Law note · Luxembourg

Act of 1 August 2018 on the Organisation of the CNPD and the General Data Protection Framework

cite Loi du 1er aout 2018 portant organisation de la Commission nationale pour la protection des donnees et du regime general sur la protection des donnees stage In effect since 2018-08-20 reviewed 2026-08-24

Luxembourg's private-sector regime is the General Data Protection Regulation (GDPR) plus the Act of 1 August 2018 on the organisation of the National Data Protection Commission (CNPD) and the general data protection framework, in effect from 20 August 2018, which repealed the prior 2 August 2002 data protection law. The Act supplies domestic derogations and procedural rules and establishes the CNPD's own organisation.

A CMS Expert Guide entry, read in this pass, states directly that no specific provisions regarding biometrics are envisaged in the Act, the genuine finding for this jurisdiction rather than a gap; see the sensitive-categories instrument below.

What it asks of an app

  • Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Luxembourg, including data collected by crawling.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: CNPD official PDF (cnpd.public.lu)
CMS Expert Guide to Data Protection and Cyber Security Laws, Luxembourg entry, fetched and read directly

← Back to the example  ·  Lint your app →