National Commission for Data Protection (CNPD) · 13 October 2021
Not named in the source
Insufficient involvement of data protection officer
- Regulator
- National Commission for Data Protection (CNPD)
- Decided
- 13 October 2021
- Country
- Luxembourg
- Sector
- Not given
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/LU/006
What happened
The Luxembourg DPA (CNPD) fined a company €13,200 for two violations of the GDPR identified in the course of an audit on the role of the Data Protection Officer's (DPO) within a company. The CNPD originally found four violations, but only upheld two of them because the company had already taken measures to remedy these breaches.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 38Position of the data protection officer38(1)Read →
- Art. 39Tasks of the data protection officer39(1)(b)Read →
- Data protection officer
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/LU/006.