Law / Liechtenstein

Liechtenstein

15 of 18 named instruments researched to a stage, across five of the six areas of law we track: 15 in force. As of 15 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 4
  4. Cybersecurity law 2
  5. Age gating law 2
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (125 words)

Liechtenstein is not an EU member; it is an EEA/EFTA state, so the General Data Protection Regulation (GDPR) does not apply directly. The controlling instrument is Liechtenstein's own Datenschutzgesetz (DSG), LGBl. 2018 Nr. 272, in effect since 1 January 2019, which gives domestic legal effect to the GDPR as incorporated into the EEA Agreement by EEA Joint Committee Decision No. 154/2018.

Two attempts to extract the DSG's own statutory text failed, so most findings below rest on the Datenschutzstelle's own first-party glossary of GDPR-equivalent concepts (which does name voice and images within the biometric-data concept it applies) or on structural inference from the DSG's GDPR-modeled design, and are recorded at medium confidence throughout rather than as primary-text findings. As at 24 August 2026; later amendment is not independently confirmed.

Breach notification

DSG Breach Notification in Liechtenstein

DSG, LGBl. 2018 Nr. 272, breach notification provisionsSecondary commentary and Datenschutzstelle materials, not independently confirmed against the DSG's own text

In force since 1 January 2019. Binds public and private bodies.

What this law does

Commentary and the Datenschutzstelle's own materials describe the DSG as carrying breach-notification duties mirroring the General Data Protection Regulation (GDPR) structure, notifying the Datenschutzstelle without undue delay on a qualifying breach and notifying the individual where the breach presents a high risk. The specific timeline, whether it is GDPR's 72-hour figure or a different DSG-specific figure, was not independently confirmed against the DSG's own text.

What it requires

Comprehensive regime

Datenschutzgesetz (DSG)

Datenschutzgesetz (DSG), LGBl. 2018 Nr. 272, dated 4 October 2018, in effect 1 January 2019gesetze.li official legislation database (navigation only, statutory text not extracted)

In force since 1 January 2019. Binds public and private bodies.

What this law does

Liechtenstein is not an EU member; it is an EEA/EFTA state, so the General Data Protection Regulation (GDPR) does not apply directly. GDPR was incorporated into the EEA Agreement by EEA Joint Committee Decision No. 154/2018, and Liechtenstein gave that incorporation domestic legal effect through its own Datenschutzgesetz (DSG), LGBl. 2018 Nr. 272, in effect 1 January 2019 together with the implementing Datenschutzverordnung (DSV) of 11 December 2018. The DSG, not the EU Regulation, is recorded here as the controlling instrument.

The Datenschutzstelle is Liechtenstein's national data protection authority. The DSG's own statutory text is not extractable from either channel located, gesetze.li serving a navigation-only page and the Datenschutzstelle's official English translation PDF an unparseable compressed structure, so article-level detail below rests on the Datenschutzstelle's own first-party glossary of GDPR-equivalent concepts, or is described only in general, structural terms.

What it requires

Cross border transfer

DSG Cross-Border Transfer Chapter and EEA Joint Committee Decision No. 154/2018

Datenschutzgesetz (DSG), LGBl. 2018 Nr. 272; EEA Joint Committee Decision No. 154/2018DSG general structure, inferred by analogy to the GDPR framework it transposes

In force since 1 January 2019. Binds public and private bodies.

What this law does

The DSG carries its own transfer chapter, modeled on General Data Protection Regulation (GDPR) Chapter V, rather than being bound by the EU Regulation's Chapter V directly, since Liechtenstein is outside the EU.

Because Liechtenstein is inside the EEA and GDPR is incorporated EEA-wide, a transfer from Liechtenstein to an EU or EEA state is not a restricted cross-border transfer under this framework, by the same logic that intra-EU transfers are unrestricted under GDPR Chapter V itself; a transfer to a country outside the EEA is where the DSG's own adequacy, safeguards, or derogation mechanism engages. The DSG's own transfer-chapter article number and text were not independently confirmed against primary text.

What it requires

Data subject rights

DSG Automated-Decision Rights in Liechtenstein

DSG, LGBl. 2018 Nr. 272, automated decision provisionsSecondary commentary, not independently confirmed against the DSG's own text

In force since 1 January 2019. Binds public and private bodies.

What this law does

Secondary commentary describes the DSG as giving individuals rights against a decision based solely on automated processing, including profiling, that produces a significant legal or similarly significant effect, mirroring General Data Protection Regulation (GDPR) Article 22, with certain exceptions for contractual or insurance purposes. This was not independently confirmed against the DSG's own text, since both attempts to access the DSG's own document failed to extract readable content.

What it requires

Enforcement supervision

DSG Datenschutzstelle Enforcement in Liechtenstein

DSG, LGBl. 2018 Nr. 272, enforcement provisionsSecondary commentary, not independently confirmed against the DSG's own text

In force since 1 January 2019. Binds public and private bodies.

What this law does

The Datenschutzstelle enforces the DSG. One commentary source states violations may attract fines of up to 22 million Swiss francs or 4 percent of global annual turnover, a CHF-denominated figure tracking the General Data Protection Regulation (GDPR) EUR 20 million or 4 percent structure, since Liechtenstein uses the Swiss franc under its currency union with Switzerland rather than the euro; not independently confirmed against the DSG's own text.

By analogy to the GDPR Article 82 structure the DSG is modeled on, the DSG is expected to carry its own compensation provision for a data subject who suffers damage from a DSG infringement; the specific article number was not confirmed and this is recorded at medium confidence, by structural inference rather than a read of the provision itself. No Liechtenstein-specific collective-redress mechanism was identified.

What it requires

Sensitive categories

DSG Special-Category Data and Datenschutzstelle Biometric-Data Concept in Liechtenstein

DSG, LGBl. 2018 Nr. 272, special categories provisionsDatenschutzstelle glossary

In force since 1 January 2019. Binds public and private bodies.

What this law does

Biometric identifiers are governed by the DSG's own special-category-data provisions, modeled on General Data Protection Regulation (GDPR) Article 9. The Datenschutzstelle's own published glossary of GDPR-equivalent concepts names both voice and images within the biometric-data concept it applies, and separately notes that voice is treated as a behavioral characteristic, with the specific technical processing method determining whether a given voice capture rises to the level of unique-identification biometric data.

This is the regulator's own restatement of the concept, not a quote from the DSG's own statutory Article 4 text, which could not be accessed directly; it is recorded at medium confidence for that reason. No Liechtenstein-specific voiceprint or faceprint case or regulatory guidance beyond this glossary entry was located.

What it requires

Scraping law4 instruments, 4 in force

Research summary (98 words)

Liechtenstein has no scraping-specific statute. Unauthorized access to, and interference with, a computer system is reached by the Strafgesetzbuch's (StGB) computer-misuse chapter (§§ 118a, 126a to 126c).

Copyright and database protection are governed by the Urheberrechtsgesetz (URG), which carries a sui generis database right modeled on EU Directive 96/9/EC and a narrow set of copyright exceptions (private, non-commercial teaching and research use) with no text-and-data-mining-specific exception or opt-out mechanism of the kind EU Directive 2019/790 introduced.

No Liechtenstein-specific case law on the lawfulness of scraping a public page, on terms-of-service enforceability, or on robots.txt's legal weight was located.

Computer misuse

Strafgesetzbuch Art. 118a, Illegal Access to a Computer System

StGB, LGBl. 1988 Nr. 37, § 118a, inserted by LGBl. 2009 Nr. 228Strafgesetzbuch (StGB), official English translation, Office for Foreign Affairs website

In force. Binds public and private bodies.

What this law does

Any person who gains access to a computer system, or part of one, that they may not use or may not use alone, by overcoming specific security precautions, is punished with up to six months' imprisonment or a fine of up to 360 daily rates, if the purpose is to obtain personal data protected by a confidentiality interest or to inflict a disadvantage on another person by using data or the system.

The penalty rises to up to two years for an act against a computer system that is part of critical infrastructure, and up to two or three years respectively where committed as part of a criminal group. Prosecution requires the authorization of the aggrieved party. The provision reaches unauthorized access achieved by circumventing a technical access control; it does not by its terms reach the collection of data made available without any security precaution to overcome.

What it requires

Strafgesetzbuch Arts. 126a to 126c, Data Damage, System Interference and Misuse of Devices

StGB, LGBl. 1988 Nr. 37, §§ 126a-126c, inserted by LGBl. 2009 Nr. 228Strafgesetzbuch (StGB), official English translation, Office for Foreign Affairs website

In force. Binds public and private bodies.

What this law does

Section 126a punishes a person who damages another by changing, deleting, or otherwise making unusable or suppressing data not at that person's sole disposal, with up to six months' imprisonment or a fine of up to 360 daily rates, rising to up to two years where the damage exceeds CHF 7,500, up to three years for compromising a large number of systems with a purpose-built tool, and six months to five years for damage exceeding CHF 300,000 or an act against critical infrastructure or by a criminal group.

Section 126b punishes serious interference with a computer system's functioning on the same escalating structure. Section 126c punishes developing, distributing, or possessing a computer program or password evidently created to commit any of these offenses, or the offense at § 118a, with up to six months' imprisonment or a fine of up to 360 daily rates, with a defense for a person who voluntarily prevents the tool's use.

An aggressive scraping or crawling operation that changes, deletes, or degrades data or a system it does not control, or that uses a purpose-built tool to compromise a large number of systems, is reached by this chapter.

What it requires

Copyright and text and data mining (TDM)

Urheberrechtsgesetz Art. 22, Privileged Uses

URG, LGBl. 1999 Nr. 160, Art. 22Urheberrechtsgesetz (URG), official consolidated text, Liechtenstein legislation database (Lilex)

In force. Binds public and private bodies.

What this law does

Published works may be used without the rightsholder's authorization only for a closed list of privileged purposes: use within a personal or closely connected circle, illustration in teaching or non-commercial scientific research, photomechanical reproduction for teaching, research, or internal documentation in an institution, and non-commercial digital reproduction for teaching or research.

The article does not apply to computer programs, and it does not create a text-and-data-mining exception or a machine-readable opt-out mechanism of the kind EU Directive 2019/790 introduced; a use falling outside this closed list, including bulk reproduction of copyrighted text for commercial AI training or aggregation, requires the rightsholder's authorization under the general reproduction right (Art. 10).

What it requires

Database right

Urheberrechtsgesetz, Sui Generis Database Right

URG, LGBl. 1999 Nr. 160, Arts. 45-49 and 64Urheberrechtsgesetz (URG), official consolidated text, Liechtenstein legislation database (Lilex)

In force. Binds public and private bodies.

What this law does

The producer of a database that required a qualitatively or quantitatively substantial investment in obtaining, verifying, or presenting its contents has the right to prohibit the extraction or re-utilization of the whole, or a substantial part, of that database's contents (Art. 45), independent of any copyright in the database or its contents.

The right runs for 15 years from completion of the database (Art. 49), and belongs to a producer who is a national of, or habitually resident in, an EEA member state, or a company with a genuine link to one (Art. 46), reflecting the sui generis right's EEA-wide incorporation of EU Directive 96/9/EC.

A lawful user of a publicly available database may extract or re-utilize a non-substantial part without authorization for private use of a non-electronic database, for teaching or scientific research with attribution, or for public security or administrative or judicial proceedings (Art. 48).

Unauthorized extraction or re-utilization is a criminal offense on the aggrieved party's complaint, with up to one year's imprisonment or a fine of up to 360 daily rates, rising to up to three years for a commercial infringement (Art. 64).

