Recital 122
General Data Protection Regulation · UE 2016/679
| (122) | Each supervisory authority should be competent on the territory of its own Member State to exercise the powers and to perform the tasks conferred on it in accordance with this Regulation. This should cover in particular the processing in the context of the activities of an establishment of the controller or processor on the territory of its own Member State, the processing of personal data carried out by public authorities or private bodies acting in the public interest, processing affecting data subjects on its territory or processing carried out by a controller or processor not established in the Union when targeting data subjects residing on its territory. This should include handling complaints lodged by a data subject, conducting investigations on the application of this Regulation and promoting public awareness of the risks, rules, safeguards and rights in relation to the processing of personal data. |
In Luxembourg, the CNPD (Commission nationale pour la protection des donnees) is the sole competent supervisory authority within the meaning of Recital 122. The law of 1 August 2018 organising the CNPD details its investigative, sanctioning and cross-border cooperation powers. Local specificity: the CNPD retains exclusive competence over Luxembourg public authorities (ministries, municipalities, public bodies), even when they use cloud providers established elsewhere in the EU, since these operations fall outside the one-stop-shop (Article 55.2).
Luxgap practice: if you are a Luxembourg administration, municipality or parastatal body, you are systematically supervised by the CNPD with no possibility to invoke a foreign lead authority. Document every processing operation with a file directly opposable to the CNPD.