🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
LI · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

Liechtenstein

LI schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 44 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
44Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Full GDPR incorporation with a closely-aligned national implementing act and an active, EDPB-integrated supervisory authority; no material derogations identified.

Primary frameworkGDPR (EU) 2016/679 as incorporated into the EEA Agreement, implemented via the Liechtenstein Data Protection Act (DSG) of 4 October 2018 and Data Protection Ordinance (DSV) of 11 December 2018
Traffic-light rationale — GreenFull GDPR incorporation with a closely-aligned national implementing act and an active, EDPB-integrated supervisory authority; no material derogations identified.

Sub-modules (5)

Regulator And AuthorityGreen

The DSS (Kirchstrasse 8, Vaduz) is the sole national supervisory authority, headed by Dr Marie-Louise Gächter, and is a full member of the EDPB with regard to GDPR matters (without voting rights).

Claims: CLM-LI-a1b2c3d4, CLM-LI-b2c3d4e5

Act And InstrumentsGreen

GDPR applies directly via EEA incorporation; the DSG and DSV are the domestic implementing instruments.

Claims: CLM-LI-c3d4e5f6, CLM-LI-d4e5f6a7

Material ScopeGreen

The DSG tracks GDPR material scope with no major derogations, covering legal bases, data subject rights, and transfer rules.

Claims: CLM-LI-e5f6a7b8

Territorial ScopeGreen

GDPR Article 3 territorial scope applies as incorporated into the EEA Agreement; no LI-specific narrowing was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Liechtenstein DSG territorial scope non-established controllers, DataGuidance Liechtenstein jurisdiction overview.

Regulator Registration And FilingAmber

Consistent with the GDPR model, Liechtenstein does not operate a general prior-registration/notification regime for controllers; accountability is discharged through internal records (ROPA) rather than filings with the DSS.

Absence provenance: not recorded. Searched: Liechtenstein DSG registration filing controllers, Datenschutzstelle Meldepflicht.

Claims: CLM-LI-f6a7b8c9

Category narrative79 words

Liechtenstein is an EEA-EFTA state that has incorporated the GDPR directly via EEA Joint Committee Decision No. 154/2018, giving the Regulation direct legal effect. The domestic implementing framework is the Data Protection Act (Datenschutzgesetz, DSG) of 4 October 2018 and the Data Protection Ordinance (DSV) of 11 December 2018, both effective 9 January 2019, closely modelled on Germany's BDSG. The Datenschutzstelle (DSS) is the national supervisory authority, an EDPB member (non-voting, as an EFTA-EEA state alongside Iceland and Norway).

Sources and claims (6)
  1. ConfirmedDatenschutzstelle / EDPBThe Datenschutzstelle (DSS), based in Vaduz, is Liechtenstein's national data protection supervisory authority responsible for GDPR enforcement.
  2. ConfirmedEDPBThe supervisory authorities of the EFTA EEA States, including Liechtenstein, Iceland and Norway, are EDPB members with regard to GDPR-related matters, without voting rights.
  3. ConfirmedDataGuidanceLiechtenstein implemented the GDPR through the Data Protection Act of 4 October 2018 (DSG) and the Data Protection Ordinance of 11 December 2018 (DSV), both effective 9 January 2019.
  4. ConfirmedDataGuidanceThe EEA Joint Committee adopted Decision No. 154/2018 incorporating the GDPR into the EEA Agreement, making the GDPR directly applicable in Liechtenstein.
  5. ConfirmedDataGuidanceThe DSG does not contain major derogations from the GDPR and details legal bases for processing, data subject rights, and requirements for data transfers, and is closely aligned with the German BDSG.
  6. ProbableDataGuidanceLiechtenstein's GDPR-aligned regime relies on internal accountability documentation (e.g., records of processing) rather than a general prior-notification/registration duty to the DSS.

#

Full GDPR-aligned lawful-basis and special-category regime; DSS has issued specific guidance filling practical gaps (e.g., incapacitated adults).

Primary frameworkGDPR Articles 6, 7, 9 as incorporated via EEA Agreement; DSG
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — GreenFull GDPR-aligned lawful-basis and special-category regime; DSS has issued specific guidance filling practical gaps (e.g., incapacitated adults).

Sub-modules (4)

Lawful BasesGreen

GDPR Article 6 lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interests) apply directly; DSS newsletters have discussed legitimate-interest principles in national court rulings.

