← All articles

consultant

GDPR Record: CNPD fines for insufficient ROPA, ICO promotes flexibility

On 16 December 2025, the CNPD fined an organisation for an “insufficient” record of processing (Art. 30 GDPR). By contrast, the ICO updated a more flexible approach in June 2026. This gap affects EU–UK groups.

Excerpt — On 16 December 2025, the CNPD imposed a fine for “insufficient information” in a record of processing activities (Art. 30 GDPR). By contrast, in June 2026 the ICO updated more flexible guidance on ROPAs. This gap affects EU–UK groups.

The case

On 16 December 2025, the CNPD adopted Deliberation No. 5FR/2025, fining an organisation for “insufficient information in the record of processing activities” (Art. 30 GDPR). The official notice, updated on 27 March 2026, confirms the infringement without disclosing the amount. See: Deliberation No. 5FR/2025 — fine.

This decision is part of inspections focusing on ROPA quality and completeness. The CNPD lists the required fields (purposes, categories, recipients, transfers, retention, security measures “where possible”) and stresses the narrowly framed < 250 employees derogation (Art. 30(5)). Ref.: CNPD — Record of processing activities.

By contrast, the UK ICO updated in June 2026 its How do we document our processing activities? page in the context of the Data (Use and Access) Act 2026, offering templates with “mandatory” and “useful” fields and a proportionate approach.

Legal reasoning

  • Baseline. GDPR Article 30 requires a record covering purposes, data/subject categories, recipients, transfers, retention, and, “where possible,” a description of security measures (Art. 30(1)(g)). The Art. 30(5) derogation for < 250 employees does not apply where processing is not occasional, involves risk, or covers special/criminal data (Arts. 9–10).
  • CNPD/EDPB (EU) stance. The CNPD applies a strict reading; in practice most Luxembourg organisations must maintain a full ROPA (see CNPD page). The EDPB curtailed derogations in 2018 (Position Paper) and in 2025 reminded in a letter (8 May) and a Joint Opinion 01/2025 that SME simplification must not hollow out the obligation.
  • ICO (UK) stance. The ICO allows integrating the ROPA into existing records, provides templates with “mandatory” vs “useful” fields, and endorses practical proportionality, while keeping the Art. 30 UK GDPR duty. See also the Accountability toolkit.

In short: in the EU/Luxembourg (CNPD/EDPB), the record is a substantive and evidential compliance tool, with a rare derogation; in the UK (ICO), it remains mandatory but the emphasis is on flexibility and proportionality.

What this changes in practice

  • EU–UK groups. If your Luxembourg HQ consolidates a group ROPA and your UK affiliate follows a lighter ICO approach, align on the stricter requirement to avoid a double standard. The CNPD’s 16/12/2025 decision shows that a deficient record risks a fine.
  • Commonly underestimated fields. Expect clear traceability of purposes, data/recipient categories, extra-EEA transfers (Arts. 44–49 legal bases and safeguards), and “where possible” security measures. Refs.: CNPD — Record ; EUR‑Lex Art. 30.
  • < 250 employees: false comfort. Many processes are not “occasional” (payroll, HR, CRM), create risk (monitoring, geolocation, health), or involve special data. In Luxembourg, even SMEs often need a full ROPA (consistent with EDPB/CNPD).
  • Evidential documentation. The ROPA should quickly evidence lawful basis (Art. 6), retention, transfers and Art. 32 measures. The ICO allows consolidation into existing records, but in Luxembourg an up‑to‑date, usable ROPA is expected.

Concrete examples (Luxembourg)

  • A bank documents third‑country transfers to vendors (SCC/BCR, TIA, access limitation), data categories and regulatory archiving periods.
  • An industrial site with access badges and CCTV describes purposes, legal bases, retention, internal recipients (security, HR) and external processors.
  • A 120‑employee services SME processing health data and non‑occasional security logs cannot rely on Art. 30(5).

Frequent pitfalls

  1. “List of processes” instead of a standardised record. A minimalist table without clear purposes, recipient categories or retention is “insufficient”. See CNPD — Delib. 5FR/2025.
  2. Forgetting extra‑EEA transfers. Indicate third country and safeguards (SCC, BCR) and/or Art. 49 basis (see Art. 30(1)(e)).
  3. Vague retention periods. Avoid “as long as necessary”: set operational/legal bounds, at least by category (ref. CNPD — Record).
  4. Missing security measures. Even “where possible,” describe access controls, encryption, MFA, logging to evidence Art. 32 (ref. Art. 30(1)(g)).
  5. Assuming the < 250 exemption applies. The derogation is cumulative and rarely fits; the EDPB (Joint Opinion 01/2025) insists on a useful, workable record.

Next steps

To secure your record and accountability evidence, a certified DPO mandate can speed up compliance and ongoing maintenance.

You can also revisit your requirements against Article 30 GDPR and apply the stricter standard across EU–UK entities.

Need a ROPA health‑check or an operational template? Feel free to contact us.

Official sources

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →