Liechtenstein DPA
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cross-Border + Articles 40-49 + EEA + Switzerland
Liechtenstein DSG Articles 40-49 International Data Transfer (transposing GDPR Chapter V Articles 44-50). Transfer of personal data outside EEA permitted only where: (a) destination jurisdiction provides adequate level of protection (DSS follows EU Commission adequacy decisions list - automatic recognition of EU/EEA + UK + Switzerland + Andorra + Argentina + Canada (commercial) + Faroe Islands + Guernsey + Isle of Man + Israel + Japan + Jersey + New Zealand + South Korea + Uruguay + USA via EU-US Data Privacy Framework 2023); (b) appropriate safeguards including 2021 EU SCCs (Decision 2021/914) + BCRs DSS-approved via consistency mechanism + Codes of Conduct + Certification; (c) derogations including explicit informed consent + performance of contract + public interest + legal claims + vital interests + register-based + limited transfers. Liechtenstein-Switzerland data flows special arra
- Cross-border transfer inventory
- EU adequacy reliance documentation
- 2021 EU SCCs executed copies
- DSS-approved BCRs
- Transfer Impact Assessment per Schrems II
- Switzerland-Liechtenstein flows documentation (Customs Union)
- CRS + FATCA + TIEA evidence for tax-information exchange
- Banking Act cross-border data exchange evidence
- Transfer without lawful basis
- Old SCCs not 2021
- No TIA
- Switzerland flows not documented
- CRS/FATCA gap
Enforcement + Sanctions + Articles 50-65
Liechtenstein DSG Articles 50-65 Enforcement and Sanctions. Articles 50-55 DSS Powers (transposing GDPR Articles 57-59): investigations + audits + on-site inspection + reprimands + warnings + temporary or definitive bans + processing suspension + Cross-Border data flow suspension + administrative fines (Verwaltungsbussen). Articles 56-58 Administrative Fines - GDPR Article 83 tiered system: (i) up to EUR 10 million or 2% of total worldwide annual turnover whichever is higher for lower-tier infringements (Article 83(4) GDPR - records + DPO + breach notification + security + processor obligations + certification); (ii) up to EUR 20 million or 4% of total worldwide annual turnover whichever is higher for higher-tier infringements (Article 83(5) GDPR - principles + lawful basis + consent + data subject rights + Cross-Border + DSS order non-compliance). DSS Resolution criteria mirroring GDPR
- DSS investigation response plan
- Sanctions exposure register (EUR 10M-20M + 2-4% turnover)
- Liechtenstein Penal Code Articles 188 + 195 awareness
- Administrative Court review procedure
- EFTA Court awareness
- Civil liability under ABGB/PGR analysis
- Certification or Code of Conduct adoption
- FMA financial sector cooperation evidence
- No DSS response plan
- No sanctions exposure analysis
- No criminal-risk register
- No EFTA Court awareness
- No certification
- No FMA cooperation
Governance + DPO + ROPA + DPIA + Whistleblowing
Liechtenstein DSG Articles 32-39 Governance and Accountability. Article 32 Data Protection Officer (Datenschutzbeauftragter - DPO/DSB) - mandatory designation under GDPR Article 37 + Liechtenstein additional requirements for: (a) financial sector entities (banks + asset managers + foundations + trusts above certain threshold); (b) public authorities; (c) core activities consisting of systematic monitoring on large scale; (d) core activities involving processing of special categories on large scale. DPO must be designated on basis of professional qualities + expert knowledge of data protection law and practice in financial sector + Liechtenstein FMA coordination experience + DSS notification + DPO contact publication + reporting to highest management + independence + no conflict of interest + DPO continuing professional development. Article 33 Records of Processing Activities (Verzeichnis
- DPO designation + DSS notification
- ROPA per processing operation
- DPIA reports for high-risk
- Privacy by Design + by Default in SDLC
- Annual training records
- Whistleblower Protection Act 2023 alignment evidence
- Liechtenstein FMA financial sector DPO coordination
- DLT/Blockchain Act token service provider DPIA
- No DPO
- ROPA incomplete
- No DPIA for high-risk
- No PbD in development
- No Whistleblower integration
- No FMA coordination
Lawful Basis + Consent + Principles + Articles 4-13
Liechtenstein DSG Articles 4-13 Principles and Lawful Basis (DSG transposes GDPR Articles 5-7 with Liechtenstein-specific national derogations). DSG Article 4 6 Principles (mirroring GDPR Article 5): Lawfulness + Fairness + Transparency + Purpose Limitation + Data Minimisation + Accuracy + Storage Limitation + Integrity and Confidentiality + Accountability. DSG Article 5 6 Lawful Bases (mirroring GDPR Article 6): consent + contract + legal obligation + vital interests + public interest + legitimate interests. DSG Article 6 Conditions for Consent (mirroring GDPR Article 7) - freely given + specific + informed + unambiguous + clear affirmative action + withdrawable + verifiable for children below age 16 (Liechtenstein follows GDPR default age 16 + parental consent for under-16s). DSG Articles 9-12 Information to Data Subjects (mirroring GDPR Articles 13-14) - notice at collection covering
- Lawful basis register
- Consent records
- German privacy notices
- Children parental consent (under 16)
- Direct marketing soft-opt-in evidence
- Records of Consent (DSG Article 13)
- Bundled consent
- Notices not in German
- No children verification
- Marketing without opt-in
- No Records of Consent maintained