Claims: CLM-LI-g7h8i9j0

Special CategoriesGreen

Article 9/10 GDPR special-category and criminal-data rules apply; DSS DPIA guidance explicitly references Art 9 and Art 10 data in its high-risk processing examples.

Claims: CLM-LI-i9j0k1l2

Pseudonymisation And AnonymisationAmber

No LI-specific pseudonymisation/anonymisation guidance beyond the GDPR baseline was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Pseudonymisierung Anonymisierung guidance.

Category narrative34 words

Lawful bases, consent standards, and special-category rules follow GDPR Articles 6, 7 and 9 directly as incorporated via the EEA Agreement, with DSS guidance addressing practical application (e.g., consent by adults incapable of consenting).

Sources and claims (3)
  1. ProbableDataGuidanceLiechtenstein's DSS newsletter summarised recent court rulings on GDPR and DSG covering, among other things, legitimate interest principles.
  2. ConfirmedDataGuidanceThe DSS issued guidance on obtaining valid consent for adults incapable of giving consent under GDPR.
  3. ConfirmedDatenschutzstelle / hosted via EDPBDSS DPIA guidance identifies processing of special categories of data under Article 9 and data referred to in Article 10 GDPR as requiring heightened scrutiny and, in certain circumstances, a mandatory DPIA.

#

Rights regime is fully GDPR-aligned with active DSS interpretive guidance; standard one-month response deadlines apply via direct GDPR incorporation.

Primary frameworkGDPR Articles 12-23 as incorporated via EEA Agreement; DSG
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — GreenRights regime is fully GDPR-aligned with active DSS interpretive guidance; standard one-month response deadlines apply via direct GDPR incorporation.

Sub-modules (5)

Access RightGreen

DSS has issued guidance on employee email access requests and general subject-access mechanics.

Claims: CLM-LI-j0k1l2m3

Rectification And ErasureGreen

DSS guidance clarifies GDPR obligations for data deletion and erasure, including storage-limitation recommendations.

Claims: CLM-LI-k1l2m3n4

Restriction And ObjectionGreen

DSS has addressed the right to object in the context of Google Street View image collection, and issued a newsletter on court rulings concerning abusive exercise of data subject rights.

Claims: CLM-LI-l2m3n4o5, CLM-LI-m3n4o5p6

Data PortabilityAmber

No LI-specific portability guidance beyond the direct GDPR Article 20 baseline was identified.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein data portability guidance Art 20.

Deadlines And Response WindowsGreen

The standard one-month (extendable to three months for complex requests) GDPR response deadline applies directly via EEA incorporation; no LI-specific shortening or lengthening was identified.

Absence provenance: not recorded. Searched: Liechtenstein DSG response deadline data subject request.

Category narrative42 words

Data subject rights (access, rectification, erasure, restriction, objection, portability) follow GDPR Articles 15-22 directly, with the DSS issuing practical guidance on access requests, erasure/deletion, and objection rights (e.g., regarding Google Street View), plus newsletter commentary on abusive exercise of data subject rights.

Sources and claims (4)
  1. ConfirmedDataGuidanceThe DSS has provided guidance on employee email access requests.
  2. ConfirmedDataGuidanceDSS guidance clarifies GDPR obligations for data deletion and erasure, emphasizing conditions and storage recommendations.
  3. ConfirmedDataGuidanceDSS has discussed Google's Street View image collection and individuals' rights to object under GDPR.
  4. ProbableDataGuidanceDSS newsletter highlighted court rulings on abusive exercise of data subject rights under GDPR.

#

Comprehensive GDPR-aligned controller/processor duties with an active, EDPB-coordinated DPIA guidance framework and functioning breach-notification channel.

Primary frameworkGDPR Articles 24-39 as incorporated via EEA Agreement; DSG/DSV
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — GreenComprehensive GDPR-aligned controller/processor duties with an active, EDPB-coordinated DPIA guidance framework and functioning breach-notification channel.

Sub-modules (7)

Accountability And DpiaGreen

The DSS's DPIA guidance (Feb 2019) provides a non-exhaustive list of processing operations requiring a DPIA, supplementing the general criteria in Article 35(1) and (3) GDPR and the WP29/EDPB DPIA guidelines.

Claims: CLM-LI-n4o5p6q7, CLM-LI-o5p6q7r8

Dpo RequirementsGreen

DPO appointment thresholds follow GDPR Articles 37-39; a DSS newsletter reported a national court ruling concerning DPO dismissal protections.

