Recital 88
General Data Protection Regulation · UE 2016/679
| (88) | In setting detailed rules concerning the format and procedures applicable to the notification of personal data breaches, due consideration should be given to the circumstances of that breach, including whether or not personal data had been protected by appropriate technical protection measures, effectively limiting the likelihood of identity fraud or other forms of misuse. Moreover, such rules and procedures should take into account the legitimate interests of law-enforcement authorities where early disclosure could unnecessarily hamper the investigation of the circumstances of a personal data breach. |
In Luxembourg, notification is filed via the dedicated online form of the CNPD (never APDL, which does not exist) and coordination with the criminal investigation runs through the Police Grand-Ducale and the Prosecutor, with possible support from CIRCL (Computer Incident Response Center Luxembourg) operated by Securitymadein.lu. The Law of 1 August 2018 organising the CNPD details the authority's investigative and supervisory powers, without altering the 72-hour deadline of Article 33 GDPR.
Luxgap practice: designating CIRCL as the technical point of contact in your incident response plan accelerates breach qualification and preserves coordination with the Police Grand-Ducale, without eating into the 72-hour CNPD window.