Council of State upholds CNIL authorisation for HDH: cloud impact and proof of compliance
On 20/03/2026, France’s Council of State upheld CNIL’s authorisation for the Health Data Hub hosted on Azure in France. Key takeaway: use CSPM to evidence compliance with GDPR, NIS 2 and CSSF 22/806.
Excerpt — On 20 March 2026, France’s Council of State upheld CNIL’s authorisation allowing the Health Data Hub to process data on Microsoft Azure in France. Business impact: use technology (CSPM) to evidence compliance with GDPR (Art. 32, 44–49) and CSSF 22/806.
What happened
On 20 March 2026, the Council of State (France) dismissed the appeals against CNIL’s authorisation for the Health Data Hub (HDH) to process health data extracted from the SNDS and hosted on Microsoft Azure in France, notably for DARWIN EU. The Council stressed the authorisation concerns data hosted in France and does not amount to an authorisation for transfers to the United States. The ruling clarifies the line: hosting in France on a non‑EU cloud is legally possible, but requires robust guarantees and continuous operational control over transfer risks and the effectiveness of security measures. Official source: Council of State, 20/03/2026. Press coverage: Le Monde Informatique and Clubic.
Why it matters in Luxembourg (May–Aug 2026): the NIS 2 law (5 May 2026) and financial sector rules (CSSF 22/806, as amended) require concrete evidence of cloud risk control: data location, access control, encryption, logging, reversibility, and governance of critical subcontractors. See CSSF 22/806 and ILR’s official NIS 2 briefing (06/07/2026).
The applicable legal framework
- GDPR — Article 32: appropriate technical and organisational measures (encryption, confidentiality, integrity, availability) proportionate to risk. Text: EUR‑Lex. For an operational overview, see our notes on GDPR requirements.
- GDPR — Chapter V (Arts. 44–49): transfers to third countries only under conditions (adequacy, SCCs plus supplementary measures, or limited derogations). Official summary: CNIL — Chapter V.
- Council of State ruling (20/03/2026): confirms CNIL’s authorisation covers hosting in France, without validating extra‑EU transfers. Operational result: the duty to prevent and detect de facto transfers (logs, diagnostics, remote admin, support) lies with the controller and its processors. Source: Council of State.
- Luxembourg — CSSF 22/806: cloud requirements for financial entities (criticality assessment, due diligence, data location, access control, encryption, logging, portability/reversibility, exit plans and audit). Text: CSSF 22/806.
- NIS 2 (LU, law of 5 May 2026): risk management and supply‑chain control for essential/important entities; supervised by ILR. Briefing: ILR and Luxembourg Government.
The technical solution: evidence‑driven CSPM
A Cloud Security Posture Management (CSPM) continuously monitors configuration and compliance across IaaS/PaaS/SaaS. The goal is not a generic “best practice”, but to evidence GDPR/CSSF/NIS 2 requirements in light of the Council of State ruling:
- Location and flows: policies that forbid resource creation outside the EU/LU/FR; detection of egress to non‑EU endpoints; blocks on unapproved cross‑region copy/sync; alerts when support/diagnostic options export logs outside the EU (GDPR Chapter V).
- Encryption and key management: mandatory encryption at rest and in transit; customer‑managed keys with EU‑only HSM; rotation, usage control via Key Access Justification or equivalent; auditable access proofs (GDPR Art. 32; CSSF 22/806).
- Access control: role‑based IAM, PAM for admins, least‑privilege policies, phishing‑resistant MFA on consoles/admin APIs; alerts on public “link‑anyone” shares and stale service accounts (GDPR Art. 32; NIS 2 Art. 21).
- Logging and traceability: systematic activation of access/config logs; compliant retention and immutability; anomaly detection (export connectors, peering attachments, transfer policy changes) to prevent unintended transfers (GDPR Chapter V; CSSF 22/806).
- Reversibility and exit: inventory of dependencies and datasets, table‑top tests for export/secure deletion; CSPM checks on purge controls and object‑lock (CSSF 22/806).
References: ISO/IEC 27001 Annex A (A.5.36 change management, A.8.24 cryptography, A.8.16 privileged access control, A.5.10 logging), NIST CSF 2.0 (ID.GV‑03, PR.AA‑01, PR.DS‑01, DE.CM‑02), CIS Benchmarks Cloud (Azure/AWS/GCP).
How Luxgap delivers
- Our ISO 27001 governance: mapping GDPR (Arts. 32, 44–49) and CSSF 22/806 into your control framework and requirements register; defining cloud policies (location, keys, access, logs), expected evidence and alert thresholds. We run “evidence‑first” to ease ILR/CSSF audits. We also engage under a DPO mandate where required.
- Our 24/7 managed SOC: ingesting CSPM/CloudTrail/Activity Logs; correlating with IAM and your DLP/EDR to spot weak signals (e.g., new log exports to non‑EU buckets). Escalation and automated remediation playbooks (rule disablement, key rotation, deny policy). In production, this is operated by our managed SOC 24/7.
- Our fractional DPO and CISO: bridging tech and legal: mapping actual/potential transfers, contractual clauses, access registers and robust documentation for authorities (CNPD/CSSF/ILR). Synchronized with your records of processing and cloud exit plan.
Concrete use case in Luxembourg/EU
Realistic example: a Luxembourg management company (NIS 2 essential entity and subject to CSSF 22/806) migrates client data to a European hyperscaler PaaS. In 8 weeks, we:
- Mapped data flows and referenced GDPR/CSSF requirements in a traceable control matrix.
- Deployed a multi‑account CSPM with location guardrails (EU regions only) and encryption‑by‑default policies with EU‑HSM customer keys.
- Integrated CSPM with the Luxgap SOC (use cases: detect log exports to non‑EU buckets, alert on global admin grants, network configuration drift).
- Documented evidence: compliance dashboards, remediation tickets, signed logs, reversibility sheet; updated contractual annexes (NIS 2/22‑806 subcontractors).
Outcome: the company obtained an internal compliance green‑light for go‑live, with an evidence package ready for CSSF supervision and CNPD inspection, and alert thresholds aligned with the risk of unintended extra‑EU transfers, in line with the spirit of the Council of State ruling (20/03/2026).
Practical first steps
- Define your allowed regions (EU/LU/FR) and block resource creation outside them at policy level. Enable a CSPM “region allow‑list”.
- Migrate critical keys to an EU‑only KMS/HSM with customer‑managed keys, enable rotation and log every key use.
- Harden IAM: remove legacy access, enforce phishing‑resistant MFA on consoles and admin APIs, integrate PAM for privileged accounts.
- Enable 100% of logs (config, access, network), lock retention (immutability), and stream to your SIEM/SOC.
- Write/Test the exit plan: portability and erasure procedures; run a table‑top reversibility exercise and record evidence.
Official sources
- Court decision — Council of State (20/03/2026): health-data-hub… GDPR‑compliant. Coverage: Le Monde Informatique, Clubic.
- GDPR — Article 32 and Chapter V (transfers): EUR‑Lex; Chapter V summary: CNIL.
- Luxembourg — Cloud/Outsourcing (financial sector): CSSF 22/806.
- NIS 2 (Luxembourg, law of 5 May 2026) — Briefing: Luxembourg Government; ILR page: ILR.
Need to align cloud posture with evidence of compliance? Reach us via the contact page.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →