Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
A controller must notify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Luxembourg, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Act of 1 August 2018 derogation from this timeline was identified in this pass.
What it asks of an app →
Comprehensive regime
cite Loi du 1er aout 2018 portant organisation de la Commission nationale pour la protection des donnees et du regime general sur la protection des donnees
stage In effect
since 2018-08-20
source CNPD official PDF (cnpd.public.lu)
Luxembourg's private-sector regime is the General Data Protection Regulation (GDPR) plus the Act of 1 August 2018 on the organisation of the National Data Protection Commission (CNPD) and the general data protection framework, in effect from 20 August 2018, which repealed the prior 2 August 2002 data protection law. The Act supplies domestic derogations and procedural rules and establishes the CNPD's own organisation.
A CMS Expert Guide entry, read in this pass, states directly that no specific provisions regarding biometrics are envisaged in the Act, the genuine finding for this jurisdiction rather than a gap; see the sensitive-categories instrument below.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Transferring personal data of a person in Luxembourg outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Act of 1 August 2018 derogation broadening or narrowing this was identified in this pass.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Art. 22
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing. No Luxembourg-specific broadening or narrowing of these rights was identified in this pass.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83
stage In effect
since 2018-05-25
source Secondary commentary (CMS) on the CNPD's administrative role and civil-court compensation route, not independently confirmed against the Act's own text for the compensation-forum detail
The CNPD is the supervisory authority for administrative enforcement (General Data Protection Regulation (GDPR) Article 83 fines), while a GDPR Article 82 compensation claim is brought before the ordinary civil courts (tribunal d'arrondissement) rather than the CNPD itself, per secondary commentary read this pass. No Luxembourg-specific fine ceiling beyond the GDPR Article 83 maximum was identified.
What it asks of an app →
Sensitive categories
cite Regulation (EU) 2016/679, Art. 9
stage In effect
since 2018-05-25
source CMS Expert Guide to Data Protection and Cyber Security Laws, Luxembourg entry, fetched and read directly
General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. Unlike every other jurisdiction in this batch, Luxembourg was searched specifically for a biometric-specific national derogation and none was found: a CMS Expert Guide entry states directly that no specific provisions regarding biometrics are envisaged in the Act of 1 August 2018, and that the general GDPR framework applies without a national addition.
A voiceprint or faceprint captured for identification purposes is therefore governed in Luxembourg by GDPR Article 9 alone. No Luxembourg-specific voiceprint case or regulatory guidance was located.
What it asks of an app →