Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

120 articles found · #luxembourg

Garante vs Lusha: €2M fine for data brokering without legal basis

Italy’s Garante fined Lusha €2,000,000 for collecting/selling professional contacts without a legal basis and adequate information. A strong signal for the use of data enrichment tools in the EU.

UL: €98,000 for late notification — what Article 33 really requires

Ireland’s DPC fined the University of Limerick for three late GDPR notifications. Here is how to meet Article 33 and notify the CNPD within 72 hours, with documented timing and solid content.

Secureholiday (Ctoutvert): 41,577 Dutch campers affected

Ctoutvert (Secureholiday) confirms a breach affecting 41,577 Dutch campers. No IBANs or cards leaked, but emails, phone numbers and stay dates exposed and used for targeted fraud.

Six weeks of downtime: German SME goes insolvent after cyberattack

On 14 July 2026, ZEGO (Aschaffenburg, DE) filed for insolvency after a March 29 cyberattack halted production for nearly six weeks—an explicit illustration of the operational cost of incidents for manufacturers.

Cookies: EDPB orders Belgian DPA to decide the merits in the VRT case

On 14 July 2026, the EDPB ordered the Belgian DPA to rule on the merits of NOYB’s complaint against VRT’s cookie banner, rejecting the abuse-of-rights argument. A signal for CNPD oversight and consent practices in Luxembourg.

NIS 2 and supply chain: the EU Toolbox is a game changer

Adopted on 13/02/2026, the EU ICT Supply Chain Security Toolbox is now the operational benchmark for NIS 2 Article 21(2)(d). In Luxembourg, the ILR will verify its implementation by entities.

AI Act: July 22 — last chance to sign the AI transparency Code

The EU will publish the initial list of signatories to the AI transparency Code before August 2, 2026. To be included, file by July 22, 2026, 18:00 CEST. Luxembourg leaders: here’s a 7‑day action plan.

ILR — CP/N26/2 consultation and NIS 2 24-hour notification

ILR opens consultation on national NIS 2 incident notification (CP/N26/2). Here are the rules, the 24/72/30 timeline, and the SIEM/SOC stack to report within 24 hours reliably.

IQVIA: €5m fine and health data — Article 9 GDPR under strain

CNIL fines IQVIA France €5m for failings in health data warehouses. Key takeaway for Luxembourg: “pseudonymised” data remains health data (Art. 9 GDPR) and requires a strict legal basis and effective safeguards.

KDDI: 12.23M emails and 7.62M passwords compromised

On July 7, 2026, KDDI confirmed unauthorized access to ~12.233M emails and ~7.616M passwords from its ISP email platform—an emblematic supply chain case with lessons for European companies.

CNPD 2025 report: 846 complaints (+40%), key takeaways for Luxembourg

CNPD 2025 annual report: 846 complaints (+40% in one year), 425 breach notifications (49% human error), 59 investigations, 16 opinions. The shift to risk-based regulation, AI as a priority, and 5 concrete actions for DPOs and CISOs in Luxembourg.

NIS 2 in Luxembourg: executive liability and mandatory training

Since 5 May 2026, Luxembourg’s NIS 2 law requires management bodies to approve and oversee cybersecurity measures and to undertake training. Sanctions can be severe and executives are explicitly targeted.

← Newer Page 3 / 10 Older →