The classic trap
Recital 165 confirms that the GDPR does not override national constitutional regimes governing churches and religious communities, and illuminates Article 91 (pre-existing internal rules). In practice, the CNPD and CNIL accept that a recognised church or congregation may rely on its own data protection rules, provided they existed on 24 May 2016 and remain in line with the GDPR, under independent supervisory authority oversight. The trap: assuming this status exempts from any GDPR compliance, when it only covers pre-existing internal rules and does not waive the register, DPIA or breach notification duties.
The concrete test: is your religious regime really covered by Article 91 ?
- Did the internal data protection rules exist before 24 May 2016 and are they formalised (episcopal decree, consistorial regulation, canonical statute) ?
- Is the religious organisation recognised under the constitutional law of the Member State (in Luxembourg: 2015 State-cults conventions, law of 13 February 2018) ?
- Do internal rules cover Article 5 principles, data subject rights, security, transfers ?
- Is there an independent religious supervisory authority (the German KDG/KDR model) or does the CNPD remain competent ?
- Processing unrelated to the religious mission (lay staff payroll, donor database, faith-based schools) falls under full GDPR, with no carve-out.
In Luxembourg, none of the six conventioned communities (Catholic, Reformed Protestant, Protestant, Jewish, Anglican, Greek and Romanian Orthodox) has notified Article 91 internal rules to the CNPD. Concretely, the GDPR applies in full to archdioceses, parishes, church fabrics and religious associations in Luxembourg, with no derogatory regime.
How Luxgap automates this risk
Our Luxgap Faith Compliance Mapper turns the religious and faith-based organisation puzzle into an operational map that separates, processing by processing, what falls under the cultic regime protected by Recital 165 and what reverts to standard GDPR. The tool cross-references your processing register, canonical statutes, State-cults conventions and EDPB case law to produce an enforceable qualification matrix.
- Classifies each processing activity (baptismal register, parishioner database, lay staff payroll, faith-based schooling, donations and legacies) depending on whether it serves the religious mission or a civil activity under full GDPR.
- Automatically checks whether your organisation benefits from a valid Article 91 regime by mapping your internal statutes against the EDPB framework and CNPD doctrine.
- Generates tailored legal bases: cultic legitimate interest for the faithful register, explicit consent under Article 9(2)(d) for religious belief data, legal obligation for payroll.
- Detects sensitive cross-border flows (registers sent to the Vatican, the Central Consistory, the headquarters of a religious order outside the EU) and proposes the right transfer framework.
- Produces a timestamped PDF report enforceable before the CNPD, evidencing the legal qualification adopted and Article 5(2) accountability.
Available alongside a Luxgap DPO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual processing, with a free 48-hour blank audit to measure your exposure before any commitment.