Recital 173
General Data Protection Regulation · UE 2016/679
| (173) | This Regulation should apply to all matters concerning the protection of fundamental rights and freedoms vis-à-vis the processing of personal data which are not subject to specific obligations with the same objective set out in Directive 2002/58/EC of the European Parliament and of the Council (18), including the obligations on the controller and the rights of natural persons. In order to clarify the relationship between this Regulation and Directive 2002/58/EC, that Directive should be amended accordingly. Once this Regulation is adopted, Directive 2002/58/EC should be reviewed in particular in order to ensure consistency with this Regulation, |
In Luxembourg, ePrivacy is transposed by the amended law of 30 May 2005 on the protection of privacy in the electronic communications sector. The CNPD is competent for cookies and B2C electronic marketing, applying GDPR and the 2005 law jointly. The ILR retains competence on certain telecom aspects (operator traffic data).
Luxgap practice: for CSSF-regulated financial actors, we coordinate the ePrivacy audit with CSSF Circular 22/806 on IT outsourcing, since CMPs are often hosted outside the EU and constitute an Article 44 GDPR transfer to be documented.