Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
64 articles found · #cnpd
GDPR Record: CNPD fines for insufficient ROPA, ICO promotes flexibility
On 16 December 2025, the CNPD fined an organisation for an “insufficient” record of processing (Art. 30 GDPR). By contrast, the ICO updated a more flexible approach in June 2026. This gap affects EU–UK groups.
Vehicle geolocation in Luxembourg: CNPD requirements 2024
On 10 April 2024, the CNPD updated its guidelines: no continuous tracking or outside working hours, DPIA often required, retention generally 2 months, and obligations under Labour Code L. 261‑1.
CNPD: recording private meetings — legitimate interest only under conditions
CNPD finds consent rarely valid in meetings and allows legitimate interest only after a strict necessity and balancing test. Recordings must be deleted as soon as minutes are approved.
UL: €98,000 for late notification — what Article 33 really requires
Ireland’s DPC fined the University of Limerick for three late GDPR notifications. Here is how to meet Article 33 and notify the CNPD within 72 hours, with documented timing and solid content.
Right of access to call recordings: the Vodafone (GR) case, 2026
On 11 February 2026, the Hellenic DPA fined Vodafone-Panafon for obstructing access rights and breaching GDPR Articles 12, 15 and 18. Key takeaway: deliver a usable copy of recordings within one month.
Cookies: EDPB orders Belgian DPA to decide the merits in the VRT case
On 14 July 2026, the EDPB ordered the Belgian DPA to rule on the merits of NOYB’s complaint against VRT’s cookie banner, rejecting the abuse-of-rights argument. A signal for CNPD oversight and consent practices in Luxembourg.
CNPD 2025 report: 846 complaints (+40%), key takeaways for Luxembourg
CNPD 2025 annual report: 846 complaints (+40% in one year), 425 breach notifications (49% human error), 59 investigations, 16 opinions. The shift to risk-based regulation, AI as a priority, and 5 concrete actions for DPOs and CISOs in Luxembourg.
EU–US DPF: CNPD/EDPB cautious, ICO ‘data bridge’ more flexible
The DPF offers a secure lane to certified US recipients in the EU, while the UK ‘data bridge’ further streamlines UK-to-US flows. Outside the DPF, SCC/BCR + TIA remain required per CNPD/EDPB guidance.
€31.8m fine against Intesa Sanpaolo: 72h to notify a GDPR breach
Italy’s DPA fined Intesa Sanpaolo €31.8m for inadequate security and late/incomplete GDPR breach notification. Immediate takeaway for Luxembourg: meet the 72-hour rule and know what to notify.
Processors: CNPD (Art. 28 GDPR) vs CSSF 22/806 — two contractual layers
CSSF’s 9 April 2025 update widens the gap with the CNPD/EDPB approach: beyond the GDPR DPA, financial entities must add access/audit clauses, prudential notifications, reversibility, and cloud-specific requirements.
Workplace video surveillance: CNPD (8 days) vs CNIL (1 month)
The CNPD sets an 8‑day retention period “in principle,” while the CNIL allows up to one month. A concrete divergence affecting retention, DPIAs and employee information.
GDPR rights at work: only the individual has standing (Cass. crim., Jan 13, 2026)
France’s Supreme Court held that a company cannot invoke employees’ GDPR rights to challenge a seizure: only the data subjects themselves have standing. A key takeaway for DSAR and DPO response workflows.