LIschema gdpri-v2trajectory: not yet assessedregulated (omnibus)overlaps: AIC
Last updated · 10 categories · 42
claims · 16 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
42Claimsbaseline..claims[]
7Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
No red categories; 10 sub-modules are flagged red.
Jurisdiction lead brief
Standing brief, as of 28 September 2026.
Lead Signal
Liechtenstein's Datenschutzstelle (DSS) is participating this cycle as one of 32 European supervisory authorities in the European Data Protection Board's 2025 Coordinated Enforcement Framework examining the practical implementation of the right to erasure under Article 17 GDPR. This places Liechtenstein inside an active, EU/EEA-wide supervisory exercise focused specifically on data subject rights, rather than in a purely domestic or isolated enforcement posture.
Other Developments
The erasure-rights exercise is the principal development for this cycle. The DSS's participation in the Coordinated Enforcement Framework indicates that erasure requests, and the practical mechanics by which controllers in Liechtenstein respond to them, are under heightened supervisory attention this period, consistent with the framework's stated focus on Article 17 implementation across participating authorities.
Cross-Monitor Connections
No cross-monitor routing signal was identified for this development this cycle.
Outlook
The Coordinated Enforcement Framework exercise is ongoing across participating authorities; the results and any consequent guidance or enforcement activity from the DSS specific to erasure-request handling in Liechtenstein would be the next indicator to watch for a shift in this module's posture.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Full GDPR incorporation with a closely-aligned national implementing act and an active, EDPB-integrated supervisory authority; no material derogations identified.
Primary frameworkGDPR (EU) 2016/679 as incorporated into the EEA Agreement, implemented via the Liechtenstein Data Protection Act (DSG) of 4 October 2018 and Data Protection Ordinance (DSV) of 11 December 2018
Traffic-light rationale — GreenFull GDPR incorporation with a closely-aligned national implementing act and an active, EDPB-integrated supervisory authority; no material derogations identified.
Sub-modules (5)
Regulator And AuthorityGreen
The DSS (Kirchstrasse 8, Vaduz) is the sole national supervisory authority, headed by Dr Marie-Louise Gächter, and is a full member of the EDPB with regard to GDPR matters (without voting rights).
Claims (2):
The Datenschutzstelle (DSS), based in Vaduz, is Liechtenstein's national data protection supervisory authority responsible for GDPR enforcement.
The supervisory authorities of the EFTA EEA States, including Liechtenstein, Iceland and Norway, are EDPB members with regard to GDPR-related matters, without voting rights.
Act And InstrumentsGreen
GDPR applies directly via EEA incorporation; the DSG and DSV are the domestic implementing instruments.
Claims (2):
Liechtenstein implemented the GDPR through the Data Protection Act of 4 October 2018 (DSG) and the Data Protection Ordinance of 11 December 2018 (DSV), both effective 9 January 2019.
The EEA Joint Committee adopted Decision No. 154/2018 incorporating the GDPR into the EEA Agreement, making the GDPR directly applicable in Liechtenstein.
Material ScopeGreen
The DSG tracks GDPR material scope with no major derogations, covering legal bases, data subject rights, and transfer rules.
Claims (1):
The DSG does not contain major derogations from the GDPR and details legal bases for processing, data subject rights, and requirements for data transfers, and is closely aligned with the German BDSG.
Territorial ScopeGreen
GDPR Article 3 territorial scope applies as incorporated into the EEA Agreement; no LI-specific narrowing was identified in the sources reviewed.
Consistent with the GDPR model, Liechtenstein does not operate a general prior-registration/notification regime for controllers; accountability is discharged through internal records (ROPA) rather than filings with the DSS.
Liechtenstein's GDPR-aligned regime relies on internal accountability documentation (e.g., records of processing) rather than a general prior-notification/registration duty to the DSS.
Category narrative79 words
Liechtenstein is an EEA-EFTA state that has incorporated the GDPR directly via EEA Joint Committee Decision No. 154/2018, giving the Regulation direct legal effect. The domestic implementing framework is the Data Protection Act (Datenschutzgesetz, DSG) of 4 October 2018 and the Data Protection Ordinance (DSV) of 11 December 2018, both effective 9 January 2019, closely modelled on Germany's BDSG. The Datenschutzstelle (DSS) is the national supervisory authority, an EDPB member (non-voting, as an EFTA-EEA state alongside Iceland and Norway).
Sources and claims (6)
ConfirmedDatenschutzstelle / EDPB — The Datenschutzstelle (DSS), based in Vaduz, is Liechtenstein's national data protection supervisory authority responsible for GDPR enforcement.observed
ConfirmedEDPB — The supervisory authorities of the EFTA EEA States, including Liechtenstein, Iceland and Norway, are EDPB members with regard to GDPR-related matters, without voting rights.observed
ConfirmedDataGuidance — Liechtenstein implemented the GDPR through the Data Protection Act of 4 October 2018 (DSG) and the Data Protection Ordinance of 11 December 2018 (DSV), both effective 9 January 2019.observed
ConfirmedDataGuidance — The EEA Joint Committee adopted Decision No. 154/2018 incorporating the GDPR into the EEA Agreement, making the GDPR directly applicable in Liechtenstein.observed
ConfirmedDataGuidance — The DSG does not contain major derogations from the GDPR and details legal bases for processing, data subject rights, and requirements for data transfers, and is closely aligned with the German BDSG.observed
ProbableDataGuidance — Liechtenstein's GDPR-aligned regime relies on internal accountability documentation (e.g., records of processing) rather than a general prior-notification/registration duty to the DSS.observed
Traffic-light rationale — GreenFull GDPR-aligned lawful-basis and special-category regime; DSS has issued specific guidance filling practical gaps (e.g., incapacitated adults).
Sub-modules (4)
Lawful BasesGreen
GDPR Article 6 lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interests) apply directly; DSS newsletters have discussed legitimate-interest principles in national court rulings.
Claims (1):
Liechtenstein's DSS newsletter summarised recent court rulings on GDPR and DSG covering, among other things, legitimate interest principles.
Consent ThresholdsGreen
The DSS has issued specific guidance on obtaining valid consent for adults incapable of giving consent, applying GDPR consent standards (freely given, informed, revocable) to vulnerable adults.
Claims (1):
The DSS issued guidance on obtaining valid consent for adults incapable of giving consent under GDPR.
Special CategoriesGreen
Article 9/10 GDPR special-category and criminal-data rules apply; DSS DPIA guidance explicitly references Art 9 and Art 10 data in its high-risk processing examples.
Claims (1):
DSS DPIA guidance identifies processing of special categories of data under Article 9 and data referred to in Article 10 GDPR as requiring heightened scrutiny and, in certain circumstances, a mandatory DPIA.
Pseudonymisation And AnonymisationAmber
No LI-specific pseudonymisation/anonymisation guidance beyond the GDPR baseline was identified in the sources reviewed.
Lawful bases, consent standards, and special-category rules follow GDPR Articles 6, 7 and 9 directly as incorporated via the EEA Agreement, with DSS guidance addressing practical application (e.g., consent by adults incapable of consenting).
Sources and claims (3)
ProbableDataGuidance — Liechtenstein's DSS newsletter summarised recent court rulings on GDPR and DSG covering, among other things, legitimate interest principles.observed
ConfirmedDataGuidance — The DSS issued guidance on obtaining valid consent for adults incapable of giving consent under GDPR.observed
ConfirmedDatenschutzstelle / hosted via EDPB — DSS DPIA guidance identifies processing of special categories of data under Article 9 and data referred to in Article 10 GDPR as requiring heightened scrutiny and, in certain circumstances, a mandatory DPIA.observed
Traffic-light rationale — GreenRights regime is fully GDPR-aligned with active DSS interpretive guidance; standard one-month response deadlines apply via direct GDPR incorporation.
Sub-modules (5)
Access RightGreen
DSS has issued guidance on employee email access requests and general subject-access mechanics.
Claims (1):
The DSS has provided guidance on employee email access requests.
Rectification And ErasureGreen
DSS guidance clarifies GDPR obligations for data deletion and erasure, including storage-limitation recommendations.
Claims (1):
DSS guidance clarifies GDPR obligations for data deletion and erasure, emphasizing conditions and storage recommendations.
Restriction And ObjectionGreen
DSS has addressed the right to object in the context of Google Street View image collection, and issued a newsletter on court rulings concerning abusive exercise of data subject rights.
Claims (2):
DSS has discussed Google's Street View image collection and individuals' rights to object under GDPR.
DSS newsletter highlighted court rulings on abusive exercise of data subject rights under GDPR.
Data PortabilityAmber
No LI-specific portability guidance beyond the direct GDPR Article 20 baseline was identified.
Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein data portability guidance Art 20.
Deadlines And Response WindowsGreen
The standard one-month (extendable to three months for complex requests) GDPR response deadline applies directly via EEA incorporation; no LI-specific shortening or lengthening was identified.
Data subject rights (access, rectification, erasure, restriction, objection, portability) follow GDPR Articles 15-22 directly, with the DSS issuing practical guidance on access requests, erasure/deletion, and objection rights (e.g., regarding Google Street View), plus newsletter commentary on abusive exercise of data subject rights.
no periodic updates on record for this sub-brief
Sources and claims (4)
ConfirmedDataGuidance — The DSS has provided guidance on employee email access requests.observed
ConfirmedDataGuidance — DSS guidance clarifies GDPR obligations for data deletion and erasure, emphasizing conditions and storage recommendations.observed
ConfirmedDataGuidance — DSS has discussed Google's Street View image collection and individuals' rights to object under GDPR.observed
ProbableDataGuidance — DSS newsletter highlighted court rulings on abusive exercise of data subject rights under GDPR.observed
Comprehensive GDPR-aligned controller/processor duties with an active, EDPB-coordinated DPIA guidance framework and functioning breach-notification channel.
Primary frameworkGDPR Articles 24-39 as incorporated via EEA Agreement; DSG/DSV
Traffic-light rationale — GreenComprehensive GDPR-aligned controller/processor duties with an active, EDPB-coordinated DPIA guidance framework and functioning breach-notification channel.
Sub-modules (7)
Accountability And DpiaGreen
The DSS's DPIA guidance (Feb 2019) provides a non-exhaustive list of processing operations requiring a DPIA, supplementing the general criteria in Article 35(1) and (3) GDPR and the WP29/EDPB DPIA guidelines.
Claims (2):
The Datenschutzstelle's DPIA guidance identifies types of processing (e.g., large-scale evaluation of authority-collected data forwarded to law enforcement, or processing of children's/vulnerable individuals' data for marketing, profiling or automated decision-making) as requiring a DPIA even where not otherwise 'extensive' within Article 35(3)(b) GDPR.
Generally, any form of processing bearing a high risk to the rights and freedoms of individuals because of its nature, scope, circumstances and purpose, particularly when using new technologies, requires a prior DPIA under the DSS framework.
Dpo RequirementsGreen
DPO appointment thresholds follow GDPR Articles 37-39; a DSS newsletter reported a national court ruling concerning DPO dismissal protections.
Claims (1):
A DSS newsletter summarised recent national court rulings on GDPR and DSG covering DPO dismissal, health data handling, and legitimate interest principles.
Ropa RequirementsAmber
Records of processing activities obligations follow GDPR Article 30 directly; no LI-specific ROPA template or additional obligation beyond the GDPR baseline was identified.
Joint-controller obligations follow GDPR Article 26 directly; DSS guidance on company-sale scenarios discusses controller responsibilities during share/asset deals but not joint-controller arrangements specifically.
Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein gemeinsame Verantwortliche Art 26.
Security MeasuresGreen
Technical and organisational security-of-processing obligations follow GDPR Article 32 directly via EEA incorporation.
Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Sicherheitsmassnahmen Art 32.
Breach NotificationGreen
The DSS accepts breach notifications in German or English, consistent with the GDPR Article 33/34 72-hour regulator-notification and high-risk subject-communication framework.
Claims (1):
Liechtenstein's Data Protection Authority accepts data breach notifications in German or English.
Retention And DisposalGreen
DSS guidance addresses storage-limitation and deletion/erasure recommendations, and separately clarifies that data protection obligations end with death (other laws govern deceased persons' data).
Claims (1):
Liechtenstein's data protection regime ends with death, with other (non-DP) laws governing the handling of deceased persons' data.
Category narrative56 words
Accountability, DPIA, DPO, ROPA, security, breach-notification and retention duties follow GDPR Articles 24-39 directly via EEA incorporation. The DSS has published a detailed DPIA 'blacklist' (high-risk processing list) since February 2019, and its breach-notification channel accepts submissions in German or English. National court rulings reported via DSS newsletters have addressed DPO dismissal protections and health-data handling.
Sources and claims (5)
ConfirmedDatenschutzstelle / hosted via EDPB — The Datenschutzstelle's DPIA guidance identifies types of processing (e.g., large-scale evaluation of authority-collected data forwarded to law enforcement, or processing of children's/vulnerable individuals' data for marketing, profiling or automated decision-making) as requiring a DPIA even where not otherwise 'extensive' within Article 35(3)(b) GDPR.observed
ConfirmedDatenschutzstelle / hosted via EDPB — Generally, any form of processing bearing a high risk to the rights and freedoms of individuals because of its nature, scope, circumstances and purpose, particularly when using new technologies, requires a prior DPIA under the DSS framework.observed
ProbableDataGuidance — A DSS newsletter summarised recent national court rulings on GDPR and DSG covering DPO dismissal, health data handling, and legitimate interest principles.observed
ConfirmedEDPB — Liechtenstein's Data Protection Authority accepts data breach notifications in German or English.observed
ProbableDataGuidance — Liechtenstein's data protection regime ends with death, with other (non-DP) laws governing the handling of deceased persons' data.observed
Full GDPR Chapter V transfer regime applies via EEA incorporation, with active DSS transfer guidance and enforcement notices, plus recognition as a qualifying state under the EU-U.S. DPF.
