Liechtenstein

Microstate with no intelligence service of its own, reliant on Swiss surveillance infrastructure yet party to Schengen, Prüm, a Europol agreement and the Council of Europe conventions, its banking secrecy exposed by the 2008 LGT scandal

← Back to Privacy Law Directory

Overview

The Principality of Liechtenstein is a constitutional hereditary monarchy of approximately 40,000 people and 160 km², nestled between Switzerland and Austria. It is a member of the European Economic Area (EEA) and EFTA but not the EU. It maintains a customs union with Switzerland, uses the Swiss franc, and integrates deeply with Swiss infrastructure across telecommunications, defence, and law enforcement.[1]

Liechtenstein has no intelligence service and no military (abolished in 1868). Its police force numbers approximately 130 staff. The GDPR applies through the EEA Agreement (applicable July 20, 2018). The principality is not a member of any Eyes alliance. Its privacy landscape is defined less by domestic surveillance concerns than by two forces: its complete telecommunications dependency on Switzerland (meaning Swiss intelligence law effectively governs the surveillance exposure of anyone whose communications transit Swiss networks, which for Liechtenstein means virtually all communications), and the tension between its historical role as a banking secrecy jurisdiction and its modern transparency obligations.[2]

The Constitution of 1921 (revised 2003) guarantees the inviolability of the home and secrecy of correspondence (Article 32) but contains no express right to data protection. All legislation requires the concurrence of the reigning Prince, who may veto any law including data protection legislation.[3]

Liechtenstein’s outward data-sharing runs through its alliances and treaties, each detailed below. Though not an EU member and belonging to no Eyes alliance, it is a Schengen and Prüm associate and cooperates with Europol under an operational agreement; it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, holds a bilateral mutual legal assistance treaty with the United States, and exchanges financial-account data with 100+ jurisdictions under the Common Reporting Standard. These frameworks, together with its involuntary exposure through Swiss networks, are the channels through which the domestic protections described above are, in practice, bypassed.[16][17][18][19]

International Data Sharing Agreements

Despite having no intelligence service and strong GDPR protections, Liechtenstein participates in multiple international data sharing frameworks and is subject to additional surveillance exposure through its Swiss infrastructure dependency.

Mutual Legal Assistance: Layered Framework

European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): Liechtenstein is party to this Council of Europe instrument (in force since 1978), its Additional Protocol, and the Second Additional Protocol (ETS 182, ratified and in force January 1, 2021), which broadens the range of situations for requesting assistance and enables faster, more flexible cooperation.[14] As of July 2026 the 1959 Convention has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[16]

Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Liechtenstein is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[17]

Bilateral MLAT with the United States: Signed July 8, 2002, entered into force August 1, 2003. This treaty was driven in part by US concerns about Liechtenstein’s banking secrecy facilitating tax evasion and financial crime, predating the LGT scandal by five years. Liechtenstein’s treaties are published in the Landesgesetzblatt, searchable in the consolidated law database gesetze.li.[15]

Swiss channels: Given its integrated infrastructure and customs union, Liechtenstein generally operates through Swiss MLA channels for practical cooperation. The Swiss Federal Office of Justice processes many requests that touch Liechtenstein’s jurisdiction.

Schengen (SIS II) and Prüm

As a non-EU Schengen-associated state, the Landespolizei has real-time access to SIS II, the EU’s largest law enforcement database, and can query and contribute alerts visible across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[18] Liechtenstein is also one of the four non-EU associates of the Prüm framework (automated DNA, fingerprint, and vehicle-registration exchange), which binds 31 states (all 27 EU members plus Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[19]

Trilateral Police Cooperation

The 2012 agreement with Switzerland and Austria enables operational intelligence sharing, joint patrols, coordinated manhunts, and cross-border hot pursuit, effectively extending Swiss and Austrian law enforcement capabilities into Liechtenstein.[12]

Financial Data Sharing

Common Reporting Standard (CRS/AEOI): Automatic exchange of financial account information with 100+ jurisdictions, the most significant international data sharing regime affecting Liechtenstein, replacing its former banking secrecy with continuous cross-border flows of personal financial data.

FATCA: Intergovernmental agreement with the United States for automatic reporting of US-person accounts.

Swiss Customs Union: Extensive data sharing with Switzerland for customs, taxation, and regulatory purposes. Swiss authorities process Liechtenstein customs data, and the FMA exchanges information with Swiss FINMA.[1]

Other Frameworks

Europol: As a non-EU state, Liechtenstein is not a Europol member but is one of the 17 non-EU states holding an operational agreement permitting personal-data exchange with Europol (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States), which is constituted by its 27 EU member states and cooperates with US law enforcement including the FBI.[20] Interpol: Participates in I-24/7 global police network. Egmont Group: The Liechtenstein FIU participates in financial intelligence sharing across 164+ FIUs.

Surveillance Exposure as Data Sharing

Liechtenstein’s most significant “data sharing” is involuntary: its entire communications infrastructure transits Swiss networks subject to NDB cable reconnaissance, BND monitoring of German transit routes, and potential Austrian HNA interception. Unlike formal data sharing agreements, this exposure operates with no Liechtenstein oversight, no notification mechanism, and no ability for Liechtenstein authorities to negotiate safeguards or conditions. For Liechtenstein persons, the strongest privacy guarantees come not from domestic law but from the Swiss Federal Administrative Court’s December 2025 ruling finding NDB cable surveillance incompatible with fundamental rights, a ruling in another country’s court system over which Liechtenstein has no influence.

Police and Security

All security functions are handled by the Landespolizei (National Police), approximately 130 staff with over 80 officers. The force includes a Crime Intelligence Unit, Financial Crime Unit, and Border Unit with 60+ cameras. A Trilateral Agreement on Cross-Border Police Cooperation with Switzerland and Austria (June 4, 2012) enables mixed patrols, information exchange, coordinated manhunts, and cross-border hot pursuit. The Landespolizei cooperates with Europol and Interpol.[12]

For intelligence matters, Liechtenstein effectively relies on the Swiss NDB. The customs union, shared currency, and integrated telecommunications mean Swiss security services have significant visibility into Liechtenstein’s threat environment. Liechtenstein’s security posture (including any intelligence collection affecting persons in Liechtenstein) is shaped by Swiss national security priorities and Swiss surveillance law rather than by Liechtenstein’s own minimal domestic framework.

Surveillance Exposure Through Swiss Infrastructure

Liechtenstein’s telecommunications is fully integrated with Switzerland. International internet traffic transits Swiss networks and exchanges. The Liechtenstein Internet Exchange (LI-IX) keeps some domestic traffic local, but most international peering occurs through Swiss exchanges.[13]

The critical implication is that Liechtenstein’s communications are subject to Swiss surveillance infrastructure. The Swiss BÜPF authorises lawful interception of communications transiting Swiss networks. The Swiss NDB conducts cable reconnaissance under the NDG that can capture cross-border communications at Swiss internet exchange points. For traffic routed beyond Switzerland, Liechtenstein’s communications face additional interception exposure through Germany (BND cable monitoring) and potentially Austria (HNA).

The result: a country with no intelligence service and strong formal GDPR protections has its entire communications infrastructure running through networks operated by nations with active signals intelligence programmes. Liechtenstein has no independent capability to monitor, regulate, or detect such interception.

Recent Developments

Liechtenstein legislates slowly and has no intelligence service of its own, so the developments that matter most to it are usually not Liechtenstein developments. They happen in Bern, and they arrive through the Swiss networks its communications depend on. Three of the four items below are Swiss.

Swiss Cable Reconnaissance Held Unconstitutional (December 2025)

The interception exposure described in the section above is no longer only a structural observation: a Swiss court has ruled the practice unlawful. In case A-6444/2020, announced on December 2, 2025, the Swiss Federal Administrative Court held that cable reconnaissance and radio surveillance as conducted by the NDB are incompatible with the Federal Constitution and the ECHR, finding insufficient protection against misuse, no instrument protecting journalistic sources or lawyer-client communications, and neither effective oversight nor an effective remedy for those affected. The legislature has a five-year transitional period; if no compliant framework is in place by 2030, cable and radio surveillance must stop altogether.[21]

What makes this directly consequential here is the distinction the court drew. It recorded that purely domestic Swiss communications were excluded from the intercepted material while cross-border traffic was not. Liechtenstein traffic crossing into and through Switzerland is cross-border by definition, so it falls on the exposed side of exactly the line the court found constitutionally deficient, and it is protected by a remedy Liechtenstein residents have no standing to invoke and no vote to shape.[21]

The Swiss Fix Has Slipped onto a Slower Track (January to August 2026)

On January 28, 2026 the Swiss Federal Council adopted the dispatch on the basic package of its Intelligence Service Act revision and sent it to Parliament the same day, extending the FIS mandate across the whole of cyberspace, allowing collection of data from financial intermediaries, and strengthening independent oversight. At that point the government said the rewrite of the radio and cable reconnaissance provisions demanded by the court would be handled separately, specifically so that careful drafting would not delay the packages already moving. That is no longer the plan. As of August 2026 the reconnaissance rewrite sits inside the supplementary cyber package, whose consultation has moved to October 2026. The constitutional repair on which the legality of intercepting Liechtenstein’s transit traffic ultimately depends is now bundled into a larger and slower vehicle.[22][23]

VÜPF Revision: Second Consultation Ordered, Still Not Opened (February 2026)

The Swiss surveillance-ordinance expansion described under Encryption below, which would reach VPN, messaging, and email providers, failed comprehensively in its first consultation. On February 11, 2026 the Federal Council formally took note of that outcome, commissioned a regulatory impact assessment on the consequences for the firms that would bear the obligations, and announced a second consultation to follow, a course both chambers of the Swiss parliament had demanded by motion. As of August 2026 no second consultation has opened and no timetable has been published. For Liechtenstein the item remains live rather than resolved, and it remains one on which the country has no vote.[24]

Cyber-Security Act: NIS2 Obligations Phasing In (2025 to 2027)

The one substantial domestic thread is the Cyber-Security Act (CSG), amended in early 2025 to transpose NIS2, which brings roughly 1,800 to 2,200 entities into scope in a country of about forty thousand people. Registration became mandatory on February 1, 2025 and the technical-compliance and audit obligations phase in toward February 1, 2027. The proportions are worth pausing on: the regulated population is a substantial fraction of all economic activity in the principality, supervised by an administration whose data protection authority has issued no significant GDPR fine since 2018.[7][5]

Privacy Framework

The Datenschutzstelle (DSS) in Vaduz is Liechtenstein’s national supervisory authority. As an EEA authority, the DSS participates in EDPB mechanisms, though disputes fall under the EFTA Court rather than the CJEU. The DSS can impose fines up to CHF 22 million or 4% of global turnover, but has imposed no significant GDPR fines since 2018, making it one of the least active DPAs in the EEA.[4][5]

The Data Protection Act (DSG), effective January 1, 2019, implements the GDPR without major derogations. The Telecommunications Act governs data retention and lawful interception. The Cyber-Security Act (CSG) was amended in early 2025 to transpose NIS2, covering approximately 1,800–2,200 entities with registration mandatory from February 1, 2025.[6][7]

Banking Secrecy and the LGT Scandal

For decades, Liechtenstein was one of Europe’s most prominent banking secrecy jurisdictions, with trust structures (Stiftungen and Anstalten) that allowed beneficial owners to shield assets from tax authorities.

The 2008 LGT Bank Scandal

LGT Bank, owned by the reigning House of Liechtenstein, became the centre of the largest tax evasion investigation in German history when a former employee provided the BND with data on approximately 1,400 account holders (Germany reportedly paid EUR 4.2 million for the stolen data). Investigations followed in the US, UK, Australia, France, Italy, and other countries. The US DOJ reached a $23.8 million settlement with LGT’s affiliate for facilitating tax evasion through undisclosed accounts held in Liechtenstein foundations.[8][9]

Reforms

Under international pressure (the FATF had identified Liechtenstein alongside Andorra and Monaco as uncooperative tax havens in 2007), Liechtenstein adopted OECD tax transparency standards, implemented the Common Reporting Standard (CRS) for automatic exchange of financial data with 100+ jurisdictions, signed FATCA agreements with the United States, strengthened AML legislation under the FMA, and paid a EUR 50 million fine to Germany. The structural capacity for financial opacity through trust law remains, now subject to transparency obligations.[10][11]

Encryption: Swiss Dependency

Liechtenstein has no encryption backdoor mandate, no compelled decryption law, and no lawful access legislation of its own. However, because all Liechtenstein internet traffic transits Swiss networks, Switzerland’s encryption debates directly affect Liechtenstein persons. The Swiss VÜPF expansion proposals (January 2025) would have extended surveillance obligations to VPN services, encrypted messaging apps, and email providers, with potential obligations to build encryption backdoors. Though paused after industry backlash and Proton’s CHF 100M infrastructure relocation, the proposals (if enacted) would apply to communications transiting Swiss networks, including all Liechtenstein traffic. Liechtenstein has no seat at the table in Swiss legislative debates that would determine the encryption standards applied to its own population’s communications.

Data Retention

The Telecommunications Act requires providers to retain communications metadata for law enforcement purposes, with judicial authorisation required for access. As an EEA state, Liechtenstein is bound by CJEU data retention jurisprudence as incorporated into the EEA Agreement, enforced by the EFTA Court. The restrictions from Digital Rights Ireland, Tele2/Watson, and La Quadrature du Net apply in principle.

Pending Legislation

As an EEA microstate with a slow legislative cadence, Liechtenstein’s pending items are largely EEA-driven transpositions:

Sources

[1] Wikipedia: Liechtenstein – EEA/EFTA membership, Swiss customs union, population, geography
[2] CaseGuard: GDPR and EEA in Liechtenstein – GDPR incorporation July 2018
[4] Datenschutzstelle (DSS): Official Website – Supervisory authority mandate
[5] GDPRhub: Datenschutzstelle (Liechtenstein) – Enforcement record, no significant fines
[6] Privacy Laws Hub: Liechtenstein DSG Guide – DSG overview, CHF 22M/4% penalty cap
[7] Copla: NIS2 Implementation in Liechtenstein – CSG amendment, 1,800–2,200 entities
[8] Wikipedia: 2008 Liechtenstein Tax Affair – LGT Bank, BND data purchase, 1,400 accounts
[9] US DOJ: LGT Bank $23.8 Million Settlement – Tax evasion facilitation
[10] Wikipedia: Corruption in Liechtenstein – FATF identification as uncooperative (2007)
[11] ICLG: AML Laws – Liechtenstein – CRS/AEOI, TIEA framework, FMA supervisory role
[12] Landespolizei: About Us – 130 staff, trilateral agreement with Switzerland and Austria
[13] TS2: Liechtenstein – Europe’s Most Connected Country – LI-IX, Swiss peering, 99% FTTH
[15] US State Department: Liechtenstein MLAT – Signed July 8, 2002, in force August 1, 2003
[16] Council of Europe Treaty Office: European Convention on Mutual Assistance in Criminal Matters (ETS No. 30) – Chart of signatures and ratifications; 51 parties as of July 2026 (all 46 Council of Europe member states plus Chile, Israel, Mongolia, the Republic of Korea and Russia), Liechtenstein among them
[17] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026 (45 Council of Europe member states plus 37 non-member states), Liechtenstein among them
[18] European Commission: Schengen Area – The 29 states of the Schengen Area (all EU members except Ireland and Cyprus, plus the non-EU associates Iceland, Liechtenstein, Norway and Switzerland; Bulgaria and Romania became full members January 1, 2025), Liechtenstein a non-EU associate
[19] Wikipedia: Prüm Convention – The Prüm framework for automated DNA, fingerprint and vehicle-data exchange; binds all 27 EU member states plus the non-EU Schengen associates Iceland, Liechtenstein, Norway and Switzerland (31 in all); Prüm II (2024) adds facial images and police records
[20] Europol: Operational Agreements – Europol is constituted by the 27 EU member states and maintains operational cooperation agreements permitting exchange of personal data with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, the United States) – Liechtenstein among them – plus Denmark under a separate agreement, and with Eurojust, Frontex and Interpol
[21] Swiss Federal Administrative Court: Bulk Interception of Cross-Border Communication Is Not Compatible with Fundamental Rights (December 2, 2025) – case A-6444/2020; cable reconnaissance and radio surveillance as practised by the NDB held incompatible with the Federal Constitution and the ECHR for insufficient protection against misuse, absence of instruments protecting journalistic sources and lawyer-client communications, and lack of effective oversight or remedy; five-year transitional period, with the surveillance to be discontinued if no compliant framework exists by 2030; purely domestic Swiss communications were excluded from the intercepted material while cross-border traffic was not
[22] Der Bundesrat: Revision des Nachrichtendienstgesetzes, Bundesrat stärkt Früherkennung und Abwehr von Bedrohungen (January 28, 2026) – the Federal Council adopted the dispatch on the basic package of the NDG revision at its sitting of January 28, 2026 and transmitted it to Parliament the same day; extends the FIS mandate to the whole of cyberspace and strengthens independent oversight; the supplementary package on cyber threats was then planned for consultation in mid-2026, and the requirements arising from the Federal Administrative Court’s November 2025 judgment on radio and cable reconnaissance were to be implemented separately so as not to delay the packages already under way
[23] Eidgenössisches Departement für Verteidigung, Bevölkerungsschutz und Sport (VBS): Revision des Nachrichtendienstgesetzes – official overview of the multi-package NDG revision; Teil II (Zusatzpaket) now covers cyber threats and the implementation of the Federal Administrative Court’s requirements for the legal bases of radio and cable reconnaissance, with the consultation planned for October 2026
[24] watson: Bundesrat steht bei geplanter Verschärfung der digitalen Überwachung auf die Bremse (February 11, 2026) – after the VÜPF revision failed in consultation, the Federal Council announced on February 11, 2026 that it would first commission an external assessment of the effects on the undertakings subject to cooperation duties, and would conduct a second consultation once the regulatory impact assessment is available; both the National Council and the Council of States had adopted motions from the FDP group demanding a fresh consultation
← Back to Privacy Law Directory