bg image

Data protection

The Laboratoire national de santé (LNS) is committed to meeting patients’ needs and protecting their privacy.

In this respect and in accordance with the European Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data, also known as the General Data Protection Regulation (GDPR)) and the Law of 1 August 2018, LNS, as data controller, has drafted a data protection policy that applies to both its analytical laboratory activities and its website.

The data controller is the LNS, a public institution under the supervision of the Ministry of Health, whose head office is located at 1, rue Louis Rech, L-3555 Dudelange.

To ensure compliance with these regulations and protect your privacy, LNS has appointed a Data Protection Officer (DPO) who can be contacted at the following address: dpo@lns.etat.lu.

This policy sets out the purposes of data processing carried out by LNS. The purpose of this document is to inform you about the personal data we collect, why we use and share it, how long we keep it, what rights you have and how you can exercise them.

In the event of medical research using your data, specific information will be provided by LNS.

As part of its analytical laboratory activities

The purpose of LNS is to:

  • Develop analytical and scientific expertise activities related to the prevention, diagnosis and monitoring of human diseases;
  • Act as a national control or reference laboratory;
  • Carry out forensic missions.

Why is some of your data collected?

LNS needs to collect your personal data for the following activities:

  • Sampling,
  • Analysis of your samples,
  • Transmission of results,
  • Billing,
  • Establishing a commercial relationship,
  • Scientific study or research

Your data is collected in order to guarantee you appropriate care, within the framework of contractual relations and/or to carry out scientific studies or research.

What data is collected?

The data collected are:

  • Your first and last name(s)
  • Your date of birth
  • Your postal address and e-mail address
  • Your telephone number
  • Your registration number
  • Your bank details for payment of certain LNS activities
  • Your health data required for LNS activities
  • Your professional data (company name, job title, etc.)

How is your data collected?

In the context of your contractual and/or commercial relationship with LNS, your personal data may be collected directly from you (during your appointment at LNS for example).

Your data may also be collected indirectly through partners or customers (hospitals, doctors, private laboratories, etc.) who need LNS expertise. In such cases, your data will be transmitted securely.

How is your data processed?

Your personal data will be subject to computerized processing which may be based on Article 6 1. e) of the GDPR. Indeed, LNS is invested with a mission of public interest by the Ministry of Health.

The processing of your data may also be based on a legal obligation (art. 6 1.c) of the GDPR) or justified by a legitimate interest (art. 6 1. f) of the GDPR) or on your consent (art. 6 1. a) of the GDPR).

In the context of commercial relationships, your data is collected to enable the development and management of the contractual relationship (art. 6. 1 b) of the RGPD).

Health data:

LNS processes health data:

  • For medical diagnostic purposes and to enable the health care of individuals (art.9 2.h) of the RGPD),
  • For reasons of public interest in the field of public health (art. 9 2.i) RGPD),
  • For the conduct of scientific research (at.9 2.j) of the RGPD)

LNS only processes personal data that is strictly necessary for the purposes of providing the services requested in connection with your care and administrative processing and its other legal obligations such as reporting infectious diseases to the Director of Health, reporting to the National Health Fund (CNS), …

Is your data transferred to certain recipients?

LNS is the recipient of your data.

In order to carry out these tasks, LNS may transfer your personal data to its partners and/or subcontractors, in particular in the context of:

  • Special examinations,
  • Conducting and/or participating in scientific research, …

The list of LNS subcontractors is available on request from the DPO.

LNS partners include, but are not limited to, physicians, private and public healthcare and medical-social establishments, laboratories and public administration.

Your personal data may be transferred outside the European Economic Area (EEA) on condition that security and confidentiality guarantees equivalent to those practised in the EEA are put in place (in particular the conclusion of binding clauses and the implementation of advanced security measures).

How long is your data stored?

Personal data collected directly or indirectly by LNS is kept for at least ten (10) years on LNS’s active database, unless otherwise required by law.

As part of LNS communication operations and its website

When you browse the LNS website, LNS collects and uses some of your personal data in its capacity as data controller.

What data is collected about you?

We collect your personal data when you browse this website (via cookies) and when you use the services offered on this site (e.g. contact request, feedback and complaints).

a. Your personal data for the provision of services

Data and purpose of use

The personal data collected via the LNS website allows us to provide you with the following services:

  • responding to contact requests, feedback and complaints,
  • event registration,
  • open online accounts to book appointments for hair toxicology tests,
  • sending documentation or information,
  • job offers (for data collection as part of the recruitment process, please refer to part 3 of this policy);

We collect your personal data when you fill in a contact form, create an online account or register for an event. This may include the following data:

  • Full name ;
  • Telephone number and e-mail address ;
  • Subject and content of your message/feedback/complaint ;
  • Date of birth ;
  • Postal address;
  • Registration number
Legal basis

The provision of services is carried out with your consent collected at the time of your request for the services offered in accordance with Article 6 1.a) of the GDPR.

Data sharing

Some of your personal data may be shared with our website host.

LNS may use third-party service providers to provide services and this may involve transfers of your personal data to countries outside the European Union/European Economic Area (EU/EEA). This transfer may occur if there is a European Commission decision stating that the country outside the EU/EEA provides an adequate level of data protection.

For transfers to countries outside the EU/EEA that do not offer an adequate level of protection, LNS will implement the appropriate protections provided by current data protection legislation (e.g., the conclusion of standard data protection clauses) or LNS may obtain your consent.

Data retention period

We will keep your personal data for no longer than is necessary for the purposes set out herein or as required by applicable law.

Your data is kept for the time strictly necessary for processing, from the moment it is collected, and is then deleted.

b. Cookies

Some data is collected automatically when you visit the site, by means of cookies.

Several types of cookies are used by the LNS site, in particular to:

  • To provide you with an optimal browsing experience on the website: adaptation of the display to the terminal used, detection of the user’s language, storage of preferences, session management, etc. ;
  • Display videos optimally on your terminal ;
  • To carry out statistical analyses of visits to this site and thus optimize it (MATOMO);
  • Offer you sharing functions on social networks (X, LinkedIn, Instagram).
Social networking

By clicking on the X, Instagram or LinkedIn button on our website, you will be redirected to these websites. These social networks may collect data relating to your browsing on our site and associate it with the data they hold about you.

These social networks have their own cookie and privacy policies, over which we have no control. We therefore invite you to consult the privacy protection policies of these networks in order to learn about the purposes for which they may use the browsing information they may collect through these application buttons, and in particular for advertising purposes.

MATOMO

MATOMO is an audience measurement tool used to generate statistics on visits to the LNS website.

The cookies used by MATOMO are hosted on LNS servers, meaning that only authorized persons will have access to your data. LNS has implemented technical and organizational measures to guarantee appropriate data security.

Data sharing

Some of your personal data may be shared with our service providers, who work with LNS to improve navigation, content and interactivity on our site (Google, YouTube, Facebook, X).

We undertake to share this data with these service providers only.

Data retention period
Cookie category Cookie name Retention period
Analytical cookie (optional) MATOMO 13 months
Legal basis

Some cookies are necessary to ensure the proper functioning of the site, improve interactivity and its multimedia content. Therefore, it is in our legitimate interest to collect and use this data (Article 6 1. f) of the GDPR).

Your consent is required for the placement of analytical and advertising cookies.

As part of the recruitment process

Why is some of your data collected?

As part of its recruitment process, LNS is responsible for collecting and processing personal data in connection with your application for a position at LNS.

What data is collected?

LNS collects and uses your personal data necessary for its recruitment process, which you decide to submit when applying for a particular position, including:

  • identification data (such as your surname, first name, date and place of birth, nationality, contact details, telephone number, e-mail address),

If you decide to attach letters of recommendation to your application, it is your responsibility to inform the persons providing the recommendation (before providing us with their personal data), that their personal data will be processed by LNS in accordance with this Recruitment Data Protection Policy. We will not contact referrers directly unless we have your consent to do so.

Only data required for the recruitment process is necessary for LNS, namely your CV and cover letter. Sensitive data such as data revealing your ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data (which allows or confirms your unique identification), data concerning your health, data concerning your sexual life or orientation or any judicial data (e.g. criminal record) are not required in order to submit your application for a position advertised by LNS.  However, such data may be collected in order to establish your employment contract if your application is accepted.

You can choose what type of information to submit as part of your application. The following categories of data are strictly necessary for us to consider your application for a given position:

  • your identification data ;
  • your professional experience ;
  • Your training data (diplomas, special training courses) ;
  • your language skills ;
  • if applicable, an authorization to practice in Luxembourg ;

In some cases, an LNS job advertisement may specify additional categories of personal data required for a particular position. If this is the case, the provision of this information is also mandatory (please check the job offer again).

The submission of any other information is entirely optional. By submitting non-mandatory data to LNS, you consent to the processing of your data for recruitment purposes.

How is your data collected?

Your data is collected directly, i.e. it is made available to us directly by you.

LNS may also collect your data indirectly by visiting professional social networks such as LinkedIn or via recruitment agencies.

What are the purposes of the processing?

The personal data you provide will be processed solely for the purposes of the LNS selection and recruitment process and in particular for:

  • register your application ;
  • assess the suitability of your application for the position you are applying for or for any existing opportunities within LNS;
  • if necessary, contact you to arrange an interview;
  • drafting contractual documentation if you are selected for the position.

How is your data processed?

Your data will be treated confidentially by the team in charge of recruitment (human resources and the department or service where a vacancy exists) if access to the data is necessary for the performance of their duties.

In the context of the recruitment of a position subject to approval or information by the Board of Directors in accordance with article 6 (2) of the law of August 7, 2012 creating the national health laboratory, your data may be communicated to our administrators.

Is your data transferred to certain recipients?

We may also pass on your personal data to the following contacts:

  • service providers/suppliers (such as recruitment agencies) who perform services on our behalf,

We may also receive requests from third parties with the necessary authority to obtain disclosure of personal data. We will only respond to such requests where we are authorized to do so in accordance with applicable laws and regulations.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law.

How long is your data stored?

If you are hired, the personal data collected during the recruitment process will be kept in your personal file in the HR department.

In the event of an unsuccessful recruitment procedure, your personal data will be kept for a limited period of two (2) years in accordance with the law in force. At the end of this period, or following your objection to the processing of your personal data, your personal data will be deleted or destroyed.

Your data and your rights

You have the right to request access to your personal data and to obtain a copy of it, and, in the event that your personal data is incomplete or erroneous, to have it corrected. You also have the right to limit the processing of your personal data, the right to object to their use, the right to obtain their portability as well as the right to obtain their deletion, under the conditions and within the limits provided for by the General Data Protection Regulation.

It is possible to request to exercise the rights listed above by submitting a written, signed request and proof of your identity to the LNS DPO at the following address:

Laboratoire national de santé
Att. Data Protection Officer
1, rue Louis Rech
L-3555 Dudelange

Or send an e-mail to dpo@lns.etat.lu.

Your request will be processed within a reasonable time.

Finally, you can lodge a complaint with the National Commission for Data Protection (“CNPD”) if you feel that your rights have not been respected: https://cnpd.public.lu/en.html