Datenschutzgesetz, DSG) of 4 October 2018 and the Data Protection Ordinance (DSV) of 11 December 2018, both effective 9 January 2019, closely modelled on Germany's BDSG. The Datenschutzstelle (DSS) is the national supervisory authority, an EDPB member (non-voting, as an EFTA-EEA state alongside Iceland and Norway).
Sources and claims (6)
ConfirmedDatenschutzstelle / EDPB — The Datenschutzstelle (DSS), based in Vaduz, is Liechtenstein's national data protection supervisory authority responsible for GDPR enforcement.
ConfirmedEDPB — The supervisory authorities of the EFTA EEA States, including Liechtenstein, Iceland and Norway, are EDPB members with regard to GDPR-related matters, without voting rights.
ConfirmedDataGuidance — Liechtenstein implemented the GDPR through the Data Protection Act of 4 October 2018 (DSG) and the Data Protection Ordinance of 11 December 2018 (DSV), both effective 9 January 2019.
ConfirmedDataGuidance — The EEA Joint Committee adopted Decision No. 154/2018 incorporating the GDPR into the EEA Agreement, making the GDPR directly applicable in Liechtenstein.
ConfirmedDataGuidance — The DSG does not contain major derogations from the GDPR and details legal bases for processing, data subject rights, and requirements for data transfers, and is closely aligned with the German BDSG.
ProbableDataGuidance — Liechtenstein's GDPR-aligned regime relies on internal accountability documentation (e.g., records of processing) rather than a general prior-notification/registration duty to the DSS.
Traffic-light rationale — GreenFull GDPR-aligned lawful-basis and special-category regime; DSS has issued specific guidance filling practical gaps (e.g., incapacitated adults).
Sub-modules (4)
Lawful BasesGreen
GDPR Article 6 lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interests) apply directly; DSS newsletters have discussed legitimate-interest principles in national court rulings.
Claims: CLM-LI-g7h8i9j0
Consent ThresholdsGreen
The DSS has issued specific guidance on obtaining valid consent for adults incapable of giving consent, applying GDPR consent standards (freely given, informed, revocable) to vulnerable adults.
Claims: CLM-LI-h8i9j0k1
Special CategoriesGreen
Article 9/10 GDPR special-category and criminal-data rules apply; DSS DPIA guidance explicitly references Art 9 and Art 10 data in its high-risk processing examples.
Claims: CLM-LI-i9j0k1l2
Pseudonymisation And AnonymisationAmber
No LI-specific pseudonymisation/anonymisation guidance beyond the GDPR baseline was identified in the sources reviewed.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Pseudonymisierung Anonymisierung guidance.
Category narrative34 words
Lawful bases, consent standards, and special-category rules follow GDPR Articles 6, 7 and 9 directly as incorporated via the EEA Agreement, with DSS guidance addressing practical application (e.g., consent by adults incapable of consenting).
Sources and claims (3)
ProbableDataGuidance — Liechtenstein's DSS newsletter summarised recent court rulings on GDPR and DSG covering, among other things, legitimate interest principles.
ConfirmedDataGuidance — The DSS issued guidance on obtaining valid consent for adults incapable of giving consent under GDPR.
ConfirmedDatenschutzstelle / hosted via EDPB — DSS DPIA guidance identifies processing of special categories of data under Article 9 and data referred to in Article 10 GDPR as requiring heightened scrutiny and, in certain circumstances, a mandatory DPIA.
Traffic-light rationale — GreenRights regime is fully GDPR-aligned with active DSS interpretive guidance; standard one-month response deadlines apply via direct GDPR incorporation.
Sub-modules (5)
Access RightGreen
DSS has issued guidance on employee email access requests and general subject-access mechanics.
Claims: CLM-LI-j0k1l2m3
Rectification And ErasureGreen
DSS guidance clarifies GDPR obligations for data deletion and erasure, including storage-limitation recommendations.
Claims: CLM-LI-k1l2m3n4
Restriction And ObjectionGreen
DSS has addressed the right to object in the context of Google Street View image collection, and issued a newsletter on court rulings concerning abusive exercise of data subject rights.
Claims: CLM-LI-l2m3n4o5, CLM-LI-m3n4o5p6
Data PortabilityAmber
No LI-specific portability guidance beyond the direct GDPR Article 20 baseline was identified.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein data portability guidance Art 20.
Deadlines And Response WindowsGreen
The standard one-month (extendable to three months for complex requests) GDPR response deadline applies directly via EEA incorporation; no LI-specific shortening or lengthening was identified.
Absence provenance: not recorded. Searched: Liechtenstein DSG response deadline data subject request.
Category narrative42 words
Data subject rights (access, rectification, erasure, restriction, objection, portability) follow GDPR Articles 15-22 directly, with the DSS issuing practical guidance on access requests, erasure/deletion, and objection rights (e.g., regarding Google Street View), plus newsletter commentary on abusive exercise of data subject rights.
Sources and claims (4)
ConfirmedDataGuidance — The DSS has provided guidance on employee email access requests.
ConfirmedDataGuidance — DSS guidance clarifies GDPR obligations for data deletion and erasure, emphasizing conditions and storage recommendations.
ConfirmedDataGuidance — DSS has discussed Google's Street View image collection and individuals' rights to object under GDPR.
ProbableDataGuidance — DSS newsletter highlighted court rulings on abusive exercise of data subject rights under GDPR.
Comprehensive GDPR-aligned controller/processor duties with an active, EDPB-coordinated DPIA guidance framework and functioning breach-notification channel.
Primary frameworkGDPR Articles 24-39 as incorporated via EEA Agreement; DSG/DSV
Traffic-light rationale — GreenComprehensive GDPR-aligned controller/processor duties with an active, EDPB-coordinated DPIA guidance framework and functioning breach-notification channel.
Sub-modules (7)
Accountability And DpiaGreen
The DSS's DPIA guidance (Feb 2019) provides a non-exhaustive list of processing operations requiring a DPIA, supplementing the general criteria in Article 35(1) and (3) GDPR and the WP29/EDPB DPIA guidelines.
Claims: CLM-LI-n4o5p6q7, CLM-LI-o5p6q7r8
Dpo RequirementsGreen
DPO appointment thresholds follow GDPR Articles 37-39; a DSS newsletter reported a national court ruling concerning DPO dismissal protections.
Claims: CLM-LI-p6q7r8s9
Ropa RequirementsAmber
Records of processing activities obligations follow GDPR Article 30 directly; no LI-specific ROPA template or additional obligation beyond the GDPR baseline was identified.
Joint-controller obligations follow GDPR Article 26 directly; DSS guidance on company-sale scenarios discusses controller responsibilities during share/asset deals but not joint-controller arrangements specifically.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein gemeinsame Verantwortliche Art 26.
Security MeasuresGreen
Technical and organisational security-of-processing obligations follow GDPR Article 32 directly via EEA incorporation.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Sicherheitsmassnahmen Art 32.
Breach NotificationGreen
The DSS accepts breach notifications in German or English, consistent with the GDPR Article 33/34 72-hour regulator-notification and high-risk subject-communication framework.
Claims: CLM-LI-q7r8s9t0
Retention And DisposalGreen
DSS guidance addresses storage-limitation and deletion/erasure recommendations, and separately clarifies that data protection obligations end with death (other laws govern deceased persons' data).
Claims: CLM-LI-r8s9t0u1
Category narrative56 words
Accountability, DPIA, DPO, ROPA, security, breach-notification and retention duties follow GDPR Articles 24-39 directly via EEA incorporation. The DSS has published a detailed DPIA 'blacklist' (high-risk processing list) since February 2019, and its breach-notification channel accepts submissions in German or English. National court rulings reported via DSS newsletters have addressed DPO dismissal protections and health-data handling.
Sources and claims (5)
ConfirmedDatenschutzstelle / hosted via EDPB — The Datenschutzstelle's DPIA guidance identifies types of processing (e.g., large-scale evaluation of authority-collected data forwarded to law enforcement, or processing of children's/vulnerable individuals' data for marketing, profiling or automated decision-making) as requiring a DPIA even where not otherwise 'extensive' within Article 35(3)(b) GDPR.
