Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
125 articles found · #luxembourg
CJEU C‑414/24 (18 June 2026): parallel GDPR remedies are not exclusive
The CJEU confirms that GDPR complaints to the authority (Art. 77) and judicial actions (Art. 79) are parallel and not mutually exclusive. An authority may not dismiss a complaint solely because a court action is pending.
CEVA Logistics: data leak at supplier — Bol and De Bijenkorf customers warned
On August 6, 2026, Bol and De Bijenkorf warned customers that a possible data leak at CEVA Logistics may have exposed names, addresses and phone numbers. The Dutch DPA was notified on August 3; no payments or passwords are implicated so far.
DORA Art. 28: Register of Information — CSSF expectations for 2026
The CSSF opened eDesk and set a DORA Register of Information submission window from 11 February to 31 March 2026. Content is standardized by ITS (EU) 2024/2956 and subject to strict validation rules.
AI Act: labelling of AI‑generated content — deadline on 2 December
AI providers get a short extension: for systems already on the market by 2 August 2026, labelling of generated content (Art. 50(2) AI Act) is due by 2 December 2026 at the latest. Deployers’ obligations remain unchanged.
AI Act: mandatory transparency from August 2 — act now
The AI Act’s transparency rules (Art. 50) have applied since August 2, 2026. Chatbots, deepfakes and AI-generated content must now be disclosed — including by deployers in Luxembourg.
Workplace video surveillance: Garante fine and lessons for Luxembourg
Italy’s Garante fined a shop €2,000 for video surveillance without notice or labor authorization. In Luxembourg, L.261‑1, two‑layer notice and short retention are mandatory.
PNLD: 135,000 police and partner contacts published on the dark web
The UK’s Police National Legal Database (PNLD) confirmed 1.9 GB of data was posted online: 114,000 PNLD subscribers and 21,000 “Ask the Police” users. The attack, claimed by ExfilSquad, was detected on July 26, 2026.
Amazon vs CNPD (12/03/2026): fine annulled, fine methodology reset
On 12 March 2026, Luxembourg’s Administrative Court annulled Amazon’s €746m fine while upholding core findings. Key takeaway: apply CJEU (Deutsche Wohnen/Nacionalinis) and robustly justify the GDPR fine methodology.
ANSSI ReCyF: immutable, isolated backups to meet DORA Art. 12
ANSSI’s ReCyF (17/03/2026) calls for immutable, isolated backups to counter ransomware. Here’s how to deploy them and evidence compliance with DORA Art. 12 and NIS 2.
NIS 2 vs DORA in Luxembourg: notify in 24 h or 4 h?
Verifiable fact: CSSF Circular 25/893 (27/05/2025) aligns DORA reporting with a first notification “within 4 hours” after classification. NIS 2 requires a preliminary alert “within 24 hours.” Key issue: who to notify, when, and against which clock in Luxembourg.
Liechtenstein: UBO register hacked (31,000 individuals affected)
Liechtenstein confirms data exfiltration from its UBO register (VwbP), affecting around 31,000 individuals. A stark reminder: these registers hold highly sensitive data that must be protected as critical assets.
DORA TLPT vs TIBER‑EU/LU: the key gap on internal testers
Delegated Regulation (EU) 2025/1190 allows, under strict conditions, internal testers for DORA TLPT. TIBER‑EU/TIBER‑LU require external providers for recognition.