Skip to content

Evidence request lists

Liechtenstein DPA

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cross-Border + Articles 40-49 + EEA + Switzerland

LIDPA-Cross-Border-International-Transfer-Articles-40-49-GDPR-Chapter-V-EEA-Adequacy-SCC-BCR-Switzerland
Liechtenstein DPA Cross-Border + Articles 40-49 + EEA + Switzerland + SCC

Liechtenstein DSG Articles 40-49 International Data Transfer (transposing GDPR Chapter V Articles 44-50). Transfer of personal data outside EEA permitted only where: (a) destination jurisdiction provides adequate level of protection (DSS follows EU Commission adequacy decisions list - automatic recognition of EU/EEA + UK + Switzerland + Andorra + Argentina + Canada (commercial) + Faroe Islands + Guernsey + Isle of Man + Israel + Japan + Jersey + New Zealand + South Korea + Uruguay + USA via EU-US Data Privacy Framework 2023); (b) appropriate safeguards including 2021 EU SCCs (Decision 2021/914) + BCRs DSS-approved via consistency mechanism + Codes of Conduct + Certification; (c) derogations including explicit informed consent + performance of contract + public interest + legal claims + vital interests + register-based + limited transfers. Liechtenstein-Switzerland data flows special arra

Artefacts an auditor will ask for
  • Cross-border transfer inventory
  • EU adequacy reliance documentation
  • 2021 EU SCCs executed copies
  • DSS-approved BCRs
  • Transfer Impact Assessment per Schrems II
  • Switzerland-Liechtenstein flows documentation (Customs Union)
  • CRS + FATCA + TIEA evidence for tax-information exchange
  • Banking Act cross-border data exchange evidence
Where this commonly fails
  • Transfer without lawful basis
  • Old SCCs not 2021
  • No TIA
  • Switzerland flows not documented
  • CRS/FATCA gap

Enforcement + Sanctions + Articles 50-65

LIDPA-Enforcement-Sanctions-Articles-50-65-DSS-Administrative-Fines-20M-EUR-4-Percent-Cooperation-Codes-Certification
Liechtenstein DPA Enforcement + Articles 50-65 + Administrative Fines EUR 20M + 4%

Liechtenstein DSG Articles 50-65 Enforcement and Sanctions. Articles 50-55 DSS Powers (transposing GDPR Articles 57-59): investigations + audits + on-site inspection + reprimands + warnings + temporary or definitive bans + processing suspension + Cross-Border data flow suspension + administrative fines (Verwaltungsbussen). Articles 56-58 Administrative Fines - GDPR Article 83 tiered system: (i) up to EUR 10 million or 2% of total worldwide annual turnover whichever is higher for lower-tier infringements (Article 83(4) GDPR - records + DPO + breach notification + security + processor obligations + certification); (ii) up to EUR 20 million or 4% of total worldwide annual turnover whichever is higher for higher-tier infringements (Article 83(5) GDPR - principles + lawful basis + consent + data subject rights + Cross-Border + DSS order non-compliance). DSS Resolution criteria mirroring GDPR

Artefacts an auditor will ask for
  • DSS investigation response plan
  • Sanctions exposure register (EUR 10M-20M + 2-4% turnover)
  • Liechtenstein Penal Code Articles 188 + 195 awareness
  • Administrative Court review procedure
  • EFTA Court awareness
  • Civil liability under ABGB/PGR analysis
  • Certification or Code of Conduct adoption
  • FMA financial sector cooperation evidence
Where this commonly fails
  • No DSS response plan
  • No sanctions exposure analysis
  • No criminal-risk register
  • No EFTA Court awareness
  • No certification
  • No FMA cooperation

Governance + DPO + ROPA + DPIA + Whistleblowing

LIDPA-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Articles-32-39-Codes-of-Conduct-Whistleblowing
Liechtenstein DPA Governance + DPO + ROPA + DPIA + Articles 32-39 + Whistleblowing

Liechtenstein DSG Articles 32-39 Governance and Accountability. Article 32 Data Protection Officer (Datenschutzbeauftragter - DPO/DSB) - mandatory designation under GDPR Article 37 + Liechtenstein additional requirements for: (a) financial sector entities (banks + asset managers + foundations + trusts above certain threshold); (b) public authorities; (c) core activities consisting of systematic monitoring on large scale; (d) core activities involving processing of special categories on large scale. DPO must be designated on basis of professional qualities + expert knowledge of data protection law and practice in financial sector + Liechtenstein FMA coordination experience + DSS notification + DPO contact publication + reporting to highest management + independence + no conflict of interest + DPO continuing professional development. Article 33 Records of Processing Activities (Verzeichnis

Artefacts an auditor will ask for
  • DPO designation + DSS notification
  • ROPA per processing operation
  • DPIA reports for high-risk
  • Privacy by Design + by Default in SDLC
  • Annual training records
  • Whistleblower Protection Act 2023 alignment evidence
  • Liechtenstein FMA financial sector DPO coordination
  • DLT/Blockchain Act token service provider DPIA
Where this commonly fails
  • No DPO
  • ROPA incomplete
  • No DPIA for high-risk
  • No PbD in development
  • No Whistleblower integration
  • No FMA coordination

Lawful Basis + Consent + Principles + Articles 4-13

LIDPA-Lawful-Basis-Consent-Notice-Principles-DSG-Articles-4-13-GDPR-Articles-5-6-7-Liechtenstein-Specific
Liechtenstein DPA Lawful Basis + Consent + Notice + Principles + Articles 4-13

Liechtenstein DSG Articles 4-13 Principles and Lawful Basis (DSG transposes GDPR Articles 5-7 with Liechtenstein-specific national derogations). DSG Article 4 6 Principles (mirroring GDPR Article 5): Lawfulness + Fairness + Transparency + Purpose Limitation + Data Minimisation + Accuracy + Storage Limitation + Integrity and Confidentiality + Accountability. DSG Article 5 6 Lawful Bases (mirroring GDPR Article 6): consent + contract + legal obligation + vital interests + public interest + legitimate interests. DSG Article 6 Conditions for Consent (mirroring GDPR Article 7) - freely given + specific + informed + unambiguous + clear affirmative action + withdrawable + verifiable for children below age 16 (Liechtenstein follows GDPR default age 16 + parental consent for under-16s). DSG Articles 9-12 Information to Data Subjects (mirroring GDPR Articles 13-14) - notice at collection covering

Artefacts an auditor will ask for
  • Lawful basis register
  • Consent records
  • German privacy notices
  • Children parental consent (under 16)
  • Direct marketing soft-opt-in evidence
  • Records of Consent (DSG Article 13)
Where this commonly fails
  • Bundled consent
  • Notices not in German
  • No children verification
  • Marketing without opt-in
  • No Records of Consent maintained

Scope + DSG 2018 + EEA + GDPR + DSS Vaduz

LIDPA-Scope-Datenschutzgesetz-DSG-2018-Princely-Decree-EEA-Agreement-GDPR-DSS-Vaduz-Constitution-Article-32
Liechtenstein DPA Scope + DSG 2018 + Princely Decree + EEA Agreement + GDPR via EEA + DSS Vaduz

Principality of Liechtenstein Datenschutzgesetz (DSG) - Data Protection Act of 4 October 2018 + published Liechtenstein Law Gazette (LGBl. 2018 No. 273) + Princely Decree (Furstliche Verordnung) + effective 1 January 2019. Foundational Liechtenstein data protection statute implementing EU GDPR (Regulation 2016/679) which applies in Liechtenstein via the EEA Agreement (European Economic Area Agreement, 1992) which Liechtenstein joined 1995. Liechtenstein is one of 3 EFTA non-EU EEA states (with Iceland and Norway) where EU acquis communautaire applies subject to EEA Joint Committee incorporation. GDPR was incorporated into EEA Agreement by EEA Joint Committee Decision No 154/2018 of 6 July 2018 + entered into force in Liechtenstein 20 July 2018 + transposed by Liechtenstein via DSG 2018. Constitutional anchor Constitution of Liechtenstein Article 32 personal liberty + Article 34 inviolabi

Artefacts an auditor will ask for
  • Applicability assessment
  • Personal data inventory
  • DSS engagement records
  • German privacy notices
  • EEA Agreement compliance memo
  • Financial sector specific evidence (Banking/FMA)
  • DLT/Blockchain Act compliance for token providers
Where this commonly fails
  • No DSS engagement
  • Notices not in German
  • Treating Liechtenstein DSG same as plain GDPR without EEA specifics
  • No financial sector specific evidence

Security + Breach + Articles 25-31

LIDPA-Security-Processor-Engagement-Breach-Notification-Articles-25-31-72-Hour-DSS-FMA-Coordination
Liechtenstein DPA Security + Processor + Breach + Articles 25-31 + 72-Hour + FMA