ConfirmedDatenschutzstelle / hosted via EDPB — Generally, any form of processing bearing a high risk to the rights and freedoms of individuals because of its nature, scope, circumstances and purpose, particularly when using new technologies, requires a prior DPIA under the DSS framework.
ProbableDataGuidance — A DSS newsletter summarised recent national court rulings on GDPR and DSG covering DPO dismissal, health data handling, and legitimate interest principles.
ConfirmedEDPB — Liechtenstein's Data Protection Authority accepts data breach notifications in German or English.
ProbableDataGuidance — Liechtenstein's data protection regime ends with death, with other (non-DP) laws governing the handling of deceased persons' data.
Full GDPR Chapter V transfer regime applies via EEA incorporation, with active DSS transfer guidance and enforcement notices, plus recognition as a qualifying state under the EU-U.S. DPF.
Primary frameworkGDPR Articles 44-49 as incorporated via EEA Agreement
Traffic-light rationale — GreenFull GDPR Chapter V transfer regime applies via EEA incorporation, with active DSS transfer guidance and enforcement notices, plus recognition as a qualifying state under the EU-U.S. DPF.
Sub-modules (6)
Transfer MechanismsGreen
GDPR Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Article 49 derogations) apply directly; DSS has published guidance on international data transfers and adequacy.
Claims: CLM-LI-s9t0u1v2
Adequacy ReceivedGreen
Liechtenstein, alongside all EEA member states, is designated a 'qualifying state' under the EU-U.S. Data Privacy Framework, giving its residents access to enhanced US privacy protections and the Data Protection Review Court.
Claims: CLM-LI-t0u1v2w3
Adequacy GrantedGreen
The UK's EU adequacy decisions (GDPR and LED) apply to personal data transferred from the whole EEA, including Liechtenstein, to the UK without additional safeguards.
Claims: CLM-LI-u1v2w3x4
Sccs And BcrsGreen
SCCs and BCRs operate as under the GDPR baseline; the EDPB has issued Article 64 opinions on BCRs involving Liechtenstein members, indicating active BCR coordination through the DSS.
Claims: CLM-LI-v2w3x4y5
Transfer Impact AssessmentAmber
Post-Schrems II transfer impact assessment practice applies via the GDPR baseline; DSS has issued guidance addressing international transfers and third-country adequacy assessment, including flagging TikTok's transfers as unlawful.
Claims: CLM-LI-w3x4y5z6
Data LocalisationGreen
No general data-localisation mandate was identified in the DSG/DSV; Liechtenstein follows the GDPR's free-flow-within-EEA model, subject to sector-specific police/judicial cooperation instruments (e.g., biometric/dactyloscopic data-sharing with the EU).
Claims: CLM-LI-x4y5z6a7
Category narrative92 words
As an EEA-EFTA state, Liechtenstein benefits from and applies the GDPR's transfer regime (adequacy decisions, SCCs, BCRs, derogations) directly. It is treated as part of the EEA for the purposes of third-country adequacy decisions (e.g., the UK's EU adequacy decisions apply to transfers from the whole EEA including Liechtenstein), and Liechtenstein is listed as a 'qualifying state' under the EU-U.S. Data Privacy Framework, giving its residents access to the U.S. Data Protection Review Court redress mechanism. The DSS has issued guidance on international transfers and warned of unlawful third-country transfers (e.g., TikTok).
Sources and claims (6)
ConfirmedDataGuidance — The DSS has published guidance on international data transfers and adequacy applicable in Liechtenstein.
ConfirmedIAPP — Under the EU-U.S. Data Privacy Framework, EU member states along with Iceland, Liechtenstein and Norway are designated 'qualifying states', whose citizens can seek redress through the U.S. Data Protection Review Court.
ConfirmedICO — The UK's EU adequacy decisions apply to personal data transferred from all EEA countries, defined to include Iceland, Liechtenstein and Norway, allowing flows to the UK without additional safeguards.
ConfirmedDatenschutzstelle / EDPB — The EDPB has adopted Article 64 opinions on Binding Corporate Rules with Liechtenstein as a concerned member state, indicating active national BCR coordination.
ConfirmedDataGuidance — The DSS issued a notice on TikTok's unlawful data transfers to third countries, recommending organizations assess transfer risks and inform users.
ConfirmedEUR-Lex / Official Journal of the EU — Personal data relating to dactyloscopic (fingerprint) data may be supplied by EU Member States to Switzerland and Liechtenstein from 1 July 2026 under a dedicated Council Implementing Decision, reflecting sector-specific (law-enforcement) cross-border data-sharing arrangements rather than general data localisation.
Financial, health, telecoms/cookie and employment overlays are evidenced via DSS guidance/reports; credit-scoring, education, and insurance sub-modules lack dedicated LI sources.
Primary frameworkGDPR as incorporated via EEA Agreement, overlaid with sector-specific Liechtenstein financial-market and other sectoral rules
Traffic-light rationale — AmberFinancial, health, telecoms/cookie and employment overlays are evidenced via DSS guidance/reports; credit-scoring, education, and insurance sub-modules lack dedicated LI sources.
Sub-modules (7)
Financial Sector OverlayAmber
DataGuidance maintains a dedicated opinion piece on data protection in Liechtenstein's financial sector, reflecting the interaction between GDPR and the jurisdiction's banking/trust industry oversight (Finanzmarktaufsicht, FMA).
Claims: CLM-LI-y5z6a7b8
Health Sector OverlayGreen
DSS newsletters reference national court rulings covering health data handling under GDPR/DSG.
Claims: CLM-LI-z6a7b8c9
Telecoms And EprivacyGreen
DSS updated cookie guidance clarifying consent requirements and conditions for relying on legitimate interest for cookies/trackers.
Claims: CLM-LI-a7b8c9d0
Employment DataGreen
The DSS's 2024 annual report highlighted inquiries covering employment data alongside AI data processing and video surveillance.
Claims: CLM-LI-b8c9d0e1
Credit And ScoringRed
No LI-specific credit-scoring guidance or rules were identified in the sources reviewed.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Kredit Scoring, Liechtenstein credit scoring data protection.
EducationRed
No LI-specific education-sector data protection guidance was identified beyond a general reference to social-media age-restriction guidance.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Schule Bildung Datenschutz.
InsuranceRed
No LI-specific insurance-sector data protection guidance was identified in the sources reviewed.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Versicherung Datenschutz.
Category narrative50 words
Liechtenstein's financial-sector data processing (a core feature of its economy as a private-banking/trust hub) interacts with GDPR through DSS-published sector guidance; other sector overlays (health, telecoms/eprivacy for cookies, employment) are addressed via DSS newsletters and reports, while credit-scoring, education, and insurance-specific overlays were not separately evidenced in the sources reviewed.
Sources and claims (4)
UncertainDataGuidance — DataGuidance publishes a dedicated analysis of data protection in Liechtenstein's financial sector, reflecting the interplay between GDPR/DSG and financial-market regulation in the jurisdiction.
ProbableDataGuidance — A DSS newsletter summarising recent court rulings on GDPR and DSG covered health data handling among other topics.
ConfirmedDataGuidance — DSS updated guidance on cookies clarifies consent requirements and the conditions under which legitimate interest may be used for cookie-based tracking.
ConfirmedDataGuidance — The DSS's 2024 report highlights inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures.
Cookie/tracker consent is actively covered by DSS guidance; several other sub-modules (dark patterns, opt-out signals, clean rooms, cross-context advertising, direct marketing specifics) lack dedicated LI sources and rely on the GDPR/ePrivacy baseline.
Primary frameworkGDPR + EU ePrivacy Directive as applied in Liechtenstein via EEA incorporation
Traffic-light rationale — AmberCookie/tracker consent is actively covered by DSS guidance; several other sub-modules (dark patterns, opt-out signals, clean rooms, cross-context advertising, direct marketing specifics) lack dedicated LI sources and rely on the GDPR/ePrivacy baseline.
Sub-modules (6)
Cookies And TrackersGreen
DSS updated cookie guidance clarifies consent requirements and legitimate-interest conditions, applying European case law on cookies in Liechtenstein.
Claims: CLM-LI-c9d0e1f2
Dark PatternsRed
No LI-specific dark-pattern guidance was identified in the sources reviewed.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein dark patterns manipulative design.
Opt Out SignalsRed
No LI-specific Global Privacy Control / opt-out-signal guidance was identified in the sources reviewed.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Global Privacy Control opt-out signal.
Clean Rooms And DcrRed
No LI-specific clean-room/data-collaboration-room guidance was identified in the sources reviewed.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein data clean room.
Cross Context AdvertisingAmber
No LI-specific 'sale'/'share' cross-context-advertising framework (a US state-law concept) was identified; the GDPR consent/legitimate-interest baseline governs behavioural advertising instead.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein cross-context advertising sale share.
Direct MarketingAmber
Direct marketing is governed by the GDPR Article 21(2) unconditional right to object baseline as incorporated via the EEA Agreement; no LI-specific suppression-list regime was identified.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Direktmarketing Widerspruchsrecht.
Category narrative47 words
Cookie/tracker consent follows the ePrivacy/GDPR baseline as applied by the DSS, which has issued updated cookie guidance. Dark-pattern prohibitions, opt-out signals (e.g., GPC), clean-room arrangements, and cross-context advertising rules specific to Liechtenstein were not separately evidenced; direct marketing follows the GDPR Article 21(2) right to object baseline.
Sources and claims (1)
ConfirmedDataGuidance — The DSS has published guidance on international data transfers and adequacy, and on the application of European case law concerning cookies in Liechtenstein.
Profiling/ADM and AI-risk sub-modules are well evidenced via active DSS guidance; biometric, genetic-data, and state-surveillance sub-modules rely more heavily on the general GDPR baseline.
Primary frameworkGDPR Article 22 and Articles 9-10 as incorporated via EEA Agreement
Traffic-light rationale — AmberProfiling/ADM and AI-risk sub-modules are well evidenced via active DSS guidance; biometric, genetic-data, and state-surveillance sub-modules rely more heavily on the general GDPR baseline.
Sub-modules (6)
Profiling RestrictionsGreen
DSS DPIA guidance flags profiling for automated decision-making, particularly involving children or vulnerable individuals, as requiring a DPIA even outside 'extensive' processing.
Claims: CLM-LI-d0e1f2g3
Automated Decision Making TransparencyGreen
Article 22 GDPR ADM transparency/explanation rights apply directly via EEA incorporation; DSS DPIA guidance references auto-decision-making as a high-risk trigger.
Claims: CLM-LI-e1f2g3h4
Ai Risk AssessmentsAmber
The DSS has actively engaged with AI-specific risks: warning against DeepSeek R1 on privacy grounds, providing guidance on using AI systems/chatbots with personal data, and announcing Meta's plan to use public EU user data for AI training with an objection deadline.
Claims: CLM-LI-f2g3h4i5, CLM-LI-g3h4i5j6
Biometric RegimeAmber
DSS has updated guidance on video surveillance limitations; dedicated facial-recognition/biometric-specific rules beyond the GDPR Art 9 special-category baseline were not separately evidenced, though cross-border dactyloscopic data-sharing with the EU is now permitted from mid-2026.
Claims: CLM-LI-h4i5j6k7
Genetic DataAmber
Genetic data is treated as a special category under GDPR Article 9 as incorporated via the EEA Agreement; no LI-specific genetic-data guidance was identified.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein genetische Daten.
State Surveillance CarveoutsRed
No LI-specific analysis of national-security/state-surveillance carve-outs and their limits was identified in the sources reviewed.
Absence provenance: not recorded. Searched: Liechtenstein Staatssicherheit Überwachung Datenschutz Ausnahme.
