CJEU C‑340/21: proving adequacy (GDPR Art. 32) requires logs
The CJEU (C‑340/21) places the burden on controllers to prove adequacy (GDPR Art. 32). In practice: 24/7 SIEM/SOC and robust logging to detect, investigate, and notify the ILR within 24h under NIS 2.
Excerpt. On 14 December 2023, the CJEU (C‑340/21, Natsionalna agentsia za prihodite) held that the data controller must prove the adequacy of its security measures (GDPR Art. 32). In practice: a 24/7 SIEM/SOC and robust logging become the key evidence — and enable ILR notification within 24h under NIS 2.
The facts
On 14 December 2023, the Court of Justice of the European Union issued the judgment VB v. Natsionalna agentsia za prihodite (C‑340/21). Following a large‑scale hack of the Bulgarian tax authority, the CJEU clarified two points:
- Burden of proof: the controller must demonstrate that its technical and organizational measures were “appropriate” under GDPR Article 32 (Arts. 5(2) and 24), including in damages actions (Art. 82). An expert report is neither systematically necessary nor sufficient; the judge assesses case by case based on internal evidence (logs, policies, tests, etc.). EUR‑Lex, C‑340/21, 14/12/2023; CJEU press release No 191/23.
- Practical scope: invoking an “external” cyberattack is not enough to escape liability; the organization must prove it selected and operated risk‑appropriate, traceable, and verifiable measures. Market analysis: DLA Piper – Privacy Matters.
In Luxembourg, this evidentiary duty dovetails with NIS 2 in Luxembourg (Law of 5 May 2026), which requires alerting the ILR within 24 hours after detecting a significant incident, then notifying within 72h and delivering a final report. Without reliable detection and usable traces, these deadlines are unrealistic. ILR — Incident notification.
The applicable legal framework
- GDPR — Article 32: “appropriate” measures considering risks (confidentiality, integrity, availability), including the ability to demonstrate compliance (Arts. 5(2) and 24). The CJEU (C‑340/21) clarifies that the burden of proof lies with the controller; adequacy is judged on concrete elements (logs, procedures, tests, evidence of effectiveness). EUR‑Lex.
- NIS 2 — Article 23 (transposed by the Luxembourg law of 5 May 2026): preliminary alert “without undue delay and at the latest within 24h” after detection, then 72h notification and a final report within one month. The ILR details the process and expects content supported by technical elements (likely cause, impact, measures taken). ILR.
- CSSF (financial sector): explicit requirements for logging and continuous monitoring (e.g., Circular CSSF 21/769: “A sound logging process must be implemented…”), reinforced by DORA for in‑scope entities. CSSF 21/769 (PDF); CSSF — ICT & cyber‑risk (DORA).
The technical solution to deploy
24/7 managed SIEM/SOC with evidential logging.
Goal: detect early, investigate fast, and prove adequacy (GDPR Art. 32) while complying with NIS 2 (ILR 24h alert).
How it works in practice
- Standardized logging: centralize events (authentication, access, admin actions, exfiltration, EDR/XDR, cloud, SaaS, VPN) with reliable timestamping, retention, and integrity (hash/immutability). References: ISO 27001 Annex A.8.15/A.8.16 (logging/time sync), A.5.10 (logging), NIST CSF 2.0 (DE.CM, RS.AN), CIS Controls 8 (Logs 8/13).
- SIEM: real‑time correlation (Sigma/UEBA rules) to detect attack chains (phishing → token theft → privilege escalation → exfiltration). Produces actionable alerts with evidence (who/when/how/what) for the ILR and the DPO.
- 24/7 SOC: triage, investigation, initial containment (account disable, network blocks), and pre‑drafting of the “24h / 72h / 1‑month” notices with ILR‑required fields. Timestamped logs serve as the factual backbone to meet C‑340/21’s demonstration requirement.
- Ready‑to‑use forensics: lawful log retention, chain of custody, and timeline reconstruction. Without these, proving “adequacy” becomes speculative — which the CJEU rejects.
Why this is the right legal/technical answer
- Adequacy (Art. 32): a “logs + SIEM + SOC” stack evidences risk control (detection, containment, traceability) and enables ex ante/ex post demonstration, as required by C‑340/21.
- NIS 2, Art. 23: it enables sufficiently early detection to alert the ILR within 24h with verifiable elements (indicators, affected scope, initial impact assessment).
- CSSF and DORA: it aligns with logging, continuous monitoring, and swift investigation/restore capabilities required for financial entities. CSSF 21/769; CSSF — DORA.
How Luxgap deploys this
- Our 24/7 managed SOC: onboarding in 4–6 weeks, out‑of‑the‑box connectors (Microsoft 365, AzureAD/Entra, Okta, VPN, EDR/XDR, firewalls, SaaS), Sigma rules for NIS 2 (service‑impact detections), built‑in ILR alert procedures. We deliver artefacts (signed logs, timelines, incident briefs) to support adequacy (Art. 32) as required by C‑340/21.
- Our ISO 27001 governance: Lead Implementer/Auditor consultants structure the logging policy (scope, retention, integrity), NIS 2 playbooks (24h/72h/1‑month), and proof indicators. ISO 27001 Annex A.5/A.8 alignment is documented for CSSF/ILR/CNPD audits.
- Our outsourced DPO and CISO: framing “adequacy” (proportionality tests, residual risks, proof registers), steering ILR/CNPD notifications, and adversarial responses in audits or disputes (DPO mandate and outsourced CISO).
Real‑world case in Luxembourg or the EU
An essential entity in the digital infrastructure sector (NIS 2) ran a SIEM limited to firewalls. After an M365 incident (OAuth impersonation), it lacked admin access traces and a reliable timeline. In 6 weeks, we:
- Expanded logging (authentication, privileged accounts, Exchange/SharePoint/Teams activities, OAuth API) and enabled 180‑day immutable retention.
- Deployed SIEM rules for anomalous tokens and privilege escalations, plus a “NIS 2 — 24h” dashboard.
- Equipped the ILR process (24h/72h briefs, field mapping, checklist of technical evidence).
Outcome: on a new incident (suspicious OAuth activity), the alert was qualified in under 2h, the ILR was alerted at T+21h with technical artefacts (logs, scope, measures), and the DPO could demonstrate control adequacy under Art. 32, aligned with C‑340/21.
First concrete steps
- Map your critical logs (authentication, IAM, admins, EDR/XDR, M365/SaaS, VPN, exfiltration). Decide target retention (≥ 6 months) and integrity (hash/immutability).
- Enable 10 “NIS 2/ILR” SIEM rules (service degradation, privileged accounts, high‑volume outbound email, risky OAuth app creation, critical EDR alerts) and test them on real data.
- Set up a “24h pack”: ILR alert template, SIEM auto‑filled fields, 24/7 point of contact, and a declaration timer.
- Stress‑test the chain of custody: a 2‑hour mini‑tabletop to rebuild a timeline from logs; confirm you can demonstrate adequacy (C‑340/21) with internal artefacts alone.
- Formalize the policy (ISO 27001): logging scope, access, retention, periodic rule review; link each control to GDPR Art. 32 and NIS 2 Art. 23.
Official sources
- CJEU, 14 Dec 2023, C‑340/21, VB v. Natsionalna agentsia za prihodite (EUR‑Lex) — burden of proof and adequacy assessment (GDPR Arts. 5(2), 24, 32, 82).
- CJEU — Press release No 191/23 (14/12/2023).
- ILR (Luxembourg) — Incident notification (NIS 2, Law of 5 May 2026).
- CSSF — Circular 21/769 (logging and ICT security) and CSSF “ICT & cyber‑risk” (DORA).
- DLA Piper — Analysis on the duty to demonstrate (GDPR Art. 32).
Need support? Explore our Luxgap approach or reach out via contact.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →