🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
LI v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing13 sources retrieved model claude-sonnet-5 · 2026-08-05

Liechtenstein

LI schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 42 claims · 16 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
42Claimsbaseline..claims[]
7Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 10 sub-modules are flagged red.

Jurisdiction lead brief

Standing brief, as of 28 September 2026.

Lead Signal

Liechtenstein's Datenschutzstelle (DSS) is participating this cycle as one of 32 European supervisory authorities in the European Data Protection Board's 2025 Coordinated Enforcement Framework examining the practical implementation of the right to erasure under Article 17 GDPR. This places Liechtenstein inside an active, EU/EEA-wide supervisory exercise focused specifically on data subject rights, rather than in a purely domestic or isolated enforcement posture.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Full GDPR incorporation with a closely-aligned national implementing act and an active, EDPB-integrated supervisory authority; no material derogations identified.

Primary frameworkGDPR (EU) 2016/679 as incorporated into the EEA Agreement, implemented via the Liechtenstein Data Protection Act (DSG) of 4 October 2018 and Data Protection Ordinance (DSV) of 11 December 2018
Traffic-light rationale — GreenFull GDPR incorporation with a closely-aligned national implementing act and an active, EDPB-integrated supervisory authority; no material derogations identified.

Sub-modules (5)

Regulator And AuthorityGreen

The DSS (Kirchstrasse 8, Vaduz) is the sole national supervisory authority, headed by Dr Marie-Louise Gächter, and is a full member of the EDPB with regard to GDPR matters (without voting rights).

Claims (2):

  • The Datenschutzstelle (DSS), based in Vaduz, is Liechtenstein's national data protection supervisory authority responsible for GDPR enforcement.
  • The supervisory authorities of the EFTA EEA States, including Liechtenstein, Iceland and Norway, are EDPB members with regard to GDPR-related matters, without voting rights.

Act And InstrumentsGreen

GDPR applies directly via EEA incorporation; the DSG and DSV are the domestic implementing instruments.

Claims (2):

  • Liechtenstein implemented the GDPR through the Data Protection Act of 4 October 2018 (DSG) and the Data Protection Ordinance of 11 December 2018 (DSV), both effective 9 January 2019.
  • The EEA Joint Committee adopted Decision No. 154/2018 incorporating the GDPR into the EEA Agreement, making the GDPR directly applicable in Liechtenstein.

Material ScopeGreen

The DSG tracks GDPR material scope with no major derogations, covering legal bases, data subject rights, and transfer rules.

Claims (1):

  • The DSG does not contain major derogations from the GDPR and details legal bases for processing, data subject rights, and requirements for data transfers, and is closely aligned with the German BDSG.

Territorial ScopeGreen

GDPR Article 3 territorial scope applies as incorporated into the EEA Agreement; no LI-specific narrowing was identified in the sources reviewed.

Absence provenance: unavailable. Searched: Liechtenstein DSG territorial scope non-established controllers, DataGuidance Liechtenstein jurisdiction overview.

Regulator Registration And FilingAmber

Consistent with the GDPR model, Liechtenstein does not operate a general prior-registration/notification regime for controllers; accountability is discharged through internal records (ROPA) rather than filings with the DSS.

Absence provenance: unavailable. Searched: Liechtenstein DSG registration filing controllers, Datenschutzstelle Meldepflicht.

Claims (1):

  • Liechtenstein's GDPR-aligned regime relies on internal accountability documentation (e.g., records of processing) rather than a general prior-notification/registration duty to the DSS.
Category narrative79 words

Liechtenstein is an EEA-EFTA state that has incorporated the GDPR directly via EEA Joint Committee Decision No. 154/2018, giving the Regulation direct legal effect. The domestic implementing framework is the Data Protection Act (Datenschutzgesetz, DSG) of 4 October 2018 and the Data Protection Ordinance (DSV) of 11 December 2018, both effective 9 January 2019, closely modelled on Germany's BDSG. The Datenschutzstelle (DSS) is the national supervisory authority, an EDPB member (non-voting, as an EFTA-EEA state alongside Iceland and Norway).

