Legal agreements and templates
Overview
Every LuxID Partner relationship is governed by a single tripartite contract: the LuxID Agreement (referred to as the CIAM Agreement in the contract text itself). This page describes its structure, the key clauses Partners should be aware of, and the template text Partners can adapt for their own privacy notices and user-facing documentation.
All template clauses in this page are marked Template - adapt under legal review. They are starting points, not final legal text. Each Partner's legal counsel must review and adapt the templates for the Partner's own jurisdiction, user base and specific use case before publication.
The LuxID Agreement
Three parties, one contract
The LuxID Agreement is tripartite: it is signed by three parties.
| Party | Role |
|---|---|
| POST Luxembourg | Operator of the platform; GDPR controller for user data; counterparty for service, security and SLA matters |
| LuxID E.I.G. | Brand licensor and invoicing party; does not process user personal data |
| Partner (Client) | The organisation integrating LuxID into its applications; independent GDPR controller for any claims received |
There is one contract, not three. All three parties sign the same document. Operational matters route to POST; commercial and invoicing matters route to the LuxID E.I.G.; technical integration is the Partner's responsibility.
Structure
A standard LuxID Agreement is structured as a main body plus a set of annexes that form an integral part of the contract:
Main body
| Clause | Content |
|---|---|
| Definitions | Key terms used throughout the agreement and annexes |
| Purpose | What POST and the LuxID E.I.G. undertake to provide |
| Provision of the CIAM Solution | Scope of the service and access to attributes |
| Service Level Agreement | Reference to the SLA annex |
| Fees | Reference to the fees annex |
| Payment | Invoicing by LuxID E.I.G.; thirty-day payment terms |
| Roles and tasks (RACI) | Reference to the RACI annex |
| Obligations of the parties | Mutual obligations; specific obligations of POST, LuxID E.I.G. and the Partner |
| Liability | Limitation of liability; no joint liability |
| Insurance | Civil and professional liability insurance requirement |
| Intellectual property | Ownership of the platform, brand assets and licence grant |
| Subcontracting | POST and LuxID E.I.G. may subcontract; remain fully liable |
| Confidentiality | Mutual confidentiality obligations |
| Data protection | Each party is an independent controller; no sub-processing relationship |
| Change procedure | Process for Partner-initiated change requests |
| Representations and warranties | Standard reps from each party |
| Security | Reference to the security annexes |
| Services suspension | Grounds on which POST may suspend the service |
| Term and termination | Indefinite term from signature; standard and extraordinary termination rights |
| Force majeure | Suspension and termination for force majeure events |
| Final provisions | Assignment, notices, amendments, severability |
| Governing law and jurisdiction | Luxembourg law; Luxembourg courts |
Annexes
| Annex | Content |
|---|---|
| C1 | Definitions |
| C2 | Service Level Agreement (SLA) |
| C3 | Fees |
| C4 | RACI matrix |
| C5 | Client Security Standards (plain-language baseline expected from the Partner) |
| C6 | Attributes Catalogue (claims available to Partners) |
| G1 | CIAM Solution Specifications (technical architecture, protocols, environments) |
| G2 | POST Security Standards (controls and ISO alignment) |
| P1 | Ethical Code of Conduct |
Key commercial clauses
Permitted use. The agreement constrains what the Partner may do with the integration. Claims received from LuxID may not be sold, the LuxID Solution may not be used as a standalone resold service, and the Partner must comply with the Ethical Code of Conduct.
Claim scope. The Attributes Catalogue (Annex C6) enumerates the claims available. Partners declare at registration which claims they need; requesting claims outside that declared set will be rejected.
Term. The agreement starts on signature and runs for an indefinite period. There is no fixed initial term and no auto-renewal mechanism - it simply continues until a party terminates.
Termination. Either party may terminate without cause on three months' written notice. Extraordinary termination rights apply for material breach (one-month cure period), non-payment, insolvency or regulator-required termination.
Exit. On termination, the Partner must remove the LuxID integration from its applications (including the login button) and certify deletion in writing to POST. LuxID-received claim data must be handled in accordance with the Partner's own GDPR retention obligations.
Liability cap. Each party's liability is capped at the total amount actually paid under the agreement in the twelve months preceding the event. The cap does not apply to liability for violation of data protection legislation. Indirect damages (loss of profits, savings, customer base, contracts, staff costs, data loss) are excluded.
Insurance. Each party must maintain civil and professional liability insurance covering its activities under the agreement and provide a certificate on request.
Fees. The current pricing model (Annex C3) is volume-based on the trailing-12-month peak of unique sign-ups:
| Sign-ups (rolling 12 months) | Annual service fee |
|---|---|
| Up to 1,000 users | Free |
| 1,000 to 50,000 users | EUR 25,000 |
| Above 50,000 users | EUR 0.50 per user |
Prices are exclusive of VAT and may be indexed annually to the Luxembourg cost-of-living index (STATEC) or adjusted by up to 5% per year.
Suspension. POST may suspend the service for cause, including: scheduled or emergency maintenance, legal or regulatory requirements, suspected fraud, contractual breach, force majeure, unpaid invoices (after 30 days' notice limited to the unpaid service), individual user accounts whose passwords have been compromised, and threats to platform stability.
Why there is no separate data processing agreement
A common question from Partner legal teams is whether a separate Data Processing Agreement (DPA) under GDPR Article 28 (opens in a new tab) is required. The answer is no, and this is by design.
The relationship is controller-to-controller
The LuxID Agreement is explicit that POST and the Partner each act as independent data controllers for their own processing activities. POST is the controller for authentication event data and account profile data; the Partner becomes the controller for any claim it receives from LuxID once that claim is delivered to its application.
The release of claims from LuxID to the Partner is a disclosure between two independent controllers, not a processor acting on instructions. Neither party determines the purposes and means of the other party's processing, so the conditions for either joint controllership (Article 26 (opens in a new tab)) or processor status (Article 28 (opens in a new tab)) are not met.
The LuxID E.I.G. does not process user personal data
The LuxID E.I.G.'s processing activities under the agreement are limited to invoicing-related data about the Partner. It does not process user data. There is therefore no GDPR sub-processing relationship between POST and the LuxID E.I.G., and none between either of them and the Partner.
The LuxID Agreement is the data protection framework
Because there is no processor relationship, the data protection framework is built into the LuxID Agreement rather than alongside it:
- Article 28-type guarantees are not contractually required, but POST commits to equivalent security obligations through Annex G2 (POST Security Standards, ISO 27001-aligned)
- Breach notification obligations are set out directly in the main body and the SLA annex - see GDPR and data protection for the contractual 24h Urgent Security Matter clock and the statutory 72h GDPR Article 33 clock
- The Ethical Code of Conduct (Annex P1) imposes data-minimisation and consent obligations on both POST and the Partner that go beyond GDPR's statutory floor
Partners conducting GDPR due diligence on LuxID should refer to the LuxID Agreement clauses on data protection, the security annexes, and the controller-to-controller disclosure structure. There is no separate DPA to request.
Controller-to-controller disclosure clause
Template - adapt under legal review
If your legal team needs an explicit textual handle on the controller-to-controller relationship for internal documentation, the operative concept is:
LuxID releases the following categories of personal data to the Partner upon successful authentication of a user who has consented to that release: [list of claims]. The disclosure is made between two independent data controllers. Each party is independently responsible for compliance with applicable data protection law in respect of the data it controls following the disclosure. POST Luxembourg acts as controller for the authentication event record; [Partner Name] acts as controller for the disclosed claims from the point of receipt.
Privacy notice template for Partners
Purpose
Every Partner must publish a privacy notice that describes its use of LuxID authentication. The following template provides the sections a Partner privacy notice should include in relation to the LuxID integration. Partners should integrate this into their existing privacy notice rather than publishing it as a standalone document.
Template sections
Template - adapt under legal review
Section heading suggestion: Authentication via LuxID
What is LuxID?
We use LuxID, a Luxembourgish digital identity service operated by POST Luxembourg, to provide secure sign-in to [Partner Service Name]. When you choose to sign in with LuxID, you will be redirected to LuxID's hosted login page at https://login.luxid.lu (opens in a new tab). LuxID authenticates your identity and, with your consent, shares certain information about you with us.
LuxID's own privacy policy is available at https://www.luxid.lu/en/info/terms-and-conditions (opens in a new tab).
What information do we receive from LuxID?
