Trust framework
What is the LuxID trust framework
The LuxID Trust Framework is the set of governance rules, contractual obligations, technical standards and regulatory alignments that define how LuxID, its Partners, and the users of those Partners interact and what each party can rely on.
It answers three foundational questions for any organisation evaluating a LuxID integration:
- Who is accountable for what? - Legal entity structure, operational delegation and the boundaries between LuxID's obligations and the Partner's obligations.
- What assurance can be placed on a LuxID authentication event? - How LuxID classifies assurance levels, how Partners declare requirements and how cross-border recognition works.
- What evidence of that assurance is available? - Audit log obligations, security certifications and the regulatory framework LuxID operates within.
Legal entity structure
The LuxID E.I.G
LuxID is governed by an Economic Interest Grouping (LuxID E.I.G.) - a legal form under Luxembourg commercial law that allows distinct entities to pool resources for a shared economic purpose while retaining their individual legal personalities. The founding LuxID E.I.G. members are:
- POST Luxembourg
- RTL Group
- Cactus
- CFL (Chemins de Fer Luxembourgeois)
The official purpose of the LuxID E.I.G. is the promotion and commercialisation of the service, together with supervising the operation of the platform as a trusted third party (in the original French: "Promotion et commercialisation, ainsi que la supervision de l'opération de plateforme en tant que tiers de confiance").
In line with that purpose, the LuxID E.I.G. holds the intellectual property rights in the LuxID platform, sets the strategic direction of the service, approves changes to the Trust Framework, and is the ultimate counterparty for Partners requiring an executed agreement at the strategic level.
POST Luxembourg as operator
POST Luxembourg operates the LuxID platform under a formal delegation from the LuxID E.I.G. As the operational entity, POST Luxembourg:
- Runs and maintains the production infrastructure (login, account management, event systems)
- Is a signatory party to the LuxID Agreement, in its capacity as operator and as controller for the user data processed by the platform
- Employs the engineering, security and support teams responsible for the platform
- Holds the GDPR Data Protection Officer appointment for the platform
- Reports to the Luxembourg CNPD (Commission nationale pour la protection des données) as the supervisory authority
- Is accountable to the Luxembourg ILR (Institut Luxembourgeois de Régulation) where applicable for electronic communications elements
LuxID E.I.G. as brand licensor and invoicing party
The LuxID E.I.G. is the second commercial party to the LuxID Agreement. Its role is narrow but distinct from POST's:
- Holds the LuxID brand and licenses it for use by the platform
- Issues the invoices for the service and receives payment from the Partner
- Does not process user personal data; its processing is limited to invoicing-related data about the Partner
This split matters legally: POST is the operator and the GDPR controller for user data, the LuxID E.I.G. is the brand and commercial counterparty. There is no GDPR sub-processing relationship between POST and the LuxID E.I.G.
What this means for organizations and Partners
The LuxID Agreement is tripartite: it is signed by POST Luxembourg, the LuxID E.I.G. and the Partner organisation. Once signed, the technical Partners created under the organisation inherit the contractual relationship; day-to-day technical work happens at the Partner level while the legal-administrative relationship stays at the organisation level.
For practical contact routing:
- Operational issues, incidents, SLA, change requests - POST Luxembourg, via the POST Customer Service Centre. See SLA and support.
- Invoicing, billing queries, contract amendments - LuxID E.I.G., typically through the POST Luxembourg account manager who manages the relationship.
- LuxID E.I.G.-level governance - only required if the organisation is itself a LuxID E.I.G. member or is negotiating a governance-level arrangement.
See Contact and support channels.
Responsibility allocation
The trust framework defines three principals - the Operator (POST Luxembourg), the Partner and the User - and maps obligations to each.
Operator obligations (POST Luxembourg)
| Obligation | Description |
|---|---|
| Availability | Maintain the agreed service availability target. Announce planned maintenance in advance. Communicate incidents to Partners technical contacts. |
| Security | Operate the platform to at minimum ISO 27001 and ETSI EN 319 401 security standards (see Security Baseline for certification status). Conduct regular penetration testing. Rotate cryptographic keys on schedule. |
| Audit | Retain authentication event logs for the documented retention period. Make logs available to Partners via the Console and Event Hub. Provide evidence of controls to auditors upon request under NDA. |
| GDPR | POST acts as controller for authentication event data and account profile data. Honour user rights (Articles 15-22 of GDPR) via https://account.luxid.lu/ (opens in a new tab). Maintain a Record of Processing Activities (RoPA). Notify Partners of any Urgent Security Matter within 24 hours of detection (contractual), and notify the CNPD of personal data breaches within 72 hours of awareness (statutory, GDPR Article 33 (opens in a new tab)). |
| Compliance | Maintain alignment with eIDAS and applicable Luxembourg law. Cooperate with supervisory authority investigations. |
| Transparency | Publish the Partner-facing Terms, Privacy Policy and Trust Framework. Communicate changes with appropriate notice. |
Partner obligations
By signing the LuxID Agreement, a Partner accepts the following obligations. These are enforced contractually; breach may result in suspension or termination of access.