Category narrative57 words
Profiling and ADM transparency follow GDPR Article 22 directly, reinforced by DSS DPIA guidance flagging profiling/automated decision-making (including for marketing purposes) as high-risk processing. The DSS has actively addressed AI-specific risks (DeepSeek R1 warnings, Meta AI-training objection notice, chatbot guidance) and video-surveillance/biometric-adjacent processing, but no dedicated genetic-data regime or state-surveillance carve-out analysis specific to Liechtenstein was identified.
Sources and claims (5)
ConfirmedDatenschutzstelle / hosted via EDPB — DSS DPIA guidance identifies processing of children's or other vulnerable individuals' data for marketing or profiling for automated decision-making as requiring a DPIA even where not 'extensive' under Article 35(3)(b) GDPR.
ConfirmedDatenschutzstelle / hosted via EDPB — The DSS's DPIA blacklist references automated decision-making as a high-risk processing trigger requiring assessment consistent with Article 22 and Article 35 GDPR.
ConfirmedDataGuidance — The DSS warned of data protection risks associated with the AI service DeepSeek R1 and advised the use of GDPR-compliant tools.
ConfirmedDataGuidance — The DSS announced Meta's plan to use public data from European users for AI training and provided a window for objections until 26 May 2025.
ConfirmedDataGuidance — The DSS updated its guidance on video surveillance, addressing limitations on the practice.
Age-verification, minor-profiling and dependent-adult sub-modules are evidenced via active DSS guidance; parental-consent-age specifics and education-settings rules rely on the unlocalised GDPR Article 8 baseline.
Primary frameworkGDPR Article 8 as incorporated via EEA Agreement; DSG
Traffic-light rationale — AmberAge-verification, minor-profiling and dependent-adult sub-modules are evidenced via active DSS guidance; parental-consent-age specifics and education-settings rules rely on the unlocalised GDPR Article 8 baseline.
Sub-modules (5)
Age VerificationGreen
DSS has provided GDPR compliance guidance addressing social media age restrictions.
Claims: CLM-LI-i5j6k7l8
Parental ConsentAmber
GDPR Article 8 sets a default digital-consent age of 16, with member/EEA states able to lower it to as low as 13; no LI-specific statutory age lower than the GDPR default was identified in the sources reviewed.
Absence provenance: not recorded. Searched: Liechtenstein DSG Art 8 GDPR age of consent children digital services.
Minor Profiling BansGreen
DSS DPIA guidance treats profiling of children or other vulnerable individuals for marketing or automated decision-making as a DPIA-triggering high-risk activity, functioning as a de facto heightened-scrutiny regime rather than an outright ban.
Claims: CLM-LI-j6k7l8m9
Education SettingsRed
No LI-specific education-settings data protection guidance was identified beyond the general age-restriction guidance.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Schule Datenschutz Bildungseinrichtung.
Dependent AdultsGreen
DSS issued specific guidance on obtaining valid consent for adults incapable of giving consent under GDPR, addressing dependent/vulnerable adult protections.
Claims: CLM-LI-k7l8m9n0
Category narrative51 words
Children's data processing follows GDPR Article 8 as incorporated via the EEA Agreement; the DSS has issued guidance on social-media age restrictions and flagged minors'/vulnerable individuals' profiling as a DPIA trigger. Vulnerable-adult protections are addressed through DSS guidance on consent by adults incapable of consenting. Education-settings-specific rules were not separately evidenced.
Sources and claims (3)
ConfirmedDataGuidance — The DSS provides GDPR compliance guidance on data access and social media age restrictions.
ConfirmedDatenschutzstelle / hosted via EDPB — Processing of personal data of children or other vulnerable individuals for marketing, profiling for automated decision-making, or the offer of online services requires a DPIA under DSS guidance even where not 'extensive' under Article 35(3)(b) GDPR.
ConfirmedDataGuidance — The DSS issued guidance on obtaining valid consent for adults incapable of giving consent under GDPR.
Enforcement powers and recent developments are well evidenced; specific collective-redress/private-right-of-action mechanics and regulator funding/headcount data for Liechtenstein were not separately sourced.
Primary frameworkGDPR Articles 58, 77-84 as incorporated via EEA Agreement; DSG
Traffic-light rationale — AmberEnforcement powers and recent developments are well evidenced; specific collective-redress/private-right-of-action mechanics and regulator funding/headcount data for Liechtenstein were not separately sourced.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The DSS has GDPR Article 58 corrective powers (investigation, warnings, orders, bans) and Article 83 administrative-fine powers, applied via direct EEA incorporation of the GDPR.
Claims: CLM-LI-l8m9n0o1
Enforcement Activity IndexAmber
The DSS's 2024 report highlighted inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures; the 2023 report covered GDPR compliance, AI services, video surveillance, and data protection breaches.
Claims: CLM-LI-m9n0o1p2, CLM-LI-n0o1p2q3
Regulator Funding And CapacityRed
No specific funding or headcount data for the DSS was identified in the sources reviewed.
Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Budget Personal Kapazität.
Collective Redress And Class ActionsRed
No Liechtenstein-specific collective-redress or class-action mechanism for data protection claims was identified; the EU Representative Actions Directive is an EU-only instrument and its applicability to the EEA-EFTA state was not confirmed in sources reviewed.
Absence provenance: not recorded. Searched: Liechtenstein collective redress class action data protection, Representative Actions Directive Liechtenstein EEA.
Private Right Of ActionGreen
GDPR Articles 79-82 (judicial remedy against controllers/processors and compensation) apply directly via EEA incorporation; individuals may also lodge complaints with the DSS or national courts.
Claims: CLM-LI-o1p2q3r4
Recent Developments 180DGreen
Within the last 180 days: the DSS issued a notice (reported 9 January 2026) on TikTok's unlawful data transfers to third countries; the May 2026 IAPP Global Summit update confirmed Liechtenstein's continued 'qualifying state' status under the EU-U.S. Data Privacy Framework; and a Council Implementing Decision of 25 June 2026 (2026/1459) set 1 July 2026 as the date from which EU Member States may supply dactyloscopic data to Switzerland and Liechtenstein.
The DSS holds full GDPR Article 58 investigative and corrective powers, including the Article 83 administrative-fine framework (up to the higher of a fixed sum or a percentage of worldwide turnover), applied directly via EEA incorporation. The DSS's 2024 annual report recorded no fines imposed despite several formal measures, following a 2023 report covering GDPR compliance inquiries, AI, video surveillance and breach matters. Recent developments include a January 2026 DSS notice on TikTok's unlawful third-country transfers, the May 2026 EU-US adequacy update confirming Liechtenstein's 'qualifying state' status, and a June 2026 Council Implementing Decision extending dactyloscopic data-sharing to Liechtenstein from July 2026.
Sources and claims (7)
ConfirmedEUR-Lex / CJEU — Each GDPR supervisory authority, including the DSS as incorporated via the EEA Agreement, has corrective powers under Article 58(2) including the power to impose administrative fines under Article 83.
ConfirmedDataGuidance — The DSS's 2024 report highlights inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures.
ConfirmedDataGuidance — Liechtenstein's DSS 2023 report covers inquiries on GDPR compliance, AI services, video surveillance, and data protection breaches.
ConfirmedEDPB — An individual has the right to lodge a complaint with a data protection authority of an EEA Member State, which includes the EU countries plus Iceland, Liechtenstein and Norway.
ConfirmedDataGuidance — The DSS issued a notice on TikTok's unlawful transfer of personal data to third countries, recommending organizations assess risks and inform users.
ConfirmedIAPP — At the IAPP Global Summit 2026, US and EU officials provided an update on the status of the EU-U.S. Data Privacy Framework, under which Liechtenstein remains a designated qualifying state.
ConfirmedEUR-Lex / Official Journal of the EU — Council Implementing Decision (EU) 2026/1459 of 25 June 2026 set 1 July 2026 as the date from which personal data relating to dactyloscopic data may be supplied by EU Member States to Switzerland and Liechtenstein.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Liechtenstein
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s), 13 source(s) in the cumulative register.