Luxembourg data protection authority – €15,000 Fine (Luxembourg, 2021)

€15,000Commission Nationale pour la Protection des Données11 June 2021Luxembourg
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Luxembourg data protection authority fined a logistics company EUR 15,000 for not properly involving their Data Protection Officer (DPO) in privacy matters. The DPO was not included in key meetings and did not report directly to top management. This case stresses the importance of giving DPOs the authority and involvement they need to ensure compliance with privacy laws.

What happened

A logistics company failed to properly involve their Data Protection Officer in privacy-related matters.

Who was affected

The company's Data Protection Officer, who was not properly involved in privacy issues, was affected.

What the authority found

The Luxembourg authority found the company did not meet GDPR requirements for involving and empowering their DPO.

Why this matters

This ruling highlights the critical role of DPOs in ensuring data protection compliance. Companies should ensure their DPOs are actively involved in privacy decisions and report directly to senior management.

Entities Involved

Luxembourg data protection authority
Logistics company (anonymized)
Full Legal Summary
Detailed

The Luxembourgish Data Protection Authority (CNPD) conducted an investigation at a logistics company within the framework of a global investigation campaign on the function of Data Protection Officer (DPO) in both private and public sectors. Did the logistics company meet the legal requirements regarding the function of DPO? Following their investigation at the company, the CNPD found: # that the company's DPO did not seem to be invited to all relevant meetings for them and that it therefore could not be considered that they were involved properly and in a timely manner in all issues which relate to the protection of personal data as required by Article 38(1) GDPR; # that the DPO did not report directly to the highest level of management at the company, thus not ensuring that the DPO could act without receiving any instructions regarding the exercise of their tasks pursuant to Art. 38(3) GDPR; # that, though it could reasonably be expected that the DPO did a formal and frequent reporting on their activities to the management, such a reporting had not been set up and that the company therefore did not meet the requirements of Article 39(1)(a) GDPR which states that the DPO should inform and advise the controller; # that the company had not been able to demonstrate that they had an audit plan for the year, thus violating Article 39(1)(b) GDPR regarding the DPO's duties to monitor compliance with GDPR. In view of those violations, the CNPD: * imposed an administrative fine of fifteen thousand euros (€15,000) on the company; * ordered them to comply with Articles 38(1), 38(3), 39(1)(a) and 39(1)(b) GDPR within four months of the notification of the decision.

Related Enforcement Actions (0)

No other enforcement actions found for Luxembourg data protection authority in LU

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

11 June 2021

Authority

Commission Nationale pour la Protection des Données

Fine Amount

€15,000

GDPRhub ID

gdprhub-3603

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Luxembourg data protection authority - Luxembourg (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: