VG Düsseldorf (02/04/2026): Transport Encryption Can Suffice
On April 2, 2026, the VG Düsseldorf held that well‑governed email transport encryption can satisfy GDPR Article 32 without mandating end‑to‑end in all cases—provided effectiveness is evidenced by measures and logs.
Summary — On April 2, 2026, the Düsseldorf Administrative Court (VG Düsseldorf) held that well‑governed email transport encryption can meet GDPR Article 32 without systematically mandating end‑to‑end encryption. The practical challenge: how to implement it and evidence effectiveness, notably under CSSF 22/806.
The facts
The VG Düsseldorf issued its judgment on April 2, 2026 (case 29 K 7351/23), reviewed by MIR. Assessing an “adequate level of protection” under GDPR Article 32 for transmitting personal data by email, the court found that properly deployed transport encryption (TLS) can be sufficient given current risks, and that end‑to‑end encryption is not per se required in every case. The reasoning emphasizes risk analysis (severity/likelihood), state of the art, and processing context; in this case, mandating E2E was not proportionate. Source: MIR — VG Düsseldorf, 02.04.2026, 29 K 7351/23 (see also dejure.org — Art. 32 DSGVO).
Why this matters in Luxembourg: GDPR Article 32 applies directly, and regulated sectors (banks, PSF, insurance, funds) must technically implement and evidence secure exchanges — including cloud — under CSSF 22/806 and the DORA framework. The ruling clarifies when well‑governed “transport” suffices and when E2E is required.
Applicable legal framework
- GDPR — Article 32: requires “appropriate technical and organisational measures” considering state of the art, costs, nature/scope, and risks. Encryption is explicitly cited. Consolidated text: EUR‑Lex — GDPR, Art. 32.
- VG Düsseldorf (02/04/2026): in the email context, transport encryption can meet Article 32 if residual risk is controlled; E2E is not required “as a rule.” Source: MIR.
- Luxembourg (financial sector) — CSSF 22/806: for ICT outsourcing and cloud, mandates assessment/control of security level (encryption, key management, logging, evidence), aligned with DORA since 17/01/2025. Reference: CSSF — Circular 22/806 (am. 25/883) and PDF (FR). Guidance: CNIL — Encryption in public cloud.
Implication: the “technical obligation” is not monolithic. The court expects a proportionate demonstration: 1) information classification; 2) state‑of‑the‑art email transport controls; 3) E2E when risks/volumes/content warrant it (health data, M&A, sensitive investigations); 4) evidence of effectiveness (logs, test reports, periodic controls). Cyber leadership by an externalized CISO helps formalize these criteria and obtain DPO validation.
Reference technical architecture
1) “In‑transit” encryption (email)
- Enforce TLS between outbound/inbound MTAs: mandatory STARTTLS, modern ciphers (TLS 1.2/1.3), PFS, disable obsolete suites.
- MTA‑STS (policy “enforce”) + TLS‑RPT to monitor TLS negotiation failures at domain scale.
- DANE for SMTP (DNSSEC) where feasible, to authenticate destination servers.
- DMARC/SPF/DKIM for authenticity and phishing reduction.
- Logging: TLS session establishment, encrypted send rates, failures, correlated alerts (SIEM).
2) At‑rest encryption and key management
- Storage (mailboxes, archives, backups): server‑side AES‑256, key rotation, role separation, KMS/HSM.
- Cloud (CSSF 22/806): select a key custody model (provider‑managed, customer‑managed keys, customer‑supplied keys, or client‑side encryption) aligned to risk and regulatory needs. See CNIL guidance.
3) End‑to‑end encryption (by exception)
- S/MIME v3.2 or OpenPGP, client‑side or via an E2E gateway, for predefined information classes: health, trade secrets, sensitive legal, highly confidential HR.
- Data‑aware policies: trigger E2E via keywords/labels/auto‑classification (DLP) and business approvals.
4) Governance and evidence
- Classification policy + “transport vs E2E” decision matrix with objective criteria (severity/likelihood/volume/partners).
- Periodic testing (CIS Controls 14, ISO 27001 Annex A — A.8.24, A.8.25): TLS checks, MTA‑STS/TLS‑RPT reports, DANE scans, cipher reviews.
- Cloud compliance (CSSF 22/806): outsourcing records, encryption/key clauses, KMS/HSM evidence, key custody reviews, audit trails. See the DORA operational resilience framework.
Consolidating logs and reports in a SIEM with 24/7 alerting accelerates detection and evidencing; leveraging a managed SOC streamlines oversight (encrypted rate, TLS failures, expiring certs, DMARC incidents).
EU/Luxembourg concrete case
A CSSF‑regulated fiduciary outsources email to an EU cloud. In 6 weeks: 1) “Confidential/Highly Confidential” classification; 2) SMTP hardening (TLS 1.3, MTA‑STS enforce, TLS‑RPT, DANE), DMARC “reject”, SEG enabled; 3) at‑rest encryption + customer‑managed keys under HSM; 4) E2E (S/MIME) playbook for M&A and sensitive HR; 5) evidence dashboards (encrypted rate, TLS incidents, key audits). Outcome: demonstrable Article 32 compliance and a CSSF 22/806‑ready file (outsourcing records, encryption clauses, TLS‑RPT reports).
First practical steps
- Measure your outbound/inbound encrypted email rate and whether MTA‑STS, TLS‑RPT, DANE are in place.
- Publish/strengthen a classification policy and encryption matrix (when transport suffices, when E2E is required) — validate with business and the DPO.
- Enable DMARC with p=quarantine then p=reject, fix subdomains, align SPF/DKIM.
- Select your cloud key model (provider‑managed vs CMK vs CSE) and document it for CSSF 22/806: responsibilities, rotation, access, HSM/KMS logs.
- Wire evidence into your SIEM (TLS‑RPT, MTA logs, cipher audits, DMARC metrics) and schedule a quarterly health check.
Official sources
- Case law: MIR — VG Düsseldorf, 02/04/2026, 29 K 7351/23 (Transportverschlüsselung); reference: dejure.org — Article 32 case law.
- GDPR text: EUR‑Lex — Regulation (EU) 2016/679 (Art. 32).
- Luxembourg (financial sector): CSSF — Circular 22/806 (am. 25/883) and PDF (FR).
- Cloud encryption guide: CNIL — Best practices in public cloud encryption.
Need support? Get in touch to structure governance, evidence, and technical choices.
Luxembourg-based Luxgap: managed SOC, outsourced DPO and CISO, ISO 27001 Lead Implementer, cyber e-learning, Dark Web monitoring. Configure your personalised quote or contact us.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →