Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
103 articles found · Expertise Luxgap
GDPR Record: CNPD fines for insufficient ROPA, ICO promotes flexibility
On 16 December 2025, the CNPD fined an organisation for an “insufficient” record of processing (Art. 30 GDPR). By contrast, the ICO updated a more flexible approach in June 2026. This gap affects EU–UK groups.
Vehicle geolocation in Luxembourg: CNPD requirements 2024
On 10 April 2024, the CNPD updated its guidelines: no continuous tracking or outside working hours, DPIA often required, retention generally 2 months, and obligations under Labour Code L. 261‑1.
CNPD: recording private meetings — legitimate interest only under conditions
CNPD finds consent rarely valid in meetings and allows legitimate interest only after a strict necessity and balancing test. Recordings must be deleted as soon as minutes are approved.
UL: €98,000 for late notification — what Article 33 really requires
Ireland’s DPC fined the University of Limerick for three late GDPR notifications. Here is how to meet Article 33 and notify the CNPD within 72 hours, with documented timing and solid content.
C‑97/23 P — Binding decisions of the EDPB are challengeable
The CJEU allows direct actions against an EDPB binding decision (WhatsApp v EDPB, 10/02/2026). Bottom line: intra‑group data sharing must be documented and defensible before the EU courts.
Profiling and automated decisions: CJEU vs UK — two opposing lines
The UK replaces Article 22 UK GDPR with 22A–22D (a “permitted subject to safeguards” model), while the CJEU (SCHUFA) confirms in the EU a default ban on fully automated decisions with legal or similarly significant effects.
Right of access to call recordings: the Vodafone (GR) case, 2026
On 11 February 2026, the Hellenic DPA fined Vodafone-Panafon for obstructing access rights and breaching GDPR Articles 12, 15 and 18. Key takeaway: deliver a usable copy of recordings within one month.
NIS 2 and supply chain: the EU Toolbox is a game changer
Adopted on 13/02/2026, the EU ICT Supply Chain Security Toolbox is now the operational benchmark for NIS 2 Article 21(2)(d). In Luxembourg, the ILR will verify its implementation by entities.
IQVIA: €5m fine and health data — Article 9 GDPR under strain
CNIL fines IQVIA France €5m for failings in health data warehouses. Key takeaway for Luxembourg: “pseudonymised” data remains health data (Art. 9 GDPR) and requires a strict legal basis and effective safeguards.
NIS 2 in Luxembourg: executive liability and mandatory training
Since 5 May 2026, Luxembourg’s NIS 2 law requires management bodies to approve and oversee cybersecurity measures and to undertake training. Sanctions can be severe and executives are explicitly targeted.
France Travail: €5M fine for inadequate security (GDPR Art. 32)
On 22 January 2026, the CNIL fined France Travail €5M for breaches of GDPR Article 32. Key takeaway: prove the proportionality and effectiveness of security measures, with clear documentation, including in Luxembourg.
EU–US DPF: CNPD/EDPB cautious, ICO ‘data bridge’ more flexible
The DPF offers a secure lane to certified US recipients in the EU, while the UK ‘data bridge’ further streamlines UK-to-US flows. Outside the DPF, SCC/BCR + TIA remain required per CNPD/EDPB guidance.