Luxembourg: Exchange Of Information Vs Data Protection: A Brave New World Of Transparency

Last Updated: 3 December 2018
Article by Antoine Dupuis and Gilles Sturbois

Automatic exchange of information ("AEoI") was developed a decade ago as the new cure-all in the fight against tax fraud for developed countries' tax administrations. In our new context of global transparency, the set-up of these instruments seems to be an unstoppable trend.

However, while the purpose of AEoI is legitimate and reversing the situation is not an option, the AEoI raises, in its current form, genuine difficulties as regards fundamental principles in European law.

Let's quickly take a look at the origins of AEoI and explain why it has developed so rapidly. Afterwards, we'll discuss why the AEoI standards are in conflict with fundamental taxpayers' rights. Finally, we'll give you our thoughts about how to increase compatibility between the AEoI and the right to privacy.

AEOI, how it all began

Exchange of information ("EoI") is almost older than the main staple of international tax law, double tax treaties ("DTT"): the first references to information exchange appear in the 1843 tax agreement between France and Belgium1. The OECD model convention has included an "exchange of information clause" from the very beginning2.

EoI has three components: spontaneous exchange, exchange on request and automatic exchange. We can also identify a fourth type of exchange, the extraterritorial tax audit, which has emerged from the Directive on Administrative Cooperation ("DAC"). Until the 2000s, automatic exchange of information was still in its infancy and EoI on request was the only tool used by tax authorities.

The only real automatic exchange of information that had existed previously was the QI3 protocol between the United States IRS4 and foreign banks which guaranteed easier access to tax treaties signed between the country of residence of the foreign bank and the US. This heightened ease of access was based on the transfer of information concerning US taxpayers who had financial assets in these foreign banks to the IRS.

The implementation of ("FATCA")5 completely changed the paradigm and made exchange of information the go-to weapon in the fight against tax fraud by individuals. In 2010, FATCA imposed a bilateral data transfer between US citizens who are either clients of non-US banks or investors in non-US financial institutions, and the IRS.

This data transfer includes personal information about investors as well as information related to the investor's bank accounts, amount of financial assets, and yearly revenues. Thanks to the IGA[6], the IRS has been able to integrate these rules into the local law of the States adopting FATCA norms. In this way, for the countries which opt for IGA model 1, the model most frequently adopted by third countries, an information transfer of the US investor's data occurs firstly from the financial institution or bank to his tax administration and secondly, from the tax administration to IRS.

In 2013, it appeared that the OECD tax commission decided to take some inspiration from FATCA and apply its principles to a multilateral approach. The Common Reporting Standard ("CRS") was born. Approved by the OECD counsel on 15 July 2013, this new multilateral approach to AEoI was subsequently validated by the European Counsel when CRS was added to the DAC in October 2014. Even if real practical and theoretical differences exist between these three standards (FATCA/CRS/DAC), they do share common objectives and similarities in how they are implemented.

The speed at which world has gone from bilateral exchange on request to a multilateral AEoI has been breakneck, and even more so if we consider that this development has also brought an end to banking secrecy. The rapid pace of change demonstrates tax administrations' ultimate goal to put a stop to perceived international tax fraud. The purpose as stated seems legitimate but the instruments used to accomplish this purpose raise questions as to rights to privacy as well as other taxpayer rights.

Issues created by the AEoI

AEoI has created difficulties with regard to data protection and the right to privacy of taxpayers involved in the automatic information exchange. The exchange involves a (i) transfer of information collected by the financial institution to the reference tax administration; this tax administration then (ii) transmits data to a third party tax administration which retains in fine (iii) the information and uses it for their tax auditing purposes. With each of these steps, comes a risk of a data breach. This risk has been known from the beginning, to the point where CRS allows for the possibility to exchange information only between jurisdictions with comparable levels of IT security. However, in the rush to reach political consensus with this topic, taxpayer rights might not have been given sufficient consideration when assessing issues created by the AEoI prior to its implementation.

But what rights are we talking about? Provisions relating to privacy rights are clearly set out in Article 8 of the European Convention on Human Rights. Article 8 states that everyone has the right to privacy in their personal and family life, their home and their communications. The authorities must not breach this right except within specific circumstances related to national security or the economic interests of a country. Equivalent rules are set out in Article 7 of Charter of Fundamental Rights of the European Union. And Article 8 of the same Charter establishes the main principles governing the protection of personal data. The EU General Data Protection Regulation7 ("GDPR") is in line with this thinking by requiring organisations to take into account the protection of the personal data that they handle, process and store and therefore, to maintain a secure information system.

The DAC has been amended in direct reference to the Directive 2014/107/EU. Following these amendments, reporting organisations have been labeled as "data protection officers". Therefore, exchange of information is directly targeted by data protection regulations and thus by the GDPR. In the context of the multilateralisation and automatisation of the exchange of information, the question is not to know if breaches will happen, but when breaches will happen. Failed systems of a tax administration could misplace information; data might be lost, stolen or poorly managed, all these acts would constitute a breach according to the right to privacy.

These potential breaches are as numerous as the exchange of information systems themselves:

  1. Three standards now coexist, leading to difficulties in controlling these norms and therefore generating operational risks;
  2. These standards were designed to be multilateral and involve as many jurisdictions as possible;
  3. These standards multiply the volume of data and the volume of data transmitted.

Furthermore, the tax administrations in their efforts to make the exchange as exhaustive and efficient as possible, have only rarely reviewed other jurisdictions' ability to receive the data while ensuring optimal IT security or even ensure a fair reciprocal exchange of information. It could be noted that the US do not seem willing to systematically provide to foreign administrations their fair share of reciprocal exchange of information. It could also be noted that most countries seem to have not paid close attention to the state of democracy in the countries with which they exchange. A real risk exists that the data exchanged will be used by authoritarian states or democratic-dictatorships, in clear opposition of the principles laid down in Charter of Fundamental Rights of the European Union. In this case, there is little doubt that information obtained through AEoI mechanisms might be at risk of being exploited by a foreign government for political reasons.

We are not alone in our finding of inconsistency between the AEoI and data protection regulation. Some taxpayers8 have even brought legal action against the various exchange of information standards. Undoubtedly, some of these cases will be won by the taxpayer and will help create a system which is more sensitive to and respectful of the taxpayer's fundamental rights.

Another disputable topic seems the respect of the rights to a fair trial for the taxpayer. As the taxpayer is not systematically informed of the exchange of information he is submitted to, these rights seems to be widely ignored by EoI, automatic and on demand.

All this raises an essential question: do the ends justify the means? Once exchange of information has grown out of its infancy and tax administrations have drawn their first conclusions, it will be critical to reevaluate the coherence of all the standards and weigh the risks posed by their artificial coexistence. The AEoI has become an integral component of the international tax landscape and nothing will change this. However, there is ample room for improvement through a series of actions that we describe below.

The AEoI has a bright future... and will continue for a long time...

In order address some of the current issues as well as to limit the risk of data breaches in the future, the OECD should turn their attention to improving the system in the following areas:

  1. Harmonisation of automatic exchange with the switch from the three standards in favor of a single one;
  2. The adherence to this single standard by the US, therefore replacing and ending FATCA and achieving reciprocity;
  3. A simplification of the information transmitted. For example, declaring only foreign accounts without indicating an amount. Tax administrations would then be responsible for collecting missing information through specific information requests;
  4. The development of a common IT infrastructure in order to provide the highest guarantee of IT security in all jurisdictions;
  5. Set limits to the duration of data retention;
  6. Effective consideration to the taxpayers' rights (e.g.: more systematic information to the taxpayers who are subject to the EoI) and the risks of misuse of the exchanged information.

There are many technical but above all political obstacles to the implementation of this exchange. As things stand, such obstacles seem quite difficult to overcome. As a consequence, we believe that if the system is not able to reform itself, the risk of increasing criticism and legal actions is not minor. We cannot exclude that in the future, such criticism even could call into question the very principle of EoI in and with some jurisdictions; it will be interesting to observe future developments in this discussion.


