Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
76 articles found · #rgpd · Expertise Luxgap
French Supreme Court (Mar 18, 2026) — Geolocation and working time
The French Supreme Court allows geolocation to measure working time if no other objective, reliable and accessible means exists and employees lack freedom to organize their time. Luxembourg focus: legal basis, necessity, DPIA.
CJEU C‑312/24 — Erasure vs legal obligation: a relative right
The CJEU clarifies that erasure (Art. 17 GDPR) yields when a clear, foreseeable and proportionate legal obligation justifies retention, including for criminal data in HR files. Once no longer necessary, erasure becomes mandatory again.
CJEU C‑199/24: the “journalism” derogation does not displace the GDPR
The CJEU holds that paywalled publication of criminal judgments is not, in principle, a journalistic purpose under Article 85 GDPR. Where the journalism derogation does not apply, GDPR rights and remedies remain available.
CNPD vs CNIL: 8 days or 1 month to retain workplace CCTV footage?
Facts: CNPD sets 8 days in principle (30 days exceptionally), while CNIL tolerates up to one month. Key point: align video retention with GDPR Art. 5(1)(e) and Luxembourg Labor Code L. 261‑1.
CJEU C‑414/24 (18 June 2026): parallel GDPR remedies are not exclusive
The CJEU confirms that GDPR complaints to the authority (Art. 77) and judicial actions (Art. 79) are parallel and not mutually exclusive. An authority may not dismiss a complaint solely because a court action is pending.
GDPR Article 32: a small Italian fine, big obligations
On 29/04/2026, the Italian Garante imposed an €8,600 fine for security failures (Arts. 5 and 32 GDPR), including non‑compliant password storage. In Luxembourg, proving proportionality and state of the art remains decisive.
Web scraping to train AI: ICO opens, EDPB tightens
The ICO considers legitimate interests a practicable basis for AI training via web scraping, subject to strict tests and transparency. The EDPB narrows this, stressing Article 14 notice and the constraints of Article 9.
Workplace video surveillance: Garante fine and lessons for Luxembourg
Italy’s Garante fined a shop €2,000 for video surveillance without notice or labor authorization. In Luxembourg, L.261‑1, two‑layer notice and short retention are mandatory.
Amazon vs CNPD (12/03/2026): fine annulled, fine methodology reset
On 12 March 2026, Luxembourg’s Administrative Court annulled Amazon’s €746m fine while upholding core findings. Key takeaway: apply CJEU (Deutsche Wohnen/Nacionalinis) and robustly justify the GDPR fine methodology.
Art. 28 GDPR: Garante fines Velletri over sub-processing chain
On 12 Feb 2026, the Italian Garante fined Velletri Servizi for non‑compliant sub‑processing contracts under Art. 28(4) GDPR and insufficient oversight. Key takeaway: document and audit the entire sub‑processing chain.
Data transfers outside the EU: EDPB vs ICO — essential equivalence or risk test?
On 15 Jan 2026, the ICO introduced a simplified three‑step test and TRA, diverging from the EDPB/CNPD’s ‘essential equivalence’ plus supplementary measures approach. Bottom line: distinct compliance tracks for EU vs UK transfers.
Workplace video surveillance: DPIA before any camera (Coccaglio)
Italy’s Garante fined the Comune di Coccaglio €6,000 for employee video surveillance without a credible DPIA and for disciplinary use of footage. In Luxembourg, a prior DPIA is almost always required when employees may be captured.