Recital 49

Recital 49

General Data Protection Regulation · UE 2016/679

(49)

The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems, by public authorities, by computer emergency response teams (CERTs), computer security incident response teams (CSIRTs), by providers of electronic communications networks and services and by providers of security technologies and services, constitutes a legitimate interest of the data controller concerned. This could, for example, include preventing unauthorised access to electronic communications networks and malicious code distribution and stopping ‘denial of service’ attacks and damage to computer and electronic communication systems.

Luxembourg specificity
loi luxembourgeoise du 1er aout 2018 portant organisation de la CNPD et loi du 28 juillet 2023 transposant NIS 2

In Luxembourg, the law of 1 August 2018 organising the CNPD does not derogate from recital 49, but the CNPD expects, in its sector audits (CSSF-supervised banks, ILR-supervised telcos), a formalised LIA whenever a SOC or MSSP processes nominative logs of Luxembourg employees. The law of 28 July 2023 transposing NIS 2 adds an obligation to notify incidents to the ILR within 24h for essential and important entities, which combines with Article 33 GDPR (CNPD within 72h).

Luxgap practice: we automatically link your LIA to the dual ILR/CNPD notification plan to avoid double piloting during an incident, and we check consistency with Article L.261-1 of the Luxembourg Labour Code on employee monitoring.