Skip to the content
Global Data RulesData governance rules, country by country

Luxembourg

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Luxembourg — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

You can send data out of Luxembourg. For most businesses the rules match the rest of the European Union. You need the right paperwork, not a local data centre. Finance is the exception, and finance is most of the economy here. Banks and insurers must keep client information secret. Breaking that secrecy is a crime. A bank that runs its accounts abroad must still keep a daily backup inside Europe.

Data governance in Luxembourg

The eight things that decide how you handle data about people in Luxembourg. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. If you sell to people in Luxembourg, the European privacy rules reach you even with no office here. The same is true if you track what they do online. There is no revenue or staff cut-off. A company with no base anywhere in Europe must appoint a representative in Europe. That representative does not have to be in Luxembourg. The extra Luxembourg-only duties in the national law mostly apply to organisations actually set up here.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, in general, with paperwork. Luxembourg has no national law telling ordinary companies to keep data in the country. European law also stops member states forcing non-personal data to stay put, except on public security grounds. But this is a banking and fund centre, and the finance rules change the answer. A bank or insurer may only hand client information to a supplier abroad with the client's agreement. The client must be told which country the supplier is in. And a bank whose accounting system sits outside Luxembourg must still keep a full daily backup somewhere inside the European Economic Area.

What you have to do here:
Keep the data in the country

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

You can only send personal data to approved countries, unless you put an approved safeguard in place first. The European Commission keeps the approved list, and it has plenty of countries on it. Luxembourg adds no national permit. The regulator does not pre-approve ordinary transfers. Finance is different. There, the client must agree to the destination country before their information moves.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

Yes, the regulators here really work. The privacy regulator is the National Commission for Data Protection, known as the CNPD. It is staffed and it publishes decisions. In 2025 it handled 846 complaints, 425 breach reports and 59 investigations. It issued the largest privacy fine ever recorded in Europe, against Amazon in 2021. The financial regulator and the insurance regulator are serious supervisors in their own right. Since May 2026 the telecoms regulator also runs the national cybersecurity rules.

What it costs if you get it wrong:
Daily fine until fixed · Criminal liability

How long you must keep it — and when to delete it

There is a minimum and a maximum, and they clash often. You must keep anti-money-laundering records for 5 years after the relationship ends. You must keep patient files for at least 10 years after care ends. You must keep telephone and internet connection records for 6 months. Pulling the other way, European privacy law says delete personal data once you no longer need it. The anti-money-laundering law says delete it when the 5 years are up, unless another law makes you keep it longer. That is how Luxembourg settles the clash. The longest specific legal duty wins. After that you must actually erase the data.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count four deadlines. They overlap and they start at different moments. Privacy breach: 72 hours to tell the privacy regulator. Telephone and internet providers: 24 hours to report a personal data breach. Cybersecurity incidents at important companies: an early warning in 24 hours, a fuller report in 72 hours, and a final report a month later. Banks and insurers have their own European reporting on top. The trap is that one incident can start all of them at once, on different teams, with different forms.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things that are not in any summary. (1) Breaking bank or insurance client secrecy is a crime, not a fine, and it lasts after the job ends. (2) Your works council can freeze a staff-monitoring project. Staff have 15 days to ask the privacy regulator for an opinion, and that request pauses the project for a month. (3) Research projects carry a fixed list of 12 extra safeguards. You must apply them or justify skipping one. (4) Using genetic data for employment or insurance purposes is banned outright. (5) The privacy regulator cannot fine the State or a commune, so a public body has far less to lose than you do.

What you have to do here:
Extra vendor secrecy terms · Assess high-risk projects · Appoint a data protection officer · Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability

What's changing next

Two dated changes are coming, plus some powers already in someone's hand. From 12 January 2027, cloud providers must let customers move away with no exit or transfer fees at all. Luxembourg's new cybersecurity law has been in force since 10 May 2026 and is still being filled in with guidance and templates. Two things could change fast. The European approval of United States transfers is under formal challenge. And the 6-month duty on telecoms firms to keep call records sits badly with European court rulings. It could be struck down at any time.

What you have to do here:
Make switching cloud provider possible

What to do: Diarise 12 January 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries6 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Cloud and outsourcing rules

Official name: Loi modifiee du 5 avril 1993 relative au secteur financier, article 41 (secret professionnel) · Article 41 LFS, paragraph 2a inserted by the Law of 27 February 2018 · Act of parliament

In forceYes, with paperwork

Breaking Luxembourg banking secrecy is a crime, not just a civil wrong. Client information can go to an outsourcing provider abroad. But the client must first agree to the outsourcing, the type of information and the supplier's country. That makes the destination country a contract term, not an engineering choice.

In force since 5 April 1993Enforced from 27 February 2018

Enforced by Financial Sector Supervisory Commission

How this country controls where data goes: Approval each time · Accepted routes: Explicit consent

Finance

Finance data needs a copy kept in the country

Official name: Circulaire CSSF 22/806 relative aux arrangements d'externalisation, telle que modifiee par la circulaire CSSF 25/883 · Circular CSSF 22/806, points 28 and 59, as amended by Circular CSSF 25/883 of 9 April 2025 · Regulator directive

Partly in forceA copy must stay

This is the only real storage-location rule we found in Luxembourg. A supervised financial firm may host its accounting system abroad. It must still hold a full, readable end-of-day backup of all accounting and client positions. That backup must sit on premises inside the European Economic Area. Critical outsourcing needs three months' notice to the regulator.

In force since 30 June 2022

Enforced by Financial Sector Supervisory Commission

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Insurance

Banking rules

Official name: Loi modifiee du 7 decembre 2015 sur le secteur des assurances, articles 181-3 et 300 · Articles 181-3 and 300, consolidated text of 3 April 2026 · Act of parliament

In forceYes, with paperwork

Insurance secrecy copies banking secrecy, and breaking it is equally a crime. On top of that, an insurer handling health data must apply a listed set of safeguards. Four of them can never be dropped: encryption, access limits, access logs and staff awareness.

In force since 7 December 2015Enforced from 27 February 2018

Enforced by Insurance Commission

How this country controls where data goes: Approval each time · Accepted routes: Explicit consent

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Europe's main privacy law (2018)

Official name: Loi du 1er aout 2018 portant organisation de la Commission nationale pour la protection des donnees et mise en oeuvre du reglement (UE) 2016/679 · Memorial A no 686 of 16 August 2018 · Act of parliament

In forceYes, with paperwork

Luxembourg's national add-on to the European rules. It creates the regulator. It adds a 12-point safeguard list for research. It bans genetic data in employment and insurance decisions. It lets staff pause monitoring projects. And it stops the regulator fining the State or the communes.

In force since 20 August 2018

Enforced by National Commission for Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Cyber security rules

Official name: Loi du 5 mai 2026 concernant des mesures destinees a assurer un niveau eleve de cybersecurite · Memorial A no 225, published 6 May 2026 · Act of parliament

In forceYes — store it anywhere

This puts the European cybersecurity directive into Luxembourg law. It was adopted on 5 May 2026 and has been in force since 10 May 2026. It sets three deadlines: 24 hours, 72 hours and one month. It also sets a registration duty. That deadline, 17 January 2025, had already passed on the day the law started.

In force since 10 May 2026

Enforced by Luxembourg Regulatory Institute

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Reglement general sur la protection des donnees (RGPD) - Reglement (UE) 2016/679 · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

The European privacy rulebook. It never requires data to stay in Europe. It sets the conditions for sending it out. Fines scale with worldwide group turnover. An order to stop using the data usually hurts more than the fine.

In force since 25 May 2018

Enforced by National Commission for Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Applies only if you signed a contract1 rule

Usually a government or enterprise contract that adds rules of its own.

Personal data needs a security certification

Official name: Loi du 25 juillet 2015 relative a l'archivage electronique · Law of 25 July 2015, amending Article 1334 of the Civil Code and Article 16 of the Commercial Code · Act of parliament

In forceYes, with paperwork

This is not a location rule. It is a certification rule. A digital copy made by a provider certified under this law counts as much as the paper original in court, unless someone proves otherwise. So if you want to scan Luxembourg records and destroy the paper, you need a certified provider from the national list.

In force since 8 August 2015

Enforced by Luxembourg Institute for Standardisation, Accreditation, Safety and Quality of Products and Services

How this country controls where data goes: No restriction · Accepted routes: Certification scheme

Who you would hear from

  • Commission nationale pour la protection des donnees (CNPD)

    General privacy law, electronic communications privacy, and new European roles under the Data Governance Act

    Fully staffed and working. Its 2025 annual report was presented on 10 July 2026. It records 846 complaints received, up 40 per cent on 2024. It also records 1,909 complaints handled, 425 personal data breach reports, 59 investigation cases and 16 opinions on draft laws. Anonymised decisions are published for 2021 to 2025, the most recent dated 16 December 2025. It cannot fine the State or the communes.

  • Commission de Surveillance du Secteur Financier (CSSF)

    Banks, investment firms, payment and e-money institutions, support PFS, funds and management companies

    Highly active. It runs the outsourcing notification rules under Circular 22/806. Circular 25/883 changed those rules with immediate effect on 9 April 2025. It also grants the support-PFS licences that computer operators and record keepers serving finance need.

