Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

103 articles found · #expertise

CJEU C‑414/24 (18 June 2026): parallel GDPR remedies are not exclusive

The CJEU confirms that GDPR complaints to the authority (Art. 77) and judicial actions (Art. 79) are parallel and not mutually exclusive. An authority may not dismiss a complaint solely because a court action is pending.

DORA Art. 28: Register of Information — CSSF expectations for 2026

The CSSF opened eDesk and set a DORA Register of Information submission window from 11 February to 31 March 2026. Content is standardized by ITS (EU) 2024/2956 and subject to strict validation rules.

GDPR Article 32: a small Italian fine, big obligations

On 29/04/2026, the Italian Garante imposed an €8,600 fine for security failures (Arts. 5 and 32 GDPR), including non‑compliant password storage. In Luxembourg, proving proportionality and state of the art remains decisive.

Web scraping to train AI: ICO opens, EDPB tightens

The ICO considers legitimate interests a practicable basis for AI training via web scraping, subject to strict tests and transparency. The EDPB narrows this, stressing Article 14 notice and the constraints of Article 9.

Workplace video surveillance: Garante fine and lessons for Luxembourg

Italy’s Garante fined a shop €2,000 for video surveillance without notice or labor authorization. In Luxembourg, L.261‑1, two‑layer notice and short retention are mandatory.

Amazon vs CNPD (12/03/2026): fine annulled, fine methodology reset

On 12 March 2026, Luxembourg’s Administrative Court annulled Amazon’s €746m fine while upholding core findings. Key takeaway: apply CJEU (Deutsche Wohnen/Nacionalinis) and robustly justify the GDPR fine methodology.

NIS 2 in Luxembourg: what ILR really expects under Article 21

ILR clarifies board duties and expected controls for NIS 2 Article 21, aligned with Implementing Regulation (EU) 2024/2690 and Luxembourg’s 5 May 2026 law.

NIS 2 vs DORA in Luxembourg: notify in 24 h or 4 h?

Verifiable fact: CSSF Circular 25/893 (27/05/2025) aligns DORA reporting with a first notification “within 4 hours” after classification. NIS 2 requires a preliminary alert “within 24 hours.” Key issue: who to notify, when, and against which clock in Luxembourg.

DORA TLPT vs TIBER‑EU/LU: the key gap on internal testers

Delegated Regulation (EU) 2025/1190 allows, under strict conditions, internal testers for DORA TLPT. TIBER‑EU/TIBER‑LU require external providers for recognition.

Art. 28 GDPR: Garante fines Velletri over sub-processing chain

On 12 Feb 2026, the Italian Garante fined Velletri Servizi for non‑compliant sub‑processing contracts under Art. 28(4) GDPR and insufficient oversight. Key takeaway: document and audit the entire sub‑processing chain.

Data transfers outside the EU: EDPB vs ICO — essential equivalence or risk test?

On 15 Jan 2026, the ICO introduced a simplified three‑step test and TRA, diverging from the EDPB/CNPD’s ‘essential equivalence’ plus supplementary measures approach. Bottom line: distinct compliance tracks for EU vs UK transfers.

Workplace video surveillance: DPIA before any camera (Coccaglio)

Italy’s Garante fined the Comune di Coccaglio €6,000 for employee video surveillance without a credible DPIA and for disciplinary use of footage. In Luxembourg, a prior DPIA is almost always required when employees may be captured.

← Newer Page 2 / 9 Older →