News

❌ Insufficient association of a dpo

DPO | 28/03/2025

πŸ”’πŸ“‰ Luxembourg: €15,000 Fine for Poor DPO Involvement

πŸ“… Decision 20FR/2021 of June 11, 2021
The Luxembourg Data Protection Authority sanctioned a company for insufficient involvement of the DPO (Data Protection Officer) in matters related to personal data protection.

🚨 Key Findings:

πŸ” Irregular Participation:
The DPO was invited to meetings on demand, but not systematically.

πŸ‘₯ Lack of Visibility:
Their position within the organization did not allow for adequate involvement or clear recognition as a point of contact for data protection.

🏒 Inadequate Hierarchical Position:
Although the DPO reported to senior management, multiple hierarchical layers undermined their real independence.

🚫 Access to Top Management Was Conditional:
Direct contact with the board was only possible in cases of a “significant issue”, which restricted the DPO’s independence.

πŸ“‹ No Formal Control Plan:
There was no structured plan to prove that the DPO was fulfilling their oversight responsibilities.

🎯 Key Takeaways:

βœ”οΈ The DPO must be systematically involved in any project involving personal data.
βœ”οΈ They must have unconditional, direct access to top management.

Back to news list

Explore all our areas of expertise:

]]>