Luxembourg
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
For most businesses, data can leave Luxembourg on the same terms as anywhere else in the European Union: you need the right paperwork, not a local data centre. Finance is the exception, and finance is most of the economy here. Banks and insurers are bound by a secrecy duty that is a crime to break, and a bank that runs its accounts abroad must still keep a daily backup inside Europe.
Eight questions about Luxembourg
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Luxembourg's rules apply to my company?
Yes. If you sell to people in Luxembourg or watch what they do online, the European privacy rules reach you even with no office here. There is no revenue or headcount threshold to hide under. A company with no base anywhere in Europe must appoint a representative in Europe, though it does not have to be in Luxembourg. The extra Luxembourg-only duties in the national law mostly apply to organisations that are actually set up here.
Reach comes from Article 3 of the General Data Protection Regulation, not from Luxembourg law. The Law of 1 August 2018 organises the national regulator and adds national choices on top; Article 2 of that law states that the duties in its Title II apply to controllers and processors established on Luxembourg territory. Separately, the new cybersecurity law of 5 May 2026 has its own reach: Article 16 requires certain entities not established in the European Union to designate a representative, and if they do not, the authority can apply to the President of the Luxembourg District Court in summary proceedings for an order appointing one. Financial and insurance secrecy duties attach to persons established in Luxembourg and supervised here, and, for insurance, also to business carried on from Luxembourg under the freedom to provide services.
Sources
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 1 August 2018 organising the CNPD and implementing the GDPR, Article 2 (territorial application of Title II)
data.legilux.public.lu
Link checked 18 August 2026
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 5 May 2026 on cybersecurity, Article 16 - representative in the European Union, appointable by court order
data.legilux.public.lu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
Can I store my users' data outside Luxembourg?
In general, yes, with paperwork. Luxembourg has no national law telling ordinary companies to keep data in the country, and European law actually forbids member states from forcing non-personal data to stay put except on public-security grounds. But this is a banking and fund centre, and the finance rules change the answer. A bank or insurer may only hand client information to a supplier abroad if the client has been told and has accepted which country that supplier is in. And a bank whose accounting system sits outside Luxembourg must still keep a full daily backup somewhere inside the European Economic Area.
Sector by sector, checked 18 August 2026. BANKING AND INVESTMENT FIRMS - conditional, with one hard location rule. Article 41 of the Law of 5 April 1993 on the financial sector makes client secrecy a criminal matter. Since a 2018 amendment, paragraph 2a lets you outsource without breaching secrecy in two situations: the supplier is itself supervised in Luxembourg and criminally bound by secrecy, or, in every other case, the client has accepted the outsourcing, the type of information transmitted and the country where the supplier is established. Country of establishment is therefore a term the client signs up to, not a free engineering choice. Separately, point 28 of Circular CSSF 22/806 requires that where the accounting system is hosted outside Luxembourg the firm must hold, at the end of each day, a secure backup of all end-of-day accounting positions including client positions, at its own premises in the European Economic Area, or those of a group entity or a different service provider in the European Economic Area. INSURANCE - the same shape. Article 300 of the Law of 7 December 2015 mirrors banking secrecy, again criminally sanctioned, again with a country-of-establishment acceptance test for outsourcing. INVESTMENT FUNDS AND SUPPORT SERVICES - Articles 29-3, 29-5 and 29-6 of the 1993 law create licensed Luxembourg statuses for firms that operate the IT systems of financial entities, or that digitise or preserve their documents. That is a licensing wall, not a storage wall. TELECOMS - no localisation found, but a 6-month duty to keep traffic and location records under the Law of 30 May 2005. HEALTH - no hosting-in-Luxembourg rule found as at 18 August 2026, unlike France. Patient files must be kept for at least 10 years. GOVERNMENT CLOUD, EDUCATION, GAMING, MAPPING AND DEFENCE - no localisation rule found in a government source on 18 August 2026. Treat that as 'not found', not as 'does not exist'; see the unconfirmed list.
Sources
- Official sourceCommission de Surveillance du Secteur FinancierLaw of 5 April 1993 on the financial sector, Article 41(2a) - outsourcing and professional secrecy
cssf.lu
“the client has accepted, in accordance with the law or according to the arrangements for information agreed on by the parties, the outsourcing of the outsourced services, the type of information transmitted in the context of the outsourcing and the country of establishment of the entities that provide outsourced services”
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierCircular CSSF 22/806 on outsourcing arrangements, point 28 - daily backup inside the European Economic Area
cssf.lu
“When using an accounting system that is located outside of Luxembourg (accounting system hosting outsourcing) ... the In-Scope Entity shall have, at the end of each day, a secure backup of all end of day accounting positions, including client positions, in a readable format”
Link checked 18 August 2026
- Official sourceCommissariat aux AssurancesLaw of 7 December 2015 on the insurance sector, Article 300(2a) - insurance secrecy and outsourcing
caa.lu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on the free flow of non-personal data
eur-lex.europa.eu
Link checked 18 August 2026
What do I need in place before data leaves Luxembourg?