When you sign in with LuxID, we receive the following information from LuxID, subject to your consent:
| Information | Why we use it | Legal basis |
|---|---|---|
| Email address | To create and manage your account in [Partner Service Name] | Contract (Art. 6(1)(b) GDPR) |
| Full name | To personalise your experience | Consent (Art. 6(1)(a) GDPR) |
| [Add further claims as applicable] | [State purpose] | [State lawful basis] |
Your rights
You may withdraw your consent to share information with us at any time by visiting your LuxID Account at https://account.luxid.lu/ (opens in a new tab) and removing [Partner Service Name] from the list of applications with access to your LuxID Account. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
For information LuxID holds about you (your authentication history, account profile), exercise your rights via https://account.luxid.lu/ (opens in a new tab) or by contacting LuxID at LuxID.
For information we hold about you on our side following receipt from LuxID, [describe Partner's rights mechanism].
Retention
We retain information received from LuxID for [state retention period]. [Describe deletion procedure on account closure.]
Transfers
LuxID processes your data within the European Union (Luxembourg). We [process / do not process] information received from LuxID outside the EEA. [If processing occurs outside the EEA, describe the transfer mechanism.]
Lawful basis guidance
The two most common lawful bases for claims received from LuxID are:
Contract (Article 6(1)(b)) applies where processing the claim is objectively necessary for the Partner to provide the service the user has requested. The email address is almost always in this category - without it, the Partner cannot create or maintain an account. The necessity test is strict: if the service could function without the claim, contract is not the correct basis.
Consent (Article 6(1)(a)) applies for claims that are useful but not strictly necessary - for example, phone number for optional 2FA in the Partner's own system, or profile picture for personalisation. Consent must be freely given, specific, informed and unambiguous. Because LuxID presents its own consent screen before releasing claims, the LuxID consent covers the release from LuxID. The Partner's own legal basis covers what the Partner does with the claim once received.
Partners should not use legitimate interests (Article 6(1)(f)) as the lawful basis for processing authentication data received from LuxID unless they have completed a documented legitimate interests assessment (LIA) and are satisfied that the user's interests do not override the Partner's interests.
Brand usage agreement
What requires a brand licence
The following elements are protected intellectual property of the LuxID E.I.G. / POST Luxembourg and require the LuxID Agreement to be in place before use:
- The "LuxID" wordmark
- The LuxID logo and logo variants
- The "Sign in with LuxID" button assets
- Any phrase stating or implying that the Partner is endorsed, certified or approved by LuxID (beyond the factual statement that the Partner uses LuxID authentication)
Permitted uses
Once the LuxID Agreement is signed at the Organization level, the Organization and the Partners created under it may:
- Display the "Sign in with LuxID" button on their login page using the approved assets provided by LuxID
- State factually in their privacy notice and marketing materials that their service uses LuxID authentication
- Use the LuxID wordmark in the context of describing the integration (for example, "We support sign-in with LuxID")
Prohibited uses
Without explicit written permission beyond the LuxID Agreement:
- The LuxID logo may not be used in a manner that implies partnership at the corporate level (for example, in a "Backed by" or "Partner logos" section)
- The LuxID wordmark may not be modified, recoloured or distorted
- The "Sign in with LuxID" button may not be resized below the minimum dimensions or modified in appearance
- LuxID branding may not appear in advertising in a manner that could be misleading about the nature of the relationship
Template - adapt under legal review
A sample brand attribution clause for a Partner's "About" or "Security" page:
[Partner Service Name] uses LuxID for secure sign-in. LuxID is a Luxembourgish digital identity service operated by POST Luxembourg. The "Sign in with LuxID" button and LuxID logo are trademarks of their respective owners and are used under licence.
Acceptable use clauses
The LuxID Agreement contains standard acceptable use clauses. The following summarises the most material restrictions.
Template - adapt under legal review - the following reflects the standard clauses; review the executed agreement for the binding text.
| Restriction | Description |
|---|---|
| Authentication only | LuxID authentication may only be used for the purpose of authenticating users to the Partner's own service. It may not be used as a signal for any other purpose (for example, presence detection, fraud scoring systems not related to the Partner's service, or third-party data enrichment). |
| No claim resale | Claims received from LuxID may not be sold, licensed, or otherwise transferred to third parties. |
| No impersonation | The Partner must not use LuxID authentication in a manner that could mislead users into believing they are interacting with LuxID directly. |
| No reverse engineering | The Partner must not attempt to reverse-engineer LuxID's authentication mechanisms, token structures or internal APIs. |
| No automated account creation | The Partner must not use LuxID authentication to programmatically create or enumerate user accounts. |
| Security reporting | The Partner must report security vulnerabilities discovered in the LuxID platform to LuxID and must not disclose such vulnerabilities publicly before LuxID has had a reasonable opportunity to remediate. |