🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
LU v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing12 sources retrieved model claude-sonnet-5 · 2026-08-04

Luxembourg

LU schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 27 claims · 21 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
27Claimsbaseline..claims[]
6Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 30 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Luxembourg's Administrative Appeal Court ruled on 12 March 2026 on the CNPD's landmark EUR 746 million fine against Amazon, and the outcome is more nuanced than a simple reversal. The court upheld the CNPD's substantive finding that Amazon's reliance on legitimate interests to justify behavioural advertising was not a legally valid basis for that processing, while annulling the fine itself on the grounds that the CNPD had not established the fault or negligence that Article 83 requires, following the CJEU's Deutsche Wohnen ruling. The court remanded the matter for fresh sanction analysis. The practical effect is that Amazon's underlying legal exposure on the substantive adtech question is unchanged and unfavourable, while Luxembourg's near-term enforcement leverage on quantum has narrowed, at least until the CNPD produces the fault-based reasoning the court now demands.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core regulator, founding statute and territorial scope are well-evidenced from primary EDPB/EUR-Lex sources; registration/filing sub-module lacks a distinct LU-specific finding.

Primary frameworkRegulation (EU) 2016/679 (GDPR), as given domestic institutional effect by the Loi du 1er août 2018
Traffic-light rationale — GreenCore regulator, founding statute and territorial scope are well-evidenced from primary EDPB/EUR-Lex sources; registration/filing sub-module lacks a distinct LU-specific finding.

Sub-modules (5)

Regulator And AuthorityGreen

CNPD, 15 Boulevard du Jazz, 4370 Belvaux, is Luxembourg's independent GDPR supervisory authority.

Claims (1):

  • The Commission Nationale pour la Protection des Données (CNPD), based at 15 Boulevard du Jazz, 4370 Belvaux, Luxembourg, is the country's independent GDPR supervisory authority.

Act And InstrumentsGreen

The Loi du 1er août 2018 is the national instrument organising the CNPD and the general data-protection regime.

Claims (1):

  • Luxembourg's GDPR-implementing act is the Loi du 1er août 2018 portant organisation de la Commission nationale pour la protection des données et du régime général sur la protection des données, published in Mémorial A No. 686 of 16 August 2018.

Material ScopeAmber

Material scope tracks GDPR's definition of personal-data processing, with the national act supplying institutional/procedural detail.

Claims (1):

  • The general data-protection regime organised by the Loi du 1er août 2018 applies alongside the directly-applicable GDPR to processing falling within GDPR's material scope, with the national act supplying Luxembourg's institutional and procedural framework (CNPD organisation, sanctions, cooperation).

Territorial ScopeGreen

Territorial scope follows GDPR Art 3 establishment and targeting criteria per EDPB Guidelines 3/2018.

Claims (1):

  • GDPR Article 3 extends Luxembourg's data-protection regime extraterritorially via the establishment criterion (Art 3(1)) and the targeting criterion (Art 3(2)).

Regulator Registration And FilingRed

No LU-specific general registration/filing obligation beyond GDPR accountability documentation (ROPA, DPIA) was located in this pass. Searched: 'CNPD registration filing requirements Luxembourg', 'Luxembourg data controller notification obligation'.

Category narrative98 words

Luxembourg is an EU Member State subject to the directly-applicable GDPR, given national institutional effect via the Loi du 1er août 2018 portant organisation de la Commission nationale pour la protection des données et du régime général sur la protection des données. The CNPD (Commission Nationale pour la Protection des Données), headquartered in Belvaux, is the sole national supervisory authority. Territorial scope follows GDPR Art 3's establishment/targeting test. Registration/filing: GDPR abolished general prior-notification regimes; no LU-specific residual filing obligation was identified in this research pass beyond DPIA/DPO record-keeping duties captured under controller_processor_duties (searched: 'CNPD registration filing requirements Luxembourg').

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedEDPB — The Commission Nationale pour la Protection des Données (CNPD), based at 15 Boulevard du Jazz, 4370 Belvaux, Luxembourg, is the country's independent GDPR supervisory authority.observed
  2. ConfirmedEUR-Lex (National Implementing Measure record) — Luxembourg's GDPR-implementing act is the Loi du 1er août 2018 portant organisation de la Commission nationale pour la protection des données et du régime général sur la protection des données, published in Mémorial A No. 686 of 16 August 2018.observed
  3. ConfirmedEDPB — GDPR Article 3 extends Luxembourg's data-protection regime extraterritorially via the establishment criterion (Art 3(1)) and the targeting criterion (Art 3(2)).observed
  4. ProbableEUR-Lex (National Implementing Measure record) — The general data-protection regime organised by the Loi du 1er août 2018 applies alongside the directly-applicable GDPR to processing falling within GDPR's material scope, with the national act supplying Luxembourg's institutional and procedural framework (CNPD organisation, sanctions, cooperation).observed

#

Lawful bases, consent and special categories are solidly evidenced from EDPB primary guidance; pseudonymisation/anonymisation sub-module has no LU-specific finding.