Sources and claims (6)
  1. ConfirmedDatenschutzstelle / EDPB — The Datenschutzstelle (DSS), based in Vaduz, is Liechtenstein's national data protection supervisory authority responsible for GDPR enforcement.observed
  2. ConfirmedEDPB — The supervisory authorities of the EFTA EEA States, including Liechtenstein, Iceland and Norway, are EDPB members with regard to GDPR-related matters, without voting rights.observed
  3. ConfirmedDataGuidance — Liechtenstein implemented the GDPR through the Data Protection Act of 4 October 2018 (DSG) and the Data Protection Ordinance of 11 December 2018 (DSV), both effective 9 January 2019.observed
  4. ConfirmedDataGuidance — The EEA Joint Committee adopted Decision No. 154/2018 incorporating the GDPR into the EEA Agreement, making the GDPR directly applicable in Liechtenstein.observed
  5. ConfirmedDataGuidance — The DSG does not contain major derogations from the GDPR and details legal bases for processing, data subject rights, and requirements for data transfers, and is closely aligned with the German BDSG.observed
  6. ProbableDataGuidance — Liechtenstein's GDPR-aligned regime relies on internal accountability documentation (e.g., records of processing) rather than a general prior-notification/registration duty to the DSS.observed

#

Full GDPR-aligned lawful-basis and special-category regime; DSS has issued specific guidance filling practical gaps (e.g., incapacitated adults).

Primary frameworkGDPR Articles 6, 7, 9 as incorporated via EEA Agreement; DSG
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — GreenFull GDPR-aligned lawful-basis and special-category regime; DSS has issued specific guidance filling practical gaps (e.g., incapacitated adults).

Sub-modules (4)

Lawful BasesGreen

GDPR Article 6 lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interests) apply directly; DSS newsletters have discussed legitimate-interest principles in national court rulings.

Claims (1):

  • Liechtenstein's DSS newsletter summarised recent court rulings on GDPR and DSG covering, among other things, legitimate interest principles.

Special CategoriesGreen

Article 9/10 GDPR special-category and criminal-data rules apply; DSS DPIA guidance explicitly references Art 9 and Art 10 data in its high-risk processing examples.

Claims (1):

  • DSS DPIA guidance identifies processing of special categories of data under Article 9 and data referred to in Article 10 GDPR as requiring heightened scrutiny and, in certain circumstances, a mandatory DPIA.

Pseudonymisation And AnonymisationAmber

No LI-specific pseudonymisation/anonymisation guidance beyond the GDPR baseline was identified in the sources reviewed.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Pseudonymisierung Anonymisierung guidance.

Category narrative34 words

Lawful bases, consent standards, and special-category rules follow GDPR Articles 6, 7 and 9 directly as incorporated via the EEA Agreement, with DSS guidance addressing practical application (e.g., consent by adults incapable of consenting).

Sources and claims (3)
  1. ProbableDataGuidance — Liechtenstein's DSS newsletter summarised recent court rulings on GDPR and DSG covering, among other things, legitimate interest principles.observed
  2. ConfirmedDataGuidance — The DSS issued guidance on obtaining valid consent for adults incapable of giving consent under GDPR.observed
  3. ConfirmedDatenschutzstelle / hosted via EDPB — DSS DPIA guidance identifies processing of special categories of data under Article 9 and data referred to in Article 10 GDPR as requiring heightened scrutiny and, in certain circumstances, a mandatory DPIA.observed

#

Rights regime is fully GDPR-aligned with active DSS interpretive guidance; standard one-month response deadlines apply via direct GDPR incorporation.

Primary frameworkGDPR Articles 12-23 as incorporated via EEA Agreement; DSG
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — GreenRights regime is fully GDPR-aligned with active DSS interpretive guidance; standard one-month response deadlines apply via direct GDPR incorporation.

Sub-modules (5)

Access RightGreen

DSS has issued guidance on employee email access requests and general subject-access mechanics.

Claims (1):

  • The DSS has provided guidance on employee email access requests.

Rectification And ErasureGreen

DSS guidance clarifies GDPR obligations for data deletion and erasure, including storage-limitation recommendations.

Claims (1):

  • DSS guidance clarifies GDPR obligations for data deletion and erasure, emphasizing conditions and storage recommendations.

Restriction And ObjectionGreen

DSS has addressed the right to object in the context of Google Street View image collection, and issued a newsletter on court rulings concerning abusive exercise of data subject rights.

Claims (2):

  • DSS has discussed Google's Street View image collection and individuals' rights to object under GDPR.
  • DSS newsletter highlighted court rulings on abusive exercise of data subject rights under GDPR.

Data PortabilityAmber

No LI-specific portability guidance beyond the direct GDPR Article 20 baseline was identified.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein data portability guidance Art 20.

Deadlines And Response WindowsGreen

The standard one-month (extendable to three months for complex requests) GDPR response deadline applies directly via EEA incorporation; no LI-specific shortening or lengthening was identified.

Absence provenance: unavailable. Searched: Liechtenstein DSG response deadline data subject request.