  • Commissariat aux Assurances (CAA)

    Insurers, reinsurers, pension funds, insurance service providers and distributors

    Active supervisor. Publishes the consolidated insurance sector law, most recently updated 3 April 2026, and maintains a public sanctions page.

  • Institut Luxembourgeois de Regulation (ILR)

    Telecoms, postal services, energy, and since May 2026 the competent authority for network and information system security

    Working, and building out the new cybersecurity rules. It runs the SERIMA incident reporting platform. It publishes security-measure templates. It extended its public consultations on the new law during 2026.

  • Institut luxembourgeois de la normalisation, de l'accreditation, de la securite et qualite des produits et services (ILNAS)

    Accredits the certifiers and maintains the public list of certified digitisation and electronic conservation providers

    The Law of 25 July 2015 names it as the body that approves listings. It can check at any time that a provider still meets the conditions. It works with the CSSF where the provider is also a support PFS.

  • Commissariat du Gouvernement a la protection des donnees aupres de l'Etat

    Acts as data protection officer for state administrations and, on request, for communes; advises ministers

    Created by Articles 56 to 61 of the Law of 1 August 2018 and placed under the Prime Minister. We confirmed that it exists and what it does from the law itself. We could not confirm its current staffing from a government source. It advises and coordinates. It does not fine.

  • Tribunal administratif

    Hears appeals against CNPD decisions and rehears them on the merits

    Article 55 of the Law of 1 August 2018 lets it rehear a case in full. It can replace the regulator's decision with its own, not just check the process.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The outcome of Amazon's appeal against the CNPD's EUR 746 million fine of July 2021

    We could not confirm the outcome of the appeal from a government source. The fine is widely reported as the largest European privacy fine ever issued. The Administrative Tribunal rehears appeals in full, so the amount could have changed. Treat the figure as the amount imposed, not the amount finally paid.

  • The general 10-year retention period for accounting books and commercial records under Article 16 of the Commercial Code

    This is widely stated, and it fits the Law of 25 July 2015 which changes that same Article 16. We could not confirm it against an official text of the Commercial Code or government guidance. Treat it as very likely true, but check it before you rely on it.

  • Whether the 6-month telecoms retention duty in Articles 5 and 9 of the Law of 30 May 2005 has been disapplied by a Luxembourg court or superseded by a reform bill

    The rule is still in the text published by the CNPD, and the law is still recorded as in force. The Court of Justice of the European Union has repeatedly criticised keeping everyone's records like this. We found no Luxembourg judgment setting it aside and no repeal, so we record it as in force with medium confidence. This is the item in this record most likely to be wrong within a year.

  • Whether any localisation or sovereign-hosting requirement applies to Luxembourg government cloud, education, online gaming, mapping and geospatial data, or defence-related data

    We found no such rule, checked 18 August 2026. We searched the regulators' own sites and the official gazette. Not finding a rule is not proof that none exists. Public buying conditions are not always published as law. If you sell to these buyers, ask them directly.

  • Whether health data hosting in Luxembourg requires any certification comparable to the French certified health data host regime

    The Law of 24 July 2014 and the shared care record rules set who can see records and how long they are kept. We found no requirement that hosts be certified. We could not confirm this either way, so check before you rely on it.

  • The exact penalties in Article 458 of the Luxembourg Penal Code that back banking and insurance secrecy

    Both industry laws point to Article 458 without repeating the numbers. We could not confirm the figures against an official Penal Code text. We did confirm that breaking secrecy is a crime. If you need the exact penalty, ask a Luxembourg lawyer.

  • Whether the registration deadline of 17 January 2025 written into Article 17 of the cybersecurity law of 5 May 2026 has been extended in practice by the regulator

    The date is in the law as passed, and the law only started on 10 May 2026. So the deadline had already passed. The ILR is running consultations and publishing templates, which suggests it is not enforcing hard yet. We found no published extension. Ask the ILR where you stand.

  • Current staffing of the Government Commissioner for Data Protection within the State

    We confirmed that the office exists and what it does from the law itself. We found no government page saying who currently holds the post.

  • The exact commencement dates of the Law of 27 February 2018 (which inserted the outsourcing carve-outs into banking and insurance secrecy), the Law of 1 August 2018, and the Law of 25 July 2015

    Luxembourg laws start a short fixed period after publication in the official journal, unless they say otherwise. We confirmed the adoption and publication dates. We could not confirm an official start date for these three. So the dates here are either the adoption date or the standard date after publication, and they may be out by a few days. The start date of the cybersecurity law of 5 May 2026 is 10 May 2026. That one comes from the official journal's own record and is confirmed.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.