Primary frameworkGDPR Articles 44-49 as incorporated via EEA Agreement
Traffic-light rationale — GreenFull GDPR Chapter V transfer regime applies via EEA incorporation, with active DSS transfer guidance and enforcement notices, plus recognition as a qualifying state under the EU-U.S. DPF.
Sub-modules (6)
Transfer MechanismsGreen
GDPR Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Article 49 derogations) apply directly; DSS has published guidance on international data transfers and adequacy.
Claims (1):
The DSS has published guidance on international data transfers and adequacy applicable in Liechtenstein.
Adequacy ReceivedGreen
Liechtenstein, alongside all EEA member states, is designated a 'qualifying state' under the EU-U.S. Data Privacy Framework, giving its residents access to enhanced US privacy protections and the Data Protection Review Court.
Claims (1):
Under the EU-U.S. Data Privacy Framework, EU member states along with Iceland, Liechtenstein and Norway are designated 'qualifying states', whose citizens can seek redress through the U.S. Data Protection Review Court.
Adequacy GrantedGreen
The UK's EU adequacy decisions (GDPR and LED) apply to personal data transferred from the whole EEA, including Liechtenstein, to the UK without additional safeguards.
Claims (1):
The UK's EU adequacy decisions apply to personal data transferred from all EEA countries, defined to include Iceland, Liechtenstein and Norway, allowing flows to the UK without additional safeguards.
Sccs And BcrsGreen
SCCs and BCRs operate as under the GDPR baseline; the EDPB has issued Article 64 opinions on BCRs involving Liechtenstein members, indicating active BCR coordination through the DSS.
Claims (1):
The EDPB has adopted Article 64 opinions on Binding Corporate Rules with Liechtenstein as a concerned member state, indicating active national BCR coordination.
Transfer Impact AssessmentAmber
Post-Schrems II transfer impact assessment practice applies via the GDPR baseline; DSS has issued guidance addressing international transfers and third-country adequacy assessment, including flagging TikTok's transfers as unlawful.
Claims (1):
The DSS issued a notice on TikTok's unlawful data transfers to third countries, recommending organizations assess transfer risks and inform users.
Data LocalisationGreen
No general data-localisation mandate was identified in the DSG/DSV; Liechtenstein follows the GDPR's free-flow-within-EEA model, subject to sector-specific police/judicial cooperation instruments (e.g., biometric/dactyloscopic data-sharing with the EU).
Claims (1):
Personal data relating to dactyloscopic (fingerprint) data may be supplied by EU Member States to Switzerland and Liechtenstein from 1 July 2026 under a dedicated Council Implementing Decision, reflecting sector-specific (law-enforcement) cross-border data-sharing arrangements rather than general data localisation.
Category narrative92 words
As an EEA-EFTA state, Liechtenstein benefits from and applies the GDPR's transfer regime (adequacy decisions, SCCs, BCRs, derogations) directly. It is treated as part of the EEA for the purposes of third-country adequacy decisions (e.g., the UK's EU adequacy decisions apply to transfers from the whole EEA including Liechtenstein), and Liechtenstein is listed as a 'qualifying state' under the EU-U.S. Data Privacy Framework, giving its residents access to the U.S. Data Protection Review Court redress mechanism. The DSS has issued guidance on international transfers and warned of unlawful third-country transfers (e.g., TikTok).
Sources and claims (6)
ConfirmedDataGuidance — The DSS has published guidance on international data transfers and adequacy applicable in Liechtenstein.observed
ConfirmedIAPP — Under the EU-U.S. Data Privacy Framework, EU member states along with Iceland, Liechtenstein and Norway are designated 'qualifying states', whose citizens can seek redress through the U.S. Data Protection Review Court.observed
ConfirmedICO — The UK's EU adequacy decisions apply to personal data transferred from all EEA countries, defined to include Iceland, Liechtenstein and Norway, allowing flows to the UK without additional safeguards.observed
ConfirmedDatenschutzstelle / EDPB — The EDPB has adopted Article 64 opinions on Binding Corporate Rules with Liechtenstein as a concerned member state, indicating active national BCR coordination.observed
ConfirmedDataGuidance — The DSS issued a notice on TikTok's unlawful data transfers to third countries, recommending organizations assess transfer risks and inform users.observed
ConfirmedEUR-Lex / Official Journal of the EU — Personal data relating to dactyloscopic (fingerprint) data may be supplied by EU Member States to Switzerland and Liechtenstein from 1 July 2026 under a dedicated Council Implementing Decision, reflecting sector-specific (law-enforcement) cross-border data-sharing arrangements rather than general data localisation.observed
Financial, health, telecoms/cookie and employment overlays are evidenced via DSS guidance/reports; credit-scoring, education, and insurance sub-modules lack dedicated LI sources.
