Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

Analytics cookies: CNIL/CNPD exemptions, ICO still requires consent

On 29 April 2026, the ICO confirmed that non-essential analytics cookies require PECR consent. In France and Luxembourg, CNIL and CNPD allow narrow exemptions for certain audience measurement cookies.

Luxgap and LuxApps at Nexus Luxembourg 2026: compliant and secure AI business applications

On 10-11 June 2026 at Luxexpo The Box, Luxgap and LuxApps are at Nexus Luxembourg. Joint booth with demos of DPO Assist, KYC AML, Third Party Register, LuxApps HRIS. Conference talk on developing AI-boosted business applications, compliant and secure.

External DPO France: why choose a Luxembourg firm recognised across Europe

French company looking for an external DPO? Discover the advantage of a Luxembourg European-scale firm: multi-regulator knowledge (CNIL, CNPD, APD, BfDI, AEPD, Garante), pluridisciplinary team, lower cost than Parisian firms.

Foxconn hit by Nitrogen: 8 TB stolen, plants slowed — SOC/NIS 2 in 24h

Ransomware group “Nitrogen” claims 8 TB and 11M+ files stolen at Foxconn, disrupting North American plants. In Europe, a managed SOC/SIEM is key to detect fast and notify the ILR within 24h (NIS 2, Art. 23).

Criteo: France’s Conseil d’État upholds €40M — consent prevails in AdTech

On 4 March 2026, France’s Conseil d’État upheld the €40M fine against Criteo for personalized advertising without valid consent. Key takeaway in AdTech: for targeting trackers, the lawful basis is (almost always) consent.

CNIL 2025 report: EUR 487M in fines, 1 breach in 2 = hacking, key takeaways

CNIL 2025 annual report: 20,150 complaints (record), EUR 487M in fines (including Google EUR 325M and Shein EUR 150M), 1 breach in 2 results from hacking. The real signal for 2026 and 4 concrete actions for DPO and CISO.

External DPO: 7 lessons from 200+ mandates in Luxembourg and Europe

200+ external DPO mandates across all sectors: the 7 recurring findings we make on takeover, and how Luxgap puts things in order. Concrete pricing, sector examples, what really changes.

FICOBA: 1.2M accounts exposed — IAM and least privilege

A compromised high-privilege account enabled access to ~1.2M FICOBA records. What happened and how least-privilege IAM addresses GDPR Art. 25 and NIS 2 Art. 21 requirements.

CSSF: DORA takes precedence and clarifies ICT outsourcing (Apr 2025)

CSSF confirmed DORA’s primacy from 17 January 2025 and issued Circular 25/882 to govern third‑party ICT use, the Article 28 register of information, and incident notifications via eDesk.

CNIL vs Free: €42M — why a 24/7 SOC is vital to meet NIS 2 Art. 23

After the €42M fine against Free/Free Mobile, slow detection proves costly. Under NIS 2 Art. 23, detecting and notifying within 24 hours is now an operational obligation in Luxembourg.

DORA — TLPT framed by Delegated Regulation (EU) 2025/1190

The Commission clarified TLPT under DORA via Delegated Regulation (EU) 2025/1190. In Luxembourg, the CSSF is the TLPT authority: timeline, scope, and method are now clear.

NIS 2 audit: method, pitfalls and quality criteria for measures

7-phase NIS 2 audit method, the 5 most common pitfalls, and the 6-criteria grid to distinguish a real SOC from a marketing product. For the 1,200+ Luxembourg entities concerned.

← Newer Page 19 / 22 Older →