CNPD
Luxembourg national DPA. Luxembourg companies must monitor CNPD in addition to EU-level EDPB guidance.
If you are in the EU, start from EU compliance. If you are outside the EU but serve EU users, clients, or market participants, EU law can still apply.
A quick matrix for founders and developers who need the right starting point.
Track date-backed CRA, consumer-rights, Data Act, DSA, product-liability, UK PSTI, and FTC Safeguards milestones from official sources.
CNPD, CSSF digital circulars, Legilux, and ILNAS add Luxembourg-specific obligations beyond EU-level guidance.
Official sources monitored across Luxembourg, EU, UK, US, and technical security authorities.
53
monitored sources
4
Luxembourg priority sources
Luxembourg national DPA. Luxembourg companies must monitor CNPD in addition to EU-level EDPB guidance.
Luxembourg financial regulator for ICT risk, DORA alignment, virtual assets, and digital finance circulars.
Official publication of Luxembourg law, including national transpositions of EU digital directives.
Official Commission CRA policy and summary pages for software, hardware, vulnerability reporting, conformity assessment, and implementation dates.
Tool boundaries, prompt injection sinks, SSRF, and manifests.
Open guidePermissions, DOM injection, CSP, message passing, and storage.
Open guideCapability, safety, jailbreak resistance, and reproducibility.
Open guideOWASP LLM Top 10 mapped to practical design controls.
Open guideSecrets, lockfiles, CI permissions, SBOM, and dependencies.
Open guideCommon AI-generated app risks and safer implementation patterns.
Open guideEU-incorporated teams selling globally: US, UK, Canada, Brazil, Australia, India, Singapore, Japan, China, Korea, New Zealand, South Africa, and Mexico triggers.
Open guideFast product triage across CRA, DSA, Data Act, PSTI, FTC, and sector rules.
Open guide