DSG · LR 235.1 · LGBl. 2018 Nr. 272 · Editorial explanation · not an official translation

Liechtenstein DSG: Data Protection, Rights and Supervision

An independently authored explanation of the official DSG consolidation effective on 1 April 2026. It is not an official translation or the full legislation and must be applied together with the GDPR version applicable in the EEA and sector-specific rules.

Editorial explanation · not an official translation

Key takeaways

This is an independently authored explanation of official materials, not an official translation or a reproduction of the complete text. The current German version, transitional provisions and the facts of the matter must be checked before reliance.

01

The DSG protects personality and fundamental rights in personal-data processing, supplements GDPR application in Liechtenstein and implements a distinct framework for competent-authority processing for law-enforcement purposes.

02

For a private organisation, compliance mapping starts not with a privacy notice but with roles, purposes, legal bases, data and subject categories, recipients, retention, international transfers and security measures.

03

The Act establishes the national Datenschutzstelle as an independent supervisory authority; within its remit it oversees public and private processing, receives complaints and exercises GDPR and DSG powers.

04

The fine framework reaches CHF 11 million or 2% of worldwide turnover for one group of infringements and CHF 22 million or 4% for another, subject to proportionality criteria and other available remedies.

02

Accountability and individual rights

An operational compliance programme connects the record of processing with notices, processor contracts, retention management, access policy, security, risk assessment and incident handling. A processor is selected only with sufficient technical and organisational guarantees, while transfers and sub-processing are documented and controlled. Where a DPO is mandatory, expertise, resources, early involvement, independence and direct access to senior management must be secured. Request workflows should identify the applicant and timely deliver access, rectification, erasure, restriction, objection and other applicable rights; exceptions are documented and communication uses clear and accessible language. International transfers and retention driven by AML or professional duties require separate design.

03

Supervision, enforcement and remedies

The Datenschutzstelle is the national independent supervisory authority and oversees public and private processing within its statutory remit. It may request information, inspect, warn about intended infringements and exercise Article 58 GDPR powers; an individual may lodge a complaint, while DSG decisions follow the prescribed administrative appeal path. Article 40 aligns fines with the infringement groups in Article 83 GDPR and sets upper limits of CHF 11 million or 2% of worldwide turnover and CHF 22 million or 4%. Practical exposure is not captured by the fine ceiling alone: orders to restrict or stop processing, remediation, civil claims, reputation and notifications to counterparties or sector regulators must also be managed.

LILEX · LLV · FMA

Official sources

This is an independently authored explanation of official materials, not an official translation or a reproduction of the complete text. The current German version, transitional provisions and the facts of the matter must be checked before reliance.

Smart Global Capital

Need to apply Liechtenstein law to a foundation, trust, company or financial structure?

We review the corporate, tax and regulatory perimeter and transition rules and prepare a documented legal position.

Discuss the legal position
WAWhatsAppTGTelegram