The classic trap
Recital 149 opens the door for Member States to add criminal penalties on top of CNPD administrative fines. The trap: assuming a CNPD fine closes the matter. In reality, in Luxembourg as in France, certain GDPR breaches (unfair collection, unlawful processing of sensitive data, obstruction of data subject rights) can trigger parallel criminal prosecution with seizure of profits. The ne bis in idem rule as interpreted by the CJEU (bpost and Nordzucker judgments, 2022) does not prohibit cumulation if the two proceedings pursue complementary aims and remain proportionate overall.
Criminal exposure zones to map
- Fraudulent or unfair collection of personal data (typically mass scraping, fake forms, purchase of illicit databases).
- Processing of sensitive data (health, political opinions, sexual orientation) without legal basis, expressly criminalized in national penal codes.
- Obstruction of the supervisory authority: refusal to cooperate with the CNPD, destruction of evidence, false statements during an inspection.
- Deliberate re-identification of pseudonymized or anonymized data.
- Seizable illicit profits: the recital expressly authorizes confiscation of the turnover generated by unlawful processing, which can far exceed the 20 M EUR or 4 percent of global turnover ceiling.
Criminal + administrative cumulation: validity conditions
The CJEU requires three cumulative conditions to validate the double track: distinct aims of the two proceedings, effective coordination between prosecutor and administrative authority, overall proportionality of the total sanction. In practice this means an effective defense must be built from the first CNPD inspection, since documents produced may be transmitted to the prosecutor.
How Luxgap automates this risk
Our Luxgap Criminal Exposure Mapper turns your processing inventory into a radar for hidden criminal risk, distinct from the usual administrative risk. The tool cross-references your Article 30 register, declared legal bases, data categories and Luxembourg and European criminal case law to identify processings where a CNPD + prosecutor double track is legally possible, well before any complaint reaches the State prosecutor.
- Automatically detects high criminal risk processings by cross-referencing data categories, declared purposes and offense definitions from the Luxembourg Criminal Code and relevant national codes.
- Calculates a ne bis in idem exposure score using the CJEU bpost and Nordzucker grid, measuring the proximity of aims between possible administrative and criminal proceedings.
- Simulates the amount of seizable profits based on your accounting data from Odoo, Sage BOB 50 or SAP, isolating the turnover attributable to the contested processing.
- Generates a defense memo ready to hand to your criminal counsel in case of CNPD inspection, documenting proportionality and coordination arguments.
- Alerts in real time via Teams or Slack as soon as a newly logged processing crosses a predefined criminal exposure threshold.
- Produces a time-stamped PDF report, admissible before the CNPD as well as before the investigating judge, demonstrating your proactive risk assessment.
Available as part of a Luxgap DPO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real processings, with a free 48-hour blank audit to measure your criminal exposure before any commitment.