| Obligation | Description |
|---|---|
| Lawful basis | Declare and maintain a documented lawful basis under GDPR for every claim received from LuxID and stored in the Partner's system. |
| Data minimisation | Request only the Claim Templates necessary for the Partner's service. Do not request claims speculatively or for future use cases not covered by the current LuxID Agreement scope. |
| Secure integration | Implement the technical security baseline set out in Protect your Application. This includes HTTPS enforcement, PKCE on all authorisation flows, validated redirect URIs and secure token storage. |
| Privacy notice | Publish a privacy notice that accurately describes the LuxID integration, the claims received, the legal basis and the user's rights. A template paragraph is provided in Legal agreements and templates. |
| Incident notification | Notify POST without undue delay of any security incident that may involve LuxID authentication data or LuxID user accounts, via LuxID with subject SECURITY INCIDENT. |
| Change notification | Notify LuxID of any material changes to the Partner's application architecture, redirect URIs or claim usage before those changes go live in production. |
| Audit cooperation | Cooperate with LuxID's reasonable audit or assurance requests, including providing evidence of the Partner's own security controls on request. |
User rights
Users of LuxID retain the following rights, which LuxID and Partners are jointly responsible for facilitating depending on where the data is held:
| Right | Where exercised |
|---|---|
| Access (Art. 15) | LuxID-held data: https://account.luxid.lu/ (opens in a new tab). Partner-held data: Partner's own rights mechanism. |
| Rectification (Art. 16) | LuxID-held data: account settings. Partner-held data: Partner's mechanism. |
| Erasure (Art. 17) | LuxID Account deletion: https://account.luxid.lu/ (opens in a new tab). Partner must erase claims received from LuxID upon valid erasure request. |
| Portability (Art. 20) | Data export available at https://account.luxid.lu/ (opens in a new tab). Partner provides its own export for Partner-side data. |
| Consent revocation | User can revoke a Partner's access via https://account.luxid.lu/ (opens in a new tab) under Applications. LuxID will stop releasing claims on future authentications; the Partner must stop processing on existing claims once notified. |
| Restriction and objection (Arts. 18-21) | Handled via LuxID or the DPO contact. |
Assurance model
Assurance levels
LuxID implements three assurance levels aligned with Commission Implementing Regulation (EU) 2015/1502 (opens in a new tab), which defines technical specifications for assurance levels under eIDAS Regulation (EU) 910/2014 (opens in a new tab):
| Level | eIDAS label | LuxID implementation |
|---|---|---|
| Low | Low | Password authentication only |
| Substantial | Substantial | Password plus a second authentication factor (OTP, TOTP or passkey) |
| High | High | LuxTrust (hardware-backed qualified credential, auth_level 9) |
The full technical mapping is documented in Assurance Levels.
How Partners declare a required assurance level
Partners declare their minimum required assurance level in their LuxID Application configuration, on a per-application basis. The declaration is reviewed during the go-live process. Accepted values are low, substantial and high.
Once configured, LuxID enforces the declared minimum at authentication time. If a user's session does not meet the required assurance level, LuxID prompts the user to step up before returning control to the Partner's redirect URI.
Partners must not accept authentication responses that report a lower assurance level than the one they declared.
The assurance level of a completed authentication is reported in the acr (Authentication Context Class Reference) claim in the OIDC ID token. Partners receiving this claim are responsible for validating it against their declared minimum.
Cross-border assurance level mapping under eIDAS
Cross-border eIDAS federation - accepting authentication from eIDAS-notified identity schemes (for example, a user authenticating with a French FranceConnect credential) with the notified LoA mapped to the LuxID assurance level per Regulation (EU) 910/2014 Article 8 (opens in a new tab) - is a planned capability on the LuxID roadmap, not yet available. The mapping rules will be documented when the integration launches.
Assurance level and eIDAS 2.0
The forthcoming Regulation (EU) 2024/1183 (opens in a new tab) (eIDAS 2.0, EUDI Wallet framework) will introduce additional assurance requirements and a new wallet-based authentication mechanism. LuxID's alignment with eIDAS 2.0 is on the roadmap.
Audit trail obligations
What LuxID logs
LuxID generates and retains audit logs for all authentication events. The log record for each event includes at minimum:
- Timestamp (UTC)
- Event type (login, logout, token refresh, failed authentication, MFA step)
- User pseudonymous identifier (not the user's email in Partner-facing logs)
- Partner application (client ID)
- Assurance level achieved
- Outcome (success, failure, step-up required)
- IP address and user agent (retained for security analysis; subject to GDPR pseudonymisation rules)
LuxID retains authentication event logs for 6 months on a rolling basis (see GDPR and data protection for the full retention schedule; cookie and navigation data has a separate 13-month maximum). Partners may access their own application's authentication event stream via:
- The LuxID Console audit view: see Logs and audit trails
- The Event Hub webhook stream: see Events and Event Hub
What the Partner must log
Partners are responsible for maintaining their own audit trail covering at minimum:
- The authentication response received from LuxID (including the
acrclaim and session identifier) - The claims received and stored
- Any access control decisions made on the basis of the LuxID authentication
- Consent records: when consent was given, for which claims, and any revocation events
These Partner-side logs are necessary to demonstrate compliance with GDPR accountability obligations (Article 5(2)) and to support the Partner's own regulatory audits.
Evidence of controls
Partners conducting IT audits or regulatory assessments may request evidence of LuxID's security controls. Requests should be directed to LuxID. Evidence is provided under NDA and may include:
- Summary certification statements (ISO 27001 certificate where issued)
- Penetration test executive summaries
- GDPR Article 30 records (summary level)
- Availability and incident statistics for the preceding 12 months
Security baseline
ISO 27001 and ISO 27701
POST Telecom (the POST Luxembourg subsidiary operating the LuxID infrastructure) is certified ISO/IEC 27001:2022 for its Information Security Management System. The certification covers the management and operation of POST's managed services, including the data centres, infrastructure operations and supporting processes on which LuxID runs.
POST also operates aligned with ISO 27701:2019 (privacy information management extension to ISO 27001) for the processing activities relevant to LuxID, although LuxID is not itself certified as a distinct scope. The LuxID platform inherits POST Telecom's certified procedures and controls but is not enrolled in the certification scope as a stand-alone service. Partners requiring a stand-alone certificate for LuxID should plan around this and rely on the POST Telecom certificate plus the contractual security commitments in the LuxID Agreement security annex.
Operational security controls
The LuxID platform inherits POST's certified security programme, including:
- Documented data encryption and key management policy; trusted signed certificates for HTTPS-based access; secure transport protocols (FTPS, LDAPS, SSH) where applicable
- Pseudonymisation by separation of identifiers from data wherever the processing allows it
- No use of real personal data in test and development environments by default; exceptions require business-owner approval and documented audit trail
- RBAC and need-to-know access control with documented segregation of access-request, access-authorisation and access-administration roles
- Mandatory MFA (password + OTP) for all remote access to POST infrastructure
- Secure software development lifecycle (SSDLC) covering security-by-design, code review, code quality, security testing, penetration testing and DevOps security gates
- Annual security awareness training and phishing simulation for all POST staff
- 24/7 Security Operations Centre (SOC) running SIEM, IDS and threat intelligence feeds
These controls are documented in the security annex of the LuxID Agreement.
Platform protection
At the network and application layer, the LuxID platform sits behind:
- Network firewalls and anti-DDoS at the edge
- Web Application Firewalls handling SSL termination and application-level inspection
- Load balancers distributing traffic across redundant CIAM instances in geographically separated Luxembourg data centres
- Dedicated IPv4 and IPv6 ranges for LuxID (production and non-production do not share IPs)
- TLS 1.2 minimum (TLS 1.3 recommended) on
luxid.lu, served over HTTP/2 with HTTP/1.1 fallback on TCP/443
Bot and abuse protection uses risk-based authentication, MFA and internal CAPTCHA mechanisms. LuxID does not use Google reCAPTCHA; this is an explicit privacy-driven choice and Partners can rely on it when describing their LuxID dependency.
ETSI EN 319 401
LuxID's operational security policies are aligned with ETSI EN 319 401 v2.3.1 (opens in a new tab) (General Policy Requirements for Trust Service Providers), which provides the applicable European standard for trust service operators.
NIS2 readiness
Directive (EU) 2022/2555 (opens in a new tab) (NIS2) establishes cybersecurity obligations for essential and important entities, including digital identity providers operating in Luxembourg. LuxID, as part of POST Luxembourg's infrastructure, is subject to NIS2 obligations.
NIS2 obligations relevant to Partners include:
- Partners in regulated sectors (banking, energy, transport, healthcare) are themselves likely to be NIS2 entities and must assess LuxID as a third-party ICT dependency in their own supply chain risk management.
- LuxID will provide Partners with the documentation they need to satisfy NIS2 third-party due diligence, including security summaries and contractual commitments on incident notification timelines.
Applicable Luxembourg law
LuxID operates under Luxembourg law, subject to:
- The loi du 1er août 2018 on the organisation of the CNPD and the general data protection framework (transposing GDPR in Luxembourg)
- The loi du 28 mai 2019 relative to the security of networks and information systems (transposing NIS in Luxembourg; to be updated for NIS2)
- Applicable ILR regulations on electronic communications where relevant to OTP delivery infrastructure