Primary frameworkGDPR (EU) 2016/679, Articles 6-9
Traffic-light rationale — GreenLawful bases, consent and special categories are solidly evidenced from EDPB primary guidance; pseudonymisation/anonymisation sub-module has no LU-specific finding.

Sub-modules (4)

Lawful BasesGreen

Controllers must identify one of the six Art 6 lawful bases before processing.

Claims (1):

  • Data controllers must rely on one of the GDPR Article 6 lawful bases (consent, contract, legal obligation, vital interests, public interest/official authority, or legitimate interests) to process personal data lawfully.

Special CategoriesGreen

Art 9 special categories are prohibited by default absent a specific exception.

Claims (1):

  • Processing of special categories of data (racial/ethnic origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic data, biometric data for identification, health data, sex life/orientation) is prohibited by default under GDPR Article 9 absent a specific exception.

Pseudonymisation And AnonymisationRed

No LU-specific CNPD guidance on pseudonymisation/anonymisation safe-harbours was located this pass.

Category narrative54 words

GDPR Articles 6, 7 and 9 apply directly in Luxembourg. Lawful bases, consent standards and special-category prohibitions/exceptions are governed by the EU text with no LU-specific derogation identified for these sub-modules. Pseudonymisation/anonymisation safe-harbours (GDPR Art 4(5), Recital 26) were not independently evidenced with LU-specific CNPD guidance in this pass (searched: 'CNPD pseudonymisation anonymisation guidance').

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedEDPB — Data controllers must rely on one of the GDPR Article 6 lawful bases (consent, contract, legal obligation, vital interests, public interest/official authority, or legitimate interests) to process personal data lawfully.observed
  2. ConfirmedEDPB — Where consent is used as the lawful basis, GDPR requires it to be freely given, informed, specific and unambiguous, with individuals able to freely withdraw consent without negative consequences.observed
  3. ConfirmedEDPB — Processing of special categories of data (racial/ethnic origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic data, biometric data for identification, health data, sex life/orientation) is prohibited by default under GDPR Article 9 absent a specific exception.observed

#

Strong enforcement-based evidence for access/rectification/erasure/objection; portability and deadlines sub-modules unevidenced.

Primary frameworkGDPR Articles 12-22, given institutional effect via the Loi du 1er août 2018
Traffic-light rationale — AmberStrong enforcement-based evidence for access/rectification/erasure/objection; portability and deadlines sub-modules unevidenced.

Sub-modules (5)

Access RightAmber

CNPD found an Art 15 violation in the Amazon Europe Core case.

Claims (1):

  • In its 16 July 2021 decision, the CNPD found Amazon Europe Core in violation of, among other provisions, GDPR Article 15 (right of access), as part of a €746 million fine.

Rectification And ErasureAmber

CNPD found Art 16/17 violations in the same case.

Claims (1):

  • The same CNPD decision against Amazon Europe Core also found violations of GDPR Articles 16 (rectification) and 17 (erasure).

Restriction And ObjectionAmber

CNPD found an Art 21 violation tied to profiling-based advertising objection rights.

Claims (1):

  • The CNPD's Amazon decision further found a violation of GDPR Article 21 (right to object), the provision underpinning objections to profiling-based targeted advertising.

Data PortabilityRed

No LU-specific portability finding located this pass.

Deadlines And Response WindowsRed

No LU-specific deadline/response-window guidance located this pass; GDPR's default one-month window is assumed absent evidence of derogation.

Category narrative61 words

CNPD's own enforcement record evidences the operative rights framework: the Amazon Europe Core decision (16 July 2021) expressly found violations of Articles 15 (access), 16 (rectification), 17 (erasure) and 21 (objection). Portability (Art 20) and the statutory response-deadline mechanics (Art 12(3)) were not independently evidenced with LU-specific material in this pass (searched: 'CNPD subject access request deadline', 'CNPD data portability guidance').

