Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

170 articles found · #rgpd

IQVIA: €5m fine and health data — Article 9 GDPR under strain

CNIL fines IQVIA France €5m for failings in health data warehouses. Key takeaway for Luxembourg: “pseudonymised” data remains health data (Art. 9 GDPR) and requires a strict legal basis and effective safeguards.

KDDI: 12.23M emails and 7.62M passwords compromised

On July 7, 2026, KDDI confirmed unauthorized access to ~12.233M emails and ~7.616M passwords from its ISP email platform—an emblematic supply chain case with lessons for European companies.

CNPD 2025 report: 846 complaints (+40%), key takeaways for Luxembourg

CNPD 2025 annual report: 846 complaints (+40% in one year), 425 breach notifications (49% human error), 59 investigations, 16 opinions. The shift to risk-based regulation, AI as a priority, and 5 concrete actions for DPOs and CISOs in Luxembourg.

Nextcloud: 367,000 records exposed (invoices, emails, scripts)

Cybernews reports an exposed Nextcloud ElasticSearch database with ~367,000 records (~8 GB) of staff and clients: invoices, emails, and scripts. The exposure was closed on May 27, 2026.

AssuranceAmerica: 6.99M drivers exposed — DLP that evidences GDPR

AssuranceAmerica confirms data exfiltration affecting 6.99M people. How a cloud/SaaS‑centric DLP limits impact and provides the evidences expected under GDPR Article 32.

France Travail: €5M fine for inadequate security (GDPR Art. 32)

On 22 January 2026, the CNIL fined France Travail €5M for breaches of GDPR Article 32. Key takeaway: prove the proportionality and effectiveness of security measures, with clear documentation, including in Luxembourg.

EU–US DPF: CNPD/EDPB cautious, ICO ‘data bridge’ more flexible

The DPF offers a secure lane to certified US recipients in the EU, while the UK ‘data bridge’ further streamlines UK-to-US flows. Outside the DPF, SCC/BCR + TIA remain required per CNPD/EDPB guidance.

EDPB: Guidelines on Anonymisation and AI Web Scraping

On 8 July 2026, the EDPB adopted draft guidelines on anonymisation and on web scraping in the context of generative AI for public consultation. Consultation open until 30 October 2026.

ShinyHunters: SSO vishing targeting Salesforce/Okta — FIDO2 as countermeasure

Mandiant details a “ShinyHunters” vishing campaign stealing SSO accounts to loot Salesforce and other SaaS. Phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces notification risk.

€31.8m fine against Intesa Sanpaolo: 72h to notify a GDPR breach

Italy’s DPA fined Intesa Sanpaolo €31.8m for inadequate security and late/incomplete GDPR breach notification. Immediate takeaway for Luxembourg: meet the 72-hour rule and know what to notify.

Medtronic notifies 3.8M+ people after data breach

Medtronic confirms an April 2026 intrusion exposed personal and health data. More than 3.8 million people have been notified since July 2, 2026.

ManoMano: 38M customers hit via contractor — DLP as GDPR proof

ManoMano confirmed a breach affecting ~38M people via a support contractor. Here’s how modern DLP demonstrates GDPR Article 32 and secures extra-EU transfers (Arts. 44–49).

← Newer Page 5 / 15 Older →