What Is Law of 1 August 2018 on the Organisation of the CNPD and the General Data-Protection Framework?
Luxembourg’s principal national privacy statute is the Law of 1 August 2018 on the organisation of the CNPD and the general data-protection framework. It complements GDPR at national level and replaced the former general data-protection framework. The Law of 19 December 2025 concerning data sovereignty and the Data Governance Act entered into force on 26 December 2025. No other amending instrument was located, and the live consolidated Legilux text should be treated as controlling before publication. GDPR Articles 12-23 remain the baseline. Luxembourg’s national layers include a special regime for processing carried out solely for journalism, academic, artistic, or literary expression, as well as research derogations affecting Articles 15, 16, 18, and 21 where exercising the right would likely make the research purpose impossible or seriously impair it. The research regime requires safeguards including a DPO, DPIA, anonymisation or pseudonymisation, operational-function separation, encryption, access restrictions, logging, confidentiality, independent audits, and a documented data-management plan. No official Luxembourg data-broker opt-out form, registry-based suppression mechanism, or public-record-specific CNPD deletion route was located. A distinct Data Governance Act complaint route was found for alleged breaches by data-intermediation-service providers or data-altruism organisations, but it is not described as a general deletion mechanism for ordinary personal-data brokers.
At a glance
- Full name
- Law of 1 August 2018 on the Organisation of the CNPD and the General Data-Protection Framework
- Short code
- Law of 1 August 2018
- Jurisdiction
- Luxembourg
- Enacted
- 2018
- Last major update
- Law of 19 December 2025 concerning data sovereignty and the Data Governance Act entered into force on 26 December 2025; no other amending instrument was located
- Regulator
- National Commission for Data Protection (CNPD)
- Private right of action
- Limited
Scope, who Law of 1 August 2018 covers
Protected data
Data subject rights
Rights to transparency and information, with the standard GDPR one-month response period extendable by 2 further months with notice
Right of access, subject to journalism, expression, and research derogations
Right to rectification, subject to the research derogation where exercise would seriously impair the purpose
Right to erasure, subject to another lawful basis, statutory retention duty, or valid restriction
Right to restriction of processing, subject to the research derogation
Right to data portability; Article 63’s research provision does not list Article 20 as a derogated right
Right to object, subject to the research derogation
Right to complain to CNPD and appeal a CNPD decision to the Administrative Tribunal within 3 months of notification
Notable features
Luxembourg’s research derogation is unusually detailed: Article 65 safeguards include a DPO, DPIA, anonymisation or pseudonymisation, separation of operational functions, encryption, access restrictions, logging, confidentiality, independent audits, and a documented data-management plan. The law also has a Data Governance Act-related amendment that entered into force on 26 December 2025.
Enforcement & penalties
Regulator: National Commission for Data Protection (CNPD)
Penalties: GDPR Article 83 applies as the baseline, with fines of up to €10 million or 2% of turnover for the lower tier and up to €20 million or 4% for the upper tier. The State and municipalities are excluded from the general Article 83 administrative-fine provision. A periodic penalty payment of up to 5% of average daily turnover per day may apply to specified information or corrective-measure non-compliance. Wilfully preventing or impeding CNPD duties is a criminal offence punishable by imprisonment of 8 days to 1 year and/or a fine of €251 to €125,000.
Private right of action: A 3-month appeal route to the Administrative Tribunal after notification of a CNPD decision is the identified mechanism; no separate Luxembourg-specific general private-action route was identified.
Relevance to data brokers
No official Luxembourg data-broker opt-out form, registry-based suppression mechanism, or public-record-specific CNPD deletion route was located. The general route is to exercise GDPR rights, including Article 17 erasure, against the relevant controller and then complain to CNPD under GDPR Article 77 if needed. CNPD also describes a Data Governance Act complaint route for alleged breaches by data-intermediation-service providers or data-altruism organisations, but it is not a general deletion mechanism for ordinary personal-data brokers.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Luxembourg have a dedicated data-broker deletion route?+
Not located. The identified route is to exercise GDPR rights against the relevant controller, including Article 17 erasure, and then complain to CNPD under GDPR Article 77 if needed.
What safeguards apply to Luxembourg research derogations?+
Article 65 safeguards include a DPO, DPIA, anonymisation or pseudonymisation, operational-function separation, encryption, access restrictions, logging, confidentiality, independent audits, and a documented data-management plan.
Was Luxembourg’s privacy law amended in 2025?+
Yes. The Law of 19 December 2025 concerning data sovereignty and the Data Governance Act modified the 2018 law and entered into force on 26 December 2025.
Official sources & citations
Other international privacy regimes
Law of 1 August 2018 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
