Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

187 articles found · #rgpd

CJEU C‑526/24 — When a first access request is “abusive” under Art. 12(5)

The CJEU allows, in exceptional cases, refusal of a first access request (Art. 15 GDPR) if the controller proves an abusive intent to manufacture compensable harm. Article 12(5) is interpreted strictly and the burden of proof lies with the controller.

MAG: 8.7M customers exposed — third‑party risk hits airports

Manchester Airports Group confirms unauthorized access to parking, lounge, Fast Track and Wi‑Fi data, affecting around 8.7M customers. The case highlights third‑party risk and GDPR/NIS 2 notification duties.

Vehicle geolocation: CNPD vs CNIL on retention and oversight

CNIL sets a 2‑month default retention for vehicle geolocation, while CNPD requires a case‑by‑case proportionality proof with potential L.261‑1 referral. Adapt HR and fleet policies accordingly in Luxembourg.

CNIL fines Free/Free Mobile €42M for weak VPN MFA

CNIL fines Free/Free Mobile €42M for weak VPN MFA and failed detection after data exfiltration affecting ~24.6M contracts. Here is the phishing-resistant MFA that would have prevented most of it.

Legitimate interest vs consent: French Supreme Court, 17 June 2026

On 17 June 2026, the French Supreme Court (commercial chamber) required strict Article 14 GDPR information when relying on legitimate interest for data collected indirectly, including in litigation contexts.

MyDr: 19M health records exposed — third‑party risk hits Europe

Polish health software vendor MyDr suffered a breach disclosed August 12–13, 2026: nearly 19M people and over 12,000 facilities may be affected. Poland’s PM suggested extortion as the motive.

ENISA Secure by Design: a measurable IAM for GDPR 25 and NIS 2

ENISA’s Secure by Design and Default Playbook provides checklists and minimal evidence. Here’s how a measurable IAM operationalizes these requirements while meeting GDPR art. 25 and NIS 2.

CNPD — Recording meetings: consent rarely valid, legitimate interest under conditions

On 08/07/2026, Luxembourg’s CNPD updated its file on recording private meetings: consent is rarely valid; legitimate interest applies only case by case; deletion is required once the minutes are approved.

RingCentral: 1.6M emails exposed — move to phishing-resistant MFA

After the ShinyHunters attack, ~1.6M RingCentral emails leaked. A FIDO2/WebAuthn MFA would have broken the attack chain and meets GDPR Article 32 requirements.

Recording calls: the SWDE case and what the CNPD expects in Luxembourg

Belgium’s DPA fined SWDE €86,000 for non-compliant call recordings. In Luxembourg, the CNPD strictly frames recordings: point-of-contact notice, clear legal basis, short retention, and Article 28 DPAs.

WEBA (BE) hit by Qilin: ransomware, customer data accessed, 48 h recovery

On August 10, 2026, Belgian retailer WEBA was hit by a ransomware attack. Customer data was accessed; operations resumed on August 12. Qilin claimed responsibility on August 16; WEBA says no ransom was paid.

US DPF: adequacy adopted, EDPB caution and CNPD guidance

On 10 July 2023, the Commission adopted the EU‑US DPF adequacy decision (GDPR art. 45). The EDPB urges caution and the CNPD sets practical checks: verify certification and scope (incl. HR) and keep a fallback plan.

Page 1 / 16 Older →