Governance, trust and compliance
Overview
LuxID is a single-tenant sovereign SaaS identity provider operated by POST Luxembourg under delegation from the LuxID E.I.G.; this section is the authoritative governance, trust and compliance reference for organisations integrating with it.
LuxID is a Luxembourgish digital identity provider operated by POST Luxembourg. It is structured as a private-sector identity infrastructure - a sovereign identity platform serving Luxembourg's commercial ecosystem, not a government portal.
LuxID is governed by an Economic Interest Grouping (LuxID E.I.G.) whose founding members are POST Luxembourg, RTL Group, Cactus and CFL. POST Luxembourg operates the platform under delegation from the LuxID E.I.G. This structure means that governance obligations, contractual relationships and compliance accountability flow through two layers: the LuxID E.I.G. as the governing entity and POST Luxembourg as the operational entity.
For Partners integrating with LuxID, this section provides the authoritative reference on:
- How the trust framework is structured and where each party's obligations begin and end
- What certifications and accreditations LuxID holds or is pursuing
- How to become a LuxID Partner (the onboarding journey)
- What legal agreements govern the relationship
- How GDPR data protection obligations are allocated between LuxID and Partners
- The service-level commitments Partners can rely on
- How LuxID communicates and manages changes to its platform
Who this section is for
These pages are written for audiences who need more than a technical integration guide:
- Legal counsel reviewing the LuxID Agreement and data flows
- Enterprise IT architects assessing LuxID's trust model and security posture before signing off on integration
- Compliance and data protection officers verifying GDPR allocation of roles, eIDAS assurance levels and audit obligations
- Government and regulated-sector integrators (financial services, healthcare, telecom) requiring evidence of certification and regulatory alignment
- Security officers validating the platform's NIS2 readiness, ISO 27001 status and incident notification procedures
- Product owners understanding the onboarding timeline, SLA commitments and change-management process
Developers building the actual integration should also read Get started and the protocol-specific guides.
The LuxID trust model in brief
LuxID acts as the identity provider in an ecosystem of Relying Parties (called LuxID Partners). The trust model rests on three pillars:
1. A governance and operational structure. The LuxID E.I.G. provides strategic governance; POST Luxembourg provides operational accountability including security, availability, audit and GDPR compliance for the platform.
2. Tripartite contractual obligations. Each integrating Organization signs a single LuxID Agreement with POST Luxembourg (operator and GDPR controller) and the LuxID E.I.G. (brand and invoicing party). There is no separate Data Processing Agreement - LuxID and the Partner are independent controllers and the data protection framework is built into the LuxID Agreement. The contractual relationship sits at the Organization level; Partners (the technical API-access units) are then created administratively under the signed Organization and inherit its contractual posture. The agreement defines the permissible use of claims released by LuxID, the security baseline obligations and the mechanisms for resolving disputes.
3. Authentication levels structurally aligned with eIDAS principles. LuxID's auth_level scale has three tiers whose strength rationale mirrors the eIDAS Low / Substantial / High framework (Commission Implementing Regulation (EU) 2015/1502 (opens in a new tab)). LuxID is not a notified eID scheme and does not issue formal eIDAS LoA assertions; the alignment is structural, not legal equivalence. Partners declare the minimum level required for their service; LuxID enforces it at login time. See Authentication levels for the technical detail.
Pages in this section
| Page | Purpose |
|---|---|
| Trust framework | Legal entity structure, responsibility allocation, assurance model, audit obligations, security baseline |
| Certification and accreditation | LuxID's own certifications; Partner certification expectations by sector |
| Service provider onboarding | End-to-end journey from first contact to production credentials |
| Legal agreements and templates | LuxID Agreement structure, why no separate DPA is needed, privacy notice template, brand usage |
| GDPR and data protection | Controller/processor roles, lawful basis, user rights, breach notification |
| SLA and support | Availability targets, incident severity, support channels, DORA considerations |
| Change management and roadmap | Versioning policy, deprecation timelines, roadmap visibility |
Related sections
- Assurance Levels - eIDAS LoA mapping and enforcement
- Privacy and consent - Consent mechanics and claim release
- Protect your Application - Technical security baseline for Partners
- Events and Event Hub - Audit event streams available to Partners
- LuxID Verified - Identity Verification - High-assurance identity proofing
- Logs and audit trails - Console-side audit access
- Contact and support channels - Escalation paths