← All articles

consultant

Amazon vs CNPD (12/03/2026): fine annulled, fine methodology reset

On 12 March 2026, Luxembourg’s Administrative Court annulled Amazon’s €746m fine while upholding core findings. Key takeaway: apply CJEU (Deutsche Wohnen/Nacionalinis) and robustly justify the GDPR fine methodology.

12 March 2026 — Amazon vs CNPD. Luxembourg’s Administrative Court (judgment No 52757C) annulled the €746m fine imposed on Amazon in 2021, while upholding core findings on processing activities. Key takeaway: GDPR fine methodology must reflect CJEU case law (Deutsche Wohnen and Nacionalinis) and the fault requirement. Official sources: Luxembourg Justice portal, CNPD (FR), CNPD (EN).

The case

The Court noted that orders and the penalty payment became moot because Amazon had brought its processing into compliance. However, the fine was annulled due to a subsequent change in CJEU case law (5/12/2023) governing sanction powers and the need to establish at least negligent fault. References: C‑807/21 Deutsche Wohnen and C‑683/21 Nacionalinis. See also the CJEU flash (Decisions of interest to the Union, 2026/2).

Legal reasoning

1) Article 83 GDPR and judicial review

Article 83 GDPR requires effective, proportionate and dissuasive fines, reasoned against specific factors (gravity, duration, intent/negligence, cooperation, corrective measures, past infringements, etc.). Text: EUR‑Lex, GDPR. The CJEU (5/12/2023) clarified: (i) the entity as controller may be directly fined; (ii) the authority must establish fault (at least negligence) and respect the autonomous framework of Article 83(2). The Administrative Court applied this framework and remitted the fine calculation/method.

2) Right to object (Article 21) and scope

The CJEU flash notes the Court dismissed an independent Article 21 violation in this case, without undermining the right to object to interest‑based marketing. It stresses specificity of charges and burden of proof. Framework: GDPR and European Commission guidance.

3) Fine calculation: EDPB expectations

EDPB Guidelines 04/2022 (24/05/2023) set five steps: starting point (gravity/category), number of infringements, aggravating/mitigating factors, legal caps, and final check (effective, proportionate, dissuasive). Refs.: EDPB 04/2022 and EDPB news.

What changes in practice

  • Executives, in‑house counsel and DPOs in Luxembourg: fines will remain high where fault is evidenced and the EDPB method is robustly reasoned. Conversely, weak reasoning can lead to annulment or recalibration even if non‑compliance persists. To secure your DPO mandate and sanction governance, structure evidence under Article 83(2) and EDPB steps.
  • Marketing and CISOs: material compliance comes first. Fix quickly and log remediation (decision logs, change logs, CMP, ID deactivation, new legal bases, updated DPAs, Article 32 controls). An independent security audit helps substantiate these controls.
  • Advertising and legitimate interest: document the balancing test (Art. 6(1)(f)), offer a frictionless objection (Art. 21) and keep execution evidence; clarify roles/contracts (Arts. 26–28) per EDPB 8/2020. For local implementation, see GDPR Luxembourg compliance with the CNPD.

Example: a banner relying on legitimate interest for marketing must provide a simple, enforceable objection, truly disable tags/IDs, and show the controller’s interests do not override data subjects’ interests. Otherwise: investigation, orders, then a fine under a methodology now tested against the 05/12/2023 CJEU rulings.

Common pitfalls

  1. Incomplete fine methodology: failure to align with EDPB 04/2022’s five steps (gravity/duration, number of infringements, factors, caps, proportionality) risks partial/total annulment. Ref.: EDPB 04/2022.
  2. Underestimating the fault requirement: since C‑807/21 and C‑683/21, provide concrete elements (known inadequate procedures, lack of controls, ignored warnings, etc.). Refs.: C‑807/21, C‑683/21.
  3. Equating remediation with no liability: later compliance affects penalty payments and quantum but does not erase past infringements. Refs.: official summary, CNPD position.
  4. Poorly implemented right to object: a non‑functional opt‑out, inconsistent request handling, or mis‑mapped legal bases triggers focused allegations. Framework: European Commission.
  5. Weak adtech governance: unclear roles/contracts (Arts. 26–28), missing records (Art. 30) and unproven measures (Art. 32). Ref.: EDPB 8/2020.

Official sources

In short

The 12 March 2026 ruling does not loosen Luxembourg enforcement: it raises the bar on reasoning and methodology for GDPR fines under CJEU oversight. Priorities for organisations: remediate fast and document legal basis, objection flows and adtech governance. For local guidance across risk calculation and evidencing, see our GDPR Luxembourg page or contact us.

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →