Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

128 articles found · #luxembourg

MAG: 8.7M customers exposed — third‑party risk hits airports

Manchester Airports Group confirms unauthorized access to parking, lounge, Fast Track and Wi‑Fi data, affecting around 8.7M customers. The case highlights third‑party risk and GDPR/NIS 2 notification duties.

Legitimate interest vs consent: French Supreme Court, 17 June 2026

On 17 June 2026, the French Supreme Court (commercial chamber) required strict Article 14 GDPR information when relying on legitimate interest for data collected indirectly, including in litigation contexts.

MyDr: 19M health records exposed — third‑party risk hits Europe

Polish health software vendor MyDr suffered a breach disclosed August 12–13, 2026: nearly 19M people and over 12,000 facilities may be affected. Poland’s PM suggested extortion as the motive.

Recording calls: the SWDE case and what the CNPD expects in Luxembourg

Belgium’s DPA fined SWDE €86,000 for non-compliant call recordings. In Luxembourg, the CNPD strictly frames recordings: point-of-contact notice, clear legal basis, short retention, and Article 28 DPAs.

WEBA (BE) hit by Qilin: ransomware, customer data accessed, 48 h recovery

On August 10, 2026, Belgian retailer WEBA was hit by a ransomware attack. Customer data was accessed; operations resumed on August 12. Qilin claimed responsibility on August 16; WEBA says no ransom was paid.

Odido (Netherlands): 6.2M customers — a 24/7 SOC to meet NIS2 Art. 23

On 7–8 February 2026, Odido suffered a CRM-targeted attack: ~6.2M individuals exposed. Here’s how a 24/7 SOC and modern SIEM enable detection, containment, and on-time NIS2 notifications (24h/72h/1 month).

French Education Ministry: data breach targeting millions of students

On 18 August 2026, France’s Education Ministry confirmed an intrusion and investigation into a breach claimed to target several million students and tens of thousands of teachers. Highly detailed databases are reportedly involved.

CNIL fines IQVIA €5M: health data warehouses under high scrutiny

On May 26, 2026, the CNIL fined IQVIA €5M for breaching authorizations and Articles 14 and 25 GDPR across two health data warehouses. Clear message: effective notice, operational opt-out, and privacy by design are non-negotiable.

NIS 2: EU adopts the supply chain Toolbox — what ILR will check

On 13/02/2026, the EU adopted the EU ICT Supply Chain Security Toolbox. Under NIS 2 and Implementing Regulation 2024/2690, supplier management becomes prescriptive and must be evidenced in Luxembourg before the ILR.

15 August 2026: the Dutch Cybersecurity Act (NIS 2 NL) has entered into force

As of 15 August 2026, the Dutch NIS 2 law (Cyberbeveiligingswet) applies. For groups in Luxembourg with activities or providers in the Netherlands, obligations now apply on both sides of the border.

NIS 2 in Luxembourg: scope, categories and self‑registration

Luxembourg’s law of 5 May 2026 transposing NIS 2 has been in force since 10 May 2026. The ILR clarifies scope, the “essential/important entity” categorization, and self‑registration.

August 11, 2026: cold calling banned without consent

Since August 11, 2026, B2C cold calling in France is banned without prior explicit consent. Fines can reach €375,000 per breach for legal entities.

Page 1 / 11 Older →