🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
LU · run data-protection-2026-08-04 v13-gdpri-1.0.0
content: ai_generated 12 sources retrieved model claude-sonnet-5 ·

Luxembourg

LU schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 27 claims · 12 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
27Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

Lead Signal

The Luxembourg Administrative Court, in case 52757C, annulled the CNPD's landmark €746 million GDPR fine against Amazon Europe Core in its entirety on 12 March 2026 and remanded the matter to CNPD. The court substantively upheld the underlying findings that Amazon's behavioural- and cross-context-advertising processing lacked a valid Article 6(1) legal basis and that the company had violated the data-subject-access, rectification and erasure rights under Articles 15, 16 and 17. Reports indicate the court excluded the decision's Article 21 right-to-object finding from its substantive review, on grounds that Amazon's rights of defence were compromised on that specific charge; that finding no longer stands as a settled, binding conclusion. CNPD's Chapter VI fining power — the mechanism by which the fine was imposed following a collective complaint lodged with the French CNIL by La Quadrature du Net under the GDPR's one-stop-shop cooperation procedure — is unaffected by the annulment; only the specific 2021 fault-assessment and fine now require CNPD to revisit them on remand.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core regulator, founding statute and territorial scope are well-evidenced from primary EDPB/EUR-Lex sources; registration/filing sub-module lacks a distinct LU-specific finding.

Primary frameworkRegulation (EU) 2016/679 (GDPR), as given domestic institutional effect by the Loi du 1er août 2018
Traffic-light rationale — GreenCore regulator, founding statute and territorial scope are well-evidenced from primary EDPB/EUR-Lex sources; registration/filing sub-module lacks a distinct LU-specific finding.

Sub-modules (5)

Regulator And AuthorityGreen

CNPD, 15 Boulevard du Jazz, 4370 Belvaux, is Luxembourg's independent GDPR supervisory authority.

Claims: CLM-LU-a1b2c3d4

Act And InstrumentsGreen

The Loi du 1er août 2018 is the national instrument organising the CNPD and the general data-protection regime.

Claims: CLM-LU-b2c3d4e5

Material ScopeAmber

Material scope tracks GDPR's definition of personal-data processing, with the national act supplying institutional/procedural detail.

Claims: CLM-LU-d4e5f6a7

Territorial ScopeGreen

Territorial scope follows GDPR Art 3 establishment and targeting criteria per EDPB Guidelines 3/2018.

Claims: CLM-LU-c3d4e5f6

Regulator Registration And FilingRed

No LU-specific general registration/filing obligation beyond GDPR accountability documentation (ROPA, DPIA) was located in this pass. Searched: 'CNPD registration filing requirements Luxembourg', 'Luxembourg data controller notification obligation'.

Category narrative98 words

Luxembourg is an EU Member State subject to the directly-applicable GDPR, given national institutional effect via the Loi du 1er août 2018 portant organisation de la Commission nationale pour la protection des données et du régime général sur la protection des données. The CNPD (Commission Nationale pour la Protection des Données), headquartered in Belvaux, is the sole national supervisory authority. Territorial scope follows GDPR Art 3's establishment/targeting test. Registration/filing: GDPR abolished general prior-notification regimes; no LU-specific residual filing obligation was identified in this research pass beyond DPIA/DPO record-keeping duties captured under controller_processor_duties (searched: 'CNPD registration filing requirements Luxembourg').

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedEDPBThe Commission Nationale pour la Protection des Données (CNPD), based at 15 Boulevard du Jazz, 4370 Belvaux, Luxembourg, is the country's independent GDPR supervisory authority.
  2. ConfirmedEUR-Lex (National Implementing Measure record)Luxembourg's GDPR-implementing act is the Loi du 1er août 2018 portant organisation de la Commission nationale pour la protection des données et du régime général sur la protection des données, published in Mémorial A No. 686 of 16 August 2018.
  3. ConfirmedEDPBGDPR Article 3 extends Luxembourg's data-protection regime extraterritorially via the establishment criterion (Art 3(1)) and the targeting criterion (Art 3(2)).
  4. ProbableEUR-Lex (National Implementing Measure record)The general data-protection regime organised by the Loi du 1er août 2018 applies alongside the directly-applicable GDPR to processing falling within GDPR's material scope, with the national act supplying Luxembourg's institutional and procedural framework (CNPD organisation, sanctions, cooperation).

#

Lawful bases, consent and special categories are solidly evidenced from EDPB primary guidance; pseudonymisation/anonymisation sub-module has no LU-specific finding.

Primary frameworkGDPR (EU) 2016/679, Articles 6-9
Traffic-light rationale — GreenLawful bases, consent and special categories are solidly evidenced from EDPB primary guidance; pseudonymisation/anonymisation sub-module has no LU-specific finding.

Sub-modules (4)

Lawful BasesGreen

Controllers must identify one of the six Art 6 lawful bases before processing.

Claims: CLM-LU-e5f6a7b8

Special CategoriesGreen

Art 9 special categories are prohibited by default absent a specific exception.

Claims: CLM-LU-a7b8c9d0

Pseudonymisation And AnonymisationRed

No LU-specific CNPD guidance on pseudonymisation/anonymisation safe-harbours was located this pass.

Category narrative54 words

GDPR Articles 6, 7 and 9 apply directly in Luxembourg. Lawful bases, consent standards and special-category prohibitions/exceptions are governed by the EU text with no LU-specific derogation identified for these sub-modules. Pseudonymisation/anonymisation safe-harbours (GDPR Art 4(5), Recital 26) were not independently evidenced with LU-specific CNPD guidance in this pass (searched: 'CNPD pseudonymisation anonymisation guidance').

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedEDPBData controllers must rely on one of the GDPR Article 6 lawful bases (consent, contract, legal obligation, vital interests, public interest/official authority, or legitimate interests) to process personal data lawfully.
  2. ConfirmedEDPBWhere consent is used as the lawful basis, GDPR requires it to be freely given, informed, specific and unambiguous, with individuals able to freely withdraw consent without negative consequences.
  3. ConfirmedEDPBProcessing of special categories of data (racial/ethnic origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic data, biometric data for identification, health data, sex life/orientation) is prohibited by default under GDPR Article 9 absent a specific exception.

#

Strong enforcement-based evidence for access/rectification/erasure/objection; portability and deadlines sub-modules unevidenced.

Primary frameworkGDPR Articles 12-22, given institutional effect via the Loi du 1er août 2018
Traffic-light rationale — AmberStrong enforcement-based evidence for access/rectification/erasure/objection; portability and deadlines sub-modules unevidenced.

Sub-modules (5)

Access RightAmber

CNPD found an Art 15 violation in the Amazon Europe Core case.

Claims: CLM-LU-b8c9d0e1

Rectification And ErasureAmber

CNPD found Art 16/17 violations in the same case.

Claims: CLM-LU-c9d0e1f2

Restriction And ObjectionAmber

CNPD found an Art 21 violation tied to profiling-based advertising objection rights.

Claims: CLM-LU-d0e1f2a3

Data PortabilityRed

No LU-specific portability finding located this pass.

Deadlines And Response WindowsRed

No LU-specific deadline/response-window guidance located this pass; GDPR's default one-month window is assumed absent evidence of derogation.

Category narrative61 words

CNPD's own enforcement record evidences the operative rights framework: the Amazon Europe Core decision (16 July 2021) expressly found violations of Articles 15 (access), 16 (rectification), 17 (erasure) and 21 (objection). Portability (Art 20) and the statutory response-deadline mechanics (Art 12(3)) were not independently evidenced with LU-specific material in this pass (searched: 'CNPD subject access request deadline', 'CNPD data portability guidance').

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceIn its 16 July 2021 decision, the CNPD found Amazon Europe Core in violation of, among other provisions, GDPR Article 15 (right of access), as part of a €746 million fine.
  2. ConfirmedOneTrust DataGuidanceThe same CNPD decision against Amazon Europe Core also found violations of GDPR Articles 16 (rectification) and 17 (erasure).
  3. ConfirmedOneTrust DataGuidanceThe CNPD's Amazon decision further found a violation of GDPR Article 21 (right to object), the provision underpinning objections to profiling-based targeted advertising.

#

DPO and accountability sub-modules well evidenced; ROPA, joint-controller, GDPR-breach-notification and retention sub-modules unevidenced in this pass.

Primary frameworkGDPR Articles 5, 24-39, given institutional effect via the Loi du 1er août 2018
Traffic-light rationale — AmberDPO and accountability sub-modules well evidenced; ROPA, joint-controller, GDPR-breach-notification and retention sub-modules unevidenced in this pass.

Sub-modules (7)

Accountability And DpiaAmber

CNPD's Amazon finding on Art 6(1) reflects the accountability principle requiring a demonstrable lawful basis.

Claims: CLM-LU-e1f2a3b4

Dpo RequirementsGreen

CNPD Decision 23FR/2021 addressed DPO reporting-line independence.

Claims: CLM-LU-f2a3b4c5

Ropa RequirementsRed

No LU-specific ROPA finding located this pass.

Joint Controller ArrangementsRed

No LU-specific joint-controller finding located this pass.

Security MeasuresAmber

Luxembourg's 2026 NIS2 transposition law imposes adjacent cybersecurity obligations supervised by ILR, distinct from GDPR Art 32 security duties enforced by CNPD.

Claims: CLM-LU-a3b4c5d6

Breach NotificationRed

No LU-specific CNPD guidance on GDPR Art 33/34 personal-data breach notification located this pass; the adjacent NIS2 incident-notification regime is distinct and supervised by ILR.

Retention And DisposalRed

No LU-specific retention/disposal finding located this pass.

Category narrative73 words

Accountability (Art 6(1) legal-basis documentation) and DPO independence are evidenced via CNPD's Amazon decision and Decision No. 23FR/2021 respectively. ROPA, joint-controller arrangements, GDPR-specific breach notification and retention/disposal lack LU-specific evidentiary findings this pass. A distinct but adjacent cybersecurity-incident-notification regime (NIS2 transposition, Law of 5 May 2026) is captured under security_measures, supervised by ILR rather than CNPD (searched: 'CNPD ROPA requirements guidance', 'CNPD breach notification guidance', 'CNPD retention disposal guidance', 'CNPD joint controller guidance').

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceThe CNPD's Amazon Europe Core decision found that the company's processing of personal data for behavioural advertising lacked a valid legal basis under GDPR Article 6(1), reflecting the accountability principle that controllers must be able to demonstrate a lawful basis for each processing purpose.
  2. ConfirmedCNILIn Decision No. 23FR/2021 of 29 June 2021, the CNPD held that direct reporting lines or the ability to bypass intermediate management levels can be proportionate measures to guarantee a Data Protection Officer's autonomy under GDPR Articles 38-39.
  3. ConfirmedOneTrust DataGuidanceLuxembourg's Law of 5 May 2026 transposing the NIS2 Directive introduces risk-based cybersecurity obligations, incident-notification requirements and governance/accountability measures for essential and important entities, with the Institut Luxembourgeois de Régulation (ILR) — not the CNPD — designated as the supervising authority.

#

General Chapter V applicability evidenced generically; LU-specific transfer-mechanism detail (SCC uptake, TIA practice, localisation) unevidenced.

Primary frameworkGDPR Chapter V (Articles 44-49), directly applicable EU law
Traffic-light rationale — AmberGeneral Chapter V applicability evidenced generically; LU-specific transfer-mechanism detail (SCC uptake, TIA practice, localisation) unevidenced.

Sub-modules (6)

Transfer MechanismsAmber

Chapter V mechanisms (adequacy, SCCs, BCRs, derogations) apply directly as EU law.

Claims: CLM-LU-b4c5d6e7

Adequacy ReceivedRed

No LU-specific finding; adequacy is an EU-Commission-level determination.

Adequacy GrantedRed

No LU-specific finding; adequacy is an EU-Commission-level determination.

Sccs And BcrsRed

No LU-specific SCC/BCR uptake data located this pass.

Transfer Impact AssessmentRed

No LU-specific TIA practice guidance located this pass.

Data LocalisationRed

No LU-specific data-localisation mandate identified this pass.

Category narrative69 words

As an EU Member State, Luxembourg's transfer regime runs directly off GDPR Chapter V (Arts 44-49) as EU law; the national act supplies institutional enforcement capacity via CNPD rather than a separate transfer statute. Adequacy decisions received/granted, SCC/BCR uptake specifics, transfer-impact-assessment practice and any data-localisation mandate were not independently evidenced with LU-specific material in this pass (searched: 'CNPD adequacy decisions', 'CNPD SCC BCR guidance Luxembourg', 'Luxembourg data localisation requirement').

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ProbableEUR-Lex (National Implementing Measure record)As an EU Member State, Luxembourg's cross-border transfer regime for personal data is governed directly by GDPR Chapter V (Articles 44-49) as directly-applicable EU law, with the Loi du 1er août 2018 supplying the national institutional and enforcement framework (CNPD) rather than a separate transfer statute.

#

Financial and telecoms overlays well evidenced; health, employment, credit-scoring, education and (binding) insurance overlays unevidenced.

Primary frameworkGDPR plus sector overlays: Law of 5 April 1993 on the financial sector (CSSF); ePrivacy Directive 2002/58/EC (as amended)
Supervisory authorityCommission de Surveillance du Secteur Financier (CSSF)
Traffic-light rationale — AmberFinancial and telecoms overlays well evidenced; health, employment, credit-scoring, education and (binding) insurance overlays unevidenced.

Sub-modules (7)

Financial Sector OverlayGreen

CSSF professional secrecy and cross-border information-exchange rules layer atop GDPR for supervised financial entities.

Claims: CLM-LU-c5d6e7f8

Health Sector OverlayRed

No LU-specific health-sector DP overlay located this pass.

Telecoms And EprivacyAmber

ePrivacy Directive remains operative; 2026 NIS2 law also amends the electronic-communications statute.

Claims: CLM-LU-e7f8a9b0, CLM-LU-f8a9b0c1

Employment DataRed

No LU-specific employment-data overlay located this pass.

Credit And ScoringRed

No LU-specific credit-scoring overlay located this pass.

EducationRed

No LU-specific education-sector overlay located this pass.

InsuranceAmber

A still-pending AI Act implementing bill would designate the Insurance Commission as AI market-surveillance authority for the insurance sector; not yet confirmed enacted.

Claims: CLM-LU-a9b0c1d2

Category narrative99 words

The financial sector carries a distinct professional-secrecy/cooperation overlay under the Law of 5 April 1993 on the financial sector (as amended), administered by the CSSF, which interacts with but is separate from GDPR. Telecoms/eProceedings run off the ePrivacy Directive pending an EU-level Regulation, with Luxembourg's 2026 NIS2 law also amending the electronic-communications-networks statute. Health, employment, credit-scoring and education sector-specific overlays were not independently evidenced this pass; the insurance sector is referenced only via a still-pending AI Act implementing bill (searched: 'Luxembourg health sector data protection law', 'Luxembourg employment data protection code', 'Luxembourg credit scoring regulation', 'Luxembourg education data protection').

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedCSSFThe Law of 5 April 1993 on the financial sector, as amended, imposes professional-secrecy obligations on the CSSF and governs its cooperation and information-exchange with EU and third-country authorities, forming a sectoral confidentiality overlay for Luxembourg's banks, investment firms and other supervised entities.
  2. ConfirmedEDPSThe ePrivacy Directive (2002/58/EC, as amended) remains the operative EU instrument governing confidentiality of electronic communications and cookie-related tracking, layered on top of the GDPR, pending adoption of a replacement ePrivacy Regulation.
  3. ConfirmedOneTrust DataGuidanceLuxembourg's Law of 5 May 2026 transposing NIS2 also amended the law of 17 December 2021 on electronic communications networks and services, linking cybersecurity obligations to the electronic-communications sector.
  4. ProbableOneTrust DataGuidanceLuxembourg's draft AI Act implementing bill (No. 8476) proposes designating the Commissariat aux Assurances (Insurance Commission) as the market-surveillance authority for AI systems placed on the market, commissioned, or used by entities under its insurance-sector supervision.

#

Cookies/dark-patterns/cross-context advertising well evidenced; opt-out signals, clean rooms and direct marketing unevidenced.

Primary frameworkePrivacy Directive (as amended) + GDPR, CNPD cookie guidance
Traffic-light rationale — AmberCookies/dark-patterns/cross-context advertising well evidenced; opt-out signals, clean rooms and direct marketing unevidenced.

Sub-modules (6)

Cookies And TrackersGreen

CNPD guidelines clarify consent requirements for essential and non-essential cookies.

Claims: CLM-LU-b0c1d2e3

Dark PatternsAmber

CNPD cookie guidance addresses manipulative consent-banner design.

Claims: CLM-LU-c1d2e3f4

Opt Out SignalsRed

No LU-specific opt-out-signal finding located this pass.

Clean Rooms And DcrRed

No LU-specific clean-room/DCR finding located this pass.

Cross Context AdvertisingGreen

The Amazon fine centred on cross-context targeted-advertising practices lacking a valid legal basis.

Claims: CLM-LU-d2e3f4a5

Direct MarketingRed

No LU-specific direct-marketing consent/suppression finding located this pass.

Category narrative59 words

CNPD's dedicated cookie guidelines address both consent architecture and dark patterns in banners; the Amazon decision independently evidences enforcement against cross-context/targeted-advertising practices lacking a valid legal basis. Opt-out signals (GPC/DAA-equivalent), clean-room/data-collaboration-room rules and direct-marketing consent/suppression specifics were not independently evidenced this pass (searched: 'CNPD Global Privacy Control opt-out signal', 'CNPD direct marketing guidance', 'CNPD clean room data collaboration guidance').

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceCNPD guidelines on cookies and other trackers clarify consent requirements for essential and non-essential cookies, including analytical cookies.
  2. ProbableOneTrust DataGuidanceCNPD cookie guidance addresses dark-pattern designs in consent banners, treating manipulative interface choices that pressure users toward accepting non-essential cookies as a compliance risk under the cookie-consent framework.
  3. ConfirmedCNILThe CNPD's €746 million decision against Amazon Europe Core centred on the company's targeted (cross-context) advertising practices, which the authority found lacked a valid GDPR Article 6(1) legal basis.

#

AI Act competent-authority designation and Art 22 baseline evidenced but the designation is still at bill stage; biometric/genetic/profiling/surveillance carve-out sub-modules unevidenced.

Primary frameworkGDPR Article 22; EU AI Act (Regulation (EU) 2024/1689); draft Luxembourg AI Act implementing Bill No. 8476
Traffic-light rationale — AmberAI Act competent-authority designation and Art 22 baseline evidenced but the designation is still at bill stage; biometric/genetic/profiling/surveillance carve-out sub-modules unevidenced.

Sub-modules (6)

Profiling RestrictionsRed

No dedicated LU-specific profiling-restriction finding beyond Art 21/22 baseline located this pass.

Automated Decision Making TransparencyAmber

GDPR Art 22 applies directly, enforced by CNPD.

Claims: CLM-LU-f4a5b6c7

Ai Risk AssessmentsAmber

Draft Bill No. 8476 would designate CNPD as AI Act market-surveillance authority/notified body for law-enforcement, immigration and asylum AI systems.

Claims: CLM-LU-e3f4a5b6

Biometric RegimeRed

No LU-specific biometric-regime finding located this pass.

Genetic DataRed

No LU-specific genetic-data regime finding located this pass.

State Surveillance CarveoutsRed

No LU-specific state-surveillance carve-out finding located this pass.

Category narrative88 words

GDPR Article 22 ADM restrictions apply directly as EU law. Luxembourg's draft AI Act implementing bill (No. 8476, introduced 23 December 2024) would designate the CNPD as market-surveillance authority/notified body for high-risk AI systems used by law-enforcement, immigration or asylum authorities, and would amend the CNPD organisation act; enactment status was not reconfirmed this pass. Biometric regime, genetic data, general profiling restrictions and state-surveillance carve-outs were not independently evidenced with LU-specific material (searched: 'CNPD facial recognition biometric guidance', 'CNPD genetic data guidance', 'Luxembourg national security data protection exemption').

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. ProbableOneTrust DataGuidanceLuxembourg's draft AI Act implementing bill (No. 8476), introduced 23 December 2024, proposes designating the CNPD as the market-surveillance authority and notified body for high-risk AI systems used by law-enforcement, immigration, or asylum authorities, and amends the Act organising the CNPD and the general data-protection regime accordingly.
  2. ProbableEUR-Lex (National Implementing Measure record)GDPR Article 22's restrictions on solely automated decision-making with legal or similarly significant effects apply directly in Luxembourg as EU law, enforced by the CNPD under the Loi du 1er août 2018's institutional framework.

#

Age-of-consent/parental-consent baseline evidenced via GDPR Art 8 generic guidance; no confirmed LU-specific derogation and other sub-modules unevidenced.

Primary frameworkGDPR Article 8
Traffic-light rationale — AmberAge-of-consent/parental-consent baseline evidenced via GDPR Art 8 generic guidance; no confirmed LU-specific derogation and other sub-modules unevidenced.

Sub-modules (5)

Age VerificationRed

No LU-specific age-verification mechanism finding located this pass.

Minor Profiling BansRed

No LU-specific minor-profiling-ban finding located this pass.

Education SettingsRed

No LU-specific education-settings finding located this pass.

Dependent AdultsRed

No LU-specific dependent-adults finding located this pass.

Category narrative76 words

GDPR Article 8's default digital-consent age of 16 applies absent an identified LU derogation lowering it toward the permitted 13-16 range; no such derogation was located in this pass. Parental-consent mechanics beyond the Art 8 baseline, minor-profiling bans, education-settings-specific rules and dependent-adult protections were not independently evidenced with LU-specific material (searched: 'Luxembourg data protection law digital age of consent minors derogation', 'CNPD minor profiling guidance', 'CNPD education sector children data guidance', 'Luxembourg dependent adults data protection').

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ConfirmedEDPBUnder GDPR Article 8, children aged 16 and above can consent to information-society-service processing on their own behalf, while for children below 16 the controller must obtain consent from a parent or legal guardian, subject to Member States' ability to lower this threshold to as low as 13 by national law.

#

Landmark enforcement action, its collective-complaint origin, and a within-180-day legislative development are all well evidenced; funding/capacity and private-right-of-action detail are gaps.

Primary frameworkGDPR Chapter VI-VIII (Articles 77-84), given institutional effect via the Loi du 1er août 2018
Traffic-light rationale — GreenLandmark enforcement action, its collective-complaint origin, and a within-180-day legislative development are all well evidenced; funding/capacity and private-right-of-action detail are gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

CNPD exercises GDPR Chapter VI powers up to statutory fine maxima, illustrated by the Amazon decision.

Claims: CLM-LU-b6c7d8e9

Enforcement Activity IndexAmber

The Amazon decision is the sole large-scale enforcement action independently confirmed this pass; broader 12-month activity statistics were not retrieved.

Regulator Funding And CapacityRed

No LU-specific funding/headcount data located this pass.

Collective Redress And Class ActionsGreen

The Amazon matter originated from a collective complaint under the GDPR one-stop-shop cooperation mechanism.

Claims: CLM-LU-d8e9f0a1

Private Right Of ActionRed

No LU-specific procedural detail on direct judicial recourse (GDPR Art 79) located this pass.

Recent Developments 180DGreen

Luxembourg's NIS2 transposition law entered into force 10 May 2026, within the 180-day window.

Claims: CLM-LU-e9f0a1b2

Category narrative117 words

CNPD's headline enforcement action is the 16 July 2021 €746 million fine against Amazon Europe Core — among the largest GDPR fines issued to date — originating from a collective complaint lodged with CNIL by La Quadrature du Net and transferred to CNPD as lead authority under the GDPR cooperation mechanism; the decision remains partly under judicial challenge. Luxembourg's Law of 5 May 2026 transposing NIS2 is the most recent (within 180 days) legislative development touching the broader data-governance/cybersecurity landscape, though its supervisory authority (ILR) sits outside CNPD's remit. Regulator funding/capacity metrics and private-right-of-action procedural detail were not independently evidenced this pass (searched: 'CNPD annual report budget staff', 'Luxembourg GDPR Article 79 private right of action procedure').

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedCNILThe CNPD exercises GDPR Chapter VI investigative and corrective powers and can impose administrative fines up to GDPR maxima, as illustrated by its €746 million fine against Amazon Europe Core on 16 July 2021, an amount described as unprecedented in scale and marking a turning point in GDPR enforcement.
  2. ConfirmedCNILThe Amazon Europe Core case originated from a collective complaint lodged with the French CNIL by the advocacy group La Quadrature du Net, which was handled by the CNPD as lead supervisory authority under the GDPR's cooperation procedures because Amazon Europe Core is established in Luxembourg.
  3. ConfirmedOneTrust DataGuidanceOn 5 May 2026, Luxembourg's Official Journal published the Law of 5 May 2026 transposing the NIS2 Directive, which entered into force on 10 May 2026 and designates the Institut Luxembourgeois de Régulation (ILR) — not the CNPD — as the competent cybersecurity supervisory authority, with self-registration required for essential/important entities.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Luxembourg
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 27 claim(s), 12 source(s) in the cumulative register.