Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

US DPF: adequacy adopted, EDPB caution and CNPD guidance

On 10 July 2023, the Commission adopted the EU‑US DPF adequacy decision (GDPR art. 45). The EDPB urges caution and the CNPD sets practical checks: verify certification and scope (incl. HR) and keep a fallback plan.

French Education Ministry: data breach targeting millions of students

On 18 August 2026, France’s Education Ministry confirmed an intrusion and investigation into a breach claimed to target several million students and tens of thousands of teachers. Highly detailed databases are reportedly involved.

VG Düsseldorf (02/04/2026): Transport Encryption Can Suffice

On April 2, 2026, the VG Düsseldorf held that well‑governed email transport encryption can satisfy GDPR Article 32 without mandating end‑to‑end in all cases—provided effectiveness is evidenced by measures and logs.

GDPR Article 22: CJEU vs United Kingdom — widening gap on automated decisions

On 7 December 2023, the CJEU tightened GDPR Article 22, while the UK broadened permitted cases via the 2025 DUAA. Luxembourg groups operating in the UK must now manage two diverging regimes.

UK Government Investments: 51 staff exposed — asset inventory is decisive

UKGI acknowledged an internal file exposed the names and work emails of 51 staff for ~40 hours. A CMDB covering information assets and sharing surfaces operationalizes NIS 2 Art. 21 and prevents such leaks.

CNIL fines IQVIA €5M: health data warehouses under high scrutiny

On May 26, 2026, the CNIL fined IQVIA €5M for breaching authorizations and Articles 14 and 25 GDPR across two health data warehouses. Clear message: effective notice, operational opt-out, and privacy by design are non-negotiable.

“Code of conduct” AiTM campaign against Microsoft 365: a GDPR-aligned response

Microsoft detailed an AiTM phishing campaign against Microsoft 365 and published IOCs. Here is how phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces operational risk.

NIS 2: EU adopts the supply chain Toolbox — what ILR will check

On 13/02/2026, the EU adopted the EU ICT Supply Chain Security Toolbox. Under NIS 2 and Implementing Regulation 2024/2690, supplier management becomes prescriptive and must be evidenced in Luxembourg before the ILR.

15 August 2026: the Dutch Cybersecurity Act (NIS 2 NL) has entered into force

As of 15 August 2026, the Dutch NIS 2 law (Cyberbeveiligingswet) applies. For groups in Luxembourg with activities or providers in the Netherlands, obligations now apply on both sides of the border.

FortiBleed targets 430k FortiGate — continuous VM to meet NIS 2

FortiBleed (Lynx/INC) mass-stole Fortinet credentials. Here’s how continuous Vulnerability Management operationalizes NIS 2 Article 21 and reduces exposure before the next campaign.

NIS 2 in Luxembourg: scope, categories and self‑registration

Luxembourg’s law of 5 May 2026 transposing NIS 2 has been in force since 10 May 2026. The ILR clarifies scope, the “essential/important entity” categorization, and self‑registration.

August 11, 2026: cold calling banned without consent

Since August 11, 2026, B2C cold calling in France is banned without prior explicit consent. Fines can reach €375,000 per breach for legal entities.

← Newer Page 2 / 23 Older →