Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
CNPD 2025 report: 846 complaints (+40%), key takeaways for Luxembourg
CNPD 2025 annual report: 846 complaints (+40% in one year), 425 breach notifications (49% human error), 59 investigations, 16 opinions. The shift to risk-based regulation, AI as a priority, and 5 concrete actions for DPOs and CISOs in Luxembourg.
CSSF 25/893: reporting a major incident in 4h with EDR/XDR
CSSF Circular 25/893 formalizes DORA reporting for major ICT incidents and significant cyber threats. A well‑tuned EDR/XDR stack speeds up detection, classification, and 4h/72h/1‑month notifications.
NIS 2 in Luxembourg: executive liability and mandatory training
Since 5 May 2026, Luxembourg’s NIS 2 law requires management bodies to approve and oversee cybersecurity measures and to undertake training. Sanctions can be severe and executives are explicitly targeted.
Nextcloud: 367,000 records exposed (invoices, emails, scripts)
Cybernews reports an exposed Nextcloud ElasticSearch database with ~367,000 records (~8 GB) of staff and clients: invoices, emails, and scripts. The exposure was closed on May 27, 2026.
AssuranceAmerica: 6.99M drivers exposed — DLP that evidences GDPR
AssuranceAmerica confirms data exfiltration affecting 6.99M people. How a cloud/SaaS‑centric DLP limits impact and provides the evidences expected under GDPR Article 32.
France Travail: €5M fine for inadequate security (GDPR Art. 32)
On 22 January 2026, the CNIL fined France Travail €5M for breaches of GDPR Article 32. Key takeaway: prove the proportionality and effectiveness of security measures, with clear documentation, including in Luxembourg.
ILR CP/N26/1: Evidence your NIS 2 measures with an ISO 27001 ISMS
ILR opens consultation on periodic notification of NIS 2 “security measures.” An ISO 27001 ISMS provides evidence, traceability, and the required format to notify with confidence.
EU–US DPF: CNPD/EDPB cautious, ICO ‘data bridge’ more flexible
The DPF offers a secure lane to certified US recipients in the EU, while the UK ‘data bridge’ further streamlines UK-to-US flows. Outside the DPF, SCC/BCR + TIA remain required per CNPD/EDPB guidance.
EDPB: Guidelines on Anonymisation and AI Web Scraping
On 8 July 2026, the EDPB adopted draft guidelines on anonymisation and on web scraping in the context of generative AI for public consultation. Consultation open until 30 October 2026.
ShinyHunters: SSO vishing targeting Salesforce/Okta — FIDO2 as countermeasure
Mandiant details a “ShinyHunters” vishing campaign stealing SSO accounts to loot Salesforce and other SaaS. Phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces notification risk.
€31.8m fine against Intesa Sanpaolo: 72h to notify a GDPR breach
Italy’s DPA fined Intesa Sanpaolo €31.8m for inadequate security and late/incomplete GDPR breach notification. Immediate takeaway for Luxembourg: meet the 72-hour rule and know what to notify.
Medtronic notifies 3.8M+ people after data breach
Medtronic confirms an April 2026 intrusion exposed personal and health data. More than 3.8 million people have been notified since July 2, 2026.