Act 2004
Law of 12 November 2004 on the fight against money laundering and terrorist financing
Loi du 12 novembre 2004 relative à la lutte contre le blanchiment de capitaux et le financement du terrorisme.
Issued by Commission de Surveillance du Secteur Financier
Effective: 23 Nov 2004
Plain-English summary
Law of 12 November 2004 relative to the fight against money laundering and the financing of terrorism is a bedrock of the national regulation for Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) in Luxembourg. Initially formulated as an implementation tool of European Union framework directives in national law, this statute introduces strict preventive measures including Customer Due Diligence (CDD), transaction monitoring, and record-keeping for an extensive range of market entities that are under the supervision of bodies such as the Financial Sector Supervisory Commission (CSSF). Within the scope of this legislative body, "professionals" from different spheres such as the financial sector, crypto-assets, and the non-financial sector are obliged to report suspicious transactions automatically to the Luxembourg Financial Intelligence Unit (CRF) to avoid serious administrative, operational, or criminal sanctions. This live text can be accessed through the official legislative resource of the Grand Duchy of Luxembourg, Legilux, and it is continuously subject to legislative changes and is updated by means of the Law of 16 July 2026 and Law of 22 July 2026.
Who it applies to
Banking · Asset & Wealth Management · DNFBPs (Lawyers, Accountants, Dealers) · Corporates (Listed)
Topics
AML / CFT / Sanctions
Obligations arising from this instrument
| Obligation | Timing | Regulator | Source | Detail |
|---|---|---|---|---|
| AML compliance programme and officer | Ongoing | CSSF | source | |
Under the AML regulatory regime for Luxembourg, which is governed by the Law of 12 November 2004 and the CSSF Regulation N° 12-02, a very rigid set of operational obligations in terms of time deadlines and monetary values is imposed. Being a legal obligation of means for the whole process of detecting crimes, but an obligation of result concerning procedures, the legislation stipulates the need to create an individual risk-based compliance program for all regulated professionals. The compliance program implies the requirement to perform CDD before creating any business relationships. The period of storage of all information is strictly regulated at the level of 5 years after the relationship termination. As for the operational obligations, STRs must be reported "without delay" to the CRF once a suspicion has arisen. In terms of value obligations, the regulation imposes the mandatory verification of cash transactions amounting to at least EUR 10,000, while non-compliant entities face heavy financial enforcement that consists of automatic EUR 10,000 fines and increased statutory penalties that might equal EUR 5,000,000 or 10% of annual turnover. |
||||
| AML record retention | Retention period 5 years | CSSF | source | |
For instance, the AML Luxembourg document retention requirement obliges all the obligated firms to properly maintain all Customer Due Diligence (CDD) documentation, transaction evidence and analytical files for at least five years. However, the time frame does not start from the point when a particular document was obtained but starts precisely from the point of cessation of the business relationship or completion of the occasional transactions. In order to provide for extensive investigation of the case by law enforcement bodies, the regulators such as CSSF have the authority to further increase the required time frame to as much as five more years in total, thereby establishing a maximum of 10 years for document retention. Upon the end of the required period of time, the obligation is reversed and becomes that of deleting the documents. |
||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | CSSF | source | |
The requirement for CDD/KYC in Luxembourg is a rigorous and risk-focused legal requirement that obliges obliged entities to conduct identification and verification of the identity of their customers and UBOs (with over 25% ownership) before onboarding the customer. The CDD/KYC framework is regulated by CSSF and under this framework, institutions are strictly prohibited from conducting any business relations or carrying out transactions until the verification of the identity is done. The rigor of the due diligence depends on the level of risk, which means that in case of high-risk customers like PEPs, EDD should be conducted to verify SoF and SoW. Lastly, this legal requirement mandates continuous monitoring of transactions of the customer's profile. |
||||
| Suspicious transaction reporting | Deadline Event-based | CSSF | source | |
The temporal value of the Suspicious Transaction Reporting system in Luxembourg is entirely event-driven, being a legal requirement to submit a report to the CRF “without delay” precisely when the suspicion is internally established. The triggering factor in question is not the date of the transaction, but rather the moment when the compliance officer discovers that the activity is unusual or suspicious. As for the uncompleted transaction, this means that a pre-facto freeze will be established, and the transfer cannot be made until the CRF decides whether to grant an opposition order. It is irrelevant whether the suspicion occurs before or after the transaction has been completed, as there is no leeway in time under this law. |
||||
| Lawful basis, notice and data subject rights | Ongoing | CSSF | source | |
These responsibilities of lawful basis, notice, and data subject rights in Luxembourg are ongoing structural responsibilities where a data controller must provide a lawful ground before the process and show proof of compliance during the CNPD audits. These requirements, created mostly by the EU GDPR and locally by the Luxembourg Law of 1 August 2018, together with the constitutional requirements, require that transparency notices be provided right when collecting data. Moreover, they create a strict one-month timing value for fulfilling the requests of individuals who exercise their right of access, rectification, or erasure of data. Organizations are responsible for paying heavy fines of €20 million or 4% of annual global turnover. |
||||
| Personal data breach notification | Deadline Event-based | CSSF | source | |
The strength on which an obligation can be based will depend on the legal document that creates it, separating the compliance obligations in Luxembourg into those arising out of national laws and European laws. The obligations related to AML Record Retention, CDD, and STR are created mainly by the amended Luxembourg AML Act (Law of 12 November 2004) [1, 2], while CSSF Regulations and CRF decrees help implement it in practice. At the same time, the obligation related to Data Breach Notification is created by an instrument applicable at the European level, Article 33 of the GDPR, and its implementation in Luxembourg takes place under the law of 1 August 2018. |
||||
| No obligations match these filters. | ||||
Latest news
-
AUSTRAC Examines Western Union AML Controls and Transaction Monitoring
26 Sep 2026
Australia's financial intelligence unit has initiated a formal investigation into Western Union's anti-money laundering framework and compliance infrastructure. The regulatory examination focuses on the company's paymen…
-
RBI penalizes Ola Financial Services for KYC compliance failures
25 Sep 2026
The Reserve Bank of India imposed a monetary penalty of ₹3.10 lakh on Ola Financial Services Private Limited for non-compliance with KYC directions under the Payment and Settlement Systems Act, 2007. Following a statuto…