Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
81 articles found · #rgpd · Expertise Luxgap
CNPD — Recording meetings: consent rarely valid, legitimate interest under conditions
On 08/07/2026, Luxembourg’s CNPD updated its file on recording private meetings: consent is rarely valid; legitimate interest applies only case by case; deletion is required once the minutes are approved.
Recording calls: the SWDE case and what the CNPD expects in Luxembourg
Belgium’s DPA fined SWDE €86,000 for non-compliant call recordings. In Luxembourg, the CNPD strictly frames recordings: point-of-contact notice, clear legal basis, short retention, and Article 28 DPAs.
US DPF: adequacy adopted, EDPB caution and CNPD guidance
On 10 July 2023, the Commission adopted the EU‑US DPF adequacy decision (GDPR art. 45). The EDPB urges caution and the CNPD sets practical checks: verify certification and scope (incl. HR) and keep a fallback plan.
GDPR Article 22: CJEU vs United Kingdom — widening gap on automated decisions
On 7 December 2023, the CJEU tightened GDPR Article 22, while the UK broadened permitted cases via the 2025 DUAA. Luxembourg groups operating in the UK must now manage two diverging regimes.
CNIL fines IQVIA €5M: health data warehouses under high scrutiny
On May 26, 2026, the CNIL fined IQVIA €5M for breaching authorizations and Articles 14 and 25 GDPR across two health data warehouses. Clear message: effective notice, operational opt-out, and privacy by design are non-negotiable.
French Supreme Court (Mar 18, 2026) — Geolocation and working time
The French Supreme Court allows geolocation to measure working time if no other objective, reliable and accessible means exists and employees lack freedom to organize their time. Luxembourg focus: legal basis, necessity, DPIA.
CJEU C‑312/24 — Erasure vs legal obligation: a relative right
The CJEU clarifies that erasure (Art. 17 GDPR) yields when a clear, foreseeable and proportionate legal obligation justifies retention, including for criminal data in HR files. Once no longer necessary, erasure becomes mandatory again.
CJEU C‑199/24: the “journalism” derogation does not displace the GDPR
The CJEU holds that paywalled publication of criminal judgments is not, in principle, a journalistic purpose under Article 85 GDPR. Where the journalism derogation does not apply, GDPR rights and remedies remain available.
CNPD vs CNIL: 8 days or 1 month to retain workplace CCTV footage?
Facts: CNPD sets 8 days in principle (30 days exceptionally), while CNIL tolerates up to one month. Key point: align video retention with GDPR Art. 5(1)(e) and Luxembourg Labor Code L. 261‑1.
CJEU C‑414/24 (18 June 2026): parallel GDPR remedies are not exclusive
The CJEU confirms that GDPR complaints to the authority (Art. 77) and judicial actions (Art. 79) are parallel and not mutually exclusive. An authority may not dismiss a complaint solely because a court action is pending.
GDPR Article 32: a small Italian fine, big obligations
On 29/04/2026, the Italian Garante imposed an €8,600 fine for security failures (Arts. 5 and 32 GDPR), including non‑compliant password storage. In Luxembourg, proving proportionality and state of the art remains decisive.
Web scraping to train AI: ICO opens, EDPB tightens
The ICO considers legitimate interests a practicable basis for AI training via web scraping, subject to strict tests and transparency. The EDPB narrows this, stressing Article 14 notice and the constraints of Article 9.