Luxembourg
4 regulators · 5 instruments · 6 obligations · 1 upcoming deadline
The Grand Duchy is an advanced and landlocked European country surrounded by three other countries, Belgium, France, and Germany.
Regulatory pulse · 90 days
Laws & circulars Enforcement NewsOverview
VERIFIED 28 SEP 2026The Grand Duchy is an advanced and landlocked European country surrounded by three other countries, Belgium, France, and Germany. It functions as a politically stable representative democracy governed by a constitutional monarch and plays a major role in the international arena by being regarded as one of the top countries for international investment funds and a financial center in the world. With one of the highest per capita GDPs, it primarily depends upon its thriving financial services and advanced technological sector.
Risk for Luxembourg remains exceptionally low, backed up by its consistent AAA rating from leading agencies around the world. The high transaction volume that comes about through border transactions means that the country suffers from structural weaknesses with respect to international money flow; however, the economy is known to be fiscally resilient and not highly indebted.
In terms of the compliance regime, Luxembourg adopts a robust and forward-looking approach. It has been granted white-listing on the global platform due to its evaluation as an outstanding jurisdiction by the FATF. This is an implication of Luxembourg’s compliance with almost all of the recommendations from FATF. In order to be in line with European Union directives, Luxembourg has revamped its legal system. Important anti-money laundering (AML) regulations, along with criminal procedure regulations, facilitated the prosecution of companies, while newly enforced mandates have made provision for automatic surveillance systems in order to ensure compliance with filing, registration, and UBO requirements in corporate registries.
In terms of international sanctions, Luxembourg does not fall under any form of sanctions or targets. On the contrary, the jurisdiction acts as a stern implementation mechanism for global financial sanctions. Based on national laws harmonized with EU regulations, there is a stringent imposition of asset freezing techniques, transaction screening, and corporate control measures aimed at preventing any forms of bypass systems, especially with regard to restrictions imposed on Russian assets. Corporate and public governance indicators for Luxembourg are highly developed, based on its tradition of total transparency of institutions and total judicial independence. In fact, the jurisdiction maintains itself as a low-corruption area at all times, and it remains among the top ranks internationally according to the Corruption Perceptions Index of Transparency International.
Who regulates what
View all →Key laws & regulations
All Laws & Regulations →| Instrument | Type | Year | Regulator | Source |
|---|---|---|---|---|
| CSSF Circular 22/806 on outsourcing arrangements | Circular | 2022 | CSSF | official |
| Register of Beneficial Owners(RBE Law) | Act | 2019 | — | official |
| Law of 17 December 2010 on undertakings for collective investment | Act | 2010 | CSSF | official |
| Law of 12 November 2004 on the fight against money laundering and terrorist financing | Act | 2004 | CSSF | official |
| Law of 5 April 1993 on the financial sector | Act | 1993 | CSSF | official |
| No instruments match these filters. | ||||
Industry compliance
Essential obligations
All obligations →| Obligation | Timing | Regulator | Source | Detail |
|---|---|---|---|---|
| AML compliance programme and officer | Ongoing | CSSF | source | |
Under the AML regulatory regime for Luxembourg, which is governed by the Law of 12 November 2004 and the CSSF Regulation N° 12-02, a very rigid set of operational obligations in terms of time deadlines and monetary values is imposed. Being a legal obligation of means for the whole process of detecting crimes, but an obligation of result concerning procedures, the legislation stipulates the need to create an individual risk-based compliance program for all regulated professionals. The compliance program implies the requirement to perform CDD before creating any business relationships. The period of storage of all information is strictly regulated at the level of 5 years after the relationship termination. As for the operational obligations, STRs must be reported "without delay" to the CRF once a suspicion has arisen. In terms of value obligations, the regulation imposes the mandatory verification of cash transactions amounting to at least EUR 10,000, while non-compliant entities face heavy financial enforcement that consists of automatic EUR 10,000 fines and increased statutory penalties that might equal EUR 5,000,000 or 10% of annual turnover. |
||||
| AML record retention | 5 years | CSSF | source | |
For instance, the AML Luxembourg document retention requirement obliges all the obligated firms to properly maintain all Customer Due Diligence (CDD) documentation, transaction evidence and analytical files for at least five years. However, the time frame does not start from the point when a particular document was obtained but starts precisely from the point of cessation of the business relationship or completion of the occasional transactions. In order to provide for extensive investigation of the case by law enforcement bodies, the regulators such as CSSF have the authority to further increase the required time frame to as much as five more years in total, thereby establishing a maximum of 10 years for document retention. Upon the end of the required period of time, the obligation is reversed and becomes that of deleting the documents. |
||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | CSSF | source | |
The requirement for CDD/KYC in Luxembourg is a rigorous and risk-focused legal requirement that obliges obliged entities to conduct identification and verification of the identity of their customers and UBOs (with over 25% ownership) before onboarding the customer. The CDD/KYC framework is regulated by CSSF and under this framework, institutions are strictly prohibited from conducting any business relations or carrying out transactions until the verification of the identity is done. The rigor of the due diligence depends on the level of risk, which means that in case of high-risk customers like PEPs, EDD should be conducted to verify SoF and SoW. Lastly, this legal requirement mandates continuous monitoring of transactions of the customer's profile. |
||||
| Suspicious transaction reporting | Event-based | CSSF | source | |
The temporal value of the Suspicious Transaction Reporting system in Luxembourg is entirely event-driven, being a legal requirement to submit a report to the CRF “without delay” precisely when the suspicion is internally established. The triggering factor in question is not the date of the transaction, but rather the moment when the compliance officer discovers that the activity is unusual or suspicious. As for the uncompleted transaction, this means that a pre-facto freeze will be established, and the transfer cannot be made until the CRF decides whether to grant an opposition order. It is irrelevant whether the suspicion occurs before or after the transaction has been completed, as there is no leeway in time under this law. |
||||
| Lawful basis, notice and data subject rights | Ongoing | CSSF | source | |
These responsibilities of lawful basis, notice, and data subject rights in Luxembourg are ongoing structural responsibilities where a data controller must provide a lawful ground before the process and show proof of compliance during the CNPD audits. These requirements, created mostly by the EU GDPR and locally by the Luxembourg Law of 1 August 2018, together with the constitutional requirements, require that transparency notices be provided right when collecting data. Moreover, they create a strict one-month timing value for fulfilling the requests of individuals who exercise their right of access, rectification, or erasure of data. Organizations are responsible for paying heavy fines of €20 million or 4% of annual global turnover. |
||||
| Personal data breach notification | Event-based | CSSF | source | |
The strength on which an obligation can be based will depend on the legal document that creates it, separating the compliance obligations in Luxembourg into those arising out of national laws and European laws. The obligations related to AML Record Retention, CDD, and STR are created mainly by the amended Luxembourg AML Act (Law of 12 November 2004) [1, 2], while CSSF Regulations and CRF decrees help implement it in practice. At the same time, the obligation related to Data Breach Notification is created by an instrument applicable at the European level, Article 33 of the GDPR, and its implementation in Luxembourg takes place under the law of 1 August 2018. |
||||
| No obligations match these filters. | ||||



