Law / Luxembourg

Luxembourg

European Union law applies in Luxembourg Luxembourg is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Luxembourg, described on this page below, applies here too.

All 15 named instruments researched to a stage, across all six areas of law we track: 14 in force and 1 proposed. As of 14 September 2026.

When they take effect9 of 15 carry a date, 6 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 6 instruments (6 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 2 instruments (2 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 proposed

Research summary (196 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Luxembourg and is not restated here as Luxembourg law. As of September 2026 Luxembourg has not yet enacted the national law the AI Act requires to designate its notifying authorities, market surveillance authorities and single point of contact, and to set national administrative-fine ceilings and procedure.

The Government's Projet de loi 8476, deposited 23 December 2024, would designate the Commission nationale pour la protection des donnees (CNPD) as the default market surveillance authority and single point of contact, with sector derogations to the judicial control authority, the Commission de surveillance du secteur financier, the Commissariat aux assurances, ILNAS, the Institut luxembourgeois de regulation, the Agence luxembourgeoise des medicaments et produits de sante, and the Autorite luxembourgeoise independante de l'audiovisuel (ALIA) for the Article 50 transparency and synthetic-content disclosure duties specifically.

As of the Chambre des Deputes' own consolidated dossier, the Conseil d'Etat delivered its opinion on 10 July 2026 and the bill remains before Parliament with no adoption recorded; Luxembourg has missed the EU AI Act's 2 August 2025 authority-designation deadline and its 2 August 2026 enforcement milestone without a formally designated national authority in force.

AI governance

Projet de loi 8476, National Designation of AI Act Authorities and Penalties

Projet de loi 8476 portant mise en oeuvre de certaines dispositions du reglement (UE) 2024/1689 (Luxembourg, depose le 23 decembre 2024, avis du Conseil d'Etat du 10 juillet 2026)Chambre des Deputes, official consolidated legislative dossier for Projet de loi 8476

Proposed: draft date not recorded. In committee, dated 10 July 2026, as of 12 September 2026. Binds public and private bodies.

What this law does

Not yet in force, as proposed.

The bill would designate the Commission nationale pour la protection des donnees (CNPD) as Luxembourg's default AI Act market surveillance authority and single point of contact, with derogations to the judicial control authority for AI systems used by courts, the Commission de surveillance du secteur financier for AI systems used by supervised financial entities, the Commissariat aux assurances for the insurance sector, the Institut luxembourgeois de la normalisation (ILNAS) for most other high-risk product categories, the Institut luxembourgeois de regulation for AI systems deployed by essential or important cybersecurity entities, the Agence luxembourgeoise des medicaments et produits de sante for medical-device AI, and the Autorite luxembourgeoise independante de l'audiovisuel (ALIA) specifically for the Article 50 bot and synthetic-content disclosure duties.

It would empower each market surveillance authority to impose a warning, a reprimand, or an administrative fine, and would set a fine of up to 35,000,000 euros or 7 percent of worldwide annual turnover for a breach of the Article 5 prohibited-practices ban, and up to 15,000,000 euros or 3 percent for a breach of the other operator and notified-body obligations the bill lists. The bill also requires the CNPD to stand up at least one AI regulatory sandbox by 2 August 2026.

As of the Chambre des Deputes' own consolidated dossier, the Conseil d'Etat delivered its opinion on 10 July 2026 and no vote or adoption is recorded.

What it requires

Privacy law6 instruments, 6 in force

Research summary (112 words)

Luxembourg's private-sector regime is the General Data Protection Regulation (GDPR) plus the Act of 1 August 2018 on the organisation of the National Data Protection Commission (CNPD) and the general data protection framework, in effect from 20 August 2018.

The notable finding for this jurisdiction is a genuine absence rather than a gap: a CMS Expert Guide entry states no specific provisions regarding biometrics are envisaged in the Act, so a voiceprint or faceprint captured for identification is governed by GDPR Article 9 alone, with no Luxembourg-specific addition. A GDPR Article 82 compensation claim is brought before the ordinary civil courts rather than the CNPD. As at 24 August 2026; later amendment is not independently confirmed.

Breach notification

GDPR Articles 33-34, Breach Notification in Luxembourg

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Luxembourg, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Act of 1 August 2018 derogation from this timeline is identified.

What it requires

Comprehensive regime

Act of 1 August 2018 on the Organisation of the CNPD and the General Data Protection Framework

Loi du 1er aout 2018 portant organisation de la Commission nationale pour la protection des donnees et du regime general sur la protection… des donneesCNPD official PDF (cnpd.public.lu)

In force since 20 August 2018. Binds public and private bodies.

What this law does

Luxembourg's private-sector regime is the General Data Protection Regulation (GDPR) plus the Act of 1 August 2018 on the organisation of the National Data Protection Commission (CNPD) and the general data protection framework, in effect from 20 August 2018, which repealed the prior 2 August 2002 data protection law. The Act supplies domestic derogations and procedural rules and establishes the CNPD's own organisation.

A CMS Expert Guide entry, read, states directly that no specific provisions regarding biometrics are envisaged in the Act, the genuine finding for this jurisdiction rather than a gap; see the sensitive-categories instrument below.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Luxembourg

Regulation (EU) 2016/679, Arts. 44-49Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Transferring personal data of a person in Luxembourg outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Act of 1 August 2018 derogation broadening or narrowing this is identified.

What it requires

Enforcement supervision

GDPR Articles 82-83 and CNPD Enforcement in Luxembourg

Regulation (EU) 2016/679, Arts. 82-83Secondary commentary (CMS) on the CNPD's administrative role and civil-court compensation route

In force since 25 May 2018. Binds public and private bodies.

What this law does

The CNPD is the supervisory authority for administrative enforcement (General Data Protection Regulation (GDPR) Article 83 fines), while a GDPR Article 82 compensation claim is brought before the ordinary civil courts (tribunal d'arrondissement) rather than the CNPD itself, per secondary commentary read. No Luxembourg-specific fine ceiling beyond the GDPR Article 83 maximum was identified.

What it requires

Sensitive categories

GDPR Article 9, Special Categories of Personal Data as Applied in Luxembourg

Regulation (EU) 2016/679, Art. 9CMS Expert Guide to Data Protection and Cyber Security Laws, Luxembourg entry

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. Luxembourg has no biometric-specific national derogation: a CMS Expert Guide entry states directly that no specific provisions regarding biometrics are envisaged in the Act of 1 August 2018, and that the general GDPR framework applies without a national addition. A voiceprint or faceprint captured for identification purposes is therefore governed in Luxembourg by GDPR Article 9 alone. No Luxembourg-specific voiceprint case or regulatory guidance is known.

What it requires

Scraping law3 instruments, 3 in force

Research summary (231 words)

Luxembourg has no scraping-specific statute, so general law governs each dimension separately, in addition to the EU-level text-and-data-mining exception in the Digital Single Market Directive researched at the European Union level.

The Code penal's articles 509-1 to 509-7 criminalize fraudulently accessing or remaining in a computer system, but the offence turns on defeating a security measure, so reading a public, unauthenticated page without circumventing an access control does not fit a plain reading of the text, and no reported Luxembourg case tests the point for scraping specifically.

Luxembourg's copyright statute, as amended in 2022 to transpose the Digital Single Market Directive, adds a national text-and-data-mining exception at article 10, points 15 and 16, permitting reproduction and extraction of lawfully accessible works for mining, subject to a rightholder's machine-readable opt-out for general use and without an opt-out for research organizations and public libraries, museums and archives.

The same statute confers a sui generis database right at article 67, letting a database producer forbid extraction or reuse of the whole or a substantial part of its contents. No Luxembourg court decision or statute is known addressing the enforceability of a browsewrap or clickwrap terms-of-service against a scraper, a scraping-specific unfair-competition or misappropriation doctrine, or the legal weight of a robots.txt directive.

Personal data scraped from a Luxembourg website remains subject to the same General Data Protection Regulation (GDPR) duties described under the privacy topic for this jurisdiction.

Computer misuse

Code penal, Computer Misuse Offences (Unauthorized Access, Interference, Data Introduction, Devices, Attempt, Association)

C.pen. arts. 509-1 a 509-7Code penal

In force. Binds public and private bodies.

What this law does

Article 509-1 punishes fraudulently accessing or remaining in all or part of an automated data-processing or transmission system with two months to two years of imprisonment and a fine of 500 to 25,000 euros, rising to four months to two years and 1,250 to 25,000 euros where data is suppressed or modified or the system's functioning is altered.

Because the offence's trigger is fraudulent access, a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision. Article 509-2 punishes intentionally interfering with or falsifying a system's functioning, and article 509-3 punishes intentionally introducing, suppressing, altering or (since a 2014 amendment) intercepting its data, each with three months to three years of imprisonment and 1,250 to 12,500 euros.

Article 509-4 raises the penalty to four months to five years and 1,250 to 30,000 euros where any of these offences causes a transfer of money or monetary value for economic gain, and article 509-5 punishes producing, selling, holding or distributing a device or electronic key intended to commit these offences at the same level. Attempt and participation in an association formed to commit these offences are punished the same as the completed offence, under articles 509-6 and 509-7.

What it requires

Copyright and text and data mining (TDM)

Loi du 18 avril 2001 sur les droits d'auteur, Text and Data Mining Exception (Art. 10, points 15 and 16)

Loi du 18 avril 2001 sur les droits d'auteur les droits voisins et les bases de donnees, art. 10, points 15 et 16, ajoutes par la loi du 1er avril 2022 portant transposition de la directive (UE) 2019/790Loi du 1er avril 2022 portant transposition de la directive (UE) 2019/790, official French text reproduced by WIPO Lex

In force. Binds public and private bodies.

What this law does

Article 10, point 16, added by the Loi du 1er avril 2022 transposing the Digital Single Market Directive, permits reproductions and extractions of lawfully accessible works for text and data mining without the rightholder's authorization, unless the rightholder has expressly and appropriately reserved that use, including by machine-readable means for content made available online.

Article 10, point 15 gives research organizations and publicly accessible libraries, museums, archives and film or sound heritage institutions the same permission for scientific research text and data mining, without being subject to that reservation. The statute defines text and data mining as any automated analytical technique to analyze text and data in digital form in order to generate information such as patterns, trends and correlations.

The amending law's own text does not state a specific entry-into-force day for these provisions beyond the Journal officiel publication mechanism.

What it requires

Database right

Loi du 18 avril 2001 sur les droits d'auteur, Sui Generis Database Right (Art. 67)

Loi du 18 avril 2001 sur les droits d'auteur, les droits voisins et les bases de donnees, art. 67Loi du 18 avril 2001 sur les droits d'auteur

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 11, 2025. Publisher's page: https://wipolex-res.wipo.int/edocs/lexdocs/laws/fr/lu/lu042fr-related_1.pdf?Expires=1765445499&Signature=li9A57DEqLUVkNQOfFD42GO7bnrn7kX9R8z…

In force since 3 May 2001. Binds public and private bodies.

What this law does

A database producer may forbid extraction or reuse of the whole, or a qualitatively or quantitatively substantial part, of the database's contents, and may also forbid the repeated and systematic extraction or reuse of insubstantial parts where that conflicts with normal exploitation of the database or unreasonably prejudices the producer's legitimate interests.

Extraction is defined as the permanent or temporary transfer of all or a substantial part of the contents to another medium by any means, and reuse as any form of making the contents available to the public, excluding public lending in both cases. The right, part of the original 2001 law implementing the EU Database Directive, is unaffected by the 2022 Digital Single Market transposition, which did not amend article 67.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (530 words)

Luxembourg's NIS2 transposition, the loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité, is enacted and in force. Signed on 5 May 2026, published in the Journal officiel (Mémorial A, No. 225) on 6 May 2026, and in force since 10 May 2026, it repeals (Article 30) the prior NIS1 transposition, the loi du 28 mai 2019, outright.

Article 12 binds an entité essentielle or entité importante, as Article 11 defines them against the Annexe I and Annexe II sector lists together with the medium-enterprise size threshold of Commission Recommendation 2003/361/EC, to appropriate and proportionate cybersecurity risk-management measures across ten baseline categories, transposing NIS2 Article 21; Article 14 binds the same entities to a graduated incident-notification clock to the competent authority (a 24-hour early warning, a 72-hour notification, and a final report within one month), transposing NIS2 Article 23.

Annexe II point 6 names an online-marketplace provider, an online-search-engine provider and a social-networking-services-platform provider among the digital providers both duties reach expressly, alongside the wider sector classes (energy, transport, health, digital infrastructure, banking, financial-market infrastructure, public administration and others) recorded here as law the lint does not yet reach rather than flagged on an unrelated activity.

The Institut luxembourgeois de régulation (ILR) is the general competent authority for cybersecurity and supervision under the law (Article 3); the Commission de surveillance du secteur financier (CSSF) is the competent authority instead for the banking sector and the financial-market-infrastructure sector, and for the digital-infrastructure and ICT-service-management sectors as far as CSSF's own supervision reaches, which is where DORA-covered financial entities are actually supervised rather than under a separate national row here.

Violation of Article 12 or Article 14 carries an administrative fine of up to EUR 10,000,000 or 2 percent of worldwide annual turnover for an essential entity, and up to EUR 7,000,000 or 1.4 percent of turnover for an important entity, whichever is higher in each case (Article 26(4)-(5)), mirroring NIS2 Article 34's two-tier structure exactly; the competent authority may also attach a daily astreinte capped at EUR 1,250 and EUR 25,000 in total (Article 26(7)), and enforcement runs through an administrative appeal (recours en réformation) to the tribunal administratif rather than through any private right of action or criminal offence.

No instrument reviewed here imposes a Luxembourg-specific product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here; no Luxembourg law designating a national market-surveillance authority under the Cyber Resilience Act (CRA) is confirmed in the primary text reviewed.

Luxembourg has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation, and personal-data breach notification under GDPR Articles 33-34 sits in the privacy topic rather than here, as does the Act of 1 August 2018 on the organisation of the CNPD.

A related but separate law of the same date, the loi du 5 mai 2026 sur la résilience des entités critiques, transposes the CER Directive's physical-resilience duties for critical entities and is not restated here; it feeds Article 11(1)(6)'s essential-entity designation but does not itself carry a cybersecurity duty.

Sector security regimes

Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important Entities

Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité, Art. 11, 12, 13Loi du 5 mai 2026, Journal officiel du Grand-Duché de Luxembourg (Legilux), Art. 12

In force 4 months, effective 10 May 2026. Binds public and private bodies.

What this law does

Article 12 requires an entité essentielle (essential entity) or entité importante (important entity) to take technical, operational and organisational measures appropriate and proportionate to the risks threatening the security of the network and information systems it uses for its activities or services, and to eliminate or reduce the impact of incidents on the recipients of its services and on other services.

The measures must follow an all-hazards approach and cover at least ten categories: risk-analysis and information-system-security policy, incident handling, business continuity including backup and crisis management, supply-chain security, security in the acquisition, development and maintenance of systems including vulnerability handling and disclosure, evaluating the measures' own effectiveness, basic cyber-hygiene and training, cryptography and encryption policy, human-resources security, access control and asset management, and multi-factor or continuous authentication and secure communications, transposing NIS2 Article 21.

Annexe II point 6 names an online-marketplace provider, an online-search-engine provider and a social-networking-services-platform provider among the digital providers this duty reaches expressly. Annexe I point 10 separately reaches public-administration entities, as defined by Article 2. Article 13 requires the entity's management body to approve these measures and oversee their implementation, and states that the body may be held liable for the entity's violation of Article 12.

What it requires

Vulnerability and incident reporting

Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification

Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité, Art. 14Loi du 5 mai 2026, Journal officiel du Grand-Duché de Luxembourg (Legilux), Art. 14

In force 4 months, effective 10 May 2026. Binds public and private bodies.

What this law does

Article 14 requires an entité essentielle or entité importante to notify the competent authority, without undue delay, of any incident with a significant impact on the provision of its services (an incident important), and, where appropriate, to notify the recipients of its services of a significant incident likely to affect the supply of those services.

An incident is significant if it has caused or is capable of causing severe operational disruption or financial loss to the entity, or has affected or is capable of affecting other natural or legal persons through considerable material, physical or moral damage.

The notification runs on a graduated clock: an early warning within 24 hours of becoming aware of the incident, a fuller notification within 72 hours giving an initial assessment of its severity and impact and any indicators of compromise, an intermediate report on request, and a final report within one month of the 72-hour notification (or a progress report followed by a final report if the incident is still ongoing at that point), transposing NIS2 Article 23.

A qualified trust-service provider notifies on the shorter 24-hour clock alone, by derogation. The mere act of notifying an incident does not itself increase the notifying entity's liability, and the competent authority forwards the notification to the relevant CSIRT and the single point of contact upon receiving it.

What it requires

Age gating law1 instrument, 1 in force

Research summary (109 words)

Luxembourg's principal age-gating duty was inserted into the loi modifiée du 27 juillet 1991 sur les médias électroniques by the loi du 26 février 2021 transposing the revised Audiovisual Media Services Directive, binding providers of audiovisual media services and providers of video-sharing platforms within Luxembourg's jurisdiction to restrict minors' access to harmful content, including through age-verification tools.

Digital Services Act Article 28, which imposes a separate platform-wide minor-protection duty, applies directly and is covered at EU level rather than restated here. No app-store-level age-verification statute, no age-appropriate design code distinct from this audiovisual framework, and no reported Luxembourg case testing either duty has been located in the sources checked.

Adult content age verification (AV)

Loi modifiée du 27 juillet 1991 sur les médias électroniques, art. 27ter et art. 28 septies (protection des mineurs / plateformes de partage de vidéos)

Loi modifiée du 27 juillet 1991 sur les médias électroniques art. 27ter et art. 28 septies, tels qu'insérés par la loi du 26 février 2021 (Mémorial A n° 174 de 2021) transposant la directive (UE) 2018/1808Loi du 26 février 2021 portant modification de la loi modifiée du 27 juillet 1991 sur les médias électroniques

In force. Binds private bodies.

What this law does

A provider of audiovisual media services must ensure that programs likely to harm minors' physical, mental or moral development are made available only under conditions that normally prevent minors from seeing or hearing them. A grand-ducal regulation sets the specific measures, which may include age-verification tools.

A provider of a video-sharing platform within Luxembourg's jurisdiction must take proportionate measures to protect minors from harmful programs, user-generated videos and audiovisual commercial communications. Those measures include systems to verify the age of users for content likely to cause such harm. Minors' personal data collected under either duty may not be processed for commercial purposes such as profiling or targeted advertising.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (218 words)

Luxembourg transposed the EU Digital Single Market Directive's press-publisher neighbouring right and text-and-data-mining exceptions through the Loi du 1er avril 2022, amending the Loi du 18 avril 2001 sur les droits d'auteur, les droits voisins et les bases de donnees.

New articles 56 bis and 56 ter give a press publisher established online reproduction and making-available rights over its publications, exempting hyperlinks and the use of single words or very short extracts, for a term of two years from the January following first publication, and give the publication's own authors a share of the compensation the publisher receives.

New points 15 and 16 of article 10 create a general text-and-data-mining exception subject to a rightholder opt-out, alongside a separate, non-waivable exception for research organizations and public libraries, museums and archives.

The original 2001 statute's article 10 also carries an older quotation exception and a current-events reporting exception, and excludes bare news-of-the-day items from authorial protection altogether; the current wording of those specific points is not described here. Luxembourg has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act.

No Luxembourg misappropriation doctrine distinct from the article 10 exceptions, and no Luxembourg case law on inline framing or hyperlinking distinct from the general EU position, was located in the sources checked.

Press publishers' right

Loi du 18 avril 2001 sur les droits d'auteur, Press Publisher Neighbouring Right (Art. 56 bis and 56 ter)

Loi du 18 avril 2001 sur les droits d'auteur les droits voisins et les bases de donnees, arts. 56 bis et 56 ter, ajoutes par la loi du 1er avril 2022 portant transposition de la directive (UE) 2019/790Loi du 1er avril 2022 portant transposition de la directive (UE) 2019/790, official French text reproduced by WIPO Lex

In force. Binds private bodies.

What this law does

Article 56 bis gives press publishers the reproduction and making-available rights of articles 43 and 44 for the online use of their press publications by information-society service providers. The right does not reach private or non-commercial use by individual users, acts of hyperlinking, or the use of isolated words or very short extracts of a press publication.

It expires two years after publication, counted from the January 1 following the date of first publication, and does not apply to a press publication first published before 6 June 2019.

Authors of works integrated in a press publication are entitled to an appropriate share of the revenue the publisher receives from information-society service providers, and article 56 ter makes any transfer or licence of an author's rights to a publisher a sufficient legal basis for the publisher to claim a share of statutory-exception compensation for uses of the work.

The amending law's own text does not state a specific entry-into-force day for these provisions beyond the Journal officiel publication mechanism.

Note and primary source

Text and data mining (TDM) opt-out

Loi du 18 avril 2001 sur les droits d'auteur, Text and Data Mining Exception for News Content (Art. 10, points 15 and 16)

Art. 10 points 15 et 16 (contenus de presse), de la loi du 18 avril 2001 sur les droits d'auteur, les droits voisins et les bases de donnees, ajoutes par la loi du 1er avril 2022 portant transposition de la directive (UE) 2019/790Loi du 1er avril 2022 portant transposition de la directive (UE) 2019/790, official French text reproduced by WIPO Lex

In force. Binds public and private bodies.

What this law does

Article 10, point 16 permits reproductions and extractions of lawfully accessible works, including news articles, for text and data mining without the rightholder's authorization, unless the rightholder has expressly reserved that use by an appropriate means, including a machine-readable reservation for content made available online.

Article 10, point 15 gives research organizations and public libraries, museums, archives and film or sound heritage institutions the same permission for scientific-research text and data mining, without being subject to that reservation. A news aggregator indexing or mining Luxembourg press content for purposes other than scientific research falls under the general, opt-out-able exception; a publisher's machine-readable reservation removes the exception's protection for that content.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.