Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

56 articles found · #actualite · Veille Luxgap

15 August 2026: the Dutch Cybersecurity Act (NIS 2 NL) has entered into force

As of 15 August 2026, the Dutch NIS 2 law (Cyberbeveiligingswet) applies. For groups in Luxembourg with activities or providers in the Netherlands, obligations now apply on both sides of the border.

August 11, 2026: cold calling banned without consent

Since August 11, 2026, B2C cold calling in France is banned without prior explicit consent. Fines can reach €375,000 per breach for legal entities.

DGFiP: 600,000 tax records for sale — warning on stealth exfiltration

On 14 August 2026, France’s Finance Ministry confirmed a DGFiP breach with over 600,000 tax records exported. A stealth exfiltration via a spoofed VPN, fueling targeted fraud risks.

CEVA Logistics: data leak at supplier — Bol and De Bijenkorf customers warned

On August 6, 2026, Bol and De Bijenkorf warned customers that a possible data leak at CEVA Logistics may have exposed names, addresses and phone numbers. The Dutch DPA was notified on August 3; no payments or passwords are implicated so far.

AI Act: labelling of AI‑generated content — deadline on 2 December

AI providers get a short extension: for systems already on the market by 2 August 2026, labelling of generated content (Art. 50(2) AI Act) is due by 2 December 2026 at the latest. Deployers’ obligations remain unchanged.

AI Act: mandatory transparency from August 2 — act now

The AI Act’s transparency rules (Art. 50) have applied since August 2, 2026. Chatbots, deepfakes and AI-generated content must now be disclosed — including by deployers in Luxembourg.

PNLD: 135,000 police and partner contacts published on the dark web

The UK’s Police National Legal Database (PNLD) confirmed 1.9 GB of data was posted online: 114,000 PNLD subscribers and 21,000 “Ask the Police” users. The attack, claimed by ExfilSquad, was detected on July 26, 2026.

Liechtenstein: UBO register hacked (31,000 individuals affected)

Liechtenstein confirms data exfiltration from its UBO register (VwbP), affecting around 31,000 individuals. A stark reminder: these registers hold highly sensitive data that must be protected as critical assets.

Coca‑Cola/Fairlife: ransomware, production halt and data theft

Coca‑Cola confirms data theft following a ransomware attack against Fairlife. U.S. production was suspended mid‑July; the Anubis group claims up to 1 TB of data.

Garante vs Lusha: €2M fine for data brokering without legal basis

Italy’s Garante fined Lusha €2,000,000 for collecting/selling professional contacts without a legal basis and adequate information. A strong signal for the use of data enrichment tools in the EU.

CNIL: New Guidelines on Tracking Pixels in Emails

The CNIL releases guidelines and FAQs to regulate tracking pixels in emails, affecting companies using tracking tools. A key priority for DPOs and CISOs across Europe.

Wind Tre: €1.715M for unprotected APIs and poor key management

Italy’s DPA fined Wind Tre €1,715,600 for security gaps: weak certificate/key management and APIs lacking basic controls, leading to data exfiltration affecting 365,048 customers (41,359 with payment data).

Page 1 / 5 Older →