Primary frameworkGDPR as incorporated via EEA Agreement, overlaid with sector-specific Liechtenstein financial-market and other sectoral rules
Traffic-light rationale — AmberFinancial, health, telecoms/cookie and employment overlays are evidenced via DSS guidance/reports; credit-scoring, education, and insurance sub-modules lack dedicated LI sources.
Sub-modules (7)
Financial Sector OverlayAmber
DataGuidance maintains a dedicated opinion piece on data protection in Liechtenstein's financial sector, reflecting the interaction between GDPR and the jurisdiction's banking/trust industry oversight (Finanzmarktaufsicht, FMA).
Claims (1):
DataGuidance publishes a dedicated analysis of data protection in Liechtenstein's financial sector, reflecting the interplay between GDPR/DSG and financial-market regulation in the jurisdiction.
Health Sector OverlayGreen
DSS newsletters reference national court rulings covering health data handling under GDPR/DSG.
Claims (1):
A DSS newsletter summarising recent court rulings on GDPR and DSG covered health data handling among other topics.
Telecoms And EprivacyGreen
DSS updated cookie guidance clarifying consent requirements and conditions for relying on legitimate interest for cookies/trackers.
Claims (1):
DSS updated guidance on cookies clarifies consent requirements and the conditions under which legitimate interest may be used for cookie-based tracking.
Employment DataGreen
The DSS's 2024 annual report highlighted inquiries covering employment data alongside AI data processing and video surveillance.
Claims (1):
The DSS's 2024 report highlights inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures.
Credit And ScoringRed
No LI-specific credit-scoring guidance or rules were identified in the sources reviewed.
Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Kredit Scoring, Liechtenstein credit scoring data protection.
EducationRed
No LI-specific education-sector data protection guidance was identified beyond a general reference to social-media age-restriction guidance.
Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Schule Bildung Datenschutz.
InsuranceRed
No LI-specific insurance-sector data protection guidance was identified in the sources reviewed.
Liechtenstein's financial-sector data processing (a core feature of its economy as a private-banking/trust hub) interacts with GDPR through DSS-published sector guidance; other sector overlays (health, telecoms/eprivacy for cookies, employment) are addressed via DSS newsletters and reports, while credit-scoring, education, and insurance-specific overlays were not separately evidenced in the sources reviewed.
Sources and claims (4)
UncertainDataGuidance — DataGuidance publishes a dedicated analysis of data protection in Liechtenstein's financial sector, reflecting the interplay between GDPR/DSG and financial-market regulation in the jurisdiction.observed
ProbableDataGuidance — A DSS newsletter summarising recent court rulings on GDPR and DSG covered health data handling among other topics.observed
ConfirmedDataGuidance — DSS updated guidance on cookies clarifies consent requirements and the conditions under which legitimate interest may be used for cookie-based tracking.observed
ConfirmedDataGuidance — The DSS's 2024 report highlights inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures.observed
Cookie/tracker consent is actively covered by DSS guidance; several other sub-modules (dark patterns, opt-out signals, clean rooms, cross-context advertising, direct marketing specifics) lack dedicated LI sources and rely on the GDPR/ePrivacy baseline.
Primary frameworkGDPR + EU ePrivacy Directive as applied in Liechtenstein via EEA incorporation
Traffic-light rationale — AmberCookie/tracker consent is actively covered by DSS guidance; several other sub-modules (dark patterns, opt-out signals, clean rooms, cross-context advertising, direct marketing specifics) lack dedicated LI sources and rely on the GDPR/ePrivacy baseline.
Sub-modules (6)
Cookies And TrackersGreen
DSS updated cookie guidance clarifies consent requirements and legitimate-interest conditions, applying European case law on cookies in Liechtenstein.
Claims (1):
The DSS has published guidance on international data transfers and adequacy, and on the application of European case law concerning cookies in Liechtenstein.
Dark PatternsRed
No LI-specific dark-pattern guidance was identified in the sources reviewed.
Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein dark patterns manipulative design.
Opt Out SignalsRed
No LI-specific Global Privacy Control / opt-out-signal guidance was identified in the sources reviewed.
Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Global Privacy Control opt-out signal.
Clean Rooms And DcrRed
No LI-specific clean-room/data-collaboration-room guidance was identified in the sources reviewed.
Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein data clean room.