Category narrative42 words

Data subject rights (access, rectification, erasure, restriction, objection, portability) follow GDPR Articles 15-22 directly, with the DSS issuing practical guidance on access requests, erasure/deletion, and objection rights (e.g., regarding Google Street View), plus newsletter commentary on abusive exercise of data subject rights.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedDataGuidance — The DSS has provided guidance on employee email access requests.observed
  2. ConfirmedDataGuidance — DSS guidance clarifies GDPR obligations for data deletion and erasure, emphasizing conditions and storage recommendations.observed
  3. ConfirmedDataGuidance — DSS has discussed Google's Street View image collection and individuals' rights to object under GDPR.observed
  4. ProbableDataGuidance — DSS newsletter highlighted court rulings on abusive exercise of data subject rights under GDPR.observed

#

Comprehensive GDPR-aligned controller/processor duties with an active, EDPB-coordinated DPIA guidance framework and functioning breach-notification channel.

Primary frameworkGDPR Articles 24-39 as incorporated via EEA Agreement; DSG/DSV
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — GreenComprehensive GDPR-aligned controller/processor duties with an active, EDPB-coordinated DPIA guidance framework and functioning breach-notification channel.

Sub-modules (7)

Accountability And DpiaGreen

The DSS's DPIA guidance (Feb 2019) provides a non-exhaustive list of processing operations requiring a DPIA, supplementing the general criteria in Article 35(1) and (3) GDPR and the WP29/EDPB DPIA guidelines.

Claims (2):

  • The Datenschutzstelle's DPIA guidance identifies types of processing (e.g., large-scale evaluation of authority-collected data forwarded to law enforcement, or processing of children's/vulnerable individuals' data for marketing, profiling or automated decision-making) as requiring a DPIA even where not otherwise 'extensive' within Article 35(3)(b) GDPR.
  • Generally, any form of processing bearing a high risk to the rights and freedoms of individuals because of its nature, scope, circumstances and purpose, particularly when using new technologies, requires a prior DPIA under the DSS framework.

Dpo RequirementsGreen

DPO appointment thresholds follow GDPR Articles 37-39; a DSS newsletter reported a national court ruling concerning DPO dismissal protections.

Claims (1):

  • A DSS newsletter summarised recent national court rulings on GDPR and DSG covering DPO dismissal, health data handling, and legitimate interest principles.

Ropa RequirementsAmber

Records of processing activities obligations follow GDPR Article 30 directly; no LI-specific ROPA template or additional obligation beyond the GDPR baseline was identified.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Verzeichnis Verarbeitungstätigkeiten ROPA template.

Joint Controller ArrangementsAmber

Joint-controller obligations follow GDPR Article 26 directly; DSS guidance on company-sale scenarios discusses controller responsibilities during share/asset deals but not joint-controller arrangements specifically.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein gemeinsame Verantwortliche Art 26.

Security MeasuresGreen

Technical and organisational security-of-processing obligations follow GDPR Article 32 directly via EEA incorporation.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Sicherheitsmassnahmen Art 32.

Breach NotificationGreen

The DSS accepts breach notifications in German or English, consistent with the GDPR Article 33/34 72-hour regulator-notification and high-risk subject-communication framework.

Claims (1):

  • Liechtenstein's Data Protection Authority accepts data breach notifications in German or English.

Retention And DisposalGreen

DSS guidance addresses storage-limitation and deletion/erasure recommendations, and separately clarifies that data protection obligations end with death (other laws govern deceased persons' data).

Claims (1):

  • Liechtenstein's data protection regime ends with death, with other (non-DP) laws governing the handling of deceased persons' data.
Category narrative56 words

Accountability, DPIA, DPO, ROPA, security, breach-notification and retention duties follow GDPR Articles 24-39 directly via EEA incorporation. The DSS has published a detailed DPIA 'blacklist' (high-risk processing list) since February 2019, and its breach-notification channel accepts submissions in German or English. National court rulings reported via DSS newsletters have addressed DPO dismissal protections and health-data handling.

Sources and claims (5)
  1. ConfirmedDatenschutzstelle / hosted via EDPB — The Datenschutzstelle's DPIA guidance identifies types of processing (e.g., large-scale evaluation of authority-collected data forwarded to law enforcement, or processing of children's/vulnerable individuals' data for marketing, profiling or automated decision-making) as requiring a DPIA even where not otherwise 'extensive' within Article 35(3)(b) GDPR.observed
  2. ConfirmedDatenschutzstelle / hosted via EDPB — Generally, any form of processing bearing a high risk to the rights and freedoms of individuals because of its nature, scope, circumstances and purpose, particularly when using new technologies, requires a prior DPIA under the DSS framework.observed
  3. ProbableDataGuidance — A DSS newsletter summarised recent national court rulings on GDPR and DSG covering DPO dismissal, health data handling, and legitimate interest principles.observed
  4. ConfirmedEDPB — Liechtenstein's Data Protection Authority accepts data breach notifications in German or English.observed
  5. ProbableDataGuidance — Liechtenstein's data protection regime ends with death, with other (non-DP) laws governing the handling of deceased persons' data.observed

#

Full GDPR Chapter V transfer regime applies via EEA incorporation, with active DSS transfer guidance and enforcement notices, plus recognition as a qualifying state under the EU-U.S. DPF.

Primary frameworkGDPR Articles 44-49 as incorporated via EEA Agreement
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — GreenFull GDPR Chapter V transfer regime applies via EEA incorporation, with active DSS transfer guidance and enforcement notices, plus recognition as a qualifying state under the EU-U.S. DPF.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Article 49 derogations) apply directly; DSS has published guidance on international data transfers and adequacy.

Claims (1):

  • The DSS has published guidance on international data transfers and adequacy applicable in Liechtenstein.

Adequacy ReceivedGreen

Liechtenstein, alongside all EEA member states, is designated a 'qualifying state' under the EU-U.S. Data Privacy Framework, giving its residents access to enhanced US privacy protections and the Data Protection Review Court.

Claims (1):

  • Under the EU-U.S. Data Privacy Framework, EU member states along with Iceland, Liechtenstein and Norway are designated 'qualifying states', whose citizens can seek redress through the U.S. Data Protection Review Court.

Adequacy GrantedGreen

The UK's EU adequacy decisions (GDPR and LED) apply to personal data transferred from the whole EEA, including Liechtenstein, to the UK without additional safeguards.

Claims (1):

  • The UK's EU adequacy decisions apply to personal data transferred from all EEA countries, defined to include Iceland, Liechtenstein and Norway, allowing flows to the UK without additional safeguards.

Sccs And BcrsGreen

SCCs and BCRs operate as under the GDPR baseline; the EDPB has issued Article 64 opinions on BCRs involving Liechtenstein members, indicating active BCR coordination through the DSS.

Claims (1):

  • The EDPB has adopted Article 64 opinions on Binding Corporate Rules with Liechtenstein as a concerned member state, indicating active national BCR coordination.

Transfer Impact AssessmentAmber

Post-Schrems II transfer impact assessment practice applies via the GDPR baseline; DSS has issued guidance addressing international transfers and third-country adequacy assessment, including flagging TikTok's transfers as unlawful.

Claims (1):

  • The DSS issued a notice on TikTok's unlawful data transfers to third countries, recommending organizations assess transfer risks and inform users.

Data LocalisationGreen

No general data-localisation mandate was identified in the DSG/DSV; Liechtenstein follows the GDPR's free-flow-within-EEA model, subject to sector-specific police/judicial cooperation instruments (e.g., biometric/dactyloscopic data-sharing with the EU).

Claims (1):

  • Personal data relating to dactyloscopic (fingerprint) data may be supplied by EU Member States to Switzerland and Liechtenstein from 1 July 2026 under a dedicated Council Implementing Decision, reflecting sector-specific (law-enforcement) cross-border data-sharing arrangements rather than general data localisation.
Category narrative92 words

As an EEA-EFTA state, Liechtenstein benefits from and applies the GDPR's transfer regime (adequacy decisions, SCCs, BCRs, derogations) directly. It is treated as part of the EEA for the purposes of third-country adequacy decisions (e.g., the UK's EU adequacy decisions apply to transfers from the whole EEA including Liechtenstein), and Liechtenstein is listed as a 'qualifying state' under the EU-U.S. Data Privacy Framework, giving its residents access to the U.S. Data Protection Review Court redress mechanism. The DSS has issued guidance on international transfers and warned of unlawful third-country transfers (e.g., TikTok).

Sources and claims (6)
  1. ConfirmedDataGuidance — The DSS has published guidance on international data transfers and adequacy applicable in Liechtenstein.observed
  2. ConfirmedIAPP — Under the EU-U.S. Data Privacy Framework, EU member states along with Iceland, Liechtenstein and Norway are designated 'qualifying states', whose citizens can seek redress through the U.S. Data Protection Review Court.observed
  3. ConfirmedICO — The UK's EU adequacy decisions apply to personal data transferred from all EEA countries, defined to include Iceland, Liechtenstein and Norway, allowing flows to the UK without additional safeguards.observed
  4. ConfirmedDatenschutzstelle / EDPB — The EDPB has adopted Article 64 opinions on Binding Corporate Rules with Liechtenstein as a concerned member state, indicating active national BCR coordination.observed
  5. ConfirmedDataGuidance — The DSS issued a notice on TikTok's unlawful data transfers to third countries, recommending organizations assess transfer risks and inform users.observed
  6. ConfirmedEUR-Lex / Official Journal of the EU — Personal data relating to dactyloscopic (fingerprint) data may be supplied by EU Member States to Switzerland and Liechtenstein from 1 July 2026 under a dedicated Council Implementing Decision, reflecting sector-specific (law-enforcement) cross-border data-sharing arrangements rather than general data localisation.observed

#

Financial, health, telecoms/cookie and employment overlays are evidenced via DSS guidance/reports; credit-scoring, education, and insurance sub-modules lack dedicated LI sources.

Primary frameworkGDPR as incorporated via EEA Agreement, overlaid with sector-specific Liechtenstein financial-market and other sectoral rules
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — AmberFinancial, health, telecoms/cookie and employment overlays are evidenced via DSS guidance/reports; credit-scoring, education, and insurance sub-modules lack dedicated LI sources.

Sub-modules (7)

Financial Sector OverlayAmber

DataGuidance maintains a dedicated opinion piece on data protection in Liechtenstein's financial sector, reflecting the interaction between GDPR and the jurisdiction's banking/trust industry oversight (Finanzmarktaufsicht, FMA).

Claims (1):

  • DataGuidance publishes a dedicated analysis of data protection in Liechtenstein's financial sector, reflecting the interplay between GDPR/DSG and financial-market regulation in the jurisdiction.

Health Sector OverlayGreen

DSS newsletters reference national court rulings covering health data handling under GDPR/DSG.

Claims (1):

  • A DSS newsletter summarising recent court rulings on GDPR and DSG covered health data handling among other topics.

Telecoms And EprivacyGreen

DSS updated cookie guidance clarifying consent requirements and conditions for relying on legitimate interest for cookies/trackers.

Claims (1):

  • DSS updated guidance on cookies clarifies consent requirements and the conditions under which legitimate interest may be used for cookie-based tracking.

Employment DataGreen

The DSS's 2024 annual report highlighted inquiries covering employment data alongside AI data processing and video surveillance.

Claims (1):

  • The DSS's 2024 report highlights inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures.

Credit And ScoringRed

No LI-specific credit-scoring guidance or rules were identified in the sources reviewed.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Kredit Scoring, Liechtenstein credit scoring data protection.

EducationRed

No LI-specific education-sector data protection guidance was identified beyond a general reference to social-media age-restriction guidance.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Schule Bildung Datenschutz.

InsuranceRed

No LI-specific insurance-sector data protection guidance was identified in the sources reviewed.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Versicherung Datenschutz.

Category narrative50 words

Liechtenstein's financial-sector data processing (a core feature of its economy as a private-banking/trust hub) interacts with GDPR through DSS-published sector guidance; other sector overlays (health, telecoms/eprivacy for cookies, employment) are addressed via DSS newsletters and reports, while credit-scoring, education, and insurance-specific overlays were not separately evidenced in the sources reviewed.

Sources and claims (4)
  1. UncertainDataGuidance — DataGuidance publishes a dedicated analysis of data protection in Liechtenstein's financial sector, reflecting the interplay between GDPR/DSG and financial-market regulation in the jurisdiction.observed
  2. ProbableDataGuidance — A DSS newsletter summarising recent court rulings on GDPR and DSG covered health data handling among other topics.observed
  3. ConfirmedDataGuidance — DSS updated guidance on cookies clarifies consent requirements and the conditions under which legitimate interest may be used for cookie-based tracking.observed
  4. ConfirmedDataGuidance — The DSS's 2024 report highlights inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures.observed

#

Cookie/tracker consent is actively covered by DSS guidance; several other sub-modules (dark patterns, opt-out signals, clean rooms, cross-context advertising, direct marketing specifics) lack dedicated LI sources and rely on the GDPR/ePrivacy baseline.

Primary frameworkGDPR + EU ePrivacy Directive as applied in Liechtenstein via EEA incorporation
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — AmberCookie/tracker consent is actively covered by DSS guidance; several other sub-modules (dark patterns, opt-out signals, clean rooms, cross-context advertising, direct marketing specifics) lack dedicated LI sources and rely on the GDPR/ePrivacy baseline.

Sub-modules (6)

Cookies And TrackersGreen

DSS updated cookie guidance clarifies consent requirements and legitimate-interest conditions, applying European case law on cookies in Liechtenstein.

Claims (1):

  • The DSS has published guidance on international data transfers and adequacy, and on the application of European case law concerning cookies in Liechtenstein.

Dark PatternsRed

No LI-specific dark-pattern guidance was identified in the sources reviewed.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein dark patterns manipulative design.

Opt Out SignalsRed

No LI-specific Global Privacy Control / opt-out-signal guidance was identified in the sources reviewed.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No LI-specific clean-room/data-collaboration-room guidance was identified in the sources reviewed.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein data clean room.

Cross Context AdvertisingAmber

No LI-specific 'sale'/'share' cross-context-advertising framework (a US state-law concept) was identified; the GDPR consent/legitimate-interest baseline governs behavioural advertising instead.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein cross-context advertising sale share.

Direct MarketingAmber

Direct marketing is governed by the GDPR Article 21(2) unconditional right to object baseline as incorporated via the EEA Agreement; no LI-specific suppression-list regime was identified.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Direktmarketing Widerspruchsrecht.

Category narrative47 words

Cookie/tracker consent follows the ePrivacy/GDPR baseline as applied by the DSS, which has issued updated cookie guidance. Dark-pattern prohibitions, opt-out signals (e.g., GPC), clean-room arrangements, and cross-context advertising rules specific to Liechtenstein were not separately evidenced; direct marketing follows the GDPR Article 21(2) right to object baseline.

Sources and claims (1)
  1. ConfirmedDataGuidance — The DSS has published guidance on international data transfers and adequacy, and on the application of European case law concerning cookies in Liechtenstein.observed

#

Profiling/ADM and AI-risk sub-modules are well evidenced via active DSS guidance; biometric, genetic-data, and state-surveillance sub-modules rely more heavily on the general GDPR baseline.

Primary frameworkGDPR Article 22 and Articles 9-10 as incorporated via EEA Agreement
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — AmberProfiling/ADM and AI-risk sub-modules are well evidenced via active DSS guidance; biometric, genetic-data, and state-surveillance sub-modules rely more heavily on the general GDPR baseline.

Sub-modules (6)

Profiling RestrictionsGreen

DSS DPIA guidance flags profiling for automated decision-making, particularly involving children or vulnerable individuals, as requiring a DPIA even outside 'extensive' processing.

Claims (1):

  • DSS DPIA guidance identifies processing of children's or other vulnerable individuals' data for marketing or profiling for automated decision-making as requiring a DPIA even where not 'extensive' under Article 35(3)(b) GDPR.

Automated Decision Making TransparencyGreen

Article 22 GDPR ADM transparency/explanation rights apply directly via EEA incorporation; DSS DPIA guidance references auto-decision-making as a high-risk trigger.

Claims (1):

  • The DSS's DPIA blacklist references automated decision-making as a high-risk processing trigger requiring assessment consistent with Article 22 and Article 35 GDPR.

Ai Risk AssessmentsAmber

The DSS has actively engaged with AI-specific risks: warning against DeepSeek R1 on privacy grounds, providing guidance on using AI systems/chatbots with personal data, and announcing Meta's plan to use public EU user data for AI training with an objection deadline.

Claims (2):

  • The DSS warned of data protection risks associated with the AI service DeepSeek R1 and advised the use of GDPR-compliant tools.
  • The DSS announced Meta's plan to use public data from European users for AI training and provided a window for objections until 26 May 2025.

Biometric RegimeAmber

DSS has updated guidance on video surveillance limitations; dedicated facial-recognition/biometric-specific rules beyond the GDPR Art 9 special-category baseline were not separately evidenced, though cross-border dactyloscopic data-sharing with the EU is now permitted from mid-2026.

Claims (1):

  • The DSS updated its guidance on video surveillance, addressing limitations on the practice.

Genetic DataAmber

Genetic data is treated as a special category under GDPR Article 9 as incorporated via the EEA Agreement; no LI-specific genetic-data guidance was identified.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein genetische Daten.

State Surveillance CarveoutsRed

No LI-specific analysis of national-security/state-surveillance carve-outs and their limits was identified in the sources reviewed.

Absence provenance: unavailable. Searched: Liechtenstein Staatssicherheit Überwachung Datenschutz Ausnahme.

Category narrative57 words

Profiling and ADM transparency follow GDPR Article 22 directly, reinforced by DSS DPIA guidance flagging profiling/automated decision-making (including for marketing purposes) as high-risk processing. The DSS has actively addressed AI-specific risks (DeepSeek R1 warnings, Meta AI-training objection notice, chatbot guidance) and video-surveillance/biometric-adjacent processing, but no dedicated genetic-data regime or state-surveillance carve-out analysis specific to Liechtenstein was identified.

Sources and claims (5)
  1. ConfirmedDatenschutzstelle / hosted via EDPB — DSS DPIA guidance identifies processing of children's or other vulnerable individuals' data for marketing or profiling for automated decision-making as requiring a DPIA even where not 'extensive' under Article 35(3)(b) GDPR.observed
  2. ConfirmedDatenschutzstelle / hosted via EDPB — The DSS's DPIA blacklist references automated decision-making as a high-risk processing trigger requiring assessment consistent with Article 22 and Article 35 GDPR.observed
  3. ConfirmedDataGuidance — The DSS warned of data protection risks associated with the AI service DeepSeek R1 and advised the use of GDPR-compliant tools.observed
  4. ConfirmedDataGuidance — The DSS announced Meta's plan to use public data from European users for AI training and provided a window for objections until 26 May 2025.observed
  5. ConfirmedDataGuidance — The DSS updated its guidance on video surveillance, addressing limitations on the practice.observed

#

Age-verification, minor-profiling and dependent-adult sub-modules are evidenced via active DSS guidance; parental-consent-age specifics and education-settings rules rely on the unlocalised GDPR Article 8 baseline.

Primary frameworkGDPR Article 8 as incorporated via EEA Agreement; DSG
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — AmberAge-verification, minor-profiling and dependent-adult sub-modules are evidenced via active DSS guidance; parental-consent-age specifics and education-settings rules rely on the unlocalised GDPR Article 8 baseline.

Sub-modules (5)

Age VerificationGreen

DSS has provided GDPR compliance guidance addressing social media age restrictions.

Claims (1):

  • The DSS provides GDPR compliance guidance on data access and social media age restrictions.

Minor Profiling BansGreen

DSS DPIA guidance treats profiling of children or other vulnerable individuals for marketing or automated decision-making as a DPIA-triggering high-risk activity, functioning as a de facto heightened-scrutiny regime rather than an outright ban.

Claims (1):

  • Processing of personal data of children or other vulnerable individuals for marketing, profiling for automated decision-making, or the offer of online services requires a DPIA under DSS guidance even where not 'extensive' under Article 35(3)(b) GDPR.

Education SettingsRed

No LI-specific education-settings data protection guidance was identified beyond the general age-restriction guidance.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Schule Datenschutz Bildungseinrichtung.

Dependent AdultsGreen

DSS issued specific guidance on obtaining valid consent for adults incapable of giving consent under GDPR, addressing dependent/vulnerable adult protections.

Claims (1):

  • The DSS issued guidance on obtaining valid consent for adults incapable of giving consent under GDPR.
Category narrative51 words

Children's data processing follows GDPR Article 8 as incorporated via the EEA Agreement; the DSS has issued guidance on social-media age restrictions and flagged minors'/vulnerable individuals' profiling as a DPIA trigger. Vulnerable-adult protections are addressed through DSS guidance on consent by adults incapable of consenting. Education-settings-specific rules were not separately evidenced.

Sources and claims (3)
  1. ConfirmedDataGuidance — The DSS provides GDPR compliance guidance on data access and social media age restrictions.observed
  2. ConfirmedDatenschutzstelle / hosted via EDPB — Processing of personal data of children or other vulnerable individuals for marketing, profiling for automated decision-making, or the offer of online services requires a DPIA under DSS guidance even where not 'extensive' under Article 35(3)(b) GDPR.observed
  3. ConfirmedDataGuidance — The DSS issued guidance on obtaining valid consent for adults incapable of giving consent under GDPR.observed

#

Enforcement powers and recent developments are well evidenced; specific collective-redress/private-right-of-action mechanics and regulator funding/headcount data for Liechtenstein were not separately sourced.

Primary frameworkGDPR Articles 58, 77-84 as incorporated via EEA Agreement; DSG
Supervisory authorityDatenschutzstelle (DSS)
Traffic-light rationale — AmberEnforcement powers and recent developments are well evidenced; specific collective-redress/private-right-of-action mechanics and regulator funding/headcount data for Liechtenstein were not separately sourced.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The DSS has GDPR Article 58 corrective powers (investigation, warnings, orders, bans) and Article 83 administrative-fine powers, applied via direct EEA incorporation of the GDPR.

Claims (1):

  • Each GDPR supervisory authority, including the DSS as incorporated via the EEA Agreement, has corrective powers under Article 58(2) including the power to impose administrative fines under Article 83.

Enforcement Activity IndexAmber

The DSS's 2024 report highlighted inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures; the 2023 report covered GDPR compliance, AI services, video surveillance, and data protection breaches.

Claims (2):

  • The DSS's 2024 report highlights inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures.
  • Liechtenstein's DSS 2023 report covers inquiries on GDPR compliance, AI services, video surveillance, and data protection breaches.

Regulator Funding And CapacityRed

No specific funding or headcount data for the DSS was identified in the sources reviewed.

Absence provenance: unavailable. Searched: Datenschutzstelle Liechtenstein Budget Personal Kapazität.

Collective Redress And Class ActionsRed

No Liechtenstein-specific collective-redress or class-action mechanism for data protection claims was identified; the EU Representative Actions Directive is an EU-only instrument and its applicability to the EEA-EFTA state was not confirmed in sources reviewed.

Absence provenance: unavailable. Searched: Liechtenstein collective redress class action data protection, Representative Actions Directive Liechtenstein EEA.

Private Right Of ActionGreen

GDPR Articles 79-82 (judicial remedy against controllers/processors and compensation) apply directly via EEA incorporation; individuals may also lodge complaints with the DSS or national courts.

