LUXEMBOURG Law and Practice Contributed by: Romain Tiffon and Marie Bentley, ATOZ Tax Advisers
8.3 Role and Authority of the Data Protection Agency In Luxembourg, the enforcement of data protection rules is entrusted to an independent supervisory authority: the Commission nationale pour la protection des données (CNPD). The CNPD is the national data protection authority established under Luxembourg law and responsible for ensuring the application of the GDPR and related national legislation. It operates as an independent administrative body. Its core mis - sion is to monitor and enforce compliance with data protection rules. This includes: • supervising how public authorities and private enti - ties process personal data; • advising the government and Parliament on data protection matters; • issuing guidance, recommendations, and opinions; and • handling complaints lodged by individuals and ensuring the exercise of their rights. The CNPD is vested with extensive powers under the GDPR and Luxembourg law, which can be grouped into three main categories. • Investigative powers – it may conduct inquiries, request information, carry out on-site inspections, and access relevant data and documentation. • Corrective powers – it may order controllers or pro - cessors to comply with the law, impose temporary or definitive bans on processing, or require rectifi - cation or deletion of data. • Sanctioning powers – it may impose administrative fines, which can reach up to EUR20 million or 4% of the undertaking’s worldwide annual turnover, depending on the seriousness of the infringement. 9. Looking Forward 9.1 Upcoming Legal Reforms There is no applicable information in this jurisdiction.
In particular, entities with no EU establishment may nevertheless be subject to the GDPR where they offer goods or services to individuals located in the EU, including Luxembourg, or monitor the behaviour of such individuals, for example through online track - ing, profiling or behavioural advertising. The decisive factor is the individual’s presence in the EU at the time of the processing, rather than their nationality or residence. Where the GDPR applies, non-EU organisations must comply with the full range of applicable obligations, including: • ensuring a lawful basis for processing; • complying with transparency requirements; • respecting data subject rights; and • implementing appropriate technical and organisa - tional security measures. In certain circumstances, they may also be required to appoint a representative within the EU. Furthermore, transfers of personal data outside the European Economic Area are subject to the GDPR’s international transfer regime and must be supported by an adequacy decision or other appropriate safe - guards, such as standard contractual clauses. From an enforcement perspective, cross-border pro - cessing may fall within the competence of the Lux - embourg National Commission for Data Protection, particularly where Luxembourg constitutes the main establishment of a corporate group. The CNPD also co-operates with other European supervisory authori - ties under the GDPR’s one-stop-shop mechanism, enabling co-ordinated investigations and enforcement action across the EU, including against organisations established outside the Union.
621 CHAMBERS.COM
Powered by FlippingBook