GDPR, the EU data protection régulation.
Régulation (EU) 2016/679 imposes around twenty précisé obligations on every organisation that processes personal data of EU residents. In Luxembourg, the CNPD (National Data Protection Commission) is the supervisory authority. Here is what really applies, without the jargon.
Law contents
All 99 articles, in the order of the official text. Each one is analysed separately, with the official text and Luxgap practical guidance.
- 5. Principles relating to processing of personal data
- 6. Lawfulness of processing
- 7. Conditions for consent
- 8. Conditions applicable to child's consent in relation to information society services
- 9. Processing of special categories of personal data
- 10. Processing of personal data relating to criminal convictions and offences
- 11. Processing which does not require identification
- 12. Transparent information, communication and modalities for the exercise of the rights of the data subject
- 13. Information to be provided where personal data are collected from the data subject
- 14. Information to be provided where personal data have not been obtained from the data subject
- 15. Right of access by the data subject
- 16. Right to rectification
- 17. Right to erasure (‘right to be forgotten’)
- 18. Right to restriction of processing
- 19. Notification obligation regarding rectification or erasure of personal data or restriction of processing
- 20. Right to data portability
- 21. Right to object
- 22. Automated individual decision-making, including profiling
- 23. Restrictions
- 24. Responsibility of the controller
- 25. Data protection by design and by default
- 26. Joint controllers
- 27. Representatives of controllers or processors not established in the Union
- 28. Processor
- 29. Processing under the authority of the controller or processor
- 30. Records of processing activities
- 31. Cooperation with the supervisory authority
- 32. Security of processing
- 33. Notification of a personal data breach to the supervisory authority
- 34. Communication of a personal data breach to the data subject
- 35. Data protection impact assessment
- 36. Prior consultation
- 37. Designation of the data protection officer
- 38. Position of the data protection officer
- 39. Tasks of the data protection officer
- 40. Codes of conduct
- 41. Monitoring of approved codes of conduct
- 42. Certification
- 43. Certification bodies
- 44. General principle for transfers
- 45. Transfers on the basis of an adequacy decision
- 46. Transfers subject to appropriate safeguards
- 47. Binding corporate rules
- 48. Transfers or disclosures not authorised by Union law
- 49. Derogations for specific situations
- 50. International cooperation for the protection of personal data
- 51. Supervisory authority
- 52. Independence
- 53. General conditions for the members of the supervisory authority
- 54. Rules on the establishment of the supervisory authority
- 55. Competence
- 56. Competence of the lead supervisory authority
- 57. Tasks
- 58. Powers
- 59. Activity reports
- 60. Cooperation between the lead supervisory authority and the other supervisory authorities concerned
- 61. Mutual assistance
- 62. Joint operations of supervisory authorities
- 63. Consistency mechanism
- 64. Opinion of the Board
- 65. Dispute resolution by the Board
- 66. Urgency procedure
- 67. Exchange of information
- 68. European Data Protection Board
- 69. Independence
- 70. Tasks of the Board
- 71. Reports
- 72. Procedure
- 73. Chair
- 74. Tasks of the Chair
- 75. Secretariat
- 76. Confidentiality
- 77. Right to lodge a complaint with a supervisory authority
- 78. Right to an effective judicial remedy against a supervisory authority
- 79. Right to an effective judicial remedy against a controller or processor
- 80. Representation of data subjects
- 81. Suspension of proceedings
- 82. Right to compensation and liability
- 83. General conditions for imposing administrative fines
- 84. Penalties
- 85. Processing and freedom of expression and information
- 86. Processing and public access to official documents
- 87. Processing of the national identification number
- 88. Processing in the context of employment
- 89. Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historica
- 90. Obligations of secrecy
- 91. Existing data protection rules of churches and religious associations
Who is concerned?
Any organisation, of any size, that processes personal data of EU residents. No size threshold exemption.
Examples: private companies (HR, customers, suppliers), associations, municipalities, hospitals, liberal professions, schools, banks, trust companies, investment funds, websites collecting emails. If you have a spreadsheet with names, GDPR applies to you.
Key obligations
- Maintain a record of processing activities (Article 30): describe every personal data processing opération (payroll, applications, marketing, CCTV, etc.) with purpose, légal basis, rétention period, recipients.
- Appoint a DPO (Article 37) if your core activity involves large-scale regular and systematic monitoring, or large-scale processing of sensitive data. In Luxembourg, recommended above 50 employées.
- Run impact assessments (DPIAs, Article 35) for new high-risk processing (CCTV, biometrics, HR profiling, decision-making AI).
- Notify data breaches within 72 hours to the CNPD and, in case of high risk, to data subjects (Articles 33-34).
- Reply to data subject requests within one month (access, rectification, erasure, objection, portability).
- Frame processors with a GDPR Article 28 contract (DPA).
- Frame transfers outside the EU/EEA (Standard Contractual Clauses, BCRs, etc.).
Deadlines
GDPR has been in force since 25 May 2018. The Luxembourg CNPD has been actively enforcing since then, with a notable intensification since 2022.
Sanctions for non-compliance
Administrative sanctions under GDPR Article 83 reach up to 20 million euros or 4% of worldwide annual turnover (whichever is higher). The Luxembourg CNPD has issued more than 30 million euros in fines in récent years, including to SMBs and associations.
How Luxgap helps
Our external DPO mandate covers all GDPR obligations listed above. You officially appoint us DPO with the CNPD; we take operational ownership. Our 9-axis method (training, register, DPIA, data security, etc.) is proven across dozens of active mandates in Luxembourg.
Let's set up your GDPR compliance.
Configure a quote for a DPO mandate or a one-off support. Reply within one business day.
Build my quote →