Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • E-mail Would Get Updated Privacy Protections Under Bicameral Bill
    • Commerce IG Finds Flaws in NIST’s Management of Cyber Vulnerability Database
    • Commerce’s Commitment to Connected Car Ban Questioned Following Volvo Deal
    • Governor Signs Connecticut Bill to Implement New Privacy Protections
    • Luxembourg DPA: Tourist Accommodation Operators May Not Copy ID Documents
    • New York Assembly Committee Advances Proposed Data Protection Act
    • Organizations Should Prioritize Privacy in Chatbot Use, Belgian Regulator Says
    • Privacy Safeguards Required for AI-Powered Employee Stress Monitoring, Garante Says
    • Singapore Cyber Agency Warns of Agentic AI Risks
    • The Week in State Privacy and Cybersecurity Legislation—May 25-29, 2026
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Luxembourg DPA: Tourist Accommodation Operators May Not Copy ID Documents, (Jun 1, 2026)

    By Tony Foley

    As summer tourist season opens, Luxembourg’s data protection authority, the National Commission for Data Protection (CNPD), has reminded operators of tourist accommodations that they are not allowed under data protection law to copy the identi ...

    By Tony Foley

    As summer tourist season opens, Luxembourg’s data protection authority, the National Commission for Data Protection (CNPD), has reminded operators of tourist accommodations that they are not allowed under data protection law to copy the identification documents of their clients.

    The agency said in a May 28 news release that under legislation enacted in February 2025, operators were obliged to establish an accommodation record for each traveler aged 15 and older and for each stay. To fulfill this obligation, operators are allowed to consult the identity documents of their clients, but CNPD emphasized that they may not make copies of the documents, as doing so constitutes a violation of the data minimization requirements of article 5(1)(c) of the European Union’s General Data Protection Regulation (GDPR).

    News: InternationalLegislation DataPrivacy GDPR

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use