Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
61 articles found · #cnpd
Belgian DPA fines SWDE €86,000 and rebukes missing Article 28 contract
Belgium’s DPA fines SWDE over call recording and monitoring: transparency, retention and a missing processor contract. A clear signal for Luxembourg: an incomplete Article 28 DPA is costly.
CNPD 16/12/2025: insufficient GDPR Article 30 record sanctioned
On 16/12/2025, the CNPD imposed a €7,000 fine for an incomplete Article 30 record. The decision clarifies required fields (recipients, transfers, categories, retention, security) and the EDPB fine calculation method.
CNPD — Vehicle geolocation: what the 2023–2025 guidance requires
The CNPD updated its vehicle geolocation guidance. Key points: structured legitimate interest, purpose limitation, off-duty deactivation, dual transparency and DPIA.
Analytics cookies: CNIL/CNPD exemptions, ICO still requires consent
On 29 April 2026, the ICO confirmed that non-essential analytics cookies require PECR consent. In France and Luxembourg, CNIL and CNPD allow narrow exemptions for certain audience measurement cookies.
External DPO: 7 lessons from 200+ mandates in Luxembourg and Europe
200+ external DPO mandates across all sectors: the 7 recurring findings we make on takeover, and how Luxgap puts things in order. Concrete pricing, sector examples, what really changes.
CJEU 19 March 2026 (Brillen Rottler): first access request may be refused for abuse
The CJEU allows a first access request (Art. 15 GDPR) to be refused as “excessive” if an abusive intent is proven (Art. 12(5)). Any refusal must remain exceptional, justified, and within deadlines.
Amazon vs CNPD (12 March 2026): Legitimate interest is not enough
Luxembourg’s Administrative Court annulled the €746M fine but confirmed that behavioral advertising cannot rely on legitimate interest. 2026 takeaways for legal bases and the requirement to prove fault.
DPIA (Art. 35 GDPR) in Luxembourg: when to trigger and how to succeed
When is a DPIA mandatory in Luxembourg and how to do it right? GDPR framework, CNPD list, EDPB method, prior consultation (Art. 36) and best practices.
CNPD — Workplace video surveillance: proportionality, DPIA and employee rights
Workplace cameras are allowed in Luxembourg, but under strict rules: legal basis, proportionality, frequent DPIA, L.261‑1 information duties and employee rights. Document everything, camera by camera.
GDPR – Article 28: the watertight processor contract
In 2026, every DPO/CISO must bulletproof processor contracts. Mandatory clauses, EDPB/CNPD guidance, and a practical audit playbook for a watertight Article 28.
GDPR Art. 33: Notify CNPD of a breach within 72h—without panic
Practical method, based on official texts and CNPD guidance, to decide, notify, and document a personal data breach within 72 hours.
EU‑US data transfers after Schrems II and the DPF: CNPD expectations 2026
Secure transatlantic flows without over‑compliance: the DPF eases transfers to certified US entities, but Article 46 and supplementary measures remain key outside the DPF. Prioritize vendor governance and DPIA documentation.