Luxembourg

Host of the CJEU and a node in Europol, Schengen and Prüm data exchange bound by the Council of Europe conventions, whose lone intelligence agency secretly taped the Prime Minister and toppled an 18-year government

← Back to Privacy Law Directory

Overview

EU Member State (founding member, 1957), NATO (founding member, 1949). For the EU framework, see the EU Framework page.

Luxembourg hosts the CJEU, European Investment Bank, Eurostat, and core EU institutions, a structural data flow hub. The CNPD issued the largest GDPR fine ever imposed: EUR 746 million against Amazon (July 2021, later annulled on procedural grounds, see Recent Developments). The SRE (sole intelligence agency, formed 1960 under NATO obligation) sits at the centre of European governance data. The SREL scandal: the former director secretly recorded PM Juncker in 2007, exposing illegal surveillance, collapsing the government after 18 years and triggering a 2016 intelligence reform. The Bommeleeër affair (1984–1986): ~20 infrastructure bombings linked to NATO Stay-Behind (Gladio) networks; trial concluded without convictions. Club de Berne founding member (1969).[1][2]

Luxembourg’s outward data-sharing runs through its alliances and treaties, each detailed below. It is a NATO founding member (1949) and a Club de Berne founding member (1969), and its sole intelligence service relies heavily on that forum, its Counter-Terrorism Group, and Benelux cooperation; it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen framework (named for the Luxembourg village where it was signed) and was an original 2005 Prüm signatory, belongs to Europol and the European Investigation Order, and holds bilateral mutual legal assistance treaties with the United States and, through the Benelux Treaty, with Belgium and the Netherlands. These are the channels through which the domestic protections described below are, in practice, bypassed.[13][14][15][16][17]

International Data Sharing Agreements

Mutual Legal Assistance

EU Member States (26 countries): Luxembourg cooperates with the other EU states through the EU Convention on Mutual Assistance in Criminal Matters (2000), the Schengen Convention (signed in 1985 in the Luxembourg village of Schengen), and the European Investigation Order; it was one of seven original Prüm Convention signatories (May 2005).

European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols apply between Luxembourg and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[13]

Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Luxembourg is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[14]

Bilateral MLAT with the United States: Signed March 13, 1997, in force February 1, 2001; the supplementary EU-US instrument entered into force February 2010. Luxembourg also maintains the Benelux Treaty on Extradition and Mutual Assistance (1962; new police treaty October 2023 adding cross-border action on own initiative and reciprocal database query access) with Belgium and the Netherlands. Luxembourg’s treaties are published in the Journal officiel (Legilux), where the full set is searchable.[8]

Intelligence Cooperation

Club de Berne founding member (1969), one of the original eight alongside Switzerland, West Germany, France, Italy, the Netherlands, Belgium, and the UK. The forum keeps no public roster, but it is today reported to comprise the intelligence services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland, with the United Kingdom also reported as a member; the Counter-Terrorism Group (CTG) comprises the same services plus the United Kingdom.[18] NATO founding member (1949). Benelux intelligence cooperation, whose Dutch partners (AIVD/MIVD) are members of the Maximator SIGINT alliance (Denmark, France, Germany, the Netherlands, and Sweden).[19] EU-US Umbrella Agreement, SWIFT/TFTP, PNR. Interpol I-24/7. Egmont Group.[9]

EU Law Enforcement Cooperation

SIS II: Real-time query and alert sharing across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[15] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange; Luxembourg was an original 2005 signatory, and the framework now binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[16]

Europol

As an EU member state, Luxembourg is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Luxembourg person data flowing through Europol is reachable onward.[17]

The Privacy Backdoor Effect

Surveillance and Intelligence

SRE (Service de Renseignement de l’État)

Luxembourg’s sole intelligence agency, responsible for domestic/foreign intelligence, counterintelligence, and counterterrorism. No separate foreign or military intelligence service. Relies heavily on Club de Berne, Benelux, and bilateral partnerships. Created 1960 under NATO obligation.[4]

SREL Scandal (2012–2013)

Former SREL director Marco Mille secretly recorded PM Juncker (2007). Parliamentary inquiry revealed illegal surveillance, unauthorised wiretaps, and misuse of intelligence funds. Juncker resigned July 10, 2013, ending 18 years as PM, the only government collapse in Luxembourg’s modern history caused by an intelligence scandal. Comprehensive intelligence reform enacted 2016.[2]

Bommeleeër Affair (1984–1986)

~20 bomb attacks on infrastructure and public buildings. Two former Brigade Mobile de la Gendarmerie members charged in 2013; trial ended without convictions for bombings. Defence argued perpetrators linked to NATO Stay-Behind (Gladio) networks. Exposed complicity or negligence of Luxembourg’s security apparatus.[5]

Internet Infrastructure and Transit Exposure

LU-CIX (founded 2009) across eight data centres. LuxConnect (state-owned): 1,900 km fibre, 14 international breakout points to Belgium, Germany, France. Landlocked: all international traffic transits through Germany (DE-CIX Frankfurt, BND cable interception since 2009), Belgium, and France. A Luxembourg-Vienna telecommunications line was identified as having been tapped by German intelligence. EU institutional data (CJEU, EIB, Eurostat) governed by Regulation 2018/1725 (separate from GDPR) traverses Luxembourg’s infrastructure.[6]

Recent Developments

Amazon EUR 746M Fine Annulled on Appeal (March 2026): The CNPD’s record EUR 746 million penalty against Amazon (July 2021), the largest GDPR fine ever imposed, was upheld at first instance by the Administrative Tribunal in March 2025 but then annulled by the Administrative Court (Cour administrative) in March 2026. The annulment rested on procedural grounds: applying two 2023 CJEU rulings, the court held that the CNPD had failed to analyse the criterion of fault (a deliberate or negligent act) required to impose an administrative fine. The court nonetheless confirmed that Amazon’s reliance on legitimate interests was not justified, and Amazon had already complied with the CNPD’s compliance order before the hearing. The CNPD characterised the outcome as having secured effective data-processing compliance with its key substantive findings confirmed, while the monetary penalty itself fell away.[1][11]

New Benelux Police Treaty (October 2023): Cross-border police action on own initiative, reciprocal database query access between Luxembourg, Belgium, and Netherlands.[10]

Data Retention Reform Bill (January 2023): Targeted retention proposal pending: prohibits general indiscriminate retention, permits category/geographic-based retention and expeditious preservation.[7]

NIS2 Enacted (Law of 5 May 2026): After missing the October 2024 deadline, Luxembourg transposed the NIS2 Directive in the Law of 5 May 2026 on measures for a high level of cybersecurity, which entered into force on 10 May 2026. The law sweeps an estimated 6,000–8,000 entities into scope with risk-management and incident-reporting obligations; in-scope entities must self-register with the ILR by 10 July 2026 under Article 11.[12]

Privacy Framework

The CNPD (Commission Nationale pour la Protection des Données) enforces the GDPR via the Act of 1 August 2018. The Amazon EUR 746M penalty is the largest GDPR fine ever imposed, though it was annulled by the Administrative Court in March 2026 (see Recent Developments). The CNPD gained representative actions authority (October 2025) and operates an AI regulatory sandbox (May 2024). The Act of 5 July 2016 reformed SRE oversight following the SREL scandal.[3]

Data Retention

6-month retention under amended Act of 30 May 2005. A January 2023 reform bill proposes targeted retention by data subject category or geographic area and expeditious preservation, prohibiting general and indiscriminate retention (pending adoption as of early 2026).[7]

Pending Legislation

Sources

[1] GDPRhub: CNPD (Luxembourg) – Amazon EUR 746M, upheld by Administrative Tribunal March 2025, representative actions
[12] Elvinger Hoss: NIS2 Now in Force in Luxembourg (2026) – Law of 5 May 2026 on a high level of cybersecurity transposing NIS2; entered into force 10 May 2026; ~6,000–8,000 entities in scope; ILR self-registration obligation under Article 11 by 10 July 2026
[2] Wikipedia: Luxembourg Spying Scandal – SREL recorded PM Juncker, government collapse, 2016 reform
[3] CNPD: Official Website – Act 1 August 2018, AI sandbox, enforcement
[4] Wikipedia: SRE – Sole intelligence agency, formed 1960, NATO obligation
[5] Wikipedia: Bommeleeër Affair – 1984–1986 bombings, NATO Stay-Behind, no convictions
[6] LuxConnect – 1,900 km fibre, 14 breakouts; see also LU-CIX
[7] ICLG: Data Protection – Luxembourg – 6-month retention, January 2023 reform bill
[8] US DOJ: MLATs (April 2022) – US-Luxembourg MLAT signed March 13, 1997, in force February 1, 2001
[9] Wikipedia: Club de Berne – Luxembourg founding member 1969, original eight
[10] Benelux: New Police Treaty (October 2023) – Cross-border action, database access
[11] ICLG: Luxembourg Court Scraps Amazon’s €746M Data Privacy Fine (March 2026) – Administrative Court (Cour administrative) annulled the CNPD’s EUR 746M penalty on procedural grounds, applying 2023 CJEU rulings requiring analysis of fault (deliberate or negligent act); court confirmed Amazon’s legitimate-interest legal basis was not justified; Amazon had already complied with the compliance order before the hearing
[13] Council of Europe Treaty Office: European Convention on Mutual Assistance in Criminal Matters (ETS No. 30) – Chart of signatures and ratifications; 51 parties as of July 2026 (all 46 Council of Europe member states plus Chile, Israel, Mongolia, the Republic of Korea and Russia), Luxembourg among them
[14] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026 (45 Council of Europe member states plus 37 non-member states), Luxembourg among them
[15] European Commission: Schengen Area – The 29 states of the Schengen Area (all EU members except Ireland and Cyprus, plus the non-EU associates Iceland, Liechtenstein, Norway and Switzerland; Bulgaria and Romania became full members January 1, 2025), Luxembourg among them
[16] Wikipedia: Prüm Convention – The Prüm framework for automated DNA, fingerprint and vehicle-data exchange; binds all 27 EU member states plus the non-EU Schengen associates Iceland, Liechtenstein, Norway and Switzerland (31 in all); Luxembourg was an original 2005 signatory; Prüm II (2024) adds facial images and police records
[17] Europol: Operational Agreements – Europol is constituted by the 27 EU member states (Luxembourg among them) and maintains operational cooperation agreements permitting exchange of personal data with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, the United States) plus Denmark under a separate agreement, and with Eurojust, Frontex and Interpol
[18] about:intel: The Club de Berne – The voluntary intelligence-sharing forum (no public membership roster) reported to comprise the intelligence services of the 27 EU member states plus Norway and Switzerland, with the United Kingdom also reported; its Counter Terrorism Group (CTG) comprises the same services plus the UK; Luxembourg’s SRE is a founding member (1969)
[19] Bart Jacobs, Maximator: European signals intelligence cooperation, from a Dutch perspective (Intelligence and National Security, 2020) – The Maximator SIGINT-sharing alliance of five states: Denmark, France, Germany, the Netherlands and Sweden; Luxembourg is not a member, but its Benelux partners the Dutch AIVD/MIVD are
← Back to Privacy Law Directory