Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
Uber fined €825m for automated decisions: strong signal on GDPR Article 22
The Dutch DPA, with the CNIL, fined Uber nearly €825m for automated driver account deactivations/suspensions without adequate safeguards. Clear message: GDPR Article 22 applies concretely to high‑impact business algorithms.
CNIL fines a hospital: €500,000 and security requirements
The CNIL fines the Hôpital privé de la Loire €500,000 after a large-scale EHR breach. A reminder of security (MFA, access rights, detection) and data subject notification requirements, with direct implications in Luxembourg.
CJEU C‑526/24 — When a first access request is “abusive” under Art. 12(5)
The CJEU allows, in exceptional cases, refusal of a first access request (Art. 15 GDPR) if the controller proves an abusive intent to manufacture compensable harm. Article 12(5) is interpreted strictly and the burden of proof lies with the controller.
MAG: 8.7M customers exposed — third‑party risk hits airports
Manchester Airports Group confirms unauthorized access to parking, lounge, Fast Track and Wi‑Fi data, affecting around 8.7M customers. The case highlights third‑party risk and GDPR/NIS 2 notification duties.
Vehicle geolocation: CNPD vs CNIL on retention and oversight
CNIL sets a 2‑month default retention for vehicle geolocation, while CNPD requires a case‑by‑case proportionality proof with potential L.261‑1 referral. Adapt HR and fleet policies accordingly in Luxembourg.
CNIL fines Free/Free Mobile €42M for weak VPN MFA
CNIL fines Free/Free Mobile €42M for weak VPN MFA and failed detection after data exfiltration affecting ~24.6M contracts. Here is the phishing-resistant MFA that would have prevented most of it.
Legitimate interest vs consent: French Supreme Court, 17 June 2026
On 17 June 2026, the French Supreme Court (commercial chamber) required strict Article 14 GDPR information when relying on legitimate interest for data collected indirectly, including in litigation contexts.
MyDr: 19M health records exposed — third‑party risk hits Europe
Polish health software vendor MyDr suffered a breach disclosed August 12–13, 2026: nearly 19M people and over 12,000 facilities may be affected. Poland’s PM suggested extortion as the motive.
ENISA Secure by Design: a measurable IAM for GDPR 25 and NIS 2
ENISA’s Secure by Design and Default Playbook provides checklists and minimal evidence. Here’s how a measurable IAM operationalizes these requirements while meeting GDPR art. 25 and NIS 2.
CNPD — Recording meetings: consent rarely valid, legitimate interest under conditions
On 08/07/2026, Luxembourg’s CNPD updated its file on recording private meetings: consent is rarely valid; legitimate interest applies only case by case; deletion is required once the minutes are approved.
RingCentral: 1.6M emails exposed — move to phishing-resistant MFA
After the ShinyHunters attack, ~1.6M RingCentral emails leaked. A FIDO2/WebAuthn MFA would have broken the attack chain and meets GDPR Article 32 requirements.
Recording calls: the SWDE case and what the CNPD expects in Luxembourg
Belgium’s DPA fined SWDE €86,000 for non-compliant call recordings. In Luxembourg, the CNPD strictly frames recordings: point-of-contact notice, clear legal basis, short retention, and Article 28 DPAs.