Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

125 articles found · #luxembourg

Recording calls: the SWDE case and what the CNPD expects in Luxembourg

Belgium’s DPA fined SWDE €86,000 for non-compliant call recordings. In Luxembourg, the CNPD strictly frames recordings: point-of-contact notice, clear legal basis, short retention, and Article 28 DPAs.

WEBA (BE) hit by Qilin: ransomware, customer data accessed, 48 h recovery

On August 10, 2026, Belgian retailer WEBA was hit by a ransomware attack. Customer data was accessed; operations resumed on August 12. Qilin claimed responsibility on August 16; WEBA says no ransom was paid.

Odido (Netherlands): 6.2M customers — a 24/7 SOC to meet NIS2 Art. 23

On 7–8 February 2026, Odido suffered a CRM-targeted attack: ~6.2M individuals exposed. Here’s how a 24/7 SOC and modern SIEM enable detection, containment, and on-time NIS2 notifications (24h/72h/1 month).

French Education Ministry: data breach targeting millions of students

On 18 August 2026, France’s Education Ministry confirmed an intrusion and investigation into a breach claimed to target several million students and tens of thousands of teachers. Highly detailed databases are reportedly involved.

CNIL fines IQVIA €5M: health data warehouses under high scrutiny

On May 26, 2026, the CNIL fined IQVIA €5M for breaching authorizations and Articles 14 and 25 GDPR across two health data warehouses. Clear message: effective notice, operational opt-out, and privacy by design are non-negotiable.

NIS 2: EU adopts the supply chain Toolbox — what ILR will check

On 13/02/2026, the EU adopted the EU ICT Supply Chain Security Toolbox. Under NIS 2 and Implementing Regulation 2024/2690, supplier management becomes prescriptive and must be evidenced in Luxembourg before the ILR.

15 August 2026: the Dutch Cybersecurity Act (NIS 2 NL) has entered into force

As of 15 August 2026, the Dutch NIS 2 law (Cyberbeveiligingswet) applies. For groups in Luxembourg with activities or providers in the Netherlands, obligations now apply on both sides of the border.

NIS 2 in Luxembourg: scope, categories and self‑registration

Luxembourg’s law of 5 May 2026 transposing NIS 2 has been in force since 10 May 2026. The ILR clarifies scope, the “essential/important entity” categorization, and self‑registration.

August 11, 2026: cold calling banned without consent

Since August 11, 2026, B2C cold calling in France is banned without prior explicit consent. Fines can reach €375,000 per breach for legal entities.

CJEU C‑312/24 — Erasure vs legal obligation: a relative right

The CJEU clarifies that erasure (Art. 17 GDPR) yields when a clear, foreseeable and proportionate legal obligation justifies retention, including for criminal data in HR files. Once no longer necessary, erasure becomes mandatory again.

DGFiP: 600,000 tax records for sale — warning on stealth exfiltration

On 14 August 2026, France’s Finance Ministry confirmed a DGFiP breach with over 600,000 tax records exported. A stealth exfiltration via a spoofed VPN, fueling targeted fraud risks.

NIS 2: common 24h/72h/1‑month templates — what ILR expects

On 26 May 2026, the EU adopted common incident reporting templates (24h/72h/1 month). In Luxembourg, ILR confirms this sequencing and sets out the expected content for entities.

Page 1 / 11 Older →