Cross Context AdvertisingAmber
No LI-specific 'sale'/'share' cross-context-advertising framework (a US state-law concept) was identified; the GDPR consent/legitimate-interest baseline governs behavioural advertising instead.
Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein cross-context advertising sale share.
Direct MarketingAmber
Direct marketing is governed by the GDPR Article 21(2) unconditional right to object baseline as incorporated via the EEA Agreement; no LI-specific suppression-list regime was identified.
Cookie/tracker consent follows the ePrivacy/GDPR baseline as applied by the DSS, which has issued updated cookie guidance. Dark-pattern prohibitions, opt-out signals (e.g., GPC), clean-room arrangements, and cross-context advertising rules specific to Liechtenstein were not separately evidenced; direct marketing follows the GDPR Article 21(2) right to object baseline.
Sources and claims (1)
ConfirmedDataGuidance — The DSS has published guidance on international data transfers and adequacy, and on the application of European case law concerning cookies in Liechtenstein.observed
Profiling/ADM and AI-risk sub-modules are well evidenced via active DSS guidance; biometric, genetic-data, and state-surveillance sub-modules rely more heavily on the general GDPR baseline.
Primary frameworkGDPR Article 22 and Articles 9-10 as incorporated via EEA Agreement
Traffic-light rationale — AmberProfiling/ADM and AI-risk sub-modules are well evidenced via active DSS guidance; biometric, genetic-data, and state-surveillance sub-modules rely more heavily on the general GDPR baseline.
Sub-modules (6)
Profiling RestrictionsGreen
DSS DPIA guidance flags profiling for automated decision-making, particularly involving children or vulnerable individuals, as requiring a DPIA even outside 'extensive' processing.
Claims (1):
DSS DPIA guidance identifies processing of children's or other vulnerable individuals' data for marketing or profiling for automated decision-making as requiring a DPIA even where not 'extensive' under Article 35(3)(b) GDPR.
Automated Decision Making TransparencyGreen
Article 22 GDPR ADM transparency/explanation rights apply directly via EEA incorporation; DSS DPIA guidance references auto-decision-making as a high-risk trigger.
Claims (1):
The DSS's DPIA blacklist references automated decision-making as a high-risk processing trigger requiring assessment consistent with Article 22 and Article 35 GDPR.
Ai Risk AssessmentsAmber
The DSS has actively engaged with AI-specific risks: warning against DeepSeek R1 on privacy grounds, providing guidance on using AI systems/chatbots with personal data, and announcing Meta's plan to use public EU user data for AI training with an objection deadline.
Claims (2):
The DSS warned of data protection risks associated with the AI service DeepSeek R1 and advised the use of GDPR-compliant tools.
The DSS announced Meta's plan to use public data from European users for AI training and provided a window for objections until 26 May 2025.
Biometric RegimeAmber
DSS has updated guidance on video surveillance limitations; dedicated facial-recognition/biometric-specific rules beyond the GDPR Art 9 special-category baseline were not separately evidenced, though cross-border dactyloscopic data-sharing with the EU is now permitted from mid-2026.
Claims (1):
The DSS updated its guidance on video surveillance, addressing limitations on the practice.
Genetic DataAmber
Genetic data is treated as a special category under GDPR Article 9 as incorporated via the EEA Agreement; no LI-specific genetic-data guidance was identified.
Profiling and ADM transparency follow GDPR Article 22 directly, reinforced by DSS DPIA guidance flagging profiling/automated decision-making (including for marketing purposes) as high-risk processing. The DSS has actively addressed AI-specific risks (DeepSeek R1 warnings, Meta AI-training objection notice, chatbot guidance) and video-surveillance/biometric-adjacent processing, but no dedicated genetic-data regime or state-surveillance carve-out analysis specific to Liechtenstein was identified.
Sources and claims (5)
ConfirmedDatenschutzstelle / hosted via EDPB — DSS DPIA guidance identifies processing of children's or other vulnerable individuals' data for marketing or profiling for automated decision-making as requiring a DPIA even where not 'extensive' under Article 35(3)(b) GDPR.observed
ConfirmedDatenschutzstelle / hosted via EDPB — The DSS's DPIA blacklist references automated decision-making as a high-risk processing trigger requiring assessment consistent with Article 22 and Article 35 GDPR.observed
ConfirmedDataGuidance — The DSS warned of data protection risks associated with the AI service DeepSeek R1 and advised the use of GDPR-compliant tools.observed
ConfirmedDataGuidance — The DSS announced Meta's plan to use public data from European users for AI training and provided a window for objections until 26 May 2025.observed
ConfirmedDataGuidance — The DSS updated its guidance on video surveillance, addressing limitations on the practice.observed
Age-verification, minor-profiling and dependent-adult sub-modules are evidenced via active DSS guidance; parental-consent-age specifics and education-settings rules rely on the unlocalised GDPR Article 8 baseline.
Primary frameworkGDPR Article 8 as incorporated via EEA Agreement; DSG
Traffic-light rationale — AmberAge-verification, minor-profiling and dependent-adult sub-modules are evidenced via active DSS guidance; parental-consent-age specifics and education-settings rules rely on the unlocalised GDPR Article 8 baseline.
Sub-modules (5)
Age VerificationGreen
DSS has provided GDPR compliance guidance addressing social media age restrictions.
Claims (1):
The DSS provides GDPR compliance guidance on data access and social media age restrictions.
Parental ConsentAmber
GDPR Article 8 sets a default digital-consent age of 16, with member/EEA states able to lower it to as low as 13; no LI-specific statutory age lower than the GDPR default was identified in the sources reviewed.
Absence provenance: unavailable. Searched: Liechtenstein DSG Art 8 GDPR age of consent children digital services.
Minor Profiling BansGreen
DSS DPIA guidance treats profiling of children or other vulnerable individuals for marketing or automated decision-making as a DPIA-triggering high-risk activity, functioning as a de facto heightened-scrutiny regime rather than an outright ban.
Claims (1):
Processing of personal data of children or other vulnerable individuals for marketing, profiling for automated decision-making, or the offer of online services requires a DPIA under DSS guidance even where not 'extensive' under Article 35(3)(b) GDPR.
Education SettingsRed
No LI-specific education-settings data protection guidance was identified beyond the general age-restriction guidance.
Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Schule Datenschutz Bildungseinrichtung.
Dependent AdultsGreen
DSS issued specific guidance on obtaining valid consent for adults incapable of giving consent under GDPR, addressing dependent/vulnerable adult protections.
Claims (1):
The DSS issued guidance on obtaining valid consent for adults incapable of giving consent under GDPR.
Category narrative51 words
Children's data processing follows GDPR Article 8 as incorporated via the EEA Agreement; the DSS has issued guidance on social-media age restrictions and flagged minors'/vulnerable individuals' profiling as a DPIA trigger. Vulnerable-adult protections are addressed through DSS guidance on consent by adults incapable of consenting. Education-settings-specific rules were not separately evidenced.
Sources and claims (3)
ConfirmedDataGuidance — The DSS provides GDPR compliance guidance on data access and social media age restrictions.observed
ConfirmedDatenschutzstelle / hosted via EDPB — Processing of personal data of children or other vulnerable individuals for marketing, profiling for automated decision-making, or the offer of online services requires a DPIA under DSS guidance even where not 'extensive' under Article 35(3)(b) GDPR.observed
ConfirmedDataGuidance — The DSS issued guidance on obtaining valid consent for adults incapable of giving consent under GDPR.observed
Enforcement powers and recent developments are well evidenced; specific collective-redress/private-right-of-action mechanics and regulator funding/headcount data for Liechtenstein were not separately sourced.
Primary frameworkGDPR Articles 58, 77-84 as incorporated via EEA Agreement; DSG
Traffic-light rationale — AmberEnforcement powers and recent developments are well evidenced; specific collective-redress/private-right-of-action mechanics and regulator funding/headcount data for Liechtenstein were not separately sourced.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The DSS has GDPR Article 58 corrective powers (investigation, warnings, orders, bans) and Article 83 administrative-fine powers, applied via direct EEA incorporation of the GDPR.
Claims (1):
Each GDPR supervisory authority, including the DSS as incorporated via the EEA Agreement, has corrective powers under Article 58(2) including the power to impose administrative fines under Article 83.
Enforcement Activity IndexAmber
The DSS's 2024 report highlighted inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures; the 2023 report covered GDPR compliance, AI services, video surveillance, and data protection breaches.
Claims (2):
The DSS's 2024 report highlights inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures.
Liechtenstein's DSS 2023 report covers inquiries on GDPR compliance, AI services, video surveillance, and data protection breaches.
Regulator Funding And CapacityRed
No specific funding or headcount data for the DSS was identified in the sources reviewed.
Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Budget Personal Kapazität.
Collective Redress And Class ActionsRed
No Liechtenstein-specific collective-redress or class-action mechanism for data protection claims was identified; the EU Representative Actions Directive is an EU-only instrument and its applicability to the EEA-EFTA state was not confirmed in sources reviewed.
Absence provenance: unavailable. Searched: Liechtenstein collective redress class action data protection, Representative Actions Directive Liechtenstein EEA.
Private Right Of ActionGreen
GDPR Articles 79-82 (judicial remedy against controllers/processors and compensation) apply directly via EEA incorporation; individuals may also lodge complaints with the DSS or national courts.
Claims (1):
An individual has the right to lodge a complaint with a data protection authority of an EEA Member State, which includes the EU countries plus Iceland, Liechtenstein and Norway.
Recent Developments 180DGreen
Within the last 180 days: the DSS issued a notice (reported 9 January 2026) on TikTok's unlawful data transfers to third countries; the May 2026 IAPP Global Summit update confirmed Liechtenstein's continued 'qualifying state' status under the EU-U.S. Data Privacy Framework; and a Council Implementing Decision of 25 June 2026 (2026/1459) set 1 July 2026 as the date from which EU Member States may supply dactyloscopic data to Switzerland and Liechtenstein.
Claims (3):
The DSS issued a notice on TikTok's unlawful transfer of personal data to third countries, recommending organizations assess risks and inform users.
At the IAPP Global Summit 2026, US and EU officials provided an update on the status of the EU-U.S. Data Privacy Framework, under which Liechtenstein remains a designated qualifying state.
Council Implementing Decision (EU) 2026/1459 of 25 June 2026 set 1 July 2026 as the date from which personal data relating to dactyloscopic data may be supplied by EU Member States to Switzerland and Liechtenstein.
Category narrative102 words
The DSS holds full GDPR Article 58 investigative and corrective powers, including the Article 83 administrative-fine framework (up to the higher of a fixed sum or a percentage of worldwide turnover), applied directly via EEA incorporation. The DSS's 2024 annual report recorded no fines imposed despite several formal measures, following a 2023 report covering GDPR compliance inquiries, AI, video surveillance and breach matters. Recent developments include a January 2026 DSS notice on TikTok's unlawful third-country transfers, the May 2026 EU-US adequacy update confirming Liechtenstein's 'qualifying state' status, and a June 2026 Council Implementing Decision extending dactyloscopic data-sharing to Liechtenstein from July 2026.
Sources and claims (7)
ConfirmedEUR-Lex / CJEU — Each GDPR supervisory authority, including the DSS as incorporated via the EEA Agreement, has corrective powers under Article 58(2) including the power to impose administrative fines under Article 83.observed
ConfirmedDataGuidance — The DSS's 2024 report highlights inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures.observed
ConfirmedDataGuidance — Liechtenstein's DSS 2023 report covers inquiries on GDPR compliance, AI services, video surveillance, and data protection breaches.observed
ConfirmedEDPB — An individual has the right to lodge a complaint with a data protection authority of an EEA Member State, which includes the EU countries plus Iceland, Liechtenstein and Norway.observed
ConfirmedDataGuidance — The DSS issued a notice on TikTok's unlawful transfer of personal data to third countries, recommending organizations assess risks and inform users.observed
ConfirmedIAPP — At the IAPP Global Summit 2026, US and EU officials provided an update on the status of the EU-U.S. Data Privacy Framework, under which Liechtenstein remains a designated qualifying state.observed
ConfirmedEUR-Lex / Official Journal of the EU — Council Implementing Decision (EU) 2026/1459 of 25 June 2026 set 1 July 2026 as the date from which personal data relating to dactyloscopic data may be supplied by EU Member States to Switzerland and Liechtenstein.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
pass
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
66.67
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Liechtenstein
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 42 claim(s) (44 category placement(s)), 16 source(s) in the cumulative register.
regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, cross_border_and_adequacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress achieved substantive T1/T2/T3 coverage anchored on the DSS's own DPIA guidance (T1), EDPB member/documentation pages (T1/T2), EUR-Lex instruments (T1), and DataGuidance secondary reporting (T3). sectoral_watch achieved partial coverage (financial, health, telecoms/cookies, employment evidenced; credit-scoring, education, insurance carry explicit absent_field_provenance). adtech_and_commercial_privacy achieved coverage only on cookies_and_trackers; dark_patterns, opt_out_signals, clean_rooms_and_dcr, cross_context_advertising and direct_marketing carry explicit absent_field_provenance reflecting reliance on the unlocalised GDPR/ePrivacy baseline rather than dedicated LI sources.
Unresolved questions (4):
Does the Liechtenstein DSG set a national digital age-of-consent below the GDPR Article 8 default of 16 (as several EU/EEA states have done, e.g., 13-15)?
Does Liechtenstein operate any collective-redress or representative-action mechanism analogous to the EU Representative Actions Directive for data protection claims, given its EEA-EFTA (non-EU) status?
Are there DSS-published funding/headcount figures establishing regulator capacity comparable to EU Member State DPA annual reports?
Is there a Liechtenstein-specific credit-scoring, education-sector, or insurance-sector data protection overlay beyond the general GDPR baseline?