Aller au contenu principal
Version 0.1Brouillon

Governance, trust and compliance

Overview

LuxID is a single-tenant sovereign SaaS identity provider operated by POST Luxembourg under delegation from the LuxID E.I.G.; this section is the authoritative governance, trust and compliance reference for organisations integrating with it.

LuxID is a Luxembourgish digital identity provider operated by POST Luxembourg. It is structured as a private-sector identity infrastructure - a sovereign identity platform serving Luxembourg's commercial ecosystem, not a government portal.

LuxID is governed by an Economic Interest Grouping (LuxID E.I.G.) whose founding members are POST Luxembourg, RTL Group, Cactus and CFL. POST Luxembourg operates the platform under delegation from the LuxID E.I.G. This structure means that governance obligations, contractual relationships and compliance accountability flow through two layers: the LuxID E.I.G. as the governing entity and POST Luxembourg as the operational entity.

For Partners integrating with LuxID, this section provides the authoritative reference on:

  • How the trust framework is structured and where each party's obligations begin and end
  • What certifications and accreditations LuxID holds or is pursuing
  • How to become a LuxID Partner (the onboarding journey)
  • What legal agreements govern the relationship
  • How GDPR data protection obligations are allocated between LuxID and Partners
  • The service-level commitments Partners can rely on
  • How LuxID communicates and manages changes to its platform

Who this section is for

These pages are written for audiences who need more than a technical integration guide:

  • Legal counsel reviewing the LuxID Agreement and data flows
  • Enterprise IT architects assessing LuxID's trust model and security posture before signing off on integration
  • Compliance and data protection officers verifying GDPR allocation of roles, eIDAS assurance levels and audit obligations
  • Government and regulated-sector integrators (financial services, healthcare, telecom) requiring evidence of certification and regulatory alignment
  • Security officers validating the platform's NIS2 readiness, ISO 27001 status and incident notification procedures
  • Product owners understanding the onboarding timeline, SLA commitments and change-management process

Developers building the actual integration should also read Get started and the protocol-specific guides.

The LuxID trust model in brief

LuxID acts as the identity provider in an ecosystem of Relying Parties (called LuxID Partners). The trust model rests on three pillars:

1. A governance and operational structure. The LuxID E.I.G. provides strategic governance; POST Luxembourg provides operational accountability including security, availability, audit and GDPR compliance for the platform.

2. Tripartite contractual obligations. Each integrating Organization signs a single LuxID Agreement with POST Luxembourg (operator and GDPR controller) and the LuxID E.I.G. (brand and invoicing party). There is no separate Data Processing Agreement - LuxID and the Partner are independent controllers and the data protection framework is built into the LuxID Agreement. The contractual relationship sits at the Organization level; Partners (the technical API-access units) are then created administratively under the signed Organization and inherit its contractual posture. The agreement defines the permissible use of claims released by LuxID, the security baseline obligations and the mechanisms for resolving disputes.

3. Authentication levels structurally aligned with eIDAS principles. LuxID's auth_level scale has three tiers whose strength rationale mirrors the eIDAS Low / Substantial / High framework (Commission Implementing Regulation (EU) 2015/1502 (opens in a new tab)). LuxID is not a notified eID scheme and does not issue formal eIDAS LoA assertions; the alignment is structural, not legal equivalence. Partners declare the minimum level required for their service; LuxID enforces it at login time. See Authentication levels for the technical detail.

Pages in this section

PagePurpose
Trust frameworkLegal entity structure, responsibility allocation, assurance model, audit obligations, security baseline
Certification and accreditationLuxID's own certifications; Partner certification expectations by sector
Service provider onboardingEnd-to-end journey from first contact to production credentials
Legal agreements and templatesLuxID Agreement structure, why no separate DPA is needed, privacy notice template, brand usage
GDPR and data protectionController/processor roles, lawful basis, user rights, breach notification
SLA and supportAvailability targets, incident severity, support channels, DORA considerations
Change management and roadmapVersioning policy, deprecation timelines, roadmap visibility
Mise à jour le 2026-05-22