Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

120 articles found · #luxembourg

External DPO France: why choose a Luxembourg firm recognised across Europe

French company looking for an external DPO? Discover the advantage of a Luxembourg European-scale firm: multi-regulator knowledge (CNIL, CNPD, APD, BfDI, AEPD, Garante), pluridisciplinary team, lower cost than Parisian firms.

Foxconn hit by Nitrogen: 8 TB stolen, plants slowed — SOC/NIS 2 in 24h

Ransomware group “Nitrogen” claims 8 TB and 11M+ files stolen at Foxconn, disrupting North American plants. In Europe, a managed SOC/SIEM is key to detect fast and notify the ILR within 24h (NIS 2, Art. 23).

CNIL 2025 report: EUR 487M in fines, 1 breach in 2 = hacking, key takeaways

CNIL 2025 annual report: 20,150 complaints (record), EUR 487M in fines (including Google EUR 325M and Shein EUR 150M), 1 breach in 2 results from hacking. The real signal for 2026 and 4 concrete actions for DPO and CISO.

External DPO: 7 lessons from 200+ mandates in Luxembourg and Europe

200+ external DPO mandates across all sectors: the 7 recurring findings we make on takeover, and how Luxgap puts things in order. Concrete pricing, sector examples, what really changes.

CNIL vs Free: €42M — why a 24/7 SOC is vital to meet NIS 2 Art. 23

After the €42M fine against Free/Free Mobile, slow detection proves costly. Under NIS 2 Art. 23, detecting and notifying within 24 hours is now an operational obligation in Luxembourg.

DORA — TLPT framed by Delegated Regulation (EU) 2025/1190

The Commission clarified TLPT under DORA via Delegated Regulation (EU) 2025/1190. In Luxembourg, the CSSF is the TLPT authority: timeline, scope, and method are now clear.

NIS 2 audit: method, pitfalls and quality criteria for measures

7-phase NIS 2 audit method, the 5 most common pitfalls, and the 6-criteria grid to distinguish a real SOC from a marketing product. For the 1,200+ Luxembourg entities concerned.

Google Groups abused: Lumma Stealer/Ninja Browser campaign

CTM360 warns of a campaign abusing Google Groups to deliver Lumma (Windows) and “Ninja Browser” (Linux). NIS 2-aligned controls, DMARC/SPF/DKIM, and an email security gateway are advised.

NIS 2 Luxembourg: 5 May 2026 law published, ILR self-registration window until 10 July 2026

Luxembourg's 5 May 2026 law transposing the NIS 2 directive entered into force on 10 May. Essential and Important Entities must self-register with the ILR by 10 July 2026.

DPIA (Art. 35 GDPR) in Luxembourg: when to trigger and how to succeed

When is a DPIA mandatory in Luxembourg and how to do it right? GDPR framework, CNPD list, EDPB method, prior consultation (Art. 36) and best practices.

Automated patching: the answer to NIS 2, Article 21

Executives must prove vulnerabilities are remediated in a timely manner. Well-configured automated patching is the safest, most auditable way to meet NIS 2 Art. 21.

CNPD — Workplace video surveillance: proportionality, DPIA and employee rights

Workplace cameras are allowed in Luxembourg, but under strict rules: legal basis, proportionality, frequent DPIA, L.261‑1 information duties and employee rights. Document everything, camera by camera.

← Newer Page 9 / 10 Older →