The model is a European approved-list. Sending personal data outside Europe is barred unless the destination is on the European Commission's approved list, or you put an approved safeguard in place first. The list is real and populated. Luxembourg adds no national permit and the regulator does not pre-approve ordinary transfers. In finance, though, you also need the client's acceptance of the destination country before their information moves.
The mechanisms are the European ones: an adequacy decision, the 2021 standard contractual clauses, binding corporate rules, an approved certification or code of conduct, or one of the narrow Article 49 exceptions. A transfer impact assessment is still expected after the Schrems II judgment. The approved list on 18 August 2026 includes Andorra, Argentina, Brazil, Canada for commercial bodies, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay, the European Patent Organisation, and the United States for organisations self-certified under the EU-US Data Privacy Framework. That last one is the fragile one: it is legally valid today, but on 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether it still stands. Do not build a single-mechanism architecture on it. On top of all of this, a Luxembourg bank or insurer needs the client-acceptance step described in question 2 before client information leaves for a named country.
Sources
- Official sourceCommission nationale pour la protection des donneesInternational transfers - CNPD guidance for professionals
cnpd.public.lu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions - the list of approved destinations
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierLaw of 5 April 1993, Article 41(2a) - client acceptance of the supplier's country of establishment
cssf.lu
Link checked 18 August 2026
Who enforces the rules in Luxembourg, and what can they do?
Yes, the regulators here really work. The privacy regulator is the National Commission for Data Protection, known as the CNPD. It is staffed, it publishes decisions, and in 2025 it handled 846 complaints, 425 breach reports and 59 investigations. It issued the largest privacy fine ever recorded in Europe, against Amazon in 2021. The financial regulator and the insurance regulator are heavyweight supervisors in their own right, and since May 2026 the telecoms regulator also runs the national cybersecurity regime.
Regulators and their reach. CNPD - privacy. Published anonymised decisions run from 2021 to 2025, most recently a December 2025 decision on incomplete processing registers. Volume is modest, roughly 3 to 12 published decisions a year after a burst of 48 in 2021, so the honest rating is active rather than aggressive. Appeals go to the Administrative Tribunal, which rehears the case on the merits rather than only reviewing the process. One genuine gap: under Article 48 of the Law of 1 August 2018 the CNPD cannot impose administrative fines on the State or on the communes. It can still order them to stop, and it can impose a daily penalty on private bodies of up to 5 per cent of average daily turnover, but a Luxembourg public body faces no fine. CSSF - banks, investment firms, payment institutions and funds. Requires prior notification at least three months before a critical or important outsourcing starts. Commissariat aux Assurances - insurers and reinsurers. Institut Luxembourgeois de Regulation - telecoms, and since the Law of 5 May 2026 the competent authority for the cybersecurity regime, taking incident notifications through its SERIMA platform. Commissariat du Gouvernement a la protection des donnees aupres de l'Etat - a separate body created by the 2018 law that acts as data protection officer for state administrations. It advises; it does not fine.
Sources
- Official sourceCommission nationale pour la protection des donneesAnnual report 2025, presented 10 July 2026 - 846 complaints, 425 breach notifications, 59 investigations
cnpd.public.lu
Link checked 18 August 2026
- Official sourceCommission nationale pour la protection des donneesDecisions and sanctions register - published decisions 2021 to 2025
cnpd.public.lu
Link checked 18 August 2026
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 1 August 2018, Articles 48, 49 and 55 - no fines against the State or communes, daily penalties up to 5 per cent of average daily turnover, appeal to the Administrative Tribunal
data.legilux.public.lu
Link checked 18 August 2026
- Official sourceInstitut Luxembourgeois de RegulationThe NIS2 law - Law of 5 May 2026 on measures for a high level of cybersecurity
ilr.lu
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierCircular CSSF 22/806, point 59 - notify the CSSF at least three months before a critical or important outsourcing begins
cssf.lu
Link checked 18 August 2026
How long do I have to keep the data?
There is a floor and a ceiling, and they collide often. You must keep anti-money-laundering records for 5 years after the relationship ends, patient files for at least 10 years after care ends, and telephone and internet connection records for 6 months. In the other direction, European privacy law says delete personal data once you no longer need it, and the anti-money-laundering law says delete it when the 5 years are up unless another law makes you keep it longer. That last sentence is how Luxembourg resolves the clash: the longest specific legal duty wins, and after that you must actually erase.
Floors verified today. Anti-money-laundering: 5 years from the end of the business relationship or the date of an occasional transaction, under Article 3(6) of the Law of 12 November 2004. A supervisor may require a further period of up to 5 more years in a specific case, and firms keep data a further 5 years where needed to make internal prevention or detection measures work. Patient records: at least 10 years from the end of care, under the Law of 24 July 2014 on patients' rights; neither the provider nor the patient may strip anything out of the file before that period ends. Telecoms: 6 months for traffic data and for location data other than traffic data, under Articles 5 and 9 of the Law of 30 May 2005. Ceilings: the anti-money-laundering law says plainly that, without prejudice to longer periods laid down by other laws, professionals must erase personal data once the retention periods end. General accounting and commercial books are widely stated to run 10 years, but we could not open a government source for that today; see the unconfirmed list.
