Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
103 articles found · #expertise
CNPD — Recording meetings: consent rarely valid, legitimate interest under conditions
On 08/07/2026, Luxembourg’s CNPD updated its file on recording private meetings: consent is rarely valid; legitimate interest applies only case by case; deletion is required once the minutes are approved.
Recording calls: the SWDE case and what the CNPD expects in Luxembourg
Belgium’s DPA fined SWDE €86,000 for non-compliant call recordings. In Luxembourg, the CNPD strictly frames recordings: point-of-contact notice, clear legal basis, short retention, and Article 28 DPAs.
US DPF: adequacy adopted, EDPB caution and CNPD guidance
On 10 July 2023, the Commission adopted the EU‑US DPF adequacy decision (GDPR art. 45). The EDPB urges caution and the CNPD sets practical checks: verify certification and scope (incl. HR) and keep a fallback plan.
GDPR Article 22: CJEU vs United Kingdom — widening gap on automated decisions
On 7 December 2023, the CJEU tightened GDPR Article 22, while the UK broadened permitted cases via the 2025 DUAA. Luxembourg groups operating in the UK must now manage two diverging regimes.
CNIL fines IQVIA €5M: health data warehouses under high scrutiny
On May 26, 2026, the CNIL fined IQVIA €5M for breaching authorizations and Articles 14 and 25 GDPR across two health data warehouses. Clear message: effective notice, operational opt-out, and privacy by design are non-negotiable.
NIS 2: EU adopts the supply chain Toolbox — what ILR will check
On 13/02/2026, the EU adopted the EU ICT Supply Chain Security Toolbox. Under NIS 2 and Implementing Regulation 2024/2690, supplier management becomes prescriptive and must be evidenced in Luxembourg before the ILR.
NIS 2 in Luxembourg: scope, categories and self‑registration
Luxembourg’s law of 5 May 2026 transposing NIS 2 has been in force since 10 May 2026. The ILR clarifies scope, the “essential/important entity” categorization, and self‑registration.
French Supreme Court (Mar 18, 2026) — Geolocation and working time
The French Supreme Court allows geolocation to measure working time if no other objective, reliable and accessible means exists and employees lack freedom to organize their time. Luxembourg focus: legal basis, necessity, DPIA.
CJEU C‑312/24 — Erasure vs legal obligation: a relative right
The CJEU clarifies that erasure (Art. 17 GDPR) yields when a clear, foreseeable and proportionate legal obligation justifies retention, including for criminal data in HR files. Once no longer necessary, erasure becomes mandatory again.
CJEU C‑199/24: the “journalism” derogation does not displace the GDPR
The CJEU holds that paywalled publication of criminal judgments is not, in principle, a journalistic purpose under Article 85 GDPR. Where the journalism derogation does not apply, GDPR rights and remedies remain available.
NIS 2: common 24h/72h/1‑month templates — what ILR expects
On 26 May 2026, the EU adopted common incident reporting templates (24h/72h/1 month). In Luxembourg, ILR confirms this sequencing and sets out the expected content for entities.
CNPD vs CNIL: 8 days or 1 month to retain workplace CCTV footage?
Facts: CNPD sets 8 days in principle (30 days exceptionally), while CNIL tolerates up to one month. Key point: align video retention with GDPR Art. 5(1)(e) and Luxembourg Labor Code L. 261‑1.