Claims: CLM-LI-p6q7r8s9

Ropa RequirementsAmber

Records of processing activities obligations follow GDPR Article 30 directly; no LI-specific ROPA template or additional obligation beyond the GDPR baseline was identified.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Verzeichnis Verarbeitungstätigkeiten ROPA template.

Joint Controller ArrangementsAmber

Joint-controller obligations follow GDPR Article 26 directly; DSS guidance on company-sale scenarios discusses controller responsibilities during share/asset deals but not joint-controller arrangements specifically.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein gemeinsame Verantwortliche Art 26.

Security MeasuresGreen

Technical and organisational security-of-processing obligations follow GDPR Article 32 directly via EEA incorporation.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Sicherheitsmassnahmen Art 32.

Breach NotificationGreen

The DSS accepts breach notifications in German or English, consistent with the GDPR Article 33/34 72-hour regulator-notification and high-risk subject-communication framework.

Claims: CLM-LI-q7r8s9t0

Retention And DisposalGreen

DSS guidance addresses storage-limitation and deletion/erasure recommendations, and separately clarifies that data protection obligations end with death (other laws govern deceased persons' data).

Claims: CLM-LI-r8s9t0u1

Category narrative56 words

Accountability, DPIA, DPO, ROPA, security, breach-notification and retention duties follow GDPR Articles 24-39 directly via EEA incorporation. The DSS has published a detailed DPIA 'blacklist' (high-risk processing list) since February 2019, and its breach-notification channel accepts submissions in German or English. National court rulings reported via DSS newsletters have addressed DPO dismissal protections and health-data handling.

Sources and claims (5)
  1. ConfirmedDatenschutzstelle / hosted via EDPBThe Datenschutzstelle's DPIA guidance identifies types of processing (e.g., large-scale evaluation of authority-collected data forwarded to law enforcement, or processing of children's/vulnerable individuals' data for marketing, profiling or automated decision-making) as requiring a DPIA even where not otherwise 'extensive' within Article 35(3)(b) GDPR.
  2. ConfirmedDatenschutzstelle / hosted via EDPBGenerally, any form of processing bearing a high risk to the rights and freedoms of individuals because of its nature, scope, circumstances and purpose, particularly when using new technologies, requires a prior DPIA under the DSS framework.
  3. ProbableDataGuidanceA DSS newsletter summarised recent national court rulings on GDPR and DSG covering DPO dismissal, health data handling, and legitimate interest principles.
  4. ConfirmedEDPBLiechtenstein's Data Protection Authority accepts data breach notifications in German or English.
  5. ProbableDataGuidanceLiechtenstein's data protection regime ends with death, with other (non-DP) laws governing the handling of deceased persons' data.

#

Full GDPR Chapter V transfer regime applies via EEA incorporation, with active DSS transfer guidance and enforcement notices, plus recognition as a qualifying state under the EU-U.S. DPF.

Primary frameworkGDPR Articles 44-49 as incorporated via EEA Agreement
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — GreenFull GDPR Chapter V transfer regime applies via EEA incorporation, with active DSS transfer guidance and enforcement notices, plus recognition as a qualifying state under the EU-U.S. DPF.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Article 49 derogations) apply directly; DSS has published guidance on international data transfers and adequacy.

Claims: CLM-LI-s9t0u1v2

Adequacy ReceivedGreen

Liechtenstein, alongside all EEA member states, is designated a 'qualifying state' under the EU-U.S. Data Privacy Framework, giving its residents access to enhanced US privacy protections and the Data Protection Review Court.

Claims: CLM-LI-t0u1v2w3

Adequacy GrantedGreen

The UK's EU adequacy decisions (GDPR and LED) apply to personal data transferred from the whole EEA, including Liechtenstein, to the UK without additional safeguards.

Claims: CLM-LI-u1v2w3x4

Sccs And BcrsGreen

SCCs and BCRs operate as under the GDPR baseline; the EDPB has issued Article 64 opinions on BCRs involving Liechtenstein members, indicating active BCR coordination through the DSS.

Claims: CLM-LI-v2w3x4y5

Transfer Impact AssessmentAmber

Post-Schrems II transfer impact assessment practice applies via the GDPR baseline; DSS has issued guidance addressing international transfers and third-country adequacy assessment, including flagging TikTok's transfers as unlawful.

Claims: CLM-LI-w3x4y5z6

Data LocalisationGreen

No general data-localisation mandate was identified in the DSG/DSV; Liechtenstein follows the GDPR's free-flow-within-EEA model, subject to sector-specific police/judicial cooperation instruments (e.g., biometric/dactyloscopic data-sharing with the EU).

Claims: CLM-LI-x4y5z6a7

Category narrative92 words

As an EEA-EFTA state, Liechtenstein benefits from and applies the GDPR's transfer regime (adequacy decisions, SCCs, BCRs, derogations) directly. It is treated as part of the EEA for the purposes of third-country adequacy decisions (e.g., the UK's EU adequacy decisions apply to transfers from the whole EEA including Liechtenstein), and Liechtenstein is listed as a 'qualifying state' under the EU-U.S. Data Privacy Framework, giving its residents access to the U.S. Data Protection Review Court redress mechanism. The DSS has issued guidance on international transfers and warned of unlawful third-country transfers (e.g., TikTok).

Sources and claims (6)
  1. ConfirmedDataGuidanceThe DSS has published guidance on international data transfers and adequacy applicable in Liechtenstein.
  2. ConfirmedIAPPUnder the EU-U.S. Data Privacy Framework, EU member states along with Iceland, Liechtenstein and Norway are designated 'qualifying states', whose citizens can seek redress through the U.S. Data Protection Review Court.
  3. ConfirmedICOThe UK's EU adequacy decisions apply to personal data transferred from all EEA countries, defined to include Iceland, Liechtenstein and Norway, allowing flows to the UK without additional safeguards.
  4. ConfirmedDatenschutzstelle / EDPBThe EDPB has adopted Article 64 opinions on Binding Corporate Rules with Liechtenstein as a concerned member state, indicating active national BCR coordination.
  5. ConfirmedDataGuidanceThe DSS issued a notice on TikTok's unlawful data transfers to third countries, recommending organizations assess transfer risks and inform users.
  6. ConfirmedEUR-Lex / Official Journal of the EUPersonal data relating to dactyloscopic (fingerprint) data may be supplied by EU Member States to Switzerland and Liechtenstein from 1 July 2026 under a dedicated Council Implementing Decision, reflecting sector-specific (law-enforcement) cross-border data-sharing arrangements rather than general data localisation.

#

Financial, health, telecoms/cookie and employment overlays are evidenced via DSS guidance/reports; credit-scoring, education, and insurance sub-modules lack dedicated LI sources.

Primary frameworkGDPR as incorporated via EEA Agreement, overlaid with sector-specific Liechtenstein financial-market and other sectoral rules
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — AmberFinancial, health, telecoms/cookie and employment overlays are evidenced via DSS guidance/reports; credit-scoring, education, and insurance sub-modules lack dedicated LI sources.

Sub-modules (7)

Financial Sector OverlayAmber

DataGuidance maintains a dedicated opinion piece on data protection in Liechtenstein's financial sector, reflecting the interaction between GDPR and the jurisdiction's banking/trust industry oversight (Finanzmarktaufsicht, FMA).

Claims: CLM-LI-y5z6a7b8

Health Sector OverlayGreen

DSS newsletters reference national court rulings covering health data handling under GDPR/DSG.

Claims: CLM-LI-z6a7b8c9

Telecoms And EprivacyGreen

DSS updated cookie guidance clarifying consent requirements and conditions for relying on legitimate interest for cookies/trackers.

Claims: CLM-LI-a7b8c9d0

Employment DataGreen

The DSS's 2024 annual report highlighted inquiries covering employment data alongside AI data processing and video surveillance.

Claims: CLM-LI-b8c9d0e1

Credit And ScoringRed

No LI-specific credit-scoring guidance or rules were identified in the sources reviewed.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Kredit Scoring, Liechtenstein credit scoring data protection.

EducationRed

No LI-specific education-sector data protection guidance was identified beyond a general reference to social-media age-restriction guidance.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Schule Bildung Datenschutz.

InsuranceRed

No LI-specific insurance-sector data protection guidance was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Versicherung Datenschutz.

Category narrative50 words

Liechtenstein's financial-sector data processing (a core feature of its economy as a private-banking/trust hub) interacts with GDPR through DSS-published sector guidance; other sector overlays (health, telecoms/eprivacy for cookies, employment) are addressed via DSS newsletters and reports, while credit-scoring, education, and insurance-specific overlays were not separately evidenced in the sources reviewed.