Liechtenstein DSG Articles 25-31 Security + Processor + Breach Notification. Article 25 Security of Processing (Sicherheit der Verarbeitung) - controllers and processors must implement appropriate technical and organisational measures proportionate to risk + state-of-the-art + including encryption (at rest + in transit) + pseudonymisation + access control + RBAC + MFA + logging + monitoring + secure SDLC + vulnerability management + Liechtenstein financial sector ISO 27001 + ISO 27701 + Banking Act information security requirements + FMA Circular on IT and Cyber Risk Management + DLT/Blockchain Act security requirements for Token Service Providers. Article 26 Processor Engagement (Auftragsverarbeiter) - written contract specifying categories + purposes + duration + obligations including process only on documented instructions + confidentiality + security + sub-processor authorisation + D

Artefacts an auditor will ask for
  • Encryption + pseudonymisation evidence
  • Processor contracts (Article 26 compliant)
  • DSS breach notification log + 72-hour evidence
  • Affected data subject notification
  • FMA financial sector breach notification + Banking Act/Insurance Supervision Act alignment
  • CSCC Cyber Security Coordination Centre coordination
  • Liechtenstein Police incident liaison
  • DLT/Blockchain Act security for Token Service Providers
Where this commonly fails
  • No encryption
  • No processor contracts
  • Late DSS notification
  • No parallel FMA notification
  • No CSCC liaison
  • DLT security gap

Special Categories + Children + Financial Sector

LIDPA-Special-Categories-Sensitive-Data-Children-Article-9-GDPR-Article-9-Health-Financial-Sector
Liechtenstein DPA Special Categories + Sensitive Data + Children + Article 9

Liechtenstein DSG Articles 9 + 23-24 Special Categories of Personal Data (transposing GDPR Article 9). Special Categories: racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union membership + genetic data + biometric data for unique identification + health data + sexual life + sexual orientation + criminal convictions. Processing prohibited except: (a) explicit consent; (b) employment + social security + social protection law; (c) vital interests; (d) processing by non-profit body for members; (e) data manifestly made public; (f) legal claims; (g) substantial public interest authorised by law; (h) preventive or occupational medicine + medical diagnosis + healthcare + public health (with professional secrecy under Liechtenstein Health Act + Doctors Act); (i) public interest in archiving + scientific or historical research + statistical purposes (wit

Artefacts an auditor will ask for
  • Special categories inventory
  • Explicit consent records
  • Healthcare data Liechtenstein Health Act compliance
  • Doctors Act professional secrecy attestations
  • FMA financial sector special-categories exemption documentation
  • CDD/AML KYC special-categories processing evidence
Where this commonly fails
  • Special categories without explicit consent
  • Healthcare without professional secrecy
  • No FMA financial sector documentation
  • CDD/AML processing not aligned

Subject Rights + Articles 15-22

LIDPA-Data-Subject-Rights-Access-Rectification-Erasure-Object-Portability-DSG-Articles-15-22-GDPR-Aligned
Liechtenstein DPA Data Subject Rights + Articles 15-22 + GDPR-Aligned

Liechtenstein DSG Articles 15-22 Data Subject Rights (transposing GDPR Articles 15-22): Article 15 Right of Access (Auskunftsrecht) - to obtain confirmation of processing + access to personal data + supplementary information + 30-day standard response + 60-day extension for complex requests + free first request. Article 16 Right to Rectification (Berichtigungsrecht) - to correct inaccurate + incomplete + outdated data + propagation to recipients. Article 17 Right to Erasure (Recht auf Loschung / Right to be Forgotten) - to delete personal data when no longer necessary + consent withdrawn + unlawful processing + legal obligation. Article 18 Right to Restriction (Recht auf Einschrankung). Article 19 Notification Obligation - controller communicates rectification/erasure/restriction to recipients. Article 20 Right to Data Portability (Recht auf Datenubertragbarkeit) - structured + commonly-

Artefacts an auditor will ask for
  • Rights request SLAs (30-day + 60-day complex) + log
  • German response templates
  • Portability format documentation
  • Article 22 automated decision opt-out
  • DSS appeals procedure
  • Administrative Court review path
  • Article 23 restriction documentation for financial sector
Where this commonly fails
  • Slow response
  • No financial sector restriction documentation
  • No appeals path
  • No portability format
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Liechtenstein DPA framework page.