Regulation (EU) 2016/679 · CNPD

GDPR compliance in Luxembourg.

The GDPR places some twenty specific obligations on every Luxembourg organisation that processes personal data. The CNPD (Commission Nationale pour la Protection des Données, the national data protection authority) has been actively enforcing it since 2018, with more than €30 million in fines imposed in Luxembourg in recent years.

Who is subject to the GDPR in Luxembourg?

Every organisation, whatever its size, that processes personal data of European residents. No size exemption. If you have an Excel file with names in it, the GDPR applies.

In Luxembourg, the organisations systematically inspected are: banks, funds, fiduciaries, medical professions, e-commerce, carriers, outsourced HR, hotels, restaurants. The CNPD also acts on complaints from employees, customers, former spouses and journalists.

What are the main GDPR obligations?

Records of processing activities (Article 30): describe each processing operation with its purpose, legal basis and retention period. Designation of a DPO (Article 37) for regular, large-scale processing. Data protection impact assessments (DPIAs) (Article 35) for high-risk processing (video surveillance, biometrics, profiling). Breach notification to the CNPD within 72h (Article 33). Data subject rights to be honoured within one month (access, rectification, erasure, portability). Compliant processor contracts (DPA, Article 28). Safeguarded transfers outside the EU (standard contractual clauses, BCRs).

What sanctions can the Luxembourg CNPD impose?

Article 83 GDPR provides for administrative fines of up to €20 million or 4% of worldwide turnover (whichever is higher). In Luxembourg, the CNPD has already imposed more than €30M in fines: Amazon (€746M initially, contested), Sumup, banks, SMEs. No organisation is too small: associations of 5 people have been fined too.

On top of that come civil claims (Article 82) from the data subjects, and the personal liability of directors where a breach is established.

How does Luxgap bring you into GDPR compliance?

Our outsourced DPO mandate covers the 9 GDPR workstreams end to end: officially registered with the CNPD as your DPO, we carry the operational responsibility. Kick-off within 2 weeks, initial audit, prioritised action plan, set-up of the records of processing, DPIAs for high-risk processing, staff training, handling of data subject requests and of any breaches.

For organisations that already have a DPO, we offer à la carte support (one-off audit, training, specific DPIA, incident handling).

Let's talk about your situation.

Quote within 24 business hours. No commitment, no sales pressure.

Build my quote → Contact us