Sources
- Official sourceCommissariat aux Assurances (coordinated text)Law of 12 November 2004 on anti-money-laundering, Article 3(6) - 5 years, extendable, then mandatory erasure
caa.lu
“Sans prejudice des delais de conservation plus longs prescrits par d'autres lois, les professionnels sont tenus d'effacer les donnees a caractere personnel a l'issue des periodes de conservation visees a l'alinea 1er.”
Link checked 18 August 2026
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 24 July 2014 on patients' rights, patient file retention
data.legilux.public.lu
“Le depositaire d'un dossier patient est tenu d'en assurer la garde pendant dix ans au moins a partir de la date de la fin de la prise en charge.”
Link checked 18 August 2026
- Official sourceCommission nationale pour la protection des donneesLaw of 30 May 2005 on privacy in electronic communications, Articles 5 and 9 - 6-month retention
cnpd.public.lu
“retain such data for a period of 6 months from the date of the communication”
Link checked 18 August 2026
What happens if there is a breach?
Count four clocks, because they overlap and they start at different moments. Privacy breach: 72 hours to tell the privacy regulator. Telephone and internet providers: 24 hours to report a personal data breach. Cybersecurity incidents at important companies: an early warning in 24 hours, a fuller report in 72 hours, and a final report a month later. Banks and insurers have their own European reporting on top. The trap is that one incident can start all of them at once, on different teams, with different forms.
Clock 1 - privacy. Article 33 of the General Data Protection Regulation: notify the CNPD within 72 hours of becoming aware, where there is a risk to people, and tell affected people without undue delay where the risk is high. Clock 2 - electronic communications. Providers must notify a personal data breach within 24 hours of detection, under Commission Regulation (EU) 611/2013 as applied by the CNPD. Clock 3 - cybersecurity. Under the Law of 5 May 2026, essential and important entities must send the competent authority a preliminary notification without undue delay and in any event within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of the incident notification. They must also warn the users of their service without undue delay where the incident may harm the service. Notifications go through the ILR's SERIMA platform. Clock 4 - finance. Financial entities also report major information and communication technology incidents under the European Digital Operational Resilience Act, which has applied since 17 January 2025.
Sources
- Official sourceCommission nationale pour la protection des donneesData breaches - notification duties for controllers and for electronic communications providers
cnpd.public.lu
Link checked 18 August 2026
- Official sourceInstitut Luxembourgeois de RegulationIncident notification - 24 hours, 72 hours and one month, via the SERIMA platform
ilr.lu
Link checked 18 August 2026
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 5 May 2026 on cybersecurity - 24-hour preliminary notification, 72-hour incident notification, final report within one month
data.legilux.public.lu
“sans retard injustifie et en tout etat de cause dans les vingt-quatre heures apres avoir eu connaissance de l'incident important, une notification prealable”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2022/2554 (Digital Operational Resilience Act)
eur-lex.europa.eu
Link checked 18 August 2026
What trips people up in Luxembourg?
Five things that are not in any summary. (1) Breaking bank or insurance client secrecy is a crime, not a fine, and it survives the end of the job. (2) Your works council can freeze an employee-monitoring project: staff have 15 days to ask the privacy regulator for an opinion, and that request suspends the project for a month. (3) Research projects carry a fixed list of 12 extra safeguards you must apply or justify skipping. (4) Using genetic data for employment or insurance purposes is banned outright. (5) The privacy regulator cannot fine the State or a commune, so a public body has far less to lose than you do.
1. Criminal secrecy. Article 41 of the Law of 5 April 1993 and Article 300 of the Law of 7 December 2015 both say disclosure is punished under Article 458 of the Penal Code. This reaches directors, employees and anyone working for the firm, and the insurance law states expressly that the duty survives after the job, mandate or practice ends. A standard European supplier contract is not enough on its own; the person with access must be under a legal secrecy duty or a confidentiality agreement, and the client must have accepted the outsourcing, the information type and the supplier's country. 2. Monitoring staff. Article L.261-1 of the Labour Code, as rewritten in 2018, requires the employer to inform the joint works committee or the staff delegation in advance, with a detailed description of the purpose, how the monitoring will work, how long data is kept, and a formal undertaking not to reuse the data for anything else. The delegation or the affected employees then have 15 days to ask the CNPD for a prior opinion, which the CNPD must give within a month, and the request suspends the project meanwhile. A complaint to the CNPD is expressly not a valid or serious reason to dismiss someone. 3. Research. Article 65 of the Law of 1 August 2018 lists 12 measures for scientific, historical or statistical research, including a data protection officer, an impact assessment, an independent trusted third party to pseudonymise, encryption in transit and at rest with state-of-the-art key management, access logs, an independent audit and a data management plan. You may leave one out, but you must document and justify it project by project. 4. Genetic data. Article 66 bans processing genetic data for the controller's own employment-law or insurance purposes. Full stop. 5. Public bodies. Article 48 of the same law bars administrative fines against the State and the communes. 6. Bonus, for insurers: Article 181-3 of the insurance law lists safeguards for health data, and four of them - encryption, access restrictions, log files and staff awareness, plus an internal policy - cannot be derogated from at all. 7. Bonus, on age: Luxembourg did not lower the age of digital consent, so it stays at 16, higher than France at 15 or the United Kingdom at 13.
Sources
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 1 August 2018, Articles 48, 65 and 66 and Article 71 rewriting Article L.261-1 of the Labour Code
data.legilux.public.lu
“la delegation du personnel, ou a defaut, les salaries concernes, peuvent, dans les quinze jours suivant l'information prealable, soumettre une demande d'avis prealable ... Cette demande a un effet suspensif pendant ce delai.”
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierLaw of 5 April 1993, Article 41(1) - disclosure punished under Article 458 of the Penal Code
cssf.lu
“Disclosure of such information shall be punishable by the penalties laid down in Article 458 of the Penal Code.”
Link checked 18 August 2026
- Official sourceCommissariat aux AssurancesLaw of 7 December 2015, Articles 181-3 and 300 - non-derogable health data safeguards and criminal insurance secrecy
caa.lu
Link checked 18 August 2026
What is changing soon in Luxembourg?
Two dated changes and several switches already in someone's hand. The dated ones: from 12 January 2027 cloud providers must let customers move away with no exit or transfer fees at all, and Luxembourg's new cybersecurity law, in force since 10 May 2026, is still being filled in with guidance and templates. The switches to watch: the European approval of United States transfers is under formal challenge, and the 6-month duty on telecoms firms to keep call records sits uneasily with European court rulings and could be struck at any time.
Dated. 12 January 2027 - the European Data Act makes all charges for switching cloud provider, including data egress fees, zero. This is a contract and architecture change, not a paperwork one. 10 May 2026 - the Law of 5 May 2026 on cybersecurity entered into force. Registration deadlines in the law are written to 17 January 2025 for cloud providers, data-centre providers, managed service providers, content delivery networks, online marketplaces, search engines and social platforms. Because that date is already past, an entity in scope is late from day one. The ILR is still running consultations and publishing templates for the security measures. Dormant switches. 1. The EU-US Data Privacy Framework. Valid on 18 August 2026, but the Latombe appeal is pending before the Court of Justice and on 31 July 2026 the European Data Protection Board asked the Commission to examine whether the decision still stands. If it falls, every transfer relying on it needs a new mechanism overnight. 2. Telecom retention. Articles 5 and 9 of the Law of 30 May 2005 impose a general 6-month duty to keep traffic and location data on every provider. Blanket, untargeted retention of this kind has repeatedly been held contrary to European law. We found no Luxembourg judgment disapplying it and no repeal, so it is treated here as in force, but it is the most likely provision in this record to change without warning. 3. Circular scope. Circular CSSF 25/883, effective immediately from 9 April 2025, switched off Part II of Circular CSSF 22/806 for firms covered by the European Digital Operational Resilience Act. Firms outside that Act still follow the old text. Reading the circular without the amendment gives the wrong answer. Proposed only, no legal effect: the European Digital Omnibus of 19 November 2025 and the Cloud and AI Development Act proposed on 3 June 2026.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) - cloud switching and egress charges
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 5 May 2026 on cybersecurity, Article 17 - registration information due by 17 January 2025
data.legilux.public.lu
“soumettent les informations suivantes a l'autorite competente au plus tard le 17 janvier 2025”
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierCircular CSSF 25/883, 9 April 2025 - Part II of Circular 22/806 no longer applies to entities in scope of the Digital Operational Resilience Act
cssf.lu
“Part II of Circular CSSF 22/806, related to ICT outsourcing arrangements, does not apply to them anymore”
Link checked 18 August 2026
- Official sourceCommission nationale pour la protection des donneesLaw of 30 May 2005, Articles 5 and 9 - the 6-month retention duty still on the books
cnpd.public.lu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions - the list of approved destinations
commission.europa.eu
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
1 rule here
Layer 2
National rules
Added by this country on top of any bloc rules.
2 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
6 rules here
Layer 4
Contract-imposed rule
Binds you because you signed something, typically a government contract.
1 rule here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules1 rule
Reglement general sur la protection des donnees (RGPD) - Reglement (UE) 2016/679
Directly binding regulation · Regulation (EU) 2016/679
The European privacy rulebook. It never requires data to stay in Europe; it sets conditions for sending it out. Fines scale with worldwide group turnover, and an order to stop processing usually hurts more than the fine.
Enforced by National Commission for Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of processing
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a local representativeRequired where there is no establishment in the European Union. It does not have to be in Luxembourg.
- Put a transfer safeguard in placePlus a documented transfer impact assessment after the Schrems II judgment.
- Do not hand data to foreign authorities on demandA third-country authority's order is not by itself a lawful basis to disclose (EDPB Guidelines 02/2024).
- Delete data after a period
- Get a parent's consent for children — applies at: under 16 in Luxembourg - the national law made no lower choice
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $11 millionController and processor obligations
- Order to stopThe CNPD can order processing to stop or suspend flows to a third country
- Claims by individualsIndividuals can claim compensation before the ordinary courts
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions - the list of approved destinations
commission.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEDPB Guidelines 02/2024 on Article 48 - a foreign authority's order is not by itself a lawful basis
edpb.europa.eu
Link checked 18 August 2026
National rules2 rules
Loi du 1er aout 2018 portant organisation de la Commission nationale pour la protection des donnees et mise en oeuvre du reglement (UE) 2016/679
Act of parliament · Memorial A no 686 of 16 August 2018
Luxembourg's national add-on to the European rules. It creates the regulator, adds a heavy 12-point safeguard list for research, bans genetic data in employment and insurance decisions, gives staff a power to suspend monitoring projects, and - a real gap - stops the regulator fining the State or the communes.
Enforced by National Commission for Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Appoint a data protection officerCompulsory for any scientific, historical or statistical research project under Article 65, on top of the usual European triggers.
- Assess high-risk projectsCompulsory for research projects under Article 65.
- Secure the dataArticle 65 requires encryption in transit and at rest with state-of-the-art key management for research data.
- Independent auditArticle 65: regular independent audit of the technical and organisational measures for research.
- Keep logsArticle 65: log files recording the reason, date, time and identity for every consultation, change or deletion of research data.
- Keep records of processingArticle 65: a data management plan must be drawn up before the research starts.
What it costs if you get it wrong
- Daily fine until fixed: up to 5% of average daily turnover, per day of delayFailing to supply information the CNPD asked for, or failing to comply with a corrective measure
- Criminal liability: 8 days to 1 year imprisonment and a fine of €251 to €125,000 (about $275 to $137,000) — about $137 thousandKnowingly preventing or obstructing the CNPD in carrying out its duties
Sources
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 1 August 2018, Articles 48, 49, 51, 55, 65, 66 and 71
data.legilux.public.lu
“La CNPD peut imposer les amendes administratives telles que prevues a l'article 83 du reglement (UE) 2016/679, sauf a l'encontre de l'Etat ou des communes.”
Link checked 18 August 2026
- Official sourceCommission nationale pour la protection des donneesLegislation - the Luxembourg texts the CNPD applies
cnpd.public.lu
Link checked 18 August 2026
Loi du 5 mai 2026 concernant des mesures destinees a assurer un niveau eleve de cybersecurite
Act of parliament · Memorial A no 225, published 6 May 2026
Luxembourg's transposition of the European cybersecurity directive, adopted 5 May 2026 and in force since 10 May 2026. Three clocks - 24 hours, 72 hours, one month - and a registration duty whose statutory deadline of 17 January 2025 was already in the past on the day the law started.
Enforced by Luxembourg Regulatory Institute
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 24 hoursPreliminary notification within 24 hours of becoming aware of a significant incident.
- Report cyber incidents — within 72 hoursFuller incident notification within 72 hours, with an initial severity and impact assessment and any indicators of compromise.
- Register or notify — from 17 January 2025Cloud providers, data-centre providers, managed service and managed security providers, content delivery networks, DNS and domain registration services, online marketplaces, search engines and social platforms must file name, sector, addresses, contacts, member states served and IP ranges. The deadline written in the law had already passed when the law commenced.
- Appoint a local representativeAn in-scope entity not established in the European Union must designate a representative; the authority can ask the President of the Luxembourg District Court to order the appointment.
- Secure the data
- Tell affected peopleUsers of the service must be warned without undue delay where a significant incident may harm the service.
What it costs if you get it wrong
- Fixed maximum fine: €10,000,000 or 2% of total worldwide annual turnover, whichever is higher, for essential entities — about $11 millionBreach of the cybersecurity risk-management or reporting duties
- Fixed maximum fine: €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher, for important entities — about $8 millionBreach of the cybersecurity risk-management or reporting duties
- Order to stopSupervisory and enforcement measures including temporary suspension of the activity
Sources
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 5 May 2026 on cybersecurity, Articles 16, 17, 20 and 26
data.legilux.public.lu
“soumettent les informations suivantes a l'autorite competente au plus tard le 17 janvier 2025”
Link checked 18 August 2026
- Official sourceInstitut Luxembourgeois de RegulationThe NIS2 law - Law of 5 May 2026 on measures for a high level of cybersecurity
ilr.lu
Link checked 18 August 2026
- Official sourceInstitut Luxembourgeois de RegulationIncident notification - 24 hours, 72 hours and one month, via the SERIMA platform
ilr.lu
Link checked 18 August 2026
Industry rules6 rules
Loi modifiee du 5 avril 1993 relative au secteur financier, article 41 (secret professionnel)
Act of parliament · Article 41 LFS, paragraph 2a inserted by the Law of 27 February 2018 · Banking
Luxembourg banking secrecy is a criminal duty, not a civil one. Client information can go to an outsourcing provider abroad, but only if the client has accepted the outsourcing, the type of information and the supplier's country of establishment - which makes the destination country a contract term, not an engineering choice.
Enforced by Financial Sector Supervisory Commission
Transfer model: Approval each time · Accepted routes: Explicit consent
What it makes you do
- Extra vendor secrecy termsThe people with access must be under a legal professional secrecy duty or bound by a confidentiality agreement. A standard processor contract on its own is not enough.
- Tell people what you doThe client must have accepted the outsourcing, the type of information transmitted and the country where the supplier is established.
- Register or notifyAn IT operator, digitiser or archiver serving Luxembourg financial firms may itself need a CSSF support-PFS licence under Articles 29-3, 29-5 or 29-6, with paid-up capital of EUR 125,000 or EUR 50,000.
What it costs if you get it wrong
- Criminal liability: the penalties in Article 458 of the Penal CodeDisclosing client information covered by banking secrecy
- Loss of your licenceLoss of authorisation for serious or repeated breaches of the financial sector law
Sources
- Official sourceCommission de Surveillance du Secteur FinancierLaw of 5 April 1993, Article 41(1) and (2a), and Articles 29-3, 29-5 and 29-6 on support-PFS statuses
cssf.lu
“the client has accepted ... the outsourcing of the outsourced services, the type of information transmitted in the context of the outsourcing and the country of establishment of the entities that provide outsourced services”
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierCSSF FAQ on Circular 22/806 on outsourcing arrangements
cssf.lu
Link checked 18 August 2026
Circulaire CSSF 22/806 relative aux arrangements d'externalisation, telle que modifiee par la circulaire CSSF 25/883
Regulator directive · Circular CSSF 22/806, points 28 and 59, as amended by Circular CSSF 25/883 of 9 April 2025 · Finance
The only genuine storage-location rule found in Luxembourg. A supervised financial firm may host its accounting system abroad, but must still hold a full, readable end-of-day backup of all accounting and client positions on premises inside the European Economic Area. Critical outsourcings need three months' prior notice to the regulator.
Enforced by Financial Sector Supervisory Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryNot Luxembourg, but the European Economic Area: where the accounting system is hosted outside Luxembourg, a secure end-of-day backup of all accounting and client positions must sit on premises inside the European Economic Area, belonging to the firm, a group entity, or a different service provider.
- Register or notify — within 2160 hoursPrior notification to the CSSF at least three months before a critical or important outsourcing takes effect.
- Written vendor contractThe written arrangement must state the regions or countries where the function is provided and where data is kept and processed.
- Independent auditRisk-based analysis covering oversight limitations in the countries where services are provided and data stored.
What it costs if you get it wrong
- Order to stopThe CSSF can require an outsourcing arrangement to be changed or terminated
Sources
- Official sourceCommission de Surveillance du Secteur FinancierCircular CSSF 22/806, points 28, 59, 61 to 65, 77 and 86
cssf.lu
“stored at the premises of the In-Scope Entity in the EEA, of a group entity located in the EEA, or of another service provider ... located in the EEA”
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierCircular CSSF 25/883 of 9 April 2025 - amends 22/806; Part II ceases to apply to entities in scope of the Digital Operational Resilience Act
cssf.lu
Link checked 18 August 2026
- Official sourceCommission de Surveillance du Secteur FinancierCSSF FAQ on Circular 22/806 on outsourcing arrangements
cssf.lu
Link checked 18 August 2026
Loi modifiee du 7 decembre 2015 sur le secteur des assurances, articles 181-3 et 300
Act of parliament · Articles 181-3 and 300, consolidated text of 3 April 2026 · Insurance
Insurance secrecy mirrors banking secrecy and is equally criminal. On top, an insurer processing health data must apply a listed set of safeguards, four of which - encryption, access limits, access logs and staff awareness - may never be derogated from.
Enforced by Insurance Commission
Transfer model: Approval each time · Accepted routes: Explicit consent
What it makes you do
- Extra vendor secrecy termsSame test as banking: the policyholder must have accepted the outsourcing, the type of information and the supplier's country of establishment.
- Secure the dataArticle 181-3: for health data, encryption in transit with state-of-the-art key management, access restrictions, log files and staff awareness cannot be waived at all.
- Appoint a data protection officerArticle 181-3 lists a data protection officer among the measures; skipping it must be documented and justified to the CNPD.
- Assess high-risk projectsArticle 181-3; skipping it must be documented and justified.
What it costs if you get it wrong
- Criminal liability: the penalties in Article 458 of the Penal CodeDisclosing information covered by insurance secrecy; the duty survives after the job or mandate ends
Sources
- Official sourceCommissariat aux AssurancesLaw of 7 December 2015 on the insurance sector, Articles 181-3 and 300
caa.lu
“Under no circumstances may a derogation be made from the measures listed in paragraph 1, point 2, letters d), e), f), g) and j).”
Link checked 18 August 2026
- Official sourceCommissariat aux Assurances (coordinated text)Law of 12 November 2004 - the anti-money-laundering retention duties that sit alongside insurance secrecy
caa.lu
Link checked 18 August 2026
Loi modifiee du 30 mai 2005 relative aux dispositions specifiques de protection de la personne a l'egard du traitement des donnees a caractere personnel dans le secteur des communications electroniques
Act of parliament · Articles 5 and 9, as amended by the Laws of 24 July 2010 and 28 July 2011 · Telecoms
Every telephone and internet provider must keep traffic and location records for 6 months and then delete or anonymise them. No storage location is specified. The duty is blanket and untargeted, which sits badly with European court rulings, so it is the provision here most likely to be struck or rewritten.
Enforced by National Commission for Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Keep data for a minimum period — 6 monthsTraffic data and location data other than traffic data, kept for criminal investigation purposes.
- Delete data after a period — 6 monthsAfter the 6 months the provider must erase or anonymise the data.
- Report breaches to the regulator — within 24 hoursElectronic communications providers report a personal data breach within 24 hours of detection.
- Secure the dataAccess must be technically impossible except for the listed judicial and billing-dispute cases.
What it costs if you get it wrong
- Criminal liability: 8 days to 1 year imprisonment and a fine of €251 to €125,000 (about $275 to $137,000) — about $137 thousandBreach of the confidentiality provisions of the law
- Order to stopA court may order the offending processing to stop, backed by a daily penalty
Sources
- Official sourceCommission nationale pour la protection des donneesLaw of 30 May 2005, Articles 5 and 9 - consolidated text published by the CNPD
cnpd.public.lu
“retain such data for a period of 6 months from the date of the communication”
Link checked 18 August 2026
- Official sourceCommission nationale pour la protection des donneesData breaches - notification duties for controllers and for electronic communications providers
cnpd.public.lu
Link checked 18 August 2026
Loi du 24 juillet 2014 relative aux droits et obligations du patient
Act of parliament · Law of 24 July 2014, patient file and shared care record · Health and social care
Patient files must be kept for at least 10 years after care ends, and nothing relevant may be stripped out during that period. We found no rule requiring health records to be hosted in Luxembourg, unlike the certified-host regime in France.
Enforced by National Commission for Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Keep data for a minimum period — 10 yearsAt least 10 years from the end of the episode of care. Neither the provider nor the patient may remove relevant items before that.
- Let people see their dataPatients access their shared care record under Article 60quater of the Social Security Code.
What it costs if you get it wrong
- Claims by individualsCivil liability of the health professional or hospital
Sources
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 24 July 2014 on patients' rights - 10-year retention of the patient file
data.legilux.public.lu
“Le depositaire d'un dossier patient est tenu d'en assurer la garde pendant dix ans au moins a partir de la date de la fin de la prise en charge.”
Link checked 18 August 2026
Loi modifiee du 12 novembre 2004 relative a la lutte contre le blanchiment et contre le financement du terrorisme, article 3, paragraphe 6
Act of parliament · Article 3(6), coordinated text of 6 February 2025 · Finance
Anti-money-laundering records run 5 years from the end of the relationship, extendable by the supervisor for up to 5 more years, and then must actually be erased. This is the clearest statement in Luxembourg law of how a keep-it duty and a delete-it duty are reconciled: the longest specific legal duty wins, and after that erasure is mandatory.
Enforced by Financial Sector Supervisory Commission
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Keep data for a minimum period — 5 yearsFive years from the end of the business relationship or the date of an occasional transaction, covering identification records, account books, business correspondence and analyses.
- Delete data after a period — 5 yearsPersonal data must be erased once the periods end, unless another law requires longer. A supervisor may order up to 5 further years in a specific case, and firms may hold data 5 more years where needed for internal prevention and detection.
- Keep records of processing
What it costs if you get it wrong
- Fixed maximum fineAdministrative fines by the CSSF or the Commissariat aux Assurances for breach of the record-keeping duty
Sources
- Official sourceCommissariat aux Assurances (coordinated text)Law of 12 November 2004, Article 3(6) - retention and mandatory erasure
caa.lu
“pendant cinq ans apres la fin de la relation d'affaires avec le client ou apres la date de la transaction conclue a titre occasionnel”
Link checked 18 August 2026
Contract-imposed rule1 rule
Loi du 25 juillet 2015 relative a l'archivage electronique
Act of parliament · Law of 25 July 2015, amending Article 1334 of the Civil Code and Article 16 of the Commercial Code
Not a location rule but a certification wall. A digital copy made by a provider certified under this law has, unless proved otherwise, the same evidential weight as the paper original - so if you want to scan and destroy Luxembourg records, you need a certified provider on the national list.
Enforced by Luxembourg Institute for Standardisation, Accreditation, Safety and Quality of Products and Services
Transfer model: No restriction · Accepted routes: Certification scheme
What it makes you do
- Hold a security certificateTo be listed as a dematerialisation or conservation service provider you must be certified by a certifier accredited by ILNAS, prove it annually, and be entered on the ILNAS list.
- Register or notifyOnly listed providers may call themselves a PSDC.
Sources
- Official sourceJournal officiel du Grand-Duche de Luxembourg (Legilux)Law of 25 July 2015 on electronic archiving, Articles 2, 11 and 12
data.legilux.public.lu
“Les copies sous forme numerique qui sont effectuees par un prestataire de services de dematerialisation ou de conservation ont, sauf preuve contraire, la meme valeur probante que l'original”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The outcome of Amazon's appeal against the CNPD's EUR 746 million fine of July 2021
We could not open a searchable database of Luxembourg administrative court decisions during this run. The fine is widely reported as the largest European privacy fine ever issued, and appeals are heard on the merits by the Administrative Tribunal, so the amount could in principle have been varied. Treat the figure as the amount imposed, not necessarily the amount finally payable.
