Law / Luxembourg

Luxembourg

privacy

Luxembourg's private-sector regime is the General Data Protection Regulation (GDPR) plus the Act of 1 August 2018 on the organisation of the National Data Protection Commission (CNPD) and the general data protection framework, in effect from 20 August 2018.

The notable finding for this jurisdiction is a genuine absence rather than a gap: a CMS Expert Guide entry, read directly this pass, states no specific provisions regarding biometrics are envisaged in the Act, so a voiceprint or faceprint captured for identification is governed by GDPR Article 9 alone, with no Luxembourg-specific addition. A GDPR Article 82 compensation claim is brought before the ordinary civil courts rather than the CNPD. As at 2026-08-24; later amendment is not independently confirmed.

11 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

GDPR Articles 33-34, Breach Notification in Luxembourg

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

A controller must notify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Luxembourg, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Act of 1 August 2018 derogation from this timeline was identified in this pass.

What it asks of an app

Comprehensive regime

Act of 1 August 2018 on the Organisation of the CNPD and the General Data Protection Framework

cite Loi du 1er aout 2018 portant organisation de la Commission nationale pour la protection des donnees et du regime general sur la protection des donnees stage In effect since 2018-08-20 source CNPD official PDF (cnpd.public.lu)

Luxembourg's private-sector regime is the General Data Protection Regulation (GDPR) plus the Act of 1 August 2018 on the organisation of the National Data Protection Commission (CNPD) and the general data protection framework, in effect from 20 August 2018, which repealed the prior 2 August 2002 data protection law. The Act supplies domestic derogations and procedural rules and establishes the CNPD's own organisation.

A CMS Expert Guide entry, read in this pass, states directly that no specific provisions regarding biometrics are envisaged in the Act, the genuine finding for this jurisdiction rather than a gap; see the sensitive-categories instrument below.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Luxembourg

cite Regulation (EU) 2016/679, Arts. 44-49 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Transferring personal data of a person in Luxembourg outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Act of 1 August 2018 derogation broadening or narrowing this was identified in this pass.

What it asks of an app

Data subject rights

GDPR Article 22, Automated Decisions as Applied in Luxembourg

cite Regulation (EU) 2016/679, Art. 22 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing. No Luxembourg-specific broadening or narrowing of these rights was identified in this pass.

What it asks of an app

Enforcement supervision

GDPR Articles 82-83 and CNPD Enforcement in Luxembourg

cite Regulation (EU) 2016/679, Arts. 82-83 stage In effect since 2018-05-25 source Secondary commentary (CMS) on the CNPD's administrative role and civil-court compensation route, not independently confirmed against the Act's own text for the compensation-forum detail

The CNPD is the supervisory authority for administrative enforcement (General Data Protection Regulation (GDPR) Article 83 fines), while a GDPR Article 82 compensation claim is brought before the ordinary civil courts (tribunal d'arrondissement) rather than the CNPD itself, per secondary commentary read this pass. No Luxembourg-specific fine ceiling beyond the GDPR Article 83 maximum was identified.

What it asks of an app

Sensitive categories

GDPR Article 9, Special Categories of Personal Data as Applied in Luxembourg

cite Regulation (EU) 2016/679, Art. 9 stage In effect since 2018-05-25 source CMS Expert Guide to Data Protection and Cyber Security Laws, Luxembourg entry, fetched and read directly

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. Unlike every other jurisdiction in this batch, Luxembourg was searched specifically for a biometric-specific national derogation and none was found: a CMS Expert Guide entry states directly that no specific provisions regarding biometrics are envisaged in the Act of 1 August 2018, and that the general GDPR framework applies without a national addition.

A voiceprint or faceprint captured for identification purposes is therefore governed in Luxembourg by GDPR Article 9 alone. No Luxembourg-specific voiceprint case or regulatory guidance was located.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.