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (743 words)

Liechtenstein's Cyber-Sicherheitsgesetz (CSG) of 5 December 2024 (LGBl. 2025 Nr. 111), in force since 1 February 2025, transposes NIS2 (Directive (EU) 2022/2555) and Regulation (EU) 2021/887 (the European Cybersecurity Competence Centre) and its Article 27 repealed the prior Cyber-Sicherheitsgesetz of 4 May 2023 (LGBl. 2023 Nr. 269).

Article 1 binds a public or private entity listed in Annex 1 or Annex 2 that qualifies as a medium or large company under Article 1064(2) or (3) of the Personen- und Gesellschaftsrecht (Persons and Companies Act) and provides its services or carries out its activities in Liechtenstein, and, regardless of size, a narrower set of entities the Act names expressly, including providers of public electronic communications networks or services, trust service providers, top-level-domain registries and DNS service providers, the sole provider of an essential service, an entity a disruption of which would materially affect public order, safety or health or cause a systemic risk, a critical-sector entity, a public administration body of the country, an entity designated critical under the CER Directive (Directive (EU) 2022/2557), and a domain-name registration service provider.

Annex 1's Digital Infrastructure sector separately names cloud-computing-service providers, data-centre-service providers, content-delivery-network operators, top-level-domain registries, trust service providers and DNS service providers (other than root-name-server operators) as entities this Act reaches regardless of size.

Only the digital-provider slice Annex 2 Item 6 names expressly, an online-marketplace provider, an online-search-engine provider and a social-networking-platform provider, is flagged on this jurisdiction's rows; the wider sector classes the Act also reaches (critical infrastructure across energy, transport, banking, health and digital infrastructure, and public administration) are recorded here as law the lint does not yet reach rather than flagged on an unrelated activity.

Article 4 requires an essential or important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the security of the network and information systems it uses and to prevent or minimise the impact of a security incident, covering at least ten baseline categories mirroring NIS2 Article 21, and Article 5 requires the entity's leadership body to approve and oversee those measures and attend, and offer staff, regular training.

Article 6 requires an essential or important entity to notify the Stabsstelle Cyber-Sicherheit (Cyber Security Office) of a significant security incident without delay, on a graduated clock mirroring NIS2 Article 23: an early warning within 24 hours of becoming aware, a full notification within 72 hours with an initial assessment and any indicators of compromise, an intermediate report on request, and a final report within one month of the 72-hour notification.

Article 23 sets the same two-tier fine structure NIS2 Article 34 specifies, denominated in Swiss francs: up to CHF 10,000,000 or 2 percent of worldwide group turnover, whichever is higher, for an essential entity's violation of Article 4 or Article 6, and up to CHF 7,000,000 or 1.4 percent for an important entity, imposed administratively by the Stabsstelle Cyber-Sicherheit where the conduct is not separately a criminal offence within the courts' jurisdiction.

The Stabsstelle Cyber-Sicherheit, under the Government's Prime Minister's Office, is the CSG's competent authority and hosts Liechtenstein's CSIRT.

The CSG's own Article 28 states that, until the EEA Joint Committee incorporates a listed EU act into the EEA Agreement, that act applies directly as national legislation, and names NIS2 (Directive (EU) 2022/2555) as the first such act; Article 29(2) accordingly holds back only Article 2(1)(a), the CSG's own formal declaration that it transposes NIS2, until that EEA Joint Committee decision, while the Article 4 and Article 6 duties documented here have applied as national law since 1 February 2025 regardless.

Whether the EEA Joint Committee has since adopted that incorporation decision is not confirmed in the primary text; the EFTA eea-lex tracker page for the directive is behind a Cloudflare CAPTCHA challenge, a stop rather than a wall to read past. The Cyber Resilience Act's incorporation into the EEA Agreement and implementation in Liechtenstein is likewise not confirmed.

Article 23(3) separately fines a manufacturer, provider or conformity-assessment body up to CHF 100,000 for violating Regulation (EU) 2019/881's European cybersecurity-certification framework (Articles 53, 55, 56 and 60), a voluntary certification scheme rather than a mandatory product-placement security duty, so no product_security_requirements instrument is coded from it.

No general reasonable-security or information-security-programme statute with no sector gate was found in the Liechtenstein law reviewed here. Liechtenstein's breach-notification duty for exposed personal data sits in the Datenschutzgesetz (DSG) and is documented as this jurisdiction's privacy-topic instrument rather than repeated here.

Sector security regimes

Cyber-Sicherheitsgesetz (CSG), Risk-Management Measures for Essential and Important Entities

Cyber-Sicherheitsgesetz (CSG) vom 5. Dezember 2024, LGBl. 2025 Nr. 111, Art. 1, 3, 4, 5Cyber-Sicherheitsgesetz (CSG), consolidated text, gesetze.li, Articles 1, 4 and 5

In force since 1 February 2025. Binds public and private bodies.

What this law does

Article 1 binds a public or private entity listed in Annex 1 or Annex 2 that qualifies as a medium or large company under Article 1064(2) or (3) of the Personen- und Gesellschaftsrecht (Persons and Companies Act) and provides its services or carries out its activities in Liechtenstein.

Article 4 requires such an essential or important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the security of the network and information systems it uses for its operations or to provide its services, and to prevent or minimise the impact of a security incident on the recipients of its services and on other services.

These measures must cover at least ten baseline categories mirroring NIS2 Article 21: risk analysis and information-system-security policy, incident handling, business continuity (including backup management and disaster recovery) and crisis management, supply-chain security, security in the acquisition, development and maintenance of systems including vulnerability management and disclosure, evaluating the measures' effectiveness, basic cyber-hygiene procedures and training, cryptography and encryption, personnel security and access control, and multi-factor or continuous authentication.

Article 5 requires the entity's leadership body (Leitungsorgan) to approve and oversee those measures and to attend, and offer its staff, regular training on recognising and assessing cybersecurity risk. Annex 2 Item 6 names an online-marketplace provider, an online-search-engine provider and a social-networking-platform provider among the digital-service providers this duty reaches expressly.

What it requires

Vulnerability and incident reporting

Cyber-Sicherheitsgesetz (CSG), Incident Notification

Cyber-Sicherheitsgesetz (CSG) vom 5. Dezember 2024, LGBl. 2025 Nr. 111, Art. 6Cyber-Sicherheitsgesetz (CSG), consolidated text, gesetze.li, Article 6

In force since 1 February 2025. Binds public and private bodies.

What this law does

Article 6 requires an essential or important entity to notify the Stabsstelle Cyber-Sicherheit (Cyber Security Office) of a significant security incident without delay.

It requires an early warning within 24 hours of becoming aware of the incident, stating where relevant whether it is suspected to result from unlawful or malicious acts or to have cross-border effect, followed by a full notification within 72 hours that updates that assessment with the incident's severity, impact and any indicators of compromise.

An intermediate report is due on the Office's request, and a final report is due within one month of the 72-hour notification, describing the incident, its cause and its mitigation in detail. Annex 2 Item 6 names an online-marketplace provider, an online-search-engine provider and a social-networking-platform provider among the digital-service providers this duty reaches expressly.

What it requires

Age gating law2 instruments, 2 in force

Research summary (120 words)

Liechtenstein has no dedicated adult-content age-verification statute, no social-media minor-access-restriction statute, and no app-store or device-level age-verification statute of the kind this topic otherwise tracks. Its Mediengesetz (MedienG) binds a video-sharing-platform provider to take appropriate measures protecting minors from content that could impair their physical, mental, or moral development, transposing EU Directive 2010/13/EU (AVMSD) Article 28b through EEA incorporation.

Separately, the general Kinder- und Jugendgesetz (KJG) binds a commercial provider of, or enabler of access to, a product or service (including a media product or service) that could endanger a minor, to take suitable and reasonable measures keeping a minor of the relevant age group from obtaining access. Neither provision reaches an adult-content-specific age-verification duty or a social-media account-age minimum.

Age-appropriate design code

Kinder- und Jugendgesetz Arts. 67-68, Child and Youth Protection for Products and Services

KJG, LGBl. 2008 Nr. 29, Arts. 67-68Kinder- und Jugendgesetz (KJG), official consolidated text, Liechtenstein legislation database (Lilex)

In force. Binds private bodies.

What this law does

A person who offers or presents a product or service, including a media product or service, that could endanger a minor's development or safety, and an entrepreneur who enables access to such a product or service, must take suitable and reasonable measures ensuring that minors of the relevant age group do not obtain access.

Audio-visual media products and services, in particular films and entertainment software, may only be offered to, or possessed and consumed by, a minor consistent with a minimum-age classification that a commercial provider must apply and clearly display, following reference-body recommendations designated by the Office for Social Services.

The Act's own general child-protection framework is expressly subordinate, for media specifically, to the media legislation's own child-protection provisions (the Mediengesetz above); it operates as the residual, non-media-specific duty for a product or service more broadly.

Note and primary source

Mediengesetz Art. 82c, Video-Sharing Platform Protection Duties

MedienG, LGBl. 2005 Nr. 250, Art. 82c, inserted by LGBl. 2023 Nr. 448Mediengesetz (MedienG), official consolidated text, Liechtenstein legislation database (Lilex)

In force. Binds private bodies.

What this law does

A video-sharing-platform provider, defined as a person who operates a video-sharing platform service, must take appropriate measures to protect minors from broadcasts, user-generated videos, and audiovisual commercial communication that could impair their physical, mental, or moral development.

It must also take appropriate measures to protect the general public from content whose dissemination is itself a criminal offense, including incitement to a terrorist act and child-pornography offenses under the Strafgesetzbuch. Disputes between users and a video-sharing-platform provider over compliance are mediated by Liechtenstein's regulatory authority (Art. 82d).

The Act's own enumerated list of administrative fines (Art. 93) does not separately name a breach of Art. 82c's protection duties themselves. The Act entered into force together with EEA Joint Committee Decision No. 337/2022 of 9 December 2022, without a further fixed commencement day stated in the consolidated text; it transposes Article 28b of Directive 2010/13/EU.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (118 words)

Liechtenstein's Urheberrechtsgesetz (URG) permits quoting a published work for explanation, reference, or illustration, and permits reproducing a short excerpt of a press article or a radio or television report for the purpose of informing about current issues, in each case with the source named.

The consolidated URG text, current as of 1 July 2026, names no press-publisher neighbouring right of the kind EU Directive 2019/790 Article 15 created and no compelled platform-to-publisher bargaining regime, notwithstanding that Directive 2019/790 has been incorporated into the EEA Agreement; it carries no provision naming a press publisher's own right or a designation or bargaining mechanism.

No Liechtenstein hot-news misappropriation doctrine, and no reported case on hyperlinking or framing liability, has been located.

Snippet reproduction

Urheberrechtsgesetz Arts. 27 and 31, Quotation and Reporting on Current Events

URG, LGBl. 1999 Nr. 160, Arts. 27 and 31

In force. Binds public and private bodies.

What this law does

Article 27 permits quoting a published work where the quotation serves explanation, reference, or illustration and its length is justified by that purpose, with the quotation and its source named. Article 31(2) separately permits reproducing, distributing, broadcasting, or retransmitting a short excerpt from a press article or a radio or television report for the purpose of informing about current issues, with the excerpt and its source named.

Together these are the exceptions an aggregator's reproduction of a headline or short excerpt of third-party journalism would rely on; both are scoped to a defined purpose (illustration or explanation; informing about current issues) and a source-attribution duty, not a general license to republish.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.