Claims (1):

  • An individual has the right to lodge a complaint with a data protection authority of an EEA Member State, which includes the EU countries plus Iceland, Liechtenstein and Norway.

Recent Developments 180DGreen

Within the last 180 days: the DSS issued a notice (reported 9 January 2026) on TikTok's unlawful data transfers to third countries; the May 2026 IAPP Global Summit update confirmed Liechtenstein's continued 'qualifying state' status under the EU-U.S. Data Privacy Framework; and a Council Implementing Decision of 25 June 2026 (2026/1459) set 1 July 2026 as the date from which EU Member States may supply dactyloscopic data to Switzerland and Liechtenstein.

Claims (3):

  • The DSS issued a notice on TikTok's unlawful transfer of personal data to third countries, recommending organizations assess risks and inform users.
  • At the IAPP Global Summit 2026, US and EU officials provided an update on the status of the EU-U.S. Data Privacy Framework, under which Liechtenstein remains a designated qualifying state.
  • Council Implementing Decision (EU) 2026/1459 of 25 June 2026 set 1 July 2026 as the date from which personal data relating to dactyloscopic data may be supplied by EU Member States to Switzerland and Liechtenstein.
Category narrative102 words

The DSS holds full GDPR Article 58 investigative and corrective powers, including the Article 83 administrative-fine framework (up to the higher of a fixed sum or a percentage of worldwide turnover), applied directly via EEA incorporation. The DSS's 2024 annual report recorded no fines imposed despite several formal measures, following a 2023 report covering GDPR compliance inquiries, AI, video surveillance and breach matters. Recent developments include a January 2026 DSS notice on TikTok's unlawful third-country transfers, the May 2026 EU-US adequacy update confirming Liechtenstein's 'qualifying state' status, and a June 2026 Council Implementing Decision extending dactyloscopic data-sharing to Liechtenstein from July 2026.

Sources and claims (7)
  1. ConfirmedEUR-Lex / CJEU — Each GDPR supervisory authority, including the DSS as incorporated via the EEA Agreement, has corrective powers under Article 58(2) including the power to impose administrative fines under Article 83.observed
  2. ConfirmedDataGuidance — The DSS's 2024 report highlights inquiries on AI data processing, video surveillance, and employment data, with no fines imposed despite several formal measures.observed
  3. ConfirmedDataGuidance — Liechtenstein's DSS 2023 report covers inquiries on GDPR compliance, AI services, video surveillance, and data protection breaches.observed
  4. ConfirmedEDPB — An individual has the right to lodge a complaint with a data protection authority of an EEA Member State, which includes the EU countries plus Iceland, Liechtenstein and Norway.observed
  5. ConfirmedDataGuidance — The DSS issued a notice on TikTok's unlawful transfer of personal data to third countries, recommending organizations assess risks and inform users.observed
  6. ConfirmedIAPP — At the IAPP Global Summit 2026, US and EU officials provided an update on the status of the EU-U.S. Data Privacy Framework, under which Liechtenstein remains a designated qualifying state.observed
  7. ConfirmedEUR-Lex / Official Journal of the EU — Council Implementing Decision (EU) 2026/1459 of 25 June 2026 set 1 July 2026 as the date from which personal data relating to dactyloscopic data may be supplied by EU Member States to Switzerland and Liechtenstein.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct66.67
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Liechtenstein
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 42 claim(s) (44 category placement(s)), 16 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer impact assessment
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, cross_border_and_adequacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress achieved substantive T1/T2/T3 coverage anchored on the DSS's own DPIA guidance (T1), EDPB member/documentation pages (T1/T2), EUR-Lex instruments (T1), and DataGuidance secondary reporting (T3). sectoral_watch achieved partial coverage (financial, health, telecoms/cookies, employment evidenced; credit-scoring, education, insurance carry explicit absent_field_provenance). adtech_and_commercial_privacy achieved coverage only on cookies_and_trackers; dark_patterns, opt_out_signals, clean_rooms_and_dcr, cross_context_advertising and direct_marketing carry explicit absent_field_provenance reflecting reliance on the unlocalised GDPR/ePrivacy baseline rather than dedicated LI sources.

Unresolved questions (4):

  • Does the Liechtenstein DSG set a national digital age-of-consent below the GDPR Article 8 default of 16 (as several EU/EEA states have done, e.g., 13-15)?
  • Does Liechtenstein operate any collective-redress or representative-action mechanism analogous to the EU Representative Actions Directive for data protection claims, given its EEA-EFTA (non-EU) status?
  • Are there DSS-published funding/headcount figures establishing regulator capacity comparable to EU Member State DPA annual reports?
  • Is there a Liechtenstein-specific credit-scoring, education-sector, or insurance-sector data protection overlay beyond the general GDPR baseline?

Escalate to primary-source review: yes