Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
103 articles found · Expertise Luxgap
AI Act — Prohibited practices (Art. 5): the Commission’s 2025 clarifications
On 4 February 2025, the Commission issued guidelines on prohibited AI practices (Art. 5 AI Act). Eight uses are banned as of 02/02/2025, with fines up to €35m or 7% of global turnover.
CNPD vs CNIL: workplace CCTV, 8 days in LU, up to 30 days in FR
The CNPD sets a default retention of “up to 8 days,” while the CNIL in practice admits up to one month. Entities operating in Luxembourg must adjust their practices and records.
72 hours or a fine: the Mayor of Myślenice flagged — a reminder for Luxembourg
On 25 May 2026, Poland’s UODO fined the Mayor of Myślenice for failing to notify a data breach within 72 hours (GDPR Art. 33). A useful reminder of what the CNPD expects in Luxembourg.
CJEU (19 March 2026): access may be refused if abusive
The CJEU accepts that a data access request may be rejected as “abusive” if it solely aims at obtaining GDPR compensation. Strong signal for reasoned refusals, burden of proof, and meeting deadlines.
Right of access vs premature deletion: Belgian DPA warns recruiter (37/2026)
On 24 February 2026, the Belgian DPA warned a company for deleting an interview video after an access request. In practice: purge must be suspended until the access right is handled (Arts. 12 and 15 GDPR).
Amazon v. CNPD (12 March 2026): Legitimate interest rejected in AdTech
Luxembourg’s Administrative Court confirms Amazon’s behavioral advertising could not rely on legitimate interest and annuls the fine in light of the CJEU’s fault requirement.
Transfers to the United States: CNPD implements the DPF, EDPB remains cautious
The CNPD confirms “free” transfers to US entities certified under the DPF (Art. 45 GDPR), while the EDPB maintains reservations and calls for ongoing vigilance.
DORA Art. 28: CSSF turns up the heat on the ICT dependencies register
As of 16 March 2026, only 40% of entities had filed their DORA Art. 28 register. CSSF warns: ESAs’ quality checks, potential rejections and tight resubmission windows, with a 30 June “best effort” for some branches.
CNPD 1FR/2025: how the DPA calculates a GDPR fine in 5 steps
On 6 January 2025, the CNPD fined a controller for delays in data subject rights and applied the EDPB’s five-step method. Key takeaway: track and document your “time-to-rights”.
GDPR Article 6: the Poste Italiane fine clarifies legitimate interest vs consent
Italy’s DPA fined Poste Italiane/PostePay €12.5m for intrusive device access via apps without a valid legal basis. Key message: anything beyond what is strictly necessary often requires valid consent, not legitimate interest.
Workplace video surveillance: the Hanako case rules out consent
Italy’s Garante (12/03/2026) fined Hanako s.r.l. for in-store video surveillance without proper notice and labor authorization. EU-wide message: in employment, employee consent is not a convenient legal basis.
AEPD vs AENA: €10,043,002 for a deficient DPIA (Art. 35 GDPR)
On 4 March 2026, the AEPD fined AENA €10,043,002 for a non‑compliant DPIA on biometric boarding. Key takeaway: a “pro forma” DPIA is tantamount to no DPIA.