Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cross-Border + EEA + Adequacy + SCC + Financial
Luxembourg LDP LU-DPA-Transfers International Data Transfers (GDPR Chapter V Articles 44-50). Transfer of personal data outside EEA permitted only where: (a) destination jurisdiction provides adequate level of protection (EU Commission adequacy decisions list - automatic recognition of EU/EEA + UK + Switzerland + Andorra + Argentina + Canada commercial + Faroe Islands + Guernsey + Isle of Man + Israel + Japan + Jersey + New Zealand + South Korea + Uruguay + USA via EU-US Data Privacy Framework 2023); (b) appropriate safeguards including 2021 EU SCCs (Decision 2021/914) + Binding Corporate Rules CNPD-approved via EDPB consistency mechanism + Codes of Conduct + Certification; (c) derogations including explicit consent + performance of contract + public interest + legal claims + vital interests + register-based + limited transfers. Schrems II Transfer Impact Assessment + EU-US Data Privacy
- Cross-border transfer inventory
- Adequacy reliance documentation
- 2021 EU SCCs executed copies
- CNPD-approved BCRs
- Transfer Impact Assessment per Schrems II
- CSSF cloud + outsourcing alignment (Circular 22/806)
- CRS + FATCA + DAC2 evidence
- MiCA crypto-asset cross-border evidence
- Transfer without lawful basis
- Old SCCs not 2021
- No TIA
- No CSSF cloud alignment
- No CRS/FATCA evidence
DPO + ROPA + DPIA + Codes + Articles 4 + 9 + 50 + 69
Luxembourg LDP Articles 4 + 9 + 50 + 69 Governance and Accountability. Article 4 CNPD Composition and Independence - 5 Commissioners appointed by Grand-Duc + 6-year term + multi-year strategic plan + Annual Report to Government + Chambre des Deputes + Belval HQ + Luxembourg financial sector cooperation. Article 9 CNPD Investigatory and Corrective Powers (GDPR Article 58 transposition) - investigations + audits + on-site inspection + access to premises + production of records + reprimands + warnings + temporary or definitive bans + processing suspension + Cross-Border data flow suspension + administrative fines + corrective orders + EU consistency mechanism participation. Article 50 Designation of the Data Protection Officer (DPO - Delegue a la Protection des Donnees) - GDPR Article 37 implementation + Luxembourg additional requirements: (a) public bodies; (b) core activities consisting o
- CNPD investigation response plan
- DPO designation + CNPD notification
- ROPA per processing operation
- DPIA reports for high-risk + CNPD AIPD list compliance
- Codes of Conduct adoption (ABBL + ALFI + ACA)
- ISO 27701 certification
- ILNAS certification body engagement
- No CNPD response plan
- No DPO
- No ROPA
- No DPIA
- No Code of Conduct
- No certification
Enforcement + Article 43 Public Sector + Fines + CNPD
Luxembourg LDP Article 43 + 57 Enforcement and Sanctions + Transitional Provisions. Article 43 Limitation on Administrative Fines for Public Sector (LUXEMBOURG-UNIQUE) - administrative fines under GDPR Article 83 do not apply to State + municipalities + public legal entities except where they operate as economic operators in competitive market or process personal data in commercial context similar to private sector + alternative sanctions for public sector include warnings + corrective orders + injunctions + cooperation with internal disciplinary procedures + parliamentary oversight + Court of Audit (Cour des Comptes) supervision. CNPD Administrative Fines for private sector follow GDPR Article 83 tiered system: (i) up to EUR 10 million or 2% of total worldwide annual turnover whichever is higher for lower-tier infringements; (ii) up to EUR 20 million or 4% of total worldwide annual turn
- CNPD investigation response plan
- Sanctions exposure register (EUR 10M-20M private + alternative public-sector sanctions)
- Code Penal Article 458 professional secrecy awareness
- Amazon Luxembourg EUR 746M precedent analysis
- Tribunal Administratif review procedure
- Cour Administrative appeal path
- No CNPD response plan
- No sanctions exposure analysis
- No Tribunal Administratif procedure
- No public-sector alternative sanctions awareness
Multilingual + Marketing + Cookies
Luxembourg LDP Multilingual Information and Communication Obligations + Electronic Marketing and Cookies. Luxembourg requires privacy notices and communications with data subjects in: (a) Luxembourg's three official languages (Luxembourgish + French + German); (b) English where reasonably required for international financial services context; (c) accessible to vulnerable customers + disabled persons + non-residents; (d) Luxembourg Civil Code requires specific clarity for distance contracts. Implementing Loi du 18 December 2015 on Electronic Commerce + Luxembourg Code Civil + Code de la Consommation + Loi du 30 May 2005 on Electronic Communications. Marketing and Cookies (Loi du 30 mai 2005 + 2024 ePrivacy modernisation): (a) Opt-in consent required for electronic direct marketing (email + SMS + automated calling) + soft-opt-in for similar products from same controller; (b) Opt-out at eve
- Privacy notices in Luxembourgish + French + German + English
- CNPD Cookies Guidelines compliance evidence
- Cookie banner + granular controls
- Marketing opt-in evidence + soft-opt-in policy
- CSSF Circular 21/789 banking marketing compliance
- No multilingual notices
- Cookie wall used
- Marketing without opt-in
- No CSSF compliance for banking
Scope + Chambre des Deputes + CNPD + GDPR
Grand Duchy of Luxembourg Law of 1 August 2018 on the Organisation of the National Commission for Data Protection and the General Regime on Data Protection (Loi du 1er aout 2018 portant organisation de la Commission nationale pour la protection des donnees et du regime general sur la protection des donnees) + adopted by Chambre des Deputes 1 August 2018 + published Memorial A No. 686 of 16 August 2018 + effective 20 August 2018. Foundational Luxembourg data protection statute implementing EU GDPR Regulation 2016/679 + Loi du 1er aout 2018 on protection of personal data in matters relating to criminal investigations (transposing LED Directive 2016/680) + replaces Luxembourg 2002 Data Protection Law. Constitutional anchor Luxembourg Constitution Article 11 paragraph 3 protection of private life (revised 2008) + Article 28 freedom of expression + Convention 108+ adherence. Commission nation
- Applicability assessment
- Personal data inventory
- CNPD engagement records
- Multilingual privacy notices (Luxembourgish + French + German)
- Constitutional Article 11 compliance memo
- Convention 108+ alignment
- No CNPD engagement
- Notices not multilingual
- No financial sector documentation
Security + Breach + CNPD + CSSF + 72-Hour
Luxembourg LDP LU-DPA-Breach Personal Data Breach Notification - GDPR Article 33 implementation: controller must notify CNPD within 72 hours of becoming aware where likely to result in risk to rights and freedoms + notify affected data subjects without undue delay where likely high-risk + content (nature + categories + approximate number + likely consequences + measures taken or proposed + DPO contact). CNPD online breach notification portal (operational since 2018). Sectoral parallel notifications: (a) CSSF (financial sector) under Loi du 5 April 1993 Article 23-1 + CSSF Circulars + 72-hour notification to CSSF Major Incident Reporting; (b) CAA (insurance) under Loi du 7 December 2015 + similar 72-hour notification; (c) BCE (Banque Centrale du Luxembourg) for credit institutions; (d) CIRCL (Computer Incident Response Centre Luxembourg) for cyber security incidents + voluntary reporting;
- CNPD breach notification + 72-hour evidence
- CSSF Major Incident Reporting
- CAA breach notification (insurance)
- BCE notification (credit institutions)
- CIRCL coordination
- CSIRT Luxembourg coordination
- NIS2 transposition compliance (Loi 30 May 2024)
- Late CNPD notification
- No parallel sectoral notification
- No CIRCL liaison
- No NIS2 transposition compliance
Subject Rights + Article 72 + Financial CSSF
Luxembourg LDP Article 72 Restrictions on Data Subject Rights for National Interest + Financial Sector Provisions. Article 72 transposes GDPR Article 23 specifying Luxembourg-permitted restrictions: (a) national security + defence (Service de Renseignement de l'Etat + Direction Generale de la Police - Service de Police Judiciaire); (b) public security + criminal investigation (Code d'Instruction Criminelle + Procureur d'Etat); (c) economic + financial interest including Luxembourg financial market supervision (CSSF + CAA) + monetary + budgetary + taxation matters (Administration des Contributions Directes + Administration de l'Enregistrement et des Domaines + TVA + AML/CFT); (d) public health (Direction de la Sante + Code de la Securite Sociale); (e) judicial independence + judicial proceedings + privileged communications + cross-border cooperation with prosecutors; (f) protection of dat
- Rights request SLAs + log
- Article 72 restriction documentation per category
- CSSF Circulars compliance evidence
- Banking secrecy + AML coordination
- CSSF Major Incident Reporting + CAA coordination
- No Article 72 restriction documentation
- No CSSF coordination
- No CAA coordination
- Banking secrecy/GDPR balance gap
Workplace + Whistleblowing + Journalism + Articles 52-67
Luxembourg LDP Articles 52 + 63 + 65 + 67 Special-Contexts Processing. Article 52 Processing of Personal Data for Journalistic Purposes (Loi du 8 juin 2004 modified 2018 sur la liberte d'expression dans les medias) - extensive GDPR Article 85 derogation balancing freedom of expression + privacy + Luxembourg Press Law + Journalists Code of Ethics + Press Council (Conseil de Presse) + public broadcaster Luxembourg Sender + RTL Group + academic freedom + creative expression + protected sources + journalistic shield + opinion polling for general elections. Article 63 Surveillance in the Workplace (Loi du 16 juin 2017 + Code du Travail Articles L.261-1 + Articles L.211-1+) - employer workplace monitoring requires: (a) legitimate purpose limited to security + worker protection + production control + IT system protection + traffic control + transaction or service monitoring; (b) employee repres
- Article 52 journalism derogation memos
- Article 63 workplace surveillance Delegation du Personnel consultation + CNPD prior consultation
- Article 65 scientific research bioethics + STATEC coordination
- Article 67 Whistleblower Protection Law 16 May 2023 + Sapin II coordination
- No journalism derogation memo
- No employee delegation consultation
- No bioethics for research
- No Whistleblower integration
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.