Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
Belgian DPA fines SWDE €86,000 and rebukes missing Article 28 contract
Belgium’s DPA fines SWDE over call recording and monitoring: transparency, retention and a missing processor contract. A clear signal for Luxembourg: an incomplete Article 28 DPA is costly.
CSSF — Circular 25/893: tightened ICT alerting and reporting under DORA
The CSSF tightens ICT incident classification and notification under DORA via eDesk. Here is how an EDR/XDR stack enables timely detection, qualification, and reporting with harmonized deadlines.
GDPR Article 22 after SCHUFA vs ICO guidance: where is the red line?
CJEU SCHUFA: a decisive credit score can be an automated decision (Art. 22). The UK ICO is more flexible if there’s meaningful human involvement. Concrete implications for LU‑UK data chains.
CSSF 25/883 amends 22/806: continuous cloud oversight
On 9 April 2025, the CSSF adjusted 22/806 via 25/883 to align ICT outsourcing with DORA. Here’s how a robust CSPM prevents cloud leaks and demonstrates compliance.
ChipSoft ransomware: why immutable, isolated backups are non-negotiable
The ChipSoft (HiX) attack disrupted hospital services and exposed data. Here’s how immutable backups and an isolated backup network meet DORA/NIS 2 and prevent prolonged outages.
France Travail fined: key lessons from GDPR Article 32
On 22 January 2026, the CNIL fined France Travail €5M for weaknesses in authentication, logging and access rights. In Luxembourg, GDPR Article 32 requires appropriate, demonstrably effective security measures.
Okta/SSO hit by vishing: how FIDO2 blocks MFA bypass
In January 2026, Okta/Entra accounts were breached via vishing and AiTM proxies capturing OTP/push in real time. Phishing-resistant FIDO2/WebAuthn meets GDPR Article 32 requirements.
CNPD 16/12/2025: insufficient GDPR Article 30 record sanctioned
On 16/12/2025, the CNPD imposed a €7,000 fine for an incomplete Article 30 record. The decision clarifies required fields (recipients, transfers, categories, retention, security) and the EDPB fine calculation method.
AZ Monica crippled by ransomware: why immutable backups matter
Belgium’s AZ Monica hospital shut down its servers after a cyberattack. Here’s how immutable, isolated backups enable fast recovery aligned with DORA/NIS 2.
French Council of State — Beaucaire (Apr 30, 2024): the CNIL bar for IAM
France’s Council of State confirms CNIL’s password guidance as state of the art to assess GDPR Article 32. Robust IAM governance enables compliance by design.
CNPD — Vehicle geolocation: what the 2023–2025 guidance requires
The CNPD updated its vehicle geolocation guidance. Key points: structured legitimate interest, purpose limitation, off-duty deactivation, dual transparency and DPIA.
CNIL vs Free/Free Mobile (€42M): a 24/7 SOC is now essential under NIS 2
Following the €42M fine against Free/Free Mobile, weak VPN auth and failed detection show why a 24/7 SOC is critical for GDPR and NIS 2 (24-hour alert).