Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
181 articles found · #rgpd
ENISA Secure by Design: a measurable IAM for GDPR 25 and NIS 2
ENISA’s Secure by Design and Default Playbook provides checklists and minimal evidence. Here’s how a measurable IAM operationalizes these requirements while meeting GDPR art. 25 and NIS 2.
CNPD — Recording meetings: consent rarely valid, legitimate interest under conditions
On 08/07/2026, Luxembourg’s CNPD updated its file on recording private meetings: consent is rarely valid; legitimate interest applies only case by case; deletion is required once the minutes are approved.
RingCentral: 1.6M emails exposed — move to phishing-resistant MFA
After the ShinyHunters attack, ~1.6M RingCentral emails leaked. A FIDO2/WebAuthn MFA would have broken the attack chain and meets GDPR Article 32 requirements.
Recording calls: the SWDE case and what the CNPD expects in Luxembourg
Belgium’s DPA fined SWDE €86,000 for non-compliant call recordings. In Luxembourg, the CNPD strictly frames recordings: point-of-contact notice, clear legal basis, short retention, and Article 28 DPAs.
WEBA (BE) hit by Qilin: ransomware, customer data accessed, 48 h recovery
On August 10, 2026, Belgian retailer WEBA was hit by a ransomware attack. Customer data was accessed; operations resumed on August 12. Qilin claimed responsibility on August 16; WEBA says no ransom was paid.
US DPF: adequacy adopted, EDPB caution and CNPD guidance
On 10 July 2023, the Commission adopted the EU‑US DPF adequacy decision (GDPR art. 45). The EDPB urges caution and the CNPD sets practical checks: verify certification and scope (incl. HR) and keep a fallback plan.
French Education Ministry: data breach targeting millions of students
On 18 August 2026, France’s Education Ministry confirmed an intrusion and investigation into a breach claimed to target several million students and tens of thousands of teachers. Highly detailed databases are reportedly involved.
VG Düsseldorf (02/04/2026): Transport Encryption Can Suffice
On April 2, 2026, the VG Düsseldorf held that well‑governed email transport encryption can satisfy GDPR Article 32 without mandating end‑to‑end in all cases—provided effectiveness is evidenced by measures and logs.
GDPR Article 22: CJEU vs United Kingdom — widening gap on automated decisions
On 7 December 2023, the CJEU tightened GDPR Article 22, while the UK broadened permitted cases via the 2025 DUAA. Luxembourg groups operating in the UK must now manage two diverging regimes.
UK Government Investments: 51 staff exposed — asset inventory is decisive
UKGI acknowledged an internal file exposed the names and work emails of 51 staff for ~40 hours. A CMDB covering information assets and sharing surfaces operationalizes NIS 2 Art. 21 and prevents such leaks.
CNIL fines IQVIA €5M: health data warehouses under high scrutiny
On May 26, 2026, the CNIL fined IQVIA €5M for breaching authorizations and Articles 14 and 25 GDPR across two health data warehouses. Clear message: effective notice, operational opt-out, and privacy by design are non-negotiable.
“Code of conduct” AiTM campaign against Microsoft 365: a GDPR-aligned response
Microsoft detailed an AiTM phishing campaign against Microsoft 365 and published IOCs. Here is how phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces operational risk.