Skip to the content
Global Data RulesData governance rules, country by country

Luxembourg

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

For most businesses, data can leave Luxembourg on the same terms as anywhere else in the European Union: you need the right paperwork, not a local data centre. Finance is the exception, and finance is most of the economy here. Banks and insurers are bound by a secrecy duty that is a crime to break, and a bank that runs its accounts abroad must still keep a daily backup inside Europe.

Eight questions about Luxembourg

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Luxembourg's rules apply to my company?

Yes. If you sell to people in Luxembourg or watch what they do online, the European privacy rules reach you even with no office here. There is no revenue or headcount threshold to hide under. A company with no base anywhere in Europe must appoint a representative in Europe, though it does not have to be in Luxembourg. The extra Luxembourg-only duties in the national law mostly apply to organisations that are actually set up here.

High confidenceBloc rulesNational rulesAppoint a local representative

Can I store my users' data outside Luxembourg?

In general, yes, with paperwork. Luxembourg has no national law telling ordinary companies to keep data in the country, and European law actually forbids member states from forcing non-personal data to stay put except on public-security grounds. But this is a banking and fund centre, and the finance rules change the answer. A bank or insurer may only hand client information to a supplier abroad if the client has been told and has accepted which country that supplier is in. And a bank whose accounting system sits outside Luxembourg must still keep a full daily backup somewhere inside the European Economic Area.

High confidenceDepends on your industryAllowlistKeep the data in the country

What do I need in place before data leaves Luxembourg?

The model is a European approved-list. Sending personal data outside Europe is barred unless the destination is on the European Commission's approved list, or you put an approved safeguard in place first. The list is real and populated. Luxembourg adds no national permit and the regulator does not pre-approve ordinary transfers. In finance, though, you also need the client's acceptance of the destination country before their information moves.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesCertification schemeApproved code of conductExplicit consentNeeded for a contractLegal claims

Who enforces the rules in Luxembourg, and what can they do?

Yes, the regulators here really work. The privacy regulator is the National Commission for Data Protection, known as the CNPD. It is staffed, it publishes decisions, and in 2025 it handled 846 complaints, 425 breach reports and 59 investigations. It issued the largest privacy fine ever recorded in Europe, against Amazon in 2021. The financial regulator and the insurance regulator are heavyweight supervisors in their own right, and since May 2026 the telecoms regulator also runs the national cybersecurity regime.

High confidenceActiveDaily fine until fixedCriminal liability

How long do I have to keep the data?

There is a floor and a ceiling, and they collide often. You must keep anti-money-laundering records for 5 years after the relationship ends, patient files for at least 10 years after care ends, and telephone and internet connection records for 6 months. In the other direction, European privacy law says delete personal data once you no longer need it, and the anti-money-laundering law says delete it when the 5 years are up unless another law makes you keep it longer. That last sentence is how Luxembourg resolves the clash: the longest specific legal duty wins, and after that you must actually erase.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

Count four clocks, because they overlap and they start at different moments. Privacy breach: 72 hours to tell the privacy regulator. Telephone and internet providers: 24 hours to report a personal data breach. Cybersecurity incidents at important companies: an early warning in 24 hours, a fuller report in 72 hours, and a final report a month later. Banks and insurers have their own European reporting on top. The trap is that one incident can start all of them at once, on different teams, with different forms.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Luxembourg?

Five things that are not in any summary. (1) Breaking bank or insurance client secrecy is a crime, not a fine, and it survives the end of the job. (2) Your works council can freeze an employee-monitoring project: staff have 15 days to ask the privacy regulator for an opinion, and that request suspends the project for a month. (3) Research projects carry a fixed list of 12 extra safeguards you must apply or justify skipping. (4) Using genetic data for employment or insurance purposes is banned outright. (5) The privacy regulator cannot fine the State or a commune, so a public body has far less to lose than you do.

High confidenceCriminal liabilityExtra vendor secrecy termsAssess high-risk projectsAppoint a data protection officerGet a parent's consent for children

What is changing soon in Luxembourg?

Two dated changes and several switches already in someone's hand. The dated ones: from 12 January 2027 cloud providers must let customers move away with no exit or transfer fees at all, and Luxembourg's new cybersecurity law, in force since 10 May 2026, is still being filled in with guidance and templates. The switches to watch: the European approval of United States transfers is under formal challenge, and the 6-month duty on telecoms firms to keep call records sits uneasily with European court rulings and could be struck at any time.

Medium confidenceProposedMake switching cloud provider possible

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    1 rule here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    2 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    6 rules here

  4. Layer 4

    Contract-imposed rule

    Binds you because you signed something, typically a government contract.

    1 rule here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules1 rule

Reglement general sur la protection des donnees (RGPD) - Reglement (UE) 2016/679

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European privacy rulebook. It never requires data to stay in Europe; it sets conditions for sending it out. Fines scale with worldwide group turnover, and an order to stop processing usually hurts more than the fine.

In force since 25 May 2018

Enforced by National Commission for Data Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

National rules2 rules

Loi du 1er aout 2018 portant organisation de la Commission nationale pour la protection des donnees et mise en oeuvre du reglement (UE) 2016/679

Act of parliament · Memorial A no 686 of 16 August 2018

In forceYes, with paperwork

Luxembourg's national add-on to the European rules. It creates the regulator, adds a heavy 12-point safeguard list for research, bans genetic data in employment and insurance decisions, gives staff a power to suspend monitoring projects, and - a real gap - stops the regulator fining the State or the communes.

In force since 20 August 2018

Enforced by National Commission for Data Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Loi du 5 mai 2026 concernant des mesures destinees a assurer un niveau eleve de cybersecurite

Act of parliament · Memorial A no 225, published 6 May 2026

In forceYes — store it anywhere

Luxembourg's transposition of the European cybersecurity directive, adopted 5 May 2026 and in force since 10 May 2026. Three clocks - 24 hours, 72 hours, one month - and a registration duty whose statutory deadline of 17 January 2025 was already in the past on the day the law started.

In force since 10 May 2026

Enforced by Luxembourg Regulatory Institute

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules6 rules

Loi modifiee du 5 avril 1993 relative au secteur financier, article 41 (secret professionnel)

Act of parliament · Article 41 LFS, paragraph 2a inserted by the Law of 27 February 2018 · Banking

In forceYes, with paperwork

Luxembourg banking secrecy is a criminal duty, not a civil one. Client information can go to an outsourcing provider abroad, but only if the client has accepted the outsourcing, the type of information and the supplier's country of establishment - which makes the destination country a contract term, not an engineering choice.

In force since 5 April 1993But only enforceable from 27 February 2018

Enforced by Financial Sector Supervisory Commission

Transfer model: Approval each time · Accepted routes: Explicit consent

High confidence

Circulaire CSSF 22/806 relative aux arrangements d'externalisation, telle que modifiee par la circulaire CSSF 25/883

Regulator directive · Circular CSSF 22/806, points 28 and 59, as amended by Circular CSSF 25/883 of 9 April 2025 · Finance

Partly in forceA copy must stay

The only genuine storage-location rule found in Luxembourg. A supervised financial firm may host its accounting system abroad, but must still hold a full, readable end-of-day backup of all accounting and client positions on premises inside the European Economic Area. Critical outsourcings need three months' prior notice to the regulator.

In force since 30 June 2022

Enforced by Financial Sector Supervisory Commission

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Loi modifiee du 7 decembre 2015 sur le secteur des assurances, articles 181-3 et 300

Act of parliament · Articles 181-3 and 300, consolidated text of 3 April 2026 · Insurance

In forceYes, with paperwork

Insurance secrecy mirrors banking secrecy and is equally criminal. On top, an insurer processing health data must apply a listed set of safeguards, four of which - encryption, access limits, access logs and staff awareness - may never be derogated from.

In force since 7 December 2015But only enforceable from 27 February 2018

Enforced by Insurance Commission

Transfer model: Approval each time · Accepted routes: Explicit consent

High confidence

Contract-imposed rule1 rule

Loi du 25 juillet 2015 relative a l'archivage electronique

Act of parliament · Law of 25 July 2015, amending Article 1334 of the Civil Code and Article 16 of the Commercial Code

In forceYes, with paperwork

Not a location rule but a certification wall. A digital copy made by a provider certified under this law has, unless proved otherwise, the same evidential weight as the paper original - so if you want to scan and destroy Luxembourg records, you need a certified provider on the national list.

In force since 8 August 2015

Enforced by Luxembourg Institute for Standardisation, Accreditation, Safety and Quality of Products and Services

Transfer model: No restriction · Accepted routes: Certification scheme

High confidence

Who you would hear from

  • Commission nationale pour la protection des donnees (CNPD)

    General privacy law, electronic communications privacy, and new European roles under the Data Governance Act

    Fully staffed and working. Its 2025 annual report, presented on 10 July 2026, records 846 complaints received (up 40 per cent on 2024), 1,909 complaints handled, 425 personal data breach notifications, 59 investigation cases and 16 opinions on draft laws. Anonymised decisions are published for 2021 to 2025, the most recent dated 16 December 2025. It cannot fine the State or the communes.

  • Commission de Surveillance du Secteur Financier (CSSF)

    Banks, investment firms, payment and e-money institutions, support PFS, funds and management companies

    Highly active. Runs the outsourcing notification regime under Circular 22/806, amended with immediate effect by Circular 25/883 on 9 April 2025, and licenses the support-PFS statuses that IT operators and archivers serving the financial sector need.

  • Commissariat aux Assurances (CAA)

    Insurers, reinsurers, pension funds, insurance service providers and distributors

    Active supervisor. Publishes the consolidated insurance sector law, most recently updated 3 April 2026, and maintains a public sanctions page.

  • Institut Luxembourgeois de Regulation (ILR)

    Telecoms, postal services, energy, and since May 2026 the competent authority for network and information system security

    Operational and building out the new cybersecurity regime: it runs the SERIMA incident notification platform, publishes security-measure templates, and extended its public consultations on the new law during 2026.

  • Institut luxembourgeois de la normalisation, de l'accreditation, de la securite et qualite des produits et services (ILNAS)

    Accredits the certifiers and maintains the public list of certified digitisation and electronic conservation providers

    Named in the Law of 25 July 2015 as the body that validates listings and may verify at any time that a provider still meets the conditions. Cooperates with the CSSF where the provider is also a support PFS.

  • Commissariat du Gouvernement a la protection des donnees aupres de l'Etat

    Acts as data protection officer for state administrations and, on request, for communes; advises ministers

    Created by Articles 56 to 61 of the Law of 1 August 2018 and placed under the Prime Minister. We verified its creation and mandate in the statute; we did not verify its current headcount from a government source. It advises and coordinates; it does not fine.

  • Tribunal administratif

    Hears appeals against CNPD decisions and rehears them on the merits

    Article 55 of the Law of 1 August 2018 gives it full merits jurisdiction, so it can substitute its own decision rather than only checking the regulator's process.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The outcome of Amazon's appeal against the CNPD's EUR 746 million fine of July 2021

    We could not open a searchable database of Luxembourg administrative court decisions during this run. The fine is widely reported as the largest European privacy fine ever issued, and appeals are heard on the merits by the Administrative Tribunal, so the amount could in principle have been varied. Treat the figure as the amount imposed, not necessarily the amount finally payable.

  • The general 10-year retention period for accounting books and commercial records under Article 16 of the Commercial Code

    Widely stated and consistent with the Law of 25 July 2015 which amends that same Article 16, but we could not open an official consolidated text of the Commercial Code or a government guidance page for it on 18 August 2026. Treat as very likely true but not backlinked here.

  • Whether the 6-month telecoms retention duty in Articles 5 and 9 of the Law of 30 May 2005 has been disapplied by a Luxembourg court or superseded by a reform bill

    The provision is still in the consolidated text published by the CNPD and the law remains recorded as in force. Blanket retention of this kind has been repeatedly criticised by the Court of Justice of the European Union. We found no Luxembourg judgment disapplying it and no repeal, so it is recorded as in force with medium confidence. This is the single most likely item in this record to be wrong within a year.

  • Whether any localisation or sovereign-hosting requirement applies to Luxembourg government cloud, education, online gaming, mapping and geospatial data, or defence-related data

    No rule found, checked 18 August 2026. We searched the regulators' own sites and the official gazette and did not locate one. Absence of a finding is not proof of absence, and public-sector procurement conditions are not always published as law.

  • Whether health data hosting in Luxembourg requires any certification comparable to the French certified health data host regime

    The Law of 24 July 2014 and the shared care record regime set access and retention rules but we found no hosting-certification requirement. Recorded as 'not found' rather than 'does not exist'.

  • The exact penalties in Article 458 of the Luxembourg Penal Code that back banking and insurance secrecy

    Both sector laws refer to Article 458 without restating the figures, and we did not open a consolidated Penal Code from an official source in this run. The criminal character of the duty is verified; the numbers are not.

  • Whether the registration deadline of 17 January 2025 written into Article 17 of the cybersecurity law of 5 May 2026 has been extended in practice by the regulator

    The date is in the enacted text and the law only commenced on 10 May 2026, so the deadline is already past on its face. The ILR is running consultations and publishing templates, which suggests practical forbearance, but we found no published extension.

  • Current staffing of the Government Commissioner for Data Protection within the State

    Its creation and mandate are verified from the statute. We did not find a government page confirming who currently holds the post.

  • The exact commencement dates of the Law of 27 February 2018 (which inserted the outsourcing carve-outs into banking and insurance secrecy), the Law of 1 August 2018, and the Law of 25 July 2015

    Luxembourg laws commence a short fixed period after publication in the official journal unless they say otherwise. We verified the adoption and publication dates but could not open an official commencement statement for these three, so the dates in this record are the adoption date or the standard post-publication date and may be out by a few days. The commencement date of the cybersecurity law of 5 May 2026, 10 May 2026, is taken from the official journal's own metadata and is verified.

60-day cadence. Three things move here: the new cybersecurity law of 5 May 2026 is being filled in with regulator guidance and templates through 2026; the telecoms retention duty is exposed to European case law and could be disapplied without a Luxembourg legislative step; and the EU-US Data Privacy Framework, which a large share of Luxembourg's fund and payments industry relies on, is under formal challenge with the European Data Protection Board having written to the Commission on 31 July 2026.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.