Law / Luxembourg

Act of 1 August 2018 on the Organisation of the CNPD and the General Data Protection Framework

Loi du 1er aout 2018 portant organisation de la Commission nationale pour la protection des donnees et du regime general sur la protection… des donnees

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 20 August 2018.

A comprehensive regime rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Luxembourg, including data collected by crawling.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Luxembourg's private-sector regime is the General Data Protection Regulation (GDPR) plus the Act of 1 August 2018 on the organisation of the National Data Protection Commission (CNPD) and the general data protection framework, in effect from 20 August 2018, which repealed the prior 2 August 2002 data protection law. The Act supplies domestic derogations and procedural rules and establishes the CNPD's own organisation.

A CMS Expert Guide entry, read, states directly that no specific provisions regarding biometrics are envisaged in the Act, the genuine finding for this jurisdiction rather than a gap; see the sensitive-categories instrument below.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

CNPD official PDF (cnpd.public.lu)
CMS Expert Guide to Data Protection and Cyber Security Laws, Luxembourg entry

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app