EnglishDeutsch

Liechtenstein Data Privacy Laws: GDPR via EEA, DSG & Datenschutzstelle (2026)

By Recording Law Editorial TeamReviewed September 9, 202622 min read
Liechtenstein Data Privacy Laws: GDPR via EEA, DSG & Datenschutzstelle (2026)

Frequently Asked Questions

Does the GDPR apply in Liechtenstein?

Yes, fully. The GDPR applies in Liechtenstein through the EEA Agreement. It was incorporated by EEA Joint Committee Decision No. 154/2018 and became directly applicable on July 20, 2018. It has the same substantive legal force as in EU member states.

What is the DSG and how does it relate to the GDPR?

The Datenschutzgesetz (DSG) is Liechtenstein's national Data Protection Act, enacted October 4, 2018, in force since January 1, 2019. It supplements the GDPR by exercising national opening clauses in areas such as employment data, journalistic expression, video surveillance, national ID numbers, and criminal data. The DSV (Data Protection Ordinance) provides procedural implementing detail. The DSG also establishes criminal penalties for intentional data protection violations.

Who is Liechtenstein's data protection authority?

The Datenschutzstelle (DSS) is the independent supervisory authority. Its Commissioner is appointed by Parliament (Landtag) for a five-year renewable term. The DSS exercises the full range of GDPR investigative, corrective, and advisory powers, participates in the EDPB, and cooperates with EU supervisory authorities through the one-stop-shop mechanism.

What are the maximum penalties for data protection violations in Liechtenstein?

Administrative fines under the GDPR can reach EUR 20 million or 4% of worldwide annual turnover for serious violations. The DSG adds criminal penalties: up to six months' imprisonment or a fine of up to 360 daily units for intentional unauthorized processing, and up to one year's imprisonment for data secrecy violations committed for financial gain or with intent to harm.

Can personal data be transferred freely between Liechtenstein and EU countries?

Yes. As an EEA member, Liechtenstein is part of the GDPR's free data movement area. Personal data flows freely between Liechtenstein and all EU and EEA member states without transfer mechanisms or additional safeguards.

How does Liechtenstein handle data transfers to Switzerland?

Switzerland holds an EU adequacy decision, so personal data may be transferred from Liechtenstein to Switzerland without additional safeguards. This is especially significant given the customs union, shared banking infrastructure, and close economic ties between the two countries.

Are there special data protection rules for Liechtenstein's financial sector?

There are no sector-specific data protection laws. Standard GDPR and DSG rules apply, with financial sector laws referencing them. The Banking Act's Article 64a adds a parallel breach notification requirement for banks. Where mandatory legal obligations apply (such as AML reporting or CRS tax exchange), those obligations provide a GDPR-compliant legal basis that may override individual rights such as erasure within their defined scope.

Does Liechtenstein's blockchain law create data protection exemptions?

No. The TVTG (Blockchain Act) creates a legal framework for the token economy but does not create exemptions from the GDPR or DSG. Blockchain businesses must comply with standard data protection rules. The EDPB's April 2025 blockchain guidelines recommend avoiding on-chain storage of personal data, using off-chain storage and encryption, and designing erasure capability into systems from the outset.

Does the EU AI Act apply in Liechtenstein?

Not yet formally. As of May 2026, the EU AI Act (Regulation 2024/1689) is under review for incorporation into the EEA Agreement. Liechtenstein participates in EU AI Board meetings as an observer. Liechtenstein signed the Council of Europe's AI Treaty in February 2025, though ratification is still under examination. Once the AI Act is incorporated, it will apply in Liechtenstein with EEA adaptations.

Is a data protection officer (DPO) required in Liechtenstein?

Yes, in the same circumstances as GDPR Article 37(1): public authorities and bodies, organizations whose core activities involve large-scale regular and systematic monitoring, and organizations processing large-scale special category or criminal data. Voluntary appointment is permitted and common. The DPO may be internal or an external service provider. The DSG does not add mandatory appointment scenarios beyond the GDPR defaults.

Updates

AI Act dates updated for the July 2026 Digital Omnibus: full applicability is now 2 August 2028, with high-risk obligations applying 2 December 2027 (Annex III) and 2 August 2028 (Annex I); the 2 August 2026 transparency date is unchanged.

Full refresh: expanded to cover DSS 2024-2026 activities (annual report, EDPB right-to-erasure CEF, AI guidance, case law digests), EDPB blockchain guidelines 02/2025, EU AI Act EEA incorporation status, Council of Europe AI Treaty, criminal penalties under DSG, DPO requirements, constitutional basis, financial sector detail (Banking Act Art. 64a, AML, CRS), and DSV ordinance.

Initial publication covering GDPR EEA incorporation, DSG national derogations, Datenschutzstelle powers, cross-border transfers, and financial sector overview.

Sources and References

  1. Datenschutzstelle (DSS) - Official Website(datenschutzstelle.li).gov
  2. DSS Tätigkeitsbericht 2024(datenschutzstelle.li).gov
  3. DSS National Laws (DSG, DSV)(datenschutzstelle.li).gov
  4. DSS EDPB CEF Right to Erasure 2025(datenschutzstelle.li).gov
  5. DSS AI and Data Protection Guidance September 2025(datenschutzstelle.li).gov
  6. Liechtenstein DSG English Text PDF(datenschutzstelle.li).gov
  7. EEA Joint Committee Decision No. 154/2018(efta.int).gov
  8. EFTA EEA Lex EU AI Act Incorporation Status(efta.int).gov
  9. EDPB Guidelines 02/2025 on Blockchain(edpb.europa.eu).gov
  10. European Data Protection Board EDPB(edpb.europa.eu).gov
  11. Liechtenstein DSG LGBl 2018.272(gesetze.li).gov
  12. Liechtenstein Financial Market Authority FMA(fma-li.li).gov
  13. VMR Liechtenstein AI and Council of Europe Treaty(menschenrechte.li)
  14. EFTA How EU Law Becomes EEA Law(efta.int).gov
  15. Liechtenstein EEA Coordination Unit(llv.li).gov
  16. Mondaq Note on Financial Sector Data Protection Liechtenstein(mondaq.com)
  17. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
Share: