A bill intended to spare people repeated administrative work could instead make them responsible for checking and correcting personal data exchanged by public authorities, the Council of State warned on 10 July as it raised a series of formal objections.
Digitalisation Minister Stéphanie Obertin and the bill’s rapporteur, DP MP Gérard Schockmel, had recently pointed to the outstanding opinion as the immediate obstacle facing the Frieden government’s long-delayed “once only” promise. Its arrival instead exposed flaws in the bill itself, more than two years after the original project was tabled.
“The bill, in its current form, remains incomplete on several essential points and imprecise on others,” the Council said. It rejected a broad provision allowing a wide range of public bodies to process personal data whenever this was needed to carry out tasks in the public interest, without defining each use precisely enough in law.
The reform is meant to stop residents and businesses from having to supply information already held by another public authority. But the bill remained unclear about which bodies could exchange data, where reliable information would come from and whether “once only” created a right for individuals or primarily imposed a duty on authorities to share data.
A system drawn too widely
The organisations covered were defined too broadly and uncertainly. Alongside ministries, national administrations and municipalities, the government could use secondary legislation to bring public bodies, economic interest groupings and public-benefit organisations into the system.
Compulsory exchanges should initially be confined to central government, the Council said, while participation beyond that perimeter should be voluntary or specifically authorised by law. Reusing personal data collected for one purpose in another procedure would, in every case, have to comply with EU data-protection rules and Luxembourg’s constitutional safeguards.
The bill also failed to establish whether “once only” gave people a right not to resubmit information or required public bodies to exchange it without their involvement. That uncertainty affected the meaning of the reform’s central provision rather than a peripheral drafting point.
Obertin said in July 2025 that she hoped parliament could vote on the measure that autumn. At the end of June this year, she and Schockmel were still publicly awaiting an opinion they hoped would arrive soon.
Simplification shifted back to residents
One of the clearest objections concerned a provision that would put new administrative work onto the people the reform was meant to help. The bill required them to certify data obtained from another public authority and, where necessary, secure a correction from the original source before sending the revised information to the authority handling their application.
The Council said the bill shifted responsibility in the wrong direction. Instead of public authorities ensuring that exchanged data were accurate and up to date, people could be made to check official records, seek corrections from the authority that held them and pass the amended information on themselves.
That could mean dealing with several public bodies, creating more work and further scope for delays or mistakes. “The ‘once only’ principle cannot, under the guise of administrative simplification, relieve public bodies of their own obligations by transferring to the applicant the work of verifying, certifying or correcting the data,” the Council said.
People could still be shown pre-filled information and invited to flag errors, the opinion added, but they should not be made responsible for correcting records held and reused by public authorities.
The bill also failed to identify which databases should be treated as authoritative or which body was responsible for keeping each category of information accurate. The proposed system therefore risked reusing information simply because it was available rather than because it came from a reliable and up-to-date source.
The Council warned of “a structural risk that inaccurate or outdated data will circulate”. It said reliable sources and responsibility for maintaining them had to be settled in law before exchanges began.
Essential rules left outside the law
Each type of data exchange would be governed by a protocol agreed between the public bodies involved, covering the information exchanged, the participating organisations and its intended use. Such agreements could deal with technical and organisational arrangements after an exchange had been authorised by law, the Council said.
They could not decide which bodies could exchange data, when exchanges were compulsory, which purposes were allowed or what protections applied. Otherwise, “the solution chosen would leave public bodies to settle among themselves—even in contractual form—questions that the constitution reserves to legislation”.
The same objection applied to a proposed register that the government intended to use to identify authoritative data sources. Those sources and the authorities responsible for them had to be established beforehand, the Council said, not inferred later from exchanges that had developed in practice.
It also objected to provisions allowing information to be reused in some circumstances for systematic fraud detection. Administrative simplification could not provide the legal basis for that separate use, which would require clear and proportionate legislation of its own.
One half became law
The government divided the original bill in April 2025 so that provisions linked to the EU Data Governance Act could proceed separately. Bill 8395A created the government commissioner for Data Sovereignty and the related governance structure, becoming law in December.
The “once only” system remained in bill 8395B. The government submitted 12 amendments in June 2025 and another 15 in February 2026, while the Digitalisation Ministry and the Council of State held two meetings during the drafting process.
Those changes did not resolve the central difficulties. The Council said the government had to review, complete and clarify the system and bring it into line with the GDPR and Luxembourg’s constitutional protections for personal data.
The data-governance half of the original project is now in force. The part intended to deliver the promised reduction in repeated paperwork remains before parliament more than two years after the original bill was tabled.