Sources and claims (4)
  1. UncertainDataGuidanceDataGuidance publishes a dedicated analysis of data protection in Liechtenstein's financial sector, reflecting the interplay between GDPR/DSG and financial-market regulation in the jurisdiction.
  2. ProbableDataGuidanceA DSS newsletter summarising recent court rulings on GDPR and DSG covered health data handling among other topics.
  3. ConfirmedDataGuidanceDSS updated guidance on cookies clarifies consent requirements and the conditions under which legitimate interest may be used for cookie-based tracking.
  4. ConfirmedDataGuidanceThe DSS's 2024 report highlights inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures.

#

Cookie/tracker consent is actively covered by DSS guidance; several other sub-modules (dark patterns, opt-out signals, clean rooms, cross-context advertising, direct marketing specifics) lack dedicated LI sources and rely on the GDPR/ePrivacy baseline.

Primary frameworkGDPR + EU ePrivacy Directive as applied in Liechtenstein via EEA incorporation
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — AmberCookie/tracker consent is actively covered by DSS guidance; several other sub-modules (dark patterns, opt-out signals, clean rooms, cross-context advertising, direct marketing specifics) lack dedicated LI sources and rely on the GDPR/ePrivacy baseline.

Sub-modules (6)

Cookies And TrackersGreen

DSS updated cookie guidance clarifies consent requirements and legitimate-interest conditions, applying European case law on cookies in Liechtenstein.

Claims: CLM-LI-c9d0e1f2

Dark PatternsRed

No LI-specific dark-pattern guidance was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein dark patterns manipulative design.

Opt Out SignalsRed

No LI-specific Global Privacy Control / opt-out-signal guidance was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No LI-specific clean-room/data-collaboration-room guidance was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein data clean room.

Cross Context AdvertisingAmber

No LI-specific 'sale'/'share' cross-context-advertising framework (a US state-law concept) was identified; the GDPR consent/legitimate-interest baseline governs behavioural advertising instead.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein cross-context advertising sale share.

Direct MarketingAmber

Direct marketing is governed by the GDPR Article 21(2) unconditional right to object baseline as incorporated via the EEA Agreement; no LI-specific suppression-list regime was identified.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Direktmarketing Widerspruchsrecht.

Category narrative47 words

Cookie/tracker consent follows the ePrivacy/GDPR baseline as applied by the DSS, which has issued updated cookie guidance. Dark-pattern prohibitions, opt-out signals (e.g., GPC), clean-room arrangements, and cross-context advertising rules specific to Liechtenstein were not separately evidenced; direct marketing follows the GDPR Article 21(2) right to object baseline.

Sources and claims (1)
  1. ConfirmedDataGuidanceThe DSS has published guidance on international data transfers and adequacy, and on the application of European case law concerning cookies in Liechtenstein.

#

Profiling/ADM and AI-risk sub-modules are well evidenced via active DSS guidance; biometric, genetic-data, and state-surveillance sub-modules rely more heavily on the general GDPR baseline.

Primary frameworkGDPR Article 22 and Articles 9-10 as incorporated via EEA Agreement
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — AmberProfiling/ADM and AI-risk sub-modules are well evidenced via active DSS guidance; biometric, genetic-data, and state-surveillance sub-modules rely more heavily on the general GDPR baseline.

Sub-modules (6)

Profiling RestrictionsGreen

DSS DPIA guidance flags profiling for automated decision-making, particularly involving children or vulnerable individuals, as requiring a DPIA even outside 'extensive' processing.

Claims: CLM-LI-d0e1f2g3

Automated Decision Making TransparencyGreen

Article 22 GDPR ADM transparency/explanation rights apply directly via EEA incorporation; DSS DPIA guidance references auto-decision-making as a high-risk trigger.

Claims: CLM-LI-e1f2g3h4

Ai Risk AssessmentsAmber

The DSS has actively engaged with AI-specific risks: warning against DeepSeek R1 on privacy grounds, providing guidance on using AI systems/chatbots with personal data, and announcing Meta's plan to use public EU user data for AI training with an objection deadline.

Claims: CLM-LI-f2g3h4i5, CLM-LI-g3h4i5j6

Biometric RegimeAmber

DSS has updated guidance on video surveillance limitations; dedicated facial-recognition/biometric-specific rules beyond the GDPR Art 9 special-category baseline were not separately evidenced, though cross-border dactyloscopic data-sharing with the EU is now permitted from mid-2026.

Claims: CLM-LI-h4i5j6k7

Genetic DataAmber

Genetic data is treated as a special category under GDPR Article 9 as incorporated via the EEA Agreement; no LI-specific genetic-data guidance was identified.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein genetische Daten.

State Surveillance CarveoutsRed

No LI-specific analysis of national-security/state-surveillance carve-outs and their limits was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Liechtenstein Staatssicherheit Überwachung Datenschutz Ausnahme.

Category narrative57 words

Profiling and ADM transparency follow GDPR Article 22 directly, reinforced by DSS DPIA guidance flagging profiling/automated decision-making (including for marketing purposes) as high-risk processing. The DSS has actively addressed AI-specific risks (DeepSeek R1 warnings, Meta AI-training objection notice, chatbot guidance) and video-surveillance/biometric-adjacent processing, but no dedicated genetic-data regime or state-surveillance carve-out analysis specific to Liechtenstein was identified.

Sources and claims (5)
  1. ConfirmedDatenschutzstelle / hosted via EDPBDSS DPIA guidance identifies processing of children's or other vulnerable individuals' data for marketing or profiling for automated decision-making as requiring a DPIA even where not 'extensive' under Article 35(3)(b) GDPR.
  2. ConfirmedDatenschutzstelle / hosted via EDPBThe DSS's DPIA blacklist references automated decision-making as a high-risk processing trigger requiring assessment consistent with Article 22 and Article 35 GDPR.
  3. ConfirmedDataGuidanceThe DSS warned of data protection risks associated with the AI service DeepSeek R1 and advised the use of GDPR-compliant tools.
  4. ConfirmedDataGuidanceThe DSS announced Meta's plan to use public data from European users for AI training and provided a window for objections until 26 May 2025.
  5. ConfirmedDataGuidanceThe DSS updated its guidance on video surveillance, addressing limitations on the practice.

#

Age-verification, minor-profiling and dependent-adult sub-modules are evidenced via active DSS guidance; parental-consent-age specifics and education-settings rules rely on the unlocalised GDPR Article 8 baseline.

Primary frameworkGDPR Article 8 as incorporated via EEA Agreement; DSG
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — AmberAge-verification, minor-profiling and dependent-adult sub-modules are evidenced via active DSS guidance; parental-consent-age specifics and education-settings rules rely on the unlocalised GDPR Article 8 baseline.

Sub-modules (5)

Age VerificationGreen

DSS has provided GDPR compliance guidance addressing social media age restrictions.

Claims: CLM-LI-i5j6k7l8

Minor Profiling BansGreen

DSS DPIA guidance treats profiling of children or other vulnerable individuals for marketing or automated decision-making as a DPIA-triggering high-risk activity, functioning as a de facto heightened-scrutiny regime rather than an outright ban.

Claims: CLM-LI-j6k7l8m9

Education SettingsRed

No LI-specific education-settings data protection guidance was identified beyond the general age-restriction guidance.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Schule Datenschutz Bildungseinrichtung.

Dependent AdultsGreen

DSS issued specific guidance on obtaining valid consent for adults incapable of giving consent under GDPR, addressing dependent/vulnerable adult protections.

Claims: CLM-LI-k7l8m9n0

Category narrative51 words

Children's data processing follows GDPR Article 8 as incorporated via the EEA Agreement; the DSS has issued guidance on social-media age restrictions and flagged minors'/vulnerable individuals' profiling as a DPIA trigger. Vulnerable-adult protections are addressed through DSS guidance on consent by adults incapable of consenting. Education-settings-specific rules were not separately evidenced.

Sources and claims (3)
  1. ConfirmedDataGuidanceThe DSS provides GDPR compliance guidance on data access and social media age restrictions.
  2. ConfirmedDatenschutzstelle / hosted via EDPBProcessing of personal data of children or other vulnerable individuals for marketing, profiling for automated decision-making, or the offer of online services requires a DPIA under DSS guidance even where not 'extensive' under Article 35(3)(b) GDPR.
  3. ConfirmedDataGuidanceThe DSS issued guidance on obtaining valid consent for adults incapable of giving consent under GDPR.

#

Enforcement powers and recent developments are well evidenced; specific collective-redress/private-right-of-action mechanics and regulator funding/headcount data for Liechtenstein were not separately sourced.

Primary frameworkGDPR Articles 58, 77-84 as incorporated via EEA Agreement; DSG
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — AmberEnforcement powers and recent developments are well evidenced; specific collective-redress/private-right-of-action mechanics and regulator funding/headcount data for Liechtenstein were not separately sourced.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The DSS has GDPR Article 58 corrective powers (investigation, warnings, orders, bans) and Article 83 administrative-fine powers, applied via direct EEA incorporation of the GDPR.

Claims: CLM-LI-l8m9n0o1

Enforcement Activity IndexAmber

The DSS's 2024 report highlighted inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures; the 2023 report covered GDPR compliance, AI services, video surveillance, and data protection breaches.

Claims: CLM-LI-m9n0o1p2, CLM-LI-n0o1p2q3

Regulator Funding And CapacityRed

No specific funding or headcount data for the DSS was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Datenschutzstelle Liechtenstein Budget Personal Kapazität.

Collective Redress And Class ActionsRed

No Liechtenstein-specific collective-redress or class-action mechanism for data protection claims was identified; the EU Representative Actions Directive is an EU-only instrument and its applicability to the EEA-EFTA state was not confirmed in sources reviewed.

Absence provenance: not recorded. Searched: Liechtenstein collective redress class action data protection, Representative Actions Directive Liechtenstein EEA.

Private Right Of ActionGreen

GDPR Articles 79-82 (judicial remedy against controllers/processors and compensation) apply directly via EEA incorporation; individuals may also lodge complaints with the DSS or national courts.

Claims: CLM-LI-o1p2q3r4

Recent Developments 180DGreen

Within the last 180 days: the DSS issued a notice (reported 9 January 2026) on TikTok's unlawful data transfers to third countries; the May 2026 IAPP Global Summit update confirmed Liechtenstein's continued 'qualifying state' status under the EU-U.S. Data Privacy Framework; and a Council Implementing Decision of 25 June 2026 (2026/1459) set 1 July 2026 as the date from which EU Member States may supply dactyloscopic data to Switzerland and Liechtenstein.

Claims: CLM-LI-p2q3r4s5, CLM-LI-q3r4s5t6, CLM-LI-r4s5t6u7

Category narrative102 words

The DSS holds full GDPR Article 58 investigative and corrective powers, including the Article 83 administrative-fine framework (up to the higher of a fixed sum or a percentage of worldwide turnover), applied directly via EEA incorporation. The DSS's 2024 annual report recorded no fines imposed despite several formal measures, following a 2023 report covering GDPR compliance inquiries, AI, video surveillance and breach matters. Recent developments include a January 2026 DSS notice on TikTok's unlawful third-country transfers, the May 2026 EU-US adequacy update confirming Liechtenstein's 'qualifying state' status, and a June 2026 Council Implementing Decision extending dactyloscopic data-sharing to Liechtenstein from July 2026.

Sources and claims (7)
  1. ConfirmedEUR-Lex / CJEUEach GDPR supervisory authority, including the DSS as incorporated via the EEA Agreement, has corrective powers under Article 58(2) including the power to impose administrative fines under Article 83.
  2. ConfirmedDataGuidanceThe DSS's 2024 report highlights inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures.
  3. ConfirmedDataGuidanceLiechtenstein's DSS 2023 report covers inquiries on GDPR compliance, AI services, video surveillance, and data protection breaches.
  4. ConfirmedEDPBAn individual has the right to lodge a complaint with a data protection authority of an EEA Member State, which includes the EU countries plus Iceland, Liechtenstein and Norway.
  5. ConfirmedDataGuidanceThe DSS issued a notice on TikTok's unlawful transfer of personal data to third countries, recommending organizations assess risks and inform users.
  6. ConfirmedIAPPAt the IAPP Global Summit 2026, US and EU officials provided an update on the status of the EU-U.S. Data Privacy Framework, under which Liechtenstein remains a designated qualifying state.
  7. ConfirmedEUR-Lex / Official Journal of the EUCouncil Implementing Decision (EU) 2026/1459 of 25 June 2026 set 1 July 2026 as the date from which personal data relating to dactyloscopic data may be supplied by EU Member States to Switzerland and Liechtenstein.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Liechtenstein
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s), 13 source(s) in the cumulative register.