Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

58 articles found · #cnpd · Expertise Luxgap

French Supreme Court (Mar 18, 2026) — Geolocation and working time

The French Supreme Court allows geolocation to measure working time if no other objective, reliable and accessible means exists and employees lack freedom to organize their time. Luxembourg focus: legal basis, necessity, DPIA.

CJEU C‑199/24: the “journalism” derogation does not displace the GDPR

The CJEU holds that paywalled publication of criminal judgments is not, in principle, a journalistic purpose under Article 85 GDPR. Where the journalism derogation does not apply, GDPR rights and remedies remain available.

CNPD vs CNIL: 8 days or 1 month to retain workplace CCTV footage?

Facts: CNPD sets 8 days in principle (30 days exceptionally), while CNIL tolerates up to one month. Key point: align video retention with GDPR Art. 5(1)(e) and Luxembourg Labor Code L. 261‑1.

CJEU C‑414/24 (18 June 2026): parallel GDPR remedies are not exclusive

The CJEU confirms that GDPR complaints to the authority (Art. 77) and judicial actions (Art. 79) are parallel and not mutually exclusive. An authority may not dismiss a complaint solely because a court action is pending.

GDPR Article 32: a small Italian fine, big obligations

On 29/04/2026, the Italian Garante imposed an €8,600 fine for security failures (Arts. 5 and 32 GDPR), including non‑compliant password storage. In Luxembourg, proving proportionality and state of the art remains decisive.

Workplace video surveillance: Garante fine and lessons for Luxembourg

Italy’s Garante fined a shop €2,000 for video surveillance without notice or labor authorization. In Luxembourg, L.261‑1, two‑layer notice and short retention are mandatory.

Amazon vs CNPD (12/03/2026): fine annulled, fine methodology reset

On 12 March 2026, Luxembourg’s Administrative Court annulled Amazon’s €746m fine while upholding core findings. Key takeaway: apply CJEU (Deutsche Wohnen/Nacionalinis) and robustly justify the GDPR fine methodology.

Art. 28 GDPR: Garante fines Velletri over sub-processing chain

On 12 Feb 2026, the Italian Garante fined Velletri Servizi for non‑compliant sub‑processing contracts under Art. 28(4) GDPR and insufficient oversight. Key takeaway: document and audit the entire sub‑processing chain.

Data transfers outside the EU: EDPB vs ICO — essential equivalence or risk test?

On 15 Jan 2026, the ICO introduced a simplified three‑step test and TRA, diverging from the EDPB/CNPD’s ‘essential equivalence’ plus supplementary measures approach. Bottom line: distinct compliance tracks for EU vs UK transfers.

GDPR Record: CNPD fines for insufficient ROPA, ICO promotes flexibility

On 16 December 2025, the CNPD fined an organisation for an “insufficient” record of processing (Art. 30 GDPR). By contrast, the ICO updated a more flexible approach in June 2026. This gap affects EU–UK groups.

Vehicle geolocation in Luxembourg: CNPD requirements 2024

On 10 April 2024, the CNPD updated its guidelines: no continuous tracking or outside working hours, DPIA often required, retention generally 2 months, and obligations under Labour Code L. 261‑1.

CNPD: recording private meetings — legitimate interest only under conditions

CNPD finds consent rarely valid in meetings and allows legitimate interest only after a strict necessity and balancing test. Recordings must be deleted as soon as minutes are approved.

Page 1 / 5 Older →