Luxembourg
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Luxembourg — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send data out of Luxembourg. For most businesses the rules match the rest of the European Union. You need the right paperwork, not a local data centre. Finance is the exception, and finance is most of the economy here. Banks and insurers must keep client information secret. Breaking that secrecy is a crime. A bank that runs its accounts abroad must still keep a daily backup inside Europe.
Data governance in Luxembourg
The eight things that decide how you handle data about people in Luxembourg. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. If you sell to people in Luxembourg, the European privacy rules reach you even with no office here. The same is true if you track what they do online. There is no revenue or staff cut-off. A company with no base anywhere in Europe must appoint a representative in Europe. That representative does not have to be in Luxembourg. The extra Luxembourg-only duties in the national law mostly apply to organisations actually set up here.
- What you have to do here:
- Appoint a representative
The reach comes from Article 3 of the General Data Protection Regulation, not from Luxembourg law. The Law of 1 August 2018 sets up the national regulator and adds national choices on top. Its Article 2 says the duties in Title II apply to companies set up on Luxembourg territory. That covers both the companies that decide how data is used and the ones that handle it for someone else. The cybersecurity law of 5 May 2026 has its own reach. Article 16 makes certain companies based outside the European Union appoint a representative. If they do not, the authority can ask the President of the Luxembourg District Court for a fast order appointing one. Financial and insurance secrecy duties attach to people set up in Luxembourg and supervised here. For insurance, they also cover business run from Luxembourg into other countries.
Sources
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 1 August 2018 organising the CNPD and implementing the GDPR, Article 2 (territorial application of Title II)
data.legilux.public.lu
Link checked 18 August 2026
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 5 May 2026 on cybersecurity, Article 16 - representative in the European Union, appointable by court order
data.legilux.public.lu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
Where the data is allowed to live
Yes, in general, with paperwork. Luxembourg has no national law telling ordinary companies to keep data in the country. European law also stops member states forcing non-personal data to stay put, except on public security grounds. But this is a banking and fund centre, and the finance rules change the answer. A bank or insurer may only hand client information to a supplier abroad with the client's agreement. The client must be told which country the supplier is in. And a bank whose accounting system sits outside Luxembourg must still keep a full daily backup somewhere inside the European Economic Area.
- What you have to do here:
- Keep the data in the country
Industry by industry, checked 18 August 2026. BANKING AND INVESTMENT FIRMS. Paperwork works, with one hard location rule. Article 41 of the Law of 5 April 1993 on the financial sector makes breaking client secrecy a crime. Since a 2018 change, paragraph 2a lets you outsource without breaking secrecy in two cases. Either the supplier is itself supervised in Luxembourg and bound by secrecy under criminal law. Or, in every other case, the client has agreed to three things. Those are the outsourcing, the type of information sent, and the country where the supplier is set up. So the supplier's country is something the client signs up to. It is not a free engineering choice. Separately, point 28 of Circular CSSF 22/806 applies where the accounting system is hosted outside Luxembourg. The firm must then hold, at the end of each day, a secure backup of all end-of-day accounting positions, including client positions. That backup must sit on premises in the European Economic Area. The premises can be its own, a group company's, or a different service provider's. INSURANCE. The same shape. Article 300 of the Law of 7 December 2015 copies banking secrecy. It is also a crime, and it also uses the client-agrees-to-the-country test for outsourcing. INVESTMENT FUNDS AND SUPPORT SERVICES. Articles 29-3, 29-5 and 29-6 of the 1993 law create Luxembourg licences. They cover firms that run the computer systems of financial companies, or that scan or store their documents. That is a licence wall, not a storage wall. TELECOMS. We found no rule that data must stay in the country. There is a 6-month duty to keep traffic and location records under the Law of 30 May 2005. HEALTH. We found no rule that health data must be hosted in Luxembourg, as at 18 August 2026. France is different. Patient files must be kept for at least 10 years. GOVERNMENT CLOUD, EDUCATION, GAMING, MAPPING AND DEFENCE. We found no storage-location rule in a government source on 18 August 2026. That means we did not find one, not that none exists. See the list of things we could not confirm.
Sources
- Official sourceCommission de Surveillance du Secteur FinancierLaw of 5 April 1993 on the financial sector, Article 41(2a) - outsourcing and professional secrecy
cssf.lu
“the client has accepted, in accordance with the law or according to the arrangements for information agreed on by the parties, the outsourcing of the outsourced services, the type of information transmitted in the context of the outsourcing and the country of establishment of the entities that provide outsourced services”
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierCircular CSSF 22/806 on outsourcing arrangements, point 28 - daily backup inside the European Economic Area
cssf.lu
“When using an accounting system that is located outside of Luxembourg (accounting system hosting outsourcing) ... the In-Scope Entity shall have, at the end of each day, a secure backup of all end of day accounting positions, including client positions, in a readable format”
Link checked 18 August 2026
- Official sourceCommissariat aux AssurancesLaw of 7 December 2015 on the insurance sector, Article 300(2a) - insurance secrecy and outsourcing
caa.lu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on the free flow of non-personal data
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
You can only send personal data to approved countries, unless you put an approved safeguard in place first. The European Commission keeps the approved list, and it has plenty of countries on it. Luxembourg adds no national permit. The regulator does not pre-approve ordinary transfers. Finance is different. There, the client must agree to the destination country before their information moves.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims
The routes are the European ones. An official decision that a country is safe enough. The 2021 standard contract clauses. Company-wide rules approved by a regulator. An approved certificate or code of conduct. Or one of the narrow Article 49 exceptions. You are still expected to write down why the destination country is safe, after the Schrems II court ruling. On 18 August 2026 the approved list held Andorra, Argentina, Brazil, Canada for commercial bodies, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay, the European Patent Organisation, and United States organisations signed up to the European Union-United States Data Privacy Framework. That last one is the fragile one. It is legally valid today. But on 31 July 2026 the European Data Protection Board formally asked the Commission to check whether it still stands. Do not make it your only route. On top of all this, a Luxembourg bank or insurer needs the client's agreement from question 2. That must come before client information leaves for a named country.
Sources
- Official sourceCommission nationale pour la protection des donneesInternational transfers - CNPD guidance for professionals
cnpd.public.lu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions - the list of approved destinations
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierLaw of 5 April 1993, Article 41(2a) - client acceptance of the supplier's country of establishment
cssf.lu
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
Yes, the regulators here really work. The privacy regulator is the National Commission for Data Protection, known as the CNPD. It is staffed and it publishes decisions. In 2025 it handled 846 complaints, 425 breach reports and 59 investigations. It issued the largest privacy fine ever recorded in Europe, against Amazon in 2021. The financial regulator and the insurance regulator are serious supervisors in their own right. Since May 2026 the telecoms regulator also runs the national cybersecurity rules.
- What it costs if you get it wrong:
- Daily fine until fixed · Criminal liability
Regulators and what they cover. CNPD - privacy. Its published anonymised decisions run from 2021 to 2025. The most recent, from December 2025, dealt with incomplete records of how data is used. Volume is modest: roughly 3 to 12 published decisions a year, after a burst of 48 in 2021. So it is active rather than aggressive. Appeals go to the Administrative Tribunal, which rehears the case in full rather than only checking the process. One real gap: under Article 48 of the Law of 1 August 2018, the CNPD cannot fine the State or the communes. It can still order them to stop. It can impose a daily penalty on private bodies of up to 5 per cent of average daily turnover. But a Luxembourg public body faces no fine. CSSF - banks, investment firms, payment institutions and funds. You must notify it at least three months before a critical or important outsourcing starts. Commissariat aux Assurances - insurers and reinsurers. Institut Luxembourgeois de Regulation - telecoms. Since the Law of 5 May 2026 it is also the authority in charge of cybersecurity. It takes incident reports through its SERIMA platform. Commissariat du Gouvernement a la protection des donnees aupres de l'Etat - a separate body created by the 2018 law. It acts as data protection officer for state departments. It advises. It does not fine.
Sources
- Official sourceCommission nationale pour la protection des donneesAnnual report 2025, presented 10 July 2026 - 846 complaints, 425 breach notifications, 59 investigations
cnpd.public.lu
Link checked 18 August 2026
- Official sourceCommission nationale pour la protection des donneesDecisions and sanctions register - published decisions 2021 to 2025
cnpd.public.lu
Link checked 18 August 2026
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 1 August 2018, Articles 48, 49 and 55 - no fines against the State or communes, daily penalties up to 5 per cent of average daily turnover, appeal to the Administrative Tribunal
data.legilux.public.lu
Link checked 18 August 2026
- Official sourceInstitut Luxembourgeois de RegulationThe NIS2 law - Law of 5 May 2026 on measures for a high level of cybersecurity
ilr.lu
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierCircular CSSF 22/806, point 59 - notify the CSSF at least three months before a critical or important outsourcing begins
cssf.lu
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a minimum and a maximum, and they clash often. You must keep anti-money-laundering records for 5 years after the relationship ends. You must keep patient files for at least 10 years after care ends. You must keep telephone and internet connection records for 6 months. Pulling the other way, European privacy law says delete personal data once you no longer need it. The anti-money-laundering law says delete it when the 5 years are up, unless another law makes you keep it longer. That is how Luxembourg settles the clash. The longest specific legal duty wins. After that you must actually erase the data.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
Minimums we confirmed today. Anti-money-laundering: 5 years from the end of the business relationship, or from the date of a one-off transaction, under Article 3(6) of the Law of 12 November 2004. A supervisor may require up to 5 more years in a specific case. Firms keep data a further 5 years where they need it to make their own prevention or detection checks work. Patient records: at least 10 years from the end of care, under the Law of 24 July 2014 on patients' rights. Neither the provider nor the patient may take anything out of the file before that period ends. Telecoms: 6 months for traffic data, and for location data that is not traffic data, under Articles 5 and 9 of the Law of 30 May 2005. Maximums. The anti-money-laundering law says plainly that firms must erase personal data once the keep-it periods end. Longer periods set by other laws still apply. General accounting and business books are widely said to run 10 years. We could not open a government source for that today. See the list of things we could not confirm.
Sources
- Official sourceCommissariat aux Assurances (coordinated text)Law of 12 November 2004 on anti-money-laundering, Article 3(6) - 5 years, extendable, then mandatory erasure
caa.lu
“Sans prejudice des delais de conservation plus longs prescrits par d'autres lois, les professionnels sont tenus d'effacer les donnees a caractere personnel a l'issue des periodes de conservation visees a l'alinea 1er.”
Link checked 18 August 2026
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 24 July 2014 on patients' rights, patient file retention
data.legilux.public.lu
“Le depositaire d'un dossier patient est tenu d'en assurer la garde pendant dix ans au moins a partir de la date de la fin de la prise en charge.”
Link checked 18 August 2026
- Official sourceCommission nationale pour la protection des donneesLaw of 30 May 2005 on privacy in electronic communications, Articles 5 and 9 - 6-month retention
cnpd.public.lu
“retain such data for a period of 6 months from the date of the communication”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count four deadlines. They overlap and they start at different moments. Privacy breach: 72 hours to tell the privacy regulator. Telephone and internet providers: 24 hours to report a personal data breach. Cybersecurity incidents at important companies: an early warning in 24 hours, a fuller report in 72 hours, and a final report a month later. Banks and insurers have their own European reporting on top. The trap is that one incident can start all of them at once, on different teams, with different forms.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
DEADLINE 1 - privacy. Article 33 of the General Data Protection Regulation. Tell the CNPD within 72 hours of finding out, where there is a risk to people. Tell the people affected without undue delay where the risk is high. DEADLINE 2 - electronic communications. Providers must report a personal data breach within 24 hours of spotting it. This comes from Commission Regulation (EU) 611/2013, as applied by the CNPD. DEADLINE 3 - cybersecurity. Under the Law of 5 May 2026, essential and important companies must send an early notice to the authority. It is due without undue delay, and in any case within 24 hours of finding out about a significant incident. A fuller notice follows within 72 hours. A final report is due within one month of that notice. They must also warn the users of their service without undue delay where the incident may harm the service. Notices go through the ILR's SERIMA platform. DEADLINE 4 - finance. Financial companies also report major technology incidents under the European Digital Operational Resilience Act, which has applied since 17 January 2025.
Sources
- Official sourceCommission nationale pour la protection des donneesData breaches - notification duties for controllers and for electronic communications providers
cnpd.public.lu
Link checked 18 August 2026
- Official sourceInstitut Luxembourgeois de RegulationIncident notification - 24 hours, 72 hours and one month, via the SERIMA platform
ilr.lu
Link checked 18 August 2026
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 5 May 2026 on cybersecurity - 24-hour preliminary notification, 72-hour incident notification, final report within one month
data.legilux.public.lu
“sans retard injustifie et en tout etat de cause dans les vingt-quatre heures apres avoir eu connaissance de l'incident important, une notification prealable”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2022/2554 (Digital Operational Resilience Act)
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things that are not in any summary. (1) Breaking bank or insurance client secrecy is a crime, not a fine, and it lasts after the job ends. (2) Your works council can freeze a staff-monitoring project. Staff have 15 days to ask the privacy regulator for an opinion, and that request pauses the project for a month. (3) Research projects carry a fixed list of 12 extra safeguards. You must apply them or justify skipping one. (4) Using genetic data for employment or insurance purposes is banned outright. (5) The privacy regulator cannot fine the State or a commune, so a public body has far less to lose than you do.
- What you have to do here:
- Extra vendor secrecy terms · Assess high-risk projects · Appoint a data protection officer · Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
1. Secrecy is criminal. Article 41 of the Law of 5 April 1993 and Article 300 of the Law of 7 December 2015 both cover disclosure. Both say it is punished under Article 458 of the Penal Code. This reaches directors, employees and anyone working for the firm. The insurance law says expressly that the duty lasts after the job, mandate or practice ends. A standard European supplier contract is not enough on its own. The person with access must be under a legal secrecy duty or a confidentiality agreement. The client must also have agreed to the outsourcing, the type of information and the supplier's country. 2. Monitoring staff. Article L.261-1 of the Labour Code, rewritten in 2018, makes the employer tell the joint works committee or the staff delegation in advance. You must give a detailed description of the purpose, how the monitoring will work, and how long data is kept. You must also promise formally not to reuse the data for anything else. The delegation or the affected staff then have 15 days to ask the CNPD for an opinion. The CNPD must answer within a month, and the request pauses the project in the meantime. Complaining to the CNPD is expressly not a valid or serious reason to dismiss someone. 3. Research. Article 65 of the Law of 1 August 2018 lists 12 measures for scientific, historical or statistical research. They include a data protection officer, an impact assessment, an independent trusted third party to strip out names, encryption in transit and at rest with up-to-date key management, access logs, an independent audit and a data management plan. You may leave one out. You must write down why, project by project. 4. Genetic data. Article 66 bans using genetic data for your own employment-law or insurance purposes. Full stop. 5. Public bodies. Article 48 of the same law bars fines against the State and the communes. 6. Bonus, for insurers. Article 181-3 of the insurance law lists safeguards for health data. Four of them can never be dropped: encryption, access limits, log files and staff awareness, plus an internal policy. 7. Bonus, on age. Luxembourg did not lower the age at which children can agree for themselves. It stays at 16. France is 15 and the United Kingdom is 13.
Sources
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 1 August 2018, Articles 48, 65 and 66 and Article 71 rewriting Article L.261-1 of the Labour Code
data.legilux.public.lu
“la delegation du personnel, ou a defaut, les salaries concernes, peuvent, dans les quinze jours suivant l'information prealable, soumettre une demande d'avis prealable ... Cette demande a un effet suspensif pendant ce delai.”
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierLaw of 5 April 1993, Article 41(1) - disclosure punished under Article 458 of the Penal Code
cssf.lu
“Disclosure of such information shall be punishable by the penalties laid down in Article 458 of the Penal Code.”
Link checked 18 August 2026
- Official sourceCommissariat aux AssurancesLaw of 7 December 2015, Articles 181-3 and 300 - non-derogable health data safeguards and criminal insurance secrecy
caa.lu
Link checked 18 August 2026
What's changing next
Two dated changes are coming, plus some powers already in someone's hand. From 12 January 2027, cloud providers must let customers move away with no exit or transfer fees at all. Luxembourg's new cybersecurity law has been in force since 10 May 2026 and is still being filled in with guidance and templates. Two things could change fast. The European approval of United States transfers is under formal challenge. And the 6-month duty on telecoms firms to keep call records sits badly with European court rulings. It could be struck down at any time.
- What you have to do here:
- Make switching cloud provider possible
Dated. 12 January 2027 - the European Data Act makes all charges for switching cloud provider zero, including data export fees. This is a contract and architecture change, not a paperwork one. 10 May 2026 - the Law of 5 May 2026 on cybersecurity came into force. The registration deadline written into the law is 17 January 2025. It applies to cloud providers, data-centre providers, managed service providers, content delivery networks, online marketplaces, search engines and social platforms. That date had already passed, so a company covered by the law is late from day one. The ILR is still running consultations and publishing templates for the security measures. Powers already in someone's hand. 1. The European Union-United States Data Privacy Framework. It is valid on 18 August 2026. The Latombe appeal is waiting at the Court of Justice. On 31 July 2026 the European Data Protection Board asked the Commission to check whether the decision still stands. If it falls, every transfer relying on it needs a new route overnight. 2. Telecoms record-keeping. Articles 5 and 9 of the Law of 30 May 2005 make every provider keep traffic and location data for 6 months. Keeping everyone's records like this has repeatedly been held to break European law. We found no Luxembourg judgment setting it aside and no repeal, so we treat it as in force. It is the rule in this record most likely to change without warning. 3. Which circular applies. Circular CSSF 25/883 took effect on 9 April 2025. It switched off Part II of Circular CSSF 22/806 for firms covered by the European Digital Operational Resilience Act. Firms outside that Act still follow the old text. Reading the circular without the change gives the wrong answer. Proposed only, with no legal effect: the European Digital Omnibus of 19 November 2025 and the Cloud and AI Development Act proposed on 3 June 2026.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) - cloud switching and egress charges
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 5 May 2026 on cybersecurity, Article 17 - registration information due by 17 January 2025
data.legilux.public.lu
“soumettent les informations suivantes a l'autorite competente au plus tard le 17 janvier 2025”
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierCircular CSSF 25/883, 9 April 2025 - Part II of Circular 22/806 no longer applies to entities in scope of the Digital Operational Resilience Act
cssf.lu
“Part II of Circular CSSF 22/806, related to ICT outsourcing arrangements, does not apply to them anymore”
Link checked 18 August 2026
- Official sourceCommission nationale pour la protection des donneesLaw of 30 May 2005, Articles 5 and 9 - the 6-month retention duty still on the books
cnpd.public.lu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions - the list of approved destinations
commission.europa.eu
Link checked 18 August 2026
What to do: Diarise 12 January 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries6 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: Loi modifiee du 5 avril 1993 relative au secteur financier, article 41 (secret professionnel) · Article 41 LFS, paragraph 2a inserted by the Law of 27 February 2018 · Act of parliament
Breaking Luxembourg banking secrecy is a crime, not just a civil wrong. Client information can go to an outsourcing provider abroad. But the client must first agree to the outsourcing, the type of information and the supplier's country. That makes the destination country a contract term, not an engineering choice.
Enforced by Financial Sector Supervisory Commission
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent
What you have to do
- Extra vendor secrecy termsThe people with access must be under a legal secrecy duty, or bound by a confidentiality agreement. A standard supplier contract on its own is not enough.
- Tell people what you doThe client must have accepted the outsourcing, the type of information transmitted and the country where the supplier is established.
- Register or notifyA company that runs computer systems, scans documents or stores records for Luxembourg financial firms may need its own CSSF support-PFS licence. This comes from Articles 29-3, 29-5 or 29-6. It needs paid-up capital of 125,000 euros or 50,000 euros.
What it costs if you get it wrong
- Criminal liability: the penalties in Article 458 of the Penal CodeDisclosing client information covered by banking secrecy
- Loss of your licenceLoss of authorisation for serious or repeated breaches of the financial sector law
Sources
- Official sourceCommission de Surveillance du Secteur FinancierLaw of 5 April 1993, Article 41(1) and (2a), and Articles 29-3, 29-5 and 29-6 on support-PFS statuses
cssf.lu
“the client has accepted ... the outsourcing of the outsourced services, the type of information transmitted in the context of the outsourcing and the country of establishment of the entities that provide outsourced services”
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierCSSF FAQ on Circular 22/806 on outsourcing arrangements
cssf.lu
Link checked 18 August 2026
Finance data needs a copy kept in the country
Official name: Circulaire CSSF 22/806 relative aux arrangements d'externalisation, telle que modifiee par la circulaire CSSF 25/883 · Circular CSSF 22/806, points 28 and 59, as amended by Circular CSSF 25/883 of 9 April 2025 · Regulator directive
This is the only real storage-location rule we found in Luxembourg. A supervised financial firm may host its accounting system abroad. It must still hold a full, readable end-of-day backup of all accounting and client positions. That backup must sit on premises inside the European Economic Area. Critical outsourcing needs three months' notice to the regulator.
Enforced by Financial Sector Supervisory Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryThe backup must be in the European Economic Area, not in Luxembourg specifically. Where the accounting system is hosted outside Luxembourg, you need a secure end-of-day backup of all accounting and client positions. It must sit on premises inside the European Economic Area. Those premises can belong to the firm, a group company or a different service provider.
- Register or notify — within 2160 hoursPrior notification to the CSSF at least three months before a critical or important outsourcing takes effect.
- Written vendor contractThe written agreement must say which regions or countries the service is provided from, and where data is kept and used.
- Independent auditYou must assess the risk, including any limits on oversight in the countries where the service runs and the data sits.
What it costs if you get it wrong
- Order to stopThe CSSF can require an outsourcing arrangement to be changed or terminated
Sources
- Official sourceCommission de Surveillance du Secteur FinancierCircular CSSF 22/806, points 28, 59, 61 to 65, 77 and 86
cssf.lu
“stored at the premises of the In-Scope Entity in the EEA, of a group entity located in the EEA, or of another service provider ... located in the EEA”
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierCircular CSSF 25/883 of 9 April 2025 - amends 22/806; Part II ceases to apply to entities in scope of the Digital Operational Resilience Act
cssf.lu
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierCSSF FAQ on Circular 22/806 on outsourcing arrangements
cssf.lu
Link checked 18 August 2026
Banking rules
Official name: Loi modifiee du 7 decembre 2015 sur le secteur des assurances, articles 181-3 et 300 · Articles 181-3 and 300, consolidated text of 3 April 2026 · Act of parliament
Insurance secrecy copies banking secrecy, and breaking it is equally a crime. On top of that, an insurer handling health data must apply a listed set of safeguards. Four of them can never be dropped: encryption, access limits, access logs and staff awareness.
Enforced by Insurance Commission
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent
What you have to do
- Extra vendor secrecy termsSame test as banking. The policyholder must have agreed to the outsourcing, the type of information and the supplier's country.
- Secure the dataArticle 181-3: for health data, you can never drop encryption in transit with up-to-date key management, access limits, log files or staff awareness.
- Appoint a data protection officerArticle 181-3 lists a data protection officer among the measures. If you skip it, you must write down why and justify it to the CNPD.
- Assess high-risk projectsArticle 181-3. If you skip it, you must write down why and justify it.
What it costs if you get it wrong
- Criminal liability: the penalties in Article 458 of the Penal CodeDisclosing information covered by insurance secrecy; the duty survives after the job or mandate ends
Sources
- Official sourceCommissariat aux AssurancesLaw of 7 December 2015 on the insurance sector, Articles 181-3 and 300
caa.lu
“Under no circumstances may a derogation be made from the measures listed in paragraph 1, point 2, letters d), e), f), g) and j).”
Link checked 18 August 2026
- Official sourceCommissariat aux Assurances (coordinated text)Law of 12 November 2004 - the anti-money-laundering retention duties that sit alongside insurance secrecy
caa.lu
Link checked 18 August 2026
Internet and platform rules
Official name: Loi modifiee du 30 mai 2005 relative aux dispositions specifiques de protection de la personne a l'egard du traitement des donnees a caractere personnel dans le secteur des communications electroniques · Articles 5 and 9, as amended by the Laws of 24 July 2010 and 28 July 2011 · Act of parliament
Every telephone and internet provider must keep traffic and location records for 6 months. After that they must delete them or strip out the names. No storage location is set. The duty covers everyone, not named suspects, which sits badly with European court rulings. It is the rule here most likely to be struck down or rewritten.
Enforced by National Commission for Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Keep data for a minimum period — 6 monthsTraffic data and location data other than traffic data, kept for criminal investigation purposes.
- Delete data after a period — 6 monthsAfter the 6 months the provider must erase or anonymise the data.
- Report breaches to the regulator — within 24 hoursElectronic communications providers report a personal data breach within 24 hours of detection.
- Secure the dataAccess must be technically impossible except for the listed judicial and billing-dispute cases.
What it costs if you get it wrong
- Criminal liability: 8 days to 1 year imprisonment and a fine of €251 to €125,000 (about $275 to $137,000) — about $137 thousandBreach of the confidentiality provisions of the law
- Order to stopA court may order the offending processing to stop, backed by a daily penalty
Sources
- Official sourceCommission nationale pour la protection des donneesLaw of 30 May 2005, Articles 5 and 9 - consolidated text published by the CNPD
cnpd.public.lu
“retain such data for a period of 6 months from the date of the communication”
Link checked 18 August 2026
- Official sourceCommission nationale pour la protection des donneesData breaches - notification duties for controllers and for electronic communications providers
cnpd.public.lu
Link checked 18 August 2026
Health data rules
Official name: Loi du 24 juillet 2014 relative aux droits et obligations du patient · Law of 24 July 2014, patient file and shared care record · Act of parliament
Patient files must be kept for at least 10 years after care ends. Nothing relevant may be taken out during that time. We found no rule requiring health records to be hosted in Luxembourg. France does have one, where the host must be certified.
Enforced by National Commission for Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Keep data for a minimum period — 10 yearsAt least 10 years from the end of the episode of care. Neither the provider nor the patient may remove relevant items before that.
- Let people see their dataPatients access their shared care record under Article 60quater of the Social Security Code.
What it costs if you get it wrong
- Claims by individualsCivil liability of the health professional or hospital
Sources
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 24 July 2014 on patients' rights - 10-year retention of the patient file
data.legilux.public.lu
“Le depositaire d'un dossier patient est tenu d'en assurer la garde pendant dix ans au moins a partir de la date de la fin de la prise en charge.”
Link checked 18 August 2026
Finance data rules
Official name: Loi modifiee du 12 novembre 2004 relative a la lutte contre le blanchiment et contre le financement du terrorisme, article 3, paragraphe 6 · Article 3(6), coordinated text of 6 February 2025 · Act of parliament
Anti-money-laundering records run 5 years from the end of the relationship. The supervisor can extend that by up to 5 more years. After that they must actually be erased. This is the clearest statement in Luxembourg law of how a keep-it duty and a delete-it duty fit together. The longest specific legal duty wins, and after it you must erase.
Enforced by Financial Sector Supervisory Commission
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Keep data for a minimum period — 5 yearsFive years from the end of the business relationship or the date of an occasional transaction, covering identification records, account books, business correspondence and analyses.
- Delete data after a period — 5 yearsPersonal data must be erased once the periods end, unless another law requires longer. A supervisor may order up to 5 further years in a specific case. Firms may hold data 5 more years where they need it for internal prevention and detection.
- Keep records of how you use data
What it costs if you get it wrong
- Fixed maximum fineAdministrative fines by the CSSF or the Commissariat aux Assurances for breach of the record-keeping duty
Sources
- Official sourceCommissariat aux Assurances (coordinated text)Law of 12 November 2004, Article 3(6) - retention and mandatory erasure
caa.lu
“pendant cinq ans apres la fin de la relation d'affaires avec le client ou apres la date de la transaction conclue a titre occasionnel”
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Europe's main privacy law (2018)
Official name: Loi du 1er aout 2018 portant organisation de la Commission nationale pour la protection des donnees et mise en oeuvre du reglement (UE) 2016/679 · Memorial A no 686 of 16 August 2018 · Act of parliament
Luxembourg's national add-on to the European rules. It creates the regulator. It adds a 12-point safeguard list for research. It bans genetic data in employment and insurance decisions. It lets staff pause monitoring projects. And it stops the regulator fining the State or the communes.
Enforced by National Commission for Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Appoint a data protection officerCompulsory for any scientific, historical or statistical research project under Article 65, on top of the usual European triggers.
- Assess high-risk projectsCompulsory for research projects under Article 65.
- Secure the dataArticle 65 requires research data to be encrypted in transit and at rest, with up-to-date key management.
- Independent auditArticle 65: regular independent audit of the technical and organisational measures for research.
- Keep logsArticle 65: log files recording the reason, date, time and identity for every consultation, change or deletion of research data.
- Keep records of how you use dataArticle 65: a data management plan must be drawn up before the research starts.
What it costs if you get it wrong
- Daily fine until fixed: up to 5% of average daily turnover, per day of delayFailing to supply information the CNPD asked for, or failing to comply with a corrective measure
- Criminal liability: 8 days to 1 year imprisonment and a fine of €251 to €125,000 (about $275 to $137,000) — about $137 thousandKnowingly preventing or obstructing the CNPD in carrying out its duties
Sources
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 1 August 2018, Articles 48, 49, 51, 55, 65, 66 and 71
data.legilux.public.lu
“La CNPD peut imposer les amendes administratives telles que prevues a l'article 83 du reglement (UE) 2016/679, sauf a l'encontre de l'Etat ou des communes.”
Link checked 18 August 2026
- Official sourceCommission nationale pour la protection des donneesLegislation - the Luxembourg texts the CNPD applies
cnpd.public.lu
Link checked 18 August 2026
Cyber security rules
Official name: Loi du 5 mai 2026 concernant des mesures destinees a assurer un niveau eleve de cybersecurite · Memorial A no 225, published 6 May 2026 · Act of parliament
This puts the European cybersecurity directive into Luxembourg law. It was adopted on 5 May 2026 and has been in force since 10 May 2026. It sets three deadlines: 24 hours, 72 hours and one month. It also sets a registration duty. That deadline, 17 January 2025, had already passed on the day the law started.
Enforced by Luxembourg Regulatory Institute
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 24 hoursPreliminary notification within 24 hours of becoming aware of a significant incident.
- Report cyber incidents — within 72 hoursFuller incident notification within 72 hours, with an initial severity and impact assessment and any indicators of compromise.
- Register or notify — from 17 January 2025Cloud providers, data-centre providers, managed service and managed security providers, content delivery networks, DNS and domain registration services, online marketplaces, search engines and social platforms must file their name, industry, addresses, contacts, the member states they serve and their IP ranges. The deadline written in the law had already passed when the law started.
- Appoint a representativeA covered company based outside the European Union must appoint a representative. If it does not, the authority can ask the President of the Luxembourg District Court to order the appointment.
- Secure the data
- Tell affected peopleUsers of the service must be warned without undue delay where a significant incident may harm the service.
What it costs if you get it wrong
- Fixed maximum fine: €10,000,000 or 2% of total worldwide annual turnover, whichever is higher, for essential entities — about $11 millionBreach of the cybersecurity risk-management or reporting duties
- Fixed maximum fine: €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher, for important entities — about $8 millionBreach of the cybersecurity risk-management or reporting duties
- Order to stopSupervisory and enforcement measures including temporary suspension of the activity
Sources
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 5 May 2026 on cybersecurity, Articles 16, 17, 20 and 26
data.legilux.public.lu
“soumettent les informations suivantes a l'autorite competente au plus tard le 17 janvier 2025”
Link checked 18 August 2026
- Official sourceInstitut Luxembourgeois de RegulationThe NIS2 law - Law of 5 May 2026 on measures for a high level of cybersecurity
ilr.lu
Link checked 18 August 2026
- Official sourceInstitut Luxembourgeois de RegulationIncident notification - 24 hours, 72 hours and one month, via the SERIMA platform
ilr.lu
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Reglement general sur la protection des donnees (RGPD) - Reglement (UE) 2016/679 · Regulation (EU) 2016/679 · Directly binding regulation
The European privacy rulebook. It never requires data to stay in Europe. It sets the conditions for sending it out. Fines scale with worldwide group turnover. An order to stop using the data usually hurts more than the fine.
Enforced by National Commission for Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of how you use data
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a representativeYou must do this if you have no office in the European Union. The representative does not have to be in Luxembourg.
- Put a transfer safeguard in placeYou must also write down why the destination country is safe, after the Schrems II court ruling.
- Do not hand data to foreign authorities on demandAn order from a foreign government is not on its own a legal reason to hand data over (European Data Protection Board Guidelines 02/2024).
- Delete data after a period
- Get a parent's consent for children — applies at: under 16 in Luxembourg - the national law made no lower choice
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $11 millionController and processor obligations
- Order to stopThe CNPD can order processing to stop or suspend flows to a third country
- Claims by individualsIndividuals can claim compensation before the ordinary courts
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions - the list of approved destinations
commission.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEDPB Guidelines 02/2024 on Article 48 - a foreign authority's order is not by itself a lawful basis
edpb.europa.eu
Link checked 18 August 2026
Applies only if you signed a contract1 rule
Usually a government or enterprise contract that adds rules of its own.
Personal data needs a security certification
Official name: Loi du 25 juillet 2015 relative a l'archivage electronique · Law of 25 July 2015, amending Article 1334 of the Civil Code and Article 16 of the Commercial Code · Act of parliament
This is not a location rule. It is a certification rule. A digital copy made by a provider certified under this law counts as much as the paper original in court, unless someone proves otherwise. So if you want to scan Luxembourg records and destroy the paper, you need a certified provider from the national list.
Enforced by Luxembourg Institute for Standardisation, Accreditation, Safety and Quality of Products and Services
How this country controls where data goes: No restriction · Accepted routes: Certification scheme
What you have to do
- Hold a security certificateTo be listed as a scanning or storage service provider, you must be certified by a certifier accredited by ILNAS. You must prove it every year and be entered on the ILNAS list.
- Register or notifyOnly listed providers may call themselves a PSDC.
Sources
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 25 July 2015 on electronic archiving, Articles 2, 11 and 12
data.legilux.public.lu
“Les copies sous forme numerique qui sont effectuees par un prestataire de services de dematerialisation ou de conservation ont, sauf preuve contraire, la meme valeur probante que l'original”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The outcome of Amazon's appeal against the CNPD's EUR 746 million fine of July 2021
We could not confirm the outcome of the appeal from a government source. The fine is widely reported as the largest European privacy fine ever issued. The Administrative Tribunal rehears appeals in full, so the amount could have changed. Treat the figure as the amount imposed, not the amount finally paid.
The general 10-year retention period for accounting books and commercial records under Article 16 of the Commercial Code
This is widely stated, and it fits the Law of 25 July 2015 which changes that same Article 16. We could not confirm it against an official text of the Commercial Code or government guidance. Treat it as very likely true, but check it before you rely on it.
Whether the 6-month telecoms retention duty in Articles 5 and 9 of the Law of 30 May 2005 has been disapplied by a Luxembourg court or superseded by a reform bill
The rule is still in the text published by the CNPD, and the law is still recorded as in force. The Court of Justice of the European Union has repeatedly criticised keeping everyone's records like this. We found no Luxembourg judgment setting it aside and no repeal, so we record it as in force with medium confidence. This is the item in this record most likely to be wrong within a year.
Whether any localisation or sovereign-hosting requirement applies to Luxembourg government cloud, education, online gaming, mapping and geospatial data, or defence-related data
We found no such rule, checked 18 August 2026. We searched the regulators' own sites and the official gazette. Not finding a rule is not proof that none exists. Public buying conditions are not always published as law. If you sell to these buyers, ask them directly.
Whether health data hosting in Luxembourg requires any certification comparable to the French certified health data host regime
The Law of 24 July 2014 and the shared care record rules set who can see records and how long they are kept. We found no requirement that hosts be certified. We could not confirm this either way, so check before you rely on it.
The exact penalties in Article 458 of the Luxembourg Penal Code that back banking and insurance secrecy
Both industry laws point to Article 458 without repeating the numbers. We could not confirm the figures against an official Penal Code text. We did confirm that breaking secrecy is a crime. If you need the exact penalty, ask a Luxembourg lawyer.
Whether the registration deadline of 17 January 2025 written into Article 17 of the cybersecurity law of 5 May 2026 has been extended in practice by the regulator
The date is in the law as passed, and the law only started on 10 May 2026. So the deadline had already passed. The ILR is running consultations and publishing templates, which suggests it is not enforcing hard yet. We found no published extension. Ask the ILR where you stand.
Current staffing of the Government Commissioner for Data Protection within the State
We confirmed that the office exists and what it does from the law itself. We found no government page saying who currently holds the post.
The exact commencement dates of the Law of 27 February 2018 (which inserted the outsourcing carve-outs into banking and insurance secrecy), the Law of 1 August 2018, and the Law of 25 July 2015
Luxembourg laws start a short fixed period after publication in the official journal, unless they say otherwise. We confirmed the adoption and publication dates. We could not confirm an official start date for these three. So the dates here are either the adoption date or the standard date after publication, and they may be out by a few days. The start date of the cybersecurity law of 5 May 2026 is 10 May 2026. That one comes from the official journal's own record and is confirmed.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.