Law / Liechtenstein

Liechtenstein

privacy

Liechtenstein is not an EU member; it is an EEA/EFTA state, so the General Data Protection Regulation (GDPR) does not apply directly. The controlling instrument is Liechtenstein's own Datenschutzgesetz (DSG), LGBl. 2018 Nr. 272, in effect since 1 January 2019, which gives domestic legal effect to the GDPR as incorporated into the EEA Agreement by EEA Joint Committee Decision No. 154/2018.

Two attempts to extract the DSG's own statutory text failed this pass, so most findings below rest on the Datenschutzstelle's own first-party glossary of GDPR-equivalent concepts (which does name voice and images within the biometric-data concept it applies) or on structural inference from the DSG's GDPR-modeled design, and are recorded at medium confidence throughout rather than as primary-text findings. As at 2026-08-24; later amendment is not independently confirmed.

12 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

DSG Breach Notification in Liechtenstein

cite DSG, LGBl. 2018 Nr. 272, breach notification provisions stage In effect since 2019-01-01 source Secondary commentary and Datenschutzstelle materials, not independently confirmed against the DSG's own text this pass

Commentary and the Datenschutzstelle's own materials describe the DSG as carrying breach-notification duties mirroring the General Data Protection Regulation (GDPR) structure, notifying the Datenschutzstelle without undue delay on a qualifying breach and notifying the individual where the breach presents a high risk. The specific timeline, whether it is GDPR's 72-hour figure or a different DSG-specific figure, was not independently confirmed against the DSG's own text this pass.

What it asks of an app

Comprehensive regime

Datenschutzgesetz (DSG)

cite Datenschutzgesetz (DSG), LGBl. 2018 Nr. 272, dated 4 October 2018, in effect 1 January 2019 stage In effect since 2019-01-01 source gesetze.li official legislation database (navigation only, statutory text not extracted)

Liechtenstein is not an EU member; it is an EEA/EFTA state, so the General Data Protection Regulation (GDPR) does not apply directly. GDPR was incorporated into the EEA Agreement by EEA Joint Committee Decision No. 154/2018, and Liechtenstein gave that incorporation domestic legal effect through its own Datenschutzgesetz (DSG), LGBl. 2018 Nr. 272, in effect 1 January 2019 together with the implementing Datenschutzverordnung (DSV) of 11 December 2018.

The DSG, not the EU Regulation, is the instrument this document records as controlling authority. The Datenschutzstelle is Liechtenstein's national data protection authority.

Two separate attempts to extract the DSG's own statutory text failed this pass (a navigation-only page at gesetze.li, and an unparseable compressed structure at the Datenschutzstelle's official English translation PDF), so article-level detail below rests on the Datenschutzstelle's own first-party glossary of GDPR-equivalent concepts, or is described only in general, structural terms.

What it asks of an app

Cross border transfer

DSG Cross-Border Transfer Chapter and EEA Joint Committee Decision No. 154/2018

cite Datenschutzgesetz (DSG), LGBl. 2018 Nr. 272; EEA Joint Committee Decision No. 154/2018 stage In effect since 2019-01-01 source DSG general structure, inferred by analogy to the GDPR framework it transposes

The DSG carries its own transfer chapter, modeled on General Data Protection Regulation (GDPR) Chapter V, rather than being bound by the EU Regulation's Chapter V directly, since Liechtenstein is outside the EU.

Because Liechtenstein is inside the EEA and GDPR is incorporated EEA-wide, a transfer from Liechtenstein to an EU or EEA state is not a restricted cross-border transfer under this framework, by the same logic that intra-EU transfers are unrestricted under GDPR Chapter V itself; a transfer to a country outside the EEA is where the DSG's own adequacy, safeguards, or derogation mechanism engages. The DSG's own transfer-chapter article number and text were not independently confirmed against primary text this pass.

What it asks of an app

Data subject rights

DSG Automated-Decision Rights in Liechtenstein

cite DSG, LGBl. 2018 Nr. 272, automated decision provisions stage In effect since 2019-01-01 source Secondary commentary, not independently confirmed against the DSG's own text this pass

Secondary commentary describes the DSG as giving individuals rights against a decision based solely on automated processing, including profiling, that produces a significant legal or similarly significant effect, mirroring General Data Protection Regulation (GDPR) Article 22, with certain exceptions for contractual or insurance purposes. This was not independently confirmed against the DSG's own text this pass, since both attempts to access the DSG's own document failed to extract readable content.

What it asks of an app

Enforcement supervision

DSG Datenschutzstelle Enforcement in Liechtenstein

cite DSG, LGBl. 2018 Nr. 272, enforcement provisions stage In effect since 2019-01-01 source Secondary commentary, not independently confirmed against the DSG's own text this pass

The Datenschutzstelle enforces the DSG. One commentary source states violations may attract fines of up to 22 million Swiss francs or 4 percent of global annual turnover, a CHF-denominated figure tracking the General Data Protection Regulation (GDPR) EUR 20 million or 4 percent structure, since Liechtenstein uses the Swiss franc under its currency union with Switzerland rather than the euro; not independently confirmed against the DSG's own text this pass.

By analogy to the GDPR Article 82 structure the DSG is modeled on, the DSG is expected to carry its own compensation provision for a data subject who suffers damage from a DSG infringement; the specific article number was not confirmed and this is recorded at medium confidence, by structural inference rather than a read of the provision itself. No Liechtenstein-specific collective-redress mechanism was identified.

What it asks of an app

Sensitive categories

DSG Special-Category Data and Datenschutzstelle Biometric-Data Concept in Liechtenstein

cite DSG, LGBl. 2018 Nr. 272, special categories provisions stage In effect since 2019-01-01 source Datenschutzstelle glossary, fetched and read directly

Biometric identifiers are governed by the DSG's own special-category-data provisions, modeled on General Data Protection Regulation (GDPR) Article 9.

The Datenschutzstelle's own published glossary of GDPR-equivalent concepts, fetched and read directly, names both voice and images within the biometric-data concept it applies, and separately notes that voice is treated as a behavioral characteristic, with the specific technical processing method determining whether a given voice capture rises to the level of unique-identification biometric data.

This is the regulator's own restatement of the concept, not a quote from the DSG's own statutory Article 4 text, which could not be accessed directly in this pass; it is recorded at medium confidence for that reason. No Liechtenstein-specific voiceprint or faceprint case or regulatory guidance beyond this glossary entry was located.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.