Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

63 articles found · Veille Luxgap

Secureholiday (Ctoutvert): 41,577 Dutch campers affected

Ctoutvert (Secureholiday) confirms a breach affecting 41,577 Dutch campers. No IBANs or cards leaked, but emails, phone numbers and stay dates exposed and used for targeted fraud.

Six weeks of downtime: German SME goes insolvent after cyberattack

On 14 July 2026, ZEGO (Aschaffenburg, DE) filed for insolvency after a March 29 cyberattack halted production for nearly six weeks—an explicit illustration of the operational cost of incidents for manufacturers.

Cookies: EDPB orders Belgian DPA to decide the merits in the VRT case

On 14 July 2026, the EDPB ordered the Belgian DPA to rule on the merits of NOYB’s complaint against VRT’s cookie banner, rejecting the abuse-of-rights argument. A signal for CNPD oversight and consent practices in Luxembourg.

AI Act: July 22 — last chance to sign the AI transparency Code

The EU will publish the initial list of signatories to the AI transparency Code before August 2, 2026. To be included, file by July 22, 2026, 18:00 CEST. Luxembourg leaders: here’s a 7‑day action plan.

KDDI: 12.23M emails and 7.62M passwords compromised

On July 7, 2026, KDDI confirmed unauthorized access to ~12.233M emails and ~7.616M passwords from its ISP email platform—an emblematic supply chain case with lessons for European companies.

CNPD 2025 report: 846 complaints (+40%), key takeaways for Luxembourg

CNPD 2025 annual report: 846 complaints (+40% in one year), 425 breach notifications (49% human error), 59 investigations, 16 opinions. The shift to risk-based regulation, AI as a priority, and 5 concrete actions for DPOs and CISOs in Luxembourg.

Nextcloud: 367,000 records exposed (invoices, emails, scripts)

Cybernews reports an exposed Nextcloud ElasticSearch database with ~367,000 records (~8 GB) of staff and clients: invoices, emails, and scripts. The exposure was closed on May 27, 2026.

EDPB: Guidelines on Anonymisation and AI Web Scraping

On 8 July 2026, the EDPB adopted draft guidelines on anonymisation and on web scraping in the context of generative AI for public consultation. Consultation open until 30 October 2026.

Medtronic notifies 3.8M+ people after data breach

Medtronic confirms an April 2026 intrusion exposed personal and health data. More than 3.8 million people have been notified since July 2, 2026.

ENISA issues Frontier AI recommendations for cybersecurity

On 7 July 2026, ENISA released an actionable report to help authorities, defenders and operators prepare for the Frontier AI era, aligned with NIS 2, the CRA and the AI Act.

AML/CFT information sharing: EDPB and AMLA to issue joint guidelines

The EDPB and AMLA announced joint guidelines on information‑sharing partnerships under AMLR Article 75, applicable from 10 July 2027. Goal: a GDPR‑compatible data‑sharing framework for AML/CFT.

Italy: €100,000 fine against Lepida over LepidaID shortcomings

Italy’s DPA fined Lepida S.c.p.A. €100,000 for GDPR violations in managing LepidaID (>1.5M users). Transparency, data minimization, and excessive log retention were flagged.

← Newer Page 2 / 6 Older →