Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
120 articles found · #luxembourg
AI Act: 3 days to respond — EU consultation on transparency
The European Commission closes its consultation on transparency guidelines (Article 50 AI Act) on 3 June 2026. Last call to finalize your “AI” notices and labelling of synthetic content.
Luxgap SealedMail: the first email server where your CIO cannot read you
Launch of SealedMail, zero-knowledge email server hosted in Luxembourg, designed for executives. End-to-end encryption with X25519 asymmetric keys. Neither IT admin nor Luxgap can read your mailboxes. Works with your usual Outlook.
Ireland — Permanent TSB fined: GDPR arts. 32/33 tested at call centers
The Irish DPC fined Permanent TSB €277,500 for call center authentication failures and late notification. Lesson for Luxembourg: Article 32 and the 72h rule (Art. 33) also apply to human processes.
CNIL updates MR‑001/MR‑003: an operational playbook (26/05)
The CNIL updates MR‑001 and MR‑003 and releases compliance checklists. Immediate effect for health research conducted in France, impacting Luxembourg sponsors when French patients or sites are involved.
Instructure/Canvas: 275M users at risk — 24/7 SOC to meet NIS2 Art. 23
ShinyHunters breached Instructure/Canvas, threatening up to 275M records. How a managed SOC/SIEM enables 24h qualification and ILR notification under NIS2 Art. 23.
Health data: €5M fine against IQVIA — what GDPR Article 9 really requires
On May 26, 2026, the CNIL fined IQVIA €5M over shortcomings in its health data warehouses. The case illustrates GDPR Article 9’s general prohibition and the strict conditions of its exceptions.
ENISA 2026: Exercise Methodology to Operationalize DORA Article 24
ENISA releases a cybersecurity exercise methodology with ready-to-use kits. In practice: DORA Article 24–aligned tabletop tests to speed decision-making and reduce ransomware impact.
FlowerStorm (KrakVM) evades email filters and the NIS 2 stakes
The FlowerStorm phishing kit runs obfuscated JavaScript in KrakVM to intercept MFA. Here is how an email gateway, DMARC/SPF/DKIM, and a 24/7 SOC help meet NIS 2 in Luxembourg.
CSSF — Circular 25/893: tightened ICT alerting and reporting under DORA
The CSSF tightens ICT incident classification and notification under DORA via eDesk. Here is how an EDR/XDR stack enables timely detection, qualification, and reporting with harmonized deadlines.
France Travail fined: key lessons from GDPR Article 32
On 22 January 2026, the CNIL fined France Travail €5M for weaknesses in authentication, logging and access rights. In Luxembourg, GDPR Article 32 requires appropriate, demonstrably effective security measures.
CNPD — Vehicle geolocation: what the 2023–2025 guidance requires
The CNPD updated its vehicle geolocation guidance. Key points: structured legitimate interest, purpose limitation, off-duty deactivation, dual transparency and DPIA.
Luxgap and LuxApps at Nexus Luxembourg 2026: compliant and secure AI business applications
On 10-11 June 2026 at Luxexpo The Box, Luxgap and LuxApps are at Nexus Luxembourg. Joint booth with demos of DPO Assist, KYC AML, Third Party Register, LuxApps HRIS. Conference talk on developing AI-boosted business applications, compliant and secure.