Scope + DSG 2018 + EEA + GDPR + DSS Vaduz
Principality of Liechtenstein Datenschutzgesetz (DSG) - Data Protection Act of 4 October 2018 + published Liechtenstein Law Gazette (LGBl. 2018 No. 273) + Princely Decree (Furstliche Verordnung) + effective 1 January 2019. Foundational Liechtenstein data protection statute implementing EU GDPR (Regulation 2016/679) which applies in Liechtenstein via the EEA Agreement (European Economic Area Agreement, 1992) which Liechtenstein joined 1995. Liechtenstein is one of 3 EFTA non-EU EEA states (with Iceland and Norway) where EU acquis communautaire applies subject to EEA Joint Committee incorporation. GDPR was incorporated into EEA Agreement by EEA Joint Committee Decision No 154/2018 of 6 July 2018 + entered into force in Liechtenstein 20 July 2018 + transposed by Liechtenstein via DSG 2018. Constitutional anchor Constitution of Liechtenstein Article 32 personal liberty + Article 34 inviolabi
- Applicability assessment
- Personal data inventory
- DSS engagement records
- German privacy notices
- EEA Agreement compliance memo
- Financial sector specific evidence (Banking/FMA)
- DLT/Blockchain Act compliance for token providers
- No DSS engagement
- Notices not in German
- Treating Liechtenstein DSG same as plain GDPR without EEA specifics
- No financial sector specific evidence
Security + Breach + Articles 25-31
Liechtenstein DSG Articles 25-31 Security + Processor + Breach Notification. Article 25 Security of Processing (Sicherheit der Verarbeitung) - controllers and processors must implement appropriate technical and organisational measures proportionate to risk + state-of-the-art + including encryption (at rest + in transit) + pseudonymisation + access control + RBAC + MFA + logging + monitoring + secure SDLC + vulnerability management + Liechtenstein financial sector ISO 27001 + ISO 27701 + Banking Act information security requirements + FMA Circular on IT and Cyber Risk Management + DLT/Blockchain Act security requirements for Token Service Providers. Article 26 Processor Engagement (Auftragsverarbeiter) - written contract specifying categories + purposes + duration + obligations including process only on documented instructions + confidentiality + security + sub-processor authorisation + D
- Encryption + pseudonymisation evidence
- Processor contracts (Article 26 compliant)
- DSS breach notification log + 72-hour evidence
- Affected data subject notification
- FMA financial sector breach notification + Banking Act/Insurance Supervision Act alignment
- CSCC Cyber Security Coordination Centre coordination
- Liechtenstein Police incident liaison
- DLT/Blockchain Act security for Token Service Providers
- No encryption
- No processor contracts
- Late DSS notification
- No parallel FMA notification
- No CSCC liaison
- DLT security gap
Special Categories + Children + Financial Sector
Liechtenstein DSG Articles 9 + 23-24 Special Categories of Personal Data (transposing GDPR Article 9). Special Categories: racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union membership + genetic data + biometric data for unique identification + health data + sexual life + sexual orientation + criminal convictions. Processing prohibited except: (a) explicit consent; (b) employment + social security + social protection law; (c) vital interests; (d) processing by non-profit body for members; (e) data manifestly made public; (f) legal claims; (g) substantial public interest authorised by law; (h) preventive or occupational medicine + medical diagnosis + healthcare + public health (with professional secrecy under Liechtenstein Health Act + Doctors Act); (i) public interest in archiving + scientific or historical research + statistical purposes (wit
- Special categories inventory
- Explicit consent records
- Healthcare data Liechtenstein Health Act compliance
- Doctors Act professional secrecy attestations
- FMA financial sector special-categories exemption documentation
- CDD/AML KYC special-categories processing evidence
- Special categories without explicit consent
- Healthcare without professional secrecy
- No FMA financial sector documentation
- CDD/AML processing not aligned
Subject Rights + Articles 15-22
Liechtenstein DSG Articles 15-22 Data Subject Rights (transposing GDPR Articles 15-22): Article 15 Right of Access (Auskunftsrecht) - to obtain confirmation of processing + access to personal data + supplementary information + 30-day standard response + 60-day extension for complex requests + free first request. Article 16 Right to Rectification (Berichtigungsrecht) - to correct inaccurate + incomplete + outdated data + propagation to recipients. Article 17 Right to Erasure (Recht auf Loschung / Right to be Forgotten) - to delete personal data when no longer necessary + consent withdrawn + unlawful processing + legal obligation. Article 18 Right to Restriction (Recht auf Einschrankung). Article 19 Notification Obligation - controller communicates rectification/erasure/restriction to recipients. Article 20 Right to Data Portability (Recht auf Datenubertragbarkeit) - structured + commonly-
- Rights request SLAs (30-day + 60-day complex) + log
- German response templates
- Portability format documentation
- Article 22 automated decision opt-out
- DSS appeals procedure
- Administrative Court review path
- Article 23 restriction documentation for financial sector
- Slow response
- No financial sector restriction documentation
- No appeals path
- No portability format
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Liechtenstein DPA framework page.