Luxembourg
4 regulators · 5 instruments · 6 obligations · 1 upcoming deadline
| Obligation | Timing | Regulator | Arises from | Source | Detail |
|---|---|---|---|---|---|
| Banking | |||||
| AML compliance programme and officer | Ongoing | CSSF | Law of 12 November 2004 on the fight against money laundering and terrorist financing | source | |
Under the AML regulatory regime for Luxembourg, which is governed by the Law of 12 November 2004 and the CSSF Regulation N° 12-02, a very rigid set of operational obligations in terms of time deadlines and monetary values is imposed. Being a legal obligation of means for the whole process of detecting crimes, but an obligation of result concerning procedures, the legislation stipulates the need to create an individual risk-based compliance program for all regulated professionals. The compliance program implies the requirement to perform CDD before creating any business relationships. The period of storage of all information is strictly regulated at the level of 5 years after the relationship termination. As for the operational obligations, STRs must be reported "without delay" to the CRF once a suspicion has arisen. In terms of value obligations, the regulation imposes the mandatory verification of cash transactions amounting to at least EUR 10,000, while non-compliant entities face heavy financial enforcement that consists of automatic EUR 10,000 fines and increased statutory penalties that might equal EUR 5,000,000 or 10% of annual turnover. |
|||||
| AML record retention | Retention period 5 years | CSSF | Law of 12 November 2004 on the fight against money laundering and terrorist financing | source | |
For instance, the AML Luxembourg document retention requirement obliges all the obligated firms to properly maintain all Customer Due Diligence (CDD) documentation, transaction evidence and analytical files for at least five years. However, the time frame does not start from the point when a particular document was obtained but starts precisely from the point of cessation of the business relationship or completion of the occasional transactions. In order to provide for extensive investigation of the case by law enforcement bodies, the regulators such as CSSF have the authority to further increase the required time frame to as much as five more years in total, thereby establishing a maximum of 10 years for document retention. Upon the end of the required period of time, the obligation is reversed and becomes that of deleting the documents. |
|||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | CSSF | Law of 12 November 2004 on the fight against money laundering and terrorist financing | source | |
The requirement for CDD/KYC in Luxembourg is a rigorous and risk-focused legal requirement that obliges obliged entities to conduct identification and verification of the identity of their customers and UBOs (with over 25% ownership) before onboarding the customer. The CDD/KYC framework is regulated by CSSF and under this framework, institutions are strictly prohibited from conducting any business relations or carrying out transactions until the verification of the identity is done. The rigor of the due diligence depends on the level of risk, which means that in case of high-risk customers like PEPs, EDD should be conducted to verify SoF and SoW. Lastly, this legal requirement mandates continuous monitoring of transactions of the customer's profile. |
|||||
| Suspicious transaction reporting | Deadline Event-based | CSSF | Law of 12 November 2004 on the fight against money laundering and terrorist financing | source | |
The temporal value of the Suspicious Transaction Reporting system in Luxembourg is entirely event-driven, being a legal requirement to submit a report to the CRF “without delay” precisely when the suspicion is internally established. The triggering factor in question is not the date of the transaction, but rather the moment when the compliance officer discovers that the activity is unusual or suspicious. As for the uncompleted transaction, this means that a pre-facto freeze will be established, and the transfer cannot be made until the CRF decides whether to grant an opposition order. It is irrelevant whether the suspicion occurs before or after the transaction has been completed, as there is no leeway in time under this law. |
|||||
| Telecom & Tech | |||||
| Lawful basis, notice and data subject rights | Ongoing | CSSF | Law of 12 November 2004 on the fight against money laundering and terrorist financing | source | |
These responsibilities of lawful basis, notice, and data subject rights in Luxembourg are ongoing structural responsibilities where a data controller must provide a lawful ground before the process and show proof of compliance during the CNPD audits. These requirements, created mostly by the EU GDPR and locally by the Luxembourg Law of 1 August 2018, together with the constitutional requirements, require that transparency notices be provided right when collecting data. Moreover, they create a strict one-month timing value for fulfilling the requests of individuals who exercise their right of access, rectification, or erasure of data. Organizations are responsible for paying heavy fines of €20 million or 4% of annual global turnover. |
|||||
| Personal data breach notification | Deadline Event-based | CSSF | Law of 12 November 2004 on the fight against money laundering and terrorist financing | source | |
The strength on which an obligation can be based will depend on the legal document that creates it, separating the compliance obligations in Luxembourg into those arising out of national laws and European laws. The obligations related to AML Record Retention, CDD, and STR are created mainly by the amended Luxembourg AML Act (Law of 12 November 2004) [1, 2], while CSSF Regulations and CRF decrees help implement it in practice. At the same time, the obligation related to Data Breach Notification is created by an instrument applicable at the European level, Article 33 of the GDPR, and its implementation in Luxembourg takes place under the law of 1 August 2018. |
|||||
| No obligations match these filters. | |||||