The general 10-year retention period for accounting books and commercial records under Article 16 of the Commercial Code
Widely stated and consistent with the Law of 25 July 2015 which amends that same Article 16, but we could not open an official consolidated text of the Commercial Code or a government guidance page for it on 18 August 2026. Treat as very likely true but not backlinked here.
Whether the 6-month telecoms retention duty in Articles 5 and 9 of the Law of 30 May 2005 has been disapplied by a Luxembourg court or superseded by a reform bill
The provision is still in the consolidated text published by the CNPD and the law remains recorded as in force. Blanket retention of this kind has been repeatedly criticised by the Court of Justice of the European Union. We found no Luxembourg judgment disapplying it and no repeal, so it is recorded as in force with medium confidence. This is the single most likely item in this record to be wrong within a year.
Whether any localisation or sovereign-hosting requirement applies to Luxembourg government cloud, education, online gaming, mapping and geospatial data, or defence-related data
No rule found, checked 18 August 2026. We searched the regulators' own sites and the official gazette and did not locate one. Absence of a finding is not proof of absence, and public-sector procurement conditions are not always published as law.
Whether health data hosting in Luxembourg requires any certification comparable to the French certified health data host regime
The Law of 24 July 2014 and the shared care record regime set access and retention rules but we found no hosting-certification requirement. Recorded as 'not found' rather than 'does not exist'.
The exact penalties in Article 458 of the Luxembourg Penal Code that back banking and insurance secrecy
Both sector laws refer to Article 458 without restating the figures, and we did not open a consolidated Penal Code from an official source in this run. The criminal character of the duty is verified; the numbers are not.
Whether the registration deadline of 17 January 2025 written into Article 17 of the cybersecurity law of 5 May 2026 has been extended in practice by the regulator
The date is in the enacted text and the law only commenced on 10 May 2026, so the deadline is already past on its face. The ILR is running consultations and publishing templates, which suggests practical forbearance, but we found no published extension.
Current staffing of the Government Commissioner for Data Protection within the State
Its creation and mandate are verified from the statute. We did not find a government page confirming who currently holds the post.
The exact commencement dates of the Law of 27 February 2018 (which inserted the outsourcing carve-outs into banking and insurance secrecy), the Law of 1 August 2018, and the Law of 25 July 2015
Luxembourg laws commence a short fixed period after publication in the official journal unless they say otherwise. We verified the adoption and publication dates but could not open an official commencement statement for these three, so the dates in this record are the adoption date or the standard post-publication date and may be out by a few days. The commencement date of the cybersecurity law of 5 May 2026, 10 May 2026, is taken from the official journal's own metadata and is verified.
60-day cadence. Three things move here: the new cybersecurity law of 5 May 2026 is being filled in with regulator guidance and templates through 2026; the telecoms retention duty is exposed to European case law and could be disapplied without a Luxembourg legislative step; and the EU-US Data Privacy Framework, which a large share of Luxembourg's fund and payments industry relies on, is under formal challenge with the European Data Protection Board having written to the Commission on 31 July 2026.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Luxembourg versus Argentina
- Luxembourg versus Armenia
- Luxembourg versus Australia
- Luxembourg versus Austria
- Luxembourg versus Azerbaijan
- Luxembourg versus Brazil
- Luxembourg versus Bulgaria
- Luxembourg versus Cambodia
- Luxembourg versus Canada
- Luxembourg versus China
- Luxembourg versus Croatia
- Luxembourg versus Cyprus
- Luxembourg versus Estonia
- Luxembourg versus France
- Luxembourg versus Georgia
- Luxembourg versus Germany
- Luxembourg versus Greece
- Luxembourg versus Hong Kong SAR
- Luxembourg versus Hungary
- Luxembourg versus Iceland
- Luxembourg versus India
- Luxembourg versus Indonesia
- Luxembourg versus Ireland
- Luxembourg versus Israel
- Luxembourg versus Italy
- Luxembourg versus Japan
- Luxembourg versus Latvia
- Luxembourg versus Lithuania
- Luxembourg versus Malta
- Luxembourg versus Mexico
- Luxembourg versus Mongolia
- Luxembourg versus Nepal
- Luxembourg versus Netherlands
- Luxembourg versus Poland
- Luxembourg versus Russia
- Luxembourg versus Saudi Arabia
- Luxembourg versus Serbia
- Luxembourg versus Singapore
- Luxembourg versus Slovakia
- Luxembourg versus Slovenia
- Luxembourg versus South Korea
- Luxembourg versus Spain
- Luxembourg versus Sri Lanka
- Luxembourg versus Sweden
- Luxembourg versus Switzerland
- Luxembourg versus Taiwan
- Luxembourg versus Thailand
- Luxembourg versus Turkey
- Luxembourg versus Ukraine
- Luxembourg versus United Arab Emirates
- Luxembourg versus United Kingdom
- Luxembourg versus United States
- Luxembourg versus Uzbekistan