EnglishFrançais
Luxembourg flag

Luxembourg

Luxembourg Data Privacy Laws: GDPR, CNPD & the Amazon Fine (2026)

By Recording Law Editorial TeamReviewed May 20, 202628 min read
Luxembourg Data Privacy Laws: GDPR, CNPD & the Amazon Fine (2026)

Frequently Asked Questions

What is the main data protection law in Luxembourg?

Luxembourg's data protection framework rests on the EU GDPR, which applies directly, and the national Law of 1 August 2018. That national law establishes the CNPD's structure and powers, sets national rules where the GDPR allows member-state flexibility, and fixes the digital age of consent at 16 years. A second Law of 1 August 2018 covers data processing in criminal matters and national security, implementing EU Directive 2016/680. The 2023 Constitution now expressly guarantees both the right to privacy (Article 20) and the right to personal data protection (Article 31).

What happened to the EUR 746 million Amazon GDPR fine?

The CNPD imposed the fine on Amazon Europe Core S.à r.l. on 15 July 2021 for processing personal data for targeted advertising without a valid legal basis. Luxembourg's Administrative Tribunal upheld the fine in full on 18 March 2025. Amazon then appealed to the Court of Appeal, which annulled the fine on 12 March 2026 on procedural grounds: the CNPD had not assessed negligence, had not conducted a genuine proportionality analysis, and had found a violation without giving Amazon a chance to respond. The underlying GDPR violations were largely confirmed at every stage. The case was sent back to the CNPD to issue a fresh analysis and potentially a new penalty. Amazon has already brought its practices into compliance.

What are the data breach notification requirements in Luxembourg?

Data controllers must notify the CNPD within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to individuals. Notifications go to databreach@cnpd.lu. If the breach poses a high risk to individuals's rights and freedoms, affected data subjects must also be notified without undue delay. All breaches must be documented in an internal register, regardless of whether they are reportable. Processors must notify their controller without undue delay so the controller can meet the 72-hour window.

What special data privacy rules apply to Luxembourg's financial sector?

Financial institutions must comply with both the GDPR and the professional secrecy obligations under Article 41 of the Law of 5 April 1993 on the financial sector. Article 458 of the Luxembourg Criminal Code makes unauthorised disclosure of client data a criminal offence, carrying a prison term of 8 days to 6 months and fines of EUR 500 to EUR 5,000. These criminal sanctions apply in addition to GDPR administrative fines. Exceptions permit disclosure for anti-money laundering, court orders, and tax exchange-of-information obligations, but financial institutions must verify each disclosure against both frameworks.

What is the CNPD's role in the EU AI Act?

Luxembourg Bill of Law 8476, submitted in December 2024, designates the CNPD as Luxembourg's primary national market surveillance authority for the EU AI Act (Regulation (EU) 2024/1689). The CNPD will supervise AI systems deployed in Luxembourg, coordinate sector-specific authorities, and serve as the primary point of contact with EU AI institutions. This designation builds on the CNPD's data protection expertise, given that AI systems heavily depend on personal data processing.

What are the maximum GDPR fines that can be imposed in Luxembourg?

The CNPD can impose fines at two tiers. For violations of controller and processor obligations (Articles 8, 11, 25-39, 42, 43), the maximum is EUR 10 million or 2 % of global annual turnover, whichever is higher. For violations of core principles, data subject rights, or international transfer rules (Articles 5-7, 9, 12-22, 44-49), the maximum is EUR 20 million or 4 % of global annual turnover. The CNPD also applies EDPB Guidelines 04/2022 on fines calculation and must now conduct an express proportionality analysis, as the Amazon appeal confirmed.

How do cross-border data transfers work from Luxembourg?

Within the EU and EEA, personal data flows freely. Transfers to third countries require one of: (1) a European Commission adequacy decision (as of early 2026, 16 countries are covered, including the US under the EU-US Data Privacy Framework and, since February 2026, Brazil); (2) Standard Contractual Clauses with a Transfer Impact Assessment; (3) Binding Corporate Rules approved by the CNPD; or (4) other derogations under Article 49. Financial institutions must also ensure that transfers comply with professional secrecy obligations, which may require additional contractual protections beyond the SCCs.

Updates

Major refresh: added EU AI Act overlay, Luxembourg bill 8476, Sandkëscht AI sandbox, 2023 constitution Articles 20 and 31, full Amazon appeal timeline through Court of Appeal annulment (March 2026) and CNPD reconsideration, Digital Sovereignty 2030 strategy, February 2024 investigation procedure regulations, and Brazil-EU adequacy decision.

Initial publication.

Sources and References

  1. CNPD - National Legislation Overview(cnpd.public.lu).gov
  2. CNPD - Official Statement on Court of Appeal Amazon Ruling (March 2026)(cnpd.public.lu).gov
  3. CNPD - Amazon Decision Announcement (March 2025)(cnpd.public.lu).gov
  4. CNPD - Data Breach Notification Guidance(cnpd.public.lu).gov
  5. CNPD - Annual Reports(cnpd.public.lu).gov
  6. CNPD - AI Act Obligations (August 2025)(cnpd.public.lu).gov
  7. CNPD - National Implementation of the AI Act (November 2024)(cnpd.public.lu).gov
  8. EUR-Lex - General Data Protection Regulation(eur-lex.europa.eu).gov
  9. EUR-Lex - EU AI Act (Regulation 2024/1689)(eur-lex.europa.eu).gov
  10. EDPB - Guidelines 04/2022 on Calculation of Administrative Fines(edpb.europa.eu).gov
  11. CSSF - Commission de Surveillance du Secteur Financier(cssf.lu).gov
  12. Arendt - Luxembourg Bill 8476 and AI Act(arendt.com)
  13. European Commission - Adequacy Decisions for Third Countries(commission.europa.eu).gov
Share: