Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

120 articles found · #luxembourg

AI Act: Code of Practice signing — D‑41 before your AI labels

On 22 June 2026, the Commission unveiled the Code of Practice for labelling AI-generated content. Transparency duties (Art. 50) apply from 2 August 2026, with penalties for non-compliance.

Novo Nordisk rejects $25M after 1.3 TB data theft

On June 16, 2026, FulcrumSec claimed to have stolen over 1 TB from Novo Nordisk and demanded $25M. The company confirmed a June 11 incident, is investigating, and did not pay.

CNPD — Employee vehicle geolocation: 2 months by default, DPIA often required

CNPD clarifies: retention “2 months by default,” no tracking outside working hours if private use is allowed, and DPIA when there is regular/systematic monitoring. Measures to implement immediately.

Kodak hacked: ShinyHunters claims 2.2M records

Kodak confirms an intrusion as ShinyHunters claims 2.2M records. Here’s how RGPD-compliant DLP (Art. 32 and 44‑49) reduces exfiltration and builds evidence.

France Travail fined €5M: GDPR Article 32 moves from theory to audit

The CNIL fined France Travail €5M for breaches of GDPR Article 32: security measures identified in the DPIA but not implemented. A clear signal for Luxembourg organizations.

CJEU: age checks for foreign porn sites, under conditions

On 16 June 2026, the CJEU conditionally upheld requiring porn sites based in another EU state to implement age checks. A strong signal for regulators like ARCOM with immediate GDPR implications.

GDPR: complaint closure and no Article 78 appeal if not concerned

The French Council of State (20 May 2026) held that a CNIL complaint closure is not a “legally binding decision” triggering an Article 78 GDPR appeal if the complainant is not concretely affected.

AI Act: Code of Practice published — D-46 for your AI notices

On 10 June 2026, the Commission published a Code of Practice for marking/labelling AI-generated content. From 2 August 2026, transparency obligations (Art. 50) apply. Sign and implement this week.

Munich: Google held liable for false “AI Overviews”

On May 28, 2026, the Munich I Regional Court barred Google from publishing false claims via “AI Overviews,” deeming them Google’s “own statements,” with penalties of up to €250,000 per breach.

AI Act — Prohibited practices (Art. 5): the Commission’s 2025 clarifications

On 4 February 2025, the Commission issued guidelines on prohibited AI practices (Art. 5 AI Act). Eight uses are banned as of 02/02/2025, with fines up to €35m or 7% of global turnover.

ILR — NIS 2 Incident Notification: 24h to alert

On 5 May 2026, Luxembourg transposed NIS 2. ILR released guidance with a 24h early warning, 72h notification and a 1‑month final report. Here is how a managed SOC/SIEM helps meet these milestones calmly.

Berlin: €14.5m cut to €900k — deletion obligation confirmed

On 9 June 2026, the Berlin Regional Court confirmed a GDPR breach by Deutsche Wohnen for archiving without deletion and cut the fine from €14.5m to €900k. A strong signal on effective deletion obligations.

← Newer Page 6 / 10 Older →