Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

Secureholiday (Ctoutvert): 41,577 Dutch campers affected

Ctoutvert (Secureholiday) confirms a breach affecting 41,577 Dutch campers. No IBANs or cards leaked, but emails, phone numbers and stay dates exposed and used for targeted fraud.

CNIL fines Free/Free Mobile €42M and why to move to FIDO2 MFA

CNIL fined Free and Free Mobile €42M for insufficient security, including weak VPN authentication. Deploying FIDO2/WebAuthn MFA concretely meets GDPR Article 32 and reduces risk.

Profiling and automated decisions: CJEU vs UK — two opposing lines

The UK replaces Article 22 UK GDPR with 22A–22D (a “permitted subject to safeguards” model), while the CJEU (SCHUFA) confirms in the EU a default ban on fully automated decisions with legal or similarly significant effects.

Six weeks of downtime: German SME goes insolvent after cyberattack

On 14 July 2026, ZEGO (Aschaffenburg, DE) filed for insolvency after a March 29 cyberattack halted production for nearly six weeks—an explicit illustration of the operational cost of incidents for manufacturers.

Right of access to call recordings: the Vodafone (GR) case, 2026

On 11 February 2026, the Hellenic DPA fined Vodafone-Panafon for obstructing access rights and breaching GDPR Articles 12, 15 and 18. Key takeaway: deliver a usable copy of recordings within one month.

Cookies: EDPB orders Belgian DPA to decide the merits in the VRT case

On 14 July 2026, the EDPB ordered the Belgian DPA to rule on the merits of NOYB’s complaint against VRT’s cookie banner, rejecting the abuse-of-rights argument. A signal for CNPD oversight and consent practices in Luxembourg.

CSSF 26/914: AMLA supervision — the ICT inventory becomes vital

CSSF 26/914 identifies entities eligible for AMLA’s direct supervision. Governance and traceability tighten: a reliable, continuous inventory/CMDB is now essential to evidence NIS 2/ISO 27001 controls.

NIS 2 and supply chain: the EU Toolbox is a game changer

Adopted on 13/02/2026, the EU ICT Supply Chain Security Toolbox is now the operational benchmark for NIS 2 Article 21(2)(d). In Luxembourg, the ILR will verify its implementation by entities.

AI Act: July 22 — last chance to sign the AI transparency Code

The EU will publish the initial list of signatories to the AI transparency Code before August 2, 2026. To be included, file by July 22, 2026, 18:00 CEST. Luxembourg leaders: here’s a 7‑day action plan.

ILR — CP/N26/2 consultation and NIS 2 24-hour notification

ILR opens consultation on national NIS 2 incident notification (CP/N26/2). Here are the rules, the 24/72/30 timeline, and the SIEM/SOC stack to report within 24 hours reliably.

IQVIA: €5m fine and health data — Article 9 GDPR under strain

CNIL fines IQVIA France €5m for failings in health data warehouses. Key takeaway for Luxembourg: “pseudonymised” data remains health data (Art. 9 GDPR) and requires a strict legal basis and effective safeguards.

KDDI: 12.23M emails and 7.62M passwords compromised

On July 7, 2026, KDDI confirmed unauthorized access to ~12.233M emails and ~7.616M passwords from its ISP email platform—an emblematic supply chain case with lessons for European companies.

← Newer Page 6 / 22 Older →