Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

30 articles found · #cnil

Uber fined €825m for automated decisions: strong signal on GDPR Article 22

The Dutch DPA, with the CNIL, fined Uber nearly €825m for automated driver account deactivations/suspensions without adequate safeguards. Clear message: GDPR Article 22 applies concretely to high‑impact business algorithms.

CNIL fines a hospital: €500,000 and security requirements

The CNIL fines the Hôpital privé de la Loire €500,000 after a large-scale EHR breach. A reminder of security (MFA, access rights, detection) and data subject notification requirements, with direct implications in Luxembourg.

Vehicle geolocation: CNPD vs CNIL on retention and oversight

CNIL sets a 2‑month default retention for vehicle geolocation, while CNPD requires a case‑by‑case proportionality proof with potential L.261‑1 referral. Adapt HR and fleet policies accordingly in Luxembourg.

CNIL fines IQVIA €5M: health data warehouses under high scrutiny

On May 26, 2026, the CNIL fined IQVIA €5M for breaching authorizations and Articles 14 and 25 GDPR across two health data warehouses. Clear message: effective notice, operational opt-out, and privacy by design are non-negotiable.

CNPD vs CNIL: 8 days or 1 month to retain workplace CCTV footage?

Facts: CNPD sets 8 days in principle (30 days exceptionally), while CNIL tolerates up to one month. Key point: align video retention with GDPR Art. 5(1)(e) and Luxembourg Labor Code L. 261‑1.

CNIL: New Guidelines on Tracking Pixels in Emails

The CNIL releases guidelines and FAQs to regulate tracking pixels in emails, affecting companies using tracking tools. A key priority for DPOs and CISOs across Europe.

IQVIA: €5m fine and health data — Article 9 GDPR under strain

CNIL fines IQVIA France €5m for failings in health data warehouses. Key takeaway for Luxembourg: “pseudonymised” data remains health data (Art. 9 GDPR) and requires a strict legal basis and effective safeguards.

France Travail: €5M fine for inadequate security (GDPR Art. 32)

On 22 January 2026, the CNIL fined France Travail €5M for breaches of GDPR Article 32. Key takeaway: prove the proportionality and effectiveness of security measures, with clear documentation, including in Luxembourg.

Workplace video surveillance: CNPD (8 days) vs CNIL (1 month)

The CNPD sets an 8‑day retention period “in principle,” while the CNIL allows up to one month. A concrete divergence affecting retention, DPIAs and employee information.

Workplace video surveillance: CNIL fine of 2 April 2026

On 02/04/2026, the CNIL imposed a €7,500 fine for CCTV non-compliance. In Luxembourg, the CNPD likewise requires proportionality, frequent DPIAs and two-layer information.

CNIL: vehicle location data — new recommendation

On 30 June 2026, the CNIL issued a recommendation on the use of vehicle location data. It clarifies ePrivacy consent, multi-user rights, security, data minimisation and the need for DPIAs.

Recording meetings and calls: €250,000 fine — CNPD framework 2026

On 16/10/2025, the CNIL fined a call center €250,000 for poorly governed recordings. Since April 2026, the CNPD has issued a dedicated framework for meeting recordings: legal basis, transparency, retention, security, and DPIA.

Page 1 / 3 Older →