1 " Convention pour régler les relations des administrations de l'enregistrement de France et de Belgique " dated 08/12/1843

2 OECD Model tax convention dated 1963

3 IRC par. 1441, qualified intermediary regulation.

4 Internal Revenue Service

5 Foreign Account tax compliance act was passed as part of the HIRE Act in 2010.

6 Intergovernmental Agreement

7 European regulation n°2016/679 / GDPR Directive adopted by the European Parliament on April 2016.

8 Cf. Financial Times August, 1st 2018: " EU national challenges HMRC over new data sharing rules ".

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

To print this article, all you need is to be registered on

Click to Login as an existing user or Register so you can print this article.

Some comments from our readers…
“The articles are extremely timely and highly applicable”
“I often find critical information not available elsewhere”
“As in-house counsel, Mondaq’s service is of great value”

Related Topics
Related Articles
Up-coming Events Search
Font Size:
Mondaq on Twitter
Mondaq Free Registration
Gain access to Mondaq global archive of over 375,000 articles covering 200 countries with a personalised News Alert and automatic login on this device.
Mondaq News Alert (some suggested topics and region)
Select Topics
Registration (please scroll down to set your data preferences)

Mondaq Ltd requires you to register and provide information that personally identifies you, including your content preferences, for three primary purposes (full details of Mondaq’s use of your personal data can be found in our Privacy and Cookies Notice):

  • To allow you to personalize the Mondaq websites you are visiting to show content ("Content") relevant to your interests.
  • To enable features such as password reminder, news alerts, email a colleague, and linking from Mondaq (and its affiliate sites) to your website.
  • To produce demographic feedback for our content providers ("Contributors") who contribute Content for free for your use.

Mondaq hopes that our registered users will support us in maintaining our free to view business model by consenting to our use of your personal data as described below.

Mondaq has a "free to view" business model. Our services are paid for by Contributors in exchange for Mondaq providing them with access to information about who accesses their content. Once personal data is transferred to our Contributors they become a data controller of this personal data. They use it to measure the response that their articles are receiving, as a form of market research. They may also use it to provide Mondaq users with information about their products and services.

Details of each Contributor to which your personal data will be transferred is clearly stated within the Content that you access. For full details of how this Contributor will use your personal data, you should review the Contributor’s own Privacy Notice.

Please indicate your preference below:

Yes, I am happy to support Mondaq in maintaining its free to view business model by agreeing to allow Mondaq to share my personal data with Contributors whose Content I access
No, I do not want Mondaq to share my personal data with Contributors

Also please let us know whether you are happy to receive communications promoting products and services offered by Mondaq:

Yes, I am happy to received promotional communications from Mondaq
No, please do not send me promotional communications from Mondaq
Terms & Conditions (the Website) is owned and managed by Mondaq Ltd (Mondaq). Mondaq grants you a non-exclusive, revocable licence to access the Website and associated services, such as the Mondaq News Alerts (Services), subject to and in consideration of your compliance with the following terms and conditions of use (Terms). Your use of the Website and/or Services constitutes your agreement to the Terms. Mondaq may terminate your use of the Website and Services if you are in breach of these Terms or if Mondaq decides to terminate the licence granted hereunder for any reason whatsoever.

Use of

To Use you must be: eighteen (18) years old or over; legally capable of entering into binding contracts; and not in any way prohibited by the applicable law to enter into these Terms in the jurisdiction which you are currently located.

You may use the Website as an unregistered user, however, you are required to register as a user if you wish to read the full text of the Content or to receive the Services.

You may not modify, publish, transmit, transfer or sell, reproduce, create derivative works from, distribute, perform, link, display, or in any way exploit any of the Content, in whole or in part, except as expressly permitted in these Terms or with the prior written consent of Mondaq. You may not use electronic or other means to extract details or information from the Content. Nor shall you extract information about users or Contributors in order to offer them any services or products.

In your use of the Website and/or Services you shall: comply with all applicable laws, regulations, directives and legislations which apply to your Use of the Website and/or Services in whatever country you are physically located including without limitation any and all consumer law, export control laws and regulations; provide to us true, correct and accurate information and promptly inform us in the event that any information that you have provided to us changes or becomes inaccurate; notify Mondaq immediately of any circumstances where you have reason to believe that any Intellectual Property Rights or any other rights of any third party may have been infringed; co-operate with reasonable security or other checks or requests for information made by Mondaq from time to time; and at all times be fully liable for the breach of any of these Terms by a third party using your login details to access the Website and/or Services

however, you shall not: do anything likely to impair, interfere with or damage or cause harm or distress to any persons, or the network; do anything that will infringe any Intellectual Property Rights or other rights of Mondaq or any third party; or use the Website, Services and/or Content otherwise than in accordance with these Terms; use any trade marks or service marks of Mondaq or the Contributors, or do anything which may be seen to take unfair advantage of the reputation and goodwill of Mondaq or the Contributors, or the Website, Services and/or Content.

Mondaq reserves the right, in its sole discretion, to take any action that it deems necessary and appropriate in the event it considers that there is a breach or threatened breach of the Terms.

Mondaq’s Rights and Obligations

Unless otherwise expressly set out to the contrary, nothing in these Terms shall serve to transfer from Mondaq to you, any Intellectual Property Rights owned by and/or licensed to Mondaq and all rights, title and interest in and to such Intellectual Property Rights will remain exclusively with Mondaq and/or its licensors.

Mondaq shall use its reasonable endeavours to make the Website and Services available to you at all times, but we cannot guarantee an uninterrupted and fault free service.

Mondaq reserves the right to make changes to the services and/or the Website or part thereof, from time to time, and we may add, remove, modify and/or vary any elements of features and functionalities of the Website or the services.

Mondaq also reserves the right from time to time to monitor your Use of the Website and/or services.


The Content is general information only. It is not intended to constitute legal advice or seek to be the complete and comprehensive statement of the law, nor is it intended to address your specific requirements or provide advice on which reliance should be placed. Mondaq and/or its Contributors and other suppliers make no representations about the suitability of the information contained in the Content for any purpose. All Content provided "as is" without warranty of any kind. Mondaq and/or its Contributors and other suppliers hereby exclude and disclaim all representations, warranties or guarantees with regard to the Content, including all implied warranties and conditions of merchantability, fitness for a particular purpose, title and non-infringement. To the maximum extent permitted by law, Mondaq expressly excludes all representations, warranties, obligations, and liabilities arising out of or in connection with all Content. In no event shall Mondaq and/or its respective suppliers be liable for any special, indirect or consequential damages or any damages whatsoever resulting from loss of use, data or profits, whether in an action of contract, negligence or other tortious action, arising out of or in connection with the use of the Content or performance of Mondaq’s Services.


Mondaq may alter or amend these Terms by amending them on the Website. By continuing to Use the Services and/or the Website after such amendment, you will be deemed to have accepted any amendment to these Terms.

These Terms shall be governed by and construed in accordance with the laws of England and Wales and you irrevocably submit to the exclusive jurisdiction of the courts of England and Wales to settle any dispute which may arise out of or in connection with these Terms. If you live outside the United Kingdom, English law shall apply only to the extent that English law shall not deprive you of any legal protection accorded in accordance with the law of the place where you are habitually resident ("Local Law"). In the event English law deprives you of any legal protection which is accorded to you under Local Law, then these terms shall be governed by Local Law and any dispute or claim arising out of or in connection with these Terms shall be subject to the non-exclusive jurisdiction of the courts where you are habitually resident.

You may print and keep a copy of these Terms, which form the entire agreement between you and Mondaq and supersede any other communications or advertising in respect of the Service and/or the Website.

No delay in exercising or non-exercise by you and/or Mondaq of any of its rights under or in connection with these Terms shall operate as a waiver or release of each of your or Mondaq’s right. Rather, any such waiver or release must be specifically granted in writing signed by the party granting it.

If any part of these Terms is held unenforceable, that part shall be enforced to the maximum extent permissible so as to give effect to the intent of the parties, and the Terms shall continue in full force and effect.

Mondaq shall not incur any liability to you on account of any loss or damage resulting from any delay or failure to perform all or any part of these Terms if such delay or failure is caused, in whole or in part, by events, occurrences, or causes beyond the control of Mondaq. Such events, occurrences or causes will include, without limitation, acts of God, strikes, lockouts, server and network failure, riots, acts of war, earthquakes, fire and explosions.

By clicking Register you state you have read and agree to our Terms and Conditions