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidance — In its 16 July 2021 decision, the CNPD found Amazon Europe Core in violation of, among other provisions, GDPR Article 15 (right of access), as part of a €746 million fine.observed
  2. ConfirmedOneTrust DataGuidance — The same CNPD decision against Amazon Europe Core also found violations of GDPR Articles 16 (rectification) and 17 (erasure).observed
  3. ConfirmedOneTrust DataGuidance — The CNPD's Amazon decision further found a violation of GDPR Article 21 (right to object), the provision underpinning objections to profiling-based targeted advertising.observed

#

DPO and accountability sub-modules well evidenced; ROPA, joint-controller, GDPR-breach-notification and retention sub-modules unevidenced in this pass.

Primary frameworkGDPR Articles 5, 24-39, given institutional effect via the Loi du 1er août 2018
Traffic-light rationale — AmberDPO and accountability sub-modules well evidenced; ROPA, joint-controller, GDPR-breach-notification and retention sub-modules unevidenced in this pass.

Sub-modules (7)

Accountability And DpiaAmber

CNPD's Amazon finding on Art 6(1) reflects the accountability principle requiring a demonstrable lawful basis.

Claims (1):

  • The CNPD's Amazon Europe Core decision found that the company's processing of personal data for behavioural advertising lacked a valid legal basis under GDPR Article 6(1), reflecting the accountability principle that controllers must be able to demonstrate a lawful basis for each processing purpose.

Dpo RequirementsGreen

CNPD Decision 23FR/2021 addressed DPO reporting-line independence.

Claims (1):

  • In Decision No. 23FR/2021 of 29 June 2021, the CNPD held that direct reporting lines or the ability to bypass intermediate management levels can be proportionate measures to guarantee a Data Protection Officer's autonomy under GDPR Articles 38-39.

Ropa RequirementsRed

No LU-specific ROPA finding located this pass.

Joint Controller ArrangementsRed

No LU-specific joint-controller finding located this pass.

Security MeasuresAmber

Luxembourg's 2026 NIS2 transposition law imposes adjacent cybersecurity obligations supervised by ILR, distinct from GDPR Art 32 security duties enforced by CNPD.

Claims (1):

  • Luxembourg's Law of 5 May 2026 transposing the NIS2 Directive introduces risk-based cybersecurity obligations, incident-notification requirements and governance/accountability measures for essential and important entities, with the Institut Luxembourgeois de Régulation (ILR) — not the CNPD — designated as the supervising authority.

Breach NotificationRed

No LU-specific CNPD guidance on GDPR Art 33/34 personal-data breach notification located this pass; the adjacent NIS2 incident-notification regime is distinct and supervised by ILR.

Retention And DisposalRed

No LU-specific retention/disposal finding located this pass.

Category narrative73 words

Accountability (Art 6(1) legal-basis documentation) and DPO independence are evidenced via CNPD's Amazon decision and Decision No. 23FR/2021 respectively. ROPA, joint-controller arrangements, GDPR-specific breach notification and retention/disposal lack LU-specific evidentiary findings this pass. A distinct but adjacent cybersecurity-incident-notification regime (NIS2 transposition, Law of 5 May 2026) is captured under security_measures, supervised by ILR rather than CNPD (searched: 'CNPD ROPA requirements guidance', 'CNPD breach notification guidance', 'CNPD retention disposal guidance', 'CNPD joint controller guidance').

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidance — The CNPD's Amazon Europe Core decision found that the company's processing of personal data for behavioural advertising lacked a valid legal basis under GDPR Article 6(1), reflecting the accountability principle that controllers must be able to demonstrate a lawful basis for each processing purpose.observed
  2. ConfirmedCNIL — In Decision No. 23FR/2021 of 29 June 2021, the CNPD held that direct reporting lines or the ability to bypass intermediate management levels can be proportionate measures to guarantee a Data Protection Officer's autonomy under GDPR Articles 38-39.observed
  3. ConfirmedOneTrust DataGuidance — Luxembourg's Law of 5 May 2026 transposing the NIS2 Directive introduces risk-based cybersecurity obligations, incident-notification requirements and governance/accountability measures for essential and important entities, with the Institut Luxembourgeois de Régulation (ILR) — not the CNPD — designated as the supervising authority.observed

#

General Chapter V applicability evidenced generically; LU-specific transfer-mechanism detail (SCC uptake, TIA practice, localisation) unevidenced.

Primary frameworkGDPR Chapter V (Articles 44-49), directly applicable EU law
Traffic-light rationale — AmberGeneral Chapter V applicability evidenced generically; LU-specific transfer-mechanism detail (SCC uptake, TIA practice, localisation) unevidenced.

Sub-modules (6)

Transfer MechanismsAmber

Chapter V mechanisms (adequacy, SCCs, BCRs, derogations) apply directly as EU law.

Claims (1):

  • As an EU Member State, Luxembourg's cross-border transfer regime for personal data is governed directly by GDPR Chapter V (Articles 44-49) as directly-applicable EU law, with the Loi du 1er août 2018 supplying the national institutional and enforcement framework (CNPD) rather than a separate transfer statute.

Adequacy ReceivedRed

No LU-specific finding; adequacy is an EU-Commission-level determination.

Adequacy GrantedRed

No LU-specific finding; adequacy is an EU-Commission-level determination.

Sccs And BcrsRed

No LU-specific SCC/BCR uptake data located this pass.

Transfer Impact AssessmentRed

No LU-specific TIA practice guidance located this pass.

Data LocalisationRed

No LU-specific data-localisation mandate identified this pass.

Category narrative69 words

As an EU Member State, Luxembourg's transfer regime runs directly off GDPR Chapter V (Arts 44-49) as EU law; the national act supplies institutional enforcement capacity via CNPD rather than a separate transfer statute. Adequacy decisions received/granted, SCC/BCR uptake specifics, transfer-impact-assessment practice and any data-localisation mandate were not independently evidenced with LU-specific material in this pass (searched: 'CNPD adequacy decisions', 'CNPD SCC BCR guidance Luxembourg', 'Luxembourg data localisation requirement').

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ProbableEUR-Lex (National Implementing Measure record) — As an EU Member State, Luxembourg's cross-border transfer regime for personal data is governed directly by GDPR Chapter V (Articles 44-49) as directly-applicable EU law, with the Loi du 1er août 2018 supplying the national institutional and enforcement framework (CNPD) rather than a separate transfer statute.observed

#

Financial and telecoms overlays well evidenced; health, employment, credit-scoring, education and (binding) insurance overlays unevidenced.

Primary frameworkGDPR plus sector overlays: Law of 5 April 1993 on the financial sector (CSSF); ePrivacy Directive 2002/58/EC (as amended)
Supervisory authorityCommission de Surveillance du Secteur Financier (CSSF)
Traffic-light rationale — AmberFinancial and telecoms overlays well evidenced; health, employment, credit-scoring, education and (binding) insurance overlays unevidenced.

Sub-modules (7)

Financial Sector OverlayGreen

CSSF professional secrecy and cross-border information-exchange rules layer atop GDPR for supervised financial entities.

Claims (1):

  • The Law of 5 April 1993 on the financial sector, as amended, imposes professional-secrecy obligations on the CSSF and governs its cooperation and information-exchange with EU and third-country authorities, forming a sectoral confidentiality overlay for Luxembourg's banks, investment firms and other supervised entities.

Health Sector OverlayRed

No LU-specific health-sector DP overlay located this pass.

Telecoms And EprivacyAmber

ePrivacy Directive remains operative; 2026 NIS2 law also amends the electronic-communications statute.

Claims (2):

  • The ePrivacy Directive (2002/58/EC, as amended) remains the operative EU instrument governing confidentiality of electronic communications and cookie-related tracking, layered on top of the GDPR, pending adoption of a replacement ePrivacy Regulation.
  • Luxembourg's Law of 5 May 2026 transposing NIS2 also amended the law of 17 December 2021 on electronic communications networks and services, linking cybersecurity obligations to the electronic-communications sector.

Employment DataRed

No LU-specific employment-data overlay located this pass.

Credit And ScoringRed

No LU-specific credit-scoring overlay located this pass.

EducationRed

No LU-specific education-sector overlay located this pass.

InsuranceAmber

A still-pending AI Act implementing bill would designate the Insurance Commission as AI market-surveillance authority for the insurance sector; not yet confirmed enacted.

Claims (1):

  • Luxembourg's draft AI Act implementing bill (No. 8476) proposes designating the Commissariat aux Assurances (Insurance Commission) as the market-surveillance authority for AI systems placed on the market, commissioned, or used by entities under its insurance-sector supervision.
Category narrative99 words

The financial sector carries a distinct professional-secrecy/cooperation overlay under the Law of 5 April 1993 on the financial sector (as amended), administered by the CSSF, which interacts with but is separate from GDPR. Telecoms/eProceedings run off the ePrivacy Directive pending an EU-level Regulation, with Luxembourg's 2026 NIS2 law also amending the electronic-communications-networks statute. Health, employment, credit-scoring and education sector-specific overlays were not independently evidenced this pass; the insurance sector is referenced only via a still-pending AI Act implementing bill (searched: 'Luxembourg health sector data protection law', 'Luxembourg employment data protection code', 'Luxembourg credit scoring regulation', 'Luxembourg education data protection').

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ConfirmedCSSF — The Law of 5 April 1993 on the financial sector, as amended, imposes professional-secrecy obligations on the CSSF and governs its cooperation and information-exchange with EU and third-country authorities, forming a sectoral confidentiality overlay for Luxembourg's banks, investment firms and other supervised entities.observed
  2. ConfirmedEDPS — The ePrivacy Directive (2002/58/EC, as amended) remains the operative EU instrument governing confidentiality of electronic communications and cookie-related tracking, layered on top of the GDPR, pending adoption of a replacement ePrivacy Regulation.observed
  3. ConfirmedOneTrust DataGuidance — Luxembourg's Law of 5 May 2026 transposing NIS2 also amended the law of 17 December 2021 on electronic communications networks and services, linking cybersecurity obligations to the electronic-communications sector.observed
  4. ProbableOneTrust DataGuidance — Luxembourg's draft AI Act implementing bill (No. 8476) proposes designating the Commissariat aux Assurances (Insurance Commission) as the market-surveillance authority for AI systems placed on the market, commissioned, or used by entities under its insurance-sector supervision.observed

#

Cookies/dark-patterns/cross-context advertising well evidenced; opt-out signals, clean rooms and direct marketing unevidenced.

Primary frameworkePrivacy Directive (as amended) + GDPR, CNPD cookie guidance
Traffic-light rationale — AmberCookies/dark-patterns/cross-context advertising well evidenced; opt-out signals, clean rooms and direct marketing unevidenced.

Sub-modules (6)

Cookies And TrackersGreen

CNPD guidelines clarify consent requirements for essential and non-essential cookies.

Claims (1):

  • CNPD guidelines on cookies and other trackers clarify consent requirements for essential and non-essential cookies, including analytical cookies.

Dark PatternsAmber

CNPD cookie guidance addresses manipulative consent-banner design.

Claims (1):

  • CNPD cookie guidance addresses dark-pattern designs in consent banners, treating manipulative interface choices that pressure users toward accepting non-essential cookies as a compliance risk under the cookie-consent framework.

Opt Out SignalsRed

No LU-specific opt-out-signal finding located this pass.

Clean Rooms And DcrRed

No LU-specific clean-room/DCR finding located this pass.

Cross Context AdvertisingGreen

The Amazon fine centred on cross-context targeted-advertising practices lacking a valid legal basis.

Claims (1):

  • The CNPD's €746 million decision against Amazon Europe Core centred on the company's targeted (cross-context) advertising practices, which the authority found lacked a valid GDPR Article 6(1) legal basis.

Direct MarketingRed

No LU-specific direct-marketing consent/suppression finding located this pass.

Category narrative59 words

CNPD's dedicated cookie guidelines address both consent architecture and dark patterns in banners; the Amazon decision independently evidences enforcement against cross-context/targeted-advertising practices lacking a valid legal basis. Opt-out signals (GPC/DAA-equivalent), clean-room/data-collaboration-room rules and direct-marketing consent/suppression specifics were not independently evidenced this pass (searched: 'CNPD Global Privacy Control opt-out signal', 'CNPD direct marketing guidance', 'CNPD clean room data collaboration guidance').

Periodic update · new data 2026-09-28

AdTech & Commercial Privacy

The Luxembourg Administrative Appeal Court's 12 March 2026 ruling is this cycle's central adtech development. The court upheld the CNPD's substantive finding that Amazon's use of legitimate interests to justify behavioural advertising was not a legally valid basis for that processing, a finding that stands as a confirmed precedent for how Luxembourg's courts read the legitimate-interests basis against behavioural-advertising practices generally, not solely against Amazon. At the same time, the court annulled the associated EUR 746 million fine, so the practical commercial consequence of the ruling is currently split: the legal-basis question is settled against the adtech practice at issue, while the financial sanction attached to it has been set aside pending fresh analysis.

For any commercial actor relying on legitimate interests to support cross-context behavioural advertising involving Luxembourg data subjects, the upheld substantive finding is the more durable and more directly relevant signal than the annulled fine, since it speaks to the validity of the underlying legal basis rather than to sanction quantum. The annulment does not amount to a finding that the underlying practice was compliant; it reflects a procedural shortfall in how the CNPD reasoned its way to the fine amount, not a substantive vindication of the processing basis used.

Outlook

Whether the CNPD's forthcoming reconsideration produces a renewed fine, and at what level, is the open question carried into the next cycle. The substantive finding against legitimate interests as a basis for behavioural advertising is not itself under appeal or in doubt following this ruling, so commercial actors relying on that basis in Luxembourg should treat the underlying legal exposure as unresolved in the CNPD's favour even while the sanction quantum remains pending.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidance — CNPD guidelines on cookies and other trackers clarify consent requirements for essential and non-essential cookies, including analytical cookies.observed
  2. ProbableOneTrust DataGuidance — CNPD cookie guidance addresses dark-pattern designs in consent banners, treating manipulative interface choices that pressure users toward accepting non-essential cookies as a compliance risk under the cookie-consent framework.observed
  3. ConfirmedCNIL — The CNPD's €746 million decision against Amazon Europe Core centred on the company's targeted (cross-context) advertising practices, which the authority found lacked a valid GDPR Article 6(1) legal basis.observed

#

AI Act competent-authority designation and Art 22 baseline evidenced but the designation is still at bill stage; biometric/genetic/profiling/surveillance carve-out sub-modules unevidenced.

Primary frameworkGDPR Article 22; EU AI Act (Regulation (EU) 2024/1689); draft Luxembourg AI Act implementing Bill No. 8476
Traffic-light rationale — AmberAI Act competent-authority designation and Art 22 baseline evidenced but the designation is still at bill stage; biometric/genetic/profiling/surveillance carve-out sub-modules unevidenced.

Sub-modules (6)

Profiling RestrictionsRed

No dedicated LU-specific profiling-restriction finding beyond Art 21/22 baseline located this pass.

Automated Decision Making TransparencyAmber

GDPR Art 22 applies directly, enforced by CNPD.

Claims (1):

  • GDPR Article 22's restrictions on solely automated decision-making with legal or similarly significant effects apply directly in Luxembourg as EU law, enforced by the CNPD under the Loi du 1er août 2018's institutional framework.

Ai Risk AssessmentsAmber

Draft Bill No. 8476 would designate CNPD as AI Act market-surveillance authority/notified body for law-enforcement, immigration and asylum AI systems.

Claims (1):

  • Luxembourg's draft AI Act implementing bill (No. 8476), introduced 23 December 2024, proposes designating the CNPD as the market-surveillance authority and notified body for high-risk AI systems used by law-enforcement, immigration, or asylum authorities, and amends the Act organising the CNPD and the general data-protection regime accordingly.

Biometric RegimeRed

No LU-specific biometric-regime finding located this pass.

Genetic DataRed

No LU-specific genetic-data regime finding located this pass.

State Surveillance CarveoutsRed

No LU-specific state-surveillance carve-out finding located this pass.

Category narrative88 words

GDPR Article 22 ADM restrictions apply directly as EU law. Luxembourg's draft AI Act implementing bill (No. 8476, introduced 23 December 2024) would designate the CNPD as market-surveillance authority/notified body for high-risk AI systems used by law-enforcement, immigration or asylum authorities, and would amend the CNPD organisation act; enactment status was not reconfirmed this pass. Biometric regime, genetic data, general profiling restrictions and state-surveillance carve-outs were not independently evidenced with LU-specific material (searched: 'CNPD facial recognition biometric guidance', 'CNPD genetic data guidance', 'Luxembourg national security data protection exemption').

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ProbableOneTrust DataGuidance — Luxembourg's draft AI Act implementing bill (No. 8476), introduced 23 December 2024, proposes designating the CNPD as the market-surveillance authority and notified body for high-risk AI systems used by law-enforcement, immigration, or asylum authorities, and amends the Act organising the CNPD and the general data-protection regime accordingly.observed
  2. ProbableEUR-Lex (National Implementing Measure record) — GDPR Article 22's restrictions on solely automated decision-making with legal or similarly significant effects apply directly in Luxembourg as EU law, enforced by the CNPD under the Loi du 1er août 2018's institutional framework.observed

#

Age-of-consent/parental-consent baseline evidenced via GDPR Art 8 generic guidance; no confirmed LU-specific derogation and other sub-modules unevidenced.

Primary frameworkGDPR Article 8
Traffic-light rationale — AmberAge-of-consent/parental-consent baseline evidenced via GDPR Art 8 generic guidance; no confirmed LU-specific derogation and other sub-modules unevidenced.

Sub-modules (5)

Age VerificationRed

No LU-specific age-verification mechanism finding located this pass.

Minor Profiling BansRed

No LU-specific minor-profiling-ban finding located this pass.

Education SettingsRed

No LU-specific education-settings finding located this pass.

Dependent AdultsRed

No LU-specific dependent-adults finding located this pass.

Category narrative76 words

GDPR Article 8's default digital-consent age of 16 applies absent an identified LU derogation lowering it toward the permitted 13-16 range; no such derogation was located in this pass. Parental-consent mechanics beyond the Art 8 baseline, minor-profiling bans, education-settings-specific rules and dependent-adult protections were not independently evidenced with LU-specific material (searched: 'Luxembourg data protection law digital age of consent minors derogation', 'CNPD minor profiling guidance', 'CNPD education sector children data guidance', 'Luxembourg dependent adults data protection').

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. ConfirmedEDPB — Under GDPR Article 8, children aged 16 and above can consent to information-society-service processing on their own behalf, while for children below 16 the controller must obtain consent from a parent or legal guardian, subject to Member States' ability to lower this threshold to as low as 13 by national law.observed

#

Landmark enforcement action, its collective-complaint origin, and a within-180-day legislative development are all well evidenced; funding/capacity and private-right-of-action detail are gaps.

Primary frameworkGDPR Chapter VI-VIII (Articles 77-84), given institutional effect via the Loi du 1er août 2018
Traffic-light rationale — GreenLandmark enforcement action, its collective-complaint origin, and a within-180-day legislative development are all well evidenced; funding/capacity and private-right-of-action detail are gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

CNPD exercises GDPR Chapter VI powers up to statutory fine maxima, illustrated by the Amazon decision.

Claims (1):

  • The CNPD exercises GDPR Chapter VI investigative and corrective powers and can impose administrative fines up to GDPR maxima, as illustrated by its €746 million fine against Amazon Europe Core on 16 July 2021, an amount described as unprecedented in scale and marking a turning point in GDPR enforcement.

Enforcement Activity IndexAmber

The Amazon decision is the sole large-scale enforcement action independently confirmed this pass; broader 12-month activity statistics were not retrieved.

Regulator Funding And CapacityRed

No LU-specific funding/headcount data located this pass.

Collective Redress And Class ActionsGreen

The Amazon matter originated from a collective complaint under the GDPR one-stop-shop cooperation mechanism.

Claims (1):

  • The Amazon Europe Core case originated from a collective complaint lodged with the French CNIL by the advocacy group La Quadrature du Net, which was handled by the CNPD as lead supervisory authority under the GDPR's cooperation procedures because Amazon Europe Core is established in Luxembourg.

Private Right Of ActionRed

No LU-specific procedural detail on direct judicial recourse (GDPR Art 79) located this pass.

Recent Developments 180DGreen

Luxembourg's NIS2 transposition law entered into force 10 May 2026, within the 180-day window.

Claims (1):

  • On 5 May 2026, Luxembourg's Official Journal published the Law of 5 May 2026 transposing the NIS2 Directive, which entered into force on 10 May 2026 and designates the Institut Luxembourgeois de Régulation (ILR) — not the CNPD — as the competent cybersecurity supervisory authority, with self-registration required for essential/important entities.
Category narrative117 words

CNPD's headline enforcement action is the 16 July 2021 €746 million fine against Amazon Europe Core — among the largest GDPR fines issued to date — originating from a collective complaint lodged with CNIL by La Quadrature du Net and transferred to CNPD as lead authority under the GDPR cooperation mechanism; the decision remains partly under judicial challenge. Luxembourg's Law of 5 May 2026 transposing NIS2 is the most recent (within 180 days) legislative development touching the broader data-governance/cybersecurity landscape, though its supervisory authority (ILR) sits outside CNPD's remit. Regulator funding/capacity metrics and private-right-of-action procedural detail were not independently evidenced this pass (searched: 'CNPD annual report budget staff', 'Luxembourg GDPR Article 79 private right of action procedure').

Periodic update · new data 2026-09-28

Enforcement & Redress

Two developments define this cycle for Luxembourg's enforcement and redress landscape. First, the Administrative Appeal Court's 12 March 2026 ruling annulled the CNPD's EUR 746 million Amazon fine, holding that the CNPD had not established the fault or negligence that Article 83 requires, an evidentiary standard clarified by the CJEU's Deutsche Wohnen ruling, and remanding the case for fresh sanction analysis. This is a confirmed, in-force development with high materiality: it signals that Luxembourg courts will now demand explicit fault-based reasoning before upholding large administrative fines, raising the evidentiary bar the CNPD must clear in future high-value sanctions, even as it leaves the underlying substantive finding against Amazon's processing basis intact.

Second, and separately, the Law of 20 November 2025, in force from 25 November 2025, transposes Directive (EU) 2020/1828 and grants the CNPD standing as a qualified entity able to bring collective consumer actions for GDPR-based harms. This is a new redress mechanism layered on top of the CNPD's existing enforcement powers, giving the regulator a route to pursue collective, rather than only individual or CNPD-initiated administrative, remedies for GDPR-based harms affecting Luxembourg consumers.

Against this backdrop, the CNPD's ordinary 2025 enforcement activity, seven corrective measures including six fines from EUR 1,277 to EUR 175,000, concentrated on records-of-processing-activities compliance and video-surveillance proportionality, describes a steady enforcement cadence well below the scale of the Amazon matter, and should be read as the regulator's baseline activity level rather than as evidence of a shift in enforcement priorities.

Outlook

The Amazon remand leaves open both the timing and quantum of any renewed fine; the CNPD's need to produce fault-based reasoning under the post-Deutsche Wohnen standard is likely to slow, without necessarily preventing, a fresh sanction. Separately, the practical significance of the CNPD's new collective-redress standing will depend on whether and how it is used in a first case; no such case had been identified as brought this cycle.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ConfirmedCNIL — The CNPD exercises GDPR Chapter VI investigative and corrective powers and can impose administrative fines up to GDPR maxima, as illustrated by its €746 million fine against Amazon Europe Core on 16 July 2021, an amount described as unprecedented in scale and marking a turning point in GDPR enforcement.observed
  2. ConfirmedCNIL — The Amazon Europe Core case originated from a collective complaint lodged with the French CNIL by the advocacy group La Quadrature du Net, which was handled by the CNPD as lead supervisory authority under the GDPR's cooperation procedures because Amazon Europe Core is established in Luxembourg.observed
  3. ConfirmedOneTrust DataGuidance — On 5 May 2026, Luxembourg's Official Journal published the Law of 5 May 2026 transposing the NIS2 Directive, which entered into force on 10 May 2026 and designates the Institut Luxembourgeois de Régulation (ILR) — not the CNPD — as the competent cybersecurity supervisory authority, with self-registration required for essential/important entities.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct50.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Luxembourg
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 27 claim(s) (27 category placement(s)), 21 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy granted
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. Strong T1/T2 evidence (EDPB primary guidance, EUR-Lex national-law record, CSSF coordinated text, CNIL reporting on CNPD's Amazon decision, CNPD's own cookie guidance and DPO decision) anchors regulator_and_framework, lawful_processing_and_special_data (lawful bases/consent/special categories), data_subject_rights (access/rectification/erasure/objection via the Amazon case), controller_processor_duties (accountability, DPO independence, NIS2 security overlay), sectoral_watch (financial, telecoms), adtech_and_commercial_privacy (cookies, dark patterns, cross-context advertising), algorithmic_biometric_and_surveillance_governance (Art 22 baseline, pending AI Act designation), children_and_vulnerable_groups (Art 8 baseline) and enforcement_and_redress (fine powers, collective-complaint origin, 180-day NIS2 development). Modules/sub-modules relying on T3/T4 or carrying explicit absent_field_provenance gaps: pseudonymisation/anonymisation; data portability and deadlines; ROPA, joint-controller, GDPR-breach-notification and retention/disposal; adequacy/SCC/BCR/TIA/localisation detail; health, employment, credit-scoring, education sector overlays and the still-pending insurance designation; opt-out signals, clean rooms, direct marketing; biometric regime, genetic data, profiling restrictions, state-surveillance carve-outs, age-verification mechanics beyond the Art 8 baseline, minor-profiling bans, education-settings and dependent-adults protections; regulator funding/capacity and private-right-of-action procedural detail.

Unresolved questions (7):

  • Has Luxembourg's AI Act implementing Bill No. 8476 (designating CNPD, ILNAS/CGPD, Insurance Commission and CSSF as AI Act competent authorities) been enacted, and if so with what effective date?
  • Does Luxembourg apply any national derogation to the GDPR Article 8 digital-consent age (potentially as low as 13), or does the default of 16 apply unmodified?
  • What are CNPD's current ROPA, joint-controller, GDPR Article 33/34 breach-notification and data-retention/disposal guidance positions specifically for Luxembourg-established controllers?
  • What CNPD-specific guidance exists on adequacy reliance, SCC/BCR uptake, and transfer-impact-assessment practice for Luxembourg controllers post-Schrems II?
  • Are there Luxembourg sector-specific data-protection rules for health, employment, credit-scoring or education beyond general GDPR application?
  • What is CNPD's current annual budget, headcount, and 12-month enforcement-activity volume (beyond the headline Amazon decision)?
  • What is the current appellate status of the CNPD's €746 million Amazon Europe Core decision following the Administrative Tribunal's partial stay?